Internet Explorer 11 is not supported

For optimal browsing, we recommend Chrome, Firefox or Safari browsers.

Vaccine Passports: Here’s How Excelsior Pass Works

Though the idea of vaccine passports has attracted criticism, the state of New York has taken the plunge as the first state in the U.S. to create one, saying it will help facilitate economic activity. Here’s how it works.

A person presenting a vaccine passport at an airport
<a href="https://www.shutterstock.com/image-photo/indian-passenger-wearing-protective-face-mask-1943749672" target="_blank">Shutterstock/Rido</a>
The president said he’d leave it up to states to figure it out. Republican governors said they would never consider it. And now, New York is the first state to actually make one.

The U.S. has its first official vaccine passport.

New York’s Excelsior Pass, developed by IBM, is essentially a simple digital wallet that can be accessed on mobile devices, which holds three items: your name, a QR code and a green check mark.

The idea is that people can use the app to prove to somebody — say, a ticket-taker at the door of a sports stadium, an airline or the staff at a large event — that they’ve received a vaccine against COVID-19. In actuality, the app can also prove that somebody’s received a negative test for the disease.

“It’s all about trust, right?” said Tim Paydos, global general manager of government for IBM. “If people are right now reluctant to go watch a Rangers game in New York City, maybe it’ll make them feel safer to know that, OK, not only are they practicing social distancing and all that within the stadium, they’re also checking to make sure that someone’s been tested or vaccinated.”

So far, Paydos said, the app has been downloaded hundreds of thousands of times.

Criticism of Vaccine Passports

There’s no mandate that anybody use the app. Rather, the state has released it as a way to reduce risk in social gatherings. The same thing could be accomplished with the paper cards people receive when they get a vaccine, though the FBI recently warned that the market for fake vaccination cards has already materialized.

Still, the idea of vaccine passports has prompted backlash from many. Republicans, who have said in public opinion surveys that they’re less likely to get the vaccine than the rest of the country, have largely rejected the idea. Civil rights advocates such as the Electronic Frontier Foundation (EFF) have also spoken out against vaccine passports, pointing that inequities in vaccine distribution have meant that racial minorities are less likely to have received their first dose than white Americans.

Alexis Hancock and Hayley Tsukayama with EFF also pointed out that the involvement of blockchain in vaccine passports — a feature of Excelsior Pass — will necessarily create a system where data that’s useful for proving vaccination in the current day will be preserved indefinitely. Creating widespread vaccine passports could, they argue, be a step toward a future where the government maintains digital IDs for everyone and uses them to collect and store personal information.

While Excelsior Pass, and likely other vaccine passports, don’t come with a government mandate, they will enable organizers and proprietors to set mandates for their own particular establishments.

“Resources, especially tax dollars, should be focused on giving people more information about and access to vaccinations, rather than creating a digital fence against those who haven’t been vaccinated yet — and subjecting people who have been vaccinated to new privacy risks,” they wrote in a blog post.

Paydos said it’s not IBM’s place to address those concerns.

“I’ll leave the policies around the use of this to the policymakers,” he said. “IBM is a technology company, and we’re committed to serving the citizens and society in the safest, most secure way that we know how.”

How Excelsior Pass Works

From the standpoint of a person using Excelsior Pass, the process is relatively simple: Put in your information, answer some basic questions to verify your identity and you’ll have your pass. To prove you’ve been vaccinated, either show somebody the app or let them scan the QR code.

Behind the scenes, what the app is doing is connecting with some kind of credentialed health authority — a state agency, a hospital, another health provider — who can verify that you’ve been vaccinated. The first time you use the app, it will send those three items (your name, QR code and green check mark) to your mobile device, where it will be available regardless of whether you have service. Once a month, it will ping the health authority again to re-verify. For tests, the information times out after 72 hours.

Should a person scan the QR code, the app will ping the health authority to verify the authenticity of the information.

IBM purposefully didn’t build a centralized database for Excelsior Pass in order to avoid creating a giant target for hackers.

“All of the data stays distributed,” Paydos said. “We’re not creating a big intergalactic database in the sky. We wouldn’t want to do that, nor given the time urgency could we do that.”

The app was built using open source standards, which IBM hopes will mean it’s interoperable across states, apps, health providers and even countries. So a person who lives in Connecticut who drives to New York City to go to a Rangers game would be able to use New York’s Excelsior Pass to show that they’ve been vaccinated.

The app was actually based on work IBM did with Maersk on shipping containers moving across the world, and Paydos said it should work for travelers moving between nations as well.

“Having this open, available, secure and safe platform will enable countries in Europe and the EU to communicate with each other,” he said. “They want interoperability so people can travel around Europe, but then when folks want to come over to the United States or go to Australia, as long as everyone’s on the same standard and we have interoperability, we’ll be able to do this validation process across the globe.”


Government Technology is a sister site to Governing. Both are divisions of e.Republic.

Government Technology is Governing's sister e.Republic publication, offering in-depth coverage of IT case studies, emerging technologies and the implications of digital technology on the policies and management of public sector organizations.
Special Projects
Sponsored Stories
Sponsored
In recent years, local governments have been forced to adapt to a wildly changing world, especially as it pertains to sending bills and collecting payments.
Sponsored
Workplace safety is in the spotlight as government leaders adapt to a prolonged pandemic.
Sponsored
While government employees, students and the general public had to wait in line for hours in the beginning of the pandemic, at-home test kits make it easy to diagnose for the novel coronavirus in less than 30 minutes.
Sponsored
Governments around the nation are working to design the best vaccine policies that keep both their employees and their residents safe. Although the latest data shows a variety of polarizing perspectives, there are clear emerging best practices that leading governments are following to put trust first: creating policies that are flexible and provide a range of options, and being in tune with the needs and sentiments of their employees so that they are able to be dynamic and accommodate the rapidly changing situation.
Sponsored
Service delivery and the individual experience within health and human services (HHS) is often very siloed and fragmented.
Sponsored
In this episode, Marianne Steger explains why health care for Pre-Medicare retirees and active employees just got easier.
Sponsored
Government organizations around the world are experiencing the consequences of plagiarism firsthand. A simple mistake can lead to loss of reputation, loss of trust and even lawsuits. It’s important to avoid plagiarism at all costs, and government organizations are held to a particularly high standard. Fortunately, technological solutions such as iThenticate allow government organizations to avoid instances of text plagiarism in an efficient manner.
Sponsored
Creating meaningful citizen experiences in a post-COVID world requires embracing digital initiatives like secure and ethical data sharing, artificial intelligence and more.
Sponsored
GHD identified four themes critical for municipalities to address to reach net-zero by 2050. Will you be ready?