Prevention by design: the controls that make theft visible fast
Summary
No single person should both move money and be the only one who ever checks the record of it. The controls that catch theft early are structural, not about trust: route bank and card statements somewhere the reconciler cannot control, require a second sign-off above a set dollar threshold, restrict who can add a payee or void a claim, and screen anyone touching billing against the federal exclusion list. Apply these from the day you hire, not after something looks wrong.
By Gale Editorial · Updated 2026-07-27. Every figure cited to a dated source. How we write.
Why trust is not a control
A one-person billing setup is not a moral failure waiting to happen — it is a structural gap, and the fix is structural too. internal controls are the habits and permissions that make a wrong number visible to a second set of eyes before it compounds into a pattern. They exist for competent, trusted people, not despite them, because the person best positioned to move money quietly is exactly the person you trust enough to hand it to.
The goal is not surveillance — it is making sure no single person can both initiate a transaction and be the only one who ever checks it. Even in a two-person practice that goal is reachable: you do not need a controller or an audit committee, you need three or four habits, applied consistently, starting the day you hire.
Most of what follows costs nothing beyond a calendar reminder and a moment of friction on payments above a threshold you set yourself. The habits work precisely because they are boring and repeatable, not because they are elaborate — an elaborate policy nobody actually follows protects less than a simple one that runs every month without fail.
The one review that catches the most: someone besides the money-handler sees the statement
If you adopt exactly one control, make it this one: bank and credit-card statements arrive somewhere the person who reconciles the books does not control, and a second person — even if that second person is you, reviewing for twenty minutes a month — actually looks at them line by line before they are filed. This single habit is the one most embezzlement schemes are built to survive undetected, because most rely on nobody else ever looking.
Route statements to an email or mailing address only the owner-clinician can access, not the office manager's inbox. Look for the boring signs: round-number transfers, a payee you don't recognize, a vendor invoice that crept up without a matching change in service, or timing that clusters around when the same person is scheduled to be out. None of these prove anything on their own — the review's job is to ask a question, not convict.
Separate who requests a payment from who approves it
The structural weakness in a one-person office is that the same hands write the check, record it, and reconcile it — so build in a threshold above which a second person has to say yes before money moves, even if that second person is you, signing off from your phone. A common convention is to set the threshold low enough to catch anything unusual without turning every routine bill into a bottleneck; a few hundred dollars is a typical starting point for a micro practice.
Apply the same split-role logic in a few other places:
- Vendor and payee changes — a new bank account for an existing vendor, or a brand-new payee, gets a verbal confirmation from a known contact before the first payment goes out.
- Payroll changes — a change to anyone's direct-deposit account routes through you, not just the person who runs payroll.
- Petty cash and card limits — set a hard ceiling low enough that going over it is itself the signal something needs a look.
Write the threshold and the approval step into the same handbook that carries your other policies, not just into a private habit only you remember. A documented threshold is something a new hire is told about on day one rather than discovered by accident, and it is evidence the control was real and consistently applied if that ever matters later.
Lock down who can add a payee, void a claim, or issue a refund
Most of the software a practice already runs — the EHR, the billing system, the bank's online portal — has permission levels, and the default is usually more access than a front-desk or billing role actually needs. Restrict who can add a new payee, void or resubmit a claim, issue a patient refund, or change a bank account on file to the smallest set of people the job requires, and review that permission list at least once a year rather than assuming it is still right.
Before anyone touches billing or claims, check them against the federal exclusion list the same way you would before credentialing a clinician — no federal program payment may be made for items or services furnished by an excluded person, and the list is free to search 1Ref 1HHS Office of Inspector General (2026).Exclusions Program.That OIG excludes individuals from federal health programs, that no federal program payment may be made for services an excluded person furnishes, and that the LEIE is free to search — the basis for screening anyone before they touch billing or claims.. A clean check does not certify honesty, but a hit is a disqualifying fact you would otherwise never see.
Build the habit: a reconciliation cadence and the surprise check
Controls decay the moment nobody actually runs them, so put the cadence on a calendar rather than leaving it to memory. A monthly reconciliation you personally review, an annual outside look from your CPA or bookkeeper, and an occasional out-of-cycle spot check of a random week's deposits do more than an elaborate policy nobody follows.
A practical habit many small offices adopt: once a year, have someone other than the usual person run payroll or reconcile the books for a cycle, on purpose, while the usual person is out. It is a common convention, not a legal requirement, and it does two things at once — it surfaces anything the regular process was quietly smoothing over, and it proves the practice is not dependent on one irreplaceable person, which matters for reasons well beyond theft prevention.
Treat the cadence itself as a policy, not a good intention. A reconciliation you meant to do but kept postponing protects nobody; put it on the same calendar you use for licensing renewals and tax deadlines, where a missed date is visible rather than quietly forgotten.
If controls did not catch it in time
Prevention is not the same job as response. If you already suspect theft has occurred, the sequence of who to call first, what to preserve, and how to talk to the employee is a different page than this one — the internal-controls habits above are what you build before that day, not what you reach for on it.
One thing does belong here: if the theft you are trying to prevent also touches how claims were billed — inflated units, services never rendered — a discovery later can trigger a duty to correct through OIG's self-disclosure protocol, which spells out what a voluntary disclosure has to contain 2Ref 2HHS Office of Inspector General (2026).Health Care Fraud Self-Disclosure Protocol.That OIG maintains a self-disclosure protocol for conduct implicating federal fraud laws — relevant when theft also touches how claims were billed.. That overlap between embezzlement and billing fraud is one more reason the controls in this article matter before the fact, not after.
Common questions
Run your practice on Gale
The software is free. Gale earns one flat 3.5% all-in per paid transaction — only on transactions that actually pay. No subscription, no setup fee, no network cut.
Start or manage a practice →References
- 1.HHS Office of Inspector General (2026). Exclusions Program. HHS Office of Inspector General (OIG). link ✓That OIG excludes individuals from federal health programs, that no federal program payment may be made for services an excluded person furnishes, and that the LEIE is free to search — the basis for screening anyone before they touch billing or claims.
- 2.HHS Office of Inspector General (2026). Health Care Fraud Self-Disclosure Protocol. HHS Office of Inspector General (OIG). link ✓That OIG maintains a self-disclosure protocol for conduct implicating federal fraud laws — relevant when theft also touches how claims were billed.
https://www.gale.care/for-providers/hsf-embezzlement-prevention · 2 sources. Competitor details are cited to dated public sources and maintained as they change; figures are estimates, not commitments. Synthetic demonstration.