Skip to content
RiskTemplates · The Daily Brief Friday, September 11, 2026
Wire SEC's $3.02M Doximity Insider Trading Judgment: The MNPI Control Test SEP 10

Breaking Regulatory Compliance

SEC's $3.02M Doximity Insider Trading Judgment: The MNPI Control Test

The SEC's Doximity insider trading judgment exposes two MNPI control tests: earnings access and post-termination trading.

By Rebecca Leung · September 11, 2026 ·
Table of Contents

TL;DR

  • On September 10, 2026, a federal court entered a final consent judgment against former Doximity Chief Revenue Officer Paul W. Jorgensen. The SEC says the civil obligation totals $3,022,852.54, with criminal forfeiture credited against most of it.
  • The SEC alleged trading before two negative earnings announcements: once while Jorgensen was CRO and again days after Doximity terminated him. He pleaded guilty in the parallel criminal case and received 26 months in prison.
  • The control lesson is narrower—and more useful—than “train executives again.” Test whether Finance, HR, Legal, IT, and the broker-preclearance process respond to actual MNPI events, especially termination before earnings.
  • Doximity was not charged in the cited action. Use the case to pressure-test controls without inventing a corporate compliance failure the SEC did not find.

The Doximity insider trading judgment puts a dollar figure on a control problem that often falls between teams: an executive can leave the company while the information in their head remains material and nonpublic.

According to SEC Litigation Release No. 26635, the final civil obligation against former Doximity Chief Revenue Officer Paul W. Jorgensen is $3,022,852.54. The court credited $2,532,775 already paid as forfeiture in the criminal case, leaving $490,077.54 due to the SEC. Jorgensen also received a 26-month prison sentence, 24 months of supervised release, a permanent officer-and-director bar, and injunctions against future violations of the cited Exchange Act provisions.

The headline number matters. The sequence matters more.

What happened in the Doximity insider trading case?

The SEC’s March 17, 2026 litigation release describes two separate trading windows.

In August 2022, while serving as Doximity’s CRO, Jorgensen allegedly sold 61,162 shares before a quarterly earnings call. The SEC said he possessed material nonpublic information about lower-than-expected sales. The complaint also alleged that he did not file the public reports required for those sales.

Approximately one year later, the SEC alleged, Jorgensen traded Doximity securities again. This time the trade occurred days after he had been terminated and before another earnings call. The nonpublic information allegedly concerned lower-than-expected sales, sales-team underperformance, and a planned reduction in force.

The SEC attributed $2,532,775 in aggregate profits and losses avoided to the trading. The procedural path then split across civil and criminal matters:

DateEventVerified outcome
January 9, 2026Guilty plea in the parallel criminal caseJorgensen pleaded guilty to insider trading.
March 16, 2026SEC complaint filed in SEC v. Paul W. Jorgensen, No. 1:26-cv-02115 (S.D.N.Y.)The SEC charged violations of Exchange Act Sections 10(b) and 16(a), and Rules 10b-5 and 16a-3.
March 18, 2026Initial consent judgment enteredPermanent injunctions and a permanent officer-and-director bar were imposed; monetary relief remained to be determined.
May 21, 2026Criminal sentencing26 months in prison, 24 months of supervised release, and $2,532,775 in forfeiture.
September 10, 2026Final consent judgment$2,532,775 disgorgement plus $490,077.54 prejudgment interest, offset by the criminal forfeiture.

One boundary is important: the cited SEC releases do not charge Doximity. They describe Jorgensen’s conduct and the judgment against him. It would be careless to turn that into a claim that Doximity lacked a preclearance process, ignored an alert, or failed to maintain a blackout list. The public record cited here does not establish those points.

That boundary does not make the case irrelevant to compliance teams. It tells them how to use it correctly: as a test script.

The real MNPI control test is event-driven

Annual insider trading training is easy to evidence. It is also a weak proxy for whether the operating control works when revenue expectations deteriorate, a reduction in force is planned, or an executive exits days before earnings.

A defensible control links four facts in near real time:

  1. Who knows the information? Finance, Sales, Investor Relations, executives, board members, outside counsel, and selected vendors may enter the population at different times.
  2. What security or transaction is affected? The company stock is obvious, but options, derivatives, gifts, and sales under trading plans may require separate review.
  3. When does the restriction begin and end? Calendar blackout periods alone can miss unscheduled forecast revisions, restructuring decisions, or departure events.
  4. What proves the control operated? A dated restriction decision, preclearance disposition, broker data, access change, acknowledgment, exception approval, and reviewer sign-off.

The awkward part is ownership. Investor Relations knows the disclosure calendar. Finance knows when the forecast changed. HR knows when employment status changes. IT controls systems. Legal decides when information is material and public. The control fails operationally when each function assumes another one sent the signal.

A practical RACI looks like this:

Trigger or activityPrimary ownerRequired evidence
Forecast or sales outlook changes outside toleranceCFO or ControllerDated escalation to Legal; affected-insider population
Earnings or restructuring information becomes MNPIGeneral Counsel or CCORestricted-list entry and rationale
Executive termination, leave, or role changeHRSame-day workflow ticket to Legal and IT
System-access suspension and log preservationCIO or IT SecurityTimestamped deprovisioning record and retained access logs
Personal-trade requestLegal/ComplianceApproval, denial, or hold with reviewer and timestamp
Broker-feed reconciliationCompliance OperationsException report tied to preclearance records
Independent design and operating-effectiveness testInternal Audit or Compliance TestingSample file, exceptions, remediation owners, and closure evidence

This is a different control problem from the document-access failures discussed in the SEC and DOJ BigLaw insider trading case. That case centers on deal files and downstream tippees. Jorgensen’s case is a tighter issuer-side test: negative earnings information, an executive’s own trading, Section 16 reporting, and information that remained sensitive after employment ended.

Five controls to test—not merely document

1. Trigger restrictions from business events

Do not make the quarterly blackout calendar the only input. Create an event-trigger matrix covering forecast deterioration, revised guidance, planned layoffs, material customer changes, financing events, acquisitions, and executive departures.

A realistic starter rule could require the CFO to notify Legal whenever an approved forecast changes beyond an internally selected tolerance. That tolerance is not a universal regulatory benchmark. Calibrate it against the last four to eight quarters of forecast changes, disclosure decisions, and stock-price sensitivity. Then back-test whether the rule would have identified every event Legal ultimately treated as MNPI.

Evidence to retain: the forecast version, alert timestamp, Legal’s materiality decision, restricted population, and date the restriction was lifted.

2. Treat termination as an MNPI event

Standard offboarding asks whether credentials and devices were returned. Insider trading offboarding must also ask: What does this person know that the market does not?

For senior Sales, Finance, Product, Legal, and Investor Relations personnel, HR should open a Legal review before—or, for an involuntary exit, contemporaneously with—the termination. Legal should record:

  • active MNPI known to the employee;
  • affected issuers or securities;
  • the expected public-disclosure event;
  • the restriction end date or review date;
  • post-employment acknowledgment delivery; and
  • any broker-account monitoring or preclearance that continues under company policy.

The key artifact is not a generic reminder in the separation agreement. It is the dated assessment tying known information to a restriction period.

3. Reconcile preclearance to executed trades

An approval log proves only that someone asked. It does not prove that all trades were approved, that the order matched the approval, or that a denied request did not execute elsewhere.

Compliance Operations should reconcile broker data or required duplicate statements against the preclearance register. A useful test compares account, security, direction, quantity, and execution date. Exceptions should create tickets with an owner and aging clock.

If automated broker feeds are unavailable, start with quarterly statements for the highest-risk population. Sample design should prioritize executives with earnings access, recent role changes, denied requests, and missing Section 16 filings rather than selecting only random accounts.

4. Connect Section 16 reporting to surveillance

The SEC’s original release alleged both insider trading and failures to file required public reports for the 2022 sales. Those are separate legal allegations, but operationally they should converge in one exception process.

A missing or late Form 4-related workflow item should prompt three checks: Was there a trade? Was it precleared? Did the trader possess MNPI? The securities-law team may own the filing, while Compliance owns personal-trading surveillance. Their records should reconcile.

A simple monthly control can compare the executive and director population, reported transactions, preclearance records, broker data, and filed ownership reports. Every unmatched item needs a documented resolution—not an email chain nobody can retrieve during an inquiry.

5. Preserve evidence before accounts disappear

Termination can trigger deletion clocks, mailbox transfers, and access revocation. Legal and IT need a preservation step before those routines destroy the evidence required to reconstruct a decision.

For a high-risk departure near earnings, preserve relevant access logs, trade requests, acknowledgments, Legal advice records, and the versions of forecasts or board materials available to the departing executive. Scope the hold with counsel; do not collect everything by reflex. The objective is a usable chronology, not a data landfill.

For broader guidance on designing offboarding around malicious or unauthorized internal activity, use the insider threat incident response playbook. The legal theory differs, but the preservation and cross-functional handoff problems are similar.

A 30/60/90-day remediation plan

Days 1–30: reconstruct the workflow

The CCO or General Counsel should select the last two earnings cycles and one senior departure. Trace each event from first MNPI creation through public disclosure.

  • Compare the actual insider population with the restricted list.
  • Match HR status changes to Legal and IT tickets.
  • Reconcile trade requests to executions and ownership reports.
  • Record every missing timestamp, population mismatch, stale restriction, and undocumented override as a separate issue.

Do not bury six gaps inside one finding called “enhance insider trading controls.” Each gap needs its own owner, cause, evidence requirement, and dependency.

Days 31–60: repair the handoffs

Legal, Finance, HR, IT, and Compliance Operations should agree on trigger definitions and service levels. A starter operating target might require HR to notify Legal and IT immediately upon approval of a senior termination and require Legal to document the MNPI decision before separation where circumstances permit. Calibrate the timing to the company’s HR and security process; then test request-to-ticket timestamps so teams cannot satisfy the metric by opening tickets after the event.

Build the event-trigger matrix, revise the offboarding checklist, define the Section 16 reconciliation, and configure exception routing. Name one accountable owner for each handoff.

Days 61–90: prove it works

Compliance Testing or Internal Audit should test a fresh earnings cycle and every high-risk departure during the period. The sample should verify timestamps, not just document presence.

Closure evidence should include a successful end-to-end test, resolved exceptions, system screenshots or reports, reviewer sign-off, and a retest date. If the test fails, reopen the issue rather than marking it complete because the policy was updated. The MRA remediation playbook explains why document completion without operating-effectiveness evidence does not close the risk.

What to check Monday morning

Pull one recent senior departure that occurred within 30 days of earnings or another material announcement. Ask Legal to identify the MNPI the person held on the departure date. Then locate the restriction decision, access record, preclearance evidence, broker reconciliation, and ownership-reporting check.

If the chronology cannot be assembled, you have found the issue. Give it an owner and due date before rewriting the policy.

For teams turning that gap into a trackable remediation plan, the Issues Management Tracker & Template provides the issue log, root-cause, action-plan, and closure-evidence structure.

Sources

◆ Need the working template?

Start with the source guide.

These answer-first guides summarize the required fields, evidence, and implementation steps behind the templates practitioners search for.

◆ Immaterial Findings · Weekly

Sharp risk & compliance insights. No fluff.

◆ FAQ

Frequently asked questions.

What did the SEC's final judgment require Paul W. Jorgensen to pay?
The September 10, 2026 final judgment made Jorgensen liable for $2,532,775 in disgorgement and $490,077.54 in prejudgment interest, a total of $3,022,852.54. The court credited the $2,532,775 forfeiture paid in the parallel criminal case, leaving $490,077.54 payable to the SEC.
What trades did the SEC allege in the Doximity insider trading case?
The SEC alleged that Jorgensen sold 61,162 Doximity shares before an August 2022 earnings call while holding material nonpublic information about lower-than-expected sales. It also alleged another trade before an August 2023 earnings call, days after his termination, based on nonpublic information about sales, sales-team performance, and a planned reduction in force.
Was Doximity charged by the SEC in this action?
No. The cited SEC releases and judgment concern Paul W. Jorgensen. Compliance teams should treat the facts as a control-testing prompt, not as a regulatory finding that Doximity's compliance program failed.
Why does post-termination access matter for MNPI controls?
Termination does not instantly make information public or immaterial. A departing executive may retain sensitive knowledge through an earnings release, restructuring announcement, or other disclosure event, so offboarding should include a dated MNPI assessment and a documented trading-restriction decision.
Which teams should own an insider trading control review?
Legal or the CCO should own policy interpretation and restricted-list decisions; HR should trigger role and termination events; Finance and Investor Relations should identify earnings and forecast access; IT should preserve and terminate system access; and Internal Audit or Compliance Testing should independently test the workflow.
Rebecca Leung

Author

Rebecca Leung

Rebecca Leung has 8+ years of risk and compliance experience across first and second line roles at commercial banks, asset managers, and fintechs. Former management consultant advising financial institutions on risk strategy. Founder of RiskTemplates.

● Don't wait for your own enforcement action

Every case like this started with a gap someone knew about but hadn't documented. The template below gives you the framework to get ahead of it.

Issues Management Tracker & Template

End-to-end issues tracking and remediation management for risk and compliance teams.

Immaterial Findings · Newsletter

The brief, in your inbox.

Enforcement of the week, a framework breakdown, and the prompts that are actually worth running. Delivered to your inbox. Free.