CipherWatch All articles
Account Security

The Most Valuable File in the Room: Why Criminals Pay Top Dollar for Your Medical Records

CipherWatch
The Most Valuable File in the Room: Why Criminals Pay Top Dollar for Your Medical Records

Photo: hospital medical records computer security padlock healthcare data, via i.pinimg.com

In the hierarchy of stolen data, medical records occupy a position that surprises many people when they first encounter it. Credit card numbers, which feel acutely personal when compromised, are actually among the least valuable items traded in criminal data markets. They can be canceled within hours. A medical record cannot be canceled. It cannot be changed. And it contains a constellation of information — insurance identifiers, prescription histories, diagnoses, Social Security numbers, employer details, and family relationships — that makes it among the most versatile instruments of fraud available.

The healthcare sector has become, by most measures, the most persistently targeted industry in the United States when measured by the sensitivity of the data it holds. According to the Department of Health and Human Services breach portal — informally known as the "Wall of Shame" — more than 133 million individuals had their protected health information exposed in 2023 alone, a record figure driven in large part by the exploitation of third-party vendors and legacy infrastructure.

Understanding why this is happening, what it means for individuals whose records have been exposed, and what limited but meaningful steps patients can take is no longer a concern reserved for security professionals. It is a matter of personal financial and physical safety.

Why Medical Records Command Premium Prices

The value of a stolen medical record on criminal markets — estimates from cybersecurity research firms have placed it between $250 and $1,000 for a complete file, compared to roughly $5 to $20 for a Social Security number in isolation — derives from its permanence and its density of exploitable information.

A complete medical record typically includes the patient's full legal name, date of birth, address, Social Security number, insurance policy number and group ID, employer information, emergency contacts, and a clinical history that may span years or decades. For a fraudster, this represents a comprehensive identity package that supports multiple simultaneous schemes.

Medical identity theft allows criminals to obtain prescriptions, medical devices, or procedures under a victim's insurance coverage. The financial harm to insurers is significant, but the harm to victims can be more severe: fraudulent entries in a medical record can alter a patient's documented blood type, allergy history, or medication list in ways that create genuine clinical risk if a provider consults that record during an emergency.

Insurance fraud is a straightforward application of the same data. Stolen insurance credentials can be used to file false claims, exhaust a policy's benefits, or establish fraudulent coverage.

Prescription drug fraud has particular relevance in the current opioid landscape. Stolen prescriber credentials combined with patient insurance data can be used to obtain controlled substances.

Targeted extortion is perhaps the most psychologically damaging use of medical data. Diagnoses of stigmatized conditions — mental health disorders, sexually transmitted infections, substance use disorders — can be used to coerce victims into paying to prevent disclosure to employers, family members, or insurers.

Recent Breaches and What They Revealed

The scale of healthcare breaches in recent years makes abstract statistics concrete.

The Change Healthcare incident of early 2024, attributed to the ALPHV/BlackCat ransomware group, is widely regarded as the most consequential healthcare data breach in U.S. history. Change Healthcare, a subsidiary of UnitedHealth Group, processes roughly 15 billion medical transactions annually — approximately one-third of all U.S. healthcare claims. The attackers accessed systems for approximately nine days before deploying ransomware, exfiltrating data that potentially included the medical and personal records of a significant proportion of the American population. UnitedHealth Group ultimately paid a reported $22 million ransom, and the full scope of individual exposure remains under ongoing investigation.

The HCA Healthcare breach of 2023 exposed the records of approximately 11 million patients, with data including names, email addresses, phone numbers, appointment dates, and service locations posted to an online forum by threat actors.

These incidents share a pattern: large aggregators of health data — clearinghouses, billing processors, electronic health record vendors — represent single points of failure whose compromise produces exposure at a scale that individual hospital breaches historically did not.

HIPAA's Limits in the Modern Threat Environment

The Health Insurance Portability and Accountability Act, enacted in 1996 and updated through the HITECH Act of 2009, established the foundational framework for protecting protected health information in the United States. Its requirements — administrative safeguards, technical controls, breach notification obligations — were meaningful when written. In the current environment, critics argue they are structurally insufficient.

HIPAA applies to covered entities (healthcare providers, insurers, and clearinghouses) and their business associates. It does not apply to the growing ecosystem of health and wellness applications — fitness trackers, mental health apps, period-tracking platforms — that collect health-adjacent data outside the clinical context. A user's data shared with a HIPAA-covered hospital is subject to federal protection; the same user's data shared with a wellness app is not.

Breaches of HIPAA-covered entities trigger notification requirements, but the timelines are permissive: covered entities have up to 60 days after discovering a breach to notify affected individuals. In the Change Healthcare incident, many patients were waiting months for formal notification while their data was already circulating on criminal forums.

Penalties for violations, while potentially substantial in egregious cases, have not historically been calibrated to produce the kind of deterrent effect that the scale of healthcare breaches demands. The Office for Civil Rights, which enforces HIPAA within HHS, operates with limited resources relative to the volume of incidents it is asked to investigate.

What Exposure Actually Looks Like for Patients

For individuals whose medical records have been compromised, the consequences tend to unfold across several dimensions, often with significant delays.

Explanation of Benefits fraud is frequently the first visible sign. A patient receives an EOB statement from their insurer for a procedure they never received. This can indicate that their insurance credentials are being used to file fraudulent claims.

Credit report anomalies may emerge months or years later, as fraudulently obtained medical services or equipment are billed and sent to collections under the victim's identity.

Prescription monitoring flags can affect a victim's ability to obtain legitimate prescriptions if controlled substances have been fraudulently obtained under their identity.

Employment and insurance consequences can follow if sensitive diagnoses are disclosed to parties who should not have access to them, even if the disclosure itself is illegal.

Monitoring and Response: What Patients Can Do

The options available to patients are more limited than those available to, say, consumers disputing a fraudulent credit card charge. Medical identity theft is harder to detect, harder to correct, and harder to remediate. That said, several concrete steps can reduce exposure and accelerate detection.

Request your medical records annually. Under HIPAA, you have the right to access your medical records from any covered entity. Reviewing them periodically allows you to identify entries that do not correspond to care you actually received — a visit you did not make, a prescription you did not receive, a diagnosis you were never given.

Monitor your Explanation of Benefits statements. Review every EOB your insurer sends, whether by mail or through an online portal. Flag any service, provider, or date that does not match your actual care history and report discrepancies to your insurer's fraud line immediately.

Check your credit reports. Fraudulent medical billing often surfaces as collection accounts. AnnualCreditReport.com provides free access to reports from all three major bureaus. Consider placing a fraud alert or credit freeze if you have been notified of a healthcare breach affecting your records.

File a complaint if your rights are violated. HIPAA complaints can be filed with the HHS Office for Civil Rights at hhs.gov/ocr. State attorneys general in many states also have independent authority to investigate healthcare data breaches.

Be cautious with health and wellness apps. Before sharing health data with any application, verify whether it is a HIPAA-covered entity. Assume that data shared with non-covered apps may be sold, shared, or exposed without the protections you would expect from a clinical provider.

A Record That Follows You

The defining characteristic of medical data — the quality that makes it so valuable to criminals and so damaging when exposed — is its permanence. A compromised password can be reset. A stolen credit card can be reissued. A medical history cannot be rewritten, and the consequences of its exposure can follow a person for years.

For that reason, the security of healthcare data deserves the same level of attention that consumers and regulators have increasingly directed at financial and identity information. The institutions entrusted with that data have, in aggregate, not yet risen to the standard of protection the sensitivity of the information demands. Until they do, the patients whose records those institutions hold bear a disproportionate share of the vigilance required.

All Articles

Related Articles

Poisoned at the Source: How Attackers Weaponize Software Updates Against the Users Who Trust Them

Poisoned at the Source: How Attackers Weaponize Software Updates Against the Users Who Trust Them

One Phone Call Away From Losing Everything: The SIM Swap Attack Explained

One Phone Call Away From Losing Everything: The SIM Swap Attack Explained

Beyond the Password: Building a Layered Defense for Your Digital Identity