Symphonix-Health Research · Cross-Border Interoperability

Trust That Travels

Africa has written its interoperability standards. What it still lacks is a way for a health record signed in one country to be believed in the next. The World Health Organization's certification network shows how to do that without anyone surrendering their data. Here is how it works, and how BulletTrain puts it to work.

A nurse at a border clinic is holding a vaccination card she cannot check. The patient crossed overnight with a paper record, a phone full of photographs and a clinical history held somewhere in a system the clinic has never heard of. She can accept the card on faith, repeat the vaccine, or turn the patient away. None of those choices is good medicine, and each one costs money the health system does not have.

Repeat that moment across more than fifty countries and millions of traders, students, migrant workers and displaced families, and you have the practical shape of Africa's interoperability problem. The difficulty is rarely that nobody has written a standard. It is that a record produced in one country carries no proof the next country can rely on.

The stakes are rising. Most African countries are pursuing Universal Health Coverage (UHC), the goal that everyone can use the health services they need without financial hardship, and most are using digital health to get there. That drive has made integration and interoperability, including across borders, a priority. Coverage that works only inside one country's systems leaves out exactly the people who move.

The standards exist. The trust does not.

The policy groundwork is more advanced than many outsiders assume. The African Union Health Information Exchange (AU-HIE) guidelines and standards were launched in Nairobi in March 2023, with 38 member states represented, setting out what each country must meet to reach health data interoperability [1]. The Smart Africa Digital Health Blueprint, validated by the Smart Africa Board of Heads of State on 12 November 2025, points countries to international standards such as HL7 Fast Healthcare Interoperability Resources (FHIR), the leading standard for exchanging health data, and notes that Africa CDC encourages member states to adopt them [2]. The number of countries in the WHO African Region with a digital health policy or strategy rose from 20 to 36 of 47 between 2016 and 2022 [3].

Yet in January 2026, when the Africa Centres for Disease Control and Prevention (Africa CDC) launched its Central Data Repository, it described public health data on the continent as still "fragmented and dispersed across multiple systems that are often not interoperable" [4]. That matters, because Africa CDC also reports that public health emergencies across the continent rose by 40% between 2022 and 2024, reaching 213 incidents [4]. Outbreaks do not wait at border posts.

Standards tell two systems how to format a record. They do not tell a clinic in one capital whether to believe a record signed in another. That second question is about trust, and it is the one African interoperability keeps stumbling over.

4 of 47
WHO African Region countries that were able to join the EU Digital COVID Certificate network [5]
80+
Countries now connected through WHO's Global Digital Health Certification Network [6]
€8m
EU grant, 2025 to 2028, to widen adoption of the network in sub-Saharan Africa [5]
◆ ◆ ◆

Why interoperability keeps stalling

A 2026 scoping review of interoperability in Africa found wide differences between countries, with Uganda, South Africa and Kenya showing more momentum, and named the same obstacles again and again: limited technical capacity, fragmented infrastructure and weak regulatory support [7]. On the ground, six problems tend to arrive together.

1. Systems built for programmes, not for patients

Many digital health investments have been vertical and partner-driven: an HIV system here, an immunisation register there, each designed for one programme and one funder [8]. Each works on its own terms. None was designed to speak to the others, let alone to a neighbouring country.

2. Meaning that does not survive the journey

Two systems can exchange a file perfectly and still disagree on what it says. A vaccine code, a test result unit or a date format that means one thing in one register can mean something else in another. Moving data is the easy part. Keeping its meaning intact is harder.

3. Power and bandwidth

Any design that assumes a constant connection to a central server fails in a rural clinic on a generator, or at a border post with one bar of signal. Checks that only work online will not be used where they are needed most.

4. Sovereignty

No ministry of health will pour its citizens' records into a database run by another government, a donor or a foreign company, and it should not have to. Many continental data proposals stall at exactly this point.

5. Trust between institutions

Even when a record arrives intact, the receiving clinician needs to know who issued it, whether that issuer is recognised, and whether the record has since been withdrawn. Paper certificates are easy to forge, and a scanned PDF is no better.

6. Capacity and cost

Proprietary platforms with per-facility licences price out exactly the health systems that need connection most, and they leave ministries dependent on vendors for every change.

Interoperability in Africa is rarely blocked by a missing standard. It is blocked by a missing reason to believe.

How GDHCN solves the trust problem

The Global Digital Health Certification Network (GDHCN) is WHO's answer to the trust question, and its design is simple enough to explain in one sentence: countries share keys, not patients.

It works like passport control. A border officer does not phone the issuing government to confirm every passport; they check security features the issuer is known to use. In GDHCN, each participating country lodges its public cryptographic keys in a directory that WHO manages. When a health authority issues a digital certificate, such as a vaccination record or a test result, it signs it with its private key. Any participant using the directory can then confirm that the certificate came from a recognised authority and has not been altered [9].

WHO never holds or sees the personal data inside those certificates; that stays with each country [9][10]. Participation is voluntary, and the network follows WHO SMART Guidelines and HL7 FHIR specifications, so it fits the standards African countries are already adopting [10]. It grew out of the EU Digital COVID Certificate system, which connected 76 countries and territories, and has been run by WHO since 2023 [5].

That history also shows the gap. Only four countries in the WHO African Region (Benin, Cabo Verde, Seychelles and Togo) were able to join the EU network [5]. In October 2025, the EU and WHO agreed an €8 million grant for 2025 to 2028 to widen GDHCN adoption in sub-Saharan Africa, working with regional partners including Africa CDC [5]. WHO also sees the network as a route to a digital International Certificate of Vaccination or Prophylaxis (ICVP), the Yellow Card, in line with the updated International Health Regulations (IHR) [5]. In March 2026, the International Organization for Migration (IOM) became the first international organisation to join, bringing people on the move into scope [11].

What GDHCN is, and what it is not

GDHCN proves where a health document came from and that it has not been tampered with. It is not a pipe for day-to-day clinical data, and it is not a central record store.

Its participants are WHO Member States and, so far, one international organisation. Software vendors, including us, do not join it. We build the tools a ministry uses to take part.

0
Patient records WHO can open through the network. Countries publish public keys. The data stays at home.

How the pieces fit together

Before looking at the software, it helps to see the whole picture. Cross-border trust in Africa works at three levels, and each level has a different owner.

Global. WHO keeps the directory of trusted keys. It records which authorities are trusted to sign health certificates, and it never sees a patient record.

Continental. The African Union and Smart Africa set the shared standards every country builds to. Africa CDC brings together surveillance, laboratory and programme data from national systems to spot outbreaks that cross borders [4].

National. Each ministry of health owns its data and holds its own signing key. BulletTrain sits inside the country as the connecting layer: it links the systems already in use, issues signed certificates on the ministry's behalf, and checks certificates arriving from elsewhere.

Only one thing crosses the border: the patient, carrying a record that proves itself.

Swipe to see the full diagram → How Africa's cross-border health trust fits together Three layers. Globally, the WHO Global Digital Health Certification Network holds a directory of countries' public keys and no patient data. Continentally, the African Union and Smart Africa provide shared standards and Africa CDC receives aggregate public health reporting. Nationally, two example countries each have a Ministry of Health holding the signing key, BulletTrain as the national interoperability layer, existing hospital, immunisation and laboratory systems, and clinics and border posts. Each ministry publishes its public key to WHO and receives other countries' keys. A signed record travels with the patient from a clinic in Country A to a clinic in Country B, where it is verified. GLOBAL CONTINENTAL NATIONAL WHO Global Digital Health Certification Network A trusted directory of public keys · no patient data African Union and Smart Africa Shared frameworks, pointing to HL7 FHIR Africa CDC Continental surveillance and public health intelligence standards and guidance public health reporting COUNTRY A Ministry of Health Owns the data and holds the signing key authorises signing BulletTrain National interoperability layer Issues and checks signed certificates links existing systems Hospital records Immunisation registers Laboratory systems serves the front line Clinics and border posts Certificate issued here COUNTRY B Ministry of Health Owns the data and holds the signing key authorises signing BulletTrain National interoperability layer Issues and checks signed certificates links existing systems Hospital records Immunisation registers Laboratory systems serves the front line Clinics and border posts Certificate checked on arrival publishes its public key receives other countries' keys publishes its public key receives other countries' keys Signed record travels with the patient
A high-level view. Two countries are shown, but the pattern repeats for every country that joins. Patient records stay in the country that holds them, and only public keys go to WHO. Dashed lines are policy and reporting relationships that depend on each country's own agreements.

How BulletTrain does it

BulletTrain is Symphonix-Health's open-source, FHIR-native interoperability engine, released under the Apache 2.0 licence. Among its services is a GDHCN service that handles the full life of a cross-border health certificate: issuing it, checking it, and withdrawing it when needed. In outline:

01 · ISSUEClinical eventA vaccination, test result or recovery is recorded, and consent is checked.
02 · SIGNAuthority's keyA FHIR record is built and signed with the issuing authority's key.
03 · CARRYPatient travelsThe signed certificate goes with the person, on a phone or as a barcode.
04 · VERIFYAny clinicThe signature is checked against the trusted issuer's public key.

The certificate carries its own proof. No central database is consulted about the patient.

Issue · on the ministry's behalf

Certificates built from real clinical events

BulletTrain takes a clinical event (an immunisation, a test or a recovery), confirms the patient's consent through its consent service, and builds a FHIR bundle holding the patient and the relevant clinical resource. Each certificate receives a unique certificate identifier and is signed with an elliptic-curve digital signature. Every issuance writes an audit record.

Verify · at the point of care

Five honest answers, not a green tick

When a certificate is presented, BulletTrain looks up the issuer in its list of trusted authorities, checks the signature, then checks expiry and revocation. The answer is one of five: active, expired, revoked, untrusted or invalid. One design choice matters here: a certificate that cannot be checked against the revocation list is refused, not waved through. A verifier should never assert something it cannot verify.

Trust list · when the network drops

Verification that survives a bad connection

BulletTrain keeps a local copy of trusted issuers' public keys and refreshes it every six hours. If the connection fails, verification continues against the last known list. A signature check needs no call to a central server, so a clinic on a weak link can still get an answer.

Governance · built in, not bolted on

Policy, consent and audit on every call

The service sits behind BulletTrain's policy enforcement layer: a caller without a verified identity and the right permission is denied. Issuance, verification and revocation are all audited. In August 2026, the clinician certificate screen passed end-to-end testing against live identity, policy, audit and registry services, including GHARRA, our agent trust registry.

◆ ◆ ◆

Challenge by challenge

Set against the six obstacles above, this is how the combination of GDHCN and BulletTrain responds.

Vertical systemsConnect, don't replace

BulletTrain is built to sit alongside the systems countries already run, such as DHIS2 (District Health Information Software 2) and OpenMRS (Open Medical Record System), rather than replace them. Each connection is built and tested system by system, so a programme system should not need rebuilding to issue a certificate another country can trust.

MeaningFHIR from the first byte

Certificates are built as FHIR resources, the standard GDHCN uses and the Smart Africa Blueprint points to, so the clinical content arrives in a structure the receiving system already understands.

Power and bandwidthOffline-tolerant checks

The cached trust list means verification keeps working when the connection does not, which matters most at the rural clinics and border posts where signal is weakest.

SovereigntyKeys and data stay home

Patient data stays in the issuing country. The signing key sits with the ministry, not with Symphonix-Health. The code is Apache 2.0, so a ministry can inspect it, run it and change it without our permission.

TrustProof in the document

A signed certificate carries its own evidence. Revoked, expired and untrusted certificates are identified, not silently accepted.

Capacity and costNo licence fee

Open source removes the per-facility licence barrier, and ministry engineers can build their skills on a codebase they own rather than rent.

What we have not solved yet

Joining GDHCN is a ministry's decision. A country's keys enter the WHO directory through WHO's own onboarding process. Our job is to make a ministry technically ready, not to take part on its behalf.

Production conformance is the next milestone. BulletTrain's service implements the same sign-and-verify model GDHCN uses. Aligning its certificate format and trust-list connection with WHO's production specifications, and moving signing keys into hardware the ministry controls, comes before any live deployment.

Revocation across borders needs agreement, not just code. Today a revocation is recorded where the certificate was issued. Sharing revocation status between countries needs arrangements between countries as well as software.

Scope is still narrow. Current templates cover vaccination, test and recovery certificates. The digital Yellow Card and cross-border patient summaries are the natural next templates.

There is a wider caution too. Africa CDC's model for assessing health information exchange maturity has four domains: leadership and governance, management and workforce, ICT infrastructure, and standards and interoperability [12]. Software speaks to one and a half of those. The rest is institutions, people and money, and no platform substitutes for them.

“

Records should travel. Sovereignty should stay at home. Cryptographic trust is how Africa gets both.

DR JOSH TEDAM · SYMPHONIX-HEALTH

Where a ministry can start

Cross-border interoperability does not begin with a continental platform. It begins with one certificate that already crosses borders, between two countries that already share patients.

  1. Settle who holds the key. Decide which body signs on the country's behalf, and keep the private key in hardware the ministry controls. Everything else depends on this.
  2. Start with the Yellow Card. Vaccination certificates already cross borders on paper, WHO sees GDHCN as the route to a digital version, and forged cards carry a real public health cost.
  3. Test with a neighbour before a continent. Two ministries issuing and verifying each other's certificates in a real border clinic will teach more than any pilot confined to one country.
  4. Build on what exists. Connect the immunisation register and electronic record systems already in place, rather than commissioning another vertical system.

The frameworks are written and the funding is moving. The certification network already exists. The remaining work is to connect Africa's clinics to it in a way that ministries own, clinicians can use offline, and patients never have to think about.

Universal Health Coverage that stops at the border is not universal. Making a health record trusted wherever the patient goes is part of the UHC promise, not an extra. That is the work BulletTrain was built for.

References

  1. "Africa CDC spearheading the strengthening of health information exchange in Africa." The Lancet Digital Health, June 2024. thelancet.com
  2. Smart Africa. "Smart Africa Board Validates Digital Health Blueprint to Build a Single Digital Health Market." November 2025. smartafrica.org; and Smart Africa Alliance, Digital Health Blueprint. smartafrica.org (PDF)
  3. Bataliack, S. Health Data Digitalization in Africa: Unlocking the potential. WHO Institutional Repository. iris.who.int
  4. Africa CDC. "Africa CDC Establishes Central Data Repository to Strengthen Public Health Surveillance." 27 January 2026. africacdc.org
  5. WHO. "WHO and the European Union launch collaboration to advance digitized health systems in sub-Saharan Africa." 14 October 2025. who.int
  6. WHO. "Global Digital Collaboration Conference 2026." Event page, August 2026. who.int
  7. "Adoption, barriers and opportunities of interoperability and eHealth standards in Africa: a scoping review." BMJ Group, 2026 (open access). pmc.ncbi.nlm.nih.gov
  8. "Strengthening Health Systems Using Innovative Digital Health Technologies in Africa." pmc.ncbi.nlm.nih.gov
  9. WHO. "Global Digital Health Certification Network." who.int
  10. WHO. "Global Digital Health Certification Network FAQs." who.int
  11. WHO. "WHO welcomes IOM into the Global Digital Health Certification Network." 26 March 2026. who.int
  12. Africa CDC HIE maturity assessment model, as described in reference 1.

References to WHO, Africa CDC, the African Union, Smart Africa, the European Union, IOM, HL7 and other organisations are made solely to cite published information and standards, and do not imply endorsement, affiliation or partnership. BulletTrain is not a participant in the Global Digital Health Certification Network; participation is reserved for WHO Member States and approved organisations.

Dr Josh Tedam

Dr Josh Tedam

DBA · EMBA · MSc · BSc

Enterprise architect and AI engineer with more than 25 years in software, solution and enterprise architecture, including 15 years as a Lead Architect in the UK National Health Service. CEO of Tedam Technologies UK Ltd. and Symphonix-Health, building open clinical interoperability infrastructure (BulletTrain, Nexus-A2A and GHARRA) across London, Dublin and Dubai.