Is It Safe to Keep Medical Information in Your Wallet?
By the Emergency Info Card Editorial Team
·

Yes — it is safe to carry your medical conditions, allergies, medications, and emergency contacts in your wallet, and that is exactly the information a paramedic needs. The risky half of the pile is different: your Social Security card, your billing paperwork, and — with more nuance — your insurance member or Medicare number. The "never keep this in your wallet" listicles tend to blur clinical information and account identifiers into a single warning, and once they're blurred the safe-sounding conclusion is to carry nothing at all.
The distinction isn't a matter of opinion. It comes directly from how medical identity theft actually works.
What medical identity theft actually runs on
The Federal Trade Commission defines it precisely: medical identity theft is when someone uses your personal information — "like your name, Social Security number, health insurance account number or Medicare number" — to get medical care, see a doctor, get prescription drugs, buy medical devices, or submit claims with your insurance provider.
Read that list again. Every item is an account identifier — something that authorizes billing. None of them is a diagnosis, a drug name, or an allergy.
The FTC's own list of documents to protect follows the same logic. It names health insurance enrollment forms, health insurance cards, prescriptions, prescription bottles, billing statements from your provider, and Explanation of Benefits statements. It is a list of billing paperwork. A card that says "Type 1 diabetes, insulin pump, allergic to penicillin, call my daughter Sarah at 555-0143" is not on it, because there is no fraud to commit with it — there's nothing in it to bill an insurer with.
That is the whole answer, and it's why a wallet emergency card and an insurance card belong in different categories even though both are "medical."
The two lists
| Safe to carry every day | Keep at home (bring only when needed) |
|---|---|
| Full name and date of birth | Social Security card |
| Medical conditions and implanted devices | Explanation of Benefits statements |
| Current medications and doses | Printed prescriptions and prescription bottles |
| Drug and food allergies | Billing statements from your provider |
| Two emergency contacts | Anything showing a claim number or account balance |
| Your doctor and preferred hospital | — |
The right-hand column is not "never leave the house with these." It's "these have no emergency value, so carrying them daily only adds exposure." You do need your insurance card at an appointment — take it that day and bring it home.
Your insurance member number or Medicare number sits in between, and it's the one field worth thinking about rather than following a rule. See the next two sections.
The Medicare nuance that outdated advice still gets wrong
Some wallet-safety advice still warns that your Medicare card exposes your Social Security number. That stopped being true years ago. CMS removed Social Security Number-based Health Insurance Claim Numbers from Medicare cards and replaced them with the Medicare Beneficiary Identifier (MBI), and CMS describes each MBI as "unique, randomly generated" with characters that are "non-intelligent, which means they don't have any hidden or special meaning."
So the old reason to fear the card is gone. The new reason is smaller but real: CMS states plainly that "the MBI is confidential like the SSN and should be protected as Personally Identifiable Information." An MBI can still be used to submit fraudulent claims — which is precisely the FTC's definition above.
The practical consequence is a genuine tradeoff rather than a rule, and it turns on where the card lives:
- On a wallet card that stays on your person: including the number is defensible. Prehospital treatment doesn't depend on it — paramedics work from your conditions, medications, and allergies — but it does speed up hospital registration, which is why plenty of medical-ID guidance (including our own medical ID card checklist) lists it. If you accept the tradeoff, keep it on the wallet copy only.
- On a fridge card, a card in a bag you leave places, or anything sitting in plain view: leave it off. Same number, much higher exposure, and no responder standing in your kitchen needs it.
If you'd rather not think about it: leaving the number off costs you a few minutes at the registration desk, and nothing clinically.
Worth noting where the advice legitimately differs by purpose: federal preparedness guidance for older adults recommends you "make copies of Medicaid, Medicare, and other insurance cards," listed alongside its emergency-supply-kit and evacuation guidance. A copy stored for an evacuation is a different threat model from a number riding in your back pocket or magneted to a fridge. Same document, different exposure.
The exposure that gets left out: the website you make the card on
Your wallet isn't the only place your medical summary exists, and the other copy is the one worth asking about.
To make a medical ID card you have to type your conditions, medications, and allergies into something — a PDF filler, a template service, or a medical-alert company's card builder. If a tool requires you to create an account, assume what you typed is stored on its servers — that's usually what the account is for. And if a page doesn't say where the card gets built, assume the copy exists. Your wallet holds one copy of your medical summary; a breached vendor holds yours alongside everyone else's.
People assume HIPAA protects them there. It generally does not. Per FTC business guidance, the HIPAA Rules apply to you if you are a HIPAA covered entity — "a health plan, a health care provider that conducts standard health care transactions electronically, or a health care clearinghouse" — plus business associates working on their behalf. A free card-generator website is none of those things. HIPAA simply doesn't reach it. (That's also separate from what a HIPAA release form actually does.)
The same FTC page tells companies not to make "false or misleading claims that you are ‘HIPAA Compliant,’ ‘HIPAA Secure,’ ‘HIPAA Certified’ or the like." If a consumer medical-card tool is wearing a HIPAA badge, that badge is doing marketing work, not legal work. What actually applies to such a service is the FTC Act and the FTC's Health Breach Notification Rule, which covers "vendors of personal health records (PHR), PHR related entities, and third party service providers" that aren't covered by HIPAA, and requires them to notify affected consumers, the FTC, and in some cases the media after a breach.
So the honest question to ask any medical-card tool isn't "are you HIPAA compliant." It's: does what I type ever reach your server at all?
For Emergency Info Card, the answer is no. The card is generated entirely in your browser — you type your details, the printable PDF is built on your own device, and nothing you enter is uploaded to us. There's no account, so there's no stored record of your medications to breach. We don't claim HIPAA compliance, because HIPAA doesn't apply to a tool like this — and by the covered-entity definition above, it wouldn't apply to a competing card-generator site either, whether or not that site advertises it.
How to carry it, once it's made
- Front of the wallet, behind your primary photo ID. That's where someone looking for identification will land first — see what paramedics actually look for.
- Add a fridge copy for emergencies that happen at home — and leave the insurance number off that one. See what to put on a fridge card.
- Keep your phone's Medical ID filled in too. It can be locked or out of battery; the card can't. Here's why many people keep both.
- Reprint whenever a medication or dose changes. A card listing a drug you no longer take can actively mislead a responder — a clinical risk that the theft of a clinical-only card simply doesn't carry.
Frequently asked questions
Frequently asked questions
Make a card that never leaves your device
The free card generator builds a filled wallet card and a matching fridge card from one set of details, as a print-ready PDF. It takes about three minutes, needs no account, and runs entirely in your browser — nothing you type is uploaded to a server. Fill in the clinical fields, leave the account numbers off, and reprint it whenever a medication changes.
Sources
We cite primary, authoritative sources. Read our editorial standards for how we research and verify information.
Federal Trade Commission
What To Know About Medical Identity TheftCenters for Medicare & Medicaid Services
Medicare Beneficiary Identifiers (MBIs)Ready.gov (FEMA)
Older Adults — Emergency Preparedness