FinCEN's September 2026 analysis identifies approximately $17.5 billion in suspicious financial activity potentially linked to health care fraud. The data identifies typologies and investigative leads, not adjudicated fraud.
Updated September 26, 2026: This article retains its complete original text, with researched updates integrated into the relevant sections.
FinCEN’s September 2026 Financial Trend Analysis on health care fraud examines 5,702 Bank Secrecy Act reports filed from March 1, 2025 through February 28, 2026. Those reports identified approximately $17.5 billion in suspicious activity potentially connected to health care fraud.
The number is significant, but it is easy to misuse. It includes completed and attempted transactions. Reports may include inbound and outbound transfers, continuing activity, amendments, transactions between related accounts, lawful and illicit activity associated with the same subject, and filer errors. The figure is not an adjudicated fraud total, a measure of unique victim losses, or a count of proceeds belonging to distinct schemes.
That limitation is not a reason to discount the report. It is a reason to use it correctly: as a source of patterns and investigation questions rather than a list of proven cases.
What FinCEN measured
FinCEN selected reports that either identified health care fraud as the suspicious activity type or combined “suspicious receipt of government payments” with health-care-fraud key terms. It used automated and manual processes to remove false positives and validate the dataset. Selection was based on filing date, so the underlying conduct could predate the review period.
Depository institutions filed about 89 percent of the reports and accounted for nearly 87 percent of the reported suspicious amount. Two large depository institutions filed 29 percent of the reports. The 471 filing institutions also included securities and futures firms, money-services businesses, insurers, casinos or card clubs, and loan or finance companies.
Concentration matters when interpreting trends. A rise or pattern may reflect detection and reporting practices as well as changes in underlying conduct. The SAR population is not a random sample of the health care economy, and suspicious activity reporting does not represent the full scope of suspected health care fraud.
FinCEN's September 2026 health care fraud analysis is valuable because it shows what financial institutions are seeing in transaction data.
It is equally important to understand what the data does not establish.
<Sector references require care
<
A provider category appearing frequently in suspicious-activity reporting should not be treated as presumptively fraudulent.
A compliant monitoring program should identify facts and behavior that elevate risk rather than assigning guilt based on industry classification.
The patterns can improve transaction review
FinCEN found reports involving a mix of Medicare, Medicaid, and private insurance payments. Medicare and/or Medicaid were named in 2,190 reports, about 38 percent of the dataset, and Medicare Administrative Contractors appeared in 1,247 reports. Home health businesses were the most frequently identified suspected provider type, appearing in 20 percent of health-care-fraud-related reports. Other frequently identified categories included hospice, behavioral health and addiction treatment, medical equipment, and adult or child daycare.
The report describes suspected perpetrators moving funds through simple transfers and more complex layering, then using funds for personal expenses or luxury goods, with some international transfers. It also notes a small percentage of reports involving possible large fraud rings or criminal networks, while stating that most filers did not specifically identify links to known transnational criminal organizations.
These are not automatic alert outcomes. An institution reviewing a health care provider should compare transaction behavior with the entity’s stated services, ownership, geography, payer relationships, expected revenue, staffing, licensing, and ordinary expenses. Payments from a government program or transfer to a foreign counterparty are not inherently unlawful. The question is whether the combined facts depart from a plausible business model and whether the explanation is supported.
<The report is useful for typologies
<
FinCEN's analysis can help institutions refine:
- customer risk assessments;
- transaction monitoring;
- government-payment analytics;
- related-account review;
- payment-chain tracing;
- entity-network analysis;
- escalation criteria; and
- SAR narratives.
The report should inform risk detection, not replace customer-specific investigation.
Investigation should move from account activity to the enterprise
A focused review begins with a chronology of incoming health care payments, transfers among related accounts, payments to owners or insiders, cash withdrawals, card spending, wires, checks, digital-asset activity, and international flows. Investigators should identify duplicate counting and transfers between accounts before calculating exposure.
The entity map should connect legal names, trade names, tax identifiers, addresses, owners, signers, phone numbers, devices, counterparties, referring businesses, billing entities, and affiliated providers. Shared residential addresses, rapid formation of multiple entities, unexplained changes in ownership, or payment flows inconsistent with stated services may warrant deeper review. None proves fraud by itself.
Relevant evidence may sit outside transaction systems. Onboarding files, beneficial-ownership records, licenses, websites, claims or remittance information, contracts, invoices, correspondence, prior alerts, employee notes, and public enforcement records can clarify the customer’s activity. Privacy and health-information rules should be considered when requesting, using, or sharing records.
When employee conduct or an override is implicated, the investigation should be directed by someone outside the challenged decision chain. Preservation should cover case-management history, model or rule changes, alert dispositions, communications, and customer documents. Investigators should state data gaps and avoid converting an inability to verify into an affirmative finding of fraud.
Escalation decisions should remain distinct
One fact pattern can trigger several decision processes, but they should not be collapsed. The institution may need to decide whether to restrict activity, continue or exit a relationship, file or supplement a suspicious activity report, contact law enforcement, address a sanctions issue, remediate monitoring, or investigate employee conduct.
Each decision has its own legal standard, evidence, confidentiality, timing, and owner. A SAR decision is not a criminal verdict. A relationship decision may account for contractual and risk considerations that do not establish unlawful conduct. If a matter is referred externally, internal descriptions should continue to use accurate terms such as “suspected,” “reported,” or “alleged” until findings support stronger language.
FinCEN’s March 2026 health care fraud advisory may help teams test typologies and reporting language. The September analysis notes that later reports, although outside the analyzed period, showed trends consistent with its findings. Institutions should still verify current guidance and use the applicable filing instructions rather than copying report terminology mechanically.
Measure the control response, not just alert volume
A useful lookback asks whether scenarios capture relevant inflows, rapid dispersal, related accounts, personal spending, international movement, and provider types while controlling false positives. Quality testing should examine whether analysts recognize payer intermediaries, reconstruct flows, document contradictory evidence, and escalate consistently.
Management information should separate alerts, cases, SARs, subjects, and dollars. Otherwise, amended filings and inter-account transfers can inflate apparent impact in the same way aggregate SAR figures can be misunderstood. Trends should be interpreted alongside customer growth, rule changes, staffing, and reporting-quality reviews.
FinCEN’s analysis gives institutions a richer map of suspected activity. Its most important methodological lesson is equally valuable: reported suspicion is evidence to examine, not a conclusion to announce.
Assessing suspicious payment activity or a potential control failure? Contact Braeden Anderson to discuss a focused investigation, the evidence needed to evaluate the concern, and appropriate remediation. Discuss suspicious-activity concerns.
September 2026 researched developments
September 26, 2026 researched update: The following developments supplement the original article where the current research did not map cleanly to an existing section.
The report is based on BSA information
FinCEN analyzed BSA reporting covering a one-year period from March 1, 2025 through February 28, 2026.
The agency identified approximately $17.5 billion in suspicious financial activity potentially linked to health care fraud.
The amount can include attempted and completed transactions.
It should not be read as a finding that $17.5 billion was stolen.
Suspicion is not proof
BSA reports are generated from financial institutions' monitoring and reporting obligations.
They can include:
- attempted transactions;
- completed transactions;
- legitimate and illegitimate activity involving the same subject;
- duplicate or overlapping amounts;
- incomplete information; and
- errors.
A suspicious activity report is an investigative lead.
It is not a judicial finding.
The content of this article is intended to provide a general guide to the subject matter. Specialist advice should be sought about your specific circumstances.
[View Source]