Medical Identity Theft: A U.S. Consumer Protection Guide

Learn what is medical identity theft and how to protect yourself. Discover warning signs and recovery steps to safeguard your health information.

Medical identity theft is when someone uses your name, Social Security number, or health insurance account number to get medical services, prescriptions, devices, or to submit fraudulent insurance claims in your name. Don’t panic. Do this first: call your insurer’s fraud unit today and save every bill, Explanation of Benefits (EOB), and pharmacy receipt you have.

  • Call your insurer’s fraud department. Get a case number.
  • Gather every EOB, bill, and medical statement you’ve received in the past 12 months.
  • Note any calls from debt collectors about medical bills you don’t recognize.

Pro Tip: Photograph or scan every document before you mail or fax anything. Originals disappear in disputes. Copies protect you.


Table of Contents

What are the warning signs of medical identity theft?

Spotting this early makes recovery far less painful. Here are the most common red flags:

  1. Unexpected EOBs or bills for services, procedures, or equipment you never received.
  2. Benefit-limit notices saying you’ve maxed out coverage you haven’t used.
  3. Debt collector calls about medical bills you don’t recognize.
  4. Wrong information at check-in — an address, date of birth, or surgical history that isn’t yours.

“If the thief’s medical treatment or diagnosis mixes with your treatment or diagnosis, your health is at risk.” — California Department of Justice, Office of the Attorney General

These identity theft warning signs look different from financial fraud because they show up in medical records, not just credit reports. A stranger’s blood type or allergy could end up in your chart.

Friendly fraud is a real and underreported problem. Many victims discover that a family member or close acquaintance used their insurance card. Because of that relationship, many never report it, which leaves the corrupted records in place and the financial damage unresolved.

Close-up of EOB statements with notes and glasses

Pro Tip: Check your EOBs every month, not just when a bill arrives. Set a calendar reminder.

Infographic showing warning signs of medical identity theft


How serious is medical identity theft — and what does recovery cost?

The financial and health stakes are higher than most people expect.

Immediate consequences include treatment delays, insurance claim denials, and incorrect diagnoses or allergies appearing in your chart. Long-term, you may face damaged credit, ongoing collection actions, and providers who refuse service because your records show unpaid balances that aren’t yours.

Medical records command up to $1,000 on illicit markets, far more than a standard credit card number. That price reflects how useful a complete health profile is for filing fraudulent claims, obtaining prescriptions, or creating fake patient identities.

Statistic: Medical identity theft accounted for 0.9% of all reported identity theft cases in the United States in 2024. Rare — but the consequences are uniquely severe because they corrupt your medical records, not just your credit file.

Stage What happens Typical timeframe
Discovery You notice an EOB error or collector call Day 1
Initial reports FTC report, insurer fraud call, provider contact Week 1–2
Record requests Gathering records from each provider and pharmacy Weeks 2–6
Disputes Correcting errors with providers, insurers, credit bureaus Months 2–6
Full resolution Records corrected, collections removed, credit restored 6–18 months

Recovery is manual and labor-intensive. You contact each provider, hospital, pharmacy, and insurer individually. Fees may apply for record copies. Budget time, not just money.


What should you do right now if you suspect medical identity theft?

Move through these steps in order. Don’t skip ahead.

  1. Preserve all evidence. Save bills, EOBs, collector letters, and voicemails. Screenshot anything digital.
  2. Call your insurer’s fraud department. Ask them to flag your account, open a fraud investigation, and send you copies of all claims filed in your name.
  3. Contact each provider directly. Request an itemized bill and your complete medical records. Ask who authorized each service.
  4. File an FTC identity theft report at IdentityTheft.gov. This generates a personal recovery plan and a report you can send to creditors and providers.
  5. Place a fraud alert with one of the three major credit bureaus (Equifax, Experian, or TransUnion). They notify the other two.
  6. Request your credit reports at AnnualCreditReport.com. Look for medical collection accounts you don’t recognize.
  7. Consider a credit freeze if you believe the fraud is ongoing. A freeze blocks new accounts from being opened in your name.

Sample call script for your insurer:
“I believe someone has filed fraudulent medical claims using my insurance. I need to open a fraud investigation, flag my account, and receive copies of all claims filed in my name for the past [X] months. Can you give me a case number?”

  • File a police report if you know who committed the fraud or if a creditor requires one.
  • Keep a log of every call: date, time, representative name, and case number.

Pro Tip: IdentityTheft.gov auto-generates dispute letters you can send directly to providers and collection agencies. Use them — they carry legal weight.


How do you check your medical and insurance records?

Request records from every organization that may have your health data.

  • Your insurer: Request an EOB history for the past 24 months and a list of all providers who billed under your policy.
  • Each treating provider and hospital: Ask for your complete medical record, including visit notes, diagnoses, and medication lists. Under HIPAA, they must provide access.
  • Pharmacies: Request a dispensing log showing every prescription filled under your name or insurance.
  • The Medical Information Bureau (MIB): Request your MIB consumer file at mib.com. Insurers use this database; errors here affect coverage decisions.

What to look for: Providers you never visited, diagnoses you’ve never received, medications you’ve never taken, and dates of service when you were elsewhere.

Record type Where to request What to look for
EOB history Your insurer’s fraud or member services line Unfamiliar providers, services, or dates
Medical records Each provider’s records office Wrong diagnoses, allergies, or procedures
Pharmacy log Your pharmacy’s patient services Prescriptions you never filled
MIB file mib.com (free once per year) Incorrect health history used for coverage
Credit report AnnualCreditReport.com Medical collection accounts

Pro Tip: Under HIPAA, you can request an “accounting of disclosures” — a log of who accessed your medical records. Ask for it. Unexpected access is a red flag.


How can you prevent medical identity theft?

Prevention is faster than recovery. Start with the highest-impact steps.

Offline hygiene:

  • Guard your insurance card like a credit card. Never photograph it and text it to anyone.
  • Shred all medical documents, EOBs, and prescription labels before discarding.
  • Avoid sharing insurance information with family members, even in emergencies, unless you’ve verified the need.
  • Check your mail promptly. Stolen EOBs are a common entry point.

Digital hygiene:

  • Use a strong, unique password for every patient portal and insurer account. A password manager makes this practical.
  • Enable multi-factor authentication (MFA) on every health-related account.
  • Never access patient portals on public Wi-Fi without a VPN.
  • Sign up for breach notifications. If a healthcare provider notifies you of a breach, act immediately.

Data-broker opt-outs: Your personal data on broker sites makes phishing attacks more convincing. Removing it reduces your exposure. See Techstacktoday’s guide on data broker removal for step-by-step instructions.

Pro Tip: Be skeptical of “free health screenings” or discount prescription offers that ask for your insurance number. These are common phishing setups.


Which digital privacy tools actually reduce your risk?

No single tool prevents medical identity theft on its own. But the right combination closes the gaps attackers exploit.

  • VPNs encrypt your connection on public Wi-Fi, blocking credential interception when you log into patient portals or insurer accounts. Look for a no-logs policy and independent audits.
  • Password managers generate and store unique credentials for every account, eliminating the reuse that lets one breach unlock dozens of accounts.
  • Data-removal services submit opt-out requests to data brokers on your behalf, reducing the personal data available to attackers building phishing profiles.
  • Identity monitoring services alert you when your information appears in breach databases or on dark-web markets.

Techstacktoday evaluates every privacy tool through hands-on testing in real-world scenarios, reviewing privacy policies, measuring technical performance, and verifying that no paid placements influence rankings. Use their privacy tools comparison checklist to evaluate options side by side.

One hard limit: Privacy tools cannot correct tainted medical records. A VPN won’t remove a wrong diagnosis from your chart. These tools reduce the risk of future theft and help you monitor for new incidents. Fixing existing record contamination requires the manual dispute process described above.

On dark-web value: Medical profiles fetch up to $1,000 on illicit markets. That’s why attackers combine breach data with stolen documents to build realistic fake patient identities. Data-broker removal and vigilant monitoring are your best digital defenses.


When should you hire professional help?

DIY recovery works for straightforward cases. Hire help when:

  • Multiple providers or insurers are involved and disputes are stalling.
  • A collection agency has sued you or obtained a judgment.
  • Incorrect medical records are actively affecting your care (wrong allergies, wrong blood type on file).
  • The fraud involves Medicare or Medicaid, which adds federal complexity.

Types of professional help:

  1. Identity-recovery services handle dispute letters, creditor calls, and monitoring on your behalf. Worth the cost if you lack time for a months-long manual process.
  2. Consumer attorneys specializing in identity theft or healthcare billing can send demand letters, dispute judgments, and pursue damages under the Fair Credit Reporting Act (FCRA) or state consumer-protection laws.
  3. Patient advocates and medical records specialists help you navigate provider records offices and correct clinical errors that administrative staff won’t fix on their own.

Red flags that mean get help now:

  • A provider refuses to correct records despite written disputes.
  • You’ve received a lawsuit summons for a fraudulent medical debt.
  • Your health insurer has canceled or suspended your coverage due to fraud-related claims.

Who do you report medical identity theft to in the United States?

File reports with multiple agencies. Each one has a different role.

  1. FTC — IdentityTheft.gov: Start here. Generates a personal recovery plan, dispute letters, and an official identity theft report.
  2. HHS Office for Civil Rights (HHS OCR): File a HIPAA complaint if a covered entity (hospital, insurer, clinic) mishandled your protected health information. File at hhs.gov/ocr.
  3. Your state attorney general: Many states have dedicated identity theft units. Find yours at naag.org.
  4. Medicare/Medicaid OIG: If fraud involves federal programs, report to the HHS Office of Inspector General at oig.hhs.gov or call 1-800-HHS-TIPS.
  5. Your insurer’s fraud department: File a formal fraud report and get a written confirmation.

Your HIPAA rights matter here. Under the HIPAA Privacy and Security Rules, covered entities must verify your identity before releasing protected health information and must maintain administrative, technical, and physical safeguards. You can request an accounting of disclosures — who accessed your records and when — from any covered entity.

Sample letter opening for disputing a fraudulent medical bill:
“I am writing to dispute a charge on account [number] dated [date]. I did not receive the services described. I have filed an FTC identity theft report (Report #[number]) and am requesting that this account be flagged as fraudulent and removed from my record.”


How do state laws on medical identity theft protection vary?

Federal law sets a floor through HIPAA and the FCRA. States often go further.

California has some of the strongest protections. The California Consumer Privacy Act (CCPA) gives residents the right to know what personal data businesses hold and to request deletion. The state also requires breach notification within 72 hours for healthcare entities.

Texas requires covered entities to notify affected individuals within 60 days of a breach. The Texas Medical Records Privacy Act extends HIPAA-like protections to a broader range of entities than federal law covers.

New York enacted the SHIELD Act, which expanded the definition of private information to include biometric data and health information, and requires businesses to implement reasonable data-security programs.

Florida mandates breach notification within 30 days, one of the shortest windows in the country, and allows individuals to place a protected consumer record freeze specifically for minors.

If you live in a state with stronger protections, you may have additional rights to request data deletion, receive faster breach notifications, or pursue state-level legal remedies. Check your state attorney general’s website for current rules.


How do you dispute a fraudulent insurance claim denial?

When a fraudulent claim results in a denial of your legitimate coverage, you have a clear path to dispute it.

Step 1: Request the insurer’s written explanation of the denial, including the claim number, date of service, and provider name.

Step 2: Compare the denial against your own EOB history. Identify which fraudulent claim triggered the denial.

Step 3: Submit a written appeal to your insurer. Include your FTC identity theft report number, a statement that the underlying claim was fraudulent, and copies of any supporting records.

Step 4: If the insurer denies your appeal, file a complaint with your state insurance commissioner. Every state has one, and most accept online complaints.

Step 5: For Medicare or Medicaid denials, contact your State Health Insurance Assistance Program (SHIP) counselor. SHIP provides free, unbiased help navigating federal program disputes.

Insurers are required under federal and state law to have an internal appeals process. If internal appeals fail, you may be entitled to an external independent review. Don’t pay a fraudulent bill to make the dispute go away. Paying it can be interpreted as accepting the debt.


Key Takeaways

Medical identity theft is rare but uniquely damaging because it corrupts your health records, not just your credit file, and recovery requires a manual, multi-agency dispute process that can take 6–18 months.

Point Details
Preserve evidence first Save every EOB, bill, and collector letter before contacting anyone.
Report to multiple agencies File with the FTC, HHS OCR, your insurer, and your state AG for full coverage.
Dark-web value is high Medical profiles sell for up to $1,000, making health data a prime target.
Privacy tools reduce future risk VPNs, password managers, and data-removal services close gaps but cannot fix tainted records.
Techstacktoday’s role Techstacktoday tests and ranks VPNs, password managers, and data-removal services with no paid placements, helping you choose tools that actually protect you.

Why medical privacy is both a digital and a paper-file problem

Most people think of identity theft as a digital problem. Medical identity theft proves that framing is incomplete. The most damaging cases often start with something low-tech: a lost insurance card, a family member who “borrowed” coverage, or a paper EOB pulled from an unlocked mailbox. By the time the fraud surfaces in a credit report or a provider’s records, months of contaminated data have already accumulated.

Privacy tools matter. A VPN protects your credentials on public Wi-Fi. A password manager stops credential reuse from turning one breach into ten. Data-removal services shrink the profile attackers can build on you. But none of those tools will call your cardiologist’s records office and correct a wrong blood type. That part is yours to do, manually, one provider at a time.

The reassuring reality: the process is documented, your rights under HIPAA and the FCRA are real, and the agencies you need to contact are accessible. Combining strong digital hygiene with the manual dispute steps above gives you the best realistic outcome. Start with the digital layer now, before you need the manual one.


Find vetted privacy tools with no paid rankings

Protecting yourself from medical identity theft starts with the right digital tools. Techstacktoday tests VPN services, password managers, and data-removal services in real-world conditions, with no paid placements influencing the rankings. Every review reflects actual performance.

Techstacktoday

If you’re ready to compare options, Techstacktoday’s trusted VPN review guides give you independent, tested recommendations you can act on today. No upsells. No sponsored results. Just honest evaluations from a team that tests what it recommends.


Useful sources and further reading

“Medical identity theft is when someone steals or uses your personal information to submit fraudulent claims to Medicare and other health insurers without your authorization.” — U.S. Department of Health and Human Services, Office of Inspector General

  • HHS Office of Inspector General — Primary federal resource on medical identity theft, including Medicare fraud reporting.
  • FTC — IdentityTheft.gov — Start your recovery here. Generates dispute letters and a personal recovery plan.
  • HHS Office for Civil Rights — File HIPAA complaints and learn your patient rights.
  • KFF Health News — Investigative reporting on healthcare fraud and breach exposure.
  • AARP Fraud Resource Center — Consumer-focused guidance, particularly useful for older adults.
  • Experian — Medical Identity Theft — Explains how medical identity theft occurs and credit-monitoring options.
  • California AG — First Aid for Medical Identity Theft — State-level guide with strong consumer protections explained clearly.

This article is general information, not legal or medical advice. Confirm current rules and your specific rights with the relevant agency or a qualified professional.

← Background Check Compliance Requirements: 2026 Guide Is a Data Removal Service Worth It for Your Privacy? →