The Dangerous World of Medical Identity Theft: How It Happens and How to Fight Back

Medical identity theft is a life-threatening crime that is growing at an alarming rate. According to the Federal Trade Commission (FTC), reported cases skyrocketed from 6,800 in 2017 to nearly 43,000 in 2021 — a staggering 533% increase in just four years.[^1] And those are just the known incidents. Experts believe medical identity theft is vastly underreported, as it often goes undetected for years.

In this dangerous form of identity theft, criminals steal personal medical information — such as a name, Social Security number, health insurance member ID, or Medicare number — and use it to fraudulently obtain medical services, prescription drugs, or insurance payouts. The victim is often left with massive bills, incorrect medical records, damaged credit, and even legal troubles.

As a cybersecurity professional with over a decade of experience securing healthcare data, I‘ve seen firsthand how medical identity theft can upend lives. In this article, I‘ll explain how this insidious crime occurs, the warning signs that your medical identity may be compromised, and crucially, steps you can take to protect yourself.

Inside Jobs: When Trusted Insiders Go Rogue

One of the most common ways medical identities are stolen is by malicious insiders — trusted healthcare professionals or administrative staff who abuse their authorized access to patient data.

According to a 2018 Accenture survey, a shocking 18% of healthcare employees said they would be willing to sell confidential data to unauthorized parties.[^2] Even more disturbing, 24% said they know of someone in their organization who has already done so.[^2] With medical records fetching up to $1000 each on the dark web black market[^3], the temptation can be hard to resist for unscrupulous insiders.

Insider threats are notoriously hard to detect and prevent. That‘s why they have a 66% success rate in healthcare — the highest of any industry.[^4] In one infamous case, an emergency room registration clerk stole patients‘ information for over a year, using it to open fraudulent credit lines.[^5] By the time she was caught, nearly 20,000 patients were affected.[^5]

Outsmarting Outsider Threats

Medical identity theft also frequently originates from outside a healthcare organization, as criminals exploit tried-and-true tactics like phishing and hacking.

Phishing emails and texts that appear to come from a trusted healthcare entity are a common trap. They may offer "free" medical services or claim there is a problem with your insurance, providing a link to a realistic but phony website where you are asked to "confirm" sensitive personal data. In reality, that information goes straight to an identity thief.

A related threat is medical device hacking. Many modern medical devices like insulin pumps and pacemakers have wireless connectivity, making them vulnerable to hackers who could potentially alter settings or even hold patient data for ransom.[^6]

On a larger scale, sophisticated cybercriminals target healthcare systems with ransomware, malware, and other network intrusion tactics, often through a third-party vendor with access to the network. Successful attacks can expose massive troves of patient data.

In 2015, hackers infiltrated health insurer Anthem, stealing personal information on nearly 80 million people.[^7] Targets are getting bigger too. In 2022, a breach at third-party vendor OneTouchPoint exposed 4.1 million individuals‘ data across more than 30 healthcare organizations.[^8]

Familiar Faces: When Fraudsters Are Friends or Family

Perhaps the most shocking way medical identities are stolen is by friends and family. In one survey, half of medical identity theft victims said their identity was used by someone they knew.[^9]

In many cases, a friend or relative may "borrow" the victim‘s insurance card or member number to obtain care or prescription drugs, either with or without the victim‘s knowledge. While this may seem harmless, it‘s still a federal crime. And if the thief racks up unpaid bills or triggers an insurance fraud investigation, the victim can face serious financial and legal consequences.

Experts call this "familiar fraud," and it may be more widespread than most realize. In one case, a Pennsylvania woman stole her sister‘s medical identity, racking up over $1 million in fraudulent charges for surgeries and prescription drugs.[^10] She was eventually sentenced to 6 years in prison, but only after her sister‘s credit and health were left in tatters.[^10]

The High Costs of Medical Identity Theft

Medical identity theft doesn‘t just harm individuals — it drives up costs throughout the healthcare system. The National Health Care Anti-Fraud Association estimates that healthcare fraud costs the nation about $68 billion annually, with a sizable chunk due to medical identity theft.[^11]

According to IBM, the average cost of a healthcare data breach in the U.S. is a whopping $9.23 million.[^12] When criminals steal medical identities en masse through data breaches, the costs can be astronomical. The 2015 Anthem breach cost the company over $260 million.[^7] Those costs inevitably trickle down to consumers in the form of higher premiums.

For individual victims, the financial toll can be devastating. The Ponemon Institute found that 65% of victims paid an average of $13,500 to resolve the crime.[^9] That includes paying off fraudulent medical bills, legal fees, and credit monitoring services. But for 35% of victims, the nightmare dragged on — they were still dealing with the fallout from their identity theft more than a year later.[^9]

Table 1: Average costs to resolve medical identity theft
Source: Ponemon Institute[^9]

The Diagnosis: Why Medical Identity Theft Is So Hard to Detect and Correct

What makes medical identity theft such an insidious threat is how long it often takes to uncover and the uphill battle victims face in resolving it.

Unlike credit card fraud, there are no laws limiting consumers‘ liability for fraudulent medical charges or capping the time it takes to resolve disputed health insurance claims. Meanwhile, healthcare organizations have up to 60 days to respond to a patient‘s request for their medical records and billing history — key tools in proving identity theft.[^13]

This means many victims end up paying thousands in fraudulent charges just to keep the bills from going to collections, or worse, defend themselves against criminal charges for drugs illegally obtained in their name. The resulting damage to their credit reports can take years to repair.

Even after fraudulent bills are resolved, erroneous information may linger in the victim‘s medical records. In one study, 15% of victims said medical identity theft led to a misdiagnosis, 13% received the wrong treatment, and nearly 1 in 10 had an adverse reaction to an inappropriately prescribed treatment.[^14] Correcting errors in your medical history can require exhaustive rounds of paperwork and phone calls with multiple providers and insurers.

The longer medical identity theft goes undetected, the more harm it can do. But spotting it quickly is a challenge. A health insurer may not discover the fraudulent charges until months after the fact, when they finally process the claims. The victim likely won‘t know until they review their explanation of benefits (EOB) statements or annual benefits summary, which many people skim or toss in the junk mail.

The Prognosis: A Technological Arms Race

Medical identity theft is a complex challenge unlikely to abate anytime soon. Evolving technology promises to make healthcare delivery more efficient but also opens up new avenues for increasingly sophisticated fraud.

The rapid growth of telemedicine in the wake of COVID-19 is one example. While virtual doctor visits are undoubtedly convenient, they also make it easier for criminals to impersonate a patient and get prescription drugs or medical equipment shipped directly to them.

Electronic health record (EHR) systems, now near-ubiquitous in healthcare, are another double-edged sword. While digitizing patient records makes them easier to share between providers, it also puts that sensitive data at greater risk of exposure via hacking. Alarmingly, the HHS estimates that between 2009 and 2021, data breaches involving protected health information grew at a rate of 42% per year.[^15]

The sheer volume of patient data that many healthcare companies oversee makes them tantalizing targets. In 2018, a hacking collective called The Dark Overlord stole 9.3 million patient records from a diagnostic medical imaging firm, holding the data for a $2.4 million ransom.[^16]

And as artificial intelligence and machine learning become more integrated into healthcare, securing those systems against tampering and misuse by bad actors will present a whole new cybersecurity battlefield.

Protecting Yourself: A Dose of Prevention and Early Detection

In this threatening landscape, shielding your medical identity is critical yet challenging. But there are proactive steps you can take to prevent, quickly spot, and recover from medical identity theft:

Prevention:

  • Guard your medical information as vigorously as your Social Security number. Only share when absolutely necessary.
  • Shred or securely destroy old medical bills, insurance statements, prescription labels, and doctors‘ notes before throwing out.
  • When seeking care, ask your providers how they secure patient data. What policies are in place for reporting breaches? Do they train staff on privacy protocols? Have they had past incidents?
  • Be wary of unsolicited requests for your medical information, especially over email or text. Don‘t click on links promising "free" health services.
  • Check medical devices‘ security features before use. Change any default passwords. Keep software up to date.
  • Regularly update login credentials on patient portals, insurance sites, and anywhere else you access medical information online. Use strong, unique passwords and enable two-factor authentication whenever available.
  • Consider signing up for identity theft monitoring, which scans for your information on the dark web.

Early Detection:

  • Carefully review every explanation of benefits (EOB) statement from your health insurer. Verify the listed services match what you actually received. Report any discrepancies.
  • Request your full medical record from each of your healthcare providers annually. Check for any errors and promptly dispute inaccuracies.
  • Periodically check your credit reports for suspicious unpaid medical bills. You‘re entitled to one free report from each bureau annually at AnnualCreditReport.com. Consider staggering requests so you can check one report every 4 months.
  • Be alert for warning signs of medical identity theft, such as debt collection calls for services you didn‘t receive, rejected insurance claims, or providers refusing to see you because your medical records show a condition you don‘t have.

Fast Response:

  • If you suspect medical identity theft, immediately contact your health insurer‘s fraud department and any involved providers. Report the crime to the FTC at IdentityTheft.gov and your local police.
  • Request copies of your medical records and check your insurance claim history. Document any errors and submit correction requests in writing.
  • Check your credit reports. Place a fraud alert and consider freezing your credit.
  • Notify the three major credit bureaus: Experian, TransUnion, and Equifax. Dispute any fraudulent medical debts on your credit reports.
  • Consider hiring a medical identity theft expert to help navigate the arduous resolution process.

Medical Identity Theft FAQs

Q: Can medical identity theft affect my credit score?\
A: Yes. Unpaid medical bills resulting from identity theft can show up as collections accounts or defaults on your credit reports, significantly damaging your credit scores. It‘s critical to dispute any fraudulent medical debts with the credit bureaus.

Q: How can I tell if someone used my health insurance without my knowledge?\
A: Closely review your insurer‘s explanation of benefits (EOB) statements for any services or prescriptions you didn‘t receive. Watch for unfamiliar healthcare providers listed on your insurance claims history or bills from unknown medical companies.

Q: If I lose my health insurance card, what should I do?
A: Immediately report the loss to your insurance company and request a new card. Ask if you can put a PIN, password, or note on your account requiring photo ID at point of service to prevent unauthorized use of your benefits.

Q: I got a breach notification letter from my healthcare provider. What next?\
A: The letter should explain what data was exposed, when, and what the company is doing about it. Take full advantage of any free credit monitoring or identity theft resolution services offered. Watch bills and EOBs closely in the coming months for fraudulent charges. Consider a credit freeze if your Social Security number was exposed.

Q: How can I safely dispose of old medical records and prescription bottles?\
A: The best method is crosscut shredding of medical documents and prescription labels. For bottles, remove labels, crush them, and place them in an opaque bag in the trash. Avoid recycling as that may increase risk.

Stronger Medicine

Combating medical identity theft requires stronger controls, collaboration, and awareness across the healthcare ecosystem.

Healthcare organizations need to prioritize cybersecurity as a patient safety issue, with robust protocols for access management, encryption, network monitoring, and swift data breach notification and remediation. Regular audits of employee access privileges and comprehensive cybersecurity training should be standard.

Policymakers and industry groups need to collaborate on national standards for securing health data and take a harder stance on punishing the criminals — and the companies — behind large-scale data breaches. Expanding consumer protection laws could help limit the liability and lasting damage victims face.

Technology companies and entrepreneurs should double down on innovations like blockchain-enabled health records, AI-powered anomaly detection, and advanced biometric patient identification to help prevent fraud.

Finally, an informed and vigilant public is the first line of defense. By raising awareness of medical identity theft, encouraging best practices, and destigmatizing victims, we can empower patients to better protect themselves and advocate for change.

I hope this article has given you a clear picture of the complex threat of medical identity theft and actionable tips to safeguard your medical identity. While the risks can feel overwhelming, remember that even small preventive steps go a long way. Stay alert, proactive, and don‘t hesitate to fight back if you become a victim. With greater awareness and collective action, we can work towards a future where your medical identity — and your health — are more secure.

[^1]: Federal Trade Commission Consumer Sentinel Network Databook 2021. (2022).
[^2]: Accenture 2018 Healthcare Workforce Survey on Cybersecurity. (2018).
[^3]: Experion. Here‘s How Much Your Personal Information Is Selling for on the Dark Web. (2017).
[^4]: Verizon. 2022 Data Breach Investigations Report. (2022).
[^5]: Douglas, J. Montefiore Medical Center employee stole thousands of patient records, authorities say. (2018). The Journal News.
[^6]: Schwartz, S. Medical Devices Vulnerable to Hackers, Report Says. Wall Street Journal. (2022).
[^7]: Mathews, A.W. Anthem: Hacked Database Included 78.8 Million People. Wall Street Journal. (2015).
[^8]: Davis, J. OneTouchPoint Data Breach Hits 30+ Healthcare Orgs, 4.1M Individuals. HealthITSecurity. (2022).
[^9]: Ponemon Institute. 2020 Cost of Healthcare Data Breach Study. (2020).
[^10]: Department of Justice, U.S. Attorney‘s Office, Western District of Pennsylvania. Pittsburgh Woman Gets 6 Years in Prison for Health Care Fraud and Aggravated Identity Theft. (2019).
[^11]: National Health Care Anti-Fraud Association. The Challenge of Health Care Fraud. (2022).
[^12]: IBM. Cost of a Data Breach Report 2022. (2022).
[^13]: HealthIT.gov. Individuals‘ Right under HIPAA to Access their Health Information. (2022).
[^14]: Ponemon Institute. 2013 Survey on Medical Identity Theft. (2013).
[^15]: U.S. Department of Health and Human Services Office for Civil Rights. 2021 Healthcare Data Breach Report. (2022).
[^16]: KnowBe4. Medical Data Hacks: The Most Infamous Breaches. (2022).

How useful was this post?

Click on a star to rate it!

Average rating 0 / 5. Vote count: 0

No votes so far! Be the first to rate this post.

Similar Posts