A health-system breach exposed your insurance member ID and you later see an Explanation of Benefits for a service you never received.
Know the warning signs that are unique to medical identity theft
The FTC lists unfamiliar medical bills, Explanation of Benefits statements for care you did not receive, collection contacts for medical debt you do not owe, and notices that you reached an insurance benefit limit as possible warning signs. These signals can appear outside a normal credit report.
Because medical identity theft can blend another person’s treatment information into your record, the problem is not only financial.
Request records from the providers where misuse may have occurred
Contact the doctor, clinic, hospital, pharmacy, laboratory, and insurer connected to the suspicious service and ask for the relevant records. Explain that you are investigating possible medical identity theft and follow the organization’s identity-verification process.
Review dates, diagnoses, medications, procedures, addresses, and insurance information for details that do not belong to you.
Dispute medical-record errors in writing
The FTC advises reporting errors to the health care provider in writing and including the record that shows the incorrect information with an explanation of why it is wrong. Use a delivery method that lets you confirm receipt when mailing.
Keep the correction request separate from a general complaint about the breach. One concerns the security incident; the other concerns the accuracy of your medical record.
Check credit reports for debt-related spillover
Medical identity theft can also create billing or collection problems. Review your credit reports for unfamiliar medical debt or collection information and use the identity-theft recovery process if fraudulent information appears.
Do not assume a clean credit report means the medical record is clean. The two systems may show different consequences of the same misuse.
Use IdentityTheft.gov for the wider recovery plan
If someone actually used your identity, report the identity theft at IdentityTheft.gov and follow the plan for affected accounts. Keep health-provider case numbers and correction letters with the FTC documentation.
That combined record helps you track both the clinical correction work and the financial identity-theft work without mixing their procedures.
Compare the insurer’s record with the provider’s clinical record
An Explanation of Benefits can show a claim that does not belong to you even when the provider’s chart has not yet been corrected, and a clinical record can contain an incorrect diagnosis or medication even if there is no credit consequence. Review both sides. Ask the insurer for the claim details and the provider for the relevant medical record so you can see where the false information entered the system.
Keep a list of every organization that may have copied the incorrect information. Correcting one hospital’s chart may not automatically correct a lab, pharmacy, specialist, or insurer record that received the same data.
Flag safety-critical errors quickly
If the fraudulent use introduces an allergy, diagnosis, blood type, medication, procedure, or other fact that could affect treatment, tell the provider that the issue is not merely a billing dispute. Ask how the organization marks a record that is under identity-theft review and how clinicians will be alerted while the correction is pending.
Do not delete or overwrite your own evidence before the record is corrected. Keep the original erroneous page and the later corrected version so you can show what changed.
Separate breach notification rights from record-correction rights
A health organization’s notice about a privacy or security incident explains the breach. Your request to inspect and correct your medical record is a different administrative process. Use the provider’s Notice of Privacy Practices or patient-relations channel to find the right office for records and privacy questions.
If you believe a covered health entity violated HIPAA, use official HHS Office for Civil Rights information rather than relying on the breached company’s marketing or monitoring vendor for legal guidance.
Example: an unfamiliar claim appears on your EOB
Suppose your insurer shows an emergency-room visit in a city you were never in. Save the Explanation of Benefits and call the insurer using the number on your member card. Ask for the fraud or special-investigations process and the provider name attached to the claim. Then contact that provider through its official records or privacy office and request the medical record connected to the visit.
Compare the record with your real history and mark every incorrect item, especially allergies, diagnoses, medications, blood type, or procedures that could affect future care. Submit a written correction request through the provider’s documented process and keep proof of receipt. Ask how the organization flags the record while the correction is under review so clinicians do not rely on information you have challenged.
Check whether the false claim created a balance, collection, or benefit-limit problem and address those systems separately. If the misuse is confirmed, report the identity theft through IdentityTheft.gov and keep the FTC documentation with the provider and insurer records. The case is not finished until both the financial claim and the clinical information have been corrected where necessary.
- Save the EOB and provider record.
- Use insurer and provider fraud/privacy channels.
- Prioritize clinically dangerous errors.
- Correct billing and medical records separately.
- Keep a list of every organization that received the bad data.
Recheck records after corrections
Ask the provider or insurer how you will be notified when a correction is complete and request a new copy of the relevant record or claim history afterward. Compare the corrected version with the evidence you saved before the dispute. If other providers received the same false information, confirm whether they were notified or whether you need to contact them separately. Medical identity theft can propagate through referrals, claims, and shared records, so the final step is verifying that the inaccurate information no longer follows you into future care.



