Skip to main content
Banks Don't Catch Health Care FraudAnti-Corruption & AML
4 min readFor Legal & Risk Counsel

Banks Don't Catch Health Care Fraud

When FinCEN reported that financial institutions flagged $17.5 billion in suspicious activity tied to health care, it sparked widespread attention. However, this figure is often misunderstood. It’s crucial to grasp how Bank Secrecy Act (BSA) reporting functions, what financial institutions can and cannot see, and their role in combating fraud.

If you're building a compliance program focused on financial crime detection, it's important to distinguish myths from facts. Here's what many get wrong about BSA filings and health care fraud.

Myth 1: Banks Are Investigating Health Care Fraud

Reality: Financial institutions file Suspicious Activity Reports (SARs) when they notice unusual transaction patterns. They aren't fraud investigators; they're pattern-spotters.

A bank might notice rapid fund movement, structuring below reporting thresholds, or account activity that doesn't align with the stated business purpose. They don’t determine if these transactions involve billing fraud, kickback schemes, or legitimate business. They file the SAR because the pattern is suspicious, then FinCEN and law enforcement investigate.

Your compliance team should understand this distinction. When designing transaction monitoring rules, look for red flags, not proof. The $17.5 billion figure represents flagged activity, not confirmed fraud. Some of it will be legitimate. Some won't. The BSA framework's purpose is to highlight anomalies for investigators to examine.

Myth 2: Health Care Providers Are the Main Target

Reality: Financial institutions flag activity across the entire payment chain, including medical equipment suppliers, billing companies, pharmacy benefit managers, and third-party intermediaries.

Health care fraud isn't just about a doctor billing for unprovided services. It could involve a shell company ordering medical equipment that never gets delivered, a billing aggregator routing payments through multiple accounts, or a pharmacy dispensing prescriptions that were never written.

Banks see the money moving between these entities but don't always know which party is at fault. When training your team on red flags, focus on transaction patterns, not customer types. Look for:

  • Payments that don’t match the business model described at account opening
  • Multiple entities sharing the same IP or mailing address
  • Sudden spikes in transaction volume without a business explanation
  • Funds moving quickly in and out without accumulating

Myth 3: BSA Filings Happen in Real Time

Reality: Most SARs are filed after transactions have cleared. Financial institutions have 30 days from detecting suspicious activity to file, or 60 days if they need to identify a suspect.

You're not stopping fraud in progress. You're creating a record for investigators to build a case, trace funds, and identify other scheme participants.

This lag is important for program design. If you're a health care organization building your own monitoring system, don't expect your bank to block suspicious payments before they post. Implement your own controls: vendor due diligence, contract review, invoice validation, and payment authorization workflows.

The BSA system is for detection and documentation, not prevention. Your internal controls must handle prevention.

Myth 4: More SARs Mean Better Compliance

Reality: Filing volume isn't a compliance metric. Quality matters more than quantity.

A SAR with specific transaction details, clear timelines, and relevant documentation aids investigators. A vague SAR doesn't. FinCEN's analysis of the $17.5 billion in health care-related activity depends on detailed reports from financial institutions.

When evaluating your reporting processes, whether filing SARs or internal reports, ask:

  • Are we documenting specific transactions that triggered alerts?
  • Are we explaining what made the activity unusual for this customer?
  • Are we including account opening documents, transaction records, and correspondence?
  • Are we filing within required timeframes?

If your team files vague reports to show activity, you're creating noise, not intelligence.

Myth 5: Financial Institutions Know What They're Looking For

Reality: Most banks use broad monitoring rules that flag patterns, not specific fraud schemes. They refine those rules as FinCEN and regulators share typologies and case examples.

This is why FinCEN's analysis matters. When the agency identifies $17.5 billion in health care-related suspicious activity, it can share that pattern data with financial institutions. What transaction types were common? What account structures appeared repeatedly? What geographic concentrations emerged?

Your compliance program should operate similarly. Don’t just collect reports. Analyze them. Look for patterns. Share what you learn with teams that can adjust controls. If you see repeated red flags in a specific vendor category or payment type, tighten your due diligence or approval process.

What to Do Instead

Think of BSA reporting as an intelligence system, not a box-checking exercise.

If you're at a financial institution: Review your SAR narratives. Are they specific enough to be useful? Do they include transaction details, not just account summaries? Are you using FinCEN's feedback to refine your monitoring rules?

If you're in health care compliance: Build your own transaction monitoring. Don’t rely on your bank to catch billing fraud or vendor kickbacks. You see the clinical and operational context they can't. Use it.

If you're in any industry with third-party payment risk: Understand that financial institutions watch for patterns like rapid fund movement, layering through multiple accounts, and mismatches between stated business purpose and actual activity. If your legitimate business creates those patterns, document why. Keep records explaining unusual transaction timing or routing.

The $17.5 billion figure shows financial institutions are filing reports. It doesn't mean they're catching fraud. That's still your job.

You Might Also Like