The Justice Department recently charged 455 people in its annual National Health Care Fraud Takedown, with cases involving more than $6.5 billion in alleged false claims. Among those charged are 90 doctors or other licensed medical professionals. Prosecutors have also added aggravated identity theft charges in cases across dozens of states. While the DOJ emphasizes that charges must still be proven in court, the scale of the operation underscores a persistent and costly problem: medical identity theft.
Medical identity theft occurs when someone uses another person's name, Social Security number, health insurance account number, or Medicare number to see a doctor, fill a prescription, buy medical equipment, or submit a claim, according to the Federal Trade Commission (FTC). Unlike credit card fraud, which can often be resolved by canceling a card, medical identity theft leaves a trail of corrupted records that can follow victims into the doctor's office for years.
Once a thief's health information is mixed with a victim's medical records, the consequences can be serious. A blood type, drug allergy, diagnosis, or prescription that belongs to a stranger can appear in the file a physician reads before treating the victim. The FTC warns that mixed records can affect the care a patient is able to receive and the benefits they are able to use. In one case detailed by prosecutors, the co-owner of a Virginia mental health company allegedly paid homeless people with hotel stays in exchange for using their Medicaid numbers, then billed Medicaid for crisis services the patients never received.
Hospitals and insurers hold the exact records that make such fraud work, and those records are stolen often. This spring, NYC Health + Hospitals reported that an intruder had copied files that may have included health insurance information, medical information, biometric data, billing data, and other personal information. The breach later affected roughly 1.8 million current and former patients and employees. Once a name, Social Security number, insurance number, Medicare number, or medical record reaches a criminal marketplace, it can be resold to operators who bill under someone else's identity.
Because fraudulent medical claims run through insurance and provider systems instead of a credit check, they often skip the alerts most people rely on. The FTC recommends guarding health insurance and Medicare numbers as carefully as a payment card. Victims may first learn of the theft through a bill, explanation of benefits (EOB), or Medicare notice showing care they never received. When that happens, the FTC advises moving quickly and keeping everything in writing.
Victims should call their insurer or Medicare using the number on their card, not a number from a random text, email, or voicemail. They should ask for the provider name, date of service, claim number, and service details. Contacting the provider in writing and requesting the medical or billing records tied to that claim is also essential. Reporting the error to the insurer's fraud department and filing a report at IdentityTheft.gov can provide a recovery plan and documentation needed if fraudulent bills or collections appear later.
Under HIPAA, a provider generally has 30 days to give access to records after a written request, with a possible 30-day extension. Fixing the record itself can take longer. The Department of Health and Human Services (HHS) says a covered provider or health plan usually has up to 60 days to act on a request to amend a medical record, with a possible 30-day extension. If the provider or plan created the wrong information, it must amend inaccurate or incomplete information. However, a provider may refuse to release records that now contain a stranger's information, citing that person's privacy. In such cases, victims can ask for the provider's privacy officer or patient advocate, or file a complaint with the HHS Office for Civil Rights.
A credit freeze blocks new accounts but does nothing about a claim filed with an insurance number. Because medical identity theft can move without touching a credit file, monitoring where personal information appears is the earliest way to act on it. Identity theft protection services can monitor the dark web, data broker sites, and people-search sites for exposed Social Security numbers, driver's license numbers, medical ID numbers, and email addresses. They can also track credit bureaus for medical collections and flag public-record changes tied to a name. Some services include fraud resolution support and identity theft insurance for eligible recovery costs. No service can prevent every misuse of a medical identity, but ongoing monitoring may flag exposed information before another person's treatment reaches a victim's records and insurance.



