Blog

The Nursing Home Billing Clerk Who Turned Resident Refunds Into a $154,000 Kickback Loop

THE NEWS IN BRIEF

On July 20, 2026, New York Attorney General Letitia James announced the arrest of Tammy Echols, 56, a former Senior Account Specialist at St. John’s Home, a Rochester nursing facility, on charges of Grand Larceny in the Second Degree and Scheme to Defraud in the First Degree, according to the Attorney General’s press release. Investigators with the AG’s Medicaid Fraud Control Unit allege that between January 2023 and August 2025, Echols used her billing role — which included issuing refund checks when residents or their families overpaid facility costs not covered by Medicaid — to write $154,525.99 in fraudulent refund checks to a local florist, a bakery, and a construction contractor, among others, all businesses or associates to whom she personally owed money. According to Spectrum News reporting, the recipients kept a small handling fee and then funneled most of the money back to Echols. She was arraigned before Rochester City Court Judge Latoya Lee on July 20 and faces up to 15 years in prison if convicted. St. John’s told reporters it “had the appropriate best practices in place during this time and has since added additional oversight measures,” and that no resident or family member suffered a financial loss. The charges are accusations, and Echols is presumed innocent unless and until proven guilty.

THE CONSULTANT’S VERDICT

Strip away the florist and the bakery and what you are left with is one of the oldest control failures in the book: the same person who calculated what a resident was owed also had the authority to decide who got paid and to cut the check. That is not a sophisticated fraud. It is a segregation-of-duties gap wide enough to drive $154,000 through, one refund at a time, for two and a half years.

Look at the mechanics again. A refund check tied to a nursing home resident’s account was paid out to a construction contractor. That is not a subtle anomaly buried in a general ledger — it is a payee name that does not match the resident or family it was supposedly refunding. Any control that compared refund payees against the resident or responsible-party name on file would have flagged every single one of these transactions on day one. The fact that it did not happen for 31 months tells you this wasn’t a control that failed under pressure; it was a control that was never built.

The fraud triangle here is straightforward once you see it. Opportunity was structural: one employee held both the calculation and the disbursement steps of the refund process, with apparently no independent reconciliation of resident trust accounts against checks issued. Pressure is implied by the scheme’s own design — Echols was reportedly routing money to people and businesses she personally owed, which points to financial obligations she needed to service. Rationalization in cases like this is usually some version of “I’ll put it back” or “the facility won’t miss it” — both comfortable lies that survive exactly as long as nobody checks the ledger.

St. John’s statement that it “had the appropriate best practices in place during this time” deserves scrutiny rather than acceptance. A best-practice control environment for a facility holding resident trust funds does not let 900-plus days of misdirected refunds pass unnoticed. It took an external Medicaid Fraud Control Unit investigation to surface this, not an internal audit finding, not a bank reconciliation exception, not a supervisor’s review. That is the real finding here, and it is one every audit committee sitting on custodial or trust funds — resident deposits, client money, escrow, employee benefit contributions — should take personally.

The regional angle is less about geography here than about the asset class. Custodial funds held on behalf of a vulnerable population — residents, patients, beneficiaries, minors — carry a fiduciary weight that ordinary operating cash does not. Financial centers in the Gulf that regulate client money and trust accounts, such as the DFSA in Dubai and the CBB in Bahrain, require strict segregation between the custodian of funds and the party authorizing disbursements, precisely because the account holder cannot easily monitor their own balance day to day. A nursing home resident trust fund deserves the same discipline as a regulated client-money account, even though it will never be examined by a financial regulator. The IIA Global Internal Audit Standards address this directly under the safeguarding-of-assets domain: internal audit is expected to evaluate whether controls over the custody and disbursement of assets held on behalf of others actually operate as designed, not simply whether a policy exists on paper. Here, the policy apparently existed. The operating control did not.

WHAT YOU SHOULD DO MONDAY MORNING

  1. Separate refund calculation from refund disbursement. The person who determines a resident, client, or employee is owed a refund should never be the same person who selects the payee and issues the check. If your organization cannot staff this split, route every refund through a second approver before it leaves the building.
  2. Hard-match every refund payee against the account holder of record. Build a control — manual or system-enforced — that flags any refund, reimbursement, or overpayment check issued to a payee whose name does not match the resident, client, or responsible party on file. A refund to a bakery or a contractor should never clear without an explicit, documented exception approval.
  3. Reconcile custodial and trust accounts monthly, independently of the person who manages them. If nobody outside the billing function is reviewing resident trust account activity against supporting documentation, you have no detective control at all — only the hope that nothing goes wrong.
  4. Run a two-year look-back on refunds issued to non-account-holder payees. Pull every refund or overpayment check from custodial accounts over the trailing 24 months and check the payee against the resident, client, or employee it relates to. This is the single fastest way to find out if this scheme, or one like it, is already running in your organization.
  5. Add positive-pay or payee-verification controls at the bank level for custodial accounts. Most banks offer payee-match services that reject checks written to names outside an approved list. For accounts holding other people’s money, this is a low-cost control with an outsized payoff.

DON’T WAIT FOR THE HEADLINE TO BE ABOUT YOU

This exact scheme is running right now inside facilities, funds, and finance functions whose leaders assume their staff are too trusted, too long-tenured, or too closely supervised for it to happen. It rarely takes a criminal mastermind — it takes one person with unchecked authority over disbursements and a personal debt they need to service quietly. If you want an honest, confidential look at whether your organization’s custodial accounts and refund controls would actually catch this before a regulator does, message me directly on WhatsApp for an independent internal audit or fraud-risk health check — before a fraudster finds the gap first.

Message me on WhatsApp for a confidential consultation