The licence is real. The nurse is not.
In the credential fraud case known as Operation Nightingale, the licences were not forged. They were genuine licences, issued by real state boards, to people who had bought the paperwork that got them in the door. Every verification a hospital could run came back clean, because there was nothing wrong with the record. The wrong thing was upstream of it.
It is a Tuesday night and you are the charge nurse on a medical surgical floor that is three people short. The agency has sent someone. She is pleasant, she is on time, and her paperwork is immaculate.
You do what your medical staff office told you to do, which is what every hospital in the country does. You take the licence number and you look it up in the state board's public verification system. It resolves. Active, in good standing, no disciplinary history, issued three years ago, expiring next year. The agency has already run a primary source verification through their credentialing vendor and the result is in the file, signed and dated. The background check is clean. The diploma is on record with the school.
Every single one of those checks is working exactly as designed. Every one of them returns the correct answer. And the correct answer, in a small number of cases that we now know about because federal prosecutors found them, is a licence that should never have existed, worn by somebody whose education never happened.
This is the cleanest illustration in professional credentialing of a problem that shows up everywhere once you learn to see it. Verifying a credential and verifying a person are two different operations. Almost every system in the regulated professions performs only the first one, then behaves as though it performed both.
What actually happened in Operation Nightingale?
In January 2023 the United States Department of Justice announced a coordinated federal enforcement action, carried out with the Department of Health and Human Services Office of Inspector General and other agencies, against a scheme that sold fraudulent nursing education credentials. The paperwork originated with a set of Florida based nursing programmes. Buyers received diplomas and transcripts attesting to education and clinical hours that they had not completed. The Department of Justice announced further charges in a subsequent phase of the investigation in 2025.
The number of fraudulent diplomas and transcripts involved has been widely reported as being in the several thousands, with figures around seven and a half thousand appearing across coverage of the initial announcement. Treat that figure as reported rather than settled: different releases and different outlets have counted different things, some counting documents, some counting individuals, some counting only those who went on to obtain licences. The exact number matters far less than the mechanism, and the mechanism is what this piece is about.
The part that makes this different from forgery
Here is where most coverage of the case stops short, and where the interesting part begins.
The scheme did not sell fake nursing licences. Selling a fake licence is an old crime and a relatively easy one to catch, because the fake does not appear in the register. Any employer who looks it up finds nothing, and the fraud collapses at the first check.
What the scheme sold was the prerequisite. A nursing licence in the United States requires, broadly, that you complete an approved education programme and then pass a licensing examination. The diploma and transcript are the evidence for the first requirement. Buy those, and you become eligible to sit the examination. Sit it, pass it, and the board issues you a licence.
That licence is genuine. It is genuinely issued, by the genuine board, and recorded in the genuine register. It will verify correctly for as long as it remains active, in every system, every time, for the rest of the licensee's career. There is no forgery to detect anywhere downstream, because after the point of purchase nothing was forged.
Think of it as a counterfeiter who never prints a banknote. Instead they persuade the mint to print one for them, with a serial number the mint records in its own ledger. Every note detector in the country will pass it, correctly, because it is not counterfeit. The failure happened in the room where the decision to print was made, and nothing downstream of that room can see it.
Why did every verification succeed?
Because each verification in the chain was answering the question it was designed to answer, and none of them was answering the question that mattered.
Credentialing is a chain of trust, and like all chains of trust it has the property that every participant is relying on an assertion made by the participant upstream. A hospital trusts the board. The board trusted the school. The school attested to the graduate. And at every single hop, the thing that binds the assertion to a specific human being is a document with a name on it.
Documents are the weak link, and they have always been the weak link. What has changed is the cost of producing a convincing one, which is now close to zero, and the ease of finding a complicit issuer, which turns out to be a market.
Here is the chain, hop by hop, with what breaks and what could hold it.
| Hop | What is asserted | How identity is bound today | Failure mode | Possible control |
|---|---|---|---|---|
| Applicant to school | This person enrolled and studied here | Enrolment paperwork, in person attendance in theory | Complicit or captured school issues records for people who never attended | Enrolled key at admission, signed attendance and clinical hour records |
| School to board | This named person completed the programme | Transcript and diploma, sometimes sent directly | Genuine looking documents for education that did not occur | School signs the transcript to a key the graduate holds, not just to a name |
| Board to exam | This applicant is eligible to sit | Documentary eligibility review, identity document at the test centre | Eligibility granted on fraudulent prerequisites | Bind the application to the applicant's key, carry it into the exam session |
| Exam sitting | This candidate passed | Identity document check at session start | Proxy test taker, swap after the check | Session continuity, covered in the proxy test taker piece |
| Board to licensee | This person is licensed | Name and licence number in a register | Licence is genuine but the basis was not | Binding attestation recording which key the licence was issued against |
| Employer verification | This licence is real and active | Primary source lookup by number | Confirms the record, not the presenter | Check a live proof from the bound key alongside the lookup |
| Shift after shift | The licensed person is working | Nothing after onboarding | Credential sharing, agency substitution, no re-check for years | Signature at shift start and on high consequence acts |
| Status change | The licence is still valid | Periodic re-credentialing, cached results | Revoked licence keeps verifying, covered in credential zombies | Short lived status attestations |
Read down the failure mode column and notice something uncomfortable. Only one row describes a forged artifact. Every other row describes a system working correctly on an input that was true in form and false in substance.
What is the difference between verifying a credential and verifying a person?
It helps to separate three questions that credentialing routinely collapses into one.
Question one: does this credential exist and what is its state?
This is the question primary source verification answers, and it answers it well. Nursys, run by the National Council of State Boards of Nursing, exists precisely so that an employer can check licensure against the boards rather than against a photocopy. State board portals do the same thing. This is genuinely valuable infrastructure and it has stopped a great deal of ordinary forgery.
Question two: is the person in front of me the person this credential was issued to?
Nothing in the credentialing stack answers this. The employer's answer is a government identity document checked once at onboarding by a human being who is not a document examiner, matched by name against a register entry that contains a name. Names are not identifiers. They collide, they change, and they can be adopted.
Some employers add identity verification at hire, which is better, and which is still a single moment. It establishes that on the day of onboarding, somebody presented a document that matched their face. It establishes nothing about the following Tuesday.
Question three: was this credential legitimately obtained?
Nothing answers this either, and this is the one Operation Nightingale turned on. The register cannot tell you, because the register only knows what the board recorded, and the board recorded what it was told. Re-credentialing every two or three years re-asks question one and skips the other two entirely.
The uncomfortable summary is that a credentialing file which is complete, current, and fully compliant with the standards a hospital is surveyed against can describe a person who is not qualified and is not the person named. Compliance and assurance are not the same property, and in credentialing the gap between them is wide.
Does primary source verification confirm identity?
No, and it does not claim to. This is worth stating plainly because the phrase sounds like it should. Primary source verification means the information was obtained from the body that issued it rather than from the applicant, which removes the applicant's ability to alter it in transit. That is the entire promise, and it is a real one.
The confusion is understandable. If you ask a medical staff professional whether a nurse's credentials have been verified, the honest answer is yes, and the honest answer is also that verification was of records rather than of the human being. Both are true. The industry has simply never had a vocabulary that separates them, which is why the distinction disappears in practice.
The same collapse happens across every regulated profession. Bar admission, engineering licensure, pilot certification, financial adviser registration, and pharmacy licensure all run on the same shape: a register keyed by name and number, checked by lookup, with identity established once by document if at all.
How does a real licence end up on the wrong person?
Fraudulent issuance is the dramatic case. The mundane cases are more common and, in aggregate, probably more costly.
The borrowed number
A licence number is a public identifier. Boards publish them deliberately, so that patients and employers can check. That transparency is correct and should not change. It also means that anybody can select a real, active, clean licence belonging to a real nurse, and present themselves under that name to an employer who will verify it successfully. The honest licensee finds out when a disciplinary matter arrives for care they did not provide.
Agency staffing and the substitution problem
Travel nursing and agency staffing spread licensees across employers and states, often through the Nurse Licensure Compact, which lets a nurse practise across participating states on one multistate licence. The compact is good policy and it solves a real mobility problem. It also means the relationship between the human and the employer is thin and short, often mediated entirely by an agency, and the person who was credentialed in January may not be the person who arrives in June.
This is the same failure that appears in gig platform account renting and in the workforce continuity problem covered in the continuity piece. Verification happens at a boundary, work happens over a duration, and nothing connects the two.
Telehealth and the invisible clinician
Remote care removes the last informal control, which was that colleagues on a unit tend to notice things. In a telehealth encounter the patient sees a video window and a name badge graphic. The clinician's identity is asserted by the platform, and the platform asserted it based on onboarding paperwork.
Why will digitising licences make this worse before it makes it better?
Boards are beginning to issue digital credentials, using formats such as W3C Verifiable Credentials and the ISO mobile document standards. This is a genuine improvement over a PDF and a register lookup, and the people doing it are serious.
It also carries a specific risk that is worth naming early, while the pilots are still small enough to change. A verifiable credential is cryptographically checkable, which means a verifier can confirm with certainty that the issuer issued it and that it has not been altered. If that credential is bound only to a name, then what the verifier now has is mathematical certainty about a claim whose link to the human in front of them is exactly as weak as it was on paper, and considerably more persuasive looking.
A perfectly verifiable credential carried by the wrong person is a perfectly verifiable lie. The cryptography does not make the lie true, it makes it faster to check and harder to question. That is the contrarian point of this piece, and it is the reason binding needs to be in the design now rather than added later.
The same distinction runs through offline credential verification, where the question is what a credential can prove without phoning home. Signature verification tells you the issuer signed something. It cannot tell you who is presenting it.
What would credential binding actually look like?
The proposal is narrow. Leave the credential where it is. The board remains the issuer and the register remains the source of truth. Add one artifact: a record that the credential was bound, after a live check, to a key that the licensee controls.
A binding attestation is a small signed object. It says that at a particular moment, a particular issuer or verifier confirmed that a live human, holding a specific key, was the person the credential describes, and it records how that confirmation was made.
{
"credential": "nur-fl-1180432",
"issuer": "did:web:board.example.gov",
"boundKey": "ed25519:9c4b7d21...e17a",
"boundAt": "2026-09-21T14:02:11Z",
"method": "live-capture + document match",
"assurance": "in-person",
"boundBy": "did:web:board.example.gov",
"revocationId": "bind-2026-4193"
}
That object is signed by whoever performed the binding. From then on, a verifier can do two things instead of one. They still look the licence up, because the register is still authoritative on status. They also ask the person in front of them to produce a fresh signature from the bound key, over a challenge that is specific to this moment.
// what the employer checks at shift start
lookup = board.status("nur-fl-1180432") // active? sanctions?
binding = board.binding("nur-fl-1180432") // which key?
proof = person.sign({
credential: "nur-fl-1180432",
purpose: "shift-start",
unit: "5-West",
at: "2026-09-21T18:58:04Z",
nonce: "b7f1c0a4"
})
verify(proof, binding.boundKey) && lookup.status == "active"
The verification is offline against a published key. It does not require the board to be reachable at two in the morning, which matters in a hospital, and it does not tell the board where the nurse is working, which matters for the same privacy reasons that made certificate status checking such a difficult problem on the web.
If you want the mechanics of how a per action signature is requested and verified, the developer documentation covers the call shape and the receipt format.
The signature is produced on the licensee's own enrolled device. Binding it there rather than to an employer badge is deliberate: the credential belongs to the person, follows them between employers and across compact states, and accumulates into a professional history that the licensee holds rather than one that dies with each job.
Where the signature is worth asking for
Not everywhere. Asking a nurse to authenticate every time they touch a chart would be both hostile and counterproductive, because controls that make care slower get routed around, and a routed around control is worse than no control because it also produces false assurance.
A short list is enough: the start of a shift with a new employer or after a gap, the signature on a controlled substance order, the attestation on a chart entry that will be relied on later, and any moment where an employer is taking on liability for someone they have not physically met. That is a handful of signatures a month for most clinicians.
What does this not fix?
A great deal, and being precise about it is the difference between a control and a claim.
It does not detect a fraudulently obtained credential at the moment of issuance. This is the most important limit and it deserves to be stated first, because it is the exact scenario the Operation Nightingale case describes. If a board is deceived about a candidate's education, binding the resulting licence to that candidate's key produces a correctly bound, genuinely issued, cryptographically verifiable credential that should not exist. Binding tells you the right person is holding it. It cannot tell you the paperwork behind it was true. The only cure for fraudulent issuance is the issuer verifying prerequisites properly, and no cryptography substitutes for that.
What binding does change, even in that scenario, is remediation. When investigators identified affected credentials, boards and employers faced the problem of working out which humans held them, across dozens of states and thousands of employment records, using names. With bindings in place that becomes a key lookup rather than an investigation, and the honest licensees whose numbers were borrowed can be distinguished from the people who bought paperwork.
It does not stop a licensee who binds their own key and then hands over their phone. Voluntary credential sharing between colleagues is real, usually well intentioned, and defeats any scheme that assumes possession of a device implies presence of a person. Liveness at binding and at high consequence moments raises the cost but does not eliminate it.
It does not evaluate competence. A bound credential proves the right human holds a valid licence. Whether they are safe to practise is a clinical governance question that no identity system touches, and anyone selling identity technology as a quality control is overselling.
It requires action by issuers, not just employers. An employer can bind at onboarding and get real value, and that is the practical starting point. The portable version, where a binding travels with the licensee across employers and compact states, needs boards to record bindings. Boards move slowly, are funded modestly, and have many priorities ahead of this. Any honest roadmap here is measured in years.
Manav has not shipped a board issuance integration or a verifiable credential binding. The per action signature, the companion device check with on device face matching, and the offline verifiable receipts are shipped and are what the employee verification demo exercises. The credential binding attestation described here is a proposal, and it is written as one.
What to do this week
None of this requires waiting for boards, standards, or vendors.
- Separate your two questions in writing. Go through your credentialing policy and mark every step as either credential verification or identity verification. Most policies will turn out to have one identity step, at onboarding, performed by someone whose job is not identity.
- Count the gap. For agency and travel staff, measure the elapsed time and the number of shifts between the identity check at onboarding and the most recent shift worked. That number is your exposure window, and in most organisations nobody has ever calculated it.
- Ask your credentialing vendor the direct question. Does your primary source verification confirm the identity of the person presenting the credential, or the existence and status of the record? Get the answer in writing. It will be the second one, and having it in writing changes the internal conversation.
- Check your revocation lag separately. Status and identity are different failures with different fixes. The status side is covered in credential zombies, and you should measure how stale your cached verification results are.
- Look at your highest consequence acts. Controlled substance orders, chart attestations, and anything a plaintiff attorney would subpoena. Ask what artifact you would produce to show which human performed it. If the answer is a username in an audit log, you have an attribution problem as well as an identity one.
- Pilot binding at onboarding for one population. Agency and travel staff are the right first cohort, because the relationship is thinnest and the turnover highest. Bind at onboarding, require a signature at shift start, and see what breaks operationally before you argue about the wider rollout.
- If you sit on a board or a standards group, ask about binding now. Digital credential pilots are being designed at the moment. Adding a field for a bound key while the schema is still in draft costs nothing. Retrofitting it after issuance costs everything.
Frequently asked questions
What was Operation Nightingale? A federal enforcement action announced by the United States Department of Justice in January 2023, conducted with the Department of Health and Human Services Office of Inspector General and other agencies, targeting a scheme that sold fraudulent nursing diplomas and transcripts issued through Florida based programmes. Buyers used the documents to become eligible for licensing examinations. Further charges were announced in a subsequent phase in 2025.
Does primary source verification confirm identity? No. It confirms that credential information came from the issuing body rather than from the applicant, and it reports the record's status. It does not establish that the person presenting the credential is the person it was issued to, and it cannot detect a credential that was genuinely issued on fraudulent prerequisites.
Can a nursing licence be used by someone else? In practice yes, because licence numbers are public by design and verification is by name and number. An impostor can present a real, active licence belonging to a real nurse, and the employer's lookup will succeed. The licensee usually discovers it only when a complaint or disciplinary matter arrives.
How can a hospital verify that a nurse is the person their licence belongs to? Verify the licence with the board as you do today, then bind it to the nurse's enrolled device after a live check, and require a signature from that device at shift start and on high consequence acts. The lookup answers whether the licence is valid, the signature answers who is holding it.
Will digital credentials solve credential fraud? Not on their own, and they may make one class of it easier. A verifiable credential bound only to a name gives a verifier cryptographic certainty about the issuer while leaving the link to the human as weak as it was on paper, and considerably more convincing. Binding to a key the holder controls is what makes the digital version an improvement.
Does this apply outside healthcare? Yes. Bar admission, engineering licensure, pilot certification, pharmacy, and financial adviser registration all use a register keyed by name and number, checked by lookup, with identity established once by document if at all. Healthcare has the best documented case, not the worst exposure.
What is the difference between this and the revoked licence problem? They are separate failures. A revoked licence that still verifies is a status freshness problem, addressed by short lived attestations. A genuine licence held by the wrong person, or obtained on false prerequisites, is a binding problem, addressed by tying the credential to a key. A system can fail either way independently.
Sources
- United States Department of Justice, newsroom. Announcements concerning Operation Nightingale and the prosecution of fraudulent nursing credential schemes.
- Department of Health and Human Services, Office of Inspector General newsroom. Participating agency in the Operation Nightingale enforcement action.
- Nursys, National Council of State Boards of Nursing. Primary source licensure verification for registered and practical nurses.
- National Council of State Boards of Nursing. The Nurse Licensure Compact and multistate licensure.
- The Joint Commission, standards. Credentialing and privileging requirements for accredited organisations.
- W3C Verifiable Credentials Data Model 2.0. The credential format being adopted in board and issuer pilots.
- ISO/IEC 18013-5. Mobile driving licence, the reference model for offline credential presentation.
A perfectly verifiable credential carried by the wrong person is a perfectly verifiable lie.