A $4.3 Billion Problem Hiding in Plain Sight
In 2023, the Department of Justice recovered over $2.2 billion in settlements and judgments related to healthcare fraud. That wasn't an outlier — it was a slow year. HHS estimates that fraud drains between $100 billion and $300 billion from the U.S. healthcare system annually, and every dollar stolen intersects with protected health information in ways most compliance teams underestimate.
If you work in HIPAA compliance, you need a precise definition of fraud in healthcare — not the vague textbook version, but the operational one. The one that tells you what to watch for in your own organization. The one that explains why a billing clerk's shortcut can turn into a federal indictment and a simultaneous OCR investigation.
That's what this post delivers. No fluff. Just the framework your team needs to recognize fraud, understand where it overlaps with HIPAA, and build defenses that actually work.
The Definition of Fraud in Healthcare — Straight From Federal Law
Under 18 U.S.C. § 1347, healthcare fraud is defined as knowingly and willfully executing, or attempting to execute, a scheme to defraud any healthcare benefit program — or to obtain money or property from any healthcare benefit program through false or fraudulent pretenses, representations, or promises.
The key word is knowingly. Honest billing mistakes aren't fraud. But the moment someone intentionally misrepresents a service, a diagnosis, or a patient's identity to extract payment, they've crossed the line.
In my experience, most compliance officers understand this in the abstract. Where things break down is in recognizing how fraud manifests inside their own workflows — and how it drags HIPAA into the picture.
What Counts as Healthcare Fraud? A Quick Reference
- Upcoding: Billing for a more expensive service than what was actually provided.
- Unbundling: Submitting separate bills for services that should be billed as a package.
- Phantom billing: Charging for services never rendered.
- Kickbacks: Receiving payment for patient referrals, violating the Anti-Kickback Statute.
- Identity theft: Using a patient's PHI to submit false claims.
- Falsifying medical records: Altering documentation to justify unnecessary services.
Each of these involves PHI. Every single one. That's the connection most people miss.
Where Healthcare Fraud and HIPAA Collide
Here's what I tell every client: fraud doesn't happen in a vacuum. To commit healthcare fraud, someone almost always has to access, misuse, or fabricate protected health information. That means a fraud scheme is frequently a HIPAA violation too — sometimes several violations stacked on top of each other.
Consider a real scenario I've consulted on. A mid-level employee at a covered entity accessed patient records they had no treatment relationship with, then used those records to generate phantom claims. That single act triggered violations of the HIPAA Privacy Rule (unauthorized access to PHI), the Security Rule (failure of access controls), and federal fraud statutes simultaneously.
OCR has made it clear that when fraud involves PHI, they will investigate the HIPAA angle independently of any DOJ prosecution. You can face criminal fraud charges and civil HIPAA penalties from the same set of facts.
The Enforcement Case That Should Keep You Up at Night
In 2018, OCR settled with Anthem Inc. for $16 million following a massive data breach that exposed ePHI of nearly 79 million individuals. While the Anthem case centered on a cyberattack rather than internal fraud, it demonstrated OCR's willingness to impose record-setting penalties when organizations fail to implement adequate safeguards — the same safeguards that prevent insider fraud. You can review OCR's enforcement actions on the HHS breach portal and resolution agreements page.
The lesson: if your access controls, audit logs, and workforce training can't detect an insider committing fraud, OCR will hold you accountable for the HIPAA failures that made it possible.
Why Your HIPAA Risk Analysis Must Account for Fraud
Most HIPAA risk analyses I review focus on external threats — hackers, ransomware, lost laptops. Those are real risks. But they're only half the picture.
The definition of fraud in healthcare should inform your risk analysis directly. Internal fraud is an insider threat. It requires access to ePHI systems. It exploits weak audit controls. And it thrives in organizations where workforce members aren't trained to spot it.
Three Controls That Stop Fraud and Satisfy HIPAA
1. Role-based access controls. The HIPAA Security Rule requires you to implement policies that grant access to ePHI only as needed. If a billing clerk can pull up any patient record in your system, you've created an environment where fraud becomes easy. Restrict access by role. Review those permissions quarterly.
2. Audit logging and review. Having audit logs isn't enough — you have to actually review them. I've seen organizations with beautiful logging infrastructure that nobody looks at for months. Set up automated alerts for unusual access patterns: after-hours logins, bulk record views, access to records outside a user's department.
3. Workforce training that covers fraud indicators. Your annual HIPAA training should include real examples of healthcare fraud and teach staff how to report suspicious activity. Generic slide decks won't cut it. Your team needs scenario-based training that connects the dots between PHI misuse and fraud. Our HIPAA training catalog includes modules designed to build exactly this kind of awareness.
The Role of the Compliance Officer in Fraud Prevention
If you're the privacy or compliance officer at a covered entity or business associate, fraud prevention sits squarely within your responsibilities — whether your job description says so or not. Here's why.
OIG's compliance guidance for healthcare organizations explicitly recommends that compliance programs address fraud, waste, and abuse. And since HIPAA's Administrative Simplification provisions were partly designed to combat fraud in the first place, there's no separating the two mandates.
In practice, this means your compliance program should include:
- A clear policy defining what constitutes healthcare fraud and the consequences for committing it.
- A confidential reporting mechanism — a hotline, an anonymous form, something accessible.
- Regular audits of billing practices, access logs, and documentation integrity.
- A documented investigation process for reported concerns.
- Annual workforce training that explicitly addresses both HIPAA compliance and fraud awareness.
If you're looking to strengthen your organization's training program, explore the options available in our comprehensive HIPAA training catalog. Building fraud awareness into your HIPAA education isn't optional anymore — it's a regulatory expectation.
What Is Healthcare Fraud Under Federal Law?
Healthcare fraud is the intentional misrepresentation or deception used to obtain unauthorized benefits or payments from a healthcare program. Under 18 U.S.C. § 1347, it includes any scheme to defraud a health benefit program through false pretenses. Penalties can include fines up to $250,000, imprisonment up to 10 years (or 20 years if the fraud results in serious bodily injury), and exclusion from federal healthcare programs. When fraud involves protected health information, it can also trigger HIPAA enforcement actions from HHS Office for Civil Rights.
The False Claims Act Connection
Most healthcare fraud prosecutions rely on the False Claims Act (31 U.S.C. § 3729), which allows the government — and private whistleblowers — to pursue anyone who knowingly submits false claims to federal healthcare programs like Medicare and Medicaid.
The False Claims Act is devastatingly effective. Whistleblowers (called "relators") can receive between 15% and 30% of whatever the government recovers. That creates a powerful financial incentive for your own employees to report fraud they witness internally.
I've seen this dynamic play out repeatedly. An employee notices suspicious billing patterns, reports internally, gets ignored, and then files a qui tam lawsuit. The organization ends up paying millions in settlements, plus faces an OCR investigation into related HIPAA failures. The entire chain of events could have been stopped with a functioning compliance program.
Building a Culture That Catches Fraud Before OCR Does
The organizations I work with that successfully prevent fraud share a few traits. They don't just have policies — they enforce them. They don't just train once — they reinforce throughout the year. And they don't treat compliance as a department — they treat it as a culture.
Start here:
- Make fraud awareness part of onboarding, not just annual training.
- Publicize enforcement actions internally — when HHS announces a settlement, share it with your team.
- Reward reporting. Make it safe and easy for employees to raise concerns.
- Conduct periodic billing audits using external reviewers who have no internal loyalties.
- Tie access control reviews to your HIPAA Security Rule risk analysis — they're the same project.
The definition of fraud in healthcare isn't academic. It's a operational reality that every covered entity and business associate confronts, whether they realize it or not. The question is whether you'll detect it internally or learn about it from a federal investigator.
Your Next Step
If your workforce training doesn't explicitly cover the intersection of HIPAA and healthcare fraud, you have a gap. And gaps get exploited — by bad actors inside your organization and by regulators after the damage is done. Browse our HIPAA training catalog to find courses that address both compliance and fraud prevention in a single, practical curriculum.
Don't wait for an OIG audit or an OCR investigation to find out what your team doesn't know.