Clingantry

The Ongoing Report of ClingantryThe Report

healthcare ai & robotics — regulatory & breach intelligence, sourced only from primary government record


Tagged “federal” · 6 entries

Right now you can demand an 'AI model card' from your EHR vendor — but that right may be going away

Two things every hospital should know about the AI built into their EHR. First: under a federal rule (HTI-1) that became fully enforceable this past February, your certified EHR vendor must disclose how its predictive AI tools work — what data trained them, who they're meant for, known risks, and how they were validated. That's 31 required disclosure items, often called an "AI model card." You can ask your vendor for this today, and they're required to have it. Second: the same federal office has proposed repealing exactly that requirement (the HTI-5 proposal, December 2025), arguing there's no evidence the disclosures improved care. Public comments closed February 27, 2026; no final decision has been published yet. Practical advice: if these model cards are useful to your AI purchasing decisions, request them from your vendors now, while the requirement is still in force.

The White House wants to override state AI laws — the state rules you follow may be challenged

A December 2025 executive order (EO 14365) directs the federal government to push back on state AI laws it considers burdensome — including a Justice Department task force to challenge them in court, and reviews by Commerce and the FTC identifying which state laws conflict with federal policy. What this means for you: the state AI rules covered in this feed (Texas, Colorado, Indiana, Alabama, and others) are valid law today and you should keep complying — but some may end up challenged in court over the next year or two. Don't un-build your compliance program based on headlines; do expect uncertainty about which state rules survive.

If you buy AI-powered medical devices: the FDA's big rulebook for them is still in draft

The FDA has authorized over a thousand AI-enabled medical devices, but its first comprehensive rulebook for how these devices should be designed, validated, and monitored over their whole life — published as a draft in January 2025 — has still not been finalized. Why a hospital should care: once final, it will shape what documentation and ongoing performance monitoring you can demand from device vendors, especially for AI tools whose behavior changes with updates. Reasonable ask of vendors today: whether they're already building to the draft guidance rather than waiting.

A federal cloud-security update is already in effect — check your vendor contracts

The federal government's rulebook for approving cloud software (FedRAMP) got a major overhaul, and it's already active as of July 4, 2026 — not something coming later this year. The old "Low/Moderate/High" security tiers are gone, replaced by new tiers called Classes A through D. If any of your software vendors handle government-adjacent data or claim FedRAMP approval, it's worth asking them directly whether they've moved to the new system, since some requirements become mandatory before January 1, 2027.

Primary source: fedramp.gov/2026

No, HIPAA does not yet require encryption everywhere — that's still just a proposal

You may have heard that HIPAA now requires encrypting all patient data. It doesn't — not yet. Federal regulators proposed making encryption mandatory (it's currently just "recommended"), but that proposal has not been finalized into law as of this writing. There's no deadline to comply with yet. Once it is finalized, organizations would get 60 days before it takes effect and 240 days after that to actually comply — so there will be advance warning. Worth watching, not worth panicking about yet.

New federal AI-security order: free cyber-defense tools may be coming to hospitals

A second AI executive order (EO 14409, signed June 2, 2026 — separate from the December order about overriding state laws) focuses on AI and cybersecurity. The part that matters for hospitals: the federal cyber agency CISA was given 30 days to expand AI-powered defensive tools and make them easier to access for critical infrastructure operators — which includes healthcare. Treasury is also standing up a clearinghouse for coordinating vulnerability detection and fixes. Nothing here requires you to do anything; it's a potential resource. Worth having your IT/security lead watch CISA's announcements over the coming weeks for new tools or programs your organization can enroll in. The order does not add licensing requirements for AI, and it says nothing about healthcare regulation or state-law preemption.

← Back to The Report