The DOJ Issues Its First Healthcare Declination & Health-ISAC Warns on ShinyHunters (07/31/2026)

July 31, 2026
The DOJ Issues Its First Healthcare Declination & Health-ISAC Warns on ShinyHunters (07/31/2026)
Key Intel / TL;DR
  • The DOJ declined to bring criminal healthcare fraud charges against Campus Eye Management and its parent, the first healthcare declination under its new department-wide Corporate Enforcement Policy.
  • Health-ISAC warned health sector organizations about an increase in successful attacks by the ShinyHunters extortion group.
  • Colorado's contested AI Act has been amended after repeated challenges and delays since it was signed in 2024.
  • California ALPR litigation is surging after the Court of Appeal's decision in Bartholomew v. Parking Concepts, exposing any business that scans license plates.
  • CMS proposed sweeping restrictions on remote patient monitoring, including an outsourcing ban and reimbursement changes, reversing last year's expansion.

Today’s compliance news gives operators a rare piece of good news and two warnings. The DOJ showed what self-disclosure can actually buy in a healthcare fraud case. Health-ISAC told the sector which group is currently succeeding against it. And a California appellate decision turned license plate scanning into litigation exposure for businesses that never thought of themselves as surveillance operators.

Top 5 Critical Compliance Alerts

1. The DOJ Declines Charges in a Healthcare Fraud Case

The Department of Justice declined to bring criminal healthcare fraud charges against Campus Eye Management and its parent company, the first healthcare fraud declination under the DOJ’s new department-wide Corporate Enforcement Policy (JD Supra). A declination is the outcome every compliance program is theoretically working toward, and the first one under a new policy is the clearest signal available about what the department expects self-disclosure, cooperation, and remediation to look like (JD Supra).

Operator Note: Read this declination alongside your own self-disclosure decision framework. The value of voluntary disclosure has been theoretical for most organizations, and a documented case gives your board something concrete when the next hard conversation arrives.

2. Health-ISAC Warns of Rising ShinyHunters Attacks

Health-ISAC warned health sector organizations about an increase in successful attacks by the ShinyHunters extortion group (HIPAA Journal). The same group was named this week in the compromise of a major physical security brand’s SaaS systems, and a threat actor working through software-as-a-service platforms reaches your data without ever touching your network.

3. Colorado’s AI Act Is Amended After a Long Fight

Colorado’s AI Act has been amended following sustained criticism that it was too onerous, burdensome, and vague to implement, closing a saga that began when it was signed in May 2024 (JD Supra). Organizations that paused their Colorado AI compliance work during the uncertainty should confirm what survived the amendments before assuming the obligation went away.

4. California ALPR Litigation Surges

Businesses that scan license plates have become a prominent target for privacy litigation in California following the Court of Appeal’s decision in Bartholomew v. Parking Concepts (JD Supra, JD Supra). Parking operators, retailers with lot cameras, and property managers rarely think of themselves as running surveillance technology, and the statute does not care how they describe it.

Operator Note: If any camera on your property reads plates, including parking enforcement and access control, find out what data it retains and who it shares with. That is now a litigation question in California.

5. CMS Moves to Restrict Remote Patient Monitoring

The CY 2027 Proposed Rule marks a sharp reversal on remote patient monitoring, proposing an outsourcing ban and reimbursement restrictions a year after CMS expanded the programs (JD Supra). Providers that built RPM programs around the 2026 expansion should model what an outsourcing ban does to their staffing before the rule is final.

Additional Compliance Alerts

Supply Chain

  • The FCC Expands Covered List Prohibitions to Component Level: A Third Report and Order extends covered list prohibitions to devices containing certain logic-bearing hardware components and imposes new compliance obligations on online marketplaces. JD Supra

The Axe Report is a daily briefing from Grab The Axe. Need help assessing your organization’s security posture? Take our free Human Attack Surface Score assessment.

Distribute Intel
Dusten Trounce
Director of Physical Security
Dusten Trounce
The Growth Architect.

A leader defined by a 'bias for action,' Dusten specializes in physical security assessments that impact profitability and facility resilience.

View Profile →
Press & Media

Media Inquiries

For expert commentary, interview requests, or high-res assets regarding this announcement, initialize the terminal.

Initialize Terminal

Initiate
Deployment.

Whether you need a full adversarial facility audit or an executive resilience protocol for your leadership team.

Secure the Facility (Assessments)
Secure the Mind (Coaching/Speaking)