Most healthcare providers assume a fraud investigation starts with a complaint. Increasingly, it starts with a computer.
Federal agencies now run enormous volumes of Medicare and Medicaid billing data through software that looks for patterns. A practice that never received a complaint can land on the government’s radar simply because its billing looks different from everyone else’s.
We defend physicians, pharmacies, clinics, and healthcare businesses in federal investigations, and our team includes a former Assistant U.S. Attorney who worked with the IRS, FBI, and Homeland Security on white-collar cases. That background matters here, because a billing “flag” can stay a civil audit — or turn into a criminal case — depending on what happens in the early stages.
This page explains how billing data actually triggers an investigation, which agencies are involved, how a routine audit can escalate, and what to do the moment you learn your billing is being reviewed.
If you have received an audit letter, a records request, or a Civil Investigative Demand, do not respond alone. Contact our office before you send anything to the government.
The Data-Driven Shift in Healthcare Fraud Enforcement
For years, healthcare fraud cases began with a whistleblower or a patient complaint. That is no longer the usual starting point.
Medicare and Medicaid process billions of claims, and every claim becomes a data point. Federal agencies use analytics tools to sift through those claims and surface providers whose billing does not fit the expected pattern.
The practical result is that you no longer need anyone to report you. Your own claims data, compared against your peers, can be enough to open a file.
Our managing partner, Russell Lorfing, saw this shift firsthand as a federal prosecutor. Years ago, a healthcare fraud case usually started with a whistleblower and a stack of paper. Today the government leads with data — scanning billing patterns across thousands of providers and flagging outliers automatically.
You no longer need an angry employee to get investigated. You just need to bill differently than your peers — and if your utilization or reimbursement per patient looks off, you may already be on a list without knowing it.
What the Government’s Software Is Looking For
The analytics are built to spot outliers — billing that stands out from what similar providers do. A few patterns draw attention most often.
Peer comparison. The software compares your billing to other providers in your specialty, region, and patient population. If you bill a particular high-level code far more often than similar doctors, that gap gets noticed.
Impossible or improbable volume. Claims are checked against what is physically possible. Billing for more hours of service than exist in a day, or for a patient who records show was hospitalized elsewhere that day, is a classic trigger.
Sudden changes. A practice whose billing spikes, shifts toward more expensive codes, or changes sharply after a new hire or new software can be flagged, because the change itself looks like a possible shift in behavior.
Code combinations. Certain pairings of billing codes — services that are rarely medically appropriate together — are specifically watched.
Why Legitimate Practices Get Flagged Too
Being flagged does not mean you did anything wrong. The software finds statistical outliers, and there are many innocent reasons a practice can look like one.
A physician who treats an unusually sick or elderly population will legitimately bill more complex codes. A specialist, a rural sole provider, or a practice that absorbed another clinic’s patients can all look like outliers for reasons that have nothing to do with fraud.
The danger is that a data flag opens the door. What happens next depends on how the review is handled — which is why the response matters as much as the underlying billing.
Who Investigates Healthcare Billing Data
Several different government bodies touch these cases, and knowing who is involved tells you how serious a matter has become.
CMS (Centers for Medicare & Medicaid Services) runs the Medicare and Medicaid programs and oversees the contractors who analyze claims.
MACs and UPICs. Medicare Administrative Contractors process and review claims, and Unified Program Integrity Contractors are specifically tasked with investigating suspected fraud, waste, and abuse. A letter from a UPIC is a signal that your billing is under program-integrity review, not routine processing.
HHS-OIG (Office of Inspector General). This is the investigative arm of the Department of Health and Human Services. When agents from HHS-OIG get involved, the matter has moved beyond spreadsheets and into an active investigation.
The Department of Justice. DOJ handles both civil False Claims Act cases and criminal healthcare fraud prosecutions, often working with the FBI and HHS-OIG through coordinated strike forces. A DOJ contact means the stakes are now at their highest.
The Path From a Data Flag to a Case
These cases tend to move through a recognizable sequence, and each step raises the stakes.
- The flag. Analytics identify your billing as an outlier, or a whistleblower’s complaint lines up with the data.
- The audit or records request. A contractor requests records for specific claims to compare what you billed against what your documentation supports.
- Extrapolation and repayment demands. If the reviewer finds errors in a sample of claims, it may apply that error rate across a much larger universe of claims, producing a repayment demand far larger than the claims actually reviewed.
- The Civil Investigative Demand. DOJ can issue a Civil Investigative Demand, or CID, to compel documents, written answers, and testimony in a False Claims Act investigation. A CID means the civil fraud side of DOJ is now involved.
- Criminal referral. If investigators believe the conduct was knowing and intentional, the matter can be referred for criminal prosecution.
Understanding where you are in that sequence changes what your attorney should be doing. If you are unsure how far along your matter has gone, speak with our team before you respond to any request.
An Audit and a Criminal Investigation Are Not the Same Thing
This distinction causes more confusion — and more costly mistakes — than almost anything else in these matters.
A billing audit is, on its face, a civil process to check whether claims were properly paid. A criminal investigation asks whether someone knowingly submitted false claims to defraud a federal program. The two can look similar at the start, and an audit can quietly become the foundation for a criminal case.
The reason this matters is that people treat audits casually. They hand over records without review, give unguarded explanations, or send in a billing manager to “sort it out” — and those statements and documents can end up feeding a criminal file.
Once you know an outside contractor or agency is examining your billing, the safest assumption is that everything you produce could matter later. That does not mean stonewalling. It means responding carefully, accurately, and with guidance.
A billing audit and a criminal investigation can look the same at the start. The records you hand over in one can become evidence in the other.
Common Billing Patterns That Draw Federal Attention
Certain billing practices come up repeatedly in healthcare fraud investigations. Some are outright fraud; others are honest errors that still invite scrutiny. Knowing the categories helps you understand what reviewers look for.
Upcoding. Billing for a more expensive service or a higher level of care than was actually provided or documented.
Unbundling. Billing separately for services that are supposed to be billed together under a single, lower-cost code.
Services not rendered. Billing for care, tests, or supplies that were never provided.
Medically unnecessary services. Billing for care that was not justified by the patient’s condition or documentation.
Kickback-tainted claims. Claims connected to improper payments for referrals, which can violate the Anti-Kickback Statute and, through it, the False Claims Act.
The presence of one of these patterns in the data does not prove intent. Whether a discrepancy reflects fraud, a coding error, poor documentation, or a legitimate clinical reason is exactly what a defense examines — and often where these cases are won or lost.
Catch a Problem Before the Software Does
The flip side of data-driven enforcement is that most billing problems that turn into investigations could have been caught internally first. When numbers slowly drift away from a provider’s peers — often through upcoding or services that grow more aggressive over time — a regular internal review of billing and coding practices will usually surface it well before the government’s software does.
An annual internal audit is not complicated or expensive compared to a federal investigation, and it gives a practice the chance to find and fix that drift on its own terms.
Civil vs. Criminal Exposure in Healthcare Billing Cases
A billing investigation can lead down two different roads, and they carry very different consequences.
Civil False Claims Act exposure. The False Claims Act allows the government — and private whistleblowers filing on its behalf — to pursue providers who knowingly submit false claims. Civil consequences can include repayment, substantial monetary penalties per claim, and multiplied damages, but not prison.
Criminal exposure. Federal law separately makes healthcare fraud a crime when claims are submitted knowingly and with intent to defraud. Criminal cases can carry federal prison time and criminal fines, and often travel alongside charges like false statements or money laundering.
The same billing data can support either track, and sometimes both at once. A defense strategy built only around the civil audit can leave a provider exposed if a criminal referral is already forming — which is why the two possibilities have to be weighed from the start.
The specific consequences in any matter depend on the facts, the evidence of intent, and how the case is resolved. No one can honestly promise an outcome before reviewing your records.
What to Do When Your Billing Is Flagged
If you have learned that your billing is under review — through an audit, a UPIC letter, a records request, or a CID — a few steps protect you more than anything else:
- Do not ignore it. These matters do not resolve on their own, and deadlines in audits and CIDs are real.
- Do not alter or “clean up” records. Changing documentation after a request can turn a billing dispute into an obstruction charge, which is often easier to prove than the underlying issue.
- Preserve everything — claims data, medical records, billing software logs, and communications tied to the claims at issue.
- Route the response through counsel. Do not let staff give explanations or hand over records without review.
- Get an honest assessment of whether the matter is civil, criminal, or both, and how far along it is.
- Involve experienced federal healthcare counsel early, before you respond to the government.
What a Defense Attorney Does in a Billing Investigation
Bringing in counsel early is about controlling a process that is designed to move forward with or without you.
Assessing the real exposure. Counsel evaluates whether the matter is a civil audit, a False Claims Act investigation, a criminal inquiry, or a mix, which determines the entire strategy.
Managing document production. An attorney reviews records before they go to the government, confirms the scope of any request, and avoids over-producing or volunteering material beyond what is required.
Challenging the data and the methodology. Extrapolated repayment demands rest on statistical sampling that can be flawed. Counsel can examine the sample size, the error findings, and the assumptions behind a large demand.
Explaining the clinical and coding reality. Many “outliers” have legitimate explanations. Counsel works to show that a billing pattern reflects a sicker patient population, a valid coding interpretation, or an honest error rather than fraud.
Positioning against criminal referral. Where intent is the real question, counsel with federal criminal experience can address the government’s theory before it hardens into charges.
Why Clients Bring Us Into Healthcare Billing Investigations
Our firm’s managing partner, Russell Lorfing, is a former Assistant U.S. Attorney who prosecuted federal cases in Lubbock, Texas, and was designated a Cyber Hacking Intellectual Property Prosecutor by the U.S. Attorney’s Office in 2017. He has trained federal agents and prosecutors for the FBI, IRS, DEA, and DOJ, and has been recognized nationally for his work on white-collar investigations involving the IRS, Homeland Security, and the FBI. In 2024, he served as Co-Chair of the Federal Criminal Defense Committee for the Texas Criminal Defense Lawyers Association. He is admitted to practice in Texas, the District of Columbia, the Fifth Circuit Court of Appeals, the Northern, Western, and Southern Districts of Texas, and the U.S. Supreme Court.
That background matters in billing cases, because the same data that starts as a civil audit can end up in front of the same federal agencies that bring criminal charges. Knowing how those referrals happen — from the inside — shapes how we respond to an audit before it becomes something worse.
Founding partner Trey Keith has spent more than 20 years defending clients in state and federal matters, including financial crimes such as money laundering, with a track record that includes not-guilty verdicts in those cases. The Honorable E. Scott Frost (Ret.), Of Counsel to the firm, brings more than 30 years on the federal bench. Our broader team includes former federal prosecutors, former federal public defenders, former FBI agents, former IRS criminal investigators, and former general counsel to major family offices.
We also work with healthcare practices before a problem ever surfaces — conducting discreet internal reviews of billing and documentation practices, strengthening compliance systems, and, where concerns arise, engaging strategically with agencies like DOJ, HHS-OIG, and the U.S. Attorney’s Office. The practices that come through these matters best are usually the ones that identified their vulnerabilities early, rather than waiting for a subpoena to define the problem for them.
If your matter involves Medicare or Medicaid specifically, or whistleblower-driven allegations, our pages on Healthcare Fraud Defense, Medicare Fraud Defense, Medicaid Fraud Defense, and False Claims Act & Qui Tam Defense explain how those cases work in more detail.
Frequently Asked Questions
How does the government find healthcare billing fraud?
Increasingly through data analytics. Federal agencies and their contractors compare your Medicare and Medicaid claims against those of similar providers and flag billing that stands out as an outlier. Whistleblower complaints and audits still matter, but data mining is now a leading trigger.
Does a billing audit mean I’m being criminally investigated?
Not necessarily. Many audits are civil reviews to check whether claims were properly paid. But an audit can become the basis for a criminal case, which is why it is risky to treat one casually or respond without careful review.
What is a Civil Investigative Demand?
A CID is a formal tool the Department of Justice uses in False Claims Act investigations to compel documents, written answers, and sometimes testimony. Receiving one means the civil fraud side of DOJ is actively looking at your billing, and you should involve counsel before responding.
Can normal, honest billing get me flagged?
Yes. The software identifies statistical outliers, and there are legitimate reasons a practice can look like one — a sicker patient population, a specialty focus, or absorbing another practice’s patients. Being flagged is not proof of wrongdoing, but it can still open an investigation.
What is the difference between the False Claims Act and criminal healthcare fraud?
The False Claims Act is civil and can lead to repayment, penalties, and multiplied damages, but not prison. Criminal healthcare fraud requires proof that claims were submitted knowingly and with intent to defraud, and it can carry federal prison time. The same billing data can support either or both.
Should I respond to a Medicare audit myself?
It is risky. Records and explanations you provide can shape whether the matter stays civil or escalates. An attorney can review what you produce, confirm the scope of the request, and keep an audit from becoming the foundation of a larger case.
What triggers a UPIC audit?
Unified Program Integrity Contractors focus on suspected fraud, waste, and abuse, so a UPIC review is often prompted by data outliers, a whistleblower complaint, or a referral. A UPIC letter is a signal that your billing is under program-integrity scrutiny rather than routine claims processing.
If your practice has been flagged, audited, or served with a demand, the earlier you involve counsel, the more you can shape the outcome. Schedule a consultation with our federal defense team to talk through where your matter stands.