Back to BlogIndustry Insights

What are current trends for Fraud, Waste and Abuse violations and fines in healthcare?

July 31, 2026
Darren Speed, MS, CHC
What are current trends for Fraud, Waste and Abuse violations and fines in healthcare?

Current enforcement trends show that healthcare Fraud, Waste, and Abuse (FWA) risk is concentrating in a few predictable areas: false claims tied to medical necessity and coding, financial relationships that implicate the Stark Law and Anti-Kickback Statute, and privacy and security failures that trigger HIPAA enforcement. Recent actions from the U.S. Department of Justice (DOJ), Office of Inspector General (OIG), and HHS Office for Civil Rights (OCR) show that regulators continue to focus on arrangements that distort clinical decision-making, billing that cannot be supported by documentation, and cybersecurity failures that expose protected health information.

What are the main healthcare FWA enforcement trends right now?

Recent public enforcement activity points to several clear patterns. First, the False Claims Act (31 U.S.C. 3729-3733) remains the government’s primary civil enforcement tool for healthcare fraud. DOJ continues to report that healthcare drives a large share of FCA recoveries, especially cases involving medically unnecessary services, upcoding, improper Medicare Advantage risk adjustment, laboratory testing, durable medical equipment, and controlled substance prescribing.

Second, financial relationship enforcement remains active. The Physician Self-Referral Law (Stark Law), 42 U.S.C. 1395nn, and the Anti-Kickback Statute (AKS), 42 U.S.C. 1320a-7b(b), continue to appear in settlements involving physician compensation, referral arrangements, management services, marketing relationships, and vendor remuneration. Because AKS violations can render claims false, many of these matters are resolved under the FCA as well.

Third, OCR’s HIPAA enforcement has increasingly emphasized risk analysis, risk management, ransomware preparedness, right-of-access, and basic security rule compliance. In recent years OCR has repeatedly highlighted failures such as missing enterprise-wide risk analyses, insufficient audit controls, weak access management, and failure to respond appropriately to known vulnerabilities.

How is the False Claims Act shaping current healthcare fraud enforcement?

The FCA remains the clearest indicator of where federal healthcare enforcement is heading. DOJ’s annual FCA summaries consistently show that healthcare matters account for a significant portion of total recoveries, and whistleblower, or qui tam, suits remain a major driver. That trend matters operationally because many investigations begin with an employee, contractor, or competitor who alleges that internal controls did not match actual practice.

What types of FCA allegations are trending?

  • Medical necessity and documentation failures: services billed without support in the record, especially in home health, hospice, therapy, and certain diagnostic testing.
  • Medicare Advantage and risk adjustment: allegations that diagnosis coding inflated risk scores without adequate clinical support.
  • Laboratory and testing arrangements: billing for unnecessary tests or using improper referral incentives.
  • Pharmacy and controlled substances: claims linked to unlawful prescribing, diversion concerns, or defective controls.
  • Billing and coding manipulation: upcoding, modifier misuse, duplicate billing, and claims submitted despite known overpayments.

OIG’s Work Plan is also useful here because it signals what federal auditors and investigators view as recurring vulnerabilities. Topics regularly appearing in the Work Plan include Medicare payments for high-risk services, telehealth program integrity, inpatient versus outpatient billing, and oversight of managed care payments. While the Work Plan does not create legal obligations by itself, it is a practical roadmap for compliance risk assessment.

What are current Stark Law and Anti-Kickback trends?

Stark and AKS exposure continues to center on whether financial relationships influence referrals or purchasing decisions. These laws differ in structure, but they often intersect in enforcement.

The Stark Law is generally a strict liability statute that prohibits a physician from referring designated health services payable by Medicare to an entity with which the physician or an immediate family member has a financial relationship, unless an exception applies. The AKS is intent-based and prohibits knowingly and willfully offering, paying, soliciting, or receiving remuneration to induce or reward referrals for items or services reimbursable by a federal healthcare program.

Where are regulators focusing?

  • Physician compensation models: productivity bonuses, medical directorships, call coverage, and co-management arrangements that are not commercially reasonable or not consistent with fair market value.
  • Private equity and investment structures: arrangements that create pressure to increase utilization or channel referrals.
  • Vendor and technology relationships: free or discounted services, marketing support, or data tools that may function as remuneration.
  • Referral-based marketing arrangements: payments to lead generators, telemarketing entities, or patient recruiters.
  • Laboratory and ancillary service relationships: recurring OIG concern because of the potential to influence ordering behavior.

OIG has also issued multiple Advisory Opinions analyzing modern care models, care coordination, and suspect remuneration structures. Those opinions apply only to the requestors, but they provide practical insight into what OIG considers low risk, manageable risk, or unacceptable risk. Organizations should also remember the AKS safe harbors in 42 CFR 1001.952 and Stark exceptions in 42 CFR 411.355-411.357; failure to satisfy every element of an exception or safe harbor is a recurring source of enforcement vulnerability.

How are HIPAA and OCR enforcement priorities changing?

OCR’s recent enforcement signals that privacy enforcement is no longer limited to paper records or isolated employee mistakes. The trend is toward enterprise-wide security governance. OCR has repeatedly announced settlements and civil money penalties involving violations of the HIPAA Security Rule, especially where covered entities or business associates failed to conduct an accurate and thorough risk analysis as required by 45 CFR 164.308(a)(1)(ii)(A).

What OCR issues are trending?

  • Risk analysis and risk management failures: OCR frequently cites the absence of a documented, organization-wide assessment of ePHI risks.
  • Ransomware and hacking incidents: enforcement increasingly examines whether the organization implemented reasonable and appropriate safeguards before the attack.
  • Right of access: OCR has devoted sustained attention to patient access failures under 45 CFR 164.524.
  • Access controls and audit controls: weak role-based access, poor log review, and inadequate monitoring of user activity.
  • Business associate oversight: gaps in contracts, due diligence, and responsibility allocation after incidents.

OCR’s guidance on ransomware and breach response, together with resolution agreements posted by HHS, show that regulators expect fundamentals: asset inventory, patching, multi-factor authentication where appropriate, vulnerability management, contingency planning, and workforce training. The message is consistent: a breach is not automatically a HIPAA violation, but an unmanaged security program often is.

What do these trends mean for healthcare fines and settlements?

The most important trend is that fines and settlements often arise from control failure, not just isolated wrongdoing. FCA settlements can reach millions of dollars when unsupported billing spans multiple years. AKS and Stark issues can trigger repayment obligations, exclusion risk, Corporate Integrity Agreements in some cases, and parallel FCA exposure. OCR penalties and settlements vary widely, but the underlying pattern is that basic compliance lapses can become expensive once they are tied to a reportable breach or a patient complaint.

Another important trend is coordination across agencies. A single fact pattern may attract scrutiny from DOJ, OIG, CMS contractors, state Medicaid authorities, and OCR. For example, a marketing arrangement could raise AKS concerns, generate false claims exposure, and create HIPAA issues if patient data is used improperly.

What should compliance officers monitor now?

Healthcare organizations should align monitoring to these enforcement realities.

  • Validate billing support: audit medical necessity, coding accuracy, modifier use, and repayment workflows for identified overpayments.
  • Review financial relationships: test physician arrangements and vendor contracts for fair market value, commercial reasonableness, and compliance with applicable Stark exceptions and AKS safe harbors.
  • Use OIG and DOJ publications as leading indicators: review the OIG Work Plan, OIG advisory opinions, and DOJ FCA annual summaries.
  • Strengthen HIPAA security governance: maintain a current risk analysis, documented risk management plan, and incident response process tied to 45 CFR Part 164, Subpart C.
  • Train with specificity: generic annual training is not enough for high-risk functions such as coding, referrals, marketing, contracting, and access to ePHI.
  • Document decisions: if an arrangement depends on an exception, safe harbor, valuation, or clinical rationale, maintain the supporting record before a regulator asks for it.

Where are the most reliable sources for tracking FWA trends?

For credible trend analysis, healthcare compliance teams should rely primarily on federal sources:

These sources consistently show the same pattern: enforcement follows incentives, documentation, and security discipline. Organizations that monitor those three areas closely are better positioned to prevent FWA violations before they become fines, repayments, or public settlements.

Bottom line: current healthcare FWA trends are not random. They reflect sustained scrutiny of unsupported claims, referral-related compensation, and weak HIPAA security programs. The most effective response is a compliance program that ties billing, contracting, privacy, and internal auditing together rather than treating them as separate silos.

#Fraud Waste and Abuse#Healthcare Compliance#Trends in FWA#False Claims Act

Frequently Asked Questions

What healthcare fraud issue is driving the most federal enforcement activity?

False Claims Act cases remain the main federal enforcement vehicle, especially for medically unnecessary services, unsupported coding, risk adjustment issues, and claims linked to kickbacks. Many of these matters originate from whistleblower complaints.

How do the Stark Law and Anti-Kickback Statute differ?

The Stark Law generally prohibits certain physician referrals when a financial relationship exists unless an exception applies, and it operates largely as a strict liability law. The Anti-Kickback Statute prohibits knowingly and willfully offering or receiving remuneration to induce referrals and requires proof of intent.

What is OCR focusing on in HIPAA enforcement right now?

OCR is strongly focused on risk analysis, risk management, ransomware readiness, patient right-of-access compliance, and core Security Rule safeguards such as access controls and audit controls. Missing or outdated risk analyses are a frequent issue in settlements.

Why do Anti-Kickback problems often become False Claims Act cases?

Claims resulting from kickback-tainted referrals can be treated as false or fraudulent claims submitted to federal healthcare programs. That is why a problematic financial arrangement can lead to both AKS exposure and major FCA settlement risk.

What sources are best for tracking current healthcare FWA trends?

The most reliable sources are DOJ False Claims Act annual announcements, the HHS OIG Work Plan and advisory opinions, and HHS OCR enforcement and guidance pages. These federal sources provide the most direct view of current enforcement priorities.

Ready to Strengthen Your Compliance Program?

Schedule a free consultation with our compliance experts and discover how we can help protect your healthcare organization.