ApolloMD's $4.02M Breach Settlement & the Scoular FCPA Action (07/21/2026)
- › ApolloMD, a healthcare business associate, agreed to pay $4.02 million to settle a data breach class action.
- › A new FCPA enforcement action against Scoular centers on customs bribes and cartel links, signaling renewed anti-corruption focus.
- › Craneware, a financial software vendor for US healthcare organizations, confirmed a cyber incident with data theft.
- › HHS is seeking public input on potential updates to the CLIA regulations that govern clinical laboratories.
- › New Jersey's labor department clarified employer obligations for job protection under its temporary disability and family leave laws.
Today’s compliance news is a run of bills coming due, most of them in healthcare. ApolloMD is paying $4.02 million to settle a breach, another healthcare software vendor is disclosing a data theft, and a fresh FCPA action puts customs bribery back on the enforcement radar. The through-line is third-party exposure: the entities in trouble today are the ones other organizations trusted to hold their data or move their goods, which makes their problems your problems.
Top 5 Critical Compliance Alerts
1. ApolloMD Pays $4.02M to Settle a Breach Suit
ApolloMD Business Services, a business associate providing physician and practice management services, agreed to pay $4.02 million to settle a data breach class action (HIPAA Journal). A business associate breach is the case where your patients’ data is exposed through a vendor you hired, and under HIPAA the obligations and the reputational damage still reach back to the covered entities that trusted them.
Operator Note: Every business associate that touches your protected health information is a path to a settlement with your name adjacent to it. Confirm your business associate agreements are current and that each one carries real breach notification and security terms.
2. A New FCPA Action Targets Scoular Over Customs Bribes
A newly announced Foreign Corrupt Practices Act enforcement action against Scoular involves customs bribes and cartel links, and sets new compliance expectations (JD Supra). Customs and logistics is where anti-corruption exposure hides for many companies, because payments to move goods across a border can cross a legal line that the people arranging them do not always recognize.
3. Craneware Discloses a Healthcare Data Theft
Craneware, a provider of financial software for US healthcare organizations, confirmed a cybersecurity incident involving unauthorized access and the theft of a significant amount of data (HIPAA Journal). Financial software for hospitals holds billing and patient records at the intersection of two regulated domains, which makes a vendor like this a high-value target and its customers a downstream exposure.
4. HHS Seeks Input on Updating CLIA Regulations
The Department of Health and Human Services is seeking public input on potential updates to the Clinical Laboratory Improvement Amendments (CLIA) regulations that govern laboratory testing (HIPAA Journal). A request for input is the early window where the rules that will bind clinical labs are still being shaped, and the organizations that comment now are the ones that get to influence what they will have to comply with later.
5. New Jersey Clarifies Leave Job Protection Obligations
New Jersey’s labor department clarified employer obligations for job protection under the state’s temporary disability and family leave insurance laws (JD Supra). Leave administration is an area where a well-meaning employer can create liability by handling a return-to-work wrong, and clearer guidance is worth reading before the next employee goes out on leave.
Additional Compliance Alerts
Third-Party Risk & Due Diligence
- Pre-Merger Notification Under Canada’s Competition Act: A practical guide walks through when a transaction triggers premerger notification obligations in Canada, useful for any business with cross-border deal exposure. JD Supra
The Axe Report is a daily briefing from Grab The Axe. Need help assessing your organization’s security posture? Take our free Human Attack Surface Score assessment.
A leader defined by a 'bias for action,' Dusten specializes in physical security assessments that impact profitability and facility resilience.
View Profile →Media Inquiries
For expert commentary, interview requests, or high-res assets regarding this announcement, initialize the terminal.