Each card leads with priority, lifecycle, applicability, and deadline, then the detail.
P1
CARRYOVER
Operationally relevant
Settled
- What changed
- The Justice Department announced that The Villages Health System LLC has agreed to a $541.5 million settlement resolving False Claims Act allegations. The government alleged that between 2020 and 2024 the organization knowingly submitted invalid diagnosis codes to Humana, UnitedHealthcare and GuideWell, which inflated the risk adjusted payments those Medicare Advantage organizations received from CMS. The codes were alleged to lack adequate medical record support, to rest on unapproved chart amendments, or to be untimely modifications not initiated by the rendering provider. The organization self disclosed to the HHS Office of Inspector General under the Health Care Fraud Self-Disclosure Protocol on December 27, 2024, filed for Chapter 11 protection on July 3, 2025, and the bankruptcy court approved the settlement on August 25, 2026. The claims resolved by the settlement are allegations only and there has been no determination of liability. Three official sources carry three different dates: the Justice Department Office of Public Affairs release is dated August 26, 2026, the Middle District of Florida release and the OIG enforcement listing are both dated August 27, 2026, and the bankruptcy court approval is dated August 25, 2026. This finding uses August 25, 2026 as the enforcement event date, because the project convention takes the date of the actual resolution where a source identifies it and reserves the earliest announcement date for matters where only announcement dates exist.
- Why it matters
- This is the largest provider side Medicare Advantage risk adjustment resolution of the year and the alleged conduct turns on three mechanics that exist in almost every risk adjustment program: documentation that does not support the code, chart amendments made outside an approved amendment policy, and diagnosis changes entered by someone other than the rendering provider. Any organization with a Medicare Advantage risk arrangement, a coding query process, or a retrospective chart review vendor has the same three exposure points, whether or not it is ever accused of anything.
- Response type
- Assess
- Confidence
- High
- Who this affects
- Health systems, Provider networks
- Jurisdiction
- Federal, Florida
- Agencies
- U.S. Department of Justice, U.S. Attorney Office, Middle District of Florida, HHS Office of Inspector General
- Entities
- The Villages Health System LLC
- Action type
- Settlement
- Event date
- Aug 25, 2026
- Alleged conduct
- Alleged knowing submission of invalid diagnosis codes to three Medicare Advantage organizations between 2020 and 2024, where the codes were alleged to lack adequate medical record support, to rest on unapproved chart amendments, or to be untimely modifications not initiated by the rendering provider. The allegations were resolved without any determination of liability.
- Resolution
- A $541.5 million False Claims Act settlement, agreed to and approved by the bankruptcy court on August 25, 2026, following a December 27, 2024 self disclosure under the OIG protocol and a July 3, 2025 Chapter 11 filing. The claims are allegations only and there has been no determination of liability. Announcement dates differ across official sources: August 26, 2026 for the Justice Department Office of Public Affairs and August 27, 2026 for both the Middle District of Florida and the OIG enforcement listing. The August 25, 2026 court approval date is used as the event date because it is the date the resolution itself was effected.
- First seen
- Aug 30, 2026
- Last materially changed
- Aug 30, 2026
- Why it is still here
- The development remains active for implementation or monitoring. The September 13 through September 19 official-source review did not identify a superseding action, and the assigned operational response remains open.
What to do nextTest the three failure modes directly. First, sample risk adjusting diagnoses submitted in the last twelve months and confirm the medical record supports each. Second, confirm the chart amendment policy names who may amend, on what basis, and inside what time limit, and that the electronic record enforces it. Third, confirm that no one other than the rendering provider can add or change a diagnosis without provider attestation. Report the sample size and the error rate to the compliance committee.
- Self disclosure did not eliminate the dollar exposure. No corporate integrity agreement for this entity appeared on the OIG corporate integrity agreement listing when that listing was reviewed on August 31, 2026, sorted by latest update, and neither official announcement referenced one. OIG can post an agreement after an announcement, so this describes the listing on that date rather than establishing that no agreement exists.
- A chart amendment policy that does not state who may amend, on what basis, and by when is a risk adjustment exposure, not only a records management gap.
- Diagnosis codes entered or changed by anyone other than the rendering provider need a provider attestation trail that survives audit.
- Retrospective chart review that only adds codes and never deletes them is the pattern the government reads as one directional.
Permalink: #villages-health-system-medicare-advantage-diagnosis-coding-settlement · Development ID GC-2026-0003
P1
NEW
Operationally relevant
Settled
- What changed
- On September 18, 2026, DOJ announced agreements under which NYU Langone Hospitals and UPMC will cease providing puberty blockers, cross-sex hormones, and surgical procedures to minors and will pay $8.5 million and $950,000 respectively. DOJ said the investigations concerned potential Food, Drug, and Cosmetic Act, False Claims Act, and other federal healthcare-law violations, including allegedly false diagnosis coding. The institutions denied the allegations, and no liability determination was made.
- Why it matters
- The resolutions show DOJ using coordinated civil enforcement, billing review, and service-line restrictions in a sensitive clinical area. The operational exposure includes diagnosis coding, coverage support, consent, pharmacy controls, and board oversight.
- Response type
- Assess
- Confidence
- High
- Who this affects
- Health systems, Provider networks
- Jurisdiction
- Federal, New York, Pennsylvania
- Agencies
- U.S. Department of Justice, HHS Office of Inspector General, Food and Drug Administration Office of Criminal Investigations
- Entities
- NYU Langone Hospitals, University of Pittsburgh Medical Center
- Action type
- Resolution agreement
- Event date
- Sep 18, 2026
- Alleged conduct
- Potential violations involving pediatric services and allegedly false diagnosis codes used to obtain federal program and private-insurer payment. The institutions denied the allegations, and there was no determination of liability.
- Resolution
- NYU agreed to pay $8.5 million, UPMC agreed to pay $950,000, and both agreed to cease the specified services for minors.
What to do nextOrganizations providing these services should have counsel review current federal and state requirements, validate diagnosis and claim support, confirm pharmacy and consent controls, and document executive oversight of any service-line decision.
- Service-line decisions require coordinated legal, coding, pharmacy, and executive oversight.
- Diagnosis codes used to support payment need contemporaneous clinical support.
- Cooperation can materially shape a resolution even when allegations are denied.
Permalink: #nyu-upmc-pediatric-care-federal-resolutions · Development ID GC-2026-0103
P1
NEW
Operationally relevant
Settled
- What changed
- A September 14, 2026 settlement agreement requires Abbott to pay $384,999,040.12 plus interest to the United States, Medicaid participating states, and Massachusetts. The government alleged that from 2018 through 2022 Abbott failed to manufacture powdered infant formula and nutritional products in compliance with federal and state requirements and misrepresented compliance to WIC and Medicaid programs. Abbott denied the allegations, and the agreement is a compromise of disputed claims.
- Why it matters
- The settlement connects product-quality compliance, government-program eligibility representations, and False Claims Act exposure. Medicaid and WIC suppliers need evidence that regulatory and contractual quality claims remain accurate throughout production.
- Response type
- Assess
- Confidence
- High
- Who this affects
- Health systems, Provider networks
- Jurisdiction
- Federal, California
- Agencies
- U.S. Department of Justice, U.S. Department of Agriculture, HHS Office of Inspector General, State Medicaid programs
- Entities
- Abbott Laboratories
- Action type
- Settlement
- Event date
- Sep 14, 2026
- Alleged conduct
- Alleged failure to manufacture covered formula and nutritional products in compliance with requirements and alleged misrepresentations to WIC and Medicaid programs. Abbott denied the allegations.
- Resolution
- Payment of $384,999,040.12 plus interest, with federal, Medicaid state, and Massachusetts allocations.
What to do nextGovernment-program suppliers should map product-quality representations to manufacturing evidence, confirm escalation of deviations and recalls, and test whether invoices or rebate submissions continue after a quality representation becomes inaccurate.
- Product-quality deviations can create payment-integrity exposure.
- Program eligibility representations need continuing support.
- Unallowable settlement costs must be separated from government-program claims and cost reporting.
Permalink: #abbott-infant-formula-fca-settlement · Development ID GC-2026-0105
P1
NEW
Operationally relevant
Final
- What changed
- OIG reported that Methodist Hospital received at least $12.4 million in Medicare overpayments, with errors in 27 of 100 sampled claims, and separately reported 17 errors in 115 sampled claims at McLeod Regional Medical Center, totaling $38,676.
- Why it matters
- The audits show recurring exposure in hospital billing controls and demonstrate that a small sample can support substantial repayment and control findings.
- Response type
- Validate
- Confidence
- High
- Who this affects
- Health systems, Provider networks
- Jurisdiction
- Federal
- Agencies
- HHS Office of Inspector General
- Entities
- Methodist Hospital, McLeod Regional Medical Center
- Action type
- Judgment
- Event date
- Sep 17, 2026
- Alleged conduct
- OIG identified sampled Medicare claim errors and estimated or calculated overpayments.
- Resolution
- OIG issued audit findings and recommendations for repayment and strengthened controls.
What to do nextRun a focused audit against the cited claim categories, quantify any overpayment, complete the 60-day repayment analysis where required, and document corrective action.
- Use targeted claim audits to identify systemic payment risk.
- Escalate credible overpayment findings promptly.
- Document coding, billing, and repayment corrective actions.
Permalink: #oig-hospital-compliance-audits · Development ID GC-2026-0121
P2
CARRYOVER
Operationally relevant
Settled
- What changed
- The Justice Department announced on August 24, 2026 that Monogram Health agreed to pay $2.4 million to settle a False Claims Act suit alleging that it caused the submission of false diagnosis codes in order to increase Medicare Advantage payments. The matter was handled by the Civil Division Commercial Litigation Branch Fraud Section and the U.S. Attorney Office for the Central District of California, with HHS-OIG. The case originated as a qui tam action brought by a physician formerly employed by the company, who receives approximately $380,000. Neither official announcement referenced a corporate integrity agreement, and none for this entity appeared on the OIG corporate integrity agreement listing reviewed on August 31, 2026. The claims resolved by the settlement are allegations only and there has been no determination of liability.
- Why it matters
- The dollar figure is small. The pattern is not. This is the second federal resolution in the same week on unsupported risk adjustment coding, and the defendant here is a value based care provider organization rather than a plan, which places the exposure with the group that documents the encounter rather than the group that submits the risk score.
- Response type
- Assess
- Confidence
- High
- Who this affects
- Health systems, Provider networks
- Jurisdiction
- Federal, California
- Agencies
- U.S. Department of Justice, U.S. Attorney Office, Central District of California
- Entities
- Monogram Health
- Action type
- Settlement
- Event date
- Aug 24, 2026
- Alleged conduct
- Alleged causing of the submission of false diagnosis codes in order to increase payments from the Medicare Advantage program. The allegations were resolved without any determination of liability.
- Resolution
- A $2.4 million False Claims Act settlement announced August 24, 2026, with approximately $380,000 to the relator. The claims are allegations only and there has been no determination of liability.
- First seen
- Aug 30, 2026
- Last materially changed
- Aug 30, 2026
- Why it is still here
- The development remains active for implementation or monitoring. The September 13 through September 19 official-source review did not identify a superseding action, and the assigned operational response remains open.
What to do nextRead this alongside The Villages resolution rather than on its own. Where the organization sends diagnosis data into a Medicare Advantage risk pool through a value based or shared risk arrangement, confirm in writing which party is accountable for coding accuracy under the contract, and confirm that the accountable party actually audits.
- Risk adjustment liability follows the party that documents and submits the diagnosis, not only the plan that receives the risk score.
- A value based contract should name the party accountable for coding accuracy and give that party audit rights it actually uses.
- Two settlements on one theory in one week is the point at which a compliance committee should ask for a risk adjustment audit result rather than a policy.
Permalink: #monogram-health-medicare-advantage-diagnosis-coding-settlement · Development ID GC-2026-0004
P2
CARRYOVER
Directly applicable
Settled
- What changed
- OCR announced on August 27, 2026 a $50,000 settlement and a two year corrective action plan with Azul Vision, a California optometry and ophthalmology provider. An individual requested her protected health information in January 2023 and did not receive it until January 2025, after OCR opened its investigation. The corrective action plan requires the practice to review and revise its Privacy Rule policies and procedures, to train all workforce members on the right of access, and to send HHS periodic lists of access requests received and the dates they were completed. OCR identified this as the 55th action under its Right of Access Enforcement Initiative.
- Why it matters
- The Privacy Rule gives thirty days, with one thirty day extension. Two years is not a close call, and the corrective action plan shows what OCR asks for when an organization cannot show its own numbers: a log of every request and its completion date, sent to the agency. A California provider that cannot produce that log on demand today is one complaint away from producing it for two years under a resolution agreement.
- Response type
- Validate
- Confidence
- High
- Who this affects
- Health systems, Provider networks
- Jurisdiction
- Federal, California
- Agencies
- HHS Office for Civil Rights
- Entities
- Azul Vision, Inc.
- Action type
- Resolution agreement
- Event date
- Aug 27, 2026
- Alleged conduct
- Failure to provide an individual timely access to her protected health information, with the request made in January 2023 and filled in January 2025, well beyond the Privacy Rule deadline.
- Resolution
- A $50,000 settlement with a two year corrective action plan requiring policy revision, workforce training, and periodic reporting of access requests and completion dates to HHS.
- First seen
- Aug 30, 2026
- Last materially changed
- Aug 30, 2026
- Why it is still here
- The development remains active for implementation or monitoring. The September 13 through September 19 official-source review did not identify a superseding action, and the assigned operational response remains open.
What to do nextPull the access request log for the trailing twelve months and compute the completion time distribution, not the average. Identify every request that passed thirty days and every request with no recorded completion date. Confirm that requests arriving outside health information management, at a clinic front desk, through a patient portal message, or to a provider directly, are captured in the same log. California providers should confirm the Confidentiality of Medical Information Act production timelines are met as well.
- Right of access remains the most frequently enforced HIPAA obligation, now at 55 actions.
- Requests that arrive outside health information management are the ones that fall out of the clock, so the intake log has to cover every channel.
- The remedy OCR imposed is a request level log reported to the agency, which is the same artifact that would have prevented the case.
- Practice size did not matter. A small specialty practice drew a five figure settlement and two years of monitoring.
Permalink: #ocr-azul-vision-right-of-access-settlement · Development ID GC-2026-0005
P2
CARRYOVER
Operationally relevant
Settled
- What changed
- The Justice Department and DEA announced on August 28, 2026 that Walmart agreed to pay $50 million to resolve allegations that its pharmacies filled thousands of invalid prescriptions for opioids and other controlled substances since June 26, 2013, in violation of the Controlled Substances Act. The government alleged that compliance staff knew certain prescribers operated as pill mills yet prescriptions continued to be filled, that pharmacists filled prescriptions despite dangerous drug combinations, excessive high dose refills and early refill requests, and that the compliance function prioritized driving sales and patient awareness over Controlled Substances Act compliance while thousands of internal refusal to fill reports went unused. The settlement includes a memorandum of agreement with DEA requiring a reporting hotline, proactive dispensing pattern monitoring, and a prescriber evaluation process. The claims are allegations only and there was no determination of liability.
- Why it matters
- The allegation that carries beyond retail pharmacy is the unused signal. Pharmacists filed refusal to fill reports and the organization had them. Any organization that collects a compliance signal it does not route, act on, or trend has the same exposure, whether the signal is a refusal to fill, a hotline report, a coding query, or a denied prior authorization pattern.
- Response type
- Assess
- Confidence
- High
- Who this affects
- Health systems
- Jurisdiction
- Federal
- Agencies
- U.S. Department of Justice, Civil Division, Drug Enforcement Administration
- Entities
- Walmart Inc.
- Action type
- Settlement
- Event date
- Aug 28, 2026
- Alleged conduct
- Filling thousands of invalid controlled substance prescriptions since June 26, 2013 despite known pill mill prescribers and documented pharmacist red flags, with internal refusal to fill reports left unacted upon.
- Resolution
- A $50 million payment and a memorandum of agreement with DEA requiring a reporting hotline, proactive dispensing pattern monitoring, and a prescriber evaluation process.
- First seen
- Aug 30, 2026
- Last materially changed
- Aug 30, 2026
- Why it is still here
- The development remains active for implementation or monitoring. The September 13 through September 19 official-source review did not identify a superseding action, and the assigned operational response remains open.
What to do nextTreat the three obligations DEA imposed as a self assessment for outpatient and retail pharmacy operations: a reporting channel for suspected illegal dispensing, proactive monitoring of dispensing patterns, and a documented process for evaluating suspect prescribers. Then ask the broader question at the compliance committee: which compliance signals does the organization collect today that nobody reviews on a schedule.
- A compliance signal that is collected and not reviewed is worse evidence than a signal never collected.
- Prescriber level evaluation, not only prescription level review, is what the agreement requires going forward.
- Sales and patient access goals sitting inside the compliance function is the structural fact the government pointed at.
Permalink: #walmart-controlled-substances-dispensing-settlement · Development ID GC-2026-0006
P2
CARRYOVER
Operationally relevant
Settled
- What changed
- The Department of Managed Health Care recorded four letters of agreement with an action date of August 26, 2026, totaling $331,000 in administrative penalties. Local Initiative Health Authority for Los Angeles County, doing business as L.A. Care Health Plan, paid $111,000 in matter 24-705 on timely access reporting violations under 28 CCR 1300.67.2.2(g)(2)(B), 1300.67.2.2(g)(2)(C)(1) and Health and Safety Code section 1367.03(f)(2) and (f)(3). California Dental Network, doing business as DentaQuest of California, paid $150,000 in matter 23-768 on improper cancellation or rescission of coverage under 28 CCR 1300.65.2(a)(3)(A) and (a)(3)(E) and on grievance and appeals failures under 28 CCR 1300.68(a)(1) and Health and Safety Code section 1368(a)(1). Kaiser Foundation Health Plan paid $45,000 in matter 24-704 on the same timely access reporting provisions. Community Care Health Plan paid $25,000 in matter 24-699 for failing to report the number of payments made to noncontracting providers at contracting health facilities under 28 CCR 1371.31(a)(4), the surprise billing data provision.
- Why it matters
- Three of the four penalties are for reporting failures rather than for denying care. The department assessed $156,000 across two plans purely for timely access reports that were late, incomplete, or not prepared using the department's own methodology, and a fourth plan paid for an incomplete surprise billing data submission. For a health system that holds delegated risk, operates a restricted Knox-Keene licensed entity, or supplies network and encounter data to a plan, the exposure sits in the regulatory reporting calendar and in the accuracy of the underlying data, not in the clinical decision. The DentaQuest matter is the reminder that a grievance system the department has not approved, and coverage terminations sent without the required notices, remain a penalty category on their own.
- Response type
- Assess
- Confidence
- High
- Who this affects
- Health systems, Provider networks
- Jurisdiction
- California
- Agencies
- California Department of Managed Health Care
- Entities
- Local Initiative Health Authority for Los Angeles County d.b.a. L.A. Care Health Plan, California Dental Network, Inc. d.b.a. DentaQuest of California, Kaiser Foundation Health Plan, Inc., Community Care Health Plan, Inc.
- Action type
- Settlement
- Event date
- Aug 26, 2026
- Alleged conduct
- Timely access reporting failures at two plans, improper cancellation or rescission of coverage and grievance and appeals failures at a third, and an incomplete surprise billing data submission at a fourth. Each matter resolved by a letter of agreement with an administrative penalty.
- Resolution
- Four letters of agreement with an action date of August 26, 2026: $111,000 (matter 24-705), $150,000 (matter 23-768), $45,000 (matter 24-704) and $25,000 (matter 24-699), totaling $331,000.
- First seen
- Aug 30, 2026
- Last materially changed
- Aug 30, 2026
- Why it is still here
- The development remains active for implementation or monitoring. The September 13 through September 19 official-source review did not identify a superseding action, and the assigned operational response remains open.
What to do nextAsk who owns each recurring DMHC filing the organization or its delegated entities contribute to, and confirm that the last timely access report and the last surprise billing data submission were prepared using the department's stated methodology rather than an internal equivalent. Where the organization delegates utilization management or grievance handling, confirm the delegate's grievance system carries current department approval and that termination and grace period notices match the content the regulation requires.
- A regulatory report filed late, filed incomplete, or filed on an internal methodology is a penalty category in its own right, separate from any access or coverage failure.
- Timely access reporting accuracy is measured against the department's stated methodology, so a plan or delegate that computes compliance its own way is exposed even when access is adequate.
- Surprise billing data reporting under 28 CCR 1371.31(a)(4) reaches the proportion of noncontracting to contracting providers at a contracting facility, which is a data set the facility usually holds.
- A grievance system needs current department approval, not merely a written procedure.
OfficialDMHC Letter of Agreement, matter 24-705 (L.A. Care Health Plan) · California Department of Managed Health Care · Source published Aug 26, 2026 · Verified Sep 10, 2026 ↗
OfficialDMHC Letter of Agreement, matter 23-768 (DentaQuest of California) · California Department of Managed Health Care · Source published Aug 26, 2026 · Verified Sep 10, 2026 ↗
OfficialDMHC Letter of Agreement, matter 24-704 (Kaiser Foundation Health Plan) · California Department of Managed Health Care · Source published Aug 26, 2026 · Verified Sep 10, 2026 ↗
OfficialDMHC Letter of Agreement, matter 24-699 (Community Care Health Plan) · California Department of Managed Health Care · Source published Aug 26, 2026 · Verified Sep 10, 2026 ↗
Permalink: #dmhc-letters-of-agreement-august-26-2026 · Development ID GC-2026-0017
P2
CARRYOVER
Directly applicable
Announced
- What changed
- The California Department of Public Health State Enforcement Actions record carries ten citations and administrative penalties with a Penalty Issue Date of August 26 or August 27, 2026, totaling $73,750 across eight facilities in Sacramento, Marin and Los Angeles counties. Professional Post Acute Center, a Marin County skilled nursing facility, received two class A citations at $25,000 each on August 26 for violations of 42 CFR 483.25(d)(1) and (2), 42 CFR 483.21(b)(1) and (b)(3)(i), and title 22 sections 72311(a)(2) and 72313(a)(2), recorded under the Patient Care penalty category. Sierra Vista Hospital, an acute psychiatric hospital in Sacramento County, received a $4,750 non immediate jeopardy administrative penalty on August 26 under Health and Safety Code section 1280.3(b)(1) and title 22 section 71507(a)(9). Long Beach Healthcare Center received two class B citations of $3,000 each on August 27 in the Abuse, Facility Not Self Reported category, one of them citing Health and Safety Code section 1418.91(a) and (b) alongside 42 CFR 483.12(c)(1) and (4). Northgate PostAcute Care received a $3,000 class B citation on August 26 under the Patient Rights category, The Gardens of El Monte a $3,000 class B citation on August 26, Astoria Healthcare Center a $3,000 class B citation on August 27 for physical environment, West Covina Healthcare Center a $3,000 class B citation on August 27 in the Medication category citing 42 CFR 483.45(f)(2), and Able, an intermediate care facility for the developmentally disabled, a $1,000 class B citation on August 26. Every record carries a disposition of Open.
- Why it matters
- This is the state licensing layer that sits underneath federal survey enforcement, and it moves weekly whether or not anything federal happens. Two features of the week are worth a compliance committee's attention. First, both class A citations rest on care planning and care delivery provisions, 42 CFR 483.21(b) and 483.25(d), which is the pairing that appears when the plan of care and the care actually delivered do not match in the record. Second, the two Long Beach Healthcare Center citations sit in the Abuse, Facility Not Self Reported category, and one of them cites Health and Safety Code section 1418.91, the statute that requires a skilled nursing facility to report suspected abuse to the Department. A citation in that category is an enforcement finding about the reporting pathway itself, not only about the underlying incident, and the same reporting logic reaches any licensed facility a health system operates. The Sierra Vista Hospital penalty under Health and Safety Code section 1280.3 is the acute side of the same week and shows the administrative penalty track is not confined to long term care.
- Response type
- Assess
- Confidence
- High
- Who this affects
- Health systems, Provider networks
- Jurisdiction
- California
- Agencies
- California Department of Public Health
- Entities
- Professional Post Acute Center, Sierra Vista Hospital, Inc., Long Beach Healthcare Center, Northgate PostAcute Care, The Gardens of El Monte, Astoria Healthcare Center, West Covina Healthcare Center, Able
- Action type
- Civil monetary penalty
- Event date
- Aug 26, 2026
- Alleged conduct
- Care planning and care delivery failures at a skilled nursing facility, drawing two class A citations. Abuse allegations the facility did not self report at a second skilled nursing facility. Patient rights, physical environment and medication violations at three further skilled nursing facilities. A habilitative services violation at an intermediate care facility for the developmentally disabled. A non immediate jeopardy administrative penalty at an acute psychiatric hospital under Health and Safety Code section 1280.3(b)(1).
- Resolution
- Ten citations and administrative penalties issued August 26 and 27, 2026, totaling $73,750 across eight facilities: two class A citations at $25,000 each, seven class B citations between $1,000 and $3,000, and one $4,750 administrative penalty. All ten records carry a disposition of Open, so appeal rights had not run at the close of the coverage window.
- First seen
- Aug 30, 2026
- Last materially changed
- Aug 30, 2026
- Why it is still here
- The development remains active for implementation or monitoring. The September 13 through September 19 official-source review did not identify a superseding action, and the assigned operational response remains open.
What to do nextPull the current abuse and unusual occurrence reporting matrix for every licensed facility the organization operates and confirm, for each licence type, who reports, to which agency, and inside what clock, and that the last quarter's reports actually went out inside it. Separately, sample recent care plans in any skilled nursing or subacute unit against the care documented in the record for the same period, focusing on the change of condition pathway that 42 CFR 483.21(b)(3)(i) and title 22 section 72311(a)(2) sit on. Confirm the organization can produce the citation history for each of its own facilities from the CDPH enforcement record rather than relying on internal logs alone.
- Both class A citations pair a care planning provision with a care delivery provision, which is the combination that surfaces when the plan of care and the record of care given diverge.
- An Abuse, Facility Not Self Reported citation is an enforcement finding about the reporting pathway, so a facility can be cited for the reporting failure independently of the underlying allegation.
- Health and Safety Code section 1418.91 sets the skilled nursing facility abuse reporting duty to the Department, and it was cited alongside the federal abuse provisions in the same citation.
- The Health and Safety Code section 1280.3 administrative penalty track reaches acute and acute psychiatric hospitals, not only long term care, and it ran in the same week.
- CDPH publishes a per record Penalty Issue Date, so a facility's own citation history is verifiable from the state record rather than only from internal logs.
Permalink: #cdph-state-enforcement-actions-august-26-27-2026 · Development ID GC-2026-0018
P2
CARRYOVER
Operationally relevant
Final
- What changed
- DOJ announced September 4 sentences of 33 months for Kenneth Kessler III and 24 months for Michael Gomez following guilty pleas. The scheme involved unnecessary orthotic braces, paid fraudulent orders and billing shifted among seven companies.
- Why it matters
- Referral-payment controls and related-entity monitoring need to operate across supplier identities.
- Response type
- Assess
- Confidence
- High
- Who this affects
- Health systems, Provider networks
- Jurisdiction
- Federal
- Agencies
- DOJ
- Entities
- Kenneth Charles Kessler III, Michael Andrew Gomez
- Action type
- Criminal resolution
- Event date
- Sep 4, 2026
- Alleged conduct
- Medicare billing for unnecessary braces using kickbacks and fraudulent orders; billing shifted between supplier entities.
- Resolution
- Prison sentences announced following guilty pleas; the $34.8 million figure is scheme billing, not the amount of a fine.
- First seen
- Sep 6, 2026
- Last materially changed
- Sep 6, 2026
- Why it is still here
- The development remains active for implementation or monitoring. The September 13 through September 19 official-source review did not identify a superseding action, and the assigned operational response remains open.
What to do nextReview DME referral sources, order authenticity, patient receipt and relationships among suppliers when assessing fraud alerts.
- Validate referrals and orders independently.
- Monitor related supplier entities and payment suspension evasion.
Permalink: #florida-dme-brace-fraud-sentences · Development ID GC-2026-0027
P2
CARRYOVER
Operationally relevant
Settled
- What changed
- On September 4 DOJ announced an agreement under which Mount Sinai will cease specified gender-affirming interventions for minors, pay an unspecified monetary penalty and dedicate $2 million to free care for people described in the agreement announcement.
- Why it matters
- The announcement is an entity-specific resolution. It does not establish a universal ban or resolve the separate Medicaid funding lawsuit.
- Response type
- Assess
- Confidence
- Moderate
- Who this affects
- Health systems, Provider networks
- Jurisdiction
- Federal
- Agencies
- DOJ
- Entities
- Mount Sinai Health System
- Action type
- Settlement
- Event date
- Sep 4, 2026
- Alleged conduct
- DOJ investigated potential federal-law violations involving pediatric gender-affirming care; this draft attributes the allegations to DOJ.
- Resolution
- DOJ announced cessation commitments, a monetary penalty with amount unstated in the release, and a separate $2 million care commitment.
- First seen
- Sep 6, 2026
- Last materially changed
- Sep 6, 2026
- Why it is still here
- The development remains active for implementation or monitoring. The September 13 through September 19 official-source review did not identify a superseding action, and the assigned operational response remains open.
What to do nextLegal should obtain the executed agreement and assess its relevance to existing federal investigations and state obligations before making service changes.
- Obtain the executed terms before interpreting the resolution.
- Separate party-specific settlement commitments from generally applicable law.
Permalink: #doj-mount-sinai-agreement · Development ID GC-2026-0030
P2
CARRYOVER
Operationally relevant
Final
- What changed
- DOJ announced a September 2 sentence of 46 months for Rebecca Fadanelli, who pleaded guilty to counterfeit-drug, device and importation offenses. Restitution and forfeiture were each $1,001,562.
- Why it matters
- Unlicensed injections and counterfeit supply chains caused patient harm; a claimed nursing credential did not establish licensure.
- Response type
- Assess
- Confidence
- High
- Who this affects
- Health systems, Provider networks
- Jurisdiction
- Federal
- Agencies
- DOJ
- Entities
- Rebecca Fadanelli, Skin Beaute Med Spa
- Action type
- Criminal resolution
- Event date
- Sep 2, 2026
- Alleged conduct
- Counterfeit botulinum toxin and dermal fillers were administered while the owner falsely claimed to be a nurse.
- Resolution
- Sentence imposed after guilty plea; more than 900 clients and 2,700 procedures describe scale, not separate financial penalties.
- First seen
- Sep 6, 2026
- Last materially changed
- Sep 6, 2026
- Why it is still here
- The development remains active for implementation or monitoring. The September 13 through September 19 official-source review did not identify a superseding action, and the assigned operational response remains open.
What to do nextClinical operations and procurement should independently verify injector licenses and manufacturer-authorized sourcing, quarantine suspect stock and escalate adverse-event reports.
- Verify licensure with the issuing board.
- Trace injectable products to authorized sources and preserve lot records.
Permalink: #skin-beaute-counterfeit-injection-sentence · Development ID GC-2026-0040
P2
CARRYOVER
Operationally relevant
Settled
- What changed
- Heuser Health agreed to pay $2,646,186.72 to resolve allegations of inflated skin-substitute invoice amounts in Medicare and TRICARE claims. No liability was determined.
- Why it matters
- Where reimbursement uses acquisition invoices, discounts and actual purchase costs must flow into claims accurately. This settlement does not establish one payment method for every product or setting.
- Response type
- Assess
- Confidence
- High
- Who this affects
- Health systems, Provider networks
- Jurisdiction
- Federal
- Agencies
- DOJ
- Entities
- Heuser Health
- Action type
- Settlement
- Event date
- Sep 2, 2026
- Alleged conduct
- Claims allegedly used invoice amounts above the true purchase price.
- Resolution
- Civil False Claims Act settlement; allegations resolved without a determination of liability.
- First seen
- Sep 6, 2026
- Last materially changed
- Sep 6, 2026
- Why it is still here
- The development remains active for implementation or monitoring. The September 13 through September 19 official-source review did not identify a superseding action, and the assigned operational response remains open.
What to do nextRevenue cycle and procurement should reconcile invoice-based wound-care claims to actual purchase records, credits and discounts under the applicable payer rules.
- Reconcile invoice-supported claims to actual acquisition costs.
- Review credits and discounts before finalizing claims.
Permalink: #heuser-health-skin-substitute-invoice-settlement · Development ID GC-2026-0041
P2
NEW
Operationally relevant
Pending litigation
- What changed
- DOJ filed a False Claims Act complaint against former Capstone Diagnostics executives and associated entities. The complaint alleges mass-event genetic testing and added respiratory panels that physicians did not individually request, supported by copied signatures, standing orders, standardized diagnosis codes, sales-personnel ordering, and kickbacks. DOJ alleges Medicare paid about $13.7 million from 2019 through 2021. These are allegations, and the civil and related criminal matters remain pending.
- Why it matters
- The complaint identifies laboratory controls that can fail together: treating-provider authorization, standing-order limits, diagnosis specificity, sales access to ordering workflows, medical necessity, and remuneration tied to volume.
- Response type
- Assess
- Confidence
- High
- Who this affects
- Health systems, Provider networks
- Jurisdiction
- Federal, Georgia
- Agencies
- U.S. Department of Justice, HHS Office of Inspector General, Federal Bureau of Investigation
- Entities
- Former Capstone Diagnostics executives and associated entities
- Action type
- Judgment
- Event date
- Sep 17, 2026
- Alleged conduct
- Alleged medically unnecessary genetic and respiratory panel testing generated through mass events, copied signatures, standing orders, standardized diagnoses, sales ordering, and kickbacks.
- Resolution
- Complaint filed. Liability has not been determined.
What to do nextSample genetic and respiratory panel claims for individualized treating-provider orders, valid signatures, patient-specific diagnoses, medical necessity, and marketer compensation. Remove sales access to clinical ordering functions and escalate copied or standing-order patterns.
- Laboratory tests need individualized treating-provider orders.
- Sales personnel should not create clinical orders.
- Standing orders and copied signatures require focused monitoring.
- Marketer compensation must not reward federally reimbursed test volume.
Permalink: #capstone-laboratory-medicare-fca-complaint · Development ID GC-2026-0104
P2
NEW
Operationally relevant
Settled
- What changed
- HHS OIG announced that Remedi SeniorCare agreed to pay $5.3 million to resolve allegations that it billed for drugs dispensed without valid prescriptions.
- Why it matters
- Long-term care pharmacy and facility workflows depend on valid, timely prescriber orders and controls that stop claims when an order is missing or expired.
- Response type
- Assess
- Confidence
- High
- Who this affects
- Health systems, Provider networks
- Jurisdiction
- Federal, Maryland
- Agencies
- HHS Office of Inspector General
- Entities
- Remedi SeniorCare
- Action type
- Settlement
- Event date
- Sep 16, 2026
- Alleged conduct
- Billing federal healthcare programs for drugs allegedly dispensed without valid prescriptions.
- Resolution
- The pharmacy agreed to pay $5.3 million to resolve the allegations.
What to do nextAudit prescription-validity controls, emergency and refill workflows, prescriber-order retention, and claim edits for long-term care pharmacy services.
- Validate prescription authority before dispensing and billing.
- Retain accessible prescriber-order evidence.
- Use claim edits to stop billing when required order data is missing.
Permalink: #remedi-invalid-prescriptions-settlement · Development ID GC-2026-0122
P3
CARRYOVER
Operationally relevant
Settled
- What changed
- The Justice Department announced on August 26, 2026 a settlement of $5,038,011, allowed as a class three general unsecured claim in bankruptcy, resolving allegations that DermTech billed Medicare for skin cancer tests using an unvalidated positive control range for one of two key melanoma markers between October 2022 and March 2023, and billed for tests that lacked sufficient patient RNA yet still produced results reported to patients between January 2020 and February 2022. The case began as a qui tam action by a former employee, who receives twenty percent of the recovery. The company is liquidating following a June 2024 Chapter 11 filing. The claims resolved by the settlement are allegations only and there has been no determination of liability.
- Why it matters
- Two distinct failures are alleged and both are laboratory quality questions that became billing questions: a control range that was not validated, and results released on specimens that did not meet the assay input requirement. A hospital that performs, sends out, or resells molecular testing inherits the same question, and CMS separately announced large scale prepayment and enrollment action against laboratory billing this same week.
- Response type
- Assess
- Confidence
- High
- Who this affects
- Health-tech, Health systems
- Jurisdiction
- Federal, California
- Agencies
- U.S. Department of Justice, Civil Division, U.S. Attorney Office, Southern District of California, Federal Bureau of Investigation, HHS Office of Inspector General
- Entities
- DermTech Inc., DTech Liquidating Inc.
- Action type
- Settlement
- Event date
- Aug 26, 2026
- Alleged conduct
- Alleged billing of Medicare for melanoma tests run against an unvalidated positive control range, and for tests performed on specimens with insufficient RNA whose results were nonetheless reported to patients. The allegations were resolved without any determination of liability.
- Resolution
- A settlement of $5,038,011 allowed as a class three general unsecured claim in the bankruptcy, with twenty percent to the relator. The claims are allegations only and there has been no determination of liability.
- First seen
- Aug 30, 2026
- Last materially changed
- Aug 30, 2026
- Why it is still here
- The development remains active for implementation or monitoring. The September 13 through September 19 official-source review did not identify a superseding action, and the assigned operational response remains open.
What to do nextAsk the laboratory director, in writing, for the validation record behind the control ranges on the molecular assays the organization bills, and for the specimen sufficiency criteria and the rate at which results are released on insufficient specimens. Where testing is sent out, confirm the reference laboratory agreement lets the organization request those records.
- Assay validation records become billing records once a claim is submitted for the result.
- Specimen sufficiency criteria need a documented failure path, not a workaround that still releases a result.
- A former employee brought this case, which is the ordinary origin of laboratory quality qui tam actions.
Permalink: #dermtech-unvalidated-skin-cancer-test-settlement · Development ID GC-2026-0007
P3
CARRYOVER
Operationally relevant
Final
- What changed
- The Federal Trade Commission announced on August 25, 2026 that it approved the final consent order in the $3.9 billion Ascension Health and AmSurg transaction, docket 251-0093, on a 2 to 0 vote after the public comment period. The order requires divestiture of seven ambulatory surgery centers across Nashville, Panama City, Tulsa, Waco and Wichita, with six going to SC Affiliates and the Panama City center to Florida Gastroenterology Center, and it requires Ascension to give the Commission prior notice of any future ambulatory surgery center acquisition in the metropolitan areas surrounding the divested centers. The Commission alleged the deal would limit competition for outpatient surgical services in gastroenterology, ophthalmology and orthopedics.
- Why it matters
- The prior notice provision is the part with a long tail. A health system that accepts a consent order accepts a reporting duty that attaches to future transactions in named markets, which is a standing compliance obligation rather than a one time divestiture. For any system evaluating ambulatory surgery center acquisitions, the order is also the current statement of how the Commission draws outpatient surgical service markets.
- Response type
- Monitor
- Confidence
- High
- Who this affects
- Health systems, Provider networks
- Jurisdiction
- Federal
- Agencies
- Federal Trade Commission
- Entities
- Ascension Health Alliance, AmSurg LLC
- Action type
- Consent order
- Event date
- Aug 25, 2026
- Alleged conduct
- That the $3.9 billion acquisition would limit competition for outpatient surgical services in gastroenterology, ophthalmology and orthopedics across five metropolitan areas.
- Resolution
- Final consent order approved 2 to 0 requiring divestiture of seven ambulatory surgery centers and prior notice to the Commission for future ambulatory surgery center acquisitions in the surrounding metropolitan areas.
- First seen
- Aug 30, 2026
- Last materially changed
- Aug 30, 2026
- Why it is still here
- The development remains active for implementation or monitoring. The September 13 through September 19 official-source review did not identify a superseding action, and the assigned operational response remains open.
What to do nextIf the organization is evaluating ambulatory surgery center or physician practice acquisitions, read the market definitions in this order before the next transaction memo is written. If the organization is subject to any existing consent order, confirm that a named owner tracks its prior notice obligations and that transaction planning routes through that owner.
- A consent order creates an ongoing reporting obligation that outlives the divestiture and needs a named owner.
- The market definitions in a finalized order are the most current statement of how the agency will look at the next deal.
- Ambulatory surgery center concentration by specialty, rather than hospital concentration, is where the Commission focused here.
Permalink: #ftc-final-consent-order-ascension-amsurg · Development ID GC-2026-0008
P3
CARRYOVER
Operationally relevant
Effective
- What changed
- FDA's August 31 order permanently bars Rahim Shafa from services to persons holding approved or pending drug applications and bars drug importation for 20 years, following federal felony convictions.
- Why it matters
- FDA debarment is a distinct screening issue from exclusion from federal healthcare programs.
- Response type
- Assess
- Confidence
- High
- Who this affects
- Health systems, Provider networks
- Jurisdiction
- Federal
- Agencies
- FDA
- Entities
- Rahim Shafa
- Action type
- Exclusion
- Event date
- Aug 31, 2026
- Alleged conduct
- Federal felony convictions relating to drug regulation and importation formed the basis of FDA's order.
- Resolution
- Permanent drug-application services debarment and 20-year import debarment; the controlled Exclusion category here denotes FDA debarment, not an OIG exclusion.
- First seen
- Sep 6, 2026
- Last materially changed
- Sep 6, 2026
- Why it is still here
- The development remains active for implementation or monitoring. The September 13 through September 19 official-source review did not identify a superseding action, and the assigned operational response remains open.
What to do nextOrganizations using drug-development or import services should assess FDA debarment screening and contract controls.
- Screen the relevant FDA debarment list as well as healthcare exclusion sources.
Permalink: #fda-rahim-shafa-debarment · Development ID GC-2026-0029
P3
CARRYOVER
Operationally relevant
Final
- What changed
- Poul Thorsen pleaded guilty to wire fraud September 1 after diverting more than $1 million of CDC research funds through false invoices and personal bank accounts. Sentencing is scheduled for December 1.
- Why it matters
- Research-payment controls need independent payee and invoice verification, including overseas collaborators.
- Response type
- Assess
- Confidence
- High
- Who this affects
- Health systems, Provider networks
- Jurisdiction
- Federal
- Agencies
- DOJ, HHS-OIG
- Entities
- Poul Thorsen
- Action type
- Criminal resolution
- Event date
- Sep 1, 2026
- Alleged conduct
- False invoices and forged authorization diverted research grants into personal accounts.
- Resolution
- Guilty plea entered; sentence has not been imposed. The $1 million describes diverted funds, not a fine.
- First seen
- Sep 6, 2026
- Last materially changed
- Sep 6, 2026
- Why it is still here
- The development remains active for implementation or monitoring. The September 13 through September 19 official-source review did not identify a superseding action, and the assigned operational response remains open.
What to do nextResearch finance should verify payee ownership separately from investigator-supplied instructions and review unusual grant reimbursement requests.
- Independently verify beneficiary bank accounts.
- Separate investigator approval from reimbursement release.
Permalink: #cdc-autism-research-grant-wire-fraud-plea · Development ID GC-2026-0036
P3
CARRYOVER
Operationally relevant
Final
- What changed
- Loretta Pyeatt pleaded guilty September 4 to access-device fraud after stealing at least $321,000 from a care client. Sentencing is scheduled for December 9.
- Why it matters
- Permission to purchase groceries became access to unrestricted withdrawals and personal spending.
- Response type
- Assess
- Confidence
- High
- Who this affects
- Health systems, Provider networks
- Jurisdiction
- Federal
- Agencies
- DOJ
- Entities
- Loretta Pyeatt
- Action type
- Criminal resolution
- Event date
- Sep 4, 2026
- Alleged conduct
- Debit cards entrusted for groceries were used for unauthorized purchases and cash withdrawals.
- Resolution
- Guilty plea entered; no sentence or fine has yet been imposed.
- First seen
- Sep 6, 2026
- Last materially changed
- Sep 6, 2026
- Why it is still here
- The development remains active for implementation or monitoring. The September 13 through September 19 official-source review did not identify a superseding action, and the assigned operational response remains open.
What to do nextHome-care and residential-care leaders should review client-fund access, receipt reconciliation, transaction alerts and independent complaint channels.
- Limit financial access to documented authorized tasks.
- Escalate unexplained transaction spikes and reconcile receipts.
Permalink: #dent-county-caregiver-access-device-plea · Development ID GC-2026-0042
P3
CARRYOVER
Operationally relevant
Final
- What changed
- DOJ reported September 2 that Adam Gentile received a four-year prison sentence on August 27 for embezzling $7.8 million from two medical practices. Restitution orders total $7.1 million; forfeiture is $7.8 million.
- Why it matters
- Sole control over payroll enabled extra paychecks labeled as bonuses and payment of personal expenses.
- Response type
- Assess
- Confidence
- High
- Who this affects
- Health systems, Provider networks
- Jurisdiction
- Federal
- Agencies
- DOJ
- Entities
- Adam Gentile
- Action type
- Criminal resolution
- Event date
- Aug 27, 2026
- Alleged conduct
- Office-manager access enabled unauthorized compensation and personal payments across two employers.
- Resolution
- Sentence followed March guilty pleas; announcement is in this coverage week, while the sentencing event predates it.
- First seen
- Sep 6, 2026
- Last materially changed
- Sep 6, 2026
- Why it is still here
- The development remains active for implementation or monitoring. The September 13 through September 19 official-source review did not identify a superseding action, and the assigned operational response remains open.
What to do nextPractice leadership should independently review payroll changes, bonuses and bank disbursements, including payments benefiting finance staff.
- Separate payroll preparation from approval.
- Review employee-linked disbursements independently.
Permalink: #medical-practice-payroll-embezzlement-sentence · Development ID GC-2026-0043
P3
CARRYOVER
Operationally relevant
Settled
- What changed
- Novum agreed to pay $3,345,000 to resolve allegations that its $2 million Second Draw PPP loan was ineligible because domestic and foreign affiliates pushed headcount above 300. No liability was determined.
- Why it matters
- Healthcare research businesses must support relief-program eligibility certifications with the required affiliate analysis. This case concerns SBA lending, not healthcare claims.
- Response type
- Assess
- Confidence
- High
- Who this affects
- Health systems, Provider networks
- Jurisdiction
- Federal
- Agencies
- DOJ
- Entities
- Novum Pharmaceutical Research Services of Delaware, Inc.
- Action type
- Settlement
- Event date
- Sep 1, 2026
- Alleged conduct
- Second Draw eligibility and forgiveness were allegedly obtained despite aggregate affiliate headcount exceeding the program threshold.
- Resolution
- Civil False Claims Act settlement with no determination of liability.
- First seen
- Sep 6, 2026
- Last materially changed
- Sep 6, 2026
- Why it is still here
- The development remains active for implementation or monitoring. The September 13 through September 19 official-source review did not identify a superseding action, and the assigned operational response remains open.
What to do nextFinance and counsel should retain contemporaneous affiliate and workforce calculations for relief-loan certifications and assess any unresolved certification discrepancies.
- Include relevant domestic and foreign affiliates in eligibility analysis.
- Retain evidence supporting application and forgiveness certifications.
Permalink: #novum-ppp-affiliate-size-settlement · Development ID GC-2026-0044
P3
CARRYOVER
Operationally relevant
Final
- What changed
- CalPrivacy announced September 1 that its August 27 decision requires SalesIntel Research to pay $36,400 for untimely data-broker registration and to implement privacy-request measures.
- Why it matters
- Health-tech marketing and data businesses should assess broker status and vendor controls. This is a professional-contact and advertising-data case; the announcement does not identify a healthcare-data violation.
- Response type
- Assess
- Confidence
- High
- Who this affects
- Health-tech
- Jurisdiction
- California
- Agencies
- California Privacy Protection Agency
- Entities
- SalesIntel Research, Inc.
- Action type
- Consent order
- Event date
- Aug 27, 2026
- Alleged conduct
- Operating as a data broker without registration by the 2025 deadline.
- Resolution
- Decision adopts a stipulated order requiring a $36,400 fine, public rights-request metrics, DROP access, and processing of future deletion requests.
- First seen
- Sep 6, 2026
- Last materially changed
- Sep 6, 2026
- Why it is still here
- The development remains active for implementation or monitoring. The September 13 through September 19 official-source review did not identify a superseding action, and the assigned operational response remains open.
What to do nextCheck broker registration, rights-request metrics, and DROP processes where applicable. Vendor review should include website-visitor identification products and the data used for outreach.
- Assess broker status before annual registration deadlines.
- Reconcile public privacy metrics with actual request handling.
Permalink: #salesintel-data-broker-registration-order · Development ID GC-2026-0049