by Wade Emmert

Wade’s Health Law Highlights for September 1, 2026

Fraud & Abuse Enforcement

  • The Justice Department’s National Fraud Enforcement Division named healthcare one of five enforcement priorities, singling out telemedicine, Medicare and Medicaid billing, controlled substance diversion, and home health and hospice arrangements. Assistant Attorney General Colin M. McDonald issued the memo, titled The Fraud Division’s Enforcement Priorities, on August 13, 2026. The division was set to reach roughly 500 attorneys and staff by August 24, 2026, organized into sections covering healthcare fraud, public trust and financial integrity, tax, global trade and corporate enforcement, with asset recovery, data science and litigation support teams behind them. Healthcare accounts for more than 80 percent of False Claims Act judgments and settlements, and the memo commits more resources and tools to the Health Care Fraud Strike Force model. The other four priorities are public trust and financial integrity, internal revenue, global trade and commerce, and corporate misconduct, where the division continues to reward voluntary self-disclosure, cooperation and remediation. Source: Eye on Enforcement
  • Aymancare PLLC, a Dallas-area medical clinic, agreed to pay $7.5 million to resolve False Claims Act allegations that it overbilled the government for COVID-19 testing of uninsured patients. The United States alleged the clinic ran pop-up testing sites advertising free COVID testing that was paid for through the Health Resources and Services Administration’s COVID-19 Claims Reimbursement to Health Care Providers and Facilities for Testing, Treatment, and Vaccine Administration for the Uninsured Program. Beyond billing for specimen collection and testing, Aymancare billed separately for evaluation and management services as though patients had been seen by a provider for a separate visit, when a technician had only administered a nasal swab. The U.S. Attorney’s Office for the Northern District of Texas and HHS-OIG handled the matter, with Assistant U.S. Attorney Brian Stoltz. The civil claims are allegations only, and there has been no determination of civil liability. Source: U.S. Department of Justice
  • The Justice Department launched the National Fraud Detection Center, a prosecutor-led multi-agency team to investigate fraud against federal programs. Inaugural members include the FBI, Homeland Security Investigations, IRS Criminal Investigation, FinCEN, the Pandemic Response Accountability Committee, the Treasury Department, and the Offices of Inspector General for Health and Human Services, Agriculture, Education, Homeland Security, Housing and Urban Development, Interior, Labor, Veterans Affairs, the Small Business Administration and the Social Security Administration. The center embeds analysts from the inspector general community and shares technology to generate criminal leads, addressing the lack of cross-program visibility that allowed some actors to run schemes against multiple taxpayer-funded programs without detection. Secretaries of State from seven states, state treasurers from four, and the South Carolina Department of Social Services are participating. The initiative sits within the National Fraud Enforcement Division created on April 7 and is led by Acting Assistant Director Amanda Riedel of the Executive Office for U.S. Attorneys and Acting Chief Cody Matthew Herche of the Global Trade & Commerce Enforcement Section. Source: U.S. Department of Justice

Remote Monitoring & Chronic Care Management

Artificial Intelligence in Patient Care

  • Texas and Louisiana now require health care providers to disclose to patients when artificial intelligence is used in their care. Texas Senate Bill 1188, effective September 1, 2025 and codified at Tex. Health & Safety Code § 183.005, permits practitioners to use AI for diagnostic purposes within their scope of license, requires them to tell patients when they do, and requires review of AI-generated records consistent with Texas Medical Board standards. House Bill 149, the Texas Responsible Artificial Intelligence Governance Act (TRAIGA), effective January 1, 2026 and codified at Tex. Bus. & Com. Code § 552.051, adds a separate notice when AI systems are used in treatment, delivered no later than the date of service in clear, conspicuous, plain language. TRAIGA also updated the Texas biometric privacy statute (CUBI), which applies when an AI tool captures voiceprints, facial geometry, fingerprints, or retina or iris scans to identify an individual, triggering separate consent, retention and destruction requirements. Louisiana House Bill 475, signed as Act 649 and effective August 1, 2026, requires a health care professional to verbally disclose the use of any recording device, software or service before recording any part of an appointment or treatment for AI transcription. Source: Phelps Dunbar
  • Sixty percent of medical practice staff surveyed identified HIPAA and data privacy as leading risks of adopting AI. The Weave survey of 285 employees across dental, specialty medical, optometry and veterinary practices found nearly two-thirds spend at least an hour each day on manual data entry, and 7 in 10 practices run software that does not share data across systems. Fifty-one percent said they expect AI to produce low-quality work, and 35 percent cited regulatory uncertainty. Fifty-eight percent of practices have no formal AI governance structure, and 48 percent leave responsibility for AI strategy with the practice owner. Among practices that automated workflows in 2025, 41 percent reported higher productivity and 29 percent reported lower staff workloads and burnout. Source: Healthcare IT News

Health Data Privacy & HIPAA

  • Washington’s My Health My Data Act reaches the digital advertising data medical aesthetic practices collect, including treatment inquiries, patient photos, booking metadata and browsing that shows interest in a treatment. The statute requires separate opt-in consent for collection and for sharing, a health-data privacy policy linked from the homepage, a stand-alone written authorization containing nine statutory elements before any sale, a 2,000-foot limit on geofencing around healthcare facilities, and responses to access and deletion requests within 45 days. Each violation is a Washington Consumer Protection Act violation, and remedies include actual damages, attorneys’ fees and up to $25,000 in treble damages per violation. Washington Attorney General Nick Brown’s first Data Privacy Report, released August 14, 2026, named weak consent requirements, deceptive cookie banner design, overcollection and secondary use, and the sale of sensitive data as recurring concerns. In July 2026 the FTC, joined by the Utah Division of Consumer Protection and the State of California, filed a complaint against Hims & Hers Health Inc. alleging the company sent treatment data and named customer lists to advertising platforms through pixels while its privacy policy promised not to share health information for advertising. Source: Holland & Knight
  • A managed service provider that creates, receives, maintains or transmits protected health information for a healthcare client is a HIPAA business associate. That status turns on the services performed rather than on whether the provider is a healthcare company, and it covers cloud infrastructure, backup and disaster recovery, servers and databases holding PHI, security monitoring, and IT support requiring access to healthcare systems. The Security Rule requires administrative, physical and technical safeguards, including role-based access controls, multi-factor authentication, encryption, audit logs and periodic risk assessments. The Privacy Rule limits technician access to what each role requires, and the Breach Notification Rule requires a documented process for detecting, investigating and reporting incidents to the covered entity. A business associate agreement must state what the MSP may do with PHI, how it will report unauthorized uses and security incidents, how subcontractor access is handled, and what happens to PHI when the relationship ends. Source: Security Boulevard

340B & Drug Pricing

  • HRSA published a revised 340B Rebate Model Pilot Program on August 3, 2026, with manufacturer plans due August 24, 2026 and approvals expected by September 24, 2026 for a January 1, 2027 effective date. The Pilot covers only drugs on the CMS Medicare Drug Price Negotiation Selected Drug List for initial price applicability years 2026 and 2027, and rebates must equal WAC minus the 340B ceiling price based on the date of dispense, paid at the unit level. Manufacturers must give covered entities at least 45 days from the date of dispense to submit data, must pay or issue a documented denial within 10 calendar days of a complete claim, and may not deny rebates based on diversion, Medicaid duplicate discount concerns, or perceived insufficient WAC purchases. Data collection is limited to standardized pharmacy and medical claims fields, and manufacturers bear all IT platform costs. The notice responds to more than 2,400 comments and to the record deficiencies that led the District of Maine to enjoin HRSA’s 2025 proposal under the Administrative Procedure Act, a proposal HRSA later withdrew. Source: Husch Blackwell

Compounding & Drug Safety

  • FDA is investigating at least 30 adverse events in patients who received compounded intravenous glutathione made from dietary supplement grade material. The glutathione came from Medisca Inc. of Plattsburgh, New York, and reached multiple compounding pharmacies; two Texas pharmacies have recalled glutathione injectables over elevated endotoxin levels. Reported events include fever, chills, pain, dizziness, and signs of shock and sepsis-like symptoms, some resulting in hospitalizations, consistent with exposure to excessive endotoxin. Medisca informed the agency on August 20, 2026 that it had warned U.S. customers not to use its dietary supplement grade glutathione in compounded injectables, and FDA urged compounders that received the material to instruct their customers to discontinue use. FDA communicated about dietary ingredient glutathione in compounded injectables in 2019 and states it remains concerned about continued risks to patients. Source: FDA

Medical Devices

  • FDA authorized the first wearable device that continuously monitors ketone levels and blood glucose in a single system. The agency granted marketing authorization to Abbott Diabetes Care for the Libre Duo 10 Day Continuous Dual Glucose Ketone Monitoring System through the De Novo premarket review pathway, for people aged 2 years and older living with diabetes. The device measures ketones and glucose in the fluid beneath the skin every minute across a 10-day wear period, sends readings to a compatible smartphone, and issues automatic alerts when ketone levels reach a set threshold, which can identify rising ketones before diabetic ketoacidosis becomes an emergency. Authorization rests on six clinical studies enrolling more than 600 participants aged 2 and older. FDA is establishing special controls covering labeling and performance testing that, combined with general controls, provide a reasonable assurance of safety and effectiveness. Source: FDA

Employee Benefits & Health Plans

  • The Department of Labor proposed a safe harbor letting group health plan administrators deliver ERISA-required disclosures electronically by default. The proposal is modeled on the notice-and-access safe harbor available to retirement plans since 2020, and it treats a participant, beneficiary, or dependent child aged 18 or older as a covered individual once that person gives the employer or plan an email address or mobile number, without the wired-at-work or affirmative consent conditions of the 2002 rule. Plans would post covered documents on a website and send a Notice of Internet Availability containing a link to the document, a statement of the right to request paper copies or opt out, and a plan phone number. Covered individuals keep the right to a free paper copy and to opt out of electronic delivery at no charge, and because of the sensitivity of protected health information the proposal does not permit the direct-to-email delivery method available to retirement plans. Comments are due September 21, 2026, and a final rule would apply on the first day of the first calendar year following its publication. Source: Husch Blackwell

Texas Licensure & CME

  • The Texas Medical Board will track completion of the Life of the Mother Act continuing medical education requirement in its own system rather than through CE Broker. Senate Bill 31 requires physicians in specialties that may provide care for pregnant women to take a one-time, one-hour course on pregnancy-related medical emergencies, and it applies to physicians obtaining or renewing licenses as of January 1, 2026. TMB offers the only qualifying course, free through MyTMB, and a licensee required to complete it cannot proceed with renewal until the board’s system shows it complete. Because the course is taken directly through MyTMB, it will not appear in CE Broker, the platform physicians must use starting September 1 to track all other CME. A physician who wants the hour to count toward the 48 hours required for renewal must report it to CE Broker separately for ethics or professional responsibility credit, and because TMB is not an accredited CME provider the course cannot qualify for AMA PRA Category 1 Credit. Source: Texas Medicine Today
Wade Emmert Avatar

Written by

More Issues