Publication
When the Algorithm Cuts Both Ways: False Claims Act Liability in the Age of AI-Driven Healthcare
By Scott Driggs and Carrie Schaffer
Artificial intelligence (AI) is rapidly becoming a significant factor in federal healthcare fraud and abuse enforcement. It is simultaneously becoming the government’s most powerful tool for detection of fraud and abuse, and a source of potential False Claims Act (FCA) exposure when AI-assisted processes contribute to inaccurate claims, unsupported diagnoses, or other compliance failures.
As one example, on June 23, 2026, the U.S. Department of Justice (DOJ) announced the 2026 National Health Care Fraud Takedown (Takedown), charging 455 defendants in schemes involving over $6.5 billion in false claims.1 The Takedown featured the first-ever prosecution arising from the DOJ’s Health Care Fraud Data Fusion Center (Data Fusion Center), resulting from a $67 million scheme to bill Illinois Medicaid for behavioral health services that were never provided. The case was opened within five (5) days of the data analysis, and the defendant was arrested within seven (7) months.
This alert examines both dimensions of this current AI landscape: the federal government’s leveraging of AI, and the defensive exposure it may create for healthcare organizations.
I. The Government’s AI Enforcement Arsenal
The Health Care Fraud Data Fusion Center
Launched as part of the Takedown, the Data Fusion Center combines experts from the DOJ Health Care Fraud Unit’s Data Analytics Team, the Department of Health and Human Services Office of Inspector General (HHS-OIG), the FBI, and other federal agencies. The Data Fusion Center deploys cloud computing, AI, and advanced analytics designed to identify fraudulent billing patterns in real time. Centers for Medicare & Medicaid Services (CMS) announced it will provide cloud computing space within its integrated data repository to support DOJ’s analytics, a direct integration of Takedown enforcement tools into the healthcare payment system itself.
From “Pay-and-Chase” to Pre-Payment Detection
CMS Administrator Dr. Mehmet Oz stated: “Prosecuting criminals who steal from American patients is necessary, but stopping them before a single dollar leaves the building is smarter. CMS is done playing catch-up.”2
The 2026 Takedown reflects this shift. As announced on June 23, 2026, CMS suspended 1,079 providers, revoked billing privileges for 1,403 providers, obtained more than $73 million in 48 Civil Monetary Payment settlements with more than 1,400 exclusions, and HHS-OIG is currently seeking more than $10 billion from payments CMS blocked before they were paid.3
Record FCA Recoveries and Institutional Investment
On January 16, 2026, DOJ announced that FCA settlements and judgments exceeded $6.8 billion in fiscal year 2025, the highest annual total in the FCA statute’s history, with over $5.7 billion from healthcare matters and a record 1,297 qui tam lawsuits filed.4
The practical implication: anomalous billing patterns that previously may have taken years to identify can now be detected far more quickly through advanced analytics and AI-enabled review tools. Although not every AI-generated coding error will result in FCA liability, as with traditional FCA cases, enforcement actions will likely continue to focus on material misrepresentations, knowingly submitted false claims, or systemic practices that affect payment decisions.
The DOJ-HHS False Claims Act Working Group, launched in July 2025, formalizes shared investigative strategies, streamlines referrals between agencies, aligns civil and criminal remedies, and channels whistleblower complaints toward priority enforcement theories.
II. AI as a Source of FCA Liability — Three Emerging Theories
The use of AI does not alter the FCA’s knowledge standard. However, healthcare organizations that deploy AI systems without adequate validation, monitoring, or oversight may face allegations that they acted with reckless disregard of the truth or falsity of claims submitted to federal healthcare programs. Conversely, documented governance processes, auditing, and clinician oversight may help demonstrate good-faith compliance efforts.
Consider three (3) theories of potential FCA liability arising from AI utilization.
Theory 1: EHR Manipulation and AI-Driven Upcoding
The DOJ-HHS FCA Working Group identified “manipulation of Electronic Health Records systems to drive inappropriate utilization of Medicare covered products and services” as one of its six priority enforcement areas, announced July 2, 2025.
HHS-OIG’s Medicare Advantage Industry Segment-Specific Compliance Program Guidance (MA ICPG), released February 3, 2026, the first MA-specific compliance guidance since 1999, specifically flagged “querying physicians via electronic medical record platforms (including prompts generated by artificial intelligence algorithms)” as “potentially abusive and fraudulent conduct.” The MA ICPG also identified deploying in-home health risk assessments primarily to capture diagnosis codes, and neglecting to delete unsupported diagnosis codes, as risk areas.
The OIG recommended pre- and post-submission audits, vendor oversight, and training on diagnostic prompts. Federal enforcers may argue that excessive reliance on AI-generated prompts can undermine independent physician judgment, leading to submission of unsupported diagnoses.
Theory 2: AI-Facilitated Enrollment and Identity Fraud
The Troy Health Non-Prosecution Agreement (NPA), dated August 14, 2025, was the first NPA issued by DOJ’s Health Care Fraud Unit under its updated Corporate Enforcement and Voluntary Self-Disclosure Policy.5 According to the NPA, Troy used an AI-based platform, Troy.ai, to scale fraudulent cold-calling of Medicare beneficiaries using pharmacy-sourced customer lists obtained without consent, with a Troy senior executive directing the scheme.
Separately, in the 2025 National Health Care Fraud Takedown, defendants allegedly used AI to create fake recordings of Medicare beneficiaries purportedly consenting to receive certain products, resulting in approximately $703 million in allegedly fraudulent claims submitted to Medicare and Medicare Advantage plans.6
Theory 3: The Regulatory Gap as FCA Opportunity
At present there is no comprehensive federal AI regulatory scheme. The National Institute of Standards and Technology (NIST) and other organizations have issued AI governance and risk management principles, but these are high-level and do not specify industry-specific compliance requirements.
This regulatory uncertainty creates opportunities for DOJ and qui tam relators to test existing FCA theories in AI-related contexts. FCA plaintiffs are likely to adapt existing enforcement frameworks, such as false payment data, failure to meet contracted specifications, and cybersecurity violations, to AI products and uses.
The DOJ’s Evaluation of Corporate Compliance Programs encourages companies to manage “emerging risks” including AI, creating an expectation that organizations assess and manage AI-related compliance risks, which may become relevant in subsequent enforcement evaluations.
III. The Payer Side — AI in Utilization Management
Insurers and Medicare Advantage Organizations (MAOs) using AI for utilization management and prior authorization decisions face their own regulatory and legal exposure, a mirror image of the provider-side risk.
States have enacted laws requiring human oversight for AI-driven adverse determinations. For example, California’s SB 1120 (2024) regulates AI in utilization review; Illinois’ HB 1806 (2025) prohibits AI from providing therapy services or generating treatment plans without licensed professional review and approval;7 and in 2026, additional states enacted transparency and oversight requirements.
On the federal side, multiple provisions of 42 CFR Part 422 constrain purely algorithmic decision-making. Most directly, 42 CFR § 422.566(d) provides that if an MA organization expects to issue a partially or fully adverse medical necessity decision, “the organization determination must be reviewed by a physician or other appropriate health care professional with expertise in the field of medicine or health care that is appropriate for the services at issue . . . before the MA organization issues the organization determination decision.” Separately, 42 CFR § 422.562(a)(4) requires each MA organization to employ a medical director “responsible for ensuring the clinical accuracy of all organization determinations and reconsiderations involving medical necessity.” And 42 CFR § 422.101(c)(1) requires medical necessity determinations to be based on “the enrollee’s medical history (for example, diagnoses, conditions, functional status), physician recommendations, and clinical notes.” These provisions collectively require that coverage denials be individualized, clinician-reviewed, and grounded in enrollee-specific clinical information, a standard that autonomous algorithmic systems cannot satisfy.
Where AI systems generate adverse determinations without this individualized physician review, MAOs face CMS enforcement, state regulatory liability, and, where algorithmic denials drive improper retention of capitated payments, reverse FCA exposure. While such theories remain largely untested in the AI utilization management context, plaintiffs may attempt to argue that improper denials resulted in the retention of funds that otherwise would have been used to provide covered services. Additionally, 42 CFR § 422.101(b)(6) permits internal coverage criteria only when criteria are “not fully established” in applicable statutes, regulations, National Coverage Determinations (NCDs), or Local Coverage Determinations (LCDs), and requires those criteria to be evidence-based and publicly accessible. AI systems applying opaque proprietary criteria to deny coverage may conflict with these requirements.
IV. Practical Steps for Healthcare Organizations to Consider
Healthcare organizations should consider preparing to defend their own AI use and deploy analytics internally to detect issues before the federal government does, including the following steps:
- Map your AI exposure. Inventory all AI tools touching clinical documentation, coding, billing, risk adjustment, and claims processing.
- Establish AI governance. Create an AI governance policy and committee with compliance, clinical, legal, and IT representation. Document algorithm provenance, validation, and ongoing monitoring.
- Implement human-in-the-loop safeguards. For MAOs, 42 CFR § 422.566(d) makes this a regulatory mandate: adverse medical necessity determinations must be reviewed by a qualified health care professional before issuance. For providers, the MA ICPG signals that perfunctory sign-off on AI-generated prompts will not satisfy regulators.
- Conduct internal analytics. Use the same data analytics tools DOJ deploys to audit the organization’s own billing patterns for outliers. Proactive self-auditing demonstrates good faith and may support voluntary self-disclosure.
- Update vendor contracts. Ensure AI vendor agreements address representations regarding model performance, audit rights, data provenance, compliance obligations, indemnification, cooperation during investigations, and retention of records needed to validate AI-generated outputs.
- Prepare for faster enforcement timelines. The Data Fusion Center moved from analysis to prosecution in days. Internal investigation protocols and response teams must be pre-established.
- Document human oversight. Maintain records demonstrating when clinicians reviewed, modified, or rejected AI-generated recommendations. Documentation may become critical in defending government investigations or relator allegations.
Conclusion
AI-powered enforcement and AI-derived liability are converging into a single compliance imperative. Existing federal and state healthcare regulations, particularly the physician review and individualized-determination requirements of 42 CFR Part 422, already constrain algorithmic decision-making in the Medicare Advantage context. But the absence of AI-specific federal legislation leaves substantial uncertainty about permissible AI use more broadly, creating space for enforcement agencies and relators to define those boundaries through litigation.
Healthcare organizations that treat AI governance as an afterthought face compounding risk from both directions. The window for proactive preparation is narrowing.
Footnotes
-
Press Release, U.S. Dep’t of Justice, National Health Care Fraud Takedown Results in 455 Defendants Charged in Connection with Over $6.5 Billion in Alleged Fraud (June 23, 2026), https://www.justice.gov/opa/pr/national-health-care-fraud-takedown-results-455-defendants-charged-connection-over-65.
-
Id.
-
Id.
-
Press Release, U.S. Dep’t of Justice, False Claims Act Settlements and Judgments Exceed $6.8B in Fiscal Year 2025 (Jan. 16, 2026), https://www.justice.gov/opa/pr/false-claims-act-settlements-and-judgments-exceed-68b-fiscal-year-2025.
-
U.S. Dep’t of Justice, Criminal Division, Non-Prosecution Agreement Letter to Troy Health Inc. (Aug. 14, 2025), https://www.justice.gov/criminal/media/1411396/dl?inline; see also Press Release, U.S. Dep’t of Justice, In Re: Troy Health, Inc. (Aug. 20, 2025), https://www.justice.gov/opa/pr/troy-health-inc-enters-non-prosecution-agreement-and-admits-fraudulently-enrolling-medicare.
-
Press Release, U.S. Dep’t of Justice, National Health Care Fraud Takedown Results in 324 Defendants Charged in Connection with Over $14.6 Billion in Alleged Fraud (June 30, 2025), https://www.justice.gov/opa/pr/national-health-care-fraud-takedown-results-324-defendants-charged-connection-over-146.
-
Wellness and Oversight for Psychological Resources Act, Ill. Pub. Act 104-0054 (HB 1806), effective Aug. 1, 2025, https://www.ilga.gov/Documents/Legislation/PublicActs/104/PDF/104-0054.pdf.
About Snell & Wilmer
Founded in 1938, Snell & Wilmer is a full-service business law firm with more than 500 attorneys practicing in 17 locations throughout the United States and in Mexico, including Phoenix and Tucson, Arizona; Los Angeles, Orange County, Palo Alto and San Diego, California; Denver, Colorado; Washington, D.C.; Boise, Idaho; Las Vegas and Reno-Tahoe, Nevada; Albuquerque, New Mexico; Portland, Oregon; Dallas, Texas; Salt Lake City, Utah; Seattle, Washington; and Los Cabos, Mexico. The firm represents clients ranging from large, publicly traded corporations to small businesses, individuals and entrepreneurs. For more information, visit swlaw.com.