Loading...

Protecting patient identities as QR codes open up new cybersecurity risks

Published: February 22, 2022 by Experian Health

Protecting-patient-identities-as-QR-codes-open up-new-cybersecurity-risks

QR codes made an unexpected comeback during the pandemic. They offered a contactless gateway for individuals to check in to venues, log COVID-19 test results, help trace the virus spread and more. Restaurants and retailers embraced the technology as a way to welcome back consumers with touch-free access to online menus and digital payments. Previously seen as gimmicky and hindered by dependence on specific apps, these scannable squares can now be read using most smartphone cameras. With new use cases emerging during the pandemic, “quick response” codes are suddenly relevant again. However, the growing popularity of QR code technology opened the door to new cybersecurity risks, so providers must remain proactive with protecting patient identities.

A 2020 survey found that almost half of consumers said they’d noticed an increase in QR codes since the first shelter-in-place orders. Online payment provider PayPal reported that a new merchant was added to its QR code payment option every 28 seconds in the first quarter of 2021.  Cybercriminals are capitalizing on consumer trust in QR codes to harvest personal data or install malware on devices. This leaves healthcare organizations and their patients vulnerable to fraud, especially given the increased adoption of digital healthcare technology during the pandemic. Providers must remain vigilant with protecting patient identities from QR code cybersecurity risks.

How do QR codes threaten patient identities?

QR codes hold far more data than traditional barcodes. They can be easily generated and fixed to any surface, ready for users to scan with their smartphones. They are primarily used to store URLs, which take the user directly to a website.

But while savvy consumers are aware of the risks associated with clicking on a suspicious link in an email, QR codes are intrinsically trusted. It’s much harder to tell if a QR code is legitimate or not. Scanning a QR code is essentially the same as clicking on an unknown link. A study by MobileIron found that while 67% of consumers say they can identify a suspicious URL, less than 30% can identify a malicious QR code. Mike Bruemmer, VP of Experian Data Breach Resolution and Consumer Protection, says that “QR codes are the new stealth threat vector. Regardless of their application, no one can tell a fake code that launches malware on your device from a legitimate one.”

There are two main risks for patients. Firstly, they may click on a QR code that takes them to a web page that appears legitimate, prompting them to share personal data or log-in details. This information is then harvested by cybercriminals. This form of QR code phishing, known as “quishing,” puts the user at risk for spam, adware and identity theft. Secondly, the user may scan a QR code that takes them to a malicious site that installs malware on their device, which will then steal and package the user’s personal and financial data. The QR code can even be used to generate actions that appear to come from the user, such as making payments, sending emails, sharing locations or following social media accounts.

In January 2022, the FBI issued a warning about cybercriminals using QR codes to redirect victims to malicious sites that steal login and financial information. Users are urged to practice caution when entering personal information after scanning a QR code.

How can healthcare organizations help with protecting patient identities against QR code cybersecurity threats?

For healthcare organizations, the concern is that if patients fall victim to a QR code scam, bad actors can steal personal identification data to access patient portals and other digital services. This information can be used to access medical services without paying, obtain medications illegally, or submit false health insurance claims, creating ongoing financial and administrative stress for patients. Or, if cybercriminals use captured information to log on as staff members there’s an added risk of further data breaches from inside the provider’s network.

Healthcare organizations have a few options to help patients protect themselves from QR code scams:

  • Targeted awareness-raising campaigns are a simple way to encourage patients to make sure their devices are updated with the latest security patches. Patients can be warned to watch out for suspicious activity, such as when a QR code redirects to a page that asks for personal details. They might also choose to ask for a direct URL, instead of using the QR code.
  • Securing access to patient portals and verifying patient identities are practical measures to ensure that the person accessing the account is who they say they are. Another best practice in patient portal security is to take a multi-layered approach. This includes two-factor authentication, device recognition and additional checks on risky requests. By securing patient portals, providers can be proactive at protecting patient identities and reduce the risk of fraud during enrollment.
  • Integrating patient identity management tools can also help verify the patient’s identity from the very first registration touchpoint all the way through their healthcare journey. Automated identity checks and algorithmic matching based on Experian Health’s unrivaled reference data can help ensure that the patient’s record is accurate and complete.
  • Offering alternative secure methods for contactless patient payments and patient access are other options to make the patient experience more secure. For example, providing patients with their own mobile payment option means they can pay bills securely and access payment plans right from their phone. Experian Health also offers various safe and secure registration and scheduling solutions that will give patients a seamless patient access experience and help protect them from identity theft. Victoria Dames, VP of Product Management at Experian Health, says that patients have come to expect a smooth and secure digital experience: “Providers are focused on patient data security in adherence to multiple health policies, like HIPAA, but also to maintain confidence with patients. They [patients] are embracing digital solutions and expecting appropriate security measures are in place.”

Find out more about how Experian Health can help healthcare providers with protecting patient identities and close the door to QR code scammers. Experian Health can also help prevent other identity theft and fraud, verify that patients are who they say are, and provide safe, secure and convenient ways for patients to get the care they need.

Related Posts

Manual prior authorization workflows represent one of the most tedious and expensive aspects of the healthcare revenue cycle. However, despite access to automated prior authorization software, only 31% of providers use electronic prior authorizations, according to the Council for Affordable Quality Healthcare (CAQH). The CAQH predicts that providers who switch to automated prior authorization software could not only gain back valuable staff time, but also see significant cost savings. What is prior authorization and why is it important? In healthcare, prior authorizations are when providers and payers decide in advance if a patient's insurance plan will pay for a specific treatment. Prior authorizations are crucial to reimbursements and keeping revenue cycles on track. Providers that offer services without prior authorization are unlikely to receive reimbursement from the patient's insurer. This can result in unpaid medical bills, leaving billing teams chasing patient collections or writing off bad debt. During the prior authorization process, providers submit a rationale for a proposed treatment to the payer. The request is approved or denied based on certain criteria, including payer policies and medical necessity. The payer may reject a prior authorization request if the treatment or service isn't covered under the patient's insurance plan, if it's not considered medically necessary or if a more affordable alternative is available. Simple paperwork errors, like missed deadlines or incomplete documentation when submitting a prior authorization, may also result in a denial. Challenges of manual prior authorization processes Despite the importance of prior authorizations in the revenue cycle, tedious manual prior authorization processes present challenges for many healthcare providers. Some of the key obstacles providers face using manual prior authorization include: Heavy administrative burden Healthcare providers spend a significant amount of time starting, completing and revising prior authorization paperwork. An AMA survey found that 86% of physicians say prior authorization has increased healthcare resource usage. At the same time, additional AMA data reports that providers spend around 13 hours working on 39 prior authorizations each week, and nearly one-third of providers report that these prior authorization requests usually end up being denied. Changing payer policies Keeping up with multiple payers and ever-evolving payer policies adds strain on staff and ultimately results in prior authorization denials. Changes are often unannounced, making it hard for providers to stay on top of updates. As a result, prior authorization submissions aren’t always accurate and may be based on outdated rules. This can lead to instant rejection and wasted time correcting and resubmitting requests. Inefficient workflows Prior authorization requirements can be complicated, especially when providers are juggling different payers, standards and service lines. Coping with these complexities often puts strain on manual systems, especially when multiple staff and notetaking methods are involved. Staff members may each get different pieces of information from payer websites (or over the phone) and not have the ability to benefit from their shared knowledge efficiently. Navigating communication hurdles and rapid payer information changes can result in workflow inefficiencies that snowball quickly. How prior authorization software can improve efficiency Replacing manual prior authorizations processes with automated prior authorization software can help providers improve efficiency. Here are some key ways providers benefit from automated prior authorization solutions, like Experian Health's Authorizations. Reduces manual interventions: This solution limits guesswork, human errors, and misinterpretations by automating data originating from the EMRs. Automation saves staff time and energy and prevents frustration. Stays current with latest payer policies: The prior authorization system stays up-to-date with the latest regulations and payer requirements. Automatic updates provide staff with the most current information, eliminating the need for staff to visit multiple payer websites or cross-check data by hand. Provides real-time updates: Providers can promptly clear authorizations for service by proactively identifying authorization status as pending, denied or authorized. This allows physicians to make timely treatment plans and for patients to avoid disruptions in care. Reduces risk of denials: Through automation, electronic prior authorization software ensures the accuracy and completeness of submissions by automatically checking with payers and vendors to validate that the authorization is on file. Payers and providers also get a shared view of account information, reducing the need for prolonged discussions about the status of authorization and rework requests. Key features to look for in prior authorization software When implementing prior authorization software, look for a solution that offers a wide range of features to automate and streamline the prior authorization process. Experian Health's prior authorization solution, Authorizations, for instance, offers healthcare providers the following key features: Real-time knowledgebase: Access to up-to-date prior authorization requirements and criteria in the National Payer Rulesets Submissions support: Removes guesswork and directs users to the correct payer portal based on procedure Automated inquiries: Automates the prior authorization payer inquiry process Enhanced workflow: Dynamic work queues display status and guides users through next steps Postback: Allows users to easily send authorization status, number and validity dates to health information systems (HIS) and practice management systems (PMS) Image storage: Receives and securely stores payer responses in an integrated document imaging system Reconciliation: Provides insights into authorization variations and helps resolve them, so staff can take proactive steps to prevent denials and appeals Integration with electronic health records and billing systems: Why it matters Providers often choose a prior authorizations platform that seamlessly integrates with existing Electronic Health Records (EHR) and billing systems for maximum efficiency. Solutions like Experian Health's automated prior authorization management tool, Authorizations, easily adapt to existing processes. This eliminates the need for a complete workflow overhaul and minimizes the learning curve for staff. Embracing prior authorization software for a more efficient revenue cycle Revenue cycle leaders who implement prior authorization automation strategies could see significant savings – $494 million annually as an industry, according to CAQH data.  Claims and revenue management processes are often complex and outdated, costing healthcare organizations time and money. High denial rates and slow reimbursements can hurt cash flow and get in the way of financial stability. Automating prior authorization can reduce claim denials, speed up reimbursements and improve the bottom line. Learn more about how Experian Health's electronic prior authorization software, Authorizations, uses automation to achieve greater consistency and efficiency for healthcare organizations. Learn more Contact us

Published: July 30, 2025 by Experian Health

Discover how automating revenue cycle management can streamline patient access, reduce claim denials, and improve reimbursement timelines.

Published: June 5, 2025 by Experian Health

In this interview, Clarissa Riggins, Chief Product Officer at Experian Health, shares key takeaways from the State of Patient Access 2025 report.

Published: May 27, 2025 by Experian Health

Subscribe to our blog

Enter your name and email for the latest updates.

This site is protected by reCAPTCHA and the Google Privacy Policy and Terms of Service apply.

Subscribe to the Experian Health blog

Get the latest industry news and updates!
Subscribe