State Attorney General Enforcement: Institutional Sexual Abuse Risk, Governance, and Enterprise Readiness
13. August 2026A recent New Hampshire attorney general report shows how organizations serving vulnerable populations can face scrutiny of their governance, safety practices, and preparedness even when investigators find no abuse.
Behavioral health organizations have historically assessed institutional sexual abuse and patient-safety exposure primarily through the lens of civil litigation. Plaintiffs’ firms, class actions, and nuclear verdicts have dominated boardroom conversations about enterprise risk. But that calculus is now incomplete, and in some respects, obsolete.
Consider a report issued in July by the New Hampshire Attorney General’s Office following its investigation into the state’s Sununu Youth Services Center. After interviewing dozens of current and former employees and reviewing hundreds of hours of video and thousands of records, investigators reached a conclusion that should command the attention of every general counsel and risk executive in the sector: the attorney general investigation found no physical or sexual abuse, no illegal restraints, and concluded the facility was operating within legal boundaries. Despite the ostensibly favorable conclusion, the office produced a scathing 56-page report describing the facility as “dysfunction[al] at all levels” and plagued by understaffing, weak leadership, a fractured administration, and a culture without accountability.
For behavioral health and youth-serving institutions, the defining enterprise risk is no longer confined to whether misconduct occurred, but instead what the institution looks like after regulatory dissection.
A BROADER ENFORCEMENT PHILOSOPHY
Across the country, state attorneys general are increasingly exercising independent authority to examine youth-serving institutions, not only in response to individual allegations, but as part of broader public-protection initiatives. Residential treatment centers, juvenile behavioral health facilities, psychiatric hospitals, and other organizations serving vulnerable populations are finding themselves the subject of expansive inquiries into governance, patient safety, abuse prevention, reporting practices, staffing, and executive decision-making.
The questions increasingly resemble an enterprise-risk assessment more than a traditional law-enforcement investigation:
- Did leadership know, or should it have known, about emerging risks?
- Were warning signs recognized and appropriately escalated?
- Were internal investigations independent, timely, and trauma-informed?
- Did staffing shortages, inadequate supervision, or poor training contribute to foreseeable harm?
- Were mandatory reporting obligations consistently followed?
- Were complaints tracked and analyzed as enterprise risk, or handled as isolated matters?
- Did governance structures give executives and boards meaningful visibility into recurring safety concerns?
The New Hampshire investigation is instructive precisely because the answer to “did abuse occur” was no, and the institution was still found wanting on nearly all of these queries.
Several converging developments may be driving the trend in state attorney general investigations and enforcement efforts. Understanding the mechanism matters, because each driver points to a specific vulnerability an organization can address in advance.
Watchdogs & Advocates
The New Hampshire investigation began with referrals from a state child advocate and a disability-rights organization, watchdogs that have increasingly functioned as first-reporters to state attorneys general and other regulators. Just a single site visit or complaint can trigger a governor’s directive and a multimonth, document-intensive review, requiring vigilant administration of safeguarding systems and clear response protocols.
The Due Diligence Blind Spot
The Sununu facility investigation sits against the backdrop of more than 1,600 lawsuits alleging historic abuse at its predecessor institution. Even when a current investigation clears an organization of present-day wrongdoing, the shadow of related litigation shapes political urgency, media attention, and the intensity of regulatory scrutiny. Abuse-adjacent history can make an institution a standing target, and sexual abuse risks are overlooked, or reviewed without requisite subject-matter expertise, in the due diligence process of mergers and acquisitions.
Statutory Expansions
Many attorney general offices possess broad authority under consumer-protection statutes, charitable-trust laws, Medicaid-fraud provisions, licensing regimes, civil investigative demand (CID) statutes, and parens patriae powers. These instruments allow investigators to compel documents and testimony well before traditional litigation would ordinarily reach them, and to examine the organization as a whole rather than through a single incident or within the confines of the rules of civil procedure.
System-wide audits conducted by trusted counsel can transform what might otherwise feel like an intrusive examination into a routine component of a mature compliance program. Although many organizations face legitimate budgetary constraints that make proactive assessments difficult to prioritize, the cost of preventive review is often modest when compared with the financial, operational, and reputational consequences of responding to a government investigation after concerns have already surfaced.
Connecting the Dots
Mandatory reporting systems, licensing complaints, whistleblower channels, civil filings, social media, and public records increasingly enable investigators to connect incidents across facilities and corporate families that once appeared unrelated. What may have been viewed internally as isolated personnel matters can, when considered collectively, be reframed as evidence of a broader systemic pattern. The same enterprise-wide perspective can also serve organizations well. Regular, consistent, and privileged assessments of these disparate data sources can reveal developing patterns early, creating an opportunity to remediate concerns before they mature into regulatory issues.
An Enduring Enforcement Priority
Protecting vulnerable youth commands broad public support and remains a consistent enforcement priority across political administrations. As a result, investigations in this space often extend beyond determining whether a legal violation occurred.
Even where regulators ultimately identify no actionable misconduct, as in the recent New Hampshire investigation, the process itself may generate public reports, legislative attention, and recommendations for operational reform. For organizations operating across state lines, the broader trend is equally important. While coordinated multistate enforcement involving behavioral health providers has not yet reached the scale seen in sectors such as technology or pharmaceuticals, the mechanisms for information-sharing and coordinated regulatory activity are already well established. Organizations should expect those capabilities to continue evolving and plan their compliance and governance strategies accordingly.
Why Behavioral Health Is Especially Exposed
Behavioral health and youth-serving organizations sit at the intersection of characteristics that naturally draw regulatory attention:
- Vulnerable, often noncommunicative or dependent patient populations
- Residential and secure environments
- Physical interventions and restraint practices
- High staff turnover and heavy reliance on contract labor
- Decentralized, multisite operations
- Extensive and overlapping regulatory oversight
- Complex mandatory-reporting obligations
- Concurrent criminal, civil, and administrative jurisdiction
When an incident occurs, investigators rarely evaluate only the underlying allegation. They assess the institution. The resulting inquiry may sweep in years of incident reports, staffing records, policies, training materials, board minutes, quality reviews, electronic communications, licensing files, and prior internal investigations. The operative question shifts from “What happened?” to “What does this say about the organization?”
The Insurance Dimension: A Word to Risk Managers, Captives, and Brokers
This shift has direct consequences for how risk is financed and transferred, and it is frequently underappreciated until a CID lands.
- A government investigation is not a lawsuit. Coverage triggers, defense-cost coverage obligations, and consent-to-settle provisions written around traditional litigation may respond awkwardly—or not at all—to a CID, subpoena, or voluntary information request. The gap often surfaces at the worst possible moment.
- Notice timing is critical. Early informal outreach from an investigator may nonetheless constitute a reportable circumstance under abuse, D&O, EPL, or regulatory-defense coverages. Late or misdirected notice can jeopardize coverage precisely when defense costs begin to escalate.
- Defense costs accrue significantly with no plaintiff in sight. Document-intensive investigations generate substantial legal spend long before—and often without—any formal allegation. Captives and self-insured programs should model and prepare for this exposure explicitly rather than treating investigation costs as an afterthought.
- Reputational and remediation costs sit outside most insurance towers. Even a favorable finding, as in New Hampshire, can compel operational overhauls, leadership changes, and public scrutiny that no policy indemnifies.
For risk managers, brokers, and captive managers, the practical takeaway is that the modern behavioral health risk profile requires deliberate coordination among coverage structure, incident-response protocol, and outside counsel—before a triggering event, not after.
A Readiness Checklist
Organizations need not wait for a subpoena or civil investigative demand to evaluate their preparedness. A few proactive steps can meaningfully improve both compliance and response capability.
Assess
- Conduct a privileged institutional readiness assessment of governance, reporting pathways, investigations, training, and mandatory-reporting practices.
- Evaluate historical incidents collectively to identify recurring themes before regulators do.
- Ensure significant safety concerns consistently reach executive leadership and the board.
- Assess whether their insurance programs align with risk profile and exposure, and whether updates or amendments should be considered.
Prepare
- Develop and periodically practice an investigation response plan covering document preservation, privilege, communications, and witness coordination.
- Review insurance coverage and notice obligations for regulatory investigations, not just civil litigation.
- Clearly define the roles of leadership, outside counsel, insurers/captives, and communications professionals before a crisis arises.
Strengthen
- Build relationships with experienced advisers before they are needed.
- Periodically test the organization’s response through tabletop exercises or similar readiness drills.
- Measure success by how effectively the organization could respond during the first 24–72 hours of an investigation.
The Broader Lesson
Although the New Hampshire investigation arose in the behavioral health context, its lessons extend well beyond that industry. Any organization entrusted with the care of vulnerable individuals, or responsible for protecting the public from foreseeable harm, should expect increasing scrutiny of its governance, culture, and decision-making, not merely the outcome of individual incidents.
Healthcare systems, educational institutions, youth-serving organizations, hospitality companies, gaming and entertainment venues, and technology platforms all share a common challenge: regulators increasingly evaluate whether an organization can demonstrate a mature, well-functioning system for identifying, escalating, and addressing risk.
The organizations best positioned to navigate that scrutiny will not be those that avoid every incident. They will be those that can demonstrate thoughtful governance, effective oversight, and a culture of continuous improvement long before regulators begin asking questions.
Contacts
If you have any questions or would like more information on the issues discussed in this Insight, please contact any of the following: