Fake Vaccination Cards: How US Healthcare Employers Detect Fraud
How hospitals, health systems and healthcare HR teams detect forged, altered or AI-generated vaccination cards and immunization records under OSHA and state law in 2026.

Summarize this article with
A fake vaccination card is any immunization record โ paper CDC-style card, PDF letter, or digital verification record โ that has been fabricated, altered, or presented under someone else's identity to satisfy an employer's occupational health requirement. In US healthcare settings, this covers four distinct patterns: a forged paper card with an invented lot number, a fraudulent digital record with a verification code that does not resolve, a genuine card belonging to someone else submitted under a different name, and an AI-generated card image or PDF built from scratch.
This article is provided for informational purposes only and does not constitute legal advice. Regulatory references are accurate as of the date of publication and vary by state โ confirm current requirements with counsel before relying on them for a specific hiring decision.
Why Healthcare Employers Are a Specific Target
US healthcare employers do not face a single national vaccination mandate the way NHS-style systems do โ they face a patchwork of a federal safety standard, a rescinded federal health-program rule, and employer or state policy on top. The closest thing to a legal floor is the OSHA Bloodborne Pathogens Standard, 29 CFR 1910.1030, which requires employers to offer the Hepatitis B vaccine series at no cost to occupationally exposed employees within ten working days of assignment. It is not a mandate: an employee may decline in writing using the standard's Appendix A form, and request the series later if they change their mind. Because Hepatitis B vaccination is offered and declinable, the documents most often faked in US healthcare hiring are COVID-19, MMR, varicella and flu records tied to a facility's own onboarding policy, not one federal standard.
The federal COVID-19 vaccination mandate for Medicare- and Medicaid-certified facilities, issued by CMS in November 2021, was formally rescinded effective August 4, 2023, and no federal requirement has replaced it as of 2026. Individual hospitals, health systems and staffing agencies set their own COVID-19, MMR, varicella and flu policies instead, often referencing CDC/ACIP recommendations for healthcare personnel as a voluntary clinical benchmark. This state-by-state, employer-by-employer variation is the single biggest structural difference from a national health system: a document that satisfies one hospital's policy may not match what a different employer requires.
There is also no single national vaccination registry. Each state and several territories run their own Immunization Information System (IIS) โ 66 separate jurisdictional databases in total โ and employer query access depends entirely on that state's own law, ranging from none at all to consent-based lookup. Most healthcare employers, and nearly all third-party occupational health clinics that smaller providers and staffing agencies rely on, have no live connection to any registry. The uploaded card or PDF is frequently the entire basis for the clearance decision โ the single point of reliance a forged or reused document is built to exploit.
Four Ways a Vaccination Card Gets Faked
A forged paper card or immunization letter uses invented details
The most common pattern is a physical or scanned CDC-style card, or a clinic letter, with a fabricated lot number, an administering pharmacy that does not exist, or a date altered with correction fluid or digital editing. Cross-referencing the stated lot number against publicly documented vaccine lot ranges and checking the administering site against a real, traceable pharmacy catches a meaningful share of these before they reach a hiring decision โ a manual visual read alone typically will not, because a convincing paper forgery is designed to pass a glance.
A fraudulent digital record carries a verification code that fails to resolve
Digital vaccine records and health-system portals increasingly attach a QR code or verification link intended to resolve back to an issuing pharmacy, clinic or state system. Many state-run digital vaccine portals launched during the pandemic have since been scaled back or retired, so a legitimate code today is more likely to resolve to a private credentialing vendor or the facility's own portal than to a state system. A code that fails to resolve, resolves to an unrelated or generic page, or is a flat, non-functional image is a strong indicator the document was produced outside any legitimate issuing system โ the same pattern documented in prescription fraud, where a static QR code is one of the clearest tells of forgery across medical document types.
A genuine card is reused under a different identity
An authentic vaccination card belonging to one person can be submitted by another candidate, particularly with travel nurses and agency staff moving between facilities on tight onboarding timelines. This pattern defeats a purely visual check because the document itself is real โ detecting it requires comparing the name, date of birth and any photo ID on the card against the candidate's other pre-employment documents, including Form I-9, and flagging inconsistencies in font or layout that suggest identity fields were edited after the original record was issued. It is also the pattern most likely to involve a family member or acquaintance rather than a stranger, and it will usually still fail a date-of-birth cross-check even when the card itself scans as entirely genuine.
An AI-generated card image or PDF is built without any real immunization event
Consumer-grade generative tools can now produce a card image or PDF that mimics a CDC-style template or a health system's own letterhead convincingly enough to pass a quick visual review, without any underlying immunization ever taking place. This is the fastest-growing category and the hardest for a human reviewer to catch unaided, because there is no altered original to compare against โ the entire document is synthetic. Structural analysis, metadata inspection and font-consistency checks are better suited to this pattern than a side-by-side visual comparison, which is why detection increasingly relies on an additional layer of AI-generation signals, used as a complement to existing structural checks rather than a replacement for occupational health verification.
Fraud Signals by Certificate Type
| Certificate type | Primary fraud signal | Verification step |
|---|---|---|
| Paper CDC-style card / clinic letter | Invented lot number, altered date, correction marks | Cross-check lot range and administering site |
| PDF immunization letter | Font or spacing inconsistency, missing letterhead detail | Structural and metadata analysis |
| Digital record with QR/verification code | Code resolves to nothing, an unrelated page, or is a static image | Resolve the code against the claimed issuer |
| Genuine card, wrong identity | Name, DOB or photo ID mismatch against other onboarding documents | Cross-document identity consistency check |
| AI-generated image or PDF | No underlying issuing record exists at all; template mimics genuine layout | AI-generation signal detection layer |
Ready to automate your checks?
Free pilot with your own documents. Results in 48h.
Request a free pilotRegulatory and Data Protection Framework
There is no single federal privacy law governing employee vaccination records comparable to UK-style data protection regimes. HIPAA is the framework people reach for first, but it generally does not apply to an employer collecting a vaccination card in its own hiring capacity: HIPAA covers "covered entities" โ providers, health plans and clearinghouses โ not employers acting outside a group health plan. What applies instead is narrower: the Americans with Disabilities Act requires medical information collected from an employee, including vaccination records, to be kept confidential in a file separate from the general personnel record; OSHA's recordkeeping rule, 29 CFR 1910.1020, adds its own confidentiality obligations; and consumer-protection and state privacy statutes โ enforced federally by the FTC and, in states with comprehensive privacy laws such as California's CCPA, at the state level โ fill the gap UK employers cover through the ICO.
Faking a vaccination card also triggers criminal exposure on two tracks. Federally, using, buying, selling or presenting a card bearing a counterfeit CDC seal can violate 18 U.S.C. ยง 1017, the fraudulent-government-seal statute, punishable by up to five years in prison โ DOJ has used it against both producers and individual buyers, including a permanent injunction shutting down a fake-CDC-card operation in Ohio and a Nebraska conviction for possession of fraudulent vaccination cards. Most individual cases, though, are prosecuted under state law, and state statutes vary significantly โ New York amended its forgery statute so a falsified vaccination card is treated as a written instrument, making possession a class A misdemeanor and, for tampering with the state's immunization registry, a class E felony; a 2022 case there charged fifteen defendants, thirteen of whom had paid to have fake data entered directly into New York's immunization registry. A card that is a misdemeanor to possess in one state can carry felony exposure in another โ compliance teams operating across state lines cannot assume one penalty framework applies everywhere.
Frequently Asked Questions
Sector forums for healthcare HR and compliance staff return to the same few questions on vaccination card fraud.
Do healthcare workers still need to be vaccinated against COVID-19 to work
Not under federal law. The CMS mandate for Medicare- and Medicaid-certified facilities was rescinded effective August 4, 2023, and no federal requirement has replaced it. Individual states, health systems and facilities can still set their own COVID-19, flu, MMR and varicella requirements as a condition of employment โ check the specific employer's policy rather than assuming a uniform national rule.
Travel nurses or agency staff arrive with immunization paperwork from a previous employer โ how far are we required to re-verify it
There is no federal requirement to repeat a full occupational health assessment if the prior clearance came from a recognized provider and the documentation is consistent. The receiving employer remains responsible for confirming the record belongs to the individual presenting it โ exactly the identity-reuse pattern a purely visual check misses.
Can an employer contact the issuing pharmacy or clinic to confirm a card is genuine without violating privacy law
Generally yes, within limits โ a pharmacy or clinic can confirm whether it issued a record bearing a specific lot number without disclosing clinical information, provided the employer has a genuine, documented concern rather than a routine query on every submission. Direct employer query access to a state's Immunization Information System is a separate question and depends entirely on that state's law; most employers should not assume they have it.
How do we tell a real formatting quirk from a fraud signal without slowing down onboarding for every genuine candidate
This is a false positive problem more than a detection problem. Contextual analysis that weighs a document against typical variation for its issuing pharmacy, health system or state, rather than flagging any deviation from a single template, keeps genuine candidates moving while still surfacing documents that warrant a second look.
Recommended Detection Approach for Healthcare Employers
Tier 1 โ Automated systematic check: structural and metadata analysis of the uploaded card, verification code resolution where present, cross-field consistency across the document.
Tier 2 โ Score-triggered review: identity cross-check against other onboarding documents, comparison against known lot number and administering-site ranges, AI-generation signal review for image and PDF submissions.
Tier 3 โ Manual investigation: direct contact with the issuing pharmacy, clinic or previous employer's occupational health provider, escalation to the organization's compliance or counter-fraud team, referral for disciplinary or criminal process where forgery is confirmed.
Manual review alone struggles to scale against this: the ACFE's 2024 Report to the Nations found organizations relying on manual detection alone catch only 37% of document fraud cases, with an average detection delay of 87 days โ long enough for an unverified worker to complete an entire onboarding cycle and begin patient-facing duties.
CheckFile's AI-generation signal detection adds a dedicated layer for synthetic card images and PDFs, used as a complement to existing occupational health and HR controls โ it does not replace pharmacy or issuing-site verification, and it will not catch every forgery on its own. For related detection patterns, see our analysis of fake medical prescriptions and reimbursement fraud and our broader guide to AI document fraud detection techniques. For sector-specific requirements across industries, see our industry verification guide.
Healthcare HR teams evaluating a document verification workflow can review CheckFile's medical sector solution, check pricing, or get in touch to discuss onboarding volumes and confidentiality requirements.
Stay informed
Get our compliance insights and practical guides delivered to your inbox.