Digital health

Headache-free patient and clinician verification Provide seamless onboarding experiences while orchestrating HIPAA-compliant identity verification.
Verify real patients and reduce onboarding drop-off

Help legitimate patients sign up and access prescriptions while keeping bad actors off your platform.

Step up verification when clinical risk is high

Apply stronger identity checks at high-risk moments, such as initial prescribing, controlled-substance refills, and sensitive record access.

Meet the standards for HIPAA, TEFCA, and whatever comes next

Receive Business Associate Agreement (BAA) support, NIST IAL2-aligned verification, and identity coverage across the full care journey, from patient onboarding to authorized health record access.

Trusted by startups & the world’s largest companies

Citizen Health
Monash IVF
Collect, verify, and make decisions, all in one place

Collect patients’ information

Choose what information to collect, such as government IDs and health insurance cards, while dynamically adjusting friction based on user risk.

Collect patients’ information

Verify patients’ identities

Confirm patients are who they say they are with ID and selfie checks. Verify coverage efficiently with a streamlined experience for insurance card collection.

Verify patients’ identities

Automatically approve or deny

Configure verification rules to automatically approve or decline patients so they get a decision right away.

Automatically approve or deny

Use cases

Verify patients and clinicians across the care journey

At patient signup and onboarding
Toggle description visibility

Collect IDs, insurance cards, and supporting documents at intake, in one seamless onboarding flow.

Ahead of an appointment
Toggle description visibility

Help patients get faster care with a convenient pre-visit identity check online.

Prior to a controlled-substance prescription
Toggle description visibility

Verify the right patient is receiving their prescription before a telemedicine visit.

Before a patient shares health records via TEFCA
Toggle description visibility

Ensure patients are who they say they are before accessing HIPAA-protected data. Perform NIST IAL2 identity proofing before patients access or authorize the sharing of their medical records across TEFCA's network.

Before a clinician onboards to your platform or accesses prescribing workflows
Toggle description visibility

Verify clinicians before granting access to prescribing systems or sensitive patient records.

During suspicious activity or account recovery
Toggle description visibility

Detect and stop unauthorized access with risk-based step-up verification at the right moments in the care cycle.

Everything you need to verify patients

“As we deal with sensitive health records, we needed a certified identity solution that would help us verify patients quickly, accurately, and safely. Not only did Persona meet all of these expectations, but their NIST IAL certification will also play a key role in our ability to help patients get more out of their health records.”

Deven McGraw
Lead for Data Stewardship and Data Sharing at Citizen Health
Citizen Health builds a faster, privacy-centric medical record request process using Persona’s NIST IAL2-certified identity proofing solution

Frequently asked questions

Toggle description visibility

What is TEFCA and why is it important?

Toggle description visibility

The Trusted Exchange Framework and Common Agreement (TEFCA) establishes a common framework for securely exchanging electronic health information across certain health networks. Historically, health records have been fragmented across regional, state, and vendor-specific networks that do not always connect. TEFCA makes it easier for patients and providers to access records wherever they are held.

Does Persona support TEFCA?

Toggle description visibility

Yes. Persona is a Kantara-certified Credential Service Provider (CSP) for the Trusted Exchange Framework and Common Agreement (TEFCA), serving Individual Access Service (IAS) providers in two key ways:

  • NIST Identity Assurance Level 2 (IAL2) identity proofing: Persona verifies patient identity at IAL2 standards using a pre-built inquiry template optimized for patient matching, with a mobile-first experience.

  • ID token issuance: After a patient completes verification, Persona generates a signed OIDC ID token containing the patient's verified demographics. IAS providers use this token in TEFCA exchange requests.

This enables IAS providers to meet TEFCA requirements without building identity proofing infrastructure from scratch.

The DEA's final Special Registration rule still isn't published. Should we wait before building out our verification infrastructure?

Toggle description visibility

No, waiting is one of the higher-risk positions a digital health company can take. As of July 10, 2026, the fourth extension of the telemedicine flexibilities is set to run through December 31, 2026. Vendor selection, Business Associate Agreement (BAA) negotiations, legal review, technical integration, and staff training can each take months to complete. The proposed Special Registration rule already signals what requirements will look like: government-issued photo ID capture and verification at multiple points in the prescribing journey. Companies that use the DEA telemedicine extension period to build audit-ready infrastructure now won't be racing to catch up when implementation timelines are compressed.

How does Persona handle identity verification for controlled-substance prescriptions?

Toggle description visibility

Persona supports step-up verification flows that trigger stronger identity checks ahead of controlled-substance prescribing or refill workflows. This is configurable to your clinical context and can be adapted as DEA telehealth rules and state-level drug prescription laws evolve. You won’t need to rebuild your verification flows each time a regulation changes; instead, you reconfigure them in Persona's no-code Flow Editor.

Can Persona verify clinicians, not just patients?

Toggle description visibility

Yes. Persona supports verification of both patients and clinicians. For clinicians, this typically means government ID and selfie matching before granting access to prescribing systems or sensitive patient records.

Persona's platform can also be configured to support NPI-based verification: clinicians enter their NPI number during onboarding, a custom workflow queries the NPPES registry, and the name returned is cross-referenced against the name on their government ID. This helps confirm that the person completing verification is the licensed provider they claim to be.

Will adding identity verification hurt my patient conversion rate?

Toggle description visibility

Not when friction is matched to risk. With Persona's Dynamic Flow, you can calibrate verification to context - lower-risk patients, like those completing standard onboarding, move through with minimal steps, while higher-risk moments, like a first controlled-substance prescription, trigger stronger checks. The result: legitimate patients convert quickly while bad actors face escalating barriers.

What happens to patients who struggle to complete a digital verification flow, such as elderly, Medicaid, or low-tech populations?

Toggle description visibility

Patients get configurable retries with real-time guidance; unresolved cases route to another step or to your team for review. Persona provides dynamic retry screens based on what went wrong, such as prompting patients to improve lighting, reduce glare, move closer, or steady their camera. This gives patients clearer guidance in the moment, helping them progress through the verification flow.

Can Persona capture insurance cards and other clinical documents?

Toggle description visibility

Yes, Persona supports automated insurance card capture and extraction and can capture additional document collection at intake. This reduces manual review time and helps accelerate care without adding a separate vendor for document collection.

Does HIPAA require us to have a BAA with our identity verification vendor before we can confirm who a patient is?

Toggle description visibility

Yes, if the vendor creates, receives, maintains, or transmits Protected Health Information (PHI) on your behalf. In that case, the vendor is generally considered a business associate, and a Business Associate Agreement (BAA) should be in place before PHI is shared. Whether identity verification data is PHI depends on the specific data flow and healthcare context. Persona offers a standard BAA for covered entities, but organizations should confirm their requirements with legal counsel.

What’s the engineering lift required to integrate Persona into a digital health platform?

Toggle description visibility

Integration can require anywhere from minimal to moderate engineering work, depending on your approach:

  • Hosted Flow: Little to no engineering resources are required to get started. Simply send patients a branded verification link by email or text. Production deployments typically involve some API work to generate links programmatically.

  • Embedded Flow: Embed verification directly within your web experience with just a few lines of code.

  • Mobile SDKs: Native development is required for iOS, Android, or React Native apps.

You can configure verification steps and routing logic directly with Persona's no-code template and workflow builder. For additional implementation support, speak with Persona’s support team or your account manager.