# Enforcement in practice: audits, False Claims, and corporate integrity
In 2014, Community Health Systems, one of the largest hospital operators in the US, agreed to pay $98.15 million to settle claims that it billed government payers for inpatient admissions that should have been cheaper outpatient stays. No single fraudster orchestrated it. The problem was systemic: admission decisions that maximized reimbursement across hundreds of facilities. That case shows the enforcement machinery in motion, and why "compliance" is a balance-sheet issue, not paperwork.
This lesson walks through how that machinery actually works: who audits, how whistleblowers trigger cases, what the penalties look like, and why hospitals end up living under a Corporate Integrity Agreement.
Most enforcement starts with routine money getting clawed back, not dramatic fraud raids.
The core payer here is CMS (the Centers for Medicare & Medicaid Services), the federal agency that runs Medicare and co-runs Medicaid. CMS does not review every claim itself. It hires contractors.
A RAC requests medical records for a batch of claims. Say a hospital billed Medicare for 200 short inpatient stays. The RAC reviews the documentation and decides 60 of them did not meet inpatient criteria (the patient should have been "observation," an outpatient status that pays less).
Worked example. Assume each inpatient claim paid $9,000 and the correct outpatient rate was $3,000 (illustrative figures). The overpayment claimed:
60 claims x ($9,000 - $3,000) = $360,000 clawbackThe hospital can appeal, and many do, but the appeals process (through Administrative Law Judges) has historically had large backlogs. Meanwhile the money is often recouped first and returned later if the hospital wins.
The key concept auditors probe is medical necessity: was the service justified and documented? Bad documentation, not bad medicine, drives most clawbacks.
The False Claims Act (FCA) is the single most important enforcement tool against healthcare fraud in the US. Passed in 1863 (Civil War military fraud) and strengthened repeatedly, it lets the government recover money for false claims submitted to federal programs like Medicare.
Why it is feared:
Worked example. A hospital submitted 4,000 false claims causing $2 million in actual loss:
Treble damages: 3 x $2,000,000 = $6,000,000
Per-claim (low): 4,000 x ~$13,900 = $55,600,000
Potential exposure ~$61,600,000That is why settlements happen. The theoretical maximum is often financially fatal.
Here is the mechanism that surprises non-lawyers. Under the FCA's qui tam provision, a private individual (the "relator," usually an employee) can file a lawsuit on the government's behalf. If the case recovers money, the relator gets a share, typically 15 to 30 percent.
Do the math on incentives. If a relator's suit leads to a $61 million recovery, their award could exceed $9 million. That is why a coding manager, a nurse, or a former compliance officer has strong reason to report, and why hospitals cannot rely on silence.
The government's Department of Justice (DOJ) recovers billions annually under the FCA, and healthcare is consistently the largest category. See DOJ's own annual fraud statistics for the current numbers: DOJ False Claims Act statistics.
Most healthcare FCA cases rest on violations of two underlying statutes:
A tainted referral under AKS or Stark makes every resulting claim "false," which is how a compensation problem becomes a False Claims Act case.
The OIG (Office of Inspector General) within the Department of Health and Human Services is the watchdog. Its ultimate weapon is exclusion: barring a provider from billing Medicare and Medicaid at all. For most hospitals, exclusion is a death sentence, since government payers are a huge share of revenue.
Because exclusion is so extreme, the OIG usually offers an alternative when settling a case: the Corporate Integrity Agreement (CIA).
A CIA is a negotiated contract, typically five years, that lets the hospital keep billing in exchange for intensive oversight. Common obligations:
Miss a CIA deadline and there are stipulated penalties (pre-agreed fines per day of noncompliance). Serious breach can still trigger exclusion.
You can read actual CIAs, which are public, on the OIG Corporate Integrity Agreements page. Reading a real one makes the operational burden concrete.
Knowledge check
1. The Community Health Systems settlement involved billing government payers for inpatient admissions that should have been outpatient stays across hundreds of facilities. What does this case primarily illustrate about healthcare enforcement?
2. Why are Recovery Audit Contractors (RACs) described as 'aggressive by design'?
3. A hospital receives a UPIC referral rather than a routine RAC record request. Why does this represent a more serious situation?
4. Select ALL correct answers about the roles of CMS contractors in the enforcement machinery.
Select all the correct answers.
5. Select ALL correct answers about why most enforcement starts at the audit layer rather than with dramatic fraud raids.
Select all the correct answers.
Put the pieces together and the logic is clear.
1. A voluntary compliance program lowers penalties. Federal sentencing guidelines and OIG settlement practice both treat an effective compliance program as a mitigating factor. The OIG publishes guidance on the seven elements of an effective program (written standards, a compliance officer, training, auditing, reporting channels, enforcement, and response to problems). The updated General Compliance Program Guidance is on the OIG's compliance guidance page.
2. Self-disclosure beats getting caught. The OIG runs a Self-Disclosure Protocol. A hospital that finds its own overpayment and reports it typically pays a lower multiplier (often around 1.5x damages) than the treble damages it would face in litigation. Finding your problem first is cheaper than a relator finding it.
3. The 60-day rule creates urgency. Under the Affordable Care Act, once a hospital identifies an overpayment, it must report and return it within 60 days. Sitting on a known overpayment can itself become a False Claims Act violation. This turns compliance from optional into a legal clock.
Here is how a typical hospital case unfolds:
1. A RAC or internal audit flags a billing pattern (for example, systematically upcoding).
2. A concerned employee, ignored internally, files a qui tamtamTotal Addressable Market: the total revenue opportunity if you captured 100% of potential customers in your target market.View full definition → suit.
3. DOJ investigates, often quietly, for months or years.
4. Facing treble damages and per-claim penalties, the hospital settles.
5. The OIG imposes a five-year CIA as a condition of not being excluded.
6. The hospital now pays for an IRO, a compliance team, and annual reporting for years.
Every step is cheaper to prevent than to remediate. A compliance program is the insurance premium against steps 3 through 6.
Europe lacks a direct FCA equivalent, but the direction of travel is similar. National health systems and insurers pursue billing fraud through criminal and administrative law, and the EU's anti-fraud office OLAF investigates misuse of EU funds. Individual countries (Germany, France, the UK) have their own healthcare fraud units. The core lesson (documentation and referral integrity) travels across borders even where the specific statutes do not.