Medical Identity Theft
Medical identity theft is the fraudulent use of someone's identity or health coverage to obtain care, drugs, or payouts — a lasting harm of healthcare breaches.
Medical identity theft is the fraudulent use of another person's identity, insurance details, or medical record number to obtain healthcare services, prescription drugs, medical equipment, or insurance reimbursements. It is the downstream crime that gives healthcare data breaches their long tail: while a stolen card number expires with the card, stolen protected health information supports fraud for years and cannot be reissued.
How it works
The raw material usually comes from a breach, a phished mailbox, or an insider, and is sold on underground markets where full health records command a premium over payment cards. Fraudsters then bill insurers or government programs for phantom treatment, fill prescriptions for controlled substances in the victim's name, or combine real medical identifiers with fabricated details into a synthetic identity. Victims often discover the crime only when a bill, a collection notice, or an insurance explanation-of-benefits arrives for care they never received — or, more dangerously, when someone else's blood type, allergies, or diagnoses have been merged into their medical chart and a clinician makes decisions on polluted data.
How to defend against it
For organizations, prevention is mostly upstream: stop the account compromises that leak records in bulk. That means multi-factor authentication in front of systems holding health data, least-privilege access, monitoring for abnormal record access, and sustained workforce training against phishing and pretext calls — the entry points behind most healthcare breaches, as covered in our guide to human risk in healthcare. HIPAA requires both the safeguards and the training, and regulators have fined providers whose staff fell to a single phishing email. Organizations should also verify patient identity at registration and reconcile billing anomalies quickly, since early detection limits both fraud losses and chart contamination. Individuals can read explanation-of-benefits statements as carefully as bank statements, request their records after any breach notice, and report discrepancies to their provider and insurer immediately.
Related terms
NOUSEC simulates attacks across 8 channels and turns the results into one number your board can read.
Book a demo