What controls does a small practice need when one person may handle multiple financial duties?
A Physician’s Guide to Internal Controls and Fraud Prevention
Design controls around the practice’s highest-risk transactions and compensate when perfect separation is impossible. Separate or independently review authorization, custody, recording, reconciliation, and system administration for cash, payments, payroll, refunds, write-offs, vendor changes, banking, cards, claims, and owner transactions. Use least-privilege access, documented approvals, source-to-bank reconciliations, exception reports, mandatory review, protected reporting channels, and prompt corrective action.
Executive summary · approximately two minutes
A small team needs visible compensating controls—not trust as a control.
Internal control is a process used to provide reasonable—not absolute—assurance that operations, reporting, and compliance objectives are achieved. Begin with risk: identify how money, records, access, claims, payroll, refunds, vendors, and owner transactions could be misstated, misused, concealed, or disrupted. Then assign preventive, detective, and corrective controls proportionate to impact and feasibility.
Where one person must perform multiple steps, move independent evidence to the physician owner or another qualified reviewer. Examples include bank-delivered statements, positive-pay or bank alerts where available, vendor-change verification, dual approval, payroll change reports, user-access reviews, posting-to-deposit tie-outs, adjustment and refund reports, and timely reconciliations. Document exceptions and investigate them without assuming that a discrepancy proves fraud.
- Reviewed 2026-07-30
- High financial, compliance, privacy, and continuity risk
- Annual and after staffing, banking, system, vendor, ownership, incident, or transaction-volume change
What is it?
Internal Controls and Fraud Prevention is a governed decision system.
Keep the core concepts separate so the practice can measure the right condition, retain the right evidence, and assign the right owner.
- Preventive control
- A policy, system, approval, access restriction, or workflow designed to stop or reduce an error or unauthorized act before completion.
- Detective control
- A reconciliation, exception report, review, confirmation, alert, or audit designed to identify a problem after or as it occurs.
- Compensating control
- An alternative review or safeguard used when the ideal control—often full segregation of duties—is not practical.
- Reasonable assurance
- A risk-based level of confidence recognizing that controls have limitations, costs, judgment, collusion, override, and change risk.
Why should I care?
Concentrated access can turn one error—or one bad act—into a hidden loss.
Controls protect the physician, the team, patients, payers, vendors, and reliable reporting while preserving evidence for investigation and correction.
Governance and tone
Set written authority, ethical expectations, reporting routes, nonretaliation, conflict disclosure, and owner oversight.
Transaction separation
Divide authorization, custody, execution, recording, reconciliation, and administration where feasible.
Access control
Use unique accounts, least privilege, multifactor authentication, prompt changes, logs, and periodic access review.
Reconciliation
Tie EHR or PM activity, remittances, merchant and lockbox deposits, bank, payroll, cards, refunds, and accounting.
Exception monitoring
Review vendor and bank changes, manual checks, refunds, credits, write-offs, voids, adjustments, overtime, and unusual access.
Response and learning
Preserve evidence, contain risk, investigate fairly, obtain counsel, correct records, report when required, and improve controls.
Show me
Build a small-practice control matrix.
For each risk, name the transaction population, preventive control, detective evidence, reviewer, cadence, and escalation.
| Risk area | Minimum control design | Compensating review | Escalate when |
|---|---|---|---|
| Banking and payments | Approved vendor setup, verified changes, role limits, dual approval where appropriate | Owner receives bank alerts and reviews statement and exceptions | New payee, bank change, unusual transfer, or control override |
| Payroll | Authorized employee and pay changes, separate payroll access, documented submission | Owner reviews change and variance reports before funding | Ghost employee, unexplained rate, bank, overtime, or bonus change |
| Collections and refunds | Controlled posting, adjustment, refund, and deposit roles | Independent remit-to-post, deposit-to-bank, and credit review | Posting, deposit, refund, or adjustment does not reconcile |
| Cards and purchasing | Named cards, limits, approved categories, receipts, and business purpose | Monthly statement review by someone without card custody | Missing support, split purchase, personal item, or repeat exception |
| Systems and vendors | Unique accounts, least privilege, MFA, approved change and termination process | Periodic access, administrator, vendor, and audit-log review | Dormant access, shared login, unexplained export, or late offboarding |
Put me in the chair
The office manager can create vendors, release payments, record expenses, and reconcile the bank.
The practice has four employees. The physician reviews the monthly P&L but does not receive bank statements or transaction alerts directly.
- Vendor setupOffice manager
- Payment releaseOffice manager
- BookkeepingOffice manager
- Bank reconciliationOffice manager
- Owner source dataP&L only
- Remove incompatible authority. Move vendor approval, bank changes, or payment release to the owner or another qualified independent role.
- Create independent evidence. Send bank statements and alerts directly to the owner and require reconciliations with exception support.
- Review high-risk populations. Examine new vendors, changed bank details, manual payments, refunds, write-offs, cards, payroll changes, and access.
The current design allows one person to complete and conceal an unauthorized or erroneous transaction. The practice should restructure approval and banking access, implement independent statement and exception review, document authority, and conduct an appropriately scoped historical review with professional support.
What would change the answerThe exact design may change with bank capabilities, staffing, systems, and transaction volume, but independent evidence and review must remain when duties cannot be fully separated.
Three-question decision exercise
Can you defend the operating decision?
Select the strongest answer. Feedback teaches the decision method; it is not individualized professional advice.
Question 1 of 3
What is the core segregation principle?
Question 2 of 3
What is a compensating control for a small team?
Question 3 of 3
What does a control exception prove?
You defended all three decisions. Carry the same evidence discipline into the written decision record.
12-question decision checklist
Expand each question and retain the evidence.
The checklist supports governance and issue spotting. It does not establish legal, accounting, payer, clinical, privacy, security, employment, or regulatory compliance.
01Is authority documented?
02Are incompatible duties mapped?
03Does the owner receive bank evidence directly?
04Are vendor changes independently verified?
05Are payments controlled?
06Are cards reviewed independently?
07Are payroll changes approved?
08Do collections reconcile end to end?
09Are credits, refunds, and write-offs reviewed?
10Is system access governed?
11Is there a protected reporting route?
12Are controls monitored and revised?
Defend the decision
Retain evidence that the control operated—not merely that a policy exists.
A defensible system shows who performed and reviewed each control, what exceptions appeared, and how the practice responded.
Risk-control matrix
Objective, risk, transaction population, control, evidence, owner, reviewer, cadence, and escalation.
Access and authority register
Users, roles, limits, administrators, banking rights, approvals, effective dates, and terminations.
Reconciliation and review file
Source reports, bank evidence, reviewer sign-off, exceptions, support, and resolution.
Incident and corrective record
Allegation or exception, preservation, triage, investigation, advice, action, reporting, and control improvement.
Common mistakes and hidden risks
These patterns weaken an otherwise reasonable decision.
Use the risk list as a structured review prompt; investigate facts before drawing conclusions.
Trust as control
Trust matters, but it cannot detect error, coercion, account compromise, or concealed activity.
One-person transaction
The same person initiates, approves, records, and reconciles activity.
P&L-only oversight
Summary reports can hide payees, timing, transfers, refunds, and unsupported entries.
Shared credentials
Accountability and access control disappear when identities are not unique.
Vendor-change fraud
Payment details are changed without independent verification through a known channel.
Unreviewed adjustments
Refunds, credits, write-offs, voids, and manual entries can conceal loss or error.
Late offboarding
Former staff or vendors retain access, cards, tokens, data, or authority.
Control never monitored
A safeguard fails silently after staffing, system, banking, or volume changes.
The MedCBO perspective
“Small practices do not need bureaucracy. They need independent evidence at the exact points where one person could make and hide a material mistake.”
The strongest control environment is practical, respectful, and visible. It protects employees from unsupported suspicion, gives the owner reliable information, and reduces dependence on any one person by documenting authority, access, reconciliations, exceptions, and continuity.
When a small team concentrates financial and system authority
Talk through your practice plans.
If you are mapping banking, payroll, refund, purchasing, revenue-cycle, access, or owner-review controls, a MedCBO discovery conversation can help identify operational gaps to align with your accountant, legal counsel, compliance, cybersecurity, banking, insurance, and HR advisors. The discussion is exploratory and focused on alignment.
Companion resources
Continue the decision with the right supporting tools.
Frequently asked questions
Questions physicians ask about internal controls and fraud prevention.
Can a small practice have effective controls without separate departments?
Should the bookkeeper reconcile the bank?
What transactions deserve the most review?
Does a discrepancy mean fraud?
How often should access be reviewed?
What should happen after suspected fraud?
Sources and further reading
Evidence used in this guide.
Current primary and authoritative sources support the national concepts in this guide. Practice-, payer-, contract-, state-, and fact-specific requirements require separate review.
- U.S. Government Accountability Office (accessed July 30, 2026). Standards for Internal Control in the Federal Government View authoritative source. Provides the current Green Book framework for control environment, risk assessment, control activities, information, communication, and monitoring.
- HHS Office of Inspector General (accessed July 30, 2026). General Compliance Program Guidance View authoritative source. Describes compliance infrastructure, risk assessment, training, reporting, auditing, monitoring, and corrective action.
- Centers for Medicare & Medicaid Services (accessed July 30, 2026). Medicare Overpayments Fact Sheet View authoritative source. Summarizes Medicare overpayment identification, reporting, and return responsibilities.
- Internal Revenue Service (accessed July 30, 2026). What kind of records should I keep? View authoritative source. Describes business books and supporting records for income, expenses, assets, payroll, and transactions.
- National Institute of Standards and Technology (accessed July 30, 2026). CSF 2.0 Quick-Start Guide for Cybersecurity Supply Chain Risk Management View authoritative source. Provides a current framework for identifying, assessing, managing, and monitoring cybersecurity supply-chain risk.
About the author
Christopher D. Poteet, DBA, FACHE
Christopher Poteet is the founder and Chief Executive Officer of MedCBO, a healthcare executive, Fellow of the American College of Healthcare Executives, and adjunct professor teaching graduate business and healthcare studies. His teaching approach connects business concepts to the decisions physicians must make in practice—without assuming prior business education and without speaking down to highly trained professionals.
This guide is for general educational, governance, and fraud-risk planning purposes. It is not legal, employment, accounting, audit, forensic, tax, banking, insurance, cybersecurity, privacy, HIPAA, payer, billing, fraud-and-abuse, law-enforcement, or patient-specific advice. Internal controls provide reasonable, not absolute, assurance and must be tailored to the entity, systems, people, transactions, law, contracts, and risk. An exception does not establish fraud. Preserve evidence and obtain qualified legal, accounting, forensic, employment, compliance, cybersecurity, insurance, banking, payer, and other appropriate guidance before investigating, accusing, disciplining, reporting, or recovering funds.