Medical Identity Theft: EOB Review, HIPAA Rights, and Fixing Your Records
Independently fact-checked against primary sources (last audited August 13, 2026). · 6 primary sources cited on this page. How we verify our legal content

Medical identity theft happens when someone uses your name, insurance ID, or Social Security number to get medical care, prescriptions, or equipment, or to bill a health plan, leaving false information mixed into your own medical and billing records. Unlike a fraudulent credit card charge, which you can dispute and walk away from, a false medical record can affect the care you receive later, since a treating provider may rely on an entry describing a condition, allergy, or medication that was never actually yours.
Information last verified on 2026-08-13. This article has not yet been reviewed by a licensed lawyer.
This page covers how to spot medical identity theft using your own paperwork, the two HIPAA rights that do the heaviest lifting once you've found it, and how to notify every provider and insurer that received the false records. It does not cover freezing your credit, which is a separate step covered at Credit Freeze vs. Fraud Alert, or the general FTC reporting process, covered at How to Report Identity Theft.
Warning Signs of Medical Identity Theft
IdentityTheft.gov lists three medical-specific entries among its identity-theft warning signs:
- A medical provider bills you for services or equipment you never received.
- Your health plan rejects a legitimate claim because its records show you've already reached a benefits limit you haven't actually reached.
- Your health plan won't cover you because its records show a health condition you don't actually have.
Source: IdentityTheft.gov, Warning Signs of Identity Theft (verified 2026-08-13)

Reviewing Your Explanation of Benefits (EOB)
The HHS Office of Inspector General, the federal watchdog for Medicare and Medicaid fraud, recommends reading every Explanation of Benefits statement your health plan sends, not just the ones tied to a bill you actually owe, as one of its core "Defend" steps against medical identity theft:
"Check All Your Medical Bills, Medicare Summary Notices, Explanation Of Benefits, and Credit Reports: Were you charged for any medical services or equipment that you didn't get? Do the dates of services and charges look unfamiliar? Were you billed for the same thing twice? Does your credit report show any unpaid bills for medical services or equipment you didn't receive? Have you received any collection notices for medical services or equipment you didn't receive?" Source: HHS Office of Inspector General, FIGHT BACK! Medical Identity Theft & Medicare Fraud (verified 2026-08-13)
An EOB lists the provider, the date of service, and what was billed to your plan for a specific visit or procedure, even when your plan paid the claim in full and you owe nothing. If a listed provider, date, or service does not match care you actually received, or a claim gets denied because your plan's records show you've used up a benefit you haven't touched, that is exactly the pattern IdentityTheft.gov flags as a warning sign above. Save every EOB you receive; you will need copies to show a provider or insurer which specific claims are fraudulent once you start the correction process below.

Your HIPAA Right to Get a Copy of Your Records
Before you can prove which entries are fraudulent, you need the actual records. HIPAA's Privacy Rule gives you a broad right to see them:
"The Privacy Rule gives you, with few exceptions, the right to inspect, review, and receive a copy of your medical records and billing records that are held by health plans and health care providers covered by the Privacy Rule." Source: HHS, Your Medical Records, 45 CFR §164.524 (verified 2026-08-13)
A provider cannot deny you a copy for nonpayment of services. It can charge a reasonable fee for copying and mailing, but it cannot charge a separate fee just to search for or retrieve the records.

Your HIPAA Right to Correct Fraudulent Entries
Once you've found entries created by whoever used your identity, HIPAA gives you a direct mechanism to request a correction, called an amendment:
"An individual has the right to have a covered entity amend protected health information or a record about the individual in a designated record set for as long as the protected health information is maintained in the designated record set." Source: 45 CFR §164.526(a)(1), eCFR (verified 2026-08-13)
A provider can deny your amendment request, but only on one of four specific grounds: the information wasn't created by that provider, unless the original creator is no longer available to act on it; it isn't part of your designated record set; it wouldn't be available for you to inspect under the access right above; or the provider determines the record "is accurate and complete." That last ground matters most for a medical identity theft case: if a provider's system genuinely believes the impostor's visit was yours, it may deny the amendment on exactly that basis. You will typically need documentation, an EOB that doesn't match, a police report, or an FTC Identity Theft Report, to make your case.
Two things HIPAA does not do here. It does not let a provider erase the fraudulent entry outright; a granted amendment is an addition or a flag linked to the original record, not a deletion. And it is not unconditional; a denial has to be pushed further rather than simply accepted, which the section below covers.
If Your Amendment Request Is Denied
A denial is not the end of the process, and an OCR complaint is not your only move. Under 45 CFR §164.526(d)(1)(ii), the written denial itself has to tell you that you may submit a statement disagreeing with it and how to file one. Under §164.526(d)(2), the covered entity must permit you to submit a written statement disagreeing with the denial and stating the basis of that disagreement.
That statement does real work. The covered entity appends it to the disputed information, along with its own written rebuttal if it prepares one under §164.526(d)(3), and under §164.526(d)(5) it must include that appended material, or an accurate summary of it, with any subsequent disclosure of the protected health information you disputed. In practice, the next provider or plan that receives the record also receives your account of why the entry is not yours.
If you would rather not write a statement, §164.526(d)(5) also lets you request that the covered entity include your amendment request and its denial, or an accurate summary of them, with any future disclosure of the disputed information.
Keep the statement factual and specific: which entries are false, the dates of service, and what documentation you supplied. Filing one does not replace a complaint to the HHS Office for Civil Rights, which enforces HIPAA; it makes sure the dispute travels with the record while everything else plays out.
Tracing Where the Fraudulent Records Went
A correction filed with one provider doesn't automatically reach every other provider, insurer, or employer that already received the impostor's records. HIPAA puts most of that job on the provider that grants the amendment.
Under 45 CFR §164.526(c)(3), a covered entity that accepts an amendment must make reasonable efforts to inform, and provide the amendment to, within a reasonable time: persons the individual identifies as having received the protected health information and needing the amendment, and persons, including business associates, that the covered entity knows have the information and that "may have relied, or could foreseeably rely, on such information to the detriment of the individual."
That first category is why the request itself matters so much. Under §164.526(c)(2), the provider is supposed to obtain your identification of the relevant persons to notify, so name them yourself and in writing: the health plan that paid the impostor's claim, any specialist or hospital the records were sent to, the pharmacy, the lab. A list you supply is the most reliable route a correction has.
The accounting of disclosures under 45 CFR §164.528 helps, but it is not the complete map it is often described as. Section 164.528(a)(1)(i) expressly excepts disclosures made "to carry out treatment, payment and health care operations as provided in §164.506." Those are exactly the disclosures that carry a fraudulent claim to your health plan and a fraudulent chart entry to another treating provider, so those recipients will usually not appear in the accounting at all. Request it for the disclosures it does cover, such as sharing with a public health authority or in response to a subpoena, and build the rest of your recipient list from your own EOBs, referral letters, and pharmacy records.
Under §164.528(c), a covered entity must act on your request no later than 60 days after receiving it, either by providing the accounting or, if it needs more time, by giving you a written explanation and taking one extension of up to 30 days. The first accounting you request in any 12-month period must be provided free of charge; ask the privacy office directly about any fee for an additional request within the same 12 months.
Notifying Providers and Insurers: A Correction Workflow
- Get copies of the affected records using your access right under §164.524, so you can identify exactly which entries are false.
- Build your own list of recipients from that paperwork: the health plan that paid the claim, every treating provider named in the file, the pharmacy, the lab, any employer or plan that received a copy. This list is what makes the next two steps work.
- Submit a written amendment request to each provider or plan under §164.526, describing exactly which entries are fraudulent and why, with supporting documentation such as mismatched EOBs, and identifying the persons you want notified if the amendment is granted, which is what §164.526(c)(2) contemplates.
- Hold the provider to §164.526(c)(3). A covered entity that accepts an amendment must make reasonable efforts to inform and provide the amendment to the recipients you identified and to anyone it knows holds the information and could foreseeably rely on it to your detriment. Ask for written confirmation, and contact directly any recipient the provider does not reach.
- Request an accounting of disclosures under §164.528 as a supplement, remembering that it excludes treatment, payment, and health care operations disclosures. Use it to catch recipients your own paperwork missed, not as a complete map.
- If a request is denied, file a statement of disagreement under §164.526(d)(2) so your objection travels with the record, then escalate. You can file a complaint with the HHS Office for Civil Rights, which enforces HIPAA, and pursue the broader identity-theft remedies at How to Report Identity Theft, including an FTC Identity Theft Report or a police report, particularly if a provider's denial rests on records the impostor created rather than any care you actually received.
Related Resources
- Identity Theft Laws covers victim rights, warning signs, and the federal identity theft statute generally.
- How to Report Identity Theft covers the FTC Identity Theft Report and the FCRA blocking process for fraudulent credit accounts.
- Credit Freeze vs. Fraud Alert covers the separate credit-side protections that do not reach medical records.
- Child Identity Theft covers a related risk when a child's Social Security number is used to obtain medical care.
- Synthetic Identity Theft covers how a stolen identity can be combined with fabricated details to build a new credit profile.
- How to Freeze Your Credit After a Data Breach covers freeze steps if a data breach exposed your information alongside a medical identity theft incident.
- What To Do After a Data Breach covers the broader response checklist for a specific breach notice, including a health-plan breach.
Disclaimer
This article provides general information about medical identity theft and the relevant HIPAA rights. It is not legal advice and does not create an attorney-client relationship. Response deadlines, fees, and procedures can vary by provider and change over time; confirm current figures directly with your provider's or health plan's privacy office, or with the HHS Office for Civil Rights, before relying on anything here.
Last updated: 2026-08-13.
Frequently Asked Questions
What is medical identity theft?
It happens when someone uses your name, insurance ID, or Social Security number to get medical care or bill a health plan, mixing false entries into your own medical and billing records.
How do I know if I'm a victim of medical identity theft?
Watch for a provider billing you for services you never received, a legitimate claim denied because your records show a benefits limit you haven't reached, or a health plan refusing coverage because your records show a condition you don't have. The HHS Office of Inspector General recommends reviewing every EOB you receive as one of the standard ways to catch these early.
Can I get fraudulent entries deleted from my medical record?
No. HIPAA's amendment right under 45 CFR §164.526 lets you request a correction, but the covered entity typically adds or flags the correction rather than deleting the original entry.
Can a doctor's office refuse to correct my medical record?
Yes, but only on one of four specific grounds under §164.526(a)(2), including a determination that the record is already accurate and complete. If it denies your request, §164.526(d)(2) lets you submit a written statement of disagreement, which the provider must then include, or summarize, with later disclosures of the disputed entry under §164.526(d)(5). You can also complain to the HHS Office for Civil Rights.
How does a correction reach the other providers and insurers that already have the false records?
Under 45 CFR §164.526(c)(3), a provider that grants your amendment must make reasonable efforts to inform and provide the amendment to the people you identify as having received the record and needing the correction, and to anyone it knows holds the information and could foreseeably rely on it to your detriment. So name every recipient you know of in writing when you file the request.
What is an accounting of disclosures and how does it help?
It's a log, available under 45 CFR §164.528, of certain disclosures your provider or plan made. It is useful but incomplete: §164.528(a)(1)(i) excepts disclosures made to carry out treatment, payment, and health care operations, which is how a fraudulent claim usually reaches your health plan and how chart entries usually reach other treating providers. Use it to catch recipients your own EOBs and records missed. A covered entity must act on your request within 60 days (one 30-day extension is allowed with written notice), and your first request in a 12-month period is free.
Does a credit freeze protect my medical records?
No. A credit freeze under the FCRA only affects credit files held by the three national credit bureaus, not health records held by providers and insurers. See Credit Freeze vs. Fraud Alert for what a freeze actually blocks, and use the HIPAA rights on this page for medical records specifically.
Updates
Corrected how a medical-record correction actually reaches other providers and insurers: the page now points to the HIPAA amendment rule’s own "informing others" requirement, adds the statement of disagreement available after a denial, and explains that an accounting of disclosures leaves out treatment, payment, and health care operations disclosures rather than listing every recipient.
Independently fact-checked against the cited primary sources
The Law Behind This Article
This article rests on the statutory provisions below, held in our own legal record and retrieved from the official source. Tap a section to read the operative text.
Code of Federal Regulations Title 45
§ 164.526Amendment of protected health information.In forcecited in 3 of our articles
(a) Standard: Right to amend. (1) Right to amend. An individual has the right to have a covered entity amend protected health information or a record about the individual in a designated record set for as long as the protected health information is maintained in the designated record set. (2) Denial of amendment. A covered entity may deny an individual's request for amendment, if it determines that the protected health information or record that is the subject of the request: (i) Was not created by the covered entity, unless the individual provides a reasonable basis to believe that the originator of protected health information is no longer available to act on the requested amendment; (ii) Is not part of the designated record set; (iii) Would not be available for inspection under § 164.524; or (iv) Is accurate and complete. (b) Implementation specifications: Requests for amendment and timely action —(1) Individual's request for amendment. The covered entity must permit an individual to request that the covered entity amend the protected health information maintained in the designated record set.
Official text (excerpt) · last checked 2026-09-02 · Read the full text in our law library · Verify at ecfr.gov
Cited in 15 court opinions in our collectionLatest citing opinion in our collection: 2026
In the courts (editorial summary, independently checked):Bondick v. Mitchell Sanchez (2024) held that claims under 45 CFR 164.526 fail as a matter of law because HIPAA creates no private right of action. Mallgren v. Burkholder (2014) reached the same result and pointed the plaintiff to the amendment procedure in subsections (b) through (d) as his remedy.
Opinions citing this section in our collection:
- Mallgren v. Burkholder (District Court, E.D. New York 2014, 52 F. Supp. 3d 490)✓A committed psychiatric patient sued because his request to review and correct his records went unfulfilled; the court dismissed, holding the amendment process in 45 CFR 164.526 is enforced by HHS and gives no private right of action, and pointed him to that process instead.
- Crowding v. Secretary of Health and Human Services (United States Court of Federal Claims 2019)✓Vaccine-program counsel filed supplemental records altered in his client's favor and signed by a doctor no longer in practice; reading 45 CFR 164.526 to require a covered entity to preserve the original and append any amendment, the special master cut off fees after that filing.
- Bondick v. Mitchell Sanchez (District Court, D. Oregon 2024)✓A patient sued his former physician for libel over a note in his chart and also claimed a right to amend the record under 45 CFR 164.526(a)(1); the court granted summary judgment, holding HIPAA gives no private right of action, so that claim failed as a matter of law.
Identified automatically from the court opinions citing this section — not a ranking of which case controls.
Also relied on in: What Is a Business Associate Agreement (BAA)? HIPAA Guide (2026), Alaska Medical Records Retention Laws (2026 Guide)
§ 164.524Access of individuals to protected health information.In forcecited in 25 of our articles
(a) Standard: Access to protected health information —(1) Right of access. Except as otherwise provided in paragraph (a)(2) or (a)(3) of this section, an individual has a right of access to inspect and obtain a copy of protected health information about the individual in a designated record set, for as long as the protected health information is maintained in the designated record set, except for: (i) Psychotherapy notes; and (ii) Information compiled in reasonable anticipation of, or for use in, a civil, criminal, or administrative action or proceeding. (2) Unreviewable grounds for denial. A covered entity may deny an individual access without providing the individual an opportunity for review, in the following circumstances. (i) The protected health information is excepted from the right of access by paragraph (a)(1) of this section.
Official text (excerpt) · last checked 2026-07-28 · Read the full text in our law library · Verify at ecfr.gov
Cited in 88 court opinions in our collectionLatest citing opinion in our collection: 2026
In the courts (editorial summary, independently checked):Webb v. Smart Document Solutions, LLC (2007) held the reduced, cost-based fee in section 164.524(c)(4) applies only when the individual himself requests his records, not a law firm acting as his agent. Ciox Health, LLC v. Hargan (2020) vacated 2016 guidance that extended that patient rate to third-party directives.
Opinions citing this section in our collection:
- Webb v. Smart Document Solutions, LLC (Court of Appeals for the Ninth Circuit 2007, 499 F.3d 1078)✓A law firm ordered its client's hospital records and was billed a copying company's higher third-party rate; the Ninth Circuit held Section 164.524(c)(4)'s cost-based fee limit applies only when the individual or a personal representative asks, not an attorney acting as agent.
- Evenson v. Hartford Life & Annuity Insurance (District Court, M.D. Florida 2007, 244 F.R.D. 666)✓A therapist refused a subpoena for her psychotherapy notes, citing Section 164.524(a)(1)'s exclusion of those notes from a patient's right of access; the court held that exclusion governs only individual access, not discovery, and ordered the notes produced.
- Ciox Health, LLC v. Hargan (District Court, District of Columbia 2020)“…fee that can be charged for such production. See generally 45 C.F.R. § 164.524. For requests brought by an individual…”
Identified automatically from the court opinions citing this section — not a ranking of which case controls.
Also relied on in: How Long Do Hospitals Keep Medical Records? (2026), How to Find Old Medical Records Online, Medical Records Retention Laws by State (2026 Guide)
§ 164.528Accounting of disclosures of protected health information.In forcecited in 2 of our articles
(a) Standard: Right to an accounting of disclosures of protected health information. (1) An individual has a right to receive an accounting of disclosures of protected health information made by a covered entity in the six years prior to the date on which the accounting is requested, except for disclosures: (i) To carry out treatment, payment and health care operations as provided in § 164.506; (ii) To individuals of protected health information about them as provided in § 164.502; (iii) Incident to a use or disclosure otherwise permitted or required by this subpart, as provided in § 164.502; (iv) Pursuant to an authorization as provided in § 164.508; (v) For the facility's directory or to persons involved in the individual's care or other notification purposes as provided in § 164.510; (vi) For national security or intelligence purposes as provided in § 164.512(k)(2); (vii) To correctional institutions or law enforcement officials as provided in § 164.512(k)(5); (viii) As part of a limited data set in accordance with § 164.514(e); or (ix) That occurred prior to the compliance date for the covered entity.
Official text (excerpt) · last checked 2026-07-28 · Read the full text in our law library · Verify at ecfr.gov
Cited in 8 court opinions in our collectionLatest citing opinion in our collection: 2024
Opinions citing this section in our collection:
- National Ass'n of Letter Carriers v. United States Postal Service (District Court, S.D. New York 2009, 604 F. Supp. 2d 665)“…ze you to withhold notification under these circumstances. 45 C.F.R. § 164.528 (a)(2) (II) (C). (Compl. Ex. A).…”
- Tripp v. United States (District Court, E.D. Michigan 2024)“…intiff’s entitlement to an accounting of disclosures under 45 C.F.R. § 164.528(a)(1) is an obligation imposed on the c…”
- Wellstar Health System, Inc. v. Jordan (Supreme Court of Georgia 2013, 293 Ga. 12)“…t to individual’s underlying health information). See also 45 CFR § 164.528 (providing for right of individual to…”
Identified automatically from the court opinions citing this section — not a ranking of which case controls.
Search our full record of US law — 2.1 million sections, every state + federal →
Sources and References
- HHS, Your Medical Records (45 CFR §164.524)(hhs.gov).gov
- 45 CFR §164.526, Amendment of protected health information(ecfr.gov).gov
- 45 CFR §164.528, Accounting of disclosures of protected health information(ecfr.gov).gov
- IdentityTheft.gov, Warning Signs of Identity Theft(identitytheft.gov).gov
- IdentityTheft.gov, Know Your Rights(identitytheft.gov).gov
- HHS Office of Inspector General, FIGHT BACK! Medical Identity Theft & Medicare Fraud(oig.hhs.gov).gov
- 45 CFR §164.526, Amendment of protected health information (2024 CFR, GPO)(govinfo.gov)
- 45 CFR §164.528, Accounting of disclosures of protected health information (2024 CFR, GPO)(govinfo.gov)