A trusted clinic employee used two ordinary financial tools—company credit cards and bank accounts—to take more than half a million dollars, according to her guilty plea. Her July 31 sentence brings prison time and a $539,451.41 restitution order. For owners approaching retirement, the case shows why access that helps a business run can also become an uninsured concentration of risk.
The loss accumulated through authorized access used improperly
Brooke Miller Duck worked for medical clinics with offices in Lafayette and Baton Rouge. Her role gave her access to cards and bank accounts, but not permission to use them for herself.
The Western District of Louisiana’s August 4 release says Duck caused $539,451.41 in unauthorized credit-card transactions between May 2020 and October 2023. She received 22 months in federal prison and three years of supervised release after pleading guilty in March.
Free retirement updates: Want plain-English help keeping more of your money in retirement? The free Retirement Shield newsletter covers scams, benefits, and money many retirees may be owed, a couple times a week. Subscribe free.
Paying the card bill concealed the card spending
Prosecutors said Duck used clinic cards for purchases that included a $15,000 timeshare payment, vacations, vehicles and consumer products. She then drew money from clinic bank accounts to pay the balances associated with those charges.
That circular movement can defeat a review focused only on whether bills were paid on time. The card statement contains the merchant detail; the bank statement merely shows a payment to the card issuer. Reconciliation must connect both sides and require business documentation for the underlying purchase.
Owners should receive statements through a channel the spender cannot change and review transactions before the payment date. A monthly profit report may reveal margin pressure but not identify a personal merchant buried among legitimate purchases.
Card limits should reflect the maximum legitimate purchase rather than the employee’s seniority. A separate card for recurring vendors can make travel and consumer merchants easier to spot. Declined-transaction notices also matter because an attempted personal charge may reveal misuse before money leaves.
Access should be divided before succession begins
Small businesses often depend on one manager to order supplies, pay bills, maintain cards and speak with the bank. That efficiency becomes dangerous when the same person can create a transaction, approve it, hide the statement and reconcile the account.
Separating those steps does not require a large finance department. One person can initiate, a second can approve above a threshold, and the owner or outside accountant can review statements delivered independently. Vendor changes and new electronic payees deserve additional confirmation.
Bank account permissions can be divided as well. Viewing balances, preparing payments and releasing funds are distinct rights on many business platforms. Giving a manager only the access needed for the assigned task creates an electronic boundary that trust alone cannot provide.
The FBI’s white-collar crime overview includes corporate fraud and money movements that abuse trust. Criminal enforcement comes after the loss; internal separation is designed to make abnormal transactions visible while recovery is still possible.
Digital controls need financial controls beside them
Bank portals should assign individual credentials rather than a shared password, with access limited to the employee’s duties. Transaction alerts, approval limits and removal of former employees can shorten the opportunity for misuse.
The FTC’s small-business cybersecurity guidance emphasizes account security, backups and staff practices. Those measures also strengthen embezzlement investigations by preserving who accessed a system and when. A secure shared password is still a weak audit trail if several people use it.
Paper controls matter too. Receipts should show the business purpose and approver, not merely match the amount. Repeated round-dollar purchases, personal travel merchants, credits followed by new charges and expenses outside normal clinic operations deserve prompt review.
A clinic also holds sensitive patient and insurance information. Financial misconduct by a privileged employee should trigger a review of access logs and data exports, even when prosecutors announce only theft of money. The inquiry should remain evidence-based and avoid assuming a privacy breach that records do not show.
Restitution does not guarantee retirement capital returns
A court order establishes an obligation to repay; it does not ensure the defendant has assets equal to the loss. Owners should not treat restitution as a substitute for insurance, cash reserves or controls. Recovery can be slow and incomplete.
Crime or fidelity coverage may respond to employee theft only under specific terms, notice deadlines and documentation requirements. The policy limit, deductible and definition of employee can leave gaps. An annual review should compare coverage with the largest balance one trusted worker could reach.
Succession planning should include a credential and authority inventory. The list needs bank portals, cards, payment processors, payroll, tax accounts and vendor systems, plus who can add another user. Removing a departing manager from email while leaving financial tokens active does not complete the transition.
The clinic case is especially relevant when a founder is preparing to sell or retire. Hidden losses can reduce working capital, distort earnings and weaken the valuation used to finance retirement. Clean account access and independent reconciliation protect not only this month’s cash but the business value the owner expects to carry away.
Card controls can be designed around the clinic’s actual spending pattern. Merchant-category blocks, per-transaction limits and separate cards for travel or purchasing make unusual charges easier to isolate. A $15,000 timeshare payment is not a subtle medical-supply expense, but it can escape notice when the reviewer sees only an automatic payment to the card company.
Bank-account permissions deserve a quarterly inventory. The owner should know who can view balances, initiate transfers, add payees, approve payments and change statement delivery. Dormant users and old devices should be removed, while dual approval should apply to transactions large enough to impair payroll or patient operations.
Insurance can help with some employee-theft losses, but policy definitions, exclusions, discovery periods and notice deadlines matter. A business should not assume a general liability policy covers embezzlement. Crime or fidelity coverage should be compared with the maximum cash exposure created by cards, checks and electronic transfers, then paired with controls because a claim cannot restore disrupted operations immediately.
After suspected misuse appears, preserving evidence takes priority over confronting the employee impulsively. Statements, receipts, access logs and accounting backups should be secured without altering originals. Counsel, the financial institution, insurer and investigators may need coordinated notice, while patient records and unrelated employee information remain protected.
This article was researched and drafted with AI assistance and reviewed against the linked primary sources.
More Financial Reading
- Bank statements: how long to keep them and when to toss them
- Adding someone to your bank account: tax traps and smart moves



