Related Experiment Videos
A Blockchain-Based Architecture for Dynamic and Auditable Patient Consent in Secondary Use of Health Data
Sudip Phuyal1, Manila Bhandari1, Rabindra Bista2
1Information Sciences, Technology and Architecture Research Center (ISTAR-ISCTE), University Institute of Lisbon, Lisbon, Portugal.
Background:
The secondary use of patient health data is critical for advancing clinical research, public health, and digital health innovation. However, traditional consent mechanisms are often static, complex, and insufficiently transparent, limiting patient control and trust. In response to regulatory requirements introduced by the General Data Protection Regulation (GDPR) and the European Health Data Space (EHDS), this article paper aims to design a secure, transparent, and revocable blockchain-based architecture for managing patient consent for the secondary use of health data, aligned with European legal frameworks and interoperability standards.
Methods:
A multilayered consent management architecture was designed by integrating blockchain smart contracts, decentralized identifiers, verifiable credentials, and Health Level Seven-Fast Healthcare Interoperability Resources. The system incorporates a patient-controlled digital wallet, off-chain health data storage, and on-chain enforcement of consent policies through smart contracts. Regulatory and technical requirements were systematically derived from GDPR and European Health EHDS provisions. The study follows a design science research methodology and includes threat modeling and a theoretical performance and scalability analysis. The design is guided by four core objectives: dynamic consent management, auditable governance, interoperability with healthcare standards, and compliance-by-design with European regulatory frameworks.
Results:
The proposed architecture enables secure creation, delegation, and revocation of patient consent through immutable blockchain-based logging and Fast Healthcare Interoperability Resources-compliant data exchange. Consent records are tamper-evident, while sensitive health data remain off-chain, ensuring data minimization and privacy protection. Consent attributes such as purpose limitation, duration, and data scope are explicitly modeled to comply with GDPR and EHDS requirements. Theoretical evaluation indicates that the architecture can scale to large healthcare data ecosystems when deployed on Ethereum-compatible blockchains combined with external storage solutions.
Conclusions:
This study presents a modular, standards-based consent management framework that enhances patient autonomy, supports regulatory compliance, and strengthens governance for the secondary use of health data. By combining blockchain, digital identity, and healthcare interoperability standards, the architecture addresses key legal and technical challenges of dynamic consent. Future work will focus on developing a user-centered prototype and conducting empirical validation in real-world secondary-use health data ecosystems.
Related Concept Videos
Issues And Trends In Healthcare Delivery System
Cost Containment
Payment for healthcare services has historically promoted adoption of costly and often unnecessary or inefficient...
Ethical Standards I
The Code of Ethics provisions outline the nurse's duty to the patient, the healthcare team, the profession, and society. The Code's fundamental principles include advocacy,...
Ethical Standards II
Nurses are entrusted with upholding various ethical principles and standards. Nurses forge solid therapeutic relationships using trust, empathy, autonomy, confidentiality, and professional competence.
Confidentiality is crucial, embodying respect for individual privacy and...
Standards of Care II
Legal Guidelines for Documentation
Purpose of Health Records II