Breaking Regulatory Compliance
SEC's $3.02M Doximity Insider Trading Judgment: The MNPI Control Test
The SEC's Doximity insider trading judgment exposes two MNPI control tests: earnings access and post-termination trading.
Table of Contents
TL;DR
- On September 10, 2026, a federal court entered a final consent judgment against former Doximity Chief Revenue Officer Paul W. Jorgensen. The SEC says the civil obligation totals $3,022,852.54, with criminal forfeiture credited against most of it.
- The SEC alleged trading before two negative earnings announcements: once while Jorgensen was CRO and again days after Doximity terminated him. He pleaded guilty in the parallel criminal case and received 26 months in prison.
- The control lesson is narrower—and more useful—than “train executives again.” Test whether Finance, HR, Legal, IT, and the broker-preclearance process respond to actual MNPI events, especially termination before earnings.
- Doximity was not charged in the cited action. Use the case to pressure-test controls without inventing a corporate compliance failure the SEC did not find.
The Doximity insider trading judgment puts a dollar figure on a control problem that often falls between teams: an executive can leave the company while the information in their head remains material and nonpublic.
According to SEC Litigation Release No. 26635, the final civil obligation against former Doximity Chief Revenue Officer Paul W. Jorgensen is $3,022,852.54. The court credited $2,532,775 already paid as forfeiture in the criminal case, leaving $490,077.54 due to the SEC. Jorgensen also received a 26-month prison sentence, 24 months of supervised release, a permanent officer-and-director bar, and injunctions against future violations of the cited Exchange Act provisions.
The headline number matters. The sequence matters more.
What happened in the Doximity insider trading case?
The SEC’s March 17, 2026 litigation release describes two separate trading windows.
In August 2022, while serving as Doximity’s CRO, Jorgensen allegedly sold 61,162 shares before a quarterly earnings call. The SEC said he possessed material nonpublic information about lower-than-expected sales. The complaint also alleged that he did not file the public reports required for those sales.
Approximately one year later, the SEC alleged, Jorgensen traded Doximity securities again. This time the trade occurred days after he had been terminated and before another earnings call. The nonpublic information allegedly concerned lower-than-expected sales, sales-team underperformance, and a planned reduction in force.
The SEC attributed $2,532,775 in aggregate profits and losses avoided to the trading. The procedural path then split across civil and criminal matters:
| Date | Event | Verified outcome |
|---|---|---|
| January 9, 2026 | Guilty plea in the parallel criminal case | Jorgensen pleaded guilty to insider trading. |
| March 16, 2026 | SEC complaint filed in SEC v. Paul W. Jorgensen, No. 1:26-cv-02115 (S.D.N.Y.) | The SEC charged violations of Exchange Act Sections 10(b) and 16(a), and Rules 10b-5 and 16a-3. |
| March 18, 2026 | Initial consent judgment entered | Permanent injunctions and a permanent officer-and-director bar were imposed; monetary relief remained to be determined. |
| May 21, 2026 | Criminal sentencing | 26 months in prison, 24 months of supervised release, and $2,532,775 in forfeiture. |
| September 10, 2026 | Final consent judgment | $2,532,775 disgorgement plus $490,077.54 prejudgment interest, offset by the criminal forfeiture. |
One boundary is important: the cited SEC releases do not charge Doximity. They describe Jorgensen’s conduct and the judgment against him. It would be careless to turn that into a claim that Doximity lacked a preclearance process, ignored an alert, or failed to maintain a blackout list. The public record cited here does not establish those points.
That boundary does not make the case irrelevant to compliance teams. It tells them how to use it correctly: as a test script.
The real MNPI control test is event-driven
Annual insider trading training is easy to evidence. It is also a weak proxy for whether the operating control works when revenue expectations deteriorate, a reduction in force is planned, or an executive exits days before earnings.
A defensible control links four facts in near real time:
- Who knows the information? Finance, Sales, Investor Relations, executives, board members, outside counsel, and selected vendors may enter the population at different times.
- What security or transaction is affected? The company stock is obvious, but options, derivatives, gifts, and sales under trading plans may require separate review.
- When does the restriction begin and end? Calendar blackout periods alone can miss unscheduled forecast revisions, restructuring decisions, or departure events.
- What proves the control operated? A dated restriction decision, preclearance disposition, broker data, access change, acknowledgment, exception approval, and reviewer sign-off.
The awkward part is ownership. Investor Relations knows the disclosure calendar. Finance knows when the forecast changed. HR knows when employment status changes. IT controls systems. Legal decides when information is material and public. The control fails operationally when each function assumes another one sent the signal.
A practical RACI looks like this:
| Trigger or activity | Primary owner | Required evidence |
|---|---|---|
| Forecast or sales outlook changes outside tolerance | CFO or Controller | Dated escalation to Legal; affected-insider population |
| Earnings or restructuring information becomes MNPI | General Counsel or CCO | Restricted-list entry and rationale |
| Executive termination, leave, or role change | HR | Same-day workflow ticket to Legal and IT |
| System-access suspension and log preservation | CIO or IT Security | Timestamped deprovisioning record and retained access logs |
| Personal-trade request | Legal/Compliance | Approval, denial, or hold with reviewer and timestamp |
| Broker-feed reconciliation | Compliance Operations | Exception report tied to preclearance records |
| Independent design and operating-effectiveness test | Internal Audit or Compliance Testing | Sample file, exceptions, remediation owners, and closure evidence |
This is a different control problem from the document-access failures discussed in the SEC and DOJ BigLaw insider trading case. That case centers on deal files and downstream tippees. Jorgensen’s case is a tighter issuer-side test: negative earnings information, an executive’s own trading, Section 16 reporting, and information that remained sensitive after employment ended.
Five controls to test—not merely document
1. Trigger restrictions from business events
Do not make the quarterly blackout calendar the only input. Create an event-trigger matrix covering forecast deterioration, revised guidance, planned layoffs, material customer changes, financing events, acquisitions, and executive departures.
A realistic starter rule could require the CFO to notify Legal whenever an approved forecast changes beyond an internally selected tolerance. That tolerance is not a universal regulatory benchmark. Calibrate it against the last four to eight quarters of forecast changes, disclosure decisions, and stock-price sensitivity. Then back-test whether the rule would have identified every event Legal ultimately treated as MNPI.
Evidence to retain: the forecast version, alert timestamp, Legal’s materiality decision, restricted population, and date the restriction was lifted.
2. Treat termination as an MNPI event
Standard offboarding asks whether credentials and devices were returned. Insider trading offboarding must also ask: What does this person know that the market does not?
For senior Sales, Finance, Product, Legal, and Investor Relations personnel, HR should open a Legal review before—or, for an involuntary exit, contemporaneously with—the termination. Legal should record:
- active MNPI known to the employee;
- affected issuers or securities;
- the expected public-disclosure event;
- the restriction end date or review date;
- post-employment acknowledgment delivery; and
- any broker-account monitoring or preclearance that continues under company policy.
The key artifact is not a generic reminder in the separation agreement. It is the dated assessment tying known information to a restriction period.
3. Reconcile preclearance to executed trades
An approval log proves only that someone asked. It does not prove that all trades were approved, that the order matched the approval, or that a denied request did not execute elsewhere.
Compliance Operations should reconcile broker data or required duplicate statements against the preclearance register. A useful test compares account, security, direction, quantity, and execution date. Exceptions should create tickets with an owner and aging clock.
If automated broker feeds are unavailable, start with quarterly statements for the highest-risk population. Sample design should prioritize executives with earnings access, recent role changes, denied requests, and missing Section 16 filings rather than selecting only random accounts.
4. Connect Section 16 reporting to surveillance
The SEC’s original release alleged both insider trading and failures to file required public reports for the 2022 sales. Those are separate legal allegations, but operationally they should converge in one exception process.
A missing or late Form 4-related workflow item should prompt three checks: Was there a trade? Was it precleared? Did the trader possess MNPI? The securities-law team may own the filing, while Compliance owns personal-trading surveillance. Their records should reconcile.
A simple monthly control can compare the executive and director population, reported transactions, preclearance records, broker data, and filed ownership reports. Every unmatched item needs a documented resolution—not an email chain nobody can retrieve during an inquiry.
5. Preserve evidence before accounts disappear
Termination can trigger deletion clocks, mailbox transfers, and access revocation. Legal and IT need a preservation step before those routines destroy the evidence required to reconstruct a decision.
For a high-risk departure near earnings, preserve relevant access logs, trade requests, acknowledgments, Legal advice records, and the versions of forecasts or board materials available to the departing executive. Scope the hold with counsel; do not collect everything by reflex. The objective is a usable chronology, not a data landfill.
For broader guidance on designing offboarding around malicious or unauthorized internal activity, use the insider threat incident response playbook. The legal theory differs, but the preservation and cross-functional handoff problems are similar.
A 30/60/90-day remediation plan
Days 1–30: reconstruct the workflow
The CCO or General Counsel should select the last two earnings cycles and one senior departure. Trace each event from first MNPI creation through public disclosure.
- Compare the actual insider population with the restricted list.
- Match HR status changes to Legal and IT tickets.
- Reconcile trade requests to executions and ownership reports.
- Record every missing timestamp, population mismatch, stale restriction, and undocumented override as a separate issue.
Do not bury six gaps inside one finding called “enhance insider trading controls.” Each gap needs its own owner, cause, evidence requirement, and dependency.
Days 31–60: repair the handoffs
Legal, Finance, HR, IT, and Compliance Operations should agree on trigger definitions and service levels. A starter operating target might require HR to notify Legal and IT immediately upon approval of a senior termination and require Legal to document the MNPI decision before separation where circumstances permit. Calibrate the timing to the company’s HR and security process; then test request-to-ticket timestamps so teams cannot satisfy the metric by opening tickets after the event.
Build the event-trigger matrix, revise the offboarding checklist, define the Section 16 reconciliation, and configure exception routing. Name one accountable owner for each handoff.
Days 61–90: prove it works
Compliance Testing or Internal Audit should test a fresh earnings cycle and every high-risk departure during the period. The sample should verify timestamps, not just document presence.
Closure evidence should include a successful end-to-end test, resolved exceptions, system screenshots or reports, reviewer sign-off, and a retest date. If the test fails, reopen the issue rather than marking it complete because the policy was updated. The MRA remediation playbook explains why document completion without operating-effectiveness evidence does not close the risk.
What to check Monday morning
Pull one recent senior departure that occurred within 30 days of earnings or another material announcement. Ask Legal to identify the MNPI the person held on the departure date. Then locate the restriction decision, access record, preclearance evidence, broker reconciliation, and ownership-reporting check.
If the chronology cannot be assembled, you have found the issue. Give it an owner and due date before rewriting the policy.
For teams turning that gap into a trackable remediation plan, the Issues Management Tracker & Template provides the issue log, root-cause, action-plan, and closure-evidence structure.
Sources
◆ Need the working template?
Start with the source guide.
These answer-first guides summarize the required fields, evidence, and implementation steps behind the templates practitioners search for.
◆ Immaterial Findings · Weekly
Sharp risk & compliance insights. No fluff.
◆ FAQ
Frequently asked questions.
What did the SEC's final judgment require Paul W. Jorgensen to pay?
What trades did the SEC allege in the Doximity insider trading case?
Was Doximity charged by the SEC in this action?
Why does post-termination access matter for MNPI controls?
Which teams should own an insider trading control review?
Author
Rebecca Leung
Rebecca Leung has 8+ years of risk and compliance experience across first and second line roles at commercial banks, asset managers, and fintechs. Former management consultant advising financial institutions on risk strategy. Founder of RiskTemplates.
● Don't wait for your own enforcement action
Every case like this started with a gap someone knew about but hadn't documented. The template below gives you the framework to get ahead of it.
Issues Management Tracker & Template
End-to-end issues tracking and remediation management for risk and compliance teams.
◆ Keep reading
Related posts.
Regulatory Compliance
FinCEN Health Care Fraud Analysis: $17.5 Billion in Suspicious Activity
FinCEN's health care fraud analysis reveals $17.5B in suspicious activity. Here is how BSA teams should update monitoring and SAR controls.
Sep 10, 2026
Regulatory Compliance
The CFPB Eliminated Federal Disparate Impact. Illinois Made It State Law. What Lenders with Illinois Customers Must Do Before January 2027.
Illinois enacted SB 3777 on July 31, 2026, creating an independent state-law disparate impact standard for credit decisions under the Illinois Human Rights Act — effective January 1, 2027. The federal government moved in exactly the opposite direction three months earlier. Lenders using AI or algorithmic underwriting need to understand what changed and what it requires.
Sep 9, 2026
Regulatory Compliance
The OCC Denied Wise and Bunq's Bank Charter Applications. Here's What 'Charter-Ready' Actually Means.
In six weeks, the OCC denied bank charter applications from two well-funded global fintechs — Wise in July 2026 and Bunq in August 2026. Both denials are now published. The reasons are specific, and they telegraph what the OCC expects before a fintech shows up with an application.
Sep 9, 2026