The first half of 2026 has confirmed that False Claims Act (FCA) enforcement is not only continuing at historically elevated levels but is expanding in scope, sophistication, and institutional backing. With the Department of Justice (DOJ) reporting more than $6.8 billion in FCA settlements and judgments for fiscal year 2025 (the highest annual total on record) and qui tam filings on pace to set another record in FY 2026, federal fund recipients across various industries face a sustained period of heightened scrutiny. This mid-year update synthesizes the most significant developments and offers practical considerations for navigating the current enforcement landscape.
Record Recoveries and a Growing Enforcement Pipeline
DOJ’s record-setting $6.8 billion in FCA recoveries for FY 2025 marked a significant increase from three prior consecutive years in which total recoveries ranged from $2.2 billion to $3.1 billion. Healthcare-related recoveries accounted for more than $5.7 billion of the total—83% of all FCA recoveries—returning to the historical pattern after two years of a lower share attributable to COVID-era fraud investigations. At the same time, defense industry recoveries surged to nearly $634 million, up from $98 million in FY 2024.
These figures reflect more than a one-year spike. The volume of qui tam filings, new enforcement infrastructure, and DOJ’s stated priorities collectively indicate a sustained pipeline of investigations and enforcement actions. Federal fund recipients—particularly in healthcare, defense contracting, and government grants—should anticipate continued scrutiny of claims for payment and compliance certifications.
The enforcement trajectory has implications for resource planning, compliance, and litigation preparedness across industries that receive federal funds.
Key Developments and Enforcement Trends
1. New Enforcement Infrastructure and Interagency Coordination
Early in 2026, the government established a new fraud enforcement division and a White House-level task force designed to coordinate FCA cases across agencies. These structural changes build on the DOJ-HHS FCA Working Group announced in July 2025, which brought together leadership from DOJ’s Civil Division, HHS Office of General Counsel, CMS, and the HHS Office of Inspector General to streamline investigations, accelerate case referrals, and leverage data analytics to identify fraud.
The practical significance of these developments is that enforcement priorities increasingly define what conduct is characterized as “fraud” under the FCA. Familiar legal tools (contract certifications, compliance attestations, grant conditions) are being applied to new categories of conduct. Businesses that interact with federal programs, grants, or contracts should expect broader scrutiny of how they meet, certify, and document their obligations.
2. Trials, Verdicts, and the Litigation Calculus
In March 2026, a jury found a defense contractor liable in an FCA case arising from Afghanistan war contracting. While the jury rejected certain claims, it found the company had failed to meet property management obligations. The case is notable not only for its verdict—a significant partial victory for the defense—but for the substantial financial costs that nevertheless followed, including disputes over legal fees that underscored the financial exposure defendants face even in partially favorable outcomes. The case is a reminder that FCA trials generate substantial litigation expenses, consume senior leadership attention, and create fee-shifting risks that extend well beyond the verdict itself. When modeling risk and establishing reserves in FCA matters, organizations should account for the full spectrum of potential costs: investigation expenses, document production and e-discovery, litigation costs, potential settlement or judgment amounts, and post-verdict fee disputes.
3. Expanding Certification-Based Theories of Liability
A recurring pattern in 2026 FCA enforcement actions is the government’s use of certification-based theories of liability. The analytical framework is consistent across cases: identification of a required certification—whether in a contract, invoice, or compliance attestation—identification of its connection to payment eligibility, and investigation into whether an alleged underlying deficiency in eligibility constitutes a knowing misrepresentation under the FCA.
In 2026, DOJ has pursued certification-based FCA cases across several areas, including:
- Operational compliance, including quality controls and performance requirements in government contracts.
- Workplace and civil rights certifications, including employment practices and anti-discrimination attestations in federal contracts.
- Cybersecurity compliance, including security controls, breach reporting, and adherence to standards such as NIST SP 800-171 and CMMC.
In many businesses, certification risk is not confined to any single department, as contracting officers, human resources, IT security, and operations teams can all make representations that could become the basis of an FCA case. Organizations should ensure cross-functional visibility into every certification or attestation that is linked to government payment or program eligibility.
A prudent step is to map every point at which the organization makes payment-linked representations to the government, identify who within the organization owns the underlying facts, and confirm that those facts are accurate and adequately documented.
4. Data-Driven Whistleblowers and DOJ’s FOCUS Initiative
In April 2026, DOJ announced the Fraud Oversight through Careful Use of Statistics (FOCUS) Initiative, a program designed to help the government assess the viability of data-driven qui tam cases. The initiative responds to a significant shift in the qui tam landscape: since FY 2024, “data miners” (individuals or entities analyzing publicly available government datasets for statistical anomalies they claim indicate fraud) have filed more than 45% of all qui tam complaints. Over 780 qui tam complaints were filed in the first quarter of FY 2026 alone, on pace for another record year.
The FOCUS Initiative has important implications for both healthcare companies and government contractors:
- Healthcare providers andentities should anticipate increased scrutiny of billing patterns, coding intensity, and risk adjustment practices, particularly where statistical analysis could identify anomalies.
- Government contractors should recognize that award data, subcontracting patterns, and pricing anomalies are subject to data-driven analysis by potential relators.
For organizations receiving federal funds, robust compliance programs and clear documentation of legitimate business rationales are essential. If data patterns appear anomalous, entities should ensure they can explain them because the FOCUS Initiative makes clear that DOJ is actively evaluating such patterns during sealed qui tam investigations.
5. AI, Technology, and Emerging Fraud Theories
AI-Assisted Documentation in Healthcare
As AI tools become embedded in medical coding and clinical documentation workflows, the FCA risk is not necessarily the use of AI itself but rather the deployment of AI at scale without adequate validation and error-monitoring protocols.
Organizations that use AI to generate outputs affecting government billing should implement controls to validate accuracy and establish processes to identify and correct error patterns. The failure to do so risks creating a body of evidence that could be argued to support scienter—a critical element of FCA liability—by demonstrating that the organization deployed tools it knew or should have known were generating inaccurate claims.
Cybersecurity Compliance
DOJ continues to pursue FCA cases against entities that billed the government while failing to meet required cybersecurity obligations or making inaccurate statements about their security controls. Through the Civil Cyber-Fraud Initiative, DOJ has targeted contractors and grantees who misrepresent cybersecurity compliance, provide products with known vulnerabilities, or fail to report cyber incidents as required by contract.
Risk assessments, security exceptions, and escalation decisions are all potential evidence in a cybersecurity-based FCA case. False certifications of compliance can carry FCA liability risk even absent a proven data breach.
Both AI governance and cybersecurity compliance should be treated as FCA risk areas, not peripheral IT concerns. Organizations should document their validation processes, maintain records of how known gaps are identified and addressed, and ensure that compliance representations accurately reflect their security posture.
6. Constitutional Challenges to the FCA’s Qui Tam Provisions
Amid this expanding enforcement activity, defendants have increasingly challenged the constitutional foundation of the FCA’s qui tam device itself. These constitutional challenges have gained some traction. Since the district court’s decision in United States ex rel. Zafirov v. Fla. Med. Assocs., LLC, which held that the FCA’s qui tam provisions violate Article II’s Appointments Clause, a number of judges, including some United States Supreme Court Justices, have questioned whether qui tam relators can lawfully prosecute claims on the government’s behalf. The United States Court of Appeals for the Eleventh Circuit heard argument in the Zafirov appeal but has not yet rendered a decision, and the Third Circuit is positioned to consider the issue as well.
However, it should be noted that most courts continue to uphold the FCA’s qui tam provisions against constitutional challenges. And even if constitutional challenges ultimately succeed in some circuits or at the United States Supreme Court, the government retains its independent enforcement authority.
Practical Considerations
In light of these developments, anyone subject to potential FCA investigation or enforcement activity may wish to evaluate the following areas:
- Review certifications and representations. Organizations may benefit from identifying each point at which they make representations to the government linked to payment or program eligibility and periodically reviewing whether the facts underlying those statements are documented, accurate, and current.
- Consider data-driven scrutiny. Given the rise of data-mining relators and the FOCUS Initiative, organizations, persons, and providers in healthcare, government contracting, and other sectors receiving federal funds may reasonably assume that billing patterns, coding practices, and contracting data could be subject to external analysis.
- Evaluate AI and cybersecurity compliance. As enforcement activity in these areas increases, AI governance and cybersecurity should be integrated into compliance programs, with validation, monitoring, and remediation processes that are documented and auditable.
- Assess trial readiness. In FCA cases proceeding to trial, organizations may want to ensure that litigation strategy, budgets, and leadership availability account for the possibility of extended proceedings and unanticipated expenses.
- Follow constitutional developments. The ongoing challenges to the FCA’s qui tam provisions may alter litigation dynamics. Staying informed of these developments and understanding their potential implications can help preserve strategic flexibility, while recognizing that enforcement activity is likely to continue regardless.
Conclusion
The first half of 2026 reflects an FCA enforcement environment shaped not only by the scale of recoveries but also by the breadth of enforcement theories, the evolving tools available to the government, and the institutional infrastructure supporting enforcement activity. The combination of elevated numbers of qui tam filings, new interagency coordination mechanisms, data-driven whistleblower activity, and expanding certification-based theories of liability suggests that enforcement will remain a significant feature of the regulatory landscape.
Husch Blackwell’s False Claims Act practice will continue to monitor these developments and provide updates as the enforcement landscape evolves.