CMS Quietly Put One Office in Charge of Your Entire AI Vendor Stack

On 11 June, CMS published a four-page Federal Register notice creating the Office of Health Technology and Products. Eight divisions, more than 90 listed responsibilities, and a mandate spanning AI strategy, interoperability standards, claims system modernisation, Medicare.gov and federal provider directories.
If you missed it, you are not alone. It ran as a paragraph in the trade press next to bigger headlines about the physician fee schedule cut. But this one is not a rate change buried in a rule. It is a jurisdiction change — and jurisdiction changes move slower and hit harder, because nobody notices them until the vendor they depend on gets stuck in a new approval queue.
What the reorg actually does
Since March, HHS has been quietly redrawing the lines around who owns federal health technology policy. ONC, which used to hold interoperability certification and standards, was narrowed back to policy and standards work. The CTO, chief AI officer and chief data officer roles moved out from under ONC and back under the HHS CIO. And CMS, which used to execute against ONC’s standards, is now the one setting them — at least for anything touching Medicare, Medicaid or CHIP data.
Translate that into vendor terms: every AI-powered RCM platform, every clearinghouse, every prior-auth automation tool, every claims-scrubbing engine that touches CMS data now answers to a single consolidated office instead of navigating ONC and CMS separately. That is not automatically bad. Consolidation can mean faster certification cycles. It can also mean one office now has the authority to set the bar higher, slower or differently than the fragmented system it replaced — and there is no track record yet to tell you which.
Why this is a procurement problem before it is a policy problem
Practices and billing companies do not contract with ONC or CMS. You contract with a vendor, and you trust that the vendor’s certifications, data-sharing agreements and AI governance posture are solid. That trust used to rest on two federal counterparties. Now it rests on one — and that one office is less than three months old, still building out its rulemaking cadence, and explicitly tasked with writing AI governance frameworks for revenue cycle and clinical tools close to from scratch.
Nobody is going to send you a change notice for that. It shows up eighteen months from now as a recertification gap, a data-sharing agreement that needs renegotiating, or a vendor scrambling to meet a standard that did not exist when you signed the contract.
What to actually do with this
- Ask every AI or automation vendor in your stack one direct question: which federal certifications do you hold today, and which office issued them? If the answer references ONC certification from before March 2026, ask what their plan is for OHTP alignment. A vendor that has not thought about this is not watching its own regulatory exposure closely enough to be watching yours.
- Build a one-page vendor map. List every tool that touches Medicare or Medicaid claims or eligibility data, and note which are AI-driven. That is your OHTP exposure list — and almost nobody has built one, because the reorg reads as an org-chart story rather than an operations story.
- Do not wait for a mandate. OHTP’s first real signal will come through guidance documents and Federal Register notices, not headlines.
- Separate this from your G2211 and modifier 25 remediation. That is rate and code logic, handled at the claim level. This is vendor and infrastructure risk, handled at the contract level.
The 2030 view
Every RCM vendor pitch in the last two years has led with AI. What almost none of those pitches mention is who is approving the AI — and that question just got a lot more concrete. For years, “we’re HIPAA compliant” was the extent of the vendor diligence most practices bothered with. That bar is about to move.
The practices that get ahead of this will be the ones who know, cold, which of their vendors sit inside OHTP’s mandate — and who ask about it before the next contract renewal instead of after a claim gets rejected for a certification gap nobody flagged.
One quiet plumbing problem a week — the CMS deadline, payer behaviour or code change that reaches your claims before it reaches the headlines. Written by Mihir Rajput, Founder & CEO of Medalyze Medtech.
Subscribe on LinkedIn →
End-to-End Revenue Cycle Management: How Automation.
From patient intake to final payment posting, the healthcare revenue cycle is full of friction points. How end-to-end automation removes.
Read More
The System Isn’t Broken. It’s Backwards.
The U.S. healthcare system collects from patients and delays providers, and calls it normal. Why the revenue cycle is not.
Read More