Financial identity theft drains your bank account. You can watch it happen and freeze the account fast. Medical identity theft is different. It quietly rewrites a record you rarely check. You might not find out until later, maybe in an emergency room, when a doctor reads a blood type or an allergy that isn't yours.
In 2025, the Department of Justice charged 324 people in a nationwide health care fraud case. Together, they had filed more than $14.6 billion in fake claims. Ninety-six of the people charged were doctors, nurse practitioners, pharmacists, and other licensed medical professionals. Hackers don't always hide behind a screen; sometimes they have a medical license. Most of the fraud still started with stolen patient identities, not forged prescriptions.
What a hijacked chart actually does
Wrong treatment risk. Say a thief's blood type ends up in your file, or their drug allergy does. Now your doctor is working off faulty information in an emergency. That mistake could be very costly.
Used-up benefits. Insurance plans limit certain treatments, like physical therapy visits or specific prescriptions. If a thief uses up your limit first, your insurer may deny you care you actually need.
False diagnoses. Thieves often use stolen identities to get strong prescription drugs. This can leave a false record showing you were prescribed opioids. That record can follow you into insurance and background checks, even if you never took a single pill.
How the data gets stolen
Medical identity theft rarely starts with a lost insurance card. It almost always starts with a data breach. Hackers break into a health provider's computer systems. They steal a full profile: your name, SSN, birth date, and insurance ID. Then they sell it on the dark web.
This already happened in 2026. In August, an Australian telehealth company called Updoc said it was hacked. Updoc serves more than 500,000 people. The hackers got names, emails, and mailing addresses. Updoc stopped the attack fast, and no health records or payment details were confirmed stolen this time. Updoc hasn't said how the intruder got into that external system. But the pattern matters. Telehealth companies are now common targets. Once hackers get in, insurance and treatment data are often next.
- Read every EOB. Your insurer sends an Explanation of Benefits after each claim. See a provider you don't know, or a date you weren't there? Report it right away.
- Check your records once a year. Under HIPAA, you can ask any doctor or hospital for your full file. Look for prescriptions or conditions that aren't yours.
- Guard your insurance card like your Social Security card. Only carry it on days you have an appointment.
There's no credit report for your medical history. That means you have to check it yourself. If you spot signs of fraud, call your insurer's fraud department right away. Then contact every doctor, clinic, and pharmacy involved, and ask them to fix your record in writing.
Was your info in a breach tied to your email?
Our free scan shows which known breaches contain your email and whether identity data was exposed alongside it.
Run the Free Breach Scan →