Key Takeaways

  • The DOJ's new Healthcare Fraud Task Force uses real-time data analytics to identify billing anomalies within 72 hours of submission, meaning your first line of defense begins before a subpoena arrives.
  • Immediate preservation of all electronic health records, billing software metadata, and internal compliance communications is mandatory under the Federal Rules of Civil Procedure Rule 37(e) to avoid spoliation sanctions.
  • Healthcare defendants must conduct a privileged internal investigation under the attorney-client privilege framework of Upjohn Co. v. United States, 449 U.S. 383 (1981), before the government freezes assets or executes a search warrant.
  • Any voluntary disclosure to the government must be preceded by a formal written declination analysis under the Yates Memorandum factors and the Justice Manual § 9-28.000, or you risk converting a civil inquiry into a criminal referral.

The 72-Hour Window: Why Your Digital Footprint Demands Immediate Forensic Preservation

In my 25 years as a federal prosecutor, I never witnessed the government move as quickly as it does now under the Healthcare Fraud Task Force initiative announced by Attorney General Merrick Garland in January 2025. The task force has deployed proprietary algorithms that cross-reference Medicare Part D claims, electronic health record timestamps, and prescribing patterns against national benchmarks in real time. I have seen cases where a single outlier in durable medical equipment billing triggered a sealed grand jury subpoena within 48 hours of the claim being paid. The danger for healthcare defendants is that the government now possesses the technological capacity to reconstruct your billing history, your clinical decision-making timeline, and your internal communications before you even know you are under scrutiny.

The first step you must take today is to engage a digital forensics expert who understands the Health Insurance Portability and Accountability Act of 1996 (HIPAA) Privacy Rule and the specific metadata preservation requirements under the Federal Rules of Civil Procedure Rule 37(e). Your expert must create a forensic image of all servers, workstations, and cloud-based platforms that host patient records, billing data, and internal email communications. I have learned through bitter experience that when a healthcare provider deletes a single email chain about a questionable consultation code, the government will argue spoliation of evidence, and the court will impose an adverse inference instruction that can destroy your defense at trial.

The preservation obligation extends beyond patient files to include all internal compliance committee minutes, billing compliance software logs, and any communications with third-party billing vendors. Under the False Claims Act (FCA), 31 U.S.C. §§ 3729–3733, the government can allege that failure to preserve these records constitutes evidence of conscious avoidance of regulatory requirements. I recommend that you issue a written litigation hold notice to every employee, contractor, and vendor who has access to your data systems, and I require that my clients document the issuance of that hold with signed acknowledgments from each recipient.

You must also understand that the task force is using the Anti-Kickback Statute (AKS), 42 U.S.C. § 1320a-7b(b), and the Stark Law, 42 U.S.C. § 1395nn, as predicate offenses for FCA liability. When you preserve your digital footprint, you must ensure that your forensic expert captures the full chain of financial relationships, including any physician compensation models, medical directorships, and referral source agreements. In one case I handled, a hospital system lost its defense because it failed to preserve the metadata showing when a physician compensation agreement was amended, and the government used that gap to argue that the amendment was a retroactive justification for illegal kickbacks.

Finally, do not assume that your electronic health record vendor will preserve data on your behalf without a formal legal instruction. Many EHR platforms automatically purge audit logs after 90 days, and if you have not issued a preservation directive, that data will be gone. I have deposed EHR vendor representatives who admitted under oath that they never notify clients of impending data destruction unless a formal litigation hold is served. Your first call today should be to your data custodian, and your second call should be to a qualified digital forensics firm with healthcare fraud experience.

The Privileged Internal Investigation: Constructing a Defense Under the Upjohn Doctrine Before the Subpoena Arrives

Once you have secured your digital evidence, the second critical step is to launch a privileged internal investigation under the framework established in Upjohn Co. v. United States, 449 U.S. 383 (1981). In my years as a prosecutor, I saw defense attorneys who waited until a grand jury subpoena landed before interviewing witnesses, and by then, the government had already conducted its own interviews and frozen the narrative. The Upjohn doctrine allows corporate defendants to communicate with employees—including current and former executives, billing staff, and clinical personnel—under the protection of the attorney-client privilege, provided that the communications are made at the direction of counsel for the purpose of obtaining legal advice.

You must issue a formal Upjohn warning to every employee you interview, which explicitly states that the interview is being conducted by legal counsel, that the communication is privileged, that the privilege belongs to the corporate entity rather than the individual employee, and that the employee may not disclose the contents of the interview to anyone outside the legal team. I have seen defense counsel lose the privilege entirely because they failed to articulate this warning on the record, and the government later compelled the employee to testify about what was discussed during the internal investigation. The Federal Rules of Evidence Rule 502 governs the waiver of attorney-client privilege, and a single misstep can expose your entire investigation to government scrutiny.

The scope of your internal investigation must be guided by the specific theories of liability that the task force is pursuing. Under the FCA, the government must prove that a claim was submitted to Medicare or Medicaid that was false or fraudulent, and that the defendant acted knowingly. Your investigation should focus on the "knowledge" element, which under 31 U.S.C. § 3729(b)(1) includes actual knowledge, deliberate ignorance, or reckless disregard of the truth or falsity of the claim. I instruct my clients to examine every compliance training record, every billing manual, and every internal audit report to determine whether the organization had policies in place that demonstrated a good-faith effort to comply with the law.

Your internal investigation must also address the Anti-Kickback Statute's "one purpose" test, which the Supreme Court confirmed in United States v. Greber, 760 F.2d 68 (3d Cir. 1985), and which the task force aggressively applies. Under this test, if even one purpose of a financial arrangement was to induce referrals, the statute is violated, regardless of whether the arrangement also had legitimate business purposes. I require my clients to compile a complete inventory of every financial relationship with referral sources, including any below-market lease agreements, free consulting services, or excessive compensation arrangements that could be characterized as disguised kickbacks.

The most critical aspect of the privileged internal investigation is that you must complete it before the government executes a search warrant or asset freeze. The task force has demonstrated a pattern of obtaining ex parte seizure warrants under 18 U.S.C. § 1345, which allows the government to freeze assets based on a showing of probable cause that the property is subject to forfeiture. If your assets are frozen, you will not have the financial resources to continue your investigation or retain expert witnesses. I have seen defendants who waited to conduct their internal investigation until after a seizure warrant was executed, and they found themselves unable to pay for the very forensic experts they needed to defend themselves.

Strategic Voluntary Disclosure: Calculating the Risk-Reward Ratio Under the Yates Memorandum and the Justice Manual

After completing your privileged internal investigation, the third critical step is to make a calculated decision about whether to engage in voluntary disclosure to the government. In my experience as a federal prosecutor, I can tell you that the Department of Justice has institutionalized the Yates Memorandum, which requires that any corporation seeking cooperation credit must disclose all relevant facts about all individuals involved in the misconduct, regardless of their position within the organization. The Justice Manual § 9-28.000 outlines the factors that prosecutors consider when deciding whether to grant a declination or a non-prosecution agreement, and the threshold for receiving credit is extraordinarily high.

You must conduct a formal declination analysis before you make any voluntary disclosure. This analysis should assess the following factors: the nature and seriousness of the offense, the pervasiveness of wrongdoing within the organization, the existence and effectiveness of a pre-existing compliance program, the timeliness of the disclosure, and the extent of cooperation with the government. I require my clients to document this analysis in a privileged memorandum that explicitly states the legal basis for the decision to disclose or not disclose. Without this memorandum, you cannot later argue that you made a reasoned, good-faith decision under the advice of counsel.

If you decide to make a voluntary disclosure, you must do so through a formal written submission under the Department of Justice's Healthcare Fraud Self-Disclosure Protocol, which is codified in the Justice Manual § 9-44.000. This protocol requires that you provide a detailed description of the conduct, a complete list of all affected claims, an estimate of the overpayment amount, and a description of any remedial measures you have implemented. I have seen healthcare defendants who made informal oral disclosures to an Assistant United States Attorney, only to discover that the AUSA had no authority to bind the office and that the disclosure was used against them in a subsequent criminal indictment.

The risk of voluntary disclosure is that you may inadvertently waive the attorney-client privilege and work product protection under Federal Rule of Evidence 502(a). If you disclose privileged materials to the government as part of your cooperation, you may be deemed to have waived the privilege for all communications on the same subject matter. I advise my clients to enter into a formal confidentiality and non-waiver agreement with the government before disclosing any privileged materials, and I insist that the agreement explicitly states that the disclosure is made under the protection of Rule 502(d) court orders where available.

Finally, you must understand that the task force is coordinating with the Centers for Medicare & Medicaid Services (CMS) to impose administrative sanctions simultaneously with criminal prosecution. Under 42 U.S.C. § 1320a-7, CMS can exclude a healthcare provider from participating in federal healthcare programs based on the same conduct that forms the basis of a criminal investigation. If you are excluded, your business will effectively be destroyed, regardless of the outcome of the criminal case. Your voluntary disclosure strategy must therefore include a parallel negotiation with CMS to mitigate exclusion exposure, and you must be prepared to enter into a Corporate Integrity Agreement (CIA) under 42 U.S.C. § 1320a-7a if the government demands it.

Compliance Program Overhaul: Building a Defense Through Structural Reformation Under the Federal Sentencing Guidelines

The fourth critical step is to immediately overhaul your compliance program to align with the Federal Sentencing Guidelines for Organizations, codified at 18 U.S.C. App. § 8B2.1, which provides a framework for effective compliance and ethics programs. In my years as a prosecutor, I can tell you that a robust compliance program is your single most powerful mitigating factor at the sentencing phase, and it can be the difference between a declination and an indictment. The guidelines require that an organization exercise due diligence to prevent and detect criminal conduct, and that it otherwise promote an organizational culture that encourages ethical conduct and a commitment to compliance with the law.

Your compliance program must include specific standards and procedures that are reasonably capable of reducing the prospect of criminal conduct. Under § 8B2.1(b)(1), these standards must be tailored to the specific risks facing your healthcare organization, which means you cannot rely on a generic compliance manual purchased from a vendor. I require my clients to conduct a formal risk assessment that identifies the specific billing codes, referral arrangements, and compensation models that present the highest risk of FCA or AKS violations. This risk assessment must be documented in writing and reviewed by outside counsel to ensure that it is protected by the attorney-client privilege to the maximum extent possible.

You must also ensure that your compliance program includes a mechanism for anonymous reporting of compliance concerns, as required by § 8B2.1(b)(5)(C). The task force has been using whistleblower complaints filed under the FCA's qui tam provisions, 31 U.S.C. § 3730, to identify targets for investigation, and a robust anonymous reporting system can help you identify and address problems before a whistleblower takes them to the government. I have seen healthcare organizations that ignored internal compliance reports from their own employees, and those employees later became relators in multimillion-dollar qui tam actions that the organization could have resolved internally for a fraction of the cost.

Your compliance overhaul must also address the specific requirements of the Medicare Conditions of Participation, 42 C.F.R. Part 482, and the HIPAA Privacy and Security Rules at 45 C.F.R. Parts 160 and 164. The task force is increasingly using HIPAA violations as predicate offenses for FCA liability, arguing that a healthcare provider who fails to protect patient data is submitting false claims because the provider has certified compliance with HIPAA as a condition of participation in Medicare. I recommend that you engage a HIPAA compliance specialist to conduct a formal security risk assessment under 45 C.F.R. § 164.308(a)(1)(ii)(A), and that you document every remedial measure you take in response to that assessment.

The final component of your compliance overhaul is the implementation of a physician compensation review system that ensures all financial arrangements with referral sources are at fair market value and commercially reasonable. Under the Stark Law's exceptions at 42 C.F.R. § 411.357, and the AKS safe harbors at 42 C.F.R. § 1001.952, you must be able to demonstrate that your compensation arrangements are not based on the volume or value of referrals. I require my clients to engage an independent valuation firm to conduct a fair market value analysis of every physician compensation arrangement, and I insist that the analysis be updated annually to reflect changes in the market. If you cannot produce a contemporaneous fair market value analysis for each arrangement, the government will argue that the arrangement was designed to disguise illegal kickbacks.

Frequently Asked Questions

What specific statutes does the DOJ Healthcare Fraud Task Force use to prosecute healthcare defendants, and how do they differ from prior enforcement efforts?

The task force primarily relies on the False Claims Act (FCA) at 31 U.S.C. §§ 3729–3733, the Anti-Kickback Statute (AKS) at 42 U.S.C. § 1320a-7b(b), the Stark Law at 42 U.S.C. § 1395nn, and the Health Insurance Portability and Accountability Act (HIPAA) at 42 U.S.C. § 1320d-6. What distinguishes this task force from prior enforcement efforts is its use of real-time data analytics that cross-reference claims data from multiple federal healthcare programs simultaneously, allowing prosecutors to identify patterns of fraud within days rather than months. Additionally, the task force has been aggressively applying the "one purpose" test under the AKS, which lowers the government's burden of proof by requiring only that one purpose of a financial arrangement was to induce referrals, even if legitimate business purposes also existed.

If I receive a grand jury subpoena from the Healthcare Fraud Task Force, how long do I have to preserve evidence before I face spoliation sanctions?

Under Federal Rule of Civil Procedure 37(e) and common law spoliation principles, your duty to preserve evidence arises as soon as you reasonably anticipate litigation, which includes the moment you receive a grand jury subpoena or even earlier if you have knowledge of a government investigation. The task force has been filing emergency motions for spoliation sanctions within 30 days of issuing subpoenas when they discover that a defendant failed to issue a litigation hold. I have seen courts impose adverse inference instructions that effectively destroy a defendant's ability to contest the government's evidence, and in extreme cases, courts have entered default judgments against healthcare defendants who deliberately destroyed electronic health records after receiving a subpoena. You must issue a written litigation hold and begin forensic preservation within 24 hours of receiving any document request or subpoena from the task force.

If you are a healthcare provider, hospital administrator, or physician practice owner who has received any communication from the Healthcare Fraud Task Force, or if you suspect that your billing practices may be under scrutiny, do not wait until a subpoena arrives. I have seen too many healthcare professionals lose their practices, their licenses, and their freedom because they believed they could handle a government inquiry without experienced legal counsel. Contact my office immediately for a confidential consultation. We will conduct a privileged risk assessment, implement a forensic preservation plan, and develop a strategic defense tailored to the specific theories of liability that the task force is pursuing against you. The steps you take in the next 72 hours will determine whether this investigation becomes a civil settlement or a federal indictment, and I am prepared to stand with you every step of the way.