
From the "Health Credential" to the National Vault: Why Are We Still Fragmenting Our Identity?
2026-01-21 · By Esteban Rey (@Kilowatto) · 7,308 reads
Narrado con la voz sintética de Larry. El texto es de Esteban; la voz no es humana. Read the transcript.
Yesterday, President Claudia Sheinbaum and the Secretary of Health announced with great fanfare the start of the credentialing process for universal access to the healthcare system (IMSS-Bienestar). I'll admit upfront that my knowledge of health policies or medical triage is zero, so I won't dive into whether this will improve or worsen hospital care. Where I will focus is on the bureaucratic hardware: the new card.
We're facing another attempt by the government — one more in a long historical list — to collect, catalog, and "credentialize" the population. Given that we've just witnessed monumental failures in implementing digital records (as I detailed in my previous column on Telcel's vulnerability), the obligatory question is: With what confidence should citizens hand over their data to get this plastic card?
The Coercion of Necessity
For the average citizen, especially the most vulnerable groups, there's no real dilemma. If the credential is the key to receiving medical attention, they'll apply for it. There's an implicit incentive that borders on coercion: "your data in exchange for your health".
However, we must be brutally honest about the risks. These massive databases, rich in demographic and socioeconomic information, are "gold nuggets". They're coveted by political operators to condition votes, by unethical marketing companies, and, most seriously, by criminal groups that see these records as a detailed menu for extortion or identity theft.
If the government couldn't guarantee the security of a phone company's API, what guarantees do we have that this new health database won't end up for sale on the black market in six months?
Enough Patches: Toward a True National Identity
But criticism shouldn't stop at complaints. The underlying problem isn't the health credential per se, but Mexico's obsession with having an identification for every window.
It's time to get serious. Mexico needs to stop playing with "credentialitas" and make a state effort — one that transcends the current government — to build a Unified Digital National Identity.
It's absurd that in 2026 we're still using an electoral credential (INE) as our primary ID, plus carrying a Professional Certificate, a Driver's License (state and fragmented), a CURP on bond paper, the SAT's RFC, the e.Firma (formerly FIEL), and now a health credential.
The proposal is clear: One identity for everything.
Imagine a system where your digital identity is a platform, not a plastic card. A "Vault of Identity" that integrates:
- Legal Data: RFC, CURP, Birth Certificates.
- Capabilities: Driver's Licenses, professional certificates, passport.
- Health: Basic medical history, blood type, right to healthcare (the famous new credential).
- Authentication: This identity should replace the SAT's e.Firma and the Judicial Power's FIREL (electronic signature), eliminating the bureaucracy of having five different passwords to interact with the State.
Open Integration and User Sovereignty
But let's go a step further. This identity shouldn't only serve the government. It should have open integration capabilities (secure APIs) so citizens can use it in the private sector.
Want to join a sports club? Use your National Identity. Open a bank account? Authenticate with it. Enroll in university? Same thing.
The technological key here is data sovereignty. The citizen must be the owner of the key. Through an app, I should be able to see exactly who has access to what data.
- "Bank X wants to see my credit history and RFC": Approve.
- "Club Y wants to see my blood type": Deny.
- "Government wants to see my current address": Approve for only 24 hours.
Total transparency. We should know who accessed, when, and for what. And have a panic button to revoke access whenever we want.
The Paradox of Security: Centralizing to Secure
I know what you're thinking: "Esteban, isn't putting all our eggs in one basket dangerous?".
It's a valid concern, but in cybersecurity, dispersion is often riskier than well-executed centralization. Today, we have our data spread across hundreds of municipal, state, and federal databases, many of which are protected with ten-year-old technology and managed by untrained personnel. These are hundreds of open backdoors.
If we create a Centralized Vault of Identity, it should be treated as a matter of National Security.
It shouldn't be managed by a transient secretary; it should be a state entity shielded with as many layers of security as possible (post-quantum encryption, private blockchain for traceability, latest-generation biometric authentication). It's easier and more efficient to invest massive resources in building a single, impenetrable digital "Fort Knox" than trying to guard a thousand wooden cabins scattered across the country.
The new health credential is a good intention with bad architecture. We're still digitizing 20th-century bureaucracy instead of designing 21st-century identity.
What do you think? Should we centralize identity vaults to protect them better, or keep trusting in having a different credential for each day of the week? I'm reading your comments.
Comments
Be the first to comment.