Five regulatory shifts landed on healthcare boards this year, and every one of them asks for documentation. Here is what changed, who feels it most, and what the boards handling it well are doing differently.
Something shifted in healthcare governance this year, and it arrived quietly from five directions at once.
- CMS published a new measure that puts your board’s governance behavior on a public website.
- HHS is finalizing a HIPAA Security Rule overhaul that ends two decades of compliance flexibility.
- State legislatures put AI laws into effect January 1 that name health systems as legally accountable when AI goes wrong.
- The Joint Commission moved its safety framework from periodic attestation to continuous performance.
- HRSA is actively auditing FQHC boards on consumer majority requirements.
Every one of them asks the same question. Can you show us the record? For most healthcare boards, that question is uncomfortable. The oversight work is happening. Directors ask hard questions, committees meet, decisions get made. Then someone asks for timestamped evidence and the search begins across email threads, shared drives, and three versions of the same PDF.
Below is what changed, and what it now takes to answer for it.
Key Takeaways
- CMS now scores hospital boards across five governance domains and will publish those scores publicly on Care Compare this fall
- The HIPAA Security Rule overhaul removes prior flexibility, making encryption, MFA, and vendor risk assessment mandatory with direct board-level oversight
- New state AI laws hold health systems accountable for AI use boards often can't see, including tools directors use informally in meeting prep
- The Joint Commission has shifted from periodic attestation to continuous performance monitoring, changing what boards need to document and how often
- HRSA is actively enforcing consumer-majority board composition rules for FQHCs, tracking member patient status alongside Medicaid eligibility churn
1. Board Governance Score is Going Public
The CMS Patient Safety Structural Measure looks past patient outcomes. It asks whether your governing board has the structures and culture to produce safe outcomes consistently, and it scores you across five domains: leadership commitment, strategic planning, culture of safety, accountability and transparency, and patient and family engagement. Each domain is worth one point, and there is no partial credit. Four details set it apart:
- CMS defines “governing board” as the highest board of the specific hospital, along with its documented governance structures. A quality subcommittee or a corporate parent will not satisfy it.
- Hospitals completed Spring 2026 attestation covering calendar year 2025.
- Scores post publicly on CMS Care Compare this fall.
- Starting in FY 2027, failure to report ties directly to reduced Medicare reimbursement.
For the board administrator assembling that attestation, the work is heavy: safety huddle records, accountability frameworks, board minutes, escalation pathways, committee evidence. Most of it lives in different places, and pulling it into one defensible submission under deadline can eat weeks. The teams that finish fastest captured governance activity in a structured system all along, the same habit that improves audit readiness across every other review cycle.
Your governance score will be public this fall. If you’re not already documenting board-level safety oversight in a structured system, you’re building the record retroactively, and that shows.
If a reporter pulls your PSSM score this fall, could you explain with documentation what your board reviewed, when, who owned it, and what changed as a result?
2. HIPAA Cybersecurity Oversight is Now the Board's Responsibility
The HIPAA Security Rule is getting its biggest overhaul since 2003. The final rule is expected in 2026 with an implementation window of 180 days to one year, and it removes the “addressable” designation that gave organizations flexibility for two decades.
Mandatory controls replace it:
- Encryption of all ePHI at rest and in transit
- Multi-factor authentication for every system touching ePHI
- 72-hour incident notification
- Annual penetration testing and vulnerability scanning
- Documented vendor risk assessment for every business associate
OCR wants evidence that your board was informed, engaged, and exercising real oversight. Policies sitting in the IT department will not carry the day on their own. Healthcare enforcement attorneys working on 2026 readiness point to the same markers: board-level dashboards tracking security performance, briefings that connect threat intelligence to control posture, and clean documentation of board accountability for vendor oversight. Those are governance requirements, and they sit inside the board’s role in cybersecurity risk management.
In 2024, reported healthcare breaches exposed protected health information belonging to an estimated 82% of the U.S. population. HIPAA violations now carry civil, criminal, and reputational weight at once, and the board sits inside that exposure.
For general counsel, the test is simple. If OCR opened an investigation today, how fast could you produce proof that the board received substantive cybersecurity briefings, asked questions, and acted? Boards running on email and PDF attachments rarely like their own answer.
3. Boards are Accountable for AI They Can't See
Of every pressure on healthcare boards this year, AI carries the widest gap between accountability and infrastructure. As of January 1, 2026, state AI laws took effect that reach health systems directly.
- California’s AB 489 holds deployers accountable when AI creates the impression that patients are dealing with licensed clinicians.
- Texas’s TRAIGA requires written patient disclosure before AI is used in diagnosis or treatment.
- California’s SB 942 and AB 2013 add transparency and training data disclosure requirements. Federal guidance remains in flux, and state enforcement is moving anyway. Health systems operating across state lines now manage a compliance map that updates every legislative session. Boards carry legal accountability for AI running inside their organizations, and most have no inventory of what is deployed, no approval workflow for new tools, and no oversight cadence.
The Healthcare and Public Health Sector Coordinating Council’s AI Cybersecurity Task Group, a coalition that includes 115 healthcare organizations, published 2026 guidance on what board-level AI governance requires:
- A complete inventory of all AI systems with documented data dependencies
- Defined roles and clinical oversight across the full AI lifecycle
- Structured vendor vetting with procurement governance standards
- Documented board review and approval of AI adoption decisions
- An auditable record of oversight activity
PwC’s 2025 Annual Corporate Directors Survey found that almost half of healthcare industry directors say management provides inadequate information on risks associated with AI use, a higher share than any other industry surveyed. If your board is starting from scratch, how to build an AI governance framework is the practical place to begin.
The second exposure is inside your own boardroom. 92% of directors already use AI to prepare for meetings, most with no policy governing that use, and board packets end up in public models. So while your organization writes AI policy for clinicians, the same AI security risks are already in play where your directors prepare.
4. Continuous Compliance is Already Here
The Joint Commission’s shift from National Patient Safety Goals to National Performance Goals changes what boards demonstrate and how often. Safety compliance used to be a state you reached and attested to. The new framework asks you to demonstrate it continuously, through governance structures that produce evidence as a byproduct of daily operations.
NCQA is shortening verification timelines and requiring continuous monitoring of credentials and exclusions. The CMS measure assesses whether governance is embedded in how the organization actually runs.
For board administrators, this reshapes the job. Meeting preparation, safety reporting, cyber briefings, AI oversight, and committee accountability can’t live in disconnected systems that require manual assembly before each cycle. The documentation has to exist because the process created it, starting with board meeting minutes that capture decisions and owners the first time.
The organizations managing this transition well built governance infrastructure into the center of how the board works week to week, so the evidence exists before anyone asks for it.
5. FQHCs: Board Composition is an Active Enforcement
Community health centers funded under HRSA Section 330 must maintain a governing board where more than half the members are patients of the center. The requirement is old. The enforcement is current, and the documentation burden is real. Consumer majority compliance means tracking composition every cycle: attendance records, member status verification, committee assignments, and term management. Health centers running that on spreadsheets and email carry a quiet drag that turns into acute risk the week a site visit lands.
The OBBBA’s Medicaid eligibility changes add a second layer. FQHCs that lose Medicaid-covered patients due to redetermination churn face pressure on both their patient population and their board composition simultaneously, because the consumer majority requirement tracks against who is actively a patient of the center. A health center managing board composition manually while navigating patient eligibility shifts is managing two documentation burdens with one spreadsheet.
The Compliance Model Itself Has Changed
For decades, compliance was something you achieved at defined intervals. Pass the audit, produce the documentation when asked, return to normal operations.
That model is finished.
CMS, the Joint Commission, OCR, HRSA, and state regulators have converged on a single expectation. Governance should be continuous, documented, embedded, and producible on demand.
The organizations handling this well restructured how governance work gets done, so defensible evidence comes out of the process itself. Financial pressure sharpens the urgency. Boards managing margin compression, payer mix shifts, and rising uncompensated care are absorbing all of it while governance scrutiny rises, and the infrastructure that answers both is the same.
Four Questions Your Board Should Be Able to Answer Today
These are the questions regulators, accreditors, and enforcement agencies can now ask:
- 1 Can you demonstrate that your board actively oversaw patient safety, with documented structures, accountability, and escalation pathways across the last reporting cycle?
- 2 Can you produce board-level documentation showing cybersecurity risk oversight was active and current before the HIPAA final rule publishes?
- 3 Does your board have a formal inventory and documented approval record for every AI system deployed in your organization?
- 4 Can you show continuous, real-time evidence of board engagement on demand?
These are the questions regulators, accreditors, and enforcement agencies can now ask:
- Can you demonstrate that your board actively oversaw patient safety, with documented structures, accountability, and escalation pathways across the last reporting cycle?
- Can you produce board-level documentation showing cybersecurity risk oversight was active and current before the HIPAA final rule publishes?
- Does your board have a formal inventory and documented approval record for every AI system deployed in your organization?
- Can you show continuous, real-time evidence of board engagement on demand?
Most boards answer no to at least one. The oversight happened, but the record to prove it lives in too many places, which is why the governance questions that matter most are the hardest ones to answer.
How the Governance Infrastructure Comes Into Play
Every requirement above rewards the same thing. One governed record your board actually works inside.
Move creation, review, distribution, minutes, votes, and committee work into a single secure system, and the audit trail builds itself. Directors prepare in one place. Approvals carry timestamps. Committee evidence sits where you can find it in February when HRSA calls.
That is also how your board stops depending on one person’s memory for governance continuity. Ask OnBoard AI what was decided, what was assigned, and what was committed to, and the answer comes from your board’s own history without a packet ever reaching a public model. Your directors get the recall. They keep the judgment. And the compliance record holds up when someone asks to see it.
See how healthcare boards run governance on a single secure record. Book a demo of OnBoard.
About The Author

- Ben Blanc
- Ben Blanc is the Brand Narrative Manager at OnBoard, where he shapes the company's public voice across social media, live programming, and external communications. With 18+ years of experience spanning media, operations, and marketing, he brings a blend of storytelling instinct and editorial discipline to B2B SaaS. Ben has spent his career turning complex ideas into clear, accessible, and actionable narratives. At OnBoard, his focus is on thought leadership grounded in real customer proof, credible perspective, and content worth paying attention to.
Latest entries
OnBoard InsightsAugust 18, 20265 Rules Reshaping Healthcare Board Governance in 2026
OnBoard InsightsAugust 13, 2026Inside the AI Vision Keynote: Where AI in the Boardroom Goes Next
OnBoard InsightsJuly 22, 2026What AI Due Diligence Reveals About Your Own Board
OnBoard InsightsJuly 9, 2026Governance Continuity: Why Boards Must Prepare Now