QR code verification in healthcare means embedding a cryptographic signature in a scannable code printed on medical documents — prescriptions, lab results, sick-leave certificates — so that any smartphone can confirm the document is genuine, unaltered, and issued by a verified provider.
A pharmacist in Dubai receives a prescription for 120 tablets of tramadol. The letterhead looks right. The doctor's stamp is there. But something feels off. Without a way to verify the document against the issuing clinic's records, she has two choices: dispense a controlled substance on the strength of a piece of paper, or call the clinic and wait on hold.
A company HR manager in Riyadh receives a sick-leave certificate for an employee who was absent for a week. The clinic name matches a real facility. The dates are plausible. But she has no way to confirm the document wasn't produced in ten minutes on a home printer.
These are not edge cases. Document fraud in healthcare — forged prescriptions, fabricated sick-leave notes, altered lab results — is a significant and growing problem across the GCC and globally. QR code verification is the most practical solution that exists today.
How forged medical documents cause real harm
The consequences of document fraud in healthcare extend well beyond financial loss or administrative inconvenience. Forged prescriptions for controlled substances — opioids, benzodiazepines, stimulants — contribute directly to drug diversion and addiction. A single forged prescription can yield hundreds of units of a controlled medication.
Fabricated sick-leave certificates and fitness-to-work clearances undermine employer trust, distort insurance claims, and — in safety-critical industries like aviation, construction, and healthcare itself — create genuine physical risk when unfit workers are certified as healthy.
Altered lab results can lead patients down the wrong clinical path. A manipulated cholesterol panel might be used to obtain insurance. A falsified pathology report might be used to avoid a required medical clearance. In each case, a downstream decision is made on the basis of information that was never real.
- Controlled substance diversion through forged or duplicated prescriptions
- Insurance fraud via fabricated diagnoses and treatment records
- Employment fraud via falsified fitness-to-work certificates
- Border health fraud via forged vaccination certificates
- Academic and licensing fraud via fabricated medical fitness clearances
What makes a QR code cryptographically verifiable
A plain QR code is just a link. Anyone can generate a QR code that points to a fake website. Cryptographic verification is what makes the difference between a QR code that is merely convenient and one that is actually trustworthy.
When Looms issues a medical document — a prescription, a lab result, a sick-leave certificate — it generates a unique digital signature for that specific document at the moment of issue. The signature is derived from the document's content using a private key held by the issuing clinic. It is encoded into a QR code printed on the document.
When someone scans that QR code, the Looms verification server checks three things: that the document was issued by a real, verified clinic on the platform; that the document content has not been altered since it was issued; and that the QR code has not been revoked (for example, if the prescription was already dispensed or the sick leave was cancelled).
What the scanner sees
Verification is intentionally simple for the person doing the scanning. A pharmacist, HR manager, school nurse, or border health officer scans the QR code with any smartphone camera. Within two seconds, they see:
- A green verified badge if the document is authentic and unaltered
- The issuing clinic's name and verified status
- The document type (prescription, sick leave, lab result, certificate)
- The issue date and, for time-limited documents, the validity period
- A masked version of the patient's name confirming it matches the person presenting the document
What the scanner does not see
Privacy is built into the verification system by design. The public verification endpoint — what anyone with a scanner can see — reveals only what is necessary to confirm authenticity. It does not expose the patient's full medical record, their diagnosis, their medication history, or any other health information beyond the specific document being verified.
A pharmacist verifying a prescription sees that the prescription is genuine — not the patient's complete medication list. An employer verifying a sick-leave certificate sees that the certificate is real — not the underlying diagnosis. This separation of verification from disclosure is fundamental to the system's design.
"Verification should tell you the document is real — nothing more. The patient's other health information is not the verifier's business."
Sara Mansour, Product Lead, Looms
Verified issuers: the other half of the equation
Cryptographic signatures are only as trustworthy as the entity that holds the signing keys. A forger could, in principle, set up a fake clinic on a platform, issue fraudulent documents, and sign them with their own key — producing verifiable but fraudulent records.
Looms addresses this through a verified issuer programme. Clinics and laboratories on the platform must submit licensing documentation and undergo an identity review before they can issue verifiable documents. The verified issuer badge — visible on every document they issue — tells anyone scanning the QR code that the issuing entity has been checked against regulatory records.
Unverified providers can still use the platform for patient management and record-keeping — but their documents do not carry the verified issuer badge, and the verification page makes this distinction explicit.
Practical applications by sector
QR verification is already in use across a range of healthcare and adjacent settings.
| Setting | Document type | Who scans | What they verify |
|---|---|---|---|
| Pharmacy | Prescription | Pharmacist | Genuine issue, not already dispensed, correct prescriber |
| Employer / HR | Sick-leave certificate | HR manager | Genuine issue, valid dates, verified clinic |
| School / university | Medical fitness clearance | Admin office | Genuine issue, valid at date of submission |
| Border / airport | Vaccination certificate | Health officer | Genuine issue, correct vaccine, valid period |
| Insurance | Lab result or diagnosis letter | Claims processor | Genuine issue, unaltered content |
| Sports federation | Medical clearance to compete | Medical officer | Genuine issue, verified provider |
How to start using verified documents
For clinics and laboratories, issuing verifiable QR documents requires joining the Looms platform and completing the verified issuer review. Once approved, every document you issue — prescription, lab result, certificate, or report — automatically carries a signed QR code. No extra steps, no separate workflow.
For patients, every document issued to you through Looms appears in your health record with its QR code intact. You can show it digitally from your phone or download a signed PDF for printing. The code never expires as long as the document remains valid, and you can share it with anyone who needs to verify it.
The technology that was once available only to government-issued identity documents — passports, driving licences, vaccine certificates — is now available for every prescription and every sick-leave note issued by any verified clinic on the platform.