Raphael Gernot · Zenodo (CERN European Organization for Nuclear Research) 2026 · 2026
DOI: 10.5281/zenodo.22855810
Counts differ because each database indexes a different set of publications. We treat OpenAlex as the canonical count; Google Scholar is not shown (no API, and crawling it violates its ToS).
Personal health data is fragmented across device vendors, laboratories, clinics and apps, each holding it under its own terms, while a new class of AI assistants seeks to become the durable holder of an individual’s longitudinal health context. We describe the LifeCare Network, a de- ployed system that separates three concerns the industry usually collapses into one: control of health data (a patient-held identity, consent and authorization layer that stores no health data), holding of the data (provider-operated nodes that keep raw values in place), and inference over it (open-weight models that run on the node, with only interpreted outputs leaving). We present the consent receipt shaped to ISO/IEC TS 27560 and approved by a passkey assertion over the canonical grant, a UMA-pattern authorization server with purpose-bound tokens validated by introspection and revoked in under a second, a hash-chained per-person ledger and resource reg- istry, three enforcement layers that make “raw data never leaves” a property of code paths rather than policy, erasure by key destruction that preserves the ledger’s verifiability, and a software- rooted attestation whose measurement anyone can recompute from the node’s public response. We report early operating results from a single production node: a champion/challenger gate that rejected a stronger benchmark model on the network’s own golden set, a conversational layer redesigned after prompt-only rules failed in live traffic, and a pre-registered twelve-week outcome study with locked endpoints and kill criteria. We state the limits: attestation is not yet hardware-rooted, enforcement of caller authentication is a deployment setting, and no outcome data exists yet. We position the design against personal data stores, patient-controlled authorization servers, confidential cloud inference, and agent-memory layers, and argue that the unoccupied position is data-scoped, purpose-bound consent enforced next to the data.
No comments yet — start the discussion below.