Category · Intel
Risk & Compliance
63 items · primary sources · updated daily
- LowJul 16, 2026Federal
CMS and CDC reopen the CLIA regulations with a request for information — comments close September 14
CMS and CDC published a Request for Information on the Clinical Laboratory Improvement Amendments of 1988 (CLIA) regulations in the Federal Register on July 16, 2026 (CMS-3485-NC, docket CMS-2026-2345). In the document's own words, it 'seeks input from the public regarding various topics related to the CLIA regulations, including: breath testing; laboratory processes and procedures; emergency preparedness, biosafety and biosecurity, and cybersecurity; and specialty testing areas.' Comments close September 14, 2026. BE PRECISE ABOUT WHY THIS IS HERE: the RFI does not mention FQHCs, RHCs, community health centers, certificates of waiver, or physician office laboratories anywhere in its text — that was checked term by term. The health-center relevance is structural, not asserted by the document: essentially every health center holds a CLIA certificate (most commonly a Certificate of Waiver or PPM) for in-clinic testing, so any rulemaking that follows would reach them the way it reaches every other CLIA-certified site. This is the first substantive regulatory reopening of CLIA since the 1992 implementing rules, which makes the comment window unusually consequential for small-volume testing sites that rarely get represented in lab policy. Do not read any FQHC-specific certification or billing change into this document — there is none yet, only a question-asking stage.
CMS / CDC — Federal RegisterRead - CriticalJul 10, 2026Federal
Eli Lilly's 340B Termination Turns Into Litigation and Congressional Pushback — Tampa General Sues in Federal Court, 72 House Members Demand HHS Act
Eli Lilly's June 1 five-day ultimatum escalated on June 18, 2026, when the manufacturer cut off 340B pricing for covered entities that refused to share in-house pharmacy claims data — Lilly directed wholesaler McKesson to end Tampa General Hospital's discounts after it missed the deadline, per the hospital's complaint. Tampa General sued Lilly on July 2 in the U.S. District Court for the Middle District of Florida, alleging the cutoff raised its average costs for Lilly medications 25-50% — losses the complaint pegs at roughly $24.7 million a year, including a 35.9% jump on Mounjaro. Separately, 72 bipartisan U.S. House members — led by Reps. Doris Matsui (D-CA) and Jack Bergman (R-MI) — signed an early-July letter to HHS Secretary Kennedy and HRSA Administrator Engels urging use of 'any enforcement mechanisms available' against Lilly's move and restoration of 340B pricing. Coverage so far documents hospitals as the entities cut off; no health-center termination has been confirmed, but FQHCs dispensing Lilly products face the same claims-data condition documented in the June 1 ultimatum item and should confirm their data-sharing posture now.
WUSF (Health News Florida); Essential Hospitals; BioPharma DiveRead - MediumJul 9, 2026Federal
OIG declines to sanction an FQHC's produce-box and voucher program — a favorable outcome, but one that legally protects only the health center that asked
HHS-OIG issued Advisory Opinion 26-16 on July 9, 2026 (posted July 14) to a requestor it describes in its own words as 'designated as a federally qualified health center, consistent with Section 330 of the Public Health Service Act.' The arrangement: a six-month food-as-medicine program for 50 financially needy patients with diabetes or hypertension, half receiving weekly $30 produce boxes delivered to their homes and half receiving weekly $20 vouchers redeemable for healthy food at grocery chains and farmers markets, wrapped in dietician assessments, physician oversight and lab testing. READ THE HOLDING CAREFULLY — it is narrower than 'approved.' OIG found the arrangement WOULD generate prohibited remuneration under the anti-kickback statute if the requisite intent were present, and that it DOES generate prohibited remuneration under the Beneficiary Inducements CMP; it then exercised enforcement discretion and declined to impose administrative sanctions, citing safeguards (voucher-redemption tracking, retailer MOUs limiting eligible items, free provision of produce, billing under the health center's sliding fee discount policy per HRSA Compliance Manual Ch. 9, no laboratory remuneration, grant funding). CRITICAL LIMITATION, in the opinion's own words: 'This advisory opinion is issued only to Requestor. This advisory opinion has no application to, and cannot be relied upon by, any other person.' It also expressly reserves any opinion on Stark or the False Claims Act. So this is a genuinely encouraging signal about how OIG views structured food-as-medicine programs — and it is NOT legal cover for another health center to launch one. Treat it as a template for the safeguards to build in and a reason to seek your own counsel, not as permission.
HHS Office of Inspector GeneralRead - MediumJul 8, 2026San Francisco Bay Area
$3.3M California Billing-Fraud Settlement Turns on Rendering-Provider NPIs and Uncredentialed NPs/PAs — an Adjacent-Sector Warning FQHCs Should Read Closely
Circle Medical Care of California, Circle Medical Technologies, and its chief medical officer agreed to pay $3,325,000 ($2.85M to California, $475K federal) to resolve False Claims Act allegations announced by San Francisco DA Brooke Jenkins with the California Department of Insurance and the U.S. Attorney for the Northern District of California. The alleged conduct: submitting claims under the National Provider Identifiers of physicians who did not render the service, where care was actually delivered by contracted nurse practitioners and physician assistants who had not been credentialed by the payer — producing a higher reimbursement rate. Notably, the complaint states there was no evidence of billing for services that were not provided; the fraud theory is purely about WHO was named as the rendering provider. Circle Medical is a San Francisco telehealth company, NOT an FQHC — but the enforcement theory maps directly onto a top-tier FQHC billing risk: heavily NP/PA-staffed panels, credentialing and payer-enrollment gaps, and rendering-provider accuracy on claims. It is also a California action assembled from a state qui tam plus the Department of Insurance — the same enforcement stack that reaches Medi-Cal providers. Compliance officers should treat this as a prompt to audit rendering-provider mapping and payer-credentialing status, not as an FQHC case.
CSLEA (San Francisco District Attorney announcement)Read - High ImpactJul 5, 2026Federal
Section 1557 Language Access Annual Notice Year 1 Anniversary — July 5, 2026 Compliance Window
HHS Section 1557 Annual Notice of Availability (free language assistance services in English + 15 most common LEP languages in the state) has been in effect since July 5, 2025. Year 1 compliance review window approaching July 5, 2026. CA's 15 LEP languages include Spanish, Chinese, Vietnamese, Tagalog, Korean, Armenian, Russian, Persian, Arabic, Punjabi, Khmer, Hmong, Hindi, Japanese, Mon-Khmer. All FQHCs taking Medicare/Medi-Cal must have posted, distributed, and translated the Notice — pairs with the May 11, 2026 WCAG 2.1AA deadline as a compounding civil rights compliance window for FQHCs. Two HHS OCR rules with overlapping enforcement risk in the same 8-week window.
HHS OCRRead - CriticalJul 3, 2026Federal
DOJ Stands Up National Fraud Enforcement Division — Healthcare Billing Now Has a Dedicated Litigating Division
Acting U.S. Attorney General Todd Blanche announced (April 7, 2026) the National Fraud Enforcement Division (NFED) — a stand-alone DOJ litigating division consolidating the Tax Section, Health Care Fraud Unit, and Market/Government/Consumer Fraud Unit under one assistant attorney general. Each U.S. Attorney's office must designate a prosecutor to NFED within 21 days. A new National Fraud Detection Center generates investigative leads from federal financial data — meaning billing anomalies can trigger investigation independent of whistleblower complaints. Combined with FY2025 record $6.8B FCA recoveries (84% from healthcare = $5.7B), 2026 enforcement risk is structurally elevated for FQHCs. PPS billing, incident-to claims, telehealth FQHC distant-site billing, 340B claim integrity, and Anti-Kickback/Stark exposure are all in scope. Strategic action items for CFOs and compliance officers in May–June: (1) refresh PPS encounter documentation review, (2) audit incident-to billing for NP/PA visits, (3) reconfirm 340B contract pharmacy patient-definition compliance, (4) tighten BAA inventory and breach-response runbook (pairs with the OCR ransomware sweep enforcement posture).
Holland & KnightRead - High ImpactJun 25, 2026Federal
DOJ’s 2026 National Health Care Fraud Takedown charges 455 defendants in $6.5B of alleged fraud — community mental health among named targets
On June 25, 2026 the U.S. Department of Justice, HHS-OIG, and partner agencies announced the 2026 National Health Care Fraud Takedown: criminal charges against 455 defendants (including about 90 licensed medical professionals) tied to more than $6.5 billion in alleged false claims, with over $182 million in cash, luxury vehicles, jewelry, and other assets seized. Community mental health and behavioral health services were explicitly named among targeted billing categories. No health center is named, but FQHCs that bill integrated behavioral health face heightened audit and documentation scrutiny; the takedown signals where Medicaid and Medicare program-integrity enforcement is concentrating in 2026.
HHS Office of Inspector General / U.S. Department of JusticeRead - High ImpactJun 9, 2026Federal
FTCA CY2027 redeeming applications due June 26 — miss it and your FQHC has a malpractice-coverage gap
HRSA Program Assistance Letter 2026-01 sets June 26, 2026 as the deadline for all currently-deemed health centers (and their sub-recipients) to submit CY2027 Federal Tort Claims Act redeeming applications — the annual filing that renews free federal medical-malpractice liability coverage. A lapse forces the center to buy private malpractice insurance to cover the gap for all of 2027. The risk is sharper this year because HRSA's EHB-to-GrantSolutions system migration is happening in the same window, making the deadline easier to miss. Compliance officers should confirm submission well before June 26.
HRSA BPHC (PAL 2026-01)Read - MediumJun 1, 2026Federal
Two Compliance Signals for FQHCs: HRSA's FY2026 340B Manufacturer-Audit Results Go Live, and OCR's Ransomware Settlements Preview a Tougher HIPAA Security Rule
Two federal compliance developments worth a calendar note. First, HRSA published its FY2026 340B Manufacturer Audit Results page (updated May 28, 2026) — the companion to the already-tracked FY2025 cycle (49% adverse findings); results are partially finalized, with corrective-action plans and any sanctions to be posted as HRSA approves them, and the agency advises covered entities not to contact audited manufacturers until CAPs post. FQHCs are the largest class of 340B covered entities, so this is a standing reference to monitor in OPAIS. Second, OCR's Risk Analysis Initiative has now completed 19 ransomware investigations with six 2026 settlements, and a June 1 Sidley analysis frames the recent settlements as a direct preview of the forthcoming HIPAA Security Rule amendments (which would make annual risk analyses, documented asset inventories, and demonstrated remediation mandatory rather than 'addressable'). No FQHC has been named, but FTCA-covered health centers are full HIPAA covered entities — meaning a center that hasn't completed a documented Security Risk Analysis is accumulating enforcement exposure ahead of a rule change, not just theoretical risk. (Affordable FQHC SRA tooling like Medcurity, added to our tech stack this cycle, exists precisely for this gap.)
Sidley Data Matters / HRSA OPA / Nixon PeabodyRead - High ImpactJun 1, 2026Federal
Eli Lilly Gives ~50 Covered Entities Five Days to Hand Over 340B Claims Data — or Lose Their Discounts
On June 1, Eli Lilly escalated its 340B claims-data fight, warning roughly 50 covered entities that they have five days to submit comprehensive claims data or stop receiving 340B price breaks — the first time the manufacturer has issued outright termination threats rather than reminder letters. The demand follows Lilly's policy announced in January and effective Feb. 1, 2026, which requires claims-level data for all 340B dispenses (including in-house pharmacies, not just contract pharmacies); STAT reports more than 2,300 entities have complied while up to 1,000 larger systems have refused. The first round targets hospital systems, but the policy applies to all covered entities — FQHCs that dispense Lilly products (insulin, oncology, psychiatric drugs) and have not enrolled in the data platform face the same termination risk. With North Dakota's contract-pharmacy law struck down and other state shields in litigation, this is the manufacturer-side pressure on 340B savings that FQHC pharmacy directors must act on now.
STAT NewsRead - High ImpactMay 29, 2026National
OMB Proposes the Biggest Rewrite of the Federal Grant Rulebook Since 2013 — Every Section 330 Grantee Would Have to Run E-Verify; Comments Closed July 13
OMB has proposed a government-wide rewrite of the Uniform Guidance (2 CFR Part 200) — the rulebook every Section 330 grant, subaward, and Single Audit runs on ('Regulation for Federal Financial Assistance,' 91 FR / FR doc 2026-10817, published May 29, 2026, joined by HHS and 49 other agencies). The provision with the sharpest operational edge for health centers: recipients AND subrecipients would be required to enroll in DHS's E-Verify system for employees and contractors working under federal awards, and to report employees found not authorized to work. The proposal also expands termination and pre-issuance review authority and rewrites the equal-opportunity award terms. Feldesman — the law firm most FQHCs use for Section 330 compliance — confirms the rule reaches 'Ryan White clinics, federally qualified health centers (FQHCs), Indian Health Service facilities, and other 340B grantees,' with partner Steve Kuperberg warning the workforce provisions 'could ultimately affect the delivery of patient care' and senior counsel Jesi Carlson noting E-Verify would be a wholly new compliance obligation for many grantees. The comment period closed July 13, 2026; OMB is expected to issue a final rule later this year (no effective date is set in the proposed rule). For an FQHC this is an unbudgeted HR and compliance lift — E-Verify enrollment, I-9 workflow changes, and subrecipient flow-down — landing in the same window as the December 31 Community Health Center Fund cliff.
Office of Management and Budget (Federal Register)Read - High ImpactMay 26, 2026California
California AB 3030 + SB 1120 Are Active FQHC AI Compliance Triggers — Disclosure + Consent + UM Restrictions in Effect
A May 2026 Holland & Knight legal review highlights two California laws that are now operational compliance triggers for any FQHC running AI: (1) AB 3030 — mandatory patient disclosure plus explicit consent before AI is used in care; (2) SB 1120 — restrictions on AI in utilization management and prior-authorization decision-making (human clinician must make the final medical-necessity call). Compliance obligations apply now to any FQHC running AI scribes (Abridge, Nabla, Suki, Heidi), AI patient-outreach (Artera Squads, healow Genie), or AI-assisted UM/prior-auth (eClinicalWorks AI Workbench). Federal preemption push is underway in Washington but no enacted preemption yet. Pairs with already-tracked CHAI/NACHC Medicaid-eligibility AI Best Practice Guides — CHAI gives the governance scaffolding, AB 3030 + SB 1120 are the legal floor. Strategic implication: FQHC CIOs and Compliance Officers should audit current AI deployments for AB 3030 patient-disclosure scripts and SB 1120 UM-decision pathways before mid-2026.
Holland & KnightRead - High ImpactMay 21, 2026Federal
Three health systems sue CVS/Caremark for ~$250M in alleged 340B savings diversion (RICO)
Mount Sinai, Michigan Medicine, and the University of Kansas Health System filed federal racketeering (RICO) suits on May 21, 2026 alleging CVS Health/Caremark secretly diverted roughly $250M in 340B program savings between 2020 and 2025 by paying covered entities artificially reduced reimbursement while concealing higher-rate claims. The cases target the contract-pharmacy and PBM machinery FQHCs depend on to convert 340B discounts into patient-care revenue. A win — or even discovery — could set precedent for FQHC 340B clawback claims and reshape contract-pharmacy economics just as manufacturer restrictions and the rebate-model fight already squeeze the program.
340B ReportRead - High ImpactMay 21, 2026Federal
HHS Launches AERO — AI Re-Scores 5 Years of Audit Data for Every $1M+ Grantee, Including FQHCs
On May 21, 2026, HHS (Office of the Assistant Secretary for Financial Resources) launched AERO — the Audit Enforcement and Risk Oversight initiative — a department-wide program-integrity effort using next-generation AI tools (reportedly built in part with ChatGPT) to re-score at least five years of Single Audit Act compliance data for every entity receiving $1M+ in annual HHS funds. That threshold puts most Section 330 FQHCs squarely in scope. Initial findings: states and grantees have left serious internal-control issues unremedied for 3-5+ years, and hundreds of HHS grantees are late on required audits (some by 2+ years). Enforcement powers: temporarily withhold payments, hold back future funds, suspend or terminate awards, and pursue debarment. This is the operational teeth behind the Dec 2025 HHS AI Strategic Plan. Strategic implication for CA FQHCs: audit/compliance readiness just became materially higher-stakes — confirm Single Audit submissions are current, remediate any repeat findings now, and treat your audit-finding corrective-action history as a live enforcement risk. Pairs with the HRSA FY2025 340B audit results and the SocialRoots ComplAIance360 compliance-automation trend already tracked.
U.S. Department of Health & Human Services (ASFR)Read - MediumMay 20, 2026Federal
HHS Section 504 Disability Rule — Medical Equipment Accessibility Deadline July 8, 2026 (Distinct from the WCAG 2027 Track)
RegLantern published a compliance brief reminding FQHCs that the HHS Section 504 Final Rule includes obligations beyond the already-tracked May 11, 2027 WCAG 2.1AA web accessibility deadline: accessible medical diagnostic equipment (height-adjustable exam tables, accessible weight scales — phased compliance by July 8, 2026); value assessment prohibitions (cannot use QALY-based clinical decision-support tools that disadvantage disabled patients); and effective communication requirements (ASL interpreters, accessible written materials). The medical equipment piece is the underdiscussed half — most FQHC compliance officers have focused on the website deadline and may have missed the physical exam-equipment phase-in. Average accessible exam table runs $4-8K replacement cost × typical 8-15 exam rooms per FQHC = $50-120K per site capital exposure. CA FQHCs with multiple sites should budget now. OCR complaint risk rises post-deadline.
RegLanternRead - High ImpactMay 18, 2026Federal
HHS OCR Reorganizes Into 3 Program Divisions — New Health Information Privacy, Data & Cybersecurity Division Signals Sustained FQHC Breach Enforcement
HHS announced May 18, 2026 that Office for Civil Rights is restructuring into three program-based divisions: (1) Conscience & Religious Freedom Division, (2) Civil Rights Division, and (3) Health Information Privacy, Data & Cybersecurity Division. The dedicated cyber/HIPAA division formalizes OCR's continued focus on breaches at FQHCs and safety-net providers — particularly in light of recent FQHC ransomware events (Sandhills Medical Foundation 169K class action May 3, Good Samaritan Atlanta 10K Feb 9, Community Health Action Staten Island 60K HIV records Feb 13). Pairs with OCR's Risk Analysis Initiative (now 12+ enforcement actions, lack of documented risk analysis is OCR's #1 enforcement target). Strategic implication for FQHC CISOs/Privacy Officers: (1) Documented HIPAA Security Rule risk analysis must be current and on file — a leading enforcement vector; (2) Ransomware tabletop exercise + IR plan refresh now an OCR audit-ready expectation; (3) Section 504 web accessibility deadline extended to May 11, 2027 (separate action — already tracked) does NOT relieve cyber posture; (4) Watch for new division leadership announcements and revised investigation priority list.
HHS Press ReleaseRead - High ImpactMay 15, 2026Federal
HRSA FY2025 340B Audit Results — 49% Adverse Findings, 75% OPAIS Errors, 50% Required to Repay Manufacturers
HRSA released full FY2025 340B program integrity audit results: 115 covered entities audited, 49% received adverse findings (improving from 64% in FY24 — still nearly 1 in 2). 75% of adverse-finding audits involved incorrect OPAIS records (master-data governance gap); 50% of adverse-finding entities required to repay manufacturers; 21% had site terminations. The 68% re-audit failure rate signals that remediation is sticking poorly. ~90% of FY2025 audits are now risk-targeted (vs. random), elevating exposure for entities with tips, OPAIS anomalies, contract-pharmacy complexity, or prior findings. Strategic implication: CA FQHCs running 340B contract pharmacy programs (often 30-50% of total revenue) face material exposure when OPAIS hygiene lapses. The 'risk-targeted' shift means CFOs can no longer treat HRSA audits as random — prior findings, tips (incl. disgruntled-employee complaints common in the current layoff climate), and contract pharmacy complexity are the trigger profile. 50% repayment rate × typical CA FQHC 340B program ($5-20M/yr) = 7-figure exposure for poorly governed programs. Pairs with already-tracked Lilly/Novo claims-data mandates and 4th Circuit contract pharmacy ruling.
HRSA Office of Pharmacy AffairsRead - High ImpactMay 11, 2026Federal
CHAI (Co-Chaired by NACHC) Releases Responsible-AI Guides for Medicaid Eligibility — Ahead of the June 1 HHS Deadline
The Coalition for Health AI (CHAI) released two Best Practice Guides on May 11, 2026 for the responsible use of AI in Medicaid enrollment and eligibility adjudication — work co-chaired by NACHC alongside Centene, HealthTech 4 Medicaid, Pair Team, and 40+ organizations. The guides are timed ahead of the June 1, 2026 HHS guidance deadline and are built around H.R. 1's new community-engagement (work) requirements, which threaten to drop eligible patients during redetermination. They give states and providers role-based guardrails so AI-driven eligibility workflows don't inappropriately cut coverage. Strategic implication for FQHCs: the H.R. 1 redetermination wave is a major threat to FQHC patient coverage — this framework helps FQHCs and their Medi-Cal managed-care partners prevent inappropriate, AI-accelerated coverage loss. NACHC's co-chair role signals FQHCs have a seat at the AI-governance table.
Coalition for Health AI (CHAI) / NACHCRead - MediumMay 11, 2026National
HHS Extends Section 504 WCAG 2.1 AA Web/Mobile Accessibility Deadline to May 11, 2027 for FQHCs (15+ Employees) — One-Year Reprieve, Obligations Unchanged
HHS's first major Section 504 update in ~50 years set WCAG 2.1 AA web/mobile accessibility requirements for every FQHC with 15+ employees. On May 7, 2026 HHS OCR issued an Interim Final Rule (Federal Register 2026-09266) EXTENDING the web/mobile compliance deadline one year to May 11, 2027 (May 10, 2028 for recipients with fewer than 15 employees) — explicitly to give community health centers, hospitals, and primary care centers time to comply. So FQHCs DID receive the extension. The underlying Section 504 non-discrimination obligations remain in effect now, and OCR can still investigate accessibility complaints. (Separate Section 504 medical-equipment accessibility requirements — e.g., accessible exam tables/scales — run on their own timeline.) Use the extra year to audit web/mobile against WCAG 2.1 AA and remediate.
HHS Office for Civil RightsRead - CriticalMay 7, 2026Federal
MAJOR PIVOT — HHS OCR Extends Section 504 / WCAG 2.1AA Deadline by One Year to May 11, 2027
On May 7, 2026 — four days before the original deadline — HHS Office for Civil Rights issued an Interim Final Rule extending the Section 504 digital accessibility compliance date by one year. FQHCs with 15+ employees now have until May 11, 2027 to make websites, mobile apps, patient portals, online scheduling, telehealth platforms, intake forms, and self-service kiosks WCAG 2.1 Level AA compliant. Recipients with fewer than 15 employees have until May 10, 2028. OCR cited concerns that FQHCs, hospitals, and primary care centers could not meet the original deadline. Comment period runs through July 6, 2026. CRITICAL: this is an extension, not a rescission — Section 504 has been enforceable since July 8, 2024, the private right of action remains active, and ADA-related healthcare litigation grew 11% YoY in 2025. FQHCs should use the 12-month runway to: (1) complete an accessibility audit, (2) publish accessibility statement + complaint intake procedure, (3) train front-desk staff, (4) document good-faith remediation milestones. For FQHCs that were sprinting to remediate, this is genuine relief; for those who deferred, the underlying obligation has not changed.
HHS Press Release + Federal RegisterRead - High ImpactMay 6, 2026Central Coast
Salud Para La Gente (Santa Cruz/Monterey FQHC) Pays $750K to Settle False Claims Act Misbranded Contraceptives Case — First CA FQHC FCA Settlement of FY2026
On May 6, 2026, Salud Para La Gente — a Santa Cruz/Monterey County FQHC serving low-income patients across the Central Coast — agreed to pay $750,000 to settle False Claims Act allegations that it billed Medi-Cal and Medicaid for misbranded contraceptives. This is the FIRST California FQHC FCA settlement of FY2026 to surface, and it arrives during peak DOJ enforcement posture (NFED stood up April 7, West Coast Strike Force April 30, FY2025 healthcare = 84% of $6.8B FCA recoveries). Even mission-driven safety-net FQHCs are not exempt from FCA scrutiny — particularly around 340B/family planning drug supply chains, FDA labeling verification, and Medicaid billing alignment. Compliance officers across CA FQHCs should immediately: (1) audit contraceptive and 340B drug procurement chains for FDA-approved labeling, (2) verify Medi-Cal billing reflects the actual product dispensed, (3) document GPO/wholesaler verification procedures, (4) review the DOJ-OIG release language for additional indicators. Pairs with the May 7 Section 504 extension as a one-two signal: OCR pulled back on accessibility enforcement, but DOJ/OIG enforcement on billing integrity is intensifying.
DOJ U.S. Attorney's Office NDCA + HHS-OIGRead - MediumMay 6, 2026Bay Area
Bay Area Community Health Confirms TriZetto Data Breach — SSN, Medicare Numbers, DOB, Insurance Data Exposed
Bay Area Community Health (BACH, Fremont/San Jose, ~30 sites) confirmed (May 6, 2026 substitute notice + class action investigation update) PHI exposure via TriZetto Provider Solutions (Cognizant subsidiary, OCHIN clearinghouse partner). Exposed: SSN, Medicare beneficiary numbers, DOB, insurance data. Part of the broader 3.4M-patient TriZetto breach. Class-action investigations active in May 2026. Distinct from already-tracked AltaMed and La Clinica breaches — third-party vendor risk pattern across FQHCs using OCHIN/TriZetto stack. Tech-stack relevance: TriZetto is a widely used FQHC RCM clearinghouse. Strategic implication for FQHC CIOs / compliance officers: (1) audit your full Business Associate Agreement (BAA) chain — clearinghouses, RCM vendors, eligibility verifiers, and any subcontractors that touch PHI; (2) TriZetto/Cognizant-related contract review is now a board-level item; (3) confirm your incident-response runbook covers vendor-side breach notification (60-day OCR HIPAA window); (4) document your Security Rule risk analysis updates (the OCR ransomware sweep April 23 and now this BACH item form a one-two compliance pressure pattern).
Class Law DC / BACH substitute noticeRead - High ImpactMay 6, 2026National
FQHC Ransomware Surge Q1 2026 — Sandhills (169K), Cherry Health (184K), Central Jersey Hit; Class-Action Lawsuits Now Routine
Comparitech's Q1 2026 healthcare ransomware roundup confirms 201 attacks (120 providers + 81 vendors) — three of which were FQHCs: Sandhills Medical Foundation (SC, 169,017 patients, INC Ransom group), Cherry Health (Michigan's largest FQHC, 184,000 patients), and Central Jersey Medical Center FQHC. Sandhills now faces a class-action investigation announced May 2026, signaling that civil litigation is becoming routine on top of OCR enforcement. Combined with OCR's April 23 four-entity ransomware sweep ($1.165M), the message to FQHC boards is unambiguous: Security Risk Analysis (45 CFR § 164.308(a)(1)(ii)(A)) is now the single most material ePHI compliance gap. CA FQHCs running OCHIN Epic, eClinicalWorks, NextGen, athenahealth — every IT environment with PHI — should refresh risk analysis before the Section 504 May 11 deadline lands and triggers heightened OCR scrutiny.
Comparitech (Q1 2026 Healthcare Ransomware Roundup)Read - CriticalMay 4, 2026Federal
HHS Section 504 / WCAG 2.1AA Deadline 7 Days Away — DOJ Title II Extension Confirmed Not Mirrored by HHS
Today is May 4, 2026 — exactly 7 days from the May 11 HHS Section 504 enforcement date. Key clarification: legal advisories from Duane Morris (April 26) and Alston & Bird (March) confirm that the DOJ's April 20 Interim Final Rule extending Title II ADA web accessibility deadlines for state/local government agencies does NOT apply to HHS Section 504. Many FQHC executives have wrongly assumed the extension applied to them — it does not. The May 11 deadline holds. OCR enforcement focus: documented good-faith progress (not perfect WCAG 2.1 AA conformance). But Section 504 has been enforceable since July 8, 2024 — May 11 simply makes WCAG 2.1 AA the technical benchmark. Critical: private right of action begins May 12. ADA-related litigation against healthcare providers grew 11% year-over-year in 2025, much of it Section 504-based. Final-week priorities: confirm exam table + scale ≥10% of MDE accessibility (HRSA OSV will check this), publish accessibility statement, document remediation timeline, train front-desk staff on accessibility complaint intake.
Duane Morris LLP / Alston & BirdRead - High ImpactMay 3, 2026Federal
Sandhills Medical Foundation Class Action Launched — 169K-Patient INC Ransom Breach First Major FQHC Ransomware Litigation of 2026
South Carolina FQHC Sandhills Medical Foundation (serving Chesterfield, Kershaw, Lancaster, Sumter Counties, SC — primary care, BH, immunizations) faces class action investigation announced May 3, 2026. INC Ransom ransomware group exfiltrated 169,017 patient records May 2-8, 2025; notification letters mailed April 28, 2026. Data included SSN, ITIN, DL#, passport#, financial info, PHI. CA FQHCs should note this is the largest FQHC ransomware breach reported in 2026 and sets a class-action precedent for safety-net providers — OCR investigation expected to follow given 169K exceeds the 500-patient OCR Breach Portal threshold. Pairs with Community Health Action Staten Island GENESIS ransomware (60K HIV testing records, Feb 13) and Good Samaritan Health Center Atlanta (10K, Feb 9) — three safety-net clinic ransomware breaches in Q1 2026 establish a clear pattern. Strategic implication for CA FQHC CISOs/Privacy Officers: (1) Cyber insurance limits and ransomware riders need re-audit against 2026 settlement floors; (2) Class action precedent in SC will inform NY/CA plaintiffs' bar appetite; (3) HHS OCR's new Health Information Privacy/Data & Cybersecurity Division (May 18) targets exactly this scenario.
HIPAA Journal / ClassActionLawyers.comRead
Showing the 25 most recent of 63 total items.
Embed this feed
<iframe src="https://www.fqhctalent.com/embed/pulse?topic=compliance" width="100%" height="500" frameborder="0" loading="lazy"></iframe>Other categories
Next move
Turn this topic feed into action
Use the category feed with daily, state, policy, and event workflows.
Daily
Read today's brief
Put this topic in the context of the most important daily signal.
States
Compare state exposure
See how this topic varies by Medicaid, PCA, budget, and scope context.
Policy
Check policy triggers
Connect the topic to bills, deadlines, and legislative risk.
Events
Find related events
Use conferences and webinars to keep the topic current.