From the "Health Credential" to the National Vault: Why Are We Still Fragmenting Our Identity? Transcript of the narrated version (5 min). Narrated with a synthetic voice (Larry). The writing is Esteban Rey's — kilowatto.com. --- From the "Health Credential" to the National Vault: Why Are We Still Fragmenting Our Identity?. Yesterday, President Claudia Sheinbaum and the Secretary of Health announced with great fanfare the start of the credentialing process for universal access to the healthcare system, known as IMSS-Bienestar. I will admit upfront that my knowledge of health policies or medical triage is zero, so I will not dive into whether this will improve or worsen hospital care. Instead, I will focus on the bureaucratic hardware, specifically the new card. We are facing another attempt by the government, one more in a long historical list, to collect, catalog, and credentialize the population. Given that we have just witnessed monumental failures in implementing digital records, as detailed in my previous column on Telcel's vulnerability, the obligatory question is, with what confidence should citizens hand over their data to get this plastic card? The Coercion of Necessity. For the average citizen, especially the most vulnerable groups, there's no real dilemma. If the credential is the key to receiving medical attention, they'll apply for it. There's an implicit incentive that borders on coercion, your data in exchange for your health. However, we must be brutally honest about the risks. These massive databases, rich in demographic and socioeconomic information, are gold nuggets. They're coveted by political operators to condition votes, by unethical marketing companies, and, most seriously, by criminal groups that see these records as a detailed menu for extortion or identity theft. If the government couldn't guarantee the security of a phone company's API, what guarantees do we have that this new health database won't end up for sale on the black market in six months? Enough Patches: Toward a True National Identity. Criticism shouldn't stop at complaints. The underlying problem isn't the health credential per se, but Mexico's obsession with having an identification for every window. It's time to get serious. Mexico needs to stop playing with "credentialitas" and make a state effort — one that transcends the current government — to build a Unified Digital National Identity. It's absurd that in 2026 we're still using an electoral credential, known as the INE, as our primary ID, plus carrying a Professional Certificate, a Driver's License, which is state and fragmented, a CURP on bond paper, the SAT's RFC, the e.Firma, formerly known as FIEL, and now a health credential. The proposal is clear: one identity for everything. Imagine a system where your digital identity is a platform, not a plastic card, a Vault of Identity that integrates legal data, including RFC, CURP, and Birth Certificates, capabilities such as Driver's Licenses, professional certificates, and passport, health information, including basic medical history, blood type, and right to healthcare, which is the famous new credential. This identity should also include authentication, replacing the SAT's e.Firma and the Judicial Power's FIREL, an electronic signature, eliminating the bureaucracy of having five different passwords to interact with the State. Open Integration and User Sovereignty. This identity shouldn't only serve the government, it should have open integration capabilities, such as secure APIs, so citizens can use it in the private sector. For instance, when wanting to join a sports club, a citizen can use their National Identity, similarly, when opening a bank account, they can authenticate with it, and when enrolling in university, they can use it as well. The technological key to this system is data sovereignty, where the citizen must be the owner of the key. Through an app, a citizen should be able to see exactly who has access to what data, and have control over it, for example, they can approve Bank X's request to see their credit history and RFC, deny Club Y's request to see their blood type, or approve the government's request to see their current address, but only for a limited time, such as 24 hours. This system should provide total transparency, where citizens know who accessed their data, when, and for what purpose, and they should also have a panic button to revoke access whenever they want. The Paradox of Security: Centralizing to Secure. You may be thinking that putting all our eggs in one basket is dangerous, but in cybersecurity, dispersion is often riskier than well-executed centralization. Today, our data is spread across hundreds of municipal, state, and federal databases, many of which are protected with ten-year-old technology and managed by untrained personnel, creating hundreds of open backdoors. If we create a Centralized Vault of Identity, it should be treated as a matter of National Security. It should not be managed by a transient secretary, but rather as a state entity shielded with as many layers of security as possible, including post-quantum encryption, private blockchain for traceability, and latest-generation biometric authentication. It is easier and more efficient to invest massive resources in building a single, impenetrable digital Fort Knox than trying to guard a thousand wooden cabins scattered across the country. The new health credential is a good intention with bad architecture, as we are still digitizing 20th-century bureaucracy instead of designing 21st-century identity. The question remains, should we centralize identity vaults to protect them better, or keep trusting in having a different credential for each day of the week.