Medical Identity Theft

Medical Identity Theft

Medical identity theft involves the fraudulent use of a person’s health insurance information to receive reimbursement for healthcare services provided to an individual not covered by the policy. Other times, the information is stolen by employees or external hackers to profit from selling personal identifying information (PII). Medical identity theft is the fraudulent use of a person's health insurance information in order to receive reimbursement for healthcare services. Perpetrators of medical identity theft include hackers who use social engineering to obtain social security numbers and health insurance information from unsuspecting medical providers and patients. Medical identity theft involves the fraudulent use of a person’s health insurance information to receive reimbursement for healthcare services provided to an individual not covered by the policy. The Fair Credit Reporting Act requires each of the three credit reporting bureaus to supply consumers with a free credit report once per year. Federal law also entitles consumers to receive free credit reports if any company has taken adverse action against them. This includes denial of credit, insurance, or employment as well as reports from collection agencies or judgments.

Medical identity theft is the fraudulent use of a person's health insurance information in order to receive reimbursement for healthcare services.

What Is Medical Identity Theft?

Medical identity theft involves the fraudulent use of a person’s health insurance information to receive reimbursement for healthcare services provided to an individual not covered by the policy. Both patients and providers may commit fraudulent medical claims, depending on circumstances. Other times, the information is stolen by employees or external hackers to profit from selling personal identifying information (PII).

Medical identity theft is the fraudulent use of a person's health insurance information in order to receive reimbursement for healthcare services.
It is possible that both patients and providers may commit fraudulent medical claims but information can also be stolen by employees or external hackers.
When an insurance provider commits identity theft it is to obtain reimbursement for procedures that were never performed on the insured individual.
Medical identity results in similar outcomes to other types of identity theft. Damages include lowered credit ratings, denial of services, increased costs of coverage, and denial of coverage.
Monitoring your credit reports, bills sent by insurance companies, and guarding your private information can help guard against or make you aware of medical identity theft.

Understanding Medical Identity Theft

Medical identity theft uses insurance coverage information for one individual to obtain or pay for care for another individual. In fact, medical organizations accounted for 30% of all observed enterprise attacks between 2006 and 2016.

Perpetrators of medical identity theft include hackers who use social engineering to obtain social security numbers and health insurance information from unsuspecting medical providers and patients. However, hackers are not the only threat to the loss of data.

A healthcare provider is almost equally likely to lose private information through either the theft of laptops, flash drives, and backup copies, or by the leaking of private data from an employee.

The loss of patient data from unauthorized access to an insurance company’s or healthcare provider’s database is like other types of identity theft. Motivations for employees who steal patients’ data include greed, revenge, and other agendas. 

Use of Stolen Medical Identities

Stolen health insurance information gets misused in two primary ways. 

  1. Consumers steal insurance information to cover benefits their insurance may not include, or because they have no insurance at all. For example, a drug trafficker might use fraudulent insurance information to purchase prescription drugs.
  2. Providers also may file fraudulent claims on an individual’s insurance to obtain reimbursement for procedures they never performed. They may do this to offset the cost of treating uninsured or under-insured clients.

Victims of medical identity theft can suffer similar outcomes to victims of other types of identity theft. Damages include lowered credit ratings and denial of services. If thieves trigger thresholds for maximum benefits on a policy, policyholders may find themselves unable to get timely coverage for urgent treatments. They might see the yearly cost of their insurance increase, or denied coverage altogether if the fraudulent treatment included care for things like diabetes, osteoarthritis, or cancer.

When medical identity fraud causes erroneous medical records, the consequences could become even more significant. For example, if an identity thief obtains medical care that enters the wrong blood type into a patient’s medical records and the victim of stolen identity needs a blood transfusion, the results could endanger their life.

Avoiding Medical Identity Theft

The best protection against either external or internal theft is constant monitoring through the use of honeypots and other security practices. Portable storage devices should be carefully regulated, and a regular inventory of their use and location kept. Regulation of employees with access to patient data also needs monitoring with the granting of access based on the work responsibilities of the employee.

The Health Insurance Portability and Accountability Act (HIPAA) passed by Congress in 1996 requires health care facilities in the U.S. to follow strict guidelines to ensure they treat patient data, including insurance information, carefully. 

Providers who commit medical identity theft usually do so to obtain reimbursement from an insurance company or the government for services they did not provide. To detect and prevent this type of fraud, consumers should carefully review any explanations of the benefit payments they receive from their insurers. Contact your insurance provider immediately if you get a statement for a procedure you did not receive.

Medical identity thieves typically require a patient’s Social Security number as well as their medical insurance information. Therefore, consumers should guard this information carefully. Only provide your social security number or health insurance information when necessary and then, only release the information when its security is guaranteed.

Credit Reports

Consumers should watch their credit reports for unpaid medical bills that enter collections. The Fair Credit Reporting Act requires each of the three credit reporting bureaus to supply consumers with a free credit report once per year.

Federal law also entitles consumers to receive free credit reports if any company has taken adverse action against them. This includes denial of credit, insurance, or employment as well as reports from collection agencies or judgments. Consumers must request reports within 60 days from the date of the adverse action.

Also, consumers whose main income is from Temporary Assistance for Needy Families (TANF) benefits, unemployed individuals planning to look for a job within 60 days, and victims of identity theft are also entitled to a free credit report from each of the reporting agencies.

Related terms:

Credit Card Cloning

Credit card cloning is copying stolen card information using an electronic device and copying it to a new card. read more

Credit Freeze

A credit freeze is an anti-fraud measure in which a credit bureau refrains from sharing a consumer’s credit report with any third parties. read more

Credit Report

A credit report is a detailed breakdown of an individual's credit history, provided by one of the three major credit bureaus. read more

Fair Credit Reporting Act (FCRA)

The Fair Credit Reporting Act (FCRA) is the federal law regulating the collection of consumers' credit information and access to their credit reports. read more

Health Insurance Portability and Accountability Act (HIPAA)

Health Insurance Portabiilty and Accountability ACT (HIPAA) is an act created by the U.S Congress in 1996 to ensure the privacy of personal medical data. read more

Identity Fraud Reimbursement Program

An Identity Fraud Reimbursement Program is insurance coverage for losses due to fraudulent use of personal financial information. read more

Identity Theft

Identity theft occurs when your personal or financial information is used by someone else to commit fraud. read more

Personally Identifiable Information (PII)

Personally identifiable information (PII) is information that, when used alone or with other relevant data, can identify an individual. read more

Social Engineering

Social engineering is the act of exploiting human weaknesses to gain access to personal information and protected systems. read more

Synthetic Identity Theft

Synthetic identity theft is a type of fraud in which a criminal combines real (usually stolen) and fake information to create a new identity. read more