Healthcare vendor payment fraud is money a hospital or medical practice loses not through a fraudulent claim, but through a legitimate payment it sends to an impostor: a supplier’s bank details are changed by a spoofed email, and the next payment for equipment, services, or supplies routes to an account no one verified. It is a different exposure from the one nearly every healthcare compliance program is built around. Those programs watch billing and coding, the integrity of claims going out to Medicare and Medicaid, and for good reason. The Association of Certified Fraud Examiners’ 2026 study recorded 140 healthcare fraud cases with a median loss of $100,0001, and the FBI ranks healthcare among the top three critical-infrastructure sectors targeted by ransomware2. But claims integrity and vendor-payment security are two different disciplines, and the second one is usually nobody’s job. This guide maps the accounts-payable-side exposure that billing compliance does not cover, decodes what the March 2026 FinCEN Health Care Fraud Advisory actually addresses and, just as importantly, what it does not, and sets out how a high-volume medical AP function verifies a vendor banking change before the money leaves.
The AP-side exposure map
Healthcare payment fraud has two sides, and conflating them is how the accounts-payable exposure goes unmanaged. One side is claims fraud: false, inflated, or unnecessary bills submitted to Medicare, Medicaid, or private insurers, money flowing into a provider. That is what fraud investigators, compliance officers, and the federal government spend most of their attention on. The other side is accounts-payable fraud: the payments flowing out of a health system to its vendors, contractors, and suppliers, redirected to an impostor. It is the same business email compromise that hits every industry, and a hospital is an especially rich target because it pays a very large number of vendors on routine terms.
The mechanics are ordinary. A spoofed or compromised email, appearing to come from a medical-equipment supplier, a construction contractor, or a service vendor, requests that future payments go to a new bank account. The change is entered and the next payment settles in the impostor’s account. Nothing about it looks like fraud to a team that processes hundreds of vendor payments a week. The federal totals are set by business email compromise, which took $3.046 billion in 2025, with 86 percent of the money moving by wire or ACH2, the same rails a health system uses to pay vendors. Payroll is exposed the same way: in the last federal breakout of payroll-diversion fraud, healthcare was among the most affected sectors4.
- Vendor bank-change scams: a supplier’s remittance details are altered by a spoofed email before a payment run.
- Medical-supplier and DME impersonation: an impostor poses as an equipment or supply vendor on a real, open account.
- Contractor and construction-project fraud: facilities and expansion projects carry the same payment-chain exposure as any construction job.
- Payroll diversion: an employee direct-deposit change reroutes wages, a sector where healthcare is heavily represented in the federal data.
Reading the FinCEN advisory from the payment desk
The FinCEN Health Care Fraud Advisory, issued March 30, 2026, is about claims fraud and money laundering, not vendor payment fraud. Read from the payment desk, this distinction matters more than anything else in the document. The advisory warns financial institutions about illicit actors, including transnational criminal organizations, who register as health care providers using straw owners and shell companies, submit false Medicare and Medicaid claims, and then launder the reimbursements. It asks banks to file Suspicious Activity Reports referencing the key term for the advisory. It does not address a health system’s outbound payments to its own vendors.
What it does cover is substantial. FinCEN reported a 330 percent increase in Bank Secrecy Act reporting on health care fraud from 2020 through 2025, with a record of more than 3,800 related suspicious activity reports in 20253. It details the June 2025 “Operation Gold Rush” case, part of a national takedown of 324 defendants tied to $14.6 billion in intended loss, in which a criminal organization submitted over $10.6 billion in fraudulent Medicare claims. Every one of the advisory’s red flags is aimed at detecting a fraudulent provider or a laundering pattern. None of them describes a hospital being deceived into paying an impostor vendor. That is not a criticism of the advisory; it is the point. The reader responsible for the payments a health system sends out will find nothing in it about the exposure sitting on their own desk, which is exactly why that exposure needs a separate owner.
Verification for high-volume medical AP
The control for accounts-payable fraud is verifying the payee before release, and in healthcare the defining challenge is volume. A health system pays thousands of vendors on standard terms, and a single changed bank account among them is easy to wave through. The verification standard is the same as in any industry: confirm any new or changed banking detail out of band, through a phone number or contact the organization already had on file, never one supplied in the request; hold the first payment to the new details until that confirmation lands; and record a named approver for the change. At scale, this works only when it is built into the payment path rather than left to whoever processes the invoice.
This is increasingly the baseline regulators expect. Nacha’s fraud-monitoring rules, whose second phase took effect on June 19, 2026 for all non-consumer ACH originators5, expect any organization that originates ACH credits, health systems included, to screen for payments induced under false pretenses. A vendor payment sent on a spoofed banking change is exactly that. The practical move for a medical AP function is to treat a banking-detail change as an exception that must be verified, not an administrative update to be keyed, and to apply that rule the same way whether the vendor bills $2,000 a month or funds a wing. The same discipline protects the accounts payable function in any organization that pays at scale.
- Verify every new or changed vendor bank account out of band, on a contact you already had, not one in the request.
- Confirm the account belongs to the vendor named on the contract or purchase order.
- Hold the first payment to new banking details until that confirmation is complete.
- Record a named approver, so a diverted payment can be traced and the control shown to an auditor.
Two fraud programs, one gap between them
Most health systems run two separate fraud functions, and the vendor payment falls between them. The billing-integrity or compliance program owns claims: coding accuracy, medical necessity, and the money coming in from payers. Treasury or accounts payable owns the mechanics of paying vendors out. Neither is chartered to verify that a vendor’s changed bank account actually belongs to the vendor. Compliance does not see it because it is not a claim; AP processes it because it looks like a routine payment. The impersonated payee lands in the seam, protected by the assumption that someone else is watching.
This is the same structural pattern that runs through every sector in the payment fraud league table: the loss happens on an authorized payment that no control was positioned to question. It is especially acute for organizations that hold a public trust, from a school district’s public funds to a health system’s. Closing it does not require a new fraud program; it requires assigning one clear owner to the question of whether a vendor payment is going where it should, and giving that owner a control that fires before the money moves.
Closing the AP-side gap
Every control above works, and every one fails the same way: under the volume of a large AP operation, when verifying one more banking change feels like friction the team cannot afford. The durable version is structural. Before a vendor payment is released, the payee is verified against the vendor entitled to it, a changed account is held until confirmed out of band, and a named approver is on record, so the health system has evidence of the control and not just a policy.
This is where RankShield Financial fits for healthcare vendor and supplier payments. It is a verification and attestation layer in the authorization path, not a bank or a payment processor, and it never takes custody of funds; your existing treasury systems and rails still move the money. It holds a changed or unverified payee before a payment is released, requires proof that an authorized person approved it, and seals a signed, tamper-evident record that an auditor, a board, or a regulator can independently verify rather than take on faith. That shared signal compounds as members join, rather than claiming a scale we have not yet reached. The honest boundary: verification does not touch claims integrity or your billing-compliance program, which remain their own discipline; it closes the accounts-payable gap those programs were never built to cover. If your health system wants that gate in front of its vendor payments, you can see how it works or request access.
The verification a claims program cannot give you
If a health system takes one action after reading this, give the vendor payment a clear owner and make every banking-detail change a verified event before the next payment runs. A billing-compliance program, however rigorous, cannot catch a payment diverted to an impostor, because that payment is not a claim. The FinCEN advisory will help your bank spot a fraudulent provider; it will not stop your own team from wiring a real invoice to a changed account. A note on timing: this guide reflects the FinCEN Health Care Fraud Advisory as of March 2026, and interpretation of new advisories evolves, so confirm the current guidance if you are building policy around it. The payment-side discipline does not expire: verify the payee, hold the change, prove the approver, before the money moves.
