The DOJ’s 2026 Unified Corporate Enforcement Policy (CEP) replaces a patchwork of district-by-district rules with one national standard for how healthcare organizations should self-disclose fraud, cooperate with investigators, and remediate misconduct. The headline change: once an organization receives an internal report of potential fraud, it has 120 days to investigate and decide whether to self-disclose, and the government is now finding billing anomalies faster than most compliance teams can respond to them.

A doctor holding a clock | DOJ's 2026 Unified Enforcement Policy

Summary

The DOJ’s 2026 Unified Corporate Enforcement Policy establishes a single national framework for evaluating corporate misconduct, voluntary self-disclosure, cooperation, and remediation. For healthcare compliance teams, the policy increases the pressure to identify and investigate potential fraud quickly, preserve evidence, document corrective action, and determine whether disclosure is necessary within a limited timeframe. Organizations that maintain real-time compliance records, escalate high-risk reports promptly, and can demonstrate effective remediation will be better positioned to receive cooperation credit, reduce penalties, and potentially avoid prosecution.

That capability is already showing up in the numbers. In June 2026, the DOJ announced a National Health Care Fraud Takedown that resulted in over $6.5 billion in false claims charges, spanning a record number of states and reaching providers, practices, and health systems nationwide. That number alone would be worth a headline, but the more important story is how the DOJ got there. Not from a tip line, but from real-time data analytics, AI, and cross-agency data sharing that flag billing anomalies as they happen.

That shift set the stage for a recent webinar from Compliancy Group’s Advisory Services team, where compliance experts Brian Burton and Kendra Graham-Paulk walked through the DOJ’s new 2026 Unified Corporate Enforcement Policy (CEP) and what it actually requires of healthcare organizations. In short: the government often identifies billing anomalies before you’ve even filed an internal report. Static, annual compliance programs can no longer keep pace. Here’s what can.

What is the DOJ’s Unified Corporate Enforcement Policy?

For years, how the DOJ handled a self-disclosure depended heavily on which U.S. Attorney’s Office you happened to be dealing with. The new Unified CEP, announced in March 2026, replaces that patchwork with a single national standard applied across every district. That’s good news for predictability, but it comes with a catch: the compliance officer’s role has shifted from an administrative back-office function to what the DOJ now treats as a frontline corporate defense asset.

The policy is built around three pillars. Clear all three, absent aggravating circumstances, and an organization can earn a declination of prosecution:

  1. Voluntary self-disclosure: reporting in good faith, before the misconduct becomes public and before there’s any imminent threat of a government investigation finding it first.
  2. Full, transparent cooperation: this is not a passive obligation. It means identifying every individual involved regardless of rank, preserving data (including ephemeral apps like WhatsApp or Signal, and personal devices), and making witnesses available.
  3. Timely remediation: a genuine root-cause analysis, not just discipline for the one employee who got caught.

How Does the DOJ’s 120-Day Self-Disclosure Window Work?

Perhaps the single most operationally significant detail in the new policy is the 120-day window. Once an internal whistleblower report comes in, the clock is running toward a self-disclosure decision, and the organization doesn’t get to decide when it starts. As one presenter put it during the session, the moment someone hits send on that internal report, the clock has already begun.

That’s a tight window. Investigations that would normally take 60 to 90 days now have to happen inside a structure that also leaves room for legal review and a disclosure decision. In practice, the webinar broke down where that time actually goes: evidence collection (pulling EHR records, claims data, and system logs), witness interviews, a scope-creep phase where one issue reveals three more, and finally the negotiation among legal, compliance, HR, and leadership over how to frame the findings. Done well, those four phases still eat 90 to 120 days, which is nearly the entire window.

How is the DOJ’s 120-Day Window Different From the 60-Day Overpayment Rule?

It’s also worth knowing which clock is actually running. Criminal misconduct (fraud, kickbacks, falsified records) follows the DOJ’s 120-day track. Identified overpayments follow a separate, faster 60-day civil clock under existing OIG or CMS self-disclosure protocols. A single event can trigger both at once, and misrouting the disclosure, or letting the faster civil clock lapse while focused on the criminal track, forfeits credit on both sides.

The practical takeaway: compliance programs need to re-engineer their intake process now, not after the next report comes in, so a high-severity tip is triaged and escalated within hours rather than weeks.

What Does the DOJ Expect From an Effective Compliance Program?

The webinar’s other major theme was evidentiary hygiene. DOJ evaluation guidance now explicitly instructs prosecutors to ignore the compliance binder sitting on a shelf. Credit turns on whether a program operates in real time, not on how thorough it looks on paper. As one presenter summarized it, if it isn’t written down, it didn’t happen.

What Compliance Records Should Healthcare Organizations Be Able to Produce?

That means compliance teams need to move from static spreadsheets to a live, defensible system that can produce three things instantly: current policy versions, a complete attestation and training history for any employee, and continuous exclusion screening for every provider, employee, and vendor. Manual tracking doesn’t just slow this down. It’s a structural weakness. A spreadsheet is editable, with no reliable audit trail, and it invites a question no compliance officer wants to answer: could this have been changed? Immutable, system-generated logs are what make a program provable rather than merely present.

How Can Compliance Officers Make the Business Case for More Resources?

None of this happens without resourcing, and compliance officers are often the ones who have to defend that budget. The most effective framing isn’t about features. It’s about risk. A single False Claims Act matter will dwarf the cost of any compliance platform, and a defensible, real-time program is what moves an organization from prosecution toward declination or meaningful penalty reduction. Regular reporting to a compliance committee, framed around metrics like Mean Time to Resolution, gives leadership a concrete basis for approving additional staff or software rather than treating compliance as a cost center.

How Should Healthcare Compliance Teams Prepare for the Unified CEP?

The path forward doesn’t require an overnight overhaul. A reasonable sequence looks like this: audit twelve months of hotline intake data and calculate your actual Mean Time to Resolution. Anything over 60 days points to your first bottleneck. From there, locate where policy attestations, training records, and exclusion-screening logs actually live, and if they’re scattered across folders, start mapping a transition to a consolidated system. Finally, bring a risk-mitigation report to the board that connects a tech-enabled compliance program directly to reduced individual liability for directors and officers under the new policy.

The core message from the session was straightforward: compliance in 2026 isn’t a back-office administrative task. It’s a defensive capability the organization has to be able to prove works on demand, not just when the DOJ comes knocking.

Frequently Asked Questions About the Unified CEP

The Unified CEP, announced in March 2026, is a single national standard the DOJ now applies across every U.S. Attorney’s Office for evaluating corporate misconduct. It replaces the prior system, where outcomes varied depending on which district handled a case, and it centers on three factors: voluntary self-disclosure, full cooperation, and timely remediation.

It’s the window a compliance program has, starting the moment an internal report of potential fraud is received, to investigate the claim and decide whether to self-disclose it to the DOJ. The clock is set by when the report comes in, not by when the compliance team is ready to act on it.

No. The DOJ’s 120-day clock applies to criminal misconduct, such as fraud or falsified records. Overpayments identified through routine audits typically fall under a separate, faster 60-day civil self-disclosure clock under existing OIG and CMS protocols. A single incident can trigger both at once.

An organization that clears all three pillars, voluntary self-disclosure, full cooperation, and timely remediation, without aggravating circumstances, can qualify for a declination of prosecution. Partial credit is still possible for organizations that fall short of full compliance but cooperate meaningfully.

The most commonly recommended steps are: re-engineering intake workflows so high-risk reports are triaged within hours, replacing static spreadsheets with a live system of record for policies and training, tracking Mean Time to Resolution, and looping in legal counsel before any contact with the DOJ.

This post is a summary of an educational webinar and is not legal advice. Organizations navigating a specific compliance matter should consult qualified counsel.