From KYC to patient identity: Why digital trust is becoming critical in healthcare
Abhinav Parashar, CEO and Co-Founder, Digio, highlights why healthcare needs to move beyond one-time identity checks to build trust across the patient journey
India’s healthcare system is being rebuilt around digital identity. Health IDs, linked records, teleconsultations, e-prescriptions and online claims are fast becoming the default way patients deal with providers, and a patient is increasingly a login and an ID number instead of a person at a desk. That shift raises a question the sector is only beginning to answer: how does anyone know the person behind the screen is who they say they are?
Think about how much of a patient’s care already happens on screens. Appointments are booked on apps, consultations take place over video, prescriptions arrive on phones and reports land in inboxes. The scale is already large. According to the Press Information Bureau (PIB), as of 17 September 2026 India had 97.61 crore ABHA IDs in operation, with 119.95 crore health records linked to them. The same PIB backgrounder reports more than 50 crore teleconsultations, including through the government’s e-Sanjeevani service. Every step assumes the organisation on the other end knows who the patient is. When that assumption is wrong, the damage does not stop at money. A wrong identity can attach the wrong medical record, prescription, diagnosis or insurance claim to a person.
Identity is a journey, not a gate
Traditional Know Your Customer (KYC) norms in banking treat verification as a checkpoint at the start of a relationship. Healthcare cannot work that way. In a few weeks, one patient may register at a hospital, get tested at a diagnostic lab, buy medicines at a pharmacy, consult a doctor online and file an insurance claim.
The cost of getting this wrong is visible in public data. The Comptroller and Auditor General of India (CAG), in Report No. 11 of 2023, audited Ayushman Bharat PM-JAY for the period September 2018 to March 2021. It found that ₹6.97 crore had been paid for the treatment of 3,446 patients who were already shown as deceased in the scheme’s database. The same audit found about 7.5 lakh beneficiaries registered against a single mobile number, 9999999999. The audit pointed to weak validation controls, and recorded the National Health Authority’s response that checks had been put in place. From an identity verification point of view, the lesson is that a record accepted once and never tested against later activity stops being reliable. The real risk sits in the gap between the person, the record and the transaction.
A better model is to establish identity once and then recognise the patient reliably at every touchpoint. That means a trusted identity layer sitting beneath registration, consultation, diagnostics, pharmacy, insurance and payments, so patients are not asked to prove themselves again and again.
India has already laid part of this groundwork. The Ayushman Bharat Digital Mission (ABDM), implemented by the National Health Authority, and its 14-digit Ayushman Bharat Health Account (ABHA) number are meant to give individuals a persistent digital identity within an interoperable, consent-based health system. But an identifier alone does not settle the matter. The system also needs confidence that the person using an ABHA number is the person it belongs to. Identity verification, authentication, consent and auditability fill that gap.
How identity fraud shows up
The forms vary. Someone may impersonate another person to get treatment or medicines. Duplicate patient records may be created. Insurance and reimbursement claims can be fraudulent. Synthetic identities and digitally altered documents can slip past a check that only looks at a scanned copy. Accounts on patient platforms can be taken over, and health records can end up linked to the wrong individual.
The scale of the losses shows why these matters. A report by Boston Consulting Group (BCG) and Medi Assist, titled From Suspicion to Solution: A Strategic Approach to Health Insurance Fraud, estimated annual claim payout losses of ₹8,000 to ₹10,000 crore from fraud, waste and abuse in India’s health insurance sector. Not all of that is identity fraud, but identity is the first thing a fraudulent claim has to get past. Data breaches add to the exposure. IBM’s 2025 Cost of a Data Breach report found that healthcare breaches were the costliest of any sector for the 14th year in a row, averaging US$7.42 million, and took the longest to identify and contain, at 279 days on average.
Checking whether a document looks genuine is no longer enough. The industry needs to think in terms of identity assurance, which asks a tougher question: is the person presenting this document really the person it describes?
What healthcare can borrow from financial services
Banks moved from asking for an ID card to combining several signals, including document checks, database lookups, liveness tests, face matching, device and location data, recorded consent and audit trails. Healthcare can adopt a similar layered approach where it fits. A digital journey might begin with trusted identity sources and OCR-based document authenticity checks, then add liveness detection and face matching. Consent can be captured along the way, and activity logs kept for review. Unusual cases can be escalated while ordinary ones pass through.
Keeping verification simple for patients
This is where healthcare differs from banking. Patients are not customers filling in a loan form by choice. They may be elderly, unwell, anxious or new to smartphones. If verification turns into a hurdle, some people will simply go without care. Assisted journeys matter here as well. A family member, a front-desk staff member or a community health worker often completes the digital steps on the patient’s behalf, so verification has to work when someone else is holding the phone, while still confirming that the patient has agreed.
Routine journeys stay simple, and stronger checks come in only when the risk calls for them. Done well, this cuts repetitive paperwork and makes the system safer.
Verified identity and access are different things
Confirming who a patient is solves only part of the problem. The harder part is deciding what each person in the chain can see. A doctor and an insurer may both need something from a patient’s record, but not the same things and not for the same reasons.
This matters under India’s Digital Personal Data Protection (DPDP) Act, 2023, which puts weight on lawful processing, notice, consent, purpose limitation, data security and individual rights. Healthcare organisations need to treat identity, authentication, consent and authorisation as separate layers that work together. A verified identity should never turn into blanket access to someone’s health information.
The data involved covers medical records, diagnostic reports, prescriptions, insurance details and payments, so a breach reaches far beyond ordinary account fraud.
Consent also has to mean something. Patients should be able to see what personal data is collected and why, and, where consent is the basis for processing, use the choices and rights available to them. That takes consent out of the tick box at the end of a registration form and into the workflow itself, captured at the right moment, tied to a purpose and backed by records. ABDM’s consent-driven design points the same way, with data exchange built around trust, purpose and patient control rather than simply moving files between systems.
Digital trust is core
One episode of care can touch a hospital, a lab, a telemedicine provider, a pharmacy and an insurer. As more of these steps move online, each organisation needs a dependable way to confirm who the patient is, record what the patient has agreed to and make sure information reaches only the people who should see it. Standards and digital public infrastructure give the sector a base to build on. The work of putting identity and consent into everyday journeys still sits with individual organisations.
Patient identity is fast becoming a core part of digital trust in healthcare. When patients can be identified with confidence and their data is used only for the purpose they agreed to, digital care becomes safer and easier to use. Consent has to hold across every touchpoint, not just the first one.
- Advertisement -