Identity Fraud in Healthcare Hiring: What the Data Could Mean for Telehealth and Remote Clinical Roles
Industry Guides

Identity Fraud in Healthcare Hiring: What the Data Could Mean for Telehealth and Remote Clinical Roles

Learn how identity fraud in healthcare hiring poses risks to organizations and patients, revealing a significant industry concern.

Created by

Charm Paz, CHRP
Charm Paz, CHRP Recruiter & Editor

Identity fraud in hiring happens when the person who was interviewed, credentialed, or background checked is not the person who shows up to do the job. GCheck’s Shadow Workforce research found that more than a quarter of employees (28%) have suspected exactly this happening to a coworker. In telehealth and other remote clinical roles, that same pattern carries a patient sitting on the other end of the call.

Key Takeaways

  • Identity fraud in hiring is distinct from credential fraud and from “ghost employee” payroll fraud, though all three get discussed together
  • A one-time background check confirms identity and credentials on a single day; nothing about that check re-confirms who is actually doing the job six months later
  • HIPAA already requires a unique user identifier for anyone accessing electronic health information, but it does not require re-verifying that the person behind that ID is still the person who was hired
  • Several states require telehealth practitioners to verify a patient’s identity at every encounter, while nothing comparable requires an employer to re-verify the practitioner’s identity on an ongoing basis
  • Closing the gap takes two separate steps: stronger identity confirmation at the point of hire, and continuous monitoring afterward, not just one or the other

What Identity Fraud in Healthcare Hiring Actually Means

Identity fraud in hiring is when someone other than the verified candidate is the one being interviewed, credentialed, or doing the work itself. That is a narrower problem than credential fraud, which is when the right person is doing the work but has exaggerated or fabricated a qualification. A nurse who overstates familiarity with a charting system has committed credential fraud. A nurse whose interview and background check belonged to someone else entirely has committed identity fraud. Healthcare hiring content tends to treat these as one topic, and they are usually handled by different controls: credential fraud is surfaced by primary source verification of licenses and degrees, while identity fraud requires confirming the person behind the paperwork is a real, consistent individual across every step.

It is also worth separating identity fraud from a third, unrelated problem that shares similar language: “ghost employee” fraud. That term refers to payroll fraud, fictitious or already-terminated employees kept active in a payroll system so someone else can collect their paychecks. The U.S. Department of Justice indicted a former nursing home scheduling supervisor on wire fraud charges for creating fictitious “certified nursing assistant” payroll entries and diverting the resulting checks. That is a real and costly problem, but it is a bookkeeping crime, not the identity-substitution risk this article addresses. If a healthcare organization is researching how to prevent one, it is worth confirming which one is actually the concern before choosing a control.

The distinction matters most in the moment it fails. A payroll audit eventually surfaces a ghost employee, usually because someone notices a paycheck going somewhere it shouldn’t. Identity fraud in a clinical role does not announce itself the same way. A remote patient monitoring technician who is not the person originally screened can review data streams and generate a full activity record without anyone downstream having a reason to question whose hands were on the work. The failure mode is quiet rather than financial, which is why it calls for a different kind of control than a payroll reconciliation.

What a Background Check Confirms at Hire, and What It Stops Confirming Right After

A background check confirms identity, history, and credentials as they stood on the day it ran. It does not, and cannot, confirm anything about the person doing the job six months or six years later. Licenses lapse. Identities can be substituted in ways that never touch the original background check. The person screened is not automatically the person still logging in.

GCheck’s research frames this as the Verification Half-Life: the assurance an employer buys with a one-time background check begins to decay the moment onboarding ends, because nothing in a standard screening workflow reconfirms who a worker is, what they can still do, or whether they are the one actually doing the work. This is a way of describing a pattern in how verification works, not a measured decay rate, and it applies to background screening broadly, not to any one industry or role.

The stakes of that decay are not evenly distributed. A lapsed credential in most jobs is primarily an employer’s liability problem. In a clinical encounter, whether in person or over video, a lapsed credential or a substituted identity is a patient safety problem first and a liability problem second. That difference is why Protective Compliance, verification that safeguards vulnerable populations and reduces organizational risk, is the pillar this issue sits under.

Why Telehealth and Remote Clinical Roles Carry Higher Stakes

What the General Workforce Data Shows

GCheck’s Shadow Workforce research surveyed 1,500 U.S. employed adults across industries, not a healthcare-specific sample, and found that more than one in four (28%) have suspected a coworker was not actually the person hired or was not performing their own work (GCheck, The Rise of the Shadow Workforce). That figure describes a general workforce pattern. It says nothing on its own about healthcare. What it establishes is that identity substitution is something a meaningful share of American workers already believe they have witnessed, which is the baseline this article applies to a higher-stakes setting.

The same research found that a third of workers (33%) have either heard of or personally know a situation where someone was offered money to let another person use their identity or work authorization to obtain employment. Again, this is a general labor-market finding, not a healthcare finding. The editorial point this article makes is that a workforce-wide pattern like this one carries more weight when the coworker in question is prescribing medication, monitoring a patient’s vitals remotely, or reading a diagnostic image, because the consequences of a substituted identity are no longer contained to a single employer’s payroll or productivity metrics.

Which Roles Carry the Most Exposure

Several categories of remote clinical work carry elevated exposure to this kind of substitution risk, largely because the working relationship is mediated entirely through a screen and a login rather than a badge and a hallway:

None of these roles are inherently riskier because the people in them are less trustworthy. They are riskier because verification infrastructure built for in-person hiring, a badge, a supervisor who recognizes a face, was never designed for a relationship that exists entirely online. A hospital floor has ambient identity checks built into its layout: a charge nurse who knows every clinician on shift, a badge that has to match a face at a locked door. None of that exists when the relationship runs through a login screen and a video feed, which is why the formal checks have to do more work remotely than they do in a building.

What the Law Already Requires, and What It Doesn’t

The HIPAA Security Rule requires covered entities to assign a unique user identifier to every workforce member who accesses electronic protected health information, a required specification under the Access Control standard at 45 C.F.R. § 164.312(a)(2)(i). A separate safeguard, Authentication, at 45 C.F.R. § 164.312(d), requires procedures to verify that a person seeking access is who they say they are when they log in. Together these confirm that system activity is attributable to a specific identifier and that whoever is logging in matches its credentials. Neither requires ongoing confirmation that the person originally issued that identifier at hire is still the person using it a year later. A stolen password is surfaced by authentication controls. A substituted identity that was never technically stolen, just never re-checked, is not.

Two states show what identity verification already looks like on the patient-facing side of telehealth specifically. Maryland’s telehealth practice regulations for podiatric medicine require a practitioner to verify a patient’s identity, using government-issued photo identification or an equivalent method, before providing telehealth services. New York’s Office of Mental Health telehealth regulations require a practitioner to verify the identity of the recipient before commencing each telehealth encounter. Both rules run the same direction: the practitioner verifies the patient.

RequirementWho verifies whomApplies once or ongoing
HIPAA unique user ID (45 C.F.R. § 164.312(a)(2)(i)) and authentication (45 C.F.R. § 164.312(d))System assigns and authenticates a workforce member’s identifierAssigned and authenticated at login, not re-verified against the original hire over time
Maryland podiatric telehealth regulations (COMAR 10.40.12.04); New York Office of Mental Health telehealth regulations (14 NYCRR § 596.6)Practitioner verifies patientEvery encounter
Standard pre-hire background checkEmployer verifies candidateOnce, at hire

Read together, these three rows describe a real gap rather than an editorial assumption. Practitioners are required to verify their patients at every encounter. Systems are required to uniquely identify every workforce member. Nothing in that stack requires an employer to re-verify, on an ongoing basis, that the practitioner behind the credential and the login is still the person who was originally hired.

Closing the Gap at the Point of Entry

What Closes the Gap

The first place to close the gap is at the moment identity is first established, before a background check is even ordered. A background check is only as reliable as the identity data underneath it, so strengthening that layer changes the reliability of everything that follows it.

None of these tools are about treating clinicians as suspects. Most people applying for remote clinical roles are exactly who they say they are, and a legitimate clinician’s reputation and credential are also protected when impersonation is identified before it starts, rather than after a patient has already been affected.

What Point-of-Entry Verification Doesn’t Solve

Biometric liveness detection and similar tools also carry their own compliance layer worth naming rather than assuming away: collecting a facial scan, voiceprint, or other biometric identifier triggers state biometric privacy laws, including Illinois’s Biometric Information Privacy Act and comparable statutes in Texas, Washington, and elsewhere, which require specific notice, consent, and data retention practices separate from standard background check authorization. Adopting biometric verification means building those requirements into the process from the start, not treating them as a detail to handle later.

Point-of-entry verification also has a natural limit worth naming honestly: it only answers who someone is on the day it runs. A candidate who passes every one of these checks on day one has proven who they were at onboarding, not who will be sitting at that workstation a year into the role. That limit is not a reason to skip point-of-entry verification. It is the reason point-of-entry verification has to be paired with something that continues after it.

Keeping the Confirmation Current After Hire

Point-of-entry verification answers who someone is on day one. It says nothing about day two hundred. Closing that half of the gap means treating verification as something that continues rather than something that finishes at onboarding.

This is what Protective Compliance looks like in practice for a distributed clinical workforce: not a single gate at hiring, but a standing process that treats the assurance from a background check as something that needs to be renewed, not something that lasts indefinitely once granted.

Without that standing process, the gap does not announce itself. A license that lapses mid-employment, an exclusion added months after hire, a disciplinary action a board publishes quietly online: none of these trigger an alert on their own. They sit there until the next scheduled rescreen finds them, or until something goes wrong first. Continuous monitoring closes that specific window, the one between when something changes and when anyone finds out.

What Healthcare Workers Themselves Want From Verification

What Workers Are Asking For

Workers are not, on the whole, resistant to stronger verification. GCheck’s Shadow Workforce research found that 78% of the general U.S. workforce strongly support stronger skills and identity verification, and 59% specifically want stronger identity verification. These are workforce-wide figures, not a healthcare-specific finding, but they support a simple point: the mandate for stronger verification is not coming only from compliance departments. It is coming from workers who would rather have their identity clearly and consistently confirmed than work alongside colleagues nobody can be sure about.

That is the case for Transparent Compliance as the secondary pillar here. Communicating what is verified, and how, and on what schedule, turns identity verification from something that feels like surveillance into something that reads as protective of everyone in the working relationship, the clinician included. A verification program that explains itself is also one that a legitimate clinician has every reason to welcome, since it is the fastest way to rule out the suspicion that the Shadow Workforce data shows colleagues are already carrying about each other.

Why Transparency Closes the Loop

The alternative, saying nothing about what gets verified and simply tightening controls quietly, tends to produce the exact discomfort GCheck’s brand principles warn against: a workforce that feels watched rather than protected. The fix is not less verification. It is verification paired with an explanation a clinician can actually read, delivered before they need to ask for one.

Protective Compliance and Transparent Compliance are not separate initiatives competing for the same budget. Both sit inside Compliance for Good®, GCheck’s operating standard for treating verification as something that builds trust on both sides of a hire rather than something done to a candidate. Closing the gap this article describes means applying both pillars together: confirming identity continuously, and explaining that process clearly enough that the clinician being verified understands exactly what is being protected, and why.

Frequently asked questions

What is identity fraud in healthcare hiring?

Identity fraud in healthcare hiring is when the person interviewed, credentialed, or background checked is not the one actually performing the clinical role. It is distinct from credential fraud, where the right person exaggerates or fabricates a qualification, and from “ghost employee” fraud, a payroll scheme involving fictitious workers rather than identity substitution.

How is identity fraud different from credential fraud?

Credential fraud means the correct individual is doing the job but has misrepresented a license, degree, or skill. Identity fraud means someone other than the verified candidate is doing the work. The first is surfaced by primary source verification of credentials. The second requires confirming the person is who their paperwork says, and staying confirmed, over time.

Does HIPAA require re-verifying a remote clinician’s identity after hire?

No. HIPAA’s Security Rule requires a unique user identifier for anyone accessing electronic protected health information, making system activity attributable to a specific person, but it does not require ongoing confirmation that the person behind that identifier is still who was originally issued it.

What is the Verification Half-Life?

The Verification Half-Life is a conceptual frame describing how the assurance from a one-time background check decays the moment onboarding ends, since nothing in a standard screening process reconfirms who a worker is or whether they are the one still doing the job. It describes a pattern, not a measured or claimed statistic.

Can biometric liveness detection be used in healthcare hiring?

Yes. Biometric liveness detection is used at the point of identity verification to confirm a real person is present, rather than a static image or recorded media, which is particularly relevant for remote and telehealth roles where a candidate is never verified in person. Because it collects biometric data, its use also triggers state biometric privacy laws such as Illinois’s Biometric Information Privacy Act, which require separate notice, consent, and retention practices beyond standard background check authorization.

Sources cited

Charm Paz, CHRP
ABOUT THE CREATOR

Charm Paz, CHRP

Recruiter & Editor

Charm Paz is an HR professional at GCheck, specializing in background screening, fair hiring, and regulatory compliance. She holds FCRA Advanced certification from the Professional Background Screening Association (PBSA) and helps organizations navigate employment regulations with clarity and confidence.

With a background in Industrial and Organizational Psychology, she translates policy into practice to build ethical, compliant, human-centered hiring systems that strengthen decision-making over time.