Eleven characters. That's the whole length of my father's real Medicare Beneficiary Identifier — the string a fake "Medicare representative" asked him to read back this spring, in exchange for a sturdier plastic replacement card and a small shipping fee. Nobody outside a Medicare office usually knows how long the real one is supposed to be, which is exactly the gap scammers count on. Medicare scams don't start with a bill — they start with a stranger asking for a number your parent has never had reason to memorize, and that's why senior safety, identity protection, and elder fraud prevention all have to begin before the bill ever arrives.
A fake IRS gift-card call in 2022 still shapes how I think about this — it nearly cost him five thousand dollars before I could step in. Two months later a gas-pump card skimmer hit my own account, and after that I stopped treating his mail and his medical benefits as two separate problems.
Families trying to protect a parent's Medicare identity usually settle into one of two habits and stop there. Some read the quarterly Summary Notice line by line, hunting for billing mistakes. Others lock down the phone and the mailbox so a stranger never gets the number to begin with. I've run both on my dad's accounts, and they catch two entirely different kinds of damage — which one to lean on, and when, matters more than which monitoring app ends up carrying his name.
Two Ways to Approach Medicare Scams and Elder Fraud Prevention
The first approach treats fraud like a spreadsheet problem: check every line of the notice, flag anything you didn't authorize, dispute it fast. It's the advice printed on nearly every government pamphlet, and it isn't wrong — it's just incomplete. The number on every Medicare card issued today is an 11-character code that replaced the old Social Security-based numbers years ago, specifically so it would be harder to weaponize. Scammers know that, so plenty of them have stopped chasing an extra box of diabetic test strips and started chasing the number itself.
What the Summary Notice Catches, and What It Misses
Billing review catches exactly what it's built to catch: a claim that doesn't match anything your parent actually received. It does not catch someone opening a new line of credit with details lifted from that same 11-character code. And it does not catch the slower, uglier version of this — medical identity theft, where a stranger's diagnoses and prescriptions get folded into your parent's actual chart. That second kind is why I treat the Medicare number with the same seriousness as a Social Security number. It's also why reading the quarterly Summary Notice line by line is still worth doing — it catches phantom billing early, even though it can't touch everything else the number gets used for.
Phone habits are where the other approach lives entirely. The Social Security Administration and Medicare will never call out of nowhere to sell a plan, verify a number, or ask for a shipping fee on a replacement card — full stop. If the phone rings about "benefits," it's a script, not a service, and no amount of billing vigilance changes that.
Locking Down the Number Before a Scammer Gets It
Our mail no-go zone is simple: anything that isn't a personal letter or a utility bill goes into my bag, not his kitchen drawer. Glossy Medicare pamphlets and the pink "urgent" envelopes made to mimic government letterhead get shredded on sight, on the shredder that sits on the floor of my home office, right next to the printer, because if it's out of reach I won't actually use it.
The phone no-go zone took longer to build. He's the generation raised to be polite to whoever calls, so hanging up on a stranger felt rude to him even when the stranger was lying. Working through how to block spam calls and stop phone scams on family phones together did more than any lecture about the Do Not Call list ever managed. Now if anyone calls about Medicare, Social Security, or his bank, his line is "my daughter handles that," and he hangs up before they can pivot to a second script.
My coworker Deon thought the phone rule sounded paranoid the first time I explained it — he's the guy who won't put so much as a bank statement in the cloud, so I expected him to be firmly on my side. What changed his mind was realizing the eleven characters aren't secret because they're complicated; they're secret because reading them out loud to a stranger on the phone is the only way they ever actually leave the house.
Why "Free" Monitoring Isn't the Same as a Habit
Not long after that gas-pump skimmer, I signed up for a year of free identity monitoring that came bundled with a data-breach settlement, the kind of offer buried in a class-action notice most people throw away (I almost did). I set it up, checked the dashboard twice, and forgot about it completely. When I finally logged back in, the year had already expired, and looking through the history, not one alert had ever fired the entire time. I don't know if that means nothing happened or the service simply never worked — either way, it taught me that a subscription sitting quietly in the background isn't a habit, it's a hope.
Contrast that with the afternoon I was sitting in my car outside SouthPark Mall and my phone buzzed with an alert that someone had just tried to open a new account in my name. That single ping did more in ten seconds than the free monitoring did in an entire year, because it actually looked at something and said so the instant it changed. Whatever you use to watch your own accounts, that's the real test — not whether it exists, but whether it would tell you anything at all.
I've written elsewhere about how I judge that kind of service more carefully — my Norton 360 credit monitoring review after a financial data breach gets into the specifics — but for Medicare, the short version holds up: a service you forget you're paying for protects nobody. The habit has to survive the moment you stop thinking about it, or it was never really a habit.
Choose the Habit That Matches Where Things Stand
The right approach depends on the current threat level. If your parent is already fielding calls about "benefits" or a stack of urgent envelopes has started showing up, lock down the phone and the mailbox immediately; by the time a scammer has the actual number, there's no bill left to review, because the exposure already happened before any claim gets filed. If things are quiet and nothing is actively targeting him yet, the quarterly Summary Notice read-through is the lower-effort backstop, the one that catches phantom billing early enough to dispute before it turns into something closer to medical record contamination.
Either way, don't mistake a free or forgotten subscription for either of those habits — it covers neither. My binder still lives on the bookshelf in that same home office, tabbed by year, with a whiteboard beside it tracking which accounts got checked and when; the rings click shut every time I slide in a new page, which happens more often than I'd like. If you're holding an actual notice saying his information turned up in a breach somewhere, read the steps to take after receiving a data breach notification letter before doing anything else, because that clock moves faster than any quarterly bill ever will.
None of this makes either one of us immune — no habit does, and anyone who tells you otherwise is selling something. What it actually means is that the next "Medicare representative" who calls my dad's house gets a dial tone instead of an eleven-character head start.