Wade’s Health Law Highlights for August 25, 2026
Reimbursement & Payment
- The Fifth Circuit, sitting en banc, vacated the federal regulations governing how insurers calculate the qualifying payment amount under the No Surprises Act. In Texas Medical Association v. United States Department of Health and Human Services, No. 23-40605, decided August 11, the court held that a plan’s QPA may not count non-negotiated “ghost rates” for services the contracting provider does not furnish, and may not categorically exclude provider bonus and incentive payments from the total maximum payment. The court upheld the exclusion of one-off single-case agreements from the calculation. The decision does not address whether past independent dispute resolution determinations may be revisited, and the court noted that the Departments can use enforcement discretion to allow continued use of current QPAs while recalculations proceed. On August 13, the Departments of Health and Human Services, Labor, and Treasury acknowledged the ruling and said guidance would follow. Source: ArentFox Schiff
HIPAA & Data Privacy
- The HIPAA breach notification clock starts on the day a breach is discovered, not on the day a forensic investigation concludes. OSF Healthcare System discovered the Nephilim ransomware variant in its systems on April 23, 2021, determined on August 24 that the protected health information of 53,907 individuals had been stolen, and notified HHS and affected individuals on October 1, 110 days after discovery. OCR announced a resolution agreement on July 29 under which the health system pays $552,250, revises its breach notification policies, trains its workforce, and submits to two years of monitoring. This is OCR’s 21st ransomware enforcement action, following Presence Health at $475,000 in 2017, Solara Medical Supplies in 2022, Vision Upright MRI at $5,000 in 2025, and MMG Fusion at $10,000 in 2026. A covered entity that has not determined the full scope of a breach by day 60 must notify OCR with its findings to that point and supplement them later, and delay is available only on a documented, specific law enforcement request. Source: Crowell & Moring
- Replying to a patient’s online review can itself disclose protected health information, even when the patient posted the details first. A two-stage review of 80,300 recent public Google review replies from 2,972 medical and dental practices in California and the Pacific Northwest estimated that 21,117 replies, or 26.3 percent, confirmed or disclosed patient information under the study’s rubric. Of the replies adjudicated by hand, 58 percent confirmed patient or visit status, 41 percent disclosed a clinical detail such as a condition, procedure, result, or symptom, and 1 percent referenced billing or insurance. Among the seven disciplines audited in full, the share of replying practices with at least one confirmed disclosure ranged from 60.8 percent in pediatrics to 90 percent in fertility and reproductive medicine. OCR has already enforced in this setting, with a $10,000 settlement with Elite Dental Associates, a $50,000 civil money penalty against Dr. U. Phillip Igbinadolor, D.M.D. & Associates, a $23,000 settlement with New Vision Dental, and a $30,000 settlement with Manasa Health Center. Source: The HIPAA Journal
- Neither SOC 2 nor the HIPAA Security Rule names penetration testing as a required control, and both create practical pressure to perform one. SOC 2’s Trust Services Criteria require evidence that a company monitors for vulnerabilities and evaluates the effectiveness of its security controls on an ongoing basis, criteria CC4.1 and CC7.1, and auditors have settled on penetration testing as the way to satisfy that requirement in Type 2 reports. The HIPAA Security Rule requires a documented risk analysis and ongoing risk management, and a 2025 proposed update from HHS would state technical testing requirements expressly rather than leaving them implied. SOC 2 testing scope follows the service commitments in the audit report, while a HIPAA risk analysis must account for everywhere PHI lives, moves, and is stored, which can reach backup systems, analytics pipelines, and third-party integrations outside the SOC 2 boundary. One engagement scoped across both boundaries can satisfy both frameworks. Source: Security Boulevard
Fraud & Abuse
- OIG will not impose sanctions on a nonprofit charity that pays health insurance premiums and cost-sharing for Federal health care program beneficiaries with rare and chronic diseases using donations from the pharmaceutical manufacturers whose drugs treat those diseases. The charity would divide its patient assistance program into per-disease funds, each split between premium assistance and copayment assistance, awarded first-come, first-served under a uniform financial need policy. Disease funds would be defined by widely recognized clinical standards rather than by symptom, severity, route of administration, or type of drug treatment, and would cover all prescription drugs the FDA has approved for the relevant disease, including generics and bioequivalents. Donors would receive no patient-identifiable data and no information allowing them to correlate the amount or frequency of donations with use of their own products, and the charity would keep absolute discretion over how earmarked donations are applied. OIG concluded the arrangement would generate prohibited remuneration under the Federal anti-kickback statute if the requisite intent were present, but found the risk of fraud and abuse low enough for a favorable opinion, and said it may request donor and distribution data roughly two years after the August 18, 2026, issuance date to reassess the arrangement after the Inflation Reduction Act’s Part D cost-sharing changes take full effect. Source: HHS Office of Inspector General
Artificial Intelligence in Health Care
- Government health care agencies have no method for deciding whether AI should be used for a given decision at all, only for mitigating the risks once they deploy it. Between FY 2024 and FY 2025, FDA reported a 148 percent increase in AI use, CDC 87 percent, CMS 78 percent, and NIH 51 percent, and GAO found that generative AI use cases across 11 federal agencies rose nine-fold from 2023 to 2024. Federal impact assessments for “high-impact” uses require agencies to explain a system’s purpose, evaluate data quality and model fitness, assess effects on privacy and civil rights, analyze costs, and obtain independent review, all of which presume the system will be deployed. Rule-based eligibility systems have already produced litigation, including a class action against TennCare alleging Medicaid Act, ADA, and due process violations tied to its computerized eligibility determination system, and a National Health Law Program complaint to the FTC over Deloitte Consulting software used in Texas and 20 other states. A proposed Five Factor Framework would have an agency identify the interests at stake, examine the normative structure of the decision under the APA’s reasoned decision-making requirement, assess the technology’s capabilities and error modes, evaluate how human judgment is integrated or displaced against nondelegation and due process principles, and identify the legal constraints, followed by public input when the agency concludes the benefits outweigh the risks. Source: Petrie-Flom Center
- Hospitals are adding AI scheduling systems that build staffing and appointment schedules from patient, shift, and facility data. The software analyzes appointments and no-shows, how long workers have been on shift, how staff expertise matches patient needs, and which beds and surgical units are open. Boston Children’s Hospital announced a partnership with OpenAI in May under which the technology reads medical records to assess whether a patient needs imaging, identifies the next opening, and matches surgical cases to operating rooms. TigerConnect sells a scheduling service inside a back-office platform that answers calls and connects to clinician messaging, with visibility into vacation requests and holiday coverage. Deloitte Consulting principal Bill Fera said agentic systems could take a scribe’s note, determine that a patient needs a CT scan, schedule the visit, and pursue prior authorization, and Boston Children’s chief innovation officer John Brownstein said advisory groups monitor the tools and humans validate their output. Source: Healthcare Brew
Texas Regulatory
- Texas HHSC proposed establishing the Hospital Payment Advisory Committee as a standalone advisory committee with 15 members, keeping the Rural Hospital Advisory Committee as its subcommittee. Proposed amendment to 1 TAC §353.1155 adding diversion slots and clinical criteria to the Medically Dependent Children Program, which would let eligible medically fragile children enroll before reaching the top of the interest list and without admission to a nursing facility. HHSC adopted amendments across 1 TAC Chapter 373 conforming the Medicaid Estate Recovery Program to federal law and implementing House Bill 4611, and consolidated the Children’s Autism Program rules into 26 TAC Chapter 358, expanding the definition of qualified professional to include nurse practitioners and physician assistants. The State Board of Dental Examiners withdrew proposed amendments to 22 TAC §101.8 on dental licensure and 22 TAC §116.3 on dental laboratories, and adopted changes to dental and dental hygiene faculty licensure rules. The Texas Optometry Board repealed or amended rules on license conversion, license designation, complaint procedures, disciplinary proceedings, alternative dispute resolution, and appointment of its emergency committee. Source: Texas Health Law
Community Health Centers
- Health centers awarded a New Access Point grant have 120 days under HRSA rules to bring the new service site online. A webinar on September 15 at 1:00 p.m. CST covers reading the Notice of Award for its terms, funding parameters, and reporting obligations, and identifying which items require immediate attention. It addresses the benefits tied to the new site, including enhanced reimbursement, 340B eligibility, and FTCA coverage. It also covers the operational, scope, and compliance steps required inside the 120-day window. The session closes on the differences between look-alike and grantee status, managing the grant and documenting draws, and first-year mistakes to avoid. Source: VMG Health
Reimbursement & Payment
- The Fifth Circuit, sitting en banc, vacated the federal regulations governing how insurers calculate the qualifying payment amount under the No Surprises Act. In Texas Medical Association v. United States Department of Health and Human Services, No. 23-40605, decided August 11, the court held that a plan’s QPA may not count non-negotiated “ghost rates” for services the contracting provider does not furnish, and may not categorically exclude provider bonus and incentive payments from the total maximum payment. The court upheld the exclusion of one-off single-case agreements from the calculation. The decision does not address whether past independent dispute resolution determinations may be revisited, and the court noted that the Departments can use enforcement discretion to allow continued use of current QPAs while recalculations proceed. On August 13, the Departments of Health and Human Services, Labor, and Treasury acknowledged the ruling and said guidance would follow. Source: ArentFox Schiff
HIPAA & Data Privacy
- The HIPAA breach notification clock starts on the day a breach is discovered, not on the day a forensic investigation concludes. OSF Healthcare System discovered the Nephilim ransomware variant in its systems on April 23, 2021, determined on August 24 that the protected health information of 53,907 individuals had been stolen, and notified HHS and affected individuals on October 1, 110 days after discovery. OCR announced a resolution agreement on July 29 under which the health system pays $552,250, revises its breach notification policies, trains its workforce, and submits to two years of monitoring. This is OCR’s 21st ransomware enforcement action, following Presence Health at $475,000 in 2017, Solara Medical Supplies in 2022, Vision Upright MRI at $5,000 in 2025, and MMG Fusion at $10,000 in 2026. A covered entity that has not determined the full scope of a breach by day 60 must notify OCR with its findings to that point and supplement them later, and delay is available only on a documented, specific law enforcement request. Source: Crowell & Moring
- Replying to a patient’s online review can itself disclose protected health information, even when the patient posted the details first. A two-stage review of 80,300 recent public Google review replies from 2,972 medical and dental practices in California and the Pacific Northwest estimated that 21,117 replies, or 26.3 percent, confirmed or disclosed patient information under the study’s rubric. Of the replies adjudicated by hand, 58 percent confirmed patient or visit status, 41 percent disclosed a clinical detail such as a condition, procedure, result, or symptom, and 1 percent referenced billing or insurance. Among the seven disciplines audited in full, the share of replying practices with at least one confirmed disclosure ranged from 60.8 percent in pediatrics to 90 percent in fertility and reproductive medicine. OCR has already enforced in this setting, with a $10,000 settlement with Elite Dental Associates, a $50,000 civil money penalty against Dr. U. Phillip Igbinadolor, D.M.D. & Associates, a $23,000 settlement with New Vision Dental, and a $30,000 settlement with Manasa Health Center. Source: The HIPAA Journal
- Neither SOC 2 nor the HIPAA Security Rule names penetration testing as a required control, and both create practical pressure to perform one. SOC 2’s Trust Services Criteria require evidence that a company monitors for vulnerabilities and evaluates the effectiveness of its security controls on an ongoing basis, criteria CC4.1 and CC7.1, and auditors have settled on penetration testing as the way to satisfy that requirement in Type 2 reports. The HIPAA Security Rule requires a documented risk analysis and ongoing risk management, and a 2025 proposed update from HHS would state technical testing requirements expressly rather than leaving them implied. SOC 2 testing scope follows the service commitments in the audit report, while a HIPAA risk analysis must account for everywhere PHI lives, moves, and is stored, which can reach backup systems, analytics pipelines, and third-party integrations outside the SOC 2 boundary. One engagement scoped across both boundaries can satisfy both frameworks. Source: Security Boulevard
Fraud & Abuse
- OIG will not impose sanctions on a nonprofit charity that pays health insurance premiums and cost-sharing for Federal health care program beneficiaries with rare and chronic diseases using donations from the pharmaceutical manufacturers whose drugs treat those diseases. The charity would divide its patient assistance program into per-disease funds, each split between premium assistance and copayment assistance, awarded first-come, first-served under a uniform financial need policy. Disease funds would be defined by widely recognized clinical standards rather than by symptom, severity, route of administration, or type of drug treatment, and would cover all prescription drugs the FDA has approved for the relevant disease, including generics and bioequivalents. Donors would receive no patient-identifiable data and no information allowing them to correlate the amount or frequency of donations with use of their own products, and the charity would keep absolute discretion over how earmarked donations are applied. OIG concluded the arrangement would generate prohibited remuneration under the Federal anti-kickback statute if the requisite intent were present, but found the risk of fraud and abuse low enough for a favorable opinion, and said it may request donor and distribution data roughly two years after the August 18, 2026, issuance date to reassess the arrangement after the Inflation Reduction Act’s Part D cost-sharing changes take full effect. Source: HHS Office of Inspector General
Artificial Intelligence in Health Care
- Government health care agencies have no method for deciding whether AI should be used for a given decision at all, only for mitigating the risks once they deploy it. Between FY 2024 and FY 2025, FDA reported a 148 percent increase in AI use, CDC 87 percent, CMS 78 percent, and NIH 51 percent, and GAO found that generative AI use cases across 11 federal agencies rose nine-fold from 2023 to 2024. Federal impact assessments for “high-impact” uses require agencies to explain a system’s purpose, evaluate data quality and model fitness, assess effects on privacy and civil rights, analyze costs, and obtain independent review, all of which presume the system will be deployed. Rule-based eligibility systems have already produced litigation, including a class action against TennCare alleging Medicaid Act, ADA, and due process violations tied to its computerized eligibility determination system, and a National Health Law Program complaint to the FTC over Deloitte Consulting software used in Texas and 20 other states. A proposed Five Factor Framework would have an agency identify the interests at stake, examine the normative structure of the decision under the APA’s reasoned decision-making requirement, assess the technology’s capabilities and error modes, evaluate how human judgment is integrated or displaced against nondelegation and due process principles, and identify the legal constraints, followed by public input when the agency concludes the benefits outweigh the risks. Source: Petrie-Flom Center
- Hospitals are adding AI scheduling systems that build staffing and appointment schedules from patient, shift, and facility data. The software analyzes appointments and no-shows, how long workers have been on shift, how staff expertise matches patient needs, and which beds and surgical units are open. Boston Children’s Hospital announced a partnership with OpenAI in May under which the technology reads medical records to assess whether a patient needs imaging, identifies the next opening, and matches surgical cases to operating rooms. TigerConnect sells a scheduling service inside a back-office platform that answers calls and connects to clinician messaging, with visibility into vacation requests and holiday coverage. Deloitte Consulting principal Bill Fera said agentic systems could take a scribe’s note, determine that a patient needs a CT scan, schedule the visit, and pursue prior authorization, and Boston Children’s chief innovation officer John Brownstein said advisory groups monitor the tools and humans validate their output. Source: Healthcare Brew
Texas Regulatory
- Texas HHSC proposed establishing the Hospital Payment Advisory Committee as a standalone advisory committee with 15 members, keeping the Rural Hospital Advisory Committee as its subcommittee. Proposed amendment to 1 TAC §353.1155 adding diversion slots and clinical criteria to the Medically Dependent Children Program, which would let eligible medically fragile children enroll before reaching the top of the interest list and without admission to a nursing facility. HHSC adopted amendments across 1 TAC Chapter 373 conforming the Medicaid Estate Recovery Program to federal law and implementing House Bill 4611, and consolidated the Children’s Autism Program rules into 26 TAC Chapter 358, expanding the definition of qualified professional to include nurse practitioners and physician assistants. The State Board of Dental Examiners withdrew proposed amendments to 22 TAC §101.8 on dental licensure and 22 TAC §116.3 on dental laboratories, and adopted changes to dental and dental hygiene faculty licensure rules. The Texas Optometry Board repealed or amended rules on license conversion, license designation, complaint procedures, disciplinary proceedings, alternative dispute resolution, and appointment of its emergency committee. Source: Texas Health Law
Community Health Centers
- Health centers awarded a New Access Point grant have 120 days under HRSA rules to bring the new service site online. A webinar on September 15 at 1:00 p.m. CST covers reading the Notice of Award for its terms, funding parameters, and reporting obligations, and identifying which items require immediate attention. It addresses the benefits tied to the new site, including enhanced reimbursement, 340B eligibility, and FTCA coverage. It also covers the operational, scope, and compliance steps required inside the 120-day window. The session closes on the differences between look-alike and grantee status, managing the grant and documenting draws, and first-year mistakes to avoid. Source: VMG Health