Healthcare Compliance News

House Subcommittee on Health Examines Healthcare Cybersecurity Proposals

On September 15, 2026, the United States House Energy and Commerce Committee Subcommittee on Health held a legislative hearing on proposals to improve healthcare cybersecurity, reform Medicare provider payments, and other healthcare matters. At the hearing, titled Examining Legislative Proposals to Reform Medicare Provider Payment and Bolster Health Care Cybersecurity, the subcommittee discussed two bills that seek to improve healthcare cybersecurity – the Rural Hospital Cybersecurity Enhancement Act and the Healthcare Cybersecurity and Resiliency Act of 2026.

Healthcare data breaches have increased significantly in recent years. For the past five years, more than 700 data breaches affecting 500 or more individuals have been reported to the HHS’ Office for Civil Rights (OCR), and a new record was set in 2025, with 804 large data breaches currently listed on the OCR data breach portal. As of August 30, 2026, 496 large data breaches have been reported to OCR, indicating that 2026 will be another 700+ data breach year. So far this year, more than 74.6 million individuals have had their protected health information exposed. Last year, 140.5 million individuals were affected by large healthcare data breaches.

The increase in data breaches is largely driven by hacking and other IT incidents. Out of this year’s 496 large data breaches, 426 breaches are due to hacking and other IT incidents. That’s 86% of this year’s total, and accounts for 97.8% of the individuals whose protected health information has been breached this year. Healthcare organizations are required to comply with the HIPAA Rules, but with data breaches occurring at the current rate, it suggests either widespread noncompliance or ineffective regulations.

Healthcare breaches not only violate Americans’ privacy and put them at risk of identity theft and fraud; hacking incidents, especially ransomware attacks, cause massive operational disruption that affects the ability of healthcare providers to provide care. All too often, cyberattacks result in cancelled appointments, rescheduled surgeries, and delays to emergency care, which affect patient outcomes.

Get The FREE
HIPAA Compliance Checklist

Immediate Delivery of Checklist Link To Your Email Address

Please Enter Correct Email Address

Your Privacy Respected

HIPAA Journal Privacy Policy

An update to the HIPAA Security Rule has been proposed that includes a raft of new security requirements to improve healthcare cybersecurity; however, the proposed rule was heavily criticized by industry groups, health systems, and hospitals. The final rule has been delayed until at least July 2027, although a decision has yet to be made about whether a final rule will be issued. Even if it is, the requirements will not need to be implemented until at least early 2028.

Implementing more robust cybersecurity measures comes at a cost, and that is especially problematic for rural healthcare providers, many of whom are already facing significant financial challenges without having to commit additional funds to improving cybersecurity. Each dollar spent on cybersecurity improvements is a dollar lost to patient care. The relative lack of cybersecurity resources and personnel makes rural and other resource-constrained healthcare providers soft targets for hackers, and cyberattacks that disrupt patient care can result in dangerous delays to healthcare services, as alternative facilities may be hundreds of miles away.

The Rural Hospital Cybersecurity Enhancement Act, a bipartisan bill co-sponsored by Representatives Erin Houchin (R-IN) and Rep. Kim Schrier (D-WA), was introduced to better protect rural healthcare providers against cyber threats by improving the cybersecurity workforce and improving resources.  That includes mandates for the HHS to provide free instructional materials to help rural healthcare providers train existing staff, targeted educational criteria aimed at improving cybersecurity training in rural educational institutions, and a workforce development strategy to expand the rural healthcare IT workforce.

The other key healthcare cybersecurity bill under consideration is the bipartisan Health Care Cybersecurity and Resiliency Act of 2026, which was introduced by Senate Health, Education, Labor & Pensions (HELP) Committee Chair, Sen. Bill Cassidy (R-LA), and co-sponsored by Sens. Mark Warner (D-VA), Maggie Hassan (D-NH), and John Cornyn (R-TX). The aim of the bill is to better protect patient health data, improve coordination between the HHS and the Cybersecurity and Infrastructure Security Agency (CISA), and strengthen overall cybersecurity defenses within the healthcare and public health sector.

At the hearing, the subcommittee heard testimony from Greg Garcia, Executive Director for Cybersecurity at the Healthcare and Public Health Sector Coordinating Council (HSCC) Cybersecurity Working Group, on the state of healthcare cybersecurity and the pending two healthcare cybersecurity bills. Garcia warned that the nation’s rural and resource-constrained healthcare providers are the most vulnerable in the sector and are unprepared to protect against evolving cyber threats and technological innovation, including beneficial and adversarial uses. He called for “a concerted, multi-pronged combination of government programs, assistance and funding with market-based mutual support and community defense.”

Garcia made several recommendations, including workforce training on cybersecurity, especially at rural and low-resourced healthcare providers where it is desperately needed. Garcia said it is essential that grants are made available to allow rural and resource-constrained healthcare providers to make the necessary upgrades to cybersecurity, such as replacing end-of-life medical devices that lack the capacity to be made secure. Garcia also recommended that the HHS official appointed as responsible for coordinating cybersecurity internally and across the sector should be designated at the deputy assistant secretary level or higher, and for that individual to have the authority to influence policy and program decisions.

He advised against implementing regulations that require specific security technologies such as encryption and multifactor authentication, such as the mandatory measures in the proposed update to the HIPAA Security Rule, as it will be far more effective to address risks through evolving industry cybersecurity frameworks. Garcia suggested that the proposed HIPAA Security Rule update should be reset or abandoned, as it “did not demonstrate sufficient insight to the complexities of achieving effective cybersecurity protections for the health sector, nor acknowledge the considerable work the sector and government partners have accomplished in good faith and urgency over the past 6 years to build a collective cyber defense.”

Garcia also requested that HSCC be involved in cybersecurity policy decisions and should be included in threat information sharing and incident response advisories, as it is the primary cross-sector healthcare advisory council focused exclusively on critical infrastructure cybersecurity

The post House Subcommittee on Health Examines Healthcare Cybersecurity Proposals appeared first on The HIPAA Journal.

FTC Rescinds 2021 Policy Statement on Health App Data Breaches

In September 2021, the U.S. Federal Trade Commission (FTC) issued a policy statement extending the FTC Health Breach Notification Rule to cover health apps and other connected devices not covered by the Health Insurance Portability and Accountability Act (HIPAA). On September 9, 2026, the FTC withdrew that policy statement as it was considered to provide little benefit, having been superseded by rulemaking.

The Health Breach Notification Rule was issued in 2009 under the Health Information Technology for Economic and Clinical Health (HITECH) Act and applies to vendors of personal health records (PHRs) and related entities that are not subject to HIPAA. In 2021, the FTC determined that because health apps were mainstream and increasingly collected consumers’ sensitive health and personal information, the developers of the apps should have a responsibility to ensure that the data they collect is secured, protected against unauthorized access, and that consumer notifications are required when there is a breach of that information or an unauthorized disclosure.

Per the 2021 policy statement, the FTC viewed the developers of health apps and other connected devices to be vendors of personal health records, if an app or device had the capability to draw data from multiple sources and was not covered by a similar rule issued by the Department of Health and Human Services. The change in position was contentious at the time, and while the policy statement received majority FTC backing, it was only approved with a 3-2 vote. Commissioners Noah Joshua Philips and Christin S. Wilson voted against the policy statement, with both believing that the FTC’s interpretation of applicability for the Health Breach Notification Rule stretched the statutory text beyond its terms.

In 2024, the FTC updated its Health Breach Notification Rule, significantly expanding its scope. The definition of health information was broadened to make it clear that the rule applies to data collected via health apps, connected devices, and any other technology that draws health inferences from user data. The update also clarified that breaches that trigger the notification requirements include cybersecurity incidents and unauthorized disclosures to third parties.

Get The FREE
HIPAA Compliance Checklist

Immediate Delivery of Checklist Link To Your Email Address

Please Enter Correct Email Address

Your Privacy Respected

HIPAA Journal Privacy Policy

In its September 9, 2026, statement, the FTC said the 2024 update the Health Breach Notification Rule rendered the policy statement unnecessary and that pursuant to an Executive Order by President Trump, agencies have been directed to eliminate obsolete guidance documents, policy statements, and unnecessary rules that provide no benefit to Americans, hence the decision to withdraw the policy statement.

The post FTC Rescinds 2021 Policy Statement on Health App Data Breaches appeared first on The HIPAA Journal.

FDA Seeks Feedback on Potential Regulation of GenAI Medical Devices

The U.S. Food and Drug Administration (FDA) has issued a discussion paper on considerations for the regulation of Generative AI (GenAI)-enabled medical devices. As a regulator of all medical devices, the FDA is considering whether new regulations are required for GenAI-enabled medical devices to ensure patients are provided with timely access to safe and effective devices.

GenAI-enabled medical devices have the potential to transform patient care, yet the devices may introduce unique risks compared to traditional software and artificial intelligence (AI)-enabled medical devices. Current regulatory frameworks, such as those used for traditional medical devices, may not be appropriate for GenAI-enabled devices, which present unique challenges and risks.

The devices have unique characteristics and behaviours, including the capability to produce variable outputs, which change over time as the devices incorporate continuously learning systems. GenAI devices can accept open-ended inputs, and it is not feasible to test the full range of inputs and assess outputs using traditional premarket testing methodologies. The FDA notes that many devices are built on general-purpose foundation models, which have been developed by third parties that have varying levels of transparency into training data, architecture, and evaluation methods. As such, specific behaviors and errors are difficult to attribute to the underlying model used by the devices.

While GenAI-enabled devices offer a wide range of benefits over and above what can be gained from traditional and AI-enabled medical devices, the characteristics that provide those benefits also present unique risks. For instance, GenAI systems may misinterpret or distort data, filling in knowledge gaps with plausible but invented information (confabulations), such as associating a symptom with the wrong condition. There is also a risk of hallucinations – the generation of false facts – on which output is based and presented as fact. GenAI tools may provide outputs that are plausible and sound authentic to end users, which may be questionable at best and potentially dangerous to health.

Get The FREE
HIPAA Compliance Checklist

Immediate Delivery of Checklist Link To Your Email Address

Please Enter Correct Email Address

Your Privacy Respected

HIPAA Journal Privacy Policy

The discussion paper, published by the FDA’s Center for Devices and Radiological Health (CDRH) –  Considerations for the Regulation of Generative AI-Enabled Medical Devices: Discussion Paper and Request for Feedback – delves into the challenges associated with premarket evaluation and postmarket monitoring of GenAI-enabled medical devices. The aim of the paper is to guide discussion and focus feedback ahead of the potential development of guidance and future regulations. No decision has been made about whether FDA regulation is required, or areas where guidance may be necessary.  The feedback obtained in response to the discussion paper will guide future FDA decisions, including new methodologies for premarket evaluation and the postmarket assessment of the performance of GenAI-enabled medical devices to ensure they remain safe and effective throughout the entire product lifecycle.

The paper discusses the possibility of competency-based testing of GenAI-enabled medical devices for premarket evaluations, using an approach modelled on medical training, licensure examinations, supervised practice, periodic reevaluation, and public reporting, and device benchmarking to assess whether a device demonstrates the necessary clinical knowledge, analytic capabilities, safety behavior, communication, and generalizability to support reasonable assurance of safety and effectiveness of the device for its intended use. Potentially, clinical confirmation will be required, as a competency-based approach may not fully assess performance in a clinical setting.

The FDA anticipates a risk-based approach will be necessary for regulation, taking into consideration the intended use and device characteristics. For instance, certain action-directing functions may be classed as higher risk than functions that provide non-directive information, as well as agentic AI systems capable of autonomous actions.

The FDA said it wishes to work collaboratively with the full range of stakeholders to develop efficient, scientifically sound, and least burdensome approaches to the premarket evaluation and postmarket monitoring of GenAI-enabled devices. Feedback on the discussion draft is requested from medical device manufacturers, clinicians, researchers, and the general public by October 19, 2026.

The post FDA Seeks Feedback on Potential Regulation of GenAI Medical Devices appeared first on The HIPAA Journal.

Merit Health Central Hospital & NorthShore University Health System Settle EMTALA Violations

The Department of Health and Human Services Office of Inspector General (HHS-OIG) has announced that two settlements have been agreed to resolve alleged violations of the Emergency Medical Treatment and Labor Act (EMTALA).

EMTALA was enacted by Congress in 1986 to ensure public access to emergency medical services. EMTALA requires Medicare-participating hospitals that offer emergency services to provide a medical screening examination (MSE) to patients who present to their emergency department requesting an examination or treatment for an emergency medical condition, regardless of the patient’s ability to pay.

A patient must be provided with stabilizing treatment if the MSE determines that they have an emergency medical condition. If the hospital lacks the capability to provide stabilizing treatment, or if requested by the patient, they must initiate an appropriate transfer.  The receiving hospital must have the available space and qualified personnel and must agree to accept the transfer. The transferring hospital must send all medical records related to the emergency condition that are available at the time of the transfer, and send all other records as soon as is practicable. Hospitals that violate EMTALA can face heavy civil monetary penalties, and individuals harmed may pursue legal action for EMTALA violations.

Merit Health Central Hospital

Merit Health Central Hospital in Jackson, Mississippi, formerly known as Central Mississippi Medical Center, has agreed to settle alleged EMTALA violations with HHS-OIG and will pay a $350,000 financial penalty. Unusually, the case relates to patients who presented at the hospital emergency room more than a decade ago. The delay in issuing the penalty was due to a False Claims Act lawsuit related to the alleged EMTALA violations that was working its way through the legal system. HHS-OIG’s investigation determined that the hospital failed to provide an adequate MSE and stabilizing treatment to fourteen patients who presented to its emergency room between January 2013 and April 2015 requesting an examination or treatment for a medical condition.

Out of the fourteen individuals, nine had emergency medical conditions and were transferred to another hospital between January 2013 and May 2013 without providing an appropriate MSE and treatment to stabilize the patients to minimize the risk of transfer, despite having staff within its facilities or available as on-call physicians who could have provided the necessary stabilizing treatment. In six cases, the transfers were based on its application of Central MS Trauma Region Trauma Activation Criteria and Destination Guidelines for the transfer of individuals with penetrating trauma to another hospital. Several of the patients had presented with gunshot wounds.

Four patients presented to the emergency room between March 2015 and April 2015 with a psychiatric emergency medical condition and were not provided with an appropriate MSE within the capabilities of the hospital or stabilizing treatment. The four individuals were transferred by taxi in an unstable condition to a homeless day shelter. One patient presented to the emergency room in March 2015 for treatment related to end-stage renal disease and had an emergency medical condition requiring dialysis, yet stabilizing treatment was not provided even though it was within the hospital’s capabilities.

NorthShore University Health System

NorthShore University Health System in Evanston, Illinois, agreed to settle alleged an EMTALA violation concerning a patient who presented to its emergency room in February 2025 complaining of leg pain and nausea.

The 64-year-old man presented to the emergency department at 10:53 a.m. and was triaged at 11:15 a.m. During triage, the patient’s vitals were taken. He had a heart rate of 126 bpm and was assigned an emergency severity index (ESI) level of 2 – high risk. The patient was placed in a wheelchair in a waiting room but was not reassessed, and his vitals were not rechecked. The patient was found slumped over and unresponsive in the wheelchair at 8:55 p.m – more than 9 hours after he was triaged. The patient was determined to be in cardiac arrest, and CPR was quickly initiated. HHS-OIG’s investigation determined that Northshore failed to provide an appropriate MSE. The case was settled with a $105,000 financial penalty.

The post Merit Health Central Hospital & NorthShore University Health System Settle EMTALA Violations appeared first on The HIPAA Journal.

FTC; Utah; California Sue Him & Hers Over Business and Data Sharing Practices

Him & Hers, a San Francisco, CA-based telehealth company, is being sued by the Federal Trade Commission (FTC) and the states of Utah and California over the company’s business and data sharing practices, which are alleged to violate the Federal Trade Act, Restore Online Shoppers’ Confidence Act, Utah Consumer Sales Practices Act, and California’s False Advertising and Unfair Competition Laws.

Him & Hers is a direct-to-consumer business that provides prescription and over-the-counter medications. According to the complaint, filed last week in the U.S. District Court for the Northern District of California, the company claims to maintain consumers’ privacy yet discloses their sensitive data to third-party advertising platforms, without consumers’ knowledge or consent. In addition, the complaint alleges that the company deceives consumers about its billing and cancellation policies.

Him & Hers used tracking technologies such as Meta Pixel and the Meta Conversions API, which automate the recording of user data based on the Him & Hers website and transmit that information to Meta in response to certain events. Him & Hers also used a variety of advertising tools from companies such as Snap, Microsoft, Google, Criteo, Pinterest, TikTok, Trade Desk, and X, which also collected sensitive consumer information and transferred the information to third-party companies for advertising purposes. Him & Hers is also alleged to have sent lists of certain customers to the Meta and Snap custom audience systems.

Oftentimes, consumers use Him & Hers to obtain medications for sensitive medical conditions such as mental health issues, erectile dysfunction, and premature ejaculation. According to the complaint, until at least mid-2023, Him & Hers claimed that “medical records and sensitive information are only accessed by the medical providers managing your care,” and has claimed in its online advertising that consumers are provided with a “100% online, private, and secure process,” yet sensitive information was being shared with third parties for advertising purposes.

In addition to the unlawful data transfers, the complaint alleges that Him & Hers failed to clearly disclose that consumer prescriptions are charged almost immediately after completing an intake form. Consumers were informed that they could consult with a medical provider to find a suitable treatment and would not be charged unless and until their prescriptions are prescribed. The FTC alleges that Him & Hers rarely provides medical consultations, enrolls customers almost immediately into recurring subscription plans, and makes it difficult for consumers to cancel their subscriptions. For instance, consumers are not informed clearly and conspicuously when their recurring prescriptions will be refilled, which makes it difficult for them to cancel before the next billing cycle. Consumers are also not permitted to cancel subscriptions online, only via the phone, email, or chat, and the complaint alleges that consumers must navigate other hurdles, making it “extremely difficult” to cancel subscriptions.

The lawsuit seeks a permanent injunction preventing the company from engaging in unfair and deceptive business practices, civil penalties, and monetary awards. “The FTC’s complaint lays out a troubling scenario—consumers unknowingly locked into recurring subscriptions and the disclosure to third parties of consumers’ most private health information without their consent,” said Christopher Mufarrige, Director of the FTC’s Bureau of Consumer Protection. “The FTC will not hesitate to act on behalf of consumers deprived of their ability to choose which products they want and whether to keep their most sensitive health information private.”

This is not the first time that the FTC has taken action against telehealth companies over the use of tracking technologies. Enforcement actions have previously been filed against the fertility tracking app Premom, BetterHelp, and GoodRx. In each case, the complaints were resolved with financial penalties.

The post FTC; Utah; California Sue Him & Hers Over Business and Data Sharing Practices appeared first on The HIPAA Journal.

GAO Report Identifies Potentially Duplicative Cyber Reporting Requirements for Critical Infrastructure

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) is shortly due to issue a final rule implementing the Cyber Incident Reporting for Critical Infrastructure Act of 2022 (CIRCIA). While the final rule was expected in May 2026, it has been delayed until September 2026. When issued, entities in the 16 critical infrastructure sectors will be required to report substantial cyberattacks to CISA within 72 hours of formulating a reasonable belief that such an incident has occurred.

The Trump administration issued a new cybersecurity strategy in March 2026 that prioritized harmonization and the reduction of compliance burdens, while enhancing cybersecurity of the nation’s critical infrastructure. The nation’s critical infrastructure is dependent on computer-based information systems, most of which are owned by the private sector. Those systems are subject to multiple federal regulations, some of which have overlapping requirements.

The Government Accountability Office was asked to review federal cybersecurity requirements for critical infrastructure to identify potential opportunities for harmonization. A recently published GAO report focuses on the potentially duplicative cybersecurity-related reporting requirements for critical infrastructure sectors. In some cases, the same types of information must be reported to different federal agencies, which requires multiple reports to be written about the same cybersecurity incident or compliance activity. That inevitably means resources are being diverted to compliance activities that could be better used for improving security.

Out of 117 regulations identified by GAO across 9 critical infrastructure sectors, 80 – approximately 70% – had the same kind of reporting requirement as another regulation. Across those 80 regulations, there were at least 125 total reporting requirements, as some regulations required multiple types of reporting – 48 required reporting of cybersecurity incidents, 52 required cybersecurity plans or other technical information, and 25 required reviews, audits, or assessments.

GAO believes that duplicative reporting requirements add an unnecessary administrative burden on critical infrastructure entities, which will soon face the additional reporting requirements of CIRCIA. While CIRCIA will improve federal visibility into cybersecurity incidents, it will certainly add to the reporting burden.

GAO is working on obtaining additional industry perspectives on federal cybersecurity regulations, such as where there are overlapping and duplicative reporting requirements, and it intends to issue an implementation plan to help streamline cybersecurity regulations for critical infrastructure entities.

The post GAO Report Identifies Potentially Duplicative Cyber Reporting Requirements for Critical Infrastructure appeared first on The HIPAA Journal.

HHS Seeks Input on Potential Updates to the CLIA Regulations

The HHS’ Centers for Medicare and Medicaid Services (CMS) and the Centers for Disease Control and Prevention (CDC) have issued a request for information (RFI) on potential updates to the Clinical Laboratory Improvement Amendments (CLIA) of 1988. The RFI covers several topics, including breath testing, laboratory processes and procedures, emergency preparedness, cybersecurity, and the use of artificial intelligence. The feedback received in response to the RFI will advise future actions and rulemaking. Comments are being accepted through September 14, 2026.

The CLIA regulations were enacted on October 31, 1988, strengthening federal oversight of clinical laboratories and helping to ensure the accuracy and reliability of patient test results. The CLIA regulations were promulgated in 1992, and while certain elements of the CLIA regulations have been updated over the years, a substantial update may be required to better reflect current knowledge and advancements in laboratory testing.

One area where updates may be required is cybersecurity, as threats across the healthcare sector have expanded significantly in both scope and severity. “As clinical laboratories increasingly rely on digital systems and connected technologies—such as Laboratory Information System (LIS), Electronic Health Record (EHR) integration, automated diagnostic devices, and virtual or remote access to laboratory and patient data—new cybersecurity risks have emerged,” explained the CMS and CDC in the RFI.

Many U.S. laboratories are HIPAA-regulated entities and must therefore comply with the requirements of the HIPAA Security Rule; however, there are gaps that need to be addressed and threats that the current HIPAA Security Rule does not adequately protect against. The CMS is seeking non-proprietary/non-confidential information on current laboratory cybersecurity practices and experiences related to protecting patient data and lab operations; user identity and access; remote access to systems containing personal information from overseas entities; restrictions on ports and/or internet protocol (IP) addresses; cybersecurity response plans; and cybersecurity training.

One area where further regulation is likely required is artificial intelligence, as the CLIA regulations were enacted long before AI tools started to be used in clinical settings. Model corruption, hallucinations, and compromises could have serious implications for the accuracy and reliability of testing. The CMS and CDC are seeking information on postanalytic interpretation and the use of AI tools, specifically, the algorithms and AI tools used in postanalytic analysis; the circumstances where software and AI tools are being used to interpret test results, histopathology slides, and results; the methods used to verify the performance of those tools; and whether there are any additional technology considerations for high complexity tests that the CMS and CDC should consider incorporating into the CLIA regulations.

The post HHS Seeks Input on Potential Updates to the CLIA Regulations appeared first on The HIPAA Journal.

DOJ’s Using Advanced Data Analytics and AI Tools to Combat Healthcare Fraud Before Payment

The U.S. government has announced record-breaking Medicaid fraud charges as part of its 2026 National Health Care Fraud Takedown, with the enforcement action resulting in charges for 455 defendants, including more than 90 doctors and other licensed medical professionals, in connection with more than $6.5 billion in healthcare fraud and opioid abuse claims.

The enforcement action involved a whole-government approach, including U.S. Department of Health and Human Services Office of Inspector General (HHS-OIG), HHS Centers for Medicare and Medicaid Services (CMS), and Drug Enforcement Administration (DEA), with cases in 56 federal districts, 45 U.S. states and territories, and 50 state Medicaid Fraud Control Units participated, more than ever before. There was also unprecedented international cooperation over the two-week takedown. The DOJ seized more than $182 million in cash, luxury vehicles, jewelry, and other assets.

“We are aggressively scaling our offensive against anyone using health care as a front to steal from the American people,” said Assistant Attorney General Colin M. McDonald of the Justice Department’s National Fraud Enforcement Division. “As today’s cases and arrests show, there is no case too big, no scheme too complex, and no hiding place too remote for our relentless fraud-fighting team. Our message is simple: if you put profit over patients, you should expect to be put in prison.”

Advanced Algorithms and AI Tools Used to Shift from Pay-and-Chase to Pre-Payment Detection

The takedown involved the use of cutting-edge data analytics algorithms and artificial intelligence tools to identify potential fraud before criminals cash out, rather than the reactive pay-and-chase approach of previous years. The use of AI tools for fraud prevention is set to expand significantly moving forward. AI tools were used to identify suspicious activity in many of the fraud schemes, including the first-ever criminal prosecution under the Data Fusion Center that was formed last year.

The Data Fusion Center was established to track, identify, and prevent fraudulent billing and medical scams and combines traditional data analytics with financial analysis and comprises experts from the Health Care Fraud Unit’s Data Analytics Team, HHS-OIG, FBI, and other agencies, supported by data sharing agreements between a wide range of government agencies. “Prosecuting criminals who steal from American patients is necessary—but stopping them before a single dollar leaves the building is smarter,” said CMS Administrator Dr. Mehmet Oz.

The Data Fusion Center helped identify a $67 million fraud scheme involving the billing of Illinois Medicaid for behavioral health services that were never provided. The defendant allegedly billed more than 500 hours a day for counselling and therapy services, which could not have been provided even if all providers on staff had been working 24 hours per day. The data analysis showed that patients were hospitalized at other institutions on days when the defendant billed for behavioral health services. Prosecutors opened the case within 5 days of the completion of the data analysis, and the defendant was arrested within 7 months while attempting to flee the country.

Actions by the CMS resulted in the suspension of 1,079 providers and the revocation of billing privileges for 1,403 providers. More than $73 million was obtained in 48 Civil Monetary Payment settlements accompanied by more than 1,400 exclusions, while 25 actions by HHS-OIG are seeking more than $10 billion in payments to the Medicare Trust Fund from payments identified by CMS and blocked before the funds were paid in fraudulent claims. CMS has announced that under a new arrangement, it will provide cloud computing space within its integrated data repository to support the DOJ fraud division’s data analysis algorithms and AI tools to combat health care fraud. Civil charges have been filed against 13 defendants for $14.8 million in health care fraud schemes, along with $23 million in civil settlements with 31 defendants. There have also been 928 administrative cases by the DEA seeking the revocation of authority to handle and prescribe controlled substances since October 1, 2025.

Fraud Costs Taxpayers and Causes Significant Patient Harm

Healthcare fraud costs U.S. taxpayers, exploits vulnerable patients and puts lives at risk, causing considerable patient harm, including death. In one case, the medical director of a cardiovascular testing and treatment practice in Florida was charged in connection with an $89 million fraud scheme to bill for medically unnecessary cardiovascular tests on student athletes. The director falsified diagnoses to defraud health care benefit programs for the testing and is alleged to have rubber-stamped test results as normal without checking them, in some cases stamping test results as normal within seconds.

Student athletes with cardiac abnormalities were not made aware that they were at high risk of sudden cardiac arrest. In one case, a patient’s test results showed an enlarged heart, but the results were signed off as normal. The patient died from complications from his enlarged heart within 24 hours of the test results being signed off as normal.

The DOJ highlighted fraud cases involving wound care, especially allografts, and hospice providers in its announcement, where fraud cases have increased significantly, and these are likely to remain key enforcement areas moving forward. Medicare billing for wound care more than doubled from $3.4 billion in 2023 to $7.5 billion in 2024 and almost doubled again in 2025 to $14.4 billion. The increase in payments was not due to medical necessity; rather, it was driven by illegal kickback and healthcare fraud schemes. Charges were filed in 6 districts for fraudulent claims for amniotic wound allografts against 11 defendants, including a company executive and 8 medical professionals.

In one scheme, a company that did not manufacture allografts obtained them from another firm, added a 2,000% mark-up, paid 40% of that in illegal kickbacks to marketers, and targeted hospice patients, providing medically unnecessary allografts, far exceeding the size of the wound, which were often provided without coordinating with the individual’s treating physician, without proper treatment for infection, and for superficial wounds that did not require the treatment, The defendant was paid more than $24 million by the company, with the marketers and medical professionals involved often paid between $500 and $600 per square centimeter of graft.

“Today’s historic enforcement action sends a clear message: if you use our health care system to enrich yourself at the expense of patients or the American people, we will find you, we will prosecute you, and we will hold you accountable,” said HHS Secretary Robert F. Kennedy, Jr. “HHS will continue working with our law enforcement partners to protect patients, safeguard taxpayer dollars, and restore integrity to our health care system.”

The post DOJ’s Using Advanced Data Analytics and AI Tools to Combat Healthcare Fraud Before Payment appeared first on The HIPAA Journal.

California AG Files Lawsuit Over 23andMe Data Breach

California Attorney General Rob Bonta has filed a lawsuit against the genetic testing company formerly known as 23andMe over its 2023 data breach that affected almost 7 million Americans. The lawsuit alleges multiple violations of state consumer privacy and data protection laws.

23andMe is a provider of direct-to-consumer DNA testing services. Consumers purchase kits for collecting saliva samples, which are sent to the company for DNA analysis. Consumers are given a report detailing their ancestry, ethnicity, and genetic health predispositions, and can access a platform that allows them to trace their biological relatives.

In 2023, 23andMe discovered that around 14,000 accounts had been subject to unauthorized access over a period of around 5 months, resulting in a breach of the personal and genetic information of 6.9 million individuals, including 855,541 California residents. Access to the accounts was gained using a technique known as credential stuffing. Credentials obtained in a data breach on one platform are used to try to access accounts another platform. The technique only works if users reuse their usernames and passwords on multiple platforms. In the case of the 23andMe attack, some of the credentials were stolen from MyHeritage, a separate genealogy site that 23andMe encouraged its users to set up an account with.

The data breach was discovered when the threat actor offered the stolen data for sale on a dark web hacking forum in October 2023. Initially, 23andMe downplayed the incident, maintaining that there had been no breach of its systems, placing the blame on customers for the poor security practice of re-using credentials on multiple platforms. 23andMe also said the breach involved data from its DNA Relatives feature, which was essentially publicly available information. 23andMe paid the threat actor to remove data that had been posted online, stop any sale of stolen data, and to receive information about the vulnerabilities that were exploited by the threat actor to access data.

23andMe, which filed for Chapter 11 bankruptcy protection in March 2025, faced class action litigation over the data breach and agreed to pay $30 million to settle claims related to the data breach, then increased the settlement fund to up to $50 million. The settlement received final approval from a judge in January 2026.

The California Department of Justice, part of a multistate coalition that investigated the data breach, determined that security vulnerabilities were exploited that should not have existed, and that the company’s handing of the breach was “entirely unacceptable.” The investigation determined that there was a well-known risk of unauthorized account access through credential stuffing, yet 23and Me failed to implement reasonable and appropriate security procedures to reduce risk. The data breach was only detected when the threat actor offered stolen data for sale in October 2023. AG Bonta alleged that 23andMe missed several opportunities to detect the credential stuffing attack, such as a suspicious spike in login attempts in July 2023, and a Reddit post discussing a potential 23andMe data breach in August 2023.

A coding error in the DNA Relatives feature meant doctored queries could be sent to the 23andMe database, and when creating and implementing its data security protocols, 23andMe failed to properly account for genetic data and its high level of sensitivity. 23andMe informed its customers that it adhered to the highest industry standards for data security; when its security practices were far below industry standards. Further, when the breach was announced, AG Bonta alleges that 23andMe made misleading statements, repeatedly stating that there had been no breach of 23andMe systems, despite the threat actor informing the company of multiple exploitable vulnerabilities within its systems, some of which were exploited in the attack.

The state Attorney General’s lawsuit was filed in the San Francisco Superior Court, California, and alleges that the company failed to implement and maintain reasonable and appropriate security procedures and practices, made untrue and misleading statements regarding its security measures and practices prior to the data breach, as well as misleading statements about the circumstances of the breach. Those failures are alleged to have violated the California Genetic Information Privacy Act, Reasonable Data Security Law, False Advertising Law, Unfair Competition Law, and the California Consumer Privacy Act. The lawsuit seeks millions of dollars in civil fines to resolve the alleged violations.

The California Attorney General has also challenged 23andMe’s sale of consumers’ genetic information and materials in bankruptcy. That lawsuit is pending in the in U.S. Bankruptcy Court for the Eastern District of Missouri.

The post California AG Files Lawsuit Over 23andMe Data Breach appeared first on The HIPAA Journal.