Episode 555 ·
Exposing Fraud In The Healthcare Space with Dale Clay, CTO at ProviderTrust
Today we’re talking to Dale Clay, CTO at ProviderTrust; and we discuss the prevalence of medical malpractice; how fraud is exposed in the healthcare space; and why leading others starts with leading yourself.
All of this right here, right now, on the Modern CTO Podcast!
Check out more about Dale and ProviderTrust at https://www.providertrust.com/!

About Dale Clay:
Dale Clay serves as the Chief Technology Officer of ProviderTrust, a Nashville-based healthcare data and technology company with the primary offering of best in class compliance monitoring and intelligence. He was been with the company for over 8 years and currently leads its data and technology team of 33 individuals. During his tenure, he has spearheaded ProviderTrust’s software development strategy and pioneered combining data science and fraud waste and abuse patterns which have now been adopted in the healthcare technology market. Dale holds a Bachelor of Business Administration in Music Business from Belmont University.
About ProviderTrust:
ProviderTrust empowers a safer, smarter healthcare for patients, providers, and payers. Founded in 2010 in Nashville, TN, ProviderTrust creates comprehensive solutions to solve complex problems to make healthcare data meaningful and actionable. Our mission is to create a safer healthcare for everyone.
ProviderTrust partners with HR, Compliance, and Provider Operations teams to continuously monitor healthcare populations to identify license, credential, compliance, and payment eligibility issues before they impact patients. Our solutions monitor employees, vendors, provider networks, licenses, credentials, and more for OIG and state Medicaid exclusions, sanctions or disciplinary actions, license expirations or suspensions.
ProviderTrust solutions combine an intuitive user experience with advanced data matching algorithms and seamless integrations to continuously identify and verify compliance issues in the optimal workflow, such as an HRIS or claims processing system.
Transcript
(Intro Narrator at 00:00:02) Today, we're talking to Dale, CTO at ProviderTrust, all about how they're exposing and stopping medical malpractice. You're listening to the Modern CTO podcast.
(Joel Beasley at 00:00:17) What type of music do you make?
(Dale at 00:00:19) It's like neoclassical orchestral film type of music.
(Joel Beasley at 00:00:22) Okay.
(Dale at 00:00:23) Not a composer or an orchestrator by training. I just fell into what sounds good, and I'm drawn to orchestral. If you want to contrast folks like Hans Zimmer and John Williams, John Williams is your classic orchestrator. He uses the symphony the way that the symphony was created to be used. Somebody like Hans Zimmer says, that's cool. I like that. I like the sound that it produces. But what if we have a section of just Juno synthesizers right in the middle? You're kind of combining some of the more modern musical elements with some of the more traditional orchestral elements, mush them together, and produce things like the Inception score.
(Joel Beasley at 00:00:59) Yes. Which is a good point.
(Dale at 00:00:59) A good point.
(Joel Beasley at 00:01:00) Yes. How did you end up not in music for your career?
(Dale at 00:01:04) Well, there's not a lot of money in film scores when you're first starting out. You're pretty much just taking what people throw at you. So I had to get a real job while I was doing that. And first job out of college was for a brand new startup called eSpaces, which is a coworking facility based out of Belle Meade. And I started the day they opened as essentially their first employee. And what I found really quickly is that if I didn't want to show up at 7 a.m. and leave at 7 p.m., I needed systems to work for me. I needed a way to track who was coming in and out of the space and how to translate that into billing. I needed a way to collect booking requests online. And so really quickly, what I gravitated towards is helping them build out their first iteration of technology solutions to operate their space, essentially automating all the things that I was doing manually. My phone was ringing all the time. I didn't want my phone to ring all the time. So I began to work with dev shops and build out things like calendar booking applications. And so I was there gathering the requirements from myself mostly, but also from the users, turning those into technical documentation, handing them off to the developers, being able to kind of go back and forth with them, iterate on it, and then test it and make sure it works, deploy it, and then rinse and repeat. And I did that a few times, decided I liked that. So I found a product management job, and I took a chance on that. That was a year-long season. I would probably categorize that as one of the harder seasons. It was a tough company to work for and kind of one of those traditional, like, toxic cultures that you—
(Joel Beasley at 00:02:53) I know exactly what you're talking about.
(Dale at 00:02:53) Yeah. So I learned a lot about myself. I learned a lot about the world and what I didn't want to do through that season. I think everyone should have a year that's like that, because it gives you lots of perspectives.
(Joel Beasley at 00:03:07) Oh, it does. Yeah.
(Dale at 00:03:08) And then from there, I went to ProviderTrust. I had met Chris Redditch, who was one of the co-founders. I had met Michael Rosen, his other co-founder, and I'd met several of the employees. And especially in contrast to the company I was working for, it's like, I think there's something different about this company and these people. I want to work with them. I don't really care that it's healthcare compliance, so to speak. Right? That's not the draw. The draw is the relationships, the people, the culture. And so that's kind of how I dove in there.
(Joel Beasley at 00:03:40) How did you actually, like, meet them?
(Dale at 00:03:43) Through eSpaces. They would come to eSpaces for their offsites. There was maybe 12 of them at that time.
(Joel Beasley at 00:03:50) And 12? There's like 100 and something now.
(Dale at 00:03:53) There's over 100 now. Yeah. Yeah. So it was a small group. So I pretty much met the whole company. I liked all of them because I was helping their day go well. I was seeing if they needed anything. So I got to know them. And especially when I am on that end of kind of a relationship, right, I'm there to make their day go well. And I had interacted with enough business leaders who treated somebody like me differently than the way that they treated their peers and their coworkers and the owner of the company.
(Joel Beasley at 00:04:25) I don't like those people.
(Dale at 00:04:26) That's what I concluded as well. And so ProviderTrust treated me the same way they treated everyone else. That stood out. Yeah. And so that was one of the many things that attracted me to the culture. That has stayed true throughout my whole tenure at ProviderTrust. It is truly a special place where I know that I am valued more than a bottom line or more than a fiduciary stakeholder. Right? I know that they hold my relationship, or our relationship, up as something that's important to them. Is that a good way?
(Joel Beasley at 00:05:00) Good culture.
(Dale at 00:05:01) That's right.
(Joel Beasley at 00:05:01) What problem are you solving?
(Dale at 00:05:03) Well, we're solving a lot of problems. I think the main problem that we're solving right now is kind of what we were alluding to earlier, which is, you know, when I started there were 15 people and now there's 110 people. We're trying to solve some pretty large problems in the marketplace. The problem I'm trying to solve internally is how to scale a high-performing engineering organization. It's one thing when you have seven developers and you can only work on one to two things at once. It's another thing to have what we have now, which is about five squad teams that are sometimes working on five different things in parallel and trying to identify that's okay. You can manage that many projects at once, but you need some really mature infrastructure and some mature communication. And so coming from kind of startup scrappy, let's just get something up and see if it works type of mindset and switching that over to a sort of a mature communication and a mature team dynamic. That's a very different thing.
(Joel Beasley at 00:06:01) Well, yeah. Well, and new things are immature by definition. Right?
(Dale at 00:06:05) That's right.
(Joel Beasley at 00:06:05) So you have to be in this hybrid mode of—you can't be in enterprise mode where everything's already known and all the processes are in place. You have to have some things that are mature, and then you have a whole spectrum of maturity across all your processes.
(Dale at 00:06:18) That's right. It's hard. It is. It is hard. We've got great people, and we hire specifically—
(Joel Beasley at 00:06:26) Mm-hmm.
(Dale at 00:06:27) —to bring in A players who are comfortable with unknowns. They're comfortable with ambiguity, and they're comfortable with being part of the solution and not just waiting for somebody to come up with the solution. So I'm really confident that we're going to get there. It doesn't make it easy as we're going through the growing pains. We kind of jokingly refer to this season as kind of our awkward teen years—
(Joel Beasley at 00:06:46) Yeah.
(Dale at 00:06:47) —as we're expanding. So technically, tech—that's kind of the people side of things. Technologically, the big problem that we're solving is how to take kind of our first iterations of products that were sort of built one by one iteratively to address specific problems in the marketplace. How do we take that and consolidate it down now into one unified platform? That's not exactly like the market-shaking innovation that's going to make headlines, but it is going to be critically important if we're going to scale from 100 employees to 250 employees, if we're going to double the number of providers and patients that we're serving over the next two years. We have to have a scalable platform. As it stands right now, we've kind of got what I think a lot of technology and software companies run into, which is kind of a disparate stack of technology that were built at different times using different technologies by different people. Looking across them, they all generally do the same thing. So we're taking all of those shared functions, those shared services, and we're now trying to consolidate it down into one platform, build it once and for all. That's the whole idea. But anyone who's done that migration knows that there's a significant amount of complications that come with that.
(Joel Beasley at 00:08:05) Do you have a coach?
(Dale at 00:08:06) What do you mean by coach?
(Joel Beasley at 00:08:07) Like someone coaching you through this that has gone through this before?
(Dale at 00:08:11) I do. A couple of years ago, we brought on a partner and investor. It wasn't a new investment round. They just bought out one of our previous investors, and the investment company is called Susquehanna. They're based out of Pennsylvania, and they've been a really helpful partner. They're playing kind of an advisory role, having helped companies go through this awkward teen stage many, many times before. And one of the things that they do is they connect key leaders with mentors. So actually, this morning, I met with the CTO mentor that they connected me with, who at age 33 was suddenly gifted 300 developers—
(Joel Beasley at 00:08:54) Yeah.
(Dale at 00:08:54) —as his first CTO role and had to figure out what it looks like to make all of that work together. And so he's been really helpful in helping me think through, here's where you are, here's where you want to get to, and so here's your next step. And a lot of it is organizational thinking. How do you build a team that is high functioning? How do you line up your accountabilities to make sure that the right folks are owning and thinking about the right things? And what we find, or at least what I've found in our team, in our department, is because we started small and we grew big so quickly, everyone kind of felt a fractional ownership five years ago, and fractional ownership doesn't scale. And so if every developer had a say in our architecture five years ago, that wasn't a problem because we could all fit in one room. Every developer can't have a say in architectural direction and vision. Today, that would be—that would be a stalemate.
(Joel Beasley at 00:09:44) Yeah. Chaos.
(Dale at 00:09:45) Chaos. And so disseminating down and clarifying who is in those ownership and accountability roles, clearly delineating who owns what so that folks can essentially focus and make gain momentum by making consistent progress on the thing that they are owning and pushing forward. That's really what the work that we've been trying to delineate is how to separate that out so that folks can just take their thing and run with it.
(Joel Beasley at 00:10:17) And then this whole organization, building all of this technology and growing all these people and figuring out all these systems and processes, why? What is the result of all of that?
(Dale at 00:10:27) Yeah. Sure. That's a good question. I mean, kind of taking a step back, ProviderTrust exists to help healthcare companies stay in compliance and optimize patient outcomes. It's kind of a corner of the healthcare universe that we've decided to specialize in. But the reality is there are a lot of bad actors that are in the healthcare industry today. And some of them are trying to commit fraud. Some of them are frankly just not good at their job. And they're abusing patients. They're swiping drugs. They're taking advantage of the system or the people involved in the system. And so the Medicare and Medicaid agencies have said, listen, we don't want any of these people that we've identified as fraudulent or abusive. We don't want them working for any company that is receiving taxpayer dollars. They don't get to participate in any program that we're funding. That's kind of the line in the sand they've drawn, and good for them. So they've built a list. They call it the exclusion list, and they have required anyone in the healthcare industry that's benefiting from the Medicare or Medicaid funding to check this list to make sure that none of those players are in the network. They're not employees. They're not referring providers. They're not vendors, et cetera, et cetera. The problem with that is that this list is now 300,000 rows long. That's a lot of names to check. If you're just Control-F-ing through an Excel file, it's pretty unwieldy pretty quickly. And the requirements are pretty stringent. You have to check this list every single month against your existing employees and any new employees that you've hired. For any medium- to large-sized organization, that quickly becomes a pretty impossible task unless you literally create an entire team and sometimes an entire department who is just focused on this. The other problem with this is the fact that there is no real standardization across these exclusion lists. So it's one thing if all 300,000 of those excluded records show up in one file, but they're spread out over 42 different files. And those 42 different files are in 42 different formats, and they have a data model that's completely separate and inconsistent. Within each one of those files, you also have different record-keeping patterns. For example, California has a list and they decide to store the business name in the last name column.
(Joel Beasley at 00:13:01) Mm-hmm.
(Dale at 00:13:01) And it's spread across 27,000 different records. If you want to clean that file up, you essentially have to go row by row and identify which one is a business, which one is a person. And sometimes they put both. And so then you have to parse out which one is the last name, which one is the business, and where does that belong. And so you begin to get a sense of sort of the state of this data. And so we take it upon ourselves to thoroughly cleanse that data, to standardize it, to consolidate it into one of those big files that we can take on that work. We'll load it into our system and then we'll take our client data and we'll compare their list of employees and providers and vendors against the list of 300,000 exclusions. And then we'll take on the extra work of actually proving the identity. So if we come up with potential matches, maybe two people share a similar name.
(Joel Beasley at 00:14:02) That's very common.
(Dale at 00:14:03) Very common. We'll run through the full investigation process and we'll definitively identify if those are a true match, if they actually are talking about the same person or vendor, or if it's just an incidental match.
(Joel Beasley at 00:14:18) Well, how much information do you get from the files? Do you get Social Security numbers and birthdays? Like, how accurate can you get with it?
(Dale at 00:14:25) So Social Security numbers, date of birth, and NPI are really—so NPI is the National Provider Identification Number.
(Joel Beasley at 00:14:33) Okay.
(Dale at 00:14:34) It's a publicly available identifier for anyone who's prescribing and referring.
(Joel Beasley at 00:14:39) Got it.
(Dale at 00:14:39) Right? That's kind of a shorthand way of thinking about it. Those are essentially the unique IDs that we run around with and that we want more than anything. In no scenario do we ever get social. That's PII. Even if the excluding agency has access to the social, they redact it. They remove it. So we never get social. We rarely get NPI and we inconsistently get date of birth. So even if an agency has access to date of birth, we don't actually get it all that often. So what we're given is primarily transient data, things like name and address. And if you've ever looked at personal data for any length of time, both of those things can be really unreliable.
(Joel Beasley at 00:15:29) You can get married.
(Dale at 00:15:30) You can get married. Your name can change. You can have nicknames. You can have a double name that gets sort of moved from double first name to double middle name to double last name, depending on how you store that data. You can have just plain old errors in data record keeping, so that the name could be misspelled. It could be inverted. There's lots of different ways that the name is unreliable. Same thing with address, people just move. And we hardly ever have to rely on the address because it is so unreliable. So very early on when we were trying to solve this problem, it was really like one hill after another that we had to come across. And so this is kind of the analogy I think about. When I was growing up, my brother and I collected baseball cards.
(Dale at 00:16:19) And we played this game. If you ever collected cards, you probably played it as well, where we would both get our books open and we'd say, okay, try to find the person that weighs the most. And so we'd flip through the card and we'd pick out, you know, Frank Thomas and somebody else, and we'd flip it over and look on the back where all the stats are. And you've got the weight and you've got the height and you've got the date of birth.
(Dale at 00:16:41) And so you can play that game, and then you can go into baseball stats. Who has the highest batting average? How many home runs? For pitchers, it's ERA, right?
(Dale at 00:16:50) So there's lots of different stats you can do. That game would be impossible to play if some cards had batting average and some cards didn't, if some cards had weight and some cards didn't. The game is only possible because all of the cards had the same amount of data and the same types of data. So we don't have that when we look at our exclusion data.
(Dale at 00:17:14) Our clients are giving us social. Our clients are giving us date of birth, and they're often providing an address and even former last name. They're giving us the good quality data. On the exclusion side, none of that is possible. So you can't do that comparison. So early on, we decided that we would actually go out and build a proprietary database where we gather that information. We took it upon ourselves to say, listen, we don't get the social from the exclusion agency, but that's the most valuable identifier. We'll develop a system to go out and collect that information, verify it, and then load it in so that it's persisted in our database.
(Dale at 00:17:55) And so over the course of three years, we found close to 300,000 socials, date of births, and then all the MPIs that go along with that dataset. Once we had the socials, then we could turn around and go to these large credit level reporting agencies like TransUnion, Equifax, that sort of thing.
(Joel Beasley at 00:18:16) Address histories.
(Dale at 00:18:17) We give them a social and they say, great, we have 300 bits of data tied to that social. Here you go. And so once we had that nucleus, we could throw into orbit the entire address history and any other missing bits of information that might potentially be useful, like AKAs, potential relatives, right? We're throwing all of that information in there now that we have that core. The really hard work was building that core and acquiring those socials in the first place and building a system that would not only do that for the existing dataset of 300,000, but for each new incoming record that we loaded month after month, year after year. So that's a long-winded answer of the problem that we solve, one of the problems that we solve for our clients. Imagine having to do that yourself if you're an acute hospital.
(Joel Beasley at 00:19:12) Yeah, easy. Spin up a team of people, right? Yeah, it's so difficult.
(Dale at 00:19:17) Yeah. Yeah. So what we've found now that we've developed this system and kind of built this proprietary database is we've begun to collect information on the exclusion matches that we find on behalf of our clients that would have been either very difficult or near impossible had we not gone and collected the socials. And on average, it's about 40% of the matches that we report back to our clients could not have been found using name, could not have been found using address or any of the other information natively given by the excluding agency because of former last names, because of mistypes, because of any of those variables that are present with that transient data. 40%. So we've actually got a number that is capturing the value of that work that we did years and years ago.
(Joel Beasley at 00:20:12) And I gotta ask, how on earth did you get Social Security numbers of these people?
(Dale at 00:20:16) Right. Well, it does go back to the credit level reporting agencies. So think of it this way: you can have access to this dataset if you have an allowable use. There are many, many different allowable uses. One of them is law enforcement. You can look up folks on your investigation if you have an allowable use for it.
(Joel Beasley at 00:20:37) So the police stations can work with the credit bureau data people.
(Dale at 00:20:42) Yep.
(Joel Beasley at 00:20:43) And under this concept of allowable use. Yes. So there you go.
(Dale at 00:20:47) Fraud prevention is our allowable use. Yeah. Another allowable use is debt.
(Joel Beasley at 00:20:54) What? Fraud prevention?
(Dale at 00:20:55) Mm-hmm.
(Joel Beasley at 00:20:56) Explain that.
(Dale at 00:20:57) Okay. So Office of Inspector General is kind of the driving force behind exclusions and exclusion monitoring. The primary reason why you get on the exclusion list is because of fraud. Defrauding the government. So if you're billing the government for services that you've provided, in many ways, they have to take your word for it that you performed that service or that you did the extra special Cadillac version of that service, and therefore, you're owed 20 times as much as the regular version.
(Joel Beasley at 00:21:28) Entry.
(Dale at 00:21:29) Yeah. Regular version, entry level version. And so over time, they realized this is a pretty major problem.
(Joel Beasley at 00:21:34) Mm-hmm.
(Dale at 00:21:35) So the Office of Inspector General really went after investigating these fraud rings and these fraudulent billing practices. And that's really a lot of where the exclusion records come from. And then they just expanded it and included folks that let their licenses relapse. And like I was mentioning earlier, folks who were found to be abusing patients or swiping drugs. And so our allowable use is to really do investigations for the purpose of preventing fraud in the health care industry.
(Dale at 00:22:08) Yeah. From the credit level reporting agencies' perspective, we are investigators investigating fraud or helping the OIG investigate fraud in that case.
(Joel Beasley at 00:22:17) That's awesome. Yeah. Maybe we can keep that in the interview.
(Dale at 00:22:19) It's completely, yeah, it's completely open.
(Joel Beasley at 00:22:21) I thought you were gonna give a dark web answer, like, I'm searching the dark web.
(Dale at 00:22:25) It's absolutely not that way. Yeah. It is interesting, the culture around that. But if you really think about it, like, the EIN for a business, that's the equivalent of their social. And that's public data. Yep. Date of birth is public. Many times you can find that online, not having to go to credit level reporting agencies.
(Joel Beasley at 00:22:48) You know what's funny about that EIN? Certain services will use that as a way for you to identify that you're the owner of the business, and I'm like, why are they using that if you can just go look up anyone's EIN?
(Dale at 00:23:04) It's true. There are certain states that do not make it easy to find EINs. There's no online way. Florida does.
(Joel Beasley at 00:23:14) You just type in the name of the LLC and it comes right up.
(Dale at 00:23:16) We love Florida's online services. Same with their license monitoring primary source website. But there are some states that will not post it online. You have to call and submit a request, or you have to go in person to the county clerk or something like that. But you can get access to it.
(Dale at 00:23:38) So what we did is we essentially built a business process around looking up a social and definitively attaching it to an exclusion record. And if you're interested, I can give you the short version of how we did that. Yeah. So the first thing that we identified is that of those 300,000 records of exclusion records of excluded individuals and businesses, those do not represent 300,000 unique entities. So immediately, we found we could find groupings of records that talk about the same person or the same vendor.
(Dale at 00:24:14) So the first thing we did is create a grouping step. Take 300,000, we group it down into 100,000 unique entities. So all of a sudden, our universe is reduced. We also benefit from the unique data across several individual records. So the consolidated record is now more robust than each individual on their own. One record brings in a date of birth, another record brings in an address, and the third record brings in a former last name. Suddenly, we have a more complete picture of the person or the entity. We take that consolidated record, and we go and we begin to do searches on our credit level reporting agency portal. If the credit level reporting agency is very confident that they found one and only one record that matches those parameters we just passed in, then we will bring that social into our system. Now here's the secret: we give a separate person the exact same job. So a totally different person just performed that search and brought in that social. And we have to see that that second independent person finds the exact same result and loads it in. And we'll compare those and say, did both people come to the same conclusion? If so, and assuming that they followed all of those rules that we just laid out, then we'll put it through another independent review where we take the consolidated record now complete with social.
(Dale at 00:25:45) We'll go to a separate, completely separate agency and, again, give it to a third person, and we'll kind of do the inverse where we search with the social and make sure that we produce the same result that matches the exclusion. Once, and if and only if all of those things come out as a pass, essentially, that's a test, and if it passes those tests, then we'll load that into our system and persist it and make decisions based on that data and report back to our clients. So we do that over and over and over again across all 100,000 of those. Once it's loaded in and persisted, again, we've collected all the address history now and loaded that in. Any new record that comes in, we're asking one question: do you belong to an existing group that we've created, or do you need to create your own new group? And either way, that goes through a different process. If it belongs to a group, then it just is one new member to an existing group.
(Dale at 00:26:44) If it creates its own, then we go out and we find the social that belongs to that person and we do that whole process. Repeat until we have a more complete version or picture of that. And so it's kind of building a process that ensures accuracy from the very beginning, knowing that the outcome of our decisions based on this data is really, really critical to get right. This isn't a matter of, did we get the right email address or not? This isn't a matter of, did we send this letter to the right address or not?
(Dale at 00:27:20) This is a matter of, can this provider work for this hospital? Can this physician be a member of this health plan network and provide critical care for patients that are being referred to them? The outcomes and the impacts are really important, ultimately affecting patients and the care that they're receiving from their health plan network or the hospital that they're choosing to go to. And so we take great care on the front end to make sure that all those little decisions in places where it could go wrong are kind of hemmed in and building in those triplicate layers of QA and validation just to make sure that we've got the right thing. And then we use that as a foundation, build everything on top of that.
(Joel Beasley at 00:28:07) Your company name makes a lot more sense now.
(Dale at 00:28:09) Yeah. That's right. That's right. Yeah. There's a lot to that.
(Joel Beasley at 00:28:13) And so preventing medical malpractice. So that would be to help protect patients from sketchy doctors. So these doctors, they would try to join this group. Like, a sketchy doctor would try to join the group. The group would use ProviderTrust and be like, nah, you're a sketch ball and then cancel it out. So you're helping prevent that. Whereas if they didn't have the system and maybe somebody came from another state or something happened, they could get in there and then they would be working as a doctor there.
(Dale at 00:28:43) That's exactly right. And what we find is all sorts of techniques that these bad apples will employ to—
(Joel Beasley at 00:28:54) What do they do?
(Dale at 00:28:55) To hide their identity. So the easiest one, of course, is to go under false aliases. They change their name, they use their middle name, they invert their names, right? There are all sorts of kind of low effort, low risk ways of getting by most surface level checks.
(Joel Beasley at 00:29:13) When they do these things, do they get their medical license pulled?
(Dale at 00:29:17) Oh, a lot of times they do, or at least suspended temporarily. And that's the second half of the picture that we can talk about here in a minute because we also do credential verifications for our clients.
(Joel Beasley at 00:29:30) Okay.
(Dale at 00:29:31) But to go back to your original question, another technique that they'll employ is they'll actually go and they'll find an available Social Security number. And so you've heard about this, collecting somebody's Social Security benefits, somebody that's been dead for two years, right? The checks keep coming in and they keep claiming them, cashing them in. Well, a similar technique can be used here. You know, you can access somebody's Social Security number of someone that's already passed away, and you can begin to use that. It passes most surface level sniff checks to, yeah, it's a valid social. Yes, it belongs to a person. On you go. One of the things that we do is we actually check that list, the list of all of the socials tied to dead Americans. It's called the Social Security Death Master Index. So we'll check that and we will occasionally find physicians, doctors, nurses that have used a falsified social or a social that belongs to one of their relatives or something like that to avoid being located by companies like ours. But because we have done the work proactively to identify this is the social that is tied to this individual, then we can also detect when data doesn't belong together. So, for example, like the date of birth, the address, and the name, those all might ring true as matches, but the social is different. Well, we don't just blindly call that a no match because the socials are different.
(Dale at 00:30:59) We take a look at the components that are matching. We'll do our own independent research and we'll figure out, report back to the client, I don't think your employee is being forthcoming about their social. We think this is the social that belongs to them. They'll launch their own investigation, and then they'll find that to be true. That happens every now and then.
(Dale at 00:31:21) The other thing that they can do, and this kind of gets us into the credential side of things, is they can begin to use maybe an old or expired license that didn't get renewed by the state board. And it's only if somebody is continuing to check on that license every month or every week or in our case every day that they would check to see the status has gone from active to suspended or active to revoked or from active to expired. And so it's a matter of kind of keeping an eye on all of those components, the Social Security Death Master Index, the exclusion list with the enriched data that we've built over time, and then pulling in credential data. That gives you the whole picture. And regardless of which technique they're employing to try to fly under the radar, we'll catch it if we're looking at all three of those and sprinkling in a few other lists along the way just to be safe.
(Joel Beasley at 00:32:20) When the report comes back, is it more like a credit report with a bunch of details, or is it binary, they pass or they don't pass? Like, can I see that someone's been, they have an active license today, but over the past ten years, they've been suspended three times?
(Dale at 00:32:35) So when somebody first comes into our system, we'll be able to look back in time and see something like, here are some sanctions that have been levied against their credential by the state board. And we'll kind of report that back within our software system. Those aren't red flags, drop everything and go pay attention. Those are more like, hey, if you're interested, here's some things that we uncovered.
(Dale at 00:33:03) From an eligibility to work and participate in the healthcare ecosystem, those don't exclude them from being able to participate, but it might be important for them as an employer to know that about their employee. So we'll report that back. And then if anything changes, so maybe the initial report is you're all clear, green lights across the board, we put them into ongoing monitoring, which is really just 24/7 monitoring. If anything changes, we'll let you know type of thing. And so anytime data comes in, either new data from the client or new data from these exclusion sources or SSDMF or licensed credential data, we'll be checking those every single day. If anything changes, and especially if it changes and impacts the outcome of one of those clear tests that we ran, we'll generate something called an alert. And we'll say, hey, you need to look at your employee or your provider or your physician. They just popped up on the exclusion list, or their license just switched from active to suspended. And we'll give that to them near real-time, within 24 hours of that change, so that they're able to respond in an adequate format and be able to do their own investigation once again and kind of clarify the situation and then take appropriate action. We don't weigh into advising what they do, but we do kind of point to the fact that you can be fined if you do this. You can adversely impact your ability to continue practicing. You can be put under a CIA, right? These are all these different outcomes or consequences if they just sweep it under the rug and ignore it. And we can help them be aware of all those consequences, but ultimately the choice is up to them. We report the facts, and then they make the decisions.
(Joel Beasley at 00:34:58) How many are there? Like, a lot of competitors to what you guys do, or are you pretty much the only one out there?
(Dale at 00:35:03) Well, there certainly are more than there used to be. Yeah. So what we've seen is an influx of low-cost competitors in the exclusion monitoring space.
(Joel Beasley at 00:35:11) That's not a place where you really want to cut cost.
(Dale at 00:35:14) No, no. Unless you are in the business of checking boxes. Yeah. So, you know, if you're a healthcare company, you know that you need to do exclusion checks and you're being required by the government to do that, and you're in danger of incurring fines if you don't do it. So you have to do it if you want to stay in that industry. And so if you pull up a little matrix where you're comparing different softwares or different companies, ProviderTrust is never going to be the cheapest. And for all the reasons why we've been talking about, we've invested a lot in building a proprietary database.
(Joel Beasley at 00:35:53) Well, also, the best people cost more money.
(Dale at 00:35:55) That's right. That's right.
(Joel Beasley at 00:35:56) Because if you want the best people to make the best product, you have to charge money. Like when we do the podcast stuff for people, we tell them right up front, hey, we are like the more premium version of this. You can go get this stuff made for $100 an episode by your nephew, and you will get those style of results.
(Dale at 00:36:14) Yep. Or you can get it made by experts and you get those results.
(Joel Beasley at 00:36:16) 100%.
(Dale at 00:36:16) Yeah. So this is probably no fault of their own. They will compare apples to apples. This person will perform a search against the exclusion list, and this company will perform a search against the exclusion list. But like I mentioned, if you're relying on name or you're relying on address or any of that transient data, the data that we found is you're missing about 40% of those results. And so you actually may be ignorant to the fact that you're missing those 40% until the OIG comes in and performs an audit.
(Joel Beasley at 00:36:54) What's the OIG?
(Dale at 00:36:55) The OIG is the Office of Inspector General. They're the ones, they're kind of the federal impetus behind creating the exclusion list and monitoring and trying to prevent fraud.
(Joel Beasley at 00:37:04) So this is the thing people have to do. If they don't do it well, they get fined?
(Dale at 00:37:09) It's likely that they will over time. It's kind of like a, I don't want to say it's guaranteed that they're going to get caught, or it's also not a guarantee that they're going to hire excluded individuals. None of that is a guarantee. But what we do know is that when clients switch from a competitor to us, we always find something that the competitor missed.
(Joel Beasley at 00:37:36) Have you guys worked with like malpractice insurance providers? Because it seems like if I was a malpractice insurance provider, I would want to force my company through the best possible thing.
(Dale at 00:37:49) Yeah, that's interesting. I can't think of an example where we've worked with that organization, but we do work with a law firm that does mergers and acquisitions.
(Joel Beasley at 00:37:58) Oh, okay.
(Dale at 00:37:59) And the law firm itself requires all of its clients to perform a check before, it's one of the due diligence steps of their M&A process. So yeah, there are more than just healthcare companies that are interested in this data. There's entire ecosystems that surround the healthcare industry, as you know, that are also interested in the integrity of the workforce, the integrity of the provider.
(Joel Beasley at 00:38:26) Lawyers don't want to take on defending clients that have issues.
(Dale at 00:38:29) 100%.
(Joel Beasley at 00:38:30) Yeah, that's why you'd want to know.
(Dale at 00:38:31) And we haven't really even talked about, but health plans are becoming one of our largest growing segments.
(Joel Beasley at 00:38:37) Health plans?
(Dale at 00:38:38) Health plans, right. So your Blue Cross Blue Shield.
(Joel Beasley at 00:38:40) What do you do with them?
(Dale at 00:38:42) So they have, of course, networks of physicians. They're a participating network, right, the in-network benefits that you get, as well as non-participating out-of-network, which is pretty much everyone else. And they're kind of looking at it from a payment perspective. So they're constantly approving claims that are flowing through their system. They're constantly approving referring physicians. This patient needs to be referred to this physician over here. They're having to make those decisions on the front end. And then, of course, do we let this physician into our network, the one that we give to all of our patients, our members. So from their perspective, if they approve a payment to somebody who is excluded or somebody with an expired license, then they are required to reimburse the government that money because you cannot make a payment to an excluded person. You cannot make a payment to somebody with an expired license. And the reality is for every dollar that they try to claw back from those payments, they're only getting 10 cents back. So it's in their best interest to stop that payment before it goes out the door. They use us to make sure that their network is free and clear of any issues. So no excluded physicians, no expired licenses, that sort of thing. And they put us kind of at the gate of, the gate out for payment approvals, claims approvals, and the gate in for letting any participating or non-participating physicians into their sort of purview. So that's kind of how health plans will use us. And then there are many companies that are sort of peripheral to the health plan ecosystem that are doing kind of, interacting with that same level of data that they want to do similar checks. They want to check the license. They want to check the exclusion status. So kind of integrating with their platforms as well is an area of growth that we want to go after.
(Joel Beasley at 00:40:50) Do you have any answers on how to make it so people don't end up on that 300,000-person list? Just a better society? That's a lot of people, man.
(Dale at 00:41:01) It's a lot.
(Joel Beasley at 00:41:02) And so it's the people that got caught, which means there's 500 to 600,000 people that are doing these not great things.
(Dale at 00:41:12) Yeah, that's right. Well, if you think about how many people are in the healthcare industry, this is a very, very, very small percent of that overall population. The thing that really, like, that stands out to us is statistically speaking, the folks that are abusing patients, the folks that are taking advantage of patients, defrauding patients, that sort of thing, they're typically, more often than not, defrauding underprivileged, underserved communities. And so these are on the outskirts of society sometimes. They're in rural areas. They're sort of outside of the beaten path. And so for us, it's kind of a mission that we've taken to heart is to make sure that underserved, underprivileged communities are getting the same level of care that everyone else is. And the main way that we are part of that solution is to make sure that these physicians and nurses that don't need to be providing care to patients are removed from the workforce or forced to go into hiding. Go find another career.
(Joel Beasley at 00:42:26) Like the sheriff over here.
(Dale at 00:42:30) Yeah, see a counselor. See if you can get yourself back up.
(Dale at 00:42:32) It's really what, yeah, that's a lot of what we're doing is we're identifying the bad apple in the orchard, and we're trying to get them out of there.
(Joel Beasley at 00:42:39) That's cool because that, as far as engineers go, there are definitely, I would say aside from just engineers, there are people that like truth, that like law and order, and they, you know, cops are those people, but there's also like engineers that have that style of personality too, right? Do you like see people finding this as like a driver as to why they want to work with you guys? Like they like the fact that they're helping people and making it difficult for bad people to be bad?
(Dale at 00:43:12) Yeah, I think that's certainly a draw. Most of the time when I am in an interview with an engineer, they have an anecdote or an experience with healthcare, and that is playing into their personal narrative. They'll say things like, I'm applying to companies that are in the healthcare industry because I'm interested in playing a part in making it better. So we certainly are adding value to the healthcare industry, and I think that's attractive. More from a technical philosophy standpoint, because of what I described earlier, you know, we are fans of automation and things like machine learning. We love being able to take advantage of cutting-edge technology. However, we are not comfortable in trusting all of the decision-making power to an algorithm or a pattern. And so we're very careful in the ways that we wield machine learning, automation, that sort of thing. Very, very careful. We don't want to make the wrong decision because a pattern was identified that looked like a different decision, and so there's just going to inherit that decision over here. You know, the details and the nuances are important to us. So very careful about that. So when we hire people, we're careful to look for the appropriate interest in emerging technologies while being rooted and grounded in the tried and true stored procedures and, you know, object-oriented programming where functions work the same way yesterday, today, and forever. We're interested in kind of a good balance between that and all of the reasons why I just mentioned is kind of playing into that. If we get too fancy with technology, there's a chance that we would allow a machine or a piece of code to make a decision that really a human should have made. And so we're very careful about architecting and engineering solutions that never engineer the person out of the formula. And I kind of say that with two meanings. One is the patient on the other end who's ultimately going to benefit or not benefit from our decision. And then the person who's kind of playing gatekeeper, that would be the person that's working for ProviderTrust, right? Sitting there making sure that before we generate a report, before we report on the status of is somebody clear or not, making sure that we've done our due diligence and investigated what needed to be investigated and not just leave that to a machine or an algorithm to do.
(Joel Beasley at 00:46:03) So are you currently hiring?
(Dale at 00:46:05) Yeah. So we're hiring. We're actually kind of in a, like we talked about earlier, kind of a maturing stage. So I'm hiring some engineering leaders, SDE managers, VP of Engineering, hiring some QA, hiring a lot of what I'm referring to is kind of our value delivery. It's like a small-scale PMO. So business analysts, project managers, and then, of course, full-stack engineers, front-end developer, API developer, and a systems engineer.
(Joel Beasley at 00:46:34) Do you have a careers page?
(Dale at 00:46:36) We do. It's providertrust.com, and then click About Us. Somewhere in there you'll find Careers.
(Joel Beasley at 00:46:44) Oh, man. All right. What else did we not talk about? You're hiring people, you're saving the world.
(Dale at 00:46:50) Yeah, yeah. Honestly, I think the one thing that we're doing that's going to be kind of a game changer, it's in parallel to what we're doing with kind of replatforming, but it's going to be a separate product and innovation. Something that we're calling NPI Live. And so we didn't talk a whole lot about our license monitoring service, but, you know, the shorthand is we're doing about 2 million license verifications a month. And we've got integrations with all these primary source license boards. We're going out and we're capturing screenshots and the statuses of all those. And the traditional way that you get a license result from us or any of our competitors is you give them the license number, the state that issued that license, and the license type. And in the case of Florida, let's go with our friend Florida. You go to one place, one website, one URL. You plug in those three parameters and you get one result. It's really easy, and you get it 99.99% of the time. So you just grab that information, send it on back. And we do that to the tune of about 2 million a month, like I mentioned. The problem is our fastest-growing segment, our health plans, they rarely have the number, the issuer, and the license type. They may have one of those components, but that's not enough to triangulate where to go. What they do have is the NPI. Their whole ecosystem is built around the physician NPI. So what we're building is a data dictionary or an index that maps all of the NPIs in the universe. So there's 7 million in total. We're not doing 7 million at once. We're doing one and then two and then five and then a thousand and then 500,000. But we're taking those NPIs and we're mapping them to the credential. So the issuer, the state, and the license number. And then we're going one step further and we're going ahead and checking that credential at the primary source. We're grabbing the screenshot. We're grabbing the status. We're grabbing the expiration date, and we're storing and persisting that result. So done at scale, all a health plan has to do, or anyone in the healthcare industry, is give us an NPI, one identifier. And what they get back is the exclusion status instantly. They get the NPI status. Is the NPI valid, in good standing? They'll get things like preclusion, opt-out status. Those are lists we didn't talk about, but they're similar to exclusion lists. But more importantly, what I'm talking about is they will get a license result. They'll get the credentials, yes, the license number, issuer, and state, but they'll also get a fresh license result returned instantly along with the screenshot. So you think about this ecosystem we were talking about with health plans. They're trying to decide if they can pay a claim for a physician. They just plug the NPI in to NPI Live, and they get a clear result across the board, they click into the license screenshot, verify that it's in good standing, and five seconds later they've made a decision.
(Dale at 00:50:16) Same with when they're bringing onboard a new physician, plug in one NPI, they get all the results in one place, including the license result, and they can approve or not approve that request to come aboard. So pulling all of that data into one place is kind of what we have found is our specialty. That's what we do well. This is a big undertaking, but we're really confident that we can do this. We've acquired a quarter of a million license results, tied them to NPIs as sort of a proof of concept.
(Dale at 00:50:50) We're loading that into our system as we speak. And over the next few years, we're going to ramp that up to the tune of 7 million. So that's our big bet, is that we can build an entire ecosystem around this and disrupt a couple of industries along the way if we do this right. But that's kind of where we're marching from an innovation standpoint, and we're really excited about it.
(Joel Beasley at 00:51:14) Best leadership advice that you've ever received?
(Dale at 00:51:18) I think of two things. One is more philosophical. You have to be able to lead yourself before you can lead others. And the way that I translate that's kind of like, you know, put that up on a poster and look at it every now and then.
(Dale at 00:51:34) But really where that, what that translates into for me, is that if I want to see an outcome in the folks that I'm leading and the teams that I'm leading, I need to figure out how to achieve it for myself first. If I want to see balance on my teams, a sustainable, balanced working rhythm, I have to first find that for myself. And for so long, I was driving myself into the ground, trying to keep teams motivated and trying to help them become balanced, while at the same time just burning myself out. And I think you could probably guess how that turned out.
(Dale at 00:52:17) And so that's been a really important sort of journey and discovery that I've had, really somewhat recently over the past year or two years. The second one is that as an executive, you know, one of your primary jobs, the primary ways that you serve your team, is by wrangling budget. And I'll admit, I didn't have that in my purview as one of my primary responsibilities, was to advocate for budget and make a case for it. For one, it forces you to really think through, what am I convicted about? What do I really need?
(Dale at 00:52:54) And what does my team really need? And then two, turn that into a plan that has dates and dollars and map that. Map that on a calendar. Put that in an org chart. And doing the work first provides me with an enormous amount of clarity and conviction about where we're going and what we need. And two, it makes it really easy for, you know, the folks that do control the money bags to say, yes, I agree with your plan. Or if they don't, to be able to contend with something very specific, not just one big fat number. And so that's a skill that I've quickly tried to develop and learn. Still have a lot to learn, but something that I'm finding is paying dividends the better I get at it.
(Joel Beasley at 00:53:38) Yeah. I found that out as well. I found that it's way more effective instead of me trying to grow my tech org for the sake of growing it and doing cooler things to go find what the CEO is saying that the mission is and then working backwards from that. And then that made going and getting the money a lot easier because the entire plan is centered around whatever the main leader is. You're not the CEO, right? You're the CTO.
(Dale at 00:54:04) CTO. Yeah. That's right.
(Joel Beasley at 00:54:06) CEO job is really hard too.
(Dale at 00:54:07) Yeah. I'm sure.
(Joel Beasley at 00:54:08) Because he has to decide that plan, right?
(Dale at 00:54:11) That's right. Yeah. Yeah. Coming up with vision is a rare ability.
(Joel Beasley at 00:54:15) Who's your CEO currently?
(Dale at 00:54:17) Chris Redditch.
(Joel Beasley at 00:54:17) Okay. Oh, so one of the founders.
(Dale at 00:54:19) One of the founders.
(Joel Beasley at 00:54:20) That's awesome.
(Dale at 00:54:20) So we're a founder-led company.
(Joel Beasley at 00:54:22) What's the one thing that you're most excited about right now?
(Dale at 00:54:26) I think the most exciting part is thinking about getting to the end of 2023 and realizing the size team that we'll have, and the opportunities that sort of got fabricated out of thin air for either new folks that we're bringing in or people that we've had on board for two or three years. Right? When you're small, you're flat as an organization. And I can kind of look into the future 12 months from now and see how we're really maturing the ranks and building out competencies that we haven't built out before, like our ability to plan 12 months, 24 months into the future and roadmap to that. So I'm excited about that.
(Dale at 00:55:13) I think going back to the original theme of just maturing. Yeah. Excited about maturing.
(Joel Beasley at 00:55:17) Dude, that's exciting. Sounds like a fun time at ProviderTrust.
(Dale at 00:55:20) It is.
(Joel Beasley at 00:55:20) Providertrust.com. We made a podcast.
(Joel Beasley at 00:55:29) If you found this episode useful, please share it with a friend or colleague who you think would get value from it. And if you have topics that you'd like to hear discussed on the podcast, either add me on LinkedIn or send me an email, [email protected]. Every time I get an email or LinkedIn message, it absolutely makes my day and inspires me to keep going.