Telehealth Patient Verification
A telehealth provider verified patient identity with ID-document and face checks before virtual visits, so remote consultations were tied to a proven person without adding friction to routine care.
A telehealth provider delivered virtual consultations at scale, but the person on the other end of the video call was only ever as verified as a self-entered name and date of birth. For routine follow-ups that was tolerable; for first visits, controlled-substance discussions, and benefit-bearing services it was a real exposure — the clinician had no assurance the patient was who the chart said.
The provider needed to verify patient identity to a real-world document and a live face, scaled to the right moments, without turning every appointment into an onboarding ordeal.
The challenge
Remote care has no front desk checking a driver’s license. Identity assurance had to be established through the device the patient already had, and it had to be proportionate: forcing a full document-and-face check before every routine refill would drive patients away, while skipping it entirely on a first controlled-substance visit was unacceptable. The provider also needed the verification result bound to the patient’s identity and carried into the clinical record, not stranded in a separate tool.
They wanted risk-based identity verification wired into the patient identity itself.
What Veripass deployed
Veripass added biometric verification — ID-document capture matched against a live face — as an identity-proofing step bound to the patient’s account in the provider’s tenant. At account creation and at defined high-assurance moments, the patient completed the document-and-face check from their own device; the result raised the assurance level recorded against their verified identity.
Context-aware policy decided when that assurance was required. A routine follow-up proceeded on an already-verified identity; a first visit or a controlled-substance consult required a fresh or elevated check before the clinician could proceed. Authorization to enter visits and act on records stayed governed by claims, capabilities, roles, and access profiles, and every verification event was written to an immutable audit trail.
- ID-document and face biometric verification bound to patient identity
- Risk-based, context-aware policy deciding when to verify or re-verify
- Assurance level recorded against the verified patient identity
- RBAC from claims, capabilities, roles, and access profiles for visit access
- Adaptive, step-up MFA over email and phone TOTP for sensitive consults
- Immutable audit trail of every verification and assurance change
For the most sensitive encounters the provider layered a step-up: adaptive MFA over email or phone TOTP on top of the biometric proof, so a controlled-substance visit carried both a verified identity and a fresh second factor, each logged with the consultation.
Outcome
Clinicians entered high-stakes virtual visits knowing the patient was a proven person, not a self-asserted name — without making routine care slower. Verification effort tracked risk, so most appointments proceeded on standing assurance while the sensitive ones demanded fresh proof.
The provider gained an immutable, per-patient record of when and how each identity was verified, what assurance level applied at each visit, and where a step-up was required — turning remote identity from a blind spot into a governed, auditable part of the clinical workflow.
More deployments
Alumni Lifelong Identity
A university gave graduates a durable identity that survived their student account, transitioning alumni to a lifelong Veripass profile with re-scoped access and no disruptive re-registration.
Digital Account KYC Onboarding
A digital bank compressed remote account opening into minutes by combining Veripass biometric verification with policy-driven onboarding, proving applicant identity before the first session began.
Fleet Device Identity
A logistics company gave every vehicle telematics unit a first-class machine identity, so device-to-cloud traffic was authenticated, scoped, and individually revocable across a fleet of thousands.


