🛡 Anti-Phishing & Security Verification

Verify a Message from AIMS Force

Healthcare professionals receive many recruiter emails. We want it to be obvious which ones are genuinely from us — this page shows you exactly how to confirm any email, document link, or phone call claiming to be from AIMS.

🔒 HIPAA Compliant ✅ Microsoft 365 Encrypted 📧 DMARC + DKIM + SPF 🏆 WOSB/EDWOSB Certified ⚙ CMMC Level 2 Aligned 🛡 NIST SP 800-171 📋 SOC 2 Type II Aligned

Real vs. Fake — At a Glance

Use this side-by-side to spot the difference quickly.

✅ A real AIMS email will

  • Come from an address ending in @aimsforce.com
  • Show the AIMS Force logo and a consistent signature block
  • List our DUNS (013855798), UEI (MDNLBQP51JB9), and CAGE (7FR96) in the signature
  • Include direct phone numbers you can call to verify the sender
  • Send document links only after you've been introduced and consented
  • Send any request for sensitive credentials (SSN, banking info, passport, license) only via a password-protected SharePoint upload link — never as an email attachment or reply
  • Never demand urgent payment, gift cards, or wire transfers

⚠ Be suspicious if the email

  • Comes from a free email address (gmail.com, outlook.com, yahoo.com) claiming to be AIMS
  • Comes from a look-alike domain (aimslocum.com, aims-locumtenens.com, aimslocumtenens.co)
  • Has no AIMS branding, signature, or government identifiers
  • Asks you to type or attach your SSN, banking info, passport, license, or password directly in an email reply — AIMS will never request credentials this way. We always send a password-protected SharePoint link to a secure upload portal instead
  • Pressures you to act in 24 hours, mentions a "limited time" job
  • Offers a job before any interview or credentialing
  • Has a SharePoint link that looks slightly off (always hover before clicking)
  • Contains spelling errors, awkward phrasing, or generic greetings ("Dear Candidate")

The 60-Second Verification Checklist

1
Check the sender domain The address must end in exactly @aimsforce.com. Anything else — even one character off — is not from AIMS.
2
Look for the AIMS logo and full signature Every real AIMS email carries the AIMS Force logo, the sender's name and title, direct phone, and our DUNS/UEI/CAGE government identifiers at the bottom.
3
Hover before you click Hover your mouse over any link (including SharePoint links). The URL preview should show netorg244443.sharepoint.com or aimsforce.com. If it doesn't, don't click.
4
Verify the sender with a phone call Call AIMS at (410) 363-1051 or (571) 253-6663 and ask the receptionist to confirm the sender is a real AIMS employee. We're happy to verify — it's never a bother.
5
Confirm our credentials on SAM.gov Search our DUNS (013855798) or UEI (MDNLBQP51JB9) at sam.gov — you'll see our active federal registration.
6
Never share sensitive credentials by email Real AIMS will never ask you to type or attach your SSN, bank account number, password, or photo of your government-issued ID into an email. When we need these documents, we send you a password-protected SharePoint upload link — a secure encrypted portal where only you and our credentialing team can access the files. The link will require you to sign in with the exact email address we invited, and the password is shared separately (by phone or text). If anyone asks for your credentials any other way, it is not AIMS.

How AIMS Securely Requests Your Credentials

Every time we need sensitive documents from you, this is exactly the process we follow.

Step 1

Email arrives with the link

You receive an email from an @aimsforce.com address with a SharePoint link to a secure upload folder. The link will only let the email address we sent it to sign in.

Step 2
📱

Password arrives separately

Your recruiter sends you the access password by a different channel — a text message or a phone call. We never put the password in the same email as the link.

Sent by text or call
Step 3
🔒

You sign in and unlock

You click the link, sign in with the exact email address we invited, then enter the password you received separately. The portal verifies both before letting you in.

Microsoft 365 encrypted
Step 4
📤

Upload your documents

You upload your credentialing documents (license, DEA, I-9, W-9, etc.) directly into the secure folder. Only you and our credentialing team can see them. They are encrypted at rest with AES-256.

End-to-end encrypted

Why this two-channel process matters

Splitting the link and the password across two different channels (email + text/call) means that even if a phisher somehow intercepted your email, they still couldn't open your documents — they would also need access to your phone. This is the same technique your bank uses for high-value transfers.

If anyone claiming to be AIMS asks you to email your credentials, attach a passport scan to a reply, or share a password in the same thread — stop, hang up, and call us at (410) 363-1051 or (571) 253-6663 to verify.

Official AIMS Force Information

All AIMS contact points, domains, and identifiers — bookmark this page.

Official Email Domain
@aimsforce.com
All AIMS staff use this domain exclusively. Anything else is not us.
Main Office Phone
(410) 363-1051
Mon–Fri, 9 AM – 6 PM EST. Call this number to verify any AIMS communication.
Recruiting Direct Line
(571) 253-6663
Northern Virginia office. Reaches our recruiting and credentialing team directly.
Government Line
(202) 688-3175
For Department of Defense and federal facility partners.
Official Website
aimsforce.com
Our only official website. Check the lock icon 🔒 in your browser before sharing any info.
DUNS Number
013855798
Verify at SAM.gov
UEI (Unique Entity ID)
MDNLBQP51JB9
Verify at SAM.gov — required for federal contractors.
CAGE Code
7FR96
Federal vendor identifier — verify at cage.dla.mil
Headquarters Address
41485 Autumn Sun Dr
Aldie, VA 20105
Washington DC Metropolitan Area
LinkedIn (Verified)
linkedin.com/company/96468701
Certified by Third Parties
WOSB / EDWOSB · MQS NG Prime · HIPAA Compliant · E-Verify Employer
Verify WOSB at certify.sba.gov
Aligned to (Certification In Process)
SOC 2 Type II · CMMC Level 2 · NIST SP 800-171 · ISO 9001 · JCAHO · CCPA / CPRA
We operate to these frameworks today; formal audits in progress.
Email Security
DMARC · DKIM 2048 · SPF Strict · TLS 1.2+
All outbound email is cryptographically authenticated and encrypted via Microsoft 365 with anti-phishing protection.
Document Portal Domain
netorg244443.sharepoint.com
SharePoint links from AIMS always start with this domain. Hover to confirm before clicking.

Still not sure? Just ask.

We would rather you call ten times to verify than fall for a phishing attempt. There is no such thing as a wasted verification call.

Trust, Security & Compliance

The protections, frameworks, and credentials behind every AIMS communication.

📧 Email & Message Security

  • DMARC Enforced (Strict Alignment)
  • DKIM 2048-bit Cryptographic Signing
  • SPF Strict Alignment
  • TLS 1.2+ Required for Mail Delivery
  • MTA-STS Protected
  • Microsoft Defender Anti-Phishing
  • External Sender Tagging

🔒 Data Protection

  • AES-256 Encryption at Rest
  • TLS 1.3 in Transit
  • U.S. Data Residency Only
  • Microsoft 365 Enterprise Encryption
  • BitLocker / FileVault on Endpoints
  • Encrypted Credentialing Portal
  • Daily Backups, 30-day Retention

🛡 Identity & Access

  • Multi-Factor Authentication Enforced
  • Microsoft Entra Security Defaults
  • Zero-Trust Architecture
  • Role-Based Access Control
  • Quarterly Access Reviews
  • Privileged Identity Management
  • Conditional Access Policies

🏥 Healthcare Compliance

  • HIPAA Privacy & Security Rules
  • HIPAA Business Associate (BAA) Ready
  • JCAHO Aligned
  • CMS Requirements Followed
  • NPDB & OIG-LEIE Screening
  • OSHA Occupational Health Records
  • ADA Confidentiality of Medical Info

🏢 Federal Frameworks

  • NIST SP 800-171 Aligned
  • CMMC Level 2 Aligned (Cert In Process)
  • FAR / DFARS Compliant
  • OFCCP Federal Contractor Compliant
  • E-Verify Employer
  • SAM.gov Active Registration
  • Section 508 Accessibility Aligned

📊 Privacy & Audit Frameworks

  • SOC 2 Type II Aligned (Cert In Process)
  • ISO 9001 Aligned
  • ISO 27001 (via Microsoft Azure)
  • FedRAMP Moderate (via Microsoft 365)
  • CCPA / CPRA Aligned
  • FCRA Compliant Background Checks
  • Annual Risk Assessment

🏆 Business Credentials

  • WOSB / EDWOSB Certified (SBA)
  • MQS NG Prime Contractor
  • DUNS 013855798 (Active)
  • UEI MDNLBQP51JB9 (Active)
  • CAGE Code 7FR96
  • Virginia State Business License
  • 15+ Years in Business (Est. 2013)

👀 Monitoring & Operations

  • Microsoft 365 Defender Active
  • Continuous Audit Logging
  • Annual Penetration Testing
  • Quarterly Vulnerability Scans
  • Quarterly Security Awareness Training
  • Phishing Simulation Exercises
  • 24/7 Operations Coverage
What “Aligned” vs “Certified” means: “Certified” means an independent third-party auditor has examined our controls and issued a certificate (for example, WOSB is certified by the SBA). “Aligned” means we operate to that framework's required controls today and have not yet completed the formal third-party audit. We are transparent about the difference because both are protective of your information — and you deserve to know which is which. See our Privacy Policy for full detail on our security and compliance posture.

Frequently Asked Questions

Common concerns from candidates and partners.

I got an email asking me to upload my I-9 and W-9 to a SharePoint link. Is that normal?
Yes — but only after we've had an introductory conversation and you've signed a placement agreement. The link will come from a recruiter you've already spoken with, will start with netorg244443.sharepoint.com, and will require you to sign in with the email address we sent the invitation to. If any of these don't match, call us at (410) 363-1051 or (571) 253-6663 before uploading anything.
Why does the sign-in page look like Microsoft, not AIMS?
AIMS uses Microsoft 365 (the same platform that powers Outlook for over 400 million businesses) for our document portal. When you sign in, you'll see the AIMS Force logo, our brand colors, and our company name on the sign-in page — Microsoft handles the secure infrastructure. This is exactly the same setup used by hospitals, universities, and the federal government.
Can AIMS see my personal email or files?
No. When you sign in to access a SharePoint document we shared with you, you are signing in to YOUR email — Google, Outlook, AOL, whatever you use. We only see the documents you upload to the specific folder we shared. We have no access to your inbox, your personal files, or any other account information.
A friend got a job offer from "AIMS Force" via Telegram or WhatsApp. Is that you?
No. AIMS does not send job offers via Telegram, WhatsApp, Signal, or any messaging app. Our recruiters communicate by email (@aimsforce.com) or phone. We never offer a job before an interview, and we never ask candidates to pay any fee. If you've encountered a scam, report it to the FTC at reportfraud.ftc.gov.
My email account "stopped working" after I clicked an AIMS document link. What happened?
This should not happen with a legitimate AIMS link. If your email is no longer accessible after clicking any link, it is a strong sign you clicked a phishing link (not from us) and your account has been compromised. Contact your email provider immediately to reset your password and enable two-factor authentication. Then call us at (410) 363-1051 or (571) 253-6663 so we can re-send the original document securely.
Who do I report a suspicious "AIMS" email to?
Forward it as an attachment to security@aimsforce.com and we'll investigate and warn other candidates. You can also report it to the FBI's Internet Crime Complaint Center at ic3.gov and to your email provider's "Report Phishing" tool.
How do you keep my personal information secure?
AIMS uses Microsoft 365 with enterprise-grade encryption (TLS 1.3 in transit, AES-256 at rest), enforced multi-factor authentication for all staff, HIPAA-compliant data handling, and SOC 2 Type II controls. We are CMMC Level 2 certified for handling controlled unclassified information (CUI) for our DoD work. See our Privacy Policy for full details.
What's the difference between aimsforce.com and amshealth.org?
amshealth.org is our former company name and is no longer used for any email or new business. All current AIMS staff communicate exclusively from @aimsforce.com. If you receive an email from @amshealth.org claiming to be from AIMS, treat it as suspicious and call us to verify.