Research Project · INESC-ID / IST

A Wallet for Electronic Health Records

WELL is a patient-centric platform that gives individuals sovereign control over their clinical data through blockchain-backed consent management and secure cloud storage.

Start March 2025
End January 2026
Funded by FCT · IACDC
Budget €42,679.74

Secure Health Wallet

Private keys stored securely. Every access logged on-chain. Consent managed by the patient — always.

Blockchain SSI GDPR-ready Cloud
Tamper-proof audit log
Cloud-of-clouds storage

Patients deserve control over their own data

Electronic Health Records (EHRs) contain deeply personal information, yet today their storage and sharing are entirely controlled by healthcare institutions. Patients cannot verify who accessed their data, cannot enforce consent, and cannot carry their records across different healthcare providers — public or private.

Portugal's NHS (SNS) stores records centrally via SPMS, while private institutions maintain isolated silos. GDPR grants patients rights of access and deletion, but the infrastructure to enforce them simply doesn't exist.

Self-Sovereign Identity

Patients share records without exposing unnecessary personal data — powered by Hyperledger Indy.

Immutable Audit Trail

Every access — creation, modification, consultation, deletion — is recorded on-chain and cannot be altered.

High Availability

A cloud-of-clouds architecture (RockFS) distributes records across multiple providers, ensuring resilience to outages.

GDPR Compliance

Right to Access and Right to be Forgotten are enforced by design through smart contracts and consent management.

Architecture

Two core components

01

WELL Repository

A hybrid back-end combining a cloud-of-clouds storage layer (RockFS) with a permissioned blockchain (Hyperledger Fabric). Data is secret-shared across N public clouds so that no single provider can reconstruct an EHR.

  • Cloud-of-clouds via RockFS
  • Hyperledger Fabric distributed ledger
  • Hyperledger Indy for identity
  • Tamper-proof access logging
  • Smart contract consent management
  • REST API for wallet integration
02

WELL Wallet

An Android application that puts patients in full control. The wallet securely stores private keys and interacts with the repository to access, share, and manage EHRs — from anywhere in the world.

  • Android application
  • Secure private key storage
  • EHR access and download
  • Consent and sharing controls
  • Activity log viewer
  • EHR creation (for medical staff)
People

The research team

DM

David R. Matos

Principal Investigator
Assistant Professor, IST · Researcher, INESC-ID
AR

António Rito Silva

Co-Principal Investigator
Associate Professor, IST · Researcher, INESC-ID
DC

Daniela Camarinha

MSc Researcher
MSc Student, IST
DM

Diogo Melita

MSc Researcher
MSc Student, IST
BM

Beatriz Militão

MSc Researcher
MSc Student, IST
JL

João Leite

MSc Researcher
MSc Student, IST
Research Outputs

Publications

25
NCA 2025 · IEEE

Bonsai: A Recovery Approach for Ethereum ERC-20 Transactions

Melita, D., Matos, D. R., & Pardal, M. L.
25
NCA 2025 · IEEE

Rûm: Multivalued Loss-Tolerant Byzantine Consensus for Mobile Ad-Hoc Networks

Pedro, J., Ramos, G., & Matos, D. R.
25
GoodIT 2025

Trust Through Transparency: Blockchain for Consent and Accountability in Femtech Applications

Tomaz, L., Matos, D. R., & Almeida, T.
25
Journal of Systems and Software

Assessment of performance and its scalability in microservice architectures: Systematic literature review

Rodrigues, H., Silva, A. R., & Avritzer, A.

Graduate work

MSc Thesis · 2025

Healthy Wallet: Blockchain Wallet for Electronic Health Records

Beatriz Militão · Advised by David R. Matos and Hugo Macedo
MSc Thesis · 2025

Bonsai: A Recovery Approach for Ethereum ERC-20 Transactions

Diogo Melita · Advised by David R. Matos and Miguel Pardal
Open Source

Prototypes on GitHub

WELL Wallet

Android client application for patients, medical staff, and insurers.

WELL Repository

Hybrid cloud-of-clouds + blockchain back-end storage system.

WELL Smart Contracts

Solidity / chaincode for access control and consent management.

Wallet ChainCode

Hyperledger Fabric chaincode integrated with the WELL Wallet.

Support

Funding & institutions

Funded under the call Artificial Intelligence, Data Science and Cybersecurity of relevance to Public Administration (IACDC).

Host institution: INESC-ID Lisboa — Instituto de Engenharia de Sistemas e Computadores, Investigação e Desenvolvimento em Lisboa.
€42,679
Total project budget
Grant ID 2024.07494.IACDC
Principal Investigator David R. Matos
Host Institution INESC-ID, Universidade de Lisboa — IST
Duration 01 Mar 2025 → 31 Jan 2026
Thematic Area Cybersecurity