The scammer at your doctor’s office may already know who you are

Scammers hide malicious QR codes in medical offices, Medicare mail and parking signs. Learn how to spot the trap before you scan.



















At a glance
  • Scammers may already know your name, address and other personal details before they contact you.
  • Fake QR codes can appear in medical mailings, doctor’s offices and hospital parking areas.
  • A convincing fake site may ask for your Medicare number, patient portal login or payment information.
  • Verify unexpected QR codes and go directly to your provider’s official website or app whenever possible.

 

You arrive at your doctor’s office and see a sign asking you to scan a QR code to check in. Later, you receive a text about a prescription. A Medicare notice with your name and address arrives in the mail. Before you leave, another QR code asks you to pay for parking. All of it looks routine. That’s exactly what can make these scams so dangerous. Criminals aren’t limited to sending obvious phishing messages to random people. Personal information available through data brokers and people-search websites can help scammers create medical, Medicare and payment scams that look like they were meant specifically for you.

Then a QR code gives them an easy way to send you to a convincing fake website asking for your Medicare number, patient portal login, credit card information or other sensitive data. Here’s what to watch for during your next trip to the doctor’s office and one important step that can make you harder for scammers to target in the first place.

 

 

A QR code connected to health information can expose sensitive personal data if it leads to a fake or malicious website

 

Why your doctor’s office makes scams easier to trust

QR codes have become a normal part of healthcare. Doctors’ offices use them for check-in forms. Pharmacies use them for pickup information. Medicare Advantage and Part D plans may include them in enrollment materials and other communications. Hospitals and medical buildings increasingly use QR codes for parking payments. That familiarity works in a scammer’s favor. When you’re standing inside your doctor’s office, holding paperwork that looks official or looking at a sign next to a parking machine, you naturally expect the information to be legitimate. Scammers know that.

A QR code also hides something that a normal web link does not: where it is actually taking you. You can usually glance at a link in an email before clicking it. With a QR code, you see a square filled with black and white patterns. You don’t know where it leads until your phone reads it. That makes the location of the QR code itself part of the deception.

 

How a fake QR code can fool you

The mechanics of the scam are surprisingly simple.

A criminal can:

  • Mail a fake notice designed to resemble something from your health plan.
  • Send a text claiming to concern a prescription or appointment.
  • Place a fraudulent QR code sticker over a legitimate code.
  • Put a fake “scan to pay” code on a parking meter or payment machine.

Scan the code, and you may land on a website designed to resemble your insurer, pharmacy, doctor’s portal or payment processor.

The site may ask for your:

  • Medicare number
  • Patient portal username and password
  • Social Security number
  • Credit or debit card
  • Date of birth
  • Address
  • Other identifying information

QR code phishing is sometimes called “quishing.” The challenge is that many people have become so accustomed to QR codes that scanning one no longer feels like clicking a link.

QR codes hide their destination until you scan, making it harder to spot a suspicious link before you tap.

 

How scammers may already know personal details about you

This is where these scams can become much more convincing. A criminal contacting you may already have access to details such as your:

  • Full name
  • Home address
  • Phone number
  • Approximate age
  • Household information
  • Other publicly available personal details

Some of that information can appear on data broker and people-search websites. Think about the difference between receiving a generic message that says: “Your health coverage has changed.” and receiving a notice addressed to you by name, sent to your correct home address and written to resemble something connected to Medicare or your health coverage. The second message feels far more believable. That’s why protecting yourself isn’t only about spotting a fake QR code. It’s also about reducing the amount of personal information strangers can easily find about you online.

 

Real QR code scams are already showing up

These examples show how fraudulent QR codes can blend into places where people already expect to see them.

A fake Medicare plan letter

One Medicare beneficiary described receiving a letter that appeared to come from a major insurer and directed the recipient to scan a QR code to read an Annual Notice of Change. The letter reportedly closely resembled legitimate plan correspondence, but the QR code pointed to a shortened, lookalike web address instead of the insurer’s actual domain. This particular example is a reported account rather than a confirmed investigated incident, but it follows a familiar scam pattern: make an official-looking Medicare communication feel urgent and legitimate, then direct the victim somewhere controlled by the scammer.

 

A hospital parking scam with real financial losses

At Totnes Community Hospital in the U.K., a fraudulent QR code sticker was discovered on a parking payment machine. One visitor who scanned the code to pay reportedly had £146.79 taken from her account. The scammers then attempted to take another £849 before her bank’s fraud team intervened. The hospital trust confirmed the fraudulent code and began monitoring payment machines at other locations.

Fake parking QR codes closer to home

Law enforcement in Redondo Beach and San Clemente, California, has documented scammers placing counterfeit QR code stickers next to legitimate parking payment instructions. A medical office or hospital parking structure can be an especially convincing place for this trick because people already expect to scan something to pay.

Medical offices increasingly use phones and digital forms for check-in, giving scammers another way to imitate trusted systems.

Why Medicare-related scams can feel especially convincing

Older Americans frequently interact with healthcare systems, pharmacies, insurance providers and Medicare.

That means a message about:

  • A doctor’s appointment
  • Prescription pickup
  • Medicare coverage
  • Insurance changes
  • Medical paperwork
  • Hospital parking

may not seem unusual. Add accurate personal information to the message, and the scam can become even harder to recognize. That’s the real danger. The QR code might be the thing you scan, but the personal details surrounding it are what can make you trust it.

Retirees often encounter QR codes through Medicare paperwork, prescriptions and appointments, making them attractive targets for scammers.

 

Your doctor’s office QR code checklist

A few quick checks can help you determine whether a QR code deserves your trust.

 

1) Preview the link before opening it

Most modern phones display the destination before opening a QR code link. Look carefully at the web address. If the domain is unfamiliar, shortened, misspelled or slightly different from the organization’s normal website, don’t continue.

 

2) Ask the doctor’s office to confirm it

If a receptionist, sign or piece of paperwork tells you to scan a QR code, there’s nothing wrong with asking: “Is this your official QR code?” That simple question can protect you if someone has placed a fraudulent sticker over a legitimate code.

 

3) Look for signs of tampering

Before scanning a QR code on a sign, parking meter or payment machine, look closely. Be suspicious if the code:

  • Appears crooked
  • Looks like a sticker placed over another sticker
  • Has peeling edges
  • Doesn’t match the rest of the sign
  • Appears to have been added later

 

4) Don’t automatically trust QR codes in the mail

An official-looking envelope does not guarantee that what’s inside is legitimate. If a Medicare or insurance notice tells you to scan a QR code, consider going directly to the organization’s known website instead. You can also call the phone number printed on your insurance card rather than relying on contact information supplied in an unexpected mailing.

 

5) Go directly to the source

Whenever possible, use your healthcare provider’s official app or type its known website address directly into your browser. The same rule applies to Medicare, pharmacies and insurers. Don’t trust a QR code simply because it appears in a place you trust.

 

6) Turn on two-factor authentication

Enable two-factor authentication (2FA) for accounts that support it, especially:

  • Patient portals
  • Pharmacy accounts
  • Medicare.gov
  • Email
  • Financial accounts

Two-factor authentication adds another barrier even if a scammer manages to obtain your password.

 

7) Keep your phone and security software updated

Install operating system, browser and security updates when they become available. Updates can help protect against dangerous websites, malicious downloads and other threats you might encounter after scanning a fraudulent code.

 

8) Report suspicious QR codes immediately

If you see a QR code at a doctor’s office, hospital, pharmacy or parking facility that appears suspicious, tell an employee. Removing one fraudulent sticker could prevent many other people from scanning it. You can also report suspected fraud to the Federal Trade Commission at ReportFraud.ftc.gov.

 

Make yourself harder for scammers to research

Spotting a fraudulent QR code can protect you from one scam. Reducing the personal information available about you can make it harder for scammers to build convincing attacks in the first place. Data brokers and people-search websites can expose information such as your name, address, phone number, age range and household details. Those pieces of information may seem harmless on their own. Put together, they can give a criminal enough background information to make a Medicare notice, medical message or other scam feel surprisingly personal. You can contact data brokers and submit removal requests yourself, although keeping track of where your information appears and whether it comes back can take time.

That’s why I recommend Incogni.

Incogni automatically sends removal requests to more than 420 data brokers and continues monitoring in case your information reappears.

 

Exclusive Deal for CyberGuy Readers (60% off): Incogni offers a 30-day money-back guarantee and applies a special CyberGuy discount to annual plans, starting as low as $6.39 per month for one person when billed annually or $13.19 per month for a family of up to five people.

The Unlimited plan also lets you request removals from specific websites where you discover your personal information.

I recommend the family plan. It works out to about $2.64 per person per month, or $4.80 per person per month for the Family Unlimited plan.

Get Incogni and remove your info

Get Incogni and remove your info

 

 

Protect your household with Incogni’s Family Plan

Get Incogni’s Family Plan

 

 

 

Related Links:

 

 

Kurt’s key takeaways

The most convincing scams don’t always feel random. They may include your name, address or other accurate personal details that make a fake medical notice, Medicare communication or payment request feel legitimate. A QR code at your doctor’s office, in a healthcare mailing or on a hospital parking machine can simply be the final step that sends you to a fraudulent website. Before scanning, check the destination, look for signs of tampering and confirm unfamiliar codes with staff. Whenever possible, go directly to the organization’s official website or app. Just as importantly, find out how much personal information about you is publicly available online. The less information scammers can easily find about you, the harder it becomes for them to create a scam that feels like it was made specifically for you.

Have you ever been asked to scan a QR code at a doctor’s office or pharmacy and wondered whether it was legitimate? Let us know in the comments below.

FOR MORE OF MY TECH TIPS & SECURITY ALERTS, SUBSCRIBE TO MY FREE CYBERGUY REPORT NEWSLETTER HERE

 

We created this article in partnership with Incogni.

Copyright 2026 CyberGuy.com. All rights reserved. CyberGuy.com articles and content may contain affiliate links that earn a commission when purchases are made.

What's Your Reaction?

like

dislike

love

funny

angry

sad

wow