|
Welcome
Welcome to our seventh issue of 2026 of The Health Record -- our healthcare law insights e-newsletter.
This month's newsletter covers a range of developments at the intersection of healthcare, technology, regulation and industry consolidation.
We begin with a look at growing concerns over how the healthcare industry evaluates AI ambient scribe technology. In data privacy, we examine 23andMe's $18 million multistate settlement over a credential-stuffing breach. We also report on the postponement of the HIPAA Security Rule update to July 2027. Turning to state-level developments, North Carolina has closed a tax loophole that allowed nonprofit hospital systems to exceed sales tax refund caps by filing separate claims through affiliated entities, and Pennsylvania is advancing bipartisan legislation to establish statewide licensure standards for medical imaging and radiation therapy professionals. On the consolidation front, hospital merger activity has surged in the first half of 2026. We also address the controversy surrounding new Medicaid work requirements taking effect in January 2027. Additionally, we highlight two important stories on AI in healthcare: Ohio University research underscoring that physician transparency about AI use is more important to patient trust than the technology's accuracy, and the rising cybersecurity risks posed by mobile health apps that increasingly function as medical devices. Finally, Nick Mooney, Chair of our Technology Practice Group, Co-Chair of our Cybersecurity & Data Protection Practice Group and Co-Chair of our Artificial Intelligence Law Practice Group, addresses cybersecurity threats and best practices for healthcare organizations in our Featured Attorney section.
In terms of firm news, we are very pleased to announce that Eric W. Iskra will begin his one-year term as Chair of the American Bar Association’s Section of Labor and Employment Law on August 1. His election to one of the ABA’s most prominent leadership positions is a testament to his thoughtful leadership abilities, his legal acumen, and his career-long dedication to advancing the practice of labor and employment law. Congratulations! Click here to learn more.
We are also pleased to announce that Joseph A. “Jay” Ford, Member attorney in our Charleston office and a team member in our Health Care Practice Group, was selected as a 2026 American Bar Association “On the Rise - Top 40 Young Lawyers” award recipient. This national honor recognizes young attorneys who exemplify a broad range of high achievement, innovation, vision, leadership, and legal and community service. Click here to learn more.
Clifford F. Kinney, Jr., Member attorney and participant in our high-stakes litigation practice group – The Battle Group – has been elected a Fellow of the American Bar Foundation, one of the legal profession’s highest honors recognizing attorneys whose careers exemplify exceptional professional achievement, leadership, and service. Click here to learn more.
Thank you for reading!
Brienne T. Marco
Member, Chair of the Corporate Department, Co-Chair of the Health Care Practice Group, and Editor of The Health Record
| | |
“As adoption of AI ambient scribe technology rapidly grows, the healthcare industry's standard method for evaluating clinical AI notes may be fundamentally flawed, failing to detect significant errors or omissions in patient notes.”
Why this is important: AI ambient scribe technology is being adopted rapidly across the healthcare sector because it helps reduce clinician documentation workload and burnout. While these tools reduce documentation burden and are popular with clinicians, researchers say the industry needs more rigorous ways to evaluate note integrity rather than focusing primarily on convenience or user satisfaction.
Suki is an AI-powered voice assistant and ambient clinical intelligence platform for healthcare. Suki’s white paper focuses on evaluation rubrics for assessing output quality and argues the industry standards need to be refreshed. While scribe technology provides convenience, the study revealed AI-generated notes scored lower than clinician-written notes on measures such as completeness, organization, and clinical usefulness. Researchers caution that documentation quality—not just time savings—should be a primary evaluation metric. But even from a time perspective, while AI scribes can generate draft notes quickly, clinicians often spend additional time reviewing and correcting them, especially when subtle but critical clinical details are missing or are inaccurate.
Suki CEO Punit Soni argues that note quality depends on how it is measured and that newer-generation systems perform significantly better than those included in some studies. He also emphasized that AI-generated documentation should be assessed in the context of clinical workflow and physician oversight.
Researchers say there is no widely accepted framework for measuring AI scribe performance, making it difficult for health systems to compare vendors objectively. They recommend standardized evaluation methods that assess documentation quality, patient safety, and clinical usefulness—not just productivity gains. --- Jennifer A. Baker
| | |
“The 23andMe data breach occurred as a result of credential stuffing, which is where credentials obtained in a data breach at one or more companies are used to try to gain access to accounts on an unrelated platform.”
Why this is important: The 23andMe data breach was attributable to a credential-stuffing attack. Credential-stuffing is a technique used by cyber criminals that involves leveraging credentials compromised in one or more prior data breaches at other companies to attempt to gain unauthorized access to accounts on an unrelated platform. The multistate theory that a company can be held liable not for the credential-stuffing attack itself but for the absence of baseline safeguards like breached-password screening, multifactor authentication, rate limiting, and adequate logging and monitoring, tracks the "reasonable security" standard that increasingly drives enforcement and civil exposure everywhere, and it maps onto the kinds of duties a West Virginia plaintiff might invoke under the state's consumer-protection and data-breach-notification framework and common-law negligence.
For counsel advising West Virginia businesses that hold sensitive personal data, the takeaways are practical: the "our customers reused their passwords" defense failed, delayed detection over a five-month window was treated as its own failing, and injunctive security mandates followed the data through bankruptcy to the acquirer, meaning a purchaser of a distressed company's data assets inherits the compliance obligations, not just the records. Users do bear some risk, but the company still owns the duty to deploy reasonable safeguards. Companies should be aware that "reasonable security" is now the operative standard across most consumer-protection and breach regimes, and that a victim-blaming posture invites both regulators and plaintiffs. The investigation also faulted 23andMe for unpatched known vulnerabilities and inadequate review and testing of platform features. Businesses should keep a real patch-management cadence, track known vulnerabilities to closure, and build security review into product design rather than bolting it on. They should also maintain a documented, current written information security program, incident-response plan, and data-retention/minimization policy; retain the sensitive data they actually need and dispose of the rest. When enforcement comes, contemporaneous documentation of reasonable measures is often the difference between a manageable matter and a headline settlement. --- Sara E. Chapman
| | |
“The Department of Health and Human Services (HHS) had proposed a May 2026 release date for a final rule implementing the proposed changes to the HIPAA Security Rule; however, the U.S. Office of Management and Budget (OMB) website has been updated, showing the final rule has been pushed back a year, with the final action due in July 2027.”
Why this is important: HHS has delayed the anticipated final update to the HIPAA Security Rule, with the OMB now targeting July 2027 instead of the previously expected May 2026 release. The delay gives healthcare organizations additional time to prepare for sweeping cybersecurity requirements intended to address a threat landscape that has evolved significantly since the Security Rule was last substantially updated in 2013.
The proposed revisions respond to the sharp rise in ransomware attacks and data breaches affecting the healthcare sector, including the 2024 Change Healthcare cyberattack, which disrupted billing and care delivery nationwide and exposed the electronic protected health information of an estimated 192.7 million individuals. The proposal would replace the Security Rule’s flexible, “addressable” safeguards with mandatory requirements such as multifactor authentication (MFA), encryption, network segmentation, anti-malware protections, annual penetration testing, semiannual vulnerability scans, annual compliance audits, enhanced risk assessments, stronger backup and recovery controls, tighter oversight of business associates, and expanded documentation obligations.
While healthcare organizations generally support strengthening cybersecurity, the proposal has drawn significant criticism for its cost, complexity and implementation timeline. Nearly 5,000 comments were submitted in response to the proposed rule, with many providers arguing that the requirements would impose substantial financial and operational burdens, particularly on smaller and rural organizations. HHS has estimated first-year compliance costs of approximately $9 billion across the industry, followed by roughly $6 billion annually over the next four years.
Although the final rule has been delayed, healthcare organizations are encouraged to use the additional time to strengthen their cybersecurity programs rather than wait for the final requirements. Covered entities and business associates should use the additional runway to inventory ePHI flows, close obvious gaps such as MFA on remote access, and begin phased implementation rather than waiting for a final rule. Early implementation of many of the proposed safeguards can improve security, reduce the risk of costly cyber incidents and ease future compliance efforts.
Meanwhile, HHS is prioritizing updates to the HIPAA Privacy Rule, with a final rule expected in August 2026. Those revisions are intended to strengthen patients’ access to protected health information, improve care coordination and information sharing, enhance family and caregiver involvement, and reduce administrative burdens, while broader federal initiatives continue to focus on advancing health information interoperability. --- Shane P. Riley
| | |
“The change would require nonprofit and public hospital systems to file a single sales tax refund claim for all their related entities.”
Why this is important: A recently approved provision in North Carolina's state budget closes a loophole that allowed some nonprofit hospital systems to exceed the state's sales tax refund cap. Going forward, all related facilities within a nonprofit or public hospital system must be treated as a single entity and file one consolidated refund claim. The change follows reports that health systems submitted separate claims through affiliated organizations, allowing the system to recover more than the statutory limit.
North Carolina permits nonprofit entities to claim semiannual refunds of sales and use taxes paid on direct purchases, subject to annual caps of $31.7 million for state taxes and $13.3 million for local taxes. Because those limits previously applied on a per-entity basis, a hospital system organized as a parent with separately incorporated affiliates could obtain multiple refunds operating under one corporate roof. No hospital approached the cap when it was set in 2013, but growth through mergers and acquisitions has since pushed the largest systems against it. The new law applies the cap on a per-system basis by requiring a single consolidated claim.
The new legislation exempts the University of North Carolina Health Care System and its affiliates, which may continue filing separate claims. For all other nonprofit and public hospital systems, the change will reduce available sales tax refunds and require systems to aggregate purchases across affiliated entities. The legislation also signals that additional tax reforms may follow, as lawmakers have continued to consider further reductions to hospital tax benefits. --- Sarah W. King
| |
“It would ensure that radiography, nuclear medicine, diagnostic sonography, MRI, CT, radiation therapy and radiology assistant professionals adhere to strict competency and continuing education requirements.”
Why this is important: Pennsylvania lawmakers have advanced legislation that would establish statewide licensure requirements for medical imaging and radiation therapy professionals, bringing Pennsylvania in line with most other states. The Medical Imaging and Radiation Therapy Health and Safety Act would require professionals operating radiation-producing equipment to meet standardized education, training, competency and continuing education requirements across disciplines including radiography, nuclear medicine, MRI, CT, diagnostic sonography, radiation therapy and radiology assistance.
The bipartisan measure passed the Pennsylvania Senate by a 45-5 vote and now moves to the House of Representatives for consideration. Supporters argue the legislation will strengthen patient safety by ensuring imaging professionals meet consistent qualifications while providing employers with clear, enforceable standards. The bill would not impose additional examinations or educational requirements on already qualified professionals but instead formalize uniform statewide licensing and competency standards for the profession. --- Shane P. Riley
| |
“That’s more than twice as many deals as the eight transactions seen in the second quarter last year.”
Why this is important: The first half of 2026 has seen a sharp rebound in hospital merger activity. This surge signals a structural shift in how health systems are positioning themselves for the future. After 2025 produced the fewest deals in 15 years, a pause driven largely by policy uncertainty early in the current presidential administration, the 40 transactions announced in the first six months of 2026 have nearly matched all of last year, with second-quarter transacted revenue jumping to $7.7 billion from $1.4 billion a year earlier. According to Kaufman Hall's Kris Blohm, this is not distress-driven consolidation but deliberate, disciplined strategy: systems are building scale, expanding ambulatory and physician-network capabilities, and getting ahead of anticipated Medicaid cuts rather than simply reacting to financial pressure. For providers, that momentum reshapes competitive positioning and access to capital; for regulators, patients, and communities, an accelerating wave of consolidation may raise questions about market concentration, pricing, and the fate of smaller or financially struggling hospitals that larger systems are increasingly reluctant to absorb. --- Brienne T. Marco
| |
“Starting Jan. 1 in most of the country, some enrollees — mainly adults without dependents — must prove they’re working or performing other qualifying activities 80 hours a month.”
Why this is important: In most of the country, beginning January 1, 2027, in order to keep their Medicaid coverage, adult recipients will have to prove they work or participate in qualifying activities for at least 80 hours per month. Final regulations provide for a “medically frail” exemption for those too sick or disabled to work, but many healthcare providers feel uneasy about this new administrative responsibility for several reasons. First, they say the term "medically frail" is unclear. Physicians say they aren't trained to determine whether someone is too sick to work and worry there is no consistent standard. Second, it adds even more administrative work to an already sizeable workload and will take more time away from patient care as these individuals will have to requalify every six months. Next, it could harm doctor-patient trust. Medical groups, including the American Medical Association, argue that requiring physicians to decide eligibility for benefits could make patients less open during appointments. In addition, there are fears of legal or regulatory consequences. Some physicians worry their decisions could later be questioned by state or federal authorities. Finally, patients who do not have access to healthcare without the Medicaid coverage may struggle to obtain the necessary opinion and documentation that would render them eligible for Medicaid coverage. Health policy analysts estimate the work requirements could increase the number of uninsured Americans more than any other provision of the One Big Beautiful Bill Act. --- Jennifer A. Baker
| | |
“A 2023 Pew Research study revealed that 57% of respondents believed AI in health care would negatively impact the patient-provider relationship, mainly due to mistrust stemming from AI's lack of social presence, black-box nature, bias and opacity.”
Why this is important: Ohio University professors surveyed roughly 650 people and found that when doctors are more open about how they use AI, patient trust increases both in the provider and the AI itself. More surprisingly, higher AI accuracy didn’t increase trust and sometimes even lowered it, likely due to patient fears that physicians will outsource their clinical judgment. The researchers emphasize that transparency in this context means the doctor and patient converse about AI use, not technical explanations of how the AI utilizes algorithms. They argue that the AI industry is too focused on building models as quickly as possible while placing less attention on processes and governance. --- Nathan T. Ellis, Summer Associate
| |
“A recent report from Zscaler shows that the healthcare industry experienced a 224% increase in mobile attacks last year, and a 2025 Ponemon Institute survey showed that insecure mobile healthcare apps are the top cybersecurity concern in the industry (cited by 55% of respondents).”
Why this is important: As mobile health (mHealth) apps increasingly function as medical devices, cybersecurity is becoming a core patient safety issue rather than just an IT concern. The global mobile healthcare app market is projected to grow from $114.2 billion in 2024 to more than $1 trillion by 2030, driven by telehealth, AI-enabled health tools, remote monitoring, patient portals, and wellness applications. The explosive market growth is driven by (1) expansion of hybrid and remote care models, especially for underserved and rural communities; (2) advances in AI-powered mobile health technologies for chronic disease management and patient engagement; and (3) growing consumer preference for managing appointments, prescriptions, and medical records through mobile apps. But with mHealth app growth comes increasing cybersecurity risks. Over the previous year, there has been a reported 224 percent increase in mobile attacks against the healthcare sector, but the need and the use of these applications is only going to increase over time, especially in rural communities. Healthcare organizations and developers should treat mobile app security as a fundamental patient safety requirement, integrating strong security practices throughout the software lifecycle rather than adding them as an afterthought. The Federal Trade Commission (FTC) also recommends that mHealth applications be designed with security in mind from the outset, with appropriate security measures testing prior to launch. --- Jennifer A. Baker
| | Featured Attorneys Question & Answer | | This is our Featured Attorney Q&A to introduce you to our large healthcare law team. To help you get to know our team a little better, we are highlighting attorneys in each issue by asking them a healthcare-related question. We hope their responses will be insightful for you. | |
Nicholas P. Mooney II
Member; Chair, Technology Practice Group; Co-Chair, Cybersecurity & Data Protection Practice Group; Co-Chair, Artificial Intelligence Law Practice Group
Office 304.340.3860
nmooney@spilmanlaw.com
Q: As Chair of our Technology Practice Group, Co-Chair of our Cybersecurity & Data Protection Practice Group, and Co-Chair of our Artificial Intelligence Law Practice Group, you deal with data privacy and cybersecurity issues on a daily basis. What are some of the issues that are particularly important to healthcare organizations and what are your recommendations for best practices for those organizations?
A: The first thing I counsel every client on, whether it be a healthcare organization or anyone else, is to be deliberate about the data that you hold and the length of time you hold it. There are different data and document retention requirements depending on the type of data that an organization holds, and the organization definitely wants to ensure that it complies with those requirements. However, beyond those requirements, the organization needs to undertake a deliberate analysis of whether there’s a benefit to continuing to hold data. One of the earliest lessons I learned when I first started working in the data privacy space was that holding more data isn’t always a good thing. We had a client who never discarded data. When that client suffered a breach, the remediation and response work were much more complicated (and expensive) because the client literally had maintained nearly two decades of data.
Healthcare organizations also should recognize that they are a target for threat actors. Like financial institutions, government agencies, and critical infrastructure, healthcare organizations are a prime target. I’ve seen some commentators estimate that healthcare data breaches are the most costly of any industry. This means the organization needs to invest the resources into building an updated and resilient data security system. The best-case scenario is security by design, where an organization is able to design its system from the ground up with security as a central focus instead of creating the security system piecemeal as it goes. That isn’t always possible, especially where the organization already has a system in place and cannot afford to start anew. Regardless, the organization should regularly assess its system. Does it have outdated hardware or software? What are its vulnerability points? What are the possible attack vectors? It also should ensure that it has a clear plan for responding to a suspected data incident. What does its Incident Response Plan provide? Who handles the response, and what are their duties? Does it maintain backup data, and how will that be deployed?
Healthcare organizations also must be mindful of the security concerns posed by their employees and vendors. Every industry has a risk that its employees and vendors may fall victim to a phishing or social engineering attack. Healthcare organizations need to guard against this as well. Simulated phishing email campaigns and regular auditing of vendors are good tools to help guard against these. Healthcare organizations also have unique concerns in this area. A provider or vendor might have excessive privileges or access. Organizations need to ensure that the scope of privileges and access is appropriate so that the provider or vendor can perform the required duties but not more. Also, healthcare organizations need to worry about snooping or intentional improper access of patient data. This has come up in our litigation cases before, and there are good software applications that can be put in place to combat improper access.
At bottom, healthcare organizations face the same data privacy issues as most industries and face some that are unique to them. They must navigate those issues, all while being heavily regulated and with the knowledge that they are a favorite target of threat actors.
| | |
This is an attorney advertisement. Your receipt and/or use of this material does not constitute or create an attorney-client relationship between you and Spilman Thomas & Battle, PLLC or any attorney associated with the firm. This e-mail publication is distributed with the understanding that the author, publisher and distributor are not rendering legal or other professional advice on specific facts or matters and, accordingly, assume no liability whatsoever in connection with its use.
Responsible Attorney: Michael J. Basile, 800-967-8251
| | | | |