KENTUCKY REGIONAL EXTENSION CENTER

QPP Time Sensitive Announcement! QPP Portal Data Slated for Removal

QPP Time Sensitive Announcement! QPP Portal Data Slated for Removal

Photo of a clinician and patient looking at each other with text in foreground: Quality Payment Program and link to website listed qpp.cms.govCMS recently announced that Performance Year 2022 resources and performance data will be archived with the release of 2025 performance feedback, slated to occur in late September 2026.

In order to ensure you have all relevant audit documentation, our Kentucky REC advisory team recommends that you download all 2022 data for your organization from the Quality Payment Program Portal as soon as possible.

This includes (but is not limited to):
• Detailed performance feedback and submission information for PY 2022
• Connected Clinician Reports
• Eligibility information, including Alternative Payment Model (APM) Participant Lists for PY 2022
• Webpage resources

Contact your Kentucky REC expert advisors for all your QPP questions. Not a client? We’re here to help! Call us at (859) 323-3090 and set up an appointment to speak with a team member today about what we can do for you!

Kentucky REC Annual Conference Oct 29: The New KHIE Portal

Hybrid Event with Special Guest Speakers – In Person and Online

Oct. 29 2026, Lexington Kentucky, The Campbell House

Trudi Matthews

The New KHIE Portal: Features, Functionality & What’s Ahead

Speaker: Rachael Roehrig, Deputy executive Director – division of the kentucky health information exchange (KHIE) & the division of telehealth services

Join Rachael Roehrig for an exciting look into the future of healthcare data in Kentucky. Rachael will showcase the powerful new features and tools now available to providers. Discover how KHIE’s new partnership with CRISP Shared Services (CSS) is upgrading the state’s digital medical network to make patient care more connected and efficient.

About Rachael Roehrig

Rachael Roehrig is Executive Director of the Kentucky Health Information Exchange (KHIE) and Deputy Executive Director within the Kentucky Office of Inspector General, where she leads statewide efforts to advance interoperability and strengthen health data infrastructure. With more than a decade of experience in Kentucky state government, she brings deep expertise in healthcare policy, data analytics, and program operations.

Rachael is known for driving data-informed decision-making and fostering collaboration across government agencies, providers, and technology partners to improve healthcare delivery. As a speaker, she offers practical insights on connecting systems, leveraging data, and enhancing care through statewide health information exchange.

Questions? Contact us at Kentucky REC or call us at 859-323-3090.

Updates to the HIPAA Security Rule Delayed

The anticipated updates to the HIPAA Security Rule are delayed until July 2027

This decision is according to the Office of Information and Regulatory Affairs (reginfo.gov).

The proposed rule, introduced on January 6, 2025 through the Notice of Proposed Rulemaking (NPRM), HIPAA Security Rule To Strengthen the Cybersecurity of Electronic Protected Health Information, was originally anticipated for final action in May 2026. If finalized, the proposal would represent the first major update to the HIPAA Security Rule since 2013 and would establish more prescriptive cybersecurity requirements for regulated entities.

The delay provides healthcare organizations additional time to prepare for potential new compliance obligations and strengthen cybersecurity programs.

Proposed Changes Outlined in the NPRM:

• Comprehensive and accurate technology asset inventory and network map showing where electronic protected health information (ePHI) is created, stored, processed, and transmitted
• New and expanded requirements for implementing encryption
• Multifactor authentication
• Network segmentation
• Anti-malware protection
• Annual penetration tests
• Vulnerability scans every 6 months
• Annual audits of Security Rule compliance
• Annual risk analyses
• Additional data backup and recovery controls and testing requirements
• Revised business associate agreements and annual written verification that business associates deploy certain technical safeguards
• Extensive documentation requirements
• Treat all implementation specifications as mandatory, eliminating the distinction between “required” and “addressable” implementation specifications

While the delay may offer some breathing room, it should not be viewed as a reason to pause security efforts.

Healthcare organizations should continue conducting annual Security Risk Assessments (SRAs), addressing identified vulnerabilities, strengthening technical safeguards, and maintaining compliance with the current HIPAA Security Rule requirements. Cyber threats continue to evolve, and proactive risk management remains essential for protecting (ePHI) and supporting patient care.

Have Questions?

Our trusted advisors at the Kentucky REC assist healthcare organizations with strengthening HIPAA Security compliance and cybersecurity readiness by offering specialized services to help organizations identify vulnerabilities, address compliance gaps, and prepare for future regulatory requirements.

Contact YOUR experts at Kentucky REC if you have any questions or need assistance with HIPAA security risk assessments, internal vulnerability network scanning, and project management support. We’re here to help: 859-323-3090.

Kentucky REC Annual Conference Oct 29: What Hospitals Need to Know for Medicare PI

Hybrid Event with Special Guest Speakers – In Person and Online

Oct. 29 2026, Lexington Kentucky, The Campbell House

Trudi Matthews

Connecting Care Through Interoperability: What Hospitals Need to Know for Medicare PI

Speaker: Kristina Stolitca,  Kentucky REC

Kentucky REC Hospital team lead Kristina Stolitca will provide an overview of the Medicare Promoting Interoperability (PI) Program for Eligible Hospitals and Critical Access Hospitals and explore how interoperability requirements continue to shape care delivery across the healthcare community. This session will review 2026 program requirements, including reporting periods, objectives, and measures, while highlighting key updates from the FY 2027 Inpatient Prospective Payment System (IPPS) Final Rule. Attendees will gain practical insight into evolving compliance expectations and the growing role of interoperability, public health reporting, and data exchange in supporting coordinated care and healthcare connectivity.

About Kristina Stolitca

Kristina Stolitca is a Health Information Technology Advisor at the Kentucky Regional Extension Center (KY REC), where she has served for 15 years. In this role, she supports hospitals across Kentucky participating in the Medicare Promoting Interoperability (PI) Program, providing expert guidance on regulatory compliance, EHR reporting, and program attestation. Kristina partners with hospital leaders and staff to assess performance, identify compliance gaps, and promote successful program participation. She develops tools and resources to help organizations navigate evolving CMS requirements, translating complex federal mandates into clear, actionable guidance. Her long-standing work at KY REC reflects a deep commitment to supporting Kentucky hospitals and advancing health information technology across the Commonwealth.

Questions? Contact us at Kentucky REC or call us at 859-323-3090.

Webinar August 27 – CMS Proposes Significant Reforms to The Quality Payment Program


Don’t Miss Our Aug 27 Webinar:

2027 CMS NOTICE OF PROPOSED RULE-MAKING: QPP and BEYOND

The Centers for Medicaid and Medicare Services (CMS) issued the notice for proposed rule-making for the 2027 Physician Fee Schedule and Quality Payment Program (QPP) on Tuesday, August 14th, 2026.

CMS is proposing transformational changes to several programs within this rule, including:

  • the sunset date for the MIPS track of the QPP
  • a further increase in available MIPS Value Pathways (MVPs)
  • significant APM incentive payment reforms
  • expansion of the Medicare Shared Savings Program
  • further clarification of the new Ambulatory Specialty Model
  • the introduction of core measures and other substantial changes to QPP performance categories

Stay in the know with the Kentucky REC – Register today and be prepared for 2027 and beyond!

2027 CMS NOTICE OF PROPOSED RULE-MAKING: QPP and BEYOND
THURSDAY AUG 27 12:00 – 1:00 PM ET

CMS encourages providers, healthcare organizations, vendors, and professional organizations to submit comments on the proposed rule.

How to comment:
The proposed rule includes directions for submitting comments within the 60-day comment period. CMS must receive comments by Monday, September 14, 2026.
When commenting, refer to file code: CMS-1848-P.
CMS does NOT accept FAX transmissions.

Use 1 of the 3 following ways to officially submit your comments:
• Electronically: www.regulations.gov
• Regular mail: Centers for Medicare & Medicaid Services, Department of Health and Human Services, Attention: CMS-1848-P, P.O. Box 8016, Baltimore, MD 21244-8016.
• Express or overnight mail: Centers for Medicare & Medicaid Services, Department of Health and Human Services, Attention: CMS-1848-P, Mail Stop C4-26-05, 7500 Security Boulevard, Baltimore, MD 21244-1850.

Contact YOUR experts at Kentucky REC with all your CMS QPP, MIPS/MVP, and APM Track questions. We’re here to help: 859-323-3090.

Kentucky REC Annual Conference Oct 29: Maximizing the HIPAA Security Rule

Hybrid Event with Special Guest Speakers – In Person and Online

Oct. 29 2026, Lexington Kentucky, The Campbell House

Trudi Matthews

Maximizing the HIPAA Security Rule for Practice Success

Speaker: Amy Daley,  Kentucky REC

Significant revisions to the HIPAA Security Rule are expected to be finalized and announced next year. Applying the new revisions to everyday operations in your practice is the key to maximizing and strengthening your overall compliance program. Our advisors will provide an overview of everything that is changing about the rule as well as timelines for expected compliance.

 

About Amy Daley

Amy Daley, CHPS, has been a Health IT Advisor for Kentucky Regional Extension Center since 2014 and is the HIPAA Team Lead. She specializes in HIPAA Security guidance for healthcare organizations across the state of Kentucky. Amy obtained her B.S. in Computer Information Systems from the University of Louisville. Amy has been a guest speaker at various conferences in Kentucky presenting on topics related to HIPAA Security and Promoting Interoperability. Her background includes expertise in the areas of implementation, training and management of EHR systems.

Questions? Contact us at Kentucky REC or call us at 859-323-3090.