A Blockchain-Based Role-Based Access Control Gateway for Secure Electronic Health Record Access and Tamper-Evident Auditing
Abstract
Electronic Health Record (EHR) systems store sensitive patient information and require strong access control and reliable audit records. Traditional centralized Role-Based Access Control (RBAC) systems may be vulnerable to unauthorized access, privilege escalation, audit-log modification, and undetected changes to stored records. This study developed a lightweight blockchain-based RBAC gateway integrated with OpenMRS. The system used three roles, Admin, Doctor, and Patient, and one Solidity smart contract to manage role assignments, Doctor–Patient permissions, access decisions, trusted record hashes, and blockchain audit events. A Node.js gateway acted as the policy-enforcement point, while SQLite was used as a centralized audit-log baseline. The system was evaluated through authorized-access, unauthorized-access, privilege-escalation, audit-log tampering, EHR data-tampering, gas-use, and throughput experiments. All 50 measured authorized requests were allowed and completed the expected OpenMRS retrieval workflow, while all 50 unauthorized-access attempts were blocked before reaching OpenMRS. The SQLite decision could be changed from deny to allow, while the corresponding blockchain event remained unchanged. The trusted-hash experiment detected all 10 simulated EHR modifications. Median end-to-end latency was 31.8 ms for denied requests and 468.9 ms for authorized requests. Sequential smart contract throughput averaged 15.0850 TPS for authorized access and 15.4214 TPS for unauthorized access. These findings show that the proposed gateway can improve access-control enforcement, detect off-chain record changes, and provide tamper-evident audit evidence without storing full EHR records on-chain.