The Healthcare Industry Is Coming for Your Face | Karen Schoellkopf
Skip to content
Home<br>Projects<br>Writing<br>About<br>Contact
All writing
July 15, 2026 · – min read
The Healthcare Industry Is Coming for Your Face
Face scans are evolving into a condition of everyday access, healthcare included. Here's what that biometric data can and can't do, why handing it over is a bigger deal than it looks, and what asking for it responsibly would actually take.
Don't miss a post →
Last week, I got an email from Headway, one of the third-party services used by my mental health provider, informing me that I would need to "Verify your identity before your next session" by submitting my biometric data. This mandatory identity verification requires a photo of a current government-issued ID plus a "live photo" scan (moving my head side to side in front of the camera) run through another third-party vendor called Persona.
Headway is requiring this of every patient who sees a prescriber, mine included, with no way to opt out short of abandoning your provider. Interestingly, the vendor doing the scanning, Persona, is backed by Peter Thiel's Founders Fund. 404 Media's Samantha Cole broke the story about Headway's plan in May, and the reporting is clear about the bind patients are in.
Let's explore what biometric data can and cannot do, why it's a big ask of consumers, and how what happened to me could have been easily avoided (there's a way to do this, friends). I'll focus on for-profit companies here, not government, as that's likely a whole other article.
"Do I give up my privacy or do I burn all my progress and then just go to a different company and try and find somebody else, and start over?"
— A Headway patient, quoted in 404 Media
Why Headway says they ask for this data
The reason Headway gave for these increased verifications is fraud prevention: people impersonating others to get controlled substances, or AI-generated faces on telehealth calls.
However, fraud is overwhelmingly on the provider side, not the patient side. When the Justice Department announced its 2026 National Health Care Fraud Takedown, it charged 455 defendants more than $6.5 billion in alleged fraud, and the high profile cases were almost uniformly committed by providers and operators, not by patients impersonating someone else: a billion-dollar telehealth platform signing orders for patients doctors never examined, a physician billing for Botox injections given while she was on vacation, a clinic billing Medicaid for more than 500 hours of therapy in a single day.
Patient impersonation (someone using another person's identity to obtain care or controlled substances) exists, but isn't a category federal enforcers highlight in their major takedowns, and the cases that do involve stolen patient identities are overwhelmingly providers misusing records to bill, not strangers turning up at a video visit wearing someone else's name. And where patient data does get stolen at scale, it isn't through unverified faces; it's through breaches of the exact kind of centralized systems Headway is now building. The 2024 Change Healthcare breach alone exposed the records of 192.7 million people. That is the actual threat model for medical identity theft: a for-profit intermediary holding a giant, breachable trove of health data. A clinical psychologist and co-founder of the Psychotherapy Action Network, Linda Michaels, told ClearHealthCosts there is "no valid clinical rationale for biometrics or facial ID. The only rationale is a commercial one."
AI-generated faces on telehealth calls are a different idea altogether. Deepfake fraud is real and climbing fast, but the clearest data on it comes from European banking and payments, not telehealth: a Signicat study shows that deepfakes jumped from 0.1% of all fraud attempts three years ago to 6.5% today. That fits a broader pattern: the most-targeted sectors are finance and crypto, and the high-profile cases are corporate wire-transfer scams. From what I see today, the threat of patients faking their own faces to see their own mental health provider lives mostly in security vendors' marketing. I couldn't find a single documented case of a patient deepfaking a telehealth visit to obtain care. I'd be keen to know if anyone knows of one. And here's the part that should give anyone pause: the security field is already concluding that facial scans don't reliably stop this threat. Gartner projected that by 2026, 30% of enterprises would stop trusting face-biometric verification on its own, because deepfakes and "injection attacks" that bypass the camera entirely defeat it (Gartner). So if the goal is to defend against an attack that mostly isn't happening in telehealth, using a method experts say is already being outrun...what is the point?
There have already been troubling signals for consumers
A few useful nuggets of additional context:
One therapist warned that these policies are "especially dangerous for...