Report sheds light on the various ways hackers make money from stolen medical data, from forging a doctor's identity to selling fake prescriptions and labels
Stolen medical information can sell for up to six times as much as PII, and there are reasons for that.
Context & Ripple Effects
This 2019 ZDNet report answers a question the healthcare breach coverage had been circling for years: why stolen medical records command such a premium. The dark-web listings were already visible — 655K patient records from three breaches put up for sale in 2016 after extortion victims refused to pay — but the monetization mechanics behind the price gap had not been spelled out. The report's answer: a medical record is not just identity data, it is a fraud toolkit — a doctor's identity to forge, prescriptions to fake, labels to counterfeit.
That framing explains why the breach counts kept climbing afterward: HHS tallied health information of 40M+ people exposed in 2021, up from 26M in 2020, and the Change Healthcare ransomware attack showed a single 2024 incident could touch a substantial proportion of the US population. Where the payout per record is six times PII, attackers have a standing reason to keep hitting healthcare first.
First-order effects
- Patients whose records leak face direct fraud exposure beyond identity theft: forged prescriptions and counterfeit medical labels are usable immediately, and forged doctor identities can be used to order services or drugs in the victim's name.
- Healthcare providers and insurers holding these records become the premium target on dark-web markets — the 6x price multiple means a healthcare breach is worth more to a seller per record than a generic PII dump of the same size.
Second-order effects
- Monetization diversity weakens the extortion standoff seen in the 2016 case: when victims refuse ransom, attackers no longer face a write-off — they can pivot to direct sale and fraud, which lowers the cost of walking away and keeps pressure on hospitals to pay.
- Leak channels diversify alongside buyers — the Star Health episode showed 31M customer records surfacing on Telegram rather than traditional dark-web markets, widening the distribution surface insurers must monitor.
Third-order effects
- If the pattern holds, healthcare consolidates its position as the most valuable and most-attacked category of personal data — the sector where breach economics, not just breach frequency, diverge from the rest of the PII market.
- That premium is a structural argument for treating medical data as a distinct regulatory and security tier: rising HHS exposure counts point toward stricter segmentation, access controls, and data-minimization requirements for health records specifically, because the downside of a health breach now exceeds that of an equivalent PII breach.
The trend: Stolen health data is shifting from a bulk commodity dumped on dark-web markets to a diversified fraud input, and that rising per-record value is making healthcare the most persistently targeted data category.