Scammers Target Patients at Doctor’s Offices, Know Personal Information

Featured & Cover How to Identify Fake Emergency Text Scams Targeting Parents

The rise of QR code scams at healthcare facilities poses a significant threat, as scammers leverage personal data to create convincing phishing attacks targeting sensitive information like Medicare numbers.

As you arrive at your doctor’s office, you might notice a sign instructing you to scan a QR code to check in. Later, you may receive a text regarding a prescription, followed by a Medicare notice containing your name and address. Before you leave, another QR code prompts you to pay for parking. While these actions seem routine, they can mask a dangerous scam. Criminals are no longer limited to sending generic phishing messages; they can now craft personalized attacks using information obtained from data brokers and people search websites.

These scams can take various forms, including medical, Medicare, and payment scams that appear specifically tailored to you. A QR code provides an easy method for scammers to direct you to a convincing fake website, where they may request your Medicare number, patient portal login, credit card information, or other sensitive data. Understanding the risks associated with QR codes and taking preventative measures can help you avoid falling victim to these scams.

QR codes have become commonplace in healthcare settings. They are used for check-in forms, prescription pickups, and even parking payments. This familiarity works in favor of scammers, as individuals expect the information to be legitimate when they are in a doctor’s office or near a parking machine. Scammers exploit this trust, knowing that a QR code conceals the destination link, making it difficult for users to verify where it leads before scanning.

The mechanics of QR code scams are surprisingly straightforward. A criminal can place a QR code that directs you to a website designed to mimic your insurer, pharmacy, or doctor’s portal. Once there, the site may prompt you for sensitive information. This tactic, often referred to as “quishing,” is particularly effective because many people have become so accustomed to scanning QR codes that it no longer feels like a risky action.

One Medicare beneficiary reported receiving a letter that appeared to come from a major insurer, instructing them to scan a QR code to access an Annual Notice of Change. The letter closely resembled legitimate correspondence, but the QR code linked to a shortened, lookalike web address instead of the insurer’s actual domain. This example illustrates a common scam pattern: creating an official-looking communication that feels urgent and directing the victim to a site controlled by the scammer.

In the U.K., a fraudulent QR code sticker was discovered on a parking payment machine at Totnes Community Hospital. A visitor who scanned the code lost £146.79 from her account, with scammers attempting to withdraw an additional £849 before her bank’s fraud team intervened. Similar incidents have been reported in California, where law enforcement documented scammers placing counterfeit QR code stickers next to legitimate parking payment instructions. Such settings can be particularly convincing, as individuals expect to scan something to make a payment.

Older Americans are frequent users of healthcare systems, pharmacies, and insurance providers, making them prime targets for these scams. A message about a doctor’s appointment or Medicare coverage may not raise suspicion, especially when it includes accurate personal information. This combination of familiarity and personalization makes these scams increasingly difficult to recognize.

To protect yourself from QR code scams, consider implementing a few simple checks. Most modern smartphones display the destination before opening a QR code link. Pay close attention to the web address; if it appears unfamiliar, shortened, misspelled, or slightly different from the organization’s official website, do not proceed.

If a receptionist or sign instructs you to scan a QR code, it’s perfectly acceptable to ask, “Is this your official QR code?” This straightforward question can help safeguard you against potential fraud. Additionally, before scanning any QR code, examine it closely for signs of tampering. If an official-looking envelope instructs you to scan a QR code, consider visiting the organization’s known website directly instead.

Whenever possible, utilize your healthcare provider’s official app or type its known website address directly into your browser. This rule applies to Medicare, pharmacies, and insurers as well. Avoid trusting a QR code solely because it appears in a familiar context.

Enabling two-factor authentication (2FA) for accounts that support it adds an extra layer of security, even if a scammer manages to obtain your password. Regularly installing operating system, browser, and security updates can also protect you from dangerous websites and malicious downloads that may result from scanning fraudulent codes.

If you encounter a suspicious QR code at a healthcare facility, report it to an employee. Removing one fraudulent sticker can prevent many others from falling victim to the same scam. You can also report suspected fraud to the Federal Trade Commission at ReportFraud.ftc.gov.

Ultimately, spotting a fraudulent QR code is crucial, but reducing the amount of personal information available online is equally important. Data brokers and people search websites can expose details such as your name, address, phone number, and age range. While these pieces of information may seem harmless individually, together they can provide criminals with enough background to create convincing scams.

You can take action by contacting data brokers and requesting the removal of your information. However, this process can be challenging, as your data may appear across multiple sites and could reemerge after removal. Utilizing a personal data removal service can help automate this process by sending removal requests on your behalf and continuously monitoring for reappearances.

Whether you choose to manage removals yourself or use a service, periodically searching for your name, phone number, and address online can help you understand what information is publicly available. The less information that is easily accessible, the harder it becomes for scammers to create personalized attacks.

In conclusion, the most convincing scams often include accurate personal details that lend them an air of legitimacy. A QR code at your doctor’s office, in a healthcare mailing, or on a hospital parking machine can be the final step leading you to a fraudulent website. Always check the destination, look for signs of tampering, and confirm unfamiliar codes with staff. Additionally, take steps to minimize the personal information available about you online. The less information scammers can find, the more challenging it becomes for them to create convincing scams.

Have you ever been asked to scan a QR code at a doctor’s office or pharmacy and questioned its legitimacy? Share your experiences with us at CyberGuy.com.

According to CyberGuy.

Leave a Reply

Your email address will not be published. Required fields are marked *

More Related Stories

-+=