Full Speed Ahead: DOJ's Fraud Division Accelerates Its Corporate Enforcement Agenda
Litigation Alert
On October 1, 2026, Assistant Attorney General (AAG) Colin M. McDonald issued a directive titled, "Corporate Enforcement in the Fight Against Fraud," to all personnel of the Department of Justice's (DOJ) newly created National Fraud Enforcement Division (Fraud Division). It is the Division's most specific statement yet on corporate enforcement and signals a change in the operating speed of corporate fraud enforcement at DOJ.
The message for companies is simple: know your data. The Fraud Division says that it is using data analytics to generate its own leads and open corporate investigations "at a rapid pace." Companies across industries must now ask themselves whether their data could send a signal to the government and draw unnecessary scrutiny. We'll walk through the directive and concrete steps companies can take now to reduce risk in a webinar on October 21, 2026.
What the DOJ is Directing and How Fast
The directive sets concrete deadlines and moves DOJ corporate cases under central control.
- Seven-Day Inventory. Within seven days (by October 8, 2026), every Fraud Division prosecutor must report all ongoing corporate investigations to the Fraud Division's Corporate Enforcement Section (CES).
- Four Corporate Priorities.
- Healthcare fraud, including controlled substances and Federal Food, Drug, and Cosmetic Act (FDCA) violations
- Procurement and government function fraud
- Significant revenue evasion
- Tariff evasion, importation, and forced labor
- Ongoing Notice. CES must be promptly notified of every new corporate investigation and every major development in existing ones.
- Resolution Oversight Centralized. CES takes primary responsibility for monitoring compliance with corporate resolutions. AAG McDonald's directive says this is meant to free prosecutors to pursue additional individual and corporate cases.
- 10 "Great Weight" Factors. With respect to charging and resolution, Fraud Division prosecutors must give "Great Weight" to various factors, including management involvement, concealment from regulators or auditors, conduct touching multiple federal districts or multiple taxpayer-funded programs, conduct that threatens the safety of Americans, and harm to 25 or more victims or $25 million or more in loss.
- Whistleblower Programs. Division leadership is directed to design incentives for whistleblowers, expressly including those who participated in the misconduct.
A Shift in Tone: Pace, Volume, and Proactivity
Recent corporate guidance from the DOJ, including the Criminal Division's May 2025 enforcement memorandum and the March 2026 department-wide Corporate Enforcement and Voluntary Self-Disclosure Policy (CEP), emphasized fairness, efficiency, and narrower enforcement. The Fraud Division's Directive keeps that focus – it pledges to guard against overbroad enforcement, protect law-abiding companies, and follow the CEP.
What is different is the operating posture. The directive calls for an "aggressive, all-tools approach," imposes a seven-day reporting deadline and builds a central section whose stated purpose includes opening more cases. In August, the Division described a corporate "pipeline." It now has a tracked, centrally managed system designed to grow that pipeline.
The numeric factors are also new. Three years, three districts, multiple programs, 25 victims, and $25 million read less like traditional culpability factors and more like data filters. These factors clearly signal an aggressive move toward data-driven enforcement.
Companies should expect more corporate enforcement matters, earlier DOJ involvement, and faster escalation from prosecutions of individuals to considerations of corporate criminal liability.
Know Your Data
The directive reinforces that the DOJ has access to data and the Fraud Division has a mandate to act on it. In June 2026, the DOJ announced that the Fraud Division would receive computing capacity inside the Centers for Medicare and Medicaid Services' (CMS) Integrated Data Repository to run artificial intelligence (AI) and analytics directly on Medicare and other program data. Parallel agreements bring in Department of Homeland Security (DHS) and Federal Trade Commission (FTC) data. The directive confirms that the Division is using this infrastructure, through its National Fraud Detection Center, to generate leads.
FDA-Regulated Companies Enter the Mix: The FDCA Comes Within the Fraud Division's Reach
The directive also calls out Food and Drug Administration (FDA) violations as a corporate enforcement priority. That matters because of where criminal FDCA enforcement has lived.
The directive does not formally transfer FDCA jurisdiction to the Fraud Division. But it signals that the Division considers FDCA conduct within its corporate reach when it connects to taxpayer-funded programs. Examples include adulterated or misbranded drugs and devices reimbursed by Medicare or Medicaid, unapproved or compounded products, and promotional practices that drive federal claims.
For life sciences and medtech companies, the practical consequences are significant:
- Two DOJ components (the Fraud Division and the Criminal Division's Health and Safety Unit), plus FDA, may now have overlapping interest in the same conduct.
- Strict liability FDCA misdemeanors could potentially be paired with fraud theories.
- The "Great Weight" factor for actions that threaten Americans' safety can elevate a product quality issue into a priority corporate case.
Strike Force Expansion: Where Data Meets Prosecutors
Health Care Fraud Strike Forces are built to turn billing data into cases, and the DOJ is placing them in major healthcare and life sciences hubs. In August 2026, the Fraud Division expanded its Northeast Strike Force to Philadelphia, embedding agents in the Eastern District of Pennsylvania. That followed the April 2026 launch of the West Coast Strike Force covering Arizona, Nevada, and Northern California, and the expansion of the New England Strike Force into Boston in September 2025.
Recent DOJ activity suggests prosecutors are becoming more creative in where they bring cases. Because fraud offenses can be charged in any district where the offense began, continued, or was completed (18 USC 3237(a)), venue is not limited to where a company is headquartered. Claims, payments, text, and other data transmitted through a district could potentially support venue there.
Incentivizing Whistleblowers
The directive notes that its efforts "can be aided" by individuals and companies who provide the DOJ with information even "when they share culpability for the misconduct." Therefore, the Division seeks to promote and protect whistleblowers. As such, AAG McDonald orders the leadership of the Division to consider how to "incentivize whistleblowers" and help "uncover criminal conduct, strengthen ongoing investigations, help prevent fraud losses, and enable the Department to effectively respond to both latent and emerging criminal fraud threats."
Join Our Webinar: October 21, 2026
The session will walk through the directive and how it fits within the Fraud Division's broader data and Strike Force initiatives. We will also discuss practical steps companies can take now to assess and reduce their exposure. Learn more and register here. Please note that this webinar is for our clients and other in-house contacts.
For more information, please contact:
Christina A. Clark, cclark@milchev.com, 202-626-5909
Joshua Drew, jdrew@milchev.com, 202-626-5811
Kevin Lowell, klowell@milchev.com, 202-626-5837
Therese Kuester, tkuester@milchev.com, 202-626-1462
The information contained in this communication is not intended as legal advice or as an opinion on specific facts. This information is not intended to create, and receipt of it does not constitute, a lawyer-client relationship. For more information, please contact one of the senders or your existing Miller & Chevalier lawyer contact. The invitation to contact the firm and its lawyers is not to be construed as a solicitation for legal work. Any new lawyer-client relationship will be confirmed in writing.
This, and related communications, are protected by copyright laws and treaties. You may make a single copy for personal use. You may make copies for others, but not for commercial purposes. If you give a copy to anyone else, it must be in its original, unmodified form, and must include all attributions of authorship, copyright notices, and republication notices. Except as described above, it is unlawful to copy, republish, redistribute, and/or alter this presentation without prior written consent of the copyright holder.