Skip to content
RiskTemplates · The Daily Brief Friday, September 11, 2026
Wire SEC's $3.02M Doximity Insider Trading Judgment: The MNPI Control Test SEP 10

Breaking Regulatory Compliance

FinCEN Health Care Fraud Analysis: $17.5 Billion in Suspicious Activity

FinCEN's health care fraud analysis reveals $17.5B in suspicious activity. Here is how BSA teams should update monitoring and SAR controls.

By Rebecca Leung · September 10, 2026 ·
Table of Contents

TL;DR

  • FinCEN analyzed 5,702 BSA reports covering approximately $17.5 billion in suspicious activity filed from March 1, 2025 through February 28, 2026. That figure is not a confirmed fraud loss or fine; it includes completed and attempted transactions.
  • Depository institutions filed 89% of the reports, but FinCEN found a visibility problem: banks usually saw the money movement without knowing the underlying billing scheme until a public charge or law-enforcement inquiry supplied the missing context.
  • Home health care, hospice, behavioral health, durable medical equipment, and daycare customers deserve a targeted coverage review—not an automatic high-risk label.
  • BSA Officers should map payer credits, ownership changes, reimbursement spikes, non-health-care spending, and shell-company transfers to monitoring scenarios, case procedures, and the SAR keyword HCF-2026-A001.

FinCEN’s health care fraud analysis puts a hard number on a familiar AML blind spot: banks can see the proceeds, but they often cannot see the claim that produced them. On September 9, 2026, FinCEN reported that 5,702 Bank Secrecy Act filings identified approximately $17.5 billion in activity potentially connected to health care fraud during a one-year review period.

Do not turn that number into a headline about confirmed losses. FinCEN’s Financial Trend Analysis: Health Care Fraud—Trends in Bank Secrecy Act Data is explicit that the total includes completed and attempted transactions. SAR amounts may also include lawful activity, inbound and outbound transfers, transfers between accounts, continuing activity, amended filings, and reporting errors. This is suspicious financial activity, not an adjudicated fraud amount and not an enforcement penalty.

The operational message is still sharp. FinCEN found that financial institutions often described the type of billing fraud only after a customer had been charged or law enforcement explained the methodology. Before that, the institution generally saw payer credits and downstream transactions—not phantom billing, upcoding, kickbacks, or medically unnecessary services.

That is the control problem to fix.

What FinCEN’s health care fraud analysis actually found

FinCEN reviewed BSA reports filed between March 1, 2025 and February 28, 2026. Its dataset covered 471 financial institutions and 13,277 subjects. The agency’s September 9 announcement and the underlying analysis identified several concentrations:

FindingVerified resultWhy a BSA team should care
BSA reports reviewed5,702This is a cross-institution pattern, not one prosecution
Suspicious activity reportedApproximately $17.5 billionUse as a coverage signal, not a confirmed-loss statistic
Depository institution filings5,080, or about 89%Banks carry most of the detection and reporting workload
Depository institution amountApproximately $15.2 billionThe fund flows are concentrated inside bank-visible payment activity
Medicare and/or Medicaid named2,190 reports, about 38%Monitoring needs payer and program context
Medicare Administrative Contractors named1,247 reports, about 22%MAC-originated credits are a useful data-enrichment field
Subject locationsAll 50 states, D.C., and U.S. territoriesThis is not confined to a few traditional fraud hubs
Foreign subject addresses187 of approximately 13,000 addressesThe schemes were overwhelmingly domestic at the subject level

Two large depository institutions filed 29% of the reports, but that concentration is not a SAR-volume benchmark. Compare coverage instead: can your institution identify health care customers receiving government or insurer reimbursements, normalize a Medicare Administrative Contractor credit, and show investigators the provider’s normal payroll, tax, equipment, and medical-supply expenses? If that depends on recognizing a payer name from memory, the control is fragile.

The provider risk is concentrated—but blunt de-risking misses the point

Home health care businesses were the most frequently identified suspected fraudulent provider type. FinCEN reported that they appeared in more than 21% of the full dataset and nearly 32% after excluding reports about possible Medicaid eligibility fraud in Puerto Rico. Hospice care, mental or behavioral health and addiction treatment, durable medical equipment, and adult or child daycare providers followed.

This does not justify treating every home health agency as suspicious. FinCEN’s March advisory says no single red flag is determinative; assess customer history, expected business practices, and the surrounding facts. The right unit is the customer’s expected payment and operating pattern.

FinCEN’s examples make that distinction concrete:

  • A purported home health agency registered at a residential address received insurance payments but spent more than $240,000 on luxury apparel and gambling.
  • A genetic testing laboratory at a strip mall with no signage received more than $190,000 from an insurer and a Medicare Administrative Contractor, followed by cash withdrawals, gambling, and travel spending.
  • A seemingly active Alaska dental office received more than $25 million in Medicaid payments, but the money funded cash withdrawals, personal expenses, and transfers to owners’ other businesses.
  • A Pennsylvania hospice business received more than $330,000 from a Medicare Administrative Contractor, then used the funds for owner credit-card payments and transfers to personal accounts.

A real office, active license, and plausible business do not neutralize transaction risk. FinCEN said seemingly legitimate providers were less than 5% of the dataset but may be underrepresented because their red flags are harder to detect without billing visibility.

This is where financial institutions get uncomfortable. You are not expected to recreate a clinical claims-audit platform inside the AML system. You are expected to understand the customer well enough to recognize when the account behaves nothing like the business described at onboarding.

The real gap: payment visibility without scheme visibility

FinCEN observed that banks see funds arriving from government health agencies, Medicare Administrative Contractors, and private insurers, but generally cannot see how the provider obtained those payments. The report states that institutions usually supplied billing-scheme detail only after a public charge, indictment, or direct law-enforcement contact.

That creates a predictable failure mode:

  1. Onboarding captures an industry code but not the reimbursement model. The file says “health services” without provider type, payer mix, operating states, expected monthly reimbursement range, or expected counterparties.
  2. Transaction monitoring sees dollars without payer identity. ACH descriptions and originators are not normalized into Medicare, Medicaid, MAC, state agency, and commercial insurance categories.
  3. The alert tests velocity but not economic purpose. A reimbursement spike may trigger, but the case view does not compare it with payroll, taxes, medical supplies, equipment, rent, or patient-service activity.
  4. Ownership changes remain in KYC operations. The monitoring team never receives an event when a health care provider is purchased or its beneficial owners change.
  5. Investigators close isolated alerts. A wire to a construction firm, transfers to personal accounts, and rapid payments to unrelated businesses are reviewed separately instead of as one health care fraud pattern.

The fix is not “add more alerts.” It is to connect customer profile, payer data, ownership events, and downstream use of funds in one investigation view.

Build a targeted health care fraud coverage matrix

Start with the population, not the scenario library. The BSA Officer should ask the AML analytics lead to identify commercial customers with health care-related NAICS codes, business descriptions, merchant data, or known insurer and government reimbursement credits. Then segment by provider type and payment model.

Coverage componentSpecific implementation stepOwnerEvidence to retain
Customer inventoryTag home health, hospice, behavioral health/addiction treatment, DME, pharmacy, laboratory, medical transportation, and daycare customersKYC/CDD OperationsQuery logic, population extract, exception log
Payer identificationNormalize known MAC, Medicare, Medicaid, state agency, and commercial insurer originatorsAML Data/EngineeringPayer reference table, mapping version, unmatched-originator report
Expected activityRecord payer mix, operating states, expected monthly reimbursement range, payroll model, and expected health-care expensesRelationship Management + CDDUpdated customer profile and approval history
Ownership eventTrigger CDD refresh and monitoring review after a beneficial ownership or control changeKYC GovernanceEvent ticket, refreshed ownership record, monitoring decision
Scenario coverageTest reimbursement spikes, rapid pass-throughs, unrelated counterparties, high-value checks, cash, personal spending, and foreign wiresTransaction MonitoringScenario specification, data lineage, test results
Investigation qualityRequire investigators to compare health care credits with expected operating expenses and related-account activityAML InvestigationsCase checklist, sampled cases, QA findings
SAR codingAdd HCF-2026-A001, field 34(g), and relevant money-laundering fields to proceduresSAR GovernanceProcedure revision, training record, QA sample

For reimbursement spikes, avoid dropping an unsupported percentage into production. A defensible starter test is to compare each customer with its own trailing history and a genuinely comparable peer segment, then calibrate using at least several months of alerts, confirmed cases, and false-positive outcomes. Document why the selected threshold catches meaningful changes without turning ordinary seasonal billing into noise.

Add an anti-gaming check: reconcile the customer population against actual payer-originator credits. If a provider receives MAC or state health agency funds but lacks the corresponding customer tag, open a data-quality issue. That catches the common problem where a beautifully tuned scenario never runs because the customer was misclassified upstream.

Translate FinCEN’s red flags into linked tests

FinCEN’s March 30, 2026 Advisory HCF-2026-A001 lists onboarding, account-access, reimbursement, and disposition-of-funds indicators. The strongest cases will combine indicators from more than one layer.

Customer and ownership layer

Check for a recently established or purchased provider with little relevant industry experience; beneficial owners connected to prior health care or government-benefit fraud; common owners across nominally separate providers; or account access through devices and IP addresses linked to multiple accounts or foreign jurisdictions.

A change in account beneficiaries without a corresponding company-name or tax-ID change deserves review. So does a sharp reimbursement increase soon after beneficial ownership changes. KYC and transaction monitoring have to share these events; neither team can detect the full pattern alone.

Reimbursement layer

Identify large payments soon after a new provider begins operations, sudden increases after a stable period, or reimbursement volume inconsistent with the provider’s stated size and service line. FinCEN specifically points to payments from MACs and state-level agencies as useful context.

The case page should answer four questions without sending the investigator into three separate systems:

  • Who paid the customer?
  • Which program or payer category does that originator represent?
  • How does the amount compare with the customer’s documented profile and history?
  • Did a recent onboarding, ownership, device, or address event change the risk?

Use-of-funds layer

FinCEN highlights minimal legitimate business expenses, repetitive “consulting” or “marketing” payments, transfers to companies at residential addresses, luxury purchases, unexplained cash withdrawals, high-value checks to individuals, structuring, foreign wires, and transfers to virtual asset service providers, brokerage accounts, or online betting platforms.

One transaction may have a plausible explanation. The pattern is what matters. A hospice receiving MAC payments and paying a marketing vendor is not inherently suspicious. A newly purchased hospice receiving an abrupt reimbursement surge, showing no normal payroll or medical expenses, and rapidly moving money to related shell companies creates a very different case.

The FTA also found that approximately 5% of reports identified international transfers funded directly or indirectly by suspected health care fraud proceeds. Hong Kong appeared most often, but FinCEN observed 32 destination countries. Because funds frequently moved through another domestic party before leaving the United States, single-account monitoring can miss the complete path. Related-account and counterparty-network views should be part of investigation procedures for higher-risk cases.

SAR procedures need a small but important update

The September FTA does not replace the March advisory’s filing instructions. For activity connected to the advisory, FinCEN asks institutions to:

  • include HCF-2026-A001 in SAR field 2, “Filing Institution Note to FinCEN,” and in the narrative;
  • select field 34(g), “Healthcare/Public or Private Health Insurance”;
  • select other relevant fields, including money laundering and other suspicious activity, when applicable;
  • include available information on accounts, locations, people, entities, and domestic or foreign financial institutions involved; and
  • consider a joint SAR where appropriate for shared suspicious activity.

FinCEN also reminds institutions to retain the SAR and supporting documentation for five years and provide the documentation when properly requested by FinCEN, law enforcement, or a supervisory agency. The procedural detail people miss: institutions should verify the identity and authority of anyone requesting SAR support. That verification step belongs in the BSA procedure, not in someone’s inbox habits.

Run a focused QA review of health care fraud SARs filed since March 30, 2026. Test the keyword, field selections, payer originators, ownership changes, related entities, use of proceeds, and the explanation of why activity departed from the customer profile.

For broader program governance, the site’s guide to AML board accountability and BSA exams explains how to bring transaction-monitoring gaps and SAR quality into board reporting. The FinCEN AML/CFT program reform breakdown covers the shift toward documented effectiveness, while the compliance KRI examples guide provides a structure for monitoring unresolved alerts and filing timeliness.

A 30-day response that produces evidence

Days 1–5 — establish the population. The BSA Officer assigns AML analytics to identify health care customers and payer-originator credits. CDD Operations reconciles the two lists. Log missing industry tags, unknown payer originators, stale expected-activity fields, and unprocessed ownership changes as discrete issues with owners and due dates.

Days 6–12 — map current controls. Transaction Monitoring maps each FinCEN red-flag family to an existing scenario, investigator procedure, KYC event, or manual control. Mark a red flag “covered” only when the required data reaches the control and testing proves it works. A policy sentence is not coverage.

Days 13–20 — test cases and data. Sample customers across home health, hospice, behavioral health, DME, daycare, pharmacy, laboratory, and transportation segments. Trace payer credits into monitoring and review downstream expenditures. Include at least one ownership-change event and one customer with significant insurer receipts but limited obvious health-care operating expense.

Days 21–25 — repair SAR procedures. Add HCF-2026-A001 and field 34(g) instructions, train investigators, and QA relevant SARs filed after the advisory date. Where the keyword or material network information was omitted, have SAR Governance determine the appropriate corrective action under existing amendment procedures.

Days 26–30 — report and govern. Present the population count, data gaps, uncovered red flags, scenario-testing results, SAR QA exceptions, and remediation dates to the financial crimes governance committee. The evidence package should include the population logic, payer table, control crosswalk, test samples, QA results, and issue log.

That package is the real deliverable. “We reviewed the FinCEN analysis” will not help when an examiner asks which customer population changed, which control was tested, and what the test found.

So what?

The Treasury Department’s release frames the $17.5 billion as evidence of how financial institutions support fraud investigations. The more useful internal reading is diagnostic: the filings show where institutions had visibility, and FinCEN’s narrative shows where they did not.

Monday morning, ask for two lists: every health care customer receiving identifiable government or insurer reimbursements, and every such customer missing a complete expected-activity profile. Reconcile them. The exceptions are your first issue log.

If that review uncovers scattered owners, missing evidence, and remediation dates living in email, the Issues Management Tracker & Template gives the BSA team one place to assign, age, validate, and close the gaps.

◆ Need the working template?

Start with the source guide.

These answer-first guides summarize the required fields, evidence, and implementation steps behind the templates practitioners search for.

◆ Immaterial Findings · Weekly

Sharp risk & compliance insights. No fluff.

◆ FAQ

Frequently asked questions.

Did FinCEN say health care fraud caused $17.5 billion in losses?
No. FinCEN identified approximately $17.5 billion in suspicious activity reported in 5,702 BSA filings between March 1, 2025 and February 28, 2026. The amount includes completed and attempted transactions and may include lawful activity, transfers between accounts, continuing activity, or amended reporting. It should not be described as a confirmed loss or penalty.
Which financial institutions filed most of the health care fraud reports?
Depository institutions filed 5,080 reports, approximately 89% of FinCEN's dataset, and reported about $15.2 billion in suspicious activity. Securities firms, money services businesses, insurers, casinos, and loan or finance companies also filed reports.
What SAR keyword applies to suspected health care fraud?
FinCEN's March 30, 2026 advisory asks institutions to include HCF-2026-A001 in SAR field 2, Filing Institution Note to FinCEN, and in the narrative. Filers should also select field 34(g), Healthcare/Public or Private Health Insurance, and other applicable activity fields.
What health care provider types appeared most often in FinCEN's analysis?
Home health care was the most frequently identified provider type. After excluding reports about possible Puerto Rico Medicaid eligibility fraud, home health care appeared in nearly 32% of the relevant dataset, followed by hospice, mental or behavioral health and addiction treatment, medical equipment, and daycare providers.
What should a bank or fintech do first after this FinCEN analysis?
Identify customers receiving Medicare Administrative Contractor, state health agency, Medicaid, Medicare, and commercial insurer payments; compare that population with current customer risk ratings and monitoring coverage; then log and assign any gaps involving payer identification, reimbursement spikes, beneficial ownership changes, shell-company transfers, or SAR coding.
Rebecca Leung

Author

Rebecca Leung

Rebecca Leung has 8+ years of risk and compliance experience across first and second line roles at commercial banks, asset managers, and fintechs. Former management consultant advising financial institutions on risk strategy. Founder of RiskTemplates.

● Don't wait for your own enforcement action

Every case like this started with a gap someone knew about but hadn't documented. The template below gives you the framework to get ahead of it.

Issues Management Tracker & Template

End-to-end issues tracking and remediation management for risk and compliance teams.

Immaterial Findings · Newsletter

The brief, in your inbox.

Enforcement of the week, a framework breakdown, and the prompts that are actually worth running. Delivered to your inbox. Free.