Summary

  • Theranos's central public proposition combined several distinct claims: that very small fingerstick samples could support a broad menu of tests, that one proprietary platform could perform them, that results would be accurate and reliable, and that the service could be faster and cheaper than conventional laboratories. Each proposition required its own evidence. A single cleared assay, a successful demonstration, or selected internal precision data could not validate the whole menu, the collection device, modified third-party instruments, and the end-to-end reporting service.
  • The chronology matters. The company was founded in 2003; Ramesh "Sunny" Balwani joined in 2009; a Walgreens relationship began in 2010; retail patient testing launched in 2013; internal laboratory concerns were raised while testing expanded; FDA inspections ran from August to September 2015; CMS inspected the clinical laboratory later in 2015; corrective action and result voiding followed in 2016; civil and criminal cases came later. Enforcement exposed earlier control failures, but it did not create them.
  • The most supportable root-cause inference is a governance system in which secrecy and concentrated authority allowed commercial representations to outrun independently reproducible validation. Contributing conditions included a board and partners without a consistently visible technical challenge function, separation between device and laboratory oversight, use of both proprietary and conventional analyzers, weak complaint and corrective-action records, and organizational pressure to expand. The immediate public trigger was not one failed assay. It was convergence among employee warnings, reporting, FDA observations, CMS findings, patient evidence, and investor records.
  • FDA's July 2015 clearance concerned the Theranos HSV-1 IgG assay and its specified system. It was not approval of every Theranos test or every claim about the platform. Weeks later, FDA inspectors recorded design-validation, document-control, complaint-handling, corrective-action, supplier, software, and listing observations at two facilities. Form 483 observations are not final agency determinations, a boundary that must remain attached to every use of those documents.
  • CLIA placed operational controls inside the clinical laboratory. In the rules applicable in 2016, modified or in-house systems required documented performance specifications before patient reporting; proficiency samples had to be handled like patient specimens using routine methods; detected reporting errors required timely notice and corrected reports; and a high-complexity laboratory director remained responsible for overall operation even when duties were delegated. Those duties identify control owners. They do not, without more, establish any individual's criminal intent or civil liability.
  • CMS's late-2015 inspection and January 2016 report became the regulatory detection point for the laboratory. The record described condition-level deficiencies and immediate jeopardy to patient health and safety. In 2016 Theranos voided all patient results generated on the Edison and notified affected parties. Voiding was necessary correction evidence, but it was also proof that the organization could no longer defend those released results. It does not establish that every voided result was wrong, nor that conventional-analyzer results were all reliable.
  • Patient impact cannot be reduced to a dramatic but unsupported total. FDA's later investigative account describes more than six million documents and more than 70 doctors and patients identified for interview, together with specific patient experiences. Arizona obtained USD 4.65 million for full refunds to consumers who bought Theranos tests. Those records establish exposure, correction costs, fear, repeat testing, and some documented adverse experiences; they do not provide a population-wide clinical-causation study.
  • Investor and patient cases had different elements and outcomes. The SEC alleged that Theranos, Elizabeth Holmes, and Balwani misrepresented technology, business relationships, finances, and third-party validation. Theranos and Holmes settled without admitting or denying the SEC allegations. In the criminal case, a jury convicted Holmes on investor-conspiracy and investor-wire-fraud counts, acquitted her on the patient-related conspiracy and three patient counts, and did not reach verdicts on three other investor counts. A separate jury convicted Balwani on all charged counts, including patient-related counts.
  • The Ninth Circuit affirmed the convictions, sentences, and USD 452,047,268 restitution order for specified victims in the investor-fraud proceeding in a December 2025 amended opinion. That opinion also preserved important evidentiary nuance: regulatory violations could not themselves establish Holmes's criminal guilt, and some laboratory testimony approached expert testimony, though the panel found no reversible error. As of July 17, 2026, Balwani's certiorari petition was pending and distributed for a September 2026 Supreme Court conference. Pending review does not erase the operative judgments; neither does an operative judgment answer every scientific or patient-causation question.
  • Durable remediation would require more than closure, refunds, sanctions, and punishment. The missing proof is a test-by-test lineage showing the specimen type, instrument, software version, validation protocol, quality-control status, proficiency-testing method, report recipient, correction decision, and independent reviewer. The governance lesson is therefore practical: no diagnostic claim should move from research to patient service or investor representation unless an accountable owner can produce that lineage and an independent challenger can reproduce the conclusion.

Incident anatomy: root cause, conditions, trigger, detection, response, and recovery

Root cause. The root cause is best stated as a supported institutional inference, not a universal legal finding: Theranos lacked an effective, independent mechanism that forced broad commercial and clinical claims to remain within the boundaries of demonstrated analytical performance. The problem was not merely that a developing instrument failed. Diagnostic development expects failures. The problem was that evidence of assay limits, quality-control failures, instrument substitutions, and unresolved validation questions did not reliably stop patient reporting, public claims, retail expansion, or fundraising.

The later Ninth Circuit record supports that inference by documenting the limited number of assays run on the Edison, the use and modification of third-party instruments, internal concerns, demonstrations, investor statements, and laboratory evidence introduced at the two trials.

Contributing conditions. Secrecy narrowed external scrutiny. Concentrated executive authority weakened the chance that laboratory, engineering, quality, commercial, and finance evidence would be reconciled before claims left the company. The laboratory and device regimes examined different entities. Retail partners and directors could create pressure for proof, but the public record does not show a durable gate requiring independent assay-level validation before each expansion decision.

Conventional analyzers also obscured the accountability question: a Theranos-branded result might come from the Edison, a modified third-party analyzer, an unmodified analyzer, or a referral laboratory. Without instrument lineage, brand-level claims were not auditable.

Trigger. The trigger for decisive external action was convergence in 2015, not a single revelation. Employee concerns reached outsiders; investigative reporting challenged the technology narrative; FDA inspected the Palo Alto and Newark facilities; and CMS conducted an unannounced clinical-laboratory inspection. A trigger is the event that changes the response, not necessarily the earliest cause. By the time the trigger arrived, patients had already received results and investors had already supplied capital.

Detection. Detection occurred through different channels with different legal powers. Laboratory workers observed quality-control and proficiency-testing problems. Physicians and patients questioned discordant results. Journalists tested public claims against insiders and records. FDA inspected device design and manufacturing controls. CMS inspected compliance with clinical-laboratory conditions. The SEC examined investor representations. Federal investigators assembled patient, financial, device, and communications evidence. None held the entire picture at the start.

Response. The response included suspension or limitation of testing, corrective submissions, voiding Edison results, physician and patient notices, refunds, laboratory sanctions, civil settlements, prosecution, sentencing, restitution, and health-program exclusion. These steps had different purposes. Corrected reports protect clinical users; refunds address purchase price; CLIA sanctions protect laboratory quality; SEC remedies protect investors and markets; criminal judgments punish proved offenses; restitution addresses losses defined by statute and judgment.

Recovery. Theranos ceased clinical testing and ultimately became defunct, which removed the immediate operational risk but did not constitute validated recovery of the service. Recovery for affected users was partial and distributed: some received corrected reports or repeat testing, Arizona purchasers received refunds, and restitution was ordered for specified investor losses. There is no public, independent end-to-end audit demonstrating that every affected clinician and patient received an intelligible correction, that downstream medical records were reconciled, or that every eligible victim was made whole.

The evidence must be separated before responsibility is allocated

Six evidence categories recur in the Theranos record, and collapsing them produces overstatement. First are confirmed administrative facts: inspection dates, documents issued, a clearance decision, notices sent, and payments required. Second are agency observations or findings within defined authority. FDA Form 483 observations record what inspectors observed and explicitly say they are not final determinations. CMS condition-level findings concern CLIA compliance and patient-safety risk; they do not decide securities fraud.

Third are allegations in indictments and civil complaints. The SEC complaint against Theranos and Holmes is a detailed primary record of what the Commission alleged, including the scale of proprietary testing, modified third-party analyzers, demonstrations, pharmaceutical reports, military representations, and financial projections. It is not itself a verdict. Fourth are adjudicated facts and legal judgments: jury verdicts, sentencing findings, restitution rulings, and appellate holdings. Fifth are supported inferences about governance, such as the conclusion that independent challenge was structurally weak.

Sixth are unresolved questions, especially the number of patients clinically harmed and the complete chain from each test's raw data to its downstream use.

This separation is not excessive caution. It is the difference between learning from the event and retelling it as a morality play. The laboratory evidence can show that a result should not have been released without proving who possessed criminal intent. A patient can have experienced serious fear, repeat procedures, or delayed care without a public record sufficient to prove a particular long-term injury was caused by one result.

Conversely, an acquittal on a patient count does not validate the laboratory's analytical performance; it means the prosecution did not secure a conviction on that charged offense under the applicable burden and instructions.

2003-2012: an ambitious diagnostic proposition accumulated proof obligations

Holmes founded Theranos in 2003. The proposed benefit was intelligible: reduce the blood volume needed for testing, lower cost, shorten turnaround, and make access less intimidating. The proposition nevertheless combined specimen collection, assay chemistry, hardware, software, calibration, reference intervals, result transmission, and clinical interpretation. Each layer could perform differently. Small capillary samples can introduce collection and matrix issues distinct from venous samples. A method that works for one analyte does not automatically work for another.

An analyzer's precision says little about the accuracy of the collection process or the correctness of a reference range.

By 2009 Balwani had joined the company and later became president and chief operating officer. The appellate record says the exact division of responsibility between Holmes and Balwani was disputed at their trials, while evidence showed Balwani oversaw patient-laboratory operations and retail relationships and both communicated with investors and business partners. That is a more defensible allocation than treating a corporate title as proof of every decision.

Operational control must be tied to a decision: who approved an assay for patient use, who accepted a validation package, who authorized a claim, who released a result, and who could stop expansion.

External scientific evidence was unusually thin relative to the scope of the claims. In February 2015, John Ioannidis observed in a JAMA viewpoint on biomedical innovation and peer review that information about Theranos appeared in business and news publications but not the peer-reviewed biomedical literature. Peer review is not regulatory clearance and publication is not a substitute for a laboratory's own validation. Yet external methods and data would have allowed qualified scientists to test whether the evidence supported the breadth of the proposition.

The absence of such access made independent replication harder and increased the burden on internal controls, directors, partners, and regulators.

The accountability defect therefore began before the retail launch. It was a mismatch between a wide claim surface and a narrow verification surface. A company can protect trade secrets while still disclosing study design, specimen handling, comparator methods, sample sizes, acceptance criteria, error rates, interferences, excluded results, and independent replication. Confidentiality need not mean that only the claim owner can inspect the evidence supporting the claim.

2013: retail launch converted development uncertainty into patient risk

Theranos and Walgreens began working together in 2010, and patient testing launched in Walgreens locations in fall 2013. That transition changed the control problem. Before clinical release, an assay failure is development data. After release, the same failure can affect diagnosis, medication, pregnancy management, emergency referral, or reassurance. A retail setting can also make a service appear standardized and externally vetted even when the partner is not operating the laboratory or validating each method.

The court record says only twelve assays were ever run on the Edison, while other general-chemistry tests ran on third-party machines, some modified to handle small samples. The number matters less than the disclosure boundary. If patients, physicians, partners, or investors understood "Theranos technology" to mean one proprietary analyzer performing a broad menu from fingerstick blood, a service assembled from several specimen and instrument pathways required explicit explanation. Conventional instruments were not inherently inferior.

The risk arose when their use, modification, or validation differed from the represented system and when the report did not preserve that lineage.

The SEC's later complaint alleged that the proprietary analyzer performed about twelve of more than 200 tests on the published menu and that most other testing used commercial analyzers or referral laboratories. The complaint also alleged that some commercial analyzers were modified for fingerstick samples and that retail partners were not told the full extent of third-party use. Those remained SEC allegations when filed. The subsequent criminal record and appellate opinion independently established relevant portions through trial evidence, but every proposition should still be attributed to the proceeding that decided it.

Commercial launch also created a data-sovereignty problem in the practical, not geopolitical, sense. Theranos controlled the mapping between brand, specimen, method, device, software, quality-control state, and final report. Patients and clinicians received the endpoint, while the organization retained the provenance needed to assess it. That information asymmetry made correction dependent on the same institution that had authorized release.

A reliable system would give the laboratory director and an independent quality authority access to the full lineage, preserve immutable result versions, and make method changes and corrections traceable to every recipient.

Validation was a test-by-test obligation, not a platform adjective

The CLIA rule in force during the episode makes the control obligation concrete. 42 CFR 493.1253 in the 2016 edition required a laboratory introducing an unmodified cleared or approved system to verify specified performance and reference intervals before reporting patient results. A laboratory modifying a cleared system or introducing an in-house or otherwise uncleared system had to establish accuracy, precision, analytical sensitivity, analytical specificity including interferences, reportable range, reference intervals, and other necessary characteristics, and document the work.

Those requirements prevent a familiar category error. "The platform is validated" is not enough. Validation belongs to a defined assay, specimen type, instrument configuration, software version, processing protocol, reportable range, patient population, and intended use. A change from venous to capillary blood can require new evidence. Dilution, instrument modification, altered calibration, or a changed reference interval can require new evidence. Passing quality control today does not retroactively validate an inadequately established method, while a sound initial validation does not excuse later control failures.

Proficiency testing asks a different question: can the laboratory reproduce acceptable performance when it receives an external challenge? 42 CFR 493.801 in the same period required covered proficiency samples to be tested in the same manner as patient specimens, integrated with the regular workload, by routine personnel, using routine methods. The Ninth Circuit summarized testimony that proficiency samples were run on third-party devices while patient samples were run on Theranos devices, and that comparisons between the systems produced differences that concerned laboratory professionals.

That testimony was litigated: the appellate panel said portions approached expert testimony but concluded any admission error was harmless because the witnesses were qualified and the wider record was ample.

Quality control is narrower still. It asks whether a test system is operating within defined limits at the relevant time. The appellate court recounted Erika Cheung's trial testimony that she ran known control samples, saw frequent failures across Edison tests, and came to doubt reliability. The court held that her account of what she did and what the device reported was permissible lay testimony, while carefully distinguishing it from a technical opinion about the instrument's mechanics. That distinction is useful outside court.

Frontline staff do not need authority to diagnose root cause before they can stop release, preserve evidence, and escalate a repeated control failure.

Validation, proficiency testing, and quality control therefore form three separate gates. Validation establishes what a method can do. Proficiency testing checks performance against an external challenge under routine conditions. Quality control checks whether the system remains in control for a run. A diagnostic governance system fails if evidence from any gate can be bypassed by changing instruments, classifying a failure as isolated, pressuring staff to rerun until acceptance, or keeping the laboratory director away from the raw record.

2014-2015: internal warnings accumulated while external claims continued

The public trial record does not support a single moment when every decision-maker acquired the same knowledge. It shows repeated warnings moving through different channels. Former laboratory directors testified about concerns with particular assays, systemic accuracy, proficiency testing, and pressure to explain problematic results to physicians and patients. Laboratory associates observed control failures. Engineers and scientists knew which tests ran on which devices. Executives received information about technology and finances.

Investors and partners received a more integrated narrative of technological readiness and commercial expansion.

That asymmetry matters for responsibility. The scientist who observes a failed control owns immediate containment and escalation within authority, but may not control public claims. The laboratory director owns result quality and regulatory compliance even when tasks are delegated, but may lack control over fundraising materials. The chief executive and operating leadership control commercialization, representations, resources, and whether dissent can halt launch. Directors control oversight, leadership consequences, and the demand for independent evidence. A retail partner controls whether its channel remains open and what proof it requires.

Responsibility follows practical control and knowledge, not proximity to the eventual scandal.

An independent comparative study later provided a limited external check. A 2016 Journal of Clinical Investigation study of 60 healthy adults compared 22 common measurements across Theranos, LabCorp, and Quest. It reported significant interservice variability for many measures, more out-of-range results from Theranos, and non-equivalence for several lipid measures. The study could not determine whether differences arose from collection, processing, instrumentation, or a combination because Theranos's methods were not disclosed.

Its small healthy cohort and service-level design make it evidence of discordance and opacity, not a prevalence estimate for erroneous Theranos results or proof of individual injury.

The delay between internal observation and external containment was therefore not merely a whistleblowing problem. It was a failed conversion path. A credible warning system needs a protected route from bench data to a stop decision, documented criteria for reopening, and an escalation path outside the reporting line that owns launch goals. It also needs a record showing what leaders saw, what they asked, what evidence resolved the concern, and why patient reporting continued. Without that record, later assertions of reasonable reliance are difficult to test.

July-September 2015: one clearance and two inspections narrowed what could be claimed

On July 2, 2015, FDA cleared the Theranos Herpes Simplex Virus-1 IgG Assay under K143236. That was a real regulatory milestone for a specified assay and system. It did not clear a universal analyzer for hundreds of tests, certify the whole clinical laboratory, or validate every use of a nanotainer. Clearance is bounded by the device description, intended use, specimen, performance data, and labeling reviewed in that submission.

FDA inspected Theranos facilities from August 25 through September 16, 2015. The Palo Alto Form 483 recorded observations concerning design validation, validation under actual or simulated use, design inputs, risk analysis, and document approval. The form's annotations said corrections were reported but not verified. The Newark Form 483 recorded, among other matters, an uncleared capillary collection device shipped in interstate commerce, inadequate complaint procedures and investigation, undocumented corrective and preventive action, software-validation records, supplier controls, device-history procedures, and internal audits.

These forms have a precise boundary printed on them: inspectional observations do not represent a final agency determination regarding compliance, and the list is not necessarily exhaustive. They are strong evidence of what inspectors observed and what controls they questioned at that time. They are not final adjudications of fraud, proof that every device failed, or substitutes for the later jury record. Their importance lies in the pattern.

Design evidence, complaint evidence, corrective-action evidence, supplier evidence, and software evidence were all needed to demonstrate control of the device pathway, yet inspectors found gaps across that pathway.

The two facilities also show why regulatory fragmentation should not be described as total absence of oversight. FDA had authority over relevant devices and manufacturing controls and acted through inspection and clearance processes. CMS administered CLIA requirements for the clinical laboratory. State authorities had their own laboratory and consumer roles. The SEC addressed securities representations.

The gap was at the interfaces: who reconciled a device observation with the exact patient tests affected, who connected a laboratory control failure to claims made to a partner, and who ensured that one limited FDA clearance was not allowed to imply platform-wide endorsement?

Late 2015-2016: CMS findings turned internal quality questions into a correction duty

CMS conducted an unannounced inspection of the Newark clinical laboratory in late 2015. A January 25, 2016 report concluded that deficient practices posed immediate jeopardy to patient health and safety. The amended appellate opinion says the report identified quality-control failures involving both Edison tests and tests run on modified commercial instruments. A district-court pretrial order reviewing the CMS record preserved the procedural boundary: the report was admitted for defined evidentiary purposes, and the criminal jury was later instructed that regulatory violations did not themselves establish guilt.

The laboratory's response became an evidence question of its own. Corrective action should identify affected methods and dates, preserve original records, determine whether prior patient reports were adversely affected, stop unreliable testing, notify ordering clinicians and users, and issue corrected reports. 42 CFR 493.1291 in the 2016 CFR required timely notification and corrected reports when errors in reported patient results were detected, while retaining both original and corrected versions.

Theranos ultimately voided every patient result generated by the Edison. The Ninth Circuit held that evidence of the voiding was admissible in Holmes's trial and described the district court's finding that it was probative of knowledge and state of mind. That evidentiary holding should not be expanded into a claim that each result was proven inaccurate. Voiding is a population-level risk-control decision made when the organization cannot support reliance on the affected set.

Some individual results could have been numerically correct by chance or in fact; the problem is that the laboratory no longer had adequate grounds to warrant them.

CMS's July 7, 2016 sanctions notice said the laboratory had not removed immediate jeopardy and described certificate revocation, a civil money penalty, suspension of Medicare and Medicaid payment approval, and a two-year prohibition affecting owners or operators. The notice and later administrative path must be read with their appeal and effective-date provisions. It was an agency enforcement action under CLIA, not a criminal judgment. By then the response had moved from assay correction to institutional containment.

Patient and physician impact is real, but its denominator remains unresolved

A laboratory result is an intermediate product with downstream effects. A false high value can lead to emergency referral or invasive follow-up. A false low value can reassure a patient or clinician when further action is needed. A pregnancy-related result can change urgent decisions. Even a quickly corrected result can impose fear, repeat venipuncture, travel, expense, and lost time. Because the clinical consequence depends on the analyte, magnitude, patient's condition, clinician response, and timing, a raw count of voided reports is not a count of injuries.

FDA's investigative retrospective on the Theranos case says an agent worked through a database containing more than six million documents, cross-referenced test results, complaint logs, internal email, and physician email, and identified more than 70 doctors and patients to interview. It recounts specific pregnancy and emergency-referral experiences. This is a first-party agency account of its investigation, not an independent epidemiological study. The examples demonstrate pathways of harm; they do not measure all exposed patients or prove that every reported experience had the same cause.

Arizona pursued a different remedy. The Arizona Attorney General's settlement record says Theranos agreed to USD 4.65 million in consumer restitution so every Arizonan who purchased a Theranos blood test could receive a full refund, with payments distributed in December 2017. A refund is evidence of financial remediation and broad consumer exposure. It is not a clinical finding that every test was wrong, and it does not compensate all possible medical consequences.

Physicians were control owners as result users, but their position was constrained. A clinician can repeat a discordant result, compare it with symptoms, and challenge a laboratory. The clinician ordinarily cannot inspect proprietary instrument logs or know that a method changed unless the laboratory discloses it. Patient safety therefore depended on timely laboratory notice. A corrected report should identify what changed, why reliance is withdrawn, what period and method are affected, whether repeat testing is advised, and whom to contact. Merely replacing a value in a portal would not repair downstream records or decisions.

Investor representations converted validation evidence into securities evidence

The same technical facts acquired a second legal meaning when used to raise capital. Investors were not deciding whether to treat a patient. They were deciding whether claims about technological readiness, external validation, commercial relationships, military use, revenue, and scale justified investment. The SEC litigation release and complaint alleged that Holmes, Balwani, and Theranos raised more than USD 700 million while making materially false or misleading statements across those subjects.

One especially important bridge was purported third-party validation. The Ninth Circuit said trial evidence showed that Holmes placed pharmaceutical-company logos on favorable reports, described them as independent technical validation, and that representatives testified their companies had neither independently validated the technology nor authorized the logo use. This did not merely embellish a presentation. Independent validation was relevant because secrecy prevented investors from examining the device directly; a credible external verifier could substitute for some inaccessible evidence.

Mischaracterizing that verification changed the investor's evidence environment.

The SEC resolution had bounded legal effect. Theranos and Holmes agreed to settle; Holmes accepted a USD 500,000 penalty, a ten-year public-company officer-and-director bar, share return, and loss of voting control. They neither admitted nor denied the allegations. The court's final SEC judgment against Holmes formalized the remedies. Balwani did not join that settlement at the time. A settled civil injunction does not establish every allegation as adjudicated fact, and the later criminal verdicts must be stated according to their own counts and proof.

The criminal verdicts answered narrower questions than the full laboratory history

Federal charges arrived in 2018 after a multi-agency investigation. The Justice Department case record separates the alleged investor scheme from the alleged doctor-and-patient scheme and provides the charge and verdict history. That separation is essential because "the Theranos fraud" is too broad a label for the actual outcomes.

On January 3, 2022, the Holmes jury convicted on one conspiracy count concerning investors and three substantive investor wire-fraud counts. It acquitted on the patient-related conspiracy and three patient wire-fraud counts; one patient count had been dismissed during trial; and the jury did not reach unanimous verdicts on three investor counts, which were later dismissed. The DOJ sentencing release records the original 135-month prison sentence and three years of supervision. The verdict supports criminal responsibility for the investor offenses of conviction. It does not support saying Holmes was convicted of defrauding patients.

Balwani was tried separately. His jury convicted on all charged counts, including investor and patient schemes. The DOJ account of Balwani's sentencing records the original 155-month sentence and the trial evidence the government relied upon. Patient examples in a prosecution release remain examples, not a complete harmed-population count. Separate trials also mean evidence, objections, and jury assessments differed; one verdict cannot be used to fill gaps in the other.

In December 2025 the Ninth Circuit issued an amended opinion affirming the convictions, sentences then on appeal, and the district court's USD 452,047,268 restitution order for specified victims in the investor-fraud proceeding. The panel addressed laboratory testimony, the CMS report, voiding, cross-examination, alleged false testimony, sentencing loss, and restitution. It held, among other things, that admitting certain laboratory opinions was at most harmless error and that the jury instruction properly limited use of CLIA violations. Those holdings matter to procedural fairness and the stability of the judgments.

They are not a fresh assay-validation study.

Later proceedings remain distinct. In January 2026, the HHS Departmental Appeals Board affirmed Holmes's 90-year exclusion from federal health-care programs under the mandatory-exclusion framework, based on the investor-fraud conviction's connection to delivery of a health-care item or service and aggravating factors. That administrative decision is remedial within federal program participation; it is not another criminal conviction. As of July 17, 2026, the Supreme Court docket for Balwani v. United States showed a certiorari petition filed May 21, a government waiver of response, and distribution for the September 28 conference.

The petition remained pending. Its allegations of legal error are arguments for review, not holdings.

Practical control owners can be identified without inventing collective guilt

The laboratory director was the clearest statutory quality owner. 42 CFR 493.1445 in the period's CFR made the high-complexity laboratory director responsible for overall operation, competent personnel, accurate and proficient reporting, and compliance, while retaining responsibility when duties were delegated. That role needed authority to reject an assay, stop a run, obtain raw engineering and software evidence, investigate complaints, and contact clinicians without commercial approval. A title without those practical powers is a control design failure; delegation without verification is not accountability.

Technical and quality leaders owned the validation package and change control. For every assay they needed to bind acceptance criteria to the exact specimen, device, reagents, calibration, software, dilution, ranges, interferences, operators, and environment. They also needed to record failed studies, not only successful summaries. Their duty was to state what the evidence did not support. They did not necessarily own external investor statements, but they needed an escalation route when those statements exceeded the package.

Executive leadership owned claim scope and commercial pace. It could require that marketing, partner materials, demonstrations, menus, and investor decks cite the current validated configuration. It controlled whether conventional instruments were disclosed, whether a partner saw the complete method map, whether a failed control paused release, and whether quality functions had resources and independence. Criminal intent must be proved person by person, but operational ownership exists before a prosecutor establishes intent.

The board owned challenge and assurance, not assay execution. Its useful questions were specific: Which tests are running on which instrument today? Which use capillary rather than venous blood? Which commercial devices are modified? What proportion of reports came from each pathway? Who independently reproduced each method? What unresolved failures block scale? How many corrections were issued and did clinicians confirm receipt? A board composed of distinguished people is not equivalent to a board with access to independent laboratory expertise and unfiltered quality data.

Retail and commercial partners owned channel controls. They could condition launch on independent validation, audit rights, method disclosure, complaint metrics, regulatory correspondence, and stop clauses. Their presence could amplify institutional legitimacy, so their diligence needed to match that signaling effect. This does not make a retailer the laboratory director or automatically liable for hidden facts. It makes the retailer a practical gatekeeper for whether an unverified service reaches more users through its premises and reputation.

Regulators owned bounded public controls. CMS could inspect and sanction the clinical laboratory under CLIA. FDA could address devices, manufacturing, clearance, and related controls. Securities regulators could challenge investor representations. State authorities could protect consumers and oversee state requirements. The agencies did not share one unified real-time information framework. A stronger interface would join device identity, assay identity, laboratory certificate, complaint trends, proficiency method, and correction population so that a concern in one regime could be translated into affected patient reports in another.

Employees, physicians, and patients were detectors, not substitutes for governance. Protected reporting channels, anti-retaliation controls, complaint investigation, and independent escalation allow their evidence to reach an owner with stop authority. A safety system that depends on an employee accepting severe personal risk to make routine quality data visible has already failed upstream.

Remediation evidence shows containment, but not complete restoration

Theranos's result voiding, patient and physician notices, testing restrictions, leadership changes, and eventual exit from clinical testing were material containment steps. FDA forms also recorded that some corrections were promised or reported. But a correction claim needs effectiveness evidence. Were all affected reports identified? Did the method-to-report query include every instrument and software version? Did ordering clinicians receive notice? Were patient portals and downstream records updated without erasing originals? Were repeat tests paid for?

Did a qualified independent party verify the affected population and notice delivery?

The public record provides pieces, not a complete closure package. Arizona's refund program is concrete financial remediation. SEC remedies removed control and imposed restrictions. Criminal restitution created a USD 452,047,268 obligation for specified victims recognized in the investor-fraud proceeding, and the appellate court affirmed the order. HHS exclusion restricted federal-program participation. None proves payment in full, clinical reconciliation for every patient, or restoration of trust in laboratory innovation generally.

Closure of the company also changes the meaning of recovery. There was no corrected Theranos service returned to safe operation for the public to evaluate over time. The immediate hazard ended because the service ended. That is containment by removal, not evidence that the original control system learned and became reliable. Sector recovery instead depends on other laboratories, device makers, investors, boards, retailers, and regulators adopting stronger evidence gates.

FDA and CMS later emphasized in a joint statement on diagnostic-test reliability that the agencies have different roles: CMS regulates laboratories under CLIA, while FDA addresses the safety and effectiveness of tests as devices. The statement postdates Theranos and arose in a broader policy debate, so it should not be treated as a Theranos-specific reform finding. It does, however, confirm that the interface remains a live governance question.

A practical counterfactual locates preventable control failures

A useful counterfactual does not assume that leaders should have known every later fact. It asks what a competent control would have done with information available at the time. Before retail launch, an independent assay committee could have required a signed matrix listing each offered test, specimen, method, device, modification, validation status, and unresolved limitation. Any blank cell would block patient reporting and any broad platform claim.

During operation, a failed control would automatically quarantine the run and trigger a look-back to the last acceptable control. Repeated failures across devices would escalate outside the laboratory's commercial reporting line. Proficiency samples would follow the same routine method as patient specimens. Instrument substitutions or sample dilution would require documented revalidation. Complaints from physicians would be linked to instrument logs and method versions, not handled as isolated customer-service events.

Before a demonstration, partnership expansion, or financing, the claim owner would certify that every technical statement remained within the independent validation package. A verifier named in a presentation would approve the exact description of its work and any logo use. Investors and directors would receive negative results, unresolved deviations, complaint rates, regulatory correspondence, and the proportion of patient reports by instrument pathway. Secrecy agreements could protect details while allowing qualified reviewers access.

When the 2015 inspections and CMS findings arrived, a cross-functional incident commander independent of prior launch decisions would own containment. The organization would publish the affected-test logic, preserve originals, notify clinicians and patients in plain language, fund repeat testing, and commission an external audit. Regulators would receive the same method-to-patient map. These controls would not guarantee perfect diagnostics. They would make uncertainty visible before it became someone else's medical or financial risk.

What remains unresolved

The first unresolved question is the denominator of clinical harm. Public records identify specific experiences, a broad voided-result population, and a large consumer population, but no complete independent study links every report to subsequent medical action and outcome. Any precise total of injuries would exceed the available record unless tied to a defined methodology.

The second is the complete internal decision trail. Trials exposed substantial communications and testimony, but litigation selects evidence for legal issues. It does not necessarily reconstruct every assay approval, software change, partner review, board discussion, or complaint. Corporate dissolution can further fragment custody. A forensic data package would need raw validation files, device logs, laboratory information-system versions, report histories, quality-control records, emails, and recipient notices joined by stable identifiers.

The third is allocation among organizational layers. The record supports direct findings about Holmes and Balwani in specified proceedings and describes the responsibilities of laboratory leaders and staff. It does not support treating every director, scientist, employee, retailer, regulator, or investor as sharing knowledge or legal responsibility. Some employees supplied warnings and evidence; some outsiders lacked access to withheld facts. Accountability must be granular enough to distinguish those roles.

The fourth is remediation completion. Restitution ordered is not restitution collected. A refund addresses purchase price, not necessarily repeat care. A voided report warns against reliance but may not remove a value copied into another medical record. An exclusion prevents participation in federal programs but does not independently repair an affected patient's history. The available records prove substantial response; they do not prove universal closure.

The final uncertainty is whether later diagnostic ventures have internalized the lesson. Policy and technology have changed, but the core temptation remains: describe a future platform as though every present assay already inherits its promise. The only reliable answer is auditable evidence at the claim level.

Conclusion

Theranos is most useful as an accountability test when the sequence remains intact. An ambitious small-sample idea became a retail laboratory service. The service used multiple technical pathways. Internal evidence and complaints challenged reliability. Public and investor representations exceeded what independent outsiders could verify. Employee reports, journalism, FDA inspection, CMS findings, patient investigation, and securities evidence eventually converged. Correction, sanctions, refunds, civil remedies, criminal judgments, restitution, and exclusion followed.

The record supports serious responsibility, but not indiscriminate blame. Holmes's criminal convictions concerned investors, while her patient counts ended in acquittals or dismissal; Balwani's separate verdict included patient counts; SEC allegations settled by Theranos and Holmes were not admitted; FDA 483 observations were not final agency determinations; and patient examples do not establish a total harmed population. Preserving those boundaries strengthens rather than weakens the conclusion.

Diagnostic legitimacy depends on an evidence chain that can survive outside the institution making the claim. The practical owners must be able to show which method produced which result, under what validated conditions, with what control status, what external challenge, what disclosed limitation, and what correction path. When that proof is unavailable, commercial confidence is not a substitute. It is the risk being transferred to patients, clinicians, partners, investors, and the public.