What to Do If a New Patient Portal Account or Medical Login Appears to Use Your Information

If you receive a “Welcome to your patient portal” email, see a new medical login on your inbox, or notice a healthcare account you never created, treat it as urgent. Unrecognized patient-portal accounts can come from a simple registration error—or signal medical identity theft, where someone uses your information to obtain care, prescriptions, or benefits. This guide shows you how to verify what happened, close any unauthorized access, protect your insurance and credit, and restore your records.

Why an Unknown Patient Portal Matters

Patient portals contain highly sensitive information: diagnoses, test results, prescriptions, insurance details, and sometimes payment methods. Unauthorized access can cause three types of harm:

  • Privacy harm: Exposure of medical details and personal identifiers (name, DOB, address, policy numbers).
  • Financial harm: Fraudulent claims, surprise bills, or collection accounts from services you never received.
  • Safety harm: Incorrect medical data (allergies, medications) added to your record, which can affect future care.

Immediate Actions: Verify, Preserve Evidence, and Stop Access

Move quickly but methodically. Start by documenting what you see and preventing further damage.

  1. Do not click suspicious links. If the notice came by email or text, avoid links and log in only through the provider’s known website or app—or call the provider’s main number from their public site.
  2. Preserve evidence. Screenshot the email or notification (include headers if possible), note dates, sender addresses, subject lines, and any account details visible.
  3. Call the provider’s privacy or patient portal support line. Use the number listed on the provider’s official website. Say: “I received a notice about a portal account I did not create. Please disable access and verify what activity occurred.” Ask for a case number.
  4. Request a portal lock and password reset. If the portal was linked to your email or phone, request a forced logout on all devices, multi-factor authentication (MFA) enforcement, and a password reset.
  5. Ask if any appointments, messages, or insurance claims were made. Record all findings and ask for copies of logs that show access attempts or changes.

Determine Whether It’s an Error or Medical Identity Theft

Unauthorized accounts arise for a few common reasons:

  • Clerical or registration error: A staff member mistyped an email or phone number, accidentally linking your contact to someone else’s record.
  • Crossed identities: Another patient with a similar name or DOB was matched to your email.
  • Actual medical identity theft: Someone used your personal information to open a portal, access your records, or obtain services.

Ask the provider to confirm which identity elements are on the account (full name, DOB, address, last 4 of SSN, insurance member ID). If these match you, assume higher risk and continue with fraud steps even if they suspect a clerical error.

Secure Your Login Credentials and Email First

Because patient portals often hinge on your email or phone, lock down your primary accounts:

  • Change your email password to a long, unique passphrase and enable MFA (preferably app-based, not SMS if possible).
  • Check your email rules and forwarding for any unauthorized filters or redirects.
  • Update passwords for any health-related accounts, pharmacy logins, and insurer portals. Use a password manager to generate unique credentials.

Work With the Provider: What to Request in Writing

Healthcare providers must protect patient information. Put key requests in writing to their privacy officer or HIPAA compliance contact.

  • Request a Security Review: Ask them to investigate how the account was created, what data or features were accessed, and whether your email/phone was verified.
  • Request Activity Logs: Ask for dates, IP addresses or device fingerprints (if available), and a list of actions (logins, profile edits, messages, downloads).
  • Request Portal Deactivation or Correction: If your contact was attached to another person’s record, request immediate correction and written confirmation of the fix.
  • Request Free Credit/Identity Protections if due to a breach: If they confirm a data exposure on their side, ask whether they are offering notification and protective services.
  • Request a copy of your designated record set, including demographics, visit history, and medication/allergy lists, so you can check for inaccuracies.

Check Your Health Insurance and Medical Bills

Fraud often shows up first in claims or billing activity. Take these steps:

  • Log into your health insurer portal and review recent claims, explanation of benefits (EOBs), and provider visits. Look for unknown services, providers, locations, or dates.
  • Call your insurer’s fraud department if you find suspicious claims. Ask them to flag your account for potential medical identity theft and to block or verify new providers.
  • Contact any provider listed on a suspicious claim and ask for records of the encounter. Inform them you did not receive services and request a fraud review.
  • Review recent statements from hospitals, labs, urgent care, pharmacies, and telehealth platforms for unfamiliar charges.

Correct Your Medical Record to Protect Your Care

If you find errors added to your chart, request corrections quickly. Incorrect allergies, medications, or conditions can put you at risk.

  1. Ask the provider’s Health Information Management (HIM) department how to submit an amendment request. Provide a clear, factual statement describing what is incorrect and why.
  2. Attach supporting documents (e.g., your ID, a timeline of the issue, any police or FTC report numbers) to reinforce the request.
  3. Ask to add a patient statement noting suspected identity theft so other clinicians see the alert.
  4. Follow up for written confirmation that corrections or addenda have been applied to your record.

File Key Reports and Freeze the Financial Angle

While medical identity theft is about healthcare, the same personal information can be used for financial fraud. Add these safeguards:

  • Place a free security freeze with the three nationwide credit bureaus (Equifax, Experian, TransUnion) to block new credit accounts in your name until you lift the freeze.
  • Get your credit reports and look for unfamiliar accounts, inquiries, or addresses. Dispute anything you don’t recognize.
  • File an identity theft report with the FTC at IdentityTheft.gov to create a recovery plan and get an Identity Theft Report you can share with providers and insurers.
  • Consider a police report if providers or insurers request it, or if bills/collections continue despite your disputes.

Monitor for Ongoing Misuse

Medical identity theft can spread across providers and time. Proactive monitoring helps you catch issues early:

  • Watch for new “welcome” emails from providers, pharmacies, or telehealth platforms you don’t use.
  • Set alerts in your email for phrases like “patient portal,” “verification code,” “EOB,” or “claim processed.”
  • Check insurer claims monthly and keep a simple log of all contacts, case numbers, dates, and outcomes.
  • Use identity and credit monitoring to track changes in your financial identity that may follow a medical incident. If you want centralized monitoring and alerts, consider a dedicated service that helps you keep tabs on your credit, report changes, and certain identity-related activity. For a practical overview of one option, see SmartCredit for privacy, credit monitoring, and identity protection.

How to Talk to Providers and Insurers (Scripts)

Use clear, concise language. Here are examples you can adapt:

  • To a provider’s privacy office: “I received a patient-portal registration notice using my email. I did not create this account. Please disable access, require MFA on any future access, and send me a summary of all activity associated with my identifiers. I am treating this as suspected medical identity theft.”
  • To a billing department: “I received a bill for services I did not receive. Please place the account in fraud review status, provide an itemized statement, and send your identity theft dispute process. I will provide my FTC Identity Theft Report number.”
  • To your insurer: “I suspect medical identity theft. Please review recent claims for fraud indicators, block out-of-pattern providers, and note my account for verification on new claims.”

If It Was a Clerical Error Only: Still Close the Loop

Even if the provider confirms a typo or misdirected registration, take these final steps:

  • Get written confirmation that your contact info was removed from the other patient’s record and that their portal access no longer touches your information.
  • Ask the provider to purge any messages, documents, or data that were sent to your email or portal by mistake.
  • Re-check your insurer portal for safety and set up MFA on your real portal accounts.
  • Keep your documentation for at least a year in case related issues appear later.

Preventive Steps for the Future

Reduce the chance of a repeat and make misuse easier to detect:

  • Use unique, strong passwords and MFA for all health, pharmacy, and insurance portals.
  • Opt for app-based authenticators when available, and store backup codes securely.
  • Limit public exposure of your identifiers (full DOB, address history, insurer details) on social media and forms that don’t need them.
  • Review privacy settings with providers—ask if they can require in-person or phone verification before account changes.
  • Shred or securely store EOBs, insurance cards, and medical paperwork.

Frequently Asked Questions

Is an unknown patient portal always identity theft?

No. It could be a staff error or a mix-up with contact information. However, treat it as suspected fraud until the provider verifies the cause and confirms no activity occurred in your name.

Can medical identity theft affect my credit?

Yes. Unpaid fraudulent medical bills can be sold to collectors and end up on credit reports. Freezing your credit, disputing unauthorized accounts, and monitoring changes help reduce this risk.

Will the provider tell me exactly who accessed my data?

They may share activity logs and steps taken, but specifics can vary by organization and law. Focus on confirming what data might have been exposed and ensuring access is closed.

What if a provider refuses to correct my record?

Submit a formal amendment request. Providers must add your statement to the record if they decline to amend. You can also escalate to their privacy office and state medical board or file a complaint with relevant regulators.

A Simple Checklist

  • Document the alert; avoid clicking suspicious links.
  • Contact the provider via their official number; request a portal lock and logs.
  • Secure your email and essential accounts with strong passwords and MFA.
  • Review insurer claims and billing; dispute unknown charges.
  • Request record copies and corrections to remove fraudulent entries.
  • Place credit freezes, pull credit reports, and file an FTC report if needed.
  • Monitor for new activity and keep organized records of all steps.

Conclusion

When a new patient portal account appears to use your information, act immediately. Confirm whether it’s an error or identity theft, shut down unauthorized access, correct your medical record, and protect your insurance and credit from fallout. With prompt, organized steps—and ongoing monitoring—you can contain the damage, restore accuracy in your health records, and reduce the chance of future misuse.

Good to Know

A surprise medical portal account can be a sign of medical identity theft or a clerical mix-up. Treat it as potential fraud until proven otherwise—errors are fixable, but delayed responses to real misuse can be costly.