3 ms·
blockchain would allow: - trustless cloud-based indexed storage of encrypted data using protocols such as IPFS - logging of data access requests to a global
by noddy1 9y ago
blockchain would allow:
- trustless cloud-based indexed storage of encrypted data using protocols such as IPFS
- logging of data access requests to a globally accessible database and ability to give and remove permissions based on timestamps
- auditing of data accessors to ensure that their access patterns match their functions - eg. if a hospital suddenly starts trying to download data on a million patients instead of 300 then this would be visible on the blockchain and individuals could then question why this is occurring and prevent access.
All of these things can be done with trusted intermediaries, but when you start considering use cases such as - being in china and needing to allow a chinese hospital to access your records back in the USA, suddenly these things become important.
- acdha 9y agoThat’s a lot of buzzwords but it fails to answer how any of it would work, why you’d want that, or why it’s better than mature alternatives. For example, how are you defining trustless? Personal data systems needs to be based on trust and reputation (otherwise you’ll have a bunch of 4chaners spamming claims about you) so are you simply thinking tamper-evidence and non-repudiation? That’d raise the questions of why this would be better than PKI, Merkel trees, etc. All of the other claims hit similar problems: e.g. you can’t store the data in a blockchain and make any of those promises, and it’s not clear how useful a shared index or log would be when you can’t trust all of the participants. Another fatal flaw is the lost of control and inability to correct mistakes. If there’s ever a vulnerability all of that data is irrecoverably public. What organization is going to turn control of something they get sued for over to an entity they don’t control? “They told us the software was perfect” doesn’t seem like a good HIPAA defense tactic to me.