Skip to content

Mon - Fri: 10.00 - 5.00

[email protected]

Delana Technologies

Delana Technologies

Delana Technologies delivers expert cybersecurity, cloud, and AI-driven IT strategy solutions. Transform your enterprise securely and intelligently.

  • Home
  • Contact Us
  • About Us
  • Case Studies
  • Workflow Automation & Systems Integration
  • AI Consulting & Agentic AI Solutions
  • Home
  • Contact Us
  • About Us
  • Case Studies
  • Workflow Automation & Systems Integration
  • AI Consulting & Agentic AI Solutions

Mon - Fri: 10.00 - 5.00

[email protected]

Your Medical Records, Now an App Store: Inside the CMS Slack Where AI Firms Shaped Medicare’s Health-App Push (AI Trends, 11 October 2026)

  1. Home   »  
  2. Your Medical Records, Now an App Store: Inside the CMS Slack Where AI Firms Shaped Medicare’s Health-App Push (AI Trends, 11 October 2026)

Your Medical Records, Now an App Store: Inside the CMS Slack Where AI Firms Shaped Medicare’s Health-App Push (AI Trends, 11 October 2026)

October 11, 2026October 11, 2026 admincybersecurityTagged AI governance, AI in healthcare, AI policy, AI regulation, AI trends, AI vendor risk, data privacy, FTC, HIPAA, Medicare App Library, OAuth

What’s trending in AI on 11 October 2026: The AI story drawing the most attention this weekend is not a model launch. It is a chat room. A joint investigation by KFF Health News and CBS News, published on 9 October, describes a Slack workspace run by the Centers for Medicare & Medicaid Services (CMS) where about 1,700 members, mostly tech executives and investors, worked with federal officials to steer Americans toward managing their health care and medical records through commercial apps and AI chatbots. It previews how your medical history may soon flow into AI tools, and how much of that flow sits outside HIPAA. Below: what was reported, what CMS says, where HIPAA stops, and a three-lane checklist for patients, employers and app builders.

Key takeaways

  • A government-run Slack became an industry channel. Created in August 2025, it grew to about 1,700 members, mostly from tech, according to KFF Health News.
  • The policy wins were real. The Medicare App Library launched in April 2026, and in September CMS opened a path for apps to bill Medicare for AI services.
  • The biggest fight is over records access. Vendors want vetted apps to stand in the patient’s shoes on TEFCA, with ongoing access after one consent.
  • HIPAA usually stops at the app. If you chose the app, HHS says your provider is not liable under HIPAA for what it does next; the FTC’s breach rule is the main backstop.
  • Governance is disputed. Experts say the group resembles a federal advisory committee that should meet openly; CMS calls it voluntary and declined to address its legality.
Your medical records, now an app storeTitle card. Headline: Your medical records, now an app store. Subhead: inside the CMS Slack where AI firms helped shape Medicare’s health-app push. Three tags: about 1,700 Slack members, mostly tech; Medicare App Library launched April 2026; HIPAA usually ends once records reach the app. Illustration of a medical folder sending records along a line into a phone showing a chat bubble, with a shield that has a gap in it. AI TRENDS · 11 OCTOBER 2026 Your medical records, now an app store Inside the CMS Slack where AI firms helped shape Medicare’s health-app and chatbot push ~1,700 Slack members, mostly tech and investors Medicare App Library live since April 2026 HIPAA usually ends once records reach the app Sources: KFF Health News / CBS News (9 Oct 2026), CMS, HHS delana.co
The question behind the headlines: when government promotes AI health apps, who decides how much of your medical history they can see, and who protects it afterward?

1. What KFF Health News and CBS News reported

The investigation, by Amanda Seitz, Maia Rosenfeld and Darius Tahir, centers on a workspace CMS manages under a “Technology Working Group.” Amy Gleason, former acting administrator of the U.S. DOGE Service and a senior CMS adviser, welcomed members in August 2025. It grew to about 1,700 people, dominated by tech leaders, investors and founders, with only a handful of patient advocates, physicians and hospital representatives. Named participants include Oura Health, Palantir and the venture firm 8VC, which the reporting links to Finn Kennedy, son of HHS Secretary Robert F. Kennedy Jr.

According to the report, invitations to closed meetings went out through the workspace, and industry used it to press for wider access to medical records. The key events in 2026:

  • February: The FDA held an unpublicized listening session on conversational AI for patients, attended by at least 35 industry organizations; invitees included Microsoft, Anthropic, OpenAI, Apple and Google. The invitation reportedly went out through the Slack.
  • February: A CMS Innovation Center official told industry the agency’s work could act as a sales channel for health apps.
  • April: A CMS adviser said seniors would trust an app if Medicare.gov promoted it. The Medicare App Library went live days later.
  • May: In a formal meeting, tech executives argued that apps requesting records should be treated as standing in the patient’s place.
  • September: CMS Administrator Dr. Mehmet Oz announced a program allowing health apps to bill Medicare for AI services such as wearable device tracking, and officials suggested App Library members would be prioritized.
Timeline: from a Slack workspace to Medicare billing for AI appsHorizontal timeline with seven milestones. August 2025: CMS Slack workspace created, welcomed by Amy Gleason. February 2026: closed FDA listening session on conversational AI, at least 35 industry organizations. March 2026: CMS tells a health IT conference it wants AI agents to help seniors navigate care. April 2026: Medicare App Library goes live on Medicare.gov. May 2026: vendors argue apps should stand in the patient’s shoes for records access. September 2026: program lets health apps bill Medicare for AI services. 9 October 2026: KFF Health News and CBS News publish the investigation. From a Slack workspace to Medicare billing Key steps in the CMS health-app and AI push, as reported and announced Aug 2025CMS Slackcreated Feb 2026Closed FDAAI session,35+ orgs Mar 2026CMS: AI agentsfor seniors’care navigation Apr 2026Medicare AppLibrary live May 2026Apps to standin patient’s shoesrecords push Sep 2026Apps can billMedicare forAI services 9 Oct 2026KFF / CBSinvestigation Audience: CMS cites 68+ million Medicare enrollees as the potential reach of the App Library. Sources: KFF Health News / CBS News (9 Oct 2026); Healthcare Dive (13 Mar 2026); CMS Medicare App Library page delana.co
Thirteen months from a welcome message to a Medicare payment pathway for AI-driven apps.

2. What CMS and its supporters say

Much is not in dispute. Getting records out of hospital portals and into tools patients actually use has been a bipartisan goal for over a decade. CMS frames its Health Technology Ecosystem as voluntary; its App Library page calls the industry pledge “a movement, not a mandate,” and Gleason told KFF the ecosystem is an open, voluntary technical collaboration. Oz has said the aim is to let industry take part in government-supported health care, and one participant described the push as a reaction to paternalism over patients’ own data.

The federal interest in AI here is also not new. At the HIMSS conference in March, Healthcare Dive reported, Oz said CMS wanted to give beneficiaries AI agents to help find doctors and compare Medicare Advantage plans, while acknowledging seniors’ distrust. A KFF survey cited in that coverage found only 31% of Medicare enrollees aged 65 and older trusted AI a great deal or a fair amount for accessing records and personalized advice.

What CMS has not done is answer the governance questions. According to the investigation, the agency declined to address whether the Slack is legal or how apps were chosen for the library, and the FDA did not respond to a request for comment.

3. The governance problem: an advisory committee by another name?

The Federal Advisory Committee Act (FACA) requires groups advising federal agencies to meet publicly and keep balanced membership. The Slack’s code of conduct says it is not such a committee. Joseph Daval, a former FDA lawyer now at Harvard Medical School, told KFF it resembles one, and that the law partly exists to prevent interest groups capturing agency policy.

For businesses, the practical point matters more than the legal one: rules shaping how tens of millions of people’s health data moves were discussed where the public could not see and patients had little voice. That pattern of fast, voluntary, industry-led standard-setting is spreading across AI policy, as in the commitments covered in our White House AI Accord explainer. Such frameworks move quickly but rarely carry enforcement.

The American Medical Association raised a separate concern about product quality. Its CEO, John Whyte, told KFF that some of these tools “just aren’t ready for primetime,” and that no one is liable when they get things wrong. Healthcare Dive noted in March that a Nature study found OpenAI’s consumer health tool often under-triaged serious cases.

4. Where HIPAA stops and your records keep going

The fight over standing in the patient’s shoes decides how much of your history an app can pull, and for how long. TEFCA is the national framework providers use to exchange electronic records. Vendors in the Slack pushed for vetted apps to be treated as the patient when requesting records, with a single consent opening a frictionless, ongoing pathway rather than a one-time download. KFF notes that one consultant advocating this sits on the board of an organization that does the vetting.

Here is the part most patients miss. HIPAA governs providers, health plans, clearinghouses and their business associates. It does not follow your data into an app you chose yourself. HHS guidance says that when a provider sends records to an app it did not supply, the provider “would not be liable under the HIPAA Rules” for what the app does next. From then on, protection is largely whatever the app’s privacy policy promises, plus a thinner layer of consumer law.

Where HIPAA stops: the path of your records into an AI appFlow diagram with four boxes left to right. Box one: hospital or doctor, covered by HIPAA. Box two: TEFCA or a CMS Aligned Network, the exchange layer, covered by network rules. Box three: the health app you chose, usually not covered by HIPAA; FTC Health Breach Notification Rule and state laws apply. Box four: AI model, analytics vendors and other third parties, governed by the app’s contracts and privacy policy. A dashed orange line between box two and box three is labeled HIPAA usually ends here. Where HIPAA stops How protections change as your records move from your doctor into an AI app you chose Doctor or hospital Covered entity HIPAA applies Privacy, Security andBreach rules Exchange network TEFCA / CMS AlignedNetwork Network rules Identity checks,standard formats Health app you chose Usually not acovered entity FTC HBNR + state Privacy policy setsmost of the rules AI model andthird parties Model provider,analytics, ads Contracts anddisclosures only HIPAA usually ends here (unless the app works for your provider as a business associate) Sources: HHS HIPAA FAQ on health apps; FTC Health Breach Notification Rule; CMS. Simplified; not legal advice. delana.co
The protection you assume follows your records often stops at the moment you press “Connect.”

The main federal backstop is the FTC’s Health Breach Notification Rule. Updates finalized in April 2024 make clear it covers health apps, including those that draw data from multiple sources, and that a “breach” includes unauthorized disclosure, such as sharing with an advertiser without permission, not only hacking. People must be notified within 60 calendar days of discovery, and violations can bring civil penalties. But it is a notification rule: it applies after something goes wrong and sets few limits on what an app may collect.

Where your data sitsMain rules that applyWho enforcesWhat it does not do
Your doctor, hospital or health planHIPAA Privacy, Security and Breach Notification RulesHHS Office for Civil RightsDoes not cover what a patient-chosen app does after it receives records
An app working for your provider (business associate)HIPAA via a business associate agreementHHS Office for Civil RightsOnly applies if the provider or plan supplied or contracted for the app
A consumer health app you connected yourselfFTC Health Breach Notification Rule, FTC Act, state health-privacy lawsFTC and state attorneys generalMostly requires notice after a breach or unauthorized sharing; few federal limits on collection
A Medicare App Library listingCMS listing requirements: IAL2/AAL2 identity checks, security checklist, data-source disclosure, third-party reviewCMS (listing decisions) and reviewers such as DiMe or CARIN AllianceCMS has not fully disclosed selection criteria; listing is not a HIPAA guarantee
The AI model or analytics vendor behind the appContracts with the app maker and the app’s privacy disclosuresIndirectly, through the app’s legal obligationsPatients usually cannot see or negotiate these terms
Sources: HHS right-of-access FAQ; FTC Health Breach Notification Rule; CMS Medicare App Library page; KFF Health News. Simplified overview, not legal advice.

This is the same consent problem we have covered with AI agents and SaaS integrations: one click grants broad, standing access that is rarely reviewed. See our posts on “Allow Always” agent permissions and OAuth attacks on the SaaS trust chain. An auto-refreshing medical-records connection is a high-value token.

5. What a Medicare App Library listing actually checks

To be fair to CMS, the App Library is not an open marketplace. It lists three use cases: digital check-in, conversational AI assistants that use secure access to medical history, and diabetes and obesity management. Apps must connect to a CMS Aligned Network, verify identity at IAL2/AAL2 levels, disclose data sources, complete a security checklist, offer trials if they charge, and label AI-generated output. They must operate consistently with HIPAA only when acting as a covered entity or business associate, which many consumer apps are not.

Seven steps to a Medicare App Library listing, and what they leave openA staircase of seven steps on the left: 1 sign the Health Tech Ecosystem pledge; 2 partner with ID.me or CLEAR for identity verification; 3 connect to a CMS Aligned Network; 4 complete third-party review with DiMe or CARIN Alliance; 5 submit the developer application; 6 undergo CMS review; 7 launch on Medicare.gov. A panel on the right lists open questions: full selection criteria not disclosed; whether ongoing records access follows one consent; how data is shared with AI model providers; who is liable if AI advice is wrong. Seven steps to a Medicare.gov listing What CMS publishes about the process, and what the public still cannot see 1 Sign the Health Tech Ecosystem pledge 2 Identity partner: ID.me or CLEAR 3 Connect to a CMS Aligned Network 4 Third-party review: DiMe or CARIN 5 Submit developer application 6 CMS review 7 Launch on Medicare.gov Still open to question Full selection criteria not disclosed Whether one consent means ongoingaccess to your records What reaches the AI model providerbehind each app Who is liable when AI healthguidance is wrong Sources: CMS Medicare App Library page; KFF Health News / CBS News (9 Oct 2026) delana.co
The published process covers identity, connectivity and a security checklist. The questions patients care about most sit outside it.

The reporting shows how new some listings are. Slothwise, launched this year, charges $9.99 a month to analyze medical records and had only a handful of app store reviews; its founder told KFF it is informational for now. Nothing suggests wrongdoing, but a government listing can lend credibility faster than a product builds a track record. And as our look at credential and identity theft shows, a verified account that unlocks a full medical history is a prize in itself.

6. Why this reaches far beyond Medicare

Medicare is the largest US payer, so what it endorses tends to become the default. Three knock-on effects to plan for:

Health chatbots become records readers. OpenAI launched ChatGPT Health in January 2026 and Microsoft announced Copilot Health in March, per Healthcare Dive. Expect more staff to connect lab results to assistants, sometimes on work devices: a new strand of shadow AI.

Benefits programs will be pitched AI apps. With a Medicare billing pathway for AI services, employer plans and brokers will see the same products. Plan sponsors can carry HIPAA obligations, so HR and procurement need a view before staff are encouraged to connect records.

“Acting on your behalf” is becoming a design pattern. The patient’s-shoes argument mirrors the push to let AI agents act as their users, covered in our piece on the Personal Agent Protocol, while AI is entering clinical decisions too, as in Utah’s AI prescriptions. For the security side, see how an AI agent got past an Australian Medicare portal’s refusal.

7. A three-lane checklist: patients, employers and health-app builders

Tick what already applies; blanks are your to-do list. Not legal advice; plan sponsors should check obligations with counsel.

Five questions before you connect medical records to an AI appFive numbered cards. One: is the app supplied by my doctor or plan, or did I choose it? Two: is access one-time or ongoing, and how do I revoke it? Three: which AI model provider sees my data, and is it used for training? Four: is my data sold, shared for ads or used to set prices? Five: what happens to my data if I delete the account or the company is sold? Five questions before you press “Connect” Ask these of any app or chatbot that wants your medical records 1Did my doctor or plan supply this app, or did I pick it? (That decides if HIPAA follows.) 2Is access one-time or ongoing, and where exactly do I revoke it? 3Which AI model provider sees my data, and can it be used to train models? 4Is any of it sold, shared for advertising or used to set prices or premiums? 5What happens to my records if I delete the account, or the company is sold? Based on HHS, FTC and CMS guidance summarized in this article. Not legal or medical advice. delana.co
If an app cannot answer these five questions in plain language, it should not get your medical history.

Lane A: Patients, caregivers and families

  • ☐ Before connecting, find out whether the app came from your provider or plan, or whether you chose it. If you chose it, assume HIPAA no longer applies once records arrive.
  • ☐ Check the privacy policy for sharing, advertising, AI training and data sale.
  • ☐ Prefer one-time downloads to standing connections. If the app keeps ongoing access, write down where to revoke it, both in the app and in your patient portal.
  • ☐ Treat AI health answers as a second opinion to discuss with a clinician, never as a reason to skip urgent care.

Lane B: Employers, HR and benefits teams

  • ☐ Add health data to your acceptable-use policy for AI tools: staff should not upload their own or anyone else’s medical records into unapproved chatbots on company devices.
  • ☐ Ask AI health-app vendors for a data-flow diagram, model providers, retention periods and, where your plan requires it, a business associate agreement.
  • ☐ Confirm in writing that employee health data from wellness or AI apps is never shared back to the employer in identifiable form.
  • ☐ Check that your incident response plan covers a vendor’s health data breach, including FTC Health Breach Notification Rule timelines.

Lane C: Health-app and AI builders

  • ☐ Map every place health data goes (model provider, logs, analytics, support tools) and publish a plain-language version.
  • ☐ Default to the narrowest scope and shortest access duration that the feature needs. Make re-consent and revocation easy to find.
  • ☐ Contractually bar model providers from training on patient data, and verify the setting in each vendor console.
  • ☐ Run your breach and unauthorized-disclosure process against the FTC rule, including the 60-day notice window and the requirement to name third parties that received data.
  • ☐ Assume malicious actors, as one founder in the Slack warned: test account takeover, token theft and prompt injection through uploaded documents.

8. What to watch next

  • The TEFCA access rules. Whether vetted apps get patient-equivalent, ongoing access through national exchange is the decision with the biggest privacy impact. Watch for formal guidance or changes to the TEFCA framework.
  • Oversight. The advisory-committee question invites congressional letters or an inspector general review that could force the group into the open.
  • The Medicare AI billing program. Which AI services qualify and what evidence is required will show how far the App Library’s influence extends.
  • FTC enforcement. The updated Health Breach Notification Rule treats unauthorized sharing, not just hacking, as a breach. A first case involving an AI health assistant would set the tone for the sector.

Frequently asked questions

What is the CMS Slack workspace in the KFF Health News report?

A Slack workspace run by CMS under a Technology Working Group since August 2025. KFF Health News and CBS News report it grew to about 1,700 members, mostly tech executives and investors, and was used to coordinate a push for health apps and AI tools with federal officials.

What is the Medicare App Library?

A Medicare.gov directory, launched in April 2026, of vetted digital health apps, including conversational AI assistants. Apps must connect to a CMS Aligned Network, use IAL2/AAL2 identity verification, complete a security checklist and pass third-party and CMS review.

Does HIPAA protect medical records I share with an AI health app?

Usually not, if you chose the app yourself. HHS says a provider that sends records to an app it did not supply is not liable under HIPAA for the app’s later use. HIPAA applies only if the app is, or works for, a covered entity; otherwise the FTC Health Breach Notification Rule and state laws apply.

What does “standing in the shoes of the patient” mean for health apps?

It refers to a proposal, pressed by tech executives in 2026, that vetted apps requesting records through TEFCA should be treated as if they were the patient. Combined with a single consent, that would give apps ongoing access to records without separate gatekeeping by each provider.

Is the CMS Slack group legal?

That is disputed. The group’s code of conduct says it is not a federal advisory committee. Legal experts interviewed by KFF Health News said it resembles one, which would require public meetings and balanced membership under the Federal Advisory Committee Act. CMS declined to answer questions about its legality.

How can I check whether a health app is safe to connect to my records?

Ask whether your provider supplied the app, whether access is one-time or ongoing and how to revoke it, which AI provider sees the data and whether it trains on it, whether data is sold or used for ads, and what happens if you delete the account or the company is sold.

Bottom line: Portable medical records are a worthy goal, and AI may help patients understand their care. But the rules for how that data moves are being shaped quickly, largely by those who stand to benefit, and HIPAA usually stops at the app. Until public rules catch up, your safeguard is the questions you ask before you connect.


Sources

  • KFF Health News: AI, tech leaders are lobbying Trump health officials in a government-run chat room (9 Oct 2026)
  • CBS News: AI, tech leaders are lobbying Trump health officials in a government-run chat room (9 Oct 2026)
  • CMS: Medicare App Library
  • HHS: HIPAA FAQ on covered entity liability when a patient directs records to an app
  • FTC: Health Breach Notification Rule final rule (April 2024)
  • Healthcare Dive: CMS wants seniors to use AI for care navigation (13 Mar 2026)

Post navigation

Previous: Fired for Talking to the Safety Auditors? OpenAI’s Three Firings and the AI Whistleblower Rules Every Company Now Needs (AI Trends, 10 October 2026)

Florida Service Location

  • Cybersecurity, AI Consulting & IT Services in West Palm Beach, Florida
  • Cybersecurity, AI Consulting & IT Services in Sarasota, Florida
  • Cybersecurity, AI Consulting & IT Services in Port St. Lucie, Florida
  • Cybersecurity, AI Consulting & IT Services in Pembroke Pines, Florida
  • Cybersecurity, AI Consulting & IT Services in Naples, Florida
  • Cybersecurity, AI Consulting & IT Services in Miramar, Florida
  • Cybersecurity, AI Consulting & IT Services in Miami, Florida
  • Cybersecurity, AI Consulting & IT Services in Hollywood, Florida
  • Cybersecurity, AI Consulting & IT Services in Hialeah, Florida
  • Cybersecurity, AI Consulting & IT Services in Fort Myers, Florida
  • Cybersecurity, AI Consulting & IT Services in Fort Lauderdale, Florida
  • Cybersecurity, AI Consulting & IT Services in Cape Coral, Florida
  • Cybersecurity, AI Consulting & IT Services in Boca Raton, Florida
  • Cybersecurity, AI Consulting & IT Services in Coral Springs, Florida

Technology Services

  • Cybersecurity Compliance & Regulatory Framework Services
  • Workflow Automation & Systems Integration
  • Cloud Modernization & Technology Innovation Services
  • Fractional CTO & Expert Technical Consultants
  • Data Analytics, BI & Modern Data Platforms
  • Cyber Litigation Support & Digital Forensics
  • Cybersecurity Solutions & Zero Trust Architecture
  • AI Consulting & Agentic AI Solutions
  • Case Studies
  • Home
  • Contact Us
  • Privacy Policy
  • Cybersecurity Compliance & Regulatory Framework Services
  • Workflow Automation & Systems Integration
  • Cloud Modernization & Technology Innovation Services
  • Fractional CTO & Expert Technical Consultants
  • Data Analytics, BI & Modern Data Platforms
  • Cyber Litigation Support & Digital Forensics
  • Cybersecurity Solutions & Zero Trust Architecture
  • AI Consulting & Agentic AI Solutions

© Copyright 2025 Delana Technologies LLC