0:00
You as a business owner, should not have to compromise your patient experience to protect your business against fraud. Welcome to
0:18
off the chart, a business of medicine podcast featuring lively and informative conversations with health care experts, opinion leaders and practicing physicians about the challenges facing doctors and medical practices. My name is Austin Luttrell. I'm the associate editor of medical economics, and I'd like to thank you for joining us today before we get started. Just a quick note, physicians practice will be hosting practice Academy's new practice management track on Thursday, March 19. The Virtual Learning Experience is designed for physicians and practice administrators looking for practical, real world strategies to strengthen operations, improve performance and build more resilient practices. Speakers include Anders Gilberg of MGMA, Bronson Cox of encoda, Justin Lamb of cool blue, VA and Mark Herzog of Vera dime. You can register today by clicking the link in the show notes or by going to registration.physicianspractice.com. That said in today's episode medical economics, managing editor Todd triox sat down with Stephanie O'Connor, the director of merchant experience at Wind River payments. They're talking about how payment processing is evolving in medical practices, what physicians should understand about transaction fees and compliance requirements and how modern payment platforms can affect patient experience and revenue cycle performance. Stephanie also shares practical insights on protecting practices from fraud, improving transparency and choosing payment systems that align with long term goals. So with that said, Stephanie, thank you for joining us, and now let's get into the episode.
1:42
You I'm here with Stephanie O'Connor, Director of merchant experience at Wind River payments, to talk about payment modernization and the role it plays in both patient experience and revenue protection. Stephanie, thanks for joining me. Absolutely. Thanks for having me so. Stephanie, a lot of practices are relying on technology more than ever for things like scheduling and payments, but sometimes this technology can lead to customer confusion, resulting in either chargebacks or maybe even use for fraud. You know, how do things like that happen?
2:17
That's a great question, because it happens too easily, and it's something that is really important for businesses to focus on. I'll get into the detail there, but I want to start by saying, like, there should be a payment strategy within every business, and that strategy should be answering questions around, like, what do you want your patient experience to be when they take payments, and how does that help avoid and remove some of the confusion around when they're paying and how they're paying? And then on the flip side to the business? You know, many businesses focus on how much they're paying to accept payments, but really they should be focusing on, what are they doing to ensure that those costs are as low as possible by preventing fraud and making sure that they're meeting their patients where they are. As far as the demands around payment acceptance,
3:09
is there something that they commonly do wrong that allows fraud to happen? Are there things they can do to make sure they're preventing it?
3:21
Yeah, so in the payment world, you have many, many options as far as acceptance choices for your patients or your customers. And one of the largest mistakes that I see every day in our world and that we help our merchants through, is they see something that is trending out in the industry as far as payment acceptance, and they want to put that out on on their website, or make that available for patients in person. And they do very quickly, because it's new and it's popular, it's trending, but they don't take the time to really think through the impact of what else needs to be considered in order to allow that to be a seamless experience for their patients, as well as protect their business from fraud. And a great example of this is a couple of years ago in the healthcare space, specifically online or multiple different payment options, which allowed a patient to make a payment. 24/7, or around the clock, essentially, were not as popular as they as they were in like a retail environment. Patients weren't asking for it, or they weren't demanding it. They would wait for their bill, and they would make their payments through the channels that were that were allowed. So when covid hit, and many healthcare practices had to start taking payments through alternative channels. They just they turned them on the patients wanted them and they turned them on, and as a result, they left their businesses susceptible to fraud because they didn't have the protections around those payment channels to cover two specific areas. Is one is card testing, and that occurs when you have an online payment channel that allows a fraudster or an individual with stolen card information to hit your website hundreds, if not 1000s of times over and over and over to validate that a card is legitimate. And now in that instance, that perpetrator is not attempting to steal any information from a business or steal any services. They're trying to validate stolen information so that they can use those cards elsewhere. So the website is like a vehicle for the fraudster in that case, and where that is important to a business is that it's expensive. If your website get gets hit 1000s of times in minutes, which is very possible in a very happens all the time, quite frankly, that can add up very quickly for a business, and you're left with that expense so not protecting the website or your online payment portal or a link if you're sending an invoice, is one way that a business is less left susceptible to fraud, and then the other is what is referred to in the industry as friendly fraud, and that can be where a patient, either, you know, says that They didn't receive the service that that was rendered, or they were confused about what they were paying for, or they paid for a co pay, co pay too far up front, and they file a charge back, or assert that it was fraud because they didn't understand what they were actually doing by making a payment in the particular manner that they did. And both of those things are, you know, they are very popular in the industry as far as fraud attacks go, and can easily cost the business way more money than one would assume without doing the proper research and making sure that there's mitigation practices in place.
6:57
And so who would the physician owner talk to should they be talking to their IT people? Should they be talking to their payment processor? How do they basically stop this from happening?
7:09
Yeah, I mean, it's really a joint effort, and it depends on their particular setup. So here at Wind River, we partner with software providers practice management. Software providers is one of our industries that we focus on, and in that case, we are working with the software provider upfront to put in some of these safeguards, and then we are also working with the merchant to make sure that the safeguards that are available, that they're picking the best options that work for their particular setup. So as a healthcare provider, I would start with, if you're accepting payments through software, I would start there, and then also get paired up with the experts in the space, which would be the payment providers that facilitate the payments for your business.
7:55
A lot of times, these are kind of integrated into the patient portal, or link out from the patient portal. Are there particular vulnerabilities in the portal? Are there things that they should be doing or not doing regarding the portal without ruining the patient experience that you know, a lot of patients rely on that for information and communication. So you know, how does the portal play into all of this?
8:18
Absolutely, and it's a delicate balance to make sure that you're providing the best experience for the patient while still managing the fraud. So I get that entirely there are different options that can happen behind the scenes, and this is where AI has really played a very important role in mitigating and managing fraud, so that the patient, when they're in the portal is does not, isn't met with like a bunch of hurdles in order to validate identity, that some of that stuff is automatically happening behind the scenes with the use of AI that is critically important to not only the patient experience, but also to Managing fraud and mitigating it on the business side, because no individual would be able to take the multiple data, data points that AI can and run that through a database and help determine, you know, what kind of activity is happening on the the customer facing side of the portal. And we've, we've all seen, you know, some of the more the early fraud mitigation practices of reCAPTCHA, where you're presented with pictures on the screen, or, you know, jumbled up words or letters that you have to type into a screen, both still exist, and they still serve a very important purpose, but there are more advanced options that do similar things In order to validate that there is a human on the other side of the screen. So we would start with some of the most basic and work our way up depending on the type of Portal that existed out that was existed in the software or that the merchant wanted to provide for their patients.
9:59
Yeah, I. Think about 25% of the time the CAPTCHAs do not believe I'm human, so because I can't take the bicycle out of the right picture or something. So the more we can avoid those, the better.
10:10
So absolutely, yeah, and there, there are other things, like recapture was one of the first things in the market, but there are other tools that are just intended to specifically target card testing, which is what reCAPTCHA was put in the market for. And again, that's where your websites or your portal is hit hundreds, if not 1000s of times within minutes, and it's just meant to ever so slightly slow that down so that a program or a script cannot be run against the website.
10:39
What about with chargebacks? Is there a particular type of chargeback that you see with medical practices, and is there something that can be done to minimize that risk? Absolutely?
10:52
Yeah, medical practice is a little bit different than some of the other industries out there, like, you know, retail, which is pretty popular right now, because you aren't typically getting an item, so you're getting a service or paying for something in advance of an upcoming service. So the type of chargebacks that we see in this area are a little bit different than others, because again, you're not getting a physical item that could be stolen or resold elsewhere. So what we see most often in the healthcare space is chargebacks for services not rendered. And those chargebacks can come through and for a couple of different reasons, and that's where this term of like friendly fraud comes through, even though there's nothing friendly about it, but in a service is not rendered, type of charge back, the patient is asserting that whatever they paid for was not delivered. And this can be especially impactful to anyone who is doing like telemedicine, because it's much more someone has different expectations over the phone sometimes and when they're actually in the doctor's office receiving a service. So telemedicine can be a particularly vulnerable to this, or anyone that is providing like counseling services over the phone. Those can be open to those, versus someone going into a doctor's office to to have an appointment. And then the other one that we see coming through, which is popular in many industries, not particularly in medical, is fraud Card Not Present. So when someone is paying for something, either over the phone or in that portal, and they're paying for it in advance, there can just be confusion around what they actually paid for in comparison to like when the insurance payment is coming in, or when they pay a copay when they actually show up at the doctor's office. So there are specific recommendations around communication and notices to patients to make sure that when they make that payment, it's very clear as to what portion of the service they are paying for and what they should expect to potentially pay for later if there is something additional due.
13:18
Hey there. Keith Reynolds here, and welcome to the p2 management minute in just 60 seconds, we deliver proven, real world tactics you can plug into your practice today, whether that means speeding up check in, lifting staff morale or nudging patient satisfaction north. No theory, no fluff, just the kind of guidance that fits between appointments and moves the needle before lunch. But the best ideas don't all come from our newsroom. They come from. You got a clever workflow. Hack an employee engagement win, or a lesson learned the hard way. I want to feature it. Shoot me an email at K Reynolds at mjh life sciences.com with your topic, quick outline or even a smartphone clip. We'll handle the rest and get your insights in front of your peers nationwide. Let's make every minute count together. Thanks for watching, and I'll see you in the next p2 management minute.
14:09
Are there any red flags that the front office staff or billing teams should be trained to recognize it might indicate fraudulent activity or chargeback risk,
14:21
yeah, absolutely, when the front office staff is taking payments over the phone, or, you know, someone calls in to make a payment, or wants a link sent to them anytime they are being rushed through a particular payment experience, or someone is unwilling to provide data relating to that payment, that should kind of put the spidey senses up a little bit. Multiple declines on several cards is a huge red flag. It happens to all of us, where a card gets declined or unrecognized purchase and you can swap it out. For another one, but having that happen more than once would be something to ask more questions about, or kind of validate who you have on the other end as well, someone also calling in relating to refunds, especially in health care, is a red flag, and we would want to ask more questions about that. Recently, we had a decent number of our health care merchants where there was a refund scam ran over the phone where someone called in and said that they made a payment and that payment was validated, and then they needed a refund on a different credit card, that should always be a red flag. It's the best practice across the payment industry to not refund on a different card unless absolutely necessary, but health care has been targeted with that in the past, and within Wind River's portfolio as well.
15:57
Are these fraud risks? Are they coming from large criminal organizations in Eastern Europe, or is it sometimes the innocent looking old lady that comes into the office that's doing this?
16:10
No, I, I can't say for certain where they come from, because often we don't know the root source of these what. What what we do know is that when we see card testing come through the multiple attacks of those cards, it's most common that those cards are from or have foreign bin numbers, so their issue the banks, are issued from outside of the United States. That doesn't tell us the source of who's actually running the fraud ring or the scheme, but it's common to see that type of activity relating to foreign cards when you have friendly fraud or something like that happening within the office. That tends to be more localized, but again, someone hiding behind a computer. It's very rare that we are able to identify the actual source of that fraud.
17:05
Is there a particular type of practice, either in size or specialty, or is it pretty much agnostic, and they'll go after anybody specialty?
17:16
There is not any specific one industry versus another, everyone is susceptible to it. However size does does matter for the specific type of fraud. Typically, small to medium sized businesses are more susceptible because they may not have as much the most advanced fraud protection set up for their business, and they might not be able to recognize that something is is happening within their payments as quickly as some of the larger entities. Everyone is vulnerable and certainly gets their attacks, but definitely small to mid sized businesses, we often see smaller things being tested out with them to see if they have the protections in place.
18:06
You touched on this a little bit before, but I think it's worth re emphasizing here. Does protecting against fraud mean sacrificing the user experience? Are we going to have to put layer upon layer of validation and kind of ruin that customer experience, or, you know, is AI and other tools making this possible where you can protect everybody and still provide a good user experience.
18:32
Yeah, it doesn't have to in 2025 almost 2026 now you, as a business owner, should not have to compromise your patient experience to protect your business against fraud. There's always pros and cons to how, how much you dial up the fraud protection that you have for your business, but that is where it is critically important that you're speaking to the to the right people who have the expertise in this area to help you weigh the pros and cons of implementing fraud tools, because it doesn't have to any longer. There are tools on the marketplace that your patient wouldn't be impacted in whatsoever in order to that still protect your business against the fraud and provide that experience that your business wants for the patient.
19:27
What questions should a practice be asking either their existing payment processor or if they're looking for somebody new? What are some good questions to ask to make sure they're getting the best technology that's out there.
19:41
Yeah, they should. They should start by asking, what type of fraud that technology is protecting them, again, because it is not a one size fits all solution, and I think that is such an important question, because if you can, if you ask that question, and. You receive an answer that makes sense for your business, then you've validated that your payment processor understands the type of fraud that your business is susceptible and they are not trying to just put a blanket protection across. Because I've worked with plenty of businesses where they say, Oh, I have fraud tools in place and I and then I ask, are those protecting you against chargebacks, or are they only protecting you against card testing? And there's a long pause, and that's what we want to avoid, and just give confidence that we've kind of, we've fully vetted and understood the type of fraud that is relative to the business, and they're protecting all of it. So that would be a good question to ask up front. The other one is, how will this impact my patient experience or the payment workflow? We should be able to walk through every step of the payment process, and even before that, you know, some of these protections happen upon login, before someone even makes a payment. So we should be able to walk through every piece of that experience and explain how it's interacting with the patient and how it's contributing to that experience, to make sure that there's a full understanding of what that outcome will look like.
21:16
2026 what are the emerging trends? Are there new tools that are coming down the road give me a snapshot into what we might see in the coming year.
21:26
Sure, absolutely, I would say. So there's a couple of things. Fraud is not going away, and so it's not it's not a new trend, but it is an existing trend, and I think that is what, or that is one of the main messages that I would deliver to merchants, is that don't wait for the newest fraud trend to hit the marketplace or for it to become a problem before you address it in your business. Every year, Visa puts out a fraud trend report that I like to review, and the top five reasons for fraud haven't really changed in a very, very long time. However, fraud continues to increase, and what I take away from that is that it's happening. It's not going away, and that we just need to continue to kind of hammer at it and make sure that businesses are being protected, so that that is one thing, and then the other is AI, especially in healthcare, has been focused around, you know, claims and data security, but AI and payments should not be ignored and and what I mean by that is Payment Protection, fraud protection, the tools are just they're so advanced, and they do so many wonderful things to help protect your business that they really should be looked at if you haven't yet. So fraud is not going away in 2026 in fact, it's been pretty stable as far as the types, and we need to continue to address that. And two, if you haven't looked at ai 2026, is the year to use that type of technology to protect your business from fraud.
23:15
Very good. Stephanie, thanks for joining me today. Absolutely.
23:18
Todd. I appreciate your time. You Hey, once again, that was
23:30
Stephanie O'Connor, the director of merchant experience at Wind River payment, speaking with medical economics Managing Editor Todd Shryock, on behalf of the whole medical economics and physicians practice teams, I'd like to thank you for listening to the show and ask that you please subscribe so you don't miss so you don't miss the next episode and don't forget physicians practice will be hosting practice Academy's new practice management track on Thursday March 19, featuring practical, actionable education for physicians and practice administrators. You can register today by clicking the link in the show notes or by going to registration.physicianspractice.com as always, be sure to check back on Monday and Thursday mornings for the latest conversations with experts, sharing strategies, stories and solutions for your practice. You can find us by searching off the chart wherever you get your podcasts. Also if you like the best stories that medical economics and physicians practice published delivered straight to your email six days of the week, subscribe to our newsletters at medical economics.com and physicians practice calm off the chart a business of medicine podcast is executive produced by Chris mazzolini and Keith Reynolds and produced by Austin Luttrell. Medical economics and physicians practice are both members of the MGH Life Sciences family. Thank you.
We recommend upgrading to the latest Chrome, Firefox, Safari, or Edge.
Please check your internet connection and refresh the page. You might also try disabling any ad blockers.
You can visit our support center if you're having problems.