healthkit digital signature

I want to verify whether the healthkit data is tampered.
Found this article

But it seems that nobody on the internet is talking about this. I want to know the workflow needed to use this feature.
Should I store a list of trusted public keys?
How can I get the signature and public from the metadata?

Anyone with experience on this topic, please share!