The False Claims Act (FCA), codified at 31 U.S.C. §§ 3729-3733, is the U.S. government’s primary civil-enforcement tool against fraud in federally funded programs — and for research institutions that receive federal grants and contracts, it is arguably the single highest-stakes compliance exposure a sponsored-programs office manages. Unlike research-misconduct proceedings, which are adjudicated by funding agencies and institutional integrity officers, an FCA case is litigated in federal court, can be brought by a private whistleblower on the government’s behalf, and carries treble damages plus per-claim penalties that regularly push university settlements into eight and nine figures. This guide covers how the FCA actually applies to research grants and contracts — false certifications, effort-reporting fraud, grant-application misrepresentation — the qui tam whistleblower mechanism that drives most research-sector cases, real enforcement history, and what a sponsored-programs office does day to day to keep certifications accurate.
What the False Claims Act actually prohibits
The FCA’s core liability provision, 31 U.S.C. § 3729(a), imposes civil liability on anyone who:
- knowingly presents, or causes to be presented, a false or fraudulent claim for payment to the U.S. government;
- knowingly makes, uses, or causes to be made or used, a false record or statement material to a false claim; or
- conspires to commit an FCA violation.
Two elements do most of the work in a research-grant context: falsity and knowledge. A “claim” is not limited to an invoice — in grant administration it extends to the application itself, progress and financial reports, and any certification submitted as a condition of receiving or drawing down federal funds. “Knowingly” is defined broadly at § 3729(b)(1): it covers actual knowledge, but also deliberate ignorance of the truth or falsity of information and reckless disregard for it. No specific intent to defraud is required — an institution cannot avoid liability by structuring its processes so that no one individual ever actually confirms whether a certification is accurate. This is precisely why sponsored-programs offices treat certification accuracy as a system-level control problem, not an individual honesty problem.
Implied false certification and materiality
Much of the FCA exposure specific to grants runs through the implied false certification theory, which the Supreme Court addressed directly in Universal Health Services, Inc. v. United States ex rel. Escobar, 579 U.S. 176 (2016). The Court held that liability can attach even when a claim for payment doesn’t contain an explicit false statement, if the claim makes specific representations and the submitter’s failure to disclose noncompliance with a material statutory, regulatory, or contractual requirement renders those representations misleading half-truths. Escobar also tightened the materiality standard: the government or a relator must show the misrepresentation was material to the government’s actual payment decision — not merely that the government had the theoretical right to withhold payment for the noncompliance. In practice, courts look at whether the government has, in the past, actually declined to pay or has demanded refunds for the same kind of noncompliance; a requirement the government routinely waives or overlooks is harder to establish as material. For research grants, this makes it critically important which certifications funders actually condition payment on (effort commitments, current-and-pending-support disclosures, financial conflict-of-interest disclosures) versus purely administrative representations — but institutions should not assume any given certification is immaterial without legal review, since the case law on this point is still developing.
Where FCA exposure actually arises in sponsored research
Three categories account for most research-sector FCA activity, and they map closely onto the responsibilities of a pre-award/post-award sponsored-programs office.
1. Grant-application misrepresentation
A federal grant application is itself a claim for the purposes of the FCA once the institution accepts funds based on it. Misrepresentations found in applications and progress reports include:
- Falsified, fabricated, or manipulated data submitted to support a funding request or reported as a result of funded work.
- Undisclosed current-and-pending support — omitting a principal investigator’s other active or pending grants, including foreign government or foreign-university appointments and funding, from the “other support” or biosketch disclosures required by NIH, NSF, and other federal sponsors.
- Undisclosed financial conflicts of interest that a sponsor’s terms require to be reported.
- Misrepresented institutional capacity or resources — describing facilities, personnel, or preliminary data that do not exist as described.
This category has been the dominant driver of research-institution FCA enforcement over the past several years, largely because of intensified federal scrutiny of foreign-funding disclosures under research-security initiatives — see NSPM-33 disclosure requirements and NSF Notice 149 for the current disclosure landscape those settlements sit within.
2. Effort-reporting fraud
Federal cost principles under 2 CFR 200.430 (Uniform Guidance) require that salaries charged to a federal award reflect the effort actually devoted to that award, supported by records that reasonably reflect the total activity for which the employee is compensated. When an institution certifies effort — whether via plan-confirmation, after-the-fact activity records, or a multiple confirmation record; see the Effort Reporting Methodologies guide for how those approaches differ — that certification is itself a representation to the federal government about how grant funds were actually used. Effort-reporting fraud typically takes one of two forms:
- Overstating effort to justify charging more salary to a grant than the work actually performed supports (the classic pattern behind the earliest research-sector FCA settlements).
- Understating or failing to report cost-shared effort that a grant’s terms committed the institution to providing.
Because effort certifications are typically signed by the individual researcher but rely on institutional systems (payroll, time-and-effort software, departmental administrator review) to be accurate, effort-reporting cases frequently implicate the institution’s control environment as much as any one investigator’s conduct — which is exactly why 2 CFR 200.303’s internal-controls requirement (see the companion guide on institutional internal controls for federal grant compliance) and effort-certification training are treated as FCA risk mitigation, not just administrative housekeeping.
3. False certifications tied to specific compliance conditions
Federal awards carry standing certifications beyond the budget and technical narrative — debarment and suspension status, lobbying restrictions, and, increasingly, cybersecurity and research-security attestations. A false certification on any condition the government treats as material to its payment decision can support FCA liability under the implied-certification theory described above, independent of whether the underlying science or scholarship was sound.
The DOJ Civil Cyber-Fraud Initiative and research security
In October 2021, the Department of Justice announced the Civil Cyber-Fraud Initiative, explicitly stating its intent to use the FCA against government contractors and grant recipients who knowingly provide deficient cybersecurity products or services, misrepresent their cybersecurity practices, or fail to monitor and report cybersecurity incidents as required. Research universities running federally funded labs — particularly those holding Department of Defense or intelligence-community-adjacent awards — fall squarely within this initiative’s scope, because federal contracts and some grants incorporate cybersecurity control requirements (such as NIST SP 800-171) as conditions of award.
The first litigated matter under this initiative involved a research university: in 2024 the United States sued the Georgia Institute of Technology and the Georgia Tech Research Corporation (GTRC), alleging that GTRC failed to install required antivirus and endpoint-protection tools at a campus lab conducting DARPA- and Air Force-funded cyber-defense research, failed to implement a system security plan required by its government contracts, and submitted a false cybersecurity compliance score to the Department of Defense. The case originated as a qui tam suit filed by two former members of Georgia Tech’s own cybersecurity team. GTRC settled in September 2025 for $875,000, with the two relators sharing $201,250 of the recovery. For sponsored-programs and research-security offices, the case is a direct illustration that FCA exposure is not limited to financial or scientific-integrity certifications — a false or unverified compliance attestation on a system security plan is functionally the same kind of claim, and institutional research-security and IT-compliance offices should be treated as an FCA-adjacent control point, not a separate silo from grants compliance.
Qui tam: the whistleblower mechanism that drives research-sector cases
Most FCA cases against research institutions do not start with a government audit — they start with a qui tam lawsuit filed under 31 U.S.C. § 3730(b) by a private individual, called a relator, acting on the government’s behalf. The mechanism works as follows:
- A relator — commonly a current or former lab employee, research administrator, co-investigator, or compliance staff member with inside knowledge of the alleged fraud — files the complaint under seal in federal district court, meaning it is not served on the defendant and is not public while the government investigates.
- The Department of Justice investigates and decides whether to intervene (take over prosecution of the case) within an initial 60-day period, though this is routinely extended, often for years in complex research-fraud matters.
- If the government intervenes and recovers funds, the relator receives between 15% and 25% of the proceeds under § 3730(d)(1). If the government declines to intervene and the relator proceeds alone, a successful relator receives between 25% and 30% under § 3730(d)(2) — a structure meant to compensate for the relator bearing the litigation risk and cost alone. Relator recoveries based primarily on already-public information are capped at 10%.
- The FCA’s anti-retaliation provision (§ 3730(h)) protects employees who investigate, report, or assist in an FCA action from being discharged, demoted, harassed, or otherwise discriminated against because of that protected activity, and provides for reinstatement, double back pay, and litigation costs where retaliation is proven.
Research institutions are a structurally high-risk environment for qui tam exposure precisely because grant compliance work is distributed across many people who each see only part of the picture — a lab manager who prepares effort records, a grants administrator who submits progress reports, a compliance officer who reviews conflict-of-interest disclosures — any one of whom may become a relator if they conclude the institution knew about, or was reckless about, a misrepresentation and did nothing to correct it. The Duke University settlement below originated exactly this way: from a lab research analyst who first raised concerns internally.
Real enforcement history: what research-sector FCA cases actually look like
The following are real, publicly announced Department of Justice settlements, cited so a sponsored-programs office can see the actual fact patterns rather than a generic description of “fraud.”
- Northwestern University (2003) — paid $5.5 million to resolve allegations, brought via a qui tam suit, that the university overstated the percentage of researchers’ effort that could actually be devoted to federal grants — an early, foundational effort-reporting case.
- University of Florida (2015) — paid $19.875 million to resolve allegations that it improperly charged HHS grants for personnel and administrative costs inconsistent with how funds were actually used.
- Duke University (2019) — paid $112.5 million, the largest research-misconduct-related FCA settlement to date, to resolve allegations that between 2006 and 2018 it knowingly submitted grant applications and progress reports to NIH and the EPA containing falsified or fabricated data across 30 grants. The case was filed under the qui tam provisions by a former Duke research analyst, who received $33.75 million of the recovery.
- Stanford University (2023) — paid $1.9 million to resolve allegations that it failed to disclose, in 16 grant applications to the Departments of the Army, Navy, and Air Force, NASA, and NSF, that 12 faculty principal investigators had current or pending research support from foreign sources, including Chinese institutions.
- Cleveland Clinic Foundation (2024) — paid $7.6 million (including $3.8 million in restitution) to resolve allegations that it repeatedly failed to disclose, on three NIH grant awards, that the designated principal investigator held active or pending foreign research support required to be reported as “other support.”
- Georgia Tech Research Corporation (2025) — paid $875,000, the first litigated matter under DOJ’s Civil Cyber-Fraud Initiative, over failures to meet cybersecurity requirements tied to DARPA and Air Force contracts (see above).
- Dana-Farber Cancer Institute (2025) — paid $15 million to resolve allegations that it made materially false statements and certifications in connection with NIH research grants after researchers used grant funds to conduct work that resulted in publications containing misrepresented or duplicated images and data.
Two patterns are worth naming explicitly. First, the two most common current fact patterns are undisclosed foreign research support (Stanford, Cleveland Clinic) and falsified underlying data (Duke, Dana-Farber) — not, in recent cases, simple arithmetic effort-reporting errors, though effort misstatement remains squarely within FCA’s reach (Northwestern, University of Florida) and 2 CFR 200.430 keeps it a live control point. Second, nearly all of these cases originated as qui tam suits, not government-initiated audits — reinforcing that an institution’s internal reporting channels and its response to internal concerns are themselves part of its FCA risk posture.
Damages, penalties, and the statute of limitations
A defendant found liable under the FCA is subject to:
- Treble damages — three times the amount of the government’s actual damages.
- A per-claim civil penalty, adjusted annually for inflation under the Balanced Budget Act of 1997’s Federal Civil Penalties Inflation Adjustment framework. Following the July 2025 inflation adjustment, the penalty range is $14,308 to $28,619 per false claim — and in grant administration, each false certification, each false progress report, and potentially each improperly charged payroll transaction can be treated as a separate “claim,” which is how per-claim penalties compound quickly even before treble damages are applied.
The FCA’s statute of limitations, at 31 U.S.C. § 3731(b), runs for whichever is later of: six years from the date of the violation, or three years from when the responsible U.S. government official knew or reasonably should have known the material facts — but never more than ten years after the violation regardless. Because that second prong depends on when the government’s own knowledge accrues, and effort or funding-disclosure violations frequently aren’t discovered until years after the underlying charge or omission, research institutions should not assume a several-year-old certification is beyond scrutiny.
What this means operationally for a sponsored-programs office
Given the fact patterns above, the practical compliance program a sponsored-programs or research-compliance office runs to manage FCA exposure centers on a small number of recurring control points:
- Effort-certification accuracy and timeliness. Certifications should be completed by someone with direct, personal knowledge of the effort actually performed (not defaulted or auto-certified without review), reconciled against payroll distribution, and retained per the institution’s record-retention policy — the audit trail is what demonstrates the institution did not act with reckless disregard even if an individual certification later proves to be in error.
- Current-and-pending-support / other-support disclosure review. Given how many recent settlements trace to undisclosed foreign or concurrent support, pre-submission review of biosketch and other-support attachments against a centralized, PI-maintained disclosure record — not solely the PI’s memory at the time of application — has become a standard control, and several sponsors (NIH among them) now require periodic updated certifications during the award period, not just at application.
- Financial conflict-of-interest disclosure reconciliation against the institution’s own COI management system before a proposal is submitted or an award is accepted — see the guide on conflict-of-interest disclosure forms for what a compliant disclosure captures.
- Cost-principle compliance on charges to the award, consistent with the allowability, allocability, and reasonableness tests under 2 CFR 200 Subpart E — see the Uniform Guidance (2 CFR 200) guide for the governing framework those tests sit within.
- A genuinely accessible internal reporting channel, and a documented, prompt response when a concern is raised internally — both because 2 CFR 200.303(d) requires prompt corrective action once noncompliance is identified, and because, as the case history above shows, the person who raises an internal concern and is ignored is often the same person who later becomes a qui tam relator.
- Coordination between grants/financial compliance and research-security/IT-compliance functions, given that the Civil Cyber-Fraud Initiative extends the same FCA exposure to cybersecurity and research-security attestations, not only financial and scientific certifications.
None of this converts a sponsored-programs office into a law firm — an actual FCA allegation, whether raised internally, through an audit finding, or through a qui tam unsealing, should go to institutional counsel immediately. But the day-to-day discipline that keeps an institution out of the fact patterns above — accurate, well-documented certifications produced by people with direct knowledge, reviewed before submission, and corrected promptly when errors surface — is squarely sponsored-programs-office work, and it is the actual, practical form that “False Claims Act compliance” takes for a research institution.
Frequently asked questions
Does the False Claims Act apply to grants, or only to procurement contracts?
It applies to both. The FCA’s language covers any false or fraudulent claim for payment made to the U.S. government, and courts have consistently applied it to grant applications, progress reports, and payment requests under federal research grants — not only to goods-and-services contracts. Every research-sector settlement cited in this guide arose from grant funding, not procurement contracts.
Can an institution be liable for an honest mistake?
Ordinary negligence, without more, does not meet the FCA’s “knowing” standard. But the standard also covers deliberate ignorance and reckless disregard — an institution that has no real process for verifying certifications, or that is on notice of a problem and does not act, can be found to have acted with reckless disregard even without anyone intending to defraud the government. This is why documented, functioning internal controls matter as much as good intentions.
Who can file a qui tam case against a university?
Any private person with direct or indirect knowledge of an alleged false claim can file, including current or former employees, though certain public-disclosure and “original source” rules under § 3730(e) can bar a case based solely on information already publicly available. In practice, research-sector relators have most often been lab staff, research administrators, or compliance personnel with inside knowledge of how certifications were actually prepared.
How is this different from a research-misconduct finding under an institution’s Office of Research Integrity policy?
Research misconduct (fabrication, falsification, plagiarism) is adjudicated administratively, typically by the institution and, for federally funded research, reported to a funder’s own integrity office — see the guide on how a research misconduct investigation actually works. An FCA case is a separate, civil legal action litigated in federal court, and the same underlying facts (as in the Duke and Dana-Farber cases above) can trigger both a research-misconduct finding and separate FCA liability, because the FCA’s question is not “was this good science” but “was a false statement material to a claim for federal payment.”







