Clingantry

The Ongoing Report of ClingantryThe Report

healthcare ai & robotics — regulatory & breach intelligence, sourced only from primary government record


Tagged “nprm” · 2 entries

Right now you can demand an 'AI model card' from your EHR vendor — but that right may be going away

Two things every hospital should know about the AI built into their EHR. First: under a federal rule (HTI-1) that became fully enforceable this past February, your certified EHR vendor must disclose how its predictive AI tools work — what data trained them, who they're meant for, known risks, and how they were validated. That's 31 required disclosure items, often called an "AI model card." You can ask your vendor for this today, and they're required to have it. Second: the same federal office has proposed repealing exactly that requirement (the HTI-5 proposal, December 2025), arguing there's no evidence the disclosures improved care. Public comments closed February 27, 2026; no final decision has been published yet. Practical advice: if these model cards are useful to your AI purchasing decisions, request them from your vendors now, while the requirement is still in force.

No, HIPAA does not yet require encryption everywhere — that's still just a proposal

You may have heard that HIPAA now requires encrypting all patient data. It doesn't — not yet. Federal regulators proposed making encryption mandatory (it's currently just "recommended"), but that proposal has not been finalized into law as of this writing. There's no deadline to comply with yet. Once it is finalized, organizations would get 60 days before it takes effect and 240 days after that to actually comply — so there will be advance warning. Worth watching, not worth panicking about yet.

← Back to The Report