Related Experiment Video
Updated: Jun 26, 2026

TBase - an Integrated Electronic Health Record and Research Database for Kidney Transplant Recipients
Published on: April 13, 2021
Development of the authentication and authorization processes for the iAgree portal, a platform for
Spencer L Soohoo1,2, Michelle Sophie Keller3,4, Yunan Chen5
1Enterprise Information Systems, Cedars-Sinai Medical Center, Los Angeles, CA, 90048, United States.
Objective:
To develop the authentication and authorization module for iAgree, a privacy-preserving platform that enables patients to manage consent preferences and share electronic health record (EHR) data across multiple health systems with researchers. The consent and blockchain modules are described elsewhere.
Materials And Methods:
We developed the authentication and authorization module of iAgree. This module supports account creation and cross-institution identity binding as part of the iAgree workflow to enable patients to authenticate using federated credentials (eg, Google, Facebook). Patients link their identities across institutions by signing into each participating health system's patient portal. Identity attributes retrieved via a Fast Healthcare Interoperability Resources (FHIR®) application programming interface (API) are cryptographically transformed into de-identified tokens so no raw identifiers are stored. Consent preferences are recorded immutably using blockchain technology. iAgree guides patients through account creation, cross-institution identity binding, and selection of granular data-sharing preferences. In this paper, we describe the design and implementation of the authentication and authorization modules, not the full workflow of the platform.
Results:
We installed the iAgree platform in a test or proof-of-concept environment at three health systems: Cedars-Sinai Medical Center, University of Colorado, and University of California, San Francisco. Functional testing with test patients demonstrated that authentication, identity binding, and secure multi-site record linkage could safely bind the identities of patients across sites, enabling patients to manage their data sharing consent preferences.
Discussion:
The results demonstrate the feasibility of a privacy-preserving multi-institutional data-sharing architecture that employs federated login, secure privacy-preserving multi-site record linkage, and blockchain-based consent tracking to align with privacy regulations while increasing transparency and patient autonomy.
Conclusion:
This effort demonstrated that the authentication and authorization module enables iAgree to be a feasible and secure platform for patient-directed sharing of EHR data across health systems with researchers. Future work will evaluate usability, patient engagement, and future real-world deployment.
Related Concept Videos
Legal Guidelines for Documentation
Integrated Healthcare System
Ethical Standards I
The Code of Ethics provisions outline the nurse's duty to the patient, the healthcare team, the profession, and society. The Code's fundamental principles include advocacy,...
Standards of Care II
Issues And Trends In Healthcare Delivery System
Cost Containment
Payment for healthcare services has historically promoted adoption of costly and often unnecessary or inefficient...
Health Information Technology and Healthcare Information System
Health Information Technology, commonly called HIT, integrates advanced information systems and technology in healthcare settings. Its primary functions include:
