0:00 George McEwan | How KERI Enables Better Private-Public Partnerships | KERI Conference 2026
0:03 So, while we let Chris find a
0:05 chair, I'm going to go ahead and start
0:06 so we can stay on time. So, one of the
0:08 things I want to ask the panel
0:10 and each one of you will get an
0:12 opportunity to answer this question.
0:15 What I want to know is if you in 2
0:17 minutes or less, could you tell us a
0:18 little about your background and
0:21 what was the specific lightbulb moment
0:23 that drove your passion in trying to fix
0:25 digital identity?
0:28 So
0:29 I don't think this is on
0:35 I turned it on, but it didn't connect
0:36 anything.
0:38 This, however, does.
0:43 So, my background is actually kind of a
0:45 bizarre. I started [inaudible] about
0:47 an hour, so we're not going to do that.
0:50 but I think my healthcare IT
0:52 background began actually at the very
0:55 beginning of the the exercise
0:58 we're all involved in, right? So, my
1:00 first health… my first job actually
1:03 was in 1986,
1:05 which is when the 8088 was the
1:08 processor du jour. And fast forward
1:11 about 10 years from that point when I
1:13 went through a couple of life cycles of
1:16 career, I ended up being transferred
1:18 back and ended up in the healthcare IT
1:20 space. Actually got the…
1:22 My first healthcare IT job was
1:24 actually the bass player in my band got
1:26 me that job, so but actually my
1:29 original notion of why I identity is
1:32 important is really far back. It is
1:34 really actually back to the notion of my
1:37 first implementation of an EMPI, if you
1:40 know what that is. So, this is the
1:41 notion of a an enterprise master patient
1:44 index. So, the idea that you would know
1:46 who you were talking to reliably at that
1:48 point was a question of probabilism with
1:51 very little very little assuredly
1:54 about who those people were in any way.
1:56 So, pretty early on I realized that the
1:59 quality of the data that was being
2:00 collected to establish this was
2:03 poor. That their ability that actually
2:05 the organization I was working with at
2:07 the time was Kaiser Permanente Northern
2:08 California. They had a about a 30%
2:14 duplication rate in their system. And so, your ability to actually resolve
2:19 identity was the first thing that was my
2:21 light bulb moment. My next big
2:23 opportunity then was like, I don't know,
2:26 20 some years later when I was
2:28 responsible for a national network
2:30 deployment that was the Commonwealth
2:33 Health Alliance. And again, when that
2:36 first launched, its focus was not on
2:38 healthcare information exchange, but on
2:40 identity first. Because the expectation
2:42 was this was the problem you had to
2:43 solve. You had to figure out who you
2:45 were talking about at this point and
2:47 that point. What I quickly learned is
2:50 that we were still talking probabilism
2:52 and we were still talking 20%
2:54 duplication some 20 years later. I mean,
2:56 this stuff had not gotten even a little
2:58 bit better.
2:59 So, the notion that identifiers would be
3:02 important, I think for me really began
3:06 to click when we couldn't resolve
3:09 identity.
3:10 So, getting to identity assurance
3:12 wasn't something I was thinking about. I
3:14 was thinking about the fact you just
3:16 couldn't match people or records with
3:18 people. And so, the my light bulb moment
3:21 really was around identity resolution
3:23 and that's really my was my raison
3:26 d'être. But then, now in this setting,
3:29 what we're trying to figure out is how
3:30 to make it possible for us to be sure
3:33 that people are who they say they are
3:35 when they're contracted over the
3:36 internet. This is very different problem
3:39 than identity resolution, but it has the
3:41 same core problem, which is that people
3:44 go through processes to do this
3:46 exercise, this initial exercise. The
3:49 initial exercise is the first
3:50 transaction. The first transaction is
3:53 the failure transaction. That is the
3:55 fact. So, if you can't get the first
3:58 transaction right, all other
4:00 transactions beyond that will fail.
4:02 So, this was my big aha moment. I've
4:05 been saying the first transaction for
4:06 about a decade. I think it's the most
4:09 important transaction of all. And if you
4:11 can't get the right stuff in the door
4:13 the first time, then you're trying to
4:15 match to it,
4:17 all bets are off. Not going to work.
4:19 So, that to me was my light bulb moment.
4:21 It's maybe, I don't know, 1993.
4:24 It's a good time to have it. We're just
4:25 going to do this like a slow stadium
4:27 wave. We'll just keep rolling on down.
4:29 Okay, well, I'll give it a try. I
4:33 suppose that light bulb moment for me
4:36 probably came back in
4:37 2015. I'd started with CMS. We were
4:41 working out how we were going to make
4:42 data available to
4:44 patients, to beneficiaries. And it
4:48 was going to be done via third-party
4:50 applications, health applications that
4:53 we're seeing
4:54 pretty typically these days.
4:56 And I just asked this the
4:58 really the simple question is there a
5:00 way
5:01 that we could automate the registration?
5:05 But if we're going to do that, I really
5:07 need to be able to have some confidence
5:09 that the organization that is
5:12 presenting themselves
5:14 is who they say they are. And so
5:18 I started this the way I seem to do
5:21 quite often. I wrote a blog.
5:23 It happened to be for HHS, and it simply
5:26 asked that question. And
5:28 that led to conversations. And I think,
5:30 Scott, we even had conversations
5:32 with the DirectTrust around is there a
5:34 way I could call an API and check with
5:37 you guys whether you know this
5:39 organization. And so that really evolved
5:42 from there
5:43 more directly around
5:45 healthKERI.
5:47 Back last year,
5:49 again, I wrote an article because I'm
5:51 thinking how do we operationalize these
5:54 APIs that
5:55 a thousand health plans are going to
5:57 have to implement and tens of thousands
6:00 of provider organizations
6:02 and I don't want to do all this
6:04 work on
6:05 defining what these
6:07 APIs are
6:08 and have them sit there and do nothing
6:09 because that doesn't benefit the patient
6:11 whatsoever.
6:13 So how can you operationalize that?
6:16 And realizing that the manual methods we
6:19 used for patient access API
6:22 which takes
6:24 days, weeks to go through
6:26 is totally non-scalable.
6:28 And so
6:30 I asked the question
6:32 how can we have an organizational
6:34 identity that we can check?
6:37 And that sort of led me down the path
6:39 to KERI.
6:41 Enough said.
6:51 Coming at it from a completely different
6:55 angle.
6:56 My background is in financial services,
6:59 particularly in transaction services,
7:01 which at the time that I started
7:04 wasn't a very common or
7:07 what would I say attractive part of
7:09 financial services to go
7:12 into.
7:13 But I've spent most of my career around
7:17 identifiers
7:19 and identification.
7:21 Which is quite different than identity.
7:24 Although a good foundation and a good
7:27 basis for the way that my career at GLEIF
7:30 and my involvement in this community has
7:33 has led to.
7:34 So…
7:37 come the financial crisis as I
7:39 explained before,
7:41 my background in standards led me to be
7:43 involved in the development of the LEI,
7:45 of course, another identifier.
7:48 And then it was its usage,
7:51 especially guided by
7:53 its initial usage in order to solve
7:56 an initial problem. We want to know who
7:58 these organizations are who are
7:59 responsible for a particular function in
8:02 a particular context, just to generalize
8:04 it, basically.
8:06 And then as we started to
8:10 to operate for a few years,
8:13 in our strategic discussions at GLEIF,
8:16 we started to talk about we have a high
8:17 assurance
8:19 identifier that's global in nature, that
8:22 can identify
8:25 a very broad list of
8:29 entity legal forms or legal entities in
8:32 effect.
8:34 Because of the effort that we put into,
8:38 or our partners put into validating this
8:40 identifier and the effort that
8:42 GLEIF puts in managing the global LEI
8:45 system and the quality of that system
8:49 and its operations,
8:51 why don't we look forward in order to be
8:54 able to see how we could make this
8:55 relevant in the digital world, which is
8:58 the way that the world is going?
9:00 And so this is when we first started to
9:04 get involved with the identity community
9:07 and I'll call it the identity industry,
9:09 which of course I had no idea up until
9:12 this particular point even was a thing.
9:15 And so luckily we were able to
9:19 get connected with and
9:22 be welcomed into the community by many
9:25 of the experts that we see here today,
9:27 who introduced us to the importance of
9:31 identity and not only identification but
9:35 verification, which of course led us
9:37 to wanting to be able to develop
9:40 the vLEI and then use the vLEI.
9:43 I have to say that it was an eye-opener
9:46 for me. My aha moment was actually not
9:50 as I was
9:51 day-to-day trying to be able to figure
9:53 out delivering on the strategy that my
9:55 CEO had given me in order to be able to
9:58 say, "Okay, let's make a verifiable
10:00 credential containing the LEI and
10:03 let's make it a success."
10:05 It was how clueless I was to how I was
10:09 exposing my own identity every day in
10:13 in the everyday things that I did
10:16 just as a natural person and a citizen
10:18 and how I naturally accepted anything
10:21 that people told me was secure
10:25 and was protecting my identity. I
10:27 took it just as face value.
10:32 So, Scott, you said your lightbulb
10:35 moment came in 1993.
10:37 I think mine came at the
10:38 exact same time. I was two.
10:41 At and I'm a little bit
10:43 tongue-in-cheek, but the truth of
10:46 the matter is that for my generation
10:49 we were born into… Now, I do remember
10:50 when we had dial-up installed in the
10:52 house. I'm not that young. But in
10:55 a real sense, I grew up in the digital
10:58 world. Like we had digital identity
11:01 before we had a term for a digital
11:02 identity. And we just accepted, you
11:04 know, in the in the halcyon days of
11:06 yore, you know, MySpace was the hot snot
11:09 and there was none of the concerns that
11:10 we had around it. But for my
11:12 generation, there's never really been a
11:15 demarcation between my identity in the
11:17 real sense in the real world and my
11:20 identity in the digital world. And so
11:23 for me it was I don't know that I ever
11:25 had a lightbulb moment. It was a
11:28 lifetime of experiences where you
11:32 know, XYZ got hacked, your credit card
11:34 gets stolen, your know, all of these
11:36 things and it wasn't until I started
11:39 to understand some of the things that
11:41 were possible with digital identity that
11:43 I went back to this whole life that I'd
11:45 lived and said,
11:47 there has to be a better way. We
11:49 have to do something different than
11:50 what's being done now. And you know,
11:52 I mentioned this earlier, but, I
11:54 guess, the coup de grâce on that
11:57 system was when I just realized the
11:59 fragility of the system we've built off
12:02 of poor identity structure and how that
12:05 could impact me as a patient.
12:08 I feel like a baby compared to this
12:10 entire group.
12:11 [laughter]
12:12 I'm a newcomer here.
12:15 I think I had three things that have
12:17 got me to this current this current
12:19 point that have I guess made me a part
12:22 of the identity movement. When I
12:24 first got into my role as chief privacy
12:26 officer, it was one of the it was the
12:28 first time the state had one. And I got
12:32 calls all the time from people that I
12:35 would sit on the phone for I think the
12:37 longest one was probably two or three
12:38 hours where I felt like I was like a
12:40 psychiatrist of they're just saying,
12:42 I've had this horrible thing happen and
12:44 I have no control.
12:46 And I've had cases where
12:48 women would call and say, my
12:50 psychiatrist literally like gave my data
12:52 to my ex-husband and now it's being
12:54 used against me in court or my data's
12:57 been breached and XYZ has happened. And
13:00 that made me realize: 1: people had
13:02 absolutely no control and 2: they had
13:05 nowhere to go. Their data's been lost
13:07 and nobody was listening to them.
13:09 The next thing that built upon that
13:12 was George and I had offices close
13:14 together for years and between George
13:17 and the rest of the team, we knew
13:19 government had a big problem. If you
13:20 don't know the problems in government
13:22 right now,
13:23 there is really no data governance and
13:26 with what's happening with technology
13:28 and the transition the last 30 years,
13:30 what used to be due process rights and
13:32 ensuring you had processes that were not
13:34 arbitrary, that were not capricious,
13:36 that eliminated bias,
13:38 that is not what you have now with
13:40 technology. And so it became very clear
13:43 that if we truly believe that the basis
13:45 of government came from the individual,
13:48 and then they're the ones authorizing
13:49 government to do what they do,
13:51 but government is now just doing
13:54 whatever, you have got to have some
13:55 anchor of trust. And that was where my
13:58 first constitutional basis came from of
14:00 it's the individual. And that's why
14:02 I hold so strong to that in
14:05 the SEDI approach. And then lastly has
14:08 come of as we work to redesign
14:11 government, not just SEDI as a point at
14:13 which you engage, but what do all the
14:15 other government processes look like for
14:17 identity, for organizational identity,
14:20 to have end-to-end verifiability, to
14:22 have that provenance, and to identify,
14:25 you know, where is automated
14:26 decision-making going to fit in and
14:27 these artifacts government has to create
14:29 so you can hold them accountable, you
14:31 can't do any of that without identity
14:34 to know who are the
14:36 accountable parties and who's been
14:37 wronged. So all of that together last
14:41 five years has
14:43 for me created a, essentially, an
14:45 undeniable truth of we have to fix
14:47 identity or we are not going to have a
14:50 trusted government in the future.
14:52 So as you can see we have a very
14:54 passionate, well-qualified group to talk
14:56 about the elephant in all of its various
14:58 facets. So what I want to do for the
15:00 about the next 15 minutes is I want to
15:01 talk a little bit about the topic
15:03 area. So we're going to start with Chris
15:05 for the for the government perspective
15:06 and then anyone on the panel jump in to
15:08 add additional perspective. So we can
15:11 acknowledge that public and private
15:13 partnerships are not new. Historically
15:15 their value is questioned and often
15:17 debated. We don't know if they deliver
15:20 on what they say they're going to
15:21 deliver on. So, describe for us, Chris,
15:24 how you view SEDI's engagement with the
15:25 KERI community and how that's going to
15:27 benefit all the parties involved.
15:30 Does anybody know how we started the
15:32 engagement with the KERI community?
15:36 How many actually know that inception
15:38 event? Okay. Well, let me tell you this.
15:41 It started with,
15:43 Sam and Timothy and Mike Lahey,
15:47 sat us down in a room with Alan
15:50 Fuller and myself and a couple others
15:52 and they were like, "We have the
15:54 solution for you."
15:56 And we were like, "You are so
15:59 full of it."
16:00 [laughter]
16:00 But just like
16:05 I think you'll find the whole Utah team,
16:07 we are willing to sit down and listen to
16:08 anyone. If you have a good idea, it
16:09 doesn't matter who you are, we sit down
16:11 and listen to everyone. So, we listened
16:13 and we listened and we listened and
16:15 before long,
16:17 It was a “We think there's
16:19 something here”. You learn things that
16:21 you can't deny.
16:22 And so that passion from the
16:26 the KERI community and their persistence
16:28 in bringing facts to the table, we've
16:30 been very fact-driven. That's what's
16:32 impressed me is you come to the table,
16:35 you bring facts, you've educated us cuz
16:37 we weren't experts, we verify and
16:39 validate on our end, but then we've
16:42 created this reciprocal relationship
16:44 of what are the facts, let's have an
16:45 honest discussion. I can assure you
16:47 every time we meet with any of you, we
16:48 bring in skeptics as well to challenge
16:50 it and we've had meetings where we have
16:52 Sam, we had Phil Windley and we had
16:54 Steve McConnell all in a room, you know,
16:56 kind of battling out in a way to get to
16:58 first principle truths and we've gotten
17:01 to the point now where I feel very
17:02 comfortable in just having honest
17:04 conversations and we've said everyone
17:06 else, bring mDoc, bring W3C, let's have
17:08 that conversation of how it fits
17:09 together and to me that's resulted
17:13 in how we have engaged with the KERI
17:15 community and then the basis of how
17:17 we're engaging going forward of
17:19 just what are the problems, what are the
17:20 facts.
17:22 And then because of that trust built,
17:24 I feel loyalty because it was
17:27 partly created in Utah to help that
17:29 community thrive cuz there's not many
17:31 like it. And if we can scale that and
17:35 that type of engagement and truth
17:36 finding, you can do really amazing
17:38 things when you have passionate people.
17:42 Anyone else want to jump in?
17:45 So, DirectTrust as an organization was
17:47 born out of a groundswell of
17:52 basically volunteer effort initially if
17:54 just in fact, I don't know if you
17:55 were involved in the in the Direct
17:56 Project initially or not, but
17:58 watching closely. So, the Direct Project
18:00 was like 150 different
18:02 organizations and individuals who were
18:04 involved in this exercise.
18:07 The idea was we need to be able to do
18:09 secure identity assured communication in
18:12 healthcare. That was the goal, right?
18:13 That was the goal. This is 2012.
18:18 This is coming out of the HITECH Act,
18:21 which is basically legislation that
18:23 says all of the electronic health record
18:25 companies are going to get a big boon as
18:29 all of the doctors can basically get
18:31 paid to implement healthcare
18:35 systems to move
18:37 from paper,
18:39 to actual electronic systems.
18:40 And that all just really happened very
18:42 quickly. So, the Direct Project was born,
18:44 kind of, in that crucible, but it was a
18:47 public private partnership. So,
18:49 the first thing that we did was they
18:52 they actually were stood up within the
18:54 ONC as the as a part of the national
18:56 coordinator's work. And then the
18:59 national coordinator gave
19:01 a couple of years of support economic
19:04 support to actually stand up the
19:06 organization. And so, since
19:09 2014, DirectTrust has had no economic
19:12 support from the federal government. But
19:14 that
19:15 short period of time where we had
19:17 federal relationships, actually the
19:19 relationships have continued, but the
19:21 economic relationship has not continued.
19:23 So, we do have one aspect today,
19:25 interestingly, we've talked about this
19:27 UDAP exercise. We're talking about the
19:29 Root of Trust that's associated with
19:31 that
19:32 is a cryptographic Root of Trust that is
19:34 an X.509
19:36 based PKI framework.
19:39 And let me tell you the challenge that
19:40 we have with it. It is not
19:42 extraterritorial.
19:44 It's bound to TEFCA. It is
19:48 invented and used intended only
19:51 be used in the TEFCA area. So, the
19:53 opportunity with this eLEI exercise for
19:56 us is to take something that is good
20:00 anywhere it's presented for
20:03 the same benefit of identity assurance
20:05 that a PKI framework can be used for.
20:08 So, we're intensely interested in this
20:11 exercise and very excited about
20:13 an ongoing relationship with GLEIF
20:15 and also hopefully with SEDI.
20:18 You had Ryan Hamilton
20:20 here yesterday and he was one of the
20:23 very early organizers, along with people
20:25 like Aneesh Chopra,
20:27 around the CARIN Alliance. Well, that
20:30 has now also evolved into… It's an
20:31 accelerator within HL7. And I think HL7
20:35 itself, those accelerators are
20:37 great example of
20:39 public-private partnership. So, really
20:41 what happens… I'm retained by HL7 to
20:44 help write some of those standards for
20:46 the DaVinci project, for the
20:48 accelerator. So, we're focused around
20:50 payer-to-provider. So, I've written
20:52 payer data exchange. Well, what you see
20:54 happening there is CMS is watching. In
20:58 fact, CMS
21:00 has a contract out there where there's a
21:02 whole bunch of contractors
21:04 that they have embedded into HL7 to help
21:09 write implementation guides to help
21:11 develop testing protocols, to help
21:15 develop the educational materials,
21:17 because the secret is you know, Congress
21:20 will go and set legislation, they'll
21:22 write a law.
21:24 The agencies then have to regulate.
21:27 Well, you can't regulate what you can't
21:28 point at. So, they really need to come
21:31 to organizations like HL7 and say
21:34 let's help you get those standards
21:37 written so we can point to them to then
21:39 get people to implement. And so, this
21:42 it's been a really
21:43 it's almost an early warning signal as
21:45 to what are they going to regulate on
21:47 next because you see where the pressure
21:49 is on to get something published.
21:53 – So, I just wanted to add that GLEIF is an
21:56 ongoing part public-private partnership.
21:59 We are under regulatory oversight and
22:01 continue to be throughout our entire
22:05 existence.
22:06 And
22:08 the engagement with the public sector
22:10 being a private sector individual and
22:11 myself
22:13 started long before that, actually in my
22:16 my standards role
22:17 at the international level.
22:19 And I think that being involved in
22:22 public-private partnerships and making
22:24 them work
22:26 that it's important in order to be able
22:28 to realize that bringing
22:30 viewpoints and sensitivities
22:33 and important points together
22:37 from the private sector and the public
22:38 sector
22:40 actually produces better conversation,
22:43 better discussion, better debate, and
22:45 hopefully in the end better solutions
22:48 than if it was a completely, you know,
22:51 one-sided discussion.
22:53 Also, it's sensitized me over the years
22:57 that I need to believe in, you know,
22:59 exactly what I'm putting forward and I
23:01 need to speak facts and I need to
23:03 understand
23:05 what I'm talking about and it
23:07 really sold us at GLEIF
23:10 in order to be able to decide to develop
23:13 the vLEI
23:14 when the people who
23:17 approached us and said that there's a
23:18 better way than the traditional way of
23:20 being able to do this were actually the
23:22 people who had built the previous
23:24 solution and were ready to move on.
23:29 – I would maybe just add a quick
23:32 thought here which is that with regards
23:33 to public private partnership and I
23:34 think we'll get into this
23:36 from a healthcare perspective. I've
23:38 seen what happens when the public part
23:40 of that partnership goes awry and they
23:43 just run at something on their own and
23:45 they don't enact
23:48 a partnership with the private market. I
23:50 think we've also seen the
23:51 alternative to that where the private
23:53 market starts to dictate terms
23:55 and I think in both cases
23:58 it is better if you get all of those
24:00 parties aligned. I think that's one of
24:01 the powerful things around
24:04 doing things like KERI that is so
24:06 open source, open standard. It
24:08 invites the collaboration and invites
24:10 the participation and it actually
24:13 defends both sides from being able to
24:16 just run amok.
24:18 – Thank you for all those answers. One of
24:20 the things that I've noticed with this
24:22 public private partnership approach that
24:23 we're taking is there's not a person we
24:26 don't talk to who realizes they're
24:27 ultimately going to be the beneficiary
24:29 of some of this technology. So we really
24:31 appreciate the fact that everyone's
24:33 putting forward the effort to say well
24:34 wait a minute.
24:35 Ultimately this is going to impact me.
24:37 How do we do it the best way and
24:39 that open discussion and that dialogue
24:41 has been super helpful for us. Well we
24:43 are at KERI council, let's take this
24:45 directly to a KERI question and this
24:47 one I'm really interested to see where
24:49 everyone goes on it. Regarding the
24:51 healthcare industry
24:52 what is the biggest problem you see KERI
24:55 solving in the time horizon of the
24:57 next 5 years.
25:00 Anyone jump in.
25:02 – Yeah, why don't I go first?
25:05 We have to solve organizational identity
25:08 and the thing I see around
25:11 digital identity particularly for
25:13 individuals is it's all about context.
25:16 Right? So, you've got to be able to tie
25:17 those threads together.
25:19 And that's where I see how we can
25:21 implement the vLEI, the ACDCs, these
25:25 here. All of the this technology to
25:27 basically say
25:29 I'm part of this organization. I'm
25:32 allowed to do these things. This is the
25:35 type of transaction I want to be able
25:37 to take on. You know,
25:39 I think some people already said that.
25:41 We exist in many different facets.
25:44 I'm in
25:46 Utah in the winter, I'm a ski
25:48 instructor. So, I have a
25:50 an employee badge for that
25:53 and I also have one for my day job.
25:56 They're totally different, right? And
25:58 give me different permissions
26:00 based on the context of am I working
26:03 there or not. So, we have to get this
26:05 problem of being able to clearly
26:08 identify and prove and be able to root
26:10 out bad actors at the organizational
26:13 level
26:14 and relate it to individual identity as
26:17 well.
26:18 Can I interject just really
26:20 quickly? 73% of all cyber attacks
26:23 that happen in the US healthcare
26:24 ecosystem come from third parties first.
26:27 The bad actors, one, we're the most
26:29 targeted industry. Two, they know
26:31 exactly how to get in and that's through
26:33 the insecurity of the identities
26:36 established between parties in those
26:39 connections. I think if there is
26:40 anything that KERI is going to do in the
26:42 next 5 years, it's going to take that
26:43 73%
26:45 and plummet it to the ground. I think
26:47 we'll be able to solve the largest
26:49 problems in that connectivity. – And
26:51 something like 60% of providers that are
26:54 hit by a ransomware attack go out of
26:56 business. – So I can tell you also
26:59 just from… So, we also accredit
27:01 healthcare organizations for their
27:02 cybersecurity capabilities. And
27:05 as we review the activities of
27:08 folks in post-breach world, what happens
27:11 what you find out is most of the
27:14 breaches are caused by the use of
27:17 a credential that is actually a
27:19 valid credential. So, you're talking
27:20 about people who are using someone
27:22 else's credential
27:23 for nefarious purposes. And once they
27:26 get in that initial door, they're able
27:28 to then use
27:29 AI, for example, to get
27:32 to traverse the entire network
27:34 once they're inside. So, from my
27:36 perspective, being able to move the
27:38 entire healthcare ecosystem from weak
27:42 credentials
27:43 to a model that is actually
27:44 password-free would be the biggest thing
27:47 we could do for the workforce in
27:49 healthcare. I think that would
27:51 be the best outcome.
27:53 I also think that in general that
27:55 the world needs a veracity engine
27:59 and we don't have one.
28:01 So, there needs to be a veracity
28:04 engine. So, when I appear online, when I
28:06 appear online in any context, like when
28:09 I'm talking to you over Zoom, you should
28:11 be able to see who I am, that I am who I
28:14 say I am, reliably. And that should be, I
28:17 think, and that's if I want my
28:19 identity to be shared. And like these
28:21 things I think are so important to
28:22 establish. I think the policy focus is
28:26 really important though. If the policy
28:28 doesn't happen right, I think this is
28:29 what Utah has done so well. You know,
28:32 first principles, policy first. I think
28:35 that has a huge impact.
28:38 – I'm going to give a slightly different
28:39 answer here. It's going to be
28:40 controversial.
28:42 This is from the policy perspective
28:44 of what needs to be done in 5 years to
28:46 actually get lots of money put into the
28:49 ecosystem and to align interest with
28:51 policy makers to get them to run
28:52 legislation and actually get the market
28:55 going cuz we've had breaches and
28:56 security and lack of trusted identity
28:59 and provenance for decades and it hasn't
29:01 fixed the issue. What is the one topic
29:04 everybody's talking about now and
29:05 pumping money into and it's AI? And so
29:08 if you want to solve all of these
29:10 problems, you've got to tie it to some
29:12 AI use case which is where all the money
29:14 is going. And so Utah did something
29:17 really unique and this is just for
29:18 everyone to think about as you're
29:19 working on the problems.
29:21 They have been in national news
29:22 because they did the first automated
29:25 prescription issuance from AI,
29:27 coming out of our regulatory sandbox.
29:29 So Utah's created some really unique
29:31 things to allow
29:34 AI to be used. We know in this room what
29:38 KERI and ACDC is going to bring to the
29:41 AI ecosystem in terms of provenance
29:44 and then associated the data or to AI
29:48 agents having being delegated with
29:50 authority to act on somebody's behalf.
29:53 And so I think it's critical to tie
29:56 in some of these unique capabilities to
29:59 AI and not show that we're reducing
30:02 fraud or losses but to show some
30:05 efficiency gains or things that directly
30:07 impact individuals. So if you can start
30:09 saying because we have proven,
30:13 you know, verifiable delegation for this
30:15 agent acting on another doctor's behalf
30:18 to start streamlining prescription
30:20 issuance and lowering cost, that's going
30:23 to get people excited. And if we can
30:25 prove the use of this technology over
30:27 the next, I don't think it's 5 years, I
30:29 think it's the next 3 years,
30:31 that is going to start turbocharging
30:34 the digital identity and verifiability
30:36 approach.
30:37 – Okay, who in the room just registered
30:38 KERI.ai? Did that Did that just happen?
30:41 Okay. Jared, go ahead.
30:44 – I agree with what
30:46 Chris is saying and really my
30:50 thought there is that
30:51 this is a problem that can't wait
30:54 and this is a problem that people should
30:55 be thinking about and working on
30:57 already. And what I guess
30:59 what I'll say is while we haven't moved
31:01 some of the work we're doing at Health
31:03 KERI around AI into open source, I
31:05 mean, we probably won't in the near
31:07 term, we definitely want to entertain
31:10 conversations with folks that look at
31:11 that and see it as a problem the same
31:13 way Chris does.
31:13 – And I will say to do what I just said,
31:15 you already have to do everything you
31:17 just said. It's just what's the story
31:19 you're going to tell and that's an
31:21 amazing story to tell that will get
31:23 people to put more money into it.
31:25 – So Karla, I'm going to lean on your
31:26 organizational experience that you've
31:28 had.
31:30 Given what you've seen in creating
31:32 verifiable organizational identity, what
31:34 do you anticipate is going to be the
31:35 practical friction or challenges that
31:37 healthcare organizations are going to
31:40 encounter going through this process?
31:42 And then, panel, listen up. My question
31:44 to you would be is how do we help
31:45 mitigate those issues?
31:50 To begin with,
31:52 I think that
31:53 the first thing is that
31:56 people are used to doing things, or not
31:59 doing anything at all, or doing things a
32:01 different way. So, there's going to need
32:03 to be a change in behavior.
32:05 And the reason why the change in
32:08 behavior is going to need to be
32:10 explained to them.
32:12 And that's a challenge for us.
32:14 Not to get into the technical details.
32:17 To focus on the user experience and
32:19 what the benefits are in order to be
32:22 able to target whether it's doctors,
32:24 whether it's patients, whether it's
32:27 payers and the plans. As we've
32:30 been speaking with healthKERI and
32:32 we've been speaking with DirectTrust.
32:35 I'm learning more and more about the
32:36 healthcare industry and the fact that
32:42 there are
32:43 data inconsistencies,
32:46 there are
32:47 efficiencies that need to be
32:50 exploited
32:52 and identity and verifiable identity is
32:56 at the core of all of these things.
32:59 And for us to be able to leverage what
33:02 we've already
33:04 created and
33:06 to see this applied in this way, to be
33:10 able to take a problem
33:12 and say, we can look at our process that
33:17 we have here
33:18 and we can explain to our members that
33:21 they're going to want to see their
33:24 credentials registered in the provider
33:26 registry so that it reflects the real
33:28 situation in the world,
33:31 I think is an improvement. In order to
33:34 be able to
33:36 to
33:37 also apply the
33:40 the credentials to the plans.
33:43 And so you know who is associated with
33:45 what plan and also to just disambiguate
33:49 the providers themselves. I go back
33:52 to the example that Scott gives to say
33:55 which St. Mary's is it.
33:57 And
33:59 you know, we had
34:01 I guess the answer kind of like sitting
34:03 there in the LEI repository
34:06 and we are glad in order to be able to
34:09 know that there is another industry and
34:12 another domain that can benefit from the
34:15 same kinds of principles that we
34:18 wanted to promote in the first place.
34:24 – I did want to say,
34:27 you asked the question about barriers,
34:29 like so what's going to keep us from
34:30 being successful? I think
34:34 I'm new to KERI. I think KERI is
34:35 incredibly interesting and exciting, and
34:37 I'm a kind of a
34:39 propeller head, but not
34:41 not my propeller is kind of just drawn
34:42 in crayon. But so but I what I've got
34:45 to tell you is that
34:47 that KERI's going to have the same
34:48 challenge that the X.509 community has,
34:50 which is y'all speak Eldish.
34:54 And so
34:55 you're going to have to translate this
34:56 into English, and really quickly,
34:59 because if you're going to try and bring
35:00 this to market,
35:02 we're going to have to start using words
35:04 that people understand. And we're
35:06 going to have to de-acronymify
35:09 because in this day and age,
35:11 I can tell you, we merged with an
35:12 organization called ENACT, and when we
35:15 did, we went and we de-acronymified
35:18 everything, cuz all their programs were
35:20 four-letter acronyms. I'm telling you,
35:22 this is really not a
35:25 2026 kind of a thing. That's a
35:27 1995 thing, right? So, acronyms are big
35:31 in technical space, because you can't do
35:33 these things without them, because you
35:34 can't describe something
35:36 technical in short words. Germans, of
35:38 course, just put words together. But
35:41 I'm telling you that this is, I think,
35:42 our biggest barrier.
35:44 What I heard some people explain here,
35:46 actually, I think it was a legislator,
35:49 it's hard to explain.
35:52 And I think that's that's probably our
35:53 biggest barrier is that we have to be
35:54 able to describe it very succinctly, and
35:57 with value proposition in mind, and with
36:00 words that people understand. If
36:02 there's a barrier here, that's the
36:04 biggest one.
36:05 – So I agree. I
36:07 think clarity in
36:08 language is the biggest hurdle. If we
36:11 can get to clarity of language, we solve
36:13 a lot of problems. I think the second
36:15 biggest hurdle,
36:16 And then the solution, honestly, is
36:19 money. And I wish that wasn't the case.
36:21 I wish we could talk about healthcare
36:22 being this folderol, and everybody
36:23 wants to be, you know, for the patient.
36:26 The reality is this industry is not
36:27 going to move unless there's money
36:29 attached to it. And that comes in two
36:31 forms. One is if companies like
36:33 HealthKERI can come and improve out a
36:35 model that KERI drives dollars for
36:38 companies like us, then a lot of
36:40 different ecosystem players are going to
36:42 come in. It's going to be new startups
36:43 competing with us on our level. It's
36:45 going to be people that are established
36:46 in the space that want to come in and
36:48 start doing what we're doing. But if we
36:49 can show money, we can move the market.
36:52 The other side of this is for the
36:54 customers, the groups that will be paying
36:55 for these new services, they need to see
36:57 money as well. For them likely, they
37:00 will see that in two forms. It's going
37:01 to be a reduction of cost or an increase
37:04 in business. If they can prove that
37:06 they're more trustworthy, they can
37:07 capture more customers. If they can do
37:09 this automatically, they will save on
37:11 COGS. So, I think it's both the
37:14 biggest barrier and if we can solve it,
37:16 we'll be the biggest activator because
37:18 people will forgive your language
37:20 if there's a big pile of money behind
37:22 your acronyms.
37:25 – So, one industry that does not get rid
37:27 of their acronyms is the legal industry
37:30 and those terms and conditions don't get
37:32 any smaller and I do think we can move
37:34 the industry and I said this at the
37:35 SEDI summit
37:37 is what's the regulatory framework to
37:39 incentivize all these experts,
37:41 technologists, and the legal
37:43 departments to move this way and so
37:47 some of our tools would be like the
37:49 reciprocal verifiability. You want
37:51 organizational identity, we're going to
37:53 require them to do reciprocal
37:55 verifiability. Who is the org? Who is
37:58 the individual? That sounds like well,
37:59 it's a cost. Who's going to do this
38:01 then? But then we say, well, if you do
38:03 this, here's the limitations now on
38:05 liability. Here's the safe harbor to
38:07 function and we give them the incentives
38:10 to move toward reciprocal verifiability
38:13 and to use tools that have the
38:15 capabilities KERI provides and that
38:18 should take away enough liability or
38:21 provide enough incentive for them
38:23 to at least start in their
38:24 transformation to move this direction.
38:27 And especially when we start tying that
38:29 to AI, I think this is a perfect
38:30 example. We say, "Your AI agent must
38:33 have some verifiable form to
38:36 say that they're acting on behalf of the
38:38 entity and who provided that
38:39 delegation." And if you do this, then
38:42 you can be in the sandbox in Utah. Those
38:44 are the incentives that I think
38:46 regulators can help with to move
38:49 things.
38:52 I want to pull a few threads together
38:54 here. The yes, we need to speak in very
38:57 plain language to folks as to what
39:00 we're trying to do. The
39:03 problem is yes, legal and government
39:05 love their acronyms. So, we've got to
39:07 also meet them there.
39:10 What we need to do is really think about
39:13 don't make it too complicated.
39:16 And also try and tie it back to things
39:18 they understand.
39:19 I jokingly tell a story about how I
39:22 actually got blue Button Built at CMS
39:25 and got it out through ATO, their
39:28 authorization to operate, so that it
39:30 went out and into the
39:32 marketplace.
39:33 And I say, "I basically designed the
39:35 project so nobody had to make a
39:37 decision,
39:38 right? So, that you always could point
39:41 to precedent so that they could say,
39:43 'You've already done that.'"
39:45 And if you were listening
39:47 to what we were saying this morning,
39:49 a lot of what we've done there is to
39:51 say, "This is just a small change on top
39:54 of what you're doing already. It's the
39:56 same type of technology. It's just a
39:58 different cryptographic key, right?" So,
40:02 that you help them make
40:06 the intellectual jump.
40:08 – One other thing to consider is what is
40:11 the use case you're building for? We've
40:13 had many verifiable credential companies
40:16 come in from KERI and every space
40:18 and they're selling a product for a use
40:21 case which is not the low-hanging fruit
40:23 that's needed. And so there are many
40:25 entities with really smart people if you
40:27 simplify what you're doing enough but
40:29 hit that right use case and there's some
40:31 out there. This isn't the healthcare
40:33 industry but we had we had Maverick in
40:35 here on the first two days of the SEDI
40:36 summit and they actually said, "Hey, if
40:38 you want, we've already made SEDI
40:41 legal for purchase of alcohol and
40:42 tobacco." And they said, "Well, if you
40:44 have the implementation guide, we could
40:46 have this implemented in 6 months and
40:47 we'll start accepting SEDI." And
40:49 that's cuz there is a product market fit
40:51 there that perfectly aligned with the
40:53 protocol we're looking at for SEDI. So
40:55 what are the right healthcare use cases
40:57 as well when and we don't need the whole
41:00 platform. I think it's what's that to
41:02 get you in the door to show value and if
41:05 you do that, then you can build from
41:06 there. Yeah.
41:08 Fantastic point and you're
41:10 right. This is all tying together. I
41:11 love when a when a panel just leads
41:13 towards that natural conclusion.
41:15 Let's talk about the ultimate
41:17 stakeholder in the healthcare industry
41:19 and that's the patient. We know that the
41:21 trust is broken in terms of the personal
41:24 data and the protections around it. We
41:25 say HIPAA a lot but that doesn't mean
41:27 anything when you're lying in the
41:29 hospital bed and
41:31 we do have some representation on here
41:33 from people who are in government or
41:35 who've done some pretty remarkable
41:36 things with government regulation trying
41:39 to help the industry move forward. So if
41:41 you can give me your closing remarks
41:44 individually and if you had the magic
41:46 wand that you could change one
41:47 regulation or add something at a state
41:50 level or a federal level that could
41:53 really kickstart everything in the right
41:54 direction, what would that be?
42:00 – Well, I'll tell you know, CMS is the
42:03 is the organization that has the biggest
42:04 hammer. I mean their hammer is
42:06 actually
42:08 is it a spoon with sugar in it or is it
42:10 hammer? I don't know which, but it's
42:11 very, very, very authoritative and
42:16 powerful. So, their two
42:18 opportunities are reimbursement
42:22 and
42:23 regulation. So, when they regulate,
42:26 if for instance, they were to
42:31 require
42:32 provider organizations to all have
42:35 vLEIs in order to get into the national
42:37 directory,
42:38 it would be an instant driver.
42:41 And this is a national directory
42:43 they're trying to build that is
42:46 failing on the subject of organizational
42:47 identity.
42:49 So, this would be a huge opportunity for
42:50 them. They haven't
42:53 learned to say GLEIF yet. They call it
42:55 GLEEF. They are confused. So, I
42:58 I'm trying to bring them forward and say
43:00 once they can pronounce it, I'm hoping
43:02 that they can also support it.
43:09 – It's a tough one. I
43:11 I think I've moved beyond this, but back
43:15 when I was with CMS, sort of 2017,
43:18 2018, there was a lot of talk about
43:21 Medicare for all.
43:23 And I was saying, "No, no. Why
43:25 don't we just start with Medicare
43:27 registration for all? So, that you got a
43:30 standard ID that you could take." And I
43:33 I've sort of moved beyond that to say
43:35 what I would love to see is probably
43:37 regulation that says,
43:39 "If I as a patient
43:42 present an identifier or an identity to
43:47 a practitioner, to an organization in
43:50 healthcare,
43:52 you should damn well put that into my
43:54 record.
43:59 As they start sharing data and you go to
44:01 more and more places, you can actually
44:03 patient match. I had a colleague
44:07 in the ideal lab at CMS who was there to
44:09 do patient matching.
44:11 You'll know who he is, if he ever sees
44:13 the video.
44:16 Every time I went
44:17 to see him, I'd say, you know, patient
44:20 matching is so much easier when you
44:22 involve the patient.
44:27 – So I haven't become a healthcare expert
44:30 overnight. So
44:32 I'm going to take a little bit of a
44:33 different tack here.
44:36 I would like to be able to see any law
44:39 going forward that
44:42 involves identity
44:44 in order to be able to come at it from
44:47 what are you trying to accomplish? What
44:51 benefits are you trying
44:53 to gain? So what features then do you
44:57 need in order to be able to have in a
45:00 solution?
45:02 Or to have the law be principle-based.
45:06 If you have need for
45:09 to be able to protect for example
45:13 children or elderly parents, do you
45:16 need delegation?
45:18 Are you trying to be able to
45:21 instantiate or give credentials in order
45:24 to be able to know the real situation of
45:28 authority within a company in the area
45:30 of organizational identity
45:33 then you're going to need a feature in
45:36 your in your identity solution that
45:38 gives you that. What level of assurance
45:41 to know that it's really the person who
45:45 is supposed to be able to be
45:47 authorized to get that credential? Do
45:49 they have that role? What level of
45:52 security am I comfortable with?
45:55 Do I need automated verification? Those
45:58 types of things. And when you answer
46:00 those questions the law then gives you a
46:04 guideline or a road map
46:07 in order to be able to pick
46:10 a good solution. And for me, I think
46:13 that changing the dynamic of
46:17 being able to come at the law in
46:20 that way would be an advantage.
46:25 – So I've been looking around the room and
46:27 I'm pretty certain that our friends from
46:29 Libertas are no longer here.
46:32 So I think I'm safe to say this without
46:34 getting a water bottle checked to my
46:35 head.
46:36 I would
46:39 at this point if I could wave a magic
46:40 wand
46:41 I would get rid of section 510 from the
46:45 HHS
46:46 labor bill. That section of that law
46:50 made it essentially
46:52 illegal for the federal government to
46:54 issue a national patient identifier.
46:58 And I agreed with all of the reasons
47:01 that law was in place in terms of
47:03 privacy and the concerns for patients up
47:06 until very recently with some of the
47:09 work that's been happening with SEDI and
47:11 other initiatives. And so now today
47:14 knowing that we have
47:17 a way to do that national patient
47:19 identifier that is privacy preserving,
47:22 that manages to keep the patient in
47:24 charge of themselves digitally,
47:27 I think that should be repealed
47:29 immediately. And again, if Connor or
47:33 Jason from
47:34 Libertas see this, we can talk later
47:37 about the implications.
47:40 – This is an unfair question for me.
47:43 [laughter]
47:45 – What would you like to do?
47:48 – Cuz
47:48 there's this bad thing that happens when
47:50 I say what we want to do in regulation
47:52 then I have to make recommendations.
47:54 It ends up happening.
47:56 Now some of this I've said
47:59 big picture we know privacy and security
48:01 is broken in the country. The amount
48:04 of correlation happening with your data
48:07 and how that profiling and the
48:09 scoring and predictive analytics is
48:10 occurring in every sector, private
48:13 sector, public sector, healthcare,
48:15 social services, education. You would be
48:18 amazed in this room and me
48:20 and George have seen these systems. And
48:23 so I'm coming at it from a different
48:24 perspective of what is coming from the
48:26 private sector industry and how that
48:28 would be used to exploit for
48:30 monetary or the public sector side to
48:32 try to influence you to make
48:34 different decisions.
48:35 I had seven years of experience in
48:37 privacy and security with human
48:39 services in Utah and I know HIPAA does
48:42 not work and the levels of
48:44 non-compliance for both privacy and
48:46 security. There's maximum use of data,
48:50 but these other things are viewed as
48:51 just hindrances or there's not the
48:53 expertise to do.
48:57 And I think this was alluded to
48:59 on the legislative panel on the
49:01 SEDI summit. What I am working
49:03 toward is
49:05 I think there needs to be a total
49:06 rewrite of the approach. And so our
49:10 goal is that you know, starting with
49:12 identity
49:13 end-to-end verifiability and zero trust.
49:17 Move toward the duty of loyalty
49:20 model where anybody with your data
49:22 should be acting in your best interest
49:24 and this crosses all industry. This
49:25 crosses healthcare, this crosses
49:27 financial. And if you're aligned with
49:30 that end-to-end verifiability, we
49:32 modernize the laws for provenance
49:34 requirements, we figure out, you know,
49:36 how to track these terms,
49:38 Then we will be creating also some
49:40 extreme safe harbors for entities to act…
49:43 to work with knowing mistakes are
49:45 going to happen, but I think that will
49:47 create a more balanced free market and
49:49 set us up for coming in the age of
49:52 of AI and automation, but anything
49:55 absent… a total overhaul
49:58 for both public and the consumer
49:59 side,
50:01 it's going to be a very fragmented
50:02 disparate market and the public is going
50:05 to be confused and businesses are going
50:07 to struggle to maintain our economic
50:09 dominance that we have here in the US.
50:12 – So, since Chris pulled me in by saying
50:14 I'd seen some of this stuff, too, I'm
50:16 just going to say, yes, that's true. I
50:18 mean, it's there have been many times
50:20 when we've effectively done our
50:21 architecture reviews and opened up a
50:23 system just to find that it has a
50:24 digital hamster wheel still spinning and
50:28 we have needed to change and some of
50:30 that's going to be in behavior, as we've
50:31 talked about, and the incentives need to
50:34 be there to help us with the change.
50:36 So, as we started this day out, Sam had
50:38 made a bold statement that this is the
50:41 potentially the year of KERI. I think
50:43 from what we've heard from this panel,
50:45 that's been corroborated. So, Sam, put
50:47 one more in the win column. Can we have
50:49 a round of applause for our panel?
50:51 [applause]
50:54 Thank you. [applause]