ACHDM

American College of Health Data Management

American College of Health Data Management

Can healthcare scale trust? The promise of the vLEI

The growing environment requiring interoperability requires organizations to establish trust quickly and at a much greater scale.




In the first article of this series, I argued that healthcare's next interoperability challenge centers on establishing scalable organizational identity and delegated authority as data exchange continues to expand. In the second, I introduced the Legal Entity Identifier (LEI) as a practical foundation for solving that challenge.

In this third and final article, we will discuss the Verifiable Legal Entity Identifier (vLEI), which builds on that foundation. Essentially, the vLEI makes trusted identities and authorizations for organizations and individuals usable in digital transactions.

But how does that actually work? This article will explain, starting with a comparison of the LEI and vLEI.

From registry to trusted exchange

One way to think about an LEI and a vLEI is to imagine standing at the entrance to a highway tunnel watching cars emerge.

An LEI is like a license plate. It uniquely identifies the vehicle, enabling you to look up who owns it, where it is registered and other important information. That works well, but someone still must perform the lookup.

A vLEI enables much of that validation to happen automatically. Rather than consulting a registry, organizations can rely on cryptographically verifiable credentials that travel with the exchange itself. Better yet, organizations can use selective disclosure to reveal only the information required for a specific interaction, such as demonstrating that an organization is authorized to act, without exposing every detail contained in the underlying credential.

Think about it like a car registration that reveals the make, but not the model or year. Healthcare and life on the Internet in general need this kind of capability.

Today, trust is often established through directories, onboarding processes and intermediary networks. Those approaches work well, but they generally require participants to look elsewhere to determine which legal entity sits behind a transaction or whether the individual, application or system making the request has the authority to act on that organization's behalf.

The LEI establishes organizational identity. The vLEI allows that identity and the associated authority to be communicated and verified as part of the exchange itself.

More than identity

One of the biggest misconceptions about digital identity is that it only answers one question: Who are you?

Healthcare almost always requires a second question: What are you authorized to do?

That distinction becomes increasingly important as healthcare exchange becomes more automated.

Identity credentials issued to individuals can verify who someone is, but they don't necessarily communicate which organization they are acting on behalf of. Most healthcare transactions are not performed by individuals acting independently. They are performed by people, applications, contractors and service providers representing healthcare organizations.

Consider a physician using an electronic health records system. The physician isn't simply acting as an individual; they're acting on behalf of the organization employing them. The same physician could later work as an expert witness for a law firm. Their identity hasn't changed, but the authority they possess in each situation is entirely different.

The same principle applies to software and automated systems.

A payer's FHIR client may automatically connect to another organization's server without any human intervention. The receiving organization needs confidence, not only in the identity of the system making the request but also in the legal entity behind it and the authority that has been delegated to that entity.

That’s where the vLEI framework becomes especially powerful.

A chain of trust

The vLEI was designed to extend trust from organizations to the people, applications and systems acting on their behalf.

The Global Legal Entity Identifier Foundation (GLEIF) accredits qualified issuers, which validate legal entities. After they’re validated, those legal entities can establish credentials for authorized representatives, role holders and others acting on their behalf. Because those credentials are cryptographically linked, they create a verifiable chain of trust that can travel with each digital interaction.

Rather than depending entirely on directories, contracts or repeated onboarding exercises, organizations can begin relying on credentials that are portable, reusable and electronically verifiable across multiple business relationships. That's a fundamentally different trust model.

Why this matters now

Historically, healthcare exchange has largely occurred between organizations with established relationships or through trusted intermediary networks. Those models have served the industry well, but healthcare’s interoperability environment is changing rapidly.

FHIR-based APIs, CMS-0057 and payer-to-payer exchange, TEFCA, and other interoperability initiatives are creating many more situations in which organizations must establish trust quickly and at a much greater scale. This includes competitors, new business partners, applications and automated systems.

Payer-to-payer exchange is one example of this. Health plans are now expected to exchange patient information when members change insurers. Those organizations may have little or no existing relationship, but they still need confidence that requests originate from the correct legal entity and that the people, applications and systems involved have the appropriate authority. Manual onboarding and contractual relationships become increasingly difficult to scale in this environment.

The future of trust

Healthcare doesn't need to replace its existing trust frameworks, accreditation programs, certificates or governance models. Instead, it has an opportunity to strengthen them with a portable, cryptographically verifiable approach to organizational identity and delegated authority.

The real value comes from using these capabilities to establish trusted relationships at nternet scale.

As healthcare continues connecting patients, providers, payers, technology companies and AI-enabled systems, organizations will need trust models that extend beyond one-to-one onboarding and static directories. Together, LEIs, vLEIs and delegated authority offer one practical path toward that future.

We’ll be exploring many of these topics during the upcoming DirectTrust Annual Conference, including interactive sessions focused on organizational identity, digital trust, interoperability, AI and other emerging technologies. I hope you’ll join us October 20 and 21 in Kansas City, and we’re offering Health Data Management readers a registration discount with code IDENTITY26.

Scott Stuewe is president and CEO of DirectTrust, driving strategy, visibility and growth of DirectTrust’s focus areas of community, accreditation, standards development and trust services.



More for you

Loading data for hdm_tax_topic #reducing-cost...