Digital Health Blog
Legal & Policy Insight to Empower the Evolution of Health Care
Never Miss an Update
FTC, Utah, and California Sue Hims & Hers Over Billing Practices and Health Data Sharing
On July 29, 2026, the Federal Trade Commission, joined by Utah and California, filed suit against telehealth company Hims & Hers in the Northern District of California. The complaint alleges that Hims shared consumers’ condition-specific health information with third-party advertising platforms, including Meta and Snap, through both customer-list uploads and tracking pixels that automatically transmitted website “Events”—despite representations to users that Hims would not disclose consumers’ health information to third parties. The complaint also alleges that Hims enrolled consumers in recurring prescription subscriptions and charged them shortly after they submitted an online intake form, before they had connected with a provider, and made subscription cancellation unreasonably difficult. The FTC asserts claims under Section 5 of the FTC Act and the Restore Online Shoppers’ Confidence Act, while Utah and California assert state consumer protection and false advertising claims.
The case reflects the FTC and states’ continued use of general consumer protection laws to scrutinize digital health companies’ use of tracking technologies, advertising platforms, subscription practices, and privacy representations, as seen in recent regulatory actions involving BetterHelp and Flo Health. The complaint also reinforces that HIPAA is not the only privacy regime with meaningful enforcement risk. Even companies that fall outside HIPAA’s scope may face exposure under the FTC Act’s deception and unfairness theories, as well as increasingly active state consumer protection and false advertising laws, which may reach conduct that HIPAA does not, and often with broader remedies.
CMS Proposes Significant Changes to RPM and RTM Services
In the CY 2027 Medicare Physician Fee Schedule proposed rule, CMS is proposing several notable changes to Remote Physiologic Monitoring (RPM) and Remote Therapeutic Monitoring (RTM) services. First, CMS would limit RPM and RTM billing to established patients. CMS proposes requiring a separately billable initiating visit before RPM or RTM services begin, meaning the billing practitioner must initiate the services during an in-person or telehealth encounter. Additionally, CMS proposes that the clinical staff time used to furnish RPM and RTM services be provided only by individuals directly employed by the billing practitioner or practice, rather than outsourced third parties. CMS states that the proposal is responsive to multiple OIG reports raising concerns about care fragmentation and insufficient practitioner oversight when monitoring services are outsourced. Comments are due September 14, 2026.
HHS OIG Updates Work Plan to Include HHS AI Audit
The U.S. Department of Health and Human Services (HHS) Office of Inspector General (OIG) announced an audit of HHS governance of artificial intelligence (AI). Given HHS’ reliance on AI tools to support public health surveillance, fraud detection, and administrative automation, OIG believes it is important that HHS fully establish and implement a comprehensive AI governance framework to manage risks. OIG will conduct the audit to determine whether HHS has established AI governance in accordance with Federal and HHS requirements.
House passes KIDS Act, sending online child safety debate to the Senate
On July 7, the House of Representatives passed the KIDS Act (H.R. 7757) in a vote of 267-117, advancing a package of online child safety measures aimed at establishing baseline federal protections for minors while allowing states to enact stronger safeguards. The legislation reflects years of congressional efforts to strengthen protections for children online and follows a bipartisan agreement reached in the House Energy and Commerce Committee.
The package includes provisions requiring AI chatbots to disclose that they are not human, restricting minors’ access to disappearing messages, and requiring age-verification technologies for certain content. The bill also establishes federal standards for children’s online safety while preserving states’ ability to adopt more stringent protections and does not preempt state artificial intelligence laws.
While House passage marks a significant milestone, substantial challenges remain before the legislation can become law. The House and Senate continue to differ on key elements of child online safety policy, including age-verification requirements, First Amendment concerns, and whether online platforms should be subject to a “duty of care” obligation requiring them to design products with children’s safety in mind. While this legislation may not see final passage this Congress, this has been an ongoing bipartisan area of interest as Congress looks to find agreement on how to regulate artificial intelligence and work will likely continue into the next Congressional session.
California expands sales tax to SaaS and digital products
On June 29, 2026, California Governor Gavin Newsom signed SB122 into law, expanding the state sales tax base to include SaaS, electronically delivered software, and certain digital products beginning in 2027. The legislation generally treats many digital products as taxable tangible personal property and adopts a customer-based sourcing methodology. For remotely accessed or electronically delivered products, sales are sourced to the purchaser’s “known address” in California.
The new tax classifications will require both software providers and customers to reassess their sales and use tax compliance obligations. These changes also may increase costs for healthcare providers and other end users as software vendors seek to pass through newly imposed sales and use tax liabilities. Users may also see increased compliance costs associated with implementing the new regime and amending existing contractual arrangements.
Illinois’ AI Safety Measures Act reflects the growing patchwork of state-level AI regulations
Illinois Governor J.B. Pritzker signed the Artificial Intelligence Safety Measures Act into law on July 6, 2026. The legislation requires developers of frontier AI models to develop and publish a transparency framework describing how they apply recognized industry standards, evaluate model capabilities, and assess and mitigate risks of catastrophic harm to individuals and the public.
The Illinois measure builds on transparency and accountability requirements included in California’s the Transparency in Frontier Artificial Intelligence Act and New York’s the Responsible AI Safety and Education (RAISE) Act, both enacted in late 2025. Like those laws, the Illinois framework imposes a range of obligations on developers of frontier models, including the publication of transparency reports and AI safety frameworks, incident reporting requirements, implementation of cybersecurity safeguards, and processes for identifying and responding to critical safety incidents.
The new law also includes, for the first time, a requirement that large frontier model developers undergo annual independent third-party audits evaluating model risks, safety controls, and mitigation measures. These audits must be conducted in accordance with accepted auditing standards and recognized industry best practices, signaling a shift from voluntary commitments toward more formal oversight and accountability mechanisms.
As transparency and accountability continue to emerge as central pillars of AI governance, particularly in healthcare, these disclosure and audit requirements may provide healthcare organizations with valuable information to support the assessment, procurement, monitoring, and governance of AI-enabled tools that incorporate frontier models. More broadly, the enactment of this law underscores the increasingly complex compliance landscape facing AI developers and deployers as states continue to advance AI-specific regulatory frameworks while federal lawmakers debate the appropriate scope and structure of national AI regulation. The result is a growing patchwork of state requirements that may create additional compliance, governance, and operational challenges for organizations deploying AI systems.
FDA authorizes first Software as a Medical Device incorporating a patient-facing LLM
Digital health company UpDoc announced that it received Food and Drug Administration approval for what the company describes as the first Software as a Medical Device (“SaMD”) incorporating patient-facing large language models for medication management purposes. The UpDoc platform, designed on previously approved tools to assist in management of type 2 diabetes medication, integrates with electronic health records and existing clinical workflows and allows patients to submit information to produce treatment plans generated in accordance with clinician-defined protocols.
While this clearance indicates the FDA’s willingness to authorize certain AI-enabled clinical tools, it does not establish a required approval pathway for all LLM-based healthcare products. Federal and state regulators continue to pursue multiple oversight approaches to regulating AI in health care, including an increasing number of states expressing interest in facilitating patient access to AI-enabled care through regulatory sandbox programs. Entities developing clinical and patient-facing AI technologies should consider governance and legal strategies calibrated to the specific intended use of the product at issue, as well as the implementation of protocols sufficient to demonstrate the safety, effectiveness, and reliability of the underlying AI technology.
TEFCA oversight and expansion
The U.S. Department of Health and Human Services (HHS), through the Office of the National Coordinator for Health Information Technology (ONC), announced new oversight measures for the Trusted Exchange Framework and Common Agreement (TEFCA), the national interoperability network designed to facilitate secure electronic exchange of health information. ONC has awarded a contract to enhance audit, review, and compliance functions and is conducting additional reviews of Qualified Health Information Networks (QHINs) and participating organizations to ensure adherence to TEFCA requirements. HHS also reported that TEFCA has grown from approximately 10 million exchanged health records to more than 1 billion records in less than one year.
CMS Announces New Technology Office
The Centers for Medicare & Medicaid Services (CMS) has announced the establishment of a new organizational component, the Office of Health Technology and Products (OHTP), effective June 9, 2026. OHTP is intended to provide enterprise-wide leadership and oversight of CMS’s health care technology modernization efforts, as well as the development and management of digital products supporting Medicare, Medicaid, the Children’s Health Insurance Program (CHIP), and other CMS-administered programs. The office will operate in coordination with the CMS Chief Information Officer (CIO).
OHTP will include several functional components, including the Open Source Program Group, the Standards & Interoperability Group, the Product Development Group, and Digital Services at CMS. This organizational change aligns with the Administration’s broader efforts to accelerate the digital transformation of CMS and modernize the agency’s technology infrastructure.
Trump Administration Issues Scaled-Back AI Executive Order
The Trump administration has issued a new executive order on artificial intelligence that emphasizes cybersecurity safeguards while pulling back from more stringent federal oversight proposed earlier. The directive introduces a voluntary review process requiring companies to submit advanced AI models to the government 30 days before public release—shortened from an earlier 90-day proposal—alongside new efforts to coordinate with industry on identifying and addressing security vulnerabilities.
Framed as a balance between innovation and risk mitigation, the order is narrower than expected and avoids mandatory licensing or preclearance requirements, reflecting industry concerns about overregulation. At the same time, it signals growing urgency within the administration to address national security risks posed by increasingly powerful AI systems, including steps to strengthen federal network defenses and expand collaboration with critical infrastructure partners.