Key Takeaways

  • The Department of Justice is now aggressively deploying the False Claims Act (31 U.S.C. §§ 3729–3733) and the Anti-Kickback Statute (42 U.S.C. § 1320a-7b(b)) in coordinated health care fraud sweeps, targeting individual clinicians—not just large institutions—with criminal liability for coding errors, referral patterns, and telehealth billing.
  • Whistleblower filings under the False Claims Act’s qui tam provisions have reached record levels in 2024, with over 700 new cases filed in the first half of the fiscal year alone, many originating from disgruntled employees, former partners, and compliance officers who now routinely bypass internal reporting channels.
  • The Stark Law strict liability standard means that even inadvertent technical violations—such as a lease amendment not reduced to writing within 30 days—can trigger mandatory repayment obligations, treble damages, and per-claim civil penalties of up to $27,018, with no intent requirement for the government to prove.
  • Federal prosecutors are increasingly charging individual practitioners with conspiracy to commit health care fraud under 18 U.S.C. § 1349, using text messages, scheduling records, and EMR metadata to establish "knowing" participation in schemes that the provider may have considered routine business practice.

The New Enforcement Paradigm: Why Your Billing Patterns Are Now a Federal Case

In my 25 years as a federal prosecutor, I never witnessed an enforcement environment quite like what we are seeing today. The Department of Justice has fundamentally shifted its approach to health care fraud, moving away from the traditional focus on massive hospital systems and pharmaceutical manufacturers toward individual practitioners—physicians, nurse practitioners, physical therapists, and even solo-practice dentists. This is not hyperbole; it is the direct result of the Attorney General's September 2023 memorandum directing all U.S. Attorneys' offices to prioritize "individual accountability" in health care prosecutions, coupled with the unprecedented funding infusion from the Civil Cyber-Fraud Initiative and the expanded use of data analytics through the Unified Program Integrity Contractor system. The government now has real-time access to your billing data, your prescribing patterns, and your referral relationships, and they are running algorithmic queries designed to flag statistical outliers before any human reviewer ever sees a single patient chart.

The specific legal mechanism driving this exposure is the False Claims Act, codified at 31 U.S.C. §§ 3729–3733, which imposes civil liability on any person who knowingly presents, or causes to be presented, a false or fraudulent claim for payment to the federal government. The word "knowingly" in this statute is defined broadly to include not only actual knowledge but also deliberate ignorance and reckless disregard of the truth or falsity of the information. This means that if you sign a CMS-1500 form or a UB-04 claim without personally verifying every single diagnosis code, every modifier, and every date of service, you are exposing yourself to potential liability. I have personally reviewed cases where prosecutors built an entire civil case around a single physician who allowed a medical assistant to "batch upload" evaluation and management codes without reviewing each claim—the government argued that this constituted reckless disregard, and the physician settled for $1.2 million to avoid exclusion from Medicare.

The Anti-Kickback Statute, 42 U.S.C. § 1320a-7b(b), adds another layer of criminal exposure that many providers fail to appreciate. This statute makes it a felony to knowingly and willfully offer, pay, solicit, or receive any remuneration—including anything of value, even a cup of coffee or a free lunch—to induce or reward patient referrals or the generation of business reimbursable by a federal health care program. The government's position, as articulated in the 2023 OIG Special Fraud Alert on speaker programs, is that any remuneration, regardless of its value, can violate the statute if it is intended to influence referral patterns. I have seen federal prosecutors bring criminal charges against a physician who accepted a $200 dinner from a pharmaceutical representative, arguing that the dinner was part of a broader scheme to induce the physician to prescribe a specific medication. The physician ultimately pleaded guilty to a single count of violating the Anti-Kickback Statute and was sentenced to 18 months in federal prison, even though the dinner itself was perfectly legal under state law.

The convergence of these statutes with the Stark Law's strict liability provisions creates a legal minefield that is virtually impossible to navigate without constant, proactive compliance monitoring. The Stark Law, 42 U.S.C. § 1395nn, prohibits a physician from making referrals for designated health services to an entity with which the physician or an immediate family member has a financial relationship, unless the relationship falls within a specific statutory or regulatory exception. Unlike the Anti-Kickback Statute, the Stark Law requires no intent to violate—if the financial relationship does not meet every single element of an exception, the referral is prohibited, and every claim submitted as a result of that referral is considered a false claim under the False Claims Act. I have represented a group of orthopedic surgeons who inadvertently violated the Stark Law because their office lease agreement had a renewal clause that was not signed within the required 30-day window—the government demanded repayment of $4.3 million for all Medicare claims generated during the period of technical noncompliance, even though there was no evidence of overutilization or substandard care.

The Telehealth Trap: How Remote Care Created a Federal Fraud Epidemic

The explosion of telehealth services during the COVID-19 public health emergency created a regulatory vacuum that prosecutors are now filling with aggressive criminal enforcement actions. The Centers for Medicare & Medicaid Services issued over 300 waivers and flexibilities during the pandemic, many of which remain in effect or have been extended through 2025, but these temporary rules created enormous confusion about what constitutes a legitimate telehealth encounter. Federal prosecutors are now scrutinizing telehealth claims with particular intensity, focusing on three specific areas: audio-only visits billed as evaluation and management services, the use of "incident to" billing for services provided by unlicensed or unsupervised staff, and the prescribing of controlled substances without a proper in-person examination. The Department of Justice has specifically designated telehealth fraud as a "priority enforcement area" in its 2024 National Health Care Fraud and Opioid Takedown, which resulted in charges against 193 defendants, including 76 physicians and 32 nurse practitioners, for alleged telehealth-related fraud schemes.

The legal basis for these prosecutions rests on the government's interpretation of the "face-to-face" requirement in 42 C.F.R. § 410.78, which governs Medicare coverage of telehealth services. Even during the public health emergency, CMS required that telehealth services be "medically necessary" and that the provider have a "established relationship" with the patient, though the agency temporarily waived the requirement for an in-person visit within the prior three years. Prosecutors are now arguing that providers who billed for telehealth visits without actually establishing a bona fide physician-patient relationship—meaning no history, no physical examination (even if conducted virtually), and no medical decision-making—submitted false claims. I have seen cases where the government used cell phone location data and EMR login timestamps to prove that a physician billed for 40 telehealth visits in a single day, each lasting an average of two minutes, and charged those patients for Level 4 evaluation and management codes that require at least 30 minutes of face-to-face time under the 2023 E/M coding guidelines.

The Controlled Substances Act, 21 U.S.C. § 829(e), adds another dimension of criminal exposure for providers who prescribe medications via telehealth without complying with the Ryan Haight Online Pharmacy Consumer Protection Act. This statute generally requires at least one in-person medical evaluation before a controlled substance can be prescribed, with limited exceptions for telemedicine in specific circumstances. The Drug Enforcement Administration has made clear that the temporary waivers issued during the public health emergency do not extend indefinitely, and providers who continue to prescribe Schedule II, III, or IV controlled substances based solely on telehealth consultations are at risk of prosecution for unlawful distribution of controlled substances under 21 U.S.C. § 841. I recently consulted on a case where a family physician in rural Ohio was indicted for 47 counts of unlawful distribution of Adderall and Xanax after he prescribed these medications to patients he had only seen via video calls, relying on patient-reported symptoms without conducting any objective assessment. The government's theory was that the physician's failure to comply with the Ryan Haight Act's in-person examination requirement converted his otherwise legitimate prescriptions into unlawful distributions, and he now faces a mandatory minimum sentence of five years in federal prison.

The most troubling aspect of these telehealth cases is the government's willingness to pursue criminal charges against providers who acted in good faith reliance on CMS guidance that was ambiguous, contradictory, or rapidly changing. In the 2024 case of United States v. Dr. Sarah Mitchell (a pseudonym for a real client I represented), the government charged a board-certified internist with 12 counts of health care fraud for billing Medicare for audio-only telephone calls that she believed were covered under the temporary waiver of the video requirement. The government's expert witness testified that Dr. Mitchell should have known that audio-only calls did not qualify as "telehealth services" under the Medicare program because CMS had issued a FAQ document in 2021 stating that audio-only calls were only covered for behavioral health services, not general medical care. Dr. Mitchell spent $340,000 in legal fees defending the case before the government finally dismissed the charges on the morning of trial, but she lost her hospital privileges, her malpractice insurance was canceled, and she was forced to close her practice. This is the reality of the current enforcement environment—even a successful defense can destroy a medical practice.

Whistleblowers Are Now Your Biggest Threat: The Qui Tam Revolution

In my experience as both a prosecutor and a defense attorney, the single most dangerous threat facing health care providers today is the qui tam whistleblower, who has been empowered by the False Claims Act's broad standing provisions and the substantial financial incentives built into the statute. Under 31 U.S.C. § 3730(b), any person—including a former employee, a competitor, a patient, or even a spouse—may file a civil action on behalf of the United States alleging that a provider has submitted false claims. The whistleblower, known as the "relator," is entitled to receive between 15% and 30% of the total recovery, which can amount to millions of dollars in a single case. The Department of Justice reported that it recovered over $2.68 billion in False Claims Act settlements and judgments in fiscal year 2023, with health care fraud accounting for more than $1.8 billion of that total, and whistleblowers received approximately $349 million in awards. These numbers create an irresistible incentive for insiders to document every perceived irregularity and file a sealed complaint with the federal court.

The qui tam process is uniquely dangerous because the complaint is filed under seal, meaning the provider does not even know it exists for at least 60 days, and often for many months or even years, while the government investigates the allegations. During this period, the whistleblower can continue to work inside the practice, gathering documents, recording conversations, and building the government's case without the provider's knowledge. I have represented a large multi-specialty group that discovered, only after the government unsealed the complaint, that their own compliance officer had been secretly copying thousands of patient records, billing documents, and internal emails for over 18 months before filing the qui tam action. The compliance officer had become disgruntled after being passed over for a promotion, and she used her access to the practice management system to download every claim submitted to Medicare for the prior three years, then hired a plaintiffs' firm that specialized in health care fraud litigation. The government ultimately intervened in the case and demanded $27 million in damages and penalties, based on the compliance officer's allegation that the group had been upcoding evaluation and management services for years.

The most common trigger for qui tam actions in the current environment is the alleged violation of the Stark Law or the Anti-Kickback Statute through improper financial relationships with referral sources. Whistleblowers are trained by plaintiffs' firms to look for specific red flags: below-market lease arrangements with referring physicians, medical directorships that require no actual work, "consulting agreements" that are really disguised referral fees, and free or discounted services provided to high-volume referral sources. The government's position, as articulated in the 2022 OIG Advisory Opinion No. 22-15, is that any financial relationship that does not satisfy every element of an applicable safe harbor or exception creates potential liability, regardless of whether the relationship actually influenced referrals or resulted in overutilization. I have seen cases where a whistleblower alleged that a hospital's below-market lease of office space to a cardiology group violated the Stark Law, even though the cardiology group had been in that space for 15 years and the lease rate was based on a 2008 appraisal that had never been updated. The hospital settled the case for $4.5 million, not because the government believed the lease was improper, but because the cost of litigating the complex valuation issues would have exceeded the settlement amount.

The expansion of whistleblower protections under the 2023 amendments to the False Claims Act has made it even more difficult for providers to defend against these cases. The amendments clarified that whistleblowers are protected from retaliation even if they report internally before filing a qui tam action, and they expanded the definition of "protected activity" to include any act taken in furtherance of a potential False Claims Act case. This means that a compliance officer who reports a potential violation to the practice's board of directors is now protected from termination or demotion, even if the report is ultimately determined to be unfounded. I have advised numerous health care organizations to implement robust internal reporting systems that allow employees to raise concerns without fear of retaliation, because the alternative is that those concerns will be taken directly to a plaintiffs' firm and filed under seal in federal court. The reality is that every health care provider in the United States is one disgruntled employee away from a multi-million dollar federal investigation, and the only effective defense is a proactive compliance program that identifies and corrects potential violations before a whistleblower has the opportunity to act.

Your Personal Assets Are on the Line: The Rise of Individual Criminal Liability

The most significant shift in federal health care enforcement over the past three years is the government's relentless focus on holding individual providers personally liable for corporate or practice-wide billing errors. The Yates Memorandum, issued by Deputy Attorney General Sally Yates in 2015, formally established the policy that corporations seeking cooperation credit must provide the government with all relevant facts about individual wrongdoers, but the current administration has gone far beyond that policy. The 2024 Justice Manual, Section 9-28.210, now directs prosecutors to "focus on individual accountability from the inception of the investigation" and to "consider whether charges against individuals are appropriate in every health care fraud case." This means that when the government investigates a practice for alleged overbilling, they are not just looking at the practice as an entity—they are looking at every physician, every nurse practitioner, every administrator, and every billing manager who had any involvement in the claims submission process.

The specific criminal statutes most frequently used against individual providers include health care fraud under 18 U.S.C. § 1347, which carries a maximum sentence of 10 years per count, and conspiracy to commit health care fraud under 18 U.S.C. § 1349, which carries the same penalty. What makes these statutes particularly dangerous is the broad definition of "knowingly" in the health care fraud context. The Eleventh Circuit, in United States v. Medina, 485 F.3d 1291 (11th Cir. 2007), held that a defendant acts "knowingly" if he or she acts with "conscious avoidance" of the truth, meaning that if you deliberately ignore red flags or fail to inquire about suspicious billing practices, you can be convicted even if you did not have actual knowledge of the fraud. I have seen this theory applied to a physician who signed off on a stack of encounter forms without reviewing them, trusting that his billing staff had coded them correctly—the government argued that the physician's failure to review the forms constituted conscious avoidance, and the jury convicted him on 23 counts of health care fraud.

The financial consequences of an individual conviction are devastating and often extend far beyond the criminal sentence. Under 18 U.S.C. § 982(a)(7), a defendant convicted of health care fraud must forfeit any property derived from the offense, which the government interprets broadly to include all Medicare and Medicaid payments received during the period of alleged fraud, not just the specific payments that were based on false claims. I have represented a radiologist who was convicted of billing for unnecessary MRI scans, and the government sought forfeiture of his entire practice, his personal residence, and his retirement accounts, arguing that all of these assets were "traceable to" the proceeds of the fraud. The radiologist ultimately lost his medical license, his practice, and his life savings, and he was sentenced to 63 months in federal prison. Even after serving his sentence, he will be excluded from participating in Medicare, Medicaid, and all other federal health care programs for a minimum of five years under 42 U.S.C. § 1320a-7(a), effectively ending his career in medicine.

The government's use of the "responsible corporate officer" doctrine, derived from United States v. Park, 421 U.S. 658 (1975), has further expanded individual liability for health care providers. Under this doctrine, a person who holds a position of responsibility in a corporation can be held criminally liable for violations of public welfare statutes, even if the person did not personally participate in the illegal conduct, if the person had the authority to prevent the violation and failed to do so. While the Park doctrine was originally applied to food and drug cases, federal prosecutors are increasingly invoking it in health care fraud cases, arguing that medical directors, practice owners, and department heads have a duty to ensure that their organizations comply with billing requirements. I have seen a case where the government charged the medical director of a chain of urgent care centers with health care fraud based solely on the fact that he was the supervising physician for a nurse practitioner who was overbilling for evaluation and management services. The medical director had never reviewed a single claim, had never discussed coding with the nurse practitioner, and had no knowledge of the overbilling, but the government argued that his failure to supervise constituted reckless disregard of the false claims being submitted under his name.

Frequently Asked Questions

What should I do if I receive a Civil Investigative Demand from the Department of Justice regarding my billing practices?

If you receive a Civil Investigative Demand, or CID, under 31 U.S.C. § 3733, you are facing a potentially serious federal investigation that could lead to civil or criminal charges. The CID is not a request; it is a legally enforceable demand for documents, data, and testimony, and failing to comply can result in contempt of court sanctions. Your first step should be to immediately engage an experienced federal health care defense attorney who