The Department of Justice recovered 6.8 billion dollars under the False Claims Act in fiscal year 2025, the highest single year total in the statute’s history. Healthcare accounted for 5.7 billion of that figure, more than 80 percent of all recoveries. DOJ named managed care, prescription drugs, and medically unnecessary care as its primary enforcement targets for the year.
Every healthcare executive, physician owner, and general counsel should read those numbers as an operating condition, not a headline. The False Claims Act is no longer a risk confined to large hospital systems and pharmaceutical manufacturers. It reaches physician practices, ambulatory surgery centers, home health agencies, laboratories, telehealth platforms, and biotech companies billing federal payers at any point in the chain. This article covers how the statute works, why the qui tam mechanism makes it different from every other compliance exposure a healthcare business carries, and what an effective defense actually requires.
The False Claims Act, codified at 31 U.S.C. sections 3729 through 3733, imposes liability on any person or entity that knowingly submits a false or fraudulent claim for payment to the federal government. In healthcare, that means any claim submitted to Medicare, Medicaid, TRICARE, or another federal health program.
Three features of the statute make it unusually severe compared to other regulatory exposure.
First, damages are trebled. A defendant found liable pays three times the government’s actual damages, not the damages themselves.
Second, penalties attach per claim, not per case. Following the 2025 inflation adjustment, the civil penalty ranges from 14,308 to 28,619 dollars for each false claim, in addition to treble damages. A practice that submitted a flawed billing code across a thousand claims is not looking at one penalty. It is looking at a thousand.
Third, the knowledge standard is broader than most executives assume. The Act defines knowing to include actual knowledge, deliberate ignorance of the truth or falsity of information, and reckless disregard of the truth or falsity of information. No specific intent to defraud is required. A certification made carelessly, without adequate verification, can satisfy the standard as easily as one made deliberately.
The feature that distinguishes the False Claims Act from nearly every other compliance regime is qui tam. The statute allows a private individual, called a relator, to file suit on behalf of the United States government against an entity the relator believes has defrauded federal health programs. The relator does not need to be a lawyer, a regulator, or even a current employee. Billers, coders, nurses, physicians, competitors, contractors, and former employees have all served as relators.
The mechanism works against the defendant in three specific ways.
The complaint is filed under seal. The target of the lawsuit typically has no knowledge that a case exists. The government investigates quietly, often for months or years, gathering records, interviewing witnesses, and building its intervention decision, while the business under investigation continues operating as though nothing has changed.
The relator has a direct financial incentive to file. Under 31 U.S.C. section 3730(d), a successful relator recovers between 15 and 25 percent of the government’s recovery if the government intervenes in the case, and between 25 and 30 percent if the relator proceeds alone after the government declines. Plaintiffs’ firms that specialize in qui tam litigation actively recruit relators from within healthcare organizations, and a growing number of cases originate from disgruntled former employees or business partners rather than from patients harmed by the conduct at issue.
Fiscal year 2025 set a record on this front as well. Relators filed 1,297 new qui tam suits, up roughly a third from 2024’s prior record of 980. Qui tam cases produced 5.3 billion of the government’s total 6.8 billion in recoveries, confirming that whistleblower litigation, not government-initiated audits, is now the primary engine of False Claims Act enforcement in healthcare.
The practical implication is that a healthcare business cannot manage this risk the way it manages an audit or a survey. There is no notice period. There is no opportunity to cure before the government becomes aware. The only leverage available is the strength of the compliance infrastructure that existed before the complaint was filed.
Enforcement data and DOJ’s own stated priorities point to a consistent set of triggers.
Medically unnecessary services rank first. Claims submitted for procedures, tests, or levels of care that documentation cannot support are among the most common basis for both government-initiated and qui tam cases, and DOJ specifically flagged this category as a 2025 priority.
Upcoding and unbundling follow closely. Billing a higher-acuity code than the service supports, or billing components of a bundled service separately to increase reimbursement, are pattern violations that data analytics at CMS and DOJ are increasingly built to detect.
Kickback-driven referrals create a direct path to False Claims Act liability through the Anti-Kickback Statute and the Stark Law. A claim submitted for a service that resulted from a prohibited referral or improper remuneration is a false claim as a matter of law, independent of whether the underlying service was medically appropriate.
False certifications carry outsized risk because they are often embedded in routine paperwork. Cost reports, quality measure attestations, compliance certifications tied to grant funding, and enrollment forms all contain representations that, if false, can support liability even when no single claim was fraudulently coded.
Retaliation against an internal complainant compounds the underlying exposure. An employee who raises a billing concern internally and is subsequently terminated, demoted, or marginalized has an independent retaliation claim under 31 U.S.C. section 3730(h), and that employee is now positioned, and often motivated, to become a relator.
The Department of Health and Human Services Office of Inspector General published updated General Compliance Program Guidance in November 2023, consolidating decades of prior guidance into a single framework built around seven elements: written policies and procedures, compliance leadership and oversight, effective training and education, open lines of communication, internal auditing and monitoring, consistent enforcement of standards, and prompt response with corrective action when problems are identified.
A compliance program that exists as a document but not as an operating practice does not satisfy this framework, and it will not reduce exposure when a qui tam complaint surfaces. Five practices separate programs that hold up under scrutiny from programs that do not.
An internal reporting channel that employees actually use, monitored by someone with the authority to act on what comes in, matters more than the existence of a hotline number on a poster. DOJ and relators’ counsel both look at whether an organization had a working channel and whether concerns raised through it were addressed.
Routine coding and billing audits, conducted on a rolling basis rather than as an annual compliance exercise, catch pattern errors before they accumulate into a large claims universe. The per-claim penalty structure means that early detection of a systemic coding error is worth far more than the cost of the audit that finds it.
Contemporaneous documentation of medical necessity, created at the time care is delivered rather than reconstructed after a demand letter arrives, is often the single factual issue that determines whether a case settles for a defensible amount or becomes a bet-the-company exposure.
An anti-retaliation practice that is enforced consistently, and that survives turnover in the compliance function, closes off the pathway that turns an internal complaint into external litigation.
Counsel engaged at the point an internal complaint is raised, not at the point a civil investigative demand or subpoena arrives, allows an organization to assess and correct exposure while it still controls the narrative and the remedy.
An organization that receives a civil investigative demand, subpoena, or search warrant related to potential False Claims Act exposure is already past the point where internal remediation alone resolves the matter. Engage outside counsel with False Claims Act experience immediately. Issue a litigation hold covering all potentially relevant records, including billing systems, email, and communications with the individual whose complaint may have triggered the inquiry. Do not contact the suspected relator, and do not take any adverse action against any current employee who may be a source, given the independent retaliation exposure described above. Conduct a privileged internal assessment of the underlying conduct before responding substantively to the government, so that the organization understands its own exposure before characterizing it to investigators.
The False Claims Act does not punish an organization for making a mistake. It punishes an organization for what it did, or failed to do, after the mistake was identifiable. Fiscal year 2025 confirmed that the government’s enforcement apparatus, and the plaintiffs’ bar that feeds it, are better resourced and more active against healthcare entities than at any point in the statute’s history. The organizations that manage this risk successfully are not the ones with the thickest policy manual. They are the ones whose reporting channels, audits, documentation practices, and legal engagement function as daily operating habits rather than annual compliance exercises.
Sources: U.S. Department of Justice, False Claims Act Settlements and Judgments Exceed 6.8 Billion Dollars in Fiscal Year 2025 (justice.gov); Sidley Austin False Claims Act Blog, Department of Justice Announces 2025 Inflationary Adjustments to FCA Penalties; HHS Office of Inspector General, General Compliance Program Guidance (November 2023).
No posts

Comments
Nothing yet. Say the first thing.
Sign in to join the conversation.