The Money That Leaves Your Practice After the Claim Is Already Paid
Ask any practice manager where the money goes missing, and you’ll get the same answer: denials, slow claims, coding mistakes. That’s what everyone watches for.
But what happens after the claim gets approved?
You’d think once insurance says, “yes, we’ll pay this”, the fight is over?
It’s not.
Getting a claim approved and keeping the full amount you’re owed are two different things. A lot of practices don’t find that out until they sit down and look at their numbers.
A claim can sail through, get marked ‘paid’ in your system, and still lose you money on the way to your bank account.
- Maybe a fee got taken out because of how the payment was sent.
- Maybe part of it got used to cover a mistake on someone else’s claim.
- Maybe the rules just changed after you submitted it, and nobody told you.
None of this shows up as a denial. There’s no red flag. No rejection letter. Nothing that makes you stop and ask questions. It just shows up as a slightly smaller number than you expected, month after month.
In this blog, I walk you through four specific ways this happens, based on what the American Medical Association, the Department of Labor, and physicians themselves have said openly in 2025 and 2026. Out of those four, two come with a copy-paste letter you can send today, they’re written out in full below, and also bundled as a one-page downloadable PDF , so you can print or forward them without hunting through the entire blog.
Let’s look at a quick map before diving into each one:
| Problem | First thing to do | Who to contact | How long it usually takes |
| Card payment fees | Ask to switch to direct deposit, in writing | CAQH form, then CMS’s ASETT tool if ignored | 1 to 2 pay cycles |
| Money taken for someone else’s overpayment | Ask which claim the deduction is tied to | Payer’s provider relations line, in writing | A few days, longer if you escalate |
| Old codes suddenly getting denied | Ask for the exact rule that changed | Payer’s provider relations line | 30 to 60 days for an appeal decision |
| Your provider number being misused | Compare your billing report to your real numbers | NPPES registry and your Medicare contractor | Ongoing, act right away if something’s off |
The first one is also the easiest to miss, because it isn’t hiding in a denial code, it’s hiding inside your own bank deposit. Now let’s dig deeper.
Problem #1: You’re Paying a Fee Just to Get Your Own Money
Here’s something that catches almost every practice off guard the first time it happens. An insurance company sends you a payment, not as a check, not as a direct deposit, but as a 16-digit credit card number in an email or fax. Your front desk runs it through your card machine like a patient payment. It feels routine. It isn’t.
Here’s what’s going on:
- You run the card payment through your machine, just like a patient’s credit card.
- You get charged a fee for that, usually 3 to 5 percent of the payment.
- That fee comes straight out of what you were supposed to be paid, it’s not a separate charge you agreed to.
- So if an insurer owes you $5,000, you might only see about $4,750 land in your account.
- Some of the companies that process these card payments give the insurer a small rebate for using this method. So the insurer saves money twice: once by not mailing a check, and again from the rebate.
- A 2025 survey by the American Medical Association, covering more than 1,100 practices, found that 67 percent had received these card payments, and 86 percent said it had gotten more common over the past year.
- If your practice gets $300,000 to $500,000 a year in insurance payments this way, that fee adds up to roughly $9,000 to $25,000 a year. Gone, for nothing.
What to do:
- Look back at your last three months of payments. Find every one that came in as a 16-digit card number instead of a check or direct deposit. Write down which insurer sent it. The three companies that usually process these are ECHO Health, Zelis, and VPay, so search for those names first.
- Add up what those fees cost you. Your card machine’s monthly statement shows the fee percentage, multiply it out. This number is what tells you the fix is worth the effort.
- Send a written request asking to switch to direct deposit instead. Don’t just call, calls are easy for a payer to “forget.” Here’s exactly what to say:
“This letter is a formal request to stop receiving claims payments via virtual credit card and to begin receiving all future payments via standard Electronic Funds Transfer (EFT) through the ACH Network. Per HIPAA Administrative Simplification Rules and CMS guidance, a health plan cannot require a provider to accept payment via virtual credit card, and must comply with a provider’s request to use standard EFT. Please confirm in writing that this change has been made, and provide the effective date for our next scheduled payment.”
- The full fill-in-the-blank version of this letter is in the attached PDF, ready to copy, personalize, and send.
- Fill out the payer’s own EFT enrollment form. Note that CAQH’s old EnrollHub tool, which used to let providers enroll with multiple payers at once, was retired, so you’ll need to go through each payer directly or through whatever enrollment vendor they now use.
- If a payer ignores you and keeps sending card payments anyway, file a complaint through CMS’s ASETT tool, the enforcement channel described in CMS’s own guidance on this exact issue.
- Set a reminder to check again in 90 days. Some companies reset your preference without notice, so a fix from month one can undo itself by month four if nobody’s watching.
How you’ll know it worked: Your payments from that insurer stop showing up as card numbers and start showing up as direct deposits, with no fee taken out. Keep a simple list by the insurer so you can watch the fee drop to zero.
Fixing the card fee problem is mostly a paperwork job, once you send the letter and the form, the insurer has to comply. The next problem is trickier, because it doesn’t leave anything you can point to. It shrinks a payment that has nothing to do with the patient in front of you, without saying why.
Problem #2: Someone Else’s Mistake, Deducted From Your Payment
This one is easy to miss because it never shows up as a denial. It just shows up as a smaller payment than you expected, with a confusing note you’d normally skip past.
It’s called cross-plan offsetting, and here’s exactly how it works:
- An insurer accidentally overpays you $300 for treating Patient A.
- Instead of asking for that $300 back, they wait.
- Later, you bill for a different patient, Patient B, who’s on a different health plan.
- The insurer takes that earlier $300 out of Patient B’s payment, without flagging it as a separate deduction.
- So now: two different patients, two different plans, and a deduction you never agreed to and might not even notice.
The legal footing here is unsettled, and here’s why:
- In 2025, the Department of Labor said this practice can break federal rules that protect employer health plans, especially when one employer’s plan ends up covering another employer’s insurer mistake.
- That builds on an earlier court ruling that said an insurer can’t do this unless it’s specifically written into the plan’s paperwork.
- The catch: a lot of insurers just started adding that language into new contracts. So the practice hasn’t stopped, it’s just become ‘allowed’ on paper.
What to do:
- Have whoever posts your payments flag anything that comes in lower than expected but has no denial attached, just a vague note about an ‘adjustment’ or ‘recoupment.’ Ask your billing software if it can flag these automatically.
- When you find one, ask the insurer, in writing, exactly which claim the deduction is tied to. They’re supposed to be able to tell you. A vague answer isn’t good enough, push for it in writing.
- Find out if the plan is ‘fully insured’ or ‘self-funded.’ Your credentialing contact or the patient’s insurance card can usually tell you. This matters because different rules apply to each.
- One important detail: the government office that handles this (the Department of Labor’s Employee Benefits Security Administration, or EBSA) technically takes complaints from patients and employers, not providers directly. So your best options are to ask the patient’s employer HR department to raise it with EBSA at askebsa.dol.gov or 1-866-444-3272, or use a signed release from the patient if you have one. Either way, just mentioning the Department of Labor’s 2025 position in your written dispute to the insurer often gets you a faster response.
- If it’s a fully insured plan (not self-funded), your state’s Department of Insurance is usually the right place to complain, most states have rules about how fast insurers must explain a deduction like this.
- Ask for the exact contract language that supposedly allows this. If your contract doesn’t clearly say the insurer can do this across different patients, you have grounds to push back in writing.
How you’ll know it worked: You start seeing fewer of these confusing short payments each month, and when they do happen, you get a clear answer with a specific claim number instead of a vague note.
The offset problem lives in your remittances, one payment borrowing from another without saying so. The next problem doesn’t touch your remittances at all, it lives in your denial log, and it’s something an insurer can turn on or off just by updating a rule in a computer system.
Problem #3: A Code That Was Fine Last Year Is Suddenly Getting Denied
If a code your practice has billed for years, no problem, is suddenly getting flagged or denied, you’re not imagining it. Here’s what’s behind it:
- Insurers are leaning harder on automated claims-editing systems that scan claims and flag small things, often with no human reviewing the claim first.
- MGMA reported in 2025 that claim scrutiny and denials are continuing to climb, and that many practices have had to adopt their own AI-driven RCM tools just to keep pace.
- MGMA’s own benchmarking work has found more than half of practices now see denial rates above 10 percent.
- This isn’t about your documentation getting worse. It’s that the rules for what counts as ‘acceptable’ keep shifting inside an automated system that doesn’t explain itself.
What to do:
- Keep a simple log: the code, the insurer, and the denial reason, every time a denial comes in. Ask your billing software if it can pull this automatically, most can.
- Once a month, look for a code and insurer combo that was fine for a while and then suddenly started getting denied. That pattern means the insurer changed something on their end, not that your team made a mistake.
- When you spot one, call the insurer and ask specifically for the written policy or coverage rule that changed. Get a document name or reference number, not just someone’s verbal explanation.
- Appeal using that specific reference, not a generic ‘please look again.’ Here’s the shape of that letter:
“This letter appeals the denial of claim [claim number], billed under CPT code [code]. This code has been billed and paid without issue by this practice as recently as [date]. We request the specific Local Coverage Determination, National Coverage Determination, or internal claims-editing policy that resulted in this denial, including its reference or version number, and request reprocessing of this claim.”
Again, the full version of this letter is in the attached PDF, so you’re not drafting it from scratch every time it happens.
- If it keeps happening with the same insurer and code, bring it up with your specialty association or your local MGMA chapter. Insurers tend to move faster when several practices flag the same issue together.
How you’ll know it worked: That code and insurer combination goes back to getting approved like before, and more of your appeals get overturned because you’re pointing to an exact policy instead of guessing.
So far, all three problems trace back to how insurers handle payment and denials. The last one is different. It has nothing to do with an insurer’s decision at all, it’s about who else might be using your identity to get paid.
Problem #4: Fraud Crackdowns Are Getting Bigger, and Your Provider Number Is Part of What’s Being Watched
This is the newest issue on this list, and it’s two related facts most practices haven’t connected yet:
- In June 2025, the Department of Justice announced its largest healthcare fraud takedown in history: 324 people charged over $14.6 billion in alleged fraudulent claims. The single biggest case, “Operation Gold Rush,” involved a criminal network that bought dozens of legitimate medical supply companies and used the stolen identities of more than one million Americans to submit $10.6 billion in bogus Medicare claims for items like catheters.
- Separately, but related: your National Provider Identifier, or NPI, has its own long-running theft problem. According to the American Academy of Family Physicians, NPIs are stolen from healthcare providers regularly and used to bill Medicare and Medicaid fraudulently. Sometimes it’s outside criminals. Sometimes it’s someone inside a practice who had access and misused it.
- If someone uses your NPI without your okay, you can end up financially responsible unless you can prove it was stolen, not just misused by someone you trusted.
- The Department of Justice’s takedown specifically credited advanced data analytics for catching the fraud, which is a sign that both fraud detection and the scrutiny that comes with it are only getting more automated.
What to do:
- Log into the NPPES registry (npiregistry.cms.hhs.gov) and check that your information is right: your location, your specialty code, your enrollment status. Don’t assume your employer keeps this updated, check yourself.
- Ask Medicare and your top three commercial insurers for a report of everything billed under your NPI. If you’re employed, this should already be something your contract entitles you to, if it’s not, ask for it to be added.
- Compare that report to what you billed and how many patients you saw. If the numbers are higher than reality, that’s a red flag someone else may be using your number.
- If you find a mismatch, reach out to CMS’s Center for Program Integrity through something called the NPI Identity Theft Victimized Provider Project. Your Medicare contractor’s website will point you to the right regional contact.
- Also contact NPPES directly. If your number’s been compromised, they can deactivate it and give you a new one.
- File a police report. It’s not just paperwork, if fraud ever shows up on your record later, proof that you reported it right away is what protects you.
How you’ll know it worked: Your NPI report matches your real patient volume and billing, and you’ve got a paper trail, the report request, your comparison, and any police report, in case anything ever comes up again.
Line these four up together and a pattern shows itself.
What These Four Problems Have in Common
- None of them are about your coding team making mistakes.
- None of them get fixed by just hiring more people or buying new software, though good software can help you spot the patterns faster.
- All four are built into how insurance companies move money, and they hit even the best-run practices.
- All four have one specific tool, contact, or letter behind fixing them, not vague advice to “watch your billing more closely.”
Knowing the pattern is one thing. Working through it in your own practice is another, so here’s a realistic pace to do it at.
Your First 90 Days: A Simple Plan
You don’t need a big overhaul to get started. Spreading this over 90 days lets you see and measure results, instead of taking one step and losing track of it.
Days 1 to 7: Go through three months of payments. Flag every card payment and every payment that came in lower than expected with no clear reason. This tells you which of these four problems apply to you, and roughly how much they’re costing.
Days 8 to 14: Send the direct-deposit request letter (from the attached PDF) to every insurer you flagged. Start your denial log if you don’t have one yet.
Days 15 to 30: Follow up in writing on any short payments you flagged. Pull your first month of denial data and start looking for patterns. Ask Medicare and your top insurers for your NPI activity report.
Days 31 to 60: Check whether your direct-deposit requests took effect. If an insurer hasn’t switched, escalate to ASETT. File any appeals for the denial patterns you’ve confirmed, citing the exact policy. Compare your NPI report against your actual numbers.
Days 61 to 90: Add up the difference between your first audit and where you are now. This is your real, measurable recovery. Double-check your direct-deposit requests one more time, since some companies reset on a 90-day cycle. Decide which of these four problems is fully fixed and which still needs regular attention.
None of this needs new software or new hires. It just needs someone spending real time on payments you already have, using free tools and the letter templates above. The practices that catch this money aren’t the ones with the fanciest technology. They’re the ones who follow through on the paperwork most people give up on halfway through.

Maximize Revenue, Minimize Challenges!
Learn how to tackle reimbursement issues with proven solutions. Get in touch with our expert today!

Dr. Giriraj Tosh Purohit is an experienced Product Manager and Security officer with a strong background in healthcare technology and management consulting. With expertise spanning clinical workflows, EHR, RCM, Digital Health, and AI-driven products, he has been instrumental in shaping innovative healthcare solutions.
