Scammers are increasingly using QR codes and personal data obtained from data brokers to launch targeted fraud schemes disguised as routine healthcare interactions. The Federal Trade Commission (FTC) has reported a rise in scams where criminals impersonate medical offices, Medicare, or payment systems to steal sensitive information.
In one common tactic, patients scan a QR code at a doctor’s office to check in, only to be directed to a fake website that requests their Medicare number, patient portal login, or credit card details. These scams are effective because they mimic legitimate processes, such as prescription notifications or parking payments, which patients expect to receive. The FTC warns that scammers can use exposed personal data—often purchased from data brokers—to make these fraudulent messages appear personalized and trustworthy.
How the scams work
- Data Collection: Scammers obtain personal information, including names, addresses, and Medicare numbers, from data brokers or people search websites.
- Targeted Messaging: They send fraudulent texts, emails, or mail—such as Medicare notices or prescription alerts—using the victim’s real details to appear authentic.
- QR Code Deception: A QR code in a doctor’s office, pharmacy, or parking area directs victims to a fake website that harvests sensitive data.
- Financial and Identity Theft: Stolen information is used to commit fraud, including unauthorized Medicare claims, credit card charges, or identity theft.
What to watch for
- Unexpected QR codes in places where they are not standard (e.g., unsolicited parking payment requests).
- Messages referencing recent doctor visits or prescriptions that you did not request.
- Websites asking for Medicare numbers, login credentials, or payment details that seem out of place.
- Urgent or threatening language, such as claims that your Medicare account is suspended.
Steps to protect yourself
- Verify before clicking: If a QR code or message seems suspicious, contact your healthcare provider directly using a known phone number or website.
- Freeze your credit: This prevents scammers from opening new accounts in your name. Visit AnnualCreditReport.com to check your credit reports for free.
- Enable bank alerts: Set up notifications for unusual transactions to catch fraud early.
- Use strong, unique passwords for patient portals and Medicare accounts.
- Opt out of data brokers: Request the removal of your personal data from people search websites to reduce exposure.
What healthcare providers and regulators are doing
The FTC and Medicare officials have issued warnings about these scams, emphasizing the need for patient vigilance and healthcare provider security measures. Some clinics have begun removing QR codes from check-in areas or adding warning signs about potential scams. Medicare Advantage plans have also increased fraud detection efforts, though officials acknowledge that scammers continue to adapt their tactics.
Long-term risks
Beyond immediate financial loss, victims of these scams may face long-term consequences, including identity theft, damaged credit scores, and fraudulent medical claims filed in their name. The Department of Health and Human Services (HHS) has noted that such scams disproportionately affect older adults, who may be less familiar with digital fraud tactics.
For those seeking additional guidance, the FTC’s website (ReportFraud.ftc.gov) provides resources on reporting scams and recovering from fraud.