What’s trending in AI on 11 October 2026: The AI story drawing the most attention this weekend is not a model launch. It is a chat room. A joint investigation by KFF Health News and CBS News, published on 9 October, describes a Slack workspace run by the Centers for Medicare & Medicaid Services (CMS) where about 1,700 members, mostly tech executives and investors, worked with federal officials to steer Americans toward managing their health care and medical records through commercial apps and AI chatbots. It previews how your medical history may soon flow into AI tools, and how much of that flow sits outside HIPAA. Below: what was reported, what CMS says, where HIPAA stops, and a three-lane checklist for patients, employers and app builders.
Key takeaways
- A government-run Slack became an industry channel. Created in August 2025, it grew to about 1,700 members, mostly from tech, according to KFF Health News.
- The policy wins were real. The Medicare App Library launched in April 2026, and in September CMS opened a path for apps to bill Medicare for AI services.
- The biggest fight is over records access. Vendors want vetted apps to stand in the patient’s shoes on TEFCA, with ongoing access after one consent.
- HIPAA usually stops at the app. If you chose the app, HHS says your provider is not liable under HIPAA for what it does next; the FTC’s breach rule is the main backstop.
- Governance is disputed. Experts say the group resembles a federal advisory committee that should meet openly; CMS calls it voluntary and declined to address its legality.
1. What KFF Health News and CBS News reported
The investigation, by Amanda Seitz, Maia Rosenfeld and Darius Tahir, centers on a workspace CMS manages under a “Technology Working Group.” Amy Gleason, former acting administrator of the U.S. DOGE Service and a senior CMS adviser, welcomed members in August 2025. It grew to about 1,700 people, dominated by tech leaders, investors and founders, with only a handful of patient advocates, physicians and hospital representatives. Named participants include Oura Health, Palantir and the venture firm 8VC, which the reporting links to Finn Kennedy, son of HHS Secretary Robert F. Kennedy Jr.
According to the report, invitations to closed meetings went out through the workspace, and industry used it to press for wider access to medical records. The key events in 2026:
- February: The FDA held an unpublicized listening session on conversational AI for patients, attended by at least 35 industry organizations; invitees included Microsoft, Anthropic, OpenAI, Apple and Google. The invitation reportedly went out through the Slack.
- February: A CMS Innovation Center official told industry the agency’s work could act as a sales channel for health apps.
- April: A CMS adviser said seniors would trust an app if Medicare.gov promoted it. The Medicare App Library went live days later.
- May: In a formal meeting, tech executives argued that apps requesting records should be treated as standing in the patient’s place.
- September: CMS Administrator Dr. Mehmet Oz announced a program allowing health apps to bill Medicare for AI services such as wearable device tracking, and officials suggested App Library members would be prioritized.
2. What CMS and its supporters say
Much is not in dispute. Getting records out of hospital portals and into tools patients actually use has been a bipartisan goal for over a decade. CMS frames its Health Technology Ecosystem as voluntary; its App Library page calls the industry pledge “a movement, not a mandate,” and Gleason told KFF the ecosystem is an open, voluntary technical collaboration. Oz has said the aim is to let industry take part in government-supported health care, and one participant described the push as a reaction to paternalism over patients’ own data.
The federal interest in AI here is also not new. At the HIMSS conference in March, Healthcare Dive reported, Oz said CMS wanted to give beneficiaries AI agents to help find doctors and compare Medicare Advantage plans, while acknowledging seniors’ distrust. A KFF survey cited in that coverage found only 31% of Medicare enrollees aged 65 and older trusted AI a great deal or a fair amount for accessing records and personalized advice.
What CMS has not done is answer the governance questions. According to the investigation, the agency declined to address whether the Slack is legal or how apps were chosen for the library, and the FDA did not respond to a request for comment.
3. The governance problem: an advisory committee by another name?
The Federal Advisory Committee Act (FACA) requires groups advising federal agencies to meet publicly and keep balanced membership. The Slack’s code of conduct says it is not such a committee. Joseph Daval, a former FDA lawyer now at Harvard Medical School, told KFF it resembles one, and that the law partly exists to prevent interest groups capturing agency policy.
For businesses, the practical point matters more than the legal one: rules shaping how tens of millions of people’s health data moves were discussed where the public could not see and patients had little voice. That pattern of fast, voluntary, industry-led standard-setting is spreading across AI policy, as in the commitments covered in our White House AI Accord explainer. Such frameworks move quickly but rarely carry enforcement.
The American Medical Association raised a separate concern about product quality. Its CEO, John Whyte, told KFF that some of these tools “just aren’t ready for primetime,” and that no one is liable when they get things wrong. Healthcare Dive noted in March that a Nature study found OpenAI’s consumer health tool often under-triaged serious cases.
4. Where HIPAA stops and your records keep going
The fight over standing in the patient’s shoes decides how much of your history an app can pull, and for how long. TEFCA is the national framework providers use to exchange electronic records. Vendors in the Slack pushed for vetted apps to be treated as the patient when requesting records, with a single consent opening a frictionless, ongoing pathway rather than a one-time download. KFF notes that one consultant advocating this sits on the board of an organization that does the vetting.
Here is the part most patients miss. HIPAA governs providers, health plans, clearinghouses and their business associates. It does not follow your data into an app you chose yourself. HHS guidance says that when a provider sends records to an app it did not supply, the provider “would not be liable under the HIPAA Rules” for what the app does next. From then on, protection is largely whatever the app’s privacy policy promises, plus a thinner layer of consumer law.
The main federal backstop is the FTC’s Health Breach Notification Rule. Updates finalized in April 2024 make clear it covers health apps, including those that draw data from multiple sources, and that a “breach” includes unauthorized disclosure, such as sharing with an advertiser without permission, not only hacking. People must be notified within 60 calendar days of discovery, and violations can bring civil penalties. But it is a notification rule: it applies after something goes wrong and sets few limits on what an app may collect.
| Where your data sits | Main rules that apply | Who enforces | What it does not do |
|---|---|---|---|
| Your doctor, hospital or health plan | HIPAA Privacy, Security and Breach Notification Rules | HHS Office for Civil Rights | Does not cover what a patient-chosen app does after it receives records |
| An app working for your provider (business associate) | HIPAA via a business associate agreement | HHS Office for Civil Rights | Only applies if the provider or plan supplied or contracted for the app |
| A consumer health app you connected yourself | FTC Health Breach Notification Rule, FTC Act, state health-privacy laws | FTC and state attorneys general | Mostly requires notice after a breach or unauthorized sharing; few federal limits on collection |
| A Medicare App Library listing | CMS listing requirements: IAL2/AAL2 identity checks, security checklist, data-source disclosure, third-party review | CMS (listing decisions) and reviewers such as DiMe or CARIN Alliance | CMS has not fully disclosed selection criteria; listing is not a HIPAA guarantee |
| The AI model or analytics vendor behind the app | Contracts with the app maker and the app’s privacy disclosures | Indirectly, through the app’s legal obligations | Patients usually cannot see or negotiate these terms |
This is the same consent problem we have covered with AI agents and SaaS integrations: one click grants broad, standing access that is rarely reviewed. See our posts on “Allow Always” agent permissions and OAuth attacks on the SaaS trust chain. An auto-refreshing medical-records connection is a high-value token.
5. What a Medicare App Library listing actually checks
To be fair to CMS, the App Library is not an open marketplace. It lists three use cases: digital check-in, conversational AI assistants that use secure access to medical history, and diabetes and obesity management. Apps must connect to a CMS Aligned Network, verify identity at IAL2/AAL2 levels, disclose data sources, complete a security checklist, offer trials if they charge, and label AI-generated output. They must operate consistently with HIPAA only when acting as a covered entity or business associate, which many consumer apps are not.
The reporting shows how new some listings are. Slothwise, launched this year, charges $9.99 a month to analyze medical records and had only a handful of app store reviews; its founder told KFF it is informational for now. Nothing suggests wrongdoing, but a government listing can lend credibility faster than a product builds a track record. And as our look at credential and identity theft shows, a verified account that unlocks a full medical history is a prize in itself.
6. Why this reaches far beyond Medicare
Medicare is the largest US payer, so what it endorses tends to become the default. Three knock-on effects to plan for:
Health chatbots become records readers. OpenAI launched ChatGPT Health in January 2026 and Microsoft announced Copilot Health in March, per Healthcare Dive. Expect more staff to connect lab results to assistants, sometimes on work devices: a new strand of shadow AI.
Benefits programs will be pitched AI apps. With a Medicare billing pathway for AI services, employer plans and brokers will see the same products. Plan sponsors can carry HIPAA obligations, so HR and procurement need a view before staff are encouraged to connect records.
“Acting on your behalf” is becoming a design pattern. The patient’s-shoes argument mirrors the push to let AI agents act as their users, covered in our piece on the Personal Agent Protocol, while AI is entering clinical decisions too, as in Utah’s AI prescriptions. For the security side, see how an AI agent got past an Australian Medicare portal’s refusal.
7. A three-lane checklist: patients, employers and health-app builders
Tick what already applies; blanks are your to-do list. Not legal advice; plan sponsors should check obligations with counsel.
Lane A: Patients, caregivers and families
- ☐ Before connecting, find out whether the app came from your provider or plan, or whether you chose it. If you chose it, assume HIPAA no longer applies once records arrive.
- ☐ Check the privacy policy for sharing, advertising, AI training and data sale.
- ☐ Prefer one-time downloads to standing connections. If the app keeps ongoing access, write down where to revoke it, both in the app and in your patient portal.
- ☐ Treat AI health answers as a second opinion to discuss with a clinician, never as a reason to skip urgent care.
Lane B: Employers, HR and benefits teams
- ☐ Add health data to your acceptable-use policy for AI tools: staff should not upload their own or anyone else’s medical records into unapproved chatbots on company devices.
- ☐ Ask AI health-app vendors for a data-flow diagram, model providers, retention periods and, where your plan requires it, a business associate agreement.
- ☐ Confirm in writing that employee health data from wellness or AI apps is never shared back to the employer in identifiable form.
- ☐ Check that your incident response plan covers a vendor’s health data breach, including FTC Health Breach Notification Rule timelines.
Lane C: Health-app and AI builders
- ☐ Map every place health data goes (model provider, logs, analytics, support tools) and publish a plain-language version.
- ☐ Default to the narrowest scope and shortest access duration that the feature needs. Make re-consent and revocation easy to find.
- ☐ Contractually bar model providers from training on patient data, and verify the setting in each vendor console.
- ☐ Run your breach and unauthorized-disclosure process against the FTC rule, including the 60-day notice window and the requirement to name third parties that received data.
- ☐ Assume malicious actors, as one founder in the Slack warned: test account takeover, token theft and prompt injection through uploaded documents.
8. What to watch next
- The TEFCA access rules. Whether vetted apps get patient-equivalent, ongoing access through national exchange is the decision with the biggest privacy impact. Watch for formal guidance or changes to the TEFCA framework.
- Oversight. The advisory-committee question invites congressional letters or an inspector general review that could force the group into the open.
- The Medicare AI billing program. Which AI services qualify and what evidence is required will show how far the App Library’s influence extends.
- FTC enforcement. The updated Health Breach Notification Rule treats unauthorized sharing, not just hacking, as a breach. A first case involving an AI health assistant would set the tone for the sector.
Frequently asked questions
What is the CMS Slack workspace in the KFF Health News report?
A Slack workspace run by CMS under a Technology Working Group since August 2025. KFF Health News and CBS News report it grew to about 1,700 members, mostly tech executives and investors, and was used to coordinate a push for health apps and AI tools with federal officials.
What is the Medicare App Library?
A Medicare.gov directory, launched in April 2026, of vetted digital health apps, including conversational AI assistants. Apps must connect to a CMS Aligned Network, use IAL2/AAL2 identity verification, complete a security checklist and pass third-party and CMS review.
Does HIPAA protect medical records I share with an AI health app?
Usually not, if you chose the app yourself. HHS says a provider that sends records to an app it did not supply is not liable under HIPAA for the app’s later use. HIPAA applies only if the app is, or works for, a covered entity; otherwise the FTC Health Breach Notification Rule and state laws apply.
What does “standing in the shoes of the patient” mean for health apps?
It refers to a proposal, pressed by tech executives in 2026, that vetted apps requesting records through TEFCA should be treated as if they were the patient. Combined with a single consent, that would give apps ongoing access to records without separate gatekeeping by each provider.
Is the CMS Slack group legal?
That is disputed. The group’s code of conduct says it is not a federal advisory committee. Legal experts interviewed by KFF Health News said it resembles one, which would require public meetings and balanced membership under the Federal Advisory Committee Act. CMS declined to answer questions about its legality.
How can I check whether a health app is safe to connect to my records?
Ask whether your provider supplied the app, whether access is one-time or ongoing and how to revoke it, which AI provider sees the data and whether it trains on it, whether data is sold or used for ads, and what happens if you delete the account or the company is sold.
Bottom line: Portable medical records are a worthy goal, and AI may help patients understand their care. But the rules for how that data moves are being shaped quickly, largely by those who stand to benefit, and HIPAA usually stops at the app. Until public rules catch up, your safeguard is the questions you ask before you connect.
Sources
- KFF Health News: AI, tech leaders are lobbying Trump health officials in a government-run chat room (9 Oct 2026)
- CBS News: AI, tech leaders are lobbying Trump health officials in a government-run chat room (9 Oct 2026)
- CMS: Medicare App Library
- HHS: HIPAA FAQ on covered entity liability when a patient directs records to an app
- FTC: Health Breach Notification Rule final rule (April 2024)
- Healthcare Dive: CMS wants seniors to use AI for care navigation (13 Mar 2026)
