In August 2025, the U.S. Department of Justice announced a non-prosecution agreement (NPA) with Troy Health, Inc. (doing business as Troy Medicare), a Medicare Advantage organization. This resolution is significant for several reasons: it is the Criminal Division’s first healthcare criminal resolution of 2025, the first real-world application of the revised Corporate Enforcement Policy (CEP) in a healthcare context, and the first time the DOJ has explicitly centered its enforcement narrative on misconduct that was facilitated by a company’s proprietary artificial intelligence platform.
For physicians, hospitals, health systems, pharmacies, Medicare Advantage plans, and health-tech vendors that are integrating AI into patient outreach, enrollment, risk adjustment, care coordination, coding, or revenue-cycle processes, this case sends an unmistakable message: the government is now actively scrutinizing how artificial intelligence is used in healthcare, and inadequate oversight will be treated as a serious compliance failure.
What Happened at Troy Medicare
Between October 2020 and December 2022, Troy used its proprietary AI platform, Troy.ai, in combination with aggressive and improper sales tactics to obtain pharmacy customer lists containing protected health information and personal identifiable information. The company then enrolled Medicare beneficiaries into its plan, frequently without their knowledge or consent.
The misconduct included paying pharmacies on a per-member basis to submit leads directly through Troy.ai, granting sales representatives unauthorized access to patient lists, using automation to batch-enroll hundreds of beneficiaries in a single day (including one instance of approximately 300 enrollments), making unsolicited and misleading phone calls that falsely claimed affiliation with the beneficiary’s pharmacy, failing to disclose that enrollment would automatically disenroll the person from their existing coverage, and deliberately avoiding recorded lines while falsely documenting calls as in-person meetings.
When CMS detected the enrollment spike and began receiving complaints from confused and angry beneficiaries, some Troy representatives used required verification calls simply to welcome people to the plan rather than confirm their actual intent.
The DOJ press release emphasized that Troy had publicly touted its AI platform as a tool to improve patient outcomes, but instead misused patient data to drive unauthorized enrollments.
Why the DOJ Is Putting Artificial Intelligence Under the Microscope
Prosecutors awarded Troy partial cooperation credit for two AI-specific actions: promptly suspending all member-referral and recruitment functions within Troy.ai and voluntarily producing detailed technical information about how the platform operated. This tells healthcare leaders exactly what future investigations will demand: full transparency into model design, training data sources, decision-making logic, audit trails, and the degree of human oversight.
When AI is involved, the investigators will request:
Complete documentation of the AI model and the datasets used to train it;
Evidence that a qualified person reviewed and approved AI outputs before any action was taken;
Details of data-sharing agreements that fed patient information into the system; and
Proof that compliance, legal, and clinical teams had real-time visibility into AI-driven decisions.
Immediate, Practical Steps Every Healthcare Organization Should Take
Healthcare leaders should now treat AI governance with the same seriousness as HIPAA compliance or Anti-Kickback Statute safeguards.
Start by inventorying every AI or automated tool that touches patient data, enrollment, coding, billing, or marketing.
Require human review before any AI-generated lead, script, enrollment, or code is used.
Establish a cross-functional governance committee that includes compliance, legal, clinical, and IT representation to regularly review data sources, model performance, bias testing, and output validation.
Update vendor and partnership agreements to mandate transparency and audit rights over third-party AI systems.
The Troy Medicare resolution is a landmark moment. For the first time, the Department of Justice has put the entire healthcare industry on notice that artificial intelligence is under active enforcement scrutiny. Strong, documented governance and proactive compliance are now essential to protect your organization.
Our firm has deep experience guiding healthcare providers through government investigations. If your organization uses artificial intelligence in patient acquisition, care delivery, coding, or revenue processes, we can help you assess risk and build the safeguards regulators now expect. Contact us today for a confidential AI compliance and enforcement readiness review at (212) 668-0200 or info@mdrxlaw.com


