Skip to main content
FQHC Talent
All issues
ComplianceWatchingUpdated

Enforcement: privacy, fraud and audits

Data breaches at health centers and their vendors, HIPAA rulemaking and enforcement, False Claims Act cases and federal audit programs.

55 updates · 52 sources · 3 analysis

RSSThis week's summary

Where it stands

The Aesto Health breach, at a vendor that archives retired EHRs, has reached Ocracoke Health Center in North Carolina and Health Access Network in Maine, beyond the vendor's own client list. Lone Star Family Health Center reported 250,130 Texans affected. On September 18 the Justice Department said False Claims Act cases must rest on binding statutes, regulations or contracts, not agency guidance.

As of

Based on: Massachusetts Office of Consumer Affairs and Business… · Texas Office of the Attorney General, Data Security Br… · U.S. Department of Justice, Office of Public Affairs

What to watch

  • Breaches at shared vendors, which reach several health centers at once.
  • The gap between proposed HIPAA rules and what is enforceable today.

Timeline

What changed

HIPAA rules and OCR enforcement

Open
Show 8 earlier updates

Data breaches

Open

Government · Massachusetts Office of Consumer Affairs and Business Regulation

Aesto vendor breach reaches two more health centers in NC and Maine

Event:

Breach letters posted by Massachusetts regulators on September 18 and 25, 2026 show the Aesto data-archiving breach reached Ocracoke Health Center in North Carolina and Health Access Network in Maine.

Show 13 earlier updates

False Claims Act, DOJ and federal audits

Open

Government · North Dakota Health and Human Services

North Dakota Medicaid warns providers of PERM audit record requests

Event:

North Dakota Medicaid's September 2026 provider newsletter says the federal PERM audit will review Medicaid and CHIP payments made from July 1, 2026, through June 30, 2027. Randomly chosen providers will get record requests in the coming months.

Show 26 earlier updates

Other updates on this issue

Sources

  • U.S. Department of Health and Human Services, Office for Civil Rights (3)
  • U.S. Department of Justice (3)
  • HHS Office for Civil Rights (2)
  • Sidley Austin LLP (2)
  • The Employer Report / Sullivan & Cromwell (2)
  • U.S. Department of Health & Human Services (ASFR) (2)
  • Aesto Health covered-entity notice (Updated 9-3-2026); Kaniksu Community Health breach letter filed with the California Attorney General (sb24-629145) (1)
  • AltaMed Health Services Corporation (1)
  • Arizona AHCCCS / AZ Capitol Times (1)
  • AWS (1)
  • Bay Area Community Health / California DOJ (1)
  • BVCHC Data Incident Settlement Administrator (Simpluris) (1)
  • CA Office of the Attorney General (1)
  • California DHCS FQHC/RHC Resources (1)
  • CentralMaine.com (Kennebec Journal / Morning Sentinel) (1)
  • Cherry Health (preliminary breach notice) (1)
  • Comparitech (Q1 2026 Healthcare Ransomware Roundup) (1)
  • CSLEA (San Francisco District Attorney announcement) (1)
  • CT News Junkie (1)
  • DOJ U.S. Attorney's Office NDCA + HHS-OIG (1)
  • Endpoints News (1)
  • Georgia Department of Community Health (1)
  • Hawaii Tribune-Herald (1)
  • HHS / OCR (1)
  • HHS OCR (1)
  • HHS Office of Inspector General (1)
  • HHS Office of Inspector General / U.S. Department of Justice (1)
  • HHS Press Release (1)
  • HIPAA Journal / ClassActionLawyers.com (1)
  • Holland & Knight (1)

and 17 more organizations

Cookie notice

We use Google Analytics, Vercel Web Analytics, and Vercel Speed Insights to improve the site. Select Decline to turn them off in this browser. We honor GPC and Do Not Track. Read our Privacy Policy.