Steps to building a scalable and secure health Internet lane
Relational models for building trust don’t scale if you are trying to connect everyone to everyone else — exactly what is being attempted in healthcare.

The first article in this series discussed the importance of organizational identity in establishing trust in healthcare exchange. In this article, we’ll look at the Legal Entity Identifier (LEI), and the Verifiable Legal Entity Identifier (vLEI) that builds upon the LEI as one possible path toward scalable operational trust.
But first, indulge my inclination to make an irreverent analogy. On the Internet, making connections is a lot like dating in the modern world. You need to know, and trust, those with whom you are connecting.
Creating this familiarity without establishing formal relationships can be a challenge, but it isn’t impossible. In fact, it’s incredibly common. When you make a connection with someone new, you need to learn who they are. For the sake of modern dating, maybe this includes their demographics, family dynamics or political views. After you know who they are, you can decide what they are authorized to do, presuming you know enough about them.
Most personal relationships are made through introductions, followed by shared experience and, if things go right, deepening trust and commitment. This model doesn’t scale if you are trying to connect everyone to everyone else. That’s what we are attempting to do in healthcare. If it sounds risky, that’s because it is — unless we can easily determine who’s who.
Third-party risk
When a consumer is using one platform to connect to another, there are three parties involved — the consumer and each of the respective platforms. Each party has an interest in understanding the answers to three critical questions about the other two: Are you who I think you are? Are you safe to transact with? What data do you have rights to?
In many circumstances, at least two of these topics are left to blind trust. Whether or not the risk is worth taking depends upon the balance between your taste for risk and your demand for convenience. In the risk-filled world we live in today, it would be ideal to have all three answers before moving on. However, convenience sometimes wins, and we connect knowing less than we would like to know.
Just as often, trust is lost and connections fail.
In today’s climate, an individual’s identity is usually assured. However, organizational identity and authorization are typically established through contracts and costly onboarding exercises — the equivalent of the aforementioned introduction. The question of whether they are safeguarding their systems depends upon an independent assessment, which is nowhere near universal and needs to be an established part of the onboarding process.
Healthcare is connecting silos
Currently, healthcare is trying to connect all the disparate systems with which people interact into a single, coherent ecosystem. The most challenging part of this isn’t the standards required or the technical connections that are needed — these are mostly established.
It's the fundamental question of trust. Trust breaks down when the initial questions about identity can’t be reliably answered for any given actor. Do I know them, and are they a real organization? What should they be able to do? Do they take care of themselves? How do they handle my data?
What if we could provide answers to these questions with a single, trust-enforcing strategy?
Status quo and minding the gap
The first article of this series noted that provider directories, NPIs, tax identifiers, digital certificates, onboarding processes and trust frameworks all exist to help identify organizations. The Centers for Medicare & Medicaid Services (CMS) is building a national provider directory. So, are we all set?
Not quite. These tools were designed to solve specific operational or technical problems. They may work well in those contexts but are not reliable for all use cases. They are missing a portable trust mechanism that can be reused across networks, business relationships and digital transactions.
We don’t need another directory or even another identifier. We need a cryptographic mechanism to assert identities and authorizations for individuals and organizations — in other words, a credential that identifies individuals and organizations and can be universally accepted for its global uniqueness and the rigorous requirements of its issuance.
Healthcare isn’t the first industry to experience this missing link. In fact, financial services grappled with it after the 2008 financial crisis. Regulators and market participants discovered that they could not consistently determine which legal entities were involved in transactions, how those entities related to one another or where risk had accumulated across increasingly complex organizational structures.
The solution was the creation of the Legal Entity Identifier, which later became the foundation for the Verifiable Legal Entity Identifier. An LEI may sound like just another identifier, but it was specifically designed to establish a consistent, globally recognized identity for legal entities across industries, jurisdictions and business relationships.
The LEI is a globally unique, 20-character identifier assigned to legal entities and governed through the Global Legal Entity Identifier Foundation (GLEIF). Today, millions of organizations around the world maintain LEIs to support transparency, trust and accountability across financial and business transactions. It’s required by regulations across dozens of jurisdictions and was recently included in the US Federal Data Transparency Act Final Rule.
Answering key questions
An LEI helps answer two fundamental questions. The first is, “Who are you?" It verifies information such as the organization's legal name, jurisdiction, registered address and unique identifier, providing a consistent way to confirm that an organization is who it claims to be.
The second is, "Who owns whom?" LEI data can include parent-child relationships and ownership structures that explain where an organization fits within a larger corporate hierarchy.
LEIs are issued by one of 39 accredited issuing organizations around the world and are transparently available through a public registry. During the issuance process, the organization’s legal existence and registration are verified against authoritative sources within its jurisdiction.
Healthcare organizations rarely operate in isolation. Hospitals may belong to large health systems. Technology companies may be subsidiaries of multinational corporations. Trust decisions often depend not only on knowing an organization’s name, but also on understanding where it fits within a larger corporate structure.
Healthcare already has a head start
When a new standard is discussed, adoption is typically a top concern.
Healthcare has good reason to be cautious about introducing new identifier standards. The industry already manages a complex ecosystem of identifiers, registries, directories and trust frameworks. What makes LEIs particularly interesting in this context is that healthcare may be much further along in adoption than many people realize.
Many large healthcare organizations already possess LEIs because of existing financial and regulatory requirements. That creates an opportunity to begin exploring practical application of the standard without waiting for the entire healthcare ecosystem to start from scratch. An LEI typically costs about $50 per year for the benefit of proving your identity to the government and your business partners.
Timing matters here. Healthcare is simultaneously implementing CMS-0057 requirements, expanding FHIR-based exchange, participating in TEFCA and exploring more automated interoperability models. As the number of digital connections grows, questions about organizational identity and authority become harder to answer through manual processes alone.
Interoperability initiatives like FHIR, UDAP, TEFCA and payer-to-payer exchange are moving healthcare toward increasingly direct and automated exchange models. This creates tremendous opportunities for the industry.
At the same time, this automation creates new expectations around trust. Historically, many trust decisions have been established through onboarding, contracts, participation agreements, endpoint configuration and manual review processes. Those mechanisms can work, but they can also become increasingly difficult to scale as the number of participants and exchange relationships grows.
LEIs should not be viewed as replacements for existing trust frameworks, accreditation programs, digital certificates or governance models. Instead, they should be considered an opportunity to provide a common organizational identity foundation that those frameworks can build upon.
In practical terms, that means helping answer questions such as the following. Which legal entity operates this system? How does that entity relate to other organizations? Is the entity active and identifiable?
Those questions already exist throughout healthcare exchange today. LEIs simply offer a more standardized and reusable way to answer them.
In the end, the question is not whether healthcare needs organizational identity. We already depend on it every day. Instead, it’s whether we can establish it in a way that is portable, reusable and scalable enough for the next generation of interoperability.
A universally recognized cryptographic mechanism is required for this model to scale. The LEI serves as the foundation for the vLEI, which extends trusted organizational identity into digital interactions by enabling identities and assertions to be cryptographically verified. It can help prove not only who an organization is, but also what authority an individual or organization has to act on its behalf.
Looking ahead
Healthcare doesn’t need to invent organizational identity from scratch. The LEI already exists, and the vLEI extends it into digital interactions. Many healthcare organizations already participate in the ecosystem, whether they realize it or not.
The third and final article of this series will explore the vLEI credentials and how organizations are beginning to test these concepts in practice and what they could mean for payer-to-payer exchange, FHIR-based interoperability, provider directories and the future of trust in healthcare exchange.
Scott Stuewe is president and CEO of DirectTrust, driving strategy, visibility and growth of DirectTrust’s focus areas of community, accreditation, standards development and trust services.
