A telehealth audit that begins as a routine Unified Program Integrity Contractor (UPIC) documentation request can turn into a federal criminal referral inside the same file. In June 2025, the Department of Justice's National Health Care Fraud Takedown charged 49 defendants in schemes tied to over $1.17 billion in fraudulent telemedicine and genetic-testing claims, part of a $14.6 billion enforcement sweep. The audit that opens the file might review evaluation and management coding on a telehealth billing audit or the time logs behind a remote patient monitoring claim, and either can escalate the same way. For a provider already answering a UPIC request, the stakes are not limited to a recoupment demand, and the signals that mark the shift toward a criminal referral are specific enough to watch for.

From Documentation Request to Federal Subpoena

A UPIC audit ordinarily begins with an additional documentation request (ADR): a letter naming the claims under review and a deadline to produce records, including the prescribing records behind any controlled-substance orders written through the platform. Most of these requests close with a payment determination or a recoupment demand and nothing more. The first sign that a file has moved past a payment review is when the request itself changes character: instead of an ADR from the contractor, the practice receives a civil investigative demand (CID) or a grand jury subpoena from the Department of Justice or the HHS Office of Inspector General (OIG). A subpoena asks for many of the same underlying records as an ADR, but it is issued under a different legal authority, and that authority only attaches once a fraud referral is already under consideration.

Who Is Asking Changes

A UPIC's own auditors and nurse reviewers rarely make direct contact with a telehealth practice beyond the records request itself. When an OIG special agent or an FBI agent calls or appears at the practice, or a billing employee or prescribing clinician is asked to sit for an interview, the file has moved to law enforcement. OIG's July 2022 Special Fraud Alert on telemedicine arrangements named the patterns that draw this attention: patients recruited through telemarketing or online advertising for free or low-cost items, a prescriber paid per completed consultation regardless of medical necessity, and referral arrangements between the telemedicine company and pharmacies, laboratories, or durable medical equipment suppliers. An Anti-Kickback Statute arrangement inside a telehealth referral chain is what most often turns an audit into an investigation.

Civil and Criminal Tracks Run at the Same Time

A UPIC's findings can support a civil recovery under the False Claims Act and a criminal charge under the federal health care fraud statute, 18 U.S.C. Section 1347, from the same claims sample, because the two tracks answer different questions under different standards of proof. The False Claims Act is a civil statute proved by a preponderance of the evidence; Section 1347 is a criminal statute that requires proof beyond a reasonable doubt and carries a prison sentence. Because the tracks are not mutually exclusive, a telehealth provider can face a payment suspension, an extrapolated recoupment demand, and a parallel criminal referral arising from the identical set of encounters.

The Target Letter

The clearest sign that an individual, not just the practice, is under criminal review is a target letter: written notice from a U.S. Attorney's Office that the recipient is a target of a federal grand jury investigation. A target letter does not always follow a subpoena that has already been answered, and it does not guarantee an indictment will follow. It confirms that prosecutors believe they already have enough evidence to name that person, and it opens a narrow window in which counsel can attempt to shape the charging decision before it is made.

A UPIC audit is a fraud screen, not a payment review, and a subpoena that replaces a routine documentation request means a criminal referral is already on the table.

Why Early Legal Counsel Is Critical

It is critical that telehealth providers promptly retain experienced healthcare defense counsel upon receiving a subpoena, audit notice, investigative request, or other government inquiry. Early legal intervention can protect the provider's rights, ensure appropriate responses to government requests, avoid inadvertent admissions, preserve relevant defenses, and allow counsel to communicate with investigators on the provider's behalf. Delaying legal representation can significantly affect the outcome of a matter and expose the provider to unnecessary risk.

How Health Law Alliance Can Help

Health Law Alliance has handled 5,000+ matters across healthcare regulatory and audit defense over 25+ years, including UPIC audits that moved into parallel civil and criminal review. If your telehealth practice has received a subpoena, a target letter, or a UPIC audit request tied to telemedicine prescribing or billing, contact Health Law Alliance's telehealth defense attorneys for a free, confidential consultation before you respond.