What Is Medical Identity Theft? Warning Signs, Your Rights, and How to Fix Your Records
If a bill shows up for a surgery you never had — you’re not losing your mind. Medical identity theft happens when someone uses your name, Social Security number, or insurance details to get treatment, drugs, or equipment under your identity. It’s not the same as a stolen credit card. Once someone else’s diagnosis lands in your chart, you can’t just cancel it.
What Counts as Medical Identity Theft?
The Federal Trade Commission defines it simply: someone uses your personal information — your name, Social Security number, health insurance ID, or Medicare number — to get medical care, prescriptions, medical equipment, or to bill your insurer for services you never received. That’s it. No hacking skills required on the thief’s end. Just your information and a provider willing to bill it.
It’s a specific branch of a bigger problem. If you want the broader legal picture — how identity theft is defined, charged, and separated from cases of mistaken identity — our breakdown of identity theft versus mistaken identity covers that ground.
Here’s the part most people miss: this isn’t only about money leaving your account. It’s about someone else’s medical history getting mixed into yours.
This Isn’t Hypothetical — One Case Shows How Far It Can Go
In 2006, a woman named Anndorie Cromar had her driver’s license stolen out of her car in Salt Lake City. Months later, a methamphetamine user used that license to check into a hospital and give birth. When the baby tested positive for drugs, child protective services opened an investigation into Cromar — believing she was the mother — and threatened to take her own four children away. It took a DNA test, a lawyer, and months of court appearances before she was cleared, and years more before her medical records were fully corrected. Cromar told her story directly to Consumer Reports and Al Jazeera America, and it remains one of the most-cited examples of how far a stolen medical identity can travel from the original theft.
That’s the extreme end. Most cases look more like a strange bill or a denied claim. But the mechanism is the same one that nearly cost Cromar her kids.

How Do Thieves Get Your Medical Information?
Your medical file is worth more on the black market than your credit card number, because it can’t be canceled and reissued. Thieves get it a few common ways:
- Data breaches at hospitals, labs, pharmacies, and insurance companies
- A dishonest employee inside a medical office or insurer
- Lost or stolen insurance cards and mail
- Phishing calls or emails posing as your provider or “Medicare”
- A family member or friend using your insurance information — with or without your permission
That last one surprises people, but it’s the most common path of all. In the Ponemon Institute’s Fifth Annual Study on Medical Identity Theft, a quarter of victims admitted they had knowingly let a family member or friend use their identification to get care, and another 24% said a relative took their credentials without asking. It’s still medical identity theft either way, and it still shows up as your record, your bill, and your problem to fix.
Health data breaches are the biggest pipeline for strangers, though. We’ve covered several settlements tied to exactly this kind of exposure — including a breach that exposed Social Security numbers, health insurance information, and medical records that regulators and plaintiffs specifically flagged as a medical identity theft risk. Federal employees have faced a version of this too, after a major government data breach left millions exposed to ongoing identity theft risk years after the fact.
FTC complaint data tells the trend on its own. Reports of medical identity theft climbed from around 6,800 in 2017 to nearly 43,000 just four years later. That’s not a shrinking problem — it’s accelerating.
Warning Signs You’ve Been a Victim
Most people find out by accident, months after it started. Watch for:
- A bill or Explanation of Benefits (EOB) for a visit, test, or procedure you didn’t have
- A debt collector calling about a medical bill that isn’t yours
- Your insurer says you’ve hit an annual or lifetime limit you know you haven’t reached
- A new diagnosis, medication, or allergy on your chart that you never reported
- Medical collections on your credit report you don’t recognize
Ever opened an EOB and thought, “I didn’t go to that doctor”? That’s usually the first clue, and most people ignore it for weeks because it looks like a billing mix-up.
Why This Is More Dangerous Than a Stolen Credit Card
You can freeze a credit card in thirty seconds. You cannot freeze your Social Security number or your medical history. If a thief’s blood type, allergies, or prescriptions get mixed into your file, a doctor treating you in an emergency is working off the wrong information. That’s not a financial inconvenience — that’s a safety problem, and it’s the one detail that separates this crime from every other kind of identity theft.
What It Actually Costs to Fix
The Ponemon Institute’s Fifth Annual Study on Medical Identity Theft — the most detailed data set on this ever published — found that 65% of victims had to pay something out of pocket to resolve the crime, at an average of $13,453 per person. That figure is from 2015, so treat it as a floor, not a current price tag. It covered payments to healthcare providers, insurers, and legal counsel — money most victims never expected to spend on a crime they didn’t commit.
More recent secondary estimates put the broader cost to the healthcare system in the tens of billions annually, but those figures trace back through several layers of citation without a single confirmed current source, so we’re not repeating a specific number here. The $13,453 figure above is the one we could verify back to the original study.
Your Legal Rights If This Happens to You
You have more legal standing here than most people realize, and it comes from two federal laws working together.
HIPAA gives you the right to get copies of your medical and billing records from every provider involved, and to request that inaccurate entries — including ones created by a thief — be corrected or amended. Providers generally have 30 days to respond, with one 30-day extension allowed if they explain the delay.
The Fair Credit Reporting Act (FCRA) does two things for you. Section 609(e) lets you demand copies of the fraudulent transaction records tied to the theft, free of charge, within 30 days of a written request. And once you have an official FTC Identity Theft Report, the FCRA blocks businesses from reporting the resulting debt to credit bureaus.
Depending on your state, using someone’s medical identity without consent can also be prosecuted as a felony — the same way most identity theft cases are classified once real financial harm is involved. And if the theft traces back to a company’s failure to secure your data, you may have grounds for a civil claim against that company, similar to the legal theory behind data-breach identity theft lawsuits against major providers.
The laws exist. Most victims just never learn they apply here too.
What to Do Right Now If You Suspect Medical Identity Theft
- Go to IdentityTheft.gov and file a report. This generates an FTC Identity Theft Report and a personalized recovery plan.
- Request your records, in writing, from every provider involved — the doctor, the hospital, the pharmacy, the lab, and your insurer. HIPAA gives you that right.
- Send each provider a written request to correct or remove the fraudulent entries. Keep copies of everything you send and receive.
- Call your insurer’s fraud department and ask them to flag the account.
- Pull your credit reports and dispute any medical collections tied to the theft, using your FTC report to back up the dispute.
- File a police report if you can point to a specific incident — some FCRA protections require it.
This isn’t a five-minute fix like a stolen card number. Expect it to take weeks, sometimes longer if multiple providers are involved.
If You’re on Medicare, Do This Too
Medicare beneficiaries are a specific target, and there’s a dedicated channel for it. The Department of Health and Human Services’ Office of Inspector General says to contact your provider first if a charge looks wrong, and if it doesn’t get resolved, report it to 1-800-MEDICARE or your local Senior Medicare Patrol at 1-877-808-2468. Don’t skip this step just because you already filed with the FTC — Medicare fraud reporting runs on a separate track, and it’s the one that actually flags your claims history.
Medical Identity Theft — Frequently Asked Questions
Is medical identity theft the same as regular identity theft?
It’s a specific type of identity theft focused on medical and insurance information rather than credit or banking data. The legal definitions and reporting process through IdentityTheft.gov are the same either way.
Can medical identity theft show up on my credit report?
Yes. Unpaid medical bills run up in your name by a thief can be sent to collections and land on your credit report, even though you never saw a doctor or received the service.
Will my insurance drop me if I’m a victim of medical identity theft?
Insurers aren’t supposed to penalize you for fraud committed against you, but you’ll need to prove it happened. That’s why filing an FTC report and correcting your records quickly matters.
Can I sue over medical identity theft?
Sometimes. If a company’s data breach or a provider’s negligence led to the theft, you may have a civil claim. A consumer rights or data privacy attorney can tell you whether your specific facts support one.
How long does it take to fix medical records after identity theft?
Each provider has up to 30 days to respond to a correction request, with one possible 30-day extension. If multiple providers are involved, expect the full process to take a few months.
Does Medicare have separate protections for medical identity theft?
Medicare fraud involving your Medicare number is handled similarly — report it at IdentityTheft.gov and also to 1-800-MEDICARE so they can flag your claims history.
What if a data breach caused my medical identity theft?
Save your breach notification letter. It can support both your FTC report and any claim you later file against the company responsible, including any related class action settlement.
Sources Used in This Article
- Federal Trade Commission — “What To Know About Medical Identity Theft,” consumer.ftc.gov
- Federal Trade Commission — “Medical Identity Theft: FAQs for Health Care Providers and Health Plans,” ftc.gov
- Federal Trade Commission — “Businesses Must Provide Victims and Law Enforcement with Transaction Records Relating to Identity Theft” (FCRA Section 609(e) guidance), ftc.gov
- U.S. Department of Health and Human Services, Office of Inspector General — “Medical Identity Theft,” oig.hhs.gov
- Identity Theft Resource Center — “Correcting Medical Records Due to Identity Theft,” idtheftcenter.org
- Ponemon Institute — “Fifth Annual Study on Medical Identity Theft” (commissioned by the Medical Identity Fraud Alliance), medidfraud.org, published February 2015
- Consumer Reports — “The Rise of Medical Identity Theft,” consumerreports.org
- Al Jazeera America — “The Case of a Stolen ID and a Meth-Addicted Baby,” aljazeera.com
Researched and written by Israr Ahmad, legal content researcher and founder of AllAboutLawyer.com. All facts verified against Federal Trade Commission and HHS Office of Inspector General guidance, the Identity Theft Resource Center, the Ponemon Institute’s Fifth Annual Study on Medical Identity Theft, and reporting from Consumer Reports and Al Jazeera America, as of September 16, 2026. Last Updated: September 16, 2026.
This article is for informational purposes only and does not constitute legal or medical advice. Laws vary by state and individual circumstances differ. For advice about your specific situation, consult a qualified attorney or healthcare provider.
