Private Health Passport
A local-first personal health memory system that helps people preserve medical history, understand their records, notice meaningful changes, and prepare better conversations with doctors.
Value map
Private Health Passport does not begin with “AI diagnosis”. It begins with a safer promise: turning scattered health data into a private, structured, shareable health memory.
Memory before prediction
The highest-value healthcare AI does not begin by replacing doctors. It begins by helping people remember accurately, organize evidence, and seek medical attention earlier.
Patients forget their own health timeline.
Symptoms, medication changes, lab results, and doctor instructions are scattered across paper, photos, chats, hospital portals, and memory.
AI is strongest when context is complete.
A doctor often sees one moment. A private health record can reveal multi-year patterns, missing follow-ups, and changes that deserve attention.
Assist decisions, do not replace care.
The app should help users decide when and how to seek care, prepare questions, and share history. It should not diagnose or prescribe treatment.
A private medical timeline
Private Health Passport is a personal health archive, context engine, and doctor-visit assistant. Its first win is trust.
Health Passport
- Personal profile, family history, allergies, medication list.
- Medical timeline for symptoms, visits, diagnoses from doctors, tests, and procedures.
- Prescription and lab-result vault with OCR/import support.
- Exportable medical brief for hospitals and clinics.
Context-aware AI companion
- Summarizes long health history into doctor-ready context.
- Flags missing follow-ups and long-running symptoms.
- Explains lab results and prescriptions using approved medical references.
- Suggests what to ask doctors, not what treatment to take.
Powerful AI, clear boundaries
The legal and ethical line is not whether the app earns money. The line is what the software claims, what it does, and how much users rely on it for medical decisions.
| Zone | Allowed in V1 | Boundary | Risk posture |
|---|---|---|---|
| Green | Store records, organize timeline, remind routine checkups, export doctor brief. | No diagnosis, no treatment decisions, no medication changes. | Low regulatory risk if privacy is handled properly. |
| Yellow | Explain lab values, summarize trends, recommend questions, suggest medical specialty to consider. | Must cite sources, show uncertainty, and frame as “discuss with doctor”. | Build carefully with clinical/legal review before public beta. |
| Red | Not in V1. | No disease probability claims, no image diagnosis, no prescribing, no “you have X”. | Requires medical governance, validation, and possibly regulated pathways. |
“The product promise is not: AI will replace your doctor. The promise is: you will never walk into a clinic empty-handed again.”
Positioning statementLocal-first is the trust layer
Health data is among the most sensitive personal data. Trust is not a feature after launch; it is the product architecture.
Data stays on device.
Local encrypted database, encrypted file vault, biometric/passcode unlock, and no mandatory account for basic use.
Minimum necessary context.
If cloud AI is used, the app should show what data is sent, why it is sent, and allow users to disable cloud AI.
Opt-in must be separate.
Data donation for research requires explicit consent, de-identification, withdrawal rights, and a governance process.
Public good, not data business
The project can avoid monetizing health data while still funding development, infrastructure, clinical review, and long-term maintenance.
Ethical funding paths
- Donations, grants, foundation support, and transparent sponsors.
- Optional supporter plan for encrypted sync, backup, family sharing, and advanced OCR.
- Institutional partnerships with clinics, NGOs, universities, or community-health programs.
- BYOK and local-model mode as advanced options, not default requirements.
Non-negotiable limits
- Do not sell health records or behavioral health data.
- Do not train models on user data without a separate opt-in program.
- Do not lock core health access behind aggressive paywalls.
- Do not market AI outputs as diagnosis or treatment.
Build trust in stages
The practical path is not to start with prediction. Start with memory, structure, and doctor collaboration; then expand AI after safety review.
Define the safe product boundary.
Confirm legal/medical constraints, source policy for medical references, privacy model, data taxonomy, and AI response rules.
Ship the private health record.
Build profile, timeline, prescriptions, labs, file vault, reminders, search, and PDF medical brief export.
Add grounded explanation and preparation.
AI summarizes records, explains lab/prescriptions, prepares doctor questions, and flags missing follow-up context without diagnosing.
Make medical history portable.
Time-limited sharing links, family/caregiver access, hospital-ready export bundles, and consent-based doctor collaboration.
Only after trust, governance, and consent.
De-identified data donation, community-health insights, and advanced AI research under a clear ethical framework.
Decisions for the team
This is where the thinking stands today. It is published so the people it is meant for can read it, disagree with it, and tell us what it misses before a line of it is built.
What is the first platform?
Mobile-first, desktop-first, or web local-first? Health capture likely favors mobile, but records and PDF workflows may favor desktop/web.
Which model strategy?
Default CAL-provided AI quota for normal users, BYOK for power users, local model for privacy mode, and strict cost controls.
Who reviews medical safety?
Before public beta, CAL should define advisor roles for medical, legal, privacy, and AI safety review.