ACH Fraud Control for a 150‑Person Fresno Clinic: Locking Down AP After a Near‑Miss BEC — Datapath managed IT, cybersecurity, and compliance
Back to Blog
GENERAL Insights Published July 17, 2026 Updated July 17, 2026 7 min read

ACH Fraud Control for a 150‑Person Fresno Clinic: Locking Down AP After a Near‑Miss BEC

For a mid‑sized healthcare clinic in Fresno that nearly sent an ACH payment to a fraudster after a BEC (business email compromise) attempt, the.

JW

By

Joel Walker

Territory Sales Manager

CaliforniaCentral Valleycybersecurity

Quick summary

  • BLUF:
  • Common buyer question: Will MFA break our ability to pay vendors quickly?
  • BLUF: For a mid‑sized healthcare clinic in Fresno that nearly sent an ACH payment to a fraudster after a BEC (business email compromise) attempt, the fastest risk reduction is (1

BLUF: For a mid‑sized healthcare clinic in Fresno that nearly sent an ACH payment to a fraudster after a BEC (business email compromise) attempt, the fastest risk reduction is (1) stop single‑email approvals, (2) require strong identity proofing + MFA on banking portals, and (3) codify a dual‑control ACH policy enforced by your bank and AP system. We helped one clinic implement this in 10 business days while preserving vendor payment SLAs.

Why this matters in Fresno, and why we wrote this for clinics

A 150‑person clinic in Fresno contacted our Datapath team after an executive assistant nearly authorized a $42,500 vendor ACH payment requested by what looked like the CEO’s email. The message used a realistic display‑name spoof and asked for an immediate change to the vendor’s bank account. That near‑miss exposed three operational weaknesses common in healthcare and mid‑market organizations we serve in the Central Valley: reliance on single‑channel email approvals, AP credentials shared loosely, and insufficient authentication on the bank portal.

We focus this article on concrete steps a Fresno clinic (and similar healthcare customers in our /locations/fresno-california/ and /solutions/healthcare/ markets) can implement quickly, plus the controls we layer when we act as a co‑managed or fully managed partner. Where useful, we cite government guidance on authentication, BEC reporting, and retail payment risk.

What attackers actually do: BEC + ACH in plain terms

Attackers harvest email threads, spoof display names, or compromise an inbox and then change vendor bank details or request an urgent wire/ACH. The FBI and IC3 advise victims to report BEC incidents immediately and note the scale of the problem — you should treat any unexpected payment‑change email as a potential crime scene and escalate rather than act on it quickly1.

Quick takeaways about attacker behavior

  • They exploit trust and speed: urgent, authority‑signed messages command action.
  • They prefer ACH because it’s fast and often reversible only with bank cooperation.
  • They use credential phishing and stolen credentials to access banking portals and authorize payments; federal guidance lists credential compromise as a common BEC vector2.

Four control layers we apply (and why each is required)

We design a layered setup that clinics can adopt immediately. Each layer reduces a different part of the kill chain.

  1. Operational controls (workflows, separation of duties)
  2. Identity controls (digital identity proofing, MFA)
  3. Banking / payment controls (dual‑approval, return limits, ACH authorization tokens)
  4. Detection & response (email protections, logging, and IR retainer)

We map these to specific, implementable actions below and a short decision table so AP teams in Fresno can act without calling their bank first.

Step 1 — Lock the workflow: stop one‑person ACH approvals

Operationally, require two independent approvers for any ACH payment above a threshold you set (we typically start at $2,500–$5,000 for clinics, then tune). Implement a written SOP: the submitter, a verifier, and a finance lead who confirms on a separate channel (phone or bank‑authenticated device). This separation of duties is the single highest leverage fix because it converts a fast, impulsive transaction into a controlled sequence.

  • Example quick rule we push at first: “No ACH changes or new vendor ACH payments > $2,500 without (a) a signed vendor change form, (b) call confirmation to a known vendor phone number, and (c) dual sign‑off in the AP system.” This rule is operational and does not require immediate bank changes, but it reduces risk in 24–48 hours.

Step 2 — Require strong identity proofing and multifactor authentication

Banks and identity frameworks recommend layered identity proofing and MFA for high‑risk transactions. NIST’s digital identity guidance (SP 800‑63) describes technical requirements for identity proofing and authenticators; treating banking portal access as high‑risk and applying MFA is standard federal guidance34. Similarly, MFA is highlighted as a core mitigation for credential theft5. Implement bank portal MFA (hardware token or mobile app push) and remove shared, generic AP logins.

Practical implementation at a clinic level:

  • Enroll the AP team and finance approvers in the bank’s highest‑assurance MFA option (hardware token or authenticator app). Treat push/SMS differently: NIST guidance favors stronger authenticators and careful configuration3.
  • Assign named accounts per approver; disable generic accounts and force unique logins.

Step 3 — Work with the bank: dual approval and ACH return limits

Banks and regulators expect institutions to manage ACH risk through vendor verification and authentication controls; examiners’ guidance on ACH risk management covers expectation of processes to identify and mitigate ACH fraud4. Ask your bank to enable the following features:

  • Dual ACH approval (two people must approve on the bank portal for transactions over your threshold).
  • Vendor positive pay / ACH blocks for new payees until verified.
  • Velocity and daily limits on outbound ACH items tied to roles.

If your current bank product cannot enforce dual approval at the portal, require that all ACH files be uploaded to a bank staging area where bank personnel or an automated rule enforces a second sign‑off.

Detection & reporting — escalate fast and use official channels

If your clinic is targeted, escalate to an incident response workflow immediately and file with IC3; the FBI recommends early reporting because law enforcement and banks can sometimes halt or trace funds if notified quickly1. We recommend including our /services/incident-response-retainer-services/ when you need a retained IR partner who understands healthcare operations and confidential reporting.

A short decision table for a Fresno clinic AP team

SituationImmediate action (0–2 hours)Who calls bankDatapath short‑term fix
Unverified vendor bank change request via emailDo not pay; call vendor on known number; require signed W‑9 + vendor change formAP manager (finance lead) and bank fraud deskPut the payment on hold; implement dual approval in AP system
Alert that employee clicked a phishing linkDisconnect affected device; reset credentials; preserve logsIT + Datapath IR if retainedBlock compromised account, require MFA re‑enrollment
Large ACH initiated and unrecognizedFile IC3 complaint; freeze outgoing ACH if bank canCEO/Finance + bank fraud teamEscalate to IR retainer and legal

What good looks like — example technical stack we deploy

  • Banking portal accounts with hardware tokens for signatories.

  • AP system (ERP) configured for two approvers and immutable audit trail.

  • Email protections: DMARC, DKIM, SPF enforcement plus display‑name anomaly detection.

  • Vendor positive pay / ACH filters at the bank.

  • We bundle these with a co‑managed model or full managed cybersecurity delivery through our /services/managed-cybersecurity-services/ and /services/co-managed-it-services/ offerings.

Common buyer question: Will MFA break our ability to pay vendors quickly?

We hear this a lot. The operational design is to keep normal payments fast for trusted, pre‑verified vendors while gating new vendors and account‑change requests. With a dual‑control workflow and bank enforced approvals, the typical delay for a new vendor is 24–48 hours — usually acceptable to vendors when you explain the verification steps.

Implementation checklist (30–60 day playbook)

  • Day 0–3: Freeze all ACH scheduling for unfamiliar vendor‑change emails; publish the new SOP.

  • Day 4–10: Enroll approvers in MFA; remove shared logins.

  • Day 10–20: Configure AP system for dual approval and audit logging.

  • Day 21–30: Work with bank to enable vendor positive pay / dual bank approvals.

  • Ongoing: Monthly payment drill and 6‑month tabletop BEC response.

  • Bullet list: immediate operational items

    • Stop single‑channel approvals (email alone).
    • Require call verification to published vendor numbers.
    • Revoke shared AP logins; require unique accounts.
    • Enroll in bank MFA and request dual approval features.

FAQs buyers ask (real questions AP/finance teams in Fresno ask us)

Q: How do we balance speed vs control when payroll and vendor payments are time‑sensitive?

We keep payroll streams separate from discretionary vendor ACH. Payroll uses a hardened, whitelisted vendor file with pre‑approved signatories; vendor‑change requests go through the dual‑control route.

Q: If the bank says it can’t do dual approval, what then?

Move to a bank product that supports it or use a third‑party payment approval gateway that inserts an approval step. At minimum, require an out‑of‑band confirmation (phone call to a known number). Regulatory and examiner guidance for retail payments and authentication emphasizes that institutions must have risk management controls and authentication practices appropriate to the risk — banks are expected to offer controls or document compensating controls67.

When to involve Datapath

If you want help building these controls while minimizing operational friction, our co‑managed teams handle the technical tasks and policy work alongside your finance team. We often pair this work with an incident response retainer and ongoing security awareness training to stop credential theft at the source: our /services/security-awareness-training-services/ plus /services/incident-response-retainer-services/ packages are typical for clinics that process ACH payments.

Closing: A practical five‑minute test you can run today

  1. Pick the next three ACH payments scheduled.
  2. For each, verify the vendor bank details via a phone call to the vendor’s published phone number.
  3. Confirm the caller ID / email match the records; if any mismatch, halt the payment and escalate.

This small test takes five minutes and will reveal whether your workflow relies on brittle email approval.

If you’d like hands‑on help in Fresno, book an advisory with our local team to run an ACH workflow assessment and quick hardening plan — we design the policy, enforce it in your AP system, and coordinate the bank features necessary to make the control durable (/contact/).

1
2
3
5


Need a partner for this work? Explore Datapath’s managed IT services or contact our team.

Footnotes

  1. Business Email Compromise: The $55 Billion Scam 2 3

  2. CISA Releases Guidance on Credential Risks Associated … 2

  3. NIST Special Publication 800-63-3 2 3

  4. FFIEC Issues Guidance on Authentication and Access to … 2

  5. Multi-Factor Authentication | NIST 2

  6. Automated Clearing House Activities: Risk Management …

  7. Financial Privacy Rule

See also

Disclaimer: This blog is intended for marketing purposes only, and nothing presented in here is contractually binding or necessarily the final opinion of the authors.

Need a practical roadmap for regulated-industry IT performance?

Datapath can benchmark your current model and define the next 90 days of high-impact improvements.

Book a Consultation