By Jackson Godwin. Cybersecurity Analyst & Penetration Tester.

In Part 1, I explained how what appeared to be an intelligent AI healthcare assistant slowly collected my personal medical information before asking me to verify my identity through a fake security page.
Unfortunately, I later discovered that fake healthcare applications have become an increasingly attractive target for cybercriminals.
Why Criminals Want Medical Records
Many people believe credit card numbers are the most valuable information hackers can steal.
Surprisingly, medical records are often worth even more.
Unlike a stolen credit card, which can quickly be cancelled and replaced, medical information is permanent.
A medical record may contain:
- Full legal name
- Date of birth
- Home address
- Phone number
- Email address
- National identification details
- Health insurance information
- Medical history
- Prescription records
- Emergency contacts
Once stolen, this information can be abused in many different ways.
Medical Identity Theft
One of the biggest risks is medical identity theft.
This occurs when criminals use someone else’s personal information to:
- Obtain medical treatment
- Purchase prescription medication
- Submit fraudulent insurance claims
- Create fake patient records
- Commit financial fraud
Victims often discover the problem only after receiving unexpected medical bills or finding inaccurate information in their healthcare records.
How Fake AI Health Apps Trick Users
Cybercriminals know that people trust healthcare providers.
To exploit that trust, they design fake applications that appear professional and medically credible.
Many include:
- Images of doctors in white coats
- Medical symbols
- Health advice articles
- Fake patient testimonials
- Claims of AI-powered diagnosis
- Promises of secure medical storage
Everything is carefully designed to convince users that the application is legitimate.
They Collect More Than Health Information
While pretending to provide medical advice, some malicious applications also collect:
- Login credentials
- Device information
- Location data
- Contact lists
- Browser information
- Uploaded documents
- Payment details
Some even request unnecessary permissions such as:
- Camera access
- Microphone access
- SMS messages
- File storage
- Accessibility services
A genuine healthcare application should clearly explain why each permission is needed.
The Fake Privacy Policy
One thing I failed to check was the privacy policy.
Later, I discovered it was extremely vague.
It never clearly explained:
- Where my data would be stored.
- Who could access it.
- Whether information would be shared with third parties.
- How long records would be retained.
- What security protections were in place.
Legitimate healthcare providers are generally transparent about how they protect sensitive patient information.
The Suspicious Email
A few days after uninstalling the app, I received another email.
This time it claimed that my “health profile” required urgent verification.
The email included a button labeled:
Verify Your Medical Account
The page looked almost identical to the application.
Fortunately, by then I had become suspicious.
Instead of clicking the button, I carefully examined the sender’s email address.
It had nothing to do with the company that supposedly operated the app.
It was another phishing attempt.
Warning Signs of Fake Healthcare Apps
Looking back, several warning signs were obvious.
The application:
- Promised instant medical diagnoses.
- Requested excessive personal information.
- Asked for sensitive documents too early.
- Used aggressive verification requests.
- Had very limited company information.
- Offered unrealistic claims about AI accuracy.
- Had suspicious online reviews.
If an application asks for more information than necessary, take time to verify its legitimacy before continuing.
How I Reduced the Damage
After realizing what had happened, I acted immediately.
I:
- Changed my passwords.
- Enabled Multi-Factor Authentication.
- Contacted the relevant service providers.
- Removed the application.
- Monitored my accounts for suspicious activity.
- Became much more cautious about sharing sensitive health information online.
Fortunately, I responded before any significant financial damage occurred.
Coming Up in Part 3
In the final part, you’ll learn:
- How to safely use AI healthcare applications
- What to do if your medical information has been stolen
- Best practices for protecting sensitive health data
- Frequently Asked Questions
- Final cybersecurity lessons
- About the Author







