Medical Identity Theft: What You Need to Know

what is medical identity theft

Did you know that one in four reports of fraud the Federal Trade Commission (FTC) receives is related to identity theft? In fact, the cost of identity fraud reached a whopping $43 billion in the U.S. in 2023. 

Of course, scams that rely on stolen identities can take surprisingly sophisticated forms. Medical ID theft is one such category that has become exceedingly common over the past few years, siphoning money not only from innocent patients but also from the government, insurers, and the healthcare industry as a whole.

But what is medical identity theft, how can you detect it on time, and what measures can you take to prevent or mitigate the damage? In this article, we discuss the answers to all these questions in detail so you could safeguard your identity.

What Is Medical Identity Theft?

Medical ID theft is when someone steals your personal information and obtains medical care or submits fraudulent claims to your insurer.

A compromised social security number, medical records, and insurance information can all give way to such fraud.

Medical identity theft may occur due to deceptive practices of health care providers, health sector employees, as well as unknown third-parties. 

For example, a hospital employee could steal your medical records, a hacker can infiltrate your insurer’s customer databases, or an identity thief may use a phishing attack to dupe you into sharing sensitive personal data.

Once they get hold of your information, they can get prescription drugs, medical equipment, treatments, and other healthcare services and bill them under your insurance policy.

Medical identity theft victims could face serious, and often long-term, consequences as a result.

Think about it for a moment — if your medical care benefit limit gets used up by a fraudster, your insurance provider will refuse reimbursements. When you’re no longer able to submit claims, you’re forced to pay for medical services out of your own pocket.

Unpaid medical bills could affect credit reports, too, diminishing your credit ratings and compromising your financial credibility.

Things can get a lot worse — your health insurance company can alert officials to investigate if they notice suspicious claims, such as large purchases of prescription drugs. This can result in criminal charges filed against you.

Moreover, inaccurate health conditions in your medical records can cause doctors to prescribe the wrong treatments, which may put your health at risk.

Warning Signs of Medical Identity Fraud

doctor examining a patient's medical card

The good news is, you can detect a medical identity breach if you remain alert to critical red flags.

What could give away such a fraud?

  • Unexpected Calls and Letters From Debt Collectors

When a debt collector reaches out to you regarding an unpaid medical debt you don’t recognize, it’s likely because someone has impersonated you to receive health services.

  • Unfamiliar Medical Bills

Bills for medical care you haven’t obtained are usually the consequence of medical identity theft and associated scams.

  • Denied Coverage by the Insurance Provider

Has your health insurer notified you about reaching the full benefit limit? If so, it could be due to fraudulent claims exhausting your policy.

  • Unusual Collection Notices in Credit Reports

Unpaid healthcare debt appearing in your credit report is often one of the top warning signs of medical identity fraud.

Protecting Yourself From Medical ID Theft

Thwarting all medical identity threats isn’t practically possible. However, you can still prevent many of them and substantially minimize damage by proactively taking the following measures.

  • Know Who You’re Dealing With

Phishing is one of the most common tactics deployed in medical identity theft to steal personally identifiable information.

It relies on impersonations to mislead victims. For instance, a scammer could mimic your health provider to trick you into disclosing your insurance details.

To prevent such attempts, confirming who you’re interacting with is critical before you share information. To do this, you can reverse search phone numbers on Nuwber to authenticate callers or use a verified contact number to call back the relevant organization and cross-check details.

  • Guard Your Personal Information

When targeting victims, identity thieves typically go after PII they could benefit from.

PII could appear on your health insurance card, medical documents, and even prescription bottles. So, protecting these is important for preventing identity theft and resulting scams.

For example, safely store documents containing sensitive data to avoid physical theft and install a virus guard on your devices to block data breach attempts.

  • Keep Records

To keep track of your medical history, get into the habit of noting down dates and other critical details about each medical procedure, treatment, and doctor’s visit. In addition, request medical records from your health care provider and file them separately.

The same goes for statements you receive from your insurer. Don’t forget to monitor how much health insurance benefits you’ve used up.

These steps will be invaluable for quickly detecting discrepancies and unusual activities so you can take prompt action to prevent scams.

  • Check Medical Bills and Explanation of Benefits Statements

Want to identify red flags of fraud before you’re denied insurance coverage? Then, you must regularly review the explanation of benefits statements issued by your insurer and the billing statements sent by health providers.

Check what you’re billed for — does it tally with the records you’ve kept? Are there prescription drugs you haven’t purchased? Have you exceeded your insurance benefit limits?

Asking the three credit bureaus for your free credit reports and examining them carefully for any anomalies is another essential step.

Medical Identity Theft: Real Stories

what to know about medical identity theft

In 2010, Katina Candrick from LaGrange, Texas, as stated by Data Breach Today, was sentenced to 15 years in prison and ordered to pay $165,000 in restitution for committing identity theft, including possessing fraudulent identification documents illegally.

Candrick was working as a patient account representative for MedAssets, where she illegally gained access to personal information of more than 1,200 individuals from their billing accounts to make fraudulent purchases.

In another medical ID case, a woman named Sosa opened an email from Scripps Memorial Hospital in La Jolla with a $113,424 medical bill. What surprised her the most wasn’t even the sum, but the fact that she wasn’t a patient at this particular hospital. It turned out that another woman had stolen her identity to receive treatment at Scripps, as reported by CBS8.

To Summarize

Medical identity theft generally involves obtaining medical services or making insurance claims using stolen personal information.

The consequences of this type of fraud can be detrimental and may extend over several years. For example, inaccurate medical records could affect your treatments, fraudulent claims can use up your health plan, unpaid medical debt may erode your credit rating, and severe offenses could even get you entangled in criminal lawsuits.

However, identifying medical ID-related fraud isn’t so hard when you know which signs to watch out for. Medical bills and debt collection notices for unfamiliar treatments, sudden denial of insurance coverage, and suspicious activities in your credit reports are common red flags of an identity breach.

To prevent medical identity theft, verifying who you’re dealing with, safeguarding personal information, keeping records of your medical history, and regularly reviewing medical bills and explanations of benefits are essential practices.

FAQ

How often does medical identity theft occur?

According to FTC data, reported incidents of medical identity theft amounted to 13,683 in 2023.

This certainly pales in comparison to the 1,036,903 total reports of ID theft. However, it’s important to note that a medical information compromise can go unreported in many instances.

If you rarely exceed your annual Medicare claims limit or private insurance coverage, it would be easier for a deceptive individual or healthcare provider to sneak in an additional claim without you noticing. As a result, such cases will usually remain undetected and unreported.

What should I do if I become a victim of medical identity theft?

Start by gathering all records of evidence and submit a complaint to the FTC on its website. Obtaining a police report is also important, especially when informing your health insurance company.

For Medicare fraud or scams involving other services of the Department of Health and Human Services, ensure you notify the Office of Inspector General.

In addition, alert your health care providers and the credit bureaus about the incident to mitigate or minimize the likely damage.

Can medical debt arising from identity fraud affect my credit rating?

Yes, any type of unsettled debt, whether intentional or fraud-related, could leave a permanent black mark on your credit report.

Remember, credit bureaus simply report your rating based on available credit data. It’s natural for them to consider any unpaid medical debt recorded under your name, despite the fact that it may have resulted from identity theft.

Leaving such matters unresolved could prevent you from opening accounts and taking mortgages, loans, and credit cards. Therefore, detecting medical identity fraud is crucial for your financial future.

How should I respond if I receive a collection notice for an unknown medical debt?

The first thing to do when you don’t recognize the debt indicated in the collection notice is to request more information.

If you kept records of the healthcare treatments and services you’ve received in the past, it would be easier to detect discrepancies. Otherwise, you may need to contact your insurance and medical providers to verify details.

When the records are inaccurate, formally request an investigation from the relevant organization in writing so you could escalate the matter to law enforcement, FTC, and other related parties if it’s unresolved.

How does the HIPAA Privacy Rule help protect my personal data?

HIPAA Privacy Rule, or the Standards for Privacy of Individually Identifiable Health Information, is in place to protect patient data by regulating how information is safeguarded, used, and shared by providers of healthcare services as well as health plan providers and clearinghouses.

It covers personal information, such as a patient’s name and date of birth.

The HIPAA Privacy Rule also applies to medical information, including details about physical and mental health conditions, treatments provided, and payments made by the patient.

Eugene Kirdzei
Eugene Kirdzei

Chief Technical Officer at Nuwber
With nearly two decades of experience in the IT industry, Eugene possesses comprehensive knowledge across his professional field, including in data management, data protection, and information search. Through his writing, he aims to provide valuable insights and practical advice on how to safely explore the online environment and leverage digital tools to enhance people’s lives.