Table of Contents
Ready to See Results?
From strategy through execution, Atlantic Health Strategies integrates compliance, operations, and growth into durable, measurable results. Let’s put our expertise to work for your organization.
The short answer for buyers
Buyers who skip pre-close compliance diligence in behavioral health inherit the seller’s False Claims Act exposure, licensure defects, and payer clawbacks, and they generally have only six months from closing to self-report criminal misconduct under the DOJ’s Mergers and Acquisitions Safe Harbor Policy. Miss that window, and the acquirer owns the problem.
Under the policy announced by then-Deputy Attorney General Lisa Monaco on October 4, 2023, an acquirer gets a presumption of declination only if it promptly and voluntarily self-reports criminal misconduct, cooperates with the ensuing investigation, and remediates, within six months of closing (disclosure) and one year of closing (remediation), regardless of whether the misconduct was discovered pre- or post-acquisition. Monaco framed the intent plainly: DOJ wants “to incentivize the acquiring company to timely disclose misconduct uncovered during the M&A process.”
I watched a Florida deal die at the eleventh hour because the buyer’s quality-of-earnings team caught upcoded PHP claims the seller had never flagged. The seller thought the letter of intent was the finish line. It was the starting gun.
The enforcement backdrop buyers keep underestimating
The dollar figures are not abstractions. On January 16, 2026, DOJ announced that False Claims Act settlements and judgments exceeded $6.8 billion in fiscal year 2025, the highest single-year total in the statute’s history, with 1,297 qui tam lawsuits filed (also a record) and 401 new government investigations opened. Of that total, over $5.7 billion related to matters that involved the health care industry. Deputy Attorney General Todd Blanche put it directly: “Stopping rampant fraud is a top priority, and this record-breaking year proves the False Claims Act remains one of the government’s most powerful weapons against fraud.”
Behavioral health sits squarely in the crosshairs. In the June 2026 National Health Care Fraud Takedown, DOJ charged 455 defendants across 56 federal districts and 45 states in schemes involving over $6.5 billion in false claims, with 50 state Medicaid Fraud Control Units participating, the most in Department history. Two of the takedown’s headline cases went straight to behavioral health operators.
In the Eastern District of Virginia, Mikia Noble, the Chief Operating Officer of Advancing Communities Everywhere, was charged by information with conspiracy to commit health care fraud tied to approximately $49.6 million in false Medicaid claims, of which roughly $38.6 million was paid. The charging documents allege improper “Team Treatment” HT-modifier billing (used on a large majority of crisis claims even though only a single QMHP was present), altered progress notes (including one signed for a session on a date the defendant was on an international flight), and kickbacks paid through an affiliated nonprofit in the form of hotel stays to recruit homeless Medicaid recipients. In the District of Arizona, a separate defendant was charged with submitting $44 million in fraudulent behavioral-services claims that primarily targeted Native Americans struggling with substance abuse.
If a buyer had signed an LOI on that Virginia operator six months earlier without a claims-level chart audit, they would be sitting in a DOJ interview room right now.
Successor liability is not a theoretical risk
Deal lawyers love to structure around it. Prosecutors have gotten better at cutting through the structure. Baker Botts, analyzing the Safe Harbor Policy, warns that the policy applies only to “bona fide, arms-length M&A transactions” and that companies that do not perform effective due diligence or self-disclose misconduct will be subject to full successor liability under the law.
What that means for behavioral health buyers in Florida, Texas, Tennessee, and Arizona (the states where I see the most deal flow): an asset purchase agreement does not scrub Medicaid overpayment liability. CMS and state Medicaid Fraud Control Units follow the NPI, the taxpayer ID, and the corporate parent.
The coordination is not theoretical either. Of the 455 defendants charged in the 2026 takedown, 295 (nearly two-thirds) were charged with Medicaid fraud involving over $518 million in alleged false claims, the largest number of Medicaid fraud defendants and the largest Medicaid loss amount charged in Department history. Alongside the criminal charges, CMS suspended 1,079 providers, revoked billing privileges for 1,403 providers, and HHS-OIG pursued over 1,400 exclusions and Civil Monetary Penalties Law actions seeking more than $10 billion. That is the enforcement machine a behavioral health buyer inherits when diligence is thin.
What real pre-close compliance diligence looks like
Financial diligence tells you what the seller booked. Compliance diligence tells you whether they were allowed to book it. Buyers who conflate the two lose money after close.
Here is what my team runs before a PE-backed buyer signs a definitive agreement on a treatment center:
- Licensure and accreditation file review. Every state license, every CARF or Joint Commission survey report, every corrective action plan, every LegitScript status. Findings, CAPs, and surveyor focus in the last survey window matter more than the certificate on the wall.
- Claims-level chart audit. Not a sample of ten. A statistically defensible pull across payers and levels of care, mapped against ASAM Criteria 4th Edition medical necessity documentation. This is where upcoding, unbundling, and PHP claims billed as something else surface.
- UM and payer file review. Denials, appeals, single-case agreements, SIU audit history, timely filing patterns. If the seller has an open payer SIU audit they did not disclose, you will find it here.
- 42 CFR Part 2 and HIPAA posture. Access controls, termination workflows, breach log, business associate agreements.
- Marketing and referral source review. Anti-Kickback Statute exposure lives in the marketing budget, not the P&L line labeled “kickbacks.” The Virginia and Arizona takedown cases both centered on inducement schemes hidden inside outreach.
The Whiteford analysis of the Richmond indictment lays out the pattern surveyors and prosecutors are now looking for: behavioral health agencies, crisis service providers, and practices that rely on team-based billing or contract clinicians may have particular reason to examine how their documentation and coding would hold up to the kind of data-driven review the Department is now applying. That “data-driven review” is not hypothetical. DOJ announced the first prosecution arising from the Health Care Fraud Unit’s Data Fusion Center, whose Financial Intelligence Review Team detected an alleged $67 million scheme to bill Illinois Medicaid for behavioral health services that were never provided.
The six-month clock and what to do with it
If diligence uncovers criminal misconduct at the target, the buyer has a decision to make, and the calendar is unforgiving. Sidley’s read of the Safe Harbor Policy is blunt: if the misconduct is identified five months after the closing date, the acquiring company would arguably have just one month to voluntarily self-disclose under the Safe Harbor Policy.
What that looks like in practice for a behavioral health buyer: pre-close diligence findings feed a Day 1 integration plan, compliance leadership is embedded in the first 30 days, a claims re-audit is scheduled inside 90 days, and counsel has a self-disclosure decision framework ready before the ink dries.
The buyers who treat compliance as a checklist item at the end of diligence are the same buyers I get calls from 14 months post-close, when the SIU letter arrives or the state health department opens a complaint investigation. By then, the safe harbor window has closed and the earnout is gone. Buyers who invest 60 to 90 days in real pre-close compliance diligence almost never need me for the turnaround work. That is the return on this spend.
Frequently asked questions
How long does a behavioral health buyer have to self-disclose misconduct discovered in diligence?
Six months from the closing date to disclose, and one year from closing to fully remediate, under the DOJ’s October 4, 2023 M&A Safe Harbor Policy. Sidley notes the clock runs whether the misconduct was discovered pre- or post-acquisition, so if it surfaces five months after closing the buyer arguably has one month left to self-disclose. DOJ may extend both deadlines depending on the specific facts and complexity of the transaction, but buyers should not plan around extensions.
Does an asset purchase structure protect a buyer from the seller’s False Claims Act liability?
Not reliably. Baker Botts, summarizing DAG Monaco’s remarks, notes the Safe Harbor Policy applies only to bona fide, arms-length M&A transactions and that companies that fail to perform effective due diligence or self-disclose misconduct will be subject to full successor liability under the law. Structuring helps, but focused compliance diligence, indemnification, escrow, and where appropriate rep and warranty insurance do the real risk allocation work, particularly where the buyer continues operating under the same NPI, provider agreements, or corporate footprint.
What specific behavioral health compliance risks should pre-close diligence prioritize?
Medical necessity documentation against ASAM Criteria 4th Edition, PHP and IOP claims accuracy, UM denial and appeal patterns, marketing and referral relationships (Anti-Kickback exposure), 42 CFR Part 2 and HIPAA controls, state licensure standing, accreditation survey findings and CAPs, and any open payer SIU audits or state Medicaid Fraud Control Unit inquiries. The June 2026 takedown showed DOJ actively targeting team-based billing modifiers, altered progress notes, and hotel-stay inducement schemes in behavioral health specifically, with the Richmond indictment alleging $49.6 million in false Medicaid claims tied to those exact patterns.
How long should compliance diligence take on a behavioral health target?
For a single-site or small multi-site behavioral health target, plan on 45 to 90 days of parallel compliance diligence alongside quality-of-earnings work. That spend is a fraction of a single FCA settlement. DOJ recovered over $6.8 billion under the False Claims Act in fiscal year 2025, with over $5.7 billion tied to healthcare matters, and individual behavioral health cases in the 2026 takedown ranged from a $44 million Arizona scheme to the $49.6 million Virginia crisis-stabilization case.
References
- DOJ: Deputy Attorney General Lisa O. Monaco Announces New Safe Harbor Policy for Voluntary Self-Disclosures Made in Connection with Mergers and Acquisitions (Oct. 4, 2023)
- DOJ: False Claims Act Settlements and Judgments Exceed $6.8B in Fiscal Year 2025 (Jan. 16, 2026)
- DOJ: 2026 National Health Care Fraud Takedown (June 23, 2026)
- U.S. Attorney’s Office, Eastern District of Virginia: Charges Against Three Defendants as Part of National Health Care Fraud Takedown
- Whiteford: 2026 DOJ Health Care Fraud Takedown Includes Virginia and a Renewed Focus on Medicaid Cases
- Sidley Austin: Key Takeaways from DOJ’s New M&A Safe Harbor Policy
- Baker Botts: DOJ’s New Safe Harbor Policy for M&A
- National Law Review: DOJ Announces Record Number of Defendants Charged in 2026 National Health Care Fraud Takedown