Loading...

Protecting patient identities as QR codes open up new cybersecurity risks

Published: February 22, 2022 by Experian Health

Protecting-patient-identities-as-QR-codes-open up-new-cybersecurity-risks

QR codes made an unexpected comeback during the pandemic. They offered a contactless gateway for individuals to check in to venues, log COVID-19 test results, help trace the virus spread and more. Restaurants and retailers embraced the technology as a way to welcome back consumers with touch-free access to online menus and digital payments. Previously seen as gimmicky and hindered by dependence on specific apps, these scannable squares can now be read using most smartphone cameras. With new use cases emerging during the pandemic, “quick response” codes are suddenly relevant again. However, the growing popularity of QR code technology opened the door to new cybersecurity risks, so providers must remain proactive with protecting patient identities.

A 2020 survey found that almost half of consumers said they’d noticed an increase in QR codes since the first shelter-in-place orders. Online payment provider PayPal reported that a new merchant was added to its QR code payment option every 28 seconds in the first quarter of 2021.  Cybercriminals are capitalizing on consumer trust in QR codes to harvest personal data or install malware on devices. This leaves healthcare organizations and their patients vulnerable to fraud, especially given the increased adoption of digital healthcare technology during the pandemic. Providers must remain vigilant with protecting patient identities from QR code cybersecurity risks.

How do QR codes threaten patient identities?

QR codes hold far more data than traditional barcodes. They can be easily generated and fixed to any surface, ready for users to scan with their smartphones. They are primarily used to store URLs, which take the user directly to a website.

But while savvy consumers are aware of the risks associated with clicking on a suspicious link in an email, QR codes are intrinsically trusted. It’s much harder to tell if a QR code is legitimate or not. Scanning a QR code is essentially the same as clicking on an unknown link. A study by MobileIron found that while 67% of consumers say they can identify a suspicious URL, less than 30% can identify a malicious QR code. Mike Bruemmer, VP of Experian Data Breach Resolution and Consumer Protection, says that “QR codes are the new stealth threat vector. Regardless of their application, no one can tell a fake code that launches malware on your device from a legitimate one.”

There are two main risks for patients. Firstly, they may click on a QR code that takes them to a web page that appears legitimate, prompting them to share personal data or log-in details. This information is then harvested by cybercriminals. This form of QR code phishing, known as “quishing,” puts the user at risk for spam, adware and identity theft. Secondly, the user may scan a QR code that takes them to a malicious site that installs malware on their device, which will then steal and package the user’s personal and financial data. The QR code can even be used to generate actions that appear to come from the user, such as making payments, sending emails, sharing locations or following social media accounts.

In January 2022, the FBI issued a warning about cybercriminals using QR codes to redirect victims to malicious sites that steal login and financial information. Users are urged to practice caution when entering personal information after scanning a QR code.

How can healthcare organizations help with protecting patient identities against QR code cybersecurity threats?

For healthcare organizations, the concern is that if patients fall victim to a QR code scam, bad actors can steal personal identification data to access patient portals and other digital services. This information can be used to access medical services without paying, obtain medications illegally, or submit false health insurance claims, creating ongoing financial and administrative stress for patients. Or, if cybercriminals use captured information to log on as staff members there’s an added risk of further data breaches from inside the provider’s network.

Healthcare organizations have a few options to help patients protect themselves from QR code scams:

  • Targeted awareness-raising campaigns are a simple way to encourage patients to make sure their devices are updated with the latest security patches. Patients can be warned to watch out for suspicious activity, such as when a QR code redirects to a page that asks for personal details. They might also choose to ask for a direct URL, instead of using the QR code.
  • Securing access to patient portals and verifying patient identities are practical measures to ensure that the person accessing the account is who they say they are. Another best practice in patient portal security is to take a multi-layered approach. This includes two-factor authentication, device recognition and additional checks on risky requests. By securing patient portals, providers can be proactive at protecting patient identities and reduce the risk of fraud during enrollment.
  • Integrating patient identity management tools can also help verify the patient’s identity from the very first registration touchpoint all the way through their healthcare journey. Automated identity checks and algorithmic matching based on Experian Health’s unrivaled reference data can help ensure that the patient’s record is accurate and complete.
  • Offering alternative secure methods for contactless patient payments and patient access are other options to make the patient experience more secure. For example, providing patients with their own mobile payment option means they can pay bills securely and access payment plans right from their phone. Experian Health also offers various safe and secure registration and scheduling solutions that will give patients a seamless patient access experience and help protect them from identity theft. Victoria Dames, VP of Product Management at Experian Health, says that patients have come to expect a smooth and secure digital experience: “Providers are focused on patient data security in adherence to multiple health policies, like HIPAA, but also to maintain confidence with patients. They [patients] are embracing digital solutions and expecting appropriate security measures are in place.”

Find out more about how Experian Health can help healthcare providers with protecting patient identities and close the door to QR code scammers. Experian Health can also help prevent other identity theft and fraud, verify that patients are who they say are, and provide safe, secure and convenient ways for patients to get the care they need.

Related Posts

Healthcare providers are under more pressure than ever. See how patient appointment scheduling software can help.

Published: March 5, 2025 by Experian Health

“You know when the Patient Access Curator went live because you can see it in our stock price. It helped us drive a $100 million bottom-line improvement within two quarters.” —Ken Kubisty, Vice President of Revenue Cycle at Exact Sciences Challenge Exact Sciences is a prominent cancer diagnostics laboratory with an annual net revenue of around $2.6 billion, that's best known for its flagship cancer screening test, Cologuard. After a period of rapid growth demand for its test, Exact Sciences faced the difficult task of collecting accurate patient data and verifying insurance eligibility at scale. Anticipating a 25% growth in annual testing volumes, Ken Kubisty, Vice President of Revenue Cycle at Exact Sciences, says the organization “needed an automated, real-time solution" to capture accurate data from the start. The company had four specific objectives: Improve the accuracy of patient insurance data to reduce errors and denials. Streamline processes to handle rising testing volumes without increasing headcount. Reduce claim denials to bring in more revenue (especially those related to eligibility and timely filing). Ensure accurate identity verification in lab settings, where patient, physician and lab data aren't unified within a single data management system. Watch the webinar: Hear our pre-recorded session from our annual Experian Health High-Performance Summit 2024 (HPS), featuring Exact Sciences and Trinity Health, as they reveal how Patient Access Curator helped their organizations automate eligibility, reduce denials, and more, all with a single click. Solution In need of a single solution to solve multiple challenges, Exact Sciences turned to Experian Health's Patient Access Curator. This new product provided the team with a way to run inquiries for eligibility, Medicare beneficiary identifiers, coordination of benefits, insurance discovery and demographic data with a single click. Instead of juggling multiple products and vendors, registrars would be able to capture and verify patient data in a single transaction. Through automation and machine learning, Patient Access Curator could deliver results in less than 30 seconds and help submit clean claims the first time – reducing the risk of denials even as volumes increased. Experian Health's implementation experts configured the tool to Exact Sciences' needs, integrating over 4,000 payer plans nationwide and customizing parameters for real-time eligibility checks and data validation. Experian Health also delivered staff training to support the transition to the new system. Watch the video: See how Experian Health's Patient Access Curator streamlines patient access and billing, addressing claim denials, data quality and real-time corrections to boost your business's bottom line. Outcome Thanks to Patient Access Curator, Exact Sciences achieved the following results: 15% increase in revenue per test due to accurate eligibility and fewer denials 4x business volume without increasing headcount 50% reduction in denials and major improvement in timely filings $100 million added to the bottom line in 6 months Ken Kubisty, VP of Revenue Cycle at Exact Sciences, shares how Patient Access Curator improved eligibility processes, reduced errors and more. Overall, Kubisty credits Experian Health's Patient Access Curator for helping Exact Sciences overcome critical pain points resulting from data errors and eligibility issues. Solving for bad data quality with real-time data correction freed staff from tedious manual work, ensuring faster, more accurate claims processing – all without growing headcount. After implementing Patient Access Curator, the company is ready to scale and handle growing volumes efficiently, say goodbye to late filing denials and scale smarter. For Kubisty, this highlights how technology drives efficiency and sustainable growth. Learn more about how Patient Access Curator helps patient access teams prevent claim denials by solving for bad data quality with real-time data correction. Learn more Contact us

Published: February 27, 2025 by Experian Health

Healthcare revenue cycle management challenges exist at every stage of the patient journey. Learn how to overcome them.

Published: February 13, 2025 by Experian Health

Subscribe to our blog

Enter your name and email for the latest updates.

This site is protected by reCAPTCHA and the Google Privacy Policy and Terms of Service apply.

Subscribe to the Experian Health blog

Get the latest industry news and updates!
Subscribe