Why is PHI Valuable to Criminals?
PHI is valuable to criminals because there are many ways in which stolen Protected Health Information can be monetized and because it often takes longer to identify the theft and misuse of PHI – giving criminals more time to profit from the stolen data. However, criminals are not the only parties who steal PHI for misuse.
In 2022 – the most recent year for which data is available – HHS’ Office for Civil Rights received 64,592 breach notifications affecting more than 52 million individuals. Not all 64,592 notifications were attributable to the theft of Protected Health Information (PHI) because covered entities are required to (for example) notify the loss of a device containing unencrypted PHI even when there is no evidence to suggest data has been accessed.

Source: HHS Report to Congress for 2022
Nonetheless, even a single stolen designated record set containing PHI can be valuable to criminals. The data in a single designated record set can be used to commit financial fraud and medical identity theft. It can also be used to obtain prescription drugs for personal use or to sell, leveraged to gain access to further designated record sets, exploited to blackmail the victims of the theft (or the source of the data), or sold to other criminals to be misused the same ways.
Except when PHI is used to blackmail the victim of a theft or the source of the data (i.e., the theft is immediately apparent), it can be a long time before the theft and misuse of PHI is identified. Some data breaches may not be identified by the source of the breach for several months, while historical data suggests up to one third of medical identity theft victims do not find out their PHI has been stolen until more than a year after the incident in which it was misused.
Why is PHI Valuable to Criminals?
The following is a list of uses of PHI which are believed to be the primary reasons why is PHI valuable to criminals. However, nobody really knows the scale of theft and misuse of PHI due to the failure to identify unlawful uses of PHI and inconsistencies in breach reporting. It can also be the case that PHI is stolen and misused by someone known to the victim of medical identity theft, who is reluctant to report the incident and get their friend or family member into trouble.
Commit Financial Fraud
Stolen PHI can be used to commit many types of financial fraud, from obtaining credit to filing fraudulent tax returns in the victims’ names. Because it is the hardest to detect, the most common way in which criminals monetize stolen PHI (according to the National Health Care Anti-Fraud Association (NHCAA)) is billing fraud – i.e., sending bills to Medicare, Medicaid, and private health plans for treatments and services provided to “phantom patients”.
Medical Identity Theft
Medical identity theft (and, more recently, synthetic identity fraud) occurs when a criminal uses an individual’s PHI to fraudulently receive medical services in the victim’s name. This not only has financial consequences for healthcare organizations and payers, but can also impact the victims of medical identity theft because their medical records are corrupted by the person who has used their identity – resulting in misdiagnoses, delays in treatment, and mistreatment.
Obtain Prescription Drugs
A further statistic from the above survey is that 60% of respondents reported that their identity was used to obtain prescription drugs – five time more than those who suffered credit fraud. In many cases, the prescription drugs obtained through medical identity theft are not for personal use. They are acquired by criminal gangs, who mix the prescription drugs with cheap synthetic additives to sell on the street – significantly increasing the mortality rate from drug overdoses.
Gain Access to More PHI
It is sometimes suggested that criminals use PHI obtained in a data breach to gain access to more PHI by sending healthcare providers emails that appear to originate from a patient. It is alleged the emails deploy malware when a workforce member interacts with them, providing the criminal with wider access to healthcare databases. There is no evidence to support this reason why is PHI valuable to criminals, but it is suggested often enough that it is likely feasible.
Blackmail the Victim/Source
It is also feasible that celebrities have been blackmailed with threats of releasing stolen personal health information about them. However, it is more common that criminals blackmail the source of the data breach – either when data has been encrypted on healthcare servers via ransomware, or when it has been extracted and money is demanded to prevent the publication or further sale of the data. Examples include the Change Healthcare data breach.
Sell for All the Above
When a criminal steals a significant volume of PHI, it is easier for them to monetize the data by selling it on the dark web. In addition to “second-hand criminals” purchasing the data to commit financial fraud and medical identity theft (etc.), some criminals groups purchase stolen PHI:
“to supply fugitives with fresh identities in order to evade law enforcement, incarceration, or even deportation in the case of illegal aliens”. Source: DOJ National Drug Intelligence Center
Theft and Misuse by Family Members/Friends
Many sources discussing reasons why is PHI valuable to criminals overlook that criminals are not the only parties who steal PHI and misuse it. Referring back to the 2015 Ponemon Survey on Medical Identity Theft, 24% of respondents said a family member used their medical credentials without consent, while a further 23% admitted sharing their medical credentials with someone they knew because they did not have insurance or they could not afford to pay for treatment.
Of those who knew a family member had used their credentials, 47% said they did not report it because they did not want to get the family member into trouble, while a further 27% said they were too embarrassed. Interestingly, of all the respondents to Ponemon’s survey, only 10% of medical identity theft victims said that their healthcare provider had suffered a data breach. However, 6% attributed the incident to insider theft and privilege misuse by employees.
Insider Theft/Privilege Misuse by Employees
Insider theft and privilege misuse by employees is a problem in healthcare. It has been claimed that “almost every healthcare fraud scheme involving Medicare or Medicaid requires the participation of a corrupt medical professional” (11 Wm. & Mary Bus. L. Rev. 479 (2020)). This claim would appear to be supported by the hundreds of case summaries listed in the DOJ’s Healthcare Fraud Database and by Verizon’s 2024 Data Breach Investigations Report.
Verizon’s Report is particularly relevant to insider theft and privilege misuse by employees because the healthcare industry already has a higher-than-average percentage of data breaches with a “human element” (interactions with phishing emails, misdeliveries of emails, non-malicious snooping, etc.). Once the privilege misuse category is included, the percentage of healthcare industry breaches with a human element increases to more than 80%.
How Healthcare Organizations Can Better Protect PHI
Healthcare organizations need to better protect PHI because the consequences of data breaches are more than financial. They affect individuals’ health, trust in the patient-physician relationship, and the efficiency of healthcare operations. The reasons why is PHI valuable to criminals needs to be explained to workforces during HIPAA training to ensure members of the workforce think twice before interacting with an email, getting involved in a healthcare fraud scheme, or stealing PHI to sell.
It is equally important that all healthcare organizations review their ID verification policies to prevent ineligible persons using stolen PHI to claim medical care or prescription drugs they are not entitled to. By explaining the real consequences of healthcare data breaches to workforces and implementing tougher ID verification policies, it may be possible to reduce the number of data breaches notified to HHS’ Office for Civil Rights and the number of individuals affected.



