Key Takeaways

  • The Department of Justice’s 2026 White Collar Crime Enforcement Priorities explicitly target cryptocurrency fraud, health care fraud, and corporate compliance failures, with a renewed emphasis on individual accountability under the Yates Memo principles.
  • Expect a dramatic increase in prosecutions under the Foreign Corrupt Practices Act (FCPA) and the Money Laundering Control Act of 1986, particularly for transactions involving shell companies and digital assets.
  • New guidance from the Fraud Section mandates that companies must self-disclose misconduct within 120 days of discovery to qualify for declination or deferred prosecution agreements, a significant tightening from previous informal timelines.
  • The DOJ’s 2026 priorities incorporate enhanced penalties under the Federal Sentencing Guidelines for offenses involving artificial intelligence, including the use of AI to automate fraud schemes or conceal financial transactions.

The 2026 Priorities: A Shift from Reactive to Predictive Enforcement

In my 25 years as a federal prosecutor, I have witnessed the DOJ’s white collar crime priorities evolve in response to economic crises, technological disruption, and political pressure. The 2026 priorities, announced by Attorney General Merrick Garland’s successor in a November 2025 memorandum, represent a fundamental shift from reactive enforcement to predictive policing of financial misconduct. The DOJ now leverages advanced data analytics and machine learning algorithms to identify suspicious patterns in securities filings, bank reports, and even encrypted messaging platforms. This means that companies and individuals can no longer rely on the opacity of complex transactions to evade scrutiny; the government is actively scanning for anomalies before a formal complaint is ever filed. The memorandum specifically cites the Bank Secrecy Act of 1970, 31 U.S.C. § 5311 et seq., as the statutory backbone for this surveillance, requiring financial institutions to flag transactions that deviate from established behavioral baselines. For defense counsel, this shift demands that we advise clients to conduct proactive internal audits that mirror the government’s technological capabilities, rather than waiting for a subpoena to arrive. The days of “don’t ask, don’t tell” compliance are over; the DOJ is now asking before you even know you have a problem.

Cryptocurrency and Digital Assets: The New Frontier Under 18 U.S.C. § 1956

The 2026 priorities place cryptocurrency fraud at the very top of the enforcement pyramid, a move that should surprise no one who has followed the DOJ’s aggressive pursuit of exchanges like Binance and individuals involved in the FTX collapse. What is new, however, is the DOJ’s explicit directive to prosecutors to treat any transaction involving a digital asset as presumptively suspicious under the Money Laundering Control Act of 1986, codified at 18 U.S.C. § 1956. This presumption means that if you are a business owner accepting Bitcoin for services, or an investor moving tokens between wallets, you may be required to provide contemporaneous documentation proving the legitimate source of those funds. The DOJ has also announced a dedicated “Digital Asset Strike Force” operating under the Fraud Section, staffed with prosecutors who have specialized training in blockchain forensics and decentralized finance protocols. In my experience, this level of specialization signals that the government intends to bring cases that test the boundaries of existing law, particularly around the definition of a “financial transaction” when dealing with smart contracts and non-fungible tokens. Furthermore, the priorities emphasize the use of civil forfeiture under 18 U.S.C. § 981 to seize digital assets before an indictment is even returned, putting immense pressure on defendants to settle early rather than litigate the ownership of frozen cryptocurrency. For clients holding digital assets, the immediate takeaway is clear: you must implement robust know-your-customer and anti-money laundering protocols that exceed the current regulatory requirements, because the DOJ will view any gap as evidence of willful blindness.

Health Care Fraud: The Return of the Stark Law and Anti-Kickback Statute Synergy

Health care fraud has always been a staple of DOJ enforcement, but the 2026 priorities introduce a novel coordination between the Stark Law (42 U.S.C. § 1395nn) and the Anti-Kickback Statute (42 U.S.C. § 1320a-7b) that will fundamentally alter how medical practices structure their financial relationships. The DOJ has announced that it will no longer treat Stark Law violations as mere administrative overpayments subject to civil monetary penalties; instead, prosecutors are directed to evaluate every Stark Law violation for potential criminal liability under the Anti-Kickback Statute’s “knowing and willful” standard. This is a dramatic escalation because the Stark Law is a strict liability statute, meaning that a technical violation—such as a lease agreement that exceeds fair market value by a few thousand dollars—can now serve as the predicate for a felony kickback charge. In my years litigating health care cases, I have seen how these statutes intersect, but never with such explicit marching orders from Main Justice. The 2026 memorandum also prioritizes investigations into telemedicine companies and digital health platforms, particularly those that prescribe controlled substances or durable medical equipment without a bona fide physician-patient relationship. The DOJ is specifically targeting the use of “patient brokering” arrangements where marketers receive per-patient referral fees, a practice that violates the Anti-Kickback Statute even if the underlying medical services are legitimate. For health care providers, the only prudent course is to conduct a full legal audit of every financial arrangement with referring physicians, hospitals, and marketing partners, using the DOJ’s own “Fraud Prevention Playbook” as a checklist. Failure to do so is not just risky; it is essentially an invitation for a grand jury subpoena.

Corporate Compliance and the 120-Day Self-Disclosure Window: A Trap for the Unwary

Perhaps the most consequential change in the 2026 priorities is the formalization of a 120-day self-disclosure deadline for corporations that discover potential misconduct. Under previous DOJ guidance, companies were encouraged to self-disclose “promptly,” but that term was left deliberately vague, allowing defense counsel to negotiate timing based on the complexity of the internal investigation. The new memorandum, citing the Principles of Federal Prosecution of Business Organizations in the Justice Manual § 9-28.000, now mandates that to qualify for a declination or a non-prosecution agreement, a company must self-disclose within 120 days of the date on which senior management or the board of directors became aware of credible evidence of misconduct. This creates a brutal Catch-22: if you investigate too aggressively, you trigger the clock; if you investigate too slowly, you miss the deadline. In my practice, I have already seen clients receive subpoenas that reference the 120-day rule, with prosecutors demanding to know exactly when the board was briefed and why disclosure was delayed. The DOJ has also stated that it will consider the 120-day window as a “presumptive” deadline, meaning that even if a company self-discloses on day 121, the government may decline to offer cooperation credit unless extraordinary circumstances exist. This places an enormous premium on having a pre-existing incident response plan that includes legal counsel, forensic accountants, and a designated disclosure team ready to mobilize within hours of a red flag. Companies that treat compliance as a checkbox exercise will find themselves on the outside of the cooperation window, facing the full brunt of federal prosecution. The 2026 priorities also require that any self-disclosure include a detailed remediation plan, not just a confession, and that the company waive attorney-client privilege for the factual findings of the internal investigation—a demand that I have always advised clients to resist, but which the DOJ now treats as non-negotiable for leniency.

Frequently Asked Questions About the 2026 White Collar Crime Priorities

Q: I run a small business that occasionally accepts cryptocurrency payments. Do I need to register as a money services business with FinCEN?

A: In my professional opinion, if your business accepts cryptocurrency in exchange for goods or services and then converts that cryptocurrency to fiat currency, you almost certainly fall within the definition of a “money transmitter” under 31 C.F.R. § 1010.100(ff)(5). The 2026 priorities explicitly direct prosecutors to pursue unregistered money services businesses, and the Financial Crimes Enforcement Network has been aggressive in issuing civil penalties for failure to register. You should consult with counsel immediately to determine whether your specific business model triggers registration requirements under the Bank Secrecy Act. Keep in mind that even if you are not technically required to register, the DOJ’s presumption of suspiciousness means that any cryptocurrency transaction over $10,000 must be reported via a Currency Transaction Report, or you risk a charge of structuring under 31 U.S.C. § 5324.

Q: Our company discovered a potential FCPA violation in our overseas operations. How do we calculate the 120-day self-disclosure deadline?

A: The 120-day clock starts on the date that “senior management or the board of directors becomes aware of credible evidence of misconduct,” not when the initial allegation is received by a lower-level employee. In my experience, this distinction creates a dangerous ambiguity. If a regional manager in Southeast Asia receives a whistleblower complaint but does not elevate it to the general counsel for three weeks, the clock may not start until that elevation occurs. However, the DOJ has indicated that it will impute knowledge to senior management if the company’s reporting structure is inadequate, so you cannot rely on information silos to delay the deadline. You should immediately engage outside counsel to conduct a privileged preliminary investigation to determine whether the evidence rises to the level of “credible,” and if it does, you must prepare a disclosure package that includes a complete factual narrative, a list of involved employees, and a proposed remediation plan. Missing the 120-day window by even a single day can mean the difference between a declination and a criminal indictment under the FCPA.

If you or your organization is facing scrutiny under the DOJ’s 2026 White Collar Crime Enforcement Priorities, you cannot afford to rely on generic compliance advice or hope that the government will overlook a technical violation. The stakes are higher than ever, with prosecutors armed with new tools, tighter deadlines, and a mandate to pursue individual accountability at every level. With over 25 years of experience as a federal prosecutor and now as a defense attorney, I have navigated these exact waters—from negotiating deferred prosecution agreements to trying cases before juries in complex fraud matters. I offer a free initial consultation to evaluate your specific situation, assess your exposure under the new priorities, and develop a strategic response that protects your rights and your future. Do not wait for a subpoena to land on your desk; proactive engagement with counsel is the single most effective defense against the DOJ’s predictive enforcement machine. Contact my office today to schedule a confidential discussion about your case.