HumanVerified is in beta — free while we build it.Help us make it better →
AI IssuesHealthcare & TelehealthSep 10, 20264 min read

Physician Deepfake Impersonation Doesn't Skip the Solo Practice

The AMA now has a framework for AI deepfakes of physicians. A two-person practice has a cell phone. The gap between those is where patients start ignoring real messages.

Listen to this article
Audio narration
Narrated in a natural voice

A patient forwards a short video: a clinician in a white coat, name and credentials on screen, recommending a supplement the practice has never heard of. Sometimes it arrives as a voice on the phone instead, a familiar-sounding doctor calling about a prescription that needs a card on file. Physician deepfake impersonation does not require a famous doctor. It requires a name, a headshot, and a few minutes of recorded audio or video, which is roughly what every independent clinician with a practice website and a telehealth intro reel has already published.

What the AMA Flagged About Physician Deepfake Impersonation

On April 29, 2026, the American Medical Association announced a seven-principle policy framework aimed at unauthorized AI-generated deepfakes of physicians. AMA CEO John Whyte called deepfakes that impersonate physicians "not just scams" but "a public health and safety crisis," and the harm the association described runs wider than a stolen likeness: bad actors using a doctor's identity to steer people toward unproven care, and in the process eroding the trust patients place in the real thing.

That second half is the part a small practice feels first. Most solo clinicians will never find their face in a supplement ad. Nearly all of them will meet patients who have been told, correctly, to be suspicious of unexpected messages from someone claiming to be their doctor. Physician deepfake impersonation does its quietest damage to practices it never actually touches, by making ordinary messages from real clinicians one more thing a cautious patient decides to ignore.

The Practice Where Everything Comes From One Phone

A hospital system answers this with infrastructure. It brands its outbound calls, routes clinical messages into a portal patients already log into, and keeps a switchboard a patient can call to ask whether something was real. Two people in a private practice — one clinician, one person handling scheduling and billing — have a cell phone, an email address, and maybe a scheduling tool that texts from a short code nobody recognizes.

There is no second channel. There is no front desk to call and ask whether the doctor actually sent this. The identity of the practice and the identity of the person are the same thing, which is efficient right up to the moment somebody copies it. A solo clinician who wants to reassure a patient has to do it in the same voice, from the same number, that an impersonator would use.

Why "Use a Number You Know Is Real" Stops Working Here

The FTC's standing advice on scam texts is sound and simple: don't click links or reply to unexpected messages, and if you think one might be legitimate, contact the business using a phone number or website you know is real rather than one from the message itself. In a solo practice, that instruction quietly assumes something that isn't true.

The number the patient knows is real is the clinician's cell. It is the same number the message came from, and the same number a spoofed text will display. If the problem is impersonation rather than a hacked account, calling back the number already saved in the contact list is exactly what the impersonator is counting on. Following the advice correctly still lands the patient in the wrong place. What it needs is a second, independent place to look, and most small practices have never had one to offer.

Verification Is Not Detection

It is worth being precise about the claim here, because overclaiming in this area does real damage. A Human ID does not detect AI. It cannot tell a patient whether a video was synthetic, a voice cloned, or a message drafted by a model. HumanVerified does not certify the content of a communication or the accuracy of any clinical guidance inside it.

AI can help write the message. Verification tells you who is willing to stand behind it. What a Human ID confirms is narrow and specific: that the identified person personally reviewed and authorized that particular communication, and that a recipient can confirm it independently, outside the channel the message arrived through. Our verification policy is explicit about where that boundary sits. For a patient holding a text they weren't expecting, narrow is the useful part. They don't need to evaluate the message. They need to know whether their clinician sent it.

It also carries nothing clinical. A Human ID holds a name, a title, and a status — not a chart, a diagnosis, or an appointment. It answers who, and it is not a substitute for a patient portal.

Where an Independent Clinician Puts It

The habit that works is the boring one: the ID goes out before anyone has a reason to be suspicious, not produced defensively after a patient already sounds uneasy. The intake packet. The email signature. The first text of a new patient relationship. The appointment-reminder template. It costs nothing when there is no problem, and it is the only version that helps later, because a patient who has seen the same ID in a dozen ordinary messages has something to compare against when an unusual one arrives.

For a single message that a scammer would find worth faking — a change in payment instructions, a note about a prescription, anything unusual enough to raise a question — a per-message verification code tied to that one communication goes further than a permanent ID alone.

None of this stops someone from generating a video of a clinician's face, and nobody should claim otherwise. That problem is aimed at platform policy and legal remedy, which is roughly what the AMA's framework is asking for and well beyond what a two-person practice can supply on its own. What an independent clinician can control is narrower: whether the patients who already trust them have anywhere to check. Solo and small-practice clinicians can get a Human ID without waiting on a health system's IT department to approve it, which matters most for the practices that don't have one.

Get your own Human Verified ID

Attach a verified human identity to the messages you personally write and authorize. Free during beta.

Get a free Human ID

More Commentary