The scammer at your doctor's office may already know who you are

QR code scams at doctor's offices use data brokers and people search websites to craft personalized phishing attacks targeting your Medicare number.

Aug 13, 2026 - 22:00
 2
The scammer at your doctor's office may already know who you are

You arrive at your doctor’s office and see a sign asking you to scan a QR code to check in. Later, you receive a text about a prescription. A Medicare notice with your name and address arrives in the mail. Before you leave, another QR code asks you to pay for parking. 

All of it looks routine. That’s exactly what can make these scams so dangerous. Criminals aren’t limited to sending obvious phishing messages to random people. Personal information available through data brokers and people search websites can help scammers create medical, Medicare and payment scams that look like they were meant specifically for you.

Then a QR code gives them an easy way to send you to a convincing fake website asking for your Medicare number, patient portal login, credit card information or other sensitive data. Here’s what to watch for during your next trip to the doctor’s office and one important step that can make you harder for scammers to target in the first place.

META MEDICARE SCAM ADS TARGETING SENIORS FACE SCRUTINY

New! Free live CyberGuy class: Protect Your Money From Today’s Biggest Threats

Join us Saturday, Aug. 29, at 10 a.m. ET for a free CyberGuy LIVE class covering five simple steps to help defend yourself against AI scams, fraud, identity theft and financial hacks. Kurt "CyberGuy" Knutsson will explain how to set up bank alerts, strengthen your account logins, protect your phone number, freeze your credit and help secure your retirement savings against unauthorized transfers. No technical experience is needed. You'll also receive our financial protection checklist, and every registrant will get a link to the class recording afterward.

Reserve your free spot today at CyberGuyLive.com.

QR codes have become a normal part of healthcare. Doctors’ offices use them for check-in forms. Pharmacies use them for pickup information. Medicare Advantage and Part D plans may include them in enrollment materials and other communications. Hospitals and medical buildings increasingly use QR codes for parking payments. That familiarity works in a scammer’s favor. When you’re standing inside your doctor’s office holding paperwork that looks official or looking at a sign next to a parking machine, you naturally expect the information to be legitimate. Scammers know that.

A QR code also hides something that a normal web link does not: where it is actually taking you. You can usually glance at a link in an email before clicking it. With a QR code, you see a square filled with black and white patterns. You don’t know where it leads until your phone reads it. That makes the location of the QR code itself part of the deception.

The mechanics of the scam are surprisingly simple.

A criminal can:

Scan the code, and you may land on a website designed to resemble your insurer, pharmacy, doctor’s portal or payment processor.

The site may ask for your:

QR code phishing is sometimes called "quishing." The challenge is that many people have become so accustomed to QR codes that scanning one no longer feels like clicking a link.

This is where these scams can become much more convincing. A criminal contacting you may already have access to details such as your:

Some of that information can appear on data broker and people search websites. Think about the difference between receiving a generic message that says: "Your health coverage has changed" and receiving a notice addressed to you by name, sent to your correct home address and written to resemble something connected to Medicare or your health coverage. The second message feels far more believable. That’s why protecting yourself isn’t only about spotting a fake QR code. It's also about reducing the amount of personal information strangers can easily find about you online.

FAKE VA SHOE OFFER TARGETS VETERANS

These examples show how fraudulent QR codes can blend into places where people already expect to see them.

One Medicare beneficiary described receiving a letter that appeared to come from a major insurer and directed the recipient to scan a QR code to read an Annual Notice of Change. The letter reportedly closely resembled legitimate plan correspondence, but the QR code pointed to a shortened, lookalike web address instead of the insurer’s actual domain. This particular example is a reported account rather than a confirmed investigated incident, but it follows a familiar scam pattern: make an official-looking Medicare communication feel urgent and legitimate, then direct the victim somewhere controlled by the scammer.

At Totnes Community Hospital in the U.K., a fraudulent QR code sticker was discovered on a parking payment machine. One visitor who scanned the code to pay reportedly had £146.79 taken from her account. The scammers then attempted to take another £849 before her bank’s fraud team intervened. The hospital trust confirmed the fraudulent code and began monitoring payment machines at other locations.

Law enforcement in Redondo Beach and San Clemente, California, has documented scammers placing counterfeit QR code stickers next to legitimate parking payment instructions. A medical office or hospital parking structure can be an especially convincing place for this trick because people already expect to scan something to pay.

Older Americans frequently interact with healthcare systems, pharmacies, insurance providers and Medicare.

That means a message about a doctor's appointment, prescription pickup, Medicare coverage, insurance changes, medical paperwork or hospital parking may not seem unusual. Add accurate personal information to the message, and the scam can become even harder to recognize. That’s the real danger. The QR code might be the thing you scan, but the personal details surrounding it are what can make you trust it.

A few quick checks can help you determine whether a QR code deserves your trust.

Most modern phones display the destination before opening a QR code link. Look carefully at the web address. If the domain is unfamiliar, shortened, misspelled or slightly different from the organization’s normal website, don't continue.

If a receptionist, sign or piece of paperwork tells you to scan a QR code, there's nothing wrong with asking, "Is this your official QR code?" That simple question can protect you if someone has placed a fraudulent sticker over a legitimate code.

Before scanning a QR code on a sign, parking meter or payment machine, look closely. Be suspicious if the code:

An official-looking envelope does not guarantee that what’s inside is legitimate. If a Medicare or insurance notice tells you to scan a QR code, consider going directly to the organization’s known website instead. You can also call the phone number printed on your insurance card rather than relying on contact information supplied in an unexpected mailing.

FCC ROBOCALL CRACKDOWN COULD CHANGE PHONE PRIVACY

Whenever possible, use your healthcare provider’s official app or type its known website address directly into your browser. The same rule applies to Medicare, pharmacies and insurers. Don’t trust a QR code simply because it appears in a place you trust.

Enable two-factor authentication (2FA) for accounts that support it, especially:

Two-factor authentication adds another barrier even if a scammer manages to obtain your password.

Install operating system, browser and security updates when they become available. Updates can help protect against dangerous websites, malicious downloads and other threats you might encounter after scanning a fraudulent code.

If you see a QR code at a doctor’s office, hospital, pharmacy or parking facility that appears suspicious, tell an employee. Removing one fraudulent sticker could prevent many other people from scanning it. You can also report suspected fraud to the Federal Trade Commission at ReportFraud.ftc.gov.

Spotting a fraudulent QR code can protect you from one scam. Reducing the personal information available about you can make it harder for scammers to build convincing attacks in the first place. Data brokers and people search websites can expose information such as your name, address, phone number, age range and household details. Those pieces of information may seem harmless on their own. Put together, they can give a criminal enough background information to make a Medicare notice, medical message or other scam feel surprisingly personal.

You can contact data brokers and people search sites yourself and request that your information be removed. The challenge is that your information may appear across many different sites and can sometimes return after it has been removed.

A personal data removal service can help automate that process by sending removal requests to data brokers on your behalf and continuing to check whether your information reappears. No service can guarantee that every piece of personal information will disappear from the internet, but reducing what is easily available can give scammers fewer details to work with when trying to create a convincing, personalized attack.

Whether you handle removals yourself or use a service, periodically search for your name, phone number and address online to see what strangers can find. The less information that is readily available about you, the harder it can be for a scammer to make a fake medical message, Medicare notice or payment request look legitimate.

Check out my top picks for data removal services and get a free scan to find out if your personal information is already out on the web by visiting CyberGuy.com.

The most convincing scams don’t always feel random. They may include your name, address or other accurate personal details that make a fake medical notice, Medicare communication or payment request feel legitimate. A QR code at your doctor’s office, in a healthcare mailing or on a hospital parking machine can simply be the final step that sends you to a fraudulent website. 

Before scanning, check the destination, look for signs of tampering and confirm unfamiliar codes with staff. Whenever possible, go directly to the organization’s official website or app. Just as importantly, find out how much personal information about you is publicly available online. The less information scammers can easily find about you, the harder it becomes for them to create a scam that feels like it was made specifically for you.

Have you ever been asked to scan a QR code at a doctor’s office or pharmacy and wondered whether it was legitimate? Let us know by writing to us at Cyberguy.com

Sign up for my FREE CyberGuy Report

Copyright 2026 CyberGuy.com. All rights reserved.

Jat AI Stay informed with the latest in artificial intelligence. Jat AI News Portal is your go-to source for AI trends, breakthroughs, and industry analysis. Connect with the community of technologists and business professionals shaping the future.