Medical Identity Theft: EOB Review, HIPAA Rights, and Fixing Your Records

Medical identity theft happens when someone uses your name, insurance ID, or Social Security number to get medical care, prescriptions, or equipment, or to bill a health plan, leaving false information mixed into your own medical and billing records. Unlike a fraudulent credit card charge, which you can dispute and walk away from, a false medical record can affect the care you receive later, since a treating provider may rely on an entry describing a condition, allergy, or medication that was never actually yours.
Information last verified on 2026-08-13. This article has not yet been reviewed by a licensed lawyer.
This page covers how to spot medical identity theft using your own paperwork, the two HIPAA rights that do the heaviest lifting once you've found it, and how to notify every provider and insurer that received the false records. It does not cover freezing your credit, which is a separate step covered at Credit Freeze vs. Fraud Alert, or the general FTC reporting process, covered at How to Report Identity Theft.
Warning Signs of Medical Identity Theft
IdentityTheft.gov lists three medical-specific entries among its identity-theft warning signs:
- A medical provider bills you for services or equipment you never received.
- Your health plan rejects a legitimate claim because its records show you've already reached a benefits limit you haven't actually reached.
- Your health plan won't cover you because its records show a health condition you don't actually have.
Source: IdentityTheft.gov, Warning Signs of Identity Theft (verified 2026-08-13)

Reviewing Your Explanation of Benefits (EOB)
The HHS Office of Inspector General, the federal watchdog for Medicare and Medicaid fraud, recommends reading every Explanation of Benefits statement your health plan sends, not just the ones tied to a bill you actually owe, as one of its core "Defend" steps against medical identity theft:
"Check All Your Medical Bills, Medicare Summary Notices, Explanation Of Benefits, and Credit Reports: Were you charged for any medical services or equipment that you didn't get? Do the dates of services and charges look unfamiliar? Were you billed for the same thing twice? Does your credit report show any unpaid bills for medical services or equipment you didn't receive? Have you received any collection notices for medical services or equipment you didn't receive?" Source: HHS Office of Inspector General, FIGHT BACK! Medical Identity Theft & Medicare Fraud (verified 2026-08-13)
An EOB lists the provider, the date of service, and what was billed to your plan for a specific visit or procedure, even when your plan paid the claim in full and you owe nothing. If a listed provider, date, or service does not match care you actually received, or a claim gets denied because your plan's records show you've used up a benefit you haven't touched, that is exactly the pattern IdentityTheft.gov flags as a warning sign above. Save every EOB you receive; you will need copies to show a provider or insurer which specific claims are fraudulent once you start the correction process below.

Your HIPAA Right to Get a Copy of Your Records
Before you can prove which entries are fraudulent, you need the actual records. HIPAA's Privacy Rule gives you a broad right to see them:
"The Privacy Rule gives you, with few exceptions, the right to inspect, review, and receive a copy of your medical records and billing records that are held by health plans and health care providers covered by the Privacy Rule." Source: HHS, Your Medical Records, 45 CFR §164.524 (verified 2026-08-13)
A provider cannot deny you a copy for nonpayment of services. It can charge a reasonable fee for copying and mailing, but it cannot charge a separate fee just to search for or retrieve the records.

Your HIPAA Right to Correct Fraudulent Entries
Once you've found entries created by whoever used your identity, HIPAA gives you a direct mechanism to request a correction, called an amendment:
"An individual has the right to have a covered entity amend protected health information or a record about the individual in a designated record set for as long as the protected health information is maintained in the designated record set." Source: 45 CFR §164.526(a)(1), eCFR (verified 2026-08-13)
A provider can deny your amendment request, but only on one of four specific grounds: the information wasn't created by that provider, unless the original creator is no longer available to act on it; it isn't part of your designated record set; it wouldn't be available for you to inspect under the access right above; or the provider determines the record "is accurate and complete." That last ground matters most for a medical identity theft case: if a provider's system genuinely believes the impostor's visit was yours, it may deny the amendment on exactly that basis. You will typically need documentation, an EOB that doesn't match, a police report, or an FTC Identity Theft Report, to make your case.
Two things HIPAA does not do here. It does not let a provider erase the fraudulent entry outright; a granted amendment is an addition or a flag linked to the original record, not a deletion. And it is not unconditional; a request a provider wrongly denies generally has to be escalated rather than simply accepted.
Tracing Where the Fraudulent Records Went
A correction filed with one provider doesn't automatically reach every other provider, insurer, or employer that already received the impostor's records. HIPAA has a separate right for that: the accounting of disclosures, under 45 CFR §164.528, lets you request a log of certain parties your covered entity shared your health information with. For a medical identity theft case, that log is the practical map of everywhere a correction notice needs to go next.
Under §164.528(c), a covered entity must act on your request no later than 60 days after receiving it, either by providing the accounting or, if it needs more time, by giving you a written explanation and taking one extension of up to 30 days. The first accounting you request in any 12-month period must be provided free of charge; ask the privacy office directly about any fee for an additional request within the same 12 months.
Notifying Providers and Insurers: A Correction Workflow
- Get copies of the affected records using your access right under §164.524, so you can identify exactly which entries are false.
- Request an accounting of disclosures under §164.528 to find every provider, insurer, or other recipient the fraudulent entries were shared with.
- Submit a written amendment request to each provider or plan under §164.526, describing exactly which entries are fraudulent and why, with supporting documentation such as mismatched EOBs.
- Ask each recipient identified in step two to correct its own copy once the originating provider has processed your amendment.
- Escalate a wrongful denial. You can file a complaint with the HHS Office for Civil Rights, which enforces HIPAA, and pursue the broader identity-theft remedies at How to Report Identity Theft, including an FTC Identity Theft Report or a police report, particularly if a provider's denial rests on records the impostor created rather than any care you actually received.
Related Resources
- Identity Theft Laws covers victim rights, warning signs, and the federal identity theft statute generally.
- How to Report Identity Theft covers the FTC Identity Theft Report and the FCRA blocking process for fraudulent credit accounts.
- Credit Freeze vs. Fraud Alert covers the separate credit-side protections that do not reach medical records.
- Child Identity Theft covers a related risk when a child's Social Security number is used to obtain medical care.
- Synthetic Identity Theft covers how a stolen identity can be combined with fabricated details to build a new credit profile.
- How to Freeze Your Credit After a Data Breach covers freeze steps if a data breach exposed your information alongside a medical identity theft incident.
- What To Do After a Data Breach covers the broader response checklist for a specific breach notice, including a health-plan breach.
Disclaimer
This article provides general information about medical identity theft and the relevant HIPAA rights. It is not legal advice and does not create an attorney-client relationship. Response deadlines, fees, and procedures can vary by provider and change over time; confirm current figures directly with your provider's or health plan's privacy office, or with the HHS Office for Civil Rights, before relying on anything here.
Last updated: 2026-08-13.
Frequently Asked Questions
What is medical identity theft?
It happens when someone uses your name, insurance ID, or Social Security number to get medical care or bill a health plan, mixing false entries into your own medical and billing records.
How do I know if I'm a victim of medical identity theft?
Watch for a provider billing you for services you never received, a legitimate claim denied because your records show a benefits limit you haven't reached, or a health plan refusing coverage because your records show a condition you don't have. The HHS Office of Inspector General recommends reviewing every EOB you receive as one of the standard ways to catch these early.
Can I get fraudulent entries deleted from my medical record?
No. HIPAA's amendment right under 45 CFR §164.526 lets you request a correction, but the covered entity typically adds or flags the correction rather than deleting the original entry.
Can a doctor's office refuse to correct my medical record?
Yes, but only on one of four specific grounds under §164.526(a)(2), including a determination that the record is already accurate and complete. A wrongful denial can be escalated with supporting documentation or a complaint to the HHS Office for Civil Rights.
What is an accounting of disclosures and how does it help?
It's a log, available under 45 CFR §164.528, of certain parties your provider or plan shared your health information with. A covered entity must act on your request within 60 days (one 30-day extension is allowed with written notice), and your first request in a 12-month period is free. For a medical identity theft case, it helps you find every recipient of the fraudulent records so you can request a correction from each one.
Does a credit freeze protect my medical records?
No. A credit freeze under the FCRA only affects credit files held by the three national credit bureaus, not health records held by providers and insurers. See Credit Freeze vs. Fraud Alert for what a freeze actually blocks, and use the HIPAA rights on this page for medical records specifically.
Updates
Independently fact-checked against the cited primary sources
Sources and References
- HHS, Your Medical Records (45 CFR §164.524)(hhs.gov).gov
- 45 CFR §164.526, Amendment of protected health information(ecfr.gov).gov
- 45 CFR §164.528, Accounting of disclosures of protected health information(ecfr.gov).gov
- IdentityTheft.gov, Warning Signs of Identity Theft(identitytheft.gov).gov
- IdentityTheft.gov, Know Your Rights(identitytheft.gov).gov
- HHS Office of Inspector General, FIGHT BACK! Medical Identity Theft & Medicare Fraud(oig.hhs.gov).gov