Practice Matters: Executive Insights for Independent Healthcare Groups
Independent healthcare practices are navigating an increasingly complex landscape—from financial pressures and regulatory changes to operational challenges and growth planning. To best support these organizations, DMJPS CPAs + Advisors is launching Practice Matters: Executive Insights for Independent Healthcare Groups, a six-part webinar series designed specifically for healthcare leaders.
Facilitated discussions led by the DMJPS healthcare team will feature industry specialists and deliver practical insights with actionable strategies to help practices strengthen performance and plan for the future.
Practice Matters: Executive Insights for Independent Healthcare Groups
Practice Matters: Medical Practice Fraud & Compliance Risks
Use Left/Right to seek, Home/End to jump to start or end. Hold shift to jump forward or backward.
Healthcare practices face increasing pressure to protect patient information, maintain compliance, and safeguard financial performance. From billing and coding risks to embezzlement and HIPAA violations, practices must stay proactive in identifying and mitigating risks before they affect operations, revenue, and patient trust.
Join our team for a practical, DMJPS-led session focused on strengthening revenue cycle integrity while reducing fraud and compliance risk. This webinar blends financial fraud insights with healthcare-specific expertise, including considerations around billing, Medicare, and coding risks.
Presenters: Noel Swartz, CPA- DMJPS Assurance Partner & Sarah Hayes, CPB, CPCO, CHBC- DMJPS Healthcare Supervisor
Facilitator: Christina Sanders, CPA - DMJPS Healthcare Director
Hello and welcome to Practice Matters, Executive Insights for Independent Healthcare Groups. I'm Karen Rodriguez, Chief Marketing Officer at DMJPS CPAs and Advisors, and thank you for joining us for another important conversation focused on helping healthcare leaders protect their organizations, strengthen operations, and plan with greater confidence. For those just getting to know us, DMJPS works with physician groups, dental practices, and healthcare organizations across North Carolina and beyond to provide accounting tax, advisory, and health care consulting services to independent practices who are navigating financial, operational, regulatory, and strategic challenges. This discussion today focuses on medical practice fraud and compliance risks, an area that continues to grow in importance as healthcare organizations manage complex billing requirements, HIPAA obligations, internal controls, and evolving expectations around patient and financial data. Facilitating today's conversation is Christina Sanders, Healthcare Director at DMJPS. Joining her for this episode is Noel Schwartz, Partner in Assurance Services at DMJPS, and Sarah Hayes, Healthcare Supervisor at DMJPS. Together they bring deep experience in audit advisory, revenue cycle management, HIPAA payer reimbursement, and healthcare compliance. In this conversation, Noel and Sarah discuss compliance risks, warning signs of fraud, the importance of strong internal controls, and practical steps leaders can take to protect sensitive information. Noel will also share real-world examples from fraud investigations and what those situations can teach practice leaders. Be sure to stay through the end for audience QA where Noel, Sarah, and Christina discuss building a culture of compliance and share helpful resources. Thanks for listening. Let's get started.
SPEAKER_01My name is Christina Sanders, and I serve as a director here in our healthcare group at DMJPS CPAs and Advisors. Thank you for taking time out of your busy schedule to join us. During today's session, we'll discuss the fundamentals of healthcare compliance, common compliance risk-facing medical practices, HIPAA requirements, fraud prevention strategies, and practical steps healthcare leaders can take to strengthen their organizations. We'll also explore warning signs of fraud, the role of internal controls, and what practice owners should do if compliance issues or fraudulent activity are identified. What we discussed today is directly aligned with the advisory work our healthcare team is doing every day alongside practice leaders. One of the primary goals of the Practice Matters series is to provide practical, actionable guidance, not just theory. We want healthcare leaders to leave each session with ideas and strategies they can implement immediately within their organizations. Whether you're a practice owner, a practice administrator, executive director, or department leader, today's discussion is designed to help you better protect your practice, your team, and your patients. I'm excited to be joined today by two of my colleagues here from DMJPS. First, we have Noel Swartz, who's a partner in our assurance services. With more than 30 years of public accounting experience, Noel advises clients across a broad range of accounting, audit, and advisory matters. He is known for his technical expertise, practical perspective, and commitment to helping organizations strengthen financial oversight and governance. Joining Noel is Sarah Hayes, a supervisor here in our healthcare department. She has more than 15 years of healthcare industry experience, including extensive work in revenue cycle management, healthcare operations, compliance matters, and practice management. Her firsthand understanding of the day-to-day challenges facing medical practices brings valuable insight to today's discussion. Together, Noel and Sarah provide a unique combination of accounting, compliance, operational, and healthcare industry expertise. Their experience working with physician practices across North Carolina gives them a practical perspective of the risk organizations face and the steps leaders can take to mitigate those risks. At DMJPS, we believe helping healthcare organizations succeed requires more than compliance. It requires building strong operational foundations, maintaining effective internal controls, and creating a culture of accountability throughout the organization. Today's discussion speaks directly to those objectives. And with that, I will turn it over to our presenters. Sarah, take it away.
SPEAKER_03Thank you, Christina. Hi, and everybody. Thank you again for joining us today to discuss compliance and fraud. As a disclaimer, the presentation is to be used for educational purposes, and the presentation is not to be used as the sole resource for compliance or fraud. As we know, this is effective as of today, but everything changes. It can be changing later on this afternoon. So if you do need any legal advice, we would recommend that you reach out to a qualified professional or attorney to help you with those matters. But let's go ahead and get started. So why does compliance matter? Well, it matters for quite frankly a number of reasons. But most importantly, it provides a guideline for how your practice should run, the policies and procedures that need to be followed, and how to handle concerns when they arise. And they will arise. There's not a single practice, whether you're dental or medical or just from a consulting standpoint, where there's not going to be a compliance concern at some point. Compliance really encompasses so much that we could have a whole session on all the different areas, but for the purposes of this presentation, we're going to focus on healthcare compliance within a medical or dental practice and how at its core it's the ongoing process of following those federal, state, and local laws and regulations. These laws and regulations protect your patients, your doctors or providers, employees, and also the reputation of your practice. Your patient's information will remain secure. Your doctors and providers again are going to be protected. Your employees will know what to do and their day-to-day job responsibilities. And the practice will have less at risk during an audit or an investigation. For those that don't follow the laws and regulations, we don't know any of those people though, right? All of the people we work with are always follow the rules and regulations. But yeah, there are fines and penalties that can be placed upon a practice or upon the individual. So there can be definitely monetary penalties, but in addition to that, the practice might have to repay claims, which could be in a lump sum amount or recoupments and underpayments for future claims that are being processed. Whenever this happens and there is a penalty, trust, there's going to be a way that the payer or the government is going to get their money back. So there's just how it's going to be pulled back, is is the process that might be a little bit different. But the practice or individual could also be excluded from the Medicare or Medicaid services, really any kind of governmental payer. And in several cases, there can be criminal charges imposed. For those that aren't aware, the exclusion, there's an OIG, the Office of Inspector General, there's an exclusion list where you need to go out there and check on that. So we'll talk more about that soon. Here are some common compliance risks that can occur within any practice. Just remember, documentation is the only way that you can justify the diagnosis and procedural codes that are being billed. It's best to remember that if it's not documented, it did not happen. Just because it's in your memory doesn't mean that anybody else is going to remember that. It needs to be written, documented, and in your medical records. Your documentation should justify the level of coding, the modifiers being used, and its medical necessity. It should really paint a picture and tell a story of what happened during the visit with that patient. And don't forget that the documentation must be signed in a timely manner before the charges are billed. For certain industries, there can also be additional information needed for services to be rendered or for the charges to be filed. For instance, you know, prior authorization before a drug can be administered, like for rheumatoid arthritis treatment or for durable medical equipment, a written order has to be signed and received before a hospital bed can be delivered to a patient's home. So there's lots of different steps and procedures that have to be followed in order for the billing to happen appropriately. And unfortunately, those rules and the way that the payers' regulations are are constantly changing. So it's really important that you stay up to date on what's happening within the industry. The risks can be limited though by pulling a random selection of patient encounters and reviewing the charts. So when you look at what the payers are doing and then you compare to what's happening in your practice, you know, does the diagnosis code in the CPT on the claim form match what's in your documentation? Is the doctor who signed the encounter the same doctor that's on the claim? Does the documentation justify the coding? It used to be that the mindset was, well, as a doctor, if I just bill level twos and threes, I will stay off the radar, nobody will pay attention, and I'll be, you know, it'll be smooth sailing. But now the opposite can actually happen. And if you're a practice who rarely bills a four and a five, that can also trigger an audit. So it's really important to make sure that your coding matches what's, you know, industry standard, what the rules and regulations are. Because believe it or not, undercoding is also a risk, not just upcoding. When you're doing the reviews on your on these patient charts, it's also important to keep a log of how many charts are being reviewed, who's doing them reviewed, and when it's when it occurred. The log, of course, should not include any patient information in it, but um but just kind of the the actual cadence of when those reviews are being done is important. We have to remain really vigilant on HIPAA regulations and preventing fraud, waste, and abuse. And that log without patient information will help you do that. Now, when it comes to HIPAA compliance, uh quite frankly, I could do a whole two-hour presentation on nothing but HIPAA, um, but I won't do that to you. Um, HIPAA or um and that stands for Health Insurance, Portability and Accountability Act. So it's H I PAA, not H I P P A, which I see all the time. Um, but it's a really extensive topic that spans from its conception in 1996 to today's ever-changing landscape. HIPAA focuses on establishing safeguards for protected health information, or PHI, and it applies to covered entities and business associates. So a few examples with covered entities. It they're really three main groups: healthcare providers who transmit any kind of health data electronically, health plans that pay for medical care, and clearinghouses that process that health information. And then business associates would be any person or organization outside of the covered entity that would have access to the PHI. So, for instance, a third billing, third-party billing company, any kind of like a cloud storage vendor or an IT contractor, or in this case, DMJPS. We also need to have business associate agreements on file with all of our clients. Covered entities really need to have a business associate agreement on file, and it's a contract that outlines what is permitted and what's restricted on how you're using that patient data. Now, HIPAA has three different rules. It's privacy rule, the security rule, and the breach notification rule. The privacy rule provides a foundation of who to go to if there are concerns. Your privacy officer, very important to know who your privacy officer is, the policies and procedures that everyone needs to follow, and not just employees, it's everybody, the owners, the doctors, the staff, everyone. How your practice is going to safeguard and disclose PHI, and again, PHI stands for your protected health information. And that could be anything that's used to identify the patient, their name, date of birth, address, their medical record number, diagnosis codes, really anything that would be unique to that patient, that is something that would be included in PHI. Not sure if everybody on your on the webinar is aware of this, but every practice should also have the notice of privacy practice. So when we go to the doctor, we get a notice of notice of privacy practice that everyone should be getting and signing on how that doctor's office is going to disclose your your PHI. There was an update that went into effect in February. So as I personally have been going around to all my different doctor's offices, I've been looking to make sure that those updates are there. So if you haven't updated your notice of privacy practice, you need to reach out and uh and get that updated soon. Um, something that's also very important and sometimes neglected is the ongoing training for employees and owners. Again, and owners, so it's not just employees. Um the training could be for coding, any kind of changes in regulations like the notice of privacy practice that happened in February, a new process that's been implemented within your practice, or just ensuring that everyone is up to date on how to detect those wonderful, lovely phishing emails and security breaches. The security rule applies to the technology being used, the access to devices, disposal of data, and encryption. I know we also all love those multi-step authentications, but due to HIPAA and all the breaches that have happened in recent, yeah, very, very recent within the last couple of years, we need to make sure that we have those to secure our data and make sure that we're taking the right steps to access it. If there is a breach of data, the breach notification rule provides the parameters of what needs to happen. Who needs to be uh contacted, who was impacted by the breach, how do we notify them, and in what time frame do they need to be notified? These are all steps that are listed in the breach notification. Now, I know many, many of us, probably everybody here and everyone we know, is aware of the breach notification because we all seem to re got a, excuse me, we all got a notification of the change healthcare data breach. I'm not sure about you, but I think we I can speak for all of us and say that we're much more conscious of our data and how easily it can be compromised. That was a historical event. If you're not aware of it, it definitely go out and Google it. But the change healthcare data breach really opened our eyes to how easy it can be to breach any kind of system, gain the data, and with it being Change Healthcare, who encompass so much across the nation with their different entities, really about everybody in the US was impacted by this. So breach notification is very important, but really all the steps in HIPAA gives us that framework of how we need to protect our patients' data, which then of course also protects ourselves. So well, when it comes to compliance, excuse me, it's important to have a working, evolving compliance program. It does nobody any good to create a compliance program that sits in a folder on a shelf that nobody is paying attention to. Your compliance program really gives everyone within your practice a framework to follow. It shows clear guidelines for daily work, training and education for everyone, again, not just for staff, but for owners as well, routine checks for audit, and to fix any errors within a process. And really also how to report compliance issues. Again, having somebody who is the compliance officer is important because then somebody, you know, anytime there's an issue, then you know exactly who to go to. So if a if the practice changes their procedures or they assign a different compliance officer, there's any changes to disciplinary actions or, you know, any step that really in the process, the program must be updated and it notated when the update had happened. If you do have an auditor come in, which is very possible, this compliance program being in place will demonstrate a good faith commitment to ethical practices. There's lots of information in this compliance program, and it can be very overwhelming when you think about all the different steps that are in there. It's important to start small, to start somewhere, and to create that framework. In a lot of cases, practices have much of this information. It's just not all consolidated into one place. And so that's where it can be most, you know, overwhelming when you look at all the things that need to be added to it. But it is very important to have. And if you don't have a compliance program, you can work with, you know, your malpractice can also help with that. But also, of course, DMJPS, we can work with you and see how we can work to create that framework and put all the pieces in place for your practice. Now, fraud and compliance, excuse me, compliance and fraud have been all over the news due to Medicare and Medicaid fraud allegations that we're seeing occurring across the country. So here are some warning signs to look out for in your practice and in your billing processes. Are there unusually high billing volumes? Is your practice still seeing the same amount of patients, but your billing and receipts have increased drastically? You know, when was the um when performing the review of the charts, does everyone look the same? Do they have the same verbiage? This could be a copy and paste scenario, which quite frankly is much easier for the provider, but it doesn't give you an act an accurate medical record. You know, not every patient is going to have the same situation, the same issues. And so the documentation and the verbiage in that would not be the same. One regulation within HIPAA, which is minimum necessary, basically means if you don't need to look at it, don't look at it. Employees should not be accessing records without a business purpose. And the security rule also includes technical safeguards that would prevent staff from accessing areas of the system if it's not needed for their role. But just because, you know, if you're in a practice and you hear that your neighbor down the street came in, that would not be a reason to go into the system to see what happened with them. So, you know, if you don't need to look at it for a business purpose, definitely don't do that. Because of course, if you do, then I would bet that you would probably terminated and should be terminated for looking at those records. So lots and lots of uh different parts of HIPAA that really again provides that framework for your for your practice. All of these things would obviously, all these warning signs would obviously fall outside of normal practice and would require remediation of processes and procedures. They could also result, of course, in termination or further action depending on circumstance. Another warning sign that you should look out for would be patients complaining about their bills. Now, patients complain about their bills all the time, but these need to be not just that they received one, but that they're being billed for services that they did that they didn't receive and really checking to see if there's a pattern with the complaints because, you know, are you doing your coding incorrectly? A patient might not necessarily know that, but they might see that something that they came in for that should be covered at 100% hit their deductible. Well, there might be a problem there with your coding. Are they getting billed again for services that they didn't receive? Well, why are we coding for things for services not received? That could be a problem too. Or also, why are they receiving a bill for something they've already paid for? Now, when we think about compliance, it's not just about following the compliance program put into place for your practice, it's also fraud, waste, and abuse. Fraud being that someone is taking intentional steps for financial gain and getting reimbursed for services not rendered. The key word there being intentional. If you're creating, um, you're intentionally doing something to try to gain financially for that. Waste would be doing unnecessary testing or maybe outdated protocols that would let then lead you to abuse, which would increase your billing, have routines um within your practice that are outside accepted standards and within the industry.
SPEAKER_00Okay, and with that, uh, we're going to change hats here. So on um Sarah's last slide, she went through fraud, waste, abuse, and mentioned fraud being intentional. So, this whole webinar, if you were to just put a hat on it, it's all about knowledge. It's all about increasing your knowledge as owners. Practitioners, practice managers, so that you know what to be aware of, giving you a different set of glasses, if you will, to just keep keep an eye on folks, uh, but also taking a look at your own practices for how you can strengthen things. And that's what we're going to talk a little bit about today. But let's start high-level. So the fraud triangle, three sides of the triangle: opportunity, pressure, rationalization. Sometimes the terminology changes, but it's all meaning the same. And for fraud to occur, all three of those need to be present. And in the next three slides, I'm going to go through each of those three and talk a little bit more about what each of those means with a couple examples. So, opportunity. Opportunity just basically means, hey, if I wanted to, could I? And so the opportunity is really that's what you can most control. Weak internal controls. You've heard that terminology already. Sarah brought that up. We'll talk a little bit about more from a tangible perspective, what are some examples of weak internal controls? How could they be strengthened a little bit? Uh, lack of segregation of duties is a is probably one of the key internal controls. Again, we'll talk about that a little bit, a little bit later as well. But lack of management oversight, if management just kind of sits back and lets people do what they want to do and doesn't really check or hold people accountable, that creates opportunity. If upper management, if people see the owners, the practitioners abusing the system, taking advantage, that's sort of uh that that's that creates opportunity as well because they're less aware of it. They're uh it creates an open door. And then uh that actually adds to the whole environment of unethical behavior. And sometimes we see that. Um, I've seen that with some investigations that I've done before, and I'll talk to you a little bit about that uh in the next two slides. So pressure. So pressure, then first of all, pressure means things, different things to different people. And so pressure in this case from the triangle is in the mind of the person that is going to be committing the fraud. And so, as you can imagine, we're all humans, we all have different lives, we all have different pressures, if you will. And so different pressure will create a a need or a want when there is opportunity to go that next step. And so some work-related pressures are you're not doing so great. Um, you you want things to look better than what they are. So that that that dovetails into what Sarah was talking about as well is make the numbers look a little bit better. That may not impact you personally, but it might if you have bonuses based on that performance. So practice isn't doing great, you're not going to get a bonus. So help you to help me, kind of a thing. Um unattainable goals. So when you do have set goals for your workers, make sure that they're not pie in the sky, because that creates an environment as well. Where I tend to see most from a fraud perspective is on the personal related pressures. And that is people have extreme levels of debt, addiction, lifestyle maintenance. Um, when I audit companies, it was funny when when I first got started, they always talked about all right, driving through the parking lot, make a note of what kind of car the bookkeepers driving, what kind of car are the controllers driving, or if there's a CFO, what kind of car are they driving. So you see three Ferraris in the parking lot, that might be an indication that something's going on. But I was recently involved in a uh in a in a fraud investigation, and this person's car was not great. It was breaking down all the time. That actually presented the pressure that this person needed to take the first step to commit fraud because they had a repair that they could not afford to do. And because I'll tell you about the internal controls in a minute here, but there was a lot of cash currency in the business. And because they were able to do a lot through improper segregation of duties, they were able to take that cash, nobody missed it, and they were able to fix their car. And what's interesting about that is, and I this is on the next slide with with uh up with um justification, is they were able to justify that or rationalize that, and we saw that as well. Rationalization is the last step. So the first two have to be present, and even if the first two are present, if rationalization doesn't exist, there might not be fraud committed. So I mentioned the person with the uh the car that was unreliable. So the relia the rationalization in this case was nobody's even gonna see this cash being gone. So I get paid in two weeks, I'm just gonna borrow $500 to fix my car, and then I'm gonna pay it back. And when we were brought in to do the investigation, we saw that that happened. We saw that there was a payback, but then it happened again and again and again. And then over the course of that first nine months, mysteriously, the payback stopped. And so then it just got really, really big. But that that gets to the third data point, the third point here on the slide, which is just borrowing with the intent to pay back. Sometimes you don't see that that actually being paid back. This same fraud case, there was also a justification or rationalization because it was helping out other family members too. We saw that. We saw that with gift cards, we saw that with other things that were being purchased. This is one sometimes, from an ownership or a leadership perspective in a practice, is feeling cheated by the owners. So it's maybe you're driving the Ferraris into the practice, and it's you know, if it's all cordoned off and you've got that, and people see that. I'm not telling you you can't have nice cars, but sometimes that leaves a certain impression, and some employees like, well, maybe maybe I deserve because the opportunity's there and the pressure's there. Maybe I deserve that. But again, because we are people, the rationalization and the pressures are not the same for everybody. Because the last point that's not a data point is hopefully your your hiring practices are are will catch this. But if the person is just a psychopath, and so again, if you know the definition of a psychopath, they have no conscious, they don't know the definition between right and wrong. And you've heard some really famous examples of that, like Bernie Madoff, for example. But if you have that, you don't need rationalization. So detection of red flags. So so this is where you look at those, you look at the first two, really the first one, because that's the one, the opportunity that you can control as leaders within your practices. And so those are the ones that if you've got a little bit of concern there, you work on those areas. We'll talk about in a minute how you can do that. But if things are already happening, or even if after, because things change, as Sarah said, the world's constantly evolving from a billing perspective. And if your systems aren't keeping up, if your internal controls aren't keeping up, then sometimes that creates an opportunity where one did not previously exist. So being aware of these detection red flags is important. Just being aware of financial difficulty. I mentioned that in some of the cases I've been involved with, well, there was a study done, and 36% of time, um, that was part of the realization is that there was financial difficulty that provided the pressure for folks to commit fraud. Living beyond their means, it's not always a Ferrari, but it's 42% of the 42% 43% of the time as well. The vacation's an interesting one, too. I I I have an example where I had a client and they they weren't an audit client, but they they called us, we had a relationship, and they said, Hey, listen, um, our CFO, longtime CFO, just got in a car accident, and something strange just sort of happened. You know, we always thought he was an amazing employee because he never wanted to take vacation. We're just like, this guy is so dedicated. Then he called the controller and the bookkeeper from the hospital bed and said, Hey, I should have gotten the we should have gotten the bank statements today. Do you mind dropping those off in the hot in the uh the hospital room for me? And so it just so happens this owner saw them walking out and said, Where are you going? And they mentioned where they were going. So he asked to look at them. And this is how bad the internal controls were. So he actually looked, and this was way back, so it probably gives you an idea, but there were canceled checks that came with the with the bank statements. And as he's thumbing through them, he's seeing that that CFO is actually writing checks to himself because he actually had check signing authority too. So wasn't even hiding it because the owners were not looking at the bank reconciliations. They, even though they signed checks, they hardly signed any checks. So the CFO was trusted to sign all of the checks. And at the end of the day, this went back years. And I think the total in this case was about three million dollars over the course of about 15 years. And he knew, because he put the budgets together, how much he could get away with and not draw red flags with some of the internal controls that they had in place. I'll touch on what those internal controls were in a minute. And he also did a nice job because he studied fraud. So he was very careful. He had some really nice stuff and very nice cars, but he drove a very, very generic car to work every single day, and nobody saw that other side of him. So it was really, really interesting. He he went through to great lengths to be able to uh to conceal that. So fraud prevention. So this is what we're all sort of leading up to is this is what you're what you're doing right now, understanding and learning how fraud is committed. But to Sarah's uh point before, the world is constantly changing. In fact, just as for a an experiment, I just typed into copilot. We have a protected copilot environment here in our in our firm, so it doesn't get it doesn't train the robots. And so I typed in, in the last six months, what's the preferred method to embezzle cash from a medical practice? And what was interesting about that is the result I got was we're not able to help you to commit fraud or give you information to do so. But what is the reason you're asking? And it actually gave me uh a go. It said, if you just want to learn more about generally how fraud is committed, or you're putting together a presentation, but but that may be just because it knew I was putting this presentation together. So um AI is a little bit smart. But I thought that was fascinating because in the past there's there's been sort of handbooks for how you could commit fraud. And I think everybody right now, if you have a phone in your pocket, probably has one of those. So the next point, evaluate your internal control environment. We'll talk about so there's lots of internal controls you can do. We'll talk about some very key controls. Lead by example. We talked a little bit about that two slides ago. If if the environment is, you know, it's okay, you know, why don't you help yourself to the uh cash box there? Word spreads pretty quickly on that, and it sort of lowers um it lowers the level of awareness that other employees have for potentially reporting fraud. And so that goes at the top with with tone at the top, but that's zero tolerance. So if fraud happens, there's no second chances with fraud. Zero tolerance, they get walked to the door, and always consult legal related to this, because there could be slander, but it's sometimes you can tell people about what happens, sometimes you can't. So always consult uh legal there. Um, but I have had situations before, and this actually happened with that cash example with the person with the car, where after that fraud investigation was happening, and by the way, when we were hired to do the fraud investigation there, they thought it was maybe $120,000, $130,000. We had trouble proving how much it was because the internal controls were so bad, the segregation of duties were so bad, the bookkeeping and accounting were so bad. All we can prove is one, the accounting was really, really horrible, or there was such a disconnect because just things weren't matching up at all. But as we ended that, I offered to come in, do an internal control assessment, um, do some recommendations for them. Uh, we do that quite a bit at DMJPS. Um and then I concluded and I said, so that this doesn't happen again. And they said, Well, you know, it's happened before, it's probably going to happen again, because the point I made was don't collect cash or make it minimal. And they said, that's not great. We'd still want to keep cash, we understand the risks, and it'll happen again, and that's okay with us. So wow. Talk about leading by example, talk about tone at the top. So I don't know whether fraud has been committed again since that, and that was about seven years ago. It makes me want to go back and uh and and check and see, or maybe make a phone call. Whistleblower policy. So everybody walks into their break rooms, their kitchens, and they've got all of the compliance information. And sometimes there's a little tiny like placard there, almost like the size of a post-it note here. And actually, that doesn't even show up. Interesting. And it says sometimes if you see something, say something with a phone number. And it's amazing because sometimes when I'm uh have my audit hat on, we see those, and uh some of my staff just pick up the phone and dial it just to see what it sounds like. Sometimes the phone doesn't even ring anywhere. Um, sometimes there's a voicemail box that is permanently full. Um, but sometimes we leave a message and never get a reply back. So it's really, really interesting. So if you put things up like that, while it does operate as a deterrent, just know if somebody's really, really good at committing fraud, like you know, the car accident hospital guy I was telling you about, they may have tested out the whistleblower hotline just to see if it really works. The next one, I'll just owner involvement, and I'll talk a little bit about this too, but that is a very powerful deterrent as it relates to um setting the tone at the top and creating a really good deterrent as well. And so, you know, we've talked about all of this um internal controls, but I'm gonna touch on one more thing from a fraud prevention perspective. Is I mentioned AI, how do you commit fraud? Well, talk to DMJPS about this first. But if you have AI tools that are protected from uploading into the the bigger robot world, then you could actually potentially do a little bit of checking yourself to see if there's transactions that don't make sense, things like that. Um, our team does some of that work as well, so so definitely reach out with them on that. All right, so now internal controls. It's sort of this big ethereal topic, and everybody says if you got them, you're good. There's two general types of preventative controls, preventative, internal controls, preventative and detective. Preventative controls are what exactly what they sound like. So they prevent fraud from happening, they usually prevent errors from happening too, because there's usually a level of review that happens. Detective controls are things that happen after the transaction happens. So if they're happening at the right level, in theory, they can detect malfeasance, hopefully in a timely manner. So let me give you an example of that. So detective controls would be something like really good budgeting or review of the financial statements, and to the extent that there are certain things that you weren't expecting, because you all as owners, practitioners, um, practice managers, you know how the practice did the previous month, the month before. So you you have a sense for what you would expect those financials to look like to the extent there's a disconnect there, and as you dive down in the details, you see things that don't make sense. Make sure you're getting good explanations for that and dive down to make sure it makes sense. On the preventative side, segregation of duties is probably one of the most powerful ones. And all that basically means is you're separating the functions between authorizing transactions, recording those transactions, which would be recording them inside your inside your books, and then maintaining custody of assets. So let me just talk real briefly about what that means is. So make sure you understand who has access to those areas, who has the ability to authorize those transactions, and are there are their duties, should they remain separate from others? Are you involved in that process as well? Are you reviewing some of the cash transactions? Are you signing checks, things like that? And again, that's a balance because your time is valuable too. And so you don't want to spend three hours a day doing internal control-related matters if you're not bringing in revenue as a result of that. And so the last slide is well, what do you do? If it happens, you could have the best internal control system in the world. Sometimes it still happens because of changes that happen with the world as we know it. Your accounting systems always routinely have updates. If those aren't being installed timely, sometimes there's a backdoor. Sarah mentioned things change with compliance too. That creates an opening, also. So, well, first of all, I mentioned this before, never let it slide. That creates a really bad tone at the top. You have to react quickly too. So no second chances. Plan for damage control. So what does that mean? Well, that can mean it really anything. So that can mean, well, how much is being stolen? Do you have resources that could that you could put in to keep things going? Um, is there significant reputational risk? Sarah mentioned about data breaches, things like that. That those create very big significant um reputational risk for a practice. The other is insurance coverage as well. Um, Sarah mentioned malpractice, but there's insurance for everything. So make sure you understand what your what your coverage is. Talk to your insurance agent. Certain fraud-specific coverage has limits, especially if the internal control system is so bad, there could be some sort of shared responsibility there, or could also call contributory negligence. And while you're at it, because we we mentioned cyber, make sure you got good cyber coverage as well. And then lastly, the authorities and prosecution, because the last thing you want is for that same person to go and do it to somebody else and do it to somebody else. But I will tell you, in your hiring practice, check references. Because you'd be surprised how few people prosecute because they don't want their name to be out in out in the public. And so somebody's good at committing fraud, they're going to do it again. And then lastly, shameless plug, called DMJPS. We we see we see fraud. We hope we don't see fraud, but sometimes we're brought in because we do. And once it happens, it's too late to put those those corrective measures in place. So we can help you do that.
SPEAKER_01All right. Well, thank you both. There are a few questions that have come up, Sarah. I'm going to start with you. What is one step a practice leader can take to build a stronger culture of compliance across the organization?
SPEAKER_03I would say start small, first of all. If you try to look at it and do everything at one time, it's just like a diet. If you try to change everything in your diet at one time, it's probably not going to stick. It's the same exact thing with the compliance program. So just start small and make a plan. Does your plan does your practice have a compliance program? That would be the first question. Is there a designated compliance officer? And really, are your coders up to date on the latest changes? So that's that's probably the first place I would start, depending on what area of the practice you're looking at first.
SPEAKER_01Great, Sarah. Another question for you. You mentioned several documents, the business associates agreement, um, notices of privacy practice. Where can they find these documents and what resources should they be accessing to get this information?
SPEAKER_03So if you go out to the HHS.gov website, that would be the first place to look. If you go and look at the notice of privacy practices in the search bar for HHS, then it will give you a guideline for what your notice of privacy practices should include. And the change that happened for February included substance abuse disorder. And um, there was also another piece that was going to be added for pregnancy, but they they paused that for now. But mainly it's the substance abuse disorder that information that needs to be included. So, and then the same thing with the business associate agreement, that should also be out there on the HHS.gov website where you can get a framework of those parameters.
SPEAKER_01Great. Thank you, Sarah. Noel, question for you. You mentioned owner involvement as some something that could help in in terms of fraud prevention. Fraud prevention, but what are a few practical ways? I know you said maybe three hours a day, maybe a little exaggeration, but from a practical perspective, what are some things that owners can do to really be effective?
SPEAKER_00First of all, that was an exaggeration by a long shot. So just owner involvement where others see that the owner is involved. So from one, from a deterrent perspective, but two, because cash is one of the most valuable assets and it's the quickest to leave, depending on what the amount is, if you're still writing checks and the volume is not that high, then if you are more more than one uh owner practitioner, uh rotate that around so that um so that others uh can sign checks, but also have them review at the same time. But the other side of that too is just review the uh bank reconciliations at the end of every month. So that should include the the bank statement, which also has a listing of all the checks, all the wires, things like that. That's that's pretty valuable as well.
SPEAKER_03And no from pure question, but I will say it's also important too to look at those clear checks. We had a situation that happened with a client of ours where internally there was no fraud, but externally a check was stolen and they were able to overwrite what was on the check, and we found fraud from that standpoint too.
SPEAKER_01So yeah, Sarah, you kind of um honed in on what I was gonna ask to pull a little deeper when reviewing things like the bank statements, besides canceled checks, you know, as a business owner, as a physician who may not necessarily understand what they're looking at, perhaps, what should they be looking for? If, for example, if I go to read medical notes, it's gonna be foreign language to me. But as a business owner, what are some things within the bank statement? Clear checks are a really great example. Looking for names that you may recognize. And then I think too, perhaps just asking questions. If something looks out of character, maybe.
SPEAKER_00No, that's you you've hit the nail on the head there. Is if everybody knows, hey, one of the uh the owner practitioners is reviewing the bank statements, but they never ever want uh answer or ask one question. Then they're like, well, he's probably not even looking at it, so not a big deal. But yes, look for those things that are unusual. But to Sarah's point, we do see that from time to time. Checks are really dangerous these days. I mean, think about it. Your routing number and your account number are on a piece of paper that goes through the most unreliable means of delivery that the US government had to offer us. And so um, so think about that because we do see that. And in the world of AI, it's super easy to create a forged check and forged signature as well. So, so look at that as well. We do see sometimes with larger amounts where two signatures are required, but sometimes that that doesn't happen either.
SPEAKER_01But well, and in this day and age too, it's so easy to go online and type in a routing number, an account number, uh, you know, bill pay, things like that. I think it goes beyond just the physical checks themselves, but also the ACH transactions. Um, some banks also don't give a ton of detail when you're looking at the statements. Not all of them give copies of canceled checks. So if that's something that you're looking at and you're not seeing the detail that perhaps you need or you want to see, I think asking for it would be helpful. Sarah, another question for you compliance issues. What do you think practices are most likely overlooking on a day-to-day basis when it comes to compliance?
SPEAKER_03I would say the number one thing is the OIG exclusion list. Um, this is really important and quite honestly mandatory to check at pre-employment. And it doesn't just apply to an employee, it also applies to any new vendor you're bringing on, a new contractor. And the OIG exclusion list is updated on a monthly basis. It may seem like it's overkill, but it really is important to check that monthly. And you can do it, you know, upload a whole spreadsheet and you can import that into the OIG exclusion list. And it will populate if you have anybody on there who should not be working with a group that handles Medicare and Medicaid. Um, because if you do have an employee or a vendor that you're using that is on that exclusion list, not only are there monetary penalties, but you may have to repay all everything that has been paid to you for um where that vendor or employee was interacting.
SPEAKER_01So yeah, really great. We did have another comment from um a participant along the lines of what we were talking about, NOL with the bank recks and the payables process, and Sarah, your commentary. Using an accounts payable service can also help mitigate their risk when you have a third unbiased party involved. So maybe you don't have the means to be able to hire someone, but utilizing technology to help with some of that can help mitigate as well. So really great commentary from our audience. Well, that's all the questions that we have for today.
SPEAKER_02Thank you for listening to Practice Matters, Executive Insights for Independent Healthcare Groups. To review supporting resources, learn more about DMJPS Healthcare Consulting Services, or explore additional episodes in the Practice Matters series, visit DMJPS.com. If you have any questions about today's discussion or would like to connect with our team, email connect at dmjps.com and we'll be happy to help you. Thanks for listening, and we'll see you next time.