On August 20, bipartisan members of Congress sent a letter to President Trump and senior Cabinet officials asking a set of unglamorous, extremely consequential questions: what does marijuana rescheduling actually mean for consumers and businesses, and are there plans to cover medical cannabis under Medicare?
Most of the industry coverage focused on the first half. The second half is the one that would rewrite how every medical dispensary in the country handles data.
To be clear about what this is: a letter asking for guidance, not a policy, not a proposed rule, not a timeline. Medicare coverage of medical cannabis is not imminent and faces obstacles that have nothing to do with scheduling. But the question has now been asked in writing by members of Congress, and the operational consequences are severe enough that thinking about them early costs nothing.
The Gap That Coverage Would Close
We have written repeatedly about the medical cannabis HIPAA gap: the strange fact that the most medically sensitive purchase many Americans make is governed not by health privacy law but by state cannabis statutes and general consumer privacy acts.
The reason is structural. HIPAA applies to covered entities — health plans, health care clearinghouses, and health care providers who transmit health information electronically in connection with a HIPAA-covered transaction. That last clause is the hinge. A provider becomes covered by billing. A dispensary that takes cash and bills no one is, in the overwhelming majority of cases, not a covered entity, no matter how much medical information it holds.
This is why a dispensary can hold a patient’s qualifying condition, physician recommendation, dosing history, and government ID, and be regulated on that data primarily by state privacy laws written for retailers.
Insurance coverage would close that gap in the most direct way possible: by creating the billing transaction that triggers HIPAA.
What Actually Changes on the Day Coverage Starts
If medical cannabis were reimbursed under Medicare, the dispensary — or whatever entity submits the claim — is transmitting health information electronically in connection with a covered transaction. That is the definition. The consequences cascade:
HIPAA Privacy Rule. Notice of privacy practices, minimum necessary, patient rights of access and amendment, accounting of disclosures, restrictions on marketing use of PHI. The last one alone would end several common dispensary practices; your loyalty program as currently designed would not survive contact with the marketing provisions.
HIPAA Security Rule. Administrative, physical, and technical safeguards with required risk analysis, workforce training, access controls, audit controls, integrity controls, and transmission security. Much of this overlaps with what good operators already do under state infosec mandates, but “overlaps” is not “satisfies.”
Breach Notification Rule. Federal notification obligations with defined timelines, HHS reporting, and — above a threshold — media notice. The breach patterns we catalogued for the first half of 2026 would each have become an HHS Office for Civil Rights matter.
Business associate agreements. Every POS vendor, seed-to-sale integration, delivery platform, analytics provider, and cloud host touching PHI needs a BAA and becomes directly liable under HIPAA. The industry’s vendor due diligence is not currently built for this, and most cannabis-specific software vendors have never signed one.
Federal claims data. This is the part that cuts both ways. Reimbursement means a patient’s cannabis use enters CMS claims systems as a permanent, federally held health record. That brings genuine protection — HIPAA is a real regime with real enforcement — and it also creates a durable federal dataset describing cannabis use by name, for a population that in many cases chose cash precisely to avoid one.
The Honest Tension
The industry tends to treat “cannabis gets treated like real medicine” as unambiguously good. On privacy, it is a trade, and operators should understand the terms before advocating for it.
What patients gain: enforceable federal rights over their own records, a breach regime with teeth, limits on secondary use, and the end of the situation where a dispensary can sell inferences about medical conditions because no health privacy law reaches it.
What patients lose: the option of anonymity. A cash purchase leaves a state-level record at most, and in some markets barely that. A claim leaves a federal one. For patients whose employment, immigration status, professional licensure, custody arrangements, or firearm rights are cannabis-sensitive, that is not a small change — and it arrives in a policy environment where federal agencies are actively expanding cannabis data collection through other channels.
Both things are true. The correct design response is that coverage should be optional at the patient’s election, and that cash-pay medical purchasing should remain available. That is a position worth taking now, while the question is still hypothetical, rather than after a rule is drafted.
What Operators Should Actually Do
Nothing here requires betting on coverage happening. Every item is worth doing regardless.
1. Find out whether you are already a covered entity. Some operators are and don’t know it. If you have an on-site practitioner, run a clinic, submit any insurance transaction, or operate a telehealth arm, the analysis is not obvious. Get a lawyer to make the determination in writing.
2. Do the risk analysis now. A HIPAA Security Rule risk analysis is the foundational document and the first thing OCR asks for. It is also just good practice, and it satisfies several state mandates simultaneously. Doing it early converts a future compliance scramble into a document you already have.
3. Separate medical records from retail records architecturally. Most dispensary systems commingle them because the POS was built for retail. If PHI ever needs different handling, segmentation is the precondition for every other control — see the network segmentation blueprint for the pattern.
4. Start asking vendors about BAAs. Not to sign one today, but to learn which of your vendors could execute one if required. A vendor that cannot answer the question is telling you something about their security program regardless of whether HIPAA ever applies.
5. Fix marketing consent before you are forced to. HIPAA’s restrictions on using health information for marketing are stricter than any state privacy law you currently follow. Auditing your SMS and email practices against that stricter standard now is cheap; retrofitting under enforcement is not.
6. Stop retaining what you would not want in a claims record. The general principle throughout this site applies with extra force here: data you never collected cannot be reimbursed, subpoenaed, breached, or federally aggregated.
Bottom Line
A congressional letter is not a policy. But it is the first time the Medicare question has been put to the administration in writing alongside the rescheduling guidance request, and the answer — whenever it comes — determines whether medical cannabis data stays in the regulatory orphanage it currently occupies.
If coverage ever arrives, the industry’s data obligations do not change incrementally. They change categorically, on a date certain, for every operator that touches a claim. The gap between “we follow state privacy law” and “we are a HIPAA covered entity” is measured in years of engineering and governance work.
The operators who will handle that well are the ones who did the risk analysis, segmented the medical data, and cleaned up their marketing consent while it was still optional.
The bipartisan letter to the President and Cabinet officials was reported on August 20, 2026 by Marijuana Moment. Medicare coverage of medical cannabis is not current policy; this article analyzes the data-governance consequences if it were adopted.



