Stay connected: follow us on LinkedIn and explore more at
www.CherryHillAdvisory.com.

Subscribe now to join the Risk Register community:

Source: U.S. Department of Justice
Summary: On July 15, 2026 the U.S. Department of Justice announced that Laboratory Corporation of America (Labcorp) agreed to pay $14.5 million to resolve allegations under the False Claims Act. The DOJ press release states Labcorp routinely submitted certain urine drug testing claims to Medicare via a marketed panel called 'ToxAssure Comprehensive' and that the company billed combinations of CPT code 80307 and HCPCS code G0483 in a way the government alleged resulted in medically unnecessary claims. The release notes Labcorp has ceased the disputed billing combination and that the settlement credited Labcorp for disclosure, cooperation, and remediation.
Internal Audit Implications: This enforcement action is a clear example of how billing design, product packaging, and coding decisions translate into legal and control risk. Internal audit should prioritize: (1) A focused review of claim‑generation controls where product design (bundled testing panels) maps to billing codes — validate automated mappings, exception handling, and supervisory approvals. (2) Reassess the organisation’s risk assessment and risk register for revenue‑adjacent operational risks: how bundled offerings, pricing, and billing logic are governed and who owns compliance sign‑off. (3) Examine control design and testing around clinical necessity documentation, test ordering workflows, and medical‑policy review to ensure appropriate clinical governance and minimizing exposure to False Claims Act allegations. (4) For SOX compliance and ICFR, test entity‑level controls and process controls that prevent inappropriate simultaneous billing or duplicate claims; include inquiry and walkthroughs, control evidence around IT billing rules, and ITGCs over code‑to‑billing mapping. (5) Ensure remediation tracking and root‑cause analysis are documented, and verify remediation actions (e.g., stopping the billing combination) are effective and monitored. Finally, internal audit should brief the audit committee on the operational control gaps discovered, implications for contingent liabilities, and whether additional audit coverage is needed in downstream revenue and compliance testing.

Source: BleepingComputer
Summary: BleepingComputer reported on July 10, 2026 that Progress Software emailed ShareFile customers running on‑premises Storage Zone Controllers to manually shut down their Windows servers after identifying a 'credible external security threat.' The article quotes Progress and reproduces the customer advisory, noting temporary disablement of ShareFile access for affected controllers, the absence of confirmed unauthorized access, and the company’s instruction that customers power off controllers as a precaution. The piece references the ShareFile status page and prior attacks on managed file transfer platforms.
Internal Audit Implications: The Progress advisory is a practical reminder that vendor architectural choices (internet‑facing on‑prem components) can create concentrated IT risk that directly affects business continuity and internal controls. Internal audit should: (1) Reassess IT and vendor risk in the risk register for systems using hybrid architectures where control ownership is split between vendor cloud services and customer‑hosted components. Identify critical business processes (e.g., HR, finance, legal file transfers) that rely on those controllers and quantify potential operational exposure. (2) Validate incident response and crisis playbooks: confirm roles, communication protocols, preservation of logs/evidence, and authority to power down systems without violating regulatory retention or evidentiary obligations. (3) Test change and configuration management controls for internet‑facing servers, including hardened baseline configurations, segmentation, and remote access controls; ensure compensating controls exist when components are taken offline. (4) Review ITGCs and application controls that govern secure file transfer workflows for SOX‑relevant processes — e.g., access provisioning, logging, and reconciliation of transferred files that impact financial reporting. (5) Assess vendor oversight: confirm timely vendor notifications are incorporated into escalation criteria and that SLAs/contract language require vendor cooperation for forensic evidence and remediation. (6) Recommend targeted control testing to verify that business continuity plans and reconciliations operate effectively during service disruptions, and that management has updated the risk register and board reporting to reflect residual exposure.

Source: PublicNow (SEC Form 8‑K filing hosted on public distribution)
Summary: A Form 8‑K posted via PublicNow discloses that High Wire Networks, Inc. advised investors (document dated July 15, 2026) that its independent auditor concluded previously issued financial statements should no longer be relied upon. The 8‑K states management identified a material weakness in internal control over financial reporting related to monitoring of debt obligations and compliance with financing agreements, and that the company will describe remediation in its forthcoming Form 10‑K. The filing attributes the determination to discussions with the auditor and cites ineffective disclosure controls and procedures as of the affected periods.
Internal Audit Implications: This filing is a direct ICFR event for internal audit teams and SOX program owners. The auditor‑advised non‑reliance finding and disclosed material weakness require immediate audit committee and remediation focus. Internal audit should: (1) Map the weakness to control objectives and impacted assertions (completeness and accuracy of liabilities, covenant compliance disclosures, going concern and note disclosures) and update the enterprise risk register to reflect increased financial‑reporting and covenant risk. (2) Perform a root‑cause review of control design and operating effectiveness — specifically controls over debt monitoring, covenant tracking, and management review processes (IPE review controls). Document gaps in segregation of duties, periodic reconciliations, and supervisory review. (3) Expand SOX 404 testing to include newly identified and adjacent controls; design and test remediation steps and evidence trails the company plans to include in its 10‑K. (4) Assess the timeline and quality of remediation activities, ensuring management checkpoints, milestone‑based testing, and independent validation are in place; require management to maintain a remediation risk register and remediation evidence repository for board and regulator scrutiny. (5) Evaluate disclosure controls and investor communications controls to ensure accurate, timely public filings and to reduce litigation or regulatory risk. (6) Advise finance and legal on potential covenant impacts and recommend stress testing and scenario analysis so management can proactively negotiate with lenders if needed. Internal audit should report progress to the audit committee and ensure remediation status is tracked in the organisation’s risk register and SOX program dashboards.
Disclaimer: This content is provided for general informational purposes only and does not constitute legal, accounting, tax, investment, or other professional advice. Portions were generated using AI tools from public web sources and may contain errors or omissions — verify important details against the primary sources linked above before relying on them. Any example prompts, scripts, templates, or other artifacts are provided “as is” without warranty of any kind, express or implied; test them on non-production data and apply your own professional judgement before use. Cherry Hill Advisory disclaims all liability for any loss or damage arising from the use of, or reliance on, this content or any artifact it contains.
Subscribe now to join the Risk Register community: