The Department of Justice has released a new plan to crack down on fraud across the medical device industry.
In April, Indiana-based legal firm Barnes & Thornburg released its annual Healthcare Enforcement and Compliance Annual Report, which found that False Claims Act recoveries for fiscal year 2025 totaled a record-setting $6.8 billion.
The majority of False Claims financial claims, $5.7 billion, came from healthcare sector entities. In the medical device industry alone, $76 million claims were secured.
Barnes & Thornburg created the report using an annual statistical report the DoJ issues that states how many Qui tam actions have been filed and how many enforcement actions the DoJ is pursuing, and other data emanating from the legal industry to identify what fraud enforcement trends are currently playing out.
The rising amount of FCA enforcement targeting the industry shows that DoJ is taking a more active role in fraud oversight in medtech.
This is something that President Donald Trump has been pushing since the beginning of his second term.
In June 2025, the DoJ launched the Health Care Fraud Data Fusion Center, which uses AI and data analytics to uncover fraud schemes in medtech. On April 30, 2026, the DoJ also announced the formation of the West Coast Health Care Fraud Strike Force.
This project united the DoJ’s National Fraud Enforcement Division and the US Attorney’s Offices for the District of Arizona, District of Nevada, and the Northern District of California, in an effort to tackle more sophisticated forms of healthcare fraud across the U.S. West Coast.
2025 also saw a record-setting number of qui tam actions, 1,297, filed by whistleblowers, signaling ongoing civil and criminal risk for providers, plans, labs, long-term care, life sciences, and digital health entrants.
Barnes & Thornburg predicts that four key dynamics will shape enforcement and compliance risk in the year ahead. The first is that prosecutors are differentiating between “paper” and operationally effective compliance programs.
Second, HHS-OIG guidance signals persistent exposure under the Anti-Kickback Statute (AKS), Stark Law, and other fraud and abuse authorities, along with heightened scrutiny of private equity and other investment models.
Third, data privacy and cybersecurity pressures are intensifying, elevating the standards for risk management, contingency planning, and real-time incident response.
Fourth, self-disclosure policies continue to incentivize timely internal investigations, remediation, and coordinated voluntary disclosures to reduce organizational liability. In this environment, proactive, risk-based compliance is not just a slogan — it is the decisive factor in mitigating enforcement action and preserving enterprise resilience.
Medical device industry under intensified scrutiny
The medical device and durable medical equipment sectors faced unprecedented enforcement action in 2025, with over $76 million recovered, a figure that doesn't include the staggering scale of the 2025 National Healthcare Fraud Takedown, which targeted the largest international DME fraud ring in U.S. history.
The takedown, which DOJ described as the largest healthcare fraud enforcement action ever measured by intended loss, resulted in charges against 324 individuals across 50 federal districts.
The operation's centerpiece was "Operation Gold Rush," a transnational criminal organization that submitted over $10 billion in false claims for urinary catheters and other DME using stolen identities, shell companies, and sophisticated money laundering operations.
Federal authorities seized over $245 million in cash, vehicles, cryptocurrency, and other assets, while CMS revoked or suspended billing privileges for 205 providers and prevented more than $4 billion in false or fraudulent payments.
Beyond the takedown, several major device manufacturers faced significant settlements for compliance failures that underscore evolving enforcement priorities.
Kickback schemes and marketing violations
C.R. Bard, Inc. and its affiliates agreed to pay $17 million to resolve allegations that they provided illegal kickbacks to urology practice groups to induce the use of Bard's "Link" prescription form for intermittent catheters.
The government alleged that between 2016 and February 2020, Bard, through its subsidiary Liberator Medical Supply, provided discounts, excessive free samples, and in-office supply cost reductions to influence prescribing decisions.
The remuneration allegedly ensured that practice groups directed prescriptions toward Bard's products rather than competitors, resulting in false claims submitted to Medicare and Medicaid in violation of the FCA.
The case highlights DOJ's continued focus on manufacturer relationships with prescribers and the fine line between legitimate business practices and illegal inducements.
The government alleged that these payments created improper financial relationships between Bard and prescribing physicians, violating the AKS by conditioning financial benefits on the use of Bard's proprietary prescription system.
Defective devices and worthless services
Exactech Inc., a medical device company based in Gainesville, Florida, agreed to pay $8 million to resolve allegations under the FCA for continuing to market and sell two types of orthopedic components despite knowing they failed prematurely at higher-than-acceptable rates.
These defective devices were implanted in patients, and Exactech allegedly submitted, or caused the submission of, false claims for reimbursement to federal healthcare programs for surgeries involving the defective components, resulting in worthless services being provided to patients.
The Exactech settlement represents a growing enforcement trend: holding manufacturers accountable not just for fraudulent billing, but for knowingly providing products that fail to deliver promised clinical value. This "worthless services" theory of liability poses significant risk for device companies that continue marketing products after discovering performance issues.
Devices that don't perform as advertised
Semler Scientific Inc. and Bard Peripheral Vascular Inc. together agreed to pay nearly $37 million to settle allegations that they caused false claims to be submitted to Medicare related to two diagnostic devices, FloChec and QuantaFlo.
Semler will pay about $29.75 million, and Bard (its former distributor) will pay about $7.2 million. The government alleged that the devices, while capable of monitoring certain metrics, failed to perform the key ankle-brachial index (ABI) testing as required under the relevant Medicare billing codes.
However, the devices were marketed and billed as though they did. In addition to the monetary settlement, Semler entered into a five-year Corporate Integrity Agreement with HHS-OIG.
Similarly, Diopsys, Inc., a Pennsylvania-based medical device company, agreed to pay $14.25 million to resolve allegations that it violated the FCA by promoting its vision testing device for unapproved uses and causing the submission of false claims to Medicare and Medicaid.
From 2015 to 2021, Diopsys allegedly marketed its NOVA device for electroretinography testing, despite lacking FDA clearance for that use. The company allegedly provided billing guidance and technical support to encourage providers to submit claims for electroretinography testing, knowing the device was not approved for that purpose.
Diopsys also allegedly made unapproved modifications to the device and continued marketing it without notifying the FDA.
Criminal prosecutions send strong deterrent message
While civil settlements dominated headlines, criminal prosecutions in the device space sent an unmistakable message about the consequences of fraud.
The former CEO, COO, and Director of Quality Assurance and Regulatory Affairs of Magellan Diagnostics, Inc. pled guilty to concealing a critical defect in the company's lead testing devices, which resulted in inaccurately low lead test results for thousands of children and other patients.
The defendants were indicted in April 2023 after a federal grand jury investigation revealed they knowingly withheld information about device malfunctions from the FDA, healthcare providers, and the public. Despite internal knowledge that the LeadCare Ultra and LeadCare II devices produced falsely low lead levels when used with venous blood samples, the executives continued marketing and distributing the devices without disclosing the defect.
DME fraud prosecutions resulted in sentences ranging from 37 months to 17 years in prison. A Florida-based CEO of Power Mobility Doctor Rx, LLC was convicted for orchestrating a $1 billion Medicare fraud scheme targeting hundreds of thousands of Medicare beneficiaries through fraudulent doctors' orders for medically unnecessary orthotic braces, pain creams, and other items secured through illegal kickbacks paid to telemedicine companies, pharmacies, marketers, and DME suppliers. Medicare and other insurers paid over $360 million based on these false claims.
Another Florida-based owner of multiple DME suppliers was sentenced to 12 years in prison for orchestrating a Medicare fraud scheme that submitted approximately $61.5 million in false claims. The defendant, who had prior felony convictions barring him from Medicare enrollment, concealed his ownership by recruiting nominee owners and falsifying enrollment records, bank documents, and other filings.
AI-powered enforcement and data analytics
The Trump administration's commitment to healthcare fraud enforcement extends beyond traditional investigative methods.
In June 2025, DOJ launched the Health Care Fraud Data Fusion Center, which uses artificial intelligence and data analytics to uncover fraud schemes in medtech. On April 30, 2026, DOJ also announced the formation of the West Coast Health Care Fraud Strike Force, uniting DOJ's National Fraud Enforcement Division and the U.S. Attorney's Offices for the District of Arizona, District of Nevada, and the Northern District of California to tackle more sophisticated forms of healthcare fraud across the U.S. West Coast.
HHS released its AI Strategic Plan on January 10, 2025, outlining a framework for integrating AI tools into its internal operations and research. The strategy focuses on five pillars: ensuring governance and risk management for public trust, designing infrastructure and platforms for user needs, promoting workforce development and burden reduction for efficiency, fostering health research and reproducibility through gold standard science, and enabling care and public health delivery modernization for better outcomes.
Goals under these pillars include using AI to accelerate drug and biologic approvals at FDA, CMS claim adjudications, and grant review throughout HHS.
One notable case from the 2025 takedown involved a $703 million genetic testing scheme where AI was used to generate fake consent recordings to use when submitting claims with illegally purchased beneficiary data — demonstrating that fraudsters are also leveraging advanced technology, prompting enforcement agencies to match their sophistication.
What Medical Device Companies Must Do Now
The enforcement landscape of 2025 makes clear that medical device manufacturers can no longer treat compliance as a checkbox exercise. Barnes & Thornburg predicts that four key dynamics will shape enforcement and compliance risk in the year ahead:
1. Operationally Effective Compliance Programs
Prosecutors are differentiating between "paper" and operationally effective compliance programs. Resolutions are increasingly tied to a program's resources, authority, and demonstrated effectiveness. Device companies must ensure their compliance programs have adequate staffing, budget, and executive-level support to identify and address risks proactively.
2. Persistent AKS and Stark Law Exposure
HHS-OIG guidance signals persistent exposure under the Anti-Kickback Statute, Stark Law, and other fraud and abuse authorities, along with heightened scrutiny of private equity and other investment models. Device manufacturers must carefully structure relationships with physicians, healthcare providers, and other referral sources to ensure compliance with these laws. Several states, most notably California, started crafting bills to address the growing role of private equity in healthcare, with proposed legislation aimed at prohibiting financial sponsors from interfering with the professional judgment of providers.
3. Elevated Cybersecurity Standards
Data privacy and cybersecurity pressures are intensifying, elevating the standards for risk management, contingency planning, and real-time incident response. Device companies — particularly those manufacturing connected devices or handling patient data — must conduct comprehensive risk analyses, implement robust access controls, and maintain incident response plans. The Illumina and HNFS settlements demonstrate that cybersecurity failures can result in FCA liability, not just HIPAA penalties.
4. Self-Disclosure Incentives
Self-disclosure policies continue to incentivize timely internal investigations, remediation, and coordinated voluntary disclosures to reduce organizational liability. DOJ updated its internal guidance on criminal self-disclosures to state that it will decline prosecution where a party engages fully in the self-disclosure process and meets all requirements for declination. Horizon Medical Center of Denton received credit for voluntarily self-disclosing its conduct to DOJ, resulting in a $14.2 million settlement rather than potentially more severe consequences.
In this environment, proactive, risk-based compliance is not just a slogan — it is the decisive factor in mitigating enforcement action and preserving enterprise resilience.
Medical device companies must invest in robust compliance infrastructure, conduct regular risk assessments, maintain strong relationships with legal counsel, and foster a culture where employees feel empowered to raise concerns without fear of retaliation.
The record-breaking enforcement numbers of 2025 signal that federal scrutiny of the medical device industry will only intensify. Companies that treat compliance as a strategic priority — rather than a regulatory burden — will be best positioned to navigate this challenging landscape and avoid becoming the next cautionary tale in DOJ's enforcement reports.