Implementation of Privacy-Preserving Identifiers for the Secure Storage of Electronic Health Records on the Ethereum Blockchain

Swati Kumari, Hitesh Tewari · Distributed Ledger Technologies Research and Practice · 2025

Patients and healthcare authorities frequently lack confidence in one another when it comes to the security of their medical records in healthcare settings. Particularly when it comes to patient data management, hospitals are infamous for having inadequate security and have long been the target of cyberattacks. Using blockchain technology to store medical records has drawbacks, including an excessive dependence on centralised cloud servers for key storage, privacy concerns and the potential for attackers to deduce personal information about patients based on their blockchain activity. A system where patients have autonomy over their medical records and who can view them is a promising scenario. This article provides a framework for indexing and securing a user’s medical records, with emphasis placed on the healthcare setting using an Ethereum blockchain. The records are secured using biometric authentication and the patient’s Personal Identifiable Information (PII). The patient can grant and revoke access to their records to individual healthcare authorities, and the Interplanetary Name System (IPNS) is used for off-chain record storage. The framework is modular and can be adapted for use in other environments, such as proof of ownership of tickets, and storing travel documents for verification by border control. A smart contract is used to store the hashes of the patient’s iris scans on an Ethereum Virtual Machine (EVM) compatible blockchain. Privacy-preserving identifiers are used to anonymise the patient and where their records are stored on the blockchain. Our approach is to the best of our knowledge the only one that simultaneously offers encryption, anonymity, unlinkability and efficient off-chain storage. Additionally, our approach is the only approach we are aware of that provides record revocability.

Read the paper · More papers on PaperTik