It's easy to fake a vaccine card.
Because the U.S. government didn't have a more elegant vaccine passport system in place when it rolled out COVID-19 vaccines earlier this year, CDC cards are what we got. The cards — or a photo or copy of them — will generally get us into the office, or a bar, or out of the Honolulu airport.
Unless something more high-tech and instantly verifiable becomes standard. That's what the Vaccination Credential Initiative is working to accomplish with QR code-based SMART Health Cards — already available in California, New York and Louisiana — as vaccine mandates become a bigger part of life in America.
"The two keys are, one, addressing the potential for fraud," said JP Pollak, the co-founder and chief architect of the Commons Project Foundation, a driving force behind VCI and SMART Health Cards. "The second is just efficiency in the system. CDC cards, if you want to use them for travel or to prove your status to a workplace, somebody has to interpret these things, and that takes time."
A niche between Big Tech, startups and government
Pollak, a Cornell University researcher who develops systems to capture health data, co-founded the nonprofit Commons Project in 2019. Now funded by the Rockefeller Foundation, the Commons Project expanded upon his team's work to build, essentially, an Android version of Apple Health.
The 70-person nonprofit has product and engineering teams that previously worked at large tech companies, but no shareholders or investors to pay. "We try and sort of fit in a niche between the kinds of things that big tech companies do, what startups do and what governments can't necessarily do," Pollak said. "The kinds of things that maybe utility operators would do in the physical world: There's not really a digital equivalent to that."
When the pandemic hit, Pollak and the Commons Project saw an application for their expertise in building these sorts of tools. The Commons Project then launched VCI alongside partners at Apple, Microsoft, Cigna, the Mayo Clinic and the Mitre Corporation, a nonprofit that does R&D for a number of federal agencies.
To these ends, the Commons Project and VCI designed SMART Health Cards, the specification behind the digital vaccine passports that are already available to people who were vaccinated in California, New York or Louisiana. SMART Health Cards verify a user's vaccination status with any of hundreds of health systems and providers, including Walmart, CVS, Walgreens, Epic and Cerner, spitting out a QR code that users can print or store on a mobile device.
Scanning the QR code shows that the vaccination record came from a trusted source like a major pharmacy, "and not some sort of sketchy fraudster organization that's just making fake credentials," Pollak said.
The Commons Project offers its own SMART Health Card app in the form of CommonPass, a digital health app that travelers to Aruba and Hawaii, as well as those traveling from Germany to the U.S., use to verify their vaccination and testing status.
That's not the only such app. Clear, the airport security company and another VCI partner, uses SMART Health Cards in its Health Pass, which the company markets for use in travel, events and the workplace. The IATA Travel Pass is a similar initiative.
Vaccine card fraud vs. privacy concerns
People are faking vaccine cards, but it's unclear how common this type of fraud is.
"I think one of the challenges is with the paper CDC cards, it's incredibly difficult to know how much fraud there really is going on," Pollak said. "It's not that hard to create a fake one. And generally speaking, if you're not trying to check those records against the state registry, if there's a good fake, there's quite literally no way that anyone would know that it's a fake."
Tech companies that have shared their vaccination verification processes with Protocol have generally described collecting proof of vaccination — often an image of a vaccine card, a digital vaccine record from California or New York, or a record from a doctor's office — through email or an HR/IS system like Workday.
Clear offers another vaccine passport option with its Health Pass.Photo: Clear
In other words, no tech company has indicated to Protocol that it will turn down a paper vaccine card in favor of a digital, verified vaccine passport, which Pollak said they can do today using open source code from VCI. Pollak is hopeful that Workday and similar systems will incorporate SMART Health Cards into their workflows so companies can even more easily collect verifiable vaccine proof from employees.
Some see the traditional vaccine card as a more straightforward alternative. "It's OK to take a low-tech approach … To do it all in the most technologically savvy and efficient way may not be the smartest option, given that we don't know all the medium-term consequences of putting this data in lots of places," said Rob Shavell, the CEO of the online privacy company Abine.
As for vaccine card fraud? Shavell isn't concerned. "Designing a whole system to make sure that we're catching that 0.1% of people that are so crazy and motivated that they want to create forged vaccine records is not a smart way to protect society," Shavell said. Pollak agreed with Shavell's concerns about privacy, noting that that's why VCI has taken such a decentralized approach: To download a SMART Health Card, a user simply has to log in to a state website, download a QR code and present it to one's employer or another authority.
Will SMART Health Cards become ubiquitous?
All told, Pollak estimates that between vaccinations at mass vaccine sites, in doctor's offices and at pharmacy chains, around 100 million people — roughly half of those who have been vaccinated in the U.S. — can gain access to their vaccine records through SMART Health Cards, "with a bunch more to come."
"It will be a long tail before every state provides this service," Pollak said. "But we think through the different channels that we're hopeful that most people who have been vaccinated by year end or so should be able to get access to their health records in this format."
VCI now has around 700 partners in the public and private sectors, ranging from medical records providers like Cerner and Epic Systems to Apple, which has integrated VCI's Smart Health cards into iOS 15, as well as Salesforce and Microsoft, which both have large vaccine administration platforms.
"Large group consensus is really important," Pollak said. "If we're not building something that all of the entities can adopt, then it really has no chance of becoming successful."