From the "Health Credential" to the National Vault: Why Are We Still Fragmenting Our Identity?
2026-01-21 · By Esteban Rey (@Kilowatto)

Yesterday, President Claudia Sheinbaum and the Secretary of Health announced with great fanfare the start of the credentialing process for universal access to the healthcare system (IMSS-Bienestar). I confess from the outset that my knowledge of health policies or medical triage is zero, so I won't get into whether this will improve or worsen hospital care. Where I will focus is on the bureaucratic hardware: the new card.
We're facing another attempt by the government — one more in a long historical list — to collect, catalog, and "credentialize" the population. Given that we've just witnessed monumental failures in the implementation of digital records (as I detailed in my previous column about Telcel's vulnerability), the obligatory question is: With what confidence should citizens hand over their data to get this plastic card?
The Coercion of Necessity
For the average citizen, especially the most vulnerable groups, there's no real dilemma. If the credential is the key to receiving medical attention, they'll apply for it. There's an implicit incentive that borders on coercion: "your data in exchange for your health".
However, we must be brutally honest about the risks. These massive databases, rich in demographic and socioeconomic information, are "gold nuggets". They're coveted by political operators to condition votes, by unethical marketing companies, and, most seriously, by criminal groups that see these records as a detailed menu for extortion or identity theft.
If the government couldn't guarantee the security of a phone API, what guarantees do we have that this new health database won't end up for sale on the black market in six months?
Enough Patches: Towards a True National Identity
But criticism shouldn't just stop at complaints. The underlying problem isn't the health credential per se, but Mexico's obsession with having an identification for every window.
It's time to get serious. Mexico needs to stop playing with "credentialitas" and make a state effort — one that transcends the current government — to build a Unified Digital National Identity.
It's absurd that in 2026 we're still using an electoral credential (INE) as our primary identification, while also carrying a Professional ID, a Driver's License (state-issued and fragmented), a paper CURP, the SAT's RFC, the e.Firma (formerly FIEL), and now a health credential.
The proposal is clear: One identity for everything.
Let's imagine a system where your digital identity is a platform, not a piece of plastic. A "Vault of Identity" that integrates:
Open Integration and User Sovereignty
But let's take it a step further. This identity shouldn't just serve the government; it should have open integration capabilities (secure APIs) so citizens can use it in the private sector.
Want to enter your sports club? Use your National Identity. Want to open a bank account? Authenticate with it. Want to enroll in university? Same thing.
The technological key here is data sovereignty. The citizen must be the owner of the key. Through an app, I should be able to see exactly who has access to what data.
Total transparency. We should know who accessed, when, and why. And have a panic button to revoke access whenever we want.
The Paradox of Security: Centralizing to Fortify
I know what you're thinking: "Esteban, isn't putting all our eggs in one basket dangerous?".
It's a valid concern, but in cybersecurity, dispersion is often riskier than well-executed centralization. Today, we have our data scattered across hundreds of municipal, state, and federal databases, many of which are protected with decade-old technology and managed by untrained personnel. These are hundreds of open backdoors.
If we create a Centralized Vault of Identity, it should be treated as a matter of National Security.
It shouldn't be managed by a transient secretary; it should be a state entity shielded with as many layers of security as possible (post-quantum encryption, private blockchain for traceability, cutting-edge biometric authentication). It's more efficient to invest massive resources in building a single, impenetrable digital "Fort Knox" than trying to guard a thousand wooden cabins scattered throughout the country.
The new health credential is a good intention with bad architecture. We're still digitizing 20th-century bureaucracy instead of designing 21st-century identity.
What do you think? Should we centralize identity vaults to protect them better, or keep trusting in having a different credential for each day of the week? I'm reading your comments.