The Last Line of Defense.
A centralised EHR is a hacker’s honeypot and a single point of failure. WaveMed distributes data to the patient — offline and encrypted — and gives the nation the iSAVE™ sovereign cloud. There is no central target left to steal.
Why now — the AI inflection point
- In September 2025 the first fully autonomous AI-orchestrated attack was confirmed (AI performed 80–90% of it).
- Once an attack starts, response is too late — only a pre-positioned architecture limits the damage.
- Romania, Feb 2024: 100+ hospitals paralysed by one infected shared platform, back to pen and paper, five days to recover. Lesson: “you survive by going offline.”
The WaveMed inversion — five architectural choices
Decentralised
Data with the patient. RadCard 8–64 GB USB+NFC, RadPatch passive NFC. No central DB.
Offline first
MicroEHR and DICOM auto-run from the card, no install, no network. RadPatch phone tap.
Edge encryption
AES-256 · WMSD format · provisioned tags only · PIN editing.
No honeypot
No jackpot to ransom, no single system to paralyse. Nothing for the AI to find.
Patient-owned
Ownership is the security architecture. Records stay available whether or not the institution is up.
iSAVE™ sovereign layer
Personal records with the patient (PIN); aggregate national data on in-country sovereign infrastructure — not a foreign cloud.
Three steps for governments and institutions
- Pilot — measure offline availability, misidentification reduction and continuity of care under network loss.
- iSAVE sovereign instance — build with governance separated between patient-owned records and aggregate national data.
- Population roll-out — phase RadCard/RadPatch through providers, clinics and government channels.




