In August 2026, the Department of Justice put behavioral health on notice, whether it meant to or not.
On August 13, the DOJ's newly created National Fraud Enforcement Division published a memorandum naming healthcare its second enforcement priority and promising to supercharge the Health Care Fraud Strike Force with more resources, a dedicated data-science team, and, in its own words, best-in-class technology. Translation: the government is scaling up the practice of finding fraud by algorithm, running machine learning against Medicare and Medicaid claims to flag outlier providers before a human ever opens a chart.
For the people actually committing fraud, that is good policy. Fraud is a real and enormous problem, and no honest provider wants to share a market, or a payer, with people stealing from it. But for the far larger group of legitimate behavioral health and substance use disorder providers, the shift raises a harder question: what happens when the algorithm flags you, and your documentation cannot explain why you look different?
The short version
- The DOJ's new National Fraud Enforcement Division is scaling data-driven enforcement, using analytics to flag outlier providers for investigation.
- Analytics finds statistical outliers, not intent. Legitimate high-acuity or high-volume behavioral health programs can look anomalous.
- Behavioral health and SUD are unusually exposed: controlled substances, telehealth, group therapy, and IOP and PHP per diems all deviate from a naive billing norm.
- When you are flagged, the investigation turns to your documentation. Contemporaneous, defensible records are the difference between an explainable outlier and a case.
- The practical response is not to bill less. It is to make every claim defensible before it is submitted.
What actually changed in 2026
The National Fraud Enforcement Division, or NFED, is not a rebrand. It is a new, stand-alone litigating division of the DOJ, announced early in 2026 and formally established in April, that consolidates fraud enforcement across taxpayer-funded programs. Within months it grew toward roughly 500 lawyers and staff, and on August 18 the Department published a final rule formally conferring its authority. This is a large, permanent commitment, not a task force that expires at the end of a fiscal year.
Its August 13 priorities memorandum lists five focus areas: public trust and financial integrity, healthcare, internal revenue, global trade and commerce, and corporate misconduct. Healthcare sits second, and that placement is not symbolic. Over the last decade, healthcare has accounted for close to 80 percent of all False Claims Act judgments and settlements. Enforcement follows the money, and in healthcare there is a great deal of it: by various government estimates, improper and fraudulent payments run into the hundreds of billions of dollars a year, and the DOJ's healthcare fraud efforts have historically returned several dollars for every dollar spent. From the Department's point of view, healthcare enforcement pays for itself.
The mechanism the memorandum leans on is data. The Division has said it will supercharge the existing Health Care Fraud Strike Force model with a cross-disciplinary team of data scientists and technologists, and pair prosecutors with real-time billing analytics. A healthcare fraud data-fusion capability applies machine learning against Medicare and Medicaid claims, and outlier billing patterns are flagged automatically for review. This works in concert with other agencies, the OIG, the IRS, state Medicaid units, and others, in what the Department describes as a whole-of-government approach. The named targets, telemedicine fraud, controlled-substance diversion, and home health and hospice schemes, all sit close to behavioral health and SUD care. (For the legal detail, see analyses from Holland & Knight, Morgan Lewis, and Nelson Mullins.)
How the machine actually decides who to investigate
Here is the uncomfortable part, and it is worth sitting with, because it is the whole story. Analytics is very good at finding statistical outliers. It is not good at telling you why a provider is an outlier. Those are different questions, and only one of them is a crime.
An outlier-detection model compares your billing to a peer group: your volume, your mix of codes, your average session length, your rate of high-intensity services, all measured against what other providers who look like you do. When you deviate far enough from that norm, you get flagged. But two questions decide whether that flag means anything, and a model usually cannot answer either.
First, what is the right peer group? Behavioral health is not one specialty; it is dozens of settings and populations. A residential SUD program, a telehealth-first psychiatry group, and a community mental health center are not peers in any clinically meaningful sense, yet a coarse model may lump them together. Second, how is the comparison risk adjusted? A program that treats sicker, more complex patients, and that attracts those patients precisely because of its reputation, will legitimately deliver more intensive services more often. Adjusting for acuity, subspecialty, and patient complexity is hard, and much of it simply does not happen at the analytics layer.
The result is that a genuinely excellent, high-complexity provider can look, on a dashboard, statistically identical to someone running a scheme. Deviation from a norm is a statistical description, not a clinical one, and it is certainly not evidence of intent. The practical danger is not that a model convicts you. It is that a model decides who gets investigated, and an investigation is expensive, disruptive, and reputationally damaging whether or not it ever produces a charge.
Why behavioral health and SUD are unusually exposed
Every field has its billing quirks. Behavioral health and SUD happen to have several that look exactly like the patterns these models are trained to notice, and several that overlap directly with the DOJ's named priorities. If you run one of these programs, it is worth understanding why you may draw a second look even when you are doing everything right.
- Controlled substances. Medication-assisted treatment for opioid use disorder involves buprenorphine and other controlled substances, and controlled-substance diversion is an explicit enforcement priority. Legitimate MAT prescribing generates patterns, high volumes, refill cadences, that a diversion model is built to flag.
- Telehealth. Behavioral health went remote faster and further than almost any other field, for good clinical and access reasons. Telemedicine fraud is also a named priority, and telehealth-heavy billing is, by definition, unusual against a pre-pandemic norm.
- Group therapy and long sessions. Group psychotherapy and extended individual sessions are core to SUD and serious mental illness. On a dashboard, high group-therapy volume or frequent use of the 53-minute-plus psychotherapy code can read as an anomaly rather than as appropriate care.
- IOP and PHP per diems. Intensive outpatient and partial hospitalization are billed as high-dollar, high-frequency per diems. That combination, big daily charges repeated over weeks, is exactly the shape of billing that outlier detection is tuned to surface.
- Heavy Medicaid volume. The Fusion Center runs against Medicaid data, and SUD and community behavioral health serve disproportionately Medicaid populations. More Medicaid claims means more surface area for the analytics.
- High-acuity churn. SUD care involves relapse, readmission, and frequent changes in level of care. That clinical reality can look, statistically, like the kind of churn a model associates with abuse.
- Thin peer groups. Specialized behavioral health providers often have small, poorly-risk-adjusted comparison groups, which makes it easier to land in the tail of a distribution for reasons that have nothing to do with fraud.
None of this is a reason to change appropriate clinical practice. It is a reason to assume that, sooner or later, your billing will be looked at by a system that does not understand your clinical context, and to make sure your record can supply the context the algorithm lacks.
Enforcement is getting more personal
There is a second trend worth naming, because it changes the stakes for owners and clinical leaders specifically. Enforcement is increasingly aimed at individuals, not just entities. The DOJ has signaled, repeatedly, that it wants to hold people accountable, and recent healthcare cases have pushed personal liability up the org chart, including executives compelled to testify in Medicare-related fraud matters. A larger, better-resourced fraud division also tends to mean more False Claims Act whistleblower cases in which the government chooses to intervene.
For a behavioral health organization, that means the compliance posture of the business is no longer only a business risk. It is increasingly a personal one for the people who sign off on billing, run the clinical program, and own the entity. That is a strong argument for getting the documentation right at the source, rather than discovering the gaps during a deposition.
When you are flagged, the record is the trial
Once an outlier flag opens a review, the story stops being about statistics and becomes about your documentation. Investigators pull claims, charts, and utilization data together and ask a simple question of each claim: does the record support it? Was medical necessity established? Was the level of care justified against the ASAM Criteria? Are the service units and session times documented? Are signatures and dates in place and contemporaneous? Was the required 42 CFR Part 2 consent captured before the disclosure?
This is where the outcome is actually decided.
If the chart tells a clean, contemporaneous story, an outlier is just an outlier, an explainable pattern with a clinical reason behind it, and the review closes. If the documentation is thin, copied forward, or missing the elements that justify what was billed, a statistical flag can harden into a case, or at least into a costly, protracted inquiry. The uncomfortable truth of data-driven enforcement is that your defense is written months or years before you ever need it, in the notes your clinicians close every day.
A defensibility playbook for behavioral health leaders
The goal is not to bill less or to treat fewer complex patients. It is to make sure your record can withstand a look. A practical program:
- Audit your own data the way the government would. Look at utilization, not just coding accuracy. Where are you an outlier, and why? Which providers, codes, or programs sit in the tail? Knowing your own numbers, and having a clinical explanation ready, is the single most valuable thing you can do before an investigator does the same analysis for you.
- Make documentation defensible at the point of care. Medical necessity, ASAM level of care, 42 CFR Part 2 consent, group attendance, service units, session time, and signatures should be right when the note is written, not reconstructed a year later. Contemporaneous beats complete-but-late every time.
- Kill copy-forward. Notes that repeat the prior visit are the fastest way to turn a legitimate pattern into an indefensible one. Every note should reflect the current assessment.
- Keep the compliance program live. A plan on a shelf, or in the cloud, is useless. Train regularly, document that you trained, and act on what audits find.
- Review referral relationships. Check arrangements with those you refer to and receive referrals from for strict compliance with the Anti-Kickback Statute and self-referral (Stark) rules, both federal and state.
- Prepare for the whistleblower vector. Better-resourced enforcement brings more qui tam cases. Maintain strong relationships with staff and vendors, take internal reports of impropriety seriously, and never take action that manufactures a whistleblower.
- Remediate and self-disclose where appropriate. When a self-audit finds a real problem, fix it, and disclose it with counsel where the situation calls for it. Voluntary disclosure is almost always better than discovery.
- Know the line between a compliance issue and a legal one. When something looks off, bring in outside counsel and counsel-engaged experts early. This article is general guidance, not legal advice.
The mindset shift
The old model of healthcare fraud enforcement was reactive and case-by-case: a tip, a whistleblower, an auditor who happened to pull the right chart. The new model is proactive and statistical, and it starts with a machine deciding who deserves a closer look. That shift does not reward the providers who bill the least or treat the simplest patients. It rewards the ones who can explain themselves, instantly and on paper.
Defensibility is not paranoia, and it is not about hiding from scrutiny. It is an operating discipline: the habit of making sure that every claim you submit is supported by a record that a stranger could read and understand. In an era where the first reviewer of your work may be an algorithm, that discipline is the most durable protection you have.
Where Adentris fits
Adentris is built for exactly this moment. It reviews every behavioral health and SUD chart in real time, before the claim is submitted, and flags the gaps that make documentation indefensible: a missing medical necessity statement, an unjustified ASAM level of care, a 42 CFR Part 2 consent that was never captured, service units, session times, and signatures that do not line up. It drafts the correction while the note is still open, and keeps a clean, contemporaneous audit trail, so that if an algorithm ever flags you as an outlier, your record does the explaining. It is HIPAA compliant and SOC 2 certified, with 42 CFR Part 2 controls and BAAs in place. This is not about hiding from scrutiny. It is about being able to withstand it. To see it on your own charts, book a 30-minute call with our team.
Related reading
- Behavioral health payer audit readiness solutions
- Best behavioral health documentation compliance software
- AI chart review tools for behavioral health
Frequently asked questions
Is the DOJ really using AI to find healthcare fraud?
Yes. The Department of Justice uses data analytics and machine learning against Medicare and Medicaid claims to identify outlier providers, and the National Fraud Enforcement Division's August 2026 priorities memorandum expands that capability with more resources, a dedicated data-science team, and technology aimed at the Health Care Fraud Strike Force. Outlier billing patterns are flagged automatically for review.
Can a legitimate provider be flagged as an outlier?
Yes. Analytics detects statistical deviation from a peer group, not intent. A program that treats higher-acuity or more complex patients, or that legitimately relies on group therapy, telehealth, longer sessions, or IOP and PHP per diems, can look statistically similar to a fraud scheme on a dashboard that has no clinical context. The defense is documentation that explains the pattern.
Why is behavioral health especially exposed to this?
Several legitimate behavioral health and SUD billing patterns overlap with the DOJ's named priorities and with the shapes outlier models are built to notice: controlled-substance prescribing in medication-assisted treatment, telehealth-heavy delivery, group therapy and long individual sessions, high-dollar IOP and PHP per diems, and heavy Medicaid volume. Specialized providers also tend to have small, poorly risk-adjusted peer groups.
What should a behavioral health program do to prepare?
Audit your own utilization the way the government would and know why you are an outlier; make documentation defensible at the point of care (medical necessity, ASAM level of care, 42 CFR Part 2 consent, service units, session time, signatures); eliminate copy-forward notes; keep compliance training live; review referral relationships for Anti-Kickback and Stark exposure; and bring in counsel early when something looks off.
Does good documentation actually help if I am investigated?
Yes. Once an outlier flag opens a review, the question becomes whether each claim is supported by the record. A contemporaneous chart that shows medical necessity and a justified level of care turns an outlier flag into an explainable pattern, and the review closes. Thin, copied-forward, or missing documentation is what lets a statistical flag harden into a case.
Is enforcement targeting individuals, or just organizations?
Both, and increasingly individuals. The DOJ has emphasized personal accountability, recent healthcare cases have pushed liability toward executives, and a larger fraud division tends to bring more False Claims Act whistleblower cases in which the government intervenes. For owners and clinical leaders, the organization's compliance posture is increasingly a personal risk as well.
About the author: Sergey Yudovskiy is the Chief Product Officer of Adentris, which builds AI for revenue integrity and documentation compliance in behavioral health and substance use disorder care.