There has been a lot of progress both in fundamentals and implementations on this front over recent years but even decades old schemes using attestations would have been a huge improvement over “dump and read data through trusted server”.
Here’s a trivial one that anyone could implement without using anything new from the past decade: Whoever stands as “trusted party” could have signing certificates distributed to the verifier-side of the app. They sign hashes of the relevant info. All data sharing needed is once per issuance of “vaccination certificate”. No persistence of PII necessary. If you don’t want to have to disclose PII as part of validation, that’s where the fancier schemes come in.
If you can’t or won’t spend resources to do it properly then yes, physical card is preferred.