FinCEN found $17.5bn of suspected health care fraud in 5,702 BSA reports. What the filings caught, what they missed, and what it changes for AML teams.
Table of contents
FinCEN identified approximately 17.5 billion dollars of suspicious activity potentially linked to health care fraud in one year of Bank Secrecy Act reporting, published on 9 September 2026. That is a reporting total, not a loss estimate. The Financial Trend Analysis covers 5,702 reports filed between 1 March 2025 and 28 February 2026, and imposes no new duties.
- FinCEN analysed 5,702 health care fraud reports from 471 institutions, averaging 3.3 million dollars per filing against a median near 600,000 dollars.
- 408 depository institutions filed about 89 percent of them and roughly 15.2 billion dollars of the total; two banks alone filed 29 percent.
- Home health care was the most common suspected provider type, and the majority of those businesses were registered at residential addresses.
- Fewer than five percent described a seemingly legitimate provider, and FinCEN says that segment is understated, as is health care fraud reporting overall.
- The report is threat pattern information issued under Section 6206 of the Anti-Money Laundering Act of 2020, not a rule.
What did FinCEN find in the health care fraud data?
FinCEN published a Financial Trend Analysis on 9 September 2026 setting out patterns in Bank Secrecy Act reports tied to suspected health care fraud. It drew on 5,702 filings submitted between 1 March 2025 and 28 February 2026 by 471 institutions, and put the reported suspicious activity at roughly 17.5 billion dollars.
That figure counts completed and attempted transactions, and FinCEN warns it can be over-inclusive. Treasury Secretary Scott Bessent said in the announcement that "financial institutions have given law enforcement critical insight into the illicit actors".
The distribution matters more than the headline. Filings arrived steadily, about 475 a month, with no spike or dip across the period. The average sits at roughly five times the median, so a small number of very large reports carry the total. Filers most often named subjects in California, then Florida, New York and Minnesota. Of 13,277 subjects across all 50 states and multiple US territories, only 187 had a non-US address.
| Measure | Value |
|---|---|
| Review period | 1 March 2025 to 28 February 2026 |
| BSA reports analysed | 5,702, from 471 institutions |
| Suspicious activity reported | approximately 17.5 billion dollars |
| Average per filing | approximately 3.3 million dollars |
| Median per filing | approximately 600,000 dollars |
Legal status matters. This is not a rule. FinCEN publishes these analyses under Section 6206 of the Anti-Money Laundering Act of 2020, which requires it to periodically release BSA-derived threat pattern information. What it changes is not an obligation but the evidence base against which an examiner judges your programme.
Who filed the reports, and what does that concentration tell you?
Filing was heavily concentrated. 408 depository institutions submitted 5,080 of the 5,702 reports, about 89 percent, covering roughly 15.2 billion dollars of the suspicious activity. Two banks, the largest in the dataset by assets, filed 29 percent of everything, and one filed roughly 1,100 reports, double any other filer.
A second concentration sits inside the first. Fifty-nine of those depository institutions are Puerto Rican financial cooperatives, or cooperativas, and they filed 1,641 reports, about 29 percent of the dataset. Almost all describe one pattern: customers lowering account balances by cashier's check or cash withdrawal ahead of a Plan Vital Medicaid eligibility meeting, requesting a balance certification letter, then re-depositing the funds the same day or within a couple of days. Roughly 67 percent of that activity was reported below 15,000 dollars. That is benefits eligibility fraud, not health care fraud by a provider, and it sits inside the same 17.5 billion dollar total.
Strip those eligibility filings out and the provider picture sharpens considerably.
| Suspected provider type | Share of reports |
|---|---|
| Home health care | 32 percent |
| Hospice care | 8 percent |
| Mental, behavioural health and addiction treatment | 7 percent |
| Medical equipment including DME | 5 percent |
| Daycare, adult and child | 3 percent |
Source: FinCEN Financial Trend Analysis, Figure 5, whose footnote is load-bearing. These shares exclude the Puerto Rico Medicaid eligibility reports; against the whole dataset home health care is more than 21 percent, not 32.
One detail sits underneath the largest of those categories. FinCEN writes in the Financial Trend Analysis that "The majority of home health care businesses were registered at residential homes". A provider book screened on entity name and licence alone will not surface that.
The money then moves in recognisable ways. FinCEN describes circular transactions to other businesses linked to the owner, payments to individuals disguised as payroll, and receipts commingled with cash, P2P transfers, wires and checks. Proceeds funded personal expenses, luxury goods, travel, real estate and construction, and in one case checks payable to money services businesses specialising in international transfers.
What changes for your BSA obligations?
Nothing in the Financial Trend Analysis is new law, but it sharpens three existing duties. The operative instrument behind all three is Advisory FIN-2026-A001 of 30 March 2026, issued with the FBI and HHS-OIG, whose SAR key term is HCF-2026-A001.
The first duty is suspicious activity reporting, under 31 CFR 1020.320 for banks and its parallels for other filer types. The Advisory asks institutions to put the key term HCF-2026-A001 in Suspicious Activity Report field 2 and the narrative, tick field 34(g) for health insurance, and add fields 36 and 38 where money laundering applies. If your filings do not carry that key term, your work is invisible to this dataset.
The second is customer due diligence, including the beneficial ownership duty at 31 CFR 1010.230, collected at account opening and refreshed on a risk basis. The health care fraud red flags are ownership questions, not transaction questions. They cover beneficial owners with prior health care or benefits fraud convictions, and owners appearing on accounts for separate and distinct providers. They cover changes to the individuals listed as beneficiaries of a corporate account with no change of name or Tax Identification Number. They cover accounts reached through a device ID or IP address linked to multiple customers. Those are ultimate beneficial owner and identity-linkage checks, and most fail if you screen only the entity.
Two of them are cross-institution by construction, which is why the Advisory covers the information sharing safe harbour at section 314(b) of the USA PATRIOT Act. You cannot see an owner recurring across rival banks from inside one of them.
The third is transaction monitoring calibration. The Advisory treats deviations in payment volume, timing and credit or debit activity after enrolment or a change of ownership as red flags in their own right, because reimbursement flows from Medicare Administrative Contractors and state agencies are otherwise predictable. MACs appeared in 1,247 reports, 22 percent of the dataset, and Medicare or Medicaid in 2,190, about 38 percent. A rule that does not know which customers receive MAC payments cannot apply that logic.
What is the reporting still missing?
The uncomfortable finding is about visibility, not volume. FinCEN says institutions mostly do not describe the underlying scheme, because banks see funds arriving from a health agency or insurer and cannot see the billing that produced them. Detail usually appears only after a customer is charged, or when law enforcement tells the bank what happened. So the dataset describes laundering patterns well and the health care fraud itself poorly.
It also skews towards the obvious. Most filers described purported providers that appeared to deliver no medical services at all, operating through apparent shell companies. At least 43 percent of the reports outside the Puerto Rico eligibility cluster identified companies registered at residential homes, and FinCEN noted businesses at boarded-up storefronts and unsigned strip mall units. Fewer than five percent of the dataset described seemingly legitimate providers engaged in double billing, phantom billing, upcoding, unbundling, kickbacks or medically unnecessary services. FinCEN is explicit that this segment is underrepresented rather than rare, because those customers show few obvious red flags.
A second tension follows. Filers largely did not identify links to known transnational criminal organisations, yet the March Advisory says health care fraud is increasingly perpetrated by them. About four percent of reports did flag larger fraud rings or criminal networks, just not TCOs, and FinCEN's footnote attributes the Advisory's view partly to evidence from outside BSA data.
Three risks follow. A programme tuned to catch shell providers will keep catching them, then report a clean record against a category it never tested. A single total that mixes a 15,000 dollar balance certification scheme with an FTA case example of a 20 million dollar New York pharmacy paying wholesalers registered in Hong Kong is a poor basis for alert thresholds. And roughly five percent of filings involved international transfers, reaching 32 countries and most often Hong Kong, usually routed through a second US party rather than the provider, so the cross-border leg is underobserved.
How does this compare with the enforcement record?
The Department of Justice charged 455 defendants in June 2026 over more than 6.5 billion dollars of alleged false claims, and 324 defendants in June 2025 over more than 14.6 billion dollars. Those are charged claims, a different unit from 17.5 billion dollars of flagged flows, so read this as scale rather than arithmetic. Health care fraud reporting is over-inclusive by design and is not a loss estimate.
| Benchmark | Figure | Date |
|---|---|---|
| FinCEN FTA, suspicious activity reported | approximately 17.5 billion dollars | 9 September 2026 |
| DOJ national takedown, alleged fraud | more than 6.5 billion dollars, 455 defendants | 23 June 2026 |
| DOJ national takedown, alleged fraud | more than 14.6 billion dollars, 324 defendants | 30 June 2025 |
| CMS action alongside the 2026 takedown | 1,079 providers suspended, 1,403 billing privileges revoked | 23 June 2026 |
Sources: FinCEN, Treasury and Department of Justice releases, linked below.
The trend line is the useful part, and it cuts the other way. The March Advisory recorded a 330 percent rise in reporting between 2020 and 2025, peaking with more than 3,800 initial SARs ticking field 34(g). It reads that as real growth since the pandemic rather than better detection, and cautions that even this reporting "likely represents only a small fraction" of the underlying activity.
Why is this an identity problem as much as a payments problem?
The entity being onboarded is frequently not what it claims to be, and the patients being billed for did not consent. FinCEN describes sophisticated health care fraud schemes that incorporate identity theft and forgery alongside the money laundering. The clearest illustration is Operation Gold Rush, charged in June 2025, in which individuals sent into the United States acting under assumed identities from overseas bought dozens of medical supply companies. They then submitted 10.6 billion dollars in Medicare claims by exploiting the stolen identities of more than one million Americans.
Read the red flags again in that light. Owners recurring across unrelated providers, beneficiary changes with no change of Tax Identification Number, and device or IP links between supposedly distinct customers are all attempts to find one real person behind several corporate masks. That is a KYB and beneficial ownership problem, the same structure we covered when FinCEN moved on federal student aid fraud and synthetic identities in July.
The patient side carries its own exposure. Health identifiers are among the most sensitive data a firm can hold, and the stolen ones behind these claims came from somewhere. Every organisation that stockpiles identity documents to prove a customer once passed a check holds raw material for the next scheme.
How should compliance teams respond?
Start by checking whether your health care fraud filings carry HCF-2026-A001 and field 34(g), because otherwise your reporting is absent from the national picture. Flag which business customers receive payments from a Medicare Administrative Contractor or a state health agency, and treat enrolment and ownership changes as monitoring events rather than static attributes. Run a registered-address test across your provider book. Re-screen beneficial owners for prior convictions, and look for owners and signatories recurring across nominally unrelated customers. Finally, sample the customers that look legitimate, since that is the segment this dataset admits it cannot see.
Zyphe's approach is to make the underlying identity verifiable without accumulating the data that makes a breach worth mounting. We read the document chip to ICAO 9303 and eIDAS standards, with two-step liveness and no image upload. We resolve ownership recursively across 240 or more corporate registries at a configurable threshold, and shard personal data across a network so no single node holds a complete record. If you are rebuilding provider onboarding around ownership rather than documents, book a demo or read how our AML software and PII storage fit together.
The bottom line
The value of this report is not its headline number, which mixes unlike things together, but its account of where bank visibility stops. Institutions are good at spotting a provider that does not exist and poor at spotting one that does. That gap is an ownership and identity problem before it is a monitoring problem. Teams running KYC onboarding for health care customers should treat enrolment, ownership change and owner recurrence as the primary risk signals. The next Section 6206 analysis is the test: if the legitimate-provider share stays under five percent, the blind spot has not moved.
Cited sources
- Treasury: Treasury Uncovers $17.5 Billion in Suspected Health Care Fraud, 9 September 2026
- FinCEN Financial Trend Analysis: Health Care Fraud: Trends in Bank Secrecy Act Data
- FinCEN Advisory FIN-2026-A001 on Health Care Fraud Schemes, SAR key term HCF-2026-A001, 30 March 2026
- DOJ: 2026 National Health Care Fraud Takedown, 455 defendants, 23 June 2026
- DOJ: 2025 National Health Care Fraud Takedown, 324 defendants, 30 June 2025
Michelangelo Frigo (Co-Founder at Zyphe) Michelangelo Frigo is a privacy and identity infrastructure expert and co-founder of Zyphe.