A Reporting Mandate Is Almost Finished (09/16/2026)
- › A federal cyber incident reporting law broadly applicable to critical infrastructure organizations is nearing completion.
- › The House Energy and Commerce Subcommittee on Health held a legislative hearing on healthcare cybersecurity proposals.
- › FCPA case volume is down while enforcement tied to export controls and sanctions remains active.
- › A practice management and EHR software provider disclosed a breach affecting 118,000 individuals.
- › A new centralized portal will replace the fragmented No Surprises Act dispute resolution process.
Reporting obligations have a pattern worth noticing. They arrive with a long runway, everybody agrees they are manageable, and then the first real incident reveals that nobody established who inside the organization is authorized to file. We watched the EU version of this go live last Friday, and the federal one is now close behind it.
Top 5 Critical Compliance Alerts
1. The Federal Incident Reporting Law Is Nearly Done
A federal cyber incident reporting law broadly applicable to critical infrastructure organizations is approaching completion, and counsel are advising companies to prepare now rather than when the requirements land. The preparation that matters is unglamorous and slow, since it means deciding who determines that an incident is reportable, who files, and what evidence you retain to show the timing was reasonable. Organizations that treat this as a legal task to start on the effective date will discover the operational half on their first real event. JD Supra has the analysis.
Operator Note: Critical infrastructure is defined more broadly than most companies assume, so confirm whether you are in scope before you decide this does not apply to you.
2. The House Examines Healthcare Cybersecurity Proposals
The House Energy and Commerce Committee’s Subcommittee on Health held a legislative hearing on September 15 covering healthcare cybersecurity proposals. Healthcare has produced more breach disclosures than any other sector in our coverage this month, and the legislative attention follows a run of provider and vendor incidents affecting populations far larger than the organizations reporting them. A hearing is the earliest visible stage of an obligation, and it is the cheapest moment to understand what is coming. HIPAA Journal has the hearing.
3. FCPA Cases Are Down and the Risk Is Not
Corporate FCPA enforcement has declined in case volume while enforcement involving international business remains active, particularly under export controls and economic sanctions, with third parties still the dominant exposure. Reading a drop in case count as a drop in risk is the mistake this analysis is written to prevent, since the conduct simply gets charged under a different statute. Your intermediaries, distributors, and agents are where this lands regardless of which authority brings it. Corporate Compliance Insights has the assessment.
4. A Practice Management Vendor Breached 118,000 Records
A practice management and electronic health record software provider disclosed a data breach affecting 118,000 individuals, alongside notices from several other organizations. A practice management platform serves many small clinics that individually have no security function and collectively hold a substantial population, which is the concentration pattern behind most healthcare breach numbers now. The affected individuals are patients of practices that never chose this vendor themselves. HIPAA Journal has the disclosure.
Operator Note: Ask your practice management or EHR vendor how many other organizations share your instance, because the answer determines whether their incident is a notice or a headline.
5. The No Surprises Act Gets a Centralized Dispute Portal
A new centralized gateway portal will standardize independent dispute resolution under the No Surprises Act, replacing a fragmented process that required providers to track down individual payer representatives. Payers must register with the new system, which moves a manual and frequently adversarial process into one place with a record. Centralization creates an audit trail where previously there were phone calls. JD Supra has the changes.
Additional Compliance Alerts
Enforcement
- The DOJ’s new National Fraud Enforcement Division took effect August 24: The reorganization materially changed the white-collar enforcement landscape and consolidates fraud work under a single division. JD Supra
Sanctions
- New terrorist designations in Brazil create fresh screening obligations: More listings are considered likely, and each round tends to catch a different set of companies unprepared. Corporate Compliance Insights
The Axe Report is a daily briefing from Grab The Axe. Need help assessing your organization’s security posture? Take our free Human Attack Surface Score assessment.
A leader defined by a 'bias for action,' Dusten specializes in physical security assessments that impact profitability and facility resilience.
View Profile →Media Inquiries
For expert commentary, interview requests, or high-res assets regarding this announcement, initialize the terminal.