Personal Medical ID

Your charts. Your Watch. Your Oura. One ID you own.

ProofCare unifies Epic MyChart clinical data with Apple Watch and Oura into an encrypted Personal Medical ID—Day Pulse on your home screen, share only when you decide.

HIPAA-aligned architecture · PHI stays off-chain · Not a medical device

  • Epic MyChart
  • Apple Watch / Health
  • Oura
ProofCare home showing Day Pulse score

Built around your day—not another portal

The new home surfaces Day Pulse, wearable mosaic, and clinical context from Epic in one glance.

Day Pulse hero

Day Pulse — local 0–100 from your wearables

Metric mosaic

Sleep, activity, readiness, HRV mosaic

Clinical sources strip

Epic + Apple + Oura in your Personal Medical ID

How your Personal Medical ID comes together

Three steps from scattered portals to a shareable identity.

1. Connect

Link Epic MyChart, Apple Health / Watch, and Oura. Upload labs when you need them.

2. Vault

Records encrypt on your device. Offline access. Integrity proofs never put PHI on-chain.

3. Share

Hand a clinician-ready PDF to a visit. Create a time-limited access grant. Audit it. Revoke when you’re done.

Trust by design

Patient-owned

You hold the vault. We don’t sell your chart notes.

Share with expiry

Clinics get what they need—links don’t live forever.

Honest claims

HIPAA-aligned architecture. Not HIPAA certified. Not a medical device.

The integrity layer

Blockchain that proves the record—without ever holding the record

Most “health on blockchain” products put too much on a ledger, or they slap a buzzword on a portal. ProofCare does the inverse: your chart stays in an AES-GCM vault on your phone. A permissioned Hyperledger Fabric ledger (Kaleido-managed in pilot) only ever sees fingerprints and consent events. That split is the product.

What stays on your phone

  • Epic MyChart FHIR—conditions, meds, allergies, labs, immunizations
  • Apple Health / Watch and Oura wearable context
  • Uploaded labs and documents, encrypted at rest
  • Vault key in Keychain / Android encrypted storage
  • The live audit trail you can open offline

What the ledger is allowed to see

  • SHA-256 content hashes (64 hex characters)—never the file
  • Event type: created, uploaded, granted, revoked
  • Hashed actor IDs—no names, emails, or MRNs
  • Grant id, action, and a short purpose string
  • Timestamp and transaction id. That is all.

Chaincode rejects FHIR, diagnoses, medications, and names if anyone tries to sneak them in. Diagnoses do not go on a public chain. They do not go on our permissioned chain either.

Fingerprint, then prove

When you import a chart, upload a lab, or write a manual record, ProofCare hashes the canonical content with SHA-256 and can anchor that hash. Later you can show the record existed, unchanged, at a point in time—without handing the ledger your labs.

Consent is a first-class event

Sharing is not a silent screenshot. An access grant is purpose-scoped and time-bounded (7, 14, or 30 days). Grant and revoke write to your local audit and can log granted / revoked on-chain. You keep the receipt.

Fail-open on purpose

If the ledger is unreachable, ingest and local audit still work. Your vault is not held hostage by a network. Chain transaction IDs attach when the write lands. Integrity is additive—not a single point of failure.

Wipe means crypto-shred

Delete the vault and we hard-delete rows and files, then shred the encryption key. The chain may keep a hash. A hash without the file and without the key is not your chart.

What we add—without replacing what already works

Keep MyChart. Keep Apple’s emergency Medical ID. ProofCare sits beside them as the ID you own, with a proof layer those tools were never built to give you.

Beside MyChart

The portal stays. Your ID travels.

MyChart is how you message your health system. It is not built to leave with you, or to carry Watch and Oura into the next specialist. ProofCare pulls the chart into an encrypted vault on your phone so the record is still yours after a job change or a new city.

Beside Apple Medical ID

Emergency card vs living identity

Apple’s Medical ID is the right lock-screen card when seconds matter. ProofCare is the fuller identity behind it: MyChart, wearables, uploads, and a share you can expire. Keep both.

Not a health coin

Proofs, not a public chart

We do not mint tokens and we do not publish diagnoses “for transparency.” The ledger only fingerprints a file and records that you granted or revoked access. The chart never leaves the vault.

Who gets leverage—and why

Same vault. Same proofs. Different jobs. ProofCare is built so each person who touches a record gets a concrete advantage, not a generic “wellness app.”

Patient

Walk into the visit with one ID

You are tired of five portals, a Watch that never makes it to the exam room, and repeating your med list from memory.

  • Pull Epic MyChart, Apple Health, and Oura into one offline vault.
  • Hand the specialist a clinical summary PDF—or a grant you can expire after the appointment.
  • Integrity proofs let you say “this lab is the file I uploaded,” not “please trust my camera roll.”
  • Day Pulse stays wellness context. It is not a diagnosis.

Caregiver

Help without taking the account

Families fight over who has the login and who changed a med. You need visibility, not a silent takeover.

  • Family plan is designed for up to five profiles and shared audit visibility.
  • Access grants are purpose-scoped and revocable—help for a hospital week, then close it.
  • The trail shows who granted and who revoked. Less “he said / portal said.”
  • Keep Apple’s emergency Medical ID for lock-screen crises; use ProofCare for the living record.

Clinician

A packet you can reconcile—not another login

You do not need a sixth inbox. You need the patient’s story in a form you can check against the chart.

  • Receive a clinician-ready PDF the patient generated—callouts included, with a reconcile-against-chart disclaimer.
  • Optional patient-initiated Send to Epic for vitals / summary, not a substitute for your note.
  • When they show an integrity proof or grant timestamp, you get provenance, not a mystery screenshot.
  • You do not create a ProofCare account to read a PDF. We are not asking clinics to adopt a new EHR.

Employer / benefits

A portable vault benefit—without seeing the chart

HR and brokers want continuity and trust. They should never see diagnoses. Most “wellness” vendors blur that line.

  • Employees keep a Personal Medical ID that survives job changes—portals often do not.
  • The ledger story is access audit and integrity, not employer surveillance of conditions.
  • Invite-code employer seats unlock the same proof and share tools as Plus. PEPM stays off until BA templates exist.
  • Honest compliance posture you can take to counsel: HIPAA-aligned, PHI off-chain, no public blockchain.

Join the beta as your role

The compliance raise

The product is built. Compliance is the runway.

ProofCare already unifies MyChart, Apple Watch, and Oura in an encrypted Personal Medical ID with PHI-off-chain integrity proofs. What we will not do is ship cloud insights, a live ledger, or employer PEPM on a handshake. This raise funds the counsel, BAAs, and insurance that let the product take off for real.

CounselHealthcare privacy memo, entity classification, residual risk sign-off.
Vendor BAAsFirebase / Gemini, Kaleido operator agreement, crash tooling only with a BAA.
InsuranceCyber / tech E&O with a health-data endorsement before launch.
Then takeoffCloud insights, production ledger, employer seats—gates we already coded.

FAQ

What is a Personal Medical ID?

Your patient-owned health identity—clinical + wearable data in one vault you control.

Is this just iPhone Medical ID?

No. Keep Apple’s emergency Medical ID; ProofCare adds MyChart, Watch, Oura, and controlled sharing.

Which data sources do you support?

Epic MyChart, Apple Watch / Apple Health, Oura, and uploads.

Do you put my diagnoses on a blockchain?

Never. PHI stays in your encrypted vault. A permissioned ledger records SHA-256 hashes and consent events only—no names, labs, or files.

Who is ProofCare for?

Patients who want one ID across MyChart, Watch, and Oura; caregivers who need revocable help; clinicians who want a PDF they can reconcile; employers who want a portable vault benefit without seeing the chart.

Are you raising?

Yes. The raise is for the compliance stack—counsel, BAAs, and insurance—so cloud insights, the production ledger, and employer seats can ship without cutting corners. Start at proofcareapp.com/investors.

How do I get into the beta?

Use the form below—emails go to natalie@equestrolabs.com.

Join the Personal Medical ID beta

Tell us who you are. We’ll send TestFlight / install instructions when your spot opens. No spam—just product access.

  • Epic MyChart + Apple Watch / Health + Oura
  • Encrypted on-device vault — PHI stays off-chain
  • Integrity proofs + time-limited access grants