Showing posts with label finance. Show all posts
Showing posts with label finance. Show all posts

Monday, May 7, 2018

Just Say NO to QuickBooks Online

Intuit is doing everything they can in their marketing endeavors to push all accounting software users to QuickBooks Online. While installing QuickBooks Desktop 2018, I was amazed at the blatant pop up offering three free months if I converted to the online version.

Let me be clear, I get it. After all, QuickBooks Online looks great. Being able to use a mobile app is appealing and having access while 
you are sitting on a beach sounds great. Although, if I am on a beach, working on my accounting would be the last thing on my mind.

The colors and graphs look amazing, but, what are they not telling us What are we sacrificing by going online?

If you hang around me long enough, you’ll learn how I really feel about

QuickBooks Online. While many CPAs and consultants do not share my views, if you look from the viewpoint of what is truly best for our clients, most cases, it is not the online version.

There are many valid reasons to not use QuickBooks Online. As I have converted as many Online users back to QuickBooks desktop version, let me explain the problems.

Change your mind? Too bad. QuickBooks Desktop version converts nicely to QuickBooks Online, however, QuickBooks Online does NOT convert cleanly to QuickBooks Desktop. There is no clean backup. I think it’s interesting that Intuit asks why you are doing a backup: as a backup or are you going back to the desktop version? With the increasing degrees of difficulty and required hoops jumped through when converting, it appears they are sabotaging the entire process. In the least, they are not making it easy.

In the past few months, the steps to download have become more refined and easier to follow. However, the data does not download as it appears online. Profit & Loss Reports, as well as Balance Sheet reports, often do not line up when converting to Desktop. This poses a massive problem.

Backups. A recent transition client’s CPA completely revised their QuickBooks Online Chart of Accounts. Incensed, the doctor decided to get off QuickBooks Online and start using the desktop version. An online client for many years, he was frustrated with the consistent errors in his data and felt he had no control.

If you make changes to your online Chart of Accounts, or balances become off for whatever reason, there is no “reset” option in the Online version. With the desktop version, there is a simple restore of your prior backup, which has been done many times with overzealous accountants who truly did not know QuickBooks as well as they should.

This is truly something for you to consider. Are you willing for your accounting data to only be accessible online? To not have a guaranteed copy downloaded?

Really think about it.

Other Names. One of the major missing components from the Online version included in the Desktop Pro version, is the Other Name payee type. The Online version has only three choices: Customer, Vendor, and Employee.

The reason this is significant does not matter to the accountant, who is simply doing your taxes, but it does matter if there is business management oversight.

Customers are patient refunds and employees are paid through payroll, but not everyone else is a Vendor.

A Vendor is someone you do business with through the course of your practice. It is the supply company, the labs, the landlord, the IRS, the professional associations, the utility companies, the plumber, the IT company, etc.

A Vendor is NOT the restaurant, the convenience store, the hotel, the airlines, the grocery store, where you get gas or the pizza delivery. These are all very common transactions in a practice and should be categorized under Other Names. The reason? A great report to review – Expenses by Vendor Summary.

Business management is most effective with separate payee types. Not separating them out convolutes the ability to fully review the report.

Cost. I recommend the QuickBooks Desktop Pro version be upgraded only every three years. In comparing cost, the QuickBooks Desktop Pro version can most of the time be purchased for $199.00 vs. $1380.00 for the Online version (3 months with a 50% discount, then $40 per month.) For me, that’s a no-brainer.

Accessibility. The reason an accountant tells their client they would prefer the business use QuickBooks Online is always for ease of access. There is simply no other reason. Period.

Let’s break that down. QuickBooks Online costs 3x more than the desktop version, for a third of the features. All so the accountant can have uncontrolled access to your data, and most likely only 1-4 times a year.

There are other ways you can give the accountant access to your QuickBooks Desktop version, in a greater controlled environment. Creating and emailing an Accountant’s Copy every month would be sufficient. They can make their changes and then import them into the Desktop version. This also provides a summary of the changes that will be imported for review PRIOR to accepting the changes.

I marvel at how QuickBooks Online has been sold as the only way to access QuickBooks through the internet. There are other options. You can access your computer remotely through GotoMyPC ($23/month), or use an online service such as iNSYNQ, which hosts the full QuickBooks desktop version in the cloud.

Chart of Accounts. The design of your chart of accounts is a vital aspect of understanding your reports. Currently unavailable online is the ability to inactivate any old accounts, vendors, employees, etc. They can be deleted, which is odd, as this removes them from the list, but still allows them to be restored if needed. This is not a smooth process and, I suspect, the reason why it is nearly impossible to download a clean backup copy.

For example, if you delete a Balance Sheet account and it has a balance, QuickBooks Online creates a journal entry for you. Likewise, with a deleted Vendor with a balance. I searched QuickBooks Online help and the alternate answers made me laugh, but it is certainly nothing I would ever recommend.

The order of organization I recommend for the desktop version is by the “weight” (cost) of the practice area, with Doctor Expenses always being last, generally being mostly subjective. The Chart of Accounts Online offers a single version of organization: alphabetical order, parent, and subaccounts.

My clients will start fresh with QuickBooks Desktop 2018 version as of January 2018, and will no longer have any historical data. To this point, I have spent 8 hours determined to give them historical data. They will, however, have a resemblance of this data with all the report detail downloaded from the online version for backup.

I had a previous client call because her IT guy recommended QuickBooks Online. My response to that? They should stay in their lane. Do not allow anyone to talk you into doing anything without doing your homework first. What sounds like a great idea, may not be so grand in the long run.

Just say no to QuickBooks Online.

Want to take control of your QuickBooks? Get Susan's book here.

Monday, April 16, 2018

Merchant Services 101: Part II

PCI Compliance: What is it and why does it matter?

By Guest Blogger: Cheryl Donahue

Whenever a merchant processes, stores or transmits cardholder data, they are claiming responsibility for protecting that information. Failure to properly secure sensitive information can result in costly fines, audit costs, restrictions or worse should an actual breach occur. To ensure businesses are kept accountable, and consumer information safe, credit card companies such as Visa, MasterCard and Discover, created PCIDSS, or Payment Card Industry Data Security Standards, herein referred to as PCI. Yet, most merchants have zero knowledge of PCI requirements, how determine if they are compliant or whether they are being charged for any non-compliance.

The PCI requirement consists of 12 steps ensuring policies, procedures, training and security measures are in place for consumer & merchant privacy and protection alike. To further this goal, all systems used to transmit data must be secure and all members must know how to safely handle patient credit card information. The ramifications of breaching any patient information are not only damaging to the patient, but also to the practice.

A lesser known requirement is the Self-Assessment Questionnaire (SAQ) of all practices accepting credit cards from patients. Additionally, for those practices utilizing a card swipe or terminal that transmits information via the internet (certainly everyone who integrates their patient payments with their practice management software) Quarterly Vulnerability Scans must also be performed in most cases.

Many reading this may be thinking, “Why have I never heard of this before? It certainly seems important!” 

And it certainly is.


However, most merchant providers do not take a proactive approach in notifying a practice that is not PCI Compliant, leaving the practice ignorant and open for penalty. In fact, 40% of the statements analyzed at Merchant Advocate show a fine for non-compliance. How could that be? My theory is, and I have been in the merchant industry for 20 years, that processors make a lot of money when their clients are not compliant, eliminating any motivation for them to shut off that revenue stream. Many processors charge between $20 and $60 dollars EACH MONTH for non-compliance. Think of how much revenue that produces! The worst case I have run across was a practice being charged $175 every month for over two years.

How to determine your compliance. 
Gather three consecutive, current monthly merchant statements and look towards the end of the statement. Find the section that contains line items like monthly statement fee, batch fees, FANF fee, etc., this is generally where a fine for non-compliance can be found. 

Here are some of the descriptions for this non-compliance fine:


     Non-Receipt of PCI Validation
     PCI Non-Validation
     PCI Non-Compliance Fee
     Quarterly PCI Non-Validation 

What to do if you are non-compliant. 
Call the merchant processor and request they send your credentials for PCI compliance. All processors contract with a PCI vendor, a company that has been certified by the PCI Council to determine compliance for businesses accepting credit cards. This company will have a website and your practice will have a login and password to access that site and complete your PCI requirements. 

Now, it gets even more confusing! The Self-Assessment Questionnaire (SAQ) can quickly bring on a headache, but there is help available. The company contracted with a processor to provide PCI typically has a support team to help navigate the process. If a practice requires a Quarterly Vulnerability Scan (QVS), the IT firm should be able to help, if not it may be time to find a new IT firm. If they have no idea what a QVS is, that’s a bad sign. An IT firm should be well versed in the PCI process and have trained staff readily available for assistance. A failed QVS could be a sign of an insecure network, leaving consumer information open for hacking. If a QVS fails, the IT firm should download the scan report, mitigate the vulnerabilities, inform the client of its completion and conduct another scan. A completed SAQ and a passed QVS (if required) are both needed to achieve compliance and avoid any unnecessary fees.

Why you should get compliant. 
Yes, at first glance, this may seem like a lot of work for a small amount of payoff. Recently, I had a dentist tell me that for a charge of $39 per month he felt it wasn’t worth his office manager’s time to go through the process. It’s important to note that he is a Merchant Advocate client and I was going to help his OM navigate the entire process. Here’s my two cents on why a dental practice ABSOLUTELY should take the time to achieve PCI Compliance. 

Fines for not being PCI Compliant can quickly skyrocket. The cost of an average breach in a regulated industry (dental practices are regulated) is $155 per record. How many patient records do you have? It adds up pretty fast, doesn’t it?

PCI and HIPAA overlap. The HIPAA Security Rule requires secure patient data, including credit card information. PCI requires secure credit card data. If a breach occurs, it’s double trouble. Medical/Healthcare breaches are the second largest category of breaches. The top two cyber-crimes are identity theft and credit card theft. Basically, a dental practice is a gold mine for cyber thieves.

PCI and HIPAA also have common requirements of poli
cies, procedures and training. PCI requires policies address staff procedures, network security, data privacy, the use of electronic mail and texting, internet and paper acceptable uses. That sounds a lot like the requirements of the HIPAA Security Rule. The Security Rule recommends a penetration test of your network, while PCI requires a vulnerability scan. If your QVS passes, meaning you don’t have vulnerabilities, it is likely your network is also secure from outside hackers.

To sum up, PCI Compliance should be taken seriously by all dental practices. Not does it protect patients, it protects the reputation and jobs of the staff, as well as the very future of the practice.

Cheryl Donahue is the Director of New Business at Merchant Advocate. Founded in 2007, Merchant Advocate is the trusted source in merchant services, providing fairness and transparency in the unregulated credit card processing industry.  We provide exceptional results and increase bottom lines by protecting our customers from unfair rates, fees and hidden costs.

You may contact Cheryl with questions or to receive a free analysis on your merchant statement by emailing her at cdonahue@merchantadvocate.com or calling 720-526-5318

Monday, April 2, 2018

ANOTHER data breach



5 Million Credit and Debit Cards Are For Sale. The average internet consumer will not participate in this sale, but if you shop on the dark web, you could.
This data breach, sponsored by Saks and Lord & Taylor customers, is a result of a mafia hacker group known as Joker's Stash. The group was also behind the Whole Food, Chipotle and Trump Hotel breach.
Though not yet confirmed, some news sources are speculating, a particular talent of theirs, that an employee clicked on a phishing email and opened an executable file, which is akin to holding the server's door open for the hackers and rolling out the red carpet. This type of hack happens too often to too many.
There are two aspects of this breach that must be addressed:
Debit Cards. Do not use your debit cards for retail, restaurants or internet purchases. I personally do not even use my debit card any longer. A debit card is the gateway to your bank account. Some banks are offering purchase protection in case of a breach, but it is not worth the time it will take to untangle the mess it will create. Use your debit card at your own high risk.
Employees and emails in your business. The beauty of an email service, such as Google, is that the email service does not download to the accessing computer. The hacking risk is greater if your business downloads emails to the computers using a software program such as Outlook. All the security implementation installed cannot prevent an unsuspecting employee from clicking a virus contained or phishing email. Phishing emails are often branded, looking like a reputable company with matching logo – a bank, an insurance company, a business. 
The email will often say you need to change your password, update your information or something else that compels you to urgent action – fear based. Their goal is your logins and passwords. Some links will even lead you to what looks like the “bank’s” valid website. Do not be fooled. Again, the goal is to obtain your logins and passwords. They will do what they can to obtain that information. Then when they have access through what you have provided them, they can wreak havoc [enter stage right - Saks and Lord & Taylor.]
Never, and I mean never, click on email links or open any attachments from senders you do not know. And never assume the sender is the true “sender.” If you have an account at the “sender’s” business, go to their main website to see if it states you need to update any information.
For reference, I once received an email from “Paypal,” and while it looked legitimate, I called Paypal to confirm. Surprisingly, it was actually them. I then I asked what insane person at Paypal thought it would be a good idea to send emails to confirm personal information in the phishing email world we live in. I have not gotten another email from them since.
Update your anti-virus, anti-spyware, filters and firewalls/vpns and update your employees as well – never ever assume your employees know about phishing emails and how dangerous they can be.  
Beware of pop-up warnings on your computers or smart devices that state you have a virus. Do NOT click on anything. Close the window and move on. It might also be a good idea to run anti-virus and anti-spyware programs for peace of mind.
Speaking of anti-virus and anti-spyware software, they're not running at their best if they're not routinely updated. Setting the software to automatically download and update will provide you maximum protection for all software. This also includes your QuickBooks software. Some of the updates are security enhancements to keep your data protected. Click Install Now when you see that message.
Welcome to the Information Age was March’s eNewsletter and it contains a plethora of information for you and your business. I will keep writing about ways to protect your business and yourself but it is up to you to implement!

Monday, March 19, 2018

Collection Agencies 101


By Guest Blogger: Andy Cleveland

Selecting a collection agency is like purchasing a hand piece, a car or a toothbrush: not all are created equal. Depending on the customer and circumstance, factors to consider are cost, risk versus reward, patient relationships, staffing scenario and brand coherence.
Lately, there have been a noticeable amount of social media posts looking for someone to “recommend a good collection agency.”  My goal is to help educate, motivate and empower the dental community to make informed decisions when looking into a collection agency for their practice.
First, it is important to acknowledge that using a collection company is merely treating the symptoms of an inefficient system. Some quick tips to help reduce the need of a collection service are:


1.  Properly pre-estimate the patient’s insurance portion at time of service. Performed internally, or by a third-party entity, it needs to be done properly.

2.  Have third-party financing options for people with a spectrum of credit scores. 

3.  Train and empower your staff to collect at time of service. If patients walk out without paying, you are creating the problem. Setting a cultural expectation to
be paid at check out relieves you from the burden of chasing down after-service payments.  

Inevitably, there will be some outstanding accounts receivable, regardless of practice efficacy. If the amount is outside your comfort zone, it's time to hire a company to help with the collection. 
Without further ado, here are 8 questions to determine the best fit for your practice when hiring a collection agency. Keep in mind, the answers are not necessarily definitive, but are tools to aid in your selection.

1.  In which states are they licensed or bonded?  Knowing this will help determine if their geographical coverage is sufficient. A collection company not authorized to collect in a neighboring can have damaging effects. In this case, going with a nationwide company is usually a safe bet.


2.  Do they have a proven process? Do they give examples of scripted patient communication, or are they  simply  “winging it?” Ultimately, how they communicate with your patient is a direct reflection of your values. So, if they seem vague, it's a red flag, as we're all prone to simple human error. The last thing you want is for your patient to leave negative reviews on your practice should they be treated unfairly by your collection agency.


3.  How is the company compensated?  Are they working strictly on a commission basis? Though initially attractive, there is no promise of performance from either party, which often leads to disappointment. If they have a large client with high volume and large balances, whose accounts are they going to call first? While neither malicious nor fraudulent, it just makes good business sense for them to cater to the high volume client, since dental patient balances are generally smaller.


4.  Technology.  Do they integrate with your software? How do you send them the data? Are they HIPAA compliant? A substantial accounts receivable that requires manual entry into a third party system can not only build up employee resentment from laborious data entry, but also marks the task as low priority. Look for a partner that can seamlessly sync up with your practice management software. If you'd like to see this done, let me know, the demo takes only about 15 minutes.


5.  Do they specialize in the dental field? If they work in other industries, how comprehensively do they understand your business?  I specialize in working with dental practices – it is what I am most passionate and is my core industry. Always be on the lookout for a company tailored to your needs. 


6.  Are the callers located in the U.S. or overseas? Are you willing to allow your patients to be called from someone in another country for cost savings? While cost is important, customer service, public perception and value are equally so. 


7.  Do they report to the credit bureau? Many collection companies insinuate they do, but never follow through. While every financial company reports to the agency when a debt is unpaid, most often dental practices do not, only to hurt the practice in the long run. 


8.  Does the company offer first party billing solutions? Will they work as an extension of your practice like a virtual assistant to your team? If the majority of accounts pay before 90 days, not only are less people being turned over to "collections," they are more likely to stay loyal to the practice, as well. 
If your practice is considering hiring a collection agency and needs further information, please do not hesitate to reach out. I will be happy to answer any questions or assist in any way I can.

About Andy Cleveland
“The Dental Accounts Receivable Ninja” has been in the revenue cycle space for almost 20 years and has served a variety of capacities. He began working with dental practices by motivating difficult patients to pay accounts on everything from hygiene visits to full mouth restorations. Learning the business from the ground up, he developed a proficiency in recovering lost revenues and rose to the top of his field.  Andy realized his skill sets were better utilized working with clients, so he moved to the consulting and service side of the business where he could make a greater impact. Currently, he works with individual and group practices optimizing their patient accounts receivable process to maximize profitability and efficiency, patient retention and frustration reduction.  

Check him out at www.andycleveland.com.