The Centers for Medicare and Medicaid Services (CMS) and the Centers for Disease Control and Prevention (CDC) have launched a request for information to modernize the Clinical Laboratory Improvement Amendments (CLIA) of 1988, with particular attention to cybersecurity and artificial intelligence concerns. The agencies are accepting public comments through September 14, 2026, to guide future regulatory updates for clinical laboratories across the United States.
The CLIA regulations, originally enacted in 1988 and promulgated in 1992, established federal oversight of clinical laboratories to ensure accuracy and reliability of patient test results. While certain elements have been updated over the years, the agencies recognize that substantial revisions are needed to reflect current knowledge and technological advancements in laboratory testing. The request for information covers multiple topics including breath testing, laboratory procedures, emergency preparedness, cybersecurity, and artificial intelligence applications.
On the cybersecurity front, CMS and CDC acknowledge that clinical laboratories face significantly expanded threats as they increasingly rely on digital systems such as Laboratory Information Systems (LIS), Electronic Health Record (EHR) integration, automated diagnostic devices, and remote access capabilities. The agencies are seeking information on current laboratory cybersecurity practices related to protecting patient data and operations, user identity and access management, remote access from overseas entities, restrictions on ports and IP addresses, incident response plans, and staff training programs. While many laboratories must comply with HIPAA Security Rule requirements, the agencies recognize that gaps exist in current protections.
The artificial intelligence component of the request addresses a technology that did not exist when CLIA was originally enacted. CMS and CDC are particularly concerned about risks including model corruption, hallucinations, and system compromises that could affect testing accuracy and reliability. The agencies are seeking detailed information about algorithms and AI tools used in postanalytic analysis, circumstances where software interprets test results and histopathology slides, methods used to verify AI tool performance, and additional technology considerations for high complexity tests.
Laboratories and cybersecurity professionals should review the request for information and consider submitting comments before the September 14, 2026 deadline. Input from the field will directly inform how federal regulators address emerging cybersecurity risks and AI implementation in clinical laboratory settings. Organizations should document their current practices, challenges, and recommendations to help shape regulations that balance innovation with patient safety and data protection.
Source: https://www.hipaajournal.com/hhs-seeks-input-potential-clia-updates/


