Anti-fraud identification method and device for insurance claim settlement, equipment and storage medium
By constructing an abnormal relationship graph of patients, hospital departments, and diseases, insurance fraud can be automatically identified, solving the problems of low efficiency and insufficient accuracy of manual identification in existing technologies, and achieving efficient identification of gang fraud.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- PING AN HEALTH INSURANCE CO LTD
- Filing Date
- 2026-02-04
- Publication Date
- 2026-05-29
AI Technical Summary
Existing insurance fraud identification methods rely on manual review and risk feature mining, resulting in high manpower costs and insufficient accuracy, making it unable to effectively identify complex group fraud activities.
An abnormal relationship graph is constructed between patients, hospital departments, and diseases. Candidate groups are segmented and risk classifications are performed based on the graph to achieve automated anti-fraud identification.
It improves the accuracy of fraud detection, reduces labor costs, and can identify complex doctor-patient collusion and gang fraud.
Smart Images

Figure CN122115122A_ABST
Abstract
Description
Technical Field
[0001] This application relates to the field of artificial intelligence technology, and is applied to the field of financial technology, particularly to an anti-fraud identification method, device, equipment, and storage medium for insurance claims. Background Technology
[0002] Insurance fraud methods are becoming increasingly professional and specialized, posing a significant challenge to insurance fraud detection. Currently, insurance fraud detection mainly relies on professional auditors directly identifying and intercepting risks from individual cases according to expert identification rules, or on mining risk characteristics from individual cases and training models based on these characteristics. However, both manual auditing and manual risk characteristic mining methods are labor-intensive, and manual risk characteristic mining is subjective, leading to significant vulnerabilities in fraud detection. Therefore, how to save manpower and improve the accuracy of fraud detection has become an urgent technical problem to be solved. Summary of the Invention
[0003] The main objective of this application is to provide a method, apparatus, device, and storage medium for anti-fraud identification in insurance claims, which aims to save manpower and improve the accuracy of anti-fraud identification.
[0004] To achieve the above objectives, a first aspect of this application proposes an anti-fraud method for insurance claims, the method comprising:
[0005] Obtain historical abnormal medical visit behavior data and behavior-related data of the target object; wherein, the target object includes: the hospital department visited, the patient, and the disease treated by the patient; Based on the historical abnormal medical visit behavior data and the behavior association data, a relationship graph is constructed for the target object to obtain an abnormal relationship graph; wherein, the abnormal relationship graph includes element nodes and node attribute features of the element nodes, the target object is used as an element node, the node attribute features are determined by the historical abnormal medical visit behavior data, and the behavior association data determines the edge weights between the element nodes; The target objects are grouped according to the abnormal relationship graph to obtain candidate groups; wherein, the candidate groups include a first risk group with a first risk category; Based on the node attribute characteristics, the target objects of the first risk group are classified into risk categories to obtain object risk categories; Anti-fraud identification of the target object is performed based on the object's risk category and the first risk group.
[0006] In some embodiments, the step of constructing a relationship graph of the target object based on the historical abnormal medical visit behavior data and the behavior association data to obtain an abnormal relationship graph includes: Feature extraction is performed on the historical abnormal medical visit data to obtain historical abnormal medical visit features; wherein, the target object is used as an element node, and the historical abnormal medical visit features are used as node attribute features; Feature extraction is performed on the behavioral association data to obtain behavioral association features; The behavioral association features are converted into edge weights between the feature nodes; The element nodes are connected according to the edge weights and node attribute features to obtain the anomaly relationship graph.
[0007] In some embodiments, the step of dividing the target objects into candidate groups based on the abnormal relationship graph includes: Obtain the node category of each element node in the abnormal relationship graph; The abnormal relationship graph is split according to the node category to obtain at least one abnormal relationship subgraph; wherein the nodes in the abnormal relationship subgraphs are of the same category; The target objects are grouped according to at least one of the abnormal relationship subgraphs to obtain candidate groups.
[0008] In some embodiments, the step of dividing the target objects into groups based on at least one of the abnormal relationship subgraphs to obtain candidate groups includes: The target objects are grouped according to the edge weights of each of the abnormal relationship subgraphs to obtain the original groups; Extract the node attribute features of each original group from at least one of the abnormal relationship subgraphs to obtain group attribute features; The original group is classified into risk categories based on the group attribute characteristics. The original group is divided into groups based on the group risk category to obtain the candidate group.
[0009] In some embodiments, classifying the target objects of the first risk group based on the node attribute characteristics to obtain object risk categories includes: Based on the node attribute characteristics, a risk assessment is performed on the target object of the first risk group to obtain object risk assessment data; The risk category of the target object is obtained by classifying the risk of the target object based on the object risk assessment data.
[0010] In some embodiments, obtaining historical abnormal medical visit behavior data and behavior-related data of the target object includes: Obtain historical medical visit data of candidate patients; The candidate objects are evaluated based on the historical medical visit data to obtain the object evaluation status; wherein, the object evaluation status includes abnormal status. The candidate objects are filtered based on the abnormal state to obtain the target object; The historical medical visit data is filtered based on the target object to obtain the historical abnormal medical visit data.
[0011] In some embodiments, after performing anti-fraud identification on the target object based on the object risk category and the first risk group, the method further includes: Receive a claim request; wherein the claim request includes the claimant and reference medical treatment behavior data of the claimant; Risk assessment data is obtained by performing a risk assessment on the claim subject based on the reference medical visit behavior data and the abnormal relationship graph. Claims will be processed based on the risk assessment data.
[0012] To achieve the above objectives, a second aspect of this application provides an anti-fraud device for insurance claims, the device comprising: The data acquisition module is used to acquire historical abnormal medical visit behavior data and behavior-related data of the target object; wherein, the target object includes: the hospital department where the patient visited, the patient, and the disease treated by the patient; The graph construction module is used to construct a relationship graph of the target object based on the historical abnormal medical visit behavior data and the behavior association data, thereby obtaining an abnormal relationship graph. The abnormal relationship graph includes element nodes and node attribute features of the element nodes. The target object is used as an element node. The node attribute features are determined by the historical abnormal medical visit behavior data, and the behavior association data determines the edge weights between the element nodes. The group segmentation module is used to segment the target objects into groups based on the abnormal relationship graph to obtain candidate groups; wherein, the candidate groups include a first risk group with a first risk category; The risk classification module is used to classify the target objects of the first risk group according to the node attribute characteristics to obtain the object risk category; The anti-fraud identification module is used to perform anti-fraud identification on the target object based on the object risk category and the first risk group.
[0013] To achieve the above objectives, a third aspect of the present application provides a computer device, the computer device including a memory and a processor, the memory storing a computer program, and the processor executing the computer program to implement the method described in the first aspect.
[0014] To achieve the above objectives, a fourth aspect of the present application provides a computer-readable storage medium storing a computer program that, when executed by a processor, implements the method described in the first aspect.
[0015] The anti-fraud identification method, device, equipment, and storage medium proposed in this application for insurance claims first constructs an anomaly relationship graph of three types of nodes: the patient, the hospital department, and the disease being treated. Based on this graph, target objects are first divided into candidate groups, including a first-risk group within a first-risk category. Then, risk classification is performed on target objects within the first-risk group to determine their risk category. Finally, anti-fraud identification is performed on the target objects by combining the first-risk group and the target risk category. Therefore, by transforming individual anti-fraud identification into identification of group collusion, complex fraudulent behaviors such as doctor-patient collusion, fraudulent medical treatment, and excessive medical treatment can be identified, improving the accuracy of anti-fraud identification. Furthermore, the entire anti-fraud identification process is automated, requiring no human intervention, thus saving labor costs in the anti-fraud identification process. Attached Figure Description
[0016] Figure 1 This is a flowchart of the anti-fraud identification method for insurance claims provided in the embodiments of this application; Figure 2 This is a specific example diagram illustrating the collection of historical abnormal medical visit behavior data and behavior-related data of the target object in the embodiments of this application; Figure 3 yes Figure 1 The flowchart of step S101 in the text; Figure 4 yes Figure 1 The flowchart of step S102 in the document; Figure 5 These are specific example diagrams of the abnormal relationship graph and abnormal relationship subgraph in the embodiments of this application; Figure 6 yes Figure 1 The flowchart of step S103 in the process; Figure 7 yes Figure 6 The flowchart of step S603 in the process; Figure 8 yes Figure 1 The flowchart of step S104 in the process; Figure 9This is a specific example diagram of the anti-fraud identification method for insurance claims in this application embodiment; Figure 10 This is a flowchart of an anti-fraud identification method for insurance claims provided in another embodiment of this application; Figure 11 This is an overall flowchart of the anti-fraud identification method for insurance claims provided in the embodiments of this application; Figure 12 This is a schematic diagram of the anti-fraud identification device for insurance claims provided in the embodiments of this application; Figure 13 This is a schematic diagram of the hardware structure of the computer device provided in the embodiments of this application. Detailed Implementation
[0017] To make the objectives, technical solutions, and advantages of this application clearer, the following detailed description is provided in conjunction with the accompanying drawings and embodiments. It should be understood that the specific embodiments described herein are merely illustrative and not intended to limit the scope of this application.
[0018] It should be noted that although functional modules are divided in the device schematic diagram and a logical order is shown in the flowchart, in some cases, the steps shown or described may be performed in a different order than the module division in the device or the order in the flowchart. The terms "first," "second," etc., in the specification, claims, and the aforementioned drawings are used to distinguish similar objects and are not necessarily used to describe a specific order or sequence.
[0019] Unless otherwise defined, all technical and scientific terms used herein have the same meaning as commonly understood by one of ordinary skill in the art to which this application belongs. The terminology used herein is for the purpose of describing embodiments of this application only and is not intended to limit this application.
[0020] First, let's analyze some of the terms used in this application: Artificial intelligence (AI) is a new branch of computer science that studies, develops, and applies theories, methods, technologies, and systems to simulate, extend, and expand human intelligence. It aims to understand the essence of intelligence and produce intelligent machines that can react in a way similar to human intelligence. Research in this field includes robotics, speech recognition, image recognition, natural language processing, and expert systems. AI can simulate the information processes of human consciousness and thought. Furthermore, AI utilizes digital computers or machines controlled by digital computers to simulate, extend, and expand human intelligence, perceiving the environment, acquiring knowledge, and using that knowledge to achieve optimal results.
[0021] Fraud prevention and identification is a comprehensive system engineering project that integrates big data, artificial intelligence, rule engines, and other technologies to provide early warnings, identify, and intercept fraudulent activities at multiple stages, including before, during, and after the event. Its core objective is to accurately distinguish between normal and abnormal behavior amidst complex and ever-changing fraudulent methods, thereby protecting asset and information security.
[0022] Relational Graph Convolutional Network (RGCN) is a model that extends the traditional Graph Convolutional Network (GCN) and is specifically designed to handle graph data with multiple relation types. By introducing relation-specific weight matrices, it can better capture complex relationships between entities and is widely used in knowledge graph reasoning, social network analysis, and drug discovery.
[0023] A relationship graph, also known as a relationship network, is a graphical data structure used to describe the relationships between entities. A relationship graph consists of nodes (representing entities) and edges (representing relationships between entities), visually illustrating the connections and interactions between data. Relationship graphs can be used not only for data visualization but also for tasks such as data mining and relationship reasoning.
[0024] Heterogeneous graphs are graphs with more than one type of node or edge relationship, which can better represent the complex multi-type entities and their interactions in the real world. For example, in a paper citation network, nodes can be divided into two types: "author" and "paper," while edges can represent "author-author" collaboration relationships, "author-paper" subordination relationships, and "paper-paper" citation relationships.
[0025] Leiden Community Detection Algorithm: This is an advanced community detection algorithm designed to divide nodes in a network into closely connected groups. It is an improvement on the classic Louvain algorithm, solving the problem that the Louvain algorithm may generate disconnected communities, while significantly improving computational efficiency and the quality of community partitioning.
[0026] With the rapid development of the health insurance market and the continuous expansion of insurance coverage, more comprehensive medical protection has been provided. However, this has also led to a surge in insurance fraud, with increasingly professional and sophisticated methods, ranging from individual claims fraud to complex organized crimes, posing significant challenges to insurance companies and regulatory authorities. In response, insurance companies have implemented anti-fraud identification systems to filter out policies with potential fraud risks during the claims process. Currently, anti-fraud identification is primarily done manually, requiring manual review of policies during claims processing. This reliance on expert rules to directly quantify and identify the risk of the target claims is not only labor-intensive but also lacks the ability to accurately identify fraud based on individual characteristics or relationships between stakeholders or historical data. Therefore, a technological solution that can achieve fully automated anti-fraud identification and improve accuracy is urgently needed.
[0027] Based on this, embodiments of this application provide a method, apparatus, device, and storage medium for anti-fraud identification in insurance claims. The aim is to construct an abnormal relationship graph using historical abnormal medical behavior data and behavioral correlation data of the hospital department, the patient, and the patient's medical conditions. This abnormal relationship graph clearly reveals the relationships and abnormal characteristics between each target object. Therefore, by first dividing the target objects into candidate groups based on the abnormal relationship graph, and then further classifying each target object within the first risk group of the first risk category to obtain an object risk category, anti-fraud identification is performed on the target objects based on the object risk category and the first risk group. This achieves automated anti-fraud identification, accurately completes anti-fraud identification, and improves the accuracy of anti-fraud identification.
[0028] The anti-fraud identification method, apparatus, equipment, and storage medium for insurance claims provided in this application are specifically described through the following embodiments. First, the anti-fraud identification method for insurance claims in this application embodiment is described.
[0029] The embodiments of this application can acquire and process relevant data based on artificial intelligence technology. Artificial intelligence (AI) refers to the theories, methods, technologies, and application systems that use digital computers or machines controlled by digital computers to simulate, extend, and expand human intelligence, perceive the environment, acquire knowledge, and use that knowledge to obtain optimal results.
[0030] Foundational technologies for artificial intelligence generally include sensors, dedicated AI chips, cloud computing, distributed storage, big data processing, operating / interactive systems, and mechatronics. AI software technologies mainly encompass computer vision, robotics, biometrics, speech processing, natural language processing, and machine learning / deep learning.
[0031] The anti-fraud identification method for insurance claims provided in this application relates to the field of artificial intelligence technology and is applied to fintech scenarios. This anti-fraud identification method for insurance claims can be applied to a terminal, a server, or software running on either a terminal or a server. In some embodiments, the terminal can be a smartphone, tablet, laptop, desktop computer, etc.; the server can be configured as an independent physical server, a server cluster or distributed system composed of multiple physical servers, or a cloud server providing basic cloud computing services such as cloud services, cloud databases, cloud computing, cloud functions, cloud storage, network services, cloud communication, middleware services, domain name services, security services, CDN, and big data and artificial intelligence platforms; the software can be an application implementing the anti-fraud identification method for insurance claims, but is not limited to the above forms.
[0032] This application can be used in a wide variety of general-purpose or special-purpose computer system environments or configurations. Examples include: personal computers, server computers, handheld or portable devices, tablet devices, multiprocessor systems, microprocessor-based systems, set-top boxes, programmable consumer computer devices, network PCs, minicomputers, mainframe computers, and distributed computing environments including any of the above systems or devices. This application can be described in the general context of computer-executable instructions executed by a computer, such as program modules. Generally, program modules include routines, programs, objects, components, data structures, etc., that perform specific tasks or implement specific abstract data types. This application can also be practiced in distributed computing environments where tasks are performed by remote processing devices connected via a communication network. In distributed computing environments, program modules can reside in local and remote computer storage media, including storage devices.
[0033] It should be noted that in all specific embodiments of this application, when processing data related to user identity or characteristics, such as user information, user behavior data, user historical data, and user location information, user permission or consent is obtained first. Furthermore, the collection, use, and processing of this data comply with relevant laws, regulations, and standards. In addition, when embodiments of this application require access to sensitive personal information of users, separate permission or consent from the user is obtained through pop-ups or redirection to confirmation pages. Only after obtaining the user's separate permission or consent is the necessary user-related data required for the proper functioning of these embodiments acquired.
[0034] Figure 1 This is an optional flowchart of the anti-fraud identification method for insurance claims provided in the embodiments of this application. Figure 1 The method may include, but is not limited to, steps S101 to S105.
[0035] Step S101: Obtain historical abnormal medical visit behavior data and behavior-related data of the target object; wherein, the target object includes: the hospital department visited, the patient, and the patient's disease. Step S102: Construct a relationship graph for the target object based on historical abnormal medical visit behavior data and behavior association data to obtain an abnormal relationship graph; wherein, the abnormal relationship graph includes element nodes and node attribute features of element nodes, the target object is used as an element node, the node attribute features are determined by historical abnormal medical visit behavior data, and the edge weights between element nodes are determined by behavior association data. Step S103: Divide the target objects into groups according to the abnormal relationship graph to obtain candidate groups; wherein, the candidate groups include the first risk group with the first risk category; Step S104: Classify the target objects of the first risk group according to the node attribute characteristics to obtain the object risk category; Step S105: Anti-fraud identification of target objects based on object risk category and first risk group.
[0036] Steps S101 to S106 of this embodiment involve collecting abnormal medical visit behavior data and behavior-related data, including data on hospital departments, patients, and diseases visited, and constructing an abnormal relationship graph based on these data. This abnormal relationship graph integrates the edge weights between element nodes of different categories and node attribute features. Therefore, when grouping target objects, classifying them into at least one candidate group according to the abnormal relationship graph is more accurate. Furthermore, risk classification is performed on target objects within the first risk group of the first risk category to determine their risk category. Finally, combining the object risk category and the first risk group, anti-fraud identification is performed on the target objects, achieving more accurate anti-fraud identification. The entire identification process is automated, saving manpower in anti-fraud identification.
[0037] In step S101 of some embodiments, the target objects include the hospital departments, patients, and diseases that exhibited abnormal medical treatment states during historical medical visits. Therefore, the historical medical treatment behavior data of the target objects is historical abnormal medical treatment behavior data. Behavioral association data characterizes the number of interactions and interaction resource values between target objects, and the degree of association between target objects can be determined through behavioral association data.
[0038] like Figure 2 As shown, the anti-fraud identification method for insurance claims is applied to a server. The server collects historical abnormal medical visit behavior data and behavioral correlation data from multiple terminals. These terminals can be terminals belonging to hospital departments, terminals used by patients, or terminals storing medical records. This allows for the collection of historical abnormal behavior data and behavioral correlation data related to hospital departments, patients, and medical conditions through multiple channels. Specifically, this includes historical abnormal medical visit behavior data for patients, historical abnormal medical visit behavior data for hospital departments, historical abnormal behavior data for medical conditions, behavioral correlation data between patients, behavioral correlation data between patients and hospital departments, behavioral correlation data between patients and medical conditions, and behavioral correlation data between hospital departments and medical conditions. Therefore, by collecting various types of data and constructing an abnormal behavior map, not only can fraud identification of patients be completed, but also the fraud probability between patients and hospital departments / medical conditions can be identified, thus accurately completing anti-fraud identification.
[0039] Please see Figure 3 In some embodiments, step S101 may include, but is not limited to, steps S301 to S304: Step S301: Obtain historical medical visit data of the candidate; Step S302: Evaluate the status of candidate objects based on historical medical visit behavior data to obtain object evaluation status; wherein, object evaluation status includes abnormal status. Step S303: Filter candidate objects based on abnormal status to obtain target objects; Step S304: Filter the historical medical visit data according to the target object to obtain historical abnormal medical visit data.
[0040] In step S301 of some embodiments, the candidate objects include the patient, the hospital department, and the disease being treated, and the patient is also the policyholder who filed an insurance claim. Further, historical medical behavior data of the candidate objects is collected, and historical medical behavior features are extracted from the historical medical behavior data, and these historical medical behavior features are used to assess whether the candidate objects belong to abnormal objects.
[0041] In step S302 of some embodiments, this application embodiment mainly targets fraud prevention identification of doctor-patient collusion, and the historical medical behavior characteristics of doctor-patient collusion mainly include abnormal medical behavior characteristics such as frequent visits, over-prescription of medication, and unreasonable expenses. Therefore, this application embodiment filters abnormal medical behavior characteristics from historical medical behavior data, and determines the evaluation status of the object based on the abnormal medical behavior characteristics to assess the status of the candidate object.
[0042] It should be noted that the embodiments of this application set anomaly assessment rules, which are constructed based on expert experience. Abnormal medical visit behavior characteristics are screened from historical medical visit behavior characteristics according to the anomaly assessment rules. The anomaly assessment rules cannot include conditions such as the number of visits exceeding a preset number, the amount of medical expenses exceeding a preset amount, or the number of prescriptions exceeding a preset quantity. This embodiment does not limit the anomaly assessment rules, and the preset number of visits, preset amount, and preset quantity are determined based on the type of disease treated, thus more accurately screening abnormal medical visit behavior characteristics.
[0043] In step S303 of some embodiments, candidate objects whose evaluation status is abnormal are selected as target objects. Specifically, if an abnormal patient status is determined, the hospital department and the disease treated during the patient's visit are both selected as target objects. Alternatively, if the hospital department is abnormal, the patients and diseases associated with that hospital department are also evaluated, and those patients and diseases evaluated as abnormal are selected as target objects. Therefore, to reduce computational resource consumption and improve the efficiency and effectiveness of anti-fraud identification, before constructing the abnormal relationship graph, candidate objects with abnormal patient behavior characteristics are selected as target objects, and relevant data such as hospital departments and diseases associated with patients with a high number of visits and large amounts of medical expenses are selected as intermediate monitoring objects.
[0044] For example, if the preset number of visits is 3, the preset amount is 30,000, and the preset quantity is 10, the status of objects that are evaluated as abnormal if the same patient visits the same hospital department or the same disease more than 3 times, or the amount of medical treatment exceeds 30,000, or the number of prescriptions exceeds 10, and the patient, the hospital department where the patient is located, and the disease treated are all selected as target objects, then the target objects belong to the key monitoring objects.
[0045] In step S304 of some embodiments, the historical medical visit data corresponding to the target object is used as historical abnormal medical visit data. By using the historical abnormal medical visit data as the basis for constructing the abnormal relationship graph, the computational resources for constructing the abnormal relationship graph can be saved.
[0046] In steps S301 to S304 of this embodiment, before constructing the abnormal relationship graph, the state of each candidate object is evaluated based on the candidate object's historical medical visit behavior data. Candidate objects with abnormal states are then designated as target objects, and the historical medical visit behavior data of the target objects is used as historical abnormal medical visit behavior data. Therefore, by collecting only the historical abnormal medical visit behavior data and action association data of the target objects, the manpower required for constructing the abnormal relationship graph can be reduced, resource consumption can be decreased, and recognition efficiency and effectiveness can be improved.
[0047] In step S102 of some embodiments, the abnormal relationship graph includes element nodes and node attribute features of the element nodes. The element nodes correspond to the target objects, the node attribute features correspond to historical abnormal medical visit behavior data, and the action association data serves as the edge weights between element nodes. The degree of association between element nodes can be determined through the edge weights.
[0048] Please see Figure 4 In some embodiments, step S102 may include, but is not limited to, steps S401 to S404: Step S401: Extract features from historical abnormal medical visit data to obtain historical abnormal medical visit features; wherein, the target object is used as an element node, and the historical abnormal medical visit features are used as node attribute features. Step S402: Extract features from the behavior-related data to obtain behavior-related features; Step S403: Convert the behavioral association features into edge weights between feature nodes; Step S404: Connect the feature nodes according to edge weights and node attribute features to obtain an anomaly relationship graph.
[0049] In step S401 of some embodiments, the hospital department, the patient, and the disease are taken as element nodes, specifically the three types of element nodes in the abnormal relationship graph. Then, the historical abnormal medical visit features of the historical abnormal medical visit behavior data are extracted as the node attribute features of the element nodes. Specifically, if the element node is a hospital department, the node attribute features are those of the hospital department, including: hospital type, hospital level, administrative region where the hospital is located, whether it is a designated hospital of the insurance company, the number of historical claims, the number of investigated cases, the number of denied claims, the number of doctors in the department, and the number of specialists. If the element node is a disease, the node attribute features are those of the disease, including: whether it belongs to the insurance company's chronic disease category or critical illness category, the insurance company's historical claim rate, and historical denied claim rate. If the element node is a patient, the node attribute features are those of the patient, including: the patient's gender, age, region, type of insurance product purchased, historical cumulative number of visits, cumulative total amount of medical expenses, cumulative amount of denied claims, cumulative number of investigations, number of diseases treated in the past, whether the treated diseases include chronic diseases, and whether the treated diseases include critical illnesses. Therefore, by determining the characteristics of each element node according to its node attribute features, anti-fraud identification can be completed more accurately.
[0050] In steps S402 and S403 of some embodiments, behavioral association features characterize the number of associations and the degree of association between target objects. The degree of association is determined by the identity relationship between the target objects. Specifically, behavioral association features include: the first social identity relationship between patients, the number of visits between patients and the hospital department and the second social identity relationship, and the number of visits by patients for the same disease. Therefore, the edge weight between two element nodes is determined based on the first social identity relationship, the number of visits, the second social identity relationship, and the number of visits. For example, if two patients are friends or relatives, the edge weight will increase; if the same patient visits the same disease multiple times, the edge weight will also increase; and if a patient visits the same hospital department many times and has a second social identity relationship, the edge weight will also increase. Therefore, the association between any two element nodes can be determined through edge weights.
[0051] In step S404 of some embodiments, the feature nodes are connected according to the edge weight to form an abnormal relationship graph, and the abnormal relationship graph is a relationship graph of the objects that need to be monitored. The node attribute features of each feature node will be set with corresponding attribute labels.
[0052] In steps S401 to S404 of this embodiment, the target object is used as an element node to determine three types of element nodes: patient, disease, and hospital department. Historical abnormal patient behavior characteristics are used as node attribute characteristics of the element nodes, and action association characteristics are used as edge weights between element nodes to construct an abnormal relationship graph of the three types of nodes: hospital department, patient, and disease. Through the abnormal relationship graph, fraudulent behavior can be accurately identified, and accurate anti-fraud identification can be achieved.
[0053] Please refer to Figure 5 , Figure 5 A schematic diagram of anomaly relationship mapping is shown, through... Figure 5 It can be seen that the abnormal relationship graph is a heterogeneous graph, representing the relationships between hospital departments, patients, and diseases. Through... Figure 5 This paper illustrates the relationships between patients, between patients and their treated diseases, between patients and hospital departments, and between patients and their treated diseases. This allows for the identification of doctor-patient collusion for insurance fraud and the identification of fraud rings. Traditional anti-fraud identification focuses on identifying the relationship between patients and their treated diseases, neglecting the relationships between patients and hospital departments, and between hospital departments and their treated diseases. This makes it difficult to identify doctor-patient collusion, leading to decreased accuracy in claims processing. Therefore, this application constructs a heterogeneous graph with hospital departments, patients, and treated diseases as element nodes. It fundamentally represents the characteristics and diagnostic relationships among these three entities, supporting in-depth correlation analysis and anti-fraud identification, thus improving the accuracy of anti-fraud identification.
[0054] In step S103 of some embodiments, after the abnormal relationship graph is constructed, the focus is on using the abnormal relationship graph to first complete the group division of the target objects, which is used as a key identification point for fraud gangs, thereby improving the accuracy of anti-fraud identification. It should be noted that the embodiments of this application use the Leiden algorithm and the abnormal relationship graph to complete the group division of the target objects. The Leiden algorithm, as an improved version of the Louvain algorithm, is based on modularity for group community discovery. However, it gradually refines the community structure through multi-layer optimization and local movement strategies. This not only solves the problem of non-connected communities in the Leiden algorithm, but is also more suitable for processing large-scale relationship graphs, with faster processing speed and more accurate group division.
[0055] Please see Figure 6 In some embodiments, step S103 may include, but is not limited to, steps S601 to S603: Step S601: Obtain the node category of each element node in the abnormal relationship graph; Step S602: The abnormal relationship graph is split according to the node category to obtain at least one abnormal relationship subgraph; wherein the nodes in the abnormal relationship subgraphs are of the same category. Step S603: Divide the target objects into groups based on at least one abnormal relationship subgraph to obtain candidate groups.
[0056] In steps S601 and S602 of some embodiments, as disclosed above, the embodiments of this application use the Leiden algorithm to complete the group partitioning. The Leiden algorithm can handle heterogeneous graphs. Specifically, it first converts the heterogeneous graph into at least one isomorphic graph, and then completes the group partitioning of the target objects through at least one isomorphic graph. Therefore, it is necessary to collect the node category of each element node, and split the abnormal relationship graph into at least one abnormal relationship subgraph according to the node category, and the node categories of each abnormal relationship subgraph are the same. For example, the same abnormal relationship subgraph only represents the relationship between patients, or the relationship between diseases, or the relationship between hospital departments.
[0057] like Figure 5 As shown, the anomaly relationship graph is split into anomaly relationship subgraphs, as follows: Figure 5 As shown, through Figure 5 It can determine the relationships between target objects in each anomaly relationship graph, making group segmentation easier.
[0058] In step S603 of some embodiments, the target objects are grouped according to at least one abnormal relationship subgraph. This grouping is not only based on the relationship between the patient and the disease, and the hospital department, but also on the relationships between patients, the diseases, and the hospital departments, thus improving the accuracy of group segmentation. It should be noted that the candidate groups include a first-risk group of a first-risk category, a second-risk group of a second-risk category, and a third-risk group of a third-risk category. The first-risk category is defined as high-risk, the second-risk category as medium-risk, and the third-risk category as low-risk, achieving group segmentation across multiple risk categories.
[0059] In steps S601 to S603 of this embodiment, the abnormal relationship graph is split into at least one abnormal relationship subgraph according to the node category, and then the target object is divided into candidate groups according to at least one abnormal relationship subgraph, so that the candidate group division is more accurate.
[0060] Please see Figure 7 In some embodiments, step S603 may include, but is not limited to, steps S701 to S704: Step S701: The target objects are grouped according to the edge weights of each abnormal relationship subgraph to obtain the original group; Step S702: Extract the node attribute features of each original group from at least one abnormal relationship subgraph to obtain the group attribute features; Step S703: Classify the original group according to its risk characteristics to obtain the group risk category; Step S704: Divide the original population into groups according to the group risk category to obtain candidate groups.
[0061] In step S701 of some embodiments, such as Figure 5 As shown, a larger edge weight indicates a closer relationship between target objects. Therefore, node groups are determined by dividing feature nodes of the same node category based on edge weights, and the original group is determined based on the node groups. For example, as... Figure 5 As shown, by using edge weights, it can be determined that patients P1 and P3 belong to the same original group, and further determined that patients with diseases B2, B4, and B6 belong to the same original group. This makes the risk group classification of the target group more accurate.
[0062] In step S702 of some embodiments, the node attribute features of each element node within the same original group are taken as group attribute features. Specifically, the node attribute features within the original group are aggregated into a whole to determine the group attribute features, and the group attribute features are used as reference features for risk classification of the original group.
[0063] In step S703 of some embodiments, the original risk is classified according to the group attribute characteristics. Specifically, the original risk is assessed according to the group attribute characteristics to obtain group risk assessment data. Then, the original group is classified according to the group risk assessment data and a preset risk threshold to obtain a group risk category. As disclosed above, the group risk categories include a first risk category, a second risk category, and a third risk category.
[0064] It should be noted that the embodiments of this application employ the RGGCN algorithm for risk category identification of the original population. The RGCN algorithm is an improved version of GCN; both are graph convolutional network algorithms. By aggregating the node attribute features of the current feature node and its neighboring feature nodes, they fully utilize the node attribute features and edge weights to represent feature nodes. This approach is widely used in tasks such as node classification and link prediction, and performs excellently. Therefore, the RGGCN algorithm accurately classifies the risk of the original population.
[0065] In step S704 of some embodiments, the original group is divided according to the group risk category into a first risk group, a second risk group, and a third risk group. The second risk group is a medium-risk group, and the third risk group is a low-risk group. The second risk group requires further confirmation before claims can be processed, while the third risk group can proceed with the claims process normally. The first risk group is a high-risk group and requires further assessment.
[0066] In steps S701 to S704 of this embodiment, the target objects are first divided into original groups according to the edge weights, and then the risk category of each original group is evaluated. Based on the group risk category, the original groups are divided into a first risk group, a second risk group, and a third risk group, which can accurately identify fraud groups.
[0067] In step S104 of some embodiments, after selecting the first risk group, it is also necessary to assess the risk category of the target objects within the first risk group to achieve more accurate anti-fraud identification. It should be noted that target objects belonging to the same first risk group are not necessarily high-risk; low-risk target objects still need to be filtered out. Then, the risk category of the first risk group and the target objects is combined to complete the anti-fraud identification and improve the accuracy of anti-fraud identification.
[0068] It should be noted that the embodiments of this application use the RGCN algorithm and node attribute features to classify the target objects of the first risk group for risk, thereby improving the accuracy of risk classification.
[0069] Please see Figure 8 In some embodiments, step S104 includes, but is not limited to, steps S801 to S802: Step S801: Conduct a risk assessment on the target objects of the first risk group based on the node attribute characteristics to obtain object risk assessment data; Step S802: Based on the object risk assessment data, classify the target object for risk to obtain the object risk category.
[0070] In step S801 of some embodiments, risk assessment is completed through a risk assessment model, and the risk assessment model is a trained RGCN model. When training the RGCN model, firstly, node attribute features at the element node level are learned based on RGCN, and then the node attribute features in the candidate group are classified and trained through pooling operations to obtain the risk assessment model. Finally, node risk assessment data is obtained by applying the risk assessment model to the element node risk assessment of the first risk group, and the node risk assessment data is the object risk assessment data of the target object.
[0071] In step S802 of some embodiments, if the object risk assessment data is greater than a preset risk threshold, the object risk category is determined to be a first risk category; if the object risk assessment data is not greater than the preset risk threshold, the object risk category is determined to be a third risk category. Target objects belonging to the third risk category in the first risk group need to be excluded to form a new risk group, and this new risk group is used as key reference data for anti-fraud identification.
[0072] In steps S801 to S803 of this embodiment, after completing the group risk classification, it is also necessary to classify the target objects of the first risk group to obtain the object risk category. By using the object risk category, the drawback of relying solely on graph topology relationships for team identification, which still requires further manual review of the team or individual, can be avoided, thereby improving the accuracy of fraud gang identification and saving manpower.
[0073] In step S105 of some embodiments, as disclosed above, the updated risk group is used as reference data for anti-fraud identification. In the process of claim settlement, the fraud risk of the policyholder is judged according to the updated risk group, which can complete the claim settlement more accurately and save manpower costs without manual review.
[0074] Please refer to Figure 9 , Figure 9 This diagram illustrates how anti-fraud identification is performed according to an embodiment of this application. Figure 9 This application demonstrates a method for fraud risk identification, automatically displaying each high-risk policyholder / patient on the interface. Figure 9 The system displays "Zhang San," "Li Si," and "Wang Wu" as policyholders with fraud risk, which can be used as a reference for fraud risk assessment before claims processing. The identification results interface only displays basic information about policyholders with high fraud risk, such as contact information, hospital and department visited, and the illness treated. If further verification of a policyholder's fraud risk is needed, the policyholder can be selected and "View Details" can be clicked to comprehensively review the policyholder's medical behavior data, improving the efficiency and accuracy of claims review.
[0075] Please see Figure 10 In some embodiments, after step S105, the anti-fraud identification method for insurance claims may also include, but is not limited to, steps S1001 to S1003: Step S1001: Receive a claim request; wherein, the claim request includes the claimant and the claimant's reference medical treatment behavior data; Step S1002: Conduct a risk assessment on the claim subject based on the reference medical treatment behavior data and abnormal relationship graph to obtain risk assessment data; Step S1003: Process the claims based on the risk assessment data.
[0076] In step S1001 of some embodiments, the claim object belongs to the policyholder who initiated the claim, and the reference medical treatment behavior data is the medical treatment behavior data corresponding to the claim object initiating the claim.
[0077] In step S1002 of some embodiments, the abnormal relationship graph is first updated based on the reference medical treatment behavior data to obtain the updated graph relationship. Then, the updated first risk group and the object risk category of each target object in the first risk group are determined based on the updated graph relationship. Finally, risk assessment data is obtained by performing risk assessment on the claim object according to the first risk group and the object risk category.
[0078] In step S1003 of some embodiments, if the risk assessment data is lower than the preset assessment threshold, the claim is directly processed. If the risk assessment data is not lower than the preset assessment threshold, the risk assessment data and the claim are subject to further manual review. The claim is processed after the manual review is approved, thereby improving the accuracy of the claim.
[0079] In steps S1001 to S1003 of this embodiment, during the claims process, the abnormal relationship graph and the reference medical behavior data are combined to complete the graph update and determine the risk assessment data of each claim object. Finally, the claims are automatically processed according to the risk assessment data, saving manpower in the claims process and enabling accurate claims operations.
[0080] Please refer to Figure 11 , Figure 11 The flowchart of an embodiment of this application is shown. This embodiment first collects historical medical visit behavior data and behavioral association data for each candidate object, extracts abnormal medical visit behavior features from the historical medical visit behavior data, and filters target objects from the candidate objects based on expert experience and abnormal medical visit behavior features. The historical medical visit behavior data of the target objects is then used as historical abnormal medical visit behavior data. Simultaneously, the target objects are treated as element nodes, and node attribute features of corresponding element nodes are mined from the historical abnormal medical visit behavior data based on different node categories. This process then constructs an abnormal relationship graph, combining the historical abnormal medical visit behavior data and behavioral association data of the target objects. Therefore, in constructing the abnormal relationship graph, not only is the size of the abnormal relationship graph significantly reduced and the operational efficiency of the abnormal relationship graph improved, but individual element nodes are also described more effectively, which is helpful for subsequent anti-fraud behavior identification.
[0081] Based on anomaly relationship graphs and combined with the Leiden algorithm and graph convolutional network algorithm, target objects are divided into candidate groups, including the first-risk group of the first risk category, specifically the high-risk group. Therefore, in the process of risk team mining, fully utilizing the node relationships and node attribute features of each element in the anomaly relationship graph to detect fraudulent behavior can effectively avoid the shortcomings of traditional rule-based interception or machine learning model prediction algorithms that can only use individual features to identify individual fraudulent behavior, and significantly reduce the risk leakage caused by group fraud.
[0082] In addition, the RGCN algorithm is used to classify the target objects within the first risk group to determine their risk classification. Therefore, the first risk group and the first risk objects are output as reference data for anti-fraud identification. Thus, this embodiment can identify fraud groups and fraudulent objects within them using a supervised approach. This avoids the drawbacks of relying solely on graph topology for group identification, which requires further manual review and confirmation of fraud groups or individuals. This method makes the identification of fraud groups and individuals more accurate and clear, effectively reducing the labor costs of review.
[0083] Please see Figure 12 This application also provides an anti-fraud identification device for insurance claims, which can implement the above-mentioned anti-fraud identification method for insurance claims. The device includes: The data acquisition module 1201 is used to acquire historical abnormal medical visit behavior data and behavior-related data of the target objects; among which, the target objects include: the hospital department, the patient, and the patient's disease. The graph construction module 1202 is used to construct a relationship graph of the target object based on historical abnormal medical visit behavior data and behavior association data to obtain an abnormal relationship graph. The abnormal relationship graph includes element nodes and node attribute features of the element nodes. The target object is used as an element node, and the node attribute features are determined by historical abnormal medical visit behavior data. The behavior association data determines the edge weights between element nodes. The group segmentation module 1203 is used to segment the target objects into groups based on the abnormal relationship graph to obtain candidate groups; wherein, the candidate groups include the first risk group with the first risk category; Risk classification module 1204 is used to classify the target objects of the first risk group according to the node attribute characteristics to obtain the object risk category; The anti-fraud identification module 1205 is used to identify target objects based on their risk category and the first risk group.
[0084] The specific implementation of the anti-fraud identification device for insurance claims is basically the same as the specific implementation of the anti-fraud identification method for insurance claims described above, and will not be repeated here.
[0085] This application also provides a computer device, which includes a memory and a processor. The memory stores a computer program, and the processor executes the computer program to implement the aforementioned anti-fraud identification method for insurance claims. This computer device can be any smart terminal, including tablet computers, in-vehicle computers, etc.
[0086] Please see Figure 13 , Figure 13 The hardware structure of a computer device according to another embodiment is illustrated. The computer device includes: The processor 1301 can be implemented using a general-purpose CPU (Central Processing Unit), microprocessor, application-specific integrated circuit (ASIC), or one or more integrated circuits, and is used to execute relevant programs to implement the technical solutions provided in the embodiments of this application. The memory 1302 can be implemented as a read-only memory (ROM), a static storage device, a dynamic storage device, or a random access memory (RAM). The memory 1302 can store the operating system and other applications. When the technical solutions provided in the embodiments of this specification are implemented through software or firmware, the relevant program code is stored in the memory 1302 and is called and executed by the processor 1301 to execute the anti-fraud identification method for insurance claims in the embodiments of this application. The input / output interface 1303 is used to implement information input and output; The communication interface 1304 is used to enable communication and interaction between this device and other devices. Communication can be achieved through wired means (such as USB, Ethernet cable, etc.) or wireless means (such as mobile network, WIFI, Bluetooth, etc.). Bus 1305 transmits information between various components of the device (e.g., processor 1301, memory 1302, input / output interface 1303, and communication interface 1304); The processor 1301, memory 1302, input / output interface 1303 and communication interface 1304 are connected to each other within the device via bus 1305.
[0087] This application also provides a computer-readable storage medium storing a computer program that, when executed by a processor, implements the aforementioned anti-fraud identification method for insurance claims.
[0088] Memory, as a non-transitory computer-readable storage medium, can be used to store non-transitory software programs and non-transitory computer-executable programs. Furthermore, memory may include high-speed random access memory, and may also include non-transitory memory, such as at least one disk storage device, flash memory device, or other non-transitory solid-state storage device. In some embodiments, memory may optionally include memory remotely located relative to the processor, and these remote memories can be connected to the processor via a network. Examples of such networks include, but are not limited to, the Internet, intranets, local area networks, mobile communication networks, and combinations thereof.
[0089] The anti-fraud identification method, apparatus, equipment, and storage medium for insurance claims provided in this application first construct an abnormal relationship graph of three types of nodes: the patient, the hospital department, and the disease being treated. Then, based on this abnormal relationship graph, the target objects are first divided into candidate groups, including a first-risk group within a first-risk category. Next, risk classification is performed on the target objects within the first-risk group to determine their risk category. Finally, anti-fraud identification is performed on the target objects by combining the first-risk group and the object's risk category. Therefore, by transforming individual anti-fraud identification into anti-fraud identification of organized crime, complex fraudulent behaviors such as doctor-patient collusion, fraudulent medical treatment, and excessive medical treatment can be identified, improving the accuracy of anti-fraud identification. Furthermore, the entire anti-fraud identification process is automated, requiring no manual intervention, thus saving labor costs in the anti-fraud identification process.
[0090] The embodiments described in this application are for the purpose of more clearly illustrating the technical solutions of this application, and do not constitute a limitation on the technical solutions provided in this application. As those skilled in the art will know, with the evolution of technology and the emergence of new application scenarios, the technical solutions provided in this application are also applicable to similar technical problems.
[0091] Those skilled in the art will understand that the technical solutions shown in the figures do not constitute a limitation on the embodiments of this application, and may include more or fewer steps than shown, or combine certain steps, or different steps.
[0092] The device embodiments described above are merely illustrative. The units described as separate components may or may not be physically separate; that is, they may be located in one place or distributed across multiple network units. Some or all of the modules can be selected to achieve the purpose of this embodiment according to actual needs.
[0093] Those skilled in the art will understand that all or some of the steps in the methods disclosed above, as well as the functional modules / units in the systems and devices, can be implemented as software, firmware, hardware, or suitable combinations thereof.
[0094] The terms “first,” “second,” “third,” “fourth,” etc. (if present) in the specification and accompanying drawings of this application are used to distinguish similar objects and are not necessarily used to describe a specific order or sequence. It should be understood that such data can be interchanged where appropriate so that the embodiments of this application described herein can be implemented in orders other than those illustrated or described herein. Furthermore, the terms “comprising” and “having,” and any variations thereof, are intended to cover non-exclusive inclusion; for example, a process, method, system, product, or apparatus that comprises a series of steps or units is not necessarily limited to those steps or units explicitly listed, but may include other steps or units not explicitly listed or inherent to such processes, methods, products, or apparatus.
[0095] It should be understood that in this application, "at least one (item)" means one or more, and "more than" means two or more. "And / or" is used to describe the relationship between related objects, indicating that three relationships can exist. For example, "A and / or B" can represent three cases: only A exists, only B exists, and both A and B exist simultaneously, where A and B can be singular or plural. The character " / " generally indicates that the preceding and following related objects are in an "or" relationship. "At least one (item) of the following" or similar expressions refer to any combination of these items, including any combination of single or plural items. For example, at least one (item) of a, b, or c can represent: a, b, c, "a and b", "a and c", "b and c", or "a and b and c", where a, b, and c can be single or multiple.
[0096] In the several embodiments provided in this application, it should be understood that the disclosed apparatus and methods can be implemented in other ways. For example, the apparatus embodiments described above are merely illustrative; for instance, the division of the units described above is only a logical functional division, and in actual implementation, there may be other division methods. For example, multiple units or components may be combined or integrated into another system, or some features may be ignored or not executed. Furthermore, the coupling or direct coupling or communication connection shown or discussed may be through some interfaces; the indirect coupling or communication connection between apparatuses or units may be electrical, mechanical, or other forms.
[0097] The units described above as separate components may or may not be physically separate. The components shown as units may or may not be physical units; that is, they may be located in one place or distributed across multiple network units. Some or all of the units can be selected to achieve the purpose of this embodiment according to actual needs.
[0098] Furthermore, the functional units in the various embodiments of this application can be integrated into one processing unit, or each unit can exist physically separately, or two or more units can be integrated into one unit. The integrated unit can be implemented in hardware or as a software functional unit.
[0099] If the integrated unit is implemented as a software functional unit and sold or used as an independent product, it can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of this application, in essence, or the part that contributes to the prior art, or all or part of the technical solution, can be embodied in the form of a software product. This computer software product is stored in a storage medium and includes multiple instructions to cause a computer device (which may be a personal computer, server, or network device, etc.) to execute all or part of the steps of the methods of the various embodiments of this application. The aforementioned storage medium includes various media capable of storing programs, such as USB flash drives, portable hard drives, read-only memory (ROM), random access memory (RAM), magnetic disks, or optical disks.
[0100] The preferred embodiments of the present application have been described above with reference to the accompanying drawings, but this does not limit the scope of the claims of the present application. Any modifications, equivalent substitutions, and improvements made by those skilled in the art without departing from the scope and substance of the embodiments of the present application shall be within the scope of the claims of the present application.
Claims
1. A method for fraud identification in insurance claims, characterized in that, The method includes: Obtain historical abnormal medical visit behavior data and behavior-related data of the target object; wherein, the target object includes: the hospital department visited, the patient, and the disease treated by the patient; Based on the historical abnormal medical visit behavior data and the behavior association data, a relationship graph is constructed for the target object to obtain an abnormal relationship graph; wherein, the abnormal relationship graph includes element nodes and node attribute features of the element nodes, the target object is used as an element node, the node attribute features are determined by the historical abnormal medical visit behavior data, and the behavior association data determines the edge weights between the element nodes; The target objects are grouped according to the abnormal relationship graph to obtain candidate groups; wherein, the candidate groups include a first risk group with a first risk category; Based on the node attribute characteristics, the target objects of the first risk group are classified into risk categories to obtain object risk categories; Anti-fraud identification of the target object is performed based on the object's risk category and the first risk group.
2. The method according to claim 1, characterized in that, The step of constructing a relationship graph of the target object based on the historical abnormal medical visit behavior data and the behavior association data to obtain an abnormal relationship graph includes: Feature extraction is performed on the historical abnormal medical visit data to obtain historical abnormal medical visit features; wherein, the target object is used as an element node, and the historical abnormal medical visit features are used as node attribute features; Feature extraction is performed on the behavioral association data to obtain behavioral association features; The behavioral association features are converted into edge weights between the feature nodes; The element nodes are connected according to the edge weights and node attribute features to obtain the anomaly relationship graph.
3. The method according to claim 2, characterized in that, The step of dividing the target objects into groups based on the abnormal relationship graph to obtain candidate groups includes: Obtain the node category of each element node in the abnormal relationship graph; The abnormal relationship graph is split according to the node category to obtain at least one abnormal relationship subgraph; wherein the nodes in the abnormal relationship subgraphs are of the same category; The target objects are grouped according to at least one of the abnormal relationship subgraphs to obtain candidate groups.
4. The method according to claim 3, characterized in that, The step of dividing the target objects into groups based on at least one of the abnormal relationship subgraphs to obtain candidate groups includes: The target objects are grouped according to the edge weights of each of the abnormal relationship subgraphs to obtain the original groups; Extract the node attribute features of each original group from at least one of the abnormal relationship subgraphs to obtain group attribute features; The original group is classified into risk categories based on the group attribute characteristics. The original group is divided into groups based on the group risk category to obtain the candidate group.
5. The method according to any one of claims 1 to 4, characterized in that, The step of classifying the target objects of the first risk group according to the node attribute characteristics to obtain object risk categories includes: Based on the node attribute characteristics, a risk assessment is performed on the target object of the first risk group to obtain object risk assessment data; The risk category of the target object is obtained by classifying the risk of the target object based on the object risk assessment data.
6. The method according to any one of claims 1 to 4, characterized in that, The acquisition of historical abnormal medical visit behavior data and behavior-related data of the target object includes: Obtain historical medical visit data of candidate patients; The candidate objects are evaluated based on the historical medical visit data to obtain the object evaluation status; wherein, the object evaluation status includes abnormal status. The candidate objects are filtered based on the abnormal state to obtain the target object; The historical medical visit data is filtered based on the target object to obtain the historical abnormal medical visit data.
7. The method according to any one of claims 1 to 4, characterized in that, After performing anti-fraud identification on the target object based on the object risk category and the first risk group, the method further includes: Receive a claim request; wherein the claim request includes the claimant and reference medical treatment behavior data of the claimant; Risk assessment data is obtained by performing a risk assessment on the claim subject based on the reference medical visit behavior data and the abnormal relationship graph. Claims will be processed based on the risk assessment data.
8. An anti-fraud identification device for insurance claims, characterized in that, The device includes: The data acquisition module is used to acquire historical abnormal medical visit behavior data and behavior-related data of the target object; wherein, the target object includes: the hospital department where the patient visited, the patient, and the disease treated by the patient; The graph construction module is used to construct a relationship graph of the target object based on the historical abnormal medical visit behavior data and the behavior association data, thereby obtaining an abnormal relationship graph. The abnormal relationship graph includes element nodes and node attribute features of the element nodes. The target object is used as an element node. The node attribute features are determined by the historical abnormal medical visit behavior data, and the behavior association data determines the edge weights between the element nodes. The group segmentation module is used to segment the target objects into groups based on the abnormal relationship graph to obtain candidate groups; wherein, the candidate groups include a first risk group with a first risk category; The risk classification module is used to classify the target objects of the first risk group according to the node attribute characteristics to obtain the object risk category; The anti-fraud identification module is used to perform anti-fraud identification on the target object based on the object risk category and the first risk group.
9. A computer device, characterized in that, The computer device includes a memory and a processor, the memory storing a computer program, and the processor executing the computer program to implement the anti-fraud identification method for insurance claims as described in any one of claims 1 to 7.
10. A computer-readable storage medium storing a computer program, characterized in that, When the computer program is executed by the processor, it implements the anti-fraud identification method for insurance claims as described in any one of claims 1 to 7.