Skip to main content
NEC and Netcracker Complete Acquisition of CSG Systems. The integration of CSG with Netcracker creates a more comprehensive and unified digital platform.Learn More
Healthcare EFT Fraud: How to Verify Payment-Instruction Changes
EFT Fraud prevention

Healthcare EFT Fraud: How to Verify Payment-Instruction Changes

CSG Forte Team
CSG Forte Team
Sep 07, 2026

Key takeaways 

  • HHS OIG has described schemes in which individuals impersonated providers and submitted fraudulent EFT authorization requests—or used other methods—to divert federal and state payments intended for providers.  

  • In OIG’s survey, about two-thirds of the Medicare and Medicaid payors that responded said they were aware of being targeted by EFT-fraud schemes, and some reported frequent or recurring activity—but the evaluation did not measure industry-wide prevalence or control effectiveness.  

  • A simple, five-step workflow—treating every change as a controlled financial change, validating the requestor independently, confirming through trusted channels, enforcing separation of duties, and monitoring the first payment—can make healthcare EFT changes more repeatable, auditable, and resilient to fraud

Why healthcare EFT-change fraud is back in focus 

Healthcare payers and provider finance teams rely on electronic funds transfer (EFT) to move large volumes of reimbursement dollars quickly. That same speed can be exploited when criminals try to redirect payments by submitting fraudulent “change my bank account” requests. 

In a February 2025 evaluation, the U.S. Department of Health and Human Services Office of Inspector General (HHS OIG) described schemes in which individuals impersonated hospital providers and submitted fraudulent EFT authorization requests—or used other methods—to divert federal and state payments that were intended for providers.  

OIG surveyed entities that process Medicare and Medicaid payments and reported that about two-thirds of respondents were aware of being targeted by EFT-fraud schemes, with some characterizing the activity as frequent or recurring. This is an important signal—but it is not evidence that every healthcare organization has been targeted, and it should not be treated as a prevalence rate for healthcare EFT fraud overall. 

OIG’s work also was not designed to test whether any reported controls were effective, compliant with federal regulations, or aligned with expert-group best practices. Instead, it highlights a practical point for operations leaders: payment-instruction changes deserve to be treated as high-risk financial changes, not routine profile updates. 

This article translates those findings into a neutral, five-step workflow you can adapt for verifying provider payment-instruction changes, plus a documentation checklist and limitations note to keep your internal materials aligned with what OIG actually reported. 

What “healthcare EFT-change fraud” looks like (at a high level) 

The schemes OIG describes center on a familiar operational scenario: 

  • Someone purports to be a provider or provider representative. 

  • They submit an EFT authorization or payment-instruction change request. 

  • If the change is accepted without strong verification, future payments can be diverted to an account controlled by the fraudster instead of to the provider. 

In the report, OIG notes that these schemes used fraudulent EFT authorization requests and other methods to divert federal and state payments. The risk is not only the fraudulent intent but the opportunity created when routine changes aren’t handled as controlled financial events. 

Because providing attacker playbooks can be harmful, this article stays focused on defensive workflow design, not on detailed evasion tactics. 

A 5-step workflow to verify provider payment-instruction changes 

This workflow is editorial risk-management guidance, not an OIG mandate and not legal or regulatory advice. Any organization should align it with its own policies, legal guidance, and regulatory obligations. 

No single control—whether verified communication channels, knowledge-based methods, authentication, or transaction monitoring—guarantees that EFT-change fraud will be stopped. The goal is layered assurance. 

Step 1: Treat every payment-instruction change as a controlled financial change 

Reframing is the first control. Classify EFT destination updates—such as new bank account details, changes to payee or remit-to information tied to payments, or changes in how remittance data is routed—as controlled financial changes, not routine “admin.” 

Operationally, that can mean: 

  • Routing all payment-instruction changes through a defined intake path (for example, a secure provider portal, ticketing workflow, or specific queue). 

  • Applying standard required fields, such as: 

  • Provider identifiers and tax IDs 

  • Request type and reason 

  • Requested effective date 

  • Requester identity and role 

  • Supporting documentation (such as a voided check or bank letter, when appropriate to your policies) 

  • Assigning a risk level (for example, based on expected payment volume, recency of provider onboarding, or unusual change patterns) to determine how strict verification must be. 

In OIG’s evaluation, surveyed payors most frequently reported using verified communication channels or knowledge-based methods to confirm EFT changes. Those methods are much easier to apply consistently when every change follows a controlled workflow. 

Step 2: Validate the requestor independently using maintained records 

Before confirming any change, validate who is asking and whether they’re authorized to do so. 

Key principles: 

  • Use records you already maintain—such as enrollment data, provider master records, or contracted-contact lists—to validate the requester’s identity and relationship to the provider. Avoid relying only on contact details presented in the change request. 

  • Check that the request is consistent with provider details on file, such as organization name, address, tax identifiers, or NPI, as appropriate to your environment. 

  • If key data points don’t match, escalate for additional review instead of “correcting” records during the same interaction that is requesting a financial change. 

This step aligns directly with the core risk OIG highlighted: individuals impersonating hospital providers to redirect payments.  

Step 3: Confirm the change through a trusted, independently sourced communication channel 

Once you’ve validated that the requester appears to be associated with the provider, confirm the change itself through a trusted channel that is independent of the request

Practical guidance: 

  • Use a trusted communication channel retrieved from internal records—for example, a phone number, secure portal inbox, or email address previously verified during onboarding—not contact information typed into a new form or email. 

  • Perform confirmation in a separate interaction, ideally separated in time and channel from the initial request. 

  • Apply consistent verification steps appropriate to your risk posture—for instance, asking the person contacted to verify specific provider identifiers or details of the requested change. In OIG’s survey, payors most frequently reported using either verified communication channels or knowledge-based methods as part of their confirmation processes.  

Even strong verification via trusted channels is only one layer of defense. It can reduce risk but does not eliminate it, particularly if an attacker has already compromised legitimate communication paths. 

Step 4: Require separation of duties and documented approval 

Reducing single-person control over payment-instruction changes limits the impact of both fraud and internal error. 

Controls to consider: 

  • Segregate responsibilities so that the person who receives and validates the request is not the same person who implements the change in core systems. 

  • Establish approval thresholds based on expected payment volume or sensitivity—for example, requiring secondary approval for high-volume providers, first-time EFT enrollments, or changes requested under time pressure. 

  • Provide a clear “stop and escalate” path when something feels inconsistent, is flagged by monitoring, or doesn’t pass normal verification steps. 

Well-documented separation of duties also makes internal reviews or investigations more straightforward by showing who did what and when. 

Step 5: Confirm implementation and monitor the first payment 

Verification shouldn’t end when an approver signs off. Implementation errors and sophisticated fraud schemes can both surface after the change is applied. 

To close the loop: 

  • Confirm that the change was implemented exactly as approved: correct provider record, routing number, account number, and effective date. 

  • Monitor the first payment (or first several payments) after the change for anomalies that may be consistent with diversion or error—for example, unexpected payment returns, mismatches in remittance behavior, or complaints from the provider about missing funds. 

  • Maintain a concise escalation playbook that aligns with your organization’s policies—for instance, when to temporarily hold additional payments, who to notify internally, and how to coordinate potential recovery efforts. 

OIG’s recommendations emphasize that payors should be prepared to adapt to evolving threats and share information about emerging schemes. First-payment monitoring gives you a practical mechanism to detect issues early and feed lessons back into training and process design. 

What to document for every EFT-change request 

A clear audit trail is as important as the steps themselves. Documentation helps demonstrate that your team treated the change as a controlled financial event and can support both internal learning and external reviews. 

For each request, consider documenting: 

  • Request date and time, and intake channel 

  • Provider identifiers connected to the change 

  • Requester identity and stated authority or role 

  • Exactly what was requested (what changed and what remained the same) 

  • Independent validation steps performed (and by whom) 

  • Confirmation method and trusted channel used, including the source of that channel information 

  • Reviewers and approvers, timestamps, and any separation-of-duties details 

  • Effective date and implementation details (for example, which systems were updated) 

  • Exceptions, escalations, and final disposition 

  • Post-change confirmation actions and the outcome of the first-payment review 

Collectively, these elements support consistent training, help identify process gaps, and provide evidence that you applied structured controls rather than ad hoc judgment. 

Interpreting the HHS OIG findings responsibly 

Because the OIG evaluation has become a reference point for discussions about healthcare EFT fraud, it’s important to be explicit about what it does—and does not—show. 

Based on the source pack and OIG’s published summary:  

  • Scope of respondents: OIG surveyed 76 payors: seven Medicare Administrative Contractors, 56 state and territorial Medicaid agencies, and 13 Medicaid Managed Care Organization parent companies. 

  • Awareness of targeting: About two-thirds of responding entities reported awareness of being targeted by EFT-fraud schemes, and some said such activity was frequent or recurring. This reflects self-reported awareness among those specific surveyed entities, not a measure of how many healthcare organizations overall have been targeted, highlighting the need for healthcare payments modernization

  • No effectiveness testing: OIG stated that the evaluation was not designed to test whether the protections payors reported were effective, compliant with federal regulations, or aligned with expert-group best practices. 

  • Common controls reported: Surveyed payors most frequently reported using verified communication channels or knowledge-based methods to confirm EFT changes. 

  • Recommendations: OIG recommended that the Centers for Medicare & Medicaid Services (CMS) engage Medicare Administrative Contractors on security measures, share information with state Medicaid agencies, and support periodic information sharing among payors and expert groups to address evolving threats. 

When you summarize or train against this report, it’s important not to: 

  • Generalize the “two-thirds” figure to all healthcare payors, providers, or organizations. 

  • Present that figure as a prevalence rate for healthcare EFT fraud. 

  • Suggest that OIG concluded any particular control set is effective or compliant. 

Why collaboration and information sharing matter 

OIG’s recommendation that CMS foster information sharing among payors and expert groups points to a broader reality: 

  • Fraud schemes evolve as controls improve. 

  • Data about payments fraud—including EFT diversion—is fragmented and inconsistently collected across institutions and payment methods. 

A 2025 Federal Register Request for Information on potential actions to address payments fraud notes that payments-fraud data and information sharing are often incomplete, fragmented, and non-standardized, which can limit system-wide understanding of fraud patterns and emerging risks. That document is general payments-fraud context; it does not measure healthcare-specific EFT-change fraud. 

For healthcare payors and provider organizations, practical collaboration steps might include: 

  • Participating in relevant industry working groups or information-sharing forums. 

  • Incorporating OIG and CMS guidance into periodic internal training or tabletop exercises. 

  • Reviewing and updating EFT-change procedures regularly as new fraud patterns or regulatory expectations emerge. 

Again, collaboration and better data do not eliminate fraud risk, but they support more adaptive and evidence-informed controls. 

Go to the source and adapt the workflow 

If you’re reviewing or updating your organization’s process for provider EFT-change requests: 

FAQs 

What did HHS OIG find about healthcare EFT fraud? 

HHS OIG described schemes in which individuals impersonated hospital providers and submitted fraudulent EFT authorization requests—or used other methods—to divert federal and state payments intended for providers. In a survey of 76 Medicare and Medicaid payors, about two-thirds of respondents reported awareness of being targeted by EFT-fraud schemes, with some reporting frequent or recurring activity.  

Does the OIG evaluation show that every healthcare organization has been targeted by EFT fraud? 

No. The “two-thirds” figure reflects reported awareness of being targeted among the surveyed Medicare and Medicaid payors. It does not establish that every healthcare payor, provider, or organization has been targeted, and it should not be treated as a healthcare-wide prevalence rate.  

What confirmation methods did surveyed payors report using for EFT changes? 

According to OIG, surveyed payors most frequently reported using verified communication channels or knowledge-based methods to confirm EFT changes submitted by or on behalf of providers.  

What are the five steps in the recommended EFT-change verification workflow? 

The workflow recommends that teams:  

  1. treat every payment-instruction change as a controlled financial change; 

  2. validate the requestor independently using maintained records;  

  3. confirm the change via a trusted, independently sourced communication channel;  

  4. require separation of duties and documented approval; and  

  5. confirm implementation and monitor the first payment. 

Did OIG test whether payor controls were effective or compliant? 

No. OIG stated that its evaluation was not designed to test whether the protections reported by surveyed payors were effective, compliant with federal regulations, or aligned with expert-group best practices.