The Office of Management and Budget (“OMB”) has released its 2026 Unified Agenda, which identifies regulatory actions that federal agencies expect to propose or finalize during the remainder of the year.  Below, we highlight several notable health privacy, interoperability, and data exchange rules that the Department of Health and Human Services (“HHS”) has listed for proposed or final action in 2026.  The descriptions and target dates below reflect only the agency’s stated intentions and are subject to change.

Final Rules

HIPAA Privacy Rule: Changes to Support Coordinated Care and Individual Engagement and Reduce Regulatory Burdens

  • The HHS Office for Civil Rights (“OCR”) intends to issue a final rule that would modify the Health Insurance Portability and Accountability Act (“HIPAA”) Privacy Rule to, among other changes, strengthen individuals’ right to access their protected health information (“PHI”), improve information sharing for care coordination and case management, facilitate greater family and caregiver involvement in emergency situations, enable greater disclosures in emergency or threatening circumstances, and reduce administrative burdens on HIPAA covered health care providers and health plans.  The proposed rule was published on January 21, 2021, and we summarized the proposal here.
  • Expected agency action: August 2026.

Health Data, Technology, and Interoperability: ASTP/ONC Deregulatory Actions to Unleash Prosperity (HTI-5)

  • HHS, through the Office of the National Coordinator for Health Information Technology (“ONC”), intends to issue a final rule focused on deregulatory changes to the ONC health information technology standards, implementation specifications, and certification criteria, as well as updates to information blocking requirements.  ONC previously issued a notice of proposed rulemaking on December 29, 2025, which we summarized here.
  • Expected agency action: August 2026.

Proposed Rules

HIPAA Privacy Rule to Promote Individuals’ Timely Access to their Protected Health Information

  • HHS intends to issue a notice of proposed rulemaking to solicit comments on proposals to modify the HIPAA Privacy Rule’s requirements regarding the time period within which covered entities must respond to an individual’s request for access to their PHI.  As part of the January 21, 2021, proposed rule to update the HIPAA Privacy Rule (mentioned above), OCR had proposed shortening covered entities’ response time to no later than 15 calendar days (from the current 30 days).
  • Expected agency action: November 2026.

Administrative Simplification: Modifications to the Health Insurance Portability and Accountability Act of 1996 (HIPAA) Electronic Transaction Standards

  • The Centers for Medicare & Medicaid Services (“CMS”) intends to issue a notice of proposed rulemaking that would propose updating the standards for the electronic exchange of health information under HIPAA’s Administrative Simplification provisions.  The rule would propose to replace the X12 Technical Reports Type 3, Version 5010 with an updated version for health care claims or equivalent encounter information transactions, as well as for electronic remittance advice transactions.
  • Expected agency action: December 2026.

Health Data, Technology, and Interoperability: Application Programming Interfaces and Information Blocking (HTI-6)

  • ONC intends to issue a notice of proposed rulemaking that would include proposals for standards adoption, certification of health IT to support expanded uses of application programming interfaces (“APIs”), and enhancements to the conditions of certification.  The notice of proposed rulemaking would also update the information blocking regulations governing information sharing.
  • Expected agency action: November 2026.
Photo of Libbie Canter Libbie Canter

Libbie Canter represents a wide variety of multinational companies on managing privacy, cyber security, and artificial intelligence risks, including helping clients with their most complex privacy challenges and the development of governance frameworks and processes to comply with U.S. and global privacy laws.

Libbie Canter represents a wide variety of multinational companies on managing privacy, cyber security, and artificial intelligence risks, including helping clients with their most complex privacy challenges and the development of governance frameworks and processes to comply with U.S. and global privacy laws. She routinely supports clients on their efforts to launch new products and services involving emerging technologies, and she has assisted dozens of clients with their efforts to prepare for and comply with federal and state laws, including the California Consumer Privacy Act, the Colorado AI Act, and other state laws. As part of her practice, she also regularly represents clients in strategic transactions involving personal data, cybersecurity, and artificial intelligence risk and represents clients in enforcement and litigation postures.

Libbie represents clients across industries, but she also has deep expertise in advising clients in highly-regulated sectors, including financial services and digital health companies. She counsels these companies — and their technology and advertising partners — on how to address legacy regulatory issues and the cutting edge issues that have emerged with industry innovations and data collaborations.

Chambers USA 2025 ranks Libbie in Band 3 Nationwide for both Privacy & Data Security: Privacy and Privacy & Data Security: Healthcare. Chambers USA notes, Libbie is “incredibly sharp and really thorough. She can do the nitty-gritty, in-the-weeds legal work incredibly well but she also can think of a bigger-picture business context and help to think through practical solutions.”

Photo of Anna D. Kraus Anna D. Kraus

Anna Durand Kraus advises on issues relating to the complex array of laws governing the health care industry. Her background as Deputy General Counsel to the U.S. Department of Health and Human Services (“HHS”) gives her broad experience with, and valuable insight into…

Anna Durand Kraus advises on issues relating to the complex array of laws governing the health care industry. Her background as Deputy General Counsel to the U.S. Department of Health and Human Services (“HHS”) gives her broad experience with, and valuable insight into, the programs and issues within the purview of HHS, including Medicare, Medicaid, fraud and abuse, and HIPAA privacy and security. Anna is co-chair of the firm’s Health Care Industry practice group.

Anna regularly advises clients on Medicare reimbursement matters, particularly those arising under Part B and the Part D prescription drug benefit. She also has extensive experience with the Medicaid Drug Rebate program. She assists numerous pharmaceutical and device manufacturers, health care providers, pharmacy benefit managers, and other health care industry stakeholders to navigate the challenges and opportunities presented by the Affordable Care Act.

Anna is a trusted adviser on health information privacy, security and breach notification issues, including those arising under the Health Insurance Portability and Accountability Act (“HIPAA”) and the Health Information Technology for Economic and Clinical Health (“HITECH”) Act. Her background in this area dates back to the issuance of the original HIPAA privacy regulations.

Anna’s clients depend on her to guide them through compliance with the Anti-Kickback statute, the Stark regulations, and other laws preventing fraud and abuse in the health care industry. Her deep knowledge of these laws has made her an important component of the firm’s representation of pharmaceutical companies and health care organizations under federal investigation or facing allegations under the False Claims Act. In addition, clients contemplating acquisitions in the health care sector rely on her to guide due diligence efforts.

Photo of Elizabeth Brim Elizabeth Brim

Elizabeth Brim is an associate in the firm’s Washington, DC office, where she is a member of the Data Privacy and Cybersecurity and Health Care Practice Groups and advises clients on a broad range of regulatory and compliance issues related to privacy and…

Elizabeth Brim is an associate in the firm’s Washington, DC office, where she is a member of the Data Privacy and Cybersecurity and Health Care Practice Groups and advises clients on a broad range of regulatory and compliance issues related to privacy and health care.

Elizabeth’s practice includes counseling clients on compliance with the complex web of health information privacy laws and regulations, such as HIPAA, the FTC’s Health Breach Notification Rule, and state medical and consumer health privacy laws as well as state consumer privacy and genetic privacy laws. She also advises clients on health care compliance issues, such as fraud and abuse, market access, and pricing and reimbursement activities.

Elizabeth routinely advises on regulatory compliance as part of transactions, clinical trial programs, collaborations and other activities that involve genetic data, and the development and operation of digital health products. As part of her practice, Elizabeth routinely counsels clients on drafting and negotiating privacy and health care terms with vendors and third parties and developing privacy notices and consent forms. In addition, Elizabeth maintains an active pro bono practice.

Elizabeth is an author of the American Health Law Association treatise, Pricing, Market Access, and Reimbursement Principles: Drugs, Biologicals and Medical Devices and the U.S. chapter of the Global Legal Insights treatise, Pricing & Reimbursement Laws and Regulations.

Photo of Kyle Falkner Kyle Falkner

Kyle Falkner is an associate in the firm’s Washington, DC office. He is a member of the Data Privacy and Cybersecurity Practice Group and the Health Care Practice Group.

Kyle advises clients on a wide range of data privacy, technology, and health care…

Kyle Falkner is an associate in the firm’s Washington, DC office. He is a member of the Data Privacy and Cybersecurity Practice Group and the Health Care Practice Group.

Kyle advises clients on a wide range of data privacy, technology, and health care issues. He assists clients in complying with U.S. state and federal privacy laws as well as federal health care laws and regulations.

Kyle also maintains an active pro bono practice focused on supporting international human rights initiatives and assisting small businesses and non-profits with data privacy compliance.