25% off all training courses Offer ends July 30, 2026
View HIPAA Courses
25% off all training courses
View HIPAA Courses
Offer ends July 30, 2026

The HIPAA Journal is the leading provider of HIPAA training, news, regulatory updates, and independent compliance advice.

HHS Seeks Input on Potential Updates to the CLIA Regulations

The HHS’ Centers for Medicare and Medicaid Services (CMS) and the Centers for Disease Control and Prevention (CDC) have issued a request for information (RFI) on potential updates to the Clinical Laboratory Improvement Amendments (CLIA) of 1988. The RFI covers several topics, including breath testing, laboratory processes and procedures, emergency preparedness, cybersecurity, and the use of artificial intelligence. The feedback received in response to the RFI will advise future actions and rulemaking. Comments are being accepted through September 14, 2026.

The CLIA regulations were enacted on October 31, 1988, strengthening federal oversight of clinical laboratories and helping to ensure the accuracy and reliability of patient test results. The CLIA regulations were promulgated in 1992, and while certain elements of the CLIA regulations have been updated over the years, a substantial update may be required to better reflect current knowledge and advancements in laboratory testing.

One area where updates may be required is cybersecurity, as threats across the healthcare sector have expanded significantly in both scope and severity. “As clinical laboratories increasingly rely on digital systems and connected technologies—such as Laboratory Information System (LIS), Electronic Health Record (EHR) integration, automated diagnostic devices, and virtual or remote access to laboratory and patient data—new cybersecurity risks have emerged,” explained the CMS and CDC in the RFI.

Many U.S. laboratories are HIPAA-regulated entities and must therefore comply with the requirements of the HIPAA Security Rule; however, there are gaps that need to be addressed and threats that the current HIPAA Security Rule does not adequately protect against. The CMS is seeking non-proprietary/non-confidential information on current laboratory cybersecurity practices and experiences related to protecting patient data and lab operations; user identity and access; remote access to systems containing personal information from overseas entities; restrictions on ports and/or internet protocol (IP) addresses; cybersecurity response plans; and cybersecurity training.

One area where further regulation is likely required is artificial intelligence, as the CLIA regulations were enacted long before AI tools started to be used in clinical settings. Model corruption, hallucinations, and compromises could have serious implications for the accuracy and reliability of testing. The CMS and CDC are seeking information on postanalytic interpretation and the use of AI tools, specifically, the algorithms and AI tools used in postanalytic analysis; the circumstances where software and AI tools are being used to interpret test results, histopathology slides, and results; the methods used to verify the performance of those tools; and whether there are any additional technology considerations for high complexity tests that the CMS and CDC should consider incorporating into the CLIA regulations.

Author: Steve Alder is the editor-in-chief of The HIPAA Journal. Steve is responsible for editorial policy regarding the topics covered in The HIPAA Journal. He is a specialist on healthcare industry legal and regulatory affairs, and has 10 years of experience writing about HIPAA and other related legal topics. Steve has developed a deep understanding of regulatory issues surrounding the use of information technology in the healthcare industry and has written hundreds of articles on HIPAA-related topics. Steve shapes the editorial policy of The HIPAA Journal, ensuring its comprehensive coverage of critical topics. Steve Alder is considered an authority in the healthcare industry on HIPAA. The HIPAA Journal has evolved into the leading independent authority on HIPAA under Steve’s editorial leadership. Steve manages a team of writers and is responsible for the factual and legal accuracy of all content published on The HIPAA Journal. Steve holds a Bachelor’s of Science degree from the University of Liverpool. You can connect with Steve via LinkedIn or email via stevealder(at)hipaajournal.com

x

Is Your Organization HIPAA Compliant?

Find Out With Our Free HIPAA Compliance Checklist

Get Free Checklist