NextGen Healthcare Inc., one of the largest electronic health record software vendors in the United States, agreed to pay $31 million to resolve Department of Justice allegations that the company falsely certified its EHR software as meeting federal certification requirements under the Health Information Technology for Economic and Clinical Health Act — requirements that, according to the government's complaint, the software did not fully satisfy despite the certifications NextGen submitted to federal health programs.DOCUMENTED
The settlement was one of the largest False Claims Act resolutions involving an EHR vendor, reflecting both the scale of NextGen's customer base — physician practices, community health centers, and outpatient facilities across the country — and the significance of EHR certification to the Medicare and Medicaid incentive programs through which the government paid healthcare providers to adopt and meaningfully use certified electronic health record systems.
- NextGen Healthcare agreed to pay $31 million to resolve DOJ False Claims Act allegations.
- Allegations covered false certification of EHR software as meeting federal interoperability and security requirements.
- The HITECH Act established EHR certification requirements tied to Medicare and Medicaid meaningful use incentive payments.
- NextGen serves physician practices and outpatient facilities across the United States.
- A whistleblower complaint triggered the federal investigation.
The HITECH Act and EHR Certification
The Health Information Technology for Economic and Clinical Health Act, passed in 2009, created a framework of financial incentives encouraging healthcare providers to adopt electronic health record systems and to use them in ways that would improve clinical quality and patient outcomes. To qualify for these incentive payments — which totaled tens of billions of dollars distributed to eligible providers — providers had to use EHR software that was certified as meeting specific technical and interoperability standards established by the federal government.DOCUMENTED
EHR vendors applied for certification from accredited testing bodies, certifying that their software met the applicable standards for data capture, interoperability, security controls, and other technical requirements. Providers who paid for and used certified EHR software received meaningful use incentive payments from Medicare and Medicaid. When an EHR vendor falsely certified software as meeting standards that it did not actually satisfy, the downstream effect was that providers received incentive payments they were not truly entitled to — making the vendor's false certification a cause of false claims against the government for those incentive payments.
What the DOJ Alleged NextGen Did
The DOJ's complaint alleged that NextGen certified its EHR software as meeting specific federal requirements when the company's own internal testing and engineering records showed that the software contained deficiencies that meant it did not fully satisfy those requirements. The alleged deficiencies covered multiple aspects of the certification requirements, including standards related to data security and privacy, interoperability with other health information systems, and specific functional requirements for how patient data should be structured, stored, and shared.DOCUMENTED
The complaint described a situation in which internal company personnel were aware of the gaps between what the certification represented and what the software actually did — but in which the company proceeded to obtain and represent certification status to customers and to federal programs in a way that did not disclose those gaps. This pattern — internal awareness of a product deficiency combined with external certification claims inconsistent with that awareness — is the core of a False Claims Act case in the government contracting and program funding context.REVIEWED
Certifying software as federally compliant while internal engineers document that it is not is not a quality control lapse. It is a false statement submitted to obtain government payment.
The Healthcare Provider Impact
For the healthcare providers who used NextGen's software and received meaningful use incentive payments, the legal consequence was not directly that providers faced recoupment — the government's enforcement focus was on the vendor rather than the downstream providers. But the real-world consequences of EHR software that does not meet its certified specifications fall on providers and ultimately on patients: software that does not properly implement interoperability standards may fail to share patient data correctly with other providers, creating gaps in care coordination; software with security deficiencies may expose patient data to risks that the certification was designed to prevent.REVIEWED
The healthcare organizations that rely on EHR certification as a signal of software quality are in a difficult position to independently verify those claims. Certification is designed precisely to provide an assurance that substitutes for provider-level technical assessment. When that assurance is false — when the certification represents what the software was supposed to be rather than what it actually is — the harm is not only to the government payment programs but to the providers who made procurement decisions based on certified status they had every reason to trust.
Pattern of EHR False Certification Cases
The DOJ's case against NextGen Healthcare was not the first EHR false certification case the agency had pursued. Multiple EHR vendors — including Greenway Health and Practice Fusion — reached earlier settlements with the DOJ in cases that involved similar theories: certification claims that were not supported by the underlying software's actual functionality. The pattern reflects both the scale of federal investment in EHR adoption, which created substantial financial incentives for vendors to obtain certified status, and the difficulty of verifying certification claims at the point of sale — particularly for the healthcare providers making purchasing decisions and the government certification bodies evaluating vendor submissions.REVIEWED
For healthcare organizations currently using EHR software and relying on its certified status to qualify for federal programs, the pattern of enforcement in this space is a reminder that vendor certification does not provide absolute assurance of compliance. Contractual representations and warranties from EHR vendors about their certified software, indemnification provisions covering government recoupment risks tied to the vendor's certification failures, and active monitoring of government enforcement activity in the EHR certification space are all mechanisms healthcare providers can use to protect their interests in an environment where false certification cases have become a recognizable enforcement category. The NextGen settlement also demonstrates that the DOJ's pursuit of EHR vendors is not limited to smaller or less prominent companies in the space — even major, publicly traded vendors with large established customer bases face meaningful False Claims Act exposure when internal records show a gap between certified status and actual software capabilities.
Sources behind this report
Have documents relevant to this story? Reach us through our tips channel.