Fraud, Abuse & False Claims Act Enforcement
- Laboratory Corporation of America will pay $14,500,000 to resolve False Claims Act allegations that it billed Medicare Part B for medically unnecessary urine drug testing under its “ToxAssure Comprehensive” panel. From January 1, 2018, through November 22, 2023, Labcorp ran presumptive and definitive tests simultaneously on the same patient, on the same date of service, using the same urine sample, and billed Medicare with CPT Code 80307 for the presumptive testing and HCPCS Code G0483 for the highest-tier definitive testing each time the panel was performed. For several substances, Labcorp performed definitive testing directly, without first conducting a presumptive test to establish the necessity of the definitive test, even where a presumptive option existed. Labcorp admitted these facts, represented that it has stopped billing Medicare the combination of codes 80307 and G0483 for ToxAssure Comprehensive beneficiaries, and received credit under Justice Manual §4-4.112 for disclosure, cooperation, and remediation. The Justice Department’s Civil Division and the U.S. Attorney’s Office for the District of Massachusetts resolved the matter with support from HHS-OIG and the FBI. Source: United States Department of Justice
- Medical technology companies face False Claims Act liability even when they do not submit claims for government funds directly. The FCA imposes liability on anyone who knowingly submits or causes the submission of false claims, defines “knowingly” broadly without requiring specific intent to defraud, and permits per-claim civil penalties between $14,308 and $28,619 plus three times the government’s damages, with most cases arising from qui tam whistleblower suits. Of the more than $6.8 billion in FCA settlements during fiscal year 2025, over $5.7 billion involved the healthcare industry, and MedTech firms have settled claims tied to kickback schemes ($17 million), training providers to reuse single-use devices in violation of Medicare’s “reasonable and necessary” requirement ($550,000), and false cybersecurity representations on genomic sequencing software ($9.8 million). Companies should build compliance programs targeting anti-kickback, Stark law, unapproved device, and off-label promotion risks, encourage internal reporting without retaliation, and investigate reports quickly since the FCA rewards swift self-disclosure. When unsure whether conduct constitutes a violation, companies should consult counsel and document remediation efforts. Upon receiving an internal complaint, civil investigative demand, subpoena, or audit request, companies should engage legal counsel experienced with the DOJ. Source: Fisher Phillips LLP
Anti-Kickback Statute & OIG Guidance
- The OIG issued a favorable advisory opinion permitting a federally qualified health center to provide free produce boxes and vouchers to financially needy patients with diabetes or hypertension. Under the Arrangement, 50 selected Participants receive either weekly $30 produce boxes delivered to their homes or $20 vouchers redeemable for healthy foods at local grocers and farmers markets over a 6-month period, alongside initial, midpoint, and final health assessments with a registered dietician and behavioral health consultant. The Requestor bills patients and insurers for reimbursable assessment services under its Sliding Fee Discount Policy, funds the program through grants, and does not consider insured status when selecting Participants. OIG concluded that although the Arrangement implicates the Federal anti-kickback statute (no safe harbor applies) and the Beneficiary Inducements CMP (the Financial Need-Based Exception is unmet because the produce is tied to reimbursable services), the fraud-and-abuse risk is low given alignment with the Requestor’s HRSA-approved scope, the in-kind and narrowly tailored nature of the remuneration, the limited value and duration, retained cost-sharing obligations, and Voucher Company safeguards including receipt checks, site visits, cashier trainings, and retailer MOUs. Source: OIG Advisory Opinion No. 26-16
HIPAA Breaches & Enforcement
- All About Women’s Care has notified 12,000 patients that their protected health information was compromised after an attacker obtained an employee’s VPN credentials and used them to enter the practice’s network. The Englewood, Colorado obstetrics and gynecology practice identified suspicious activity involving the VPN account and engaged third-party cybersecurity experts, who confirmed the unauthorized access and determined that files were copied, with the file review completed on June 5, 2026. The affected data included names, dates of birth, Social Security numbers, driver’s license numbers, other identification numbers, clinical and treatment information, lab results, prescription information, provider information, medical documents, ultrasound images, copies of identification documents such as passports, and health insurance information. The breach was reported to the HHS Office for Civil Rights as affecting up to 12,000 patients, and the practice is reviewing its data privacy and security policies and procedures. Separately, Mid-South Pulmonary Sleep Specialists in Memphis, Tennessee began notifying patients about a November 2, 2025 network intrusion claimed by the Anubis ransomware group, with the data review completed May 18, 2026 and the affected individual count not yet posted to the OCR breach portal. Source: The HIPAA Journal
Medical Device Regulation & Compliance
- The number of regulations imposed on medical device manufacturers increased 64% between 2015 and 2022, and the compliance landscape has continued to expand since. U.S. manufacturers spend an average of $24 million on FDA-related requirements to bring a single device from concept to market, a figure that rises to $75 million for devices in the FDA’s highest-risk Class III, while the European Union’s 2021 replacement of the Medical Device Directive with the Medical Device Regulation has increased manufacturer regulatory costs up to tenfold. Approval timelines range from a few weeks to eight months in the United States, a year or longer in the EU, and one to three years in Japan. The United States regulates devices through the FDA across three risk categories, requiring clearance to market, a Quality Management System Regulation harmonized to ISO 13485, and post-market surveillance; the United Kingdom requires UKCA marking and registration through the MHRA; and Canada’s Medical Devices Directorate licenses Class II, III, and IV devices and may suspend a license or require a recall or refit when a device no longer meets safety and effectiveness requirements. Violations can carry penalties of $100,000 or more and imprisonment in cases of criminal negligence. Source: The HIPAA Journal
Health IT, Data Security & HIPAA Compliance Practice
- iMessage cannot meet HIPAA requirements, and no configuration changes can fix that. Apple’s iCloud Terms of Service prohibit healthcare organizations from using iCloud to create, receive, maintain, or transmit protected health information, and because iMessages back up to iCloud by default, texting about patients violates both HIPAA and Apple’s terms. Three gaps disqualify the app: Apple will not sign a Business Associate Agreement, the encryption key for backed-up messages sits on Apple’s servers under default settings, and personal Apple IDs provide no admin controls, audit trails, or exportable records. Messages sync across every device on an Apple ID, former employees retain full chat histories on their own devices, and HIPAA fines can reach $50,000 per violation, with the average healthcare data breach costing $7.42 million according to the HIPAA Journal. A compliant replacement requires a signed BAA, organization-controlled cloud storage, one-click offboarding, granular admin permissions, and exportable activity records, with Zenzap cited as an option built for healthcare teams. Source: Analytics Insight
- AWS is not HIPAA-compliant by default, and organizations must sign a Business Associate Addendum before any covered service can touch protected health information. Under the shared responsibility model, the customer configures encryption, access control, network isolation, audit logging, and breach notification, using VPCs with private subnets, KMS for key management, scoped IAM policies, and CloudTrail and CloudWatch for audit trails. Compliant architectures separate public-facing components from patient-data workloads in private subnets, encrypt data at rest with KMS keys and in transit with TLS, apply the same encryption to backups, and keep S3 buckets holding health data private. HIPAA’s minimum necessary standard requires IAM roles mapped to job function, immutable CloudTrail logs stored in a separate restricted account, and mandatory multi-factor authentication for human access. Common failures include leaving default security group rules in place, storing keys in code or environment variables, skipping BAAs with third-party tools, and treating compliance as a one-time setup rather than conducting regular access reviews and configuration audits. Source: Finextra
- Five specialized assessments enable regulated organizations to achieve and maintain SOC 2 Type II certification for artificial intelligence systems. The five evaluations cover AI governance and policy, data security and privacy controls, risk management and threat modeling, continuous monitoring and incident response, and third-party vendor and supply chain compliance. Each assessment maps controls across additional frameworks, including CMMC for defense contractors, NIST for cybersecurity risk management, ISO 27001 for information security management, HIPAA for protected health information, and FedRAMP for cloud service providers. Recommended practices include quarterly gap analyses, deploying automated monitoring tools for real-time anomaly detection, building a prioritized risk register for 2027 regulatory updates, and establishing contractual controls with periodic vendor reassessments. Organizations should schedule annual assessments beginning in 2026 and pair them with ongoing training and technology investments. Source: Security Boulevard
Texas Regulatory Developments
- Beginning July 31, Texas will classify Delta-8 THC and other hemp-derived THC isomers as controlled substances, forcing their removal from store shelves. The Texas Department of State Health Services republished its 2021 rule in the Texas Register on July 10, following the Texas Supreme Court’s reversal of an injunction that a Travis County judge had granted to block enforcement. The rule affects products containing Delta-8, Delta-10, Delta-6, and THCP, and the Texas Hemp Business Council is advising retailers to remove or sell through affected inventory before the effective date. Under federal and Texas law, hemp contains less than 0.3% Delta-9 THC while marijuana exceeds that threshold, a framework established by the 2018 Farm Bill and adopted by Texas in 2019. At least two lawsuits challenging the regulations remain active with additional challenges being prepared, and questions persist over enforcement because DSHS has stated it is not the enforcement mechanism. Source: Chron
