GoodCanna: How Dutchie verifies patient identity and prevents duplicate profiles for medical card applications

This article explains how the GoodCanna Medical Card Integration verifies a patient's identity, supports manual ID verification, and prevents duplicate patient profiles when an applicant submits a medical card application.

Whenever a patient applies for a medical card through the GoodCanna Medical Card Integration, Dutchie runs two identity verification checks before the application is completed: one against the State of Louisiana's official patient registry, and one against Dutchie's internal patient records. Neither check is optional, and every applicant passes through both. In addition, the intake form includes a government ID photo upload step that gives the medical provider a way to manually confirm the applicant's identity during the evaluation call.

This process exists to solve related problems for Compliance Officers and Dispensary Managers. First, it ensures that a patient's application is always matched to their correct, existing profile when one exists, so staff are not left reconciling conflicting records after the fact. Second, it prevents new, duplicate profiles from being created for patients who already have one, which reduces the manual cleanup work that would otherwise fall to compliance and front desk staff. Third, it gives providers a way to visually confirm that the name and date of birth entered on the intake form actually match the applicant's ID, closing a gap where patients could previously enter unreliable information and still receive a certificate. 

This means fewer follow-up corrections when a returning patient applies again under a new email address, phone number, or Dutchie account, and a documented photo on file if a certificate is ever questioned at the point of sale.

Before you begin

  • Every applicant passes through two sequential checks: one against the state's official patient registry (Section 1) and one against Dutchie's internal patient records (Section 2). Both checks run for every application.
  • Verification stops as soon as a confident match is found. Once a match is confirmed at any priority level, the applicant's existing profile is updated rather than duplicated.
  • The government ID photo upload step supports manual verification only. It does not perform automated identity verification or extract data from the image, and a failed photo upload will not prevent a patient profile from being created.
  • The state registry check relies first on the applicant's driver's license number. If no match is found by driver's license number, the check falls back to the combination of first name, last name, and date of birth.

How Dutchie checks patient identity against the state registry

Before any information is entered into or updated in Dutchie's system, the applicant's identity is checked against the state's official registry of medical marijuana patients. This happens in two stages:

  1. Dutchie performs a primary check using the driver's license number provided on the application.
  2. If no match is found by driver's license number, Dutchie performs a secondary check using the combination of first name, last name, and date of birth.

The outcome of this check determines what happens next:

  • If the state registry does not find the applicant, Dutchie treats the applicant as not currently holding state-issued patient status, and processing continues with the internal records check described below.
  • If the state registry finds the applicant, Dutchie treats the state's records as the authoritative source of that patient's identity. Dutchie corrects the applicant's name and date of birth on the intake form to match the state's official record, which prevents misspellings, nicknames, or formatting differences from interfering with the internal matching process. Dutchie also retrieves the state's official medical marijuana identification number and carries it forward as a matching criterion in the next step.

How Dutchie matches patients to internal records

Once the state registry check is complete, Dutchie compares the applicant's information against its existing patient records using six criteria, evaluated in a fixed order of priority.

PriorityMatching criteria
1Dutchie online account identifier
2Driver's license number
3Medical marijuana identification number (as retrieved from the state registry, when available)
4Email address combined with date of birth
5Phone number combined with last name and date of birth
6First name combined with last name and date of birth

Dutchie evaluates these criteria in strict order, from highest to lowest priority, and stops immediately at the first successful match. Dutchie does not check any remaining criteria once a match is found. If none of the six criteria produce a match, Dutchie determines that the applicant is a new patient and creates a new profile using the submitted information.

Dutchie checks the Dutchie online account identifier first because every applicant is logged into their Dutchie account while completing the intake form, which makes it the most direct and reliable identifier available. A match typically will not be found at this step only when the applicant has just created a new account for the purpose of applying. In that case, verification continues to the remaining criteria.

Why this approach prevents incorrect matches

No single piece of information used in the internal records check is, by itself, sufficient to confirm a match. This is intentional: information such as an email address or a phone number can be shared by more than one person, for example members of the same household, and relying on either one alone would risk matching an applicant to the wrong profile.

To guard against this, every criterion below priority 3 requires more than one piece of information to agree at the same time:

  • A match on email address also requires the date of birth to match.
  • A match on phone number also requires the last name and date of birth to both match.

This means that two people would need to share an email address (or phone number) and a date of birth (or last name and date of birth) for an incorrect match to occur, which is a far less likely coincidence than sharing just one of those details.

How Dutchie avoids creating duplicate profiles

Beyond matching an applicant to the correct profile, Dutchie is designed so that a patient who already exists in the system under any prior name spelling, contact detail, or account is not mistakenly treated as new. Dutchie applies several layers of protection to achieve this:

Breadth of matching criteria. Because Dutchie checks six different types of identifying information rather than just one, a patient is unlikely to go unrecognized simply because a single detail has changed. A patient who has switched phone numbers, updated their email, or opened a new Dutchie account will still typically be identified through another criterion, such as their driver's license number, medical marijuana ID, or name and date of birth together. Dutchie does not require every piece of information to match; it requires only one full, reliable combination.

Stop-on-match rule. As soon as Dutchie confirms an existing profile at any priority level, the process ends there. Dutchie updates the applicant's existing profile with the new information, and a second, separate profile is never created alongside it.

Early check for patients who already hold a valid card. Before an applicant reaches the identity verification steps, Dutchie first checks whether the applicant is logged in with a Dutchie account that already has a valid, unexpired medical marijuana ID on file. If so, Dutchie informs the applicant that they do not need to reapply, and the process stops before a new application is generated at all.

Duplicate application checks at the state and provider level. Even if an applicant proceeds past the check above, both the state registry and the medical provider maintain their own safeguards. An applicant who already has a pending, in-progress, approved, or recently rejected application is identified as already being in the system, and a second application is not created.

Government ID photo capture on the medical intake form

In addition to the automated matching described above, the GoodCanna intake form includes a step where the applicant uploads a photo of a government-issued ID, such as a driver's license or medical marijuana ID card. This step supports manual identity verification and does not replace or interact with the automated matching process described in the sections above.

Why this exists. Previously, patients typed their name and date of birth into the intake form and simply confirmed whatever the provider read back to them during the evaluation call. When that information did not match the patient's actual ID, the certificate would not match the patient's legal identity, and dispensaries were unable to dispense to that patient. The photo upload step gives the provider a way to visually confirm the applicant's identity against their ID before issuing a certificate.

How it works:

  • The applicant uploads a photo of their government-issued ID as part of the intake form. Dutchie validates the file size and file type at the time of upload.
  • Dutchie saves the image to the patient's customer profile, where dispensary staff can view it in the Dutchie Backoffice.
  • Dutchie forwards the image to the medical provider so it can be reviewed during the evaluation call.
  • If the photo upload fails for any reason, the patient profile is still created. A failed upload does not block the application.

What this feature does not do. The photo upload step is scoped as manual verification support only. It does not perform automated identity verification, and it does not extract structured data (such as name or date of birth) from the image. Any comparison between the photo and the information on the intake form is performed manually by the provider.

Troubleshooting

A patient's application is going through even though they already have a medical card. Why?
Before identity verification begins, Dutchie checks whether the applicant is logged in with a Dutchie account that already has a valid, unexpired medical marijuana ID on file. If this check is not stopping the application, confirm that the patient is logged into the correct Dutchie account, since the check relies on the account being logged in at the time of application.

A returning patient's application created a second profile instead of updating their existing one. Why?
This should not happen under normal conditions, since Dutchie checks six different matching criteria and stops at the first confirmed match. If a duplicate profile was created, it means none of the six criteria matched the applicant's existing record. Compare the new application's driver's license number, medical marijuana ID, email and date of birth, and phone, last name, and date of birth against the existing profile to identify which details changed.

Two patients in the same household share an email address or phone number. Will they get matched to each other's profile?
No. A match on email address also requires the date of birth to match, and a match on phone number also requires both the last name and date of birth to match. Sharing only the email address or only the phone number is not enough to produce a match.

A patient's application shows corrected name or date of birth information that does not match what they entered. Why?
This happens when the state registry finds the applicant. Dutchie treats the state's records as authoritative and corrects the applicant's name and date of birth to match the state's official record, which prevents minor discrepancies from interfering with internal matching.

An applicant tried to submit a second application while one was already pending. What happens?
Both the state registry and the medical provider independently recognize when an applicant already has a pending, in-progress, approved, or recently rejected application, and they will not create a second one.

Was this article helpful?