The DOJ’s 2026 Unified Corporate Enforcement Policy (CEP) replaces a patchwork of district-by-district rules with one national standard for how healthcare organizations should self-disclose fraud, cooperate with investigators, and remediate misconduct. The headline change: once an organization receives an internal report of potential fraud, it has 120 days to investigate and decide whether to self-disclose, and the government is now finding billing anomalies faster than most compliance teams can respond to them.

Table of Contents
- Summary
- Table of Contents
- What is the DOJ’s Unified Corporate Enforcement Policy?
- How Does the DOJ’s 120-Day Self-Disclosure Window Work?
- What Does the DOJ Expect From an Effective Compliance Program?
- Frequently Asked Questions About the Unified CEP
- What is the DOJ's Unified Corporate Enforcement Policy (CEP)?
- What is the 120-day whistleblower clock?
- Is the 120-day rule the same as OIG or CMS self-disclosure deadlines?
- What happens if an organization voluntarily self-discloses under the new policy?
- How can a compliance program prepare for the Unified CEP?
- About the Author: Miranda Satterly
- Related Posts
That capability is already showing up in the numbers. In June 2026, the DOJ announced a National Health Care Fraud Takedown that resulted in over $6.5 billion in false claims charges, spanning a record number of states and reaching providers, practices, and health systems nationwide. That number alone would be worth a headline, but the more important story is how the DOJ got there. Not from a tip line, but from real-time data analytics, AI, and cross-agency data sharing that flag billing anomalies as they happen.
That shift set the stage for a recent webinar from Compliancy Group’s Advisory Services team, where compliance experts Brian Burton and Kendra Graham-Paulk walked through the DOJ’s new 2026 Unified Corporate Enforcement Policy (CEP) and what it actually requires of healthcare organizations. In short: the government often identifies billing anomalies before you’ve even filed an internal report. Static, annual compliance programs can no longer keep pace. Here’s what can.
What is the DOJ’s Unified Corporate Enforcement Policy?
For years, how the DOJ handled a self-disclosure depended heavily on which U.S. Attorney’s Office you happened to be dealing with. The new Unified CEP, announced in March 2026, replaces that patchwork with a single national standard applied across every district. That’s good news for predictability, but it comes with a catch: the compliance officer’s role has shifted from an administrative back-office function to what the DOJ now treats as a frontline corporate defense asset.
The policy is built around three pillars. Clear all three, absent aggravating circumstances, and an organization can earn a declination of prosecution:
- Voluntary self-disclosure: reporting in good faith, before the misconduct becomes public and before there’s any imminent threat of a government investigation finding it first.
- Full, transparent cooperation: this is not a passive obligation. It means identifying every individual involved regardless of rank, preserving data (including ephemeral apps like WhatsApp or Signal, and personal devices), and making witnesses available.
- Timely remediation: a genuine root-cause analysis, not just discipline for the one employee who got caught.
How Does the DOJ’s 120-Day Self-Disclosure Window Work?
Perhaps the single most operationally significant detail in the new policy is the 120-day window. Once an internal whistleblower report comes in, the clock is running toward a self-disclosure decision, and the organization doesn’t get to decide when it starts. As one presenter put it during the session, the moment someone hits send on that internal report, the clock has already begun.
That’s a tight window. Investigations that would normally take 60 to 90 days now have to happen inside a structure that also leaves room for legal review and a disclosure decision. In practice, the webinar broke down where that time actually goes: evidence collection (pulling EHR records, claims data, and system logs), witness interviews, a scope-creep phase where one issue reveals three more, and finally the negotiation among legal, compliance, HR, and leadership over how to frame the findings. Done well, those four phases still eat 90 to 120 days, which is nearly the entire window.
How is the DOJ’s 120-Day Window Different From the 60-Day Overpayment Rule?
It’s also worth knowing which clock is actually running. Criminal misconduct (fraud, kickbacks, falsified records) follows the DOJ’s 120-day track. Identified overpayments follow a separate, faster 60-day civil clock under existing OIG or CMS self-disclosure protocols. A single event can trigger both at once, and misrouting the disclosure, or letting the faster civil clock lapse while focused on the criminal track, forfeits credit on both sides.
The practical takeaway: compliance programs need to re-engineer their intake process now, not after the next report comes in, so a high-severity tip is triaged and escalated within hours rather than weeks.
What Does the DOJ Expect From an Effective Compliance Program?
The webinar’s other major theme was evidentiary hygiene. DOJ evaluation guidance now explicitly instructs prosecutors to ignore the compliance binder sitting on a shelf. Credit turns on whether a program operates in real time, not on how thorough it looks on paper. As one presenter summarized it, if it isn’t written down, it didn’t happen.
What Compliance Records Should Healthcare Organizations Be Able to Produce?
That means compliance teams need to move from static spreadsheets to a live, defensible system that can produce three things instantly: current policy versions, a complete attestation and training history for any employee, and continuous exclusion screening for every provider, employee, and vendor. Manual tracking doesn’t just slow this down. It’s a structural weakness. A spreadsheet is editable, with no reliable audit trail, and it invites a question no compliance officer wants to answer: could this have been changed? Immutable, system-generated logs are what make a program provable rather than merely present.
How Can Compliance Officers Make the Business Case for More Resources?
None of this happens without resourcing, and compliance officers are often the ones who have to defend that budget. The most effective framing isn’t about features. It’s about risk. A single False Claims Act matter will dwarf the cost of any compliance platform, and a defensible, real-time program is what moves an organization from prosecution toward declination or meaningful penalty reduction. Regular reporting to a compliance committee, framed around metrics like Mean Time to Resolution, gives leadership a concrete basis for approving additional staff or software rather than treating compliance as a cost center.
How Should Healthcare Compliance Teams Prepare for the Unified CEP?
The path forward doesn’t require an overnight overhaul. A reasonable sequence looks like this: audit twelve months of hotline intake data and calculate your actual Mean Time to Resolution. Anything over 60 days points to your first bottleneck. From there, locate where policy attestations, training records, and exclusion-screening logs actually live, and if they’re scattered across folders, start mapping a transition to a consolidated system. Finally, bring a risk-mitigation report to the board that connects a tech-enabled compliance program directly to reduced individual liability for directors and officers under the new policy.
The core message from the session was straightforward: compliance in 2026 isn’t a back-office administrative task. It’s a defensive capability the organization has to be able to prove works on demand, not just when the DOJ comes knocking.
Frequently Asked Questions About the Unified CEP
This post is a summary of an educational webinar and is not legal advice. Organizations navigating a specific compliance matter should consult qualified counsel.








