Bots attack healthcare

Relentless bots. Legacy security. Healthcare in the crosshairs.

AI bots conduct recon to steal high-value data and target HSA and FSA funds.

Listen now

[!AUDIO]https://cdn.prod.website-files.com/6a809521fc6b7dfa71f2e253/6aa17ca60785348eb8ec2991_AI-Fraud-Guide_Chapter-3.mp3[/]

AI bots are hammering healthcare—with no signs of slowing.

After implementing Pindrop, a major U.S. healthcare provider uncovered bot attacks account for more than half of all fraud in their systems.1 Bots like these systemically exploit healthcare contact centers, probing IVR systems for reconnaissance, using intel from the IVR to carry out social engineering schemes with live agents, taking over accounts, and in some cases, gaining access to HSA, FSA, and other employer-funded savings accounts.

This same customer saw over 15,000 unique bot fraud calls since the summer of 2025,1 indicating that attackers are turning this tactic into a repeatable scheme. By deploying automated bots at scale, attackers can harvest or validate Social Security numbers, dates of birth, balances, and transaction histories—without ever speaking with a live agent.

AI bots are hammering healthcare

Why do we think they’re bots?

Despite the fact that our researchers aren’t seeing text-to-speech artifacts or lag, they’re noticing “programming-style” commands that suggest script-driven interactions. These commands let bots interact with near-human speed. Background noise analysis also suggests that attackers are in a call-center-style fraud operation, deploying their fraud schemes at scale.

Why is healthcare a target?

Healthcare is facing a perfect storm. The controls that once kept attacks manageable are failing at the exact moment that scams are getting faster, cheaper, and harder to spot. Legacy security checks are no longer a meaningful barrier when stolen personal data is everywhere. Nearly 60% of organizations now report fraudsters using compromised Personally Identifiable Information (PII) to quickly bypass knowledge-based authentication (KBAs).2

At the same time, generative AI has changed the threat landscape. According to Pindrop data, deepfake attacks exploded by 880% in 2024.3 This is not a theoretical risk. It is showing up at scale, in real accounts, with real losses.

Regulators are cracking down too. The largest general healthcare fraud takedown in U.S. history, charging 324 defendants tied to $14.6 billion in intended losses, signals a new era of scrutiny and enforcement.4 For healthcare, these forces collide at once: weak legacy defenses, AI-fueled attacks at industrial scale, and growing regulatory pressure.

Listen to a deepfake call in healthcare.

[!AUDIO]https://cdn.prod.website-files.com/6a809521fc6b7dfa71f2e253/6aa17cd43b66cf8439a8c090_Healthcare-Extracted-Recreation-V1-11-21-25_AI-Fraud-Guide.mp3[/]

AI attacks put your bottom line at risk.

AI-driven scams create real business damage fast. The most immediate impact is financial loss. Compromised accounts can lead to direct financial losses, especially when potentially high-balance accounts like HSAs and FSAs are targeted. Beyond that, indirect costs like investigations and reimbursements can quickly add up, turning a single incident into a significant financial loss.

Trust is also damaged. Healthcare organizations are trusted with some of the most sensitive and valuable data and financial accounts consumers have. When those accounts are compromised, confidence in an organization can drop drastically. High-balance accounts attract attackers, and even a small number of public failures can damage brand reputation. Rebuilding trust takes time, effort, and additional investment long after the attack itself is mitigated.

Healthcare financial exposure

Operational strain is another impact of an attack. When AI-powered schemes are convincing in the voice channel, it ends up wasting agents’ time. Fraud management teams can also face a massive increase in alerts and investigations. The result is longer handle times, overworked teams, and slower service for genuine customers.

Case in point: A U.S. healthcare provider faced over $40M in account exposure related to fraudulent AI bot calls in 2025.1

AI isn’t always nefarious.

AI isn’t necessarily the villain—it’s just a tool. Its impact depends entirely on the intent of the human behind it.

In healthcare, that reality is already playing out in legitimate ways. Providers, trying to reduce administrative burden, may turn to AI agents to handle routine tasks like insurance verification. Or members may use AI to assist in translation services during a call. These AI-assisted callers aren’t trying to deceive or steal; they’re trying to communicate, access systems, or streamline workflows. The challenge for healthcare organizations isn’t stopping AI—it’s learning how to distinguish between AI being used as a productivity or accessibility tool and AI being weaponized for fraud.

Citations

AI retail fraud rises

Continue reading

Move from understanding to action

Fight back against AI attacks with Pindrop.

Schedule a demo