Provider payment diversion: the enrolment portal is the attack surface
A health system's entire remittance stream from one payer can be redirected by editing a field. The provider discovers it when reconciliation fails, which is typically two payment cycles later, by which time the funds have moved on and the services have already been delivered.
How are healthcare provider payments diverted?
Through a profile edit in an enrolment portal. HHS-OIG has documented schemes diverting federal and state payments intended for providers, and the mechanism is a change to the electronic funds transfer details — processed as routine paperwork and discovered weeks later during reconciliation.
- HHS-OIG identified schemes in which fraudsters diverted federal and state payments intended for providers by taking over enrolment records.
- Value at risk per provider spans four orders of magnitude, from a solo practice to a health system, so the control must be value-tiered rather than uniform.
- Recovery rates on diverted remittances are poor, which makes prevention the only economically rational control.
Part of Insurance and payer identity
What the practice manager found
The first sign was a variance report. Expected remittance from one payer, for a two-week period, showing zero. Not reduced — zero.
The billing lead assumed a clearinghouse problem and opened a ticket. Four days later the payer confirmed the payments had been made, on schedule, to an account the practice did not recognise. The enrolment record had been updated three weeks earlier through the payer portal, using credentials from a phishing campaign that had also taken the practice's email.
The practice had delivered the care. The payer had paid. Neither party had done anything wrong and the money was gone.
Why the portal is where this happens
Provider enrolment portals exist to reduce payer administrative cost, and they succeeded. Providers update demographics, add locations, manage credentialing documents and — critically — set electronic funds transfer details.
Identity verification occurs at initial enrolment, where the payer verifies the provider's identity, licensure and tax identification. Subsequent changes inherit the portal session, because the enrolment record is modelled as a profile.
| Enrolment stage | Verification performed | Value at risk |
|---|---|---|
| Initial enrolment | Identity, licensure, TIN, sometimes site visit | Future payment stream |
| Demographic update | Session | Low |
| Add location or provider | Session, sometimes credentialing review | Moderate |
| EFT detail change | Session | Entire remittance stream |
The federal record
HHS-OIG identified a scheme in which fraudsters diverted federal and state payments intended for providers, published in its work on Medicare and Medicaid payment risk. Enforcement activity through 2026 — including a National Health Care Fraud Takedown charging 455 defendants in June 2026 and a CMS crackdown on large-scale billing schemes announced in September 2026 — kept payment integrity at the centre of the agenda.
Diversion losses are not published separately from broader health care fraud totals, so this article does not attribute a figure to it. The mechanism is documented; the aggregate is not.
Value tiering, because the population is not uniform
A solo behavioural health practice may receive a few thousand dollars per remittance cycle. A large health system may receive tens of millions. A uniform control is either too heavy for the first or too light for the second.
- Rank your provider population by trailing twelve-month remittance value.
- For the top decile, require an authorised-official signature on any EFT change, with the full account details rendered unmasked.
- For the middle, require the signature plus a hold with dual notification.
- For the smallest, retain the current process plus dual notification, which costs nothing.
The top decile is typically a few hundred organisations covering most of the value. That is a tractable enrolment programme, not a population-scale one.
Who signs on the provider side
This question is worth resolving explicitly because getting it wrong recreates the problem.
The signer should be the provider organisation's authorised official — the person already named in the enrolment record as authorised to act for the entity — under a delegation the organisation issues. Allowing any portal user to sign returns the control to session strength.
What the provider gets
A dual-sided receipt. The provider organisation holds independent evidence of what was requested, which is the artefact they currently lack when disputing a diversion.
That matters commercially. Today a diverted provider is in a weak position with the payer: the change came through their own portal session. A signed record either shows their authorised official approved it, or shows they did not — and the second is far more useful to them than the current ambiguity.
Why the practice cannot protect itself
| Party | Lever | Incentive |
|---|---|---|
| Payer | Controls the change process | Bears no loss |
| Practice | None — cannot gate its own record | Bears the loss |
| Clearinghouse | Sees the remittance flow | Intermediary, limited standing |
This is the same misalignment as beneficiary designation, in a different industry. The practice cannot require a stronger control on its own record because the record is not theirs to configure.
Objections and honest limits
“Payers verify enrolment changes.” Against documents and knowledge, both obtainable. The question is whether an authorised person at the practice approved the change, which is different.
“Reconciliation catches it.” At the next cycle, after several remittances. For a small practice that is a cash-flow event before it is a fraud event.
What a payer should require
- Require a bound signature from a practice signatory. Enrolled once, at enrolment.
- Render the delta. Old and new account, and when it last changed.
- Notify the practice out of band, stating the new account. Not merely that a change occurred.
- Hold the first remittance after a change. The only realistic recovery window.
Terms used here
- EFT enrolment
- The process by which a provider registers the account payments are made to.
- Remittance advice
- The statement accompanying payment, and frequently the first place a practice notices a diversion.
- Clearinghouse
- An intermediary processing claims and remittances between providers and payers.
Frequently asked questions
Is this Medicare-specific? No. The same portal architecture and the same profile-field modelling exist across commercial payers, Medicaid programmes and Medicare Administrative Contractors.
What about providers who will not enrol a credential? Tier them. Small providers retain the current process plus dual notification; the control concentrates where value concentrates.
Does CMS require this? No. Provider enrolment requirements address identity and licensure verification at enrolment. Subsequent banking change authorisation is not prescribed.
How quickly is diversion detected today? Typically at reconciliation, which is one to two payment cycles. That interval is the exposure, and it is measurable within any provider organisation.
Why can't the practice protect its own record? Because the record is held and configured by the payer. The practice has no lever over the change process.
What does the payer verify today? Documents and knowledge, both obtainable. Not whether an authorised person at the practice approved the change.
Why is reconciliation too late? It catches the diversion after several remittances, which for a small practice is a cash-flow crisis before it is a fraud case.
Where this fits in Manav
Manav binds the authorising person to the exact change or payout instruction, and produces a receipt a carrier, a beneficiary or a court can verify without calling the issuer.
Sources and further reading
- FCC — protecting consumers from SIM swap and port-out fraud
- HHS Office of Inspector General enforcement
- CMS announcements on billing scheme enforcement, 2026.
- CMS — Medicare provider enrollment