Bill Buchanan - A Vision for the NHS: A Citizen Wallet
Release Date: 08/15/2023
ASecuritySite Podcast
Martin Albrecht is a Professor of Cryptography at King's College London and a Principal Research Scientist at SandboxAQ. He works broadly across the field of cryptography. His work focuses on the analysis of deployed or soon-to-be deployed cryptographic solutions and he has responsibly disclosed severe vulnerabilities to various public and private stakeholders such as OpenSSH, Amazon EC2, Apple, Telegram, Jitsi and Matrix. He further works on designing advanced cryptographic solutions. He is well known for analysing the security of lattice-based cryptography against classical and quantum...
info_outlineASecuritySite Podcast
Gilles has been a full Professor at the Université de Montréal for more than 45 years. He laid the foundations of quantum cryptography at a time when no one could have predicted that the quantum information revolution would usher in a multi-billion-dollar industry, much less that the United Nations would proclaim 2025 to be the International Year of Quantum Science and Technology. He is also among the inventors of quantum teleportation, which is one of the most fundamental pillars of the theory of quantum information. In addition to this, his research focuses on areas of classical...
info_outlineASecuritySite Podcast
Christof is a director at the Max Planck Institute for Security and Privacy in Bochum, Germany. He is also, a member of the German National Academy of Sciences Leopoldina and a Fellow of the IACR and IEEE. His research includes areas of light-weight cryptography, efficient cryptographic implementations, cryptographic Trojans and physical layer security. Christof is one of the co-creators of the PRESENT light-weight cipher and of the PRINCE block cipher, In 2003, he founded Escrypt GmbH together with Willi Mann-heims, and which was one of the first companies to focus on industrial...
info_outlineASecuritySite Podcast
info_outlineASecuritySite Podcast
Victor is a Senior Research Scientist at Nexus Laboratories. He received his PhD in Mathematics from Harvard University in 1975, and was an assistant professor at the University of Massachusetts Boston from 1973 to 1978. Victor has since worked for the IBM Research Center, The Institute for Defence Analyses in Princeton, Meta Platforms and SRI International. For his research, Victor has focused on areas of computational number theory, data compression and cryptography. Along with Neal Koblitz, he was the co-creator of Elliptic Curve Cryptography, the inventor of Miller's algorithm and...
info_outlineASecuritySite Podcast
A fireside chat from the International Conference on Digital Trust, AI and the Future. Bruce has created a wide range of cryptographic methods including Skein (hash function), Helix (stream cipher), Fortuna (random number generator), and Blowfish/Twofish/Threefish (block ciphers). Bruce has published 14 books, including best-sellers such as Data and Goliath: The Hidden Battles to Collect Your Data and Control Your World. He has also published hundreds of articles, essays, and academic papers. Currently, Bruce is a fellow at the Berkman Center for Internet and Society at Harvard University.
info_outlineASecuritySite Podcast
Federico Charosky, CEO Quroum CyberFederico is a seasoned cybersecurity executive with over 25 years of distinguished experience across the Americas, Europe, and the Middle East. He specialises in cyber risk management, security operations, and incident response, Federico has dedicated his career to safeguarding organisations against the ever-evolving landscape of digital threats. In 2016, he founded Quorum Cyber, a premier cybersecurity firm backed by private equity, headquartered in Edinburgh with offices across the UK, North America, and the UAE. At Quorum Cyber, our mission is to...
info_outlineASecuritySite Podcast
info_outlineASecuritySite Podcast
Chair: Stephen Ingledew OBE, Chair, Fintech Scotland Nishant Govil: MD, Innovation Adoption, BlackRock Kara Kennedy: Head of Digital Assets, JP Morgan Nick Jones: CEO Zumo. Dia Banerji: Imagine Ventures.
info_outlineASecuritySite Podcast
Date: 24 June 2025 Chair: Peter Ferry, CEO, TRUST Centre of Excellence. Martin Doherty Hughes: Former MP, Chair of All Party Parliamentary Group on Blockchain. Martin Trotter: Regtech leader, BRS Grant Thornton Martin Halford: CTO SICCAR and Tech Steering Committee Accord Project Chris Tate: CEO Condatis.
info_outlineYour organisation needs a vision. Without it, you will never be great. You will never advance. You will keep doing the same old things and without any real purpose. A vision gives you a purpose and a focus. But, it needs to have a plan which takes you there. But, without it, how can you ever plan? For any great organisation, you start with a vision.
So, what about a vision for the NHS? I appreciate that I am only a technologist, but I am also a citizen, and I care about the health and well-being of my fellow citizens. I also don’t like bureaucracy and inefficiencies — and I strive in my working life to overcome these. So, our work has generally focused on improving the citizen’s viewpoint of health care.
And, so, I am honoured to present at Digital Scotland 2023 this year, and on a topic which has been our passion for over a decade — a citizen-focused health care system:
I have attended conferences in Scotland and which talk about “citizen-focused health care”, and the audience all go away inspired and ready to build new digital worlds for citizens. But nothing happens, and then we repeat the next year again. Well, this year, I will show that a vision can be created as a reality. With digital wallets, the technology is all in place, and there are no great barriers to overcome, any more.
During the COVID-19 time, there was some hope for digital advancedment and where we saw the use of digital passports — but we have failed to build of these, and have ended up with little in the way of digital engagement between the NHS and the citizen.
So here’s the problem and my vision — and it’s quite simple.
The Problem
I have interacted with the NHS for several decades — luckily, I have never had any medical ailments, but have observed it in relation to others. I have seen some truly shocking practices in dealing with patient records -including for someone in my family have “Do not resuscitate” written on their records without any discussion with the family, and where a physical filing cabinet of patient records had to be moved by taxi from one hospital in Edinburgh to another one.
Overall, there is often great resistance to change and to the adoption of digital methods. The Connecting for Health programme — which cost over £15 billion — had to be eventually cancelled, as it delivered nothing.
Why? Well, one reason is, “Won’t this replace my existing job of writing down the details?”, “Yes, but you can do and do something even better with your time”, “But, this is what I was trained for. Anyway, I don’t trust computers, anyway!”
And, so, recently, I went to register for a GP and was handed a piece of paper and told to find a pen and write down all my details. In virtually every interaction with the NHS, I have had to do this, and perhaps, one day, I will have all my medical details stored on a digital wallet on my phone, and where the GP just scans them in. Once I filled in it, it then went into a black hole — and where I hoped that a human would eventually make sense of my scribbles.
To date, I have yet to receive any confirmation that I have been registered, and I have no on-line place to check my details. The NHS can hardly get to first base in creating a proper online world for my data. It fleetingly sends me the odd email or SMS message, but it still sits behind a high wall.
Overall, in places, it feels like there are still parts of our lives that are stuck in the 20th Century.
The Vision
Let me dream now. One day, I will register for a new GP. I will walk in, and the receptionist will ask me to register. I will press a few buttons and generate a QR code. They will scan this in, and an instant message will appear to say that I am now registered and say that all my details have been registered,
“Ah, Nice to meet you, Bill. I see it is your birthday today. Please can you check your details are okay and consent to its storage?”. “All looks good”.
“How would you like us to contact you, by email or SMS?”, “Email. Please. Here is the QR code for my email address, and you can scan it”.
When I go to see the GP, they ask me for my weight and height, and, again, I go to my wallet and generate a QR code and where the GP scans it in and says,
“That’s great. All is okay. But your BMI is a little high, and a little up from the last time we meet. I will store this in your record, and we can keep a track on it. I will email you some recommendations for your diet”.
How long for this to happen?
How long will it take for this to ever happen? Well, it’s actually not that difficult. We are part of an EU project which has developed the GLASS wallet and which puts the control back in the citizen’s hands:
So, why not come and see it live on 12 Sept in London [here]:

And in November [here]:

Conclusions
We have a dream for an improved healthcare system — and we have had this dream for over a decade. The technology is all in place — we now need to use it and put the power back into the hands of those who really matter — the citizen!