by Wade Emmert

Wade’s Health Law Highlights for September 29, 2026

Fraud & Abuse Enforcement

HIPAA & Health Privacy

  • HHS appears poised to finalize its long-pending HIPAA Privacy Rule revisions. The proposed rule, released in the final days of the first Trump administration, would expand information sharing for care coordination and with caregivers and family members, and would revise access-fee and fee-transparency requirements. Covered providers may need to provide access through a secure, standards-based API when requested electronic PHI is readily available through that API, and to permit patients to take notes, photographs, and videos when inspecting their records in person. The rule would eliminate the Notice of Privacy Practices (NPP) acknowledgment requirement for providers with direct treatment relationships and require NPPs to add a right to discuss the notice with a designated contact person. The rule has not yet been published in final form. Source: Hogan Lovells Cadwalader
  • Healthcare privacy obligations are expanding through state consumer health data laws and AI use while HHS’s proposed HIPAA Privacy Rule changes remain pending. Washington’s My Health My Data Act requires opt-in consent, grants deletion rights, and allows private lawsuits, and the first class action under it was filed against Amazon in February 2025. Nevada’s SB 370 and Connecticut’s SB 3 amendments are in effect, and New York’s Health Information Privacy Act was vetoed in 2025 and reintroduced in 2026. The Office for Civil Rights has not issued an AI-specific HIPAA rule but has signaled that HIPAA applies to AI tools, with attention to data leakage and missing business associate agreements (BAAs) with AI vendors. Standard rulemaking practice would give covered entities approximately 240 days to comply once the Privacy Rule changes are final. Source: RSM US
  • Aspen Dental Management agreed to pay $18.7 million to settle a class action alleging its website tracking pixels shared patient data with Meta and Google without consent. The case, Donnelly v. Aspen Dental Management, covered more than 2 million people who booked appointments on the website between February 2022 and January 2025, and the settlement administrator began issuing payments in February 2026. Pixels on appointment pages, contact forms, and patient portals can capture identifiable health information. Under HHS Office for Civil Rights guidance, transmitting that information to a tracking vendor requires a business associate agreement or a valid patient authorization. Neither Meta nor Google will sign a business associate agreement for its standard pixel and analytics products. Source: DrBicuspid

Data Breaches & Cybersecurity

Physician Arrangements & Restrictive Covenants

FDA & Biologics

  • FDA warned Irvine, California-based NexCell Scientific that its umbilical cord blood-derived cell product is an unapproved new drug and an unlicensed biological product. The September 11, 2026 warning letter, which followed inspections in December 2025 and February 2026, found the product does not qualify for regulation solely as a section 361 HCT/P because it is not intended for homologous use and depends on the metabolic activity of living cells. FDA cited website statements promoting the product for inflammation, neurological conditions, liver cirrhosis, and autoimmune disease as evidence of its intended use. The letter also cited CGMP violations, including an unvalidated aseptic process, no root-cause investigation of lots that failed sterility testing between August 2023 and June 2025, and a single employee handling both manufacturing and quality control. FDA gave the company 15 working days to respond and stated that failure to correct the violations may result in seizure or injunction. Source: FDA

Artificial Intelligence

  • AI inventions in the life sciences can be patented when claims tie the AI to specific hardware, data inputs, and outputs rather than reciting an abstract idea. The USPTO applies the Alice-Mayo framework under 35 U.S.C. § 101, and AI claims typically face rejection as abstract ideas directed to mathematical concepts, methods of organizing human activity, or mental processes. The USPTO’s 2024 guidance states that AI limitations that cannot practically be performed in the human mind do not fall within the mental-processes grouping, and that claims reflecting a specific technological solution to a technological problem may be eligible. In Ex Parte Desjardins (2025), the USPTO Appeal Review Panel vacated a § 101 rejection of claims for training machine learning models, finding them directed to an improvement in machine learning. U.S. Patent No. 12,268,530, covering the Oura ring, anchors two machine learning classifiers to wearable heart rate sensors and displays an illness-risk metric. Source: Healthcare Law Insights
  • Health systems building AI agents in-house for revenue cycle work face underestimated costs in drift control, model spend, and audit defense. An agent can leave its intended workflow without detection and edit the wrong patient record or submit to the wrong claim, which requires deviation detection and automatic safe-stop controls. Routing every step through a frontier model costs about 10 times as much as using smaller, task-specific models, according to Harpaul Sambhi, CEO of AI agent vendor Magical. In announcing its $23 million settlement with UCHealth over an automated emergency-room coding rule, the Department of Justice said it will hold accountable companies whose automatic coding practices lead to improper billing. Defending an audit requires scoped credentials, permissions enforced at the tool-call level, and a complete, traceable record of every agent action. Source: Becker’s Hospital Review
Wade Emmert Avatar

Written by

More Issues