HCP resources  /  Beyond Health

How physicians can protect against physician impersonation and AI deepfakes

An illustration of a doctor in a white coat, shirt, and tie, wearing a lanyard against a purple background with abstract circles, styled as a physician impersonation.

Estimated reading time: 15 minutes

Nearly 1 in 5 physicians (19%) surveyed on Sermo say they’ve already been impersonated on a social media platform, and 8% say it damaged their reputation. 

Even among physicians who haven’t been targeted yet, more than a third (37%) think it’s only a matter of time before someone poses as them online, usually as part of a scam built to make money or otherwise benefit from their name. When members were asked what worries them most about impersonation, the answers split fairly evenly across legal complications (28%), harm to patients (25%), reputational damage (23%), and erosion of trust in the medical profession (23%).

Dr. Eleonora Teplinsky, a board-certified medical oncologist and Sermo Medical Advisory Board member, has been through it more than once. “I’ve been impersonated several times. A year and a half ago, someone messaged me on LinkedIn and said, ‘There’s someone on Facebook pretending to be you.’ It turned out there were multiple fake accounts across different platforms,” she shared on Sermo. Dr. Teplinsky discussed her experience in more depth in a Sermo webinar on managing misinformation and protecting your digital presence as a physician, which Sermo members can watch on demand.

Physician impersonation is already becoming common, and deepfake technology has made it convincing enough to fool patients. CBS News has documented more than 100 AI-generated doctor videos on social media pushing fake endorsements and telehealth consultations, many with millions of views. In April 2026, American Medical Association (AMA) CEO John Whyte described deepfakes that impersonate physicians as “not just scams” but “a public health and safety crisis.” 

One endocrinologist on Sermo emphasized this, saying, “As physicians become more visible online, our digital identity becomes part of our professional responsibility. Impersonation is not only a threat to personal reputation, but also to patient trust and safety. In an era where credibility can be copied in seconds, staying vigilant and educating our communities is more important than ever.” 

This article covers the practical steps that can make you a harder target for physician deepfakes and other scams, alongside what to do the day you find out someone is using your name. The threat of impersonation is not new to physicians, but it is evolving. More commonly known forms still need to be considered, including identity theft, fake credentials, and phishing scams built around a physician’s National Provider Identifier (NPI) and Drug Enforcement Administration (DEA) numbers.

Physicians on Sermo swap strategies for protecting their digital identity every day. Join the community to see how your peers are handling it. 

The AI deepfake threat to physician identity

Physicians have many good reasons to be online, from meeting patients where they already are to connecting with colleagues and becoming better known in their communities. But, the rise of advanced AI tools and the advent of deepfakes has exposed a downside to having this public footprint: being discoverable to actors with ill intent, who can use your public content as the raw material for fabricated video, audio, and images. AI tools are now capable of manufacturing content that never existed at all, right down to a believable video clip of you saying something you never said. This is what makes AI deepfake impersonation so dangerous. 

An ICU physician on Sermo put the risk in patient terms, “I don’t have a large social media presence, but I’ve seen colleagues deal with fake accounts using their credentials. The scariest part isn’t the reputational hit, it’s the patient who follows bad advice thinking it came from a real doctor. Staying vigilant and educating our patients to verify sources is probably the most practical thing we can do right now.”

How can AI deepfakes impersonate physicians?

The latest consumer-grade tools can clone a voice from a short audio sample and even animate a still photo into speaking video. According to one physician’s experience shared on KevinMD in December 2025, a LinkedIn profile photo and a few clips from podcast appearances were enough for scammers to produce a convincing impersonation. These fakes are built to make money off an unsuspecting public, typically following these steps:

  • Scammers scrape your face and voice from publicly available content like headshots, social media clips, or recordings from talks or interviews that you have given.
  • Your likeness is used to create content that recommends a supplement, device or “cure”, or even offer paid telehealth visits.
  • The clip is published from a duplicate account carrying your name and credentials, then gets pushed to patients through paid ads and direct messages.
  • Patients believing the content to be authentic then buy the supplement, pay for the “consultation,” or click a link that harvests their card details to perpetrate further fraud.

The AMA’s 7-point framework for protecting physician identity

Deepfakes move faster than the rules meant to stop them.

The AMA’s April 2026 framework, developed by its Center for Digital Health and AI, is explicit that institutions, vendors, and third-party apps must treat your identity as non-transferable, and that a clause buried in an employment agreement or terms of service doesn’t count as consent.

The framework comes down to seven principles:

  • Identity is legally protected: Your name, image, likeness and voice belong to you.
  • Consent must be affirmative and informed: Any use of your identity requires opt-in permission.
  • Fake endorsements are deceptive: Using your identity to imply you endorsed something should be treated as a deceptive practice.
  • Platforms must act on reports: Reported deepfakes must be taken down within a set timeframe.
  • Employers can’t transfer your rights: Institutions can’t hand your identity to vendors through employment agreements.
  • Physicians need meaningful recourse: There has to be a workable path to a remedy when your identity is misused.
  • Enforcement has to be accessible: A remedy only counts if an individual doctor can act on it without hiring a lawyer.

This is AMA policy rather than law, though, so enforcement is still running behind the technology. Physician identity has become a medicolegal issue in its own right, alongside the more familiar healthcare law concerns, and it’s worth reviewing your contract for any clause that hands your institution rights to your image, voice, or likeness.

An anesthesiologist on Sermo argued that social media platforms are getting off too easy. “In this era of ‘Dr. Google,’ I believe it’s crucial for medical professionals to establish an online presence. People want and need reliable health education. While verifying identity is a positive first step, it places the onus on patients and healthcare staff, inadvertently absolving the platforms themselves. A persistent scammer will inevitably find loopholes. It’s time for the government to set higher standards for social media platforms.”

Real cases of AI physician impersonation

“Any content of any sort that you provide puts you at risk of impersonation. They have your face, your voice. That’s it. All they need.”

Sermo member and dermatologist

For Dr. Teplinsky, the fake Facebook profiles weren’t the end of her impersonation story, and she later found a TikTok account using her name and credentials to sell paid consultations. The KevinMD piece quoted earlier came from a medical oncologist whose Facebook identity was cloned to sell fake cancer treatments. When she reported it, Facebook banned her instead of the scammers, and the fraudulent page kept operating. These are real-world examples of how your identity could be compromised. 

Building the fake takes minutes, while proving you’re the real physician can take weeks of reports and appeals, so it’s easy to see why Sermo members treat the risk as universal. “We are all targets,” one pediatrician on Sermo said.

Traditional physician impersonation: identity theft, fraud and credential misuse

Deepfakes may get the headlines, but “traditional” scams still cost physicians money, time, and peace of mind. They’ve grown right alongside the new technology—since so much of what a scammer needs is already public—and they’re often the more immediate financial threat. Beyond deepfakes, scams can often mean credential theft, phishing aimed at your practice, scam calls from fake investigators, and people with no medical training passing themselves off as doctors.

Common credential theft and impersonation scams

NPI and DEA number exploitation

The Centers for Medicare & Medicaid Services (CMS) issued a fraud alert in January 2025 about scammers faxing phishing requests for medical records on convincing CMS letterhead, pretending to be part of a Medicare audit, and the Michigan State Medical Society (MSMS) highlighted the same scheme in April 2026. Because NPI and DEA numbers are publicly searchable, they can be easy pickings for fraudulent billing and forged prescriptions.

Impersonation scams by phone and email

A physician writing for the American College of Osteopathic Family Physicians (ACOFP) in October 2025 described a call from a supposed investigator at the Iowa Board of Medicine, who claimed drugs had been seized at the Texas-Mexico border linked to his name and that the FBI had an active warrant for his arrest. Scripts like these are built to trigger panicked response. 

Fake physicians and fraudulent credentials

The oldest version of physician identity theft is someone simply pretending to be a doctor. In Los Angeles, Stephan Gevorkian allegedly falsified physician credentials and treated thousands of patients with life-threatening illnesses before he was charged. In San Diego, a man was arrested for impersonating an anesthesiologist at Sharp Grossmont Hospital while wearing surgical scrubs and a doctor’s coat with hospital logos.

An internal medicine physician on Sermo lived through the most unsettling version, a stranger practicing medicine under their name: “Someone was working there using my name, posing as a medical specialist. They even mentioned irregularities in his clinical practice and deficiencies in patient care. At that moment I understood that the problem was no longer just a crime against my professional identity, but a direct risk to human life. Someone was treating patients under a false identity and practicing a profession for which they were apparently not qualified.”

One cardiologist on Sermo turned their digital impersonation fears into a simple habit, “A colleague mentioned someone was using her headshot to run a fake ‘private consultation’ account. It took weeks to get it taken down. The scary part is how convincing these profiles look. I’ve started doing monthly reverse image searches just as a habit now. It takes five minutes and has become part of my routine. If you haven’t tried it yet, do it today. You might be surprised what comes up.”

How to proactively protect your physician identity

You can’t make yourself impossible to impersonate, but you can make it more difficult to do, as well as catch impersonation fraud sooner to limit the fallout when it happens.

Monitor your digital footprint

  • Google Alerts: Head to Google Alerts and enter your full name in quotes plus “MD” or “Dr.” to get an email whenever it shows up somewhere new.
  • Reverse image searches: Put your professional headshots into Google Images every month or two to catch anyone using your photo without permission. An obstetrician-gynecologist on Sermo described their routine: “I routinely do self google searches. Personal social media does not include any professional material or items. Professional social media only has work-related topics with no sharing of personal information.”
  • Platform sweeps: Search your name on Instagram, TikTok, Facebook, X, and LinkedIn. This is especially important on platforms where you don’t have an official account.
  • NPI and DEA monitoring: Periodically check your Medicare claims history and your state’s prescription drug monitoring program for activity you don’t recognize.

The CMS phishing fax scam mentioned above was aimed at the front desk rather than the physician, with an employee processing what looked like a routine records request, so it’s a reminder that these attacks can go after the whole practice. Everyone in your workplace needs to be ready. Put multi-factor authentication on every account, train staff to recognize phishing, set a verification protocol for any records or credential request, and write down a plan for the moment impersonation is detected.

A urologist on Sermo is already budgeting for it. “I can only imagine this is going to become more of a problem as AI matures. I will certainly pay for a service to monitor for impersonators.

 Build a professional online presence that you control

Going invisible online isn’t realistic for most physicians, because it would mean giving up the significant benefits of having a professional presence. When asked what motivates their online presence, 33% of Sermo members named sharing medical knowledge, 30% building professional connections, 20% promoting their practice, and 16% engaging with the wider community.

When it comes to reducing impersonation risk, limiting the personal information they share came out on top of the strategies at 38%, followed by relying on platform security features (27%) and regularly searching their own name online (18%). Nearly a third (33%) keep separate accounts for professional and personal use, and only 16% avoid sharing personal information on social media altogether.

The single most useful step is to secure your professional name on the major platforms even if you never plan to post, and to get verified where you can, including X, LinkedIn, and Instagram. An unclaimed username in your professional name can be an open door for an impersonator.

A general practitioner on Sermo made the case for staying visible while keeping firm boundaries, saying, “Beyond reputational damage, these situations can directly harm patients and weaken trust in the medical profession. Regularly monitoring one’s digital presence, clearly communicating official channels, and maintaining appropriate professional boundaries online have become increasingly important.”

A thoracic and general surgeon on Sermo keeps their footprint minimal for reasons that go beyond reputation. “My hospital system does push for online presence, and I certainly understand the business aspect, but I keep it to the absolute minimum. There has been one attempt at harming a physician in our hospital from a disgruntled family member, and that risk alone, not just for me but for family, is enough to make me minimize any personal info despite any benefit.”

Signs you may be being impersonated

Prevention only goes so far with a problem this widespread, so at some point you may need to recognize that something’s wrong and move quickly, first to get the account taken down and then to keep patients from being fooled in the meantime.

  • A patient or colleague mentions content, advice, or an account that has nothing to do with you
  • A duplicate profile turns up using your headshot, your credentials, or a near-miss spelling of your name
  • Reviews, complaints, or messages arrive from people who were never your patients
  • Records requests, prescription inquiries, or consultation bookings show up that you can’t account for
  • Claims, prescriptions, or registry activity appear under your NPI or DEA number that you didn’t authorize

How to respond to physician impersonation

Report the fake account to the platform right away, but document it first by screenshotting the profile, posts and any messages. This is important as accounts can be deleted or otherwise seem to vanish once they have been reported and you’ll want to ensure you have a record. 

Use the platform’s impersonation reporting form, ideally from your own verified account, then notify your institution, your state medical board, and the Federal Trade Commission (FTC), which tracks impersonation scams. If the fake account is taking payments, giving medical advice, or writing prescriptions in your name, treat it as urgent and escalate to law enforcement rather than waiting on the platform’s review.

How to warn your patients about fake physician accounts

Warning patients is part of the ethical duty that comes with this new territory, and the goal is to reach them before a scammer does.

  • Point patients to your official channels: Confirm which accounts are official and can be trusted. You may even want to post a note on your verified accounts and practice website along the lines of, “I do not offer consultations or sell products through social media” to make it clear. 

Inform your patients during in-person visits as well, since many patients may not be following your social media channels. 

  • Set expectations in person: Remind patients during appointments that real medical advice comes through the physician-patient relationship, not a direct message on social media or other unofficial channels. 
  • Encourage patients to check: If your patients encounter a suspicious message, phone call, or contact from someone claiming to be you, ask them to call your office before responding and verify the authenticity of the request. .  

Key takeaways

  • Nearly 1 in 5 physicians on Sermo have already been impersonated on social media, and more than a third of those who haven’t expect it to happen eventually.
  • AI deepfakes can fabricate content that never existed, while traditional scams keep exploiting publicly searchable NPI, DEA, and credential information.
  • The AMA’s April 2026 framework treats physician identity as protected and non-transferable, which makes your employment contract worth revisiting. 
  • Google Alerts, regular reverse image searches, claimed usernames, and minimal personal sharing are among the most effective monitoring steps.

Protect against online impersonation

Physician impersonation won’t slow down as the tools for pulling off these scams get more convincing. The threat now runs on two tracks: with deepfakes spreading across social media and old-fashioned credential scams persisting alongside them, both trading on the trust patients place in your name. The AMA has made physician identity a formal policy priority, but the law still moves slower than the technology, so most of the practical defense falls to you and your practice. The preventive habits that make the biggest difference are claiming the accounts that carry your professional name, periodically checking where your face and name turn up online and making sure patients know how to reach the real you.

Frequently asked questions

Can Physicians Sue Someone Who Impersonates Them Online?

You’re often within your rights to sue, but it depends on your location and if you can identify the impersonator, which is usually the hardest part. Depending on the state, potential claims include right of publicity (commercial use of your name or likeness without consent), defamation, and fraud. Always consult an attorney familiar with your state’s laws to confirm.

Does Malpractice Insurance Cover Physician Impersonation Damage?

Coverage varies by insurer and policy type. Malpractice policies are designed around claims tied to patient care, so reputational harm from impersonation usually falls under a separate liability category and may not be covered at all. Review your policy language and ask your carrier directly.

How Do AI Deepfake Detection Tools Work for Physicians?

Detection tools analyze video and audio for the artifacts generative AI still leaves behind, like irregular blinking or lip movements slightly out of sync with speech. These tools are best for confirming a clip you already suspect rather than finding fakes in the first place, so what’s more useful for a busy physician is a monitoring service that scans platforms for your face and name and alerts you when something appears.

Should Physicians Avoid Social Media To Prevent Impersonation?

For most physicians, the answer is no. Staying offline costs you the patient education, referrals, and networking that come with an online presence, and it doesn’t stop a determined scammer from using your name and photo anyway. Claiming and verifying your accounts usually protects you better than leaving them open.

Do Physicians Own The Rights to Their Professional Image and Likeness?

In most states, yes. Right of publicity laws give you control over commercial use of your name, image, and voice, though the specifics vary by state, and the AMA’s 2026 framework is pushing to make those rights explicit and non-transferable for physicians. The exception is an employment agreement that signs some of those rights over to your institution, so read those clauses closely before you sign.

Home » Resources » How physicians can protect against physician impersonation and AI deepfakes