DOJ-OIG Guidelines
The DOJ-OIG Guidelines establish frameworks for detecting and deterring fraud, waste, and abuse in federal healthcare programs. They provide voluntary compliance guidance to help healthcare entities design effective programs that prevent violations of the False Claims Act, Anti-Kickback Statute, and other federal laws.
The General Compliance Program Guidance (GCPG) covers seven core elements of an effective compliance program, outlines federal fraud and abuse laws, and provides resources for understanding healthcare compliance. Industry-specific guidance addresses risks unique to sectors like Medicare Advantage and pharmaceutical manufacturers.
OIG’s Self-Disclosure Protocol allows entities to voluntarily report misconduct in exchange for reduced penalties—a mechanism distinct from the FCA’s qui tam provisions. In March 2026, DOJ released its first-ever department-wide corporate enforcement policy, creating a parallel self-disclosure pathway for criminal violations. This policy, combined with OIG’s existing protocol, establishes a comprehensive framework that encourages proactive compliance rather than reactive enforcement.
The GCPG uses the word “should” throughout to present voluntary, nonbinding guidance—a deliberate choice signaling that these are recommendations, not mandatory requirements. This “should” language is unique to OIG guidance and does not appear in the FCA or AKS, which use mandatory terms like “shall” or “prohibited.” Together, these provisions make the DOJ-OIG Guidelines an essential resource for healthcare entities seeking to navigate the complex regulatory landscape while avoiding the severe penalties associated with healthcare fraud.
The DOJ Corporate Enforcement Policy and the OIG Self-Disclosure Protocol are two distinct self-disclosure pathways for healthcare companies. The DOJ policy is a department-wide program for criminal misconduct applicable to all business entities. The OIG protocol is a healthcare-specific program covering criminal, civil, and administrative violations.
– DOJ policy: Requires voluntary disclosure to DOJ, full cooperation, timely remediation, and no aggravating factors to receive a declination from criminal prosecution
– OIG protocol: Less prescriptive about disclosure content and favors prompt reporting over completing an internal investigation first
To qualify for declination under the DOJ’s Corporate Enforcement Policy, a company must meet four criteria:
1. Voluntary self-disclosure: The company proactively discloses the misconduct to the DOJ before an imminent threat of disclosure or government investigation
2. Full cooperation: The company provides comprehensive and ongoing cooperation with the DOJ’s investigation
3. Timely and appropriate remediation: The company takes prompt and effective corrective actions to address the misconduct
4. No aggravating circumstances: The company does not have aggravating factors related to the nature and seriousness of the misconduct
These criteria come from the DOJ’s “Evaluation of Corporate Compliance Programs” guidance. They represent three core questions prosecutors use to assess a compliance program.
– “Well-designed”: The program must be tailored to the company’s specific risks, not a one-size-fits-all template. This includes risk assessments, appropriate policies and procedures, and training for high-risk employees
– “Applied earnestly”: The program must be adequately resourced and implemented in good faith, not just on paper. Prosecutors look for genuine commitment from senior leadership and a culture of compliance
– “Works in practice”: The program must actually function effectively. This requires continuous improvement, adaptation to new risks, and the ability to detect and correct problems in real time
The DOJ-HHS False Claims Act Working Group is a joint enforcement body established in July 2025 to strengthen collaboration between the Department of Justice and the Department of Health and Human Services in combating healthcare fraud.
It includes leadership from HHS, CMS, HHS-OIG, and DOJ’s Civil Division. The group has transformed interagency coordination by moving beyond the traditional reliance on qui tam filings to proactively sharing data and identifying new investigative targets.
It prioritizes specific enforcement areas like Medicare Advantage and drug pricing, and coordinates on critical decisions such as payment suspensions and motions to dismiss qui tam complaints.
The OIG evaluates a range of factors when deciding whether to impose a permissive exclusion. The key considerations are organized into four general categories: the nature and circumstances of the conduct; the party’s conduct during the investigation; any significant ameliorative efforts; and the party’s history of compliance.
– OIG examines the seriousness of the misconduct, including patient harm and financial loss to federal programs
– It assesses whether the misconduct was an isolated incident or a pattern of wrongdoing
– A lack of cooperation or failure to self-disclose can weigh heavily against the provider
Successor liability is the legal principle that an acquiring company may inherit the past legal liabilities and violations of the company it purchases. In healthcare, the risks are acute because liabilities can include the “draconian penalties” available under the False Claims Act.
Changing ownership does not erase the underlying misconduct. DOJ guidance makes this a critical due diligence concern because the government explicitly named acquiring companies as “successor in liability” for an acquired company’s alleged violations, even for conduct that occurred years before the acquisition.
Furthermore, the DOJ’s M&A Safe Harbor Policy does not reduce liability for failure to perform effective due diligence.
DOJ and OIG have shifted from reactive “pay and chase” to proactive “detect and prevent” enforcement. They now use AI-driven tools to identify fraud before payment.
CMS employs AI-powered “heat maps” and is moving toward near-real-time fraud detection at the point of payment.
OIG mines CMS program-integrity data multiple times per week to spot vulnerabilities.
The revived DOJ-HHS False Claims Act Working Group facilitates proactive data sharing to identify new investigative targets. DOJ’s Data Analytics Team uses peer comparison and outlier detection to initiate cases without whistleblower tips.
