Healthcare Fraud
Healthcare fraud is deliberate deception to obtain payment or benefits from a health care program that would not otherwise be owed. In the United States it is a federal offense under 18 U.S.C. § 1347, and it covers schemes against public programs such as Medicare and Medicaid as well as private insurers.
| Also called | Health care fraud, medical fraud, healthcare billing fraud |
| Primary US statute | 18 U.S.C. § 1347, enacted as part of HIPAA in 1996 |
| Applies to | Public programs and private health insurers alike |
| Related statutes | False Claims Act, Anti-Kickback Statute, Stark Law |
| Penalty | Up to 10 years imprisonment; life where the scheme results in death |
| Provider-side schemes | Billing for services never rendered, upcoding, unbundling, medically unnecessary care, kickbacks |
| Identity-side schemes | Medical identity theft, phantom patients, stolen or fabricated provider credentials |
| Who investigates | HHS Office of Inspector General, the FBI, and DOJ, often with state Medicaid fraud control units |
| Where verification applies | The identity-side schemes only — billing fraud is an audit problem |
How it works
Healthcare fraud is not one behavior. It is a category holding two different problems that share a victim, and conflating them is why so much writing on the subject is useless to anyone trying to prevent it.
Provider-side billing fraud is the larger share by value. A claim is submitted for a service never delivered. A procedure is coded at a higher reimbursement level than the one performed — upcoding. A bundled procedure is split into separately billed components — unbundling. Care is delivered that was never medically necessary. Payments are exchanged for referrals, which the Anti-Kickback Statute prohibits outright. Every one of these is committed by someone who is exactly who they claim to be, using credentials they hold legitimately.
Identity-side fraud is smaller in aggregate and structurally different. Someone uses another person’s insurance details to obtain treatment or prescriptions. A scheme enrolls patients who do not exist, or who exist and never consented, and bills for their care. A person practices or bills under credentials belonging to a real clinician. Here the deception is about who, not about what was done.
The distinction matters because the controls do not transfer. An audit that catches upcoding by comparing coding patterns against peer norms will never notice a phantom patient whose claims look perfectly ordinary. A check confirming a patient is real says nothing about whether the procedure billed for them was necessary.
Why it matters for identity verification
Verification addresses one half of this category and it is worth being precise about which half, because vendors routinely imply otherwise.
Medical identity theft is the clearest case. A person’s insurance credentials are used by someone else, and unlike a stolen card nothing reveals it — victims often discover it years later through a collections notice or a corrupted record. The damage compounds, because another person’s treatment history is now merged into theirs, which is a clinical safety problem as much as a financial one. Verifying that the person presenting a policy is its holder prevents it, and that has to happen at enrollment or point of service rather than in a claims review afterwards.
Telehealth widened the exposure. Enrollment and consultation that once happened in a room with a receptionist now happen through a phone, removing every incidental identity check physical presence used to provide — the same shift that pushed financial services toward remote verification, arriving later and with less infrastructure behind it. Authenticating a government-issued document and matching it to a live face is what replaces the front desk, and Microblink’s stolen and synthetic identity detection covers the case where the identity presented was assembled rather than stolen.
Billing fraud vs medical identity theft
| Provider billing fraud | Medical identity theft | |
|---|---|---|
| Who commits it | A real, credentialed provider | Someone using another person’s identity |
| What is false | The service, the code, or its necessity | Who received the care |
| Victim | The payer, and taxpayers | The payer and the individual whose record is corrupted |
| How it surfaces | Claims analytics, peer comparison, audit, whistleblowers | Often years later, through billing or a medical record error |
| Identity verification helps | No | Yes — directly |
| Primary control | Coding audit and payment integrity review | Verification at enrollment and point of service |
Programs that buy one tool expecting it to address both are disappointed by whichever half it was not built for. The useful question is which of the two is driving loss in a given organization.
What identity verification can’t do here
It cannot detect upcoding, unbundling, or unnecessary care. These are judgments about clinical and billing accuracy made after the fact, by people comparing claims against norms. No identity check touches them, and the majority of healthcare fraud losses by value sit here.
It cannot stop a credentialed insider. A clinician defrauding a program is exactly who they say they are. Verification confirms identity; it does not evaluate conduct, and a program built on the assumption that verified equals trustworthy has misread what the control does.
It cannot repair a corrupted medical record. Once another person’s treatment history is merged into a patient’s file, unpicking it is a manual clinical exercise. Verification prevents the merge and offers nothing retrospectively, which is why timing matters more here than in most sectors.
It cannot be applied only at enrollment. Insurance credentials are used repeatedly over years. A check performed once at sign-up says nothing about who presented that policy number at a pharmacy counter last week — which is where most medical identity theft actually happens.
Frequently asked questions
What are the most common types of healthcare fraud?
Billing for services never provided, upcoding, unbundling procedures that should be billed together, medically unnecessary care, and kickbacks for referrals. Medical identity theft is a smaller but structurally distinct category.
What is medical identity theft?
Using another person’s insurance or medical credentials to obtain treatment, prescriptions, or reimbursement. It is usually discovered late — through a collections notice or an error in the victim’s record — because nothing reveals it the way a bank alert would.
Is healthcare fraud a federal crime?
Yes. In the United States it is prosecuted under 18 U.S.C. § 1347, which carries up to ten years imprisonment and a life sentence where the scheme results in death. Cases frequently involve the False Claims Act, the Anti-Kickback Statute, or the Stark Law alongside it.
Can identity verification prevent healthcare fraud?
It prevents the identity-driven part — medical identity theft, phantom patients, and fraudulent use of provider credentials. It does nothing about billing fraud by legitimate providers, the larger share of losses, which requires claims auditing instead.
Related reading
- Insurance fraud — the broader category healthcare fraud sits inside
- Identity theft — the mechanism behind the medical variant
- Synthetic identity fraud — the phantom patient with no real person behind it
- Application fraud — the equivalent problem at enrollment