Compliance Radar
Who was sanctioned, and for what?
Fines, court rulings and incidents from Europe and North America: 718 cases from 32 jurisdictions, each with an official source and checked against that source before publication. Filter by country, area of law and sector. Click a chart to drill down one level.
Click a bar to drill down one level.
Where?
by regionAll jurisdictions
What for?
by area of lawAll areas of law
- Capital markets and financial supervision €166.7m 51 % · 1 case
- Bribery and corruption €129.6m 39 % · 11 cases
- Competition law €27.1m 8 % · 6 cases
- Data protection €3.53m 1 % · 16 cases
- Whistleblower protection €1.26m 0 % · 1 case
- Health and safety and employment law €652,272 0 % · 2 cases
- Consumer protection and online retail €133,279 0 % · 3 cases
Who?
by company- Becton, Dickinson and Company (BD) €166.7m 51 % · 1 case
- Access DX Laboratory, LLC €31.7m 10 % · 1 case
- DaVita Inc. €31.6m 10 % · 1 case
- Advanced Pathology Solutions PLLC und APS MSO LLC €25.9m 8 % · 1 case
- Medirex s. r. o.; KLINICKÁ BIOCHÉMIA s.r.o.; Unilabs Slovensko, s. r. o.; synlab slovakia s. r. o.; Asociácia laboratórií €14.6m 4 % · 1 case
- Innovasis Inc. €11.1m 3 % · 1 case
- NeoGenomics Laboratories Inc. €8.59m 3 % · 1 case
- PHOENIX Zdravotnícke zásobovanie, a.s.; TRANSMEDIC SLOVAKIA, s.r.o. (in Konkurs) €7.8m 2 % · 1 case
- Modern Nuclear Inc. €7.12m 2 % · 1 case
- New York-Presbyterian Hudson Valley Hospital €5.79m 2 % · 1 case
- 26 more€18m
When?
per quarter, by date of decision| Period | Cases | Total |
|---|---|---|
| Q3 2023 | 0 | — |
| Q4 2023 | 1 | €43,000 |
| Q1 2024 | 0 | — |
| Q2 2024 | 2 | €11.7m |
| Q3 2024 | 5 | €37.2m |
| Q4 2024 | 3 | €166.7m |
| Q1 2025 | 1 | €4,722 |
| Q2 2025 | 3 | €2.76m |
| Q3 2025 | 2 | €2,669 |
| Q4 2025 | 4 | €10.6m |
| Q1 2026 | 7 | €11.5m |
| Q2 2026 | 7 | €47.6m |
| Q3 2026 | 5 | €40.9m |
40 cases
16 Dec 2024 Becton, Dickinson and Company (BD)Becton Dickinson: risks of Alaris infusion pump concealed – 175 million USD €166.7m
The medical technology manufacturer misled investors about regulatory risks of the Alaris infusion pump, which had more than 25 software defects, and did not record the remediation costs, as a result of which operating income in the fourth quarter of 2019 was overstated by 82 %. BD is paying 175 million USD and must appoint an independent compliance consultant.
Product and approval problems are capital market issues: quality and regulatory affairs departments must be involved in the disclosure process.
- Authority / court
- U.S. Securities and Exchange Commission (SEC)
- Area of law
- Capital markets and financial supervision · Disclosure and reporting obligations
- Legal basis
- Antifraud-, Reporting-, Buchführungs-, interne Kontroll- und Disclosure-Controls-Vorschriften der US-Wertpapiergesetze
- Action
- Fine
- Status of proceedings
- final
- Sector
- Healthcare
Original amount 175,000,000 USD, converted at the ECB reference rate of 16 Dec 2024.
- Becton Dickinson to Pay $175 Million for Misleading Investors About Alaris Infusion Pump Press release of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
3 Sep 2026 Azienda Sanitaria Universitaria Friuli Centrale (ASUFC)Garante: Udine hospital group pays 24,000 EUR for viewing a colleague's patient record €24,000
Hospital staff opened a colleague's electronic health record to organise duty rosters during Covid rather than for treatment purposes. Technical barriers limiting access to treating staff were lacking; the Italian data protection authority (Garante per la protezione dei dati personali) imposed 24,000 EUR (Provvedimento No. 616).
Patient records may only be opened for treatment – include this in training and secure it technically through role-based rights and logging.
Purpose limitation when accessing patient records
- Authority / court
- Garante per la protezione dei dati personali
- Area of law
- Data protection · Employee data
- Legal basis
- Art. 5 Abs. 1 lit. a, b, c, f, Art. 9, 25, 32 DSGVO; Art. 75 Codice privacy; Linee guida dossier sanitario
- Action
- Fine
- Status of proceedings
- unknown
- Sector
- Healthcare
- Published
- 11 Sep 2026
- Newsletter del 11 settembre 2026 – Garante privacy Press release of an authority
- Garante privacy, azienda sanitaria di Udine sanzionata per 24mila euro Press release of an authority
- Garante – Provvedimento n. 616 del 3 settembre 2026 [10293994] (ASUFC) Decision of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
30 Jul 2026 Access DX Laboratory, LLCAccess DX Laboratory: 36.4 million USD – kickbacks for unnecessary genetic tests €31.7m
The Houston laboratory, its former CEO Michael Stewart and the businessman Harold Shatz allegedly paid kickbacks and billed Medicare and Medicaid for medically unnecessary genetic tests. The three settlements add up to 36.4 million USD; the laboratory is subject to a Corporate Integrity Agreement.
Commission models for intermediaries who bring in orders or patients are a classic gateway for bribery.
Remuneration of intermediaries and referrers
- Authority / court
- U.S. Department of Justice
- Area of law
- Bribery and corruption · Commercial bribery
- Legal basis
- Anti-Kickback Statute (42 U.S.C. § 1320a-7b(b)); False Claims Act (31 U.S.C. §§ 3729 ff.)
- Action
- Other
- Status of proceedings
- final
- Sector
- Healthcare
- Liability of senior managers
- Former CEO pays under a separate settlement.
Original amount 36,400,000 USD, converted at the ECB reference rate of 30 Jul 2026.
- HHS-OIG Enforcement Actions: Texas Laboratory, Former CEO, and Florida Businessman Pay a Total of $36.4M … (30.07.2026) Enforcement database of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
21 Jul 2026 Hôpital Privé de la LoireHôpital Privé de la Loire: 500,000 EUR after data exfiltration affecting over 520,000 patients €500,000
In summer 2025, an attacker gained access to the private hospital's electronic patient record system and obtained data on 524,867 patients and 202,246 trusted persons. There was no VPN or multi-factor authentication for external users, no appropriate access control and no detection of suspicious activity; the trusted persons were not notified. France's data protection authority (Commission nationale de l'informatique et des libertés, CNIL) imposed a fine of 500,000 EUR (SAN-2026-009).
External access to patient records belongs behind multi-factor authentication and continuous monitoring for unusual access.
Access security and attack detection in hospitals
- Authority / court
- Commission nationale de l'informatique et des libertés (CNIL)
- Area of law
- Data protection · Data breaches and data security
- Legal basis
- DSGVO Art. 32, Art. 34
- Action
- Fine
- Status of proceedings
- final
- Sector
- Healthcare
- Published
- 3 Sep 2026
- Sanction : amende de 500 000 euros à l'encontre de l'Hôpital Privé de la Loire Press release of an authority
- Délibération SAN-2026-009 du 21 juillet 2026 Decision of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
20 Jul 2026 NeoGenomics Laboratories Inc.NeoGenomics: 9.8 million USD after self-disclosure – discounted consulting for referring physicians €8.59m
The Florida laboratory provided referring physicians with consulting services below market value and paid independent consultants referral-based remuneration for recruiting physicians. Following a self-disclosure, NeoGenomics paid 9,813,260 USD.
Free or discounted services are also benefits – like cash payments, they belong in the anti-corruption review.
Services with monetary value provided to customers below market value
- Authority / court
- U.S. Department of Justice
- Area of law
- Bribery and corruption · Commercial bribery
- Legal basis
- Anti-Kickback Statute (42 U.S.C. § 1320a-7b(b)); False Claims Act (31 U.S.C. §§ 3729 ff.)
- Action
- Other
- Status of proceedings
- final
- Sector
- Healthcare
- Mitigating circumstances
- Self-disclosure of the remuneration arrangements.
Original amount 9,813,260 USD, converted at the ECB reference rate of 20 Jul 2026.
- HHS-OIG Enforcement Actions: Florida Laboratory Agrees to Pay $9.8M … Self-Disclosure of Compensation Arrangements (20.07.2026) Enforcement database of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
7 Jul 2026 Γενικό Νοσοκομείο Θεσσαλονίκης Γ. Γεννηματάς «Ο Άγιος Δημήτριος» (Allgemeines Krankenhaus Thessaloniki G. Gennimatas – Agios Dimitrios)Thessaloniki hospital: 25,000 EUR because surgery lists with diagnoses were online €25,000
From May to the end of August 2024, the public hospital accidentally published on its website a surgery list containing patients' telephone numbers, illnesses and planned procedures; a member of the public found the document via Google. The Hellenic Data Protection Authority imposed a total of 25,000 EUR: 10,000 EUR for inadequate security, 2,000 EUR for the late notification, 10,000 EUR for failing to notify the data subjects and 3,000 EUR for missing contact details of the data protection officer (DPO).
Every publication on the website needs an approval step that reliably intercepts documents containing health data – and after a data breach, data subjects must be informed.
Publication of documents containing health data
- Authority / court
- Αρχή Προστασίας Δεδομένων Προσωπικού Χαρακτήρα (Hellenic Data Protection Authority)
- Area of law
- Data protection · Data breaches and data security
- Legal basis
- DSGVO Art. 5 Abs. 1 lit. f, 32 Abs. 1, 33 Abs. 1, 34 Abs. 1, 12, 13 i. V. m. 37 (Entscheidung 13/2026)
- Action
- Fine
- Status of proceedings
- final
- Sector
- Healthcare
- Επιβολή προστίμου σε νοσοκομείο (Απόφαση 13/2026) Decision of an authority
- Απόφαση 13/2026 Decision of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
25 Jun 2026 Самостоятелна медико-диагностична лаборатория „Лина“ ЕООДLaboratory Lina lures customers with free blood tests – 52,097 EUR for unfair competition €52,097
On application by its competitor Ramus, the Комисия за защита на конкуренцията (Bulgarian Commission for the Protection of Competition, KZK) established that the laboratory had offered packages of medical laboratory tests free of charge nationwide over extended periods (only against a fee of 2 leva for taking blood) – conduct shown by no other market participant outside joint campaigns. It found an infringement of the general clause of unfair competition law (Art. 29 ZZK – Bulgarian Protection of Competition Act) and imposed 0.3% of 2024 turnover, i.e. 52,096.55 EUR. Appeals have been lodged against the decision.
Permanent free offers to win customers can be unfair if they deviate significantly from market practice and drive out competitors.
- Authority / court
- Комисия за защита на конкуренцията (КЗК, Bulgarische Wettbewerbskommission)
- Area of law
- Competition law
- Legal basis
- Art. 29 ZZK (Generalklausel unlauterer Wettbewerb)
- Action
- Fine
- Status of proceedings
- under appeal
- Sector
- Healthcare
- Published
- 2 Jul 2026
- КЗК Публичен електронен регистър – Производство (Решение № 591 от 25.06.2026; Volltext als PDF im Register) Official register or notice
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
18 Jun 2026 St. Joseph's Healthcare HamiltonHamilton hospital: CA$65,000 after injury caused by known centrifuge defect €40,151
In the teaching hospital's virology laboratory, the lid of a centrifuge fell on an employee who had to hold it open by hand because of a defective gas spring; she was seriously injured. Maintenance reports from 2023 and 2024 had already called for the spring to be replaced. Fine of CA$65,000 plus victim fine surcharge.
A defect documented in maintenance reports that is not remedied makes every subsequent accident foreseeable – defective equipment must be taken out of use.
Reporting defective equipment and taking it out of service
- Authority / court
- Provincial Offences Court Hamilton (Ermittlung: Ontario Ministry of Labour, Immigration, Training and Skills Development)
- Area of law
- Health and safety and employment law · Workplace safety and accidents
- Legal basis
- Section 25(1)(b) Occupational Health and Safety Act (Ontario)
- Action
- Fine
- Status of proceedings
- final
- Sector
- Healthcare
- Mitigating circumstances
- Guilty plea; repair two days after the accident.
- Published
- 21 Jul 2026
Original amount 65,000 CAD, converted at the ECB reference rate of 18 Jun 2026.
- St. Joseph's Healthcare Hamilton Fined $65,000 for Workplace Injury (Ontario Newsroom, Court Bulletin) Press release of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
17 Jun 2026 Advanced Pathology Solutions PLLC und APS MSO LLCAdvanced Pathology Solutions: 30 million USD for kickbacks and unnecessary laboratory tests €25.9m
The Arkansas pathology laboratory, its management company and the owners Kevin Hannah, Donell Burkett and Daniel Hunter Pledger allegedly granted unlawful kickbacks and ordered medically unnecessary tests. Together they paid 30 million USD; the laboratory entered into a Corporate Integrity Agreement.
Where services are sold through referrals, all benefits to referrers belong in a central approval and review procedure.
Benefits to clients in healthcare
- Authority / court
- U.S. Department of Justice
- Area of law
- Bribery and corruption · Commercial bribery
- Legal basis
- Anti-Kickback Statute (42 U.S.C. § 1320a-7b(b)); False Claims Act (31 U.S.C. §§ 3729 ff.)
- Action
- Other
- Status of proceedings
- final
- Sector
- Healthcare
- Liability of senior managers
- The owners contribute personally as parties to the settlement.
Original amount 30,000,000 USD, converted at the ECB reference rate of 17 Jun 2026.
- HHS-OIG Enforcement Actions: Arkansas Pathology Laboratory and Its Owners Pay $30M … (17.06.2026) Enforcement database of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
2 Jun 2026 Ascension Health Alliance; AmSurg LLC / Ambulatory Topco LLCAscension/AmSurg: seven ambulatory surgery centres must be sold Order
The non-profit hospital group Ascension wanted to acquire AmSurg for 3.9 billion USD. Owing to overlaps in outpatient surgery in five regions, the Federal Trade Commission (FTC) requires the sale of seven AmSurg centres to SC Affiliates and a gastroenterology practice, as well as transitional support.
Non-profit healthcare providers are also subject to merger control – regional market shares determine divestitures.
- Authority / court
- Federal Trade Commission (FTC)
- Area of law
- Competition law · Merger control
- Legal basis
- Section 7 Clayton Act; Section 5 FTC Act (Consent Order)
- Action
- Order
- Status of proceedings
- unknown
- Sector
- Healthcare
- Employees
- 10,000 or more
- FTC Requires Divestiture of Ambulatory Surgery Centers … Ascension Health-AmSurg Deal (02.06.2026) Press release of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
1 May 2026 Modern Nuclear Inc.Modern Nuclear: 8.33 million USD – excessive supervision fees paid to referring cardiologists €7.12m
The Californian provider of mobile PET scans allegedly paid referring cardiologists excessive fees for supervising the examinations in order to secure referrals. The settlement of 8,334,350.71 USD plus revenue-based payments is based on ability to pay; in addition, there is a Corporate Integrity Agreement.
Remuneration of business partners who refer work must correspond to the market value of the service – any overpayment acts as a bribe.
Checking fee agreements with referrers for market conformity
- Authority / court
- U.S. Department of Justice / U.S. Attorney's Office, Central District of California
- Area of law
- Bribery and corruption · Commercial bribery
- Legal basis
- Anti-Kickback Statute (42 U.S.C. § 1320a-7b(b)); False Claims Act (31 U.S.C. §§ 3729 ff.)
- Action
- Other
- Status of proceedings
- final
- Sector
- Healthcare
Original amount 8,334,350.71 USD, converted at the ECB reference rate of 30 Apr 2026.
- HHS-OIG Enforcement Actions: Mobile PET Scan Provider to Pay $8.33 Million … Unlawful Kickbacks to Medical Practices (01.05.2026) Enforcement database of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
17 Apr 2026 Medirex s. r. o.; KLINICKÁ BIOCHÉMIA s.r.o.; Unilabs Slovensko, s. r. o.; synlab slovakia s. r. o.; Asociácia laboratóriíLaboratory cartel: 14.6 million EUR and procurement bans against diagnostic laboratories €14.6m
Four laboratories and their association coordinated negotiations on prices with health insurers, coordinated in tenders, exchanged sensitive information and allocated customers. At first instance, the Protimonopolný úrad Slovenskej republiky (Antimonopoly Office of the Slovak Republic, PMÚ SR) imposed 14,551,800 EUR and three-year procurement bans; Unilabs received a substantially reduced fine as leniency applicant and under a settlement.
Common negotiating positions towards payers via an association are a cartel – association meetings need minutes and a review of the agenda.
Information exchange among competitors and association work
- Authority / court
- Protimonopolný úrad Slovenskej republiky (PMÚ SR)
- Area of law
- Competition law · Cartels and collusion
- Legal basis
- Slowakisches Wettbewerbsschutzgesetz (Kartellverbot)
- Action
- Fine
- Status of proceedings
- unknown
- Sector
- Healthcare
- Culpability
- intentional
- Mitigating circumstances
- Unilabs: leniency reduction (50%) and settlement (a further 30%).
- Published
- 12 May 2026
- KARTELY: PMÚ odhalil kartel laboratórií a uložil pokuty takmer 15 miliónov eur Press release of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
16 Apr 2026 Fullgevity OÜ (vormals OÜ Dr Mõttus Hambaravi)Fullgevity (dental clinic) must reorganise data processing in Invisalign treatment Order
The starting point was a complaint about incomplete disclosure of patient data; the clinic left several requests from the supervisory authority unanswered. The Andmekaitse Inspektsioon (Estonian Data Protection Inspectorate, AKI) ordered it to revise its contracts with Align Technology (Invisalign) with regard to the GDPR roles (Art. 26/28 GDPR), to adapt the consent form and the privacy notices in accordance with Art. 7, 9, 13 and 14 GDPR and to publish them in Estonian; non-compliance is subject to a penalty payment of 1,000 EUR per item.
Anyone passing patient data on to manufacturers or platforms must clarify roles, contracts and consents properly in advance – and respond to supervisory requests on time.
Consent and transparency for health data; cooperation with the supervisory authority
- Authority / court
- Andmekaitse Inspektsioon (AKI)
- Area of law
- Data protection · Data processors
- Legal basis
- § 56 Abs. 1 IKS; Art. 58 Abs. 2 lit. d DSGVO i. V. m. Art. 5 Abs. 1 lit. a, 7, 9, 13, 14, 26, 28 DSGVO
- Action
- Order
- Status of proceedings
- unknown
- Sector
- Healthcare
- Ettekirjutus-hoiatus isikuandmete kaitse asjas nr 2.1-1/24/397-890-38 (Fullgevity OÜ), 16.04.2026 Decision of an authority
- Andmekaitse Inspektsioon – veröffentlichte Ettekirjutused (Liste) Official register or notice
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
20 Mar 2026 Gesundheitsdienstleister (in der Entscheidung anonymisiert)Hungarian GP practice: 500,000 HUF for 47 EESZT queries without legal basis €1,274
A general practitioner who had no longer been treating the complainant since January 2023 accessed his health data (findings, prescriptions) on the national e-health platform EESZT a total of 47 times via his practice software until August 2024 and did not respond to an access request. The Hungarian data protection authority (Nemzeti Adatvédelmi és Információszabadság Hatóság, NAIH) found infringements of Art. 5(2), 6(1), 9(2), 12(2) and 15(1) GDPR, ordered compliance with the access request and imposed 500,000 HUF.
Every access to electronic health records is logged and must be linked to treatment – even if it is triggered by practice staff.
Access to health data and access requests
- Authority / court
- Nemzeti Adatvédelmi és Információszabadság Hatóság (NAIH)
- Area of law
- Data protection · Data subject rights and transparency
- Legal basis
- DSGVO Art. 5 Abs. 2, 6 Abs. 1, 9 Abs. 2, 12 Abs. 2, 15 Abs. 1 (NAIH-273-7/2026)
- Action
- Fine
- Status of proceedings
- final
- Sector
- Healthcare
- Published
- 20 Mar 2026
Original amount 500,000 HUF, converted at the ECB reference rate of 20 Mar 2026.
- NAIH-273-7/2026 – Jogalap nélküli hozzáférés az EESZT rendszeréhez Decision of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
19 Mar 2026 Balt USA LLC (Balt-Gruppe)Balt USA: CJIP in France over payments to a hospital physician €1.77m
In parallel with the US declination, the PNF concluded a CJIP with the US subsidiary of the French medical technology manufacturer for 1,765,493 EUR (after crediting the US disgorgement) and a three-year AFA compliance programme. The case arose from Balt SAS's voluntary self-disclosure of 22 May 2023 concerning offences committed by a former manager of the acquired company Blockade Medical.
Acquisitions require anti-corruption due diligence on the target company – otherwise legacy misconduct by its management becomes a group risk.
Benefits to hospital physicians, integration of acquired companies
- Authority / court
- Parquet national financier (PNF); Validierung durch den Präsidenten des Tribunal judiciaire de Paris
- Area of law
- Bribery and corruption · Bribery of public officials
- Legal basis
- Art. 41-1-2 Code de procédure pénale (CJIP); aktive und passive Bestechung von Amtsträgern
- Action
- Fine
- Status of proceedings
- final
- Sector
- Healthcare
- Employees
- 250 to 999
- Culpability
- intentional
- Mitigating circumstances
- Voluntary self-disclosure to the PNF and the DOJ; coordinated resolution with crediting.
- Liability of senior managers
- The CJIP does not address the criminal liability of natural persons.
- Published
- 19 Mar 2026
- Communiqué de presse du procureur de la République financier – CJIP BALT USA Press release of an authority
- Ministère de la Justice – Conventions judiciaires d'intérêt public (Liste) Official register or notice
- CJIP Société BALT USA LLC (17.03.2026) Decision of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
17 Mar 2026 Balt SAS / Balt USA LLCMedical technology: DOJ declination for Balt SAS after bribery of a hospital physician €1.05m
Through sham consultancy agreements, fictitious invoices and purported bonus payments, around 602,000 USD in bribes flowed from 2017 to 2023 via a Belgian consultant to a physician in a senior position at a French public hospital, so that the hospital would purchase embolisation coils from Balt. The DOJ declined to prosecute on account of voluntary self-disclosure, cooperation and remediation (declination of 17 March 2026); Balt is disgorging 1,214,797 USD in profits.
Physicians at public hospitals are public officials – consultancy agreements with them require documented services and approval by the compliance function.
Benefits to physicians in the public healthcare sector, sham consultancy agreements
- Authority / court
- U.S. Department of Justice (Criminal Division, Fraud Section)
- Area of law
- Bribery and corruption · Bribery of public officials
- Legal basis
- FCPA; Corporate Enforcement and Voluntary Self-Disclosure Policy (Declination)
- Action
- Disgorgement of profits
- Status of proceedings
- final
- Sector
- Healthcare
- Culpability
- intentional
- Mitigating circumstances
- Voluntary self-disclosure (including to the French national financial prosecutor's office, PNF), full cooperation, timely remediation, disciplinary measures, parallel resolution in France.
- Liability of senior managers
- A former manager of the US subsidiary (David Ferrera) and a consultant (Marc Tilman) were charged with FCPA violations and money laundering.
- Published
- 19 Mar 2026
Original amount 1,214,797 USD, converted at the ECB reference rate of 17 Mar 2026.
- Justice Department Resolves Foreign Bribery Investigation with Balt SAS; Healthcare Executive and Sales Consultant Indicted Press release of an authority
- Communiqué de presse du procureur de la République financier – CJIP BALT USA (19.03.2026) Press release of an authority
- DOJ Criminal Division, Fraud Section: Declination Letter Re: Balt SAS (17.03.2026) Decision of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
5 Mar 2026 Allin IP DX LLCAllin IP DX: 980,000 USD after self-disclosure over paid referral marketers €843,519
Between January and June 2023, the Sarasota laboratory paid independent marketers to steer laboratory samples from Medicare beneficiaries to it. It self-disclosed the conduct, cooperated extensively and paid 980,000 USD.
Early self-disclosure limits the damage – but this requires the compliance function to actually get to see problematic sales contracts.
Success-based remuneration of sales partners
- Authority / court
- U.S. Attorney's Office, Middle District of Florida
- Area of law
- Bribery and corruption · Commercial bribery
- Legal basis
- Anti-Kickback Statute (42 U.S.C. § 1320a-7b(b)); False Claims Act (31 U.S.C. §§ 3729 ff.)
- Action
- Other
- Status of proceedings
- final
- Sector
- Healthcare
- Mitigating circumstances
- Voluntary self-disclosure, detailed disclosure and cooperation.
Original amount 980,000 USD, converted at the ECB reference rate of 5 Mar 2026.
- HHS-OIG Enforcement Actions: Sarasota Lab Agrees to Pay $980,000 to Resolve False Claims Act Violations (05.03.2026) Enforcement database of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
20 Feb 2026 SC Hayat Dent SRLDental clinic Hayat Dent obstructs investigation of data leak – 2,000 EUR €1,999
The clinic’s managing director himself reported that a former employee had copied contact details and patient records of all patients and poached them for a new clinic. In the subsequent investigation, the clinic did not fully answer the requests of the Romanian data protection authority (ANSPDCP) despite a reprimand and an order; the authority therefore imposed 10,190 lei (2,000 EUR). Date = publication of the press release; according to the authority, the investigation was concluded in February 2026.
Offboarding processes must block data access immediately – and anyone reporting an incident must also support its investigation.
Taking patient data when leaving; cooperation with the supervisory authority
- Authority / court
- Autoritatea Națională de Supraveghere a Prelucrării Datelor cu Caracter Personal (ANSPDCP)
- Area of law
- Data protection
- Legal basis
- Art. 58 Abs. 1, Art. 83 Abs. 5 lit. e DSGVO
- Action
- Fine
- Status of proceedings
- unknown
- Sector
- Healthcare
- Published
- 20 Feb 2026
Original amount 10,190 RON, converted at the ECB reference rate of 20 Feb 2026.
- ANSPDCP – Comunicat de presă 20.02.2026 (SC Hayat Dent SRL) Press release of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
18 Feb 2026 Fraser Health Authority, Provincial Health Services Authority, Vancouver Coastal HealthBritish Columbia: 36 hospital staff accessed records of Lapu-Lapu Day victims without authorisation Other
Following the tragedy at the Lapu-Lapu Day festival in 2025, 36 employees of three health authorities accessed patient data of 16 admitted persons without authorisation in 71 instances. Those affected were not informed without undue delay; the Information and Privacy Commissioner for British Columbia (OIPC BC) made nine recommendations, including automated access monitoring and deterrent disciplinary measures.
Curiosity is no reason for access: monitor access to the records of high-profile cases in real time and sanction breaches noticeably.
Unauthorised viewing of patient records (snooping)
- Authority / court
- Office of the Information and Privacy Commissioner for British Columbia (OIPC BC)
- Area of law
- Data protection · Data breaches and data security
- Legal basis
- Freedom of Information and Protection of Privacy Act (FIPPA) BC, s. 25.1
- Action
- Other
- Status of proceedings
- unknown
- Sector
- Healthcare
- Culpability
- intentional
- Mitigating circumstances
- Appropriate safeguards were in place; the authorities responded quickly and accepted all recommendations.
- Published
- 18 Feb 2026
- Investigation reveals 71 snooping incidents by 36 healthcare workers following Lapu Lapu Day tragedy Press release of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
20 Jan 2026 PHOENIX Zdravotnícke zásobovanie, a.s.; TRANSMEDIC SLOVAKIA, s.r.o. (in Konkurs)Pharmaceutical cartel uncovered thanks to whistleblower: 7.8 million EUR against PHOENIX and TRANSMEDIC €7.8m
The two companies colluded in tenders of the General Health Insurance Company for the supply of medicines (2017–2020). For the first time, a cartel was uncovered on the basis of information from a whistleblower; the Protimonopolný úrad Slovenskej republiky (Antimonopoly Office of the Slovak Republic, PMÚ SR) imposed 7,595,200 EUR and a one-year procurement ban on PHOENIX and 201,800 EUR and a three-year procurement ban on TRANSMEDIC (first instance).
Whistleblowers receive a reward in Slovakia – internal reporting channels should be faster than the route to the authority.
Bid rigging in public tenders; whistleblowing channels
- Authority / court
- Protimonopolný úrad Slovenskej republiky (PMÚ SR)
- Area of law
- Competition law · Cartels and collusion
- Legal basis
- Slowakisches Wettbewerbsschutzgesetz (Submissionsabsprache)
- Action
- Fine
- Status of proceedings
- unknown
- Sector
- Healthcare
- Culpability
- intentional
- Mitigating circumstances
- PHOENIX: settlement with a 30% fine reduction and a shortened procurement ban.
- Published
- 24 Feb 2026
- KARTELY: PMÚ aj vďaka whistleblowerovi odhalil kartel v dodávkach liekov a uložil pokuty takmer 7,8 milióna eur Press release of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
22 Dec 2025 New York-Presbyterian Hudson Valley HospitalNYP Hudson Valley Hospital: 6.8 million USD for payments to referring practice €5.79m
The hospital (until 2015 Hudson Valley Hospital Center) allegedly paid an oncology practice in Westchester millions of dollars to induce it to refer patients to the hospital; the hospital billed the services to Medicare and Medicaid. The U.S. Attorney’s Office filed a complaint and at the same time concluded a settlement of 6.8 million USD.
Cooperation agreements between hospitals and office-based practices must properly document services and remuneration – otherwise payments are treated as referral bonuses.
Payments to referrers in hospitals
- Authority / court
- U.S. Attorney's Office, Southern District of New York
- Area of law
- Bribery and corruption · Commercial bribery
- Legal basis
- Anti-Kickback Statute (42 U.S.C. § 1320a-7b(b)); False Claims Act (31 U.S.C. §§ 3729 ff.)
- Action
- Other
- Status of proceedings
- final
- Sector
- Healthcare
Original amount 6,800,000 USD, converted at the ECB reference rate of 22 Dec 2025.
- HHS-OIG Enforcement Actions: U.S. Attorney Announces $6.8 Million Settlement With New York-Presbyterian Hudson Valley Hospital … (22.12.2025) Enforcement database of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
3 Dec 2025 Southern Health Solutions, Inc. (Next Medical / NextMed)NextMed: FTC settlement over allegations of hidden costs and review manipulation €128,557
According to the FTC, the telemedicine company advertised GLP-1 weight-loss programmes with monthly prices that did not include medication, laboratory costs and medical consultations, concealed the minimum term and cancellation fees, published fake testimonials from employees and relatives, and induced customers to delete negative reviews by offering vouchers or refunds. Under the final settlement order, the company and its management are paying 150,000 USD, which is earmarked for refunds.
"Buying off" negative reviews with vouchers is just as misleading as inventing positive ones.
Review manipulation and price disclosures
- Authority / court
- Federal Trade Commission (FTC)
- Area of law
- Consumer protection and online retail · Fake reviews
- Legal basis
- Section 5 FTC Act; Restore Online Shoppers' Confidence Act (ROSCA)
- Action
- Disgorgement of profits
- Status of proceedings
- final
- Sector
- Healthcare
- Liability of senior managers
- Founder Robert Epstein and CEO Frank Leonardo III are named in the press release as parties involved.
- Published
- 3 Dec 2025
Original amount 150,000 USD, converted at the ECB reference rate of 3 Dec 2025.
- FTC Takes Action Against Telemedicine Firm NextMed Press release of an authority
- FTC Approves Final Order against Telehealth Provider NextMed (03.12.2025) Press release of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
6 Nov 2025 DoctolibFrance: 4.665 million EUR against Doctolib for abuse in doctor appointment booking €4.67m
Doctolib tied doctors with exclusivity clauses, bundled telemedicine with the appointment booking subscription and in 2018 acquired its main competitor MonDocteur in order to eliminate it (decision 25-D-06). Fines: 4.615 million EUR for exclusivity and tying, 50,000 EUR for the acquisition.
Platforms with high market shares should have exclusivity clauses, bundled offers and acquisitions of rivals reviewed under competition law.
- Authority / court
- Autorité de la concurrence
- Area of law
- Competition law · Abuse of market power
- Legal basis
- Art. 102 AEUV, Art. L.420-2 Code de commerce
- Action
- Fine
- Status of proceedings
- under appeal
- Sector
- Healthcare
- Culpability
- intentional
- Published
- 6 Nov 2025
- L'Autorité de la concurrence sanctionne Doctolib à hauteur de 4 665 000 euros Press release of an authority
- Décision 25-D-06 relative à des pratiques mises en œuvre dans le secteur de la prise de rendez-vous médicaux en ligne Decision of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
13 Oct 2025 Nura OÜNura OÜ must hand over scan files of their treatment to two patients Order
Despite access requests, two patients did not receive copies of their scan files at the end of treatment; the practice responded only sluggishly to enquiries and did not attend an appointment with the supervisory authority. The Andmekaitse Inspektsioon (Estonian Data Protection Inspectorate, AKI) ordered disclosure under Art. 15(3) GDPR or a reasoned refusal and threatened a penalty payment of 2,000 EUR.
Access requests concerning health data require a fixed procedure with deadlines – in small practices too.
Handling access requests from patients
- Authority / court
- Andmekaitse Inspektsioon (AKI)
- Area of law
- Data protection · Data subject rights and transparency
- Legal basis
- § 56 Abs. 1 IKS; Art. 58 Abs. 2 lit. c, Art. 12 Abs. 4, Art. 15 DSGVO
- Action
- Order
- Status of proceedings
- unknown
- Sector
- Healthcare
- Ettekirjutus-hoiatus nr 2.1-1/25/737-1585-20 (Nura OÜ), 13.10.2025 Decision of an authority
- Andmekaitse Inspektsioon – veröffentlichte Ettekirjutused (Liste) Official register or notice
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
12 Sep 2025 Specer sp. z o.o.Medical company Specer: CEO acting as data protection officer costs 11,365 PLN €2,669
For almost six years, the chair of the management board of the medical company was also its data protection officer; this came to light after a report that a patient had been handed documents relating to another person. Poland’s data protection authority (UODO) found a conflict of interest and imposed 11,365 PLN.
This also applies in small practices and companies: management cannot be its own data protection officer.
Role and independence of the data protection officer; release of patient records
- Authority / court
- Prezes Urzędu Ochrony Danych Osobowych (UODO)
- Area of law
- Data protection
- Legal basis
- Art. 38 Abs. 6 DSGVO (DKN.5131.7.2025)
- Action
- Fine
- Status of proceedings
- final
- Sector
- Healthcare
- Mitigating circumstances
- An independent external data protection officer was appointed in July 2024.
- Published
- 29 Sep 2025
Original amount 11,365 PLN, converted at the ECB reference rate of 12 Sep 2025.
- Prezes firmy nie może być jednocześnie IOD. Kara dla spółki Specer Press release of an authority
- Decyzja DKN.5131.7.2025 z 12 września 2025 Decision of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
31 Jul 2025 BGH: no before-and-after images for nose and chin correction with hyaluronic acid Order
A practice for aesthetic treatments advertised hyaluronic acid filler injections for the nose and chin on its website and on Instagram using before-and-after images. In an action brought by a consumer advice centre (Verbraucherzentrale), the BGH upheld the injunction issued by the Higher Regional Court of Hamm (OLG Hamm): such procedures are deemed to be surgical cosmetic procedures, for which this kind of advertising is prohibited.
Instagram posts are also advertising – the strict limits of the law on advertising for medicinal products and treatments (Heilmittelwerberecht) apply to aesthetic procedures.
Social media advertising for healthcare services
- Authority / court
- Bundesgerichtshof (I. Zivilsenat), Az. I ZR 170/24
- Area of law
- Consumer protection and online retail · Misleading advertising and pricing
- Legal basis
- § 11 Abs. 1 Satz 3 Nr. 1, § 1 Abs. 1 Nr. 2 Buchst. c HWG; UKlaG
- Action
- Order
- Status of proceedings
- final
- Sector
- Healthcare
- Published
- 31 Jul 2025
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
5 Jun 2025 23andMe, Inc.ICO: £2.31 million against 23andMe after credential stuffing targeting genetic data €2.74m
From April to September 2023, attackers used reused credentials to access data on 155,592 people in the United Kingdom, including ancestry, family trees and health information. There was no MFA, no secure password rules and no effective monitoring; despite anomalies in July 2023, the full investigation only began in October. Joint investigation by the UK Information Commissioner's Office (ICO) with the Privacy Commissioner of Canada.
Companies that manage genetic or health data must protect customer accounts against credential stuffing with MFA and investigate warning signs immediately.
- Authority / court
- Information Commissioner's Office (ICO)
- Area of law
- Data protection · Data breaches and data security
- Legal basis
- UK GDPR Art. 5 Abs. 1 lit. f, Art. 32 Abs. 1
- Action
- Fine
- Status of proceedings
- unknown
- Sector
- Healthcare
- Culpability
- negligent
- Published
- 17 Jun 2025
Original amount 2,310,000 GBP, converted at the ECB reference rate of 5 Jun 2025.
- 23andMe fined for failing to protect UK users' genetic data Press release of an authority
- ICO Penalty Notice: 23andMe, Inc. Decision of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
27 May 2025 Yliopiston ApteekkiYliopiston Apteekki: 1.1 million EUR over tracking in online shop – court annuls fine overturned
In 2018–2022, the online pharmacy transmitted purchase data, including data on prescription medicines, to the tracking providers via Google and Meta tracking. The sanctions board of the Tietosuojavaltuutetun toimisto (Office of the Data Protection Ombudsman) imposed 1.1 million EUR and a reprimand; on 1 June 2026 the Helsingin hallinto-oikeus (Helsinki Administrative Court) upheld the infringement but annulled the fine because it was unclear whether a fine may be imposed on the university pharmacy at all (not final).
Tracking tools on health-related websites can easily transmit sensitive data – include marketing technology in the data protection review.
Tracking pixels on sensitive websites
- Authority / court
- Tietosuojavaltuutetun toimisto – seuraamuskollegio; Helsingin hallinto-oikeus
- Area of law
- Data protection · Cookies and tracking
- Legal basis
- DSGVO Art. 9, Art. 25, Art. 32
- Action
- Fine
- Status of proceedings
- overturned
- Sector
- Healthcare
- Published
- 4 Jun 2025
Amount in EUR; no ECB reference rate is available for this currency.
- Finlex – Tietosuojavaltuutettu 27.5.2025 (verkkoapteekin seurantateknologiat) Decision of an authority
- Tietosuojavaltuutettu – Hallinto-oikeudelta päätös Yliopiston Apteekille määrätystä seuraamusmaksusta (2.6.2026) Press release of an authority
- Helsingin hallinto-oikeus – kumosi Yliopiston Apteekille määrätyn 1,1 miljoonan euron seuraamusmaksun (01.06.2026) Court press release
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
2 Apr 2025 Malta: 20,000 EUR against healthcare provider over electoral register data and missing DPO €20,000
Despite being asked to do so, a healthcare provider (name redacted) did not correct a patient’s address, so that health reports were sent to third parties, and used address data from the electoral register without a legal basis. The Information and Data Protection Commissioner (IDPC) issued a reprimand, ordered rectification, erasure of the register data and the designation of a data protection officer, and imposed fines of 12,500, 5,000 and 2,500 EUR.
Anyone processing health data on a large scale needs a data protection officer – and a reported incorrect address must be corrected immediately.
Implementing rectification requests promptly
- Authority / court
- Information and Data Protection Commissioner (IDPC)
- Area of law
- Data protection · Data subject rights and transparency
- Legal basis
- Art. 5 Abs. 1 lit. a und d, Art. 6 Abs. 1, Art. 14, 16, 37 Abs. 1 lit. c DSGVO
- Action
- Fine
- Status of proceedings
- unknown
- Sector
- Healthcare
- IDPC Decision CDP/COMP/282/2024 Decision of an authority
- Data Protection Decisions – IDPC Enforcement database of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
6 Feb 2025 Медицински център „Люлин Мед“ ООДMC Lyulin Med presented practice as branch of the Military Medical Academy – 9,236 leva €4,722
Following a tip-off from the Military Medical Academy (VMA), the Комисия за защита на конкуренцията (Bulgarian Commission for the Protection of Competition, KZK) found that the centre presented its gynaecological practice as a VMA branch with signs reading ‘МЦ „ЛЮЛИН МЕД“ АГ – ВМА ФИЛИАЛ’ and corresponding online information. For misleading conduct (Art. 31 ZZK – Bulgarian Protection of Competition Act) it imposed 0.4% of 2023 turnover, i.e. 9,236 leva. An appeal has been lodged against the decision.
Cooperation with renowned institutions must not be presented as affiliation on signage and in online profiles.
- Authority / court
- Комисия за защита на конкуренцията (КЗК, Bulgarische Wettbewerbskommission)
- Area of law
- Consumer protection and online retail · Misleading advertising and pricing
- Legal basis
- Art. 31 ZZK (Irreführung)
- Action
- Fine
- Status of proceedings
- under appeal
- Sector
- Healthcare
Original amount 9,236 BGN, converted at the ECB reference rate of 6 Feb 2025.
- КЗК Публичен електронен регистър – Производство (Решение № 131 от 06.02.2025; Volltext als PDF im Register) Official register or notice
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
16 Oct 2024 DSB: 5,000 EUR against Covid laboratory with managing director as data protection officer €5,000
A limited company operating a diagnostic laboratory (name pseudonymised), which during the pandemic carried out up to 45,000 PCR analyses a day with around 200 employees, had appointed its managing director as data protection officer at the same time. Because of the resulting conflict of interest, the Austrian data protection authority (Datenschutzbehörde, DSB) imposed 5,000 EUR; the penalty decision is final.
Whoever decides on the purposes and means of processing cannot monitor themselves as data protection officer.
- Authority / court
- Datenschutzbehörde (DSB)
- Area of law
- Data protection
- Legal basis
- Art. 37, Art. 38 Abs. 6 DSGVO
- Action
- Fine
- Status of proceedings
- final
- Sector
- Healthcare
- Employees
- 50 to 249
- Liability of senior managers
- The managing director was also appointed as data protection officer – an impermissible conflict of interest.
- DSB Straferkenntnis GZ 2024-0.641.771 vom 16.10.2024 (RIS) Decision of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
1 Oct 2024 Kræftens BekæmpelseKræftens Bekæmpelse: 75,000 DKK after theft of unencrypted laptops €10,057
The cancer charity reported thefts of computers from its offices in Copenhagen and Aarhus as well as phishing attacks in 2019 and 2020; according to the Danish Data Protection Agency (Datatilsynet), at least 1,448 people were affected, some with health data. Although the organisation itself had considered multi-factor authentication necessary after an attack in 2018, this and encryption of the computers were lacking; Københavns Byret (Copenhagen City Court) issued a final judgment ordering it to pay 75,000 DKK (Datatilsynet’s recommendation and the prosecution’s request: 800,000 DKK).
Encrypt mobile devices holding health data – repeated incidents without implementing one’s own measures weigh heavily.
Encryption of mobile devices and phishing defence (multi-factor authentication)
- Authority / court
- Københavns Byret (auf Anzeige der Datatilsynet)
- Area of law
- Data protection · Data breaches and data security
- Legal basis
- DSGVO Art. 32 Abs. 1; databeskyttelsesloven § 41
- Action
- Fine
- Status of proceedings
- final
- Sector
- Healthcare
- Repeat case
- yes
Original amount 75,000 DKK, converted at the ECB reference rate of 1 Oct 2024.
- Datatilsynet – Kræftens Bekæmpelse indstillet til bøde (Opdatering zum Verfahrensausgang) Press release of an authority
- Domsdatabasen – Københavns Byret SS-7513/2023-KBH, Dom 01.10.2024 Court decision
- Domsdatabasen – Københavns Byret SS-7513/2023-KBH, Dom 01.10.2024 (Status: Endelig) Court decision
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
18 Sep 2024 VSIA "Paula Stradiņa klīniskā universitātes slimnīca"Pauls Stradiņš Clinical University Hospital refuses information to data protection authority – 2,000 EUR €2,000
The Datu valsts inspekcija (Latvian Data State Inspectorate, DVI) examined several complaints against the state hospital, including about the processing of patient and health data by a physician assistant and about an unanswered access request. Because the hospital did not provide the requested information, the authority imposed 2,000 EUR for breach of the duty to cooperate.
Hospitals need logged access to patient records and a central office that responds to supervisory requests on time.
Access to patient data only where related to treatment
- Authority / court
- Datu valsts inspekcija (DVI)
- Area of law
- Data protection
- Legal basis
- Art. 58 Abs. 1, Art. 83 Abs. 5 lit. e DSGVO
- Action
- Fine
- Status of proceedings
- unknown
- Sector
- Healthcare
- Culpability
- intentional
- DVI Lēmums Par soda piemērošanu (Paula Stradiņa klīniskā universitātes slimnīca), 18.09.2024 Decision of an authority
- Datu valsts inspekcija – Lēmumi (Liste der veröffentlichten Entscheidungen) Official register or notice
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
13 Sep 2024 Croatia: 190,000 EUR against specialist hospital after loss of X-ray images without backup €190,000
In 2019, a specialist hospital in the Rijeka area (name not published) irretrievably lost patients’ radiological images because it did not make backup copies, and did not report the incident although management had been informed. The Agencija za zaštitu osobnih podataka (Croatian Personal Data Protection Agency, AZOP) imposed 190,000 EUR, including for a missing data processing agreement, call recordings without a legal basis and failure to involve the data protection officer.
Backups are not a cost factor but an obligation – and a known data loss must be notified within 72 hours.
Notification of data breaches within 72 hours
- Authority / court
- Agencija za zaštitu osobnih podataka (AZOP)
- Area of law
- Data protection · Data breaches and data security
- Legal basis
- Art. 5 Abs. 1 lit. e, Art. 6, 12, 13, 28 Abs. 3, 32 Abs. 1 lit. b, 33 Abs. 1, 38 Abs. 1 DSGVO
- Action
- Fine
- Status of proceedings
- unknown
- Sector
- Healthcare
- Published
- 13 Sep 2024
- Izdane nove upravne novčane kazne u ukupnom iznosu od 270.700 eura Press release of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
9 Sep 2024 Acadia Healthcare Company, Inc.SEC: Acadia Healthcare pays 1,386,000 US dollars over waivers of whistleblower awards €1.26m
Between July 2019 and July 2023, Acadia Healthcare had employees waive potential awards for reports to authorities in 98 employment, separation, retention and settlement agreements; in 56 further separation and settlement agreements, they had to waive complaints to federal authorities. As part of a sweep against seven listed companies, Acadia paid 1,386,000 US dollars to the U.S. Securities and Exchange Commission (SEC); the contract templates were amended.
Separation and employment agreements must restrict neither reports to authorities nor the entitlement to whistleblower awards.
Whistleblower protection in contract templates (HR/Legal)
- Authority / court
- U.S. Securities and Exchange Commission
- Area of law
- Whistleblower protection · Retaliation against whistleblowers
- Legal basis
- Securities Exchange Act of 1934, Rule 21F-17(a)
- Action
- Fine
- Status of proceedings
- final
- Sector
- Healthcare
- Mitigating circumstances
- Partial amendment of the templates even before contact by the SEC, information provided to those affected, and cooperation
- Published
- 9 Sep 2024
Original amount 1,386,000 USD, converted at the ECB reference rate of 9 Sep 2024.
- SEC Charges Seven Public Companies with Violations of Whistleblower Protection Rule Press release of an authority
- In the Matter of Acadia Healthcare Company, Inc., Release No. 34-100970 Decision of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
18 Jul 2024 DaVita Inc.DaVita: 34.5 million USD – kickbacks for referrals to dialysis centres and pharmacy €31.6m
The dialysis group allegedly paid kickbacks to promote referrals to its former pharmacy subsidiary DaVita Rx and granted benefits to nephrologists and vascular surgeons to induce them to send patients to DaVita dialysis centres. DaVita paid 34,487,390 USD.
Intra-group routing of customers to subsidiaries must not be bought with benefits for third parties.
Benefits for referrers
- Authority / court
- U.S. Department of Justice
- Area of law
- Bribery and corruption · Commercial bribery
- Legal basis
- Anti-Kickback Statute (42 U.S.C. § 1320a-7b(b)); False Claims Act (31 U.S.C. §§ 3729 ff.)
- Action
- Other
- Status of proceedings
- final
- Sector
- Healthcare
- Employees
- 10,000 or more
Original amount 34,487,390 USD, converted at the ECB reference rate of 18 Jul 2024.
- HHS-OIG Enforcement Actions: DaVita To Pay Over $34M To Resolve Allegations Of Illegal Kickbacks (18.07.2024) Enforcement database of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
1 Jul 2024 Guardian Health Care Inc., Gem City Home Care LLC, Care Connection of Cincinnati LLC und Evolution Health LLCEvolution Health home care providers: 4.5 million USD – kickbacks to senior living facilities and physicians €4.18m
Three home health agencies in Texas, Ohio and Indiana and their parent company allegedly granted kickbacks to assisted living facilities and physicians for Medicare referrals. They paid 4,496,330 USD.
Cooperation with facilities that refer customers requires written contracts with remuneration at market rates and regular review.
Benefits for cooperation partners who refer customers
- Authority / court
- U.S. Department of Justice
- Area of law
- Bribery and corruption · Commercial bribery
- Legal basis
- Anti-Kickback Statute (42 U.S.C. § 1320a-7b(b)); False Claims Act (31 U.S.C. §§ 3729 ff.)
- Action
- Other
- Status of proceedings
- final
- Sector
- Healthcare
Original amount 4,496,330 USD, converted at the ECB reference rate of 1 Jul 2024.
- HHS-OIG Enforcement Actions: Home Health Providers To Pay $4.5M … Kickbacks To Assisted Living Facilities And Doctors (01.07.2024) Enforcement database of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
12 Jun 2024 Edgewood Residential Facility (Los Angeles)Edgewood Residential: 658,948 USD – care workers up to 24 hours without breaks €612,121
At the care facility, employees worked up to 24 hours a day, seven days a week, were not allowed to leave the premises, had to work through breaks and received no overtime pay. The settlement of 658,948 USD comprises 608,948 USD for 34 employees (including overtime and break premiums) and 50,000 USD in civil penalties.
Round-the-clock shifts without rest periods are a recurring pattern in care – rosters need checks against maximum working hours and breaks.
Working time limits and breaks in care
- Authority / court
- California Labor Commissioner's Office (Division of Labor Standards Enforcement)
- Area of law
- Health and safety and employment law · Working time
- Legal basis
- California Labor Code (Überstunden, Meal and Rest Periods, Mindestlohn)
- Action
- Other
- Status of proceedings
- final
- Sector
- Healthcare
Original amount 658,948 USD, converted at the ECB reference rate of 12 Jun 2024.
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
29 May 2024 Innovasis Inc.Innovasis: 12 million USD – kickbacks to spine surgeons €11.1m
The Utah manufacturer of spinal implants and two executives – founder and president Brent Felix and former CFO Garth Felix – allegedly paid surgeons kickbacks to induce them to use Innovasis products. Together they paid 12 million USD; HHS-OIG placed the company under heightened scrutiny.
Consultancy agreements, royalty payments or fees to users who decide on the use of products require proof of need and a fair market value review.
Payments to users of medical devices
- Authority / court
- U.S. Department of Justice
- Area of law
- Bribery and corruption · Commercial bribery
- Legal basis
- Anti-Kickback Statute (42 U.S.C. § 1320a-7b(b)); False Claims Act (31 U.S.C. §§ 3729 ff.)
- Action
- Other
- Status of proceedings
- final
- Sector
- Healthcare
- Liability of senior managers
- Founder/president and former CFO pay personally as parties to the settlement.
Original amount 12,000,000 USD, converted at the ECB reference rate of 29 May 2024.
- HHS-OIG Enforcement Actions: Medical Device Manufacturer Innovasis Inc. and Two Top Executives Agree to Pay $12M … (29.05.2024) Enforcement database of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
20 Dec 2023 Veterinarska zbornica SlovenijeVeterinary chamber: 43,000 EUR for ban on discounts and advertising €43,000
Since 2015, the chamber’s professional code had prohibited its members from offering services below list price, at a discount or free of charge and from advertising prices and promotions – including online. As the first decision under the new act and in the first settlement procedure, the Javna agencija Republike Slovenije za varstvo konkurence (Slovenian Competition Protection Agency, AVK) imposed 43,000 EUR.
Professional codes of chambers are decisions of associations of undertakings – price and advertising bans in them infringe competition law.
- Authority / court
- Javna agencija Republike Slovenije za varstvo konkurence (AVK)
- Area of law
- Competition law · Cartels and collusion
- Legal basis
- Art. 5 ZPOmK-2, Art. 101 AEUV (3062-13/2019)
- Action
- Fine
- Status of proceedings
- unknown
- Sector
- Healthcare
- Mitigating circumstances
- Settlement with acknowledgement of responsibility.
- Published
- 22 Jan 2024
- Agencija je izdala prvo odločbo na podlagi vloge za poravnavo Press release of an authority
- AVK – Odločitve agencije Enforcement database of an authority
Checked against the official source on 25 Sep 2026 · Direct link