Logo
  • Our Approach
  • Providers
    • Release of Information
  • Payers
    • Chart Retrieval
  • Partners
Request a Demo
Logo Request a Demo
  • Our Approach
  • Providers
    • Release of Information
  • Payers
    • Chart Retrieval
  • Partners
  • Developer Portal
  • Resources
  • Careers
  • Contact
  • Security

Stop Healthcare Data Fraud Before It Starts

Why Automated ROI Is Key to Healthcare Privacy

Moxe Health: 08.01.2025 5:34 PM
CybersecurityDigital ROIrelease of information

In his mid-year update, our CEO talked about the importance of ensuring that healthcare stakeholders have a privacy-centric interoperability strategy to combat fraudulent Release of Information (ROI) requests. Why the recent focus on this topic?

As fraudsters get smarter, it’s getting harder to differentiate their requests from the real thing. Even trusted payers and requestors are being spoofed, putting patient data and provider reputations at serious risk. To compound the challenge, not only are their schemes getting more sophisticated, but the number of fraudulent requests are growing. Modern phishing schemes require a modern ROI solution.

What is causing the uptick in fraudulent requests?

After recent large data breaches, it is not surprising that there are more fraudsters using legitimate information to gain unauthorized access to patient data. Once data has been compromised it becomes much easier to use real patient names, Medicare numbers, dates of birth, etc., making the phony requests that much harder to spot. What can your team do?

Stop cyberattacks with automated Release of Information

Leveraging a fully automated solution fundamentally eliminates these risks. 

Moxe’s automated Release of Information (ROI) solution uses API-based integration that requires all requestors to use token-based authentication with established credentials making fraudulent requests nearly impossible. When a new requestor is added to Moxe’s digital network their identity is verified, therefore when a request is received electronically from that requestor, providers can be confident that it is not a fraudulent request. 

Along with significantly reducing the risk of fraudulent requests by eliminating manual processes, our HIPAA-compliant ROI solution accelerates record delivery, reduces costs, and improves accuracy. Real-time dashboards provide transparency in medical record fulfillment, while our privacy-centric health data exchange ensures only the minimum necessary information is shared.

Having the right experts matters

Moxe’s experts are dedicated, passionate professionals trained to spot fraudulent requests. Fully certified and US-based, our experts stay up to date with the latest resources from HHS, AHIOS, and state-specific resources.

“I am passionate about privacy. I love reviewing statutes and regulations to ensure that Moxe’s solutions are compliant,” says Tabitha Peterson, our ROI Lead. In her position, Tabitha works directly with our customers to offer specialized training focused on spotting fraudulent requests. 

Some of her top tips to spot a fraudulent request?

  1. Different area codes for phone and fax numbers
  2. Fake or outdated company logo
  3. Asks for provider’s physical signature
  4. No medical condition specified
  5. Sender may sign the request using a celebrity name
  6. “Patient is under our care” / “Regarding our mutual patient”
  7. Asks for last or most recent notes, rather than a specific date of service
  8. Will use multiple reasons for requesting record
  9. Claims to be urgent and HIPAA compliant
  10. Poor grammar and/or punctuation

The importance of collaboration

Taking a partnership approach, we work with our customers to ensure we are aware of the latest phishing schemes and pass that information along and vice versa. Recently, one of our health system customers brought a breach to our attention.

“In this instance, we provided information on how to spot fraudulent requests and guidance on a process they can implement for when they do find a fraudulent request,” shared Peterson.

Considering your options

When evaluating ROI solutions, it is important to ask yourself the question, “How will this solution scale with our business?” As regulations evolve and technology changes, is your ROI solution flexible enough to stand the test of time? Moxe is proud to bring all the stakeholders—payers, providers, and requestors—together to modernize ROI, automating requests. 

Check out our security eBrief to get our 6 tips on protecting against cyberattacks.

Logo

Keep up with the latest in interoperability.

  • Our Approach
  • Providers
  • Payers
  • Partners
  • Contact
  • Resources
  • Careers
  • Developer Portal

608.669.9176
info@MoxeHealth.com

228 North Henry St., Ste. #300
Madison, WI 53703

10 Post Office Sq., 8th floor
Boston, MA 02109

© 2025 Moxe Health

Terms of Use Privacy policy Technology Governing Agreement
Manage Consent
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behavior or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
  • Manage options
  • Manage services
  • Manage {vendor_count} vendors
  • Read more about these purposes
View preferences
  • {title}
  • {title}
  • {title}
Manage Consent
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behavior or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
  • Manage options
  • Manage services
  • Manage {vendor_count} vendors
  • Read more about these purposes
View preferences
  • {title}
  • {title}
  • {title}