← All terms

Medical Identity Theft

Medical identity theft is the fraudulent use of someone's identity or health coverage to obtain care, drugs, or payouts — a lasting harm of healthcare breaches.

Medical identity theft is the fraudulent use of another person's identity, insurance details, or medical record number to obtain healthcare services, prescription drugs, medical equipment, or insurance reimbursements. It is the downstream crime that gives healthcare data breaches their long tail: while a stolen card number expires with the card, stolen protected health information supports fraud for years and cannot be reissued.

How it works

The raw material usually comes from a breach, a phished mailbox, or an insider, and is sold on underground markets where full health records command a premium over payment cards. Fraudsters then bill insurers or government programs for phantom treatment, fill prescriptions for controlled substances in the victim's name, or combine real medical identifiers with fabricated details into a synthetic identity. Victims often discover the crime only when a bill, a collection notice, or an insurance explanation-of-benefits arrives for care they never received — or, more dangerously, when someone else's blood type, allergies, or diagnoses have been merged into their medical chart and a clinician makes decisions on polluted data.

How to defend against it

For organizations, prevention is mostly upstream: stop the account compromises that leak records in bulk. That means multi-factor authentication in front of systems holding health data, least-privilege access, monitoring for abnormal record access, and sustained workforce training against phishing and pretext calls — the entry points behind most healthcare breaches, as covered in our guide to human risk in healthcare. HIPAA requires both the safeguards and the training, and regulators have fined providers whose staff fell to a single phishing email. Organizations should also verify patient identity at registration and reconcile billing anomalies quickly, since early detection limits both fraud losses and chart contamination. Individuals can read explanation-of-benefits statements as carefully as bank statements, request their records after any breach notice, and report discrepancies to their provider and insurer immediately.

Related terms

Protected Health Information (PHI)Protected health information (PHI) is individually identifiable health data safeguarded under HIPAA — and one of the most valuable targets attackers can steal.HIPAAHIPAA sets US rules for protecting health information — including a required security awareness and training program for the entire workforce.Synthetic Identity FraudSynthetic identity fraud combines real and fabricated personal data into a new, fake identity used to open accounts, pass checks, or get hired.Data BreachA data breach is an incident where confidential data is accessed, stolen or exposed by an unauthorized party — most often starting with a human mistake.
See your Human Risk Score

NOUSEC simulates attacks across 8 channels and turns the results into one number your board can read.

Book a demo