Privacy by design
Share an answer. Keep your health story private.
A partner may need to know that an offer’s condition was met. That is a different request from access to a complete health history.

Imagine a partner offers a reward for completing a health check. To fulfil that offer, it needs a way to confirm that the check happened.
That raises a useful design question: what is the smallest amount of information needed to provide that confirmation?
This question sits at the centre of HealthID’s approach to privacy.
Define the question before requesting information
Your health identity is personal. Our design for a private Health ID starts with your control over it. You choose which information to connect and whether to participate in an offer. Before sharing, you should be able to understand who is asking, what they will receive and why.
For a health-check offer, the answer might be confirmation that an eligible check was completed during the relevant period. The design goal is to avoid disclosing additional details that the offer does not require.
The precise proof depends on the programme and the systems involved. It also needs a reliable way to establish that the underlying event occurred.
Control has to be understandable
Privacy is experienced through practical choices. Can you see what is connected? Can you understand an offer before accepting it? Can you stop future sharing? Is it clear what information a partner has already received?
Those questions shape the experience we are building. A permission screen should be clear enough for someone to make a meaningful decision without understanding the technical architecture underneath it.
Keep the boundaries explicit
Our intended architecture keeps personal health records on the individual’s device and uses permissioned answers or proofs for relevant partner interactions. That design requires careful choices about processing, backup, recovery and what happens when a person changes devices.
The privacy of an answer also needs attention. Even a simple confirmation can reveal something about a person. Sharing less information must be paired with a clear purpose and an understandable choice.
Liv and the HealthID experience are in development. As capabilities become available, we need to explain the implemented data flows and controls precisely.
The principle guiding that work is straightforward: participation in a useful programme should require only the information needed for that programme.
A private health identity. A personal companion. Built to stay with you.
About the company
Let’s talk