Every January brings a fresh round of “top trends” lists, and health IT is no exception. But heading into 2026, the conversation among CIOs, CISOs, and chief health information officers feels less speculative than it did even two years ago. Generative AI has moved from pilot projects to production workflows in many health systems. TEFCA has gone from a policy abstraction to a live network moving hundreds of millions of records. And the Change Healthcare attack is no longer breaking news — it’s a case study that shapes budget conversations in nearly every IT steering committee.
None of this means the picture is settled. Budgets remain tight, staffing gaps persist, and regulatory direction on AI oversight is shifting under the current administration. What follows is a grounded outlook — built on 2024–2025 developments and early 2026 signals — on where health IT leaders appear to be focusing their attention this year, and the open questions that will determine how those priorities actually play out.
Why does AI scaling look different in 2026 than it did a year ago?
Through 2023 and 2024, most health system AI activity centered on pilots: a handful of departments testing ambient documentation tools, a small cohort of clinicians using AI-assisted scribes, isolated proofs of concept for predictive models. By 2025, several large systems — including academic medical centers and multi-hospital networks — had moved ambient AI scribes into broad clinical use rather than limited trials, and industry surveys have pointed to AI and automation as the leading area where health IT leaders expect to increase spending in 2026.
The shift in focus isn’t just about adoption volume; it’s about governance catching up to deployment. Health systems that spent 2023–2024 asking “should we use this AI tool” are now asking “how do we manage the twenty AI tools already running inside our EHR, our revenue cycle, and our call center.” That includes:
- Establishing AI governance committees that sit alongside (or inside) existing clinical informatics and IT governance structures
- Inventorying “shadow AI” — tools clinicians or departments have adopted informally, outside a formal vetting process
- Building processes to monitor model performance over time, since a predictive model validated on one population can drift or underperform on another
Regulatory direction here is unsettled. The Office of the Assistant Secretary for Technology Policy (ASTP), formerly ONC, proposed the HTI-5 rule in late 2025, which would roll back some Biden-era AI transparency requirements — including “model card” disclosure requirements for predictive decision-support tools embedded in certified health IT — while also proposing new FHIR-based API pathways intended to support AI-enabled interoperability. ASTP’s stated rationale is that the existing transparency mandate lacked evidence of improving patient care, but provider and patient-advocacy groups have pushed to preserve at least some disclosure requirements. However this rule is finalized, it signals that federal AI oversight for health IT is still being actively negotiated, not settled — which means health system AI governance policies written in 2026 should be built to flex as federal requirements change.
Where does TEFCA and FHIR-based interoperability stand heading into 2026?
Interoperability has quietly graduated from “compliance checkbox” to genuine infrastructure. The Trusted Exchange Framework and Common Agreement (TEFCA), overseen by ASTP through the Recognized Coordinating Entity, saw a sharp acceleration in actual usage during 2025 that carried into 2026: exchange volume grew from roughly 10 million records in January 2025 to nearly 500 million by early 2026 and, by HHS’s own account, past 1 billion records exchanged by mid-2026, according to figures published by HHS. By late 2025, more than a dozen Qualified Health Information Networks (QHINs) had been designated, connecting tens of thousands of participating organizations.
A few threads are worth watching in 2026:
- USCDI v3 conformance. Data created or captured for TEFCA exchange is expected to conform to USCDI version 3 data classes and vocabulary as of January 1, 2026, which pushes health systems and their EHR vendors to keep pace with an expanding standard data set.
- New exchange purposes. TEFCA’s use cases have broadened beyond basic treatment-related queries — 2025 saw new standard operating procedures approved for purposes like government benefits determination, with agencies such as the Social Security Administration connecting through participating QHINs.
- FHIR as the connective layer. Much of the practical interoperability work inside health systems in 2026 is less about TEFCA itself and more about maturing FHIR-based APIs — for patient access, provider-to-provider exchange, and increasingly as the data layer that AI tools depend on. An AI model is only as useful as the data feeding it, and fragmented or incomplete records undercut both clinical AI and basic care coordination.
It’s reasonable to expect continued growth in TEFCA volume through 2026, but adoption remains uneven across the industry — smaller and rural systems in particular still report resource constraints in standing up full interoperability programs, and how quickly that gap closes is genuinely uncertain.
What does cybersecurity resilience mean after Change Healthcare?
The February 2024 ransomware attack on Change Healthcare remains the reference point for healthcare cybersecurity planning heading into 2026, and for good reason: it ultimately affected an estimated 192.7 million individuals, by the U.S. Department of Health and Human Services’ Office for Civil Rights count — the largest healthcare data breach on record — and disrupted claims processing and payments for a large share of U.S. hospitals for weeks.
The lasting effect isn’t just heightened awareness; it’s a shift in what “cybersecurity readiness” is understood to mean. Where earlier programs emphasized perimeter defense and breach prevention, 2026 planning conversations lean more heavily toward resilience and continuity — the assumption that a critical vendor or system may go down, and the question of how care delivery and cash flow keep functioning anyway. Concretely, that’s showing up as:
- Third-party and vendor risk assessments that treat clearinghouses, revenue-cycle intermediaries, and cloud EHR hosts as potential single points of failure, not just IT vendors
- Downtime and continuity planning that’s tested through tabletop exercises rather than left as a binder on a shelf
- Continued investment in zero-trust architecture and medical device security, since connected clinical devices remain a common attack surface
- Budget allocations for cybersecurity that industry estimates put at a meaningfully larger share of technology spend than in years past, though exact figures vary by organization size and prior investment
Healthcare cybersecurity incidents overall may have affected somewhat fewer organizations in 2025 than in the peak years before it, per some industry trackers, but the scale and clinical impact of individual events — including reported disruptions to patient care during major attacks — argue against reading that as a sign the underlying risk has eased. Ransomware groups continue to view healthcare as a high-leverage target precisely because outages carry patient-safety stakes that increase pressure to pay.
Is clinician experience finally improving, or just shifting?
Documentation burden and EHR-related burnout have been named priorities for health IT leaders for years, but 2026 is the first stretch where there’s a reasonably large body of real-world data — not just vendor claims — suggesting ambient AI documentation tools are moving the needle. Published research on ambient documentation technology has associated its use with reductions in reported burnout symptoms and improvements in clinicians’ perceived well-being, and multiple health systems that deployed ambient scribes at scale in 2025 have reported measurable reductions in time spent on notes and in after-hours EHR use (“pajama time”).
In CHIME’s 2025 CIO survey, more than half of respondents pointed to clinical documentation burden as the EHR-related workflow challenge they most hoped AI could address — which tracks with how quickly ambient scribe deployments have expanded from single departments to health-system-wide rollouts at organizations like Mount Sinai and The Permanente Medical Group.
That said, a few honest caveats belong in any 2026 outlook:
- Burnout is multi-causal. Documentation is one driver among many (staffing ratios, inbox volume, prior authorization burden, productivity expectations), so easing one contributor doesn’t guarantee overall burnout scores fall.
- Governance and accuracy oversight still matter. Ambient AI output typically requires clinician review before it becomes part of the legal record, and health systems are still refining how much of that review can safely be streamlined without introducing documentation errors.
- Rollout unevenness. Ambulatory settings have generally moved faster than inpatient and emergency department settings, where workflows are more complex and integration is harder.
The realistic 2026 framing is that ambient AI and related workflow tools are a genuine, evidence-supported lever for clinician experience — not a solved problem, but one of the few areas where the data trend looks encouraging rather than merely promised.
How is cost pressure reshaping IT decision-making?
Health system margins remain under strain heading into 2026, driven by a mix of labor costs, supply costs, and a persistent gap between the cost of care and government reimbursement rates. That pressure flows directly into IT budget conversations, but not in a uniform direction: some health system CIOs report modest budget growth focused narrowly on AI and cybersecurity, while others describe flat or shrinking overall technology budgets even as specific priority areas get protected or expanded.
A few patterns show up repeatedly in how IT leaders are describing 2026 planning:
- Application rationalization. Consolidating redundant or legacy systems — sometimes described as reducing technical debt — has moved up as a stated priority, both to cut licensing and support costs and to reduce the attack surface tied to unmaintained software.
- ROI scrutiny on AI investment. As AI spending grows, IT and finance leaders are asking harder questions about measurable return — reduced documentation time, fewer denied claims, faster prior authorization turnaround — rather than approving pilots on promise alone.
- EHR optimization over EHR replacement. With many systems already on a small number of major EHR platforms, 2026 spending in this category leans toward migrations, upgrades, and workflow optimization rather than wholesale platform switches, which remain expensive and disruptive.
- IT’s own cost growth. Ironically, technology itself — software licensing, cloud hosting, and outsourced IT services — is frequently cited as one of the faster-growing expense categories in health system budgets, adding pressure to demonstrate that new investments pay for themselves.
None of this is likely to resolve cleanly in 2026. Reimbursement policy, labor markets, and the pace of AI vendor consolidation are all moving pieces that could push health system IT budgets in either direction over the course of the year.
What should health IT leaders watch for the rest of 2026?
Pulling these threads together, a few open questions seem likely to define how the year actually unfolds rather than how it was projected in January:
- Whether the HTI-5 rule and other pending ASTP actions land in a form that meaningfully changes AI transparency and certification obligations for health IT developers and, by extension, provider organizations
- Whether TEFCA exchange volume continues its steep 2025 growth trajectory or plateaus as easier integrations are exhausted and harder, long-tail connections remain
- Whether ambient AI and workflow-automation tools produce durable clinician satisfaction gains once the novelty period passes and broader inpatient rollouts are attempted
- Whether another large-scale vendor or infrastructure incident tests the resilience investments made in the wake of Change Healthcare
Health IT leaders navigating this landscape appear to be converging on a common posture: invest deliberately in AI and interoperability, but pair that investment with governance, vendor-risk discipline, and a clear-eyed view of the return expected — because the margin for approving technology on faith alone is thinner than it’s been in years.
Related reading
- Generative AI in the EHR: Where It Helps and Where It Worries
- Clinical AI Governance: Building the Guardrails
Frequently Asked Questions
What are the top health IT priorities for 2026?
Based on 2025 CIO surveys and early 2026 reporting, the recurring priorities are AI governance and scaled deployment, interoperability driven by TEFCA and FHIR maturation, cybersecurity resilience following the Change Healthcare attack, reducing clinician documentation burden, and managing IT costs amid margin pressure.
Is TEFCA mandatory for hospitals and health systems in 2026?
No. TEFCA participation remains voluntary, though it’s growing quickly — exchange volume rose from about 10 million records in January 2025 to nearly 500 million by early 2026 and past 1 billion by mid-2026, per HHS. Organizations connect through a Qualified Health Information Network rather than joining TEFCA directly.
How has the Change Healthcare attack changed hospital cybersecurity planning?
It shifted emphasis from pure breach prevention toward resilience and continuity planning — assuming a critical vendor could go down and preparing to keep claims, payments, and care delivery functioning anyway. It also intensified scrutiny of third-party and clearinghouse vendor risk industry-wide.
Do ambient AI scribes actually reduce clinician burnout?
Early published research links ambient documentation tools to reduced reported burnout symptoms and less after-hours EHR time for some clinicians. Results vary by specialty and setting, and documentation is only one of several burnout drivers, so it’s a meaningful but partial improvement, not a complete fix.
Are health IT budgets increasing or decreasing in 2026?
It varies by organization. Many health systems report targeted increases for AI and cybersecurity while holding other IT spending flat or reducing it, reflecting broader margin pressure and a push for more selective, ROI-focused technology investment industry-wide. Application rationalization and EHR optimization, rather than net-new platform spending, are the recurring cost-control themes leaders cite.
This article is intended for general informational purposes for health IT professionals and does not constitute medical, legal, or compliance advice. Health systems should consult qualified counsel and compliance staff before acting on regulatory matters such as TEFCA participation or AI certification requirements.
