Yes, STI Test Results Are Trivially Easy to Fake
Here’s why, how to tell the difference, and what actually can’t be faked.
Screenshots can be edited. PDFs can be modified. Photos of test results can be fabricated. This is why verification matters, and why most sexual health platforms can’t guarantee it.
How Results Actually Get Faked
This is technically easy, not a moral failing. The tools involved are ordinary photo and document editors that most people already have.
Screenshots
- Take a screenshot of a test result
- Edit it in Photoshop, Preview, Canva, or any online tool
- Change the date, status, or provider name
- Send it, the recipient has no way to know it was edited
PDFs
- Download a PDF from a healthcare portal or email
- Edit text fields with Preview, Acrobat, or an online tool
- Change the provider name, result status, or date
- Add a fake provider stamp with a digital signature tool
Physical Documents
- Print a legitimate test result
- Alter handwritten or printed fields
- Photograph the altered document
- Send it as a photo or scan
The Three Tiers of “Verification”
Not all “verified” badges mean the same thing. The difference comes down to where the data originated.
Self-Reported
The user types in their own status, for example “I’m negative.”
Document Uploaded
The user uploads a screenshot, PDF, or photo of a test result.
Provider-Sourced
The result is pulled directly from the provider’s system via an authenticated connection (FHIR, SMART on FHIR).
The Gap Recipients Face
Most platforms that accept a user-uploaded document render it exactly like a provider-sourced result: green checkmark, status, date, provider name. Without an explicit label, a recipient cannot tell which tier they’re looking at.
These two cards are identical on purpose. If a platform doesn’t label its verification tier, this is genuinely what both look like, and there’s no way to tell them apart from the outside.
There Is No Upload Button in Protecht
Protecht makes the upload path impossible by design. Other platforms offer upload options, which means recipients must trust the uploader, not the system. Here’s why that matters.
There is no upload button. Results can’t enter the app as a file.
Results are pulled only through authenticated connections to healthcare providers.
Once pulled, a result can’t be edited, screenshotted, or altered by the user.
Recipients see a read-only, time-limited view, attributed to the provider by name.
Some platforms clearly label self-reported versus uploaded versus provider-verified results. That transparency helps. But most don’t, leaving recipients guessing which tier they’re actually looking at.
Asking for Proof Without Making It Accusatory
Asking for verification isn’t suspicion, it’s responsibility. This is how mature adults handle sexual health, and it works best when it’s reciprocal: if you’re asking for proof, you show proof too.
“Before we get more intimate, I’d like to share recent test results with you, and I’d love to see yours too. No judgment, just part of how I stay healthy.”
“Thanks for sharing. I can see it’s a screenshot though, can we connect our actual results through a health app instead? That way we both know they’re current and real.”
“I get that it feels vulnerable. That’s exactly why I’m asking. If you’re not ready to share, that’s information too, and it might mean we wait before moving forward.”
“Getting tested is easy, sharing results is even easier now. There are apps that pull results directly from your provider, no screenshots, no editing possible. Want to try that?”
Frequently Asked Questions
Now You Know What Verification Actually Requires
Here’s what a provider-sourced, tamper-proof-by-design result looks like in practice.