How KERI Enables Better Private-Public Partnerships - George McEwan

KERICONF26 Day 1 · 44:20

0:00 George McEwan | How KERI Enables Better Private-Public Partnerships | KERI Conference 2026

0:03 So, while we let Chris find a

0:05 chair, I'm going to go ahead and start

0:06 so we can stay on time. So, one of the

0:08 things I want to ask the panel

0:10 and each one of you will get an

0:12 opportunity to answer this question.

0:15 What I want to know is if you in 2

0:17 minutes or less, could you tell us a

0:18 little about your background and

0:21 what was the specific lightbulb moment

0:23 that drove your passion in trying to fix

0:25 digital identity?

0:28 So

0:29 I don't think this is on

0:35 I turned it on, but it didn't connect

0:36 anything.

0:38 This, however, does.

0:43 So, my background is actually kind of a

0:45 bizarre. I started [inaudible] about

0:47 an hour, so we're not going to do that.

0:50 but I think my healthcare IT

0:52 background began actually at the very

0:55 beginning of the the exercise

0:58 we're all involved in, right? So, my

1:00 first health… my first job actually

1:03 was in 1986,

1:05 which is when the 8088 was the

1:08 processor du jour. And fast forward

1:11 about 10 years from that point when I

1:13 went through a couple of life cycles of

1:16 career, I ended up being transferred

1:18 back and ended up in the healthcare IT

1:20 space. Actually got the…

1:22 My first healthcare IT job was

1:24 actually the bass player in my band got

1:26 me that job, so but actually my

1:29 original notion of why I identity is

1:32 important is really far back. It is

1:34 really actually back to the notion of my

1:37 first implementation of an EMPI, if you

1:40 know what that is. So, this is the

1:41 notion of a an enterprise master patient

1:44 index. So, the idea that you would know

1:46 who you were talking to reliably at that

1:48 point was a question of probabilism with

1:51 very little very little assuredly

1:54 about who those people were in any way.

1:56 So, pretty early on I realized that the

1:59 quality of the data that was being

2:00 collected to establish this was

2:03 poor. That their ability that actually

2:05 the organization I was working with at

2:07 the time was Kaiser Permanente Northern

2:08 California. They had a about a 30%

2:14 duplication rate in their system. And so, your ability to actually resolve

2:19 identity was the first thing that was my

2:21 light bulb moment. My next big

2:23 opportunity then was like, I don't know,

2:26 20 some years later when I was

2:28 responsible for a national network

2:30 deployment that was the Commonwealth

2:33 Health Alliance. And again, when that

2:36 first launched, its focus was not on

2:38 healthcare information exchange, but on

2:40 identity first. Because the expectation

2:42 was this was the problem you had to

2:43 solve. You had to figure out who you

2:45 were talking about at this point and

2:47 that point. What I quickly learned is

2:50 that we were still talking probabilism

2:52 and we were still talking 20%

2:54 duplication some 20 years later. I mean,

2:56 this stuff had not gotten even a little

2:58 bit better.

2:59 So, the notion that identifiers would be

3:02 important, I think for me really began

3:06 to click when we couldn't resolve

3:09 identity.

3:10 So, getting to identity assurance

3:12 wasn't something I was thinking about. I

3:14 was thinking about the fact you just

3:16 couldn't match people or records with

3:18 people. And so, the my light bulb moment

3:21 really was around identity resolution

3:23 and that's really my was my raison

3:26 d'être. But then, now in this setting,

3:29 what we're trying to figure out is how

3:30 to make it possible for us to be sure

3:33 that people are who they say they are

3:35 when they're contracted over the

3:36 internet. This is very different problem

3:39 than identity resolution, but it has the

3:41 same core problem, which is that people

3:44 go through processes to do this

3:46 exercise, this initial exercise. The

3:49 initial exercise is the first

3:50 transaction. The first transaction is

3:53 the failure transaction. That is the

3:55 fact. So, if you can't get the first

3:58 transaction right, all other

4:00 transactions beyond that will fail.

4:02 So, this was my big aha moment. I've

4:05 been saying the first transaction for

4:06 about a decade. I think it's the most

4:09 important transaction of all. And if you

4:11 can't get the right stuff in the door

4:13 the first time, then you're trying to

4:15 match to it,

4:17 all bets are off. Not going to work.

4:19 So, that to me was my light bulb moment.

4:21 It's maybe, I don't know, 1993.

4:24 It's a good time to have it. We're just

4:25 going to do this like a slow stadium

4:27 wave. We'll just keep rolling on down.

4:29 Okay, well, I'll give it a try. I

4:33 suppose that light bulb moment for me

4:36 probably came back in

4:37 2015. I'd started with CMS. We were

4:41 working out how we were going to make

4:42 data available to

4:44 patients, to beneficiaries. And it

4:48 was going to be done via third-party

4:50 applications, health applications that

4:53 we're seeing

4:54 pretty typically these days.

4:56 And I just asked this the

4:58 really the simple question is there a

5:00 way

5:01 that we could automate the registration?

5:05 But if we're going to do that, I really

5:07 need to be able to have some confidence

5:09 that the organization that is

5:12 presenting themselves

5:14 is who they say they are. And so

5:18 I started this the way I seem to do

5:21 quite often. I wrote a blog.

5:23 It happened to be for HHS, and it simply

5:26 asked that question. And

5:28 that led to conversations. And I think,

5:30 Scott, we even had conversations

5:32 with the DirectTrust around is there a

5:34 way I could call an API and check with

5:37 you guys whether you know this

5:39 organization. And so that really evolved

5:42 from there

5:43 more directly around

5:45 healthKERI.

5:47 Back last year,

5:49 again, I wrote an article because I'm

5:51 thinking how do we operationalize these

5:54 APIs that

5:55 a thousand health plans are going to

5:57 have to implement and tens of thousands

6:00 of provider organizations

6:02 and I don't want to do all this

6:04 work on

6:05 defining what these

6:07 APIs are

6:08 and have them sit there and do nothing

6:09 because that doesn't benefit the patient

6:11 whatsoever.

6:13 So how can you operationalize that?

6:16 And realizing that the manual methods we

6:19 used for patient access API

6:22 which takes

6:24 days, weeks to go through

6:26 is totally non-scalable.

6:28 And so

6:30 I asked the question

6:32 how can we have an organizational

6:34 identity that we can check?

6:37 And that sort of led me down the path

6:39 to KERI.

6:41 Enough said.

6:51 Coming at it from a completely different

6:55 angle.

6:56 My background is in financial services,

6:59 particularly in transaction services,

7:01 which at the time that I started

7:04 wasn't a very common or

7:07 what would I say attractive part of

7:09 financial services to go

7:12 into.

7:13 But I've spent most of my career around

7:17 identifiers

7:19 and identification.

7:21 Which is quite different than identity.

7:24 Although a good foundation and a good

7:27 basis for the way that my career at GLEIF

7:30 and my involvement in this community has

7:33 has led to.

7:34 So…

7:37 come the financial crisis as I

7:39 explained before,

7:41 my background in standards led me to be

7:43 involved in the development of the LEI,

7:45 of course, another identifier.

7:48 And then it was its usage,

7:51 especially guided by

7:53 its initial usage in order to solve

7:56 an initial problem. We want to know who

7:58 these organizations are who are

7:59 responsible for a particular function in

8:02 a particular context, just to generalize

8:04 it, basically.

8:06 And then as we started to

8:10 to operate for a few years,

8:13 in our strategic discussions at GLEIF,

8:16 we started to talk about we have a high

8:17 assurance

8:19 identifier that's global in nature, that

8:22 can identify

8:25 a very broad list of

8:29 entity legal forms or legal entities in

8:32 effect.

8:34 Because of the effort that we put into,

8:38 or our partners put into validating this

8:40 identifier and the effort that

8:42 GLEIF puts in managing the global LEI

8:45 system and the quality of that system

8:49 and its operations,

8:51 why don't we look forward in order to be

8:54 able to see how we could make this

8:55 relevant in the digital world, which is

8:58 the way that the world is going?

9:00 And so this is when we first started to

9:04 get involved with the identity community

9:07 and I'll call it the identity industry,

9:09 which of course I had no idea up until

9:12 this particular point even was a thing.

9:15 And so luckily we were able to

9:19 get connected with and

9:22 be welcomed into the community by many

9:25 of the experts that we see here today,

9:27 who introduced us to the importance of

9:31 identity and not only identification but

9:35 verification, which of course led us

9:37 to wanting to be able to develop

9:40 the vLEI and then use the vLEI.

9:43 I have to say that it was an eye-opener

9:46 for me. My aha moment was actually not

9:50 as I was

9:51 day-to-day trying to be able to figure

9:53 out delivering on the strategy that my

9:55 CEO had given me in order to be able to

9:58 say, "Okay, let's make a verifiable

10:00 credential containing the LEI and

10:03 let's make it a success."

10:05 It was how clueless I was to how I was

10:09 exposing my own identity every day in

10:13 in the everyday things that I did

10:16 just as a natural person and a citizen

10:18 and how I naturally accepted anything

10:21 that people told me was secure

10:25 and was protecting my identity. I

10:27 took it just as face value.

10:32 So, Scott, you said your lightbulb

10:35 moment came in 1993.

10:37 I think mine came at the

10:38 exact same time. I was two.

10:41 At and I'm a little bit

10:43 tongue-in-cheek, but the truth of

10:46 the matter is that for my generation

10:49 we were born into… Now, I do remember

10:50 when we had dial-up installed in the

10:52 house. I'm not that young. But in

10:55 a real sense, I grew up in the digital

10:58 world. Like we had digital identity

11:01 before we had a term for a digital

11:02 identity. And we just accepted, you

11:04 know, in the in the halcyon days of

11:06 yore, you know, MySpace was the hot snot

11:09 and there was none of the concerns that

11:10 we had around it. But for my

11:12 generation, there's never really been a

11:15 demarcation between my identity in the

11:17 real sense in the real world and my

11:20 identity in the digital world. And so

11:23 for me it was I don't know that I ever

11:25 had a lightbulb moment. It was a

11:28 lifetime of experiences where you

11:32 know, XYZ got hacked, your credit card

11:34 gets stolen, your know, all of these

11:36 things and it wasn't until I started

11:39 to understand some of the things that

11:41 were possible with digital identity that

11:43 I went back to this whole life that I'd

11:45 lived and said,

11:47 there has to be a better way. We

11:49 have to do something different than

11:50 what's being done now. And you know,

11:52 I mentioned this earlier, but, I

11:54 guess, the coup de grâce on that

11:57 system was when I just realized the

11:59 fragility of the system we've built off

12:02 of poor identity structure and how that

12:05 could impact me as a patient.

12:08 I feel like a baby compared to this

12:10 entire group.

12:11 [laughter]

12:12 I'm a newcomer here.

12:15 I think I had three things that have

12:17 got me to this current this current

12:19 point that have I guess made me a part

12:22 of the identity movement. When I

12:24 first got into my role as chief privacy

12:26 officer, it was one of the it was the

12:28 first time the state had one. And I got

12:32 calls all the time from people that I

12:35 would sit on the phone for I think the

12:37 longest one was probably two or three

12:38 hours where I felt like I was like a

12:40 psychiatrist of they're just saying,

12:42 I've had this horrible thing happen and

12:44 I have no control.

12:46 And I've had cases where

12:48 women would call and say, my

12:50 psychiatrist literally like gave my data

12:52 to my ex-husband and now it's being

12:54 used against me in court or my data's

12:57 been breached and XYZ has happened. And

13:00 that made me realize: 1: people had

13:02 absolutely no control and 2: they had

13:05 nowhere to go. Their data's been lost

13:07 and nobody was listening to them.

13:09 The next thing that built upon that

13:12 was George and I had offices close

13:14 together for years and between George

13:17 and the rest of the team, we knew

13:19 government had a big problem. If you

13:20 don't know the problems in government

13:22 right now,

13:23 there is really no data governance and

13:26 with what's happening with technology

13:28 and the transition the last 30 years,

13:30 what used to be due process rights and

13:32 ensuring you had processes that were not

13:34 arbitrary, that were not capricious,

13:36 that eliminated bias,

13:38 that is not what you have now with

13:40 technology. And so it became very clear

13:43 that if we truly believe that the basis

13:45 of government came from the individual,

13:48 and then they're the ones authorizing

13:49 government to do what they do,

13:51 but government is now just doing

13:54 whatever, you have got to have some

13:55 anchor of trust. And that was where my

13:58 first constitutional basis came from of

14:00 it's the individual. And that's why

14:02 I hold so strong to that in

14:05 the SEDI approach. And then lastly has

14:08 come of as we work to redesign

14:11 government, not just SEDI as a point at

14:13 which you engage, but what do all the

14:15 other government processes look like for

14:17 identity, for organizational identity,

14:20 to have end-to-end verifiability, to

14:22 have that provenance, and to identify,

14:25 you know, where is automated

14:26 decision-making going to fit in and

14:27 these artifacts government has to create

14:29 so you can hold them accountable, you

14:31 can't do any of that without identity

14:34 to know who are the

14:36 accountable parties and who's been

14:37 wronged. So all of that together last

14:41 five years has

14:43 for me created a, essentially, an

14:45 undeniable truth of we have to fix

14:47 identity or we are not going to have a

14:50 trusted government in the future.

14:52 So as you can see we have a very

14:54 passionate, well-qualified group to talk

14:56 about the elephant in all of its various

14:58 facets. So what I want to do for the

15:00 about the next 15 minutes is I want to

15:01 talk a little bit about the topic

15:03 area. So we're going to start with Chris

15:05 for the for the government perspective

15:06 and then anyone on the panel jump in to

15:08 add additional perspective. So we can

15:11 acknowledge that public and private

15:13 partnerships are not new. Historically

15:15 their value is questioned and often

15:17 debated. We don't know if they deliver

15:20 on what they say they're going to

15:21 deliver on. So, describe for us, Chris,

15:24 how you view SEDI's engagement with the

15:25 KERI community and how that's going to

15:27 benefit all the parties involved.

15:30 Does anybody know how we started the

15:32 engagement with the KERI community?

15:36 How many actually know that inception

15:38 event? Okay. Well, let me tell you this.

15:41 It started with,

15:43 Sam and Timothy and Mike Lahey,

15:47 sat us down in a room with Alan

15:50 Fuller and myself and a couple others

15:52 and they were like, "We have the

15:54 solution for you."

15:56 And we were like, "You are so

15:59 full of it."

16:00 [laughter]

16:00 But just like

16:05 I think you'll find the whole Utah team,

16:07 we are willing to sit down and listen to

16:08 anyone. If you have a good idea, it

16:09 doesn't matter who you are, we sit down

16:11 and listen to everyone. So, we listened

16:13 and we listened and we listened and

16:15 before long,

16:17 It was a “We think there's

16:19 something here”. You learn things that

16:21 you can't deny.

16:22 And so that passion from the

16:26 the KERI community and their persistence

16:28 in bringing facts to the table, we've

16:30 been very fact-driven. That's what's

16:32 impressed me is you come to the table,

16:35 you bring facts, you've educated us cuz

16:37 we weren't experts, we verify and

16:39 validate on our end, but then we've

16:42 created this reciprocal relationship

16:44 of what are the facts, let's have an

16:45 honest discussion. I can assure you

16:47 every time we meet with any of you, we

16:48 bring in skeptics as well to challenge

16:50 it and we've had meetings where we have

16:52 Sam, we had Phil Windley and we had

16:54 Steve McConnell all in a room, you know,

16:56 kind of battling out in a way to get to

16:58 first principle truths and we've gotten

17:01 to the point now where I feel very

17:02 comfortable in just having honest

17:04 conversations and we've said everyone

17:06 else, bring mDoc, bring W3C, let's have

17:08 that conversation of how it fits

17:09 together and to me that's resulted

17:13 in how we have engaged with the KERI

17:15 community and then the basis of how

17:17 we're engaging going forward of

17:19 just what are the problems, what are the

17:20 facts.

17:22 And then because of that trust built,

17:24 I feel loyalty because it was

17:27 partly created in Utah to help that

17:29 community thrive cuz there's not many

17:31 like it. And if we can scale that and

17:35 that type of engagement and truth

17:36 finding, you can do really amazing

17:38 things when you have passionate people.

17:42 Anyone else want to jump in?

17:45 So, DirectTrust as an organization was

17:47 born out of a groundswell of

17:52 basically volunteer effort initially if

17:54 just in fact, I don't know if you

17:55 were involved in the in the Direct

17:56 Project initially or not, but

17:58 watching closely. So, the Direct Project

18:00 was like 150 different

18:02 organizations and individuals who were

18:04 involved in this exercise.

18:07 The idea was we need to be able to do

18:09 secure identity assured communication in

18:12 healthcare. That was the goal, right?

18:13 That was the goal. This is 2012.

18:18 This is coming out of the HITECH Act,

18:21 which is basically legislation that

18:23 says all of the electronic health record

18:25 companies are going to get a big boon as

18:29 all of the doctors can basically get

18:31 paid to implement healthcare

18:35 systems to move

18:37 from paper,

18:39 to actual electronic systems.

18:40 And that all just really happened very

18:42 quickly. So, the Direct Project was born,

18:44 kind of, in that crucible, but it was a

18:47 public private partnership. So,

18:49 the first thing that we did was they

18:52 they actually were stood up within the

18:54 ONC as the as a part of the national

18:56 coordinator's work. And then the

18:59 national coordinator gave

19:01 a couple of years of support economic

19:04 support to actually stand up the

19:06 organization. And so, since

19:09 2014, DirectTrust has had no economic

19:12 support from the federal government. But

19:14 that

19:15 short period of time where we had

19:17 federal relationships, actually the

19:19 relationships have continued, but the

19:21 economic relationship has not continued.

19:23 So, we do have one aspect today,

19:25 interestingly, we've talked about this

19:27 UDAP exercise. We're talking about the

19:29 Root of Trust that's associated with

19:31 that

19:32 is a cryptographic Root of Trust that is

19:34 an X.509

19:36 based PKI framework.

19:39 And let me tell you the challenge that

19:40 we have with it. It is not

19:42 extraterritorial.

19:44 It's bound to TEFCA. It is

19:48 invented and used intended only

19:51 be used in the TEFCA area. So, the

19:53 opportunity with this eLEI exercise for

19:56 us is to take something that is good

20:00 anywhere it's presented for

20:03 the same benefit of identity assurance

20:05 that a PKI framework can be used for.

20:08 So, we're intensely interested in this

20:11 exercise and very excited about

20:13 an ongoing relationship with GLEIF

20:15 and also hopefully with SEDI.

20:18 You had Ryan Hamilton

20:20 here yesterday and he was one of the

20:23 very early organizers, along with people

20:25 like Aneesh Chopra,

20:27 around the CARIN Alliance. Well, that

20:30 has now also evolved into… It's an

20:31 accelerator within HL7. And I think HL7

20:35 itself, those accelerators are

20:37 great example of

20:39 public-private partnership. So, really

20:41 what happens… I'm retained by HL7 to

20:44 help write some of those standards for

20:46 the DaVinci project, for the

20:48 accelerator. So, we're focused around

20:50 payer-to-provider. So, I've written

20:52 payer data exchange. Well, what you see

20:54 happening there is CMS is watching. In

20:58 fact, CMS

21:00 has a contract out there where there's a

21:02 whole bunch of contractors

21:04 that they have embedded into HL7 to help

21:09 write implementation guides to help

21:11 develop testing protocols, to help

21:15 develop the educational materials,

21:17 because the secret is you know, Congress

21:20 will go and set legislation, they'll

21:22 write a law.

21:24 The agencies then have to regulate.

21:27 Well, you can't regulate what you can't

21:28 point at. So, they really need to come

21:31 to organizations like HL7 and say

21:34 let's help you get those standards

21:37 written so we can point to them to then

21:39 get people to implement. And so, this

21:42 it's been a really

21:43 it's almost an early warning signal as

21:45 to what are they going to regulate on

21:47 next because you see where the pressure

21:49 is on to get something published.

21:53 – So, I just wanted to add that GLEIF is an

21:56 ongoing part public-private partnership.

21:59 We are under regulatory oversight and

22:01 continue to be throughout our entire

22:05 existence.

22:06 And

22:08 the engagement with the public sector

22:10 being a private sector individual and

22:11 myself

22:13 started long before that, actually in my

22:16 my standards role

22:17 at the international level.

22:19 And I think that being involved in

22:22 public-private partnerships and making

22:24 them work

22:26 that it's important in order to be able

22:28 to realize that bringing

22:30 viewpoints and sensitivities

22:33 and important points together

22:37 from the private sector and the public

22:38 sector

22:40 actually produces better conversation,

22:43 better discussion, better debate, and

22:45 hopefully in the end better solutions

22:48 than if it was a completely, you know,

22:51 one-sided discussion.

22:53 Also, it's sensitized me over the years

22:57 that I need to believe in, you know,

22:59 exactly what I'm putting forward and I

23:01 need to speak facts and I need to

23:03 understand

23:05 what I'm talking about and it

23:07 really sold us at GLEIF

23:10 in order to be able to decide to develop

23:13 the vLEI

23:14 when the people who

23:17 approached us and said that there's a

23:18 better way than the traditional way of

23:20 being able to do this were actually the

23:22 people who had built the previous

23:24 solution and were ready to move on.

23:29 – I would maybe just add a quick

23:32 thought here which is that with regards

23:33 to public private partnership and I

23:34 think we'll get into this

23:36 from a healthcare perspective. I've

23:38 seen what happens when the public part

23:40 of that partnership goes awry and they

23:43 just run at something on their own and

23:45 they don't enact

23:48 a partnership with the private market. I

23:50 think we've also seen the

23:51 alternative to that where the private

23:53 market starts to dictate terms

23:55 and I think in both cases

23:58 it is better if you get all of those

24:00 parties aligned. I think that's one of

24:01 the powerful things around

24:04 doing things like KERI that is so

24:06 open source, open standard. It

24:08 invites the collaboration and invites

24:10 the participation and it actually

24:13 defends both sides from being able to

24:16 just run amok.

24:18 – Thank you for all those answers. One of

24:20 the things that I've noticed with this

24:22 public private partnership approach that

24:23 we're taking is there's not a person we

24:26 don't talk to who realizes they're

24:27 ultimately going to be the beneficiary

24:29 of some of this technology. So we really

24:31 appreciate the fact that everyone's

24:33 putting forward the effort to say well

24:34 wait a minute.

24:35 Ultimately this is going to impact me.

24:37 How do we do it the best way and

24:39 that open discussion and that dialogue

24:41 has been super helpful for us. Well we

24:43 are at KERI council, let's take this

24:45 directly to a KERI question and this

24:47 one I'm really interested to see where

24:49 everyone goes on it. Regarding the

24:51 healthcare industry

24:52 what is the biggest problem you see KERI

24:55 solving in the time horizon of the

24:57 next 5 years.

25:00 Anyone jump in.

25:02 – Yeah, why don't I go first?

25:05 We have to solve organizational identity

25:08 and the thing I see around

25:11 digital identity particularly for

25:13 individuals is it's all about context.

25:16 Right? So, you've got to be able to tie

25:17 those threads together.

25:19 And that's where I see how we can

25:21 implement the vLEI, the ACDCs, these

25:25 here. All of the this technology to

25:27 basically say

25:29 I'm part of this organization. I'm

25:32 allowed to do these things. This is the

25:35 type of transaction I want to be able

25:37 to take on. You know,

25:39 I think some people already said that.

25:41 We exist in many different facets.

25:44 I'm in

25:46 Utah in the winter, I'm a ski

25:48 instructor. So, I have a

25:50 an employee badge for that

25:53 and I also have one for my day job.

25:56 They're totally different, right? And

25:58 give me different permissions

26:00 based on the context of am I working

26:03 there or not. So, we have to get this

26:05 problem of being able to clearly

26:08 identify and prove and be able to root

26:10 out bad actors at the organizational

26:13 level

26:14 and relate it to individual identity as

26:17 well.

26:18 Can I interject just really

26:20 quickly? 73% of all cyber attacks

26:23 that happen in the US healthcare

26:24 ecosystem come from third parties first.

26:27 The bad actors, one, we're the most

26:29 targeted industry. Two, they know

26:31 exactly how to get in and that's through

26:33 the insecurity of the identities

26:36 established between parties in those

26:39 connections. I think if there is

26:40 anything that KERI is going to do in the

26:42 next 5 years, it's going to take that

26:43 73%

26:45 and plummet it to the ground. I think

26:47 we'll be able to solve the largest

26:49 problems in that connectivity. – And

26:51 something like 60% of providers that are

26:54 hit by a ransomware attack go out of

26:56 business. – So I can tell you also

26:59 just from… So, we also accredit

27:01 healthcare organizations for their

27:02 cybersecurity capabilities. And

27:05 as we review the activities of

27:08 folks in post-breach world, what happens

27:11 what you find out is most of the

27:14 breaches are caused by the use of

27:17 a credential that is actually a

27:19 valid credential. So, you're talking

27:20 about people who are using someone

27:22 else's credential

27:23 for nefarious purposes. And once they

27:26 get in that initial door, they're able

27:28 to then use

27:29 AI, for example, to get

27:32 to traverse the entire network

27:34 once they're inside. So, from my

27:36 perspective, being able to move the

27:38 entire healthcare ecosystem from weak

27:42 credentials

27:43 to a model that is actually

27:44 password-free would be the biggest thing

27:47 we could do for the workforce in

27:49 healthcare. I think that would

27:51 be the best outcome.

27:53 I also think that in general that

27:55 the world needs a veracity engine

27:59 and we don't have one.

28:01 So, there needs to be a veracity

28:04 engine. So, when I appear online, when I

28:06 appear online in any context, like when

28:09 I'm talking to you over Zoom, you should

28:11 be able to see who I am, that I am who I

28:14 say I am, reliably. And that should be, I

28:17 think, and that's if I want my

28:19 identity to be shared. And like these

28:21 things I think are so important to

28:22 establish. I think the policy focus is

28:26 really important though. If the policy

28:28 doesn't happen right, I think this is

28:29 what Utah has done so well. You know,

28:32 first principles, policy first. I think

28:35 that has a huge impact.

28:38 – I'm going to give a slightly different

28:39 answer here. It's going to be

28:40 controversial.

28:42 This is from the policy perspective

28:44 of what needs to be done in 5 years to

28:46 actually get lots of money put into the

28:49 ecosystem and to align interest with

28:51 policy makers to get them to run

28:52 legislation and actually get the market

28:55 going cuz we've had breaches and

28:56 security and lack of trusted identity

28:59 and provenance for decades and it hasn't

29:01 fixed the issue. What is the one topic

29:04 everybody's talking about now and

29:05 pumping money into and it's AI? And so

29:08 if you want to solve all of these

29:10 problems, you've got to tie it to some

29:12 AI use case which is where all the money

29:14 is going. And so Utah did something

29:17 really unique and this is just for

29:18 everyone to think about as you're

29:19 working on the problems.

29:21 They have been in national news

29:22 because they did the first automated

29:25 prescription issuance from AI,

29:27 coming out of our regulatory sandbox.

29:29 So Utah's created some really unique

29:31 things to allow

29:34 AI to be used. We know in this room what

29:38 KERI and ACDC is going to bring to the

29:41 AI ecosystem in terms of provenance

29:44 and then associated the data or to AI

29:48 agents having being delegated with

29:50 authority to act on somebody's behalf.

29:53 And so I think it's critical to tie

29:56 in some of these unique capabilities to

29:59 AI and not show that we're reducing

30:02 fraud or losses but to show some

30:05 efficiency gains or things that directly

30:07 impact individuals. So if you can start

30:09 saying because we have proven,

30:13 you know, verifiable delegation for this

30:15 agent acting on another doctor's behalf

30:18 to start streamlining prescription

30:20 issuance and lowering cost, that's going

30:23 to get people excited. And if we can

30:25 prove the use of this technology over

30:27 the next, I don't think it's 5 years, I

30:29 think it's the next 3 years,

30:31 that is going to start turbocharging

30:34 the digital identity and verifiability

30:36 approach.

30:37 – Okay, who in the room just registered

30:38 KERI.ai? Did that Did that just happen?

30:41 Okay. Jared, go ahead.

30:44 – I agree with what

30:46 Chris is saying and really my

30:50 thought there is that

30:51 this is a problem that can't wait

30:54 and this is a problem that people should

30:55 be thinking about and working on

30:57 already. And what I guess

30:59 what I'll say is while we haven't moved

31:01 some of the work we're doing at Health

31:03 KERI around AI into open source, I

31:05 mean, we probably won't in the near

31:07 term, we definitely want to entertain

31:10 conversations with folks that look at

31:11 that and see it as a problem the same

31:13 way Chris does.

31:13 – And I will say to do what I just said,

31:15 you already have to do everything you

31:17 just said. It's just what's the story

31:19 you're going to tell and that's an

31:21 amazing story to tell that will get

31:23 people to put more money into it.

31:25 – So Karla, I'm going to lean on your

31:26 organizational experience that you've

31:28 had.

31:30 Given what you've seen in creating

31:32 verifiable organizational identity, what

31:34 do you anticipate is going to be the

31:35 practical friction or challenges that

31:37 healthcare organizations are going to

31:40 encounter going through this process?

31:42 And then, panel, listen up. My question

31:44 to you would be is how do we help

31:45 mitigate those issues?

31:50 To begin with,

31:52 I think that

31:53 the first thing is that

31:56 people are used to doing things, or not

31:59 doing anything at all, or doing things a

32:01 different way. So, there's going to need

32:03 to be a change in behavior.

32:05 And the reason why the change in

32:08 behavior is going to need to be

32:10 explained to them.

32:12 And that's a challenge for us.

32:14 Not to get into the technical details.

32:17 To focus on the user experience and

32:19 what the benefits are in order to be

32:22 able to target whether it's doctors,

32:24 whether it's patients, whether it's

32:27 payers and the plans. As we've

32:30 been speaking with healthKERI and

32:32 we've been speaking with DirectTrust.

32:35 I'm learning more and more about the

32:36 healthcare industry and the fact that

32:42 there are

32:43 data inconsistencies,

32:46 there are

32:47 efficiencies that need to be

32:50 exploited

32:52 and identity and verifiable identity is

32:56 at the core of all of these things.

32:59 And for us to be able to leverage what

33:02 we've already

33:04 created and

33:06 to see this applied in this way, to be

33:10 able to take a problem

33:12 and say, we can look at our process that

33:17 we have here

33:18 and we can explain to our members that

33:21 they're going to want to see their

33:24 credentials registered in the provider

33:26 registry so that it reflects the real

33:28 situation in the world,

33:31 I think is an improvement. In order to

33:34 be able to

33:36 to

33:37 also apply the

33:40 the credentials to the plans.

33:43 And so you know who is associated with

33:45 what plan and also to just disambiguate

33:49 the providers themselves. I go back

33:52 to the example that Scott gives to say

33:55 which St. Mary's is it.

33:57 And

33:59 you know, we had

34:01 I guess the answer kind of like sitting

34:03 there in the LEI repository

34:06 and we are glad in order to be able to

34:09 know that there is another industry and

34:12 another domain that can benefit from the

34:15 same kinds of principles that we

34:18 wanted to promote in the first place.

34:24 – I did want to say,

34:27 you asked the question about barriers,

34:29 like so what's going to keep us from

34:30 being successful? I think

34:34 I'm new to KERI. I think KERI is

34:35 incredibly interesting and exciting, and

34:37 I'm a kind of a

34:39 propeller head, but not

34:41 not my propeller is kind of just drawn

34:42 in crayon. But so but I what I've got

34:45 to tell you is that

34:47 that KERI's going to have the same

34:48 challenge that the X.509 community has,

34:50 which is y'all speak Eldish.

34:54 And so

34:55 you're going to have to translate this

34:56 into English, and really quickly,

34:59 because if you're going to try and bring

35:00 this to market,

35:02 we're going to have to start using words

35:04 that people understand. And we're

35:06 going to have to de-acronymify

35:09 because in this day and age,

35:11 I can tell you, we merged with an

35:12 organization called ENACT, and when we

35:15 did, we went and we de-acronymified

35:18 everything, cuz all their programs were

35:20 four-letter acronyms. I'm telling you,

35:22 this is really not a

35:25 2026 kind of a thing. That's a

35:27 1995 thing, right? So, acronyms are big

35:31 in technical space, because you can't do

35:33 these things without them, because you

35:34 can't describe something

35:36 technical in short words. Germans, of

35:38 course, just put words together. But

35:41 I'm telling you that this is, I think,

35:42 our biggest barrier.

35:44 What I heard some people explain here,

35:46 actually, I think it was a legislator,

35:49 it's hard to explain.

35:52 And I think that's that's probably our

35:53 biggest barrier is that we have to be

35:54 able to describe it very succinctly, and

35:57 with value proposition in mind, and with

36:00 words that people understand. If

36:02 there's a barrier here, that's the

36:04 biggest one.

36:05 – So I agree. I

36:07 think clarity in

36:08 language is the biggest hurdle. If we

36:11 can get to clarity of language, we solve

36:13 a lot of problems. I think the second

36:15 biggest hurdle,

36:16 And then the solution, honestly, is

36:19 money. And I wish that wasn't the case.

36:21 I wish we could talk about healthcare

36:22 being this folderol, and everybody

36:23 wants to be, you know, for the patient.

36:26 The reality is this industry is not

36:27 going to move unless there's money

36:29 attached to it. And that comes in two

36:31 forms. One is if companies like

36:33 HealthKERI can come and improve out a

36:35 model that KERI drives dollars for

36:38 companies like us, then a lot of

36:40 different ecosystem players are going to

36:42 come in. It's going to be new startups

36:43 competing with us on our level. It's

36:45 going to be people that are established

36:46 in the space that want to come in and

36:48 start doing what we're doing. But if we

36:49 can show money, we can move the market.

36:52 The other side of this is for the

36:54 customers, the groups that will be paying

36:55 for these new services, they need to see

36:57 money as well. For them likely, they

37:00 will see that in two forms. It's going

37:01 to be a reduction of cost or an increase

37:04 in business. If they can prove that

37:06 they're more trustworthy, they can

37:07 capture more customers. If they can do

37:09 this automatically, they will save on

37:11 COGS. So, I think it's both the

37:14 biggest barrier and if we can solve it,

37:16 we'll be the biggest activator because

37:18 people will forgive your language

37:20 if there's a big pile of money behind

37:22 your acronyms.

37:25 – So, one industry that does not get rid

37:27 of their acronyms is the legal industry

37:30 and those terms and conditions don't get

37:32 any smaller and I do think we can move

37:34 the industry and I said this at the

37:35 SEDI summit

37:37 is what's the regulatory framework to

37:39 incentivize all these experts,

37:41 technologists, and the legal

37:43 departments to move this way and so

37:47 some of our tools would be like the

37:49 reciprocal verifiability. You want

37:51 organizational identity, we're going to

37:53 require them to do reciprocal

37:55 verifiability. Who is the org? Who is

37:58 the individual? That sounds like well,

37:59 it's a cost. Who's going to do this

38:01 then? But then we say, well, if you do

38:03 this, here's the limitations now on

38:05 liability. Here's the safe harbor to

38:07 function and we give them the incentives

38:10 to move toward reciprocal verifiability

38:13 and to use tools that have the

38:15 capabilities KERI provides and that

38:18 should take away enough liability or

38:21 provide enough incentive for them

38:23 to at least start in their

38:24 transformation to move this direction.

38:27 And especially when we start tying that

38:29 to AI, I think this is a perfect

38:30 example. We say, "Your AI agent must

38:33 have some verifiable form to

38:36 say that they're acting on behalf of the

38:38 entity and who provided that

38:39 delegation." And if you do this, then

38:42 you can be in the sandbox in Utah. Those

38:44 are the incentives that I think

38:46 regulators can help with to move

38:49 things.

38:52 I want to pull a few threads together

38:54 here. The yes, we need to speak in very

38:57 plain language to folks as to what

39:00 we're trying to do. The

39:03 problem is yes, legal and government

39:05 love their acronyms. So, we've got to

39:07 also meet them there.

39:10 What we need to do is really think about

39:13 don't make it too complicated.

39:16 And also try and tie it back to things

39:18 they understand.

39:19 I jokingly tell a story about how I

39:22 actually got blue Button Built at CMS

39:25 and got it out through ATO, their

39:28 authorization to operate, so that it

39:30 went out and into the

39:32 marketplace.

39:33 And I say, "I basically designed the

39:35 project so nobody had to make a

39:37 decision,

39:38 right? So, that you always could point

39:41 to precedent so that they could say,

39:43 'You've already done that.'"

39:45 And if you were listening

39:47 to what we were saying this morning,

39:49 a lot of what we've done there is to

39:51 say, "This is just a small change on top

39:54 of what you're doing already. It's the

39:56 same type of technology. It's just a

39:58 different cryptographic key, right?" So,

40:02 that you help them make

40:06 the intellectual jump.

40:08 – One other thing to consider is what is

40:11 the use case you're building for? We've

40:13 had many verifiable credential companies

40:16 come in from KERI and every space

40:18 and they're selling a product for a use

40:21 case which is not the low-hanging fruit

40:23 that's needed. And so there are many

40:25 entities with really smart people if you

40:27 simplify what you're doing enough but

40:29 hit that right use case and there's some

40:31 out there. This isn't the healthcare

40:33 industry but we had we had Maverick in

40:35 here on the first two days of the SEDI

40:36 summit and they actually said, "Hey, if

40:38 you want, we've already made SEDI

40:41 legal for purchase of alcohol and

40:42 tobacco." And they said, "Well, if you

40:44 have the implementation guide, we could

40:46 have this implemented in 6 months and

40:47 we'll start accepting SEDI." And

40:49 that's cuz there is a product market fit

40:51 there that perfectly aligned with the

40:53 protocol we're looking at for SEDI. So

40:55 what are the right healthcare use cases

40:57 as well when and we don't need the whole

41:00 platform. I think it's what's that to

41:02 get you in the door to show value and if

41:05 you do that, then you can build from

41:06 there. Yeah.

41:08 Fantastic point and you're

41:10 right. This is all tying together. I

41:11 love when a when a panel just leads

41:13 towards that natural conclusion.

41:15 Let's talk about the ultimate

41:17 stakeholder in the healthcare industry

41:19 and that's the patient. We know that the

41:21 trust is broken in terms of the personal

41:24 data and the protections around it. We

41:25 say HIPAA a lot but that doesn't mean

41:27 anything when you're lying in the

41:29 hospital bed and

41:31 we do have some representation on here

41:33 from people who are in government or

41:35 who've done some pretty remarkable

41:36 things with government regulation trying

41:39 to help the industry move forward. So if

41:41 you can give me your closing remarks

41:44 individually and if you had the magic

41:46 wand that you could change one

41:47 regulation or add something at a state

41:50 level or a federal level that could

41:53 really kickstart everything in the right

41:54 direction, what would that be?

42:00 – Well, I'll tell you know, CMS is the

42:03 is the organization that has the biggest

42:04 hammer. I mean their hammer is

42:06 actually

42:08 is it a spoon with sugar in it or is it

42:10 hammer? I don't know which, but it's

42:11 very, very, very authoritative and

42:16 powerful. So, their two

42:18 opportunities are reimbursement

42:22 and

42:23 regulation. So, when they regulate,

42:26 if for instance, they were to

42:31 require

42:32 provider organizations to all have

42:35 vLEIs in order to get into the national

42:37 directory,

42:38 it would be an instant driver.

42:41 And this is a national directory

42:43 they're trying to build that is

42:46 failing on the subject of organizational

42:47 identity.

42:49 So, this would be a huge opportunity for

42:50 them. They haven't

42:53 learned to say GLEIF yet. They call it

42:55 GLEEF. They are confused. So, I

42:58 I'm trying to bring them forward and say

43:00 once they can pronounce it, I'm hoping

43:02 that they can also support it.

43:09 – It's a tough one. I

43:11 I think I've moved beyond this, but back

43:15 when I was with CMS, sort of 2017,

43:18 2018, there was a lot of talk about

43:21 Medicare for all.

43:23 And I was saying, "No, no. Why

43:25 don't we just start with Medicare

43:27 registration for all? So, that you got a

43:30 standard ID that you could take." And I

43:33 I've sort of moved beyond that to say

43:35 what I would love to see is probably

43:37 regulation that says,

43:39 "If I as a patient

43:42 present an identifier or an identity to

43:47 a practitioner, to an organization in

43:50 healthcare,

43:52 you should damn well put that into my

43:54 record.

43:59 As they start sharing data and you go to

44:01 more and more places, you can actually

44:03 patient match. I had a colleague

44:07 in the ideal lab at CMS who was there to

44:09 do patient matching.

44:11 You'll know who he is, if he ever sees

44:13 the video.

44:16 Every time I went

44:17 to see him, I'd say, you know, patient

44:20 matching is so much easier when you

44:22 involve the patient.

44:27 – So I haven't become a healthcare expert

44:30 overnight. So

44:32 I'm going to take a little bit of a

44:33 different tack here.

44:36 I would like to be able to see any law

44:39 going forward that

44:42 involves identity

44:44 in order to be able to come at it from

44:47 what are you trying to accomplish? What

44:51 benefits are you trying

44:53 to gain? So what features then do you

44:57 need in order to be able to have in a

45:00 solution?

45:02 Or to have the law be principle-based.

45:06 If you have need for

45:09 to be able to protect for example

45:13 children or elderly parents, do you

45:16 need delegation?

45:18 Are you trying to be able to

45:21 instantiate or give credentials in order

45:24 to be able to know the real situation of

45:28 authority within a company in the area

45:30 of organizational identity

45:33 then you're going to need a feature in

45:36 your in your identity solution that

45:38 gives you that. What level of assurance

45:41 to know that it's really the person who

45:45 is supposed to be able to be

45:47 authorized to get that credential? Do

45:49 they have that role? What level of

45:52 security am I comfortable with?

45:55 Do I need automated verification? Those

45:58 types of things. And when you answer

46:00 those questions the law then gives you a

46:04 guideline or a road map

46:07 in order to be able to pick

46:10 a good solution. And for me, I think

46:13 that changing the dynamic of

46:17 being able to come at the law in

46:20 that way would be an advantage.

46:25 – So I've been looking around the room and

46:27 I'm pretty certain that our friends from

46:29 Libertas are no longer here.

46:32 So I think I'm safe to say this without

46:34 getting a water bottle checked to my

46:35 head.

46:36 I would

46:39 at this point if I could wave a magic

46:40 wand

46:41 I would get rid of section 510 from the

46:45 HHS

46:46 labor bill. That section of that law

46:50 made it essentially

46:52 illegal for the federal government to

46:54 issue a national patient identifier.

46:58 And I agreed with all of the reasons

47:01 that law was in place in terms of

47:03 privacy and the concerns for patients up

47:06 until very recently with some of the

47:09 work that's been happening with SEDI and

47:11 other initiatives. And so now today

47:14 knowing that we have

47:17 a way to do that national patient

47:19 identifier that is privacy preserving,

47:22 that manages to keep the patient in

47:24 charge of themselves digitally,

47:27 I think that should be repealed

47:29 immediately. And again, if Connor or

47:33 Jason from

47:34 Libertas see this, we can talk later

47:37 about the implications.

47:40 – This is an unfair question for me.

47:43 [laughter]

47:45 – What would you like to do?

47:48 – Cuz

47:48 there's this bad thing that happens when

47:50 I say what we want to do in regulation

47:52 then I have to make recommendations.

47:54 It ends up happening.

47:56 Now some of this I've said

47:59 big picture we know privacy and security

48:01 is broken in the country. The amount

48:04 of correlation happening with your data

48:07 and how that profiling and the

48:09 scoring and predictive analytics is

48:10 occurring in every sector, private

48:13 sector, public sector, healthcare,

48:15 social services, education. You would be

48:18 amazed in this room and me

48:20 and George have seen these systems. And

48:23 so I'm coming at it from a different

48:24 perspective of what is coming from the

48:26 private sector industry and how that

48:28 would be used to exploit for

48:30 monetary or the public sector side to

48:32 try to influence you to make

48:34 different decisions.

48:35 I had seven years of experience in

48:37 privacy and security with human

48:39 services in Utah and I know HIPAA does

48:42 not work and the levels of

48:44 non-compliance for both privacy and

48:46 security. There's maximum use of data,

48:50 but these other things are viewed as

48:51 just hindrances or there's not the

48:53 expertise to do.

48:57 And I think this was alluded to

48:59 on the legislative panel on the

49:01 SEDI summit. What I am working

49:03 toward is

49:05 I think there needs to be a total

49:06 rewrite of the approach. And so our

49:10 goal is that you know, starting with

49:12 identity

49:13 end-to-end verifiability and zero trust.

49:17 Move toward the duty of loyalty

49:20 model where anybody with your data

49:22 should be acting in your best interest

49:24 and this crosses all industry. This

49:25 crosses healthcare, this crosses

49:27 financial. And if you're aligned with

49:30 that end-to-end verifiability, we

49:32 modernize the laws for provenance

49:34 requirements, we figure out, you know,

49:36 how to track these terms,

49:38 Then we will be creating also some

49:40 extreme safe harbors for entities to act…

49:43 to work with knowing mistakes are

49:45 going to happen, but I think that will

49:47 create a more balanced free market and

49:49 set us up for coming in the age of

49:52 of AI and automation, but anything

49:55 absent… a total overhaul

49:58 for both public and the consumer

49:59 side,

50:01 it's going to be a very fragmented

50:02 disparate market and the public is going

50:05 to be confused and businesses are going

50:07 to struggle to maintain our economic

50:09 dominance that we have here in the US.

50:12 – So, since Chris pulled me in by saying

50:14 I'd seen some of this stuff, too, I'm

50:16 just going to say, yes, that's true. I

50:18 mean, it's there have been many times

50:20 when we've effectively done our

50:21 architecture reviews and opened up a

50:23 system just to find that it has a

50:24 digital hamster wheel still spinning and

50:28 we have needed to change and some of

50:30 that's going to be in behavior, as we've

50:31 talked about, and the incentives need to

50:34 be there to help us with the change.

50:36 So, as we started this day out, Sam had

50:38 made a bold statement that this is the

50:41 potentially the year of KERI. I think

50:43 from what we've heard from this panel,

50:45 that's been corroborated. So, Sam, put

50:47 one more in the win column. Can we have

50:49 a round of applause for our panel?

50:51 [applause]

50:54 Thank you. [applause]