Categories
Health Law Highlights

Wade’s Health Law Highlights for August 11, 2026

False Claims Act & Fraud Enforcement

  • False Claims Act settlements and judgments announced in the first half of 2026 total more than $1.8 billion The total includes two nine-figure Medicare Advantage resolutions and a customs duties settlement exceeding half a billion dollars, the largest of its kind. As of April, DOJ reported that more than 780 qui tam cases had been filed in FY 2026, and it announced an initiative formalizing its focus on data-mining by relators along with direction to fast-track investigations of matters alleging fraud on federally funded, state-administered benefit programs. Whether False Claims Act enforcement stays in the Civil Division or moves into the National Fraud Enforcement Division that DOJ created in April remains unresolved. Several states moved to expand their false claims statutes, including a Minnesota proposal that would extend liability to investors in entities that commit violations. Source: Gibson Dunn
  • Access DX Laboratory, its former chief executive, and a Florida businessman will pay a combined $36.4 million to resolve False Claims Act allegations of kickbacks and medically unnecessary genetic testing The United States alleged that from January 2018 through January 2020 the Houston laboratory and the two men paid marketers for patient referrals, unbundled genetic testing billing codes, and paid telemedicine providers for false doctors’ orders. Both men agreed to plead guilty to conspiracy to defraud the United States and to pay and receive health care kickbacks in violation of 18 U.S.C. § 371, and entered civil settlements at the time of their pleas. Access DX entered a five-year Corporate Integrity Agreement with HHS-OIG requiring a compliance program, training and education, and a review of its arrangements with referral sources. The settlements resolve a qui tam action filed by the president of a Massachusetts marketing company hired to market the testing to Medicare and Medicaid beneficiaries, who receives a $7.2 million share. Source: U.S. Department of Justice
  • The CMS Medicaid Fraud War Room stopped more than $203 million in potentially improper Medicaid payments during its first 88 days Since its launch on April 23, the unit has coordinated actions against 50 high-risk Medicaid providers identified through data analytics. HHS-OIG issued 42 federal notices of intent to exclude providers from federal health care programs, covering approximately $160.7 million in Medicaid payments made since January 1, 2025. States took 15 enforcement actions on War Room referrals covering approximately $46.2 million, and seven providers were subject to both federal and state action. The War Room was established in coordination with the White House Task Force to Eliminate Fraud and brings together CMS, OIG, state Medicaid agencies, and federal law enforcement. Source: CMS

Controlled Substance Enforcement

  • A Texas physician was sentenced to 12.5 years in prison for operating her Kingwood clinic as a cash-only pill mill that issued prescriptions for more than 3 million opioid pills The physician owned and was the sole prescriber at Recare Health Clinic, and sold controlled substance prescriptions to street-level drug dealers whom the clinic called “providers,” issuing them without a legitimate medical purpose and often without ever interacting with the patient. Prices tracked street value, with an oxycodone 30mg prescription costing as much as $500 and hydrocodone prescriptions often $300, and staff took tips from dealers to move patients and prescriptions to the front of the line. She pleaded guilty in March 2026 to conspiracy to unlawfully distribute controlled substances, covering prescriptions issued between 2022 and 2025, when law enforcement shut the clinic down. Four codefendants were sentenced earlier, including a dealer who received 210 months, a nurse practitioner who received 96 months, the clinic’s security guard who received 63 months, and the pharmacist owner of the pharmacy that filled the prescriptions, who received 42 months. Source: U.S. Department of Justice

Medicare Reimbursement

  • CMS has proposed a 2027 Medicare Physician Fee Schedule that would pay for certain FDA-authorized AI-enabled software used in physicians’ clinical decision-making The proposal ties payment to technologies that demonstrate measurable clinical value, and adds policies to improve physicians’ access to existing clinical information and to reduce duplicate diagnostic testing. CMS states that its current Practice Expense methodology relies on outdated physician practice survey information and no longer reflects the costs of operating a physician practice, and proposes objective, routinely updated, auditable cost data in its place. Because Practice Expense is built into payment for thousands of physician services, the change could affect physician compensation, service-line profitability, capital investment, and merger and acquisition valuations. Medicare payment influences commercial reimbursement, so the proposals reach private insurers as well. Source: Clark Hill

HIPAA & Data Security

  • Health care organizations deploying AI tools that touch protected health information face risks that traditional security controls do not address Employees entering patient details into unapproved generative AI tools, a practice called shadow AI, leaves an organization unable to identify which applications are in use, what data is entered, where it is processed, and whether the vendor retains it. AI systems also introduce prompt injection attacks against chatbots and virtual health assistants, data poisoning of training data, and API vulnerabilities in integrations with electronic health record systems. The Security Rule requires accountability over how PHI is accessed and used, which is harder to establish when an AI-influenced clinical or administrative decision carries no auditable rationale. HHS and the Office for Civil Rights have signaled increased scrutiny of AI-related PHI breaches, and recommended steps include business associate agreements with explicit terms on model training, risk assessments extended to cover AI systems, and logging of all AI interactions involving PHI. Source: Security Boulevard
  • The target date for final rulemaking on the proposed HIPAA Security Rule overhaul has moved to July 2027 HHS published the proposal in January 2025, covering administrative, physical, and technical safeguards, and it would require accurate asset inventories, ongoing risk analyses, and an understanding of where electronic protected health information resides. A health record is worth between ten and fifty times what personally identifiable information alone is worth, and ePHI now moves through email, collaboration platforms, cloud repositories, file shares, and a growing number of AI-enabled applications rather than sitting inside electronic health record systems. Compliance under the proposal turns on demonstrating where sensitive data resides, how it is used, and how it is protected, supported by audit trails sufficient to investigate incidents and document oversight. Source: Proofpoint

Website Tracking Litigation

  • Five health care providers have agreed to settle class action lawsuits over website tracking and analytics tools that allegedly disclosed patient data to third parties Penn Medicine will establish a $9.5 million settlement fund over its use of Meta Pixel and Google Analytics code, with class members able to claim up to $15 each, and it has stopped using Meta Pixel and agreed not to use analytics and advertising technologies on the website for at least two years. Concord Hospital Health System agreed to an $800,000 fund, Emanate Health Medical Center to $777,000, and Mount Sinai Medical Center of Florida to a $220,000 fund plus one year of medical data monitoring for class members. Bayhealth Medical Center will pay $25 per claiming class member and offer one year of medical data monitoring. A proposed class action against CRH Healthcare, doing business as Peachtree Immediate Care, was dismissed with prejudice because the plaintiff did not explain what damages resulted from the disclosures, with 14 days to file an amended complaint. Source: The HIPAA Journal

Cybersecurity Incidents

  • JPS Health Network in Fort Worth has run its hospital and clinics on paper for several days after identifying suspicious activity within its technology environment The system calls the situation a controlled network downtime, says its hospital, clinics, and care locations remain open, and says physicians, nurses, and staff are using established backup procedures while technology systems are unavailable. Patients write their information by hand at check-in, MyChart and other systems are down, virtual appointments have been canceled, and pharmacy services are taking longer. One patient of seven years said her new physician could not pull up her medical history or see a recent CT scan, that no one contacted her about her canceled appointment, and that she cannot reach the pharmacy by phone to refill two medications. Asked what caused the outage, when the network would be restored, and whether law enforcement is involved, the health network’s vice president of communications said there were no new updates. Source: WFAA

Medical Spa Regulation

  • Indiana, Rhode Island, and Texas have enacted statutes regulating medical spas directly, and federal and state regulators have brought enforcement actions against the industry Indiana’s Senate Enrolled Act 282, effective July 1, 2026, requires medical spas to register with the Indiana Medical Licensing Board beginning January 1, 2027, designate a responsible practitioner to oversee facility operations, report serious adverse events, and limit compounding to licensed pharmacists and physicians, with fines up to $5,000 for operating unregistered. Rhode Island’s Medical Spas Safety Act requires a physician or certified nurse practitioner medical director and licensure of medical spas as health care facilities, though the Department of Health has not issued the implementing regulations that were due July 1, 2026. New York inspected more than 200 medical spas and cited 87 for possible violations, including the unlawful practice of medicine, with penalties ranging from fines to license revocation and criminal charges, and the Georgia Composite Medical Board issued a position statement targeting “matchmaker medical director” arrangements in which a physician signs a contract but provides no clinical oversight. FDA issued its first Drug Supply Chain Security Act warning letter to a dispenser in April 2026, to a Southlake, Texas medical spa whose patient dispensing records showed more Botox administered than the facility had purchased from its authorized trading partner. Source: Holland & Knight