Guide

Prevention by design: the controls that make theft visible fast

Summary

No single person should both move money and be the only one who ever checks the record of it. The controls that catch theft early are structural, not about trust: route bank and card statements somewhere the reconciler cannot control, require a second sign-off above a set dollar threshold, restrict who can add a payee or void a claim, and screen anyone touching billing against the federal exclusion list. Apply these from the day you hire, not after something looks wrong.

By Gale Editorial · Updated 2026-07-27. Every figure cited to a dated source. How we write.

Why trust is not a control

A one-person billing setup is not a moral failure waiting to happen — it is a structural gap, and the fix is structural too. internal controls are the habits and permissions that make a wrong number visible to a second set of eyes before it compounds into a pattern. They exist for competent, trusted people, not despite them, because the person best positioned to move money quietly is exactly the person you trust enough to hand it to.

The goal is not surveillance — it is making sure no single person can both initiate a transaction and be the only one who ever checks it. Even in a two-person practice that goal is reachable: you do not need a controller or an audit committee, you need three or four habits, applied consistently, starting the day you hire.

Most of what follows costs nothing beyond a calendar reminder and a moment of friction on payments above a threshold you set yourself. The habits work precisely because they are boring and repeatable, not because they are elaborate — an elaborate policy nobody actually follows protects less than a simple one that runs every month without fail.

The one review that catches the most: someone besides the money-handler sees the statement

If you adopt exactly one control, make it this one: bank and credit-card statements arrive somewhere the person who reconciles the books does not control, and a second person — even if that second person is you, reviewing for twenty minutes a month — actually looks at them line by line before they are filed. This single habit is the one most embezzlement schemes are built to survive undetected, because most rely on nobody else ever looking.

Route statements to an email or mailing address only the owner-clinician can access, not the office manager's inbox. Look for the boring signs: round-number transfers, a payee you don't recognize, a vendor invoice that crept up without a matching change in service, or timing that clusters around when the same person is scheduled to be out. None of these prove anything on their own — the review's job is to ask a question, not convict.

Separate who requests a payment from who approves it

The structural weakness in a one-person office is that the same hands write the check, record it, and reconcile it — so build in a threshold above which a second person has to say yes before money moves, even if that second person is you, signing off from your phone. A common convention is to set the threshold low enough to catch anything unusual without turning every routine bill into a bottleneck; a few hundred dollars is a typical starting point for a micro practice.

Apply the same split-role logic in a few other places:

  • Vendor and payee changes — a new bank account for an existing vendor, or a brand-new payee, gets a verbal confirmation from a known contact before the first payment goes out.
  • Payroll changes — a change to anyone's direct-deposit account routes through you, not just the person who runs payroll.
  • Petty cash and card limits — set a hard ceiling low enough that going over it is itself the signal something needs a look.

Write the threshold and the approval step into the same handbook that carries your other policies, not just into a private habit only you remember. A documented threshold is something a new hire is told about on day one rather than discovered by accident, and it is evidence the control was real and consistently applied if that ever matters later.

Lock down who can add a payee, void a claim, or issue a refund

Most of the software a practice already runs — the EHR, the billing system, the bank's online portal — has permission levels, and the default is usually more access than a front-desk or billing role actually needs. Restrict who can add a new payee, void or resubmit a claim, issue a patient refund, or change a bank account on file to the smallest set of people the job requires, and review that permission list at least once a year rather than assuming it is still right.

Before anyone touches billing or claims, check them against the federal exclusion list the same way you would before credentialing a clinician — no federal program payment may be made for items or services furnished by an excluded person, and the list is free to search 1. A clean check does not certify honesty, but a hit is a disqualifying fact you would otherwise never see.

Build the habit: a reconciliation cadence and the surprise check

Controls decay the moment nobody actually runs them, so put the cadence on a calendar rather than leaving it to memory. A monthly reconciliation you personally review, an annual outside look from your CPA or bookkeeper, and an occasional out-of-cycle spot check of a random week's deposits do more than an elaborate policy nobody follows.

A practical habit many small offices adopt: once a year, have someone other than the usual person run payroll or reconcile the books for a cycle, on purpose, while the usual person is out. It is a common convention, not a legal requirement, and it does two things at once — it surfaces anything the regular process was quietly smoothing over, and it proves the practice is not dependent on one irreplaceable person, which matters for reasons well beyond theft prevention.

Treat the cadence itself as a policy, not a good intention. A reconciliation you meant to do but kept postponing protects nobody; put it on the same calendar you use for licensing renewals and tax deadlines, where a missed date is visible rather than quietly forgotten.

If controls did not catch it in time

Prevention is not the same job as response. If you already suspect theft has occurred, the sequence of who to call first, what to preserve, and how to talk to the employee is a different page than this one — the internal-controls habits above are what you build before that day, not what you reach for on it.

One thing does belong here: if the theft you are trying to prevent also touches how claims were billed — inflated units, services never rendered — a discovery later can trigger a duty to correct through OIG's self-disclosure protocol, which spells out what a voluntary disclosure has to contain 2. That overlap between embezzlement and billing fraud is one more reason the controls in this article matter before the fact, not after.

Common questions

Yes, in the sense that matters: the second sign-off can be you. The point is that the person entering and recording a payment is never the only person who ever looks at whether it should have happened. Set a dollar threshold above which you personally confirm before money moves, and keep it low enough to actually catch something unusual.

Route the bank and credit-card statements somewhere only you can see them, and actually read them monthly. It costs nothing beyond twenty minutes, and it is the single control most theft schemes depend on nobody doing. Everything else in this article builds on that habit existing first.

At minimum, check them against the federal exclusion list before they touch claims or billing — the same check credentialing already requires for clinicians. It will not catch every risk, but an exclusion hit is a disqualifying fact you would have no other way to see, and it takes minutes to run.

Monthly, at minimum, and on a calendar reminder rather than whenever you remember. A monthly review by you or a second set of eyes, plus an annual outside look from your CPA or bookkeeper, catches most patterns early enough to matter without becoming a second job.

Frame it as protecting them, not doubting them — a clean, structured process is also what proves an honest employee never touched anything improperly if a number is ever questioned. Controls applied evenly, before anyone is a suspect, read very differently than controls introduced after a specific person is.

Run your practice on Gale

The software is free. Gale earns one flat 3.5% all-in per paid transaction — only on transactions that actually pay. No subscription, no setup fee, no network cut.

Start or manage a practice →

References

  1. 1.HHS Office of Inspector General (2026). Exclusions Program. HHS Office of Inspector General (OIG). linkThat OIG excludes individuals from federal health programs, that no federal program payment may be made for services an excluded person furnishes, and that the LEIE is free to search — the basis for screening anyone before they touch billing or claims.
  2. 2.HHS Office of Inspector General (2026). Health Care Fraud Self-Disclosure Protocol. HHS Office of Inspector General (OIG). linkThat OIG maintains a self-disclosure protocol for conduct implicating federal fraud laws — relevant when theft also touches how claims were billed.

https://www.gale.care/for-providers/hsf-embezzlement-prevention · 2 sources. Competitor details are cited to dated public sources and maintained as they change; figures are estimates, not commitments. Synthetic demonstration.

Findability, by specialty

How practices like yours get found in local search and AI answers — the honest playbook, per specialty.

SEO for private practices · SEO for AI search / answer engines (all verticals)