If your practice is experiencing a high volume of fraudulent payment attempts through your third-party payment platform, it is important to understand where the activity is occurring and what protections can effectively address it.
We want to clarify what appears to be happening with the payment link.
The issue is not that someone is hacking your website. Credit card thieves are using the payment platform itself to rapidly test stolen card numbers and determine which cards are valid.
We can add an additional security barrier on your website before someone is redirected to the payment page, but more importantly, it would very likely not solve the problem at its core.
The reason is that the fraudulent activity is happening on the POS/payment platform itself. Once a bot discovers the direct payment URL, it can bypass your website entirely and continue submitting card attempts directly through the payment system.
For that reason, the strongest protection needs to exist on the POS provider side. They should have robust fraud-prevention tools such as bot detection, velocity limits, repeated-attempt blocking, IP/device monitoring, and card-testing prevention. That is the point where the transactions are actually being submitted, so that is where the abuse needs to be stopped.
Our recommendation would be to first contact the POS provider and ask them to enable or strengthen their anti-fraud and card-testing protections.
Another option would be to use a payment portal that integrates directly with your practice management system and verifies the patient before allowing them to submit a payment method. That creates a much stronger barrier because the person must be tied to a legitimate patient record before reaching the payment process.