The DOJ Issues Its First Healthcare Declination & Health-ISAC Warns on ShinyHunters (07/31/2026)
- › The DOJ declined to bring criminal healthcare fraud charges against Campus Eye Management and its parent, the first healthcare declination under its new department-wide Corporate Enforcement Policy.
- › Health-ISAC warned health sector organizations about an increase in successful attacks by the ShinyHunters extortion group.
- › Colorado's contested AI Act has been amended after repeated challenges and delays since it was signed in 2024.
- › California ALPR litigation is surging after the Court of Appeal's decision in Bartholomew v. Parking Concepts, exposing any business that scans license plates.
- › CMS proposed sweeping restrictions on remote patient monitoring, including an outsourcing ban and reimbursement changes, reversing last year's expansion.
Today’s compliance news gives operators a rare piece of good news and two warnings. The DOJ showed what self-disclosure can actually buy in a healthcare fraud case. Health-ISAC told the sector which group is currently succeeding against it. And a California appellate decision turned license plate scanning into litigation exposure for businesses that never thought of themselves as surveillance operators.
Top 5 Critical Compliance Alerts
1. The DOJ Declines Charges in a Healthcare Fraud Case
The Department of Justice declined to bring criminal healthcare fraud charges against Campus Eye Management and its parent company, the first healthcare fraud declination under the DOJ’s new department-wide Corporate Enforcement Policy (JD Supra). A declination is the outcome every compliance program is theoretically working toward, and the first one under a new policy is the clearest signal available about what the department expects self-disclosure, cooperation, and remediation to look like (JD Supra).
Operator Note: Read this declination alongside your own self-disclosure decision framework. The value of voluntary disclosure has been theoretical for most organizations, and a documented case gives your board something concrete when the next hard conversation arrives.
2. Health-ISAC Warns of Rising ShinyHunters Attacks
Health-ISAC warned health sector organizations about an increase in successful attacks by the ShinyHunters extortion group (HIPAA Journal). The same group was named this week in the compromise of a major physical security brand’s SaaS systems, and a threat actor working through software-as-a-service platforms reaches your data without ever touching your network.
3. Colorado’s AI Act Is Amended After a Long Fight
Colorado’s AI Act has been amended following sustained criticism that it was too onerous, burdensome, and vague to implement, closing a saga that began when it was signed in May 2024 (JD Supra). Organizations that paused their Colorado AI compliance work during the uncertainty should confirm what survived the amendments before assuming the obligation went away.
4. California ALPR Litigation Surges
Businesses that scan license plates have become a prominent target for privacy litigation in California following the Court of Appeal’s decision in Bartholomew v. Parking Concepts (JD Supra, JD Supra). Parking operators, retailers with lot cameras, and property managers rarely think of themselves as running surveillance technology, and the statute does not care how they describe it.
Operator Note: If any camera on your property reads plates, including parking enforcement and access control, find out what data it retains and who it shares with. That is now a litigation question in California.
5. CMS Moves to Restrict Remote Patient Monitoring
The CY 2027 Proposed Rule marks a sharp reversal on remote patient monitoring, proposing an outsourcing ban and reimbursement restrictions a year after CMS expanded the programs (JD Supra). Providers that built RPM programs around the 2026 expansion should model what an outsourcing ban does to their staffing before the rule is final.
Additional Compliance Alerts
Supply Chain
- The FCC Expands Covered List Prohibitions to Component Level: A Third Report and Order extends covered list prohibitions to devices containing certain logic-bearing hardware components and imposes new compliance obligations on online marketplaces. JD Supra
The Axe Report is a daily briefing from Grab The Axe. Need help assessing your organization’s security posture? Take our free Human Attack Surface Score assessment.
A leader defined by a 'bias for action,' Dusten specializes in physical security assessments that impact profitability and facility resilience.
View Profile →Media Inquiries
For expert commentary, interview requests, or high-res assets regarding this announcement, initialize the terminal.