Medical Identity Theft: How to Spot It and Fix Your Records


Most people know to watch their bank statements and credit reports. Almost nobody checks their medical records. That gap is exactly why medical identity theft is one of the most damaging and least detected forms of fraud: it can drain your insurance benefits, saddle you with bills for treatment you never received, and — uniquely among identity crimes — put false information into the file doctors use to treat you.

Health records sell for far more on criminal markets than credit card numbers, because they contain everything needed for sustained fraud: name, date of birth, national insurance or Social Security number, address, insurance policy details, and often financial data. Here is how the fraud works and how to detect and unwind it.

What Medical Identity Theft Looks Like

Someone uses your identity or insurance details to obtain healthcare. In practice that means one of several patterns:

  • Treatment fraud. An uninsured person uses your insurance card or policy number to get care — an emergency room visit, a surgery, ongoing prescriptions.
  • Prescription fraud. Your details are used to obtain controlled substances, which are then resold. This is a frequent driver of the crime.
  • Provider billing fraud. A dishonest clinic bills your insurer for services never rendered, using patient identities harvested from a breach.
  • Equipment fraud. Expensive durable medical equipment is billed against your policy and shipped elsewhere.
  • Enrolment fraud. Someone uses your identity to enrol in coverage or claim benefits.

Why It Is So Hard to Spot

Credit card fraud produces an immediate, itemised statement. Medical fraud produces an Explanation of Benefits document that most people file unread, or a bill that arrives months later from a provider you have never heard of and assume is a mistake.

Worse, health privacy laws that protect you can slow down your own investigation. Once fraudulent treatment is mixed into your file, the thief's information is also protected health information, and providers may be cautious about what they will show you.

Warning Signs

  • An Explanation of Benefits listing a doctor, date, or procedure you do not recognise.
  • A bill or collection notice for medical care you never received.
  • A call from a debt collector about a medical account you cannot place.
  • Your insurer says you have reached a benefit limit — a cap on physiotherapy sessions, a lifetime limit, an annual maximum — that you know you have not used.
  • A denial of coverage for a condition you do not have.
  • Your pharmacy says you already filled a prescription you did not.
  • Records in your patient portal showing visits, allergies, blood type, or diagnoses that are not yours.
  • A letter confirming enrolment in a plan you never applied for.

Any one of these deserves a phone call the same week. Do not assume it is a clerical error.

How to Protect Yourself

1. Read Every Explanation of Benefits

This is the medical equivalent of checking your bank statement, and it is the single most effective habit. Check the provider name, the service date, and the procedure. If anything is unfamiliar, call the number on your insurance card — not any number printed on a suspicious bill.

2. Request Your Records Annually

Ask your insurer for a full claims history for the past year, and ask your main providers for a copy of your medical file. In the UK you can access your GP record through the NHS App. In the US you have a right to your records and an accounting of disclosures. Review both for entries that are not yours.

3. Treat Your Insurance Card Like a Credit Card

Do not photograph it and send it over messaging apps, do not post it, and do not give the policy number to anyone who calls you unsolicited. Legitimate insurers already have your number.

4. Recognise Health-Themed Phishing

Fake messages about test results, prescription refills, insurance renewals, or health benefits are extremely effective because they create curiosity and anxiety. Never log in through a link in such a message. Open the patient portal or insurer app directly.

5. Secure the Patient Portal Itself

Use a unique password stored in a password manager and turn on two-factor authentication if the portal offers it. A compromised portal account hands over the full record.

6. Be Sceptical of "Free" Health Offers

Free genetic testing kits, free braces, free mobility scooters, or free screenings offered by phone or at community events are a common harvesting tactic. They ask for your insurance details, then bill your policy for equipment you never wanted.

7. Dispose of Paperwork Properly

Shred anything with a policy number, member ID, or claim reference. Do not leave prescription labels on discarded bottles.

If It Already Happened

  1. Call your insurer's fraud line and formally report it. Ask them to flag the account and to send you a full claims history.
  2. Contact every provider named in the fraudulent claims. Ask for a copy of the records associated with the visit and state in writing that you were not the patient.
  3. Request corrections in writing. Ask each provider to amend the record and to notify anyone they shared it with. Keep copies of every letter and note the date, time, and name of everyone you speak to.
  4. File an official report. In the US, report to the FTC at identitytheft.gov and to your insurer; Medicare fraud goes to 1-800-MEDICARE. In the UK, report to Action Fraud and notify the provider's data protection officer.
  5. File a police report if debts or prescriptions are involved. Many providers require one before they will write off fraudulent charges.
  6. Check your credit report for medical collections and dispute them. Place a fraud alert or credit freeze, since whoever has your health data usually has enough for financial fraud too.
  7. Verify your record is actually corrected a few months later. Amendments frequently fail to propagate to every system that received the original data. This step is the one people skip and the one that matters most clinically — a wrong blood type or allergy in your file is a safety risk, not just a billing problem.

The Bottom Line

Medical identity theft is slow, quiet, and unusually hard to reverse, because the damage lands in two places at once: your finances and your clinical record. The defence is unglamorous — read your Explanation of Benefits documents, pull your records once a year, protect your policy number as carefully as your card number, and never hand over insurance details to someone who contacted you first. If you find something wrong, act in writing, keep a paper trail, and follow up until the correction is confirmed in every system that holds it.

Comments

Popular posts from this blog

Best Antivirus Software of 2026: Top 5 Compared After Real Testing

Public Wi-Fi Dangers: 7 Critical Steps to Stay Safe

Best Identity Theft Protection Services of 2026: Top 5 Ranked and Reviewed