Inspiration
Across many African healthcare systems, a patient's medical history is fragmented across paper prescriptions, laboratory reports, vaccination cards, radiology images, and records held by different facilities. Important information can be lost, unavailable during a consultation, or difficult to share safely.
WérPass is designed to give patients a secure and portable way to organize and share their medical documents while remaining in control of their data.
What it does
WérPass is a privacy-first mobile application and patient-controlled digital health vault.
Patients can use the mobile app to scan or import prescriptions, laboratory results, medical reports, vaccination records, certificates, images, and PDF files. Their documents are organized into a personal medical timeline while the original files remain securely stored.
WérPass generates a secure QR code that a healthcare professional can scan to request temporary access. The QR code never contains medical information. It contains only a secure, short-lived access reference.
The patient decides:
Which documents can be viewed Who can view them How long access remains valid Whether downloading is allowed When access should be revoked
Every access is recorded in an audit log visible to the patient.
Patient-controlled use of GPT-5.6
The patient decides whether to use GPT-5.6 for each document import. Smart Import is activated only when the patient chooses it. Before any processing begins, the application clearly explains what will be shared, how GPT-5.6 will be used, and requests the patient's explicit approval.
When Smart Import is approved:
The document is processed to detect and remove identifying information before AI analysis. The patient can review what will be shared. Only the minimum information needed for classification is sent to GPT-5.6. The original medical document is not sent to GPT-5.6. GPT-5.6 proposes a document type and structured metadata. The patient must review and confirm the result before it becomes part of the medical timeline.
GPT-5.6 is used only to assist with document classification, structured metadata extraction, and detection of unreadable or missing information. It does not diagnose conditions, recommend treatments, or make clinical decisions.
How we are building it
WérPass is being developed as a mobile application with React Native, Expo, and TypeScript, supported by a secure backend and private document storage.
Codex supports architecture, implementation, testing, security reviews, documentation, and iterative product decisions. GPT-5.6 powers the patient-approved Smart Import workflow using structured outputs.
The system is designed around:
Explicit patient consent Data minimization Local redaction and pseudonymization Private storage Short-lived access permissions Revocable sharing Audit logs Clear data provenance Human validation of AI-generated information Separation between original documents and AI-generated metadata
Safety and privacy
Medical information is highly sensitive. WérPass therefore follows a privacy-by-design approach.
The QR code contains no medical data. Access grants are temporary, selective, and revocable. AI processing remains under the patient's control, and no information is sent without explicit approval.
Information is labeled according to its provenance:
Patient-declared AI-extracted Patient-confirmed Healthcare-professional-issued Healthcare-facility-verified
AI-generated information is never presented as verified clinical information. The original document remains the reference, and every AI extraction requires human review.
Only synthetic patients and synthetic medical documents are used in the hackathon demonstration. WérPass is a prototype and is not presented as a production-certified medical system.
Challenges
The central challenge is balancing portability with medical confidentiality.
A QR code containing a complete medical history would create serious privacy risks. WérPass therefore uses the QR code only as a controlled access mechanism.
Another challenge is benefiting from AI without making it a mandatory or invisible processor of medical information. We designed Smart Import as a patient-controlled, consent-based workflow with local de-identification, data minimization, clear provenance, and mandatory human validation.
What we are proud of
Designing the product as a mobile-first experience Keeping the patient in control of every sharing decision Giving the patient full control over when GPT-5.6 is used Preventing medical information from being embedded in the QR code Making access temporary, selective, revocable, and auditable Separating original records from AI-generated metadata Treating privacy and informed consent as product features rather than afterthoughts
What's next
Future development could include HL7 FHIR interoperability, verified submissions by healthcare facilities, secure laboratory integrations, offline emergency summaries, dependent profiles, local-language accessibility, independent security audits, regulatory assessments, and partnerships with healthcare institutions.
Built With
- codex
- expo.io
- gpt-5.6
- react-native
- supabase
- typescript