The DOJ just let us know the factors used in their decision to prosecute your business for your employee’s crime. And health care fraud is a specific prosecution priority.
On October 1, the Department of Justice revealed those factors. A memo entitled “Corporate Enforcement in the Fight Against Fraud” tells federal prosecutors within its Fraud Division how to decide whether to charge a company, not only the involved employees, with fraud.
Two Initial Things You Need to Know
One: the memo names four enforcement priorities, and health care schemes are listed first.
Two: it lists ten factors on which prosecutors “must place great weight” when deciding whether to bring charges against a company and what kind of deal to offer it. Your medical group is a company. An ASC is a company. So is your imaging center. And so is any other sort of business entity.
Here are the factors, in plain English: management knew about or was involved in the scheme; someone tried to hide it from the government or auditors; it lasted three years or more; it threatened Americans’ safety or security; it caused substantial financial hardship to a taxpayer-funded program; it affected multiple taxpayer-funded programs; it touched three or more federal districts; it harmed 25 or more victims or caused $25 million or more in loss; it sent American dollars to foreign adversaries; or it involved immigration offenses. Note that the memo states that those factors are non-exhaustive.
Meet Apple Pie Anesthesia
Apple Pie Anesthesia is a fictitious 60-clinician anesthesia group covering three hospitals and nine ASCs spread from the suburbs north of Dallas to Fort Worth to Austin.
Back in 2022, the group’s office manager sent the board an email. She reported that a meaningful number of cases were being improperly billed. Perhaps it was billing cases as “medically directed” even though the anesthesia record didn’t document medical direction. Whatever it was, the board discussed the email, agreed it was “something to look at,” and tabled it. After all, they had busy schedules. You know how it goes.
But now it’s late 2026. Let’s score those facts against the memo’s factors.
Did management know? Well, the board got the email from the office manager. In many medical groups, the board is management. So that’s one point in favor of prosecution.
Did the scheme last three years or more? If it continued from 2022, or earlier, to now, the score is two to nothing.
Were multiple taxpayer-funded programs involved? Nearly every medical group of size bills more than one federally funded program. We’re up to three points against the group.
Three or more federal districts? Texas has four federal districts, and Apple Pie’s footprint reaches three of them. By virtue of being a successful regional group, Apple Pie’s racked up another point in favor of prosecution.
25 or more victims? That depends on how a prosecutor chooses to count, but I wouldn’t want to be the one arguing about it, so consider that we’ve checked off five of the ten factors. And note that the memo presents the factors as independent, non-exhaustive, and not necessarily determinative, but, rather, that great weight must be placed on each.
That said, within the realm of what’s controllable, what your business’ management does when it knows, or should have known, about a problem, how long the problem is allowed to run, and how the business responds are crucial.
The memo also explains how investigations might start. The directive states that the Division is using data analytics through its National Fraud Detection Center to generate leads “at a rapid pace,” and it orders Fraud Division leadership to build programs that reward whistleblowers, including people who participated in the misconduct.
To be fair, the memo also promises credit for companies that disclose, cooperate, and remediate, and it says prosecutors will “guard against overbroad corporate enforcement.” And technically, it governs cases supervised by the Fraud Division, not those handled exclusively by a local U.S. Attorney’s Office. But I wouldn’t plan your compliance efforts around which DOJ office happens to open the file.
Now let’s shift the hypothetical game slightly and turn it inward onto your own group of business.
Optimally through counsel, take a red team approach and do more than just conduct a compliance review; run through the factors listed in the memo. Pay particular attention to which elements are controllable by your entity’s management.
Play prosecutor against yourself once a year. It’s the same exercise the government will run, just without a subpoena.
As you do, remember that many physician-owned entities have no layer of executives to absorb the blame. For these groups, the board is management. Every compliance email, every set of minutes, and every hallway “we should look at that”, is evidence of what management knew and when it knew it.
Finally, if you do find something, sit down with counsel early and decide whether to self-disclose. The DOJ rewards companies that come forward, and that credit evaporates once the government finds you first.
And the person who raised the issue? Treat him or her as an asset, not an annoyance. They’re exactly whom the government wants to hear from. Respond to them, document your response, and fix the problem. Don’t create a whistleblower.
If you’d like help running your group through any part of this process, let me know. And, if you’d like a copy of the DOJ’s memo, email me.
Related posts


