A $12M FTC Filing Penalty, Atrium's Pixel Payout & a CPOM First (07/17/2026)
- › The FTC fined Edwards Lifesciences and Genesis MedTech $12 million for closing a 2024 acquisition without the required Hart-Scott-Rodino premerger filing.
- › Atrium Health agreed to pay up to $1.8 million to settle a class action over tracking pixels that sent patient data to third parties.
- › California's Carbon Health settlement is the first enforcement action aimed directly at the MSO-PC structure under its corporate practice of medicine rules.
- › The EU's Critical Entities Resilience Directive hit its designation deadline, requiring member states to name the entities considered critical.
- › All About Women's Care in Colorado notified up to 12,000 patients of a data breach.
Two of today’s penalties land on paperwork nobody thought would cost this much. The FTC fined two medical device firms $12 million for skipping a merger filing, and Atrium Health is paying up to $1.8 million because a tracking pixel on its website did exactly what tracking pixels do. Add a first-of-its-kind California action against how a healthcare company is structured, and the message is consistent: the obligation you treated as a formality is the one writing the check.
Top 5 Critical Compliance Alerts
1. FTC Fines Two Medtech Firms $12M for a Skipped Merger Filing
The FTC imposed $12 million in penalties on Edwards Lifesciences and Genesis MedTech for closing a July 2024 acquisition without the premerger notification the Hart-Scott-Rodino (HSR) Act requires (JD Supra). The deal itself was not the problem. The failure to file the notice before closing was, which is what makes this a procedural miss that cost eight figures.
Operator Note: If your business does acquisitions, the HSR filing threshold is a hard line, not a judgment call. Build the check into every deal’s closing checklist, because the penalty here is for the missing form, not a bad transaction.
2. Atrium Health Pays Up to $1.8M Over Tracking Pixels
Charlotte-Mecklenburg Hospital Authority, doing business as Atrium Health, agreed to pay up to $1.8 million to settle a class action over tracking pixels that transmitted patient information to third parties (HIPAA Journal). The marketing team that added the pixel was doing its job, and that is exactly the trap. A tag meant to measure website traffic quietly shipped protected health information to an ad platform, and the settlement is the bill for a tool most organizations never audited.
Operator Note: Inventory the third-party tags on any web property that touches patient or customer data. A tracking pixel is a data transfer, and under HIPAA that transfer is your liability, not the vendor’s.
3. California’s Carbon Health Settlement Targets How Care Is Structured
The California Attorney General’s settlement with Carbon Health is the first enforcement action aimed directly at the management services organization and professional corporation (MSO-PC) structure under the state’s corporate practice of medicine doctrine (JD Supra). This one reaches past a single violation and questions the arrangement itself, which means healthcare operators using the common MSO-PC model in California now have a regulator’s template for what draws scrutiny.
4. The EU’s Critical Entities Resilience Directive Hits Its Deadline
July 17 marked the designation milestone under the EU’s Critical Entities Resilience (CER) Directive, the date by which member states must identify the entities considered critical to essential services (JD Supra). Being designated critical brings a set of resilience and reporting obligations, not a badge, and any operator in energy, transport, water, or health with EU exposure should find out now whether they made the list.
5. All About Women’s Care Breach Affects Up to 12,000 Patients
All About Women’s Care in Colorado notified up to 12,000 patients that their data was exposed in a breach (HIPAA Journal). A women’s health practice holds some of the most sensitive records a person has, and a clinic of this size rarely carries the security budget that data warrants, which is the recurring gap underneath most healthcare breach notices.
Additional Compliance Alerts
Policy & Governance Updates
- AI Trained on Employees Becomes a Trade Secret Fight: As companies build models on internal work product, legal teams are warning that confidentiality, employee mobility, and AI governance need rethinking before the litigation arrives. JD Supra
Third-Party Risk & Due Diligence
- New CIPA Claims Target Website Consent Banners: A lawsuit against Ace Hardware shows how plaintiffs are using California wiretapping law to sue over website tracking and consent banners, expanding privacy litigation risk for any company with a public site. Corporate Compliance Insights
The Axe Report is a daily briefing from Grab The Axe. Need help assessing your organization’s security posture? Take our free Human Attack Surface Score assessment.
A leader defined by a 'bias for action,' Dusten specializes in physical security assessments that impact profitability and facility resilience.
View Profile →Media Inquiries
For expert commentary, interview requests, or high-res assets regarding this announcement, initialize the terminal.