With the rapid development of wireless communication technologies and the growing prevalence of smart devices, medical care system allows patients to receive medical treatments from the doctors in remote over wireless sensor networks via Internet of things (IoT). However, the medical data transmission through IoT concerns the privacy issue of patient. To solve this problem, Li et al. proposed an efficient user authentication and user anonymity scheme for medical care system over IoT and claimed their scheme is provably secure. This paper shows that Li et al.'s scheme has some security weaknesses and presents an enhanced scheme to solve the problems in Li et al.'s scheme. The proposed scheme has a bit of overhead in computation but provides security with privacy.Index Terms-Internet of things, medical care system, privacy, authentication, public key cryptography.