The healthcare sector increasingly relies on digital infrastructures to manage large volumes of sensitive medical data. Ensuring integrity, controlled access, interoperability, and auditability remains a fundamental challenge. We propose BlockHealth, a hybrid blockchain-based framework that integrates smart contracts, distributed databases, and proxy re-encryption to support secure and verifiable healthcare data management. The system leverages Ethereum and NFT-based identities for access control, Merkle-tree commitment for tamper-evident integrity verification, and a distributed Cassandra storage layer for scalable and regulation-compliant off-chain data management. Proxy re-encryption enables secure delegation of access without exposing private keys, while a coordinating API service ensures interoperability with existing hospital infrastructures. Our evaluation demonstrates the feasibility and efficiency of core operations — including hashing, on-chain commits, and re-encryption — indicating that the proposed framework can provide a practical balance among verifiability, performance, and deployability in realistic healthcare environments.

BlockHealth: a Blockchain based Framework for Secure and Efficient Healthcare Data Management / C. Braghin, S. Cimato, S. Pesci, E. Riccobene. - In: BLOCKCHAIN: RESEARCH AND APPLICATIONS. - ISSN 2096-7209. - (2026). [Epub ahead of print] [10.1016/j.bcra.2026.100468]

BlockHealth: a Blockchain based Framework for Secure and Efficient Healthcare Data Management

C. Braghin
Primo
;
S. Cimato
Secondo
;
S. Pesci
Penultimo
;
E. Riccobene
Ultimo
2026

Abstract

The healthcare sector increasingly relies on digital infrastructures to manage large volumes of sensitive medical data. Ensuring integrity, controlled access, interoperability, and auditability remains a fundamental challenge. We propose BlockHealth, a hybrid blockchain-based framework that integrates smart contracts, distributed databases, and proxy re-encryption to support secure and verifiable healthcare data management. The system leverages Ethereum and NFT-based identities for access control, Merkle-tree commitment for tamper-evident integrity verification, and a distributed Cassandra storage layer for scalable and regulation-compliant off-chain data management. Proxy re-encryption enables secure delegation of access without exposing private keys, while a coordinating API service ensures interoperability with existing hospital infrastructures. Our evaluation demonstrates the feasibility and efficiency of core operations — including hashing, on-chain commits, and re-encryption — indicating that the proposed framework can provide a practical balance among verifiability, performance, and deployability in realistic healthcare environments.
Blockchain; Healthcare Data Management; Identity Management; Non-Fungible Tokens (NFTs); Merkle Trees; Proxy Re-Encryption; Apache Cassandra; Data Privacy; Ethereum; Smart Contracts;
Settore INFO-01/A - Informatica
   SEcurity and RIghts in the CyberSpace (SERICS)
   SERICS
   MINISTERO DELL'UNIVERSITA' E DELLA RICERCA
   codice identificativo PE00000014

   SAFEST: Trust assurance of Digital Twins for medical cyber-physical systems
   SAFEST
   MINISTERO DELL'UNIVERSITA' E DELLA RICERCA
   20224AJBLJ_002
2026
10-mar-2026
Article (author)
File in questo prodotto:
File Dimensione Formato  
1-s2.0-S2096720926000308-main.pdf

accesso aperto

Tipologia: Post-print, accepted manuscript ecc. (versione accettata dall'editore)
Licenza: Creative commons
Dimensione 1.61 MB
Formato Adobe PDF
1.61 MB Adobe PDF Visualizza/Apri
Pubblicazioni consigliate

I documenti in IRIS sono protetti da copyright e tutti i diritti sono riservati, salvo diversa indicazione.

Utilizza questo identificativo per citare o creare un link a questo documento: https://hdl.handle.net/2434/1234157
Citazioni
  • ???jsp.display-item.citation.pmc??? ND
  • Scopus ND
  • ???jsp.display-item.citation.isi??? ND
  • OpenAlex 0
social impact