A Program That Won't Sit Still
South Dakota's Department of Health has scheduled a public hearing for September 23 on a package of proposed changes to Article 44:90, the regulation governing the state's medical marijuana program. The scope isn't small. Thirty-seven sections are up for revision, touching patient registry cards, business registration, dispensary operations, testing facility requirements, product packaging, and enforcement.
The timing says something too. State data released September 2 put registered patients at 19,821, up from 19,530 the month before. Registered caregivers climbed from 609 to 620. Participating providers rose from 209 to 211. A program that started with a 2020 ballot measure has grown into something the original rules weren't quite built to handle, and the state is now catching up.
Written comments close October 3. The Legislature's Interim Rules Review Committee takes it up October 14. None of this is unusual, and that's the point.
Rule Changes Aren't the Exception, They're the Job
Every state cannabis registry program gets rewritten. Not once, but repeatedly, as patient volume grows, as legislators respond to enforcement gaps, and as agencies learn what the original rule language didn't anticipate. Georgia's registry passed 40,000 patients this year under an expanded law. Hawaii is mid-migration to a new registry platform. Utah just stood up a new purchase-history search tool. South Dakota is now touching patient card provisions, caregiver rules, and recordkeeping requirements all in the same rulemaking cycle.
Agencies that treat their registry system as a one-time build tend to feel every one of these changes as a crisis. A new field requirement means a developer ticket. A change to caregiver limits means a data migration. A new reporting rule means someone exporting spreadsheets by hand until IT can get to it. The rule text changes on a legislative timeline. The software underneath it usually doesn't move nearly as fast, and that gap is where registry programs get into trouble.
The states running into trouble aren't the ones with complicated rules. They're the ones whose registry software can't keep up with rules that were always going to change.
What “Built for Change” Actually Looks Like
Configuration, Not Custom Code
A registry platform built for regulatory change handles new fields, new document types, and new workflow steps through configuration - admin-level settings a program manager can adjust - rather than a development sprint. When South Dakota's final rule adds a new patient card data element or a new caregiver registration step, that should be a form update, not a software release.
Audit Trails That Predate the Rule Change
Rule packages like this one usually come with new recordkeeping and enforcement language. A registry that already tracks every record through a full audit timeline, who touched it, when, and what changed, doesn't need to retrofit compliance after the fact. The audit trail was already there. Only the retention or reporting rule around it changed.
HIPAA Compliance That Doesn't Reset
South Dakota's program, like most statewide medical cannabis registries, handles protected health information under HIPAA. A rule change to patient card requirements shouldn't force a re-evaluation of the entire compliance posture. If the underlying platform is already SOC 2 Type II certified and built around signed BAAs, new provisions slot into an existing framework instead of triggering a new one.
The Real Lesson From Pierre
South Dakota isn't doing anything wrong here. A program growing from a 2020 ballot initiative to nearly 20,000 patients was always going to need its rules cleaned up, contradictions corrected, and administrative processes modernized, which is exactly what the Department of Health says it's doing. That's a healthy program maturing, not a broken one.
The question for any state running, or building, a cannabis registry is whether the technology underneath can mature at the same pace as the rules. cloudPWR's AIRLIFT platform, including its work supporting statewide medical cannabis registry programs, is built around that assumption: rules will change, volume will grow, and the software has to absorb both without a rebuild every time a legislature acts. If your agency is watching a rulemaking docket and wondering how much of it turns into a developer backlog, that's a conversation worth having before the next comment period closes.
