Federated Threshold Key Custody for Blockchain-Based Electronic Health Records: A Patient-Centric Approach to DPDP 2023 Compliance
Federated Threshold Key Custody for Blockchain-Based Electronic Health Records: A Patient-Centric Approach to DPDP 2023 Compliance
Aditya Nair, Kaustubh Bagale, Mitali Parulekar, Jignesh Sisodia, Kailas K. Devadkar
Department of Computer Science and Engineering & Data Science Sardar Patel Institute of Technology
Email: {aditya.nair22, kaustubh.bagale22, mitali.parulekar22, jsisodia, kailas devadkar}@spit.ac.in
Abstract—This paper is a proof of concept for a decentralized Electronic Health Record (EHR) that is compliant with India’s Digital Personal Data Protection (DPDP) Act, 2023. The main goal of the paper is to observe the “Right to be Forgotten” while maintaining the data sovereignty. The proposed model encrypts the records with AES-256 Encryption and achieves federated key architecture with Shamir’s Secret Sharing Algorithm. The health records are stored encrypted in an IPFS system and the encryption keys are split into 5 shards (3-of-5 threshold) and distributed among system, hospital, insurance, government and patient custodians. Ethereum smart contracts handle dele-tion, verification, key recovery and access control. This design enables encrypted data deletion by destroying key shards while maintaining patient data secure and decentralized.
Index Terms—Electronic Health Records, Blockchain, Thresh-old Cryptography, Shamir’s Secret Sharing, DPDP 2023, Patient Sovereignty, Smart Contracts, IPFS, Right to be Forgotten, Federated Key Custody, Healthcare Privacy, Ayushman Bharat Digital Mission