Med-Chain: A Privacy-Preserving Blockchain–Cloud Hybrid Framework for Secure Healthcare Data Validation Using zk-SNARKs
Abstract
Electronic Health Records (EHRs) demand simultaneous guarantees of confidentiality, verifiable integrity, patient-controlled access, and regulatory auditability — guarantees that neither centralised cloud storage nor fully on-chain blockchain systems can jointly provide. Cloud platforms concentrate trust and deny patients verifiable audit; blockchains cannot economically hold bulk medical data, and their transparency leaks patient–provider interaction patterns. Hybrid architectures anchor off-chain data to the ledger by hash, but every substantive validation of record content still requires disclosure to the verifier. This paper proposes Med-Chain, a privacy-preserving blockchain–cloud hybrid framework in which the validity of healthcare data is established by zero-knowledge Succinct Non-interactive ARguments of Knowledge (zk-SNARKs) rather than by disclosure. Encrypted records reside in cloud object storage and IPFS; hiding Poseidon commitments, consent policies, and constant-size Groth16 proofs are anchored and verified on a permissioned EVM ledger by a five-contract Solidity suite. Four validation predicates — record integrity, ownership, range eligibility, and code-set membership — are realised as Circom circuits and verified on-chain through auto-generated verifier contracts bound to one-time nonces. A prototype implementation is evaluated for proving time, verification gas, latency, throughput, and storage overhead, demonstrating sub-second proof generation on commodity hardware, ~128-byte proofs, and record-size-independent verification cost of approximately 215k gas†. A structured security analysis reduces confidentiality, integrity, soundness, and replay-resistance to standard assumptions. Med-Chain thus offers predicate-level validation of medical data with zero disclosure across the complete EHR lifecycle, aligning naturally with HIPAA, GDPR, and India’s DPDP Act, 2023.