Showing posts with label guest blogger. Show all posts
Showing posts with label guest blogger. Show all posts

Monday, April 16, 2018

Merchant Services 101: Part II

PCI Compliance: What is it and why does it matter?

By Guest Blogger: Cheryl Donahue

Whenever a merchant processes, stores or transmits cardholder data, they are claiming responsibility for protecting that information. Failure to properly secure sensitive information can result in costly fines, audit costs, restrictions or worse should an actual breach occur. To ensure businesses are kept accountable, and consumer information safe, credit card companies such as Visa, MasterCard and Discover, created PCIDSS, or Payment Card Industry Data Security Standards, herein referred to as PCI. Yet, most merchants have zero knowledge of PCI requirements, how determine if they are compliant or whether they are being charged for any non-compliance.

The PCI requirement consists of 12 steps ensuring policies, procedures, training and security measures are in place for consumer & merchant privacy and protection alike. To further this goal, all systems used to transmit data must be secure and all members must know how to safely handle patient credit card information. The ramifications of breaching any patient information are not only damaging to the patient, but also to the practice.

A lesser known requirement is the Self-Assessment Questionnaire (SAQ) of all practices accepting credit cards from patients. Additionally, for those practices utilizing a card swipe or terminal that transmits information via the internet (certainly everyone who integrates their patient payments with their practice management software) Quarterly Vulnerability Scans must also be performed in most cases.

Many reading this may be thinking, “Why have I never heard of this before? It certainly seems important!” 

And it certainly is.


However, most merchant providers do not take a proactive approach in notifying a practice that is not PCI Compliant, leaving the practice ignorant and open for penalty. In fact, 40% of the statements analyzed at Merchant Advocate show a fine for non-compliance. How could that be? My theory is, and I have been in the merchant industry for 20 years, that processors make a lot of money when their clients are not compliant, eliminating any motivation for them to shut off that revenue stream. Many processors charge between $20 and $60 dollars EACH MONTH for non-compliance. Think of how much revenue that produces! The worst case I have run across was a practice being charged $175 every month for over two years.

How to determine your compliance. 
Gather three consecutive, current monthly merchant statements and look towards the end of the statement. Find the section that contains line items like monthly statement fee, batch fees, FANF fee, etc., this is generally where a fine for non-compliance can be found. 

Here are some of the descriptions for this non-compliance fine:


     Non-Receipt of PCI Validation
     PCI Non-Validation
     PCI Non-Compliance Fee
     Quarterly PCI Non-Validation 

What to do if you are non-compliant. 
Call the merchant processor and request they send your credentials for PCI compliance. All processors contract with a PCI vendor, a company that has been certified by the PCI Council to determine compliance for businesses accepting credit cards. This company will have a website and your practice will have a login and password to access that site and complete your PCI requirements. 

Now, it gets even more confusing! The Self-Assessment Questionnaire (SAQ) can quickly bring on a headache, but there is help available. The company contracted with a processor to provide PCI typically has a support team to help navigate the process. If a practice requires a Quarterly Vulnerability Scan (QVS), the IT firm should be able to help, if not it may be time to find a new IT firm. If they have no idea what a QVS is, that’s a bad sign. An IT firm should be well versed in the PCI process and have trained staff readily available for assistance. A failed QVS could be a sign of an insecure network, leaving consumer information open for hacking. If a QVS fails, the IT firm should download the scan report, mitigate the vulnerabilities, inform the client of its completion and conduct another scan. A completed SAQ and a passed QVS (if required) are both needed to achieve compliance and avoid any unnecessary fees.

Why you should get compliant. 
Yes, at first glance, this may seem like a lot of work for a small amount of payoff. Recently, I had a dentist tell me that for a charge of $39 per month he felt it wasn’t worth his office manager’s time to go through the process. It’s important to note that he is a Merchant Advocate client and I was going to help his OM navigate the entire process. Here’s my two cents on why a dental practice ABSOLUTELY should take the time to achieve PCI Compliance. 

Fines for not being PCI Compliant can quickly skyrocket. The cost of an average breach in a regulated industry (dental practices are regulated) is $155 per record. How many patient records do you have? It adds up pretty fast, doesn’t it?

PCI and HIPAA overlap. The HIPAA Security Rule requires secure patient data, including credit card information. PCI requires secure credit card data. If a breach occurs, it’s double trouble. Medical/Healthcare breaches are the second largest category of breaches. The top two cyber-crimes are identity theft and credit card theft. Basically, a dental practice is a gold mine for cyber thieves.

PCI and HIPAA also have common requirements of poli
cies, procedures and training. PCI requires policies address staff procedures, network security, data privacy, the use of electronic mail and texting, internet and paper acceptable uses. That sounds a lot like the requirements of the HIPAA Security Rule. The Security Rule recommends a penetration test of your network, while PCI requires a vulnerability scan. If your QVS passes, meaning you don’t have vulnerabilities, it is likely your network is also secure from outside hackers.

To sum up, PCI Compliance should be taken seriously by all dental practices. Not does it protect patients, it protects the reputation and jobs of the staff, as well as the very future of the practice.

Cheryl Donahue is the Director of New Business at Merchant Advocate. Founded in 2007, Merchant Advocate is the trusted source in merchant services, providing fairness and transparency in the unregulated credit card processing industry.  We provide exceptional results and increase bottom lines by protecting our customers from unfair rates, fees and hidden costs.

You may contact Cheryl with questions or to receive a free analysis on your merchant statement by emailing her at cdonahue@merchantadvocate.com or calling 720-526-5318

Monday, March 19, 2018

Collection Agencies 101


By Guest Blogger: Andy Cleveland

Selecting a collection agency is like purchasing a hand piece, a car or a toothbrush: not all are created equal. Depending on the customer and circumstance, factors to consider are cost, risk versus reward, patient relationships, staffing scenario and brand coherence.
Lately, there have been a noticeable amount of social media posts looking for someone to “recommend a good collection agency.”  My goal is to help educate, motivate and empower the dental community to make informed decisions when looking into a collection agency for their practice.
First, it is important to acknowledge that using a collection company is merely treating the symptoms of an inefficient system. Some quick tips to help reduce the need of a collection service are:


1.  Properly pre-estimate the patient’s insurance portion at time of service. Performed internally, or by a third-party entity, it needs to be done properly.

2.  Have third-party financing options for people with a spectrum of credit scores. 

3.  Train and empower your staff to collect at time of service. If patients walk out without paying, you are creating the problem. Setting a cultural expectation to
be paid at check out relieves you from the burden of chasing down after-service payments.  

Inevitably, there will be some outstanding accounts receivable, regardless of practice efficacy. If the amount is outside your comfort zone, it's time to hire a company to help with the collection. 
Without further ado, here are 8 questions to determine the best fit for your practice when hiring a collection agency. Keep in mind, the answers are not necessarily definitive, but are tools to aid in your selection.

1.  In which states are they licensed or bonded?  Knowing this will help determine if their geographical coverage is sufficient. A collection company not authorized to collect in a neighboring can have damaging effects. In this case, going with a nationwide company is usually a safe bet.


2.  Do they have a proven process? Do they give examples of scripted patient communication, or are they  simply  “winging it?” Ultimately, how they communicate with your patient is a direct reflection of your values. So, if they seem vague, it's a red flag, as we're all prone to simple human error. The last thing you want is for your patient to leave negative reviews on your practice should they be treated unfairly by your collection agency.


3.  How is the company compensated?  Are they working strictly on a commission basis? Though initially attractive, there is no promise of performance from either party, which often leads to disappointment. If they have a large client with high volume and large balances, whose accounts are they going to call first? While neither malicious nor fraudulent, it just makes good business sense for them to cater to the high volume client, since dental patient balances are generally smaller.


4.  Technology.  Do they integrate with your software? How do you send them the data? Are they HIPAA compliant? A substantial accounts receivable that requires manual entry into a third party system can not only build up employee resentment from laborious data entry, but also marks the task as low priority. Look for a partner that can seamlessly sync up with your practice management software. If you'd like to see this done, let me know, the demo takes only about 15 minutes.


5.  Do they specialize in the dental field? If they work in other industries, how comprehensively do they understand your business?  I specialize in working with dental practices – it is what I am most passionate and is my core industry. Always be on the lookout for a company tailored to your needs. 


6.  Are the callers located in the U.S. or overseas? Are you willing to allow your patients to be called from someone in another country for cost savings? While cost is important, customer service, public perception and value are equally so. 


7.  Do they report to the credit bureau? Many collection companies insinuate they do, but never follow through. While every financial company reports to the agency when a debt is unpaid, most often dental practices do not, only to hurt the practice in the long run. 


8.  Does the company offer first party billing solutions? Will they work as an extension of your practice like a virtual assistant to your team? If the majority of accounts pay before 90 days, not only are less people being turned over to "collections," they are more likely to stay loyal to the practice, as well. 
If your practice is considering hiring a collection agency and needs further information, please do not hesitate to reach out. I will be happy to answer any questions or assist in any way I can.

About Andy Cleveland
“The Dental Accounts Receivable Ninja” has been in the revenue cycle space for almost 20 years and has served a variety of capacities. He began working with dental practices by motivating difficult patients to pay accounts on everything from hygiene visits to full mouth restorations. Learning the business from the ground up, he developed a proficiency in recovering lost revenues and rose to the top of his field.  Andy realized his skill sets were better utilized working with clients, so he moved to the consulting and service side of the business where he could make a greater impact. Currently, he works with individual and group practices optimizing their patient accounts receivable process to maximize profitability and efficiency, patient retention and frustration reduction.  

Check him out at www.andycleveland.com.

Tuesday, March 6, 2018

Merchant Services 101: Part 1


Introduction To A (Mostly) Unregulated Industry
By Guest Blogger: Cheryl Donahue

Editor's Note: Dealing with merchant card service providers in business can be costly. That’s why I invited Cheryl Donahue to guest blog and provide insight to help save us some $$$$. This is part one of her three part series. 

Behind the system that allows a practice to collect credit card payments is a complicated and largely unregulated industry. Chances are, this revenue collection system costs significantly more than needed and is currently siphoning money straight out of your practice. Welcome to the Merchant Services Industry, where acquisitions are common and fraud abounds.
Today, we dive into Part 1 of the Merchant Services 101 Three Part Series. We will examine a few aspects of the merchant card services industry that will not only make you a more informed consumer, but also provide tools to better evaluate your practice’s statements. Let’s dig in!
Merchant services is a largely unregulated industry. As incredible as it seems, there is very little regulation in the merchant services industry. Merchant processing companies, hereafter referred to as “processors,” can add or increase fees without requiring notification.
Occasionally, there might be a notice at the bottom of your practice's monthly statement informing of an upcoming rate increase; however, we have discovered many increases where no preceding message was ever sent.
Rate increase is common. When one processor is acquired by another processor, your practice is likely to experience a rate increase within six months to one year of the acquisition.  Two of the three biggest processors catering to the healthcare industry have been sold in the last year and a half. Since then, we have discovered that 90% of our clients using one of these two processors have had their rates increased.

So, how do you know if your practice has been affected? Look at the statement, has the processor name or the format of the statement changed recently? If so, watch out!
What’s worse is that these increases have occurred with no notification to the practice.  Too often, increases are hidden toward the bottom of statements, typically being included in the ‘Other Fees’ or ‘Surcharges’ sections. The only way to determine if there was an increase is to examine the specific line items on each statement.
How about a spot check? Pick five to ten line items on the statement and see if the costs have increased from one statement to the next. As an example, pick the Technology and Security Fee, Authorization Fee, DISC fee, etc. It is critical to perform a spot check each month, as most processors only allow 30-60 days for an error to be corrected. After this time period, you can still request that they lower the fee or fix an error, but, unfortunately, the refund deadline has passed.
Determine your effective rate. The practice's effective rate is determined by taking the total fees charged in a particular month and dividing that number by the total credit card volume processed in the same month. The rate will fluctuate each month based on the credit card types processed.
For instance, one month the practice might accept more debit cards which usually cost less to process than an airline miles reward card. Although there will be fluctuations each month, if those fluctuations are more than 0.20%, the practice's rates have most likely increased.
Coding errors happen without accountability. When a merchant account is initially set up, the data entry is performed by a human being and human beings are prone to error. The person entering the data may have had a bad morning, not enough sleep or committed a simple typo; either way, the mistake could be costing the practice.
In one case, we identified a practice not coded properly with American Express, causing that practice to be charged an unnecessarily high rate for years. While the error was finally corrected, the processor refused a refund for the overcharges. Why? The processor simply isn’t required to, proving again the lack of regulation in the industry.
Mid and non-qualified charges can double your cost. On the practice's statement, does it list mid-qualified or non-qualified line items? Do you know the definition of mid or non-qualified items? If not, don’t worry; no one else does either. Amazingly, there is no industry standard definition for these terms. If you call and ask your processor, they will likely tell you those categories are credit card transactions that do not qualify for the practice's base rate. Okay...that clears it all up, doesn’t it? If there is a large amount of mid and non-qualified charges, call the processor immediately for an explanation, ask them to educate you on ways to avoid them.
Watch out for costly procedural errors. When the processor initially creates the new merchant account, there was most likely a training session. However, changes in equipment, industry standards (such as chip cards), and employee turnover means the practice may no longer be following the best practices of card acceptance.
To get the most out of your merchant service, your team must use proper procedures when accepting a card. The same card taken by the practice will cost you different amounts depending on how it is accepted. Keying in a credit card costs more than swiping or chipping a card. If a team member is not entering additional information such as zip code or street number, those transactions may cost more.
Sometimes, the processor will set up the practice's equipment or software incorrectly and the system will not prompt for this additional information. Moral of the story, stay aware of merchant card provider changes and be vigilant when entering cards.
Skip the credit card insurance reimbursements. Are you accepting insurance reimbursements via a credit card number that is “keyed” into the system? These card brands charge a higher interchange rate to process a keyed sale versus a card present at sale.
Corporate cards have some of the highest costs. If your practice is accepting credit card payments from insurance companies, you have a double whammy: a keyed transaction on a corporate card. Call the insurance companies and insist they send a check, or electronic funds transfer directly to the practice's bank account instead.
Join me for Part 2 when we examine Payment Card Industry Compliance.  You will learn why a practice needs to be compliant, how to determine it is compliant and how PCI Compliance overlaps the HIPAA Security Rule.

Cheryl Donahue is the Director of New Business at Merchant Advocate. Founded in 2007, Merchant Advocate is the trusted source in merchant services, providing fairness and transparency in the unregulated credit card processing industry.  We provide exceptional results and increase bottom lines by protecting our customers from unfair rates, fees and hidden costs.

You may contact Cheryl with questions or to receive a free analysis on your merchant statement by emailing her at cdonahue@merchantadvocate.com or calling 720-526-5318