DOJ Fraud Division Prioritizes Health Care
October 09, 2026DOJ Health Care Fraud Priorities for FDA-Regulated Companies
The U.S. Department of Justice (DOJ) has made health care one of five enforcement priorities for its new National Fraud Enforcement Division (Fraud Division). An August 13, 2026, memorandum also identified corporate misconduct as a separate priority and promised more resources, data analytics, and technology for health care fraud enforcement.
Medical product and life sciences companies should pay particular attention. DOJ's priorities extend beyond billing fraud to kickbacks, deception of regulators about health care products or services, and deceptive marketing of unsafe products or services.
What Changed at DOJ
DOJ established the Fraud Division in April 2026 and placed the Criminal Division's Health Care Fraud Unit, Tax Section, and Market, Government, and Consumer Fraud Unit under its operational control. The August memorandum said the reorganization would increase the Division's headcount to approximately 500 attorneys and staff by August 24, with further growth planned over the next two years.
An August 18 final rule, effective August 24, assigned the Division authority over criminal proceedings involving health plan fraud, health care fraud, and controlled-substance distribution and diversion. The Division is primarily a criminal component, but the rule also authorizes specified related actions for injunctions, restitution, forfeiture, damages, and penalties. DOJ's earlier creation memorandum required every U.S. Attorney's Office to designate an experienced prosecutor for the Division's mission and directed the Civil Division to appoint a liaison for civil-criminal coordination.
Who the New Health Care Fraud Priorities Affect
The priorities expressly identify telemedicine, Medicare and Medicaid fraud, controlled substances, home health and hospice, and companies or individuals that deceptively market unsafe products and services. DOJ also criticized kickbacks and companies that "cut corners to deceive regulators" about health care products or services.
These priorities can affect pharmaceutical, biotechnology, medical device, diagnostic, and digital health companies, along with providers, pharmacies, suppliers, distributors, management organizations, and billing or reimbursement vendors. The memorandum signals that regulator-facing conduct may become part of a fraud investigation when DOJ perceives deception about a health care product or service.
Not every regulatory violation is fraud, and sub-regulatory guidance does not itself create binding legal obligations. DOJ's September 2026 Justice Manual revisions state that enforcement must rest on applicable legal requirements, although guidance may serve as evidence of notice, knowledge, intent, or professional standards. Risk rises when evidence suggests intentional false or misleading statements tied to product safety, reimbursement, government purchasing, or federal program claims. Inconsistencies across FDA submissions, commercial materials, quality records, reimbursement communications, and claims data may therefore attract scrutiny from more than one agency.
How DOJ Will Identify Health Care Fraud
DOJ has paired the new Division with a National Fraud Detection Center, launched August 24 as a prosecutor-led, multi-agency team whose members include the FBI, IRS Criminal Investigation, FinCEN, HHS-OIG, and other government partners. DOJ says the Center will improve cross-program visibility and generate criminal leads.
The 2026 National Health Care Fraud Takedown illustrates the approach. DOJ charged 455 defendants in alleged schemes involving more than $6.5 billion in false claims and emphasized data analytics, cross-agency coordination, and parallel administrative actions. One case charged a company sales executive in an alleged kickback and health care fraud scheme involving wound allografts. Gardner Law previously discussed the Takedown's data-driven enforcement implications.
“DOJ is building the capacity to identify connections across regulatory, commercial, and reimbursement activities that companies may evaluate separately. Companies should take a similarly coordinated approach to identifying and addressing potential compliance risks before they become enforcement concerns.”
Amanda Johnston, Partner
What Health Care Companies Should Do Now
Companies should consider the following steps in light of DOJ's stated priorities and expanded resources:
- Conduct a targeted risk assessment, under privilege when appropriate, covering health care professional (HCP) payments, claims and reimbursement practices, promotional claims, and representations made to regulators or government payers.
- Connect regulatory, quality, reimbursement, commercial, and compliance escalation pathways so that a safety, quality, or promotional concern is evaluated for related payment and fraud-and-abuse implications.
- Use internal data to identify unusual billing, utilization, HCP payment, discount, rebate, complaint, or adverse-event patterns that may also appear anomalous in government datasets.
- Review oversight of distributors, consultants, telehealth partners, reimbursement vendors, and other third parties whose conduct may create liability or generate problematic data in the company's name.
- Establish a rapid process for investigating internal reports and evaluating whether voluntary disclosure may be appropriate in time to preserve available disclosure options.
DOJ's Corporate Enforcement and Voluntary Self-Disclosure Policy sets out a declination path for companies that voluntarily disclose to an appropriate DOJ criminal component, fully cooperate, timely and appropriately remediate, and ordinarily lack specified aggravating circumstances. DOJ may grant a declination even when aggravating circumstances exist. The policy creates no general duty to disclose; the decision requires fact-specific analysis of separate reporting obligations. If a whistleblower reports the same conduct internally and to DOJ, the company may remain eligible even if the whistleblower contacts DOJ first, provided the company self-reports as soon as reasonably practicable and within 120 days after receiving the internal report and satisfies the policy's other conditions.
How Gardner Law Can Help
Gardner Law advises medtech, biotech, pharmaceutical, and other FDA-regulated companies on the intersection of FDA requirements and health care fraud-and-abuse laws. We conduct privileged risk assessments and internal investigations, review HCP and reimbursement arrangements, analyze Anti-Kickback Statute and False Claims Act risk, and help companies prepare for or respond to FDA, CMS, OIG, and DOJ scrutiny.
Companies evaluating how the new priorities affect existing practices or a specific internal concern may contact Amanda Johnston or Gardner Law's Compliance team.