The Security Snooze Button: HIPAA Security Rule delayed to (at least) July 2027

By the EHR Association Privacy & Security Workgroup

With the recent publication of the US Department of Health and Human Services’ (HHS) 2026 unified regulatory agenda, the HHS Office for Civil Rights (OCR) hit the snooze button on HIPAA Security Rule updates. Final rulemaking for the January 2025 HIPAA Security Notice of Proposed Rule Making (NPRM) was targeted for a May 2026 release in the previous unified agenda, but notably excluded from the current agenda. Instead, it was transitioned to a long-term action with a target date of July 2027.

While this delay buys time to get the rule right, it isn’t cost-free, as the cyberattack trend that justified the NPRM in the first place hasn’t paused. 

Read the full post »

Sensitive Data Management: The Need for Standards to Catch Up to Policy

By The EHR Association Sensitive Data Management Task Force

This is the first in an occasional blog series focused on framing the work that lies ahead to establish clear, consistent, computable standards governing the management of sensitive data.

Health information is personal. It is also essential to the provision of safe, coordinated, high-quality care. Stakeholders across the health IT ecosystem are intimately familiar with managing the tension between ensuring the right information is available to the right people at the right time and also respecting patient privacy, legal restrictions, and patients’ expectations about how their information will be used and disclosed.

While the tension is not new, the pace, complexity, and variability of the rules being applied to sensitive health information are.

Read the full post »

HTI-5 Big Picture: Key Certification Takeaways

By the EHR Association Certification Workgroup

When it comes to the HTI-5 proposed rule and its focus on certification, our primary message to ONC is this: the deregulatory push is needed and yet should be undertaken with caution.

We appreciate ONC’s efforts to streamline the certification program through deregulation. Some of the criteria have been around for many years, and removing them will help reduce the certification burden on the health IT industry and, in some cases, on providers using the software, while maintaining progress toward advancing interoperability, transparency, and access to electronic health information. We agree with ONC that many certification criteria not directly associated with interoperability should be considered for removal.  

Read the full post »

AI in Healthcare: What I Learned from Our Fireside Chat with AWS

By Leigh Burchell (Altera Digital Health), Chair, EHR Association

At a recent EHR Association General Membership Meeting, an event we hold monthly to bring together our members for conversations on a wide variety of topics, I had the pleasure of sitting down with Bret Borota, Head of Global Strategic Sales and Business Development for Healthcare and Payer Segments at Amazon Web Services (AWS), for a wide-ranging fireside chat on the state of AI in health IT.

Bret brings a unique vantage point to this conversation: a current portfolio spanning medical imaging, EHRs, interoperability, revenue cycle management, and commercial payers, plus 20 years in health IT before joining AWS.

Read the full post »

FDA’s Revised CDS Guidance: Opportunities and the Path Forward for EHR Developers

By the EHRA Artificial Intelligence, Public Policy Leadership & Value-based Care and Quality Programs Workgroups

In January 2026, the FDA released revised guidance on Clinical Decision Support (CDS) software, clarifying the scope of the FDA’s oversight of CDS software intended for use by health care professionals, including software identified as artificial intelligence (AI). While the guidance includes some genuine improvements over the previous iterations released in 2022 and 2023, the EHR Association has identified concerns about ambiguous new standards, regulatory overreach, and the potential to negatively affect both innovation and patient care.

Read the full post »

HTI-5 Part One: Information Blocking Red Flags

By the EHR Association Information Blocking Compliance Task Force

This is the first installment of a multi-part blog series on the EHR Association’s analysis of the HTI-5 proposed rule.

The HTI-5 proposed rule, Health Data, Technology, and Interoperability: ASTP/ONC Deregulatory Actions To Unleash Prosperity, significantly updates information blocking compliance provisions. The proposed changes raised red flags for the EHR Association because they do not provide the simplification, guidance, and education needed to cut through the complexity of current policy. In fact, they increase the complexity and challenges of compliance.

Also among our overarching concerns are ASTP/ONC’s apparent overstatement of the burden-reduction outcomes of its proposed changes and its underestimation of the true economic impact of both the current information blocking policy and the proposed changes, as implied by the agency’s failure to provide an estimate of the implementation costs borne by the industry. The reality is that the proposed changes will increase the administrative burden on software developers and other stakeholders who interact with our community in the process of determining the best path forward for information access, exchange, and use. 

Read the full post »
  • Categories

  • Follow EHRA on Twitter

  • Enter your email address to follow this blog and receive notifications of new posts by email.

    Join 213 other subscribers
  • Contact Us

    Kasey Nicholoff
    staff @ ehra.org

    Amanda Patanow
    Communications and Media
    ehracomms @ npccs.com