Payer Virtual Credit Cards Are Skimming Your Reimbursements: How Providers Opt Out and Enroll in EFT and ERA

Payer Virtual Credit Cards Are Skimming Your Reimbursements: How Providers Opt Out and Enroll in EFT and ERA
By Harley Saunders September 20, 2026

A medical practice receiving virtual credit card payments from insurance payers can generally request claim payment through the HIPAA-adopted ACH healthcare EFT standard. The practice must then complete the payer’s current EFT enrollment process, arrange ERA/835 delivery where needed, and verify that future reimbursements arrive as ACH deposits rather than card transactions.

This is a payer-to-provider reimbursement issue, not a patient-payment workflow. The problem begins when an insurer or its payment vendor sends a one-time virtual card number for a claim payment and practice staff key that number into the same merchant terminal or virtual terminal used for ordinary card acceptance. 

The payment may be for the full claim amount, but merchant-processing charges can reduce the practice’s net settlement.

CMS continues to identify Guidance Letter 2022-04 as its guidance on health plans’ use of virtual credit cards and adopted healthcare EFT/ERA standards. 

That guidance makes an important distinction: health plans may use alternative electronic-payment methods in some circumstances, but when a provider requests payment using the adopted HIPAA healthcare EFT and ERA standards and successfully completes required enrollment, the health plan must conduct the standard transaction. CMS grounds that obligation in 45 CFR § 162.925(a)(1).

Virtual Credit Card Payments From Insurance Payers: What Providers Should Do First

Healthcare provider reviewing virtual credit card insurance payment

Treat payer VCC conversion as a small revenue-cycle project rather than asking the front desk simply to “stop running those cards.”

The first task is identification. Determine which card transactions are insurance reimbursements, which payer funded each payment, whether a separate payment vendor delivered the card, and how much the practice actually pays to process those transactions.

Then convert payment and remittance together.

A practical workflow is:

  1. Identify payer VCC transactions in merchant and remittance records.
  2. Calculate the actual card-processing expense attached to those reimbursements.
  3. Identify both the underlying health plan and any payment vendor.
  4. Request the HIPAA-adopted ACH healthcare EFT standard.
  5. Complete the payer’s current EFT enrollment requirements.
  6. Complete ERA/835 enrollment or routing where it is handled separately.
  7. Record the approval and effective date.
  8. Verify that the first converted reimbursement reaches the intended bank account by ACH.
  9. Test whether the ACH payment correctly reassociates with the corresponding 835 ERA.
  10. Continue watching merchant statements for unexpected VCC activity.
StepActionEvidence to KeepCommon Failure
1Identify VCCsCard notices, batches, processor statementsVCC mistaken for patient card payment
2Quantify costMerchant statement and effective rateUsing a generic 3% assumption
3Identify payer/vendorERA, EOP, payer portal, VCC noticeContacting vendor but not underlying plan
4Request standard ACH EFTWritten request/ticketAsking merely for “direct deposit”
5Complete EFT enrollmentForm/portal confirmationOpting out but never supplying bank data
6Establish ERA835 enrollment confirmationAssuming EFT activates ERA automatically
7Verify activationEffective date, ticket numberTreating submission as approval
8Check first depositBank trace/origin dataWrong TIN or pay-to entity
9Test reassociationMatching TRN and posted claimsACH arrives but posting remains manual
10MonitorMonthly payer/payment-method logVCC silently resumes for another product

What a Payer Virtual Credit Card Actually Is

A payer virtual credit card, sometimes called a VCC or VCP, usually consists of payment-card credentials generated for a specific reimbursement. No physical card has to exist.

A common flow looks like this:

Health plan or payment vendor → one-time virtual card number → medical practice keys number into POS or virtual terminal → payment-card network → merchant settlement to practice

At the point the practice enters that number into its card-processing system, it is acting as the merchant accepting a card transaction. That means the reimbursement follows the normal credit-card authorization, clearing, and settlement process, and applicable processing charges can be deducted according to the practice’s merchant agreement.

UnitedHealthcare, for example, currently describes its VCP as a virtual card issued for a claim payment and instructs providers to process it as a credit transaction through a point-of-sale terminal. UnitedHealthcare also warns that merchant-processing fees may apply. Humana similarly describes a 16-digit VCC that is entered into the provider’s credit/debit POS terminal.

That is materially different from the HIPAA-adopted healthcare ACH EFT standard. With standardized ACH EFT, the payer initiates a bank-to-bank ACH credit using CCD+ and required payment-identification data. The practice does not redeem a card number through its merchant account.

A broader explanation of interchange, network assessments, acquiring costs, and processor markup can help finance staff understand why a keyed payer VCC can produce deductions at settlement.

VCC vs ACH EFT vs Paper Check

QuestionPayer VCCHIPAA-Standard ACH EFTPaper Check
How money movesPayment-card networkACH NetworkCheck clearing
Practice processes card?YesNoNo
Merchant card fees possible?YesNo card-acquiring fee; other costs may existNo card-acquiring fee
HIPAA healthcare EFT standard?NoYes, when CCD+ and required TRN data are usedNo
Bank information required from provider?Usually noYesNo
ERA may be separate?YesYesYes
Supports standardized reassociation?Not by virtue of being a VCCYes, through matching TRN dataNot as healthcare EFT

Why Do Payers Use Virtual Cards?

Virtual cards can reduce paper-check handling, automate disbursement, provide payment controls and tracking, and eliminate the need to collect the provider’s banking information before sending an electronic payment.

There can also be card-program economics elsewhere in the payment chain.

The provider’s merchant statement may contain several cost components. Interchange generally flows toward the card-issuing side of the transaction. Card networks may assess network fees, while the provider’s acquirer, processor or gateway may add its own charges.

Separately, a payer, affiliated company or payment vendor may receive rebates, revenue-sharing payments or other program compensation depending on the specific arrangement. It would be inaccurate to say that every health plan simply “keeps the interchange.”

Current payer disclosures illustrate why the distinction matters. UnitedHealthcare states that affiliated companies may receive transaction fees or other compensation related to some payment options. Humana states that its VCC merchant fees include banking loyalty fees and Humana revenue-share payments.

The provider, meanwhile, usually experiences the economics in a simpler way: the insurance reimbursement is run as a merchant card transaction, and processing charges appear on the merchant statement or are deducted from card settlement.

Do Virtual Cards Really Cost Practices 2%–3%?

Sometimes. But 2%–3% is not a universal VCC price.

CMS guidance states more generally that card-processing networks typically charge providers fees calculated as a percentage of the payment. 

Historical physician-industry materials have reported considerably different ranges depending on the card program and merchant arrangement; some AMA materials, for example, discussed VCC costs as high as 3%–5%. Those figures are useful historical context, not a substitute for the practice’s own merchant statement.

Your effective rate depends on factors such as:

  • the commercial-card product used;
  • merchant category and qualification;
  • keyed or card-not-present treatment;
  • interchange category;
  • card-network assessments;
  • processor markup;
  • transaction charges;
  • gateway or virtual-terminal fees;
  • the merchant-pricing model.

For payer payment fees, a medical practice should therefore calculate actual expense from processor statements rather than multiplying every reimbursement by an assumed 3%.

The Financial Math: How Much VCC Acceptance Can Cost

These are illustrative scenarios only, not standard payer or processor rates.

Annual VCC Reimbursement VolumeIllustrative Effective Card CostIllustrative Annual Processing Expense
$250,0002.00%$5,000
$500,0002.50%$12,500
$1,000,0002.50%$25,000
$2,000,0002.75%$55,000

The basic formula is:

Annual VCC reimbursement volume × actual effective processing rate = estimated annual card-acceptance expense

Do not automatically call that entire figure “savings” after conversion. Standard ACH eliminates the card-acquiring transaction, but a practice may still incur bank, clearinghouse, payment-vendor, software or administrative expenses.

A better financial measure is:

Potential conversion benefit = avoided VCC processing expense − incremental EFT/ERA/vendor/bank expense

Can a Provider Require a Health Plan to Pay by ACH EFT Instead of VCC?

For a health plan subject to the applicable HIPAA Administrative Simplification requirements, the answer is yes when the provider requests the adopted standard transaction and successfully completes the required enrollment. 

CMS’s guidance on virtual credit card claim payments and the adopted EFT/ERA standards explains that a health plan may use other payment methods in some circumstances, but it must conduct the adopted standard transaction when a provider properly requests it.

45 CFR § 162.925(a)(1) states that if an entity requests that a health plan conduct a transaction as a standard transaction, the health plan must do so.

CMS Guidance Letter 2022-04 applies that requirement directly to payer claim payments. CMS explains that a provider may request use of the adopted healthcare EFT/ERA standards, including:

  • the Nacha CCD+ Addenda standard for the ACH payment initiation;
  • the required X12 835 TRN data in the ACH addenda;
  • the adopted X12 835 standard for electronic remittance information.

CMS further states that the requirement applies regardless of whether the provider is in the health plan’s network or otherwise affiliated with the plan.

CMS’s current transaction page continues to identify CCD+ and the X12 835 TRN segment as the healthcare EFT standards and explains that those standards apply to transmissions over the ACH Network.

The distinction matters. A wire transfer, VCC, proprietary bank transfer and standardized healthcare ACH may all move money electronically, but they are not interchangeable for purposes of the adopted healthcare EFT standard.

The Provider Still Has to Enroll

The regulatory right to request the standard transaction does not mean a payer must begin sending ACH to an account it has never authenticated.

CMS explicitly recognizes the enrollment step. A provider requesting standard EFT and ERA still must successfully complete the payer’s enrollment process. Those enrollment processes are subject to the applicable adopted operating rules.

That is why a good VCC opt-out request asks for two things:

  1. stop or decline the virtual-card payment method; and
  2. establish the destination and routing needed for compliant healthcare ACH EFT and ERA.

EFT and ERA Are Related, but They Are Not the Same Transaction

Billing departments often speak of “EFT/ERA” as though it were one product. Operationally, it is safer to think of them as two connected components.

ItemEFTERA
Primary purposeMoves claim-payment fundsExplains how claims were paid or adjusted
Typical healthcare standardACH CCD+ with required payment informationX12 835
Contains funds?YesNo
Contains detailed claim adjustments?Only limited payment-identification dataYes
Role in automated postingDeposit sideClaim/remittance side
Connection between themTRN/reference dataMatching TRN/reference data

ERA enrollment without EFT means the practice can receive electronic claim-payment detail while still being paid through another method.

EFT enrollment without working ERA delivery means the money may reach the bank electronically, yet staff can still be left hunting for the claims represented by each deposit.

How EFT and ERA Reassociation Lets the Deposit Post Automatically

“Reassociation” is the process of matching the money that arrived at the bank to the electronic remittance file explaining which claims that money pays.

CMS describes the technical mechanism clearly: the healthcare ACH payment uses CCD+; the payer places X12 835 TRN information in the ACH addenda; and the same TRN information should appear in the associated ERA. Matching those references allows the payment and remittance to be reassociated.

Operationally:

  1. The payer adjudicates claims and builds payment information.
  2. It initiates the healthcare ACH EFT.
  3. The CCD+ Addenda record carries the required payment-identification information.
  4. The payer generates the associated X12 835 ERA.
  5. Matching TRN information appears on the EFT and associated ERA.
  6. The practice’s clearinghouse, RCM platform or practice-management workflow obtains both sides.
  7. The software can match the bank payment to the 835 and then apply claim-level payment and adjustment data.

ACH deposit → TRN match → 835 ERA → claim lines → payment posting

The phrase “automatic posting” therefore should not be interpreted as “ACH appeared in the checking account, so everything posts automatically.” The posting workflow still depends on receiving the ERA, routing it to the correct system and matching it accurately.

CAQH CORE’s Payment & Remittance operating rules establish standardized requirements around healthcare EFT and ERA, including enrollment data.

Hypothetical Scenario 1 — Small Specialty Practice

A six-provider specialty group receives several mailed “payment” notices each week. The billing staff sees a 16-digit number, expiration date and instructions to key the amount into the same terminal used for patient balances.

The controller reviews three months of merchant activity and tags the transactions to insurer remittances. What had looked like ordinary card volume includes about $42,000 per month in insurance reimbursements.

The practice identifies both the underlying health plan and the payment vendor shown on the notices. Rather than merely asking the vendor for paper checks, it requests standardized healthcare ACH EFT, completes the payer’s current bank-enrollment procedure, submits its ERA routing information through its clearinghouse and retains both confirmation numbers.

After activation, the team verifies that no new payer cards are being keyed and confirms that the first ACH deposit’s payment reference matches the corresponding 835.

How to Find VCC Payments Hiding in Your Reimbursement Workflow

Start with the merchant account, not the general ledger.

Look for:

  • unusually large manually keyed card transactions;
  • one-time card numbers;
  • card notices attached to payer remittances;
  • faxed or mailed instructions containing payment credentials;
  • payer-portal fields describing VCC or VCP;
  • card batches processed by billing staff rather than front-desk staff;
  • insurance payments settling under the merchant acquirer’s descriptor;
  • unexplained processing expense on high-dollar reimbursement transactions;
  • staff instructions to “run the insurance card” for the exact reimbursement amount.

A bank statement alone may obscure the source because the bank may show the card processor’s settlement rather than the payer that generated the original VCC. 

When several payment channels feed different financial systems, stronger payment reconciliation and integrated reporting workflows can make it easier to trace a reimbursement from the original payer notice through processor settlement and into the accounting record.

Create a payer inventory:

PayerPayment VendorMonthly VCC VolumeProcessing FeesEFT Available?Opt-Out Submitted?EFT Effective?
Payer AVendor X$___$___Yes/NoDateDate
Payer BDirect$___$___Yes/NoDateDate
Payer CVendor Y$___$___Yes/NoDateDate

Reconciling payer payments across separate financial systems is also where broader payment-integration controls can reduce duplicate research and posting work.

How to Opt Out of Payer Virtual Credit Cards

Step 1 — Identify the Actual Payer

Do not assume the company named on the card notice is the insurer.

Separate the parties:

  • health plan;
  • TPA or plan administrator;
  • payment vendor;
  • card issuer;
  • payment platform;
  • clearinghouse.

The payer’s business associate may administer the payment, but CMS states that a health plan using a business associate for a HIPAA transaction does not shed its compliance responsibilities. If the payer directs providers to a business associate for payments, the health plan can remain accountable for applicable requirements.

Step 2 — Locate the Payer’s Current Provider-Payment Instructions

Use the payer’s current official provider resources.

Do not use an old SOP simply because it worked three years ago. Payment vendors, portal locations and enrollment platforms change frequently.

Step 3 — Find Both the VCC Opt-Out and EFT Instructions

Some payers make EFT enrollment the practical mechanism for moving away from VCC.

Others separately require the provider to decline VCC participation.

Do not assume one action completes the other.

Step 4 — Request the Adopted Healthcare ACH EFT Standard

Precise wording helps distinguish the request from a generic electronic-payment preference.

Ask to receive claim payments through the HIPAA-adopted healthcare EFT standard over the ACH Network and to complete the payer’s required enrollment process.

Step 5 — Complete EFT Enrollment

Typical information can include:

  • legal provider or group name;
  • Taxpayer Identification Number;
  • NPI;
  • billing or pay-to entity;
  • bank routing number;
  • account number;
  • account type;
  • voided check;
  • bank letter;
  • authorized signer;
  • contact information.

Each payer may request a different permitted enrollment data set and validation process.

Step 6 — Complete ERA Enrollment

Confirm:

  • X12 835 delivery;
  • clearinghouse or EDI vendor;
  • ERA receiver or trading-partner identifiers;
  • which TIN/NPI entities are covered;
  • where the 835 will be delivered.

Step 7 — Preserve Evidence

Keep:

  • submission date;
  • portal confirmation;
  • downloaded PDF or screenshot;
  • ticket/reference number;
  • payer representative name if supplied;
  • requested or assigned effective date.

Step 8 — Verify the First Payment

A submitted EFT form is not proof that ACH is active.

Confirm the first converted payment in the bank account, obtain its trace/payment-identification data and locate the matching ERA.

VCC Opt-Out vs EFT Enrollment vs ERA Enrollment

ActionWhat It ChangesWhat It Does Not Necessarily Complete
VCC opt-outRequests termination of card-based reimbursementBank enrollment
EFT enrollmentEstablishes ACH payment destinationERA delivery
ERA enrollmentEstablishes 835 deliveryBank transfer
Clearinghouse setupRoutes remittance dataPayer payment preference
Bank verificationConfirms account ownership/detailsERA routing

The distinction is central to the project. A practice can successfully opt out of payer virtual credit cards and still wind up receiving checks if EFT enrollment was never completed. It can also receive ACH while continuing to reconcile deposits manually if its ERA setup is incomplete.

How to Opt Out of VCC and Enroll in EFT With Major Health Plans

The routes below were checked against currently available official provider resources on September 20, 2026. Payers can change vendors and procedures, and Medicaid, Medicare, dental, behavioral-health, TPA and regional products may use different workflows.

PayerCurrent VCC Opt-Out RouteCurrent EFT Enrollment RouteERA RouteVerified
UnitedHealthcareChoose ACH/direct deposit instead of VCP; current UHC payment page directs providers to Optum PayOptum Pay ACH/direct depositClearinghouse/EDI or Optum Pay 835 accessSept. 20, 2026
AetnaCurrent public page says non-EFT providers may receive VCC; current page routes payment-preference management through Payer Enrollment ServicesPayer Enrollment ServicesPayer Enrollment Services/EDI arrangementSept. 20, 2026
Cigna HealthcareNo distinct current public national VCC opt-out route located in the reviewed official material; confirm for the applicable productCignaforHCP.com EFT enrollmentThrough EDI vendor/ERA enrollmentSept. 20, 2026
HumanaCurrent official page directs VCC participants to decline through ECHOHumana ERA/EFT Enrollment app in Availity EssentialsIncluded/routed through Humana/Availity and clearinghouseSept. 20, 2026
Anthem/Elevance-affiliated plansVaries by plan; some current plan manuals state that enrolling in EFT automatically opts out of VCCEnrollSafe is used by current Anthem resources reviewedAvaility or clearinghouse for 835Sept. 20, 2026
Other BCBS organizationsMust be checked by regional Blue planPlan-specificPlan-specificRegional verification required

UnitedHealthcare

UnitedHealthcare’s current provider-payment page offers ACH/direct deposit and virtual card payment through Optum Pay. It says ACH claim payments can be routed by TIN, payer and NPI and states there is no charge for the deposit itself. UHC also states that a provider that does not want VCP can choose ACH/direct deposit/EFT instead.

For ERA, UHC states that 835 files can be delivered through a clearinghouse or accessed through Optum Pay, with ERA routing performed at the TIN level.

Aetna

Aetna’s current provider page states that if a provider does not enroll in EFT, future payments may be issued as VCCs. It directs providers to its Payer Enrollment Services for EFT/ERA authorization and for changing or canceling payment preferences.

Because public Aetna instructions have changed over time, practices should use the current Payer Enrollment Services route rather than relying on older VCC-discontinuation SOPs.

Cigna Healthcare

Cigna currently directs providers to enroll in EFT through CignaforHCP.com. Its instructions describe bank verification through a prenote and allow practices to check EFT status through the same provider environment.

For ERA, Cigna’s provider materials direct practices to work with their EDI vendor.

The official national sources reviewed did not present a separate current public VCC opt-out procedure comparable to Humana’s. A practice encountering a Cigna-related VCC should therefore identify the specific payer/product or TPA and confirm the payment-method-change route while requesting standardized EFT.

Humana

Humana’s current provider page is unusually explicit. It says Humana uses PNC Healthcare and ECHO Health for eligible VCC payments, tells participants that they may opt out through ECHO, and instructs providers preferring ERA/EFT to decline the virtual-card program and complete electronic enrollment.

Humana’s current EFT/ERA workflow uses its ERA/EFT Enrollment app in Availity Essentials. The same official resource states that Humana’s EFT uses CCD+ and that its ERA is delivered as the 5010 835 through Availity or a clearinghouse.

Anthem and Elevance-Affiliated Plans

Current Anthem provider resources reviewed direct providers to EnrollSafe for EFT enrollment and to Availity or the provider’s clearinghouse for 835 ERA registration.

Plan-specific instructions matter. An Anthem Ohio provider manual, for example, states that EFT enrollment automatically opts the provider out of VCC and provides an additional VCC opt-out route. That does not mean the identical procedure applies to every Anthem or Elevance product nationally.

Blue Cross Blue Shield Plans Are Not One Enrollment System

Do not build an SOP called “BCBS EFT enrollment” and assume it applies nationally.

Blue Cross and Blue Shield organizations are regional plans with different payment vendors, portals and product arrangements. Some use platforms also seen in Anthem workflows; others do not. Verify the specific Blue plan identified on the remittance or member plan.

What Happened to CAQH EnrollHub?

Old payer instructions and internal revenue-cycle binders may still tell staff to use CAQH EnrollHub EFT enrollment.

That instruction is obsolete for the former general EnrollHub service. CAQH’s EnrollHub page states that EnrollHub became unavailable on February 1, 2022.

Some payer migrations occurred earlier. For example, Blue Cross NC communications documented a transition from CAQH EnrollHub to EnrollSafe beginning November 1, 2021 for the products described in those notices.

Do not confuse three different CAQH functions:

  • EnrollHub was an EFT/ERA enrollment service and is no longer available in its former general form.
  • CAQH ProView is principally used for provider data and credentialing functions; it should not be treated as the universal replacement for EFT enrollment.
  • CAQH CORE develops healthcare administrative operating rules, including Payment & Remittance operating rules. It is not a payer-payment enrollment portal.

A practice should therefore follow each payer’s current provider-payment instructions or an authorized multi-payer enrollment platform specifically identified by that payer.

EFT Enrollment Security: Why the Bank Verification Is So Strict

Changing a practice’s reimbursement destination is a high-risk financial event.

An attacker who successfully changes a pay-to bank account may divert multiple claim payments before the organization notices. That explains why payer enrollment procedures may require a voided check, bank letter, authorized signer, account validation, MFA, callback verification or a waiting period before the change becomes active.

Revenue-cycle staff should use only verified payer or authorized vendor channels and should not send banking credentials to an unfamiliar address merely because an email claims to come from “provider payments.” 

The same separation of responsibilities matters when reviewing HIPAA and PCI requirements in healthcare payment environments: HIPAA requirements and card-data security controls may overlap operationally, but they govern different information and should not be treated as interchangeable.

Maintain internal separation of duties where practical: one staff member initiates the change, another validates the payer/vendor destination, and finance verifies the first deposit.

General healthcare payment-security controls can complement—but should not be confused with—the HIPAA Administrative Simplification transaction rules discussed here.

What If the Payer Keeps Sending VCCs After Opt-Out?

Do not jump immediately from “another VCC arrived” to “the payer is violating HIPAA.”

First determine whether the conversion actually completed.

Use this sequence:

  1. Confirm EFT was approved, not merely submitted.
  2. Confirm the TIN, NPI and pay-to entity attached to the enrollment.
  3. Confirm the bank-account effective date.
  4. Determine whether every relevant payer product was included.
  5. Confirm that both the VCC payment preference and EFT enrollment were addressed where separate processes exist.
  6. Identify whether the new VCC originated from the same health plan, another TPA or another product.
  7. Contact the payer’s current provider-payment support channel.
  8. Supply the prior approval or ticket evidence.
  9. Request correction of the payment-method record.
  10. Track every VCC issued after the confirmed EFT effective date.
  11. Escalate through provider relations or the health plan’s compliance channel when ordinary correction fails.

A vendor problem does not necessarily remove the health plan from the analysis. CMS Guidance Letter 2022-04 states that use of a business associate does not relieve the health plan of applicable Administrative Simplification obligations.

When ASETT May Become Relevant

If a covered provider believes a covered health plan is failing to conduct an applicable standard transaction as required after the provider has made the request and successfully completed enrollment, CMS currently allows complaints regarding potential Administrative Simplification transaction or operating-rule violations through the Administrative Simplification Enforcement and Testing Tool (ASETT).

ASETT should not be treated as the first response to an ordinary enrollment delay. An incomplete form, incorrect TIN, unverified bank account or mismatched product record may be an administrative problem rather than regulatory noncompliance.

CMS’s own FAQ also cautions against assuming that any fee associated with EFT/ERA automatically violates HIPAA. The regulatory question depends on whether the health plan’s conduct improperly affects the entity or transaction because it is a standard transaction.

Illustrative Administrative Request — Customize to the Payer’s Required Process

Provider/legal entity: [Name]
TIN: [TIN]
Billing/pay-to NPI: [NPI]

We decline virtual credit-card claim payments for the provider entity identified above and request that applicable healthcare claim payments be conducted using the HIPAA-adopted healthcare EFT standard over the ACH Network.

Please provide or confirm the current process required to complete EFT enrollment and, where handled separately, ERA/835 enrollment and routing.

Please also confirm in writing when the payment-method change becomes effective and identify any payer products or provider records requiring separate enrollment.

This is an administrative template, not a substitute for the payer’s official enrollment form, bank-verification process or portal workflow.

Hypothetical Scenario 2 — Mid-Size Multispecialty Group

Assume a multispecialty group discovers that $650,000 of annual payer reimbursement is currently arriving by VCC.

Its processor statements show an actual effective card-processing cost of 2.45% on that reimbursement volume.

The calculation is:

$650,000 × 0.0245 = $15,925

So the practice is incurring an illustrative $15,925 per year in card-processing expense on that VCC volume.

Management should not automatically book $15,925 as savings after conversion. Instead, it identifies any additional bank, clearinghouse or vendor charges associated with its EFT/ERA setup.

If documented incremental EFT/ERA costs were hypothetically $1,200 annually, then:

$15,925 − $1,200 = $14,725

That would be an illustrative potential net conversion benefit, subject to the practice’s actual costs.

If five payers account for the VCC volume, management need not convert them randomly. Start with the payer generating the largest combination of annual VCC dollars and card-processing expense, while simultaneously checking how complicated its EFT and ERA implementation will be.

Hypothetical Scenario 3 — EFT Works, but ERA Does Not

A behavioral-health group successfully moves a payer from VCC to ACH.

Finance sees the deposit in the bank. The billing team, however, cannot determine which patient accounts should receive the payment without opening the payer portal and manually searching the amount.

The EFT conversion succeeded. The end-to-end automation did not.

The team should investigate:

  • whether ERA enrollment was completed;
  • whether the correct TIN was enrolled;
  • whether the payer is transmitting the 835 to the expected clearinghouse;
  • whether the clearinghouse has the correct receiver/trading-partner setup;
  • whether the ERA contains the expected payment reference;
  • whether the practice-management system receives the file;
  • whether the EFT and ERA TRN values can be matched.

Until those pieces line up, ACH provides electronic funds movement but not necessarily automated remittance posting.

Measuring the Financial Recovery From VCC Conversion

Use a repeatable monthly audit.

Monthly VCC Expense

Monthly VCC reimbursement × actual effective VCC card-processing rate

Example:

$80,000 monthly VCC reimbursement × 2.35% actual effective cost = $1,880 monthly card expense

Annualized Expense

$1,880 × 12 = $22,560

Potential Conversion Benefit

Avoided VCC card-processing expense − incremental EFT/bank/vendor/administrative expense

This calculation should be performed from actual merchant statements. If different VCC programs process at materially different effective rates, calculate them separately instead of averaging everything into one number.

The payer payment fees a medical practice identifies should also be reconciled to gross reimbursement. That prevents accounting from confusing ordinary patient card fees with claim-payment processing expense.

Common Mistakes That Keep VCC Costs in Place

1. Assuming “electronic payment” automatically means standardized healthcare EFT

A VCC is electronic, but it is not the HIPAA-adopted ACH healthcare EFT standard.

2. Processing every payer card because staff assumes it is mandatory

That can unintentionally keep a costly VCC workflow operating when standardized ACH is available upon proper request and enrollment.

3. Opting out of VCC without completing EFT enrollment

The card preference changes, but the payer has nowhere verified to send ACH.

4. Enrolling in EFT but forgetting ERA

Money moves electronically while remittance posting remains manual.

5. Following an old CAQH EnrollHub SOP

EnrollHub became unavailable in February 2022; current payer-specific enrollment routes must be used.

6. Treating BCBS as a single national payer workflow

Regional Blues can use different vendors and procedures.

7. Enrolling only one TIN/NPI combination

Large organizations may have multiple legal entities, billing NPIs or pay-to arrangements, leaving some reimbursements on VCC.

8. Estimating card expense with an assumed 3%

Use actual processor data. Merchant pricing is not uniform.

9. Destroying VCC notices before mapping the payer

The notice may contain the clue needed to determine the underlying plan and payment administrator.

10. Assuming ACH means auto-posting

The ERA and TRN reassociation workflow still have to function.

11. Treating form submission as activation

Keep following the payer until the first ACH arrives correctly.

12. Sending bank details through an unverified channel

Payment-method changes are prime targets for account-redirection fraud.

Myth vs Fact: Payer VCC, EFT and ERA

MythMore Accurate Explanation
Payers can force every provider to accept VCCA covered health plan must conduct the adopted standard transaction when properly requested and enrollment requirements are successfully completed.
EFT and ERA are the sameEFT moves money; ERA explains the claim payment.
CAQH EnrollHub is still the universal EFT portalEnrollHub has been unavailable since February 1, 2022.
Any direct deposit will auto-postAuto-posting also depends on ERA delivery, matching data and system configuration.
Every VCC costs exactly 3%Actual merchant cost varies.
Every payer pockets interchangeCard-program economics differ; rebates or revenue-sharing may exist, but arrangements are not universal.
Any fee attached to EFT automatically violates HIPAACMS says fees are not categorically prohibited merely because they exist; the regulatory context matters.
A payment vendor replaces the payer’s responsibilityCMS states applicable health-plan responsibilities are not eliminated by using a business associate.

[Expert review opportunity: a revenue-cycle leader or healthcare EDI specialist can review the organization-specific EFT/ERA reassociation workflow before implementation.]

Frequently Asked Questions

Can a medical practice refuse virtual credit card payments from an insurer?

A provider can decline VCC as its desired payment method and request the HIPAA-adopted healthcare EFT standard from an applicable health plan. The provider must still complete the health plan’s required EFT enrollment successfully.

Can I require a payer to pay my practice by ACH EFT?

For a health plan subject to the HIPAA transaction requirements, CMS states that when the provider requests the adopted healthcare EFT standard, the health plan must comply, subject to successful provider enrollment. This does not mean every payer must default every provider to ACH automatically.

What regulation covers healthcare EFT requests?

The core general requirement is 45 CFR § 162.925(a)(1), which says that when an entity asks a health plan to conduct a transaction as a standard transaction, the health plan must do so. CMS Guidance Letter 2022-04 applies this rule to healthcare EFT/ERA requests.

Is a virtual credit card the same as EFT?

No. A VCC can meet the broad regulatory concept of an electronic transfer of payment, but it is not the adopted ACH healthcare EFT standard. The adopted ACH standard uses CCD+ with required X12 835 TRN information.

Why do payer VCCs create merchant-processing fees?

Because the practice processes the VCC through its merchant card system. The transaction can therefore incur card-network, acquiring, processor and related merchant-account charges according to the practice’s pricing agreement.

Does the insurance company receive the interchange fee?

Do not assume that. Interchange is part of the card ecosystem, and some payer or vendor arrangements may include rebates or revenue-sharing, but the economics differ by program. Current UHC and Humana materials disclose compensation or revenue-sharing associated with certain payment arrangements.

How do I opt out of payer virtual credit cards?

Identify the payer and payment vendor, locate the payer’s current provider-payment instructions, request standardized healthcare ACH EFT, complete the required EFT enrollment, establish ERA delivery and verify the first converted payment. A separate VCC opt-out action may also be required.

Is CAQH EnrollHub still available for EFT enrollment?

No. CAQH states that EnrollHub has not been available since February 1, 2022. Providers encountering older CAQH EnrollHub EFT instructions should obtain the payer’s current enrollment route.

Do I need to enroll separately with every payer?

CMS Guidance Letter 2022-04 states that providers must enroll with each health plan they bill in order to receive EFT and ERA transactions. Actual administrative platforms may serve multiple payers, but the provider still needs the necessary payer authorization and enrollment.

Is EFT enrollment the same as ERA enrollment?

No. EFT enrollment establishes where funds are deposited. ERA enrollment establishes how the X12 835 remittance reaches the provider or its clearinghouse. Some payers combine the process; others separate it.

What is an 835 ERA?

The X12 835 is the adopted electronic remittance format used to communicate claim-payment and adjustment information from a health plan to a provider.

What is the TRN number used for?

The TRN reference links the healthcare EFT payment to its associated 835 ERA. Matching references allow a practice or its technology to reassociate the bank deposit with the correct remittance.

Why is my ACH deposit not automatically posting?

Common causes include missing ERA enrollment, incorrect clearinghouse routing, an unmatched TRN, a TIN/NPI enrollment mismatch or a practice-management interface problem. ACH solves money movement; it does not by itself complete claim posting.

Moving Payer Reimbursement From Card Rails to Healthcare ACH

Virtual credit card payments from insurance payers deserve their own control inside the revenue cycle. They should not be mixed into ordinary patient card activity simply because both pass through the same merchant terminal.

A practice can begin by mapping its VCC reimbursement volume to payer, TIN/NPI combination and payment vendor, then calculating the real processing expense from merchant statements. 

For health plans subject to the applicable Administrative Simplification requirements, the next step is to request the HIPAA-adopted healthcare ACH EFT standard and successfully complete the payer’s current enrollment process.

ERA should be addressed at the same time. The strongest implementation is not merely “the money reached the bank.” It is ACH payment + working 835 delivery + accurate TRN reassociation + successful posting.

After conversion, monitor merchant statements and payer-payment reports for any virtual cards that continue to appear. Keep opt-out confirmations, EFT approvals, ERA routing records and effective dates so the practice can distinguish an ordinary configuration problem from a payment-vendor error or a potential Administrative Simplification issue.