Dark Reading is part of the Informa Tech Division of Informa PLC

This site is operated by a business or businesses owned by Informa PLC and all copyright resides with them.Informa PLC's registered office is 5 Howick Place, London SW1P 1WG. Registered in England and Wales. Number 8860726.

Comments
Medical Identity Theft Costs Victims $13,450 Apiece
Oldest First  |  Newest First  |  Threaded View
Nemos
50%
50%
Nemos,
User Rank: Apprentice
2/24/2015 | 5:50:29 PM
An example
Could you please give an example as here in Europe we have a bit different health system and I dont understand why one should cheat about his/her identity ? Is this action has to do that there is not a public insurance therefore you have to pay for your medical expenses ?
Sara Peters
50%
50%
Sara Peters,
User Rank: Author
2/25/2015 | 10:52:21 AM
Re: An example
@Nemos   Yes, you've got it. Health insurance in the US is very expensive, but the costs of medical appointments and procedures is INCREDIBLY expensive.

(For example, when I was admitted to the hospital a few years ago, the hospital room cost $800 per night. That's not including the doctors, the medication, the tests, the procedures, etc. The MRI I had was about $13,000 insurance, if I remember correctly. Even with insurance, the trip cost me a couple thousand dollars. Even with insurance, an ambulance trip cost me $600.)

And that's why people often ALLOW their friends/family to borrow their insurance. And why it costs so much to remediate the damage.

 
Marilyn Cohodas
50%
50%
Marilyn Cohodas,
User Rank: Strategist
2/26/2015 | 11:09:50 AM
Re: An example > borrow insurance?
@Sara, Call me naive but how is it possible to borrow insurance? Don't you need to provide information about your identity, beyond simply the insurance card/number? 
JPtaylorL
50%
50%
JPtaylorL,
User Rank: Apprentice
2/26/2015 | 12:48:07 PM
huh?
So if anyone went out at looked at the HHS Wall of Shame (which is where public breaches of PHI are disclosed), you'll see that there are 278 breaches in 2014.   31 were actually as a result (self reported) of hacking.  The vast majority of other issues tagged - were mistakes or problems resulting from poor execution of policies and procedures.  Hacking is a problem.  Advanced malware is a problem.  However, GETTING GOOD AT RISK ASSESSMENTS, RESPONDING TO RISK, and EXECUTING POLICIES AND PROCEDURES is STILL the most reliable method for avoiding getting owned. The spin is spin.
Sara Peters
50%
50%
Sara Peters,
User Rank: Author
2/26/2015 | 12:49:10 PM
Re: An example > borrow insurance?
@Marilyn  Not really, Marilyn. Generally, they'll ask for your insurance card, but not your ID. And most of the time you're getting billed, not paying up front (except maybe a co-pay that you can pay in cash), so they won't even see a credit card or a checkbook with the wrong person's name on it.

They'll ask for all kinds of medical history on your first appointment. But since most healthcare centers don't share that information, they won't necessarily know that the 37-year-old Sara Peters with epilepsy at hospital A is one person and the 22-year-old 'Sara Peters' with diabetes is a different person, much less a fraud. This is one of those reasons that health information exchange technology could be useful.
Marilyn Cohodas
50%
50%
Marilyn Cohodas,
User Rank: Strategist
2/26/2015 | 2:19:11 PM
Re: An example > borrow insurance?
Now that you mention it, @sarapeters, i've never had to present my ID for a medical appointment. And speaking of health records, i got an email from a Veterinarian's office in Seattle recently about an outpatient discharge report for a "Bridget" Cohodas (no relation-- as far as  I know). So much for confidentiality of PII . But then, maybe pets aren't covered by HIPAA. :-)
Sara Peters
50%
50%
Sara Peters,
User Rank: Author
2/27/2015 | 11:51:36 AM
Re: An example > borrow insurance?
@Marilyn  Wow! What did you do about it? And what sort of creature was Bridget?
Joe Stanganelli
50%
50%
Joe Stanganelli,
User Rank: Ninja
3/1/2015 | 3:00:38 AM
Re: An example > borrow insurance?
That's funny, Marilyn; it seems I *always* have to present my medical ID whenever I go in for a doctor's appointment.  I guess it depends where you go.


COVID-19: Latest Security News & Commentary
Dark Reading Staff 4/7/2020
The Coronavirus & Cybersecurity: 3 Areas of Exploitation
Robert R. Ackerman Jr., Founder & Managing Director, Allegis Capital,  4/7/2020
'Unkillable' Android Malware App Continues to Infect Devices Worldwide
Jai Vijayan, Contributing Writer,  4/8/2020
Register for Dark Reading Newsletters
White Papers
Video
Cartoon Contest
Write a Caption, Win a Starbucks Card! Click Here
Latest Comment: This comment is waiting for review by our moderators.
Current Issue
6 Emerging Cyber Threats That Enterprises Face in 2020
This Tech Digest gives an in-depth look at six emerging cyber threats that enterprises could face in 2020. Download your copy today!
Flash Poll
State of Cybersecurity Incident Response
State of Cybersecurity Incident Response
Data breaches and regulations have forced organizations to pay closer attention to the security incident response function. However, security leaders may be overestimating their ability to detect and respond to security incidents. Read this report to find out more.
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2020-1633
PUBLISHED: 2020-04-09
Due to a new NDP proxy feature for EVPN leaf nodes introduced in Junos OS 17.4, crafted NDPv6 packets could transit a Junos device configured as a Broadband Network Gateway (BNG) and reach the EVPN leaf node, causing a stale MAC address entry. This could cause legitimate traffic to be discarded, le...
CVE-2020-8834
PUBLISHED: 2020-04-09
KVM in the Linux kernel on Power8 processors has a conflicting use of HSTATE_HOST_R1 to store r1 state in kvmppc_hv_entry plus in kvmppc__tm, leading to a stack corruption. Because of this, an attacker with the ability run code in kernel space of a guest VM can cause the host kernel to...
CVE-2020-11668
PUBLISHED: 2020-04-09
In the Linux kernel before 5.6.1, drivers/media/usb/gspca/xirlink_cit.c (aka the Xirlink camera USB driver) mishandles invalid descriptors, aka CID-a246b4d54770.
CVE-2020-8961
PUBLISHED: 2020-04-09
An issue was discovered in Avira Free-Antivirus before 15.0.2004.1825. The Self-Protection feature does not prohibit a write operation from an external process. Thus, code injection can be used to turn off this feature. After that, one can construct an event that will modify a file at a specific loc...
CVE-2020-7922
PUBLISHED: 2020-04-09
X.509 certificates generated by the MongoDB Enterprise Kubernetes Operator may allow an attacker with access to the Kubernetes cluster improper access to MongoDB instances. Customers who do not use X.509 authentication, and those who do not use the Operator to generate their X.509 certificates are u...