DOJ v. OIG Self-Disclosure Policies: What Healthcare Entities Should Know & Why It Matters

Healthcare providers across the nation have been on high alert as federal agencies continue to increase their focus on fraud, waste, and abuse.

On March 10, 2026, the U.S. Department of Justice (DOJ) released its first department-wide Corporate Enforcement and Voluntary Self-Disclosure Policy for nearly all criminal cases. At the same time, healthcare organizations continue to have the option of utilizing the U.S. Department of Health and Human Services Office of Inspector General's (OIG) Health Care Fraud Self-Disclosure Protocol for certain healthcare-related violations.

While both programs encourage organizations to voluntarily disclose misconduct, they differ in their eligibility requirements, scope, and potential benefits. Understanding when each pathway applies can have significant implications for healthcare organizations navigating today's increasingly active enforcement environment.

Why This Matters

In light of the current administration's heightened focus on healthcare fraud enforcement, organizations that fail to proactively identify and disclose potential misconduct may find themselves at a significant disadvantage if issues are later uncovered during a government investigation.

Both the DOJ's Corporate Enforcement Policy and the OIG's Health Care Fraud Self-Disclosure Protocol provide meaningful incentives for organizations that voluntarily come forward. However, the requirements, protections, and outcomes differ depending on the type of misconduct and the agency involved.

Understanding these distinctions allows healthcare organizations to make more informed compliance decisions, strengthen internal response processes, and better position themselves should a potential violation arise.

DOJ vs. OIG: Key Differences at a Glance

McDermott, Will & Schulte recently published an overview comparing the DOJ's Corporate Enforcement Policy with the OIG's Health Care Fraud Self-Disclosure Protocol. The comparison highlights several important distinctions healthcare organizations should understand when evaluating self-disclosure options.

Eligibility Requirements

DOJ Corporate Enforcement Policy

The disclosing company must:

  • Voluntarily self-disclose misconduct to the appropriate DOJ criminal component.

  • Fully cooperate with the DOJ's investigation.

  • Timely and appropriately remediate the misconduct.

  • Have no aggravating factors or pattern of repeat criminal behavior.

OIG Health Care Fraud Self-Disclosure Protocol

The disclosing organization must:

  • Be a healthcare provider, supplier, or other entity subject to OIG Civil Monetary Penalty authorities.

  • Reasonably believe the conduct may violate federal criminal, civil, or administrative laws subject to a Civil Monetary Penalty.

  • Ensure the conduct has ended, or, in the case of an improper kickback arrangement, take corrective action within 90 days of the self-disclosure.

  • Include all required information outlined in the OIG Self-Disclosure Protocol.

Types of Misconduct Covered

DOJ Policy

  • Criminal misconduct

  • Excludes antitrust violations

OIG Protocol

  • Criminal, civil, and administrative healthcare misconduct

  • Does not apply to conduct unrelated to healthcare laws or Stark Law-only matters

Benefits of Self-Disclosure

DOJ Policy

Organizations that satisfy the eligibility requirements may receive a declination of prosecution, subject to approval by the appropriate DOJ leadership. Full declination generally requires a truly voluntary disclosure made before the government becomes aware of the misconduct.

OIG Protocol

While self-disclosure may still result in financial penalties, participating organizations may benefit from lower damages multipliers, faster resolution timelines, reduced likelihood of Corporate Integrity Agreement obligations, and suspension of certain overpayment reporting requirements during the process.

Timing Requirements

DOJ Policy

The DOJ encourages organizations to disclose potential misconduct as early as possible—even before an internal investigation is fully complete. To qualify, disclosure must occur within a reasonably prompt timeframe.

OIG Protocol

Timely disclosure remains important, but the emphasis is on good-faith participation and compliance with the protocol's submission requirements.

If the Government Is Already Aware

DOJ Policy

If the DOJ or another government agency has already initiated an inquiry, a subsequent disclosure may still receive partial cooperation credit. However, organizations generally will no longer qualify for a full declination because the disclosure is no longer considered truly voluntary.

OIG Protocol

An existing government inquiry does not automatically prevent an organization from using the OIG Self-Disclosure Protocol. If the organization can demonstrate that its disclosure is made in good faith and is not simply an attempt to circumvent an ongoing investigation, it may still receive the protocol's available benefits.

Purpose of Each Program

DOJ Corporate Enforcement Policy

The DOJ's primary objective is to encourage organizations to identify misconduct early, cooperate fully, remediate effectively, and reduce the likelihood of future violations.

OIG Health Care Fraud Self-Disclosure Protocol

The OIG protocol is designed to encourage healthcare organizations to voluntarily disclose potential healthcare fraud and resolve matters more efficiently while demonstrating a commitment to compliance.

Cooperation Requirements

DOJ Policy

Organizations are expected to disclose all relevant, non-privileged facts related to the misconduct, including information regarding individuals responsible for or involved in the conduct.

OIG Protocol

Organizations must report the results of their internal investigation—or certify that an investigation will be completed within 90 days—and provide a concise summary of all relevant facts supporting the disclosure.

Actions Healthcare Providers Should Take Now

As McDermott, Will & Schulte notes, "the best way for healthcare entities to mitigate civil and criminal exposure is to prevent misconduct in the first instance."

An effective compliance program does more than satisfy regulatory requirements—it helps organizations proactively identify, investigate, and address risk before it becomes an enforcement action.

Solutions Group provides comprehensive compliance support, proactive risk identification, and ongoing program oversight to help organizations strengthen their compliance programs and prepare for potential DOJ and OIG self-disclosure opportunities.

Our services include:

  • Direct access to experienced healthcare compliance professionals for guidance, recommendations, templates, and ongoing support.

  • Comprehensive claim lifecycle auditing through our proprietary nControl Audit Tool to identify compliance risks and opportunities.

  • Proactive monitoring and compliance program oversight to help ensure continued effectiveness and alignment with regulatory expectations.

Whether you're strengthening an existing compliance program or building one from the ground up, Solutions Group provides the expertise and tools to help you manage compliance with confidence.

Contact us today at connect@solutionsgroup.com to learn more.

By Alexandra Hembrough, Esq., General Counsel, Solutions Group Services

Previous
Previous

The Clock Is Working Against Your TPL Recoveries

Next
Next

MedPAC's Ambulance Cost Data:The Case for Trust, But Verify.