Table of Contents
Ready to See Results?
From strategy through execution, Atlantic Health Strategies integrates compliance, operations, and growth into durable, measurable results. Let’s put our expertise to work for your organization.
The $18.4M Brooklyn case, in plain operator terms
If you own or operate a behavioral health center, the Brooklyn Total Rehab case is the exact enforcement pattern you need to reverse-engineer against your own operation this quarter. HHS-OIG is actively seeking a licensed physical therapist and clinic owner tied to roughly $18.4 million in fraudulent Medicare and Medicaid claims out of the Eastern District of New York, and the underlying conduct maps cleanly onto risks every SUD and mental health operator carries.
Here is what investigators say happened. Federal investigators say Lopez and others submitted or caused the submission of approximately $18.4 million in fraudulent reimbursement claims to Medicare and Medicaid. HHS-OIG says the claims included services that were not rendered, not medically necessary, not appropriately supervised, or performed by unlicensed people. Authorities say Lopez is wanted on charges including health care fraud, conspiracy to commit health care fraud, false claims, false statements related to health care matters, and falsification of records.
Read that list of allegations again, because every single one is something an operator-side compliance program should be catching before a payer or a federal agent does. Services not rendered. Notes that do not support medical necessity. Supervision gaps. Unlicensed rendering providers. If your PHP or IOP program cannot prove the opposite on demand, you have the same exposure profile, whether the dollar figure is $184,000 or $18.4 million.
Federal enforcement is not slowing down. It is accelerating.
Operators who still treat compliance as a back-office chore are misreading the trajectory of federal enforcement. In total, the collaboration between HHS-OIG and DOJ, as well as the Federal Bureau of Investigation and other state and local law enforcement agencies, is anticipated to recover $14.6 billion through criminal resolutions and seizures. HHS-OIG also reported a renewed emphasis on civil enforcement, noting that its investigations led to nearly 500 False Claims Act cases between April and September 2025.
The state layer is just as active. Medicaid Fraud Control Units, which investigate and prosecute statewide Medicaid provider fraud and beneficiary abuse and neglect, recovered $1.4 billion in FY 2024, which equates to $3.46 for every $1 spent. That is a return on investment number that guarantees your state MFCU is not going away. Read the MFCU FY2024 Annual Report if you have not.
The Brooklyn case is one file in a very large stack. In the same Eastern District, Brown-Arkah and his co-conspirators caused over $52 million in false claims to Medicare and Medicaid, and a jury convicted him of conspiracy to commit healthcare fraud, 12 counts of healthcare fraud, conspiracy to illegally distribute narcotics, 3 counts of illegal distribution of narcotics, conspiracy to pay and receive kickbacks and to defraud the United States, and 2 counts of receipt of kickbacks. Operators in Florida, Texas, South Carolina, Tennessee, Georgia, and every other state we work in should assume the same investigative playbook is being run near them.
What a real compliance program looks like inside a treatment center
A compliance binder on a shelf will not save you. What DOJ and OIG look for is a living program that generates evidence: chart audits with dates, corrective action plans with owners, utilization review notes tied to authorizations, and an accessible audit trail inside the EMR. When we do an operational audit at a treatment center, we are essentially pre-running the review that a federal investigator or MFCU auditor would run.
Concretely, here is what an operator should have running right now:
- Weekly hour verification for PHP (ASAM Level 2.5) and IOP (Level 2.1) before any claim goes out. If a patient did not hit the required weekly hours, the claim does not go out at that level of care. Full stop.
- Medical necessity documentation tied to ASAM Criteria 4th Edition dimensions and, where applicable, LOCUS scoring. Notes must actually support the level of care billed.
- Rendering provider verification. The person signing the note must be licensed, credentialed, and actually present for the service. The Brooklyn allegations of services performed by unlicensed people are exactly the trap that catches sloppy operations.
- A kickback and patient-brokering firewall. Marketing agreements, lab arrangements, sober living referrals, everything gets papered and reviewed against the Anti-Kickback Statute and Eliminating Kickbacks in Recovery Act.
- Documented corrective action plans for every issue an internal audit surfaces, with dates, owners, and evidence of closure.
None of this is theoretical. Our team at AHS just closed out a run of Joint Commission surveys across five facilities in three states, all accredited for three years. The through-line in every one of those surveys was the same: operators who could produce evidence of their own oversight, on demand, in the room. Surveyors, and federal investigators, both respond to that.
Where operators actually get exposed
In practice, the fraud cases that come out of the Eastern District of New York, the Southern District of Florida, and other active jurisdictions are not usually the result of one mastermind. They are the result of small documentation and control failures that compounded over years until the total loss amount hit a federal threshold. In FY 2024, HHS-OIG reported 1,548 criminal and civil enforcement actions against individuals and entities suspected of engaging in crimes targeting HHS programs and the people they serve, including settlements resulting from using OIG’s civil monetary penalty authorities and criminal convictions. HHS-OIG also excluded 3,234 individuals and entities from participation in Federal health care programs. Exclusion ends a career.
The recurring exposure points we identify in operational audits at behavioral health centers:
- PHP claims billed when the patient did not meet the weekly hour minimum required by the payer.
- IOP claims submitted before attendance was reconciled for the week.
- Group notes that are cloned across patients and cannot survive a payer takeback review.
- Marketing or admissions arrangements structured as per-head payments, which walks into EKRA and AKS territory fast.
- Utilization review teams that do not know the payer-specific definitions of the level of care they are defending.
- EMR configurations that let staff bill a session before a supervising clinician has signed the note.
Any one of these, at scale, produces the exact fact pattern the Brooklyn indictment describes. And when a federal takedown gets announced, the numbers are staggering. The Department of Health and Human Services, Office of Inspector General participated alongside key law enforcement partners in the 2024 Nationwide Health Care Fraud Enforcement Action, which resulted in criminal charges brought against 193 defendants, with intended losses exceeding $2.75 billion.
If you are heading to the Cape Cod Symposium in Providence, Sariah and I will be at Booth 402. Come by. If you want a candid read on where your current compliance program would land if OIG walked in tomorrow, that is a conversation worth having in person.
Frequently asked questions
What is the difference between a billing error and health care fraud?
Intent and pattern. A one-off coding mistake corrected on the next claim is a billing error. A repeated pattern of billing for services not rendered, not medically necessary, or delivered by unlicensed staff is what DOJ and HHS-OIG build cases around. The Brooklyn indictment specifically cites services that were not rendered, not medically necessary, not appropriately supervised, or performed by unlicensed people.
Does having a compliance officer protect the owner personally?
Not on its own. Owners and executives can face personal criminal liability when they knew, or should have known, that fraudulent claims were going out. A compliance officer without authority, budget, and direct access to leadership is a paper title. Regulators look for evidence that the compliance function actually functions: audit reports, corrective action plans, board or ownership reporting, and documented follow-through.
How often should a behavioral health operator run an internal chart audit?
At minimum quarterly for a sample across every level of care you bill, and continuously through concurrent utilization review. For any level of care where the payer mix or clinical model recently changed, run a targeted audit within 60 days of the change. If you have never had an outside operational audit, that is the first step.
What should an operator do immediately after seeing a case like the Brooklyn indictment?
Three things this week. First, pull a random sample of 20 charts across your billed levels of care and test whether the notes actually support medical necessity and the weekly hour minimums. Second, verify that every rendering provider on recent claims is licensed and credentialed with the payer. Third, review any marketing, lab, or referral arrangement against AKS and EKRA. If any of those three tests surface a gap, open a corrective action plan the same day.
References
- U.S. Attorney’s Office, Eastern District of New York, DOJ
- HHS-OIG Enforcement Actions
- HHS-OIG: Medicaid Fraud Control Units Fiscal Year 2024 Annual Report
- HHS-OIG Fall 2024 Semiannual Report to Congress
- DOJ Criminal Division: Health Care Fraud Unit
- CMS Fraud Prevention and Program Integrity
- Substance Abuse and Mental Health Services Administration (SAMHSA)
- ASAM Criteria, 4th Edition