A practical framework for healthcare revenue-cycle professionals to prevent cyber-enabled financial fraud, built on real FBI case experience from Scott Augenbaum.
Every prevention strategy built on this framework begins here. Truth Four is the pivot from helplessness to action.
Every victim was surprised. The assumption of safety is exactly what criminals count on. Preparedness is not paranoia. It is the first line of prevention.
Speed is the criminal's greatest weapon. Once funds move, recovery is rare and slow. The only reliable window is before the transaction completes.
Most operate overseas, outside U.S. jurisdiction. Arrest is the exception, not the rule. Prevention is not optional. It is the only reliable outcome.
Simple steps like a pause, a callback, or a second person stop the majority of fraud before it completes. This is the pivot from helplessness to action.
Consequence, not suspicion, triggers verification. Five steps that work regardless of how sophisticated the story is.
What is different about this request: identity, channel, destination, timing, or phone number?
What happens if this request is not real? Money · data · access · patient care · payroll.
Slow the action down enough to step outside the request. Even thirty seconds matters.
Use a trusted contact established before the change. Never a number from inside the request.
If the change cannot be verified through a trusted channel, it does not move.
Stop before you act. The criminal shrinks this moment. You expand it.
Separate the emotion from the decision. Urgency is a manipulation tool.
Step outside the request. Call a known number. Use a trusted channel.
Confirm the change is real before anything consequential moves.
Use these when any request could move money, data, access or trust. You do not need to answer "yes" to all seven. The questions help you recognize when to pause.
Start with one workflow. Identify where a believable change could redirect something consequential, then decide where verification belongs.
| Workflow / Process | Consequence | Change Trigger | Verification Step |
|---|---|---|---|
| Vendor bank account change | Critical | New routing or account number | Call established vendor contact + dual approval before payment |
| Patient refund request | High | Change in payment destination | Confirm via pre-established patient contact; second approval above threshold |
| Payroll direct deposit change | Critical | Employee banking update | In-person or known-phone confirmation; 24-hr hold before activation |
| New vendor setup | High | New relationship, unknown channel | Verify via public contact; W-9 match; leadership sign-off |
| Payer portal access change | High | New credentials or admin change | IT verification + MFA reset; email to known payer contact |
| Wire transfer / EFT above threshold | Critical | Any wire instruction | Dual approval + callback to known bank contact before release |
| Your workflow here |
Print this worksheet and bring it to your next team meeting. Ask: where could a believable change enter our workflow?
These cases illustrate how the same framework applies across different revenue-cycle scenarios. The story changes. The prevention principle does not.
A controller's email account was compromised. Criminals studied the company's communication patterns, then introduced a believable new executive figure into the relationship. Seven authorized wire transfers followed, each moving through the established approval process.
The controller was authorized. The bank had authorized people involved. The process was followed. Only the destination was wrong.
A legitimate vendor. A real transaction already in process. A replacement invoice arrived with different banking details. The document looked routine and the timing felt plausible. The change redirected a legitimate payment to a criminal account.
The message used executive authority and familiar language. Urgency created a deadline. An employee was prepared to send payroll records to what appeared to be an internal leadership request. The data would have enabled downstream identity and payment fraud.
Scott Augenbaum spent over 30 years with the FBI, the last 16 years managing the FBI's cyber squad in Nashville, Tennessee. He was one of the first FBI agents assigned to cybercrime in the late 1990s and retired in 2018 to protect more people from outside than inside.
His book The Secret to CyberSecurity became an Amazon bestseller. He has spoken to thousands of healthcare leaders, financial executives, and revenue-cycle professionals about preventing cyber-enabled fraud through behavioral awareness and practical frameworks, not technology alone.
In 2016, Scott addressed CHIME/AEHIS leadership and warned: "Are things getting better or worse? They're getting worse." The second-best time to act is today.