DarkNet Dispatch All articles
Cybercrime & Law Enforcement

Bleeding Data: The Underground Economy Feeding on America's Stolen Health Records

DarkNet Dispatch
Bleeding Data: The Underground Economy Feeding on America's Stolen Health Records

Photo: The National Archives UK - Flickr account derivative work: Hic et nunc, OGL v1.0, via Wikimedia Commons

In February 2024, Change Healthcare — a subsidiary of UnitedHealth Group and one of the largest health payment processors in the United States — suffered a ransomware attack that exposed the medical and personal data of an estimated 100 million Americans. It was the single largest healthcare data breach in U.S. history. Yet for most of the individuals affected, the implications extended well beyond a disrupted pharmacy claim. Their information had entered a supply chain they never consented to, one operating entirely in the dark.

Healthcare data breaches are not anomalies. They are, by most measures, the defining cybersecurity crisis of the American medical system. The Department of Health and Human Services reported more than 700 large breaches in 2023 alone, affecting tens of millions of patients. What the statistics rarely convey is what happens after the breach notification letter arrives — the quiet, methodical commerce that unfolds in spaces most people will never see.

Why Medical Records Command a Premium

On underground forums and dark web marketplaces, stolen financial credentials are plentiful and, as a result, relatively cheap. A compromised credit card number might sell for a few dollars. A complete medical record — what the industry refers to as a "fullz" when it contains comprehensive personal data — can command anywhere from $50 to several hundred dollars per record, depending on its completeness and freshness.

The reason is straightforward: a credit card can be canceled. A medical history cannot.

A comprehensive health record typically contains a patient's full legal name, date of birth, Social Security number, home address, insurance policy details, prescription history, diagnostic codes, and treating physician information. That constellation of data points is extraordinarily difficult to repudiate or replace. It enables a range of fraudulent schemes that financial data alone cannot support, and it retains its value for years after the initial theft.

Security researchers who monitor dark web forums consistently note that healthcare records are treated as a premium commodity. Sellers frequently advertise the source institution, the date range of the records, and the volume available — marketing language indistinguishable, structurally, from legitimate data brokerage.

The Path From Breach to Marketplace

The journey of a stolen medical record typically begins not with a dramatic intrusion, but with something far more mundane: a phishing email sent to a hospital billing clerk, an unpatched vulnerability in a legacy electronic health records system, or compromised credentials purchased from a previous, unrelated breach.

Once inside a healthcare network, threat actors move laterally, identifying databases containing patient records and exfiltrating them — often over days or weeks — before detection. In ransomware cases, the data may be stolen and encrypted simultaneously, giving attackers two distinct points of leverage: the ransom demand and the threat of public sale.

Following exfiltration, the data typically passes through several layers before reaching an end buyer. Initial access brokers may sell network entry points to ransomware operators. Ransomware groups may sell bulk datasets to data brokers operating on private forums. Those brokers, in turn, parcel records into smaller lots for resale to identity thieves, fraudulent billing operators, and pharmaceutical scammers. Each transaction adds distance between the original breach and the ultimate harm — a deliberate feature of the underground economy that complicates law enforcement attribution.

What Criminals Do With It

The criminal applications of stolen medical data are more varied than most patients appreciate.

Medical identity theft is the most direct form of exploitation. A fraudster armed with a victim's insurance credentials and basic identifying information can file false claims with Medicare or private insurers, obtain prescription medications under the victim's name, or receive medical services billed to the victim's policy. The consequences for the victim can be severe: corrupted medical records, wrongful debt collection, and, in serious cases, dangerous errors in future medical treatment if a provider's records reflect procedures or medications the patient never received.

Synthetic identity fraud is a related but distinct threat. Criminals combine legitimate data points from multiple individuals — a Social Security number from one record, a date of birth from another — to construct entirely fictitious identities capable of opening credit accounts, obtaining loans, or committing tax fraud. Healthcare records are particularly valuable inputs for this process because of their data richness.

Prescription fraud and drug diversion represent another downstream application. Records detailing a patient's prescription history can be used to fraudulently obtain controlled substances, either for personal use or resale.

Finally, targeted phishing and social engineering attacks leveraging medical information have grown more sophisticated. A message that references a patient's actual physician, their recent procedure, or their insurance provider carries a credibility that generic phishing attempts cannot replicate.

The Regulatory Landscape and Its Limits

The Health Insurance Portability and Accountability Act — HIPAA — imposes breach notification requirements and security standards on covered entities. But critics argue the law's enforcement mechanisms are insufficient relative to the scale of the problem. Civil penalties, while substantial in high-profile cases, have not materially deterred breaches at smaller providers and rural hospital systems, which often lack the resources to maintain robust cybersecurity programs.

The FBI and the Department of Justice have pursued enforcement actions against ransomware groups responsible for major healthcare breaches, including the indictment and sanctioning of individuals affiliated with the ALPHV/BlackCat group — the ransomware variant responsible for the Change Healthcare attack. International coordination through Europol and bilateral agreements with allied nations has produced notable takedowns. However, the decentralized, pseudonymous architecture of dark web marketplaces means that disrupting one node rarely eliminates the underlying data already in circulation.

What Patients Can Do

The systemic vulnerabilities in healthcare cybersecurity are largely beyond an individual patient's control. That said, several concrete actions can reduce personal exposure and enable earlier detection of exploitation.

Request your records regularly. Under HIPAA, patients have the right to request a copy of their medical records from any covered provider. Reviewing them periodically allows you to identify procedures, prescriptions, or diagnoses you do not recognize — potential indicators of medical identity theft.

Monitor your Explanation of Benefits. Every claim processed by your insurer generates an Explanation of Benefits (EOB) document. Reviewing EOBs — particularly for services at unfamiliar providers — is one of the most effective early-detection tools available.

Check your credit reports. Because medical identity theft frequently cascades into financial fraud, monitoring your credit reports through AnnualCreditReport.com and considering a credit freeze with the three major bureaus (Equifax, Experian, and TransUnion) provides an additional layer of protection.

Place a fraud alert with providers. If you have reason to believe your medical identity has been compromised, contact your insurer's fraud department directly and request that a flag be placed on your account requiring additional verification before claims are processed.

Respond promptly to breach notifications. When a healthcare provider notifies you of a breach, take the offered credit monitoring services and follow up on any recommended protective steps. The notification itself is a signal that your data has likely already entered the supply chain described above.


The breach notification letter is, in many respects, the beginning of the story rather than its end. The records it references have value that extends years beyond the incident date, in markets operating well outside the reach of any single regulator or law enforcement agency. Treating that letter as a call to action — rather than a bureaucratic formality — may be among the most consequential decisions a patient makes.

All Articles

Related Articles

From Pixels to Pavement: How Threat Actors Reconstruct Your Physical Life From Digital Crumbs

From Pixels to Pavement: How Threat Actors Reconstruct Your Physical Life From Digital Crumbs

Open Secrets, Loaded Weapons: How Threat Actors Forge Dossiers From Your Public Life

Open Secrets, Loaded Weapons: How Threat Actors Forge Dossiers From Your Public Life

Silent Conscripts: How Cybercriminals Quietly Draft Your Devices Into a Global Attack Network

Silent Conscripts: How Cybercriminals Quietly Draft Your Devices Into a Global Attack Network