Fraud Unit Under Pressure; AI Watching Claims: What NY Providers Should Know

Together, these developments point toward a more aggressive New York Medicaid enforcement environment.


Glenn M. Jones
Best Lawyers logo

Glenn M. Jones

October 2, 2026 01:06 PM

New York Medicaid providers are facing a convergence of two enforcement developments. First, the U.S. Department of Health and Human Services Office of Inspector General (“HHS-OIG”) has denied recertification of the New York State Medicaid Fraud Control Unit (“MFCU”) and suspended a substantial share of its federal grant funding, with a corrective action deadline arriving September 30, 2026. Second, the U.S. Department of Justice (“DOJ”) and the Centers for Medicare & Medicaid Services (“CMS”) have expanded their use of artificial intelligence and advanced data analytics to detect Medicaid and Medicare fraud, including in at least one prosecution reaching New York providers directly.

Together, these developments point toward a New York Medicaid enforcement environment in which the state’s primary fraud unit faces external pressure to increase criminal case output while the government’s underlying detection tools become more automated and more far-reaching.

HHS-OIG Denies the New York MFCU’s Recertification

By letter dated June 30, 2026, HHS-OIG denied the New York MFCU’s application for annual recertification and suspended the unit’s federal grant, effective July 1, 2026, through September 30, 2026, the end of the unit’s current grant period. Because recertification is a statutory precondition to federal funding under the Social Security Act §§ 1903(a)(6) and (q) and 42 C.F.R. § 1007.19(d)(1), the denial suspends federal reimbursement for the unit’s statutory functions unless, and until, the unit is recertified.

  • HHS-OIG found the New York MFCU to be the lowest-performing unit among similarly sized state units (California, Texas, Ohio and Florida) for both Medicaid fraud and patient abuse and neglect enforcement from 2023 to 2025, citing, among other metrics, only 53 fraud convictions and as few as 7 to 9 annual criminal indictments over that period.
  • HHS-OIG attributed the unit’s performance to a leadership decision to prioritize “high-impact, complex” civil fraud cases over criminal fraud and patient abuse and neglect cases, and identified deficiencies under four MFCU performance standards: staffing mix, referral generation (particularly from Medicaid managed care organizations), case progression (34 percent of open cases are more than three years old), and cooperation with HHS-OIG’s Office of Investigations.
  • The corrective action conditions require the unit to submit staffing, referral, case-progression and cooperation plans within 30 days of the letter and progress reports within 90 days, including a written strategy to increase criminal indictments.
  • If the Unit demonstrates sufficient corrective action by September 30, 2026, the suspension may be lifted; if not, recertification remains denied and HHS-OIG will not award the unit’s federal grant funds for FY 2027.

This is not an isolated action. HHS-OIG denied recertification to Hawaii’s MFCU in early June 2026 and has stated it will apply heightened scrutiny to MFCU performance nationally going forward. For New York providers, the practical significance of the denial is less the funding dispute itself than its likely effect on the unit’s investigative posture: a unit under an explicit federal directive to “establish a written strategy to increase indictments” ahead of a fixed, near-term deadline has an institutional incentive to move pending matters toward criminal charging decisions more quickly than it has in recent years, renew the unit’s focus on nursing home patient abuse and neglect cases, and to lean more heavily on managed care organization referrals and data-driven leads to do so.

DOJ and CMS Deploy AI and Advanced Analytics Against Claims Data

The recertification denial arrived one week after DOJ and HHS announced the results of the 2026 National Health Care Fraud Takedown on June 23, 2026, which charged 455 defendants in connection with more than $6.5 billion in alleged fraud across 56 federal districts, with participation by all 50 state MFCUs. The Takedown included the largest number of Medicaid fraud defendants in department history (295 defendants, over $518 million in alleged false claims) and highlighted DOJ’s growing reliance on automated detection tools.

  • DOJ’s Fraud Division and CMS announced an agreement allowing the Fraud Division cloud computing space within CMS’s Integrated Data Repository to deploy advanced data analytics algorithms and artificial intelligence tools directly against Medicare and Medicaid claims data.
  • DOJ highlighted a multi-agency Data Fusion Center (DOJ’s Data Analytics Team, HHS-OIG and the FBI) and a Financial Intelligence Review Team that pairs claims analytics with financial transaction tracing, and reported the Fusion Center’s first prosecution: a $67 million Illinois Medicaid behavioral health scheme identified through implausible billing volumes.
  • New York providers were charged using this analytic approach in this Takedown. In the Eastern District of New York, eight defendants were charged in an alleged $38 million fraud on New York Medicaid involving social adult day care services, where DOJ alleged providers billed for hundreds of beneficiaries per day at facilities with a permitted occupancy of only 30 people — a mismatch between billed volume and physical capacity that claims analytics are designed to expose.

CMS’s own public description of the effort reflects the same direction. At the Takedown announcement, CMS Administrator Dr. Mehmet Oz said the agency intends to identify and freeze suspicious Medicaid and Medicare payments before they are issued, rather than pursue recovery only after a fraudulent claim has been paid, consistent with the Fraud Division-CMS data-sharing arrangement described above.

What This Means for New York Providers

Read together, these two developments point in the same direction for New York Medicaid and Medicare providers: more automated detection feeding into a state fraud unit under explicit federal pressure to close cases and increase indictments before a fixed deadline. A provider with accurate billing but poor data hygiene, or a legitimate statistical outlier, can be swept into that environment before any evidence of wrongdoing exists.

Compliance programs organized around periodic policy attestations alone do not address this risk; programs organized around continuous internal analytics, documentation integrity, and inquiry-response readiness do. This state-level exposure is not limited to the MFCU. The New York State Office of the Medicaid Inspector General (OMIG’s ) 2026 Work Plan describes its own Pre-Payment Review process, under which OMIG identifies aberrant billing through analysis of post-payment reports, data mining, and referrals, then pends the claim for review before payment issues, and confirms that OMIG will continue referring Medicaid fraud allegations to the MFCU and its other law enforcement partners. OMIG describes this work as data mining and advanced analytics rather than artificial intelligence, but the practical effect for a New York provider is the same pre-payment, referral-driven exposure described above at the federal level, operating in parallel at the state level.

What Should Providers Do?

Providers should consider the following measures:

  • Know your own statistical profile. Periodically benchmark coding level distributions, utilization per beneficiary, services per day per rendering provider, modifier usage and telehealth volume against specialty and regional norms, and document the clinical explanation for any legitimate outlier before an inquiry arrives.
  • Eliminate data-integrity problems that manufacture false anomalies. Confirm accurate rendering-provider attribution, current credentialing and enrollment records, discipline in time-based coding, Electronic Visit Verification compliance and documentation that supports the code billed.
  • Direct internal audit resources toward the categories the government has publicly identified as priorities and add capacity-plausibility checks comparing billed volume to staffing and physical capacity. Those services include telehealth, durable medical equipment, genetic testing, behavioral health, social adult day care and other community-based services, home health and personal care and pharmacy billing.
  • Build the inquiry-response posture in advance. Designate a response team and protocol for pended claims, comparative billing letters and MFCU or OMIG record requests, and involve counsel early enough that internal reviews are conducted under privilege.
  • Treat self-disclosure as the release valve. Federal law requires identified overpayments to be reported and returned within 60 days. Maintain a counsel-directed protocol for quantifying, repaying and evaluating disclosure through OMIG’s Self-Disclosure Program, where appropriate.

On the inquiry-response point, in United States v. Heppner, 820 F. Supp. 3d 292 (S.D.N.Y. 2026), the court held that documents an individual generated using a consumer AI platform, in connection with a pending criminal investigation and outside the direction of counsel, were protected by neither the attorney-client privilege nor the work product doctrine. That holding is expressly limited to the criminal-investigation context in which it arose, and at least one New York trial court has since declined to extend it to a civil discovery dispute. In Assini v. Hayward, 2026 N.Y. Slip Op. 26086 (Sup. Ct., Nassau County, June 4, 2026), the court quashed a subpoena seeking a pro se litigant’s AI communications, holding that those communications could be protected as work product notwithstanding the AI platform’s data-collection practices, and expressly following Morgan v. V2X, Inc. No. 25–CV–01991–SKC–MDB (D. Colo. Mar. 30, 2026), which distinguished Heppner as a criminal matter. The law in this area is unsettled rather than uniform. Personnel should nonetheless be instructed that self-directed use of AI tools to analyze billing questions or investigation-related matters during an active or anticipated inquiry creates a real risk of disclosure, particularly in a criminal or agency-investigation posture like an OMIG or MFCU matter, and should occur, if at all, only under counsel’s direction.

How Harris Beach Murtha Can Help

Harris Beach Murtha’s Government Compliance and Investigations Practice Group and Health Care Industry Team are following the New York MFCU’s corrective action process and the government’s expanding use of AI-driven fraud detection and will report on significant developments. If you are a Medicaid or Medicare provider and need assistance with this or related matters, please reach out to attorney attorney Glenn M. Jones at (516) 880-8494 and gjones@harrisbeachmurtha.com; attorney Selma Al Taii at (585) 419-8793 and saltaii@harrisbeachmurtha.com; or the Harris Beach Murtha attorney with whom you most frequently work.

For other health care regulatory, operational or compliance questions, Harris Beach Murtha’s Health Care Industry Team brings together attorneys with expertise across the full range of health care topics and is available as a resource. For broader questions on artificial intelligence governance, risk and strategy outside the health care enforcement context, Harris Beach Murtha’s Artificial Intelligence Industry Team is also available as a resource.

This alert is not a substitute for advice of counsel on specific legal issues.

Harris Beach Murtha’s lawyers and consultants practice from offices throughout Connecticut in Bantam, Hartford, New Haven and Stamford; New York State in Albany, Binghamton, Buffalo, Ithaca, New York City, Niagara Falls, Rochester, Saratoga Springs, Syracuse, Long Island and White Plains; as well as in Boston, Massachusetts; Providence, Rhode Island. and Newark, New Jersey.