American Health Intel
The Regulator · Wednesday, August 12, 2026

The Regulator

Rules. Money. Medicine. Decoded daily.
Reading as

235 million dollars: that is the ten-year taxpayer savings CMS projects from a rule ending federal Medicaid and CHIP funding for gender-transition procedures in children, released yesterday and headed for the Federal Register tomorrow. The Centers for Medicare and Medicaid Services on August 11, 2026 finalized a rule barring federal Medicaid dollars from paying for puberty blockers, hormone therapy and surgeries CMS calls “sex-rejecting procedures” for children under 18, and blocking Children’s Health Insurance Program funding for the same care for people under 19, across programs that together cover an estimated 35.5 million children nationwide. CMS projects $138 million in federal savings and $97 million in state savings over ten years; children currently on hormone therapy get six months of continued coverage to taper off once the rule takes effect, a grace period that does not extend to puberty blockers or surgery, and the rule is scheduled for formal Federal Register publication August 13 with an effective date roughly 60 days later. Confidence: Medium. This run could not independently retrieve CMS’s or HHS’s own release, which returned access errors, but the rule’s terms, dollar figures and dates are corroborated directly across multiple outlets citing the agencies’ releases and the Federal Register’s public-inspection listing. Sources: CMS Ends Federal Medicaid and CHIP Funding for Sex-Rejecting Procedures for Children and Youth, Centers for Medicare and Medicaid Services, Medicaid Program; Prohibition on Federal Medicaid and Children’s Health Insurance Program Funding for Sex-Rejecting Procedures Furnished to Children, Federal Register.

6: that is how many vaccines dropped off the federal government’s recommended childhood immunization schedule this week, and insurers are covering them free only under a pledge that expires at the end of this year. President Trump signed an executive order August 10, 2026, “Delivering Gold Standard Childhood Vaccine Recommendations for Americans,” directing the Centers for Disease Control and Prevention and its Advisory Committee on Immunization Practices to narrow the recommended childhood vaccine list from 17 shots to 11, dropping flu, COVID-19, rotavirus, meningococcal, hepatitis A and hepatitis B from the recommended schedule. Because the Affordable Care Act ties no-cost insurance coverage to whatever ACIP currently recommends, the change removes the legal coverage mandate for those six vaccines; AHIP, the insurance industry’s trade group, has pledged its member health plans will keep covering every vaccine ACIP recommended as of September 1, 2025 at no cost only through the end of 2026, with no commitment beyond that date. Confidence: Medium. The executive order’s text and the removed vaccines are stated directly in White House and CDC materials, but AHIP’s coverage pledge and its expiration date are drawn from KFF’s independent tracking of insurer commitments, not a government source. Sources: Delivering Gold Standard Childhood Vaccine Recommendations for Americans, The White House, Recent Changes in Federal Vaccine Recommendations: What’s the Impact on Insurance Coverage?, KFF.

46 million dollars: that is what a North Carolina drugmaker will pay after admitting it bribed doctors and pharmacies with resort trips, meals and fake consulting fees to push a kidney transplant drug. The Department of Justice announced August 11, 2026 that Veloxis Pharmaceuticals entered a deferred prosecution agreement and agreed to pay more than $46 million, including a criminal penalty over $10 million, to resolve criminal and civil allegations it ran a kickback scheme from October 2016 through June 2023 to boost prescriptions of Envarsus XR, an immunosuppressant for kidney transplant patients. Veloxis admitted providing healthcare providers with lavish meals, trips and resort stays and paying specialty pharmacies per-patient and per-month fees disguised in contracts as “enhanced services,” while employees falsified expense reports and under-reported physician payments through the federal Open Payments program. Confidence: Medium. This run could not independently retrieve the Justice Department’s own release, which returned an access error, but the settlement amount, scheme and admissions are corroborated directly across multiple outlets citing the deferred prosecution agreement. Sources: Veloxis Pharmaceuticals Agrees to Pay Over $46M to Resolve Criminal and Civil Liability for Kickback Schemes, U.S. Department of Justice, Drugmaker admits paying kickbacks to boost transplant drug prescriptions, The Washington Times.

20,000 dollars: that is the maximum civil penalty per violation Colorado can now levy against AI chatbots that pose as therapists, under a law that takes effect today. Colorado’s HB 26-1195 became effective August 12, 2026, barring artificial intelligence systems from directly engaging in therapeutic communication with clients, generating treatment plans without a licensed professional’s review and approval, or being advertised as a substitute for a licensed psychotherapist, while still permitting AI for administrative tasks like recording or transcribing sessions with the client’s written consent. Violations are treated as unfair or deceptive trade practices under the Colorado Consumer Protection Act, exposing violators to civil penalties up to $20,000 per violation under the state’s standing consumer-protection statute, on top of professional discipline the state’s licensing boards can impose on regulated therapists; Colorado becomes one of five states, joining Illinois, Nevada, Rhode Island and Maine, to restrict AI therapy chatbots this year. Confidence: High on the statutory terms and effective date, stated directly in the bill text; Medium on the five-state count, which reflects trade-press tracking rather than a government tally. Sources: HOUSE BILL 26-1195, Colorado General Assembly, Civil Penalties, Colorado Revised Statutes 6-1-112.

15 million: that is how many people a dental benefits administrator serving state Medicaid programs says had their data stolen, in the largest health data breach reported to federal regulators this year. DentaQuest, the country’s second-largest dental benefits administrator with roughly 32 million members and Medicaid dental contracts in multiple states, began notifying 15 million people August 11, 2026 that hackers accessed its network between May 17 and May 20, stealing Social Security numbers, Medicaid and Medicare ID numbers, and diagnosis, treatment and billing records, in a breach the hacking group ShinyHunters claimed responsibility for. DentaQuest filed the required breach notice with federal regulators and is offering affected individuals 24 months of free credit monitoring and identity-theft restoration; an independent researcher reviewing the leaked data told the HIPAA Journal the true toll could exceed 23 million people. Confidence: Medium. DentaQuest’s own notification filings were not independently reviewed this run, but the breach scope, dates and data types are corroborated directly by trade-press review of the company’s notification letters. Sources: DentaQuest breach exposes data of 15M people, a record this year, Healthcare Dive, DentaQuest Starts Notifying 15 Million+ Individuals About May 2026 Cyber Incident, The HIPAA Journal.

Get tomorrow's edition in your inbox.

Free, daily. Three editions, pick your field.

Where these stories are tracked
Get the next issue Free, daily