Wade's Health Law Highlights for July 21, 2026


July 22, 2026

This week

  • Laboratory Corporation of America agreed to pay $14.5 million to settle False Claims Act allegations that it billed Medicare for unnecessary urine drug tests by routinely running and charging for both presumptive and definitive testing on the same sample under its “ToxAssure Comprehensive” panel.
  • iMessage can’t be made HIPAA compliant no matter how you configure it, because Apple won’t sign a Business Associate Agreement, backs up messages to iCloud with keys stored on its own servers, and offers no admin controls or audit trails, leaving healthcare organizations exposed to fines up to $50,000 per violation.
  • Beginning July 31, Texas will ban Delta-8 and other hemp-derived THC isomers by classifying them as controlled substances, though ongoing lawsuits and unclear enforcement leave the future of the rule in doubt.

Fraud, Abuse & False Claims Act Enforcement

  • Laboratory Corporation of America will pay $14,500,000 to resolve False Claims Act allegations that it billed Medicare Part B for medically unnecessary urine drug testing under its “ToxAssure Comprehensive” panel. From January 1, 2018, through November 22, 2023, Labcorp ran presumptive and definitive tests simultaneously on the same patient, on the same date of service, using the same urine sample, and billed Medicare with CPT Code 80307 for the presumptive testing and HCPCS Code G0483 for the highest-tier definitive testing each time the panel was performed. For several substances, Labcorp performed definitive testing directly, without first conducting a presumptive test to establish the necessity of the definitive test, even where a presumptive option existed. Labcorp admitted these facts, represented that it has stopped billing Medicare the combination of codes 80307 and G0483 for ToxAssure Comprehensive beneficiaries, and received credit under Justice Manual §4-4.112 for disclosure, cooperation, and remediation. The Justice Department’s Civil Division and the U.S. Attorney’s Office for the District of Massachusetts resolved the matter with support from HHS-OIG and the FBI. Source: United States Department of Justice
  • Medical technology companies face False Claims Act liability even when they do not submit claims for government funds directly. The FCA imposes liability on anyone who knowingly submits or causes the submission of false claims, defines “knowingly” broadly without requiring specific intent to defraud, and permits per-claim civil penalties between $14,308 and $28,619 plus three times the government’s damages, with most cases arising from qui tam whistleblower suits. Of the more than $6.8 billion in FCA settlements during fiscal year 2025, over $5.7 billion involved the healthcare industry, and MedTech firms have settled claims tied to kickback schemes ($17 million), training providers to reuse single-use devices in violation of Medicare’s “reasonable and necessary” requirement ($550,000), and false cybersecurity representations on genomic sequencing software ($9.8 million). Companies should build compliance programs targeting anti-kickback, Stark law, unapproved device, and off-label promotion risks, encourage internal reporting without retaliation, and investigate reports quickly since the FCA rewards swift self-disclosure. When unsure whether conduct constitutes a violation, companies should consult counsel and document remediation efforts. Upon receiving an internal complaint, civil investigative demand, subpoena, or audit request, companies should engage legal counsel experienced with the DOJ. Source: Fisher Phillips LLP

Anti-Kickback Statute & OIG Guidance

  • The OIG issued a favorable advisory opinion permitting a federally qualified health center to provide free produce boxes and vouchers to financially needy patients with diabetes or hypertension. Under the Arrangement, 50 selected Participants receive either weekly $30 produce boxes delivered to their homes or $20 vouchers redeemable for healthy foods at local grocers and farmers markets over a 6-month period, alongside initial, midpoint, and final health assessments with a registered dietician and behavioral health consultant. The Requestor bills patients and insurers for reimbursable assessment services under its Sliding Fee Discount Policy, funds the program through grants, and does not consider insured status when selecting Participants. OIG concluded that although the Arrangement implicates the Federal anti-kickback statute (no safe harbor applies) and the Beneficiary Inducements CMP (the Financial Need-Based Exception is unmet because the produce is tied to reimbursable services), the fraud-and-abuse risk is low given alignment with the Requestor’s HRSA-approved scope, the in-kind and narrowly tailored nature of the remuneration, the limited value and duration, retained cost-sharing obligations, and Voucher Company safeguards including receipt checks, site visits, cashier trainings, and retailer MOUs. Source: OIG Advisory Opinion No. 26-16

HIPAA Breaches & Enforcement

  • All About Women’s Care has notified 12,000 patients that their protected health information was compromised after an attacker obtained an employee’s VPN credentials and used them to enter the practice’s network. The Englewood, Colorado obstetrics and gynecology practice identified suspicious activity involving the VPN account and engaged third-party cybersecurity experts, who confirmed the unauthorized access and determined that files were copied, with the file review completed on June 5, 2026. The affected data included names, dates of birth, Social Security numbers, driver’s license numbers, other identification numbers, clinical and treatment information, lab results, prescription information, provider information, medical documents, ultrasound images, copies of identification documents such as passports, and health insurance information. The breach was reported to the HHS Office for Civil Rights as affecting up to 12,000 patients, and the practice is reviewing its data privacy and security policies and procedures. Separately, Mid-South Pulmonary Sleep Specialists in Memphis, Tennessee began notifying patients about a November 2, 2025 network intrusion claimed by the Anubis ransomware group, with the data review completed May 18, 2026 and the affected individual count not yet posted to the OCR breach portal. Source: The HIPAA Journal

Medical Device Regulation & Compliance

  • The number of regulations imposed on medical device manufacturers increased 64% between 2015 and 2022, and the compliance landscape has continued to expand since. U.S. manufacturers spend an average of $24 million on FDA-related requirements to bring a single device from concept to market, a figure that rises to $75 million for devices in the FDA’s highest-risk Class III, while the European Union’s 2021 replacement of the Medical Device Directive with the Medical Device Regulation has increased manufacturer regulatory costs up to tenfold. Approval timelines range from a few weeks to eight months in the United States, a year or longer in the EU, and one to three years in Japan. The United States regulates devices through the FDA across three risk categories, requiring clearance to market, a Quality Management System Regulation harmonized to ISO 13485, and post-market surveillance; the United Kingdom requires UKCA marking and registration through the MHRA; and Canada’s Medical Devices Directorate licenses Class II, III, and IV devices and may suspend a license or require a recall or refit when a device no longer meets safety and effectiveness requirements. Violations can carry penalties of $100,000 or more and imprisonment in cases of criminal negligence. Source: The HIPAA Journal

Health IT, Data Security & HIPAA Compliance Practice

  • iMessage cannot meet HIPAA requirements, and no configuration changes can fix that. Apple’s iCloud Terms of Service prohibit healthcare organizations from using iCloud to create, receive, maintain, or transmit protected health information, and because iMessages back up to iCloud by default, texting about patients violates both HIPAA and Apple’s terms. Three gaps disqualify the app: Apple will not sign a Business Associate Agreement, the encryption key for backed-up messages sits on Apple’s servers under default settings, and personal Apple IDs provide no admin controls, audit trails, or exportable records. Messages sync across every device on an Apple ID, former employees retain full chat histories on their own devices, and HIPAA fines can reach $50,000 per violation, with the average healthcare data breach costing $7.42 million according to the HIPAA Journal. A compliant replacement requires a signed BAA, organization-controlled cloud storage, one-click offboarding, granular admin permissions, and exportable activity records, with Zenzap cited as an option built for healthcare teams. Source: Analytics Insight
  • AWS is not HIPAA-compliant by default, and organizations must sign a Business Associate Addendum before any covered service can touch protected health information. Under the shared responsibility model, the customer configures encryption, access control, network isolation, audit logging, and breach notification, using VPCs with private subnets, KMS for key management, scoped IAM policies, and CloudTrail and CloudWatch for audit trails. Compliant architectures separate public-facing components from patient-data workloads in private subnets, encrypt data at rest with KMS keys and in transit with TLS, apply the same encryption to backups, and keep S3 buckets holding health data private. HIPAA’s minimum necessary standard requires IAM roles mapped to job function, immutable CloudTrail logs stored in a separate restricted account, and mandatory multi-factor authentication for human access. Common failures include leaving default security group rules in place, storing keys in code or environment variables, skipping BAAs with third-party tools, and treating compliance as a one-time setup rather than conducting regular access reviews and configuration audits. Source: Finextra
  • Five specialized assessments enable regulated organizations to achieve and maintain SOC 2 Type II certification for artificial intelligence systems. The five evaluations cover AI governance and policy, data security and privacy controls, risk management and threat modeling, continuous monitoring and incident response, and third-party vendor and supply chain compliance. Each assessment maps controls across additional frameworks, including CMMC for defense contractors, NIST for cybersecurity risk management, ISO 27001 for information security management, HIPAA for protected health information, and FedRAMP for cloud service providers. Recommended practices include quarterly gap analyses, deploying automated monitoring tools for real-time anomaly detection, building a prioritized risk register for 2027 regulatory updates, and establishing contractual controls with periodic vendor reassessments. Organizations should schedule annual assessments beginning in 2026 and pair them with ongoing training and technology investments. Source: Security Boulevard

Texas Regulatory Developments

  • Beginning July 31, Texas will classify Delta-8 THC and other hemp-derived THC isomers as controlled substances, forcing their removal from store shelves. The Texas Department of State Health Services republished its 2021 rule in the Texas Register on July 10, following the Texas Supreme Court’s reversal of an injunction that a Travis County judge had granted to block enforcement. The rule affects products containing Delta-8, Delta-10, Delta-6, and THCP, and the Texas Hemp Business Council is advising retailers to remove or sell through affected inventory before the effective date. Under federal and Texas law, hemp contains less than 0.3% Delta-9 THC while marijuana exceeds that threshold, a framework established by the 2018 Farm Bill and adopted by Texas in 2019. At least two lawsuits challenging the regulations remain active with additional challenges being prepared, and questions persist over enforcement because DSHS has stated it is not the enforcement mechanism. Source: Chron

Wade Emmert

Partner & Healthcare Practice Group Leader

Board Certified, Health Law // Certified Information Privacy Professional (CIPP/US) // Artificial Intelligence Governance Professional (AIGP) // Certified in Cybersecurity (ISC2 CC)

Healthcare Empowered Podcast

Thanks for reading! If you loved it, tell your friends to subscribe. To change your email or preferences manage your profile. You can unsubscribe here.

901 Main Street, Suite 5500, Dallas, TX 75202

Wade Emmert

Carrington, Coleman, Sloman & Blumenthal, LLP

Read more from Wade Emmert

July 22, 2026 This week The Texas Supreme Court ruled that omissions claims under the Texas Health Care Program Fraud Prevention Act must prove materiality even though the statute never uses that word, holding that a defendant who disclosed its conduct and kept getting paid without objection had effectively negated any claim that the omitted pricing information mattered to the government’s payment decision. Express Scripts is suing Texas Attorney General Ken Paxton to block the full release...

July 22, 2026 This week HHS Secretary Robert F. Kennedy Jr. has stacked the FDA’s Pharmacy Compounding Advisory Committee with nine new members largely favorable to peptide use, just ahead of July meetings on whether compounding pharmacies can produce unproven peptides like BPC-157 that FDA scientists say lack sufficient evidence of safety and efficacy. OIG Advisory Opinion No. 26-15 concludes that a home health agency’s payment of per-hospital subscription fees for online referral management...

July 22, 2026 This week The Justice Department’s 2026 National Health Care Fraud Takedown charged 455 defendants, including 90 medical professionals, across 56 federal districts in schemes totaling more than $6.5 billion in false claims, with authorities seizing over $182 million in assets and securing arrests abroad in massive catheter and telemedicine fraud cases. Thirteen defendants in the Northern District of Texas have been charged across seven cases tied to more than $365 million in...