Patients aren’t tied to HealthPass
HealthPass is one place a patient can keep her record. We call such a place a wallet. HealthPass shouldn’t be the only one. On a beckn network any company, hospital or NGO can run a wallet, and every wallet reaches every clinic, lab and pharmacy on the same terms. A patient can change wallet and take their record with them, the way people in India change payment app without changing bank.
How a wallet joins
A wallet joins the network once, the same way a lab does. It registers in the network registry, which lists every organisation on the network and its digital keys, and it is approved under the network’s rules, including the rule that it must hand records over when asked. From then on it can search, order and receive results for all of its patients. Patients don’t join one by one; their wallet acts for them. There are three ways to run a wallet:
- Run your own node, as HealthPass does.
- Use a hosted node run by someone else. This suits a hospital or NGO that wants its own wallet without running servers.
- Build an app with no storage of its own, working on top of a wallet that someone else runs.
Finding a patient’s wallet
Usually no lookup is needed, because the wallet starts nearly every order or booking. When HealthPass orders a lab test, the order carries HealthPass’s network address, so the lab sends the result straight back to it. Any other wallet works the same way.
A lookup only matters when the provider starts the contact and has nothing but the patient’s ID. For example, she walks into a clinic without booking through her wallet, or a doctor sends a prescription a week after the visit. There are two ways to handle that:
She shares her wallet addressShe shows a QR code at the clinic, or gives an address such as thandi@healthpass. Like an email address, it says which wallet to send to, and nothing central is involved.
The provider asks the patient registryAn optional registry answers one question: which wallet holds this person’s record? It holds her ID, name, contact details and the name of her wallet, and no health data. Patients choose whether to be listed.
These are two registries with two jobs. The network registry lists organisations, and every beckn network needs one. The patient registry lists people, and it is optional. A central list of who uses which health wallet is sensitive, so if one exists it should be opt-in and held by the government. India’s ABHA works this way (see How India did it): the ID is voluntary and issued by a national registry, and a consent manager tracks which hospitals hold each person’s records without seeing what they say.
South Africa’s Department of Health already runs a national patient register, the Health Patient Registration System. It is used in 3,265 public facilities and holds 37.2 million verified registrations12. The network could add an optional note of each patient’s wallet to that register rather than building a new one. Where a country has no national register, one can be built as part of the network, as a public good.
Switching wallets
- She asks the new wallet to take over.It confirms her identity with a one-time PIN sent to her phone.
- HealthPass hands over her full record.It sends it to the new wallet in the standard format: FHIR, with her International Patient Summary.
- Results find the new wallet.If she is listed in the patient registry, the registry records her new wallet, and providers find it from her ID. If she isn’t, HealthPass forwards anything sent to her old address for a set period, and she gives providers her new address at her next visit.
Using more than one app or wallet
Several apps, one walletThe simplest choice, and the one we recommend. Her record lives in one wallet, and any number of apps read and add to it with her permission, using the standard method for secure access to health records: a pregnancy app, a pharmacy app, or an app a family member uses to help with her care. It’s like using two payment apps on the same bank account.
Two walletsPossible, but it splits the record again, which is the problem we started with. It works if she picks one as her main wallet, where providers send results by default, and the other keeps a copy that stays in sync with her permission.
What keeps patients free to switch
- The patient’s ID belongs to the patient. It is a national ID, not an account with any wallet.
- The record is in a standard format. Every wallet stores FHIR and must hand the record over when the patient asks. That is a network rule, not a promise from any one company, including us.
- Providers join the network, not a wallet. A lab connects once and serves patients from every wallet.
- The rules are open. The health domain pack and the adapters we build are published for anyone to use, including competing wallets.