Fraud & Abuse Enforcement
- A Houston-area pharmacist was convicted of conspiracy to pay health care kickbacks after paying more than $2 million for patient referrals Tronown Thomas owned and operated Rayford ACP Pharmacy in Spring, Texas, and paid the owner of a Houston clinic for referrals of patients insured through the Department of Labor’s Office of Workers’ Compensation Programs who had been prescribed high-reimbursement compounded medications. Thomas billed DOL-OWCP for those medications, and from November 2015 through September 2017 the pharmacy collected more than $20 million in reimbursements. The defense argued at the five-day trial that the payments bought marketing services, and the jury rejected that argument after deliberating more than a day. Sentencing is set for November 12 before U.S. District Judge Alfred H. Bennett, and Thomas faces up to five years in prison and a $250,000 fine. Source: U.S. Department of Justice
- Two Dallas-based physician staffing and emergency services companies agreed to pay $3.5 million to resolve False Claims Act allegations involving Paycheck Protection Program loans Integrative Emergency Services Physician Group, PA, and its affiliated management services organization, Integrative Emergency Services, LLC, applied for and received PPP loans totaling approximately $2.8 million in 2021, and the loans were later forgiven in full. The government contended that the two were related entities whose combined employee count exceeded the applicable Small Business Administration size standard, so neither qualified as a small business eligible for the loans. The settlement resolves a qui tam action filed in the U.S. District Court for the Northern District of Texas, case number 3:25-CV-1246-B, and the relator, Blockquote, Inc., will receive approximately $350,000. The civil claims are allegations only, and there has been no determination of civil liability. Source: U.S. Department of Justice
HIPAA & Data Security
- A federal magistrate judge approved a protective order setting handling rules for the Change Healthcare breach dataset in multidistrict litigation The 2024 ransomware attack took roughly 6 terabytes of data, including the electronic protected health information of an estimated 192,700,000 individuals, and the Judicial Panel on Multidistrict Litigation consolidated the resulting suits as In Re: Change Healthcare, Inc. Customer Data Security Breach Litigation in the U.S. District Court for the District of Minnesota, where the action has grown past 150 cases. Under the stipulated order approved by Magistrate Judge Dulce Foster, UnitedHealth Group will provide a single copy of the data on an encrypted hard drive with the decryption key delivered separately, and plaintiffs’ counsel must re-encrypt it, make no copies, keep it off the shared case file library, and refrain from using it to identify or locate class members. Access is limited to newly provisioned air-gapped computers with no cables, phones, or storage devices nearby, to small samples encrypted under passwords of at least 16 characters, and to no more than 25 people at a time. A chain-of-custody log must be produced to UnitedHealth Group on request, the data must be destroyed within 30 days of the case ending using NIST SP 800-88 or by physical destruction of the drive, and any unauthorized access must be reported within 48 hours, with plaintiffs paying the full forensic investigation costs if they are at fault. Source: The HIPAA Journal
- Texas Hearing Institute notified 29,744 current and former patients of a ransomware attack that exposed Social Security numbers and treatment records The Center for Hearing and Speech, which does business as Texas Hearing Institute and provides pediatric audiology services, identified suspicious network activity on March 20, 2026, and determined on or around April 22 that an unauthorized party had accessed files containing names, personal identifiers, Social Security numbers, diagnosis and treatment information, and financial account information. Notification letters went out June 26, and affected individuals were offered single-bureau credit monitoring. The Interlock ransomware group claimed responsibility, states that it copied 540 GB of data, and published the stolen files, which indicates the ransom was not paid. Two other providers reported breaches the same week: Family Partnerships of Central Florida notified 8,151 individuals after the MoneyMessage group held network access between December 4, 2025, and January 2, 2026, and SportsMed Physical Therapy in Glen Rock, New Jersey, reported to the HHS Office for Civil Rights that a compromised employee email account exposed information on 3,400 patients. Source: The HIPAA Journal
Texas Health Data Policy
- The Texas Data Privacy and Security Act’s consumer protections should be extended to health data that falls outside HIPAA HIPAA reaches only covered entities and their business associates under 45 CFR Section 160.103, so readings from wearables, entries in wellness and fertility applications, direct-to-consumer genetic results, and location trails recording a clinic visit carry no federal protection, and the Texas Act expressly exempts the entities HIPAA does cover. The recommendation is to activate the broader definition of “covered entity” in the Texas Medical Records Privacy Act, which reaches any person who, for commercial, financial, or professional gain, assembles, collects, analyzes, uses, evaluates, stores, or transmits protected health information. On portability, Texas would make intentional violations of the federal information-blocking rules actionable as an unlawful restraint of trade, void contract terms restricting patient access, extend the CMS interoperability application interfaces to state-regulated insurers, set a 15-business-day response deadline with no fee for electronic transmission, and require records in USCDI and HL7 FHIR format. On secondary use, Texas would bar any third-party recipient or data broker from selling, licensing, or using identifiable health information for a secondary purpose without affirmative, specific, and revocable consent obtained apart from general terms of service, prohibit re-identification of de-identified data, and require each recipient to bind the next by written agreement to the same limits. Source: Texas Public Policy Foundation
Pharmaceutical Litigation
- Eli Lilly filed six lawsuits against sellers offering versions of retatrutide, its experimental obesity drug No regulatory agency anywhere has approved retatrutide, and Lilly does not plan to submit an application to the Food and Drug Administration until next year. The defendants are Striker Pharmacy, Aesthetic Envy, Astra Peptides, Legendary Peptides, Texas Peptides, and Lone Star Peptide, several of them targeted over claims that they sell retatrutide as “research use only” product. Lilly said the substances moving through these channels could be fake, impure, or mis-dosed, and that the medical spas, wellness clinics, and self-styled suppliers offering the drug are selling illegal drugs rather than practicing medicine. The company has referred more than 200 people and entities to regulators, professional licensing boards, and law enforcement, and has reported more than 14,000 websites, advertisements, social media posts, and product listings in over 100 countries. Source: BioPharma Dive
Physician Compensation & Fair Market Value
- Surgical first assistant arrangements cannot be valued on compensation survey benchmarks alone Traditional surveys cover physicians and advanced practice providers and carry little data for certified surgical first assistants, certified surgical assistants, or registered nurse first assistants, and where the data exists the sample sizes are small and do not distinguish between provider types or surgical specialties. Compensation expectations vary with years of surgical experience, specialty expertise, certifications, and the complexity of the procedures supported, and third-party staffing companies supply a mix of provider types depending on scheduling needs and case complexity. Productivity is difficult to measure because most organizations do not track work relative value units at the first-assistant level, and reimbursement turns on the assistant’s credentials, the procedure, and payer policy, so collections data is often incomplete or unavailable. A defensible fair market value analysis documents the qualifications each service requires, compares staffing alternatives including direct employment, individual independent contracts, third-party staffing companies, and per-case coverage, preserves evidence of recruitment difficulty such as vacancy duration and declined offers, and provides for periodic review of collections and payer policy changes. Source: VMG Health
