Public working draft · 4 September 2026

Health Data and AI-Use Consent Profile v1.0

A HUGS ID authorization profile for Apple Health, EHR/EMR, wearable and other health-adjacent data used by healthcare, research or AI organizations.

Consent must remain specific, inspectable and revocable after a person presses Submit and after data crosses an organizational boundary.

Implemented control-plane profile

Motivating problem

A form is not a durable authorization record.

A participant may connect a personal device, Apple Health, an electronic health record and selected health information so an organization can deliver a de-identified dataset for research or model development. A submission alone does not prove which source, recipient, operation, study, model, retention period or downstream use the person approved.

This gap reflects the healthcare-system lessons that motivated HUGS ID and the early WaveOn Health Network work: identity, consent and provenance must remain governable after data moves.

Normative authorization

Every permitted use binds the complete tuple.

ElementRequired evidence
PersonDurable HUGS subject and authorizing person or authority.
SourceRegistered provider, classification and hashed source identity.
RecipientRegistered organization, display name and recipient role.
PurposeUnderstandable declared purpose—not merely “research.”
ScopePermitted data categories and each permitted processing operation.
Study or modelExact study/model reference for analysis, training or validation.
TimeStart, expiration and separate retention end.
Downstream useProhibited, named processors only, or an authorized research network.
WithdrawalFuture-access stop plus the recorded obligation for prior disclosures.
Consent evidenceConsent version and SHA-256 digest of the document shown.
Critical rule: consent to collect is not consent to train or validate an AI model. model_training and model_validation must be explicitly authorized.
Enforcement

Authorization happens before access.

Withdrawal

Stop future use without rewriting history.

Pause or withdrawal stops future authorization immediately. Historical evidence remains so the participant and reviewer can see what already occurred. The profile records whether prior copies are subject to future-access cessation, a deletion request or contractual retention. HUGS does not claim a recipient deleted data until a deletion attestation is recorded.

Implementation

What exists now.

Boundary: Apple Health and direct EHR adapters remain evaluation integrations pending provider access, participant UX, commercial terms and independent security assessment. This profile is the enforceable control plane those adapters must use; it is not a claim that all connectors are live or certified.
WaveOn application

How a WaveOn pilot must use HUGS ID.

The approved WaveOn entity must be registered as the recipient organization. Every Apple Health or EHR source must be registered separately. The participant must see the complete authorization tuple, and the adapter must call the HUGS authorization gate before every covered operation.

Any research sponsor, processor, model developer or downstream network participant must be named or covered by the recorded downstream policy. A general research consent cannot silently expand into future model training or secondary use.