Certainly healthcare is shopped by its regulators, but it is done so through MSPs, not directly. I have also seen some shops assisting inspectors to make certain that previous offenders are now disposing of sensitive information properly. I don't believe the the Feds hire mystery shoppers directly but rather go through established companies.
As for Sarbaes-Oxley, that pertains to corporate accounting practices and is not something where your 'man on the street' shopper would be able to determine anything at all.