The license was real.
It was current, in good standing, and it verified cleanly through the proper channel. It belonged to a registered nurse in Virginia named Alicia Pierce, who had done nothing wrong and had no idea any of this was happening.
It was being used by a woman in Arkansas named Alicia Flanagan, who was not a nurse. In March 2026, Flanagan pleaded guilty to practicing medicine without a license and to identity fraud. She had worked at two Northwest Arkansas healthcare facilities.
Every credentialing control those facilities ran worked exactly as designed. Primary source verification returned a valid license. It would have returned a valid license every time it was run, because the license was valid.
The control answered the question it was built to answer. The question it was never built to answer is the one that mattered: is the person standing in front of us the person this license belongs to?
What primary source verification actually verifies
Credentialing exists to confirm that a credential is genuine. Nursys and the state boards do this well. Query a license number and you learn whether that license exists, whether it is active, what its expiration is, and whether it carries discipline.
What you do not learn is anything about the applicant.
The verification runs against the credential. The connection between that credential and the human being who submitted it is established somewhere else entirely — usually by a photocopied ID reviewed by a recruiter, or by a name and date of birth typed into a form, or, increasingly, by nothing at all.
That is not a criticism of primary source verification. It is a description of scope. Credential verification and identity verification are two different controls, and most healthcare hiring workflows run only one of them.
Fraudsters have worked this out. It is the reason the successful cases follow such a consistent pattern.
The pattern in the cases
Thomasina Amponsah worked as a nurse at more than forty Maryland facilities using stolen identities and falsified credentials. She was sentenced to 38 months in federal prison and ordered to repay over $145,000 in wages.
In Los Angeles, a woman who held no nursing license — and who was on federal probation for fraud at the time — obtained positions at two county hospitals using a registered nurse's stolen identity. She cared for roughly sixty patients over a month at a Burbank hospital before anyone discovered it.
Read enough of these and the shape becomes obvious:
They steal real credentials, not fake ones. Forging a license means passing document scrutiny. Stealing a valid one means passing verification. The second is easier and far more durable.
They target high-velocity hiring. Staffing agencies, travel nursing, per-diem and short-term placements all compress credentialing timelines. Faster cycles mean thinner verification, and the industry's reliance on contingent clinical labour has grown sharply.
They exploit the handoff. In a permanent hire, several people meet the candidate. In an agency placement, the facility may never verify identity independently, assuming the agency did. The agency may assume the same about the facility.
They stay a long time. The Burbank case ran a month. Amponsah moved through forty facilities. These are not one-shift scams — they are employment, with patient contact, payroll and system access.
The scale is no longer marginal. Reporting on healthcare hiring in 2026 indicates that a substantial share of healthcare organisations encountered identity-related issues with candidates over the past year, and that identity fraud has moved into the top tier of CHRO concerns. It has stopped being a credentialing footnote and become a patient safety exposure.
Why the gap is widening now
Three changes have compounded.
Remote and hybrid hiring removed the incidental checks. Interviews over video, documents by upload, onboarding by portal. The in-person moments that used to catch impostors by accident — walking into a building, handing over a physical licence, being recognised by someone — have quietly disappeared from large parts of the process.
Documents stopped being evidence. AI-generated credentials are now trivial to produce, and stolen identity data is abundant after years of breaches. In July 2026, LexisNexis Risk Solutions reported that roughly one in every hundred identity check failures involved a deepfake document, image or liveness video. A convincing document is no longer proof of anything.
Contingent staffing keeps growing. Every additional intermediary between the clinician and the facility adds a place for the identity handoff to be assumed rather than performed.
The NCSBN has issued guidance aimed at helping boards and employers detect fraudulent nurses, which is a reasonable signal of how seriously the regulatory side now takes this. But guidance for boards does not resolve the operational question for a talent acquisition or credentialing team: at what point in our process do we actually bind this applicant to this credential?
Closing the gap: three additions to an existing workflow
None of this requires replacing credentialing. It requires adding an identity control alongside it, ideally earlier.
1. Verify identity before you verify credentials. If identity is confirmed first, every downstream check runs against a person you know exists rather than against a name on a form. It also fails cheaply — you have not yet paid for primary source verification, background screening or a drug panel on an applicant who was never real.
2. Bind a live person to a government-issued document. Document authentication alone is no longer sufficient. The control that matters is biometric liveness: confirming a real, present human matches the document, and distinguishing that human from a photo, a prerecorded video, a mask or a deepfake. This is the specific control that would have stopped Flanagan, because the stolen licence would have verified perfectly while the face would not have matched Alicia Pierce.
3. Make the verification reusable. In a sector where the same clinician is re-credentialed across facilities, agencies and renewal cycles, a verification that expires on delivery is pure cost. A portable, cryptographically sealed credential the individual carries turns a one-time check into an asset that speeds up every subsequent placement — which is also what makes clinicians willing to complete it.
Where Cerebrum fits
We are an identity company, not a credentialing company, and the distinction matters here.
vID binds a real person to their identity at the start of the process using biometric verification and liveness detection, before credentials are ordered or screening begins. Synapse takes that verified identity and automates the background and compliance checks that follow. The Wallet seals the result into a portable credential the clinician keeps and can present at the next facility, the next agency, the next renewal.
Two things worth being direct about:
vID does not require a background check. It can run as a standalone identity step inside an existing credentialing workflow. If your screening vendor and credentialing process already work, you do not need to replace them to close this gap.
We do not verify licences. Nursys and the state boards do that, and they do it well. We verify that the person presenting the licence is the person it was issued to. Those are complementary controls, and healthcare organisations need both.
Talk to our team about healthcare identity verification → · See our healthcare solutions →
FAQ
Doesn't primary source verification already prevent this? Primary source verification confirms that a credential is genuine, current and in good standing. It does not confirm that the applicant is the person the credential was issued to. In the documented impostor cases, the stolen licences were genuine and verified correctly — the failure was in identity, not in credentialing.
What is the difference between credential verification and identity verification? Credential verification asks whether a licence, degree or certification is real. Identity verification asks whether the person presenting it is who they claim to be. Healthcare workflows typically run the first thoroughly and the second informally, if at all.
How do impostors pass background checks? By using a real person's identity. A background check run against a stolen identity returns that person's clean record. Without an identity control, the report is accurate and completely misleading at the same time.
Where in the hiring process should identity verification happen? As early as possible — ideally at application or immediately after, before credentialing and screening are ordered. Verifying first means later checks run against a confirmed person, and fraudulent applicants are filtered before you pay for downstream searches.
Does this apply to travel nurses and agency placements? Those are the highest-exposure category. Compressed timelines and multiple intermediaries create the handoff gaps the documented cases exploited, and each additional party in the chain is a place where identity verification can be assumed rather than performed.
Subscribe to our newsletter to get the latest updates and news