.

How Cybersecurity Standards and False Claims Act Heighten Litigation Risks

December 11, 2025

by Kent J. Schmidt and Seth Goertz

Download as a PDF

Share this page

The connection between changes on the regulatory horizon and the creation of new theories of liabilities in civil litigation is well known. A new regulation often creates or expands a standard of care or obligation for a company that a plaintiff, including a consumer in a class action, can point to as a predicate for a tort or other legal theory. The nexus between the regulatory landscape goes even further. In this episode Kent Schmidt interviews Dorsey Partner Seth Goertz on the unconventional mix between cybersecurity standards and False Claims Act, which empowers whistleblowers to bring lucrative claims for even small deviations. This creates a template for whistleblowing and cybersecurity standards even in the private sector, creating a litigation risk even where there has been no data breach.

This podcast is not legal advice and does not establish an attorney-client relationship or create any duty of Dorsey & Whitney LLP or those appearing in this podcast to anyone. Although we try to assure that the content of this podcast is accurate, comprehensive, and reflects current legal developments, we do not warrant or guarantee those things. The opinions expressed in this podcast are the opinions of those appearing in the podcast only and not those of Dorsey & Whitney. This podcast is considered attorney advertising under the applicable rules of certain states.

Transcript

Voiceover [00:00:00]

Welcome to another episode of the SharkCast on litigation risks management, where we explore why businesses are so frequently sued, and how to mitigate and navigate the dangers lurking in these risky waters. Join us now as we welcome our host Kent Schmidt, Litigation Partner at the law firm of Dorsey & Whitney.

Schmidt [00:00:25]

Welcome to another episode of SharkCast. You know, in thinking through, writing, and speaking about litigation risk, we often refer to the connection that exists between changes on the regulatory horizon and the creation or spawning of new litigation risk. And there’s clearly a very significant connection between the regulatory world and litigation risk. For example, a new regulation can create or expand a standard of care. It can be pointed to by a litigant as evidence of a breach, of a duty, a tort, a violation of another statute, and so we want to keep an eye on what’s happening in the regulatory world, and even what’s happening with criminal prosecutions, because that informs our approach to mitigating litigation risk. And I can think of no one better to invite to the SharkCast virtual studios to address this in general, and more specifically, how cyber threats and cybersecurity standards in a particular area of federal contracting can impact litigation risk, than our relatively new partner, Seth Goertz. Seth joined our office from the U.S. Attorney’s Office in Phoenix, and he’s been at Dorsey for a relatively short amount of time, so I don’t know him that long, but Seth, welcome to SharkCast, and welcome to Dorsey as well.

Goertz [00:02:03]

Yeah, thanks Kent, appreciate it. Glad to be here and enjoying my time at Dorsey so far.

Schmidt [00:02:09]

And how long have you been at Dorsey?

Goertz [00:02:11]

Joined, yeah, in March of 2024. So, I guess it’s getting on to be about 18 months now, so year and a half.

Schmidt [00:02:17]

Okay, well, let’s, before we get into this, let me ask you a little bit about your prior work at the U.S. Attorney’s Office because I think that’s going to impact your perspective on the topic we’re going to be discussing today. What’d you do in that career before joining Dorsey?

Goertz [00:02:40]

Yeah, sure. So, I was a federal prosecutor in the white-collar section of the U.S. Attorney’s Office in Phoenix, and so the work, easiest way to explain is it’s split between, for me, traditional investigating, prosecuting, going to trial, and traditional white-collar frauds. Which include, like, healthcare fraud, investment fraud, other types of business-related frauds that rise to the level of the crime, and then, that was about half of my work and the other half I focused on cyber related fraud. And so I worked the FBI in Phoenix as a cyber division and I would work with them, sometimes even in a SCIF, a secure area that you have to have top secret clearance to even be in, and would investigate and prosecute cyber related crimes, and those are very parallel to what we see today a lot in related to like, network intrusions and cybersecurity. Those events will happen. Bad guys will come in, infiltrate a system, take data, take money, and then businesses will obviously have to do things to mitigate those risks, but when the FBI comes in, they are then looking to try to find the bad guys to figure out what they did, where they’re located, and the trickiest part of that is putting someone actually behind the keyboard that was involved in the crime and then charging them. And so it was a fascinating, fascinating experience that I enjoyed a lot and have now parlayed that into a similar practice, just from the other side, where it’s defending individuals and entities involved in regulatory inquiries, criminal offense, but I also do a lot of cybersecurity related counseling, guidance, sort of post-incident mitigation, drawing on a lot of what I learned at DOJ about how the cyber threat landscape is currently today.

Schmidt [00:04:27]

Okay, well let’s, that’s a perfect segway to where we’re really gonna get into the meat of our conversation, and that is cybersecurity, the federal standards, prosecutions of companies under the federal standard, specifically federal contractors, as well as a different angle, which is whistleblowing through False Claims Act. It’s not something you have traditionally heard of before. So, some things that you’ve written, Seth, caught my eye and I would like you to sort of unpack what’s going on in the last couple years on cybersecurity standards and False Claims Act.

Goertz [00:05:15]

Yeah, yeah. We are, I mean, this is a space that continues to evolve very quickly. I mean, almost daily, hearing new, yeah, new evolutions really. And one of the main shifts, just broadly, sort of on a philosophical level, is that we’re starting to see, and we’re entering a phase in which cyber incidents, the broad loss and disclosure of personal identifying information, accounts, the stuff that we kind of just now take for granted is occurring. Regulators are starting to see a shift in that they are determining this is no longer okay. Like, we want to do whatever we can now to stop this from happening, and we are going to start enforcing certain regulations and basic protocols that businesses who possess this information need to be complying with, and this is beyond just data breach notification and how to possess, you know, PII, like we have all of the broad data disclosure, data retention obligations, but we’re getting into the actual cybersecurity protocols and certain things that need to be done to protect a system. Those are slightly different, and one of the main ones…

Schmidt [00:06:26]

Let me just interject here and make sure that our listeners understand the distinction.

Goertz [00:06:30]

Okay.

Schmidt [00:06:31]

We have an entire world out there relating to data breach and what happens when there’s been a data breach. For a private company, disclosures that are required to consumers, to the attorney general, some other regulator. This has nothing to do with that in one sense, I mean, obviously commonality. Is what you’re saying is that this relates to the standards even if there’s never a data breach?

Goertz [00:06:59]

Exactly, exactly. And you are right. They do relate, ‘cause one sort of leads to the other. You don’t get the breach often without sort of an infiltration to your network on a basic level, right, and the regime we currently have is sort of post-incident requirements. Post-incident requirements and other basic regimes for what entities are required to do what with certain types of information, right? So, if you’re a healthcare entity, you have certain regulations regarding the HIPAA and your various patient information, treatment records, stuff like that that you have to possess, and in the event of an incident, you gotta notify people, like you said. What we are seeing though now, is that regulators are starting to look at, what are the actual technical specifications that these companies are employing to protect this data on the front end, right? What is going on with their actual network security? What type of testing are they doing and how regular is it? How aware are they of, sort of, their vendors, their networks, the data that they’re possessing? What are they actually doing from a technical capacity to protect this information? And that actually becomes far more important than I think people realize, because entities that receive federal funds, federal contractors, will receive those funds and their contracts signed various attestations. In one of the attestations they’re now signing, is relates to their cybersecurity protocols. This is very important when you get to, like, Department of Defense, and other various sensitive information where there are pretty specific frameworks that companies are attesting to, and even that is beginning to be far more particularized as to the specific type of cybersecurity framework that is being attested to, okay? And so now that actually becomes very important. It’s a little different than just these notifications, it’s stuff you have to be doing on an ongoing basis and it doesn’t matter whether you’ve had a breach or not and so what we have seen is that formalization with the Department of Justice is called the Civil Cyber Fraud Initiative which is going and assessing whether or not recipients of federal funds are actually complying with the cyber security protocols they’ve attested to, regardless of a breach. And they’re bringing actions, based upon whistleblowers, against entities who have not complied simply with the attestation regardless of the incident. And we’re seeing significant settlements already, significant actions in this space, and that is one that I think sort of demonstrates the paradigm shift sort of best in this space.

Schmidt [00:09:33]

Yeah, it sort of reminds of every once and a while I will look outside my office door and I will see the fire marshal walking through doing an inspection making sure that the, you know, hallways, there aren’t obstructions, there’s fire extinguishers and so forth and what we’re seeing is, even if there isn’t a fire, the equivalent of the fire marshal in the cybersecurity realm is more and more focused on federal contractors. Now let’s talk about the way in which False Claims Act, which is something we haven’t seen in cybersecurity, is being brought to bear in this area and maybe for our listeners that aren’t as familiar with False Claims Act claims or theories, or that body of law…

Goertz [00:10:26]

Yeah.

Schmidt [00:10:27]

Can you unpack that a bit for us?

Goertz [00:10:29]

Yeah, so the False Claims Act actually is a very old law, it dates back to the Civil War, and it’s basically the government’s effort to police recipients of federal funds to make sure they’re doing with the funds what they said they were going to do. They’re not wasting them, prevent fraud waste and abuse. And so, the False Claims Act is a mechanism for the government to go after contractors who have failed to do what they said they were going to do with the money they received, basically. And the way in which they do that is often through whistleblowers and so the reason this is such a powerful tool is because the penalties under the False Claims Act are extreme. On a basic level, you get triple damages and so the government can triple, they will, this isn’t always how it works out, but the government will often start their case with whatever contract you received, triple that and that’s our damages. And the whistleblowers get a portion of that, often a third essentially is what they can initially expect or attempt to claim…

Schmidt [00:11:26]

A bounty of sorts.

Goertz [00:11:27]

A bounty, yeah exactly. Exactly. And so, these cases will start often by a whistleblower bringing suit and filing a qui tam action. The government then has a certain amount of time to intervene on this behalf or let the relator, as they’re called, go forward with the suit. And so what, you typically see that in industries where federal funds are routinely granted. You see this in Department of Defense related contracts, you see this in healthcare a lot. Healthcare is a common space where this is used and particularly related to Medicare violations and enforcement of different billing fraud. You see it, sort of, Medicare pharmaceutical related stuff but we haven’t seen it in cybersecurity space, and this is very novel. Under the Biden administration, the DOJ established what was called the Civil Cyber Fraud Initiative and it is, like I said previously, to use the False Claims Act to ensure that federal contractors are complying with their cybersecurity protocols that they attested to. So using the False Claims Act as a tool to enforce this and, you know, as you can imagine, it’s a pretty powerful tool if your, you know, the contracts you are receiving are the basic starting point for damages and they’re going to look at what box you checked in which cyber protocols you said you were going to attest to and it becomes even more interesting and, I think novel, novel’s not the right word. The nuance is slightly different in this cyberspace because a typical whistleblower, the whistleblowers in this space, the relators, receive a tremendous amount of scrutiny because a lot of these cases, the relators are just very important, there’s no way to get around that. And in the healthcare setting, relators can range from a front desk staff to doctors, potentially, but they sort of span the gamut. What we’re seeing right now, though, initially, the Cyber Fraud Initiative, is that some of these whistleblowers are like the Chief Information Security Officer, for instance, so these are whistleblowers that have, you would think, complete insight into the actual cybersecurity framework and protocols, what is happening and, I don’t want to say unimpeachable, but that is a very strong, from the government’s perspective, if you’re getting a relator who is an executive level employee with full oversight on how an entire program is run, that’s not often the case with relator I would say, that is a very strong relator, something you are going to take seriously. And you’re seeing the result of that, at least for the most part, with some of the early settlements that have already occurred under the Cyber Fraud Initiative.

Schmidt [00:14:04]

They know where the bodies are buried.

Goertz [00:14:06]

Exactly, exactly.

Schmidt [00:14:09]

And has that initiative continued full steam ahead with the transition to the Trump administration?

Goertz [00:14:15]

It seems so, actually. And one of the, there’s been a lot that’s been said about the DOJ, we don’t need to get into, and in every administration, there are prosecution priorities that change, right? And in this one, there’s much more of a focus on violent crime, immigration, less so on, sort of, criminal fraud in certain respects. What hasn’t though and what we have not seen over the last almost year now, and what people I think were waiting for, is well what’s going to happen in this healthcare fraud, the False Claims Act, and the Civil Cyberfraud Initiative. Those have remained relatively intact both in terms of like manpower, like you’re not hearing about exodus of prosecutors or AUSAs from those groups. You’re seeing continued enforcement, and you’re even seeing a signal that we’re going to continue to bolster the focus on, like, health care fraud, False Claims Act, and the Civil Cyber Fraud Initiative. So…

Schmidt [00:15:12]

That’s interesting. It’s interesting it’s one of the perhaps few areas in which there’s continuity between the administrations, at least apparently, because it seems virtually everything else that I’m reading about is, you know, completely changing priorities and discontinuing something or starting something new but there’s apparently some threads of continuity.

Goertz [00:15:40]

There is and it’s interesting. I think people have been cautiously cautious in their assessment of this and not wanting to prognosticate too quickly because of how rapidly things have changed. What I would said is unique about the False Claims Act, though, is that in where it is in some ways different, it derives a tremendous amount of money for the government like these are funds that are recouped, whistleblower payments go out, but the government retains the money, I mean they’re recouping money the government paid and huge amounts of monies and so that’s where, it would, it would be quite a significant move for the DOJ to really ramp down or not prioritize in a different spot False Claims Act enforcement because of , sort of, just the amount of money that’s an issue there.

Schmidt [00:16:26]

Right, right. Well the issue that I think carries over here is the, to even non-government contractors, is the cybersecurity threat, even if you’re not a Department of Defense contractor or Medicaid, you know, funds recipient, you have cybersecurity threats and you also have whistleblower protections for employees that are invoked all the time by employees that are looking for a reason to hang onto their job and to, you know, put the, shroud themselves in some sort of heroic whistleblowing context as they’re being shown the door. Could this model of marrying the whistleblowing concept with cybersecurity end up being a, essentially the template for more civil litigation that sort of, is patterned after this?

Goertz [00:17:35]

Yeah, and I think that is exactly why this is such an interesting paradigm shift and important to see because I think you could certainly see states, for instance like California which already have very robust regulations for privacy, compliance regarding the possession of personal information. You could see a state like California saying okay, if you’re a company subject to these protocols regarding privacy and data, these are also cybersecurity protocols you need to be adopting. And if you are not, here are the potential penalties and I think that is where this is going. I think, one thing to get into sort of civil litigation, is this is a component you are seeing more and, actually, in civil litigation, this space, this sort of class action cases that follow on the data breach cases is that this should never have happened because here are the basic cyber protocols that were not implemented. And there are now, sort of, basic standards that exist for cybersecurity based upon certain industries that are just, you can find online anywhere, right? And this is a good one and, sort of, everyone could be doing that as a baseline. And that’s what I think is, when I saw a philosophic shift, that’s what I think is the biggest difference is five years ago, it was a cost-benefit analysis for companies in terms of how much money to put into their cybersecurity infrastructure to prevent a data breach and sort of attempted civil litigation that follows it. It’s still a cost-benefit analysis but now there’s a lot more of a hammer than just, and not to say class action isn’t a big hammer, that’s significant, but now you’re having regulatory requirements and so it’s not just that in the event something happens, it’s no, I have to have this as a baseline and if I’m not, at any moment the government can come in and hit me with that and then now there might be follow on class actions, regardless of the breach. And if I do have a breach, now there’s all this other baseline standard of care that I would have always required to maintain that I may not be able to show and that’s going to make this class action significantly more problematic.

Schmidt [00:19:33]

So, we really follow a pattern in these podcasts where we spend about twenty minutes talking about things that, at least for some listeners in the relevant industry, raised the hair on the back of their necks in terms of how scary things are. We try to turn to some more pragmatic takeaways and steps so let’s do that now. Enough of the scary stuff, what are the things that you are working with clients on and the consultants that are being retained and so forth to essentially audit these compliance issues?

Goertz [00:20:14]

Yeah, I think the biggest one is that you want to have and this seems self-serving and it’s actually not, you want to have an attorney and a forensic investigator who are doing proactive testing, compliance to ensure your framework is operating the way it should and as the space continues to evolve you are updating and taking account of that and doing quarterly testing, yearly, extensive tabletop testing, is what it’s called. And the reason you want to have an attorney engaged or forensic investigator, as they’re called, is so that whatever work the forensic investigator is doing and all the profit, they’re gonna find some gap. Like there’s just no system that’s perfect, there’s always gonna be a gap. But you want that analysis to be under the cover of the attorney/client privilege so that if you have some issue, that analysis isn’t disclosed automatically and anywhere. I can’t tell you how many times, even post-incident, where I get a call from a client, we had this issue, don’t worry, we got a forensic investigator in and they got their report, and here it is. And I just, my heart it’s like every time, and it happens more than you would think. And it’s sort of you understand the clients. Like, that was the right instinct, but they don’t realize, you’ve now created significantly more problems because now there’s a report out there that is talking about all the things that weren’t done because you’re always gonna find something, but now it has to be disclosed because…

Schmidt [00:21:33]

It's a very nicely written smoking gun.

Goertz [00:21:36]

Yes, yes, exactly, exactly. And now this person you had, who was doing all this investigation, is now conflicted off ‘cause they’re gonna be called to testify and you can’t have them continue to do stuff, so you need to bring someone else in. So, it’s just having, I would say the best piece of advice is proactive compliance where you are, sort of have your team in place. And it’s a kind of a multi-facet there. But…

Schmidt [00:21:59]

No, no, please, finish that thought.

Goertz [00:22:03]

multi-facet, where you have cybersecurity, sort of expertise, along with your counsel to ensure that it’s protected by privilege, but you also wanna be interfacing with, like, your data privacy experts who also be sort of staying current on what is easy to retain, how long it needs to retain, what type of information is subject to a retention policy, ‘cause that’s a constantly evolving space, and retaining data is hugely expensive and burdensome, and sometimes you don’t need to retain it for as long as you think you do. And that is only gonna be positive in this space. So, there’s just a little bit of medicine on the front end makes a huge difference to sort of the outcomes if something significant were to happen.

Schmidt [00:22:45]

You know, I think the most common thing I say in this context is the old Ben Franklin ounce of prevention worth a pound of cure, and it applies here as well. I wanna go back to what you had said about doing the internal assessment, the tabletop audit and so forth. If breaches are found, not breaches, if deficiencies are found, is there a duty to disclose, or is there, is it advantageous to disclose to prevent, you know, it’s the age-old question, to prevent or mitigate and/or obtain favor if there’s a later prosecution?

Goertz [00:23:23]

Yeah, yeah. So, I guess there’s two things there. What you want to be, have your forensic investigator find or just the gaps in the network where someone could get in and do something bad, right? What you hope you don’t find is that there is someone in there and there has been a breach. If you do get in and find, and if at some point it’s disclosed, and I have a good example of this, that you’ve had a breach or you’ve lost information, you have to take immediate measures to understand the significance, the scope, and what your reporting obligations are. I mean, absolutely. And I think a good illustration of this was a year or so ago, sort of public lawsuits now related to it is this enormous AT&T data breach that happened I think about a year ago. And that one is very instructive because it was in 2019 that AT&T was sent a ransom that they had a data set that was taken, that was gonna be published to the dark web, multiple data sets. AT&T didn’t do anything. They ignored it, which is, okay, that’s a business decision, that’s fine. But they didn’t even perform an internal investigation to confirm where this occurred. And so, they had no idea whether it had or hadn’t and they didn’t do anything to determine that. Couple years later, similar ransom threat to disclose this, ignored. Again, no internal investigation to determine that, no advance reporting. And then finally it gets released on the dark web, and now you’re sort of seeing the, I mean just an enormous fallout. And what I would say is instances like that happening five or six years into the future, this is just not going to be palatable at all and you’re gonna see intense regulatory scrutiny if companies are aware of instances and they don’t look into them because now you’re starting to get into the realm of significant civil and potentially even criminal liability for stuff like this. And so that’s where I would be, you’re talking about proactive prevention. You’re hoping you don’t catch that. That’s often not what’s caught, is sort of a breach as it’s occurring. But you can, and you want, you absolutely wanna act quickly there, but this sort of proactive hope is you just were able to identify the gaps because you have a good forensic investigator who is acting like a bad guy, trying to figure out where can I get in, where are the vendor vulnerabilities, where is this sort of lowest common denominator space for me to access. Like a great story of this is Pentagon did some penetration testing, and they had the weakest link because they had a vending machine that was accessing the network because there was automatic payments, and that sort of compliance protocol for the vending machine payment processing spot, right, was linked to another network that had some spot to get in. And so, you just, people don’t realize that, you know, we are very connected and there’s a lot of benefit to that, but as a result of that, like, our networks are far more sprawling that you even sometimes realize.

Schmidt [00:26:09]

Yeah. So, to recap, if there’s a breach, the disclosure obligation is pretty clear. But if it’s just…

Goertz [00:26:16]

Yes, depending on your state. But for the most part, yes.

Schmidt [00:26:19]

Right. But if it’s not a breach, and we’re not really getting into state-by-state data breach disclosure obligations, which is a whole ‘nother conversation. But if there’s not a breach, you’re a federal contractor and you just have noticed that there’s some gaps in your cybersecurity that need to be tightened, some bells and whistles that need to be adjusted, is there a disclosure obligation on that to go to the government and say hey, we noticed we didn’t have this protocol and we now do?

Goertz [00:26:49]

I would think, so it’s a case-by-case basis so I’d be a little careful. It would depend on how, what the delta in that gap was.

Schmidt [00:26:55]

Right.

Goertz [00:26:57]

But I would be careful for sure, yes, and I would want to assess that pretty closely, and that’s why I would wanna be doing routine, testing routine, sort of auditing essentially my cybersecurity program because that is now the standard if you’re a federal contractor is that you are actually implementing what you’ve attested to, and these attestations as to the frameworks are very, are becoming very, very specific. And so yeah, you want to take that seriously for sure. Because…

Schmidt [00:27:26]

And I don’t know, talking to a lawyer, maybe a former U.S. Attorney like you, right, to assess that sliding scale of a voluntary disclosure.

Goertz [00:27:36]

Yes, yes, because you know who’s gonna be in the room when you sort of do the testing to determine what your gaps are? Your who will know exactly what the network was, will likely be aware of the contract, who will understand what these sort of whistleblower how lucrative that could be, and so you wanna make sure you’ve taken that very seriously.

Schmidt [00:27:55]

Right, right. Well, these are some very interesting but also sobering developments in the world of cybersecurity, now infused with False Claims Act additions. And so, I appreciate this conversation and all the practical takeaways that you’ve given us, and our time is about up for this episode and for that discussion. But before we let you go, we reached now the component of our episode in which we call The Deeper Dive, in which we learn a little bit about our guest and the life that they live and pursue outside of the four walls of the office, and outside the pursuit of serving clients and their communities in the legal arena. So, I don’t know you very well, haven’t, since you’re new to Dorsey, but I understand that one of your pursuits there in Phoenix where the weather is tolerable, is mountain biking. Tell me about how you got into mountain biking, and hopefully it’s been a pretty safe pursuit for you, and what some of your goals have been in mountain biking.

Goertz [00:29:18]

Yeah, yeah, well thanks. Phoenix is a fantastic outdoor city for most of the year. We’re about to get there, we’re hitting October. From October to May, being outside in Phoenix is hard to beat, and one of my favorite sort of outdoor hobbies is mountain biking. We got two young girls, seven and three. So, I don’t have as much time for this right now as I would like between chasing them around. I live, you know, minutes away from some just fantastic trails, and I enjoy getting out, decompressing, riding, and it’s just incredibly beautiful. I got into it, I was a road cyclist, kind of like yourself, for a while. And you had some buddies and friends who were constantly chirping about how enjoyable mountain biking would be. And I just did not believe them. But during Covid, for whatever reason, I got a wild hair, I was like I’m just gonna, there was a great sale on a mountain bike from a local shop. I said I’m just gonna try this, and if it doesn’t, if I don’t enjoy it in a month I’ll sell this bike. And three months later I sold my road bike ‘cause I just, I enjoyed mountain biking so much. I enjoyed being able to just disconnect, which I feel like I’m able to do a little bit better on a trail than like on the road where I’m worried about cars and just, it just feels different. But my goal ultimately, and who knows if this will ever be achieved, is to do the Leadville 100, which is a 100-mile mountain bike race, race is an odd word for it but sort of suffer fest I guess, in Leadville, Colorado, a town that’s at 10,000 feet elevation.

Schmidt [00:30:46]

All finishers are winners.

Goertz [00:30:48]

All finishers, yes, yes, and every finisher is absolutely a winner. And the thing I say, if that wasn’t enough in terms of how sort of epic this event is, Lance Armstrong, at his height, did this and set the course record, I think the course record’s actually, someone beat that. But a long-standing course record, when he was at his height at like seven hours or something. So, this is.

Schmidt [00:31:11]

With any performance enhancing or not?

Goertz [00:31:14]

There might have been. I mean, there might have been. This was sort of at his height. So, like, it’s, he was certainly hard to tell.

Schmidt [00:31:22]

Yeah.

Goertz [00:31:23]

But it’s sort of like always been, and I have some friends who’ve done it actually, and it’s something that’s on the bucket list for me.

Schmidt [00:31:31]

So, what’s a more typical time for that? If Lance Armstrong has seven hours and change, what’s…

Goertz [00:31:39]

For someone like me, it would be, you know, nine to ten hours probably on the bike. And you’re sort of taking some breaks, but I mean it’s a full, full day of riding.

Schmidt [00:31:52]

Yeah, well good luck on that. Hopefully you hydrate. When you’re mountain biking in Phoenix, are you able to, if you go in the evening as the sun’s setting, are you able to do that year-round, or are there just some months where it’s just, even at 8:00 at night it’s just a non-starter?

Goertz [00:32:13]

I used to be a little bit tougher, and I would just get up at like 5:00 am and go ride, and you can do that all year if you’re willing to get up early. Now the weather, you go out in the middle of the day, it’s just beautiful so that’s great. I think I don’t really have an appetite anymore to just suffer in the heat that early, so I kind of for the last few months in the summer just do the Peloton and I do that and sort of, I’ve grown soft.

Schmidt [00:32:39]

Yeah. And injuries so far have been not too devastating? Falls here and there?

Goertz [00:32:46]

You know, knock on wood, knock on wood, I’ve had some falls, you know, but nothing too devastating at all.

Schmidt [00:32:51]

Not into a cactus, I hope.

Goertz [00:32:53]

Yeah, not into a cactus, that’s right. So, we’ll see. About to enter a new season, so hopefully we’ll touch base in May.

Schmidt [00:33:01]

Okay. Well, stay safe out there.

Goertz [00:33:03]

Yeah.

Schmidt [00:33:04]

And thank you so much for taking the time to be on SharkCast and it’s been a pleasure to get to know you better through this process and our conversation, and I look forward to further opportunities to connect on these things.

Goertz [00:33:19]

Absolutely, thanks for having me, appreciate it.

Schmidt [00:33:21]

As always, I’m indebted to the extraordinary team at Dorsey for making this podcast and episode possible. For many resources on this and other litigation risk, go to litigationrisks.com where more information can be found, including a book on managing litigation risk written by yours truly. Until next time, my friends, this is yet another reminder that there are a lot of sharks swimming out there in the murky waters, so swim safely.

Voiceover [00:33:49]

This podcast is not legal advice and does not establish an attorney/client relationship or create any duty of Dorsey & Whitney LLP for those appearing in this podcast to anyone. Although we try to assure that the content of this podcast is accurate, comprehensive, and reflects current legal developments, we do not warrant or guaranty those things. The opinions expressed in this podcast are the opinions of those appearing in the podcast only and not those of Dorsey & Whitney. This podcast is considered attorney advertising under the applicable rules of certain states.

Firm Highlights

News

Patent Partners Al Araiza and Lena Petrovic Join Dorsey in Palo Alto

Patent partners Al Araiza and Lena Petrovic have joined Dorsey & Whitney LLP in Palo Alto, the international law firm announced today. Al Araiza works with clients to develop and implement patent strategies that align with corporate objectives, supporting growth initiatives, financing efforts, and successful exits, including initial public offerings and acquisitions. He advises on building, managing, and optimizing patent portfolios across a broad range of emerging and frontier technologies, with depth in wireless communications, artificial intelligence, and energy innovation. Before practicing law, Al gained engineering experience in the defense industry, working on energy system modeling and communications circuitry design. He also conducted biomedical research, with findings published in peer-reviewed journals. He has been recognized in the IAM Patent 1000 for his work advising clients on patent strategy and portfolio development. Al received his J.D. from Duke University School of Law, his M.E. in Biomedical Engineering from Tulane University, and his B.S. in Electrical Engineering from UCLA. Lena Petrovic works across the software and hardware industries to develop clear, well-supported patent applications. She guides clients through the prosecution process and advises on global trademark and copyright matters, including licensing and portfolio management. Lena regularly supports clients developing technologies such as artificial intelligence and machine learning, fintech, cryptography, interactive and immersive experiences, and digital media, and works with companies in entertainment, gaming, and sports. Before practicing law, Lena spent a decade at Pixar, where she contributed to major films including The Incredibles, Ratatouille, WALL‑E, and Brave. Lena received her J.D. from Santa Clara University School of Law, her M.S. in Computer Science from Princeton University, and her B.S. from California Institute of Technology. “Al and Lena bring a practical, technical, and business-focused approach informed by extensive experience working with technology companies, startups, and investors,” said Gina Cornelio, Patent Practice Group Co-Leader. “We are thrilled to welcome them to the Patent team and our growing Palo Alto office.” “Dorsey’s Patent practice is dedicated to understanding each client's business deeply, tailoring patent strategies that directly advance their goals,” said Al Araiza. “We are proud to join this outstanding team and look forward to driving success for our clients.”

Insights

Alaska HB 126: What Changes for Alaska Native Corporations, Proxy Filings, and Annual Reports

Alaska House Bill 126 (HB 126), sponsored by Representative Neal Foster and passed by the 34th Alaska Legislature, is now law. The bill changes which Alaska Native Corporations (ANCs) must file proxy and annual report materials with the State of Alaska, and makes it easier to reinstate certain dissolved Village Corporations. For many smaller Village Corporations, the practical result is less public disclosure. For shareholders, advisors, and the public, it means some financial information that used to be available through the State will no longer be readily obtained. This eUpdate explains what HB 126 does in plain terms, walks through the practical trade-offs, and answers common questions. 1. What HB 126 Changes The old rule Under prior law (Alaska Statutes Sec. 45.55.139), an Alaska Native Corporation had to file its annual report, proxies, and proxy statements with the Alaska Division of Banking and Securities (the Division) if it had more than $1 million in assets and 500 or more shareholders on its current rolls. A filing ANC was also required to follow the Division’s proxy rules (3 AAC 08.305 through .365), which require specific disclosures such as top 5 executive compensation, and related-party transactions. Because these filings are treated as public records, they gave non-shareholders, including the public and the press, visibility into ANC financial information that is not filed with the SEC. The new rule HB 126 changes how the 500-shareholder test is measured. Now, the asset test is removed, and the shareholder count is based on how many shareholders the corporation originally enrolled when it was formed under the Alaska Native Claims Settlement Act (ANCSA), not how many it has today. As shares have passed down through families over the decades, some Village Corporations that started with fewer than 500 shareholders now have more than 500 recordholders. Under the old current-count test, when those corporations had crossed the threshold, they had to file. Under the new original-enrollment test, they do not. Who is affected Village Corporations that originally enrolled fewer than 500 shareholders are the main beneficiaries. They no longer have to file proxy and annual report materials with the Division or follow the Division’s proxy regulations at 3 AAC 08.305 through .365. Two groups must continue to file as before: all twelve ANCSA Regional Corporations, each of which enrolled more than 500 shareholders at creation, and all Village Corporations that originally enrolled 500 or more shareholders. As reported by the Alaska Beacon, when the bill was under consideration, the Division identified 59 corporations then filing, expected at least seven village corporations to become exempt, and was reviewing roughly 30 more. 2. Practical Analysis HB 126 reduces a real compliance burden for smaller Village Corporations, which now need not spend time and money on State filings. In coming years, the exempt Village Corporations may experience benefits associated with less public disclosure and less regulation. But at the same time, less public disclosure carries trade-offs. Benchmarking will become harder Publicly-filed proxy statements and annual reports have long served as a reference set. Shareholders, corporations, advisors, and counsel use them to compare governance practices, compensation, and financial results across similarly-situated ANCs. Since fewer of these materials will be filed publicly, there will be fewer comparable documents available, which will make benchmarking and market-checking more difficult for like-sized ANCs over time. Executive compensation transparency may be reduced The Division’s proxy rules require disclosure of the compensation of ANC’s top five most highly compensated individuals (3 AAC 08.345(b)(2)), related-party transactions above $20,000 (3 AAC 08.345(b)(3)), and audited financial statements and management’s discussion and analysis (3 AAC 08.365). When a corporation is no longer required to file these disclosures publicly, it becomes harder for shareholders and others to obtain the information, to understand how compensation is set for their corporate leadership, and how it compares across corporations of similar size and complexity. Transparency may matter more as ANCs grow Some ANCs have grown into large, complex enterprises with substantial revenue and many subsidiaries, even with fewer than 500 shareholders. For an ANC with a broad and dispersed shareholder base, public materials can be an important way for shareholders and other stakeholders to understand governance, compensation, and performance across ANCs. Reduced disclosure may carry more practical weight in those settings than for a small corporation whose shareholders are closely connected to the business. The ANCSA annual report obligation continues It is important not to overstate what HB 126 does. HB 126 changes the state filing proxy requirements. It does not remove the separate obligation under ANCSA itself. That obligation comes from ANCSA at 43 U.S.C. Sec. 1625(c), which requires a Native Corporation that would otherwise be subject to the Securities Exchange Act of 1934 to prepare and transmit to its shareholders an annual report containing substantially the information a company subject to that Act would include. Similarly, ANCs that solicit proxies for an annual meeting are still required to furnish shareholders with those proxy materials under general Alaska corporate law. However, ANCs are now no longer required to transmit proxy statements to the State. ANCs’ reporting obligations to their shareholders are unaffected by HB 126. Any corporation newly exempt from state filing still owes its shareholders a detailed annual report and a proxy statement, even though that report is no longer routed through the State and made public. Reinstatement of dissolved Village Corporations Separately, HB 126 amends AS 10.06.960(k) to remove the prior deadline (previously December 31, 2020) for reinstating an involuntarily dissolved Native Village Corporation. A dissolved Village Corporation may now apply to be reinstated under AS 10.06.633(e) at any time. Reinstatement still runs through the commissioner under AS 10.06.633(e). In general, that means the ANC must apply, cure the neglect or delinquency that led to dissolution, and pay the amounts owed, and the corporation’s name must be available or be changed to one that is. Once reinstated, the corporation and its shareholders are restored to the rights, privileges, liabilities, and obligations they would have had as if the dissolution had never occurred, and corporate and shareholder actions taken during the dissolution are treated as valid. If the previously-used corporate name is no longer available, the board alone may amend the articles to adopt a new name (without the necessity for shareholder approval). 3. Frequently Asked Questions What does HB 126 do? It changes how Alaska measures the 500-shareholder test that decides which ANCs must file proxy and annual report materials with the state. It removes the asset test, and it counts shareholders based on original enrollment rather than the current rolls. It also removes the deadline for reinstating an involuntarily dissolved Native Village Corporation. Which ANCs are affected? Village Corporations that originally enrolled fewer than 500 shareholders, because they may no longer need to file with the Division. Regional Corporations and Village Corporations that originally enrolled 500 or more shareholders must continue to file as before. Does HB 126 eliminate all reporting obligations? No. It changes the state filing requirement under AS 45.55.139, but it does not remove the separate ANCSA obligation (43 U.S.C. Sec. 1625(c)) to provide shareholders with an annual report, and general corporate law still calls for a proxy statement when the ANC solicits proxies. Corporations that remain subject to state filing requirements must also continue to comply with the Division's rules. We think we are now exempt. What should our ANC board and management consider? Confirm your ANC’s original enrollment number and whether your corporation falls below the new threshold. Watch for communications from the State on this topic as they proceed with their research. If your ANC is now exempt, decide how your corporation will meet its continuing ANCSA obligation to shareholders, review proxy and annual meeting materials and timelines, and consider what to communicate to shareholders about any change in how they will receive information. It is worth documenting the basis for any exemption. What should ANC shareholders watch for? Shareholders should watch for how and when they will continue to receive annual report and proxy statement information directly from their ANC, since some material that used to be available through the State’s online website will no longer be publicly filed. If something is unclear, shareholders can ask their ANC how it intends to meet its ANCSA reporting obligations. How Dorsey Can Help HB 126 lightens the State filing load for smaller Village Corporations, but it also raises practical questions: confirming who is exempt, meeting continuing ANCSA obligations to shareholders, keeping proxy and annual meeting processes on track, and maintaining benchmarking when public materials become less available. These are exactly the kinds of judgment calls that benefit from early planning. Dorsey’s attorneys work closely with Alaska Native Corporations and related stakeholders. If you have questions about HB 126, ANC governance, proxy filings, annual reports, disclosure obligations, or shareholder communications, please contact your Dorsey attorney, including the authors of this eUpdate.

News

37 Dorsey Attorneys Named 2026 Top Lawyers by Minnesota Monthly

Minnesota Monthly has recognized 37 Dorsey attorneys across 27 practice areas as 2026 Top Lawyers in Minnesota. Honorees are selected through a peer nomination process and a curated survey of practicing attorneys in Minnesota, who identify leading lawyers across a range of practice areas. Administrative / Regulatory Law Jennifer Coates Antitrust Law Michael Lindsay Banking & Financial Service Law Peter Nelson Copyright Law  Jeffrey Cadwell Corporate Law  Robert Hensley Robert Rosenbaum Criminal Defense: White-Collar  Beth Forsythe Edward Magarian RJ Zayed Health Care Law  Claire Topp Immigration Law  J. Mike Sevilla Insurance Law  Daniel Brown Intellectual Property and Patent Law  Stuart Hemphill International Trade Law  Jonathan Van Horn Labor and Employment Law  Edward Magarian Ryan Mick Melissa Raphan Land Use & Zoning  Jay Lindgren Marcus Mollison Litigation – Antitrust  Michael Lindsay F. Matthew Ralph Jaime Stilson Litigation – Commercial  Michael Lindsay Litigation – Construction  Eric Ruzicka Litigation – Intellectual Property  Peter Lancaster RJ Zayed Litigation – Labor Employment Benefits  Ryan Mick Melissa Raphan Litigation – Trusts and Estates  William J. Berens Theresa Bevilacqua Bridget Logstrom Koci Mass Tort Litigation / Class Actions  James K. Langdon Mergers & Acquisitions Law  Keith Ahlgren Rachel Benedict Brian Burke Morgan Helme John Jorgenson Brian Moore Robert Rosenbaum Jonathan Van Horn Bri Whiting Municipal Law Jay Lindgren Nonprofit/Charities Law Claire Topp Securities / Capital Markets Law Cam Hoang Robert Rosenbaum Securities Regulation Theresa Bevilacqua James K. Langdon Tax Law William J. Berens Trusts and Estates Jennifer Ede Bridget Logstrom Koci Sonny Miller Kiley Petty Henry

Insights

Litigation Privilege Does Not Automatically Protect Communications with Funders: The Commercial Court Clarifies the Limits of Privilege in the Context of Litigation Funding

In Uber London Ltd & Ors v Garry White & Ors; Mishcon de Reya LLP [2026] EWHC 1610 (Comm), the Commercial Court held that documents created to help a funder decide whether to invest in a claim will not ordinarily attract litigation privilege. This means that information a firm gathers while acting for a funder can later fall within the control of the claimants it goes on to represent in the same matter. Background The Claimants (a claim group of over 10,000 individual London black cab drivers and the assignee of two former minicab operators) alleged that the Defendants (three companies in the Uber group) obtained and retained their private hire operator's licence through an unlawful means conspiracy alleged to involve fraud. Because the claims were issued outside the ordinary six-year limitation period, the Claimants relied on section 32 of the Limitation Act 1980, contending they could not, with reasonable diligence, have discovered the fraud before June 2018. A preliminary issue trial was listed to determine the question of whether the Claimants discovered, or could have discovered with reasonable diligence, the alleged fraud and/or deliberate concealment only after June 2018. The Claimants were represented by Mishcon de Reya ("MdR"). However, before MdR’s engagement with the individual drivers had begun, in late 2017 it was engaged by the litigation funder Harbour to investigate the merits and value of the potential claim. During that stage, MdR corresponded extensively with Harbour and with the Licensed Taxi Drivers' Association ("LTDA"), a black cab drivers' trade association. MdR was not formally engaged by the Claimants until October 2018 onwards. Once the proceedings had started, the Defendants sought disclosure of communications exchanged between MdR and Harbour before the engagement of MdR by the Claimants (the "Harbour Communications"). This included correspondence between MdR and Harbour, communications with the LTDA, and documents held on MdR's file opened in Harbour's name in connection with the potential claim. The Claimants resisted disclosure on four grounds: (i) that the documents were not relevant; (ii) on the grounds of litigation privilege; (iii) that the documents were outside their control; and (iv) that disclosure occurring so close to trial would be disproportionate. Judgment (i) Were the Harbour Communications relevant to the preliminary issue? The Court held that the Harbour Communications were likely to contain relevant material, on two bases. First, where the Claimants or the LTDA had communicated directly with MdR, that material could shed light on individual Claimants' actual knowledge of the alleged facts. Secondly, what MdR and Harbour had discovered during their investigation could inform the question of what a Claimant could reasonably have discovered at the time (even though the Defendants accepted that MdR's knowledge could not simply be imputed to the Claimants). (ii) Were the Harbour Communications protected by litigation privilege? As set out in the classic cases of Three Rivers (No. 6) [2005] 1 AC 610 and WH Holding Ltd v E20 Stadium LLP [2018] EWCA Civ 2652, communications between parties or their solicitors and third parties for the purpose of obtaining information or advice in connection with existing or contemplated litigation are privileged when the following conditions are satisfied: Litigation must be in progress or in reasonable contemplation. The communications must have been made for the sole or dominant purpose of conducting litigation. The litigation must be adversarial, not investigative or inquisitorial. The Court rejected the Claimant’s claim to be able to withhold the Harbour Communications on the basis of litigation privilege. The Court confirmed that litigation privilege protects only communications created for the dominant purpose of conducting litigation. The Court found that Harbour had instructed MdR so that Harbour could decide whether to fund the proceedings. As such, the dominant purpose of the communications was in relation to funding, not the conduct of litigation. This was distinguished from the situation where an individual litigant who takes its own funding decision. In that situation, the decision whether to fund and the decision whether to litigate are one and the same, made by the person who will actually be the claimant, and so it forms a part of that person's conduct of their own litigation. In contrast, a third-party funder's commercial decision whether to fund someone else's claim is not necessarily part of conducting that litigation. The fact that litigation privilege can, in principle, be claimed by a non-party funder (as recognised in the case of Al Sadeq v Dechert [2024] EWCA 28) did not assist Harbour, since there was no evidence it intended to play any role in the litigation itself beyond funding it. Communications between Harbour and MdR did remain capable of attracting another kind of privilege: legal advice privilege, because of the solicitor-client relationship between Harbour and MdR. But communications with third parties such as the LTDA were not automatically protected in the same way. (iii) Were the Harbour Communications within the Claimants' control? The Court also rejected the argument that the Harbour Communications sat outside the Claimants' control because they belonged to Harbour and not the Claimants. The Court’s reasoning was that once the individual Claimant drivers became MdR's clients, MdR also owed them a duty to disclose material information. That included information that MdR had originally acquired while acting for Harbour. As held in the case of Hilton v Barker Booth & Eastwood (a firm) [2005] 1 WLR 567, a solicitor owing duties to two clients cannot simply prefer one over the other, and it was unrealistic to suppose MdR would investigate the same claims for Harbour, then represent the Claimants, while disregarding everything it had already learned. The obvious commercial expectation was that this earlier work would be used to advance the Claimants' case. MdR sought to rely on a confidentiality clause in a 2024 retainer agreement between it and RGL Management Ltd (a claims management company acting on behalf of the Claimants) to argue that it was relieved of any duty to disclose information obtained while acting for other clients. The provision stated that MdR may "have acted for persons in the same or similar sector as yours and by agreeing to the terms of this letter you agree that will have no duty to disclose to you any confidential information that we have obtained, or might in the future obtain, from acting for such persons or which is derived from any other source". The Court rejected this on several grounds. Claimants who had already become MdR's clients had an existing right to information in the Harbour Communications where it was relevant to their claims before the 2024 retainer agreement. If they were to surrender that right, it would have required their informed consent (also required under the SRA Code of Conduct). The Court found no evidence that such informed consent had been given. The terms had simply been made available to the Claimants through a portal, with no indication that Claimants understood they were giving up existing rights to relevant information. The Court found that even if the terms had been contractually binding, that would not have amounted to informed consent. In addition, the wording of the clause was not sufficiently clear to show that the Claimants had agreed to waive access to this information. (iv) Was disclosure reasonable, proportionate, and necessary at this stage? The Claimants argued that it was neither reasonable nor proportionate for disclosure to be given at such a late stage (approximately two weeks before the start of the preliminary issue trial) and that it was not necessary for the just disposal of the proceedings. The Court rejected this, but it drew a distinction between two categories of documents within the Harbour Communications: Documents bearing on the actual knowledge of the individual drivers, including communications with the LTDA, were not privileged, likely straightforward to review, and directly relevant to the preliminary issue. Their disclosure was ordered as reasonable, proportionate, and necessary. Documents reflecting only MdR's or Harbour's own assessment of the merits were of more marginal, indirect relevance and largely likely to fall under legal advice privilege. A review to isolate the smaller pool of non-privileged material in this category would be time-consuming for limited benefit, so this was excluded from the order. Key Points to Note The judgment is an important reminder of several practical points: However closely a funder is involved in evaluating a claim's merits, litigation privilege will only apply to communications where the sole or dominant purpose of the communication is the conduct of litigation, not the funder's own decision on whether to finance it. Unless that communication separately attracts legal advice privilege, it may need to be disclosed. The same considerations apply to other communications. For example, in RBS Rights Litigation [2017] 1 WLR 3539 the argument that an After the Event (ATE) policy was subject to litigation privilege was rejected on a similar basis. Whilst in this case, there was no dispute as to whether litigation was in contemplation, it is important to note that litigation privilege will not automatically apply to the investigative stages of a claim, i.e. before litigation is in contemplation. Even where litigation is reasonably contemplated, the dominant purpose test must still be satisfied. Material created primarily for fact-finding, risk assessment, or other investigative purposes will not attract litigation privilege unless those activities are actually undertaken for the dominant purpose of conducting the litigation. (See The Director of the Serious Fraud Office v Eurasian Natural Resources Corporation Ltd [2017] EWHC 1017 (QB)). When engaging a law firm, clients should ensure that they understand whether the firm has previously obtained information about their claim while acting for another party (for example, a funder or another interested party) and how that information will be handled. Any restrictions on the firm’s ability to share relevant information with the client should be explained clearly at the outset, including what information may be withheld and why. If this decision raises questions about your own funding arrangements, disclosure strategy, or privilege position, please get in touch with our Commercial Litigation team.

Insights

Proposed CMS Rule Ramps Up Potential Medicare Fraud Administrative Remedies

On July 6, 2026, the Centers for Medicare & Medicaid Services (“CMS”) proposed a rule that would expand its administrative remedies to combat potential fraud. The proposed rule is the latest in a round of administrative actions that signal CMS’s intent to aggressively pursue allegations of Medicare and Medicaid fraud and heighten the risk of fraud enforcement against even well-intentioned Medicare and Medicaid providers and suppliers. The proposed rule includes several changes to regulations that govern Medicare billing privileges. Providers and suppliers should be aware that these changes dramatically expand the flexibility afforded to CMS in enrollment and revocation actions, potentially leading to harsh consequences for ministerial and administrative errors. If finalized, moreover, the proposed rule could have material implications for providers and suppliers facing threatened revocation, including heightened risk of overpayment liability and increased hurdles to challenging revocations and denials of enrollment. Added Flexibility to Existing Revocation Grounds CMS has proposed to remove a number of factors that the regulations list as relevant to a determination of whether a provider has engaged in “abuse of billing privileges.” While acknowledging that the inclusion of these factors in the regulations was permissive (requiring consideration only where “as appropriate or applicable”), CMS stated that it must be afforded “the maximum flexibility to address all possible . . . scenarios without the rigid constraints of our existing factors.” CMS provided little guidance as to the outer bounds of what conduct could constitute an “abuse of privileges” that merits revocation of Medicare billing privileges. Instead, CMS noted that a “pattern of practice” of abuse of billing privileges might be established “by a simple finding that several of a provider’s claims do not meet Medicare requirements.” Similarly, CMS has proposed to expand the regulatory provision that permits revocation of enrollment if a provider certifies as “true” false or misleading information in Medicare enrollment application or renewal forms to include any scenario in which a provider submits “false or misleading information on or associated with any CMS Medicare enrollment-related form,” including materials submitted to Medicare contractors. CMS stated that it interprets this expanded rule to include anything related to Medicare enrollment, and not only those submissions that are “intended to gain or maintain Medicare enrollment.” If finalized, the proposed rule would add significant flexibility to CMS’s ability to pursue revocation of a provider’s enrollment. While CMS has assured providers that it would “invoke [the revised regulations]. . . only when legitimately warranted under the facts and circumstances and not as a matter of course,” such expanded flexibility threatens unpredictability in the event of even administrative or ministerial errors in submissions and claims. These changes would, moreover, make it more difficult for providers to challenge a revocation action. Expanded Revocation Grounds In addition to adding flexibility to existing grounds for revocation, CMS’s proposed rule adds to and expands CMS’s already broad authority to revoke provider and supplier enrollment. Such proposed changes include adding the following grounds for revocation: Denial of Enrollment Application. Where CMS could previously revoke a provider’s other enrollments if one enrollment is revoked, CMS would also be able to revoke a provider’s existing enrollments if an application for enrollment submitted by the provider is denied. High-Risk Enrollments. CMS would be able to revoke enrollment if it determines the provider or supplier (including owning/managing employees or organizations) poses a high risk of fraud, waste, or abuse due to “. . . an affiliation under [42 C.F.R.] § 424.519” or “the provider’s or supplier’s location within a limited geographic area that has an excessive number of providers and suppliers.” Certain Misdemeanor Convictions. CMS would be able to revoke enrollment if a provider or supplier—or its owners, managing employees, managing organizations, officers, or directors—are convicted of a “misdemeanor related to sexual assault or financial misconduct within the past 10 years that CMS deems detrimental to the best interests of the Medicare program and its beneficiaries.” Ownership Changes (HHA, Hospice, DMEPOS). CMS would have broad authority to revoke enrollment of home health agencies, hospices, and DMEPOS suppliers who do not comply with the regulations governing provider changes of ownership. These proposed, expanded grounds for revocation are notably broad, and CMS provides only limited guidance as to what conduct might result in revocation under these grounds. As with the proposed expansion of existing grounds for revocation, the open-ended nature of these proposed grounds for revocation may make it more difficult for providers and suppliers to challenge revocation actions. Expanded Grounds to Deny Medicare Enrollment As with revocations, CMS proposes to expand the grounds under which a provider’s application to enroll in Medicare can be denied. These expanded and additional grounds include many of the grounds added for revocations, but also include: Medicare Debt or Payment Suspension. CMS proposes expanding the ground to deny enrollment based on Medicare debt or payment suspension to include a provider or supplier’s “managing employee, managing organization, or individual or entity with any other form of business or financial relationship with the provider or supplier[.]” Significantly, this expansive definition (called an “associated party” under the proposed regulation) currently contains no material limitations, meaning almost any person or entity with whom an applicant does business could create denial liability. Sharing Locations with Denied/Revoked Providers or Suppliers. CMS would have authority to deny applications where a “provider’s or supplier’s practice location is in the same suite or office as another provider or supplier whose Medicare enrollment has been revoked or denied.” Hospices with Distant Medical Directors or Administrators. CMS would have discretion to deny hospice applications if the hospice’s medical director or administrator serves “multiple other hospices” or practices/is located “at such a distance (for example, in a different state) from the enrolling hospice that the medical director cannot realistically perform all medical director functions,” with a similar provision for administrators. In addition, CMS proposes applications denied for “other program termination or suspension,” may be applied to the provider or supplier in its own name or NPI or that of its owners, managing employees, or managing organization regardless of whether any appeals are pending. Retroactive Revocation CMS proposed to restructure and expand the regulatory grounds for retroactive revocation of billing privileges. Currently, Medicare regulations provide that revocations are, by default, prospective in nature: effective 30 days after CMS or the CMS contractor mails notice to the provider. Under certain circumstances, the regulations provide for revocations to be retroactive, such as when a provider is convicted of a felony, the date a professional license is suspended, revoked, or surrendered, or when a provider submits a false certification in their enrollment application. CMS has proposed to reframe the rule so as to default to retroactive revocation of billing privileges. CMS expressed concern that providers may collect payment from Medicare while remaining so non-compliant with enrollment requirements as to merit revocation. To address this concern, CMS proposed that all revocations be retroactive to the date of determined non-compliance.[1] As a result, providers suspected of misconduct or non-compliance are likely to face claims of retroactive overpayments in addition to the immediate concern no longer receiving Medicare payments while their enrollment is revoked. Reapplication Bar CMS’s proposed rule expands the grounds from which a provider may be prohibited from seeking reapplication as a Medicare provider. Under current regulations, CMS may prohibit prospective providers from enrolling in Medicare for up to 10 years if its enrollment application is denied because the applicant submitted false or misleading information in its application. Under the proposed rule, CMS will have the discretion to prohibit a provider from enrolling in Medicare if their enrollment application is denied for any reason. Conclusion As a part of the federal government’s increasingly aggressive push to combat real or perceived healthcare fraud, the proposed rule both broadens CMS’s authority to revoke and deny Medicare enrollment and raises the stakes for revocation and denial. What the proposed rule does not share is how CMS plans to exercise this expanded discretion: as a result, the proposed rule, if enacted, increases the unpredictability and potential ramifications of even technical noncompliance with CMS rules. As a result, Medicare providers should keep a close eye on potential revisions to these rules and their potential implementation and consider proactively evaluating their compliance under CMS standards. [1] In the proposed rule, CMS identifies, with respect to each ground for revocation, what it will consider to be the effective date of revocation.

Insights

State Affordability Infrastructure Districts (SAIDs) — A Financing Tool for Taiwanese Investment in Arizona Science and Technology Parks

If you have developed a facility inside one of Taiwan's science or technology parks, you are accustomed to the one-stop-shop of government planning the park and delivering the roads, water, power, and other infrastructure before your building is even constructed. In the United States, including Arizona, land development generally does not work that way. In Arizona, the cost of infrastructure such as water, sewer, stormwater, roads, power, and the digital backbone, typically falls on the private landowner and is incurred up front before operations generate revenue to offset that cost. For a company entering the Arizona market, this is often the largest and earliest capital burden of the entire project. Arizona recently created a tool that provides a more cost-effective way for landowners and developer to finance some of that infrastructure. House Bill 2999, signed into law June 2026 and codified at Chapter 40 of Title 48 of the Arizona Revised Statutes, establishes the creation of a State Affordability Infrastructure District (SAID). How a SAID Works Landowners are now able to use a SAID to finance public infrastructure such as water, sewer, stormwater, roads, parking, lighting, communications, rail sidings and signalization, and similar improvements, through tax-exempt bonds. The bonds are repaid over up to 30 years and secured solely by the property within the SAID. No city, county, or state credit is pledged, and no obligation falls on other taxpayers, and therefore no city, county, or state approval other than from the Arizona Finance Authority (AFA). In effect, a SAID lets you spread the cost of horizontal infrastructure over the life of the asset instead of funding it entirely at the outset. And tax-exempt bonds often offer a lower interest rate than taxable or other types of financing. How a SAID is Formed A SAID is formed upon the filing of a petition with the AFA. The petition must include the finance plan, general plan, estimated costs, maximum tax rate, appraisal, bond counsel certificate, consultant list, petitioner experience, legal description, title report, and other materials. While the landowner is required to provide notice to the local governing jurisdiction, local governing jurisdiction does not have the right to approve or deny. The petition is reviewed administratively by the AFA through a standards-based process. For an inbound investor without long-standing local relationships, an objective, criteria-driven process is a meaningful advantage to the overt political process associated with other financing districts in Arizona. Formation requirements. A SAID requires consent from 100% of landowners within the proposed district; public infrastructure costs must exceed $5 million (easily met at any real scale); the district property must all be in the same county and need not be contiguous provided that noncontiguous property is located within five miles of the district's other property; and the board is initially appointed by the forming owners of the SAID district, later transitioning to election as ownership diversifies. Actual bond issuance requires an election of the SAID property owners. Ownership and corporate structure. Consent rights and board seats run with title. If you hold the Arizona land through a U.S. blocker beneath your Taiwan parent, the standard model for Taiwanese/Arizona real estate and operating investment, the U.S. property-holding entity, rather than it’s corporate parent, is the landowner of record for the district. Before formation, our Dorsey team will confirm that you have the proper corporate structure and board mechanics to be compliant.  Board composition has no citizenship or residency requirement. This is a common concern for foreign investors, and the statute answers it cleanly. Under A.R.S. § 48-7004, a director must either hold fee title to real property in the district or be an individual designated or appointed by a fee-title owner. Corporations, partnerships, and other business entities are expressly permitted to be those owners, to vote as owners, and to designate an individual to serve. There is no requirement that a director be a U.S. citizen or resident. So your U.S. property-holding entity, as landowner of record, can appoint whichever of your principals you choose, including a Taiwan-based individual, as the three-member board.  Power infrastructure limitation. The enacted definition of "public infrastructure" in A.R.S. § 48-7001 does not include electrical power generation or transmission. The reference to electrical facilities appears only as components of lighting and traffic-control systems, and the Legislature removed broader energy infrastructure from the definition during the Senate amendments. A SAID will likely not finance the high-load power infrastructure required for semiconductor fabrication, data storage, or heavy manufacturing.  Water infrastructure within a current utility CC&N. Where water, sewer, or wastewater facilities fall within a regulated utility's certificated service territory, the SAID cannot build or own them without the utility's written consent and must convey them to the utility on completion. Entitlements and zoning: The determination of entitlements, zoning, and other land use permitting, as well as construction permitting for a technology or manufacturing facilities remain with the local jurisdiction and run on a separate track. Our Dorsey team will help you coordinate the financing and entitlement timelines together. Our Dorsey team works regularly with Taiwanese and other Asia-Pacific companies entering the Arizona market. If a SAID fits your project, we can structure it for your cross-border ownership.

News

Dorsey Partner Melissa Raphan Elected a Fellow of the College of Labor & Employment Lawyers

International law firm Dorsey & Whitney LLP is pleased to announce that Partner Melissa Raphan has been elected a Fellow of the College of Labor & Employment Lawyers (CLEL) as part of its 2026 class. “Melissa’s election to this prestigious fellowship comes as no surprise to those of us who have had the privilege of working with her,” says Peter Nelson, Dorsey’s Managing Partner.  “She is an exceptional employment lawyer, a trusted advisor, and a leader whose impact extends far beyond her matters. Clients rely on her deep knowledge, strategic counsel, and ability to navigate complex workplace disputes and sensitive employment matters with both confidence and compassion. She has helped shape our firm, strengthen our profession, and opened doors for countless others through her commitment to mentorship and diversity. We are incredibly proud of her accomplishments and delighted to see her receive this recognition.” CLEL is a nonprofit professional association that honors the nation’s leading attorneys in the field of labor and employment law. Originally established to recognize excellence in the profession, CLEL has evolved into a respected intellectual and practical resource for the legal community and its many audiences. Its mission centers on recognizing individuals who have made significant contributions to the field, fostering the exchange of knowledge and delivering value to academia, government, the judiciary, and the broader public. Election as a fellow represents the highest level of peer acknowledgment, reflecting sustained achievement, integrity, and a commitment to advancing the profession. Melissa’s career reflects CLEL’s mission. She has been recognized both regionally and nationally for her advocacy, leadership, and achievements both inside and outside of the courtroom. Her employment litigation experience spans class actions, collective actions, and high-stakes individual disputes in state and federal courts, as well as arbitration forums including the American Arbitration Association and the Financial Industry Regulatory Authority (FINRA). She is also a trusted advisor on a full range of workplace issues, from hiring and performance management to sensitive terminations and organizational change. She brings decades of experience representing clients across the financial services, healthcare, food and agriculture, and energy sectors. Melissa will be formally inducted during CLEL’s installation ceremony held in conjunction with the American Bar Association’s Labor & Employment Law Conference in Washington, D.C., on November 7.

News

Real Estate Attorney Alexis Olsen Joins Dorsey in Phoenix

Attorney Alexis Olsen has joined Dorsey & Whitney LLP as Of Counsel in the Real Estate group in Phoenix, the law firm announced today. Alexis focuses her practice on large-scale residential, mixed-use, and multi-asset development projects as well as multi-state commercial leasing transactions. She guides clients through sophisticated acquisitions, dispositions, leasing, entity structuring, investment strategies, and due diligence matters. She has structured co-investment arrangements that drive capital deployment into housing subdivisions nationwide and has represented both landlords and tenants in commercial leasing transactions involving office, retail, industrial, and specialty-use properties, including cannabis dispensaries. Alexis received her J.D. from Sandra Day O’Connor College of Law and her B.A. from the University of Arizona. Alexis comes to Dorsey from Squire Patton Boggs. “Alexis strengthens Dorsey’s real estate capabilities at a time when Phoenix remains one of the fastest-growing and most dynamic real estate markets in the country,” said Scott Jenkins, Dorsey’s Phoenix office head. “Her addition further enhances our deep bench of 12 real estate attorneys in Phoenix and reflects our continued investment in serving clients throughout Arizona and supporting their real estate transactions and objectives across the country. We are thrilled to welcome Alexis to Dorsey.” “Joining a firm with such a deep bench of experienced attorneys in the Phoenix office, especially in the Real Estate group, presents an exciting opportunity not just for my own professional growth, but for the clients we service,” said Alexis Olsen. “I look forward to building on this strong foundation, growing our national practice, and delivering top-tier service to our clients.”

Insights

The Long-Awaited Public Infrastructure Financing Solution for Development in Arizona

Every developer who has taken raw Arizona ground to a finished project knows the largest upfront cost other than the land price is almost always the cost to install the public infrastructure. Water, sewer, stormwater, streets, dry utilities, and the fiber backbone all have to be in the ground before a single lot closes or a building opens. That capital is deployed early and generates no return for years. For decades the standard workaround has been the Community Facilities District (CFD). That tool has grown materially harder to use, for reasons cited below, and House Bill 2999, signed in June 2026 and now codified as Chapter 40 of Title 48, is Arizona's response. Some Background I have spent a good part of my career on the other side of this problem. In the 1990s and early 2000s I served as general counsel of SunCor Development Company, one of Arizona's most active master-planned community developers, where we used Community Facilities Districts to finance hundreds of millions of dollars of major infrastructure across Arizona in cities such as Goodyear, Phoenix, Tempe, Litchfield Park, and Prescott Valley. For its time the CFD was an effective structure, and a great deal of what is now on the ground in those communities was financed with this tool. Unfortunately, CFDs have over time become considerably harder to use. Successive legislative amendments have layered on tax-rate ceilings, homebuyer disclosure obligations, and added procedural steps. Another drag on the use of CFDs is that formation of them runs through the municipality, where approval can turn as much on local politics as on the merits of a project. Developers now routinely are asked to absorb delay and uncertainty that a project's economics cannot support, which is a large part of why Arizona has fallen behind Colorado, Texas, and Utah in getting infrastructure financed. A better tool was needed, and Chapter 40 is it. How a SAID Improves on a CFD A State Affordability Infrastructure District (SAID) keeps what worked about the CFD: tax-exempt, property-secured, non-recourse infrastructure financing — while shedding much of what made the CFD cumbersome. Its principal advantages over a traditional CFD: Administrative formation. A SAID is formed by the Arizona Finance Authority against fixed statutory criteria, through a yes-or-no compliance review on a sixty-day clock, rather than through the discretionary approval of a city council or a board of supervisors. Insulation from municipal politics. Because formation is a state-level compliance determination, a meritorious project is far less exposed to local political headwinds than it is under the CFD process. Landowner control of the board. A SAID is governed by a board of the landowners — appointed at formation, then elected on an acreage basis. In a typical municipal CFD, the city council sits as the district board; here, the developer controls governance. Advance funding of impact fees. A SAID can use bond proceeds to advance-pay municipal development impact fees, unlike CFDs, removing one of the largest upfront cash burdens in a project. A uniform, statewide process. The criteria are the same regardless of jurisdiction, replacing the municipality-by-municipality variation that has made CFD outcomes hard to predict. Flexible boundaries. A district may include noncontiguous parcels in the same county within five miles of one another, which fits phased and multi-tract development. Capped cost and a fixed timeline. Authority fees to form a district are capped at $15,000, and a complete petition must be acted on within sixty days. The full range of bonds. A SAID may issue general obligation, special assessment, revenue, and refunding bonds, secured solely by district property and creating no obligation for any other taxpayer. What is a SAID A SAID is a special taxing district that the owners of a development form to finance public infrastructure with tax-exempt bonds: general obligation bonds, special assessment bonds, and revenue bonds. The bonds are secured only by the property inside the district and are repaid over the long term, with terms up to 30 years. They do not affect the credit of the city, the county, or the State, and they create no obligation for any taxpayer outside the district. In practical terms, a SAID lets you finance horizontal infrastructure over the life of the asset instead of writing the check at the front end. The maximum ad valorem rate securing general obligation bonds is capped by statute at $5.00 per $100 of net assessed limited property valuation, with a limited step-up to cover a debt-service shortfall. SAIDs Work for Commercial as Well as Residential Development The SAID bill drew most of its press as a housing-affordability measure, and it appears to be a strong one. It is the first Arizona district statute to let bond proceeds advance-fund municipal development impact fees, which pulls one of the largest upfront cash burdens off a homebuilder's pro forma. But the statute's eligible infrastructure categories apply with equal force to commercial, industrial, and mixed-use projects. An industrial or logistics project can finance roads, rail crossings, sidings, and grade separations. A life-sciences or technology campus can finance its water, sewer, roads, and broadband the same way a subdivision can. Read Chapter 40 as a general-purpose infrastructure finance platform, not a subdivision-only device. How Formation Works A SAID is formed administratively by the Arizona Finance Authority. The Authority reviews the petition for compliance with the statute; it is a yes-or-no review against fixed criteria, not a discretionary negotiation with a city council or a board of supervisors, and it runs on a sixty-day clock once a complete petition is filed. Formation requires the written consent of 100% of the landowners in the proposed district and an engineer's certification that public infrastructure costs will exceed $5 million. The district may include noncontiguous parcels so long as they lie in the same county and within five miles of the district's other property, which accommodates phased and multi-tract development; if any part of the district sits inside a municipality, the whole district must stay within that municipality's limits or planning area. The Authority's fees to form a district are capped at $15,000. Issuing bonds requires a district election. Governance Simplified A SAID is run by a three-member board. The initial directors are named in the petition; after that, directors are elected by the landowners on an acreage basis as ownership diversifies. Board service runs with ownership; a director must either hold fee title inside the district or be an individual designated by a fee-title owner; and corporations, partnerships, and other entities may hold that ownership, vote as owners, and designate the individual who serves. A district has no power of eminent domain and no zoning authority, and directors may not be officials or employees of the municipality in which the district sits. What a SAID Does Not Do It finances; it does not entitle. Zoning, platting, rezonings, use permits, and the specialized approvals a manufacturing or life-sciences facility may need all remain with the local jurisdiction and proceed on their own track. The financing and entitlement timelines should be coordinated with formation of the SAID, but they are separate processes. Two substantive limits are worth flagging at the planning stage. First, electric power is largely outside the tool: the statutory definition of public infrastructure does not reach power generation or transmission, and broader energy infrastructure was removed from the bill during the Senate amendments. A power-intensive user should not assume a SAID will carry its electrical load. Second, where water, sewer, or wastewater facilities fall within a regulated utility's certificated service territory, the district cannot build or own them without the utility's written consent and must convey them to the utility upon completion. Our Take For most master-planned residential work, and for a wide range of commercial and industrial development, a SAID will be the most efficient infrastructure-financing structure Arizona has offered. The right time to evaluate it is early in the acquisition and pre-development process, while the capital stack, the development agreement, and the entitlement strategy are still being set. Once the district's boundaries, general plan, and financing parameters are set, it is cumbersome at best to bring those into conformance later. Our Dorsey team has begun advising our developer clients on SAID formation on residential, commercial, and industrial projects statewide. If you would like us to assess whether a SAID fits a project you are working on, please reach out.