Rapid growth, evolving regulations and rising competition can pull fintech companies in every direction. Wipfli helps you scale strategically while managing risk and complexity.

New fintech opportunities
New fintech opportunities

A new executive order modernizes regulations, reduces friction, encourages collaboration and more.

Why Wipfli?

Reach out to our team

Pressure to deliver growth can expose gaps in compliance, operations and talent. Access the experience and support needed to build a stronger, more scalable business.

Perspective changes everything.

Receive timely industry developments, regulatory changes and other news impacting your success.

Insights and resources

  • A middle aged woman working on digital tablet.

    ARTICLE

    Revenue leakage in healthcare: How to find and prevent it

    Healthcare organizations continue to face mounting financial pressure. Labor costs remain elevated, reimbursement uncertainty persists and leaders are expected to invest in technology, workforce, compliance and patient or resident experience — often with limited resources. In response, many organizations focus on growth initiatives. But before looking outside the org for growth, healthcare leaders should prioritize identifying and preventing revenue leakage that is damaging their bottom line. Whether revenue leakage stems from denied claims, underpayments, documentation gaps, billing inefficiencies, reimbursement opportunities, occupancy challenges or operational breakdowns, the result is the same: Financial performance suffers. For organizations operating on narrow margins, small inefficiencies can create significant financial impact over time. What is revenue leakage in healthcare? Revenue leakage occurs when an organization fails to collect all the money it is owed for services provided. These losses can occur at any point in the revenue cycle, from patient registration and eligibility verification to clinical documentation, billing, collections and payer reimbursement. Revenue leakage often results from multiple small breakdowns across departments and processes. A registration error, missed charge, coding issue, delayed claim submission or overlooked payer underpayment may seem minor on its own. Collectively, however, these issues can significantly reduce margins, delay cash flow and limit a healthcare provider’s ability to invest in patient care, technology and workforce needs. Revenue leakage goes beyond claim denials While claims denials are a significant form of revenue leakage, there are other causes of lost revenue, including: Underpayments Inaccurate coding Incomplete charge capture Staffing shortages that prevent services from being delivered Inefficient workflows Where does revenue leakage occur in healthcare? Many leaders assume financial performance challenges stem from a single issue. In reality, revenue leakage often occurs through a series of small breakdowns across clinical, operational and financial functions. Mistakes that can lead to revenue leakage include: Patient registration, eligibility and authorization Errors in patient registration and insurance information can lead to claim denials, delayed payments and lower reimbursement levels, creating avoidable revenue leakage throughout the revenue cycle. Clinical documentation, coding and charge capture Incomplete clinical documentation, coding inaccuracies and missed charges can prevent organizations from collecting all the money they are owed for services performed. Even small documentation and charge capture mistakes can result in underpayments, claim denials or missed reimbursement opportunities. These errors can contribute to significant revenue leakage over time while increasing compliance and audit risks. Claims and denials Claims that are denied or paid below expected reimbursement levels often require significant time and resources to investigate, appeal and resolve, reducing overall revenue and increasing administrative burden. Payer reimbursement and underpayments Organizations may fail to capture all available reimbursement due to overlooked payer requirements, incomplete charge capture, unclaimed supplemental payments or a lack of processes to identify and pursue eligible revenue opportunities. Billing, accounts receivable and collections Inefficient workflows, staffing constraints or process bottlenecks can slow claim submission and collections efforts, extending the revenue cycle and negatively impacting cash flow. Operational inefficiencies Poor workforce planning, underutilized staff or scheduling inefficiencies can increase labor costs while limiting productivity and operational performance. In senior living and post-acute care settings, delays in admissions, prolonged vacancy periods or barriers in the move-in process can reduce occupancy rates and result in lost revenue opportunities. Lack of visibility into operational performance When data is fragmented across departments or systems, leaders may struggle to identify emerging issues, track key performance indicators or understand the root causes of declining financial performance. Individually, these issues may appear manageable. Collectively, they can represent meaningful lost revenue and reduced financial flexibility. How can you identify leakage in healthcare? Revenue leakage occurs across multiple departments, not just financial. Because of that, organizations must conduct a comprehensive assessment of operational, clinical and revenue-cycle performance to identify where revenue is being lost. Healthcare organizations should evaluate: Claim denial trends: Analyze denial rates, denial reasons and appeal outcomes to identify recurring issues and process gaps. Registration and eligibility accuracy: Review patient registration errors, insurance verification processes and authorization compliance to uncover front-end breakdowns that lead to reimbursement challenges. Clinical documentation quality: Assess documentation completeness and accuracy to determine whether services are being fully supported for coding and reimbursement purposes. Coding and charge capture performance: Look for coding inconsistencies and mistakes and missed charges that may be reducing reimbursement. Payer reimbursement patterns: Compare expected and actual reimbursement amounts to identify underpayments or missed payment opportunities. Accounts receivable aging: Monitor aging receivables, collection timelines and outstanding balances that may indicate process inefficiencies. Operational and workforce metrics: Evaluate productivity, staffing utilization, scheduling patterns and workflow bottlenecks that may be contributing to financial inefficiencies. Occupancy and admissions performance: For senior living and post-acute organizations, review occupancy trends, move-in timelines and admission conversion rates to identify lost revenue opportunities. Key performance indicators (KPIs): Track metrics such as clean claim rates, days in accounts receivable, denial rates, net collection rates, case mix index and reimbursement per service line. Data visibility and reporting capabilities: Determine whether leadership has timely access to accurate, actionable information that supports informed decision-making. How can healthcare organizations prevent revenue leakage? The highest-performing healthcare organizations do more than recover lost revenue. They create systems that consistently protect revenue across operations. By focusing on these three high-impact areas, healthcare leaders can often uncover meaningful financial improvements while also strengthening long-term operational performance. 1. Strengthen the front-end processes that influence financial performance Financial outcomes are often determined long before payment is received. For hospitals and Federally Qualified Health Centers (FQHCs), this may include patient access, eligibility verification, documentation and coding processes. For senior living organizations, it may involve occupancy management, admissions workflows and resident billing practices. Regardless of the setting, breakdowns early in the process can create downstream financial challenges that are difficult and costly to correct later. To strengthen front-end processes, organizations should start by mapping key workflows from initial patient or resident contact through reimbursement. This can help identify bottlenecks, handoff issues and areas where errors commonly occur. Leaders should also establish standardized procedures for registration, insurance verification, authorizations, documentation and coding to improve consistency across departments. Regular staff training is equally important. Front-line employees often have a direct impact on revenue capture, yet they may not fully understand how documentation errors, missing information or workflow delays affect reimbursement. Ongoing education can help reduce mistakes and strengthen accountability. Organizations should also monitor performance metrics such as registration accuracy, clean claim rates, coding accuracy, authorization compliance and admission-to-service timelines. Tracking these indicators allows leaders to identify problems early and address issues before they result in denials or delayed payments. Organizations that establish clear processes, accountability and performance monitoring are better positioned to reduce downstream revenue loss. 2. Improve operational visibility and consistency Improved visibility and consistency allow organizations to identify issues earlier and make more informed decisions. However, many organizations struggle to identify where financial performance is being impacted because data is fragmented across departments. Leaders can improve operational visibility by: Breaking down departmental data silos: Finance, clinical, operational and administrative teams should have access to consistent data and clearly defined metrics that align with organizational goals. Developing dashboards: Gain real-time or near-real-time insight into key performance indicators with dashboards. Rather than reviewing financial results after issues occur, leaders can monitor trends such as denial rates, labor costs, occupancy levels, accounts receivable that are beyond the due date and productivity measures as they happen. Maintaining consistency: Establishing routine performance reviews, department scorecards and leadership reporting helps ensure issues are identified and addressed promptly. Cross-functional meetings that bring together operational and financial leaders can also improve collaboration and deepen understanding of how day-to-day decisions affect overall financial performance. Leaders should also focus on understanding how operational decisions influence financial outcomes. Workforce utilization, clinical productivity, documentation quality, reimbursement performance, occupancy trends and patient service utilization all contribute to overall margin performance. 3. Identify and recover missed revenue opportunities The back end of the financial process often reveals opportunities for improvement. Denials, underpayments, aging receivables, reimbursement variances, collection challenges or billing delays frequently point to broader process issues that can be corrected. Organizations should conduct regular reviews of denial trends, payer performance and reimbursement outcomes to identify patterns that may be limiting revenue collection. Rather than addressing individual denials one at a time, leaders should analyze root causes to determine whether recurring issues stem from documentation gaps, coding errors, authorization problems or workflow inefficiencies. In addition, finance and revenue cycle teams should periodically evaluate accounts receivable, payer contracts and collection processes to identify underpayments or reimbursement opportunities that may have been overlooked. For senior living organizations, this may also include reviewing occupancy trends, move-in conversion rates and resident billing processes to identify opportunities to improve financial performance. Technology and analytics tools can also play an important role by helping organizations identify anomalies, monitor trends and prioritize areas requiring attention. However, the greatest value often comes from combining data analysis with cross-departmental collaboration to address issues in underlying processes. Organizations that regularly review financial performance data and investigate root causes of revenue leakage are often able to recover revenue while strengthening future performance. How Wipfli can help Wipfli has a team of professionals dedicated to helping healthcare organizations achieve their financial goals. We can help your organization identify where it is leaking revenue and develop processes to prevent it. Start a conversation . Capitalize on revenue capture opportunities Learn more Webinar: Find hidden revenue without adding services or staff AI in healthcare finance: Practicality over hype, strategy over speculation 2026 healthcare industry outlook: Get ready for seismic disruption

  • Stock photograph depicting a professional team meeting in an office environment.

    ARTICLE

    A SOC 2 report can be a launching pad for FedRAMP certification

    Healthtech companies, SaaS organizations and other technology businesses that hold a current SOC 2 Type II report have a potential new market to tap into. Revisions to FedRAMP have created an easier path for selling cloud service offerings (CSOs) to federal agencies. Continue reading to learn more about the FedRAMP program and the new, lower-resistance road to certification available to companies with a SOC 2 report. What is FedRAMP? The Federal Risk and Authorization Management Program is the federal government’s standardized approach for assessing, authorizing and monitoring cloud service offerings used by federal agencies. Cloud service providers (CSPs), including SaaS companies with cloud-based software, that want to sell their products and services to federal agencies via the FedRAMP marketplace need some level of FedRAMP certification (formerly known as authorization) before their CSO can be listed. FedRAMP uses the NIST SP 800-53 security controls and includes parameters and guidance that go above the NIST baseline to address the unique elements of cloud computing. How is FedRAMP changing? To streamline certification, increase automation and reduce compliance friction, FedRAMP is transitioning from the legacy Rev. 5 model to FedRAMP 20x . As part of the transition, FedRAMP is also shifting away from the low, moderate and high impact-level terminology and moving to a class-based certification structure. The certification classes are: Class A is a new entry-level certification designed to help eligible providers enter the FedRAMP marketplace. Class B generally aligns with lower-risk use cases and limited or departmental adoption. Class C is intended for broader agency use cases, including more sensitive or mission-critical workloads. Class D is expected to support the highest-risk or most sensitive use cases. A SOC 2 report can serve as a foundation for FedRAMP Class A FedRAMP 20x allows companies to use a qualifying SOC 2 Type II report as proof of the security maturity needed for Class A certification. Class A does not have the agency sponsorship requirement. In the past, many SaaS providers and healthtech organizations struggled to find an agency willing to sponsor them, creating a major roadblock to getting their products listed on the marketplace. The SOC 2 option creates an easier path to certification. Businesses need to understand that Class A certification is not a permanent solution. It gives your business a two-year window to begin assessing your security framework against Class B, C or D standards. Class A is only authorized for low-risk deployments. The value of FedRAMP Class A certification Think of FedRAMP Class A as a way to test the federal market before making the full investment required for higher FedRAMP certification levels. If you are unsure whether there is federal demand for your products, Class A offers a chance to assess interest levels. It will also give your business time to determine which product or security improvements may be needed to support federal agency needs. Easing into FedRAMP via Class A certification will allow your business to: Test demand for your cloud offering within the federal market. Increase visibility by appearing in the FedRAMP marketplace. Validate how well your CSOs fit the federal market before making larger compliance investments. Build a roadmap toward higher certification levels based on actual customer interest. What federal opportunities exist for healthtech companies? For healthtech companies, being able to sell their CSOs to federal agencies opens the potential to land significant contracts. A notable example is the Department of Veterans Affairs (VA). Selling patient monitoring tools, telehealth platforms, medical imaging archiving systems or other cloud-based products to the largest integrated healthcare system in the U.S. could be very lucrative. But handling VA data requires FedRAMP certification. Instead of delaying market entry to pursue a more rigorous FedRAMP certification, your organization can use Class A to begin engaging the federal marketplace faster. Use your two-year window to prepare for a Class B, C or D certification. Other federal agencies that are potential customers for FedRAMP-certified healthtech companies include HHS and CMS. What are the SOC 2 requirements to secure FedRAMP Class A? A SOC 2 Type II report can support the Class A path, but you will still need to meet other FedRAMP-specific requirements. A provider cannot simply submit any SOC 2 report and assume it will be accepted. To use SOC 2 for Class A , companies should be prepared to provide: A complete SOC 2 Type II report that was completed in the last 12 months Any bridge or gap letters Verified audit engagement documentation An estimated schedule for the next SOC 2 report Supplemental compliance evidence (if applicable) Your SOC 2 scope does need to include cloud security. There are other FedRAMP Class A requirements, including relevant Key Security Indicators , which address areas such as vulnerability detection, incident communication, network traffic restrictions, service configuration and more. What are the steps to getting FedRAMP Class A certification? The path to Class A is relatively short compared to higher FedRAMP certification classes. However, it still requires planning, evidence collection and implementation of FedRAMP-specific requirements. Companies should consider the following steps: Confirm eligibility: Verify that your organization holds a current SOC 2 Type II report. Validate the scope of your SOC 2 report: Make sure the SOC 2 report covers the cloud service offering you want to submit for FedRAMP Class A. If the scope is too narrow, outdated or misaligned with the product being submitted, you may need to remediate gaps or complete additional assessment work. Assemble your evidence package: Gather the complete SOC 2 Type II report, any bridge or gap letters, verified audit engagement documentation, the estimated schedule for your next SOC 2 report and any supplemental evidence that helps show how your controls align with FedRAMP expectations. Implement the required FedRAMP controls: Implement the necessary policies, procedures and controls to meet the mandatory FedRAMP 20x rules and key security indicators required for Class A. Prepare machine-readable certification materials: FedRAMP 20x emphasizes more structured, machine-readable evidence. Companies should expect to modernize how they manage compliance documentation and move away from manual, screenshot-heavy evidence models. Submit through program certification: Apply through the FedRAMP program certification path. How can businesses move to a higher FedRAMP certification? If your business decides FedRAMP certification is a long-term strategy, it will need to advance to one of the more rigorous certification levels. Here are some steps your business can take to prepare for Class B, C or D certification: Adopt a broader control baseline: Higher classes require more rigorous security controls and more extensive evidence. The organization will need to mature its control environment beyond what was necessary for Class A. Prepare for more detailed assessment expectations: Companies moving to Class B, C or D should be ready for a more comprehensive review of their cloud security controls. Strengthen automation and evidence collection: FedRAMP 20x places more emphasis on machine-readable evidence and automation. Providers may need to modernize their governance, risk and compliance processes so evidence is continuously available and easier to validate. Build ongoing certification processes: FedRAMP required companies to demonstrate that controls continue to operate effectively over time, not just at a single point in time during an assessment. Align the certification level to the target market: Class B may be appropriate for more limited or departmental use cases, while Class C and D may be needed for broader, more sensitive or mission-critical federal deployments. Companies should align their target class to the agencies and use cases they want to pursue. Plan early: The two-year Class A window can move quickly. Providers should use the time to validate federal demand, prioritize gaps and develop a realistic roadmap for reaching the next certification class. CSPs that pursue Class B or C have a choice between the agency sponsorship route or the new program certification route without a sponsor. All Class D certifications require a sponsor. Read more Which AI risk framework is right for your organization? Tech companies experience thousands of attempted cyberattacks each day. Are your defenses ready for 2026? SOC audit timing: When to schedule your SOC 1 or SOC 2 exam

  • Bank on Wipfli podcast: Programmable money and the future of banking

    PODCAST

    Bank on Wipfli podcast: Programmable money and the future of banking

    In this episode of Bank on Wipfli, host Robert Zondag sits down with Justin Seidl, chief technology officer at Coinbax, to discuss the growing role of programmable money and stablecoins in financial services. Together, they explore how financial institutions can safely participate in this emerging payment ecosystem, including: How to balance the speed and efficiency of blockchain-based payments with the trust, controls and compliance frameworks customers expect. Why stablecoins should be viewed as a payment mechanism rather than an investment vehicle. How financial institutions can apply compliance checks, escrow functionality and risk controls to stablecoin transactions. Emerging use cases for programmable money, including treasury management, cross-border payments, investor funding, invoice reconciliation and automated escrow transactions. Why major core providers such as Fiserv, Jack Henry and FIS are investing in stablecoin infrastructure. Learn more Risk Roundtable: Navigating SAR investigations and regulatory expectations with confidence For financial institutions, the control environment is no longer just an audit issue Stablecoin compliance: What you need to know about the GENIUS Act and PPSIs