AI in Healthcare: Five Use Cases and Their False Claims Act Exposure

The False Claims Act is the federal government’s primary tool for combating healthcare fraud, and it is working. In fiscal year 2025, the Department of Justice recovered a record $6.8 billion in FCA settlements, with $5.7 billion of that coming from healthcare alone. That number did not happen by accident. The DOJ has expanded its enforcement infrastructure, built data analytics capacity, and explicitly named artificial intelligence as a priority enforcement area.

For healthcare organizations deploying AI — whether in the clinic, the billing department, or the patient engagement channel — this is not background noise. It is a direct signal that the tools you are adopting right now are on the government’s radar, and that the compliance frameworks built for a pre-AI environment will not be sufficient to protect you.

This post walks through five specific AI use cases that are reshaping healthcare operations and explains the particular False Claims Act exposure each one creates. The goal is not to discourage AI adoption. The benefits are real. The goal is to make sure your organization understands what it is taking on before it deploys.


What the False Claims Act Actually Requires

Before getting into the use cases, a quick primer on the law itself. The False Claims Act, 31 U.S.C. § 3729 et seq., imposes liability on any person or entity that knowingly submits a false or fraudulent claim for payment to the federal government. In healthcare, this means claims submitted to Medicare, Medicaid, TRICARE, or other federal healthcare programs.

“Knowingly” under the FCA does not require proof of specific intent to defraud. The statute covers actual knowledge, deliberate ignorance, and reckless disregard of the truth. This definition is important when discussing AI: an organization does not have to know that its AI tool produced a false claim. If the organization was reckless — if it deployed a tool it knew could produce errors, failed to validate outputs, or ignored red flags — that may be enough.

Penalties for FCA violations currently run between approximately $13,700 and $27,500 per false claim, plus treble damages. In a healthcare context, where a single billing run can generate thousands of claims, the exposure compounds quickly.

The FCA also permits qui tam suits, meaning private individuals — including current or former employees — can file suit on the government’s behalf and share in any recovery. Disgruntled employees who know how your AI tools work are potential whistleblowers.


Use Case 1: Clinical Decision Support

Clinical decision support (CDS) tools use AI to analyze patient data and generate recommendations — flagging drug interactions, suggesting diagnoses, prompting preventive screenings, or recommending treatment protocols. These tools are embedded in electronic health records, used at the point of care, and increasingly capable of processing more clinical information faster than any human reviewer can.

The FCA exposure: When a CDS tool’s recommendation becomes the basis for ordering a service or treatment that is then billed to Medicare or Medicaid, the tool’s output sits in the chain of causation for the resulting claim. If the tool systematically overcodes diagnoses to increase risk adjustment scores, recommends procedures that are not medically necessary for the patient’s actual condition, or generates outputs that are not supported by the underlying clinical record, the resulting claims may be false.

HHS-OIG has specifically identified “querying physicians via electronic medical record platforms (including prompts generated by artificial intelligence algorithms)” as potentially abusive and fraudulent conduct when those prompts are designed to drive utilization rather than guide care. The concern is that AI tools can be architected — intentionally or by virtue of their training data and optimization targets — to generate prompts that increase billing rather than improve outcomes.

What to watch for: CDS tools that are trained on historical claims data rather than clinical outcomes data carry particular risk. If the model was optimized to predict what was billed in similar cases rather than what was clinically indicated, its recommendations will reflect historical billing patterns — including any overcoding embedded in the training data. You need to know what your tool was trained on, what it was optimized for, and how its recommendations correlate with your organization’s billing patterns over time.

Clinician attestation matters here. When a physician clicks through a CDS recommendation without genuinely reviewing the basis for it, the certification on the resulting claim — that services were medically necessary — may not be accurate. Training clinicians to meaningfully engage with CDS outputs rather than treat them as automatic approvals is both a patient safety and a compliance obligation.


Use Case 2: Patient-Facing Chatbots

AI-powered chatbots are now a common feature of patient portals. They schedule appointments, answer questions about coverage and benefits, collect intake information, triage symptoms, and in some deployments provide health coaching or mental health support. From an operational standpoint, they reduce call center volume and improve patient access. From a compliance standpoint, they create several distinct exposure vectors.

The FCA exposure: The primary FCA risk from patient chatbots arises when chatbot interactions generate or influence billable services. If a chatbot conducts a symptom triage that is then billed as a telehealth visit, the characterization of that interaction as a billable service depends on whether it actually meets the criteria for that service. If the chatbot collects information that is later used to support diagnoses that were not clinically evaluated by a treating physician, the resulting claims may not be supported.

A recent DOJ enforcement action made this risk concrete. In connection with the 2025 National Health Care Fraud Takedown, the DOJ targeted the use of AI to fabricate patient consent in telehealth schemes. Chatbots were used to simulate patient interactions, generate consent documentation, and trigger prescription or service orders that were then billed to federal programs. The patients in some cases had no substantive clinical encounter at all.

What to watch for: Beyond outright fraud, the subtler risk is scope creep. A chatbot deployed for appointment scheduling that gradually expands into symptom assessment, care recommendations, or de facto clinical triage creates documentation that may be used to support claims you cannot substantiate. Audit what your chatbot is actually saying to patients. Compare chatbot interaction logs to subsequent billing. If the chatbot is generating clinical-sounding outputs, your compliance team needs to be reviewing those outputs with the same scrutiny applied to clinical documentation.


Use Case 3: Ambient Scribing

Ambient scribing tools use microphones and AI to listen to patient-provider encounters and automatically generate clinical documentation — history of present illness, assessment, plan, and billing codes. The appeal is obvious: documentation burden is one of the leading causes of physician burnout, and ambient scribing promises to restore time to patient care. The tools have improved rapidly and several major EHR vendors now offer integrated ambient scribing.

The FCA exposure: Ambient scribing inserts an AI system directly into the clinical documentation process, and clinical documentation is the evidentiary basis for every claim you submit. If the AI mishears, mischaracterizes, or embellishes what happened in the encounter, the resulting note may not accurately reflect the services rendered. If that note supports a claim for services that were not actually provided — or that were provided at a lower level than billed — the claim is false.

Several specific risks deserve attention. First, ambient scribing tools can generate notes that reflect what a thorough evaluation would have included rather than what actually happened. If a physician spends four minutes with a patient and the AI generates a note suggesting a comprehensive evaluation, the evaluation and management code supported by that note may be inflated. Second, the AI may capture and document conditions mentioned in passing — a patient mentions a family history of diabetes, for example — that the physician did not evaluate or address, and the documentation of those conditions may influence coding decisions.

Third, there is the attestation problem. When a physician signs a note generated by an ambient scribing tool, they are certifying its accuracy. In practice, physicians reviewing AI-generated notes may miss errors that would be caught if they wrote the notes themselves. This is not a hypothetical: class action litigation has already emerged targeting healthcare AI recordings, raising questions about the accuracy of AI-generated documentation and the consent practices around recording patient encounters.

What to watch for: Your ambient scribing implementation needs a meaningful physician review and attestation workflow — not a rubber stamp. Document that physicians are reviewing AI-generated notes before signing, not just clicking through. Conduct regular audits comparing AI-generated documentation to audio recordings. Ensure your informed consent process for patients covers the recording of their encounters.


Use Case 4: Patient Flow Management

AI patient flow management tools optimize hospital operations — predicting admissions, managing bed allocation, coordinating care transitions, forecasting discharge timing, and flagging patients at risk for readmission. These tools are embedded in hospital information systems and used by case managers, utilization review teams, and discharge planners. They can meaningfully improve patient outcomes and reduce avoidable readmissions.

The FCA exposure: The FCA risk in patient flow management is more indirect than in billing or documentation, but it is real. It operates primarily through the utilization review function: decisions about whether a patient meets criteria for inpatient admission versus observation, whether a continued stay is medically necessary, and when a patient is ready for discharge are all consequential billing determinations. If an AI tool is driving those decisions — and if the tool is optimized for throughput, bed turnover, or revenue rather than clinical criteria — the resulting admission and discharge decisions may not meet medical necessity standards.

CMS’s two-midnight rule provides the core framework: inpatient admission is appropriate when the admitting physician expects the patient to require hospital care spanning two or more midnights. If an AI tool is recommending discharge or reclassification from inpatient to observation status based on operational metrics rather than this clinical standard, and if the resulting billing reflects the AI’s recommendation rather than genuine medical necessity review, the claims may be false.

Prior authorization denials driven by AI present a related risk. Several major insurers have faced litigation and regulatory action for using AI to deny claims with inadequate clinical review. Healthcare providers on the other side of those denials — who may be appealing to continue necessary care — should document their medical necessity determinations carefully and not defer to AI-generated denial determinations without genuine clinical review.

What to watch for: Ensure that your patient flow AI is configured to support utilization review rather than replace it. The tool should flag cases for human review, not make final admit/discharge determinations. Document the clinical basis for admission and continued stay decisions independently of the AI’s output.


Use Case 5: Billing Optimization

AI billing optimization tools are perhaps the most direct source of FCA exposure in this list. These tools crawl electronic health records, parse clinical notes, identify billable diagnoses or procedures that were not initially coded, suggest higher-acuity codes, and help organizations avoid undercoding. In the Medicare Advantage context, they are used to surface Hierarchical Condition Category (HCC) codes that increase risk adjustment payments.

The appeal is straightforward: healthcare organizations routinely leave money on the table through undercoding, and AI tools can identify missed revenue. But the same capability that finds legitimate missed codes can also surface diagnoses that are documented somewhere in the record but were not actually evaluated, treated, or relevant to the encounter — and adding those codes to claims may constitute fraud.

The January 2026 Kaiser Permanente settlement illustrates the stakes. Kaiser Permanente paid $556 million — the largest Medicare Advantage FCA settlement in history — for a practice that amounts to exactly what AI billing optimization tools are designed to do: mining charts to find diagnoses that boost HCC risk adjustment scores. The diagnoses in question were found in historical records but were not evaluated or treated during the claim period. The government’s theory was that claiming payment based on those codes misrepresented the health status of Kaiser’s Medicare Advantage enrollees.

The FCA exposure: The core problem is that AI billing optimization tools generally have no native mechanism for distinguishing between legitimate undercoded diagnoses and historical conditions that do not support current claims. The tool finds a code. The tool reports it. The coder adds it. The claim goes out. Nobody asked whether the condition was actually evaluated during the relevant period.

HHS-OIG has been explicit about this pattern. Its guidance identifies chart mining to identify historical diagnoses as potentially abusive conduct, particularly in the Medicare Advantage context where risk adjustment payments create strong financial incentives to add codes.

What to watch for: Any AI billing tool that is marketed primarily around finding “missed revenue” or “undercoded diagnoses” should be evaluated with care. The operative question is not whether the diagnosis appears somewhere in the record — it is whether the condition was evaluated, addressed, and clinically relevant during the claim period. Your compliance program should include a process for reviewing AI-suggested code additions against this standard, not just accepting the tool’s output. Document your review process.


The Compliance Architecture You Need

Across all five of these use cases, several compliance principles apply consistently.

Know your tools. Before deploying an AI tool, understand what it was trained on, what it was optimized for, and what its known failure modes are. An AI tool that was trained on claims data and optimized for revenue will behave very differently from one trained on clinical outcomes and optimized for accuracy. The difference matters enormously for FCA exposure.

Human review is not optional. The FCA’s scienter standard — which covers reckless disregard — means that deploying an AI tool and accepting its outputs without meaningful human review can constitute knowing submission of false claims. Every AI output that influences a claim needs a human in the loop who is genuinely reviewing it, not rubber-stamping it.

Audit your AI outputs. Build regular audits into your compliance program that compare AI recommendations or outputs to actual clinical and billing records. If your ambient scribing tool is systematically generating notes that support higher E&M codes than your historical patterns, that is a finding that requires action. If your billing optimization tool is adding HCC codes that do not correspond to conditions addressed in current encounters, that is a finding that requires action.

Train your staff. Clinicians, coders, and case managers using AI tools need to understand what the tools can and cannot do, what their compliance obligations are when working with AI outputs, and how to escalate concerns. A coder who adds a code because the AI suggested it without knowing whether the underlying diagnosis meets current documentation standards is a liability.

Document your governance. When a compliance issue arises, the government will ask what oversight mechanisms you had in place. Document your AI governance program, your validation process, your audit findings, and the remedial actions you took. The existence of a robust, documented compliance program is not a defense to FCA liability, but it is evidence that the organization was not reckless.

The government has made clear that AI in healthcare is an enforcement priority. The organizations that navigate this period successfully will be the ones that invest in compliance infrastructure before the subpoena arrives, not after.


This post is for general informational purposes only and does not constitute legal advice. Reading this post does not create an attorney-client relationship. If you have questions about your specific situation, consult a qualified attorney.



Leave a Reply