Cosmos AI Lab logo Cosmos AI Lab Private Health Passport
A project Cosmos AI Lab is preparing to build

Private Health Passport

A local-first personal health memory system that helps people preserve medical history, understand their records, notice meaningful changes, and prepare better conversations with doctors.

View roadmap Public-good posture Local-first privacy AI companion, not AI doctor
00 · Model

Value map

Private Health Passport does not begin with “AI diagnosis”. It begins with a safer promise: turning scattered health data into a private, structured, shareable health memory.

User Captures symptoms, habits, prescriptions, lab results, and care history.
Local vault Encrypted on device, user-controlled, no default cloud upload of health records.
Private Health Passport Private health memory
AI companion Summarizes, explains, reminds, and prepares doctor questions; does not prescribe or replace care.
Doctor / clinic Receives a concise, context-rich brief for more focused medical visits.
Family / caregiver Receives limited, consent-based access, especially useful for elderly care and chronic conditions.
01 Reduce forgotten history No longer rely only on memory during visits.
02 Earlier care decisions Reminds follow-ups and long-running signals to discuss.
03 Better clinical context Medical briefs show a timeline, not only a snapshot.
04 User-owned data Local-first, consent-first, and not a health-data resale business.
01 · Thesis

Memory before prediction

The highest-value healthcare AI does not begin by replacing doctors. It begins by helping people remember accurately, organize evidence, and seek medical attention earlier.

Problem

Patients forget their own health timeline.

Symptoms, medication changes, lab results, and doctor instructions are scattered across paper, photos, chats, hospital portals, and memory.

Opportunity

AI is strongest when context is complete.

A doctor often sees one moment. A private health record can reveal multi-year patterns, missing follow-ups, and changes that deserve attention.

Principle

Assist decisions, do not replace care.

The app should help users decide when and how to seek care, prepare questions, and share history. It should not diagnose or prescribe treatment.

02 · Product

A private medical timeline

Private Health Passport is a personal health archive, context engine, and doctor-visit assistant. Its first win is trust.

Capture Symptoms, visits, prescriptions, lab reports, images, habits, and doctor notes.
Structure Convert scattered records into a searchable timeline and profile.
Explain Translate medical documents into plain language with cited sources.
Prepare Generate doctor brief, questions, medication list, and missing data checklist.
Remind Prompt periodic checkups, follow-ups, and signals that deserve medical attention.
Core V1

Health Passport

  • Personal profile, family history, allergies, medication list.
  • Medical timeline for symptoms, visits, diagnoses from doctors, tests, and procedures.
  • Prescription and lab-result vault with OCR/import support.
  • Exportable medical brief for hospitals and clinics.
Differentiator

Context-aware AI companion

  • Summarizes long health history into doctor-ready context.
  • Flags missing follow-ups and long-running symptoms.
  • Explains lab results and prescriptions using approved medical references.
  • Suggests what to ask doctors, not what treatment to take.
A Families with elderly members Track chronic conditions, medication, follow-ups, and long-term health changes.
B Busy adults Cannot reliably remember visits, labs, symptoms, and health habits.
C Caregivers Need a clear record to support relatives with visits and medication routines.
D Community health partners Can use a non-commercial, consent-first model for community health programs.
03 · AI Safety

Powerful AI, clear boundaries

The legal and ethical line is not whether the app earns money. The line is what the software claims, what it does, and how much users rely on it for medical decisions.

Zone Allowed in V1 Boundary Risk posture
Green Store records, organize timeline, remind routine checkups, export doctor brief. No diagnosis, no treatment decisions, no medication changes. Low regulatory risk if privacy is handled properly.
Yellow Explain lab values, summarize trends, recommend questions, suggest medical specialty to consider. Must cite sources, show uncertainty, and frame as “discuss with doctor”. Build carefully with clinical/legal review before public beta.
Red Not in V1. No disease probability claims, no image diagnosis, no prescribing, no “you have X”. Requires medical governance, validation, and possibly regulated pathways.

“The product promise is not: AI will replace your doctor. The promise is: you will never walk into a clinic empty-handed again.”

Positioning statement
04 · Privacy

Local-first is the trust layer

Health data is among the most sensitive personal data. Trust is not a feature after launch; it is the product architecture.

Default

Data stays on device.

Local encrypted database, encrypted file vault, biometric/passcode unlock, and no mandatory account for basic use.

AI access

Minimum necessary context.

If cloud AI is used, the app should show what data is sent, why it is sent, and allow users to disable cloud AI.

Research

Opt-in must be separate.

Data donation for research requires explicit consent, de-identification, withdrawal rights, and a governance process.

05 · Sustainability

Public good, not data business

The project can avoid monetizing health data while still funding development, infrastructure, clinical review, and long-term maintenance.

Do

Ethical funding paths

  • Donations, grants, foundation support, and transparent sponsors.
  • Optional supporter plan for encrypted sync, backup, family sharing, and advanced OCR.
  • Institutional partnerships with clinics, NGOs, universities, or community-health programs.
  • BYOK and local-model mode as advanced options, not default requirements.
Do not

Non-negotiable limits

  • Do not sell health records or behavioral health data.
  • Do not train models on user data without a separate opt-in program.
  • Do not lock core health access behind aggressive paywalls.
  • Do not market AI outputs as diagnosis or treatment.
06 · Roadmap

Build trust in stages

The practical path is not to start with prediction. Start with memory, structure, and doctor collaboration; then expand AI after safety review.

Phase 0 · Research & Governance

Define the safe product boundary.

Confirm legal/medical constraints, source policy for medical references, privacy model, data taxonomy, and AI response rules.

Phase 1 · Local Passport MVP

Ship the private health record.

Build profile, timeline, prescriptions, labs, file vault, reminders, search, and PDF medical brief export.

Phase 2 · Safe AI Assistant

Add grounded explanation and preparation.

AI summarizes records, explains lab/prescriptions, prepares doctor questions, and flags missing follow-up context without diagnosing.

Phase 3 · Sharing & Caregiver Mode

Make medical history portable.

Time-limited sharing links, family/caregiver access, hospital-ready export bundles, and consent-based doctor collaboration.

Phase 4 · Research Opt-in

Only after trust, governance, and consent.

De-identified data donation, community-health insights, and advanced AI research under a clear ethical framework.

07 · Meeting Agenda

Decisions for the team

This is where the thinking stands today. It is published so the people it is meant for can read it, disagree with it, and tell us what it misses before a line of it is built.

Product

What is the first platform?

Mobile-first, desktop-first, or web local-first? Health capture likely favors mobile, but records and PDF workflows may favor desktop/web.

AI

Which model strategy?

Default CAL-provided AI quota for normal users, BYOK for power users, local model for privacy mode, and strict cost controls.

Governance

Who reviews medical safety?

Before public beta, CAL should define advisor roles for medical, legal, privacy, and AI safety review.