Healthcare providers often assume federal fraud exposure ends when the Department of Justice (DOJ) closes its file or declines to prosecute. The Civil Monetary Penalties Law (CMPL), 42 U.S.C. § 1320a-7a, gives the Department of Health and Human Services Office of Inspector General (OIG) its own administrative track to seek monetary penalties and program exclusion, apart from any DOJ lawsuit. A flagged claim, a kickback arrangement, or an unreported overpayment can carry exposure that never reaches a federal courtroom.
What the Civil Monetary Penalties Law Reaches
The CMPL reaches a wide range of misconduct: false or fraudulent claims, billing for services rendered during an exclusion period, remuneration arrangements that implicate the anti-kickback statute, physician self-referral arrangements under the stark law, knowingly employing or contracting with an excluded individual, false records submitted with a claim, denying OIG's auditors access to records, and knowingly retaining an identified overpayment without reporting it. Providers that accepted pandemic relief dollars have been drawn into this last category: a Provider Relief Fund Audits and Enforcement review that identifies an unreported overpayment falls under the same provision. OIG built the law to reach conduct that falls short of a DOJ criminal charge or civil suit.
An Administrative Track, Not a Lawsuit
A CMPL matter starts with a written notice from OIG, not a civil complaint filed in federal court. The notice states the allegations and proposed penalty, and the recipient has 60 days from receipt to request a hearing before an administrative law judge (ALJ), filed with the Departmental Appeals Board by certified mail. At that hearing the provider has counsel, can present witnesses, and can cross-examine OIG's witnesses. OIG must prove the violation by a preponderance of the evidence, the civil standard rather than a criminal one. Any affirmative defense is the provider's to prove. A final decision can be appealed to a federal court of appeals within 60 days, and OIG generally cannot open a claims-based CMPL action more than six years after the claim was presented.
Where It Overlaps the False Claims Act and the Anti-Kickback Statute
The same conduct often sits under more than one statute at once. Congress wrote the anti-kickback statute so that a claim resulting from a kickback violation is itself a false or fraudulent claim for False Claims Act purposes, which means a single remuneration arrangement can generate a criminal referral, a civil investigative demand, and a CMPL penalty from OIG, all from the same facts. DOJ's civil division typically moves on a civil investigative demand or, in a criminal posture, a grand jury subpoena, while OIG can act on its own audit findings or a provider's self-disclosure without needing either.
OIG's Independent Track After a DOJ Declination
The Secretary has delegated civil penalty and exclusion authority to OIG, and by statute the Secretary may open a CMPL proceeding only as the Attorney General authorizes under procedures the two agencies have agreed upon. That is a different question from DOJ's charging decision: the statute lets OIG pursue a civil penalty against a person already convicted of a related federal crime without relitigating the facts, showing the CMPL track runs independently of DOJ's criminal case. A provider who receives a DOJ target letter (see A DOJ Target Letter: What Happens in the First 48 Hours) and later learns the criminal matter was declined should not treat that as the end of the story.
A declined prosecution tells you what DOJ decided. It says nothing about what OIG will still do.
What an OIG Settlement Resolves, and What It Leaves Open
OIG's published settlement language is explicit: in a CMPL case resolved by settlement, the settling party contests OIG's allegations and denies liability, and no CMP judgment or finding of liability is entered. A settlement typically releases CMP exposure only for the conduct and period it covers. Program exclusion is a separate question: the CMPL lets OIG pursue exclusion in the same proceeding, so a provider should confirm before signing whether a Reinstatement After an OIG Exclusion process is part of the deal. A settlement resolves only what it names: a published OIG settlement, for example, keeps criminal liability outside its release even while resolving the named CMPL and False Claims Act exposure. A provider should confirm in writing whether a qui tam suit, a state Medicaid claim, or exclusion is addressed before treating a CMPL matter as closed.
Why Early Legal Counsel Is Critical
It is critical that healthcare providers promptly retain experienced healthcare defense counsel upon receiving a CMPL notice, subpoena, audit finding, or other government inquiry. Early legal intervention can protect the provider's rights, help shape appropriate responses to OIG's requests, avoid inadvertent admissions, preserve relevant defenses, and allow counsel to communicate with OIG on the provider's behalf. Delaying legal representation can significantly affect the outcome of a CMPL matter and expose the provider to unnecessary risk.
How Health Law Alliance Can Help
We defend healthcare providers at every stage of a CMPL matter, from the first OIG notice through an ALJ hearing and any overlapping False Claims Act or Anti-Kickback Statute exposure. Health Law Alliance's attorneys have overseen 2,000+ audits and handled 5,000+ matters, with 25+ years of experience. If your practice has received an OIG notice letter or any other federal fraud inquiry, contact our healthcare fraud defense team for a free, confidential consultation.





