Blogs
Clock 4 minute read

On September 11, 2026, California’s Office of Health Care Affordability (OHCA) Department of Health Care Access and Information (HCAI) released advance notification of proposed emergency regulatory action (the “Proposed Emergency Regulations”) regarding material change health care transactions. The Proposed Emergency Regulations—subsequently submitted to the state’s Office of Administrative Law (OAL)—further implement California’s AB 1415[1] respecting state oversight of private equity (PE) groups, hedge funds, and management services organizations (MSOs) operating in the health care space. As EBG wrote at the time of signing in 2025, AB 1415, which took effect January 1, 2026, represented a significant change for PE groups, hedge funds, and MSOs in the state by expanding OHCA’s notice requirements.

[1] Cal. Stats. 2025, ch. 641

Blogs
Clock 8 minute read

On September 18, 2026, the U.S. Department of Justice (DOJ) announced revisions to two sections of the Justice Manual (JM) in an effort to strengthen the “fight against fraud” in False Claims Act (FCA) and other civil enforcement matters. The revisions clarify and reinforce limits on the use of sub-regulatory guidance in DOJ litigation and on when DOJ will seek dismissal of qui tam actions.

Blogs
Clock 5 minute read

On September 14, 2026, the U.S. Small Business Administration (SBA) announced suspensions for 870,000 U.S. borrowers, tied to an estimated $39 billion in suspected fraud in COVID-era loan programs (“SBA Announcement”). The same day, the U.S. Department of Justice’s (DOJ) National Fraud Enforcement Division (NFED) reported the results of a related criminal enforcement effort targeting SBA-related pandemic fraud (“DOJ Announcement”).

Blogs
Clock 6 minute read

On September 2-3, 2026, the Department of Health and Human Services (“HHS”) Office for Civil Rights (“OCR”) and the National Institute of Standards and Technology (“NIST”) hosted the Safeguarding Health Information: Building Assurance Through HIPAA Security 2026 conference.

This post shares takeaways in three key areas highlighted at the conference.

Blogs
Clock 2 minute read

On behalf of one or more health care practices that furnish device-enabled remote monitoring services to Medicare beneficiaries, Epstein Becker Green (EBG) submitted comments on September 14, 2026, to the Centers for Medicare and Medicaid Services (CMS) related to the 2027 Physician Fee Schedule Proposed Rule (“Proposed Rule”).

These comments oppose restrictions the practices believe would reduce patient access and care quality and recommend evidence-based oversight alternatives instead.

In the Proposed Rule, CMS announced potentially sweeping changes to Medicare payment rules for remote physiologic monitoring (RPM) and remote therapeutic monitoring (RTM). The practices assert that, if finalized, these rules would negatively impact the future of both RPM and RTM. EBG submitted comments on five specific proposed restrictions.

Blogs
Clock 8 minute read

On September 8, 2026, the U.S. Department of Labor’s (DOL’s) Employee Benefits Security Administration (EBSA) issued Field Assistance Bulletin No. 2026-03 (“FAB 2026-03”) and an accompanying compliance resource identifying potential warning signs of Mental Health Parity and Addiction Equity Act (MHPAEA) violations.

Blogs
Clock 3 minute read

Veloxis Pharmaceuticals, Inc. (“Veloxis”) recently agreed to pay more than $46 million to resolve criminal and civil allegations that it paid kickbacks to health care professionals to encourage prescriptions and sales of a brand-name immunosuppression drug to kidney transplant recipients instead of a generic drug. What makes this settlement noteworthy is that it includes a civil penalty of $1.55 million to address claims that Veloxis knowingly failed to report to the Centers for Medicare and Medicaid Services payments to health care professionals (“HCPs”) under the federal Open Payments Program (also known as the Physician Payments Sunshine Act or “Sunshine Act”). This civil penalty is the largest penalty ever imposed under the Sunshine Act.

Blogs
Clock 4 minute read

On September 9, 2026, the Federal Trade Commission (“FTC”) rescinded its 2021 policy statement which extended the Health Breach Notification Rule (“HBNR”) to health apps and connected devices outside the reach of the Health Insurance Portability and Accountability Act of 1996 and its implementing regulations (collectively “HIPAA”).

In its recent press release, the FTC called that prior guidance “obsolete” and “unnecessary,” concluding it provided minimal benefit and had been superseded by rulemaking. This is not a minor course correction at a moment when the Centers for Medicare and Medicaid Services (“CMS”) is actively steering seniors toward health apps that require collection and processing of identifiable consumer health information outside the reach of HIPAA.

Blogs
Clock 8 minute read

Almost two years after Judge Kathryn Kimball Mizelle of the U.S. District Court for the Middle District of Florida became the first federal judge in the country to declare the qui tam provisions of the False Claims Act (FCA) unconstitutional, the U.S. Court of Appeals for the Eleventh Circuit vacated Judge Mizelle’s September 30, 2024, order and held that the FCA’s qui tam provisions do not violate the Appointments Clause of the U.S. Constitution. The case now returns to the District Court.

On September 1, 2026, a unanimous panel of the Eleventh Circuit concluded in United States ex rel. Zafirov v. Florida Medical Associates LLC that qui tam whistleblowers, or relators, who bring a case under the federal FCA in the name of the U.S. government are not “officers of the United States” occupying a “continuing position established by law.”

However, the lower court considered only the Appointments Clause; on remand, the Middle District of Florida must consider, in the first instance, whether the same qui tam provisions violate the Constitution’s Vesting and Take Care clauses.

Blogs
Clock 4 minute read

Bill Gates published an essay this week arguing that the AI transition will be one of the most turbulent periods in modern history.  And critically, neither governments nor industry have a plan to manage it. While the essay has far-reaching implications for all industries and humanity generally, three key risk categories emerge for health care and life sciences organizations. It is a useful moment to connect his framing to what is actually showing up in legislative bodies, enforcement actions, and litigation.

Search This Blog

Recent Updates

Related Services

Topics

Archives

Jump to Page

Subscribe

Sign up to receive an email notification when new Health Law Advisor posts are published:

Privacy Preference Center

When you visit any website, it may store or retrieve information on your browser, mostly in the form of cookies. This information might be about you, your preferences or your device and is mostly used to make the site work as you expect it to. The information does not usually directly identify you, but it can give you a more personalized web experience. Because we respect your right to privacy, you can choose not to allow some types of cookies. Click on the different category headings to find out more and change our default settings. However, blocking some types of cookies may impact your experience of the site and the services we are able to offer.

Strictly Necessary Cookies

These cookies are necessary for the website to function and cannot be switched off in our systems. They are usually only set in response to actions made by you which amount to a request for services, such as setting your privacy preferences, logging in or filling in forms. You can set your browser to block or alert you about these cookies, but some parts of the site will not then work. These cookies do not store any personally identifiable information.

Performance Cookies

These cookies allow us to count visits and traffic sources so we can measure and improve the performance of our site. They help us to know which pages are the most and least popular and see how visitors move around the site. All information these cookies collect is aggregated and therefore anonymous. If you do not allow these cookies we will not know when you have visited our site, and will not be able to monitor its performance.