Wade’s Health Law Highlights for September 29, 2026
Fraud & Abuse Enforcement
- The Department of Justice revised the Justice Manual to limit the use of sub-regulatory guidance in False Claims Act enforcement and to direct attorneys to consider dismissing qui tam actions the government declines. The first revision, announced September 18, 2026, reinstates and builds on the Department’s 2017 policy that agency guidance cannot impose legal obligations beyond those established by statute or regulation. The second revision directs the Department to consider exercising its dismissal authority whenever it declines to intervene in a qui tam action, and to revisit that assessment during litigation where it does not seek dismissal. Associate Attorney General Stanley E. Woodward, Jr. said the Department “should enforce the law, not make law through enforcement.” The revisions appear in Justice Manual 1-19.000 and Justice Manual 4-4.111. Source: U.S. Department of Justice
- HHS OIG waived the requirement that state Medicaid Fraud Control Units (MFCUs) obtain federal approval before conducting federally funded data mining of Medicaid claims. State Fraud Policy Transmittal No. 2026-1, issued August 13, 2026, waives the prior-approval and three-year renewal requirements in 42 C.F.R. § 1007.20(a)(4) in their entirety. Before the change, OIG’s list reflected approved data-mining programs in only 25 states and the District of Columbia. MFCUs must still coordinate with their state Medicaid agencies, train data-mining staff, and report costs, cases, recoveries, and return on investment under 42 C.F.R. § 1007.17(a)(1)(ii). The waiver does not authorize payment suspensions, but a credible allegation of fraud arising from claims analysis can trigger a state Medicaid agency’s separate suspension obligations under 42 C.F.R. § 455.23. Source: Holland & Hart Health Law Blog
HIPAA & Health Privacy
- HHS appears poised to finalize its long-pending HIPAA Privacy Rule revisions. The proposed rule, released in the final days of the first Trump administration, would expand information sharing for care coordination and with caregivers and family members, and would revise access-fee and fee-transparency requirements. Covered providers may need to provide access through a secure, standards-based API when requested electronic PHI is readily available through that API, and to permit patients to take notes, photographs, and videos when inspecting their records in person. The rule would eliminate the Notice of Privacy Practices (NPP) acknowledgment requirement for providers with direct treatment relationships and require NPPs to add a right to discuss the notice with a designated contact person. The rule has not yet been published in final form. Source: Hogan Lovells Cadwalader
- Healthcare privacy obligations are expanding through state consumer health data laws and AI use while HHS’s proposed HIPAA Privacy Rule changes remain pending. Washington’s My Health My Data Act requires opt-in consent, grants deletion rights, and allows private lawsuits, and the first class action under it was filed against Amazon in February 2025. Nevada’s SB 370 and Connecticut’s SB 3 amendments are in effect, and New York’s Health Information Privacy Act was vetoed in 2025 and reintroduced in 2026. The Office for Civil Rights has not issued an AI-specific HIPAA rule but has signaled that HIPAA applies to AI tools, with attention to data leakage and missing business associate agreements (BAAs) with AI vendors. Standard rulemaking practice would give covered entities approximately 240 days to comply once the Privacy Rule changes are final. Source: RSM US
- Aspen Dental Management agreed to pay $18.7 million to settle a class action alleging its website tracking pixels shared patient data with Meta and Google without consent. The case, Donnelly v. Aspen Dental Management, covered more than 2 million people who booked appointments on the website between February 2022 and January 2025, and the settlement administrator began issuing payments in February 2026. Pixels on appointment pages, contact forms, and patient portals can capture identifiable health information. Under HHS Office for Civil Rights guidance, transmitting that information to a tracking vendor requires a business associate agreement or a valid patient authorization. Neither Meta nor Google will sign a business associate agreement for its standard pixel and analytics products. Source: DrBicuspid
Data Breaches & Cybersecurity
- Healthcare was the third most targeted U.S. sector for ransomware, with 154 of 200 tracked ransomware groups (77%) targeting it. Anomali’s US Ransomware Industry Targeting Report observed targeting across eight sectors, led by technology at 86% and manufacturing at 83%. Unpatched VPNs, firewalls, edge devices, and other internet-facing applications remain the most common entry points into healthcare environments. Anomali recommends phishing-resistant multifactor authentication for remote access, administrator, SSO, VPN, and privileged service accounts, along with offline, immutable backups tested under ransomware conditions. It also predicts increased use of tools that disable endpoint detection and response (EDR) software over the coming year. Source: The HIPAA Journal
- Austin-based Oculus Pathology notified 20,040 patients that their protected health information was exposed in an email account compromise. Unauthorized third parties accessed employee email accounts between March 31 and April 2, 2026, and the laboratory identified the suspicious activity on April 1. Exposed data included names, Social Security numbers, driver’s license numbers, financial account and payment card numbers, diagnoses, prescription and treatment information, health insurance information, and Medicare numbers. The laboratory provides pathology services to hospitals, ambulatory surgery centers, and physician groups. No misuse of the information has been detected. Source: The HIPAA Journal
Physician Arrangements & Restrictive Covenants
- State noncompete law has split into four models since a federal court set aside the FTC’s nationwide noncompete ban. In Ryan LLC v. FTC, the U.S. District Court for the Northern District of Texas held that the FTC lacked statutory authority to issue the rule, and the FTC later ended its appeals. Texas now requires new or renewed covenants for physicians, dentists, nurses, and physician assistants to be limited to one year and a five-mile radius, be conspicuous, and include a capped buyout, and physician covenants are void after an involuntary discharge without good cause. Pennsylvania voids most new practitioner noncompetes longer than one year, Virginia prohibits noncompetes for health care professionals, and Wyoming separately invalidates physician noncompetes. Florida’s 2025 CHOICE Act moves the other direction, validating qualifying noncompetes of up to four years and requiring courts to preliminarily enjoin covered employees. Source: Law and the Workplace
- Health systems can use existing Stark Law and Anti-Kickback Statute (AKS) flexibilities, including directed-referral provisions and value-based exceptions, to strengthen physician alignment without capital-intensive transactions. CMS has indicated that, under the Stark Law, a physician may receive a bonus or withhold tied to achieving a percentage, but not a number or value, of in-network referrals if the payment meets an applicable exception’s volume or value standards. A compensation arrangement that satisfies a Stark Law value-based exception can take into account the volume or value of referrals and need not be consistent with fair market value, provided the value-based purpose is genuine and commercially reasonable. Recent advisory opinion activity suggests room for ASC arrangements that let employed physicians participate in an ASC’s performance. The 2027 OPPS/ASC proposed rule would change payment for 340B-acquired drugs and remove another 637 procedures from the inpatient-only list. Source: McDermott Will & Schulte
FDA & Biologics
- FDA warned Irvine, California-based NexCell Scientific that its umbilical cord blood-derived cell product is an unapproved new drug and an unlicensed biological product. The September 11, 2026 warning letter, which followed inspections in December 2025 and February 2026, found the product does not qualify for regulation solely as a section 361 HCT/P because it is not intended for homologous use and depends on the metabolic activity of living cells. FDA cited website statements promoting the product for inflammation, neurological conditions, liver cirrhosis, and autoimmune disease as evidence of its intended use. The letter also cited CGMP violations, including an unvalidated aseptic process, no root-cause investigation of lots that failed sterility testing between August 2023 and June 2025, and a single employee handling both manufacturing and quality control. FDA gave the company 15 working days to respond and stated that failure to correct the violations may result in seizure or injunction. Source: FDA
Artificial Intelligence
- AI inventions in the life sciences can be patented when claims tie the AI to specific hardware, data inputs, and outputs rather than reciting an abstract idea. The USPTO applies the Alice-Mayo framework under 35 U.S.C. § 101, and AI claims typically face rejection as abstract ideas directed to mathematical concepts, methods of organizing human activity, or mental processes. The USPTO’s 2024 guidance states that AI limitations that cannot practically be performed in the human mind do not fall within the mental-processes grouping, and that claims reflecting a specific technological solution to a technological problem may be eligible. In Ex Parte Desjardins (2025), the USPTO Appeal Review Panel vacated a § 101 rejection of claims for training machine learning models, finding them directed to an improvement in machine learning. U.S. Patent No. 12,268,530, covering the Oura ring, anchors two machine learning classifiers to wearable heart rate sensors and displays an illness-risk metric. Source: Healthcare Law Insights
- Health systems building AI agents in-house for revenue cycle work face underestimated costs in drift control, model spend, and audit defense. An agent can leave its intended workflow without detection and edit the wrong patient record or submit to the wrong claim, which requires deviation detection and automatic safe-stop controls. Routing every step through a frontier model costs about 10 times as much as using smaller, task-specific models, according to Harpaul Sambhi, CEO of AI agent vendor Magical. In announcing its $23 million settlement with UCHealth over an automated emergency-room coding rule, the Department of Justice said it will hold accountable companies whose automatic coding practices lead to improper billing. Defending an audit requires scoped credentials, permissions enforced at the tool-call level, and a complete, traceable record of every agent action. Source: Becker’s Hospital Review