dHealth Protocol Paper: From Draft to Version 1
- eHealth Consulting

- Jul 17
- 6 min read

For the past year, the dHealth Protocol Paper was a living draft. Version 0.x meant: the ideas were there, but the details could still change. That phase is now over. Version 1 describes the protocol as it is. The rules are set. The numbers add up. We are ready to stand behind them.
This post explains the biggest changes. In short, joining is now simpler, the DHP token has a clearer job, and the Health Memory is now the heart of the protocol.
Joining no longer requires tokens
In the early drafts, everyone had to lock DHP tokens to join. Individuals, organisations, and machines each had their own amount.
Version 1 removes this. You no longer need to buy, lock, or hold any DHP to participate. Instead, you pay a small one-time fee when you join:
Individual: 1 USD
AI agent or robot: 0.50 USD
Organisation: 100 USD
The fee is set in US dollars, so the price stays predictable. It is paid in SOL, at an exchange rate set by community vote. The community can also change the fees at any time through voting.
Why did we change this? Two reasons. First, a patient should not need to buy a crypto token to control their own health data. That was wrong in principle. Second, it made the role of DHP unclear. A token that everyone must buy to enter is a toll. A token that stands behind real responsibility is infrastructure. We chose infrastructure.
One rule stays strict: you need a dHealth identity credential to participate. A normal Solana wallet is not enough. A wallet only proves that you control an address. It does not prove who you are, or what you are allowed to do. When you join, you receive a credential. It states your class: individual, organisation, agent, or robot. Individuals are also verified as real humans. Without a credential, you cannot act in the protocol. The fee is simply the price of this entry. And it is low enough that a sponsor, for example a hospital or a study, can easily pay it for a whole group of patients.
What DHP does now
DHP now has three clear jobs:
Responsibility capital. Locking DHP is needed for the actions that carry real weight: registering a Health Memory, becoming a trusted issuer, and backing important attestations with a bond. If such an actor cheats, the bond can be taken away. Nobody is forced to hold DHP. But those who want the network's trust must back it with capital.
Governance. DHP holders vote on everything: fees, deposit levels, upgrades, treasury spending, and the Community Fund. Only DHP on Solana can vote. Wrapped versions on other chains cannot.
The Community Fund. Every credential and every attestation costs a fee in SOL. The issuer pays the same amount again on top. This second amount is used to buy DHP on the open market, and that DHP goes into the Community Fund. So the more the protocol is used, the more DHP is bought. The community votes on whether to spend the fund on growth or burn it to reduce supply forever.
The two main applications
Two applications carry most of the protocol's daily use.
Mandate credentials. Every automated system in healthcare must one day answer a simple question: who allowed you to do that? A mandate credential is the answer. It is a digital permission that states: who may act, for whom, which actions, for how long, and under which limits. It can be cancelled at any moment, in one transaction. Anyone can verify it.
This matters most for machines. In the dHealth Protocol, an AI agent or a care robot never acts on its own authority. It always acts under a mandate given by a responsible human or institution. Every action it takes points back to that mandate. Cancel the mandate, and the machine's authority ends immediately. Software agents will do more and more work for us. Mandate credentials make sure that the responsibility always stays with people.
QR-code attestations. These solve another important question: how does a patient know that their AI assistant is set up the way their doctor intended?
It works like this. A doctor writes the instructions (the system prompt) for a patient's AI companion. The protocol creates a digital fingerprint of these instructions and stores it on the blockchain. The patient scans a QR code to open the AI. At any time, the AI's instructions can be compared with the stored fingerprint. If they match, the setup is exactly what the doctor approved. If they do not match, something was changed, and the change is visible.
Nobody sees any private data in this process. But the patient, the sponsor, an auditor, or a regulator can all verify the setup independently. It also supports an important point: the doctor is configuring a general tool as part of medical practice. The doctor is not building a new medical device.
The Health Memory: back to the original idea
dHealth started with one conviction, long before AI agents existed: people should own their health data. Not a copy. Not a login to someone else's database. The data itself. Version 1 finally makes this real. The Health Memory is the most important part of the paper.
A Health Memory is a personal, encrypted record of your health, built up over time. It is the one thing that stays constant in modern care. AI models get replaced. Devices get replaced. Doctors change. With AI agents, this change only gets faster. The memory stays with you.
The design rests on three rules:
The content stays off the blockchain. Your memory is encrypted on your own device before it goes anywhere. It is stored where you, or your sponsor, choose. The blockchain only stores fingerprints: from time to time, a fingerprint of your memory is saved on-chain. With it, anyone you allow can check that they see the true, unchanged version.
Nobody has access by default. No app, no AI agent, no robot can open your memory on its own. Not even the systems of your own doctor. Access works only through a mandate: limited in scope, limited in time, and cancellable at any moment. When the mandate ends, the door closes, and the other side keeps nothing.
Deletion is real. If you delete your memory, the encryption keys are destroyed. Every copy of the data becomes unreadable forever, wherever it is stored.
This is what data ownership means in the age of agents. Your agent reads your memory because you allowed it. Your clinic's agent reads it because you allowed it. When you cancel, the access ends, and the fingerprints on the blockchain prove that nobody changed your record along the way.
Creating a memory requires a DHP deposit. This is the clearest example of DHP as responsibility capital. The deposit starts at 10,000 DHP while the network is young. It halves as the network grows, step by step, down to a minimum of 20 DHP. Early memories carry a high bond because few others secure the network yet. A mature network asks much less. The deposit always stays your property, and you can always take it back.
Inflation with a purpose
Version 1 also answers what the 2% yearly inflation is for. Each quarter, new DHP is created. It is used first to pay Health Memory deposit holders a cost compensation: 2% per year on their locked deposit. This is a flat-rate contribution toward the storage rent they pay for their memory. It only counts for days on which the memory is properly bonded and in real use. An inactive memory earns nothing. This is not passive income.
Everything that remains goes into the Community Fund. The numbers always work out: deposits are always
smaller than total supply, and the compensation rate equals the inflation rate, so the payments can never exceed the new DHP. In the beginning, most new DHP goes to the fund, and the community can keep effective inflation near zero by burning it. As more DHP gets locked behind active memories, the share paid as compensation grows. Every new DHP either supports a memory in real use or falls under community control.
What version 1 means
A living draft is permission to stay vague. Version 1 ends that permission. The protocol now says clearly what it asks of participants: a credential and one dollar. What it asks of DHP: responsibility and governance, nothing else. And what it protects: your health, memory, verifiable and truly yours, in a world where software acts on our behalf more every day.
The parameters can still be changed by vote. The direction cannot.
The full Protocol Paper version 1 is available.


Comments