False Claims Act
The False Claims Act is a federal law that makes it illegal to knowingly submit, or cause the submission of, false claims for payment to the U.S. government, such as fraudulent claims by government contractors. Violators can face significant financial liability, and the law also allows private citizens to bring lawsuits on the government's behalf. Because of this whistleblower provision, it is sometimes called the 'Lincoln Law' after its Civil War-era origins.
The False Claims Act (originally enacted in 1863) is a federal statute imposing civil liability on any person or entity that knowingly submits, or causes to be submitted, false or fraudulent claims for payment or approval to the federal government, and on those who make or use false records or statements material to such claims. As described in the evidence, the FCA generally provides for treble (three times) damages plus per-claim civil penalties, and includes qui tam whistleblower provisions permitting private citizens to file suit on behalf of the government. This entry addresses the statute at a conceptual level only; specific penalty amounts, which are subject to periodic inflation adjustment, and the precise statutory elements, procedures, and any application to cybersecurity or CUI-related misrepresentations by federal contractors should be verified against the current authoritative text and Department of Justice guidance.
Why it matters
The False Claims Act is one of the federal government's primary tools for combating fraud against the public fisc, and its reach extends well beyond traditional billing fraud. For government contractors, the FCA imposes civil liability for knowingly submitting false claims for payment or approval, and it generally provides for treble (three times) damages plus per-claim civil penalties. Because these penalties accumulate on a per-claim basis and the damages are trebled, potential exposure can escalate quickly, making the statute a significant source of financial and reputational risk for any organization doing business with the federal government.
Of particular relevance to compliance officers in the defense and public sector cybersecurity space is the possibility that misrepresentations about a contractor's security posture or compliance with contractual cybersecurity requirements could form the basis of an FCA claim. This entry does not confirm the specific contours of such theories, and readers should understand that whether a given cybersecurity-related misrepresentation constitutes an actionable false claim is a legal question that must be verified against the current statutory text, Department of Justice guidance, and applicable case law. The general point for practitioners is that attestations, self-assessments, and representations of compliance made to obtain or retain federal payment are not merely administrative formalities, they can carry legal consequences.
The FCA's qui tam whistleblower provisions add a further dimension: private citizens may file suit on the government's behalf, meaning that employees, subcontractors, or other insiders with knowledge of alleged false claims can initiate enforcement action independent of a government-initiated investigation. This structure broadens the universe of parties who may bring an organization's compliance practices under scrutiny and reinforces the importance of accurate, defensible representations across a contractor's dealings with the federal government.
Who it's relevant to
Inside FCA
Common questions
Answers to the questions practitioners most commonly ask about FCA.