Healthcare & Digital Health

A patient photo is now a clinical input. Treat it like one.

Digital health platforms make eligibility, triage and prescribing decisions from photographs patients upload — and reimbursement decisions from documents providers submit. When either can be generated, the clinical and financial risk are the same risk. TruthScan validates both.

Seconds End-to-end verdict
2 APIs Image and PDF, purpose-built
Heatmaps Evidence for every decision
Patient-submitted photo analyzed for AI generation

THE THREAT

When a photo decides eligibility, a generated photo decides it too.

Digital health moved intake, triage and eligibility onto the patient's phone. That was the right call clinically and the right call commercially — but it quietly made a photograph into a control. Patients seeking a prescription they do not qualify for, or a treatment their condition does not warrant, now have a tool that produces exactly the image the eligibility rule is looking for. On the reimbursement side, the same generative capability produces medical invoices and lab documentation that are structurally perfect and clinically fictional.

In seconds

End-to-end verdict, fast enough to run inside an intake flow without adding perceptible latency for the patient.

2 APIs

Image detection for patient photos; PDF detection for medical invoices, prescriptions and lab reports.

Both Sides

Region-level evidence a clinical reviewer can act on, rather than an unexplained score.

ATTACK PATTERNS

Three attack patterns in digital health

Two clinical, one financial. All three arrive as an ordinary upload from an ordinary account.

Eligibility photo used to qualify for treatment

The eligibility photo

A patient uploads a generated image of a condition they do not have, in order to qualify for a medication, a treatment or a coverage decision that their actual clinical picture would not support. The reviewing clinician sees a photograph and reasons from it, because reasoning from photographs is what the workflow asks them to do.

WHY THIS ONE IS DIFFERENT

This is not a financial loss in the first instance. It is a patient obtaining a medication they should not receive.

Fabricated clinical progress photo

The progress photo that shows progress that did not happen

Programs that gate continued treatment, reimbursement or subscription on documented improvement create an incentive to document improvement. Generated or manipulated progress imagery corrupts both the clinical record and any outcomes data built on top of it.

SECOND-ORDER DAMAGE

Fabricated progress photos do not just cost money. They poison the outcomes dataset the program is evaluated on.

Forged medical invoice and prescription documents

The OCR-clean forged medical invoice

On the reimbursement side: medical invoices, superbills, prescriptions and lab reports generated end to end. Correctly coded, arithmetically valid, formatted exactly as the claimed provider's system would format them — describing care that was never delivered.

WHY CLAIMS SYSTEMS APPROVE IT

Adjudication engines validate coding and format. A generated superbill is correctly coded and correctly formatted. That is the whole problem.

THE ENGINES

Two detection engines. Two purpose-built APIs. One platform.

Photos and documents require different forensic models and APIs — unified in one dashboard and one contract.

IMAGE DETECTION API

Validates patient-submitted photos

Confirms that an image used for a clinical or eligibility decision was captured by a camera, not produced by a model.

  • Generative and in-painting detection on patient-submitted imagery
  • Capture-provenance analysis: EXIF, device fingerprint, render artifacts
  • Region heatmaps a clinical reviewer can interpret
  • Runs inside intake without adding perceptible latency

PDF DETECTION API

Scores medical documentation

Invoices, superbills, prescriptions, lab reports and prior-authorization documents.

  • Detects fully generated documents that were never issued by a real system
  • Template-reuse matching across your own submission history
  • Structural and object-layer forensics beneath the coded text
  • Batch mode for retroactive audit of reimbursements already paid
They are separate APIs, called separately. A single fraudulent submission usually carries both a photo and a document, so most teams call both and merge the verdicts in their own decision layer. End to end, the whole process takes one to two seconds.

WHERE IT SITS

Inside intake and inside adjudication

Two insertion points, one platform: the patient-facing photo at intake, and the provider-facing document at reimbursement.

STEP 01

Photo submitted at intake

Patient uploads a condition, eligibility or progress photo.

STEP 02

Image scored

The Image API returns a verdict and heatmap in one to two seconds — before the clinician reasons from it.

STEP 03

Documents scored at adjudication

The PDF API scores invoices, superbills and lab documentation on the reimbursement path.

STEP 04

Clinical review, better informed

Flagged submissions route to a human with evidence attached. Detection ranks; clinicians decide.

DEFENSIBILITY

Evidence a clinician can reason about

In a clinical setting an unexplained score is worse than useless — it asks a reviewer to override their own judgment on the authority of a black box. Heatmaps make the signal inspectable.

Detailed AI analysis report for clinical review
  • Heatmaps for clinical review. The reviewer sees which region of the image drove the verdict, and can weigh it against the rest of the presentation.

  • Detection never makes the clinical decision. It flags an authenticity problem with an input. A clinician decides what that means for the patient.

  • Retained provenance. Verdict, model version and timestamp attach to the record, which matters when the record is a medical one.

  • Retroactive audit on the financial side. Batch-scan reimbursements already paid to size the documentation-fraud exposure.

COMPLIANCE & DEPLOYMENT

Built for regulated health data

AICPA SOC certification seal

SOC 2 Type II

Audited controls

Independently audited security, availability, and confidentiality controls, renewed annually.

ISO 27001 certification seal

ISO 27001

Certified ISMS

Certified information security management across the full platform and API surface.

GDPR compliance seal

GDPR

Privacy-first processing

DPA available. Enterprise customers can pin processing to the EU.

Regional or on-site deployments seal

Global Infrastructure

Regional & On-site

UK, EU and on-premise deployments for Enterprise.

TECHNOLOGY FEATURED IN

Forbes logo
Business Insider logo
Nature logo
CBS News logo
Yahoo logo
BuzzFeed logo

Forensic Grade AI Fraud Prevention

Get full forensic reports - heat maps, key indicators, and detailed descriptions.

Free

$0/month

Try the full engine

  • 25 results/month (images + PDF pages)
  • Detailed indicators on every result
  • Full API access
  • Detection history in dashboard
  • Free forever — no trial period

Starter

$24/month

$0.03 / result - $290/yr

For individuals and small teams

  • 1,000 results/month included
  • $0.03 per additional result
  • CSV export of result history
  • Batch uploads
  • Audit-ready detection reports
  • Standard support
MOST POPULAR

Professional

$83/month

$0.02 / result - $990/yr

For teams in production

  • 5,000 results/month included
  • $0.02 per additional result
  • Priority processing queue
  • Higher API rate limits

Business

$333/month

$0.01 / result - $3,990/yr

For high-volume operations

  • 40,000 results/month included
  • $0.01 per additional result
  • Zero Data Retention (ZDR)
  • Highest self-serve rate limits
  • Priority support

Enterprise

Customize a Plan For Your Needs

$0.005 or less per result

Contact Sales
  • Discounts scale with volume
  • Custom SLAs with service credits
  • Zero Data Retention (ZDR)
  • Custom integrations
  • Custom MSA and DPA
  • Dedicated throughput
  • Named 24/7 account team
  • Dedicated / on-prem deployment

No hard quota walls — usage is simply metered at your plan's rate. Custom contracts, SLAs, DPAs, and hosting environments are available exclusively on Enterprise. All plans include SOC 2 Type II compliance.

FAQ

What clinical operations and integrity teams ask us first

Validate the photos your clinicians are already reasoning from.

Send us a sample of intake images and reimbursement documents. We will run both engines and show you what came through generated.

NO CARD REQUIRED · UNLIMITED SEATS ON EVERY PLAN · SOC 2 TYPE II · ISO 27001 · GDPR