Back to signals
Federal RegisterGuidance and regulationPublished May 20, 2026

Patient Protection and Affordable Care Act, HHS Notice of Benefit and Payment Parameters for 2027; and Basic Health Program

This final rule contains provisions to improve implementation of the Patient Protection and Affordable Care Act, including payment parameters and provisions related to the HHS-operated risk adjustment and risk adjustment data validation (HHS-RADV) programs, as well as 2027 user fee rates for issuers offering qualified health plans (QHPs) through Federally-facilitated Exchanges (FFEs) and State-based Exchanges on the Federal platform (SBE-FPs). This final rule also includes provisions related to civil money penalties (CMPs) for noncompliant issuers and other responsible entities; standards governing agents, brokers, and web-brokers; the expansion and codification of hardship exemption eligibility; implementation of the State Exchange Improper Payment Measurement (SEIPM); provider access standards and essential community provider standards for QHP certification; QHP certification of non-network plans; a prohibition on issuers from including routine non-pediatric dental services as an Essential Health Benefit (EHB); requirements related to defrayal for the cost of any State-required benefits in addition to the EHB; cost- sharing flexibilities for catastrophic and individual market bro

Open the source record
Tags
HIPAA, Rule, Health and Human Services Department, Centers for Medicare & Medicaid Services, breach notification, health IT
Related exam domains
CISSP 1: Security and Risk Management; CISSP 4: Communication and Network Security; CISSP 7: Security Operations; CISM 2: Information Security Risk Management; CISM 3: Information Security Program
Source record id
2026-10050
First seen by InfoSec Signals
9/23/2026

Exam domain labels come from a keyword heuristic and are study hints, not an official mapping. The summary is the publisher's own text, shortened; the linked record is authoritative.