MMedCBO Practice Controls Guide

What controls does a small practice need when one person may handle multiple financial duties?

A Physician’s Guide to Internal Controls and Fraud Prevention

Design controls around the practice’s highest-risk transactions and compensate when perfect separation is impossible. Separate or independently review authorization, custody, recording, reconciliation, and system administration for cash, payments, payroll, refunds, write-offs, vendor changes, banking, cards, claims, and owner transactions. Use least-privilege access, documented approvals, source-to-bank reconciliations, exception reports, mandatory review, protected reporting channels, and prompt corrective action.

Executive summary · approximately two minutes

A small team needs visible compensating controls—not trust as a control.

Internal control is a process used to provide reasonable—not absolute—assurance that operations, reporting, and compliance objectives are achieved. Begin with risk: identify how money, records, access, claims, payroll, refunds, vendors, and owner transactions could be misstated, misused, concealed, or disrupted. Then assign preventive, detective, and corrective controls proportionate to impact and feasibility.

Where one person must perform multiple steps, move independent evidence to the physician owner or another qualified reviewer. Examples include bank-delivered statements, positive-pay or bank alerts where available, vendor-change verification, dual approval, payroll change reports, user-access reviews, posting-to-deposit tie-outs, adjustment and refund reports, and timely reconciliations. Document exceptions and investigate them without assuming that a discrepancy proves fraud.

Decision rule: No person should be able to initiate, approve, execute, record, and reconcile a high-risk transaction without independent evidence or review.
  • Reviewed 2026-07-30
  • High financial, compliance, privacy, and continuity risk
  • Annual and after staffing, banking, system, vendor, ownership, incident, or transaction-volume change

What is it?

Internal Controls and Fraud Prevention is a governed decision system.

Keep the core concepts separate so the practice can measure the right condition, retain the right evidence, and assign the right owner.

Preventive control
A policy, system, approval, access restriction, or workflow designed to stop or reduce an error or unauthorized act before completion.
Detective control
A reconciliation, exception report, review, confirmation, alert, or audit designed to identify a problem after or as it occurs.
Compensating control
An alternative review or safeguard used when the ideal control—often full segregation of duties—is not practical.
Reasonable assurance
A risk-based level of confidence recognizing that controls have limitations, costs, judgment, collusion, override, and change risk.

Why should I care?

Concentrated access can turn one error—or one bad act—into a hidden loss.

Controls protect the physician, the team, patients, payers, vendors, and reliable reporting while preserving evidence for investigation and correction.

Governance and tone

Set written authority, ethical expectations, reporting routes, nonretaliation, conflict disclosure, and owner oversight.

Transaction separation

Divide authorization, custody, execution, recording, reconciliation, and administration where feasible.

Access control

Use unique accounts, least privilege, multifactor authentication, prompt changes, logs, and periodic access review.

Reconciliation

Tie EHR or PM activity, remittances, merchant and lockbox deposits, bank, payroll, cards, refunds, and accounting.

Exception monitoring

Review vendor and bank changes, manual checks, refunds, credits, write-offs, voids, adjustments, overtime, and unusual access.

Response and learning

Preserve evidence, contain risk, investigate fairly, obtain counsel, correct records, report when required, and improve controls.

Show me

Build a small-practice control matrix.

For each risk, name the transaction population, preventive control, detective evidence, reviewer, cadence, and escalation.

Risk areaMinimum control designCompensating reviewEscalate when
Banking and paymentsApproved vendor setup, verified changes, role limits, dual approval where appropriateOwner receives bank alerts and reviews statement and exceptionsNew payee, bank change, unusual transfer, or control override
PayrollAuthorized employee and pay changes, separate payroll access, documented submissionOwner reviews change and variance reports before fundingGhost employee, unexplained rate, bank, overtime, or bonus change
Collections and refundsControlled posting, adjustment, refund, and deposit rolesIndependent remit-to-post, deposit-to-bank, and credit reviewPosting, deposit, refund, or adjustment does not reconcile
Cards and purchasingNamed cards, limits, approved categories, receipts, and business purposeMonthly statement review by someone without card custodyMissing support, split purchase, personal item, or repeat exception
Systems and vendorsUnique accounts, least privilege, MFA, approved change and termination processPeriodic access, administrator, vendor, and audit-log reviewDormant access, shared login, unexplained export, or late offboarding
Investigation limitation: A control exception is a signal for documented review—not proof of fraud. Preserve evidence, protect confidentiality and nonretaliation, and obtain qualified legal, employment, compliance, accounting, insurance, cybersecurity, and law-enforcement guidance as appropriate.

Put me in the chair

The office manager can create vendors, release payments, record expenses, and reconcile the bank.

The practice has four employees. The physician reviews the monthly P&L but does not receive bank statements or transaction alerts directly.

Known factsWhat is actually supported
  • Vendor setupOffice manager
  • Payment releaseOffice manager
  • BookkeepingOffice manager
  • Bank reconciliationOffice manager
  • Owner source dataP&L only
Decision workWhat must be resolved
  • Remove incompatible authority. Move vendor approval, bank changes, or payment release to the owner or another qualified independent role.
  • Create independent evidence. Send bank statements and alerts directly to the owner and require reconciliations with exception support.
  • Review high-risk populations. Examine new vendors, changed bank details, manual payments, refunds, write-offs, cards, payroll changes, and access.
Defensible conclusionAdd direct owner oversight immediately.

The current design allows one person to complete and conceal an unauthorized or erroneous transaction. The practice should restructure approval and banking access, implement independent statement and exception review, document authority, and conduct an appropriately scoped historical review with professional support.

What would change the answerThe exact design may change with bank capabilities, staffing, systems, and transaction volume, but independent evidence and review must remain when duties cannot be fully separated.

Three-question decision exercise

Can you defend the operating decision?

Select the strongest answer. Feedback teaches the decision method; it is not individualized professional advice.

Teaching progress0/3 decisions defended

Question 1 of 3

What is the core segregation principle?

Question 2 of 3

What is a compensating control for a small team?

Question 3 of 3

What does a control exception prove?

You defended all three decisions. Carry the same evidence discipline into the written decision record.

12-question decision checklist

Expand each question and retain the evidence.

The checklist supports governance and issue spotting. It does not establish legal, accounting, payer, clinical, privacy, security, employment, or regulatory compliance.

01Is authority documented?
Evidence to retain: Banking, vendors, purchasing, cards, payroll, refunds, write-offs, contracts, and system administration.
02Are incompatible duties mapped?
Evidence to retain: Initiation, approval, execution, custody, recording, reconciliation, and review by process.
03Does the owner receive bank evidence directly?
Evidence to retain: Statements, alerts, check images, transfers, new payees, and changed bank details.
04Are vendor changes independently verified?
Evidence to retain: Known contact, callback method, approval, supporting contract, and audit trail.
05Are payments controlled?
Evidence to retain: Limits, dual approval where appropriate, supporting invoice, business purpose, and duplicate check.
06Are cards reviewed independently?
Evidence to retain: Named holder, limit, receipt, business purpose, statement review, and exception follow-up.
07Are payroll changes approved?
Evidence to retain: Employee list, pay, bank, bonus, overtime, deduction, termination, and funding review.
08Do collections reconcile end to end?
Evidence to retain: Remittance, posting, lockbox or merchant, deposit, bank, refund, adjustment, and ledger.
09Are credits, refunds, and write-offs reviewed?
Evidence to retain: Population report, supporting reason, authority, patient or payer disposition, and trend.
10Is system access governed?
Evidence to retain: Unique ID, least privilege, MFA, administrator inventory, log review, and timely offboarding.
11Is there a protected reporting route?
Evidence to retain: Multiple reporting channels, nonretaliation, confidentiality, triage, and investigation protocol.
12Are controls monitored and revised?
Evidence to retain: Exception trends, incidents, staffing and system changes, control testing, owner review, and corrective action.

Defend the decision

Retain evidence that the control operated—not merely that a policy exists.

A defensible system shows who performed and reviewed each control, what exceptions appeared, and how the practice responded.

Risk-control matrix

Objective, risk, transaction population, control, evidence, owner, reviewer, cadence, and escalation.

Access and authority register

Users, roles, limits, administrators, banking rights, approvals, effective dates, and terminations.

Reconciliation and review file

Source reports, bank evidence, reviewer sign-off, exceptions, support, and resolution.

Incident and corrective record

Allegation or exception, preservation, triage, investigation, advice, action, reporting, and control improvement.

Common mistakes and hidden risks

These patterns weaken an otherwise reasonable decision.

Use the risk list as a structured review prompt; investigate facts before drawing conclusions.

01

Trust as control

Trust matters, but it cannot detect error, coercion, account compromise, or concealed activity.

02

One-person transaction

The same person initiates, approves, records, and reconciles activity.

03

P&L-only oversight

Summary reports can hide payees, timing, transfers, refunds, and unsupported entries.

04

Shared credentials

Accountability and access control disappear when identities are not unique.

05

Vendor-change fraud

Payment details are changed without independent verification through a known channel.

06

Unreviewed adjustments

Refunds, credits, write-offs, voids, and manual entries can conceal loss or error.

07

Late offboarding

Former staff or vendors retain access, cards, tokens, data, or authority.

08

Control never monitored

A safeguard fails silently after staffing, system, banking, or volume changes.

The MedCBO perspective

“Small practices do not need bureaucracy. They need independent evidence at the exact points where one person could make and hide a material mistake.”

The strongest control environment is practical, respectful, and visible. It protects employees from unsupported suspicion, gives the owner reliable information, and reduces dependence on any one person by documenting authority, access, reconciliations, exceptions, and continuity.

When a small team concentrates financial and system authority

Talk through your practice plans.

If you are mapping banking, payroll, refund, purchasing, revenue-cycle, access, or owner-review controls, a MedCBO discovery conversation can help identify operational gaps to align with your accountant, legal counsel, compliance, cybersecurity, banking, insurance, and HR advisors. The discussion is exploratory and focused on alignment.

Schedule a Discovery Call →

Companion resources

Continue the decision with the right supporting tools.

Frequently asked questions

Questions physicians ask about internal controls and fraud prevention.

Can a small practice have effective controls without separate departments?
Yes. Separate the highest-risk duties where feasible and use direct owner or qualified independent review, bank-delivered evidence, limits, alerts, reconciliations, and exception reports.
Should the bookkeeper reconcile the bank?
A preparer may perform the reconciliation, but someone independent of incompatible transaction authority should receive bank evidence directly and review the reconciliation and exceptions.
What transactions deserve the most review?
Prioritize by risk and impact, including bank and vendor changes, payments, payroll changes, refunds, credits, write-offs, cards, owner activity, manual entries, exports, and access changes.
Does a discrepancy mean fraud?
No. It may reflect timing, error, system mapping, misunderstanding, or misconduct. Preserve evidence and conduct fair, confidential, appropriately advised review.
How often should access be reviewed?
Use a cadence based on risk and review promptly after hires, terminations, role or vendor changes, incidents, system changes, and elevated access grants.
What should happen after suspected fraud?
Protect patients and operations, preserve evidence, restrict access proportionately, avoid premature conclusions, notify appropriate leadership, and obtain legal, accounting, employment, insurance, cybersecurity, payer, and law-enforcement guidance as applicable.

Sources and further reading

Evidence used in this guide.

Current primary and authoritative sources support the national concepts in this guide. Practice-, payer-, contract-, state-, and fact-specific requirements require separate review.

  1. U.S. Government Accountability Office (accessed July 30, 2026). Standards for Internal Control in the Federal Government View authoritative source. Provides the current Green Book framework for control environment, risk assessment, control activities, information, communication, and monitoring.
  2. HHS Office of Inspector General (accessed July 30, 2026). General Compliance Program Guidance View authoritative source. Describes compliance infrastructure, risk assessment, training, reporting, auditing, monitoring, and corrective action.
  3. Centers for Medicare & Medicaid Services (accessed July 30, 2026). Medicare Overpayments Fact Sheet View authoritative source. Summarizes Medicare overpayment identification, reporting, and return responsibilities.
  4. Internal Revenue Service (accessed July 30, 2026). What kind of records should I keep? View authoritative source. Describes business books and supporting records for income, expenses, assets, payroll, and transactions.
  5. National Institute of Standards and Technology (accessed July 30, 2026). CSF 2.0 Quick-Start Guide for Cybersecurity Supply Chain Risk Management View authoritative source. Provides a current framework for identifying, assessing, managing, and monitoring cybersecurity supply-chain risk.

About the author

Christopher D. Poteet, DBA, FACHE

Christopher Poteet is the founder and Chief Executive Officer of MedCBO, a healthcare executive, Fellow of the American College of Healthcare Executives, and adjunct professor teaching graduate business and healthcare studies. His teaching approach connects business concepts to the decisions physicians must make in practice—without assuming prior business education and without speaking down to highly trained professionals.

This guide is for general educational, governance, and fraud-risk planning purposes. It is not legal, employment, accounting, audit, forensic, tax, banking, insurance, cybersecurity, privacy, HIPAA, payer, billing, fraud-and-abuse, law-enforcement, or patient-specific advice. Internal controls provide reasonable, not absolute, assurance and must be tailored to the entity, systems, people, transactions, law, contracts, and risk. An exception does not establish fraud. Preserve evidence and obtain qualified legal, accounting, forensic, employment, compliance, cybersecurity, insurance, banking, payer, and other appropriate guidance before investigating, accusing, disciplining, reporting, or recovering funds.