Three layers, from short to long: recurring Compliance and Enforcement Sweeps, the full regulatory tracker behind them, and practical articles on what the rules actually require.
Short recurring recaps of what moved across HHS, OCR, DOJ, OIG, and California: a Compliance Sweep for rules and guidance, an Enforcement Sweep for settlements and actions.
Tracked developments in compliance, privacy, and fraud-and-abuse regulation, with a plain read on what each one means for the organizations we serve.
Reviewed through August 2026
Entries reflect publicly reported regulatory developments and are summarized for general awareness. They are not legal advice, and details and effective dates change. Verify current requirements with primary sources and qualified counsel before acting.
Practical perspective on the regulations and enforcement trends that shape how a compliance program gets run.
Most programs can name the OIG's seven elements. Far fewer can show them operating. Here's how to tell the difference during a gap analysis.
PrivacyWhy provider networks that build only to the federal standard still carry real exposure under California's stricter privacy regime, and where the gaps usually hide.
AI governanceAmbient scribes and AI coding tools are arriving faster than the contracts covering them. A mapping of each OIG element onto AI risk, and the four places the fit is genuinely imperfect.
Risk defenseA field guide to the transaction reviews that keep fair-market-value and commercial-reasonableness questions from becoming enforcement questions.