Photo via 11Alive Atlanta
According to 11Alive Atlanta, a former CPA has been sentenced to prison time following conviction for embezzling approximately $5 million from Children's Healthcare of Atlanta (CHOA), one of the region's largest pediatric medical systems. The fraud scheme involved sophisticated manipulation of vendor payment systems, highlighting vulnerabilities in financial controls at even well-established healthcare organizations.
The criminal method was notably direct: the perpetrator gained access to Children's systems and altered bank account information for an existing vendor in the accounts payable system. By redirecting ACH (Automated Clearing House) payment instructions to a fraudulent account, the individual successfully diverted $5.3 million in wire transfers that were intended for legitimate vendor payments. The scheme exploited trust in established payment protocols within the hospital network.
This case underscores ongoing cybersecurity and internal control risks facing Atlanta's healthcare sector, particularly as institutions process millions in vendor payments annually. For local healthcare administrators and finance leaders, the incident serves as a cautionary reminder of the importance of multi-factor authorization, segregation of duties, and regular audits of payment systems—especially for high-value transactions and vendor account changes.




