Revenue Cycle Resource

When the Money Moves

A practical framework for healthcare revenue-cycle professionals to prevent cyber-enabled financial fraud, built on real FBI case experience from Scott Augenbaum.

~85%
of IC3 losses from cyber-enabled fraud
$17.7B
reported losses · 452,868 complaints · 2025
$12.2T
projected global cybercrime cost by 2031
#4
Truth: most incidents could have been prevented

Foundation

The Four Truths

Every prevention strategy built on this framework begins here. Truth Four is the pivot from helplessness to action.

1
Nobody expects to become a victim.

Every victim was surprised. The assumption of safety is exactly what criminals count on. Preparedness is not paranoia. It is the first line of prevention.

2
Once the money is gone, recovery is difficult.

Speed is the criminal's greatest weapon. Once funds move, recovery is rare and slow. The only reliable window is before the transaction completes.

3
The chances of the bad guys going to jail are slim to none.

Most operate overseas, outside U.S. jurisdiction. Arrest is the exception, not the rule. Prevention is not optional. It is the only reliable outcome.

4
Most cybercrime incidents could have been prevented.

Simple steps like a pause, a callback, or a second person stop the majority of fraud before it completes. This is the pivot from helplessness to action.

Complete Framework

The When the Money Moves Framework

Consequence, not suspicion, triggers verification. Five steps that work regardless of how sophisticated the story is.

1
Detect the Change

What is different about this request: identity, channel, destination, timing, or phone number?

2
Measure Consequence

What happens if this request is not real? Money · data · access · patient care · payroll.

3
Create Friction

Slow the action down enough to step outside the request. Even thirty seconds matters.

4
Verify Independently

Use a trusted contact established before the change. Never a number from inside the request.

5
Stop If It Fails

If the change cannot be verified through a trusted channel, it does not move.

Pause

Stop before you act. The criminal shrinks this moment. You expand it.

Separate

Separate the emotion from the decision. Urgency is a manipulation tool.

Verify

Step outside the request. Call a known number. Use a trusted channel.

Confirm

Confirm the change is real before anything consequential moves.


Verification Checklist

Seven Questions Before You Act

Use these when any request could move money, data, access or trust. You do not need to answer "yes" to all seven. The questions help you recognize when to pause.

1
Did something change? Identity, bank account, phone number, timing, channel, contact method or level of urgency.
2
Is something consequential about to move? Money, patient data, payroll records, credentials, vendor access or operational control.
3
Does this request use authority, urgency, trust or fear to compress the decision? Any of these emotions is a warning signal, not proof of fraud, but a reason to pause.
4
Can I verify this change using contact information I trusted before the change arrived? A known number, a vendor file, a relationship that pre-dates this request.
5
Is there a reason given to skip the normal process? Exceptions are the criminal's entry point. Normal friction exists for a reason.
6
Have I confirmed through a channel the requester does not control? Email replies and numbers inside the message are part of the potentially compromised channel.
7
If this request is not real, what is the consequence? This answer determines the level of verification required. Greater consequence means more friction.
Revenue-Cycle Workflow Worksheet

Map Your Consequential Moments

Start with one workflow. Identify where a believable change could redirect something consequential, then decide where verification belongs.

Workflow / Process Consequence Change Trigger Verification Step
Vendor bank account change Critical New routing or account number Call established vendor contact + dual approval before payment
Patient refund request High Change in payment destination Confirm via pre-established patient contact; second approval above threshold
Payroll direct deposit change Critical Employee banking update In-person or known-phone confirmation; 24-hr hold before activation
New vendor setup High New relationship, unknown channel Verify via public contact; W-9 match; leadership sign-off
Payer portal access change High New credentials or admin change IT verification + MFA reset; email to known payer contact
Wire transfer / EFT above threshold Critical Any wire instruction Dual approval + callback to known bank contact before release
Your workflow here

Print this worksheet and bring it to your next team meeting. Ask: where could a believable change enter our workflow?


Case Studies · Revenue Cycle

What Happens When Verification Is Skipped

These cases illustrate how the same framework applies across different revenue-cycle scenarios. The story changes. The prevention principle does not.

Case Study 1: Business Email Compromise
The New CFO and Seven Wires
~$1,000,000 at risk

A controller's email account was compromised. Criminals studied the company's communication patterns, then introduced a believable new executive figure into the relationship. Seven authorized wire transfers followed, each moving through the established approval process.

The controller was authorized. The bank had authorized people involved. The process was followed. Only the destination was wrong.

LessonA valid approver can still authorize a fraudulent transaction. Authorization is not verification.
InterruptionOne known-number callback before any wire would have stepped outside the compromised channel.
Case Study 2: Vendor Fraud
The Replacement Invoice Changed the Destination
$3,500,000 at risk

A legitimate vendor. A real transaction already in process. A replacement invoice arrived with different banking details. The document looked routine and the timing felt plausible. The change redirected a legitimate payment to a criminal account.

LessonMost of the story was true; only the destination had changed. A real invoice can carry false payment instructions.
InterruptionVerify account changes using the established vendor contact from before the change arrived. Never from inside the replacement document.
Case Study 3: Data as the Target
The Payroll Request Looked Internal
Sensitive HR data targeted

The message used executive authority and familiar language. Urgency created a deadline. An employee was prepared to send payroll records to what appeared to be an internal leadership request. The data would have enabled downstream identity and payment fraud.

LessonThe asset is not always money; sometimes it is what unlocks money. Data movement enables downstream loss.
InterruptionSeparate channel to confirm + data minimization policy + second approval for sensitive records before any data leaves.
About Scott Augenbaum

The FBI Agent Who Warned Healthcare in 2016

SA
Scott Augenbaum
Retired FBI Supervisory Special Agent · Author · Speaker

Scott Augenbaum spent over 30 years with the FBI, the last 16 years managing the FBI's cyber squad in Nashville, Tennessee. He was one of the first FBI agents assigned to cybercrime in the late 1990s and retired in 2018 to protect more people from outside than inside.

His book The Secret to CyberSecurity became an Amazon bestseller. He has spoken to thousands of healthcare leaders, financial executives, and revenue-cycle professionals about preventing cyber-enabled fraud through behavioral awareness and practical frameworks, not technology alone.

In 2016, Scott addressed CHIME/AEHIS leadership and warned: "Are things getting better or worse? They're getting worse." The second-best time to act is today.

Book Scott Send Email
Get the Audio Book Free
Coupon code:
SCOTTAUGENBAUM

If your organization is thinking about cyber risk only from a technology standpoint, you're missing where most losses actually occur.

Scott works with organizations to map where money, data, access and trust move, and build verification that people can actually follow.

Work With Scott