Listen now
[!AUDIO]https://cdn.prod.website-files.com/6a809521fc6b7dfa71f2e253/6aa17ca60785348eb8ec2991_AI-Fraud-Guide_Chapter-3.mp3[/]
AI bots are hammering healthcare—with no signs of slowing.
After implementing Pindrop, a major U.S. healthcare provider uncovered bot attacks account for more than half of all fraud in their systems.1 Bots like these systemically exploit healthcare contact centers, probing IVR systems for reconnaissance, using intel from the IVR to carry out social engineering schemes with live agents, taking over accounts, and in some cases, gaining access to HSA, FSA, and other employer-funded savings accounts.
This same customer saw over 15,000 unique bot fraud calls since the summer of 2025,1 indicating that attackers are turning this tactic into a repeatable scheme. By deploying automated bots at scale, attackers can harvest or validate Social Security numbers, dates of birth, balances, and transaction histories—without ever speaking with a live agent.

Why do we think they’re bots?
Despite the fact that our researchers aren’t seeing text-to-speech artifacts or lag, they’re noticing “programming-style” commands that suggest script-driven interactions. These commands let bots interact with near-human speed. Background noise analysis also suggests that attackers are in a call-center-style fraud operation, deploying their fraud schemes at scale.
Why is healthcare a target?

Healthcare is facing a perfect storm. The controls that once kept attacks manageable are failing at the exact moment that scams are getting faster, cheaper, and harder to spot. Legacy security checks are no longer a meaningful barrier when stolen personal data is everywhere. Nearly 60% of organizations now report fraudsters using compromised Personally Identifiable Information (PII) to quickly bypass knowledge-based authentication (KBAs).2

At the same time, generative AI has changed the threat landscape. According to Pindrop data, deepfake attacks exploded by 880% in 2024.3 This is not a theoretical risk. It is showing up at scale, in real accounts, with real losses.

Regulators are cracking down too. The largest general healthcare fraud takedown in U.S. history, charging 324 defendants tied to $14.6 billion in intended losses, signals a new era of scrutiny and enforcement.4 For healthcare, these forces collide at once: weak legacy defenses, AI-fueled attacks at industrial scale, and growing regulatory pressure.
Listen to a deepfake call in healthcare.
[!AUDIO]https://cdn.prod.website-files.com/6a809521fc6b7dfa71f2e253/6aa17cd43b66cf8439a8c090_Healthcare-Extracted-Recreation-V1-11-21-25_AI-Fraud-Guide.mp3[/]
AI attacks put your bottom line at risk.
AI-driven scams create real business damage fast. The most immediate impact is financial loss. Compromised accounts can lead to direct financial losses, especially when potentially high-balance accounts like HSAs and FSAs are targeted. Beyond that, indirect costs like investigations and reimbursements can quickly add up, turning a single incident into a significant financial loss.
Trust is also damaged. Healthcare organizations are trusted with some of the most sensitive and valuable data and financial accounts consumers have. When those accounts are compromised, confidence in an organization can drop drastically. High-balance accounts attract attackers, and even a small number of public failures can damage brand reputation. Rebuilding trust takes time, effort, and additional investment long after the attack itself is mitigated.

Operational strain is another impact of an attack. When AI-powered schemes are convincing in the voice channel, it ends up wasting agents’ time. Fraud management teams can also face a massive increase in alerts and investigations. The result is longer handle times, overworked teams, and slower service for genuine customers.
Case in point: A U.S. healthcare provider faced over $40M in account exposure related to fraudulent AI bot calls in 2025.1
AI isn’t always nefarious.
AI isn’t necessarily the villain—it’s just a tool. Its impact depends entirely on the intent of the human behind it.
In healthcare, that reality is already playing out in legitimate ways. Providers, trying to reduce administrative burden, may turn to AI agents to handle routine tasks like insurance verification. Or members may use AI to assist in translation services during a call. These AI-assisted callers aren’t trying to deceive or steal; they’re trying to communicate, access systems, or streamline workflows. The challenge for healthcare organizations isn’t stopping AI—it’s learning how to distinguish between AI being used as a productivity or accessibility tool and AI being weaponized for fraud.
Text
1%
Text
Text
1%
Text
Text
1%
Text
Text
Lorem ipsum dolor sit amet consectetur. Sit convallis ullamcorper et varius venenatis blandit vitae hendrerit blandit. Hac aenean tellus consectetur elit orci aenean ipsum arcu. Turpis a laoreet sit rhoncus eros penatibus facilisis dolor tempus. Vitae gravida fames nunc dui scelerisque porta nulla ut. Sit mi volutpat ipsum odio nulla sociis.
Lorem Ipsum is simply dummy
Vitae eleifend mi lorem iaculis malesuada sit adipiscing vel. Sit massa ut etiam eu.
1 Anonymous Pindrop healthcare data collected in 2025
2 Hypr, “TransUnion 2025 State of Omnichannel Fraud Report Insights,” May 2025.
3 Pindrop, “2025 Voice Intelligence and Security Report,” June 2025.
4 U.S. Department of Health Human Services, “2025 National Health Care Fraud Takedown,” 2025.




