Limitations
mynachat is a hackathon prototype. So it never looks like more than it is, here is what it can't do yet and what's still open.
What a proof does and doesn't show
A prescription is not a diagnosis
A proof shows a drug was prescribed, not why. Some drugs treat more than one condition (montelukast is used for both hay fever and asthma), so each group lists only drugs closely tied to its condition. This is implemented as a workaround because no other useful data is available to me at the time of the hackathon.
Intractable disease proofs are untested
mynachat started from the fact that Myna Portal provides medical information for people with designated intractable diseases (指定難病), which are conditions officially designated by the Ministry of Health, Labour and Welfare (MHLW). I do not have a designated intractable disease, so I haven't been able to test this proof yet. I will be testing with volunteers who have a designated intractable disease going forward.
Official diagnoses can't be proven yet
Japan's EHR sharing service (電子カルテ情報共有サービス) is a government initiative to share diagnoses and other data from hospitals' electronic medical records. It is in a pilot phase and is expected to be fully running in 2027. Myna Portal already has an endpoint for this data (
/api/my/healthinfo/get-six-medical-info), with diagnoses recorded as MEDIS standard disease codes (標準病名マスター), which map to ICD-10. Today the endpoint returns an error (WDE401) because no data flows into it yet. Once the service rolls out, we expect it to become the main way to prove a condition.
Depending on Myna Portal
The TLSNotary verifier makes the call
Medical records from Myna Portal carry no digital signature, so we rely on TLSNotary to show that a record really came from Myna Portal. In TLSNotary terms, you are the prover and mynachat is the verifier. The verifier can't read anything you don't disclose, but nothing technically stops it from ignoring the proof and deciding however it likes. The design assumes that a trusted party within each patient group will eventually run the verifier. In the long run, we can avoid this trust assumption if the government signed the data it provides, which would be awesome.
Terms of use and health data rules are unresolved
We reuse the user's session cookie to send requests to Myna Portal's web page, which requires the user to install a custom Chrome extension. This is a workaround. Requesting official Myna Portal API access would resolve this issue, but approval takes 6 to 12 months, so we think it's justified for a hackathon demo.
The proof itself is explained on the How it works page.
How it works