FinCEN Will Delete the Ownership Data It Collected (08/14/2026)
- › FinCEN's August 11 final rule permanently exempts US-formed entities from beneficial ownership reporting and will remove US person records from the database automatically.
- › ZOLL Medical will pay $3.5 million to settle litigation over a January 2023 breach affecting 997,097 people, with no admission of liability.
- › Aesto Health, a healthcare data migration vendor, was breached through its Amazon Web Services infrastructure, and the notifications reached more than two dozen provider clients.
- › Boston Health Care for the Homeless Program reported a breach affecting at least 184,914 Massachusetts residents.
- › A New Jersey management services company earned the first healthcare declination under the Justice Department's March self-disclosure policy by reporting itself and paying $1 million in restitution.
Yesterday this briefing asked what happens to the beneficial ownership data companies collected for a law that no longer requires it. The Financial Crimes Enforcement Network (FinCEN) answered. The August 11 final rule permanently exempts US-formed entities from reporting and states the agency will remove information on any individual it reasonably believes is a US person, with no action required from the filer. That resolves the federal copy. It does nothing about the copy sitting in your own files.
Top 5 Critical Compliance Alerts
1. FinCEN Ends the Reporting and Deletes the Data
The final rule permanently exempts all US-formed corporations, limited liability companies, and limited partnerships from beneficial ownership reporting under the Corporate Transparency Act. FinCEN will strip US person records from its database, and companies that filed before the 2025 rollback do not need to request removal. The rule takes effect on publication in the Federal Register. JD Supra
Operator Note: The government cleaning its copy is not the same as you cleaning yours. If your operations or legal team gathered driver’s licenses, passports, home addresses, and ownership percentages to build those filings, that packet is still in a shared drive or an email thread with no obligation left to justify it. Decide this week whether you retain or destroy it, write down the decision and the reason, and act on it.
2. ZOLL Medical Settles for $3.5 Million
ZOLL Medical received preliminary court approval today for a $3.5 million settlement covering a January 28, 2023 network intrusion that exposed names, addresses, dates of birth, and Social Security numbers for 997,097 people. The company disputed every claim of wrongdoing and settled anyway. Class members can claim documented losses up to $5,000. HIPAA Journal
Operator Note: Three and a half years from intrusion to preliminary approval, and roughly $3.51 per affected person before legal costs. When you model breach exposure for your board, that multiplier is the civil side alone, sitting on top of whatever regulators do.
3. One Vendor Breach Reached Two Dozen Healthcare Clients
Aesto Health, an Alabama company that handles data migration, legacy archiving, and records exchange for medical practices, had its Amazon Web Services infrastructure accessed by an unauthorized party between December 2 and December 18, 2025. More than two dozen provider clients were affected, hundreds of thousands of patients in total, with names, Social Security numbers, driver’s license numbers, financial account numbers, and medical histories exposed. Client notifications started June 26, 2026. HIPAA Journal
Operator Note: Aesto is a business associate, so every covered entity on that client list carries its own notification obligation for a breach it did not cause and could not see. Six months passed between the intrusion and the first client notice. Ask your archiving and migration vendors two questions today: what is your contractual notification window, and when did you last test it.
4. A Homeless Health Care Program Reports 184,914 Affected
Boston Health Care for the Homeless Program disclosed a breach affecting at least 184,914 Massachusetts residents. An unauthorized third party reached the network after a service disruption discovered November 11, 2025, and the review finished June 8, 2026, exposing Social Security numbers, payment card details, government identification numbers, medical records, and insurance information. HIPAA Journal
5. The First Healthcare Declination Under the Justice Department’s New Policy
Campus Eye Management, a New Jersey management services organization, became the first healthcare company to avoid criminal charges under the Corporate Enforcement and Voluntary Self-Disclosure Policy the Justice Department announced on March 10, 2026. It reported the conduct itself, cooperated, strengthened its compliance program, and paid $1 million in restitution. The underlying fraud liability stayed with the individual. JD Supra
Operator Note: This is the first data point on what the policy is worth in practice, and the answer is that the company walked and the founder did not. That trade is only available if you find the conduct before an investigator does, which puts the decision in your internal audit function rather than your general counsel’s office.
Additional Compliance Alerts
Regulatory Updates
- Regulation O faces its first major overhaul in nearly 50 years: The Federal Reserve Board and the Federal Deposit Insurance Corporation jointly proposed on July 31 to raise the dollar thresholds governing credit extended to bank executives, directors, and principal shareholders. JD Supra
- Federal Acquisition Regulation Case 2026-007 rewrites improper business practices and termination rules: Government contractors get new language on conflicts and contract termination. JD Supra
- New Section 301 forced labor tariffs hit imports from 60 countries: The measures touch roughly 99.4% of US imports, so supply chain teams need to reconcile sourcing against the list. JD Supra
- Consumer Financial Protection Bureau guidance on immigration status creates a catch-22 for creditors: Lenders are caught between anti-discrimination rules and verification expectations. JD Supra
Policy & Governance Updates
- A quarter of executives say audit caught an AI mistake that already went out: In a Workiva survey of more than 2,200 finance, risk, and sustainability professionals, 26% said audits found AI-generated errors in material that had reached the board or an external audience. Corporate Compliance Insights
- The Financial Industry Regulatory Authority is not writing new AI rules, and that is the problem: For two years running it has applied the rules already on the books, such as supervision, communications, and recordkeeping, to conduct they were not drafted for. JD Supra
- An Office of Foreign Assets Control penalty came out of a communication failure: A Wisconsin maker of commercial weighing equipment is paying $60,700 after an overseas subsidiary sold goods into Iran, because the compliance instruction never reached the people who needed it. Radical Compliance
Compliance Frameworks
- Texas Hearing Institute ransomware affected almost 30,000 patients: Another provider added to the month’s HIPAA breach total. HIPAA Journal
Third-Party Risk & Due Diligence
- Government contractors face widening scrutiny across compliance, grants, and supply chains: Two Justice Department False Claims Act resolutions involving organizational conflicts of interest headline an expanding review surface. JD Supra
The Axe Report is a daily briefing from Grab The Axe. Need help assessing your organization’s security posture? Take our free Human Attack Surface Score assessment.
A leader defined by a 'bias for action,' Dusten specializes in physical security assessments that impact profitability and facility resilience.
View Profile →Media Inquiries
For expert commentary, interview requests, or high-res assets regarding this announcement, initialize the terminal.