1. Home
  2. |Insights
  3. |DOJ Memo Limits the Use of Agency Guidance in FCA Enforcement

DOJ Memo Limits the Use of Agency Guidance in FCA Enforcement

Client Alert | 1 min read | 02.22.18

A recent memorandum issued by Associate Attorney General Rachel Brand (Brand Memo) prevents Department of Justice (DOJ) civil litigators from relying on agency guidance documents to demonstrate violations of the False Claims Act (FCA).  Specifically, the Brand Memo prohibits using noncompliance with agency guidance documents to presumptively or conclusively establish violation of the underlying law or regulation.  The Brand Memo references an earlier memorandum issued by Attorney General Jeff Sessions (Sessions Memo) that prohibits DOJ agencies from creating binding standards in guidance documents without engaging in notice-and-comment rulemaking.  The Brand Memo reiterates the core premise of the Sessions Memo – that guidance documents cannot create legal obligations.  It also expands on the Sessions Memo by directing DOJ litigators to apply that premise when interpreting other agencies’ guidance documents in civil enforcement actions.  While DOJ litigators may continue using agency guidance for “proper purposes,” such as to establish that a party had the requisite knowledge of a legal mandate because the party was familiar with a guidance document that explained it, this new policy represents a distinct limitation on the use of agency guidance in FCA enforcement.    

Insights

Client Alert | 7 min read | 08.17.26

Delayed Notification of Cyberattacks May Trigger HIPAA Breach Notification Rule

After identifying a ransomware attack in 2021, OSF Healthcare System waited until its forensic investigation had concluded before notifying the U.S. Department of Health and Human Services (HHS) — and the affected individuals — of the breach. The 110-day delay (nearly double the 60-calendar-day notification deadline mandated by the HIPAA Breach Notification Rule) triggered an investigation from HHS’s Office for Civil Rights (OCR). The health system’s investigation determined that protected health information (PHI) had been stolen....