Skip to main content

HHS’s 2026 Regulatory Agenda: Privacy Overhauls, Interoperability Expansion, and Rising TEFCA Scrutiny

The Office of Management and Budget’s 2026 Unified Agenda signals significant regulatory activity ahead for the Department of Health and Human Services (HHS), spanning proposed changes to HIPAA Privacy Rule provisions, updates to the Department’s decades-old Privacy Act regulations, and interoperability rules from HHS’s Office of the National Coordinator for Health Information Technology (ONC). Below, we summarize the notable rules the agencies have listed for action in 2026, organized by rulemaking stage. The descriptions and timelines reflect the agencies’ current plans and may evolve.  

Final Rules 

HIPAA Privacy Rule: Changes to Support Coordinated Care and Individual Engagement 
Expected August 2026 

The Office for Civil Rights (OCR) intends to finalize its long-pending January 2021 Notice of Proposed Rulemaking to modify the HIPAA Privacy Rule. As proposed, the rule would: strengthen individuals’ access rights by shortening response times and limiting fees; ease information sharing by adding an exception to the minimum necessary standard for care coordination and case management; expand family and caregiver involvement by replacing the “professional judgment” standard with a “good faith belief” standard for disclosures when individuals are incapacitated; broaden permitted disclosures by replacing the “serious and imminent threat” standard with “serious and reasonably foreseeable threat”; accommodate telecommunications relay services for workforce members and individuals with hearing or speech disabilities; and extend the existing military-personnel disclosure permission to all uniformed services. OCR estimates roughly $785 million in annualized cost savings from streamlined recordkeeping. For covered entities and their business associates, finalization would likely require updating HIPAA policies, access-request workflows, and Notices of Privacy Practices (entities already revising their notices may prefer to wait to avoid doing so twice) while value-based care organizations, ACOs, and care-management vendors could benefit significantly from the eased care-coordination disclosures. (RIN 0945-AA00

HTI-5: ONC Deregulatory Actions to Unleash Prosperity 
Expected August 2026 

Following a December 29, 2025 proposal, ONC intends to finalize deregulatory changes to health IT certification criteria and information blocking rules under 45 CFR parts 170 and 171, aimed at reducing burden on developers and providers. Health IT developers would be the principal beneficiaries, with ONC estimating $1.53 billion in cost savings (at 7% discount rate) over the long term. Notably, the proposed rule would remove the “decision support interventions” certification criterion’s AI “model card” transparency and risk management requirements; providers and health systems deploying clinical decision support or AI tools would lose that transparency requirement and should consider reinforcing their own AI governance. (RIN 0955-AA09

Proposed Rules 

Privacy Act Regulations 
Expected July 2026 

HHS plans to issue a proposed rule modernizing its Privacy Act regulations at 45 CFR part 5b, largely unchanged since 1975, and removing the FDA’s duplicative Privacy Act rules at 21 CFR part 21. Notably, HHS would eliminate outdated provisions requiring indirect release of medical records through a designated representative rather than directly to the individual. The change primarily affects individuals seeking their own HHS records and the healthcare-adjacent entities that interact with HHS systems of records by permitting records, including medical records, to be released directly to the individual. (RIN 0991-AC05)

HTI-6: Application Programming Interfaces and Information Blocking 
Expected November 2026 

Framed around the Make America Healthy Again initiative and executive orders on price transparency and anti-competitive regulatory barriers, this proposal would adopt updated standards, expand certification for APIs and successor technologies, add certification conditions, and revise information blocking rules. Health IT developers should anticipate expanded API certification requirements and new certification conditions, and providers would face revised information-blocking rules; healthcare-adjacent app developers and data-exchange vendors sit squarely within scope. (RIN 0955-AA10

HIPAA Privacy Rule to Promote Individuals’ Timely Access to Their Protected Health Information 
Expected November 2026 

A newly listed, economically significant proposal would revisit how quickly covered entities must respond to access requests, building on OCR’s 2021 proposal to shorten the response window from 30 to 15 calendar days. Halving the response window to 15 days would compress records-release timelines industry-wide, requiring providers, health plans, and their release-of-information vendors to re-engineer intake, review, and fulfillment processes and to revisit vendor service-level commitments. (RIN 0945-AA28

A Backdrop of Heightened Scrutiny 

These rulemakings arrive alongside a parallel, non-rulemaking trend worth watching: intensifying federal oversight of the Trusted Exchange Framework and Common Agreement (TEFCA), the nationwide network ONC administers through its Recognized Coordinating Entity, the Sequoia Project. According to ONC, TEFCA’s volume has exploded, growing from roughly 10 million exchanged records in January 2025 to more than 1 billion today, while new exchange purposes have emerged, most notably the Social Security Administration’s connection through the eHealth Exchange QHIN, which lets Epic-connected health systems share records to speed disability determinations. In response, ONC awarded a multiyear contract to audit QHIN compliance and has expanded reviews of participants. In addition, in March 2026, the United States District Court for the Central District of California permanently enjoined GuardDog Telehealth from requesting records through the TEFCA or Carequality interoperability frameworks after the company allegedly obtained thousands of patient medical records by falsely asserting treatment purposes. As ONC ramps up audit capacity and compliance monitoring for exchange networks, health systems, payers, health IT developers, and QHIN participants should treat 2026 as a year of two parallel tracks: easing paperwork burdens on one hand with tightening enforcement and oversight on the other.