Skip to Main Content
02/24/2025|7 minute read

As a new year begins, along with a new presidential administration, we have summarized below some of the key updates in the regulatory landscape of the healthcare technology industry.

Artificial Intelligence

  • The Trump administration rescinded a major executive order from President Joe Biden regarding the responsible use of artificial intelligence (AI) in healthcare.
  • During the final days of the Biden administration, the U.S. Department of Health and Human Services (HHS) published its AI Strategic Plan, though its weight is called into question with the arrival of the new administration.
  • The U.S. Food and Drug Administration published draft guidance on incorporating AI into premarket submissions.

Impact of Trump Administration’s Executive Order on Artificial Intelligence

The Trump administration rescinded the Biden administration’s Executive Order 14110 (Biden AI EO), which was the impetus for healthcare organizations to agree to fair, appropriate, valid, effective and safe (FAVES) principles in the use AI and called for a coordinated government effort to establish guardrails around the use of AI in healthcare.

In its place, Trump issued a short executive order on AI (Trump AI EO) that does not contain its own principles on AI but instead directs various officials to review orders and actions to ensure they adhere to Section 2 of the Trump AI EO, which states, “It is the policy of the United States to sustain and enhance America’s global AI dominance in order to promote human flourishing, economic competitiveness, and national security.” The Trump AI EO also requires, within 60 days of the date the order was issued, the Office of Management and Budget director to revise certain memoranda on federal AI governance and federal AI acquisition to ensure they are consistent with the above policy, and within 180 days, certain positions and agencies within the administration must submit an action plan to achieve the policy in Section 2.

The FAVES principles, as well as the HTI-1 Final Rule that requires transparency by certified health IT developers in the use of AI, previously analyzed here, could be impacted by the rescission. It remains to be seen what impact the Trump AI EO will have on the policies and actions taken in response to the Biden AI EO to implement, safeguard and adopt AI within the healthcare industry.

HHS Strategic Plan for Use of Artificial Intelligence

On Jan. 10, in one of the final moves before Biden left office, HHS published its Strategic Plan for the Use of Artificial Intelligence in Health, Human Services, and Public Health (Strategic Plan), which set forth the goals of HHS — one of the top governmental users of AI — in fostering and guiding the use of AI in the healthcare system, including insight on HHS’ plan for encouraging the establishment of guardrails around the quickly evolving healthcare technology landscape, as well as its priorities regarding the ever-evolving adoption of AI.

The Strategic Plan is focused on four key goals across seven domains:

  1. Catalyzing health AI innovation and adoption to unlock new ways to improve people’s lives
  2. Promoting trustworthy AI development and ethical and responsible use of AI to avoid potential harm
  3. Democratizing AI technologies and resources to promote access
  4. Cultivating AI-empowered workforces and organizational cultures to effectively and safely use AI.

Key aspects of the Strategic Plan include the following already implemented or future goals of HHS:

  • Increasing funding for and supporting the adoption of AI and the development of AI for medical products
  • Issuing guidance and regulations for, as well as clarity on, the use of AI in federal agencies
  • Democratizing AI technologies and resources by promoting collaborative engagement with the public and aligning data standards across industries
  • Continuing rulemaking to incorporate AI technology into existing and future regulations
  • Promoting the safe and responsible use of AI by state, local, tribal and territorial governments
  • Identifying and utilizing pathways for using AI to benefit public health, including improving threat detection, optimizing allocation of limited resources, improving efficiencies for public health operations and enhancing health equity among underserved populations, including via the use of generative AI
  • Addressing cybersecurity risks imposed by the adoption of AI, supporting the standardization and alignment of best practices with regard to cybersecurity governance (including developing guidelines on maintaining operations after an AI system is compromised), encouraging developers to implement privacy by design, and developing guidelines for balancing privacy and security goals with the inclusion of AI models.  

At this time, it Is unclear how the Strategic Plan as published will be implemented or whether HHS will shift direction. As of Jan. 20, the former assistant secretary for technology policy and national coordinator for health information technology (ASTP), who implemented regulations and guidance on the use of AI during the Biden administration, including the Strategic Plan, is no longer in that position (no other ASTP has been named). On Feb. 13, Robert F. Kennedy Jr. was confirmed as HHS secretary, and it remains to be seen what impact this will have on HHS’ AI objectives. Finally, as of this writing, the Strategic Plan is no longer listed on the ASTP website, but it has not been formally rescinded.

FDA Draft Guidance on AI-Enabled Devices and Marketing Submission Recommendations

On Jan. 7, the U.S. Food and Drug Administration (FDA) issued a draft guidance, Artificial Intelligence-Enabled Device Software Functions: Lifecycle Management and Marketing Submission Recommendations, which provides recommendations for AI-enabled devices throughout the total product life cycle. Specifically, the document gives clarity on which devices the FDA considers to be “AI-enabled devices” and provides sponsors with guidance on how the FDA plans to regulate these devices by addressing the types of information to include in a premarket submission.

The draft guidance provides details on what information sponsors should include in an AI-enabled device marketing submission, why the specific information should be included and where sponsors should provide the information within a marketing submission. The FDA recommends including the following information:

  • Device Description: Sponsors should provide a detailed device description that includes a statement that AI is used in the device, the device inputs and outputs, an explanation of how AI is used to achieve the device’s intended use, a description of the device’s intended users and environment, and any installation and maintenance procedures.
  • User Interface: Sponsors should provide a clear description of the device workflow, including the information provided to users and how the information is presented to users through a graphic representation, written description, demonstration video or overview of the operational sequence of the device.
  • Labeling: Sponsors should follow appropriate labeling requirements for the specific device and ensure information is provided to users in an appropriate format and reading level.
  • Risk Assessment: Sponsors should provide a comprehensive risk assessment in their submission, which includes a risk management plan that addresses risks that occur throughout the life cycle of the device, including installation, maintenance and any other risks associated with user interpretation of the results of a device.
  • Data Management: Sponsors should include a description of how data were collected, limitations of the dataset, the data-cleaning process, a description of the reference standard (if used), data annotation, data storage and how the data is representative of the intended use population.
  • Model Description and Development: Sponsors should include information on the AI model’s design, which includes a description of the model architecture and features and how the model was trained.
  • Performance Validation: Sponsors should provide objective information to characterize the model’s performance based on its intended use. A submission should include the model’s validation methods, study protocols and study results.
  • Device Performance Monitoring: Sponsors should provide information regarding their performance-monitoring plans, which may include a description of data collection and analysis methods, a description of the software life cycle process, a plan for deploying updates and corrective actions, and any procedures for communicating the results of performance monitoring with users.
  • Cybersecurity: Sponsors should include any considerations unique to AI cybersecurity, an explanation of how cybersecurity testing is appropriate to address the risk associated with the model and a description of controls implemented to address data vulnerability.
  • Public Submission Summary: Sponsors should include specific information describing the characteristics of the devices to support public understanding of the AI-enabled devices, including a statement that AI is used in the device, how AI is used as part of the device’s intended use, a description of the class of model, a description of the development and validation of datasets, a description of statistic obedience prediction, and a description of how the model will be updated and maintained over time.

In addition, the FDA discusses strategies to address transparency and bias throughout the life cycle of AI-enabled devices. The FDA is requesting public comments to the draft guidance by April 7. However, this guidance is subject to review under the Trump AI EO, which requires a review of all existing AI policies, directives, regulations and actions taken by the Biden administration.[1]

Telehealth

Tales from the Never-Ending Telehealth Cliff

As noted in the BakerHostetler Health Care Year in Review, Congress in late December again extended, through March 31, many of the Medicare telehealth flexibilities initially implemented during the height of the COVID-19 pandemic in 2020. Without the extension, many regulatory flexibilities that have enabled the provision of care via telehealth since the COVID-19 pandemic would have expired, impacting access to care for patients and digital operations for healthcare providers.

Though the extension ostensibly indicates a level of bipartisan support, with a new administration and such a tight deadline, it’s not clear whether the telehealth flexibilities will eventually be made permanent. If not made permanent (or extended again), Medicare telehealth coverage will revert to much more restrictive conditions that limited the reach of care that had increased during the pandemic. Industry stakeholders continue to advocate for making such telehealth flexibilities permanent.

Drug Enforcement Agency Issues a Trio of Telemedicine Prescribing Rules

As we previously reported, the United States Drug Enforcement Administration (DEA) issued a third extension to enable telemedicine prescribing flexibilities to remain in place through 2025. On Jan. 17, the DEA issued two final rules and also a proposed rule addressing issuing prescriptions for controlled substances via telemedicine. One finalized rule permits remote prescription via telehealth, including via audio-only visits, for a six-month buprenorphine supply. The other finalized rule allows Department of Veterans Affairs (VA) practitioners to prescribe controlled substances over telemedicine for VA patients without in-person exams so long as another VA practitioner had, at any time, previously evaluated the patient in person. Notably, the DEA announced on Feb. 19 that, as a result of the Trump administration’s Regulatory Freeze Pending Review, the effective date for both rules is delayed to March 21.

The proposed rule would establish a long-gestating “special registration” system for permitting the prescription of controlled substances via telemedicine without an in-person evaluation. At this time, it is unclear where the Trump administration stands on telemedicine policy. However, the American Telemedicine Association has urged Trump to immediately withdraw the DEA proposed rule over concerns that as proposed it would create an unworkable framework that could not be operationalized.

New Updates to the Information Blocking Rule

We previously analyzed the Health Data, Technology, and Interoperability: Patient Engagement, Information Sharing, and Public Health Interoperability proposed rule, which would have codified a nonexhaustive list of practices that would constitute information blocking and made several changes and additions to the exceptions to the Information Blocking Rule (IBR). However, the Health Data, Technology, and Interoperability: Trusted Exchange Framework and Common Agreement final rule largely did not address the IBR and focused on final changes to the Trusted Exchange Framework and Common Agreement. On Dec. 17, 2024, the Health Data, Technology, and Interoperability: Protecting Care Access final rule was published but again did not address many proposals and comments regarding the IBR; instead, it made minor modifications to the existing Privacy and Infeasibility exceptions to the IBR and finalized the new Protecting Care Access exception, which is aimed at protecting decisions not to disclose health information to avoid the risk of exposing a patient, provider or facilitator of lawful reproductive healthcare to potential legal action.

We will continue to monitor major legislative and regulatory changes impacting the healthcare industry.


[1] Exec. Order No. 14179, Removing Barriers to American Leadership In Artificial Intelligence (Jan. 23), https://www.whitehouse.gov/presidential-actions/2025/01/removing-barriers-to-american-leadership-in-artificial-intelligence.


Featured Insights