Why I Stopped Trusting My Own Monthly Reports
By Jill Steeley, former FQHC CEO and founder of Steeley Strategic Solutions. I help leaders of Federally Qualified Health Centers build organizations that are financially sustainable and true to their mission - and I write from the CEO chair, because I sat in it.
In this article:
The four signs you've lost line of sight on part of your health center
Why "everything looks fine" is structurally meaningless
The two ways a closed loop forms, and why neither one is anybody's fault
What your HRSA site visit and annual audit actually check - and what they don't
The five-item line-of-sight floor every CEO should be able to clear
The one question to ask your team this week
For years as a CEO, I got a stack of reports every month. Financial reports. Quality reports. I read them. My board read them. Somebody asked a question, somebody answered it, and we moved on.
And I did not know where the data was coming from.
I want to be precise about that, because it's worse than it sounds. I don't mean I didn't understand the numbers. I mean I could not have told you what the report was pulling, or whether we pulled it the same way twice. If someone had put two months side by side and asked whether they were measuring the same thing, I'd have had to go ask the person who built them.
So every month I was taking someone's word for it. And calling that oversight.
Eventually I started digging in. What data does this pull from? Are we running it the same way every time? Show me.
Here's what I figured out. I didn't have oversight. I had a very well-designed window, with a view somebody else selected.
What does it mean when you lose "line of sight" in your organization?
It means there's a part of your health center you used to be able to see, and now you can't - and there was never a day it changed.
Nothing is wrong, exactly. You couldn't point at a problem if someone asked you to. That's what makes it so hard to act on. It doesn't show up as an alarm. It shows up as a quiet gap between what you're responsible for and what you can actually verify.
Here's where I see it show up most:
1. You can't verify a number without a person. You look at a figure in a report and realize you'd have to ask one specific person whether it's accurate - and then take their word for it.
2. A process stopped crossing your desk. Payroll approvals. A/R. A report you haven't seen in a year. Nobody decided that. Nobody announced it. It just gradually became true.
3. You couldn't explain a function to your board. Billing, credentialing, grant reporting, IT. It runs perfectly well and you could not walk a board member through how it actually works.
4. You rehearse your questions. You catch yourself planning how to ask something, because saying it plainly might sound like an accusation.
If you can relate to any of those: you're not paranoid, and you're not a bad leader. You've got a closed loop.
What is a closed loop, and why does everything in one look fine?
A closed loop is any part of your organization where the only person who can see the work is the person doing the work.
The billing goes out, and the person who decides whether the billing is right is the person who did the billing. The financials come to you, and the person deciding what's in them is the person who prepared them.
And here's the property that matters: a closed loop always reports that everything is fine.
Not because anyone is lying. Not because anyone is hiding anything. Because when the work and the check on the work live inside the same person, "fine" is structurally the only report the system can produce.
So when you look around your health center and everything looks fine, that isn't evidence. That's the loop talking.
I started thinking hard about this after we brought Matt Stevens into one of our FQHC CEO Bootcamp sessions. He's an attorney who does outside general counsel work for health centers, and he was walking us through where centers actually get hurt - not the dramatic stuff, the undercurrent stuff. He got to internal billing teams and said this:
"When somebody tells me they have 20 years of experience and they've been at the same company for 20 years, I think - okay. Do you have 20 years of experience, or one year of experience repeated 20 times? Because that's how you've always done it."
During his presentation, I filed that as a billing point. It took me a while to see it wasn't one. It's the same shape as my reports. It's the same shape as a login only one person holds. It's the same shape as the process that stopped crossing your desk.
Doesn't my HRSA site visit or annual audit already catch this?
No. And this is the part that keeps the whole problem alive, because you feel watched constantly. Safety net health centers are among the most reviewed organizations in American healthcare.
So let's be specific about what's actually being checked.
1. Your HRSA operational site visit reviews the health center program requirements - governance, scope, sliding fee, quality, credentialing. It's serious and it can absolutely hurt you. It is not a claims audit. Nobody on that team opens a chart to ask whether the code matches what the provider documented.
2. Your annual financial audit tests whether your statements fairly present your financial position. Auditors sample transactions. They are not adjudicating whether a modifier belonged on a claim, and they are certainly not evaluating whether the CEO can see enough. That's not their role.
3. Your UDS report is a data report. It tells HRSA who you served. It says nothing about whether you billed it correctly.
4. Your monthly financials feel the most like oversight, and they're the ones I'd look at hardest. If one person prepares the report, decides what goes in it, and is the only one who can explain a variance in it, you don't have oversight. You have that well-designed window.
Why do providers say they need 30 minutes?
Two doors. Neither one is malice.
1. Tenure. Somebody learned the job from the person before her, who learned it from the person before her. Nobody in that chain was ever trained by an outsider, and every one of them has been graded their whole career on one thing: did the claim get paid? Did the report go out? Was the patient seen? So habits accumulate. A modifier added back in 2017 because it stopped claims from bouncing - it works, so it's still there. A rule that changed, where the update went to an email address belonging to somebody who left. That's not incompetence. That's a good employee doing exactly what she was taught, for a long time, with nobody telling her the ground moved.
2. Relief. This is the one you won't see coming. At some point you were drowning. You inherited a mess, or you lived through COVID, or a bad funding year, or three in a row. And somebody competent walked in and said, I've got this. You were grateful, and you should have been. That person may have saved your organization. But relief is the thing that stops a CEO from asking the follow-up question. You don't audit the person who rescued you. You don't go poking at the one part of the organization that finally stopped hurting.
Which brings me to the distinction I'd tattoo on a whiteboard if I could:
Delegation is handing off the work. Abdication is handing off the visibility.
Those two look identical for six months. Twelve. Eighteen. Then they stop looking identical, usually at a very bad moment.
What does a closed loop actually cost?
The cost of any problem isn't just how bad it is. It's how bad it is times how long it ran before anybody looked. And extending that second number - time to detection - is the only thing a closed loop reliably does for you.
Catch a bad billing habit in year two and you have a correction and a repayment. Catch it in year six, or have somebody else catch it in year six, and it's a seven-figure conversation with attorneys in the room. Same error. Same team. Same good intentions.
For scale: once you identify a Medicare overpayment, the lookback is six years. Not this fiscal year. Six years.
And it runs the other direction too, which nobody talks about. Undercoding is the more common problem in our world, because cautious people serving vulnerable patients round down. There is no denial letter for money you never asked for.
I'll give you my own number. I inherited a health center carrying close to a million dollars in deficit. I usually say $800,000, because that's what I was handed on day one. The real number moved as we dug in - and the only reason it ever moved is that we started looking.
That deficit didn't appear the month I walked in the door. It built, in a building full of competent, well-meaning people, underneath reports somebody was reading every single month.
Nobody was lying to anyone. Nobody was checking, either.
How do I get line of sight back without blowing up a relationship?
Two fixes. Neither one is a confrontation.
1. Buy outside eyes, on a schedule. Every other year, hire an outside revenue cycle firm to pull a sample of your claims. Not a full audit - a sample. An outside firm works with dozens of health centers, so they see problems yours never will. You can't read the label if you're in the bottle.
2. Insist they look both directions. Where are we billing something we shouldn't, and where are we not billing something we should. Most firms only look for risk. The upside half is usually what pays for the whole engagement.
3. Put the same thing on the calendar everywhere one person is your single point of expertise. Payer contracts. Vendor contracts. Inventory. Cybersecurity. Your compensation structure. When it's scheduled, it stops being a decision you have to make about a person - which is what makes it feel like an accusation.
4. Set a line-of-sight floor. Not control - visibility. You don't need to approve every invoice and you shouldn't want to. But you should be able to see the A/R aging without asking anyone. Same with cash position. You should have read-only access to your own bank accounts - not to manage them, to see them. Ask someone to record a two-minute Loom video walking you through how a key report actually gets built, so next time you can run it yourself. And no single human being should be the sole holder of a key login.
5. Run the same question across every other function. Credentialing, grant reporting, IT. In each case: what would I need to be able to see, on my own, without asking permission, to know this is actually fine?
None of that requires you to distrust anybody. Every item is something a good leader in that seat should want - because the person with sole line of sight is also the person with sole blame the day something goes wrong.
The Part Nobody Says Out Loud
More than once in my coaching practice, a health center executive has asked me whether it's okay to ask their own team for a number they're entitled to see.
Not how to ask. Whether to ask.
They didn't need my permission. They needed somebody outside their organization to confirm that "can I see the A/R aging?" is a normal question for a CEO.
That's what makes this different from every other problem on your desk. A closed loop doesn't just hide the information. It makes asking about the information feel like an accusation. That's what keeps it closed.
And it compounds, because the longer you wait, the less routine the question sounds. Now you're not asking a normal question. You're asking one you visibly waited a year to ask.
Which is why the cheapest day to ask is always today. Not because something is wrong - because the question is still ordinary today, and it gets a little less ordinary every month you sit on it.
Your one thing this week
Two questions. Costs nothing, needs nobody's permission.
Ask your team: when is the last time anyone outside this organization looked at our claims? Not our finances - our claims. Most of you will get a pause, and then, "you know, I don't think anyone ever has."
Then ask yourself. Take a blank page and finish this sentence as many times as you can:
The only person who can tell me the truth about ______ is ______.
Your denial rate. Your days in A/R. Your 340B numbers. Your cybersecurity position. Your credentialing status. Your real cash position on a normal day of the week.
Every line you write is a closed loop. Some are completely fine - you can't personally verify everything and you shouldn't try. But find the ones where the answer would change a decision you're making this year. Those need a second set of eyes.
And notice what happens when you write it as a list. It stops being about a person. It's just a list.
Then go ask the one that made your stomach drop while you were writing it.
Want to keep going?
🎧 Listen to the full episode - You Didn't Lose Control. You Lost Line of Sight.on The Community Health Collective.
This is exactly the kind of thing we pull apart in the FQHC CEO Connect Bootcamp - somebody brings something they heard, and a room full of peers who have actually implemented it runs the numbers together. Our fifth cohort starts October 9, and enrollment is open now at www.fqhc-ceo.com.
📅 Or schedule a call with me and we'll talk about whether it's the right fit.
This work is hard, and it's getting harder. But you're capable of more than you think - and you're not doing this alone.
About the Author
Jill Steeley is the host of the Community Health Collective Podcast and an executive coach to leaders across community health centers, FQHCs, and mission-driven healthcare organizations. After two decades inside the healthcare leadership world and close to 250 healthcare leaders coached and mentored, she helps healthcare executives build the leadership skills they were never formally taught - and helps full leadership teams shift culture together rather than one leader at a time.
Learn more at jillsteeley.com.