WritingEssay

The patient who must not be named

Why an identity system has to be able to not identify someone.

No. 03 · June 2026 · 5 min read

An identity network has an obvious failure mode, and it is not a technical one. It is that the system works too well. Build something that knows exactly who every patient is, binds every diagnosis to a verified name, and makes it all portable and permanent, and you have also built the most efficient tool ever made for finding the people who most need not to be found.

The woman hiding a pregnancy from a factory that fires pregnant women. The man with a diagnosis that would cost him his housing or his marriage. The teenager who needs a test her family must never see. The Rohingya refugee for whom a government-linked record is a danger rather than a convenience. For these people a perfectly verified identity is a threat, and a health system that can only serve the fully identified has drawn a line and left them on the far side of it.

So the test of this identity layer is not how well it identifies. It is whether it can deliberately decline to. And it can, using the same machinery, because the thing that makes a credential trustworthy is the signature, not the name. A prescription is valid because a verifiable doctor signed it, and that fact holds no matter how little the system knows about the patient. You can prove a doctor authorized a treatment without proving who received it. You can carry a real, signed clinical record under an identity anchored to nothing: no national ID, no passport, no name a factory or a family or a ministry could pull. The record is real. The link to a legal identity is the part that is absent, on purpose.

The thing that makes a credential trustworthy is the signature, not the name.

This is anonymous mode, and it is not a lesser tier bolted on for awkward cases. It is reached through a trusted intermediary, an NGO or a clinic or a counselor, who stands between the patient and the system, so that someone with the most to lose can hold a verifiable record without exposing themselves to acquire it. The pregnancy consultation, the stigmatized diagnosis, the test that must stay invisible: shielded categories, visible to the patient and the clinicians she chooses and to no one else, because the keys are hers and the identity beneath them points nowhere.

The factory worker is the sharpest version, because the same system serves her employer and must still protect her from it. The factory pays for the medical room. The factory wants proof the room is used. The architecture gives it that proof, in aggregates and compliance, the room is staffed and working, and gives it nothing about her. Her early-pregnancy consultation writes to her wallet, under her key, on a device the factory cannot read, in a category management cannot see. The system the employer paid for is the system that hides her from the employer. That is not a contradiction the design tolerates. It is the design.

There is a deeper point about what owning a record means. A record the patient owns is one she can also withhold. If the only way to receive care is to be fully and permanently identified into a system someone else controls, she does not own anything. She has been enrolled. Patient-held keys are what make refusal possible, and refusal includes the choice to let no one see her legal identity at all. For the people in this essay that difference is measured in whether she keeps her job, her housing, her safety.

It would be easier to build the system that only serves the fully identified. It would cover most people, demo cleanly, and raise no hard questions about edge cases. But the edge is where the need is sharpest. The measure of this network is not that it can prove who you are. It is that when proving who you are would hurt you, it can still prove what you need and keep the rest. An identity system worth building has to be able to not identify someone. This one is built to.

All writing

The worldview, made real

See the products