Recent developments related to government contracting include significant changes to federal contractor affirmative action requirements and two developments involving False Claims Act (FCA) enforcement. The latest updates include US Department of Labor rules that formally rescind the regulations implementing Executive Order 11246 and modify Section 503 requirements, an Eleventh Circuit decision rejecting an Appointments Clause challenge to the FCA’s qui tam provisions, and a $2 million cybersecurity-related FCA settlement involving a defense contractor.
DOL Rescinds EO 11246 Rules and Revises Section 503 Requirements
The US Department of Labor (DOL) has finalized rules to formally eliminate the federal contractor regulations implementing Executive Order (EO) 11246 and make significant changes to regulations implementing Section 503 of the Rehabilitation Act (Section 503).
The EO 11246 rule removes the regulations at 41 CFR Parts 60-1 through 60-30, while the Section 503 rule eliminates both the requirement for contractors to invite applicants and employees to self-identify as individuals with disabilities and the disability utilization goal.
The Section 503 rule is notable not only for eliminating prospective compliance obligations but also for DOL’s discussion of affirmative action practices assumed under the former requirements. DOL asserts that employment decisions based on race or sex pursuant to the former requirements may constitute direct evidence of discrimination under Title VII and questions whether those practices fall within the US Supreme Court’s framework for lawful voluntary affirmative action.
That reasoning could become important in disputes involving employment practices adopted while EO 11246 remained in effect.
The Section 503 changes also warrant review of applicant tracking and voluntary self-identification processes. DOL justified removal of the self-identification requirement in part by pointing to limitations on disability inquiries under the Americans with Disabilities Act (ADA), particularly the act’s prohibition on preemployment inquiries.
While DOL does not prohibit contractors from continuing to collect this information, it advises them to evaluate whether they have a legally permissible reason for doing so under the ADA. Contractors should therefore reassess which demographic information they continue to collect, why they collect it, and whether existing application and employee systems should be modified in light of the new rules.
Eleventh Circuit Upholds FCA Qui Tam Provisions Against Appointments Clause Challenge
The Eleventh Circuit recently reversed a district court decision holding that the FCA’s qui tam provisions violate the Appointments Clause.
The court concluded that qui tam relators are not “Officers of the United States” because they do not occupy a continuing position that is established by law. Instead, a relator’s authority is temporary and tied to a particular lawsuit, with any financial recovery being contingent rather than continuing.
The decision reverses a closely watched 2024 ruling that had raised questions about a central feature of FCA enforcement. DOJ, although it declined to intervene in the underlying fraud action, intervened on appeal to defend the statute’s constitutionality.
The constitutional challenge is not entirely resolved. The Eleventh Circuit addressed only the Appointments Clause issue and remanded the case for consideration of separate challenges under the Take Care Clause and the Vesting Clause. For now, the decision aligns the Eleventh Circuit with other appellate courts that have considered the Appointments Clause issue and preserves the ability for private whistleblowers to pursue FCA claims where DOJ declines to intervene.
For additional analysis, please see our prior LawFlash, Eleventh Circuit Rejects One Constitutional Challenge But Leaves Open Questions on FCA Qui Tam Provisions, covering this development.
Cybersecurity FCA Settlement Reinforces Risks of Unsupported Compliance Certifications
A defense contractor recently agreed to pay $2 million to resolve allegations that inadequate cybersecurity controls resulted in FCA liability under US Department of Defense contracts involving quantum computing services.
According to the whistleblower complaint, the contractor received controlled unclassified information (CUI) but allegedly failed to implement required protections, including adequate anti-malware controls, access restrictions, employee incident-response training, and monitoring for suspicious activity. The matter was resolved without an admission of wrongdoing.
The settlement serves as a reminder that cybersecurity compliance can create FCA exposure when contractors certify compliance with contractual security requirements but fail to apply the necessary security protocols in practice.
Combined with the Eleventh Circuit’s decision preserving qui tam enforcement against the Appointments Clause challenge, the settlement also highlights the importance of internal reporting and escalation mechanisms. Contractors handling CUI should continue to ensure that cybersecurity representations are supported by actual practices and that identified compliance gaps are documented, escalated, and addressed appropriately.
Looking Ahead
These latest developments illustrate significant changes to contractor compliance obligations while reinforcing the continuing importance of FCA risk management. Federal contractors should reassess employment and demographic data collection practices following DOL’s regulatory changes and continue to monitor constitutional challenges to qui tam enforcement.
Contractors handling sensitive government information should ensure that cybersecurity certifications and representations accurately reflect implemented controls, especially since cybersecurity remains an active area for whistleblower claims and FCA enforcement.