Insights

Professional
Practice
Industry
Region
Trending Topics
Location
Type

Sort by:

Client Alerts 8 results

Client Alert | 3 min read | 08.26.25

Hardening Software Security: DOJ’s Civil Cyber Fraud Settlements Continue to Illumina[te] the Importance of Cybersecurity

On July 31, 2025, the Department of Justice (DOJ) announced that Illumina, Inc. will pay $9.8 million to resolve allegations that it violated the False Claims Act (FCA) by selling genomic sequencing systems with software containing cybersecurity vulnerabilities to federal agencies. This is the first FCA settlement involving claims that a medical manufacturer failed to incorporate adequate product cybersecurity into its software design and development.The allegations were first made in United States ex rel. Lenore v. Illumina Inc., No. 1:23-cv-00372 (D.R.I.), a qui tam action filed by Illumina’s former Director for Platform Management, On-Market Portfolio in September 2023. The relator alleged that, between February 2016 and September 2023, Illumina knowingly sold genomic sequencing systems to government agencies without adequate security programs or quality systems to identify and address software vulnerabilities. The complaint further alleged that Illumina failed to properly resource personnel and processes responsible for product security, did not remediate design features introducing cybersecurity risks, and misrepresented the software’s adherence to required cybersecurity standards.According to the government, Illumina’s actions included:
...

Client Alert | 4 min read | 04.01.25

For Better or MORSE: Another Settlement Under DOJ’s Civil Cyber-Fraud Initiative

On March 26, 2025, the Department of Justice (DOJ) announced that defense contractor MORSECORP Inc. (MORSE) will pay $4.6 million to settle allegations that MORSE violated the False Claims Act (FCA) by failing to comply with cybersecurity requirements and subsequently submitting false or fraudulent claims for payment in its contracts with the Departments of the Army and Air Force. This is the first FCA settlement that is based on a defense contractor’s failure to reevaluate and promptly update its self-assessment score in the Supplier Performance Risk System (SPRS) after a third-party assessment resulted in a lower score.
...

Client Alert | 2 min read | 03.31.25

Canadian CMMC? Canada Proposes Cyber Compliance Regime for Canadian Defense Suppliers

On March 12, 2025, the Government of Canada announced plans to launch the Canadian Program for Cyber Security Certification (CPCSC). CPCSC is a cybersecurity compliance verification program that aims to protect sensitive unclassified government information handled by Canadian government contractors and subcontractors within Canada’s defense sector. Canada will roll out CPCSC to contractors in four phases, with the first phase launching this month.
...

Publications 1 result

Events 1 result

Event | 05.08.24, 4:30 PM MDT - 7:00 PM MDT

Denver Government Contracts Seminar

Join Crowell & Moring for Our Denver Government Contracts Seminar: Doing Business with the U.S. Government
The U.S. Government is investing more money than ever in new and emerging technologies, through R&D and procurement contracts, Other Transactions, and federal grant funding, even as it continues to spend in traditional aerospace, defense, and construction markets. This is a great opportunity to connect in person and explore the significant legal issues impacting companies in the Denver area doing business with federal, state, and local governments. 

Webinars 1 result

Webinar | 02.19.25, 12:00 PM EST - 1:00 PM EST

Civil Cyber-Fraud Enforcement: The Latest Developments and Risk-Mitigation Strategies

Please join Crowell & Moring attorneys, Steve Byers, Nkechi Kanu, Tully McLaughlin, and Jessica Chao for a webinar covering the latest developments stemming from the Department of Justice's Civil Cyber-Fraud Initiative.