The deepfake patient is here: how AI impersonation is infiltrating telehealth

Doctor on a telehealth video call, illustrating how deepfakes can impersonate patients or clinicians in virtual care

Thirty-eight percent of Americans received a scam call in 2025 from someone impersonating their healthcare provider — and the tactics are evolving fast. Security researchers are now tracking a stranger variant of the same fraud: a video call where the "patient" requesting a controlled-substance refill, or the "specialist" joining a virtual consult, was never a real person at all. As telehealth becomes the default front door to care, fraud teams accustomed to defending bank logins and call centers are discovering that virtual medicine has the exact same weakness — and almost none of the same defenses.

When the patient — or the doctor — isn't real

Telehealth platforms lean on video and voice verification to confirm who is on the other end of a call. Generative AI tools have caught up to that trust. Security firm Ramsey Theory Group flags AI-generated clinical impersonation and synthetic patient fraud as the single biggest emerging telehealth threat of 2026, driven by three attack patterns already showing up in the wild:

  1. Deepfake patient calls. Attackers simulate a patient's identity, complete with fabricated video, to obtain telehealth prescriptions for ADHD medication, painkillers, or anti-anxiety drugs.
  2. Impersonated specialists. A fake "specialist" joins a virtual consult with forged credentials and a deepfake video feed, gaining access to EHR notes and imaging.
  3. Synthetic patient identities. Fabricated demographic profiles schedule virtual visits and bill insurers for high-value procedure codes.

None of this requires movie-studio budgets. Consumer-grade tools can now generate a convincing deepfake video in under 60 seconds, and a cloned voice needs as little as three seconds of source audio to sound convincing.

Fake doctors are selling real — and dangerous — drugs

The fraud doesn't only run toward providers; it runs the other direction too. Check Point Research has been tracking a wave of pharmaceutical scams in which criminals impersonate licensed physicians to promote counterfeit medications, using deepfake video and cloned voices to fabricate convincing "doctor endorsements." Since October 2025 alone, researchers identified more than 200 fraudulent advertisements across social platforms promoting a single counterfeit weight-loss product, and roughly 72% relied on deepfake video, cloned voices, or impersonated physician profiles to look authentic.

The scams route victims to spoofed clinic websites — complete with countdown timers and stolen medical-association branding — that end in one of two outcomes: stolen payment with no product delivered, or an unregulated substance of unknown composition. Investigators describe the underlying infrastructure as a fraud-as-a-service economy: prepackaged kits with templates, stock imagery, and hosting automation that let low-skill operators stand up a convincing fake clinic in hours.

Voice and video stopped being proof

The common thread across both directions of telehealth fraud is that the channels providers have always relied on for identity — a familiar voice, a face on a video call — no longer reliably prove anything on their own. That shift is landing on a public that already senses the risk: 77% of Americans say they're very concerned that AI could be used to convincingly impersonate their voice or identity to access sensitive accounts. Notably, 84% say they're willing to accept a longer verification process if it meaningfully reduces that risk — the appetite for stronger identity checks already exists on the patient side; the infrastructure hasn't caught up.

A gap widened by scale, not neglect

This isn't a story of telehealth platforms being careless. Virtual care scaled extraordinarily fast — over 90% of large health systems now run weekly virtual visits — and identity verification simply wasn't designed for a world where any inbound video or audio stream might be synthetic. A password or a login code confirms an account; it does not confirm that the face and voice on the call belong to the same real person requesting care.

What telehealth and fraud teams should do now

Closing the gap means treating voice and video as data to be verified, not evidence to be trusted. That starts with:

  • Move beyond single-channel checks. A voice or a face alone is no longer sufficient — cross-modal matching that ties a specific voice to a specific face closes the gap that face-only or voice-only liveness checks leave open.
  • Verify continuously, not just at intake. Identity risk doesn't end once a patient or clinician passes an initial check; sessions should be able to flag anomalies mid-call.
  • Screen video and audio in real time. Real-time deepfake detection on live consults catches injected or synthetic streams before a prescription is authorized or sensitive data is shared.
  • Treat AI agents as identities too. Any AI system handling intake, scheduling, or EHR updates needs the same least-privilege access and audit trail as a human employee.

Telehealth isn't going to stop growing, and neither will the incentive to exploit it. Providers, insurers, and the fraud teams that support them need identity verification built for a world where a face and a voice are no longer enough on their own. Corsound AI's Deepfake Detect identifies synthetic audio and video in real time, so virtual care teams can trust who's actually on the call.

Photo: Kaboompics.com / Pexels

See Corsound AI Voice Intelligence In Action
Thank you.
Your submission has been received.
Oops! Something went wrong while submitting the form.