Medical Identity Theft: Fixing Your Records and Bills
Medical identity theft can corrupt bills, insurance claims, and clinical records; recover both the financial record and the health record instead of treating it as ordinary credit fraud.

Medical identity theft is different from a stolen card because the wrong information can become part of a record used to make health decisions. A thief may use your name, insurance member number, Medicare number, or other identifiers to obtain care, prescriptions, devices, or insurance payments. Start by identifying the provider, insurer, pharmacy, laboratory, or collector connected to the unfamiliar service. Ask for the records related to that service, mark the entries that are not yours, and request correction through the provider or health plan. If the bad information reaches a credit report or collection account, work that financial record separately. Do not stop after a bill is waived if the chart still contains another person’s diagnoses, allergies, medications, or procedures.
The first clue often comes from an EOB, bill, or portal
An Explanation of Benefits for care you never received, a prescription you do not take, a provider you have never visited, a benefit-limit notice, or a collection account can all be warning signs. Save the original notice before calling. In the patient portal, capture the date, provider, procedure, and claim number associated with the unfamiliar entry. If your portal contains clinical notes that could affect future care, flag those specifically when speaking with the provider’s privacy or health-information-management office.
Do not assume every billing error is identity theft. Coding mistakes and duplicate claims occur. Ask the provider and insurer to explain the service and confirm whether the patient identity was verified. The distinction matters because a clerical correction may be simple, while misuse of your identity calls for broader protection and documentation.
Request records from every place the thief may have used your identity
FTC guidance recommends contacting each doctor, clinic, hospital, pharmacy, laboratory, and health insurer where the identity may have been used and asking for the relevant medical records. Keep the requests narrow enough that you can compare the questionable episodes. If a provider resists because the record contains information about another person, explain that you are reporting medical identity theft and ask for the organization’s privacy officer or health information management department. The goal is to correct information attached to your identity without obtaining unnecessary details about the thief.
HIPAA gives individuals rights to access and seek amendment of protected health information in many covered-entity settings, but the exact process and exceptions matter. Follow the provider’s current amendment form or written process and keep the response. If the amendment is denied, HIPAA includes rights related to a statement of disagreement in some circumstances. A simple phone note from billing is not a substitute for correcting a clinical record that could later influence treatment.
| Problem | Who owns the record | What to ask for |
|---|---|---|
| Unfamiliar medical service or diagnosis | Doctor, clinic, hospital, lab, pharmacy | Relevant chart, encounter, prescription, and amendment/correction process |
| Claim you did not make | Health insurer or Medicare plan | Claim detail, provider identity, fraud or appeals channel |
| Debt collection for care you did not receive | Collector and original medical provider | Debt detail, original account, identity-theft dispute path |
| Credit report item tied to fraudulent medical debt | Consumer reporting company and furnisher | Dispute or identity-theft block using the required documentation |
| Possible improper disclosure | Covered entity privacy office | Privacy complaint route and, where applicable, information about disclosure accounting rights |
Correct clinical data before it becomes a safety problem
A wrong blood type, allergy, diagnosis, medication, procedure, or substance-use entry can create more than financial inconvenience. Tell the provider exactly which entry you believe belongs to another person. Ask how the corrected or disputed information will be displayed to clinicians, not merely whether the balance is removed. If the organization operates several hospitals or clinics under one system, ask whether the correction propagates across the shared record.
Carry a concise corrected medication and allergy list while the dispute is open. If a wrong clinical fact could affect imminent care, tell the treating clinician directly and ask that the concern be noted. Do not wait for a billing investigation to finish before addressing a patient-safety issue.
Use the insurer to trace the fraud path
An insurer can often see the claim, rendering provider, date of service, and benefit impact. Ask the fraud or special-investigations unit to review claims you did not authorize and to explain whether a new member card or identifier is appropriate. If the misuse consumed a benefit limit, request written confirmation of the correction because that issue can resurface when you later seek legitimate care. For Medicare-related misuse, use the official Medicare and HHS channels rather than a generic credit-monitoring service.
- □ Save the EOB, bill, portal entry, collection notice, or claim that first showed the unfamiliar service.
- □ Request records from the specific providers and insurer associated with the questionable encounter.
- □ Mark clinical entries that could affect care separately from billing or insurance entries.
- □ Use the provider’s formal amendment or correction process and keep written responses.
- □ Dispute any resulting collection or credit-report item through the appropriate consumer-reporting process.
- □ Report broader identity theft at IdentityTheft.gov and secure insurance, email, and portal credentials.
A breach notice is not the same as medical identity theft
If a hospital says data was exposed, that is a reason to protect credentials and watch for misuse, but it is not proof that someone obtained care in your name. Read what data was involved and follow the organization’s breach instructions. If you later see a claim or chart entry you did not create, the incident moves from exposure to actual medical identity theft. Keep the breach notice because it may help explain how the identifiers were compromised, but do not assume causation unless the facts support it.
Escalate privacy or safety failures through the right channel
If a covered provider or plan refuses to address an access, amendment, or privacy issue that falls under HIPAA, HHS Office for Civil Rights has a complaint process. That is different from asking HHS to fix a bill; the provider or insurer still owns the underlying record. A state insurance regulator, state attorney general, Medicare fraud channel, or lawyer may also be relevant depending on the entity and harm. Use escalation when the primary record owner has failed to correct a documented problem, not as a substitute for making the correction request first.
Recovery is complete only when both sides reconcile
Before closing the incident, compare the corrected medical record, insurer claims history, outstanding bills, and any credit reporting. Make sure an invalid diagnosis or prescription did not survive after the claim was reversed. Save the written correction and the identity-theft report. Medical identity theft deserves this extra step because a future doctor can act on clinical data long after a fraudulent charge disappears from a statement.
Questions specific to Medical Identity Theft: Fixing Your Records and Bills
What is the biggest risk unique to medical identity theft?
Incorrect clinical information can be mixed into your health record and potentially affect future care. That is why correcting only the bill or insurance claim may be insufficient.
Can I ask a provider to amend a medical record?
In many HIPAA-covered settings, individuals have rights to request amendment of protected health information. Use the provider’s formal process and keep the written response; the rule includes limitations and procedures for denials.
Should I dispute medical identity theft with a credit bureau first?
If a fraudulent medical debt is reporting, use the credit-report process, but also correct the source provider and insurer records. The bureau cannot repair a contaminated clinical chart.
When should I complain to HHS OCR?
OCR can be relevant when a HIPAA-covered entity does not honor applicable privacy, access, or amendment rights. It is an escalation path for privacy-law issues, not a replacement for the provider’s billing or record-correction process.