Do Your Due Diligence Before Hiring For Financial Positions

Adam Gentile, 39, from Massachusetts, recently pled guilty to embezzling funds from two medical practices from at least 2015 to 2024.

Around 2014, Gentile was hired as an administrative assistant at an unnamed medical practice in Massachusetts. He was promoted to office manager and was given the responsibility of processing payroll and overseeing other recordkeeping.

Beginning in 2015, he embezzled more than $4.5 million from the practice by issuing himself extra paychecks. Some were labeled as "bonuses". He also paid off personal credit cards via the medical practice's bank account.

In 2021, he was hired as office manager at a second unnamed medical practice. His duties also included payroll processing. From 2021 to 2024, he executed a similar scheme by issuing himself extra payments, which he sometimes called "bonuses." Gentile then used the company's bank account to pay off personal credit cards, purchase and upgrade his home, and put money into a side business he ran. This scheme resulted in an embezzlement of $3.3 million.

Source: https://www.justice.gov/usao-ma/pr/sudbury-man-pleads-guilty-carrying-out-78-million-embezzlement-scheme

Commentary

The total cost of the embezzlement for both employers in the above case is $7.8 million. A trusted financial position of authority was utilized twice to carry out a multi-year embezzlement scheme by the same employee.

A striking element of the embezzlement scheme was that the same man carried out the same scheme at a second employer. He even went as far as labeling the additional paychecks as "bonuses", not altering his tactics at all.

This highlights the need for quality hiring and vetting practices for financial positions. Reference checks are not simply administrative box checking tasks. They are a risk control, especially for vulnerable healthcare employers.

Failed attempts at verbal reference checks, written references that only confirm dates of employment, or a background check that stops at criminal record searches are not enough to help protect healthcare employers from fraud.

When hiring for financial roles, healthcare employers should:

· Make their best attempt to speak directly with prior supervisors, specifically asking about the financial duties the employee performed and whether they were satisfactory

· Require the candidate to list every employer for whom they held a financial position

· Run a credit check consistent with state law

· Utilize a third-party verification service

· Ask targeted behavioral questions to uncover instances of fraud

· Document every step of the hiring and vetting process to show reasonable diligence

The final takeaway is hiring practices for healthcare employers must be thorough and accurate to help avoid the risks of a bad hire.

Finally, your opinion is important to us. Please complete the opinion survey:

Product

Articles

Do Your Due Diligence Before Hiring For Financial Positions

A Massachusetts man pled guilty to embezzling $7.8 million from two different medical practices using the same scheme. We discuss the importance of due diligence when hiring and how it can help avoid the fraud risks.

The Multiple Risks From "Boss Scams": More Than Just Lost Revenue

Executive impersonation is a common social engineering tactic used by cyber criminals. We comment on protecting the tricked employee from unfounded accusations while protecting the organization from loss.

Novel AI Malware Presents New Challenges And Requires More From Employers

Cybersecurity experts have identified detection gaps with AI-generated malware. We discuss what makes AI malware unique and how it evades discovery.

Requiring "Full Recovery" For Return-To-Work Increases EPL Risk

The EEOC sued a New Mexico hospital for allegedly requiring an employee to be fully recovered before returning to work. We examine this case and the discrimination risks of full recovery policies.

AI-Assisted Fraud Is On The Rise: What Can Your Organization Do?

Multiple cybersecurity reports indicate AI scams are increasing in number. Knowing about these threats is not enough to stay safe, so we discuss the threats and what organizations can do to boost their cybersecurity.