Aug 31, 2026
CMS recently announced that Performance Year 2022 resources and performance data will be archived with the release of 2025 performance feedback, slated to occur in late September 2026.
In order to ensure you have all relevant audit documentation, our Kentucky REC advisory team recommends that you download all 2022 data for your organization from the Quality Payment Program Portal as soon as possible.
This includes (but is not limited to):
• Detailed performance feedback and submission information for PY 2022
• Connected Clinician Reports
• Eligibility information, including Alternative Payment Model (APM) Participant Lists for PY 2022
• Webpage resources
Contact your Kentucky REC expert advisors for all your QPP questions. Not a client? We’re here to help! Call us at (859) 323-3090 and set up an appointment to speak with a team member today about what we can do for you!
Jul 28, 2026
The anticipated updates to the HIPAA Security Rule are delayed until July 2027
This decision is according to the Office of Information and Regulatory Affairs (reginfo.gov).
The proposed rule, introduced on January 6, 2025 through the Notice of Proposed Rulemaking (NPRM), HIPAA Security Rule To Strengthen the Cybersecurity of Electronic Protected Health Information, was originally anticipated for final action in May 2026. If finalized, the proposal would represent the first major update to the HIPAA Security Rule since 2013 and would establish more prescriptive cybersecurity requirements for regulated entities.
The delay provides healthcare organizations additional time to prepare for potential new compliance obligations and strengthen cybersecurity programs.
Proposed Changes Outlined in the NPRM:
• Comprehensive and accurate technology asset inventory and network map showing where electronic protected health information (ePHI) is created, stored, processed, and transmitted
• New and expanded requirements for implementing encryption
• Multifactor authentication
• Network segmentation
• Anti-malware protection
• Annual penetration tests
• Vulnerability scans every 6 months
• Annual audits of Security Rule compliance
• Annual risk analyses
• Additional data backup and recovery controls and testing requirements
• Revised business associate agreements and annual written verification that business associates deploy certain technical safeguards
• Extensive documentation requirements
• Treat all implementation specifications as mandatory, eliminating the distinction between “required” and “addressable” implementation specifications
While the delay may offer some breathing room, it should not be viewed as a reason to pause security efforts.
Healthcare organizations should continue conducting annual Security Risk Assessments (SRAs), addressing identified vulnerabilities, strengthening technical safeguards, and maintaining compliance with the current HIPAA Security Rule requirements. Cyber threats continue to evolve, and proactive risk management remains essential for protecting (ePHI) and supporting patient care.
Have Questions?
Our trusted advisors at the Kentucky REC assist healthcare organizations with strengthening HIPAA Security compliance and cybersecurity readiness by offering specialized services to help organizations identify vulnerabilities, address compliance gaps, and prepare for future regulatory requirements.
Contact YOUR experts at Kentucky REC if you have any questions or need assistance with HIPAA security risk assessments, internal vulnerability network scanning, and project management support. We’re here to help: 859-323-3090.
Jul 21, 2026

Don’t Miss Our Aug 27 Webinar:
2027 CMS NOTICE OF PROPOSED RULE-MAKING: QPP and BEYOND
The Centers for Medicaid and Medicare Services (CMS) issued the notice for proposed rule-making for the 2027 Physician Fee Schedule and Quality Payment Program (QPP) on Tuesday, August 14th, 2026.
CMS is proposing transformational changes to several programs within this rule, including:
- the sunset date for the MIPS track of the QPP
- a further increase in available MIPS Value Pathways (MVPs)
- significant APM incentive payment reforms
- expansion of the Medicare Shared Savings Program
- further clarification of the new Ambulatory Specialty Model
- the introduction of core measures and other substantial changes to QPP performance categories
Stay in the know with the Kentucky REC – Register today and be prepared for 2027 and beyond!
2027 CMS NOTICE OF PROPOSED RULE-MAKING: QPP and BEYOND
THURSDAY AUG 27 12:00 – 1:00 PM ET
CMS encourages providers, healthcare organizations, vendors, and professional organizations to submit comments on the proposed rule.
How to comment:
The proposed rule includes directions for submitting comments within the 60-day comment period. CMS must receive comments by Monday, September 14, 2026.
When commenting, refer to file code: CMS-1848-P.
CMS does NOT accept FAX transmissions.
Use 1 of the 3 following ways to officially submit your comments:
• Electronically: www.regulations.gov
• Regular mail: Centers for Medicare & Medicaid Services, Department of Health and Human Services, Attention: CMS-1848-P, P.O. Box 8016, Baltimore, MD 21244-8016.
• Express or overnight mail: Centers for Medicare & Medicaid Services, Department of Health and Human Services, Attention: CMS-1848-P, Mail Stop C4-26-05, 7500 Security Boulevard, Baltimore, MD 21244-1850.
Contact YOUR experts at Kentucky REC with all your CMS QPP, MIPS/MVP, and APM Track questions. We’re here to help: 859-323-3090.