Skip to main content
All

This digest covers key virtual and digital health regulatory and public policy developments during August and early September 2026 from the United States, United Kingdom, and European Union.

In this issue, you will find the following:

U.S. News

U.S. Featured Content

Enforcement and policy activity this month reflected the government’s dual focus on curbing telehealth-related fraud while accelerating a federal framework for artificial intelligence (AI) in health care. The U.S. Department of Justice’s (DOJ) newly created National Fraud Enforcement Division named telemedicine and Medicare/Medicaid fraud as top enforcement priorities, a focus underscored by a two-year prison sentence in a $110 million telemedicine durable medical equipment (DME) scheme. On the regulatory front, the Drug Enforcement Administration’s (DEA) long-awaited final rule on special registration for telemedicine prescribing of controlled substances is now under the White House Office of Management and Budget (OMB) review, while the Centers for Medicare & Medicaid Services (CMS) expanded its value-based ACCESS model to cover additional chronic conditions and unveiled plans for an AI-inferred risk-adjustment model in its LEAD ACO program. Congress also weighed in, with bipartisan legislation introduced to require human review of AI-driven medical-necessity denials, and the Federal Trade Commission (FTC) rescinded its 2021 policy statement extending health data breach notification obligations to health apps. Meanwhile, the U.S. Food and Drug Administration (FDA) continued to build out its AI infrastructure and leadership, naming its first Deputy Commissioner for Technology and Artificial Intelligence, migrating agency staff to an upgraded internal AI tool, and issuing a paper on using digitally derived measures in clinical investigations. Together, these developments show U.S. regulators and lawmakers moving in parallel: tightening enforcement against exploitative telehealth practices while laying the institutional groundwork for AI’s expanding role in health care delivery and oversight.

EU and UK News

EU/UK Featured Content

The more significant developments this month have been in the data protection space. Notably, Uber was fined almost €825 million following a finding that they breached the general prohibition on fully automated decision-making in the General Data Protection Regulation (GDPR). This decision serves as an important reminder for the need for meaningful human review in the Life Sciences industry as companies increasingly rely on AI-assisted decision-making, for example in screening candidates for eligibility to take part in clinical trials.

Further, the European Data Protection Board (EDPB) has written to the European Commission to request that the commission “closely assess” the recent U.S. Supreme Court decision of Trump v. Slaughter and its impact on the EU-U.S. Data Privacy Framework (DPF) adequacy decision. The EDBP has raised that this decision, which holds that the statutory protection against removal of Federal Trade Commissioners are unconstitutional, may affect the validity of the DPF decision.

Other developments include that the International Medical Device Regulators Forum (IMDRF) has published technical guidance regarding Predetermined Change of Control Plans (PCCP) for medical device software. This guidance intends to foster regulatory harmonization by identifying the essential principles for developing PCCP. 

U.S. News

Health Care Fraud And Abuse Updates

The Fraud Division’s Enforcement Priorities Memorandum. On August 13, 2026, Assistant Attorney General Colin M. McDonald issued a memorandum to all personnel in the National Fraud Enforcement Division, setting forth the enforcement priorities of the newly created division. The memorandum identified five priority areas: public trust and financial integrity, health care, internal revenue, global trade and commerce, and corporate misconduct. The memorandum states that the division will use, “cutting-edge data analysis to target exploitative health care fraud schemes,” expressly naming telemedicine programs and Medicare and Medicaid fraud. The memorandum further commits to “supercharging” the Health Care Fraud Strike Force model with additional resources, data analytics support, and technology. 

Owner of Telemedicine Companies Sentenced in Medicare Fraud Scheme. On August 20, 2026, Steven Richardson, former owner of Expansion Media and Hybrid Management Group, was sentenced to two years in prison for a $110 million telemedicine scheme involving medically unnecessary DME. The government alleged that between March 2016 and January 2023, Richardson contracted with telemarketing companies that generated leads by targeting Medicare beneficiaries and paid Richardson’s companies on a per-order basis to generate DME orders. As part of the scheme, doctors and nurses allegedly reviewed and signed prepopulated orders without examining the beneficiary, falsely making it appear a legitimate exam had occurred. Richardson then allegedly provided the signed orders back to the telemarketers, who sold them to DME suppliers. In turn, those suppliers submitted claims to Medicare for equipment. 

Provider Reimbursement Updates

DEA Special Registration Final Rule for Telemedicine Prescribing Is Under OMB Review. The DEA has submitted its final rule, Special Registrations for Telemedicine and Limited State Telemedicine Registrations, to the OMB for review. OMB’s Office of Information and Regulatory Affairs received the rule on August 25, 2026, and lists it as an economically significant DOJ/DEA final rule.

At issue is a permanent federal framework for prescribing controlled substances via telemedicine when the practitioner and patient have not had a prior in-person medical evaluation. The Ryan Haight Online Pharmacy Consumer Protection Act of 2008 generally requires an in-person medical evaluation before a practitioner may prescribe or dispense controlled substances by means of the internet, subject to specified exceptions within the statutory definition of the “practice of telemedicine.” One such exception applies to a practitioner who obtains a special registration from the DEA Administrator under 21 U.S.C. § 831(h).

DEA’s January 2025 proposed rule would have established a special-registration framework under which practitioners and mid-level practitioners could prescribe controlled substances through audio-video telemedicine, and, in limited circumstances, video-only telemedicine, without a prior in-person medical evaluation, provided they complied with applicable prescribing, recordkeeping, and reporting requirements. It also proposed to require certain direct-to-consumer telemedicine platforms to register with DEA when they engage in intermediary conduct integral to the provider-patient relationship.

DEA had described the proposal as permitting special registrants to prescribe Schedule III-V controlled substances remotely and, for certain board-certified specialists, to obtain an advanced registration for designated Schedule II prescribing. The proposal also contemplated online-platform registration and a nationwide prescription drug monitoring program. The final rule’s text and safeguards are not yet public. DEA reports that it reviewed more than 6,400 comments on the 2025 proposal and is considering alternatives in drafting a final rule responsive to public and industry concerns. DEA’s current agenda anticipates final action in November 2026. In the interim, DEA and the U.S. Department of Health and Human Services (HHS) have extended the existing telemedicine prescribing flexibilities through December 31, 2026.

Privacy and AI Updates

CMS Expands ACCESS to Cover Chronic Conditions. On September 15, 2026, CMS announced that it is expanding its “Advancing Chronic Care with Effective, Scalable Solutions” (ACCESS) model to include four new areas of remote treatment for selected chronic diseases. ACCESS, which began in July and will continue for a 10-year period, gives participating organizations recurring payments tied to improvements in patient health rather than traditional fee-for-service reimbursement through Medicare and Medicaid. Initially, ACCESS’ coverage “tracks” were for technology used to treat early cardiovascular, kidney, and musculoskeletal pain. The new expansion will mean that, as of the spring of 2027, ACCESS will also offer technology options to Medicare beneficiaries who have heart failure, chronic obstructive pulmonary disease (COPD), substance use disorders, and nicotine dependence. CMS will also publish a reference guide in the future on specification for a maternal cardiovascular kidney metabolic track, including hypertensive disorders for pregnancy, as a voluntary reference that other payers, including Medicaid plans, can use to support cross-payer alignment.

FTC Rescinds Policy Statement on Health Apps Under Health Breach Notification Rule. On September 9, 2026, the FTC rescinded its 2021 Statement of the Commission on Breaches by Health Apps and Other Connected Devices, which took the position that certain mobile applications and connected devices collecting consumers’ health information qualify as “vendors of personal health records” subject to the FTC’s Health Breach Notification Rule (HBNR). The HBNR, which is the FTC’s regulation implementing the Health Information Technology for Economic and Clinical Health (HITECH) Act, requires vendors of personal health records that are not HIPAA-covered entities to notify individuals, the FTC, and in some cases, the media, of breaches in the security of personal health information, in the same manner as HIPAA requires for HIPAA-covered entities. In rescinding the 2021 policy statement, the FTC stated that it provided “minimal benefit” and that its rescission advances the current administration’s deregulation of metabolic diseases, such as hypertension, diabetes, depression, and anxiety, and the commission’s policy of avoiding unnecessary subregulatory guidance. It is unclear how the rescission may impact enforcement of the HBNR, which was amended in 2024 in part to indicate coverage of mobile apps and connected devices.

Policy Updates

CMS Developing an AI-Inferred Risk-Adjustment Model for the LEAD Model. On August 17, 2026, the CMS stated that it is developing an AI-inferred risk-adjustment model for the Long-Term Enhanced ACO Design (LEAD) Model. CMS plans to share AI-inferred scores with participating Accountable Care Organizations for 2028 shadow testing, use a phased blend of AI-inferred and conventional scores in 2029 and 2030, and fully integrate AI-inferred scores for the aged and disabled population beginning in 2031, subject to testing and validation.

Representatives Introduce Doctors Not AI Act. On September 1, 2026, Reps. Greg Landsman (D-OH), Buddy Carter (R-GA), Kim Schrier (D-WA), and Tom Barrett (R-MI) introduced the Doctors Not AI Act (H.R. 10210). The bill would permit AI to assist with claims processing, but require a licensed health care professional with appropriate expertise to make medical-necessity denials after independently reviewing the patient’s individual medical circumstances. It also would require disclosure when AI is used in the review process.

FDA Seeks Feedback on Risk Assessment, Premarket Evaluation, Postmarket Monitoring, and Related Issues. On August 18, 2026, FDA issued Considerations for the Regulation of Generative AI-Enabled Medical Devices: Discussion Paper and Request for Feedback. The Digital Health Center of Excellence, within FDA’s Center for Devices and Radiological Health, is seeking feedback on risk assessment, premarket evaluation, postmarket monitoring, and related issues. The paper is for discussion only and does not constitute draft or final guidance or propose changes to FDA policy. Feedback is due October 19, 2026.

FDA Migrates to Elsa 4.0. On August 24, 2026, FDA migrated all agency staff to Elsa 4.0 from the legacy model of its FDA-specific AI tool. Originally announced in May, Elsa 4.0 offers enhanced search and research tools.

FDA Updates

FDA Announces New Deputy Commissioner for Technology and Artificial Intelligence. On September 8, 2026, HHS announced four senior leadership selections at the FDA, including the creation of FDA’s first Deputy Commissioner for Technology and Artificial Intelligence. Jared Seehafer, M.S., has been selected for the newly created role. As FDA’s senior leader for technology, software, and AI, Seehafer will lead the development of FDA strategy and priorities in these areas. HHS stated that the position reflects the administration’s focus on accelerating reliable AI innovation, modernizing federal technology, and establishing an effective regulatory framework for emerging technologies. Seehafer brings two decades of technical and leadership experience involving software, AI, and FDA-regulated medical technology.

The announcement also makes permanent three officials who had been serving in acting capacities: Michael Davis, M.D., Ph.D., as Director of the Center for Drug Evaluation and Research; Karim Mikhail, B.Pharm, M.Sc., as Director of the Center for Biologics Evaluation and Research; and Bret Koplow, Ph.D., J.D., as Director of the Center for Tobacco Products. Collectively, the selections indicate FDA’s continued emphasis on modernization, innovation, and cross-center infrastructure, including technology and AI capabilities, as the agency advances its public health priorities.

FTC Updates

FTC Proposes Enforcement Policy Statement on Personalized Pricing. On August 19, 2026, the FTC issued a proposed policy statement explaining that it intends to pursue personalized-pricing practices that it views as deceptive or unfair under Section 5 of the FTC Act. The statement does not propose to prohibit personalized pricing outright, and recognizes that prices may appropriately vary based on factors such as supply and demand, geography, taxes, market conditions, and risk-based underwriting in industries such as insurance and credit. But where consumers reasonably expect a price to be static or widely available, the FTC takes the position that businesses using personal data to set an individualized price should clearly and conspicuously disclose that the price is personalized, the basis for the personalization, and the types of data used. The FTC cautions that a generic statement that a price is “specially selected” would likely be insufficient. The statement also flags potential privacy concerns where businesses collect, use, or obtain personal data for personalized pricing without adequate notice and consent, including where they fail to verify that a third-party data source obtained the requisite consumer consent. Although the statement is nonbinding and does not create new legal requirements, it signals heightened FTC scrutiny of data-driven pricing — particularly where pricing is based on consumers’ perceived willingness or inability to shop elsewhere, health needs, household characteristics, or other sensitive circumstances.

EU and UK News

Regulatory Updates

IMDRF Publishes Technical Guidance Document Regarding Predetermined Change Control Plans for Medical Device Software. The IMDRF has published a technical guidance document regarding PCCP for medical device software. Whereas traditional regulatory processes may lead to delays in deploying important updates to medical device software because the manufacturer would be required to submit a new or additional application for relevant changes, a PCCP allows the manufacturer to receive advance authorization for multiple planned changes during the initial or an existing application. The guidance sets out what PCCPs should contain and is intended to support regulatory harmonization without superseding existing national laws or regulations. It identifies the essential principles for developing PCCPs, including that they must be risk-based, evidence-based, transparent, and focused.

NICE Launches Public Dialogue on the Use of AI in Health Care. NICE has announced that AI will be the next topic considered through its “NICE Listens” public engagement program, which aims to explore the moral, ethical, social, and value-based questions that underpin complex health care decisions. NICE states that, while AI has the potential to support diagnosis, productivity, and help services respond to growing pressure, its increasing use also raises important questions regarding trust, transparency, accountability, and fairness. NICE will use the dialogue to shape its approach to AI effectively and at an early stage. The dialogue will help inform how NICE communicates about AI-related guidance, thinks about evidence and value, and how NICE builds confidence in decisions that may increasingly involve AI-enabled technologies.

UK Advertising Standard Authority (ASA) Issues Guidance on the Illusion of Artificial Intelligence in Advertisements. ASA issued guidance on the illusion of artificial intelligence in advertisements. ASA has advised advertisers to be careful with the claims that they make in relation to AI chatbots including those which are proposed to be used as a tool for patients waiting to talk to mental health care professionals. ASA has recommended that any advertisement should avoid implying that the AI tool can be used in place of a qualified therapist, and any claims that the apps are suitable for emergency or crisis situations are strongly discouraged. If health claims are made, the advertiser must be able to provide evidence to support them. However, ASA’s “CAP Code” only applies to advertisements rather than the products which are advertised. Therefore, the ASA cannot necessarily comment on the AI products themselves.

Privacy Updates

Dutch DPA Fines Uber Almost €825 Million Over Unlawful Automated Decision-Making. The Autoriteit Persoonsgegevens (AP), the Dutch data protection authority, has fined Uber €824,990,000 after finding that the company breached the GDPR’s prohibition on fully automated decision-making. The AP found that, between 2018 and 2022, Uber used software to monitor drivers’ behavior and customer ratings and, where the software flagged suspected fraud or persistently low ratings, automatically suspended or permanently deactivated drivers’ accounts with no meaningful human review, cutting off their income with immediate effect. The AP also found that Uber failed to give drivers adequate information about this automated decision-making. The investigation originated from complaints by 171 French drivers to the Ligue des droits de l’Homme, which were referred to the CNIL and, because Uber’s European headquarters are in the Netherlands, passed to the AP as lead supervisory authority. Uber has said it disagrees with the decision and will appeal. This is the second-largest fine ever imposed under the GDPR, after the Irish DPC’s €1.2 billion fine against Meta in 2023, and a reminder of the priority EU regulators continue to place on Article 22 GDPR compliance for algorithmic human resource (HR) and platform-worker decisions. Life sciences companies increasingly rely on automated or AI-assisted decision-making of their own, for example in screening clinical trial candidates for eligibility, or managing HR and field-force decisions, and this decision is a reminder that such systems generally require meaningful human review and clear upfront information to the individuals affected wherever they produce legal or similarly significant effects.

EDPB Asks European Commission to Assess Impact of U.S. Supreme Court Ruling on EU-U.S. Data Privacy Framework. Following a discussion at its June plenary, the EDPB has written to European Commissioner Michael McGrath asking the commission to “closely assess” whether the U.S. Supreme Court’s judgment in Trump v. Slaughter (June 29, 2026), which held that statutory protections against at-will removal of FTC commissioners are unconstitutional, affects the continued validity of the EU-U.S. DPF adequacy decision. In its letter to Commissioner McGrath, dated July 31, 2026 (reported August 3, 2026), the EDPB notes that the existence and effective functioning of independent supervisory authorities in a third country is a key factor in assessing adequacy, and that the DPF adequacy decision expressly relied on FTC commissioners being removable only for cause. The DPF adequacy decision remains in force and transfers under it remain lawful; the letter does not itself change the legal position, but it formally puts the question before the commission and may prompt a wider review of the framework. This is particularly relevant for life sciences companies that rely on the DPF for transatlantic transfers of clinical, research, or HR data, who should keep transfer impact assessments under review as this develops.   

© Arnold & Porter Kaye Scholer LLP 2026 All Rights Reserved. This Newsletter is intended to be a general summary of the law and does not constitute legal advice. You should consult with counsel to determine applicable legal requirements in a specific fact situation.