Regulatory and Compliance

What Gets a Practice Flagged in 2026: A Physician's Guide to the DOJ's New Fraud Detection Center

Dr. Sarah Matt, MD, MBA  |  September 1, 2026  |  The Sarah Matt Briefing, Issue 28

Enforcement used to start with a complaint. It now starts with a comparison.

On August 24, the Justice Department launched the National Fraud Detection Center, a prosecutor-led unit that pools analysts and data from roughly a dozen federal inspector general offices, the FBI, Homeland Security Investigations, IRS Criminal Investigation, FinCEN and Treasury into one place. The stated purpose is closing the blind spot between programs. The practical effect for a practicing physician is narrower and more immediate: your claims are now read as a population, against your peers, continuously, without anyone opening a chart.

This is not a warning about fraud. If you are billing honestly, you are not the target of this center. But honest billing and a normal-looking data profile are two different things, and only one of them is visible to a benchmarking engine.

What changed

The old model sampled. An investigator pulled forty claims, found an error rate, and extrapolated across the population. That method has obvious problems, and it also had an obvious threshold: somebody had to decide you were worth sampling first, usually because a patient, an employee or a competitor said something.

The new model reverses the order. The full claims population is benchmarked against peers, and divergence in a single code family surfaces on its own. The trigger is arithmetic rather than accusation.

The scale is not theoretical. The June 2026 National Health Care Fraud Takedown charged 455 defendants, including 90 doctors and other licensed medical professionals, across 56 federal districts and 45 states and territories, tied to more than $6.5 billion in alleged fraud. Alongside it, CMS suspended 1,079 providers and revoked billing privileges for 1,403 more. HHS OIG added more than 1,400 provider exclusions. DOJ credited its Data Fusion Center, staffed jointly with HHS OIG and the FBI, with driving many of the cases, and announced new data-sharing agreements with CMS, DHS and the FTC.

The first consequence is a payment hold, not an indictment

This is the part most physicians get wrong, and it is the part that determines what you should actually prepare for.

Claims data mining was written into federal regulation in 2011 as a potential basis for a "credible allegation of fraud." That phrase is the bar CMS has to clear before suspending payments. It is a lower bar than probable cause and far lower than a conviction. A practice can submit a written rebuttal, but whether CMS considers or rejects that rebuttal is discretionary, and formal review runs through administrative appeals long before any court sees it.

So the sequence that should shape your planning is: divergence surfaces, payments stop, and you spend months in an administrative process demonstrating that your patient mix explains your code mix. Cash flow is the exposure. For a small practice, a ninety-day hold is an existential event whether or not the underlying claims were correct.

Where AI tools enter this

Here is the connection almost nobody is making yet.

Your AI scribe, your ambient documentation tool and your coding assistant all carry default behaviors. Some suggest the higher of two supportable E/M levels. Some auto-append modifiers. Some populate history-of-present-illness detail from prior notes, which can make a level of service look supported when the clinical work that day did not support it. Every one of those defaults, applied across four thousand encounters a year, becomes your data profile.

You did not choose those settings. A vendor chose them, once, probably before you signed, optimized for a metric the vendor cares about. And a benchmarking engine cannot tell the difference between a physician who upcodes and a physician whose software upcodes on their behalf. Both look identical from the outside, because from the outside they are identical: the claims went out under your NPI.

A benchmarking engine cannot tell the difference between a physician who upcodes and a physician whose software upcodes on their behalf. From the outside they are identical: the claims went out under your NPI.

Compliance professionals have started saying this plainly. The recommendation running through the current guidance is a documented internal risk assessment of how AI-assisted documentation and coding tools affect billing risk, plus real diligence on the vendor and the business associate agreement. OIG has separately signaled that the absence of an effective compliance program is itself an aggravating factor, including at the smallest practices.

The six scrutiny areas

Current enforcement guidance points consistently at the same list. Read it as a checklist rather than a threat inventory.

1. E/M level selection and medical necessity. The single largest source of benign divergence. If your panel skews complex, your distribution should skew high, and you should be able to show why with data rather than assertion.
2. Modifier use. Particularly 25 and 59. High-frequency modifier application is one of the cheapest patterns for an engine to spot.
3. Incident-to billing, and split or shared visits. Documentation requirements here are specific and are frequently satisfied by a template rather than by the facts of the encounter.
4. Telehealth documentation. The place where the gap between what happened and what the note supports opens most easily.
5. Medicare Advantage risk adjustment. Diagnosis capture that the chart does not sustain.
6. DME and referral relationships. Financial relationships that look ordinary internally and look like a pattern from outside.

What to do in the next quarter

Five things, in rough order of how much they buy you per hour spent.

Ask your vendor, in writing, what the tool does by default. Which E/M level it suggests when documentation supports two. Whether it appends modifiers without prompting. Whether it carries history forward between encounters. Keep the answer. It is both a configuration decision and, later, evidence about what you knew.
Pull your own distribution before somebody else does. Your E/M level distribution against your specialty benchmark, and your modifier frequency against the same. This is a report your billing system already produces. If you have an outlier, you want to find it while it is a question rather than after it is a hold.
Write down why your outliers are real. A geriatric panel, a referral-heavy practice, a rural site absorbing complexity that has nowhere else to go: all of these produce legitimate divergence. Divergence you can explain in a paragraph is a very different object than divergence you discover under a rebuttal deadline.
Read your BAA for the coding tool specifically. Most were signed for a documentation product and never revisited when the same vendor added coding suggestions.
Have a compliance program that exists. Not a binder. A named owner, a documented annual risk assessment, and evidence that somebody looked. OIG treats its absence as aggravating, and it is the cheapest item on this list.

The thing worth sitting with

A note error is a records problem. A code error is a False Claims Act problem. Physicians have spent three years being told that AI documentation tools reduce burden, and by and large they do. What has not been said in the same sentence is that those tools moved a set of decisions out of the exam room and into a configuration file, and that the liability did not move with them.

The configuration file is now writing your peer comparison. Somebody should read it.


Sarah Matt, MD, MBA is a surgery-trained physician-executive currently practicing internal medicine (charity care). She advises health systems and health-tech companies on clinical AI governance and implementation through Vital Werks.

Sources

U.S. Department of Justice, launch of the National Fraud Detection Center, August 24, 2026: a prosecutor-led unit pooling analysts and data from federal inspector general offices, the FBI, Homeland Security Investigations, IRS Criminal Investigation, FinCEN and Treasury.

DOJ 2026 National Health Care Fraud Takedown, June 2026: 455 defendants charged, including 90 licensed medical professionals, across 56 federal districts and 45 states and territories, tied to more than $6.5 billion in alleged fraud.

CMS enforcement actions announced alongside the June 2026 takedown: 1,079 provider payment suspensions and 1,403 billing privilege revocations. HHS OIG: more than 1,400 additional provider exclusions.

42 CFR 405.370 and 405.371, "credible allegation of fraud" standard for payment suspension, including claims data mining as a potential basis, effective 2011.

HHS OIG General Compliance Program Guidance on the role of an effective compliance program, including for small practices.

Advisory for Health System Leaders

If nobody in your organization can say what your AI documentation and coding tools do by default, that answer is worth having in writing before a peer comparison produces it for you. I build the governance and vendor-diligence layer with leadership teams in four to six weeks.


Schedule a scoping call   |   drsarahmatt.com