Fake Vaccination Certificates: How Healthcare Employers Detect Fraud
How NHS trusts, care homes and healthcare HR teams detect forged, altered or AI-generated vaccination certificates and immunisation records in 2026.

Summarize this article with
A fake vaccination certificate is any immunisation record โ paper Red Book entry, PDF letter, or digital QR-linked certificate โ that has been fabricated, altered, or presented under someone else's identity to satisfy an employer's occupational health requirement. In UK healthcare settings, this covers four distinct patterns: a forged paper record with an invented date or batch number, a fraudulent digital certificate with a QR code that does not resolve, a genuine certificate belonging to someone else submitted under a different name, and an AI-generated certificate image or PDF built from scratch.
This article is provided for informational purposes only and does not constitute legal or regulatory advice. Regulatory references are accurate as of the date of publication.
Why Healthcare Employers Are a Specific Target
Healthcare employers verify immunity status, not vaccination status as a condition of employment โ a distinction that matters because it shapes what fraudsters try to fake. Since March 2022, when the regulations making COVID-19 vaccination a condition of deployment in CQC-registered care homes were revoked, no UK healthcare role legally requires COVID-19 vaccination. What NHS trusts, private hospitals and care providers do still require, per Green Book Chapter 12 on immunisation of healthcare and laboratory staff, is documented immunity to Hepatitis B, MMR and varicella for clinical staff and anyone undertaking exposure-prone procedures.
This creates a narrower but higher-stakes verification problem than a blanket vaccine mandate. A candidate who cannot prove Hepatitis B immunity through vaccination history or a blood titre test cannot be cleared for exposure-prone procedures, which puts direct pressure on the individual to produce paperwork rather than wait for an occupational health blood test. Nurseries and childcare settings face a parallel version: no legal MMR mandate exists for staff, but many providers set it as a condition of employment given proximity to unvaccinated infants.
Private hospitals and independent care providers face the same immunity checks as NHS trusts but often without an in-house occupational health department to fall back on. A smaller care home group or agency staffing provider commonly outsources screening to a third-party clinic, which means the certificate itself becomes the entire basis for the clearance decision โ the single point of reliance a forged or reused certificate is designed to exploit.
NHS England's screening and vaccinations trust framework, published in April 2026, sets a shared baseline for how NHS employers request and manage staff immunisation records, replacing the previously fragmented trust-by-trust approach documented in the NHS England long-read on the framework. A standardised national baseline raises the bar for what a forged document has to imitate convincingly, but it does not close the gap on its own โ occupational health teams still receive the evidence as a photograph, scan, or PDF upload, with no live connection to a vaccination registry in most cases.
Four Ways a Vaccination Certificate Gets Faked
A forged paper Red Book or immunisation letter uses invented details
The oldest pattern is a physical or scanned paper record with a fabricated batch number, an issuing GP practice that does not exist, or a date altered with correction fluid or digital editing. Cross-referencing the stated batch number against known UK vaccine batch ranges and checking the practice address against a real, traceable surgery catches a meaningful share of these before they reach a hiring decision โ a manual visual read alone typically will not, because a convincing paper forgery is designed to pass a glance.
A fraudulent digital certificate carries a QR code that fails to resolve
Digital vaccination certificates and immunisation letters increasingly carry a QR code intended to link back to an issuing record. A QR code that fails to resolve, resolves to an unrelated or generic page, or is a flat, non-functional image rather than a live code is a strong indicator the document was produced outside any legitimate issuing system โ the same pattern documented in fit note fraud, where a static QR code is one of the clearest tells of forgery across medical document types generally.
A genuine certificate is reused under a different identity
An authentic vaccination record belonging to one person can be submitted by another candidate, particularly where agency staff move between trusts and providers on tight onboarding timelines. This pattern defeats a purely visual check because the document itself is real โ detecting it requires comparing the name, date of birth and any photographic ID on the certificate against the candidate's other pre-employment documents, and flagging inconsistencies in font, spacing or layout that suggest the identity fields were edited after the original record was issued.
This is also the pattern most likely to involve a family member or acquaintance rather than a stranger, since access to someone else's genuine record is the limiting factor โ and it will usually still fail a date-of-birth cross-check even when the certificate itself scans as entirely genuine.
An AI-generated certificate image or PDF is built without any real immunisation event
Consumer-grade generative tools can now produce a certificate image or PDF that mimics an NHS or private clinic template convincingly enough to pass a quick visual review, without any underlying immunisation ever taking place. This is the fastest-growing category and the hardest for a human reviewer to catch unaided, because there is no altered original to compare against โ the entire document is synthetic. Structural analysis, metadata inspection and font-consistency checks are better suited to this pattern than a side-by-side visual comparison, which is why detection increasingly relies on an additional layer of AI-generation signals deployed according to client configuration, used as a complement to existing structural checks rather than a replacement for occupational health verification.
Fraud Signals by Certificate Type
| Certificate type | Primary fraud signal | Verification step |
|---|---|---|
| Paper Red Book / handwritten record | Invented batch number, altered date, correction marks | Cross-check batch range and issuing practice address |
| PDF immunisation letter | Font or spacing inconsistency, missing practice letterhead detail | Structural and metadata analysis |
| Digital certificate with QR code | QR resolves to nothing, an unrelated page, or is a static image | Scan and resolve the code against the claimed issuer |
| Genuine certificate, wrong identity | Name, DOB or photo ID mismatch against other onboarding documents | Cross-document identity consistency check |
| AI-generated image or PDF | No underlying issuing record exists at all; template mimics genuine layout | AI-generation signal detection layer |
Ready to automate your checks?
Free pilot with your own documents. Results in 48h.
Request a free pilotRegulatory and Data Protection Framework
Occupational health verification in NHS settings follows the NHS Employment Check Standards, which set out pre-employment health assessment requirements including immunisation history, with results processed by an occupational health service before a clearance certificate is issued to HR. Green Book Chapter 12 remains the clinical reference for which roles require Hepatitis B, MMR and varicella immunity, and at what threshold.
Because a vaccination record is health data, it is special category data under UK GDPR, and the ICO's guidance on workers' health information requires employers to identify both an Article 6 lawful basis and a separate Article 9 condition before processing it โ typically employment obligations under Article 9(2)(b) or preventive occupational medicine under Article 9(2)(h), not employee consent, which the ICO treats as inherently weak given the power imbalance in an employment relationship. A document verification workflow that stores and processes vaccination certificates needs to reflect this distinction in its retention and access controls, not just its detection logic.
Submitting a forged immunisation record to secure or retain a role can constitute fraud by false representation under the Fraud Act 2006, section 2, and altering a genuine certificate falls within the Forgery and Counterfeiting Act 1981. UK enforcement activity has already reached healthcare staff directly: the National Crime Agency's investigation into a fake COVID vaccine record scheme found nearly 2,000 fraudulent entries distributed between June and October 2021, and led to arrests that included NHS staff accused of altering patient records to show doses that were never administered.
Frequently Asked Questions
Sector forums for healthcare HR and compliance staff return to the same few questions on vaccination certificate fraud.
Do care home or NHS staff still need to be vaccinated against COVID-19 to work
No. COVID-19 vaccination stopped being a legal condition of employment in CQC-registered care homes and the wider NHS in England when the regulations were revoked in March 2022. What remains a genuine employment requirement for clinical roles is documented immunity to Hepatitis B, MMR and varicella under Green Book Chapter 12, which is the record that actually gets forged in practice.
Agency staff arrive with immunisation paperwork from a previous employer โ how far are we expected to re-verify it
There is no requirement to repeat a full occupational health assessment if the prior clearance came from a recognised NHS or equivalent occupational health service and the documentation is consistent. The receiving employer remains responsible for confirming the record belongs to the individual presenting it, which is exactly the identity-reuse pattern that a purely visual check misses.
Can an employer contact a GP practice or clinic to confirm a certificate is genuine without breaching confidentiality
Yes, within limits. A practice can confirm whether it issued a record bearing a specific reference number or batch detail without disclosing clinical information, provided the employer has a genuine, documented concern rather than a routine query on every submission.
How do we tell a real formatting quirk from a fraud signal without slowing down onboarding for every genuine candidate
This is a false positive problem more than a detection problem. Contextual analysis that weighs a document against typical variation for its issuing practice or country of origin, rather than flagging any deviation from a single template, keeps genuine candidates moving while still surfacing documents that warrant a second look.
Recommended Detection Approach for Healthcare Employers
Tier 1 โ Automated systematic check: structural and metadata analysis of the uploaded certificate, QR code resolution where present, cross-field consistency across the document.
Tier 2 โ Score-triggered review: identity cross-check against other onboarding documents, comparison against known batch and practice-address ranges, AI-generation signal review for image and PDF submissions.
Tier 3 โ Manual investigation: direct contact with the issuing practice or previous employer's occupational health service, escalation to the trust's counter-fraud team, referral for disciplinary or criminal process where forgery is confirmed.
Manual review alone struggles to scale against this: the ACFE's 2024 Report to the Nations found organisations relying on manual detection alone catch only 37% of document fraud cases, with an average detection delay of 87 days โ long enough for an unverified worker to complete an entire onboarding cycle and begin exposure-prone procedures.
CheckFile's AI-generation signal detection adds a dedicated layer for synthetic certificate images and PDFs, used as a complement to your existing occupational health and HR controls โ it does not replace GP or issuing-practice verification, and it will not catch every forgery on its own. For related detection patterns across medical documents, see our analysis of fake medical prescriptions and reimbursement fraud and our broader guide to AI document fraud detection techniques. For sector-specific verification requirements across industries, see our industry verification guide.
Healthcare HR and occupational health teams evaluating a document verification workflow can review CheckFile's medical sector solution, check pricing, or get in touch to discuss onboarding volumes and retention requirements for special category data.
Stay informed
Get our compliance insights and practical guides delivered to your inbox.