Risk & Compliance · Bay Area
Risk & Compliance in Bay Area
2 items · primary sources · updated daily
- MediumJul 8, 2026San Francisco Bay Area
$3.3M California Billing-Fraud Settlement Turns on Rendering-Provider NPIs and Uncredentialed NPs/PAs — an Adjacent-Sector Warning FQHCs Should Read Closely
Circle Medical Care of California, Circle Medical Technologies, and its chief medical officer agreed to pay $3,325,000 ($2.85M to California, $475K federal) to resolve False Claims Act allegations announced by San Francisco DA Brooke Jenkins with the California Department of Insurance and the U.S. Attorney for the Northern District of California. The alleged conduct: submitting claims under the National Provider Identifiers of physicians who did not render the service, where care was actually delivered by contracted nurse practitioners and physician assistants who had not been credentialed by the payer — producing a higher reimbursement rate. Notably, the complaint states there was no evidence of billing for services that were not provided; the fraud theory is purely about WHO was named as the rendering provider. Circle Medical is a San Francisco telehealth company, NOT an FQHC — but the enforcement theory maps directly onto a top-tier FQHC billing risk: heavily NP/PA-staffed panels, credentialing and payer-enrollment gaps, and rendering-provider accuracy on claims. It is also a California action assembled from a state qui tam plus the Department of Insurance — the same enforcement stack that reaches Medi-Cal providers. Compliance officers should treat this as a prompt to audit rendering-provider mapping and payer-credentialing status, not as an FQHC case.
CSLEA (San Francisco District Attorney announcement)Read - MediumMay 6, 2026Bay Area
Bay Area Community Health Confirms TriZetto Data Breach — SSN, Medicare Numbers, DOB, Insurance Data Exposed
Bay Area Community Health (BACH, Fremont/San Jose, ~30 sites) confirmed (May 6, 2026 substitute notice + class action investigation update) PHI exposure via TriZetto Provider Solutions (Cognizant subsidiary, OCHIN clearinghouse partner). Exposed: SSN, Medicare beneficiary numbers, DOB, insurance data. Part of the broader 3.4M-patient TriZetto breach. Class-action investigations active in May 2026. Distinct from already-tracked AltaMed and La Clinica breaches — third-party vendor risk pattern across FQHCs using OCHIN/TriZetto stack. Tech-stack relevance: TriZetto is a widely used FQHC RCM clearinghouse. Strategic implication for FQHC CIOs / compliance officers: (1) audit your full Business Associate Agreement (BAA) chain — clearinghouses, RCM vendors, eligibility verifiers, and any subcontractors that touch PHI; (2) TriZetto/Cognizant-related contract review is now a board-level item; (3) confirm your incident-response runbook covers vendor-side breach notification (60-day OCR HIPAA window); (4) document your Security Rule risk analysis updates (the OCR ransomware sweep April 23 and now this BACH item form a one-two compliance pressure pattern).
Class Law DC / BACH substitute noticeRead
Next move
Turn this regional feed into action
Connect the topic to regional intelligence, statewide exposure, policy, and events.
Region
Open Bay Area
See the full regional operating picture around this topic.
Topic
Compare all Risk & Compliance
Step back from this region to the full category feed.
Policy
Check policy triggers
Connect the regional signal to bills, hearings, and deadlines.
Events
Find related events
Use convenings and webinars to keep the regional topic current.