Health-data integrity and consent architecture advisory
Delivered an audit-ready blockchain architecture for tamper-evident patient records and consent, cleared against HIPAA and GDPR before build.
Audit-ready design
Problem, approach, and the outcome
The client operates a clinical-grade heart-monitoring platform that streams continuous patient data to clinicians and care teams. Trust in the integrity of that data, and in who is permitted to see it, is fundamental to how the platform is used in care.
They wanted a blockchain architecture that could make patient records tamper-evident and put consent on a verifiable footing, but only if it could stand up to a regulator's inspection.
Patient records and consent decisions needed to be provably tamper-evident, yet the platform had no design that reconciled on-chain integrity guarantees with the strict data-minimisation and right-to-erasure obligations of health regulation. Putting clinical data on-chain naively would have created more compliance risk than it solved.
Consent was the harder problem: it changes over time, and the architecture had to honour withdrawal without ever exposing personal data on an immutable ledger. Getting this wrong is a regulatory incident, not a bug.
The platform needed a design that its own compliance function, and an external auditor, could sign off before a line of production code was written. Inspection-readiness was the bar.
We designed an architecture that keeps personal health data off-chain and anchors only tamper-evidence proofs and consent state on-chain, so integrity is guaranteed without putting patient data on an immutable ledger. That separation is what makes the design compliant by construction.
We modelled consent with decentralised identifiers, so a patient can grant and withdraw access verifiably, and the ledger never holds anything that erasure obligations would require removing. Consent shaped the architecture rather than being bolted on.
We ran a security and compliance review across the design, mapping it against HIPAA and GDPR and documenting the controls, so the platform entered build with an audit-ready blueprint. The reasoning was written down for the inspector, not just the engineer.
- Audit-ready architecture cleared against HIPAA and GDPR
- Personal data kept off-chain, only proofs anchored on-chain
- Consent modelled with DIDs, honouring withdrawal and erasure
- Security and compliance risks resolved before build
More Blockchain case studies

Verifiable-credential feasibility study for a workforce platform
Scoped a focused credentialing pilot over a full rebuild, narrowing the programme 60% for a workforce management platform.
Read the full case study
Stablecoin settlement strategy for a finance SaaS
Delivered a reference architecture and a three-chain shortlist for embedding stablecoin settlement into a SaaS finance platform's cash-flow workflows.
Read the full case study
Real-estate tokenisation and tokenomics advisory
Delivered a fractional real-estate tokenisation model with an ERC-3643 compliance blueprint for regulated investor onboarding.
Read the full case studyGet a senior architect on the call, first time, every time.
No SDR gauntlet. 30 minutes with an engineer who can scope the problem, name the risks, and give you an honest feasibility call.
