How Physicians Can Protect Themselves Against Identity Theft
- 52 minutes ago
- 10 min read
As identity theft concerns rise globally, so do complicated targeted schemes. Physicians are especially vulnerable and attractive targets for identity theft, financial fraud, and professional credential misuse because doctors often have high incomes, strong credit, and publicly available professional information. As such, we see a lot of posts from physicians in our online communities for doctors about attempts to steal their information, successfully or unsuccessfully. While this is scary and frustrating, there are several steps physicians can take to reduce their risk of falling victim to identity theft, from strengthening their online security to monitoring their financial and professional identities. Below, we provide a guide for how to protect yourself, and what to do if your identity is ever compromised.
Disclosure/Disclaimer: This page contains information about our sponsors and/or affiliate links, which support us monetarily at no cost to you. These should be viewed as introductions rather than formal recommendations, and often provide you with perks, so we hope it's win-win. Our content is for generalized educational purposes. While we try to ensure it is accurate and updated, we cannot guarantee it. We are not formal financial, legal, or tax professionals and do not provide individualized advice specific to your situation. You should consult these as appropriate and/or do your own due diligence before making decisions based on this page. To learn more, visit our disclaimers and disclosures.

Article Navigation
Why are physicians targeted for identity theft?
Unfortunately, doctors are often made targets for identity theft because they tend to have higher incomes, excellent credit scores, larger bank account balances, and busy schedules that may delay detection of fraudulent activity. Additionally, there is a wealth of publicly available information about physicians, some of which can be used to make it easier to know identifying information about the doctor such as addresses and education, and some of which can actually be used to conduct fraud on a much larger level, including:
Medical license information
DEA registration
National Provider Identifier (NPI) number
Practice webpages
Professional bios
Social media content
Professional pictures
Combined with information obtained through data breaches, this can make physicians easier targets for sophisticated fraud.
PSG resource:Â Â
DeleteMe is a subscription-based service that automatically finds and removes your personal information from data brokers and people-search sites. You can save 20% off by using our unique affiliate link.
What types of identity theft should physicians worry about?
Identity theft related to physicians can extend far beyond stolen credit card numbers, opening new accounts, or fraudulent wire transfers. Some schemes may involve impersonating physicians professionally or even prescribe controlled substances using stolen credentials.
Financial identity theft
This is the form most people think about. As alluded to above, doctors tend to have larger bank accounts, investment accounts, and available credit limits, making them attractive targets for those looking to make a quick buck.
Examples of financial identity theft include:
Opening credit cards under your name and credit limit
Applying for loans or lines of credit using your credit history
Filing fraudulent tax returns so that they can have tax refunds sent to them
Draining bank accounts of the balances, either through routine purchases or transfers, or in lump sums
Taking over existing investment or retirement accounts and transferring money out of them
Medical or professional identity theft
Unfortunately, patients may use a physician’s personal information as a way to obtain the medical care that they want, whether it be for referrals, prescription drugs, helping with insurance authorizations, alter medical records, etc. More maliciously, a physician’s information can also be used to file fraudulent claims with payers, such as health insurance companies, or engage in other forms of healthcare or financial fraud.
Examples of your credentials that could be used to do these things include:
DEA registration numbers
NPI numbers
State medical licenses
Digital prescribing credentials
Hospital credentials
If somebody is able to impersonate a physician professionally, you can imagine the number of possible nightmare scenarios that may arise. These include, but are certainly not limited to:
Using your license or NPI to prescribe or otherwise act as a physician
Engaging in insurance fraud by submitting fraudulent claims for services not delivered (but which are often very lucrative)
Redirecting insurance payments owed to you to their personal accounts
Using your credentials to order tests or equipment that generate large amounts of revenue - this is particularly concerning if they're fraudulently billing Medicare for things like DME or genetic testing
Selling or otherwise engaging in fraud with prescription drugs by forging prescriptions, creating counterfeit prescription pads, using electronic prescribing, or diverting controlled substances
Business identity theft
If you own a private practice, criminals may use fraud to get at your financial information, accounts receivable, or otherwise leverage your business to steal from you or open lines of credit. They could also file fake tax returns on behalf of your private practice and steal money in this way, or hijack vendor payments. Additionally, they could use you to pass credentialing checks, file for unemployment, or to obtain employment.
Social media impersonation
Physicians with podcasts, educational content, or large social media followings may be particularly vulnerable. Increasingly, scammers are creating fake physician profiles on various social media channels, and using the trust that the physician has to:
Promote medical treatments, equipment, or medicines that generate revenue for themselves through partnerships or affiliate links (examples: GLP drugs, supplements, etc)
Solicit money (for example, fake GoFundMes for tragic patient anecdotes or donations for various noble causes that get redirected to their personal accounts)
Damage your professional reputation
Contact patients or colleagues and engage in criminal activity, perhaps related to identity theft, sales, or financial schemes

Why physician identity theft can be especially damaging, financially and professionally
Unfortunately, a lot of these schemes go beyond inconvenience and minor financial losses. Resolving these issues can require lots of documentation, reissuing of documents, and other things that can take up many hours. Complicated schemes can have huge financial and professional consequences, even if a physician can prove their innocence and that they were a victim. Some of these situations may result in having to disclose or explain situations on licensing and credentialing applications, or result in things like:
Damage to your credit score and history, which can cause issues getting loans or funding in the future
Damages to your professional reputation or credibility
Potential licensing investigations or complications with the DEA that make getting these credentials more involved
Practice disruption
Lost income
How can physicians protect themselves from identity theft and fraud?
Fortunately, there are many steps physicians can take to reduce their risk.
Be vigilant and keep your guard up
Cynicism is key to detecting fraud. Many complex identity theft schemes involve preying on a physician's fears of lawsuits, fraud, medical board complaints, and more. We often see posts on the communities about calls made to the physician saying that they are in trouble with the DEA or with the medial board for various reasons, and asking them to give information to resolve the issue or to send money to a certain location. These calls are understandably terrifying, but note that these are not typical ways for the medical board or DEA to communicate with you. If you recieve one of these calls, stay calm, look at the number calling, and then attempt to independently verify that they are who they saw that they are. Whether you choose to hang up or investigate, don't give up personal information, bank account or credit card numbers, or other information that could be used to help them steal your identity. The people calling will often reveal themselves by not being able to answer questions appropriately, or get frustrated and hang up (and unfortunately move on to their next potential target).
Freeze your credit
A credit freeze is one of the simplest and most effective protections that prevent people from opening up new accounts or lines of credit under your name. Many financial experts recommend keeping your credit frozen year-round unless you're actively applying for new credit. When a freeze is in place, new lenders generally cannot access your credit report without your authorization, which is usually a non-starter when it comes to opening up an account where the lender is extending money in good faith.
Learn how to freeze your credit.
Use unique, complex passwords and a password manager
Reusing passwords remains one of the biggest cybersecurity risks out there, as passwords are constantly leaked in data breaches. It's important that you create unique passwords for every important account that has access to personal or financial information, and that the passwords are strong (i.e. longer in length, variation in characters and upper case vs. lower case, special characters.
Enable multifactor authentication (MFA)
Multifactor authentication adds a critical layer of protection. By using MFA, even if your password becomes compromised, the hacker will not be able to access your account unless they also have access to the device or email account where the verification is going. This means that if they simply found your password in a data leak, they still won't be able to actually login to your account. You should have multifactor authentication on most accounts, but especially email accounts, bank and investment accounts, retirement accounts, cloud storage, anything that stores passwords, and practice related accounts..
Monitor your financial accounts regularly
We cannot emphasize this enough. Many complex fraud schemes involve taking out money in small amounts and then making those withdrawals progressively bigger until they're detected. Make sure you regularly review the statements sent to you, but also set up alerts on all of your credit card, bank, investment, and retirement accounts to notify you about suspicious activity, new ACH connections, etc. It's easy to ignore routine statements when you're a busy physician, but getting a text message saying money was transferred from your account, hat your account balances have changed, or a new vendor or ACH was set up will instantly set off alarm bells. The earlier fraudulent activity is detected, the easier it usually is to resolve.
Monitor your professional identity
This is a hard one to remember, but periodically check on databases for your NPI information, state medical license records, DEA registration, and other public physician profiles. If anything appears inaccurate or unfamiliar, investigate it promptly. It may also help you catch if somebody has associated your license with their practice (we've seen lots of physicians find out that they've been listed as supervising physicians for non physician clinicans without their permission in this way!).
Limit publicly available personal information
Although it's hard in today's world to hide much of anything, try to limit how much information you put out to the world that's publicly available. You may have more information out there than you realize, including your home address, personal phone number, or personal email addresses. These often appear on public people-search websites.
PSG resource:
DeleteMe is a subscription-based service that automatically finds and removes your personal information from data brokers and people-search sites. You can save 20% off by using our unique affiliate link.
Watch for phishing attempts in your email or text messages
Phishing emails are increasingly common ways of getting into your accounts. Be very careful about clicking on links in your email box, especially from unknown senders, but even from known senders that are sending things that seem atypical. Never enter your email password or other password into a site if you click on a link within an email. If you hover over a link, you can usually see where it's sending you - if that domain is not recognizable or a series of random characters, it's generally advisable to avoid clicking it, as it could download malware or otherwise expose you to risks.
When in doubt, go directly to the website to find information, rather than clicking email links.
Be extremely cautious of emails requesting password resets, financial information, credential verification, or even 'requests' from your employees to change their payroll information and update it with new account numbers.
Should physicians purchase identity protection services?
Identity protection services can provide additional peace of mind that you're not the only one looking out for yourself. There are many identity monitoring services out there, which usually offer features such as:
Credit monitoring
Identity monitoring
Dark web monitoring
Fraud alerts
Identity restoration assistance
Insurance for eligible identity theft expenses
While no service can prevent identity theft entirely, they may help identify suspicious activity sooner and/or simplify the recovery process. Make sure that you choose one that is reputable, as you will have to give them information about yourself to enroll in monitoring features as well.
What should you do if your identity has been stolen?
This is understandably so stressful. The first thing to do is to stay calm and act quickly. This can substantially reduce financial losses, as fraudsters tend to act quickly once they know they're at risk of being detected. If you suspect identity theft, you should:
Freeze your credit immediately.
Contact all affected financial institutions and lock down your accounts.
Change compromised passwords (and possibly even those that weren't compromised, as a compromised email account may lead to the ability to log into other accounts).
File reports with the appropriate credit bureaus.
Report identity theft to the Federal Trade Commission and to the police or other federal agencies if needed.
Monitor all major accounts closely for suspicious activity over the next few weeks to months.
Notify your licensing board or DEA if professional credentials may have been compromised.
Keep detailed documentation of every communication, as you may need this as proof as you recover your losses or need to submit accounts of what happened.
Conclusion
Identity theft has become increasingly sophisticated, and unfortunately, physicians present attractive targets both because of their financial profiles and professional credentials. It's important to be smart, use common sense, and also proactively use protective measures such as credit freezes, multifactor authentication, password managers, routine account monitoring, and identity protection services to combat your risk. Always be cynical if asked to give up passwords or other sensitive personal or financial data. Consider using professional services to help as well.
PSG resource:Â Â
DeleteMe is a subscription-based service that automatically finds and removes your personal information from data brokers and people-search sites. You can save 20% off by using our unique affiliate link.
Related personal finance resources
Sign up for our weekly newsletter for more physician financial education, career resources, and practical tips to help protect your professional and personal life.
Related PSG resources:
