Health Credentials Are Starting to Travel Across Borders Like Passports: How WHO’s Digital Trust Network Verifies Documents Without Excluding People Who Lack Smartphones
Original Chinese title: 健康證明開始像護照一樣跨國互認:WHO 的數位信任網路怎麼驗證文件,又怎麼避免把沒有手機的人擋在門外?
WHO’s GDHCN verifies health documents through a trust and public-key architecture rather than a centralized medical-record database; this feature also examines cross-border access for people without smartphones.
Lawrence Lee
Lawrence Lee is a scholar at the University of Leeds, UK, and a technology policy observer focused on digital governance, AI regulation and Indigenous/community data sovereignty.

# Health Credentials Are Starting to Travel Across Borders Like Passports: How WHO’s Digital Trust Network Verifies Documents Without Excluding People Who Lack Smartphones
By Lawrence Lee | Scholar at the University of Leeds, UK | Technology policy observer | Focused on digital governance, AI regulation, and Indigenous/community data sovereignty
The Global Digital Collaboration Conference 2026, held in Geneva from 1 to 3 September, placed a post-pandemic infrastructure question on the international cooperation agenda: when vaccination certificates, prescriptions, patient summaries or other health documents need to be verified across hospitals and national borders, can the world build a shared mechanism for trusting document issuers rather than forcing every country to create another closed application? WHO’s conference programme highlighted secure, portable and trusted digital health wallets, but the real subject is larger than a phone interface. It involves document standards, governance, interoperability and trust architecture.
The first step is to avoid a common misunderstanding. WHO’s Global Digital Health Certification Network, or GDHCN, is not a giant database into which the world uploads medical records. WHO’s official FAQ describes it as an open and interoperable digital public infrastructure. Participants submit public keys used to verify digital signatures into a trust directory. Other participants can then use those keys to check whether a health credential was genuinely issued by a trusted authority. WHO does not thereby gain access to the underlying personal health data contained in individual credentials.
The distinction is similar to verifying that a passport is authentic without reading and storing every detail of a traveler’s life. A border authority or health facility may need to know whether a document came from the genuine issuer and whether its signature has been altered, but a global center does not need to maintain everyone’s complete health record. The architecture therefore separates “who is trusted to issue” from “where the health data are stored.” From a data-protection perspective, that separation makes it easier to apply data-minimization principles than a design that centralizes all content on one platform.
GDHCN grew out of experience with digital COVID-19 certificates, but WHO positions it as infrastructure that can support additional use cases, including cross-border verification and continuity of care. In March 2026 the International Organization for Migration became the first international organization to join the network. WHO specifically linked the collaboration to people on the move and to humanitarian, crisis and low-connectivity environments, where trusted digital tools could help verify health information and support continuity of care. That moves the conversation beyond the convenience of scanning a QR code at an airport. It connects credential portability to migrants, displaced people, cross-border families and healthcare during emergencies.
Technical interoperability, however, is not the same as service equity. Imagine a credential system that assumes every user has a recent smartphone, stable connectivity, a permanent phone number, a single-language interface and exactly the same Romanized name on every document. The people who most need continuity across institutions may be the people most likely to fail those assumptions. An older resident in a remote area may share a device with family members. A migrant may change SIM cards repeatedly. Names may be spelled differently under different document systems. Disaster sites may have no network at all. If digital trust solves cryptographic trust while ignoring access, it can simply convert administrative friction into a new digital barrier.
WHO’s FAQ offers an important design clue: GDHCN can support offline use because participants may cache the trust information needed for verification rather than remaining online at every moment. That matters greatly in low-connectivity settings. Yet offline verification alone does not make a service universally accessible. Inclusive public services also need printable or paper fallbacks, assisted service through clinics or community points, recovery procedures after device loss, and a human verification route when a person cannot present a digital credential.
Data minimization has to become operational as well. A service verifying one fact does not necessarily need a person’s entire health history. If the task is to confirm a vaccination record, prescription validity or professional qualification, the system should expose only the fields required for that transaction wherever possible. As digital health wallets expand to more document types, field-level authorization, purpose limitation, revocation and audit trails will become at least as important as encryption itself.
For remote and Indigenous-area public services, there is a relevant perspective that does not require forcing every case into a cultural frame. Central systems are often designed from standards, public-key infrastructure, APIs and cross-border interoperability. Local service points encounter electricity, connectivity, literacy, language, shared devices, identity documentation and trust relationships first. Both sets of problems are real. A mature digital public infrastructure should allow field experience to change central specifications—for example by making offline mode a requirement, supporting multiple languages and name aliases, enabling assisted access without password sharing, retaining non-smartphone and paper routes, and stress-testing the system against vulnerable-user scenarios.
Governance matters just as much. Who is allowed to join the trust network? How are participants notified when an issuer’s key is revoked? When a credential format changes, can older systems still verify it? National laws differ on health data, minors, delegated decision-making and retention periods. Cross-border interoperability cannot pretend those differences do not exist. Mature interoperability does not mean every system looks identical. It means participants share enough technical specification to know clearly what they recognize from one another and which permissions remain governed by local law.
This is why “trust network” is a more accurate description of GDHCN than “global health database.” Its core asset is not a centralized collection of everyone’s medical records but a verifiable set of issuing relationships and common specifications. That design can reduce the cost of cross-border verification without unnecessary centralization—provided future expansion continues to enforce data minimization, defined purpose, revocation, auditability and non-digital alternatives.
The next test for digital health may not be whether a health credential can fit inside a phone. It may be whether public service still works when the phone is dead, the network is down, a name is spelled differently, the interface is unreadable to the user, or no smartphone exists at all. A good global trust architecture should make credentials easier to verify without making care harder to obtain for people who lack ideal digital conditions. As international interoperability becomes real, technical design and rights design have to advance together; otherwise we risk creating a credential the whole world can read while leaving the people who most need it outside the door.
Primary sources
AI use and content-safety disclosure
This English edition is an AI-assisted translation of the Chinese article, reviewed for source parity and evidence boundaries.