Skip to main content
Have a personal or library account? Click to login
Privacy-Aware and Scalable Blockchain Solutions in Healthcare: Emerging Directions Cover

Privacy-Aware and Scalable Blockchain Solutions in Healthcare: Emerging Directions

By:  and    
Open Access
|Jun 2026

Full Article

1
Introduction

Medical data are very sensitive, as they include personal information about individuals, medical conditions, and treatment. If IoMT solutions or electronic health records (EHRs) are breached, the effects are beyond the financial loss, as the healthcare data is very critical [1]. Unauthorized access, incorrect data interpretation, or delayed clinical decisions may lead to patient harm, inappropriate treatment, and erosion of trust in healthcare systems. The HIPAA (Health Insurance Portability and Accountability Act) and GDPR (General Data Protection Regulation) are examples of international rules that were put in place to protect patient privacy [2]. Today’s healthcare systems rely mostly on data sharing among different medical research institutions, hospitals, research labs, and telemedicine platforms as we are in the era of smart healthcare systems. The traditional centralized design cannot provide interoperability and Privacy both to the healthcare data [3].

To address this gap, blockchain is proposed as a framework that enables verifiable access and tamper-resistant audit trails, while mitigating risks associated with centralized system architectures without depending on a single authority. Healthcare Blockchain has properties such as distributed consensus, immutability, and transparent auditing [4]. Despite much research and pilot deployments, most implementations remain limited in scope. This is because researchers often ignore the most important features, like being able to handle a lot of clinical data, working with standards like HL7, FHIR, and DICOM, and using privacy-preserving cryptography that is necessary for compliance with regulations [5]. The current solutions provide immutability alone.

The integration of emerging technologies with blockchain has begun to address several of these limitations in real-world healthcare systems, these technologies can achieve what the traditional systems were lacking. As an example, Federated learning using blockchain systems. This allows AI models to co-learn and protect patient information in the hospital that develops it [6, 7]. The creation of the crosschain interoperability systems is another milestone since it allows the network to be interoperable in licensed under the Creative Commons Attribution-NonCommercial-ShareAlike 4.0 a way that sharing electronic health records (EHR) between hospitals is simple even across countries. Ring Signatures and zero-knowledge proofs are used to secure medically related transactions and ensure patient consent [8].

Numerous new ideas are not experimented with to find out whether they are effective, beneficial, and practical or not. This paper will concentrate on research on blockchain in healthcare between January 2019 and August 2025, utilizing the different types of methods to address the existing gaps. Our PRISMA-based search identified 94 peer-reviewed Scopus, IEEE Xplore, ACM, Springer, Elsevier, and the Web of Science studies. Unlike previous surveys that focused narrowly on topics such as security or immutability, our review looks more broadly at emerging trends in privacy, scalability, interoperability, and advanced cryptography. The new emerging innovations include blockchain-assisted federated learning [9], cross-chain frameworks [10], and advanced cryptographic techniques like zero-knowledge proofs [11, 12], these are beginning to shape the current research discussions.

Figure 1 shows the conceptual framework of the review of existing literature concerning blockchain based smart healthcare systems. This is based on the previous literature on healthcare blockchain, federated learning and cryptographic privacy technologies. It is this high-level conceptual synthesis which inspires the need to look at solutions in an integrated way although further figures in the research paper give further detailed taxonomies and comparative analysis. The healthcare issues depicted in the first layer, such as privacy leakage, interoperability issues, scaling issues, and decentralization, are rampantly reported in extant surveys and system studies etc. The intermediate layer draws attention to fundamental blockchain features including decentralized trust and unalterable auditability, as mentioned in [13, 14]. The recent research complements this by noting that blockchain is not sufficient to scale to the healthcare level, which prompts integrating the emerging technologies, including federated learning, cross-chain interoperability, zero-knowledge proofs, ring signature and privacy-preserving consensus mechanisms, discussed in [15, 16].

Figure 1.

The major key challenges, blockchain-enabled opportunities, and emerging privacy-preserving and scalability-enhancing technologies in smart healthcare systems

This research work covers 4 major research questions:

  • RQ1:What privacy models have been proposed for blockchain-based healthcare systems?

  • RQ2: What scalability strategies have been proposed for blockchain-based healthcare systems, and how effectively do they meet real-time throughput requirements?

  • RQ3: What roles do emerging technologies and advanced cryptographic techniques (e.g., zero knowledge proofs and ring signatures) play in existing blockchain-based healthcare architectures?

  • RQ4: What are the existing research gaps in the creation of privacy-preserving, interoperable, and regulation-compliant healthcare blockchains, and what future research directions can be expected?

This study aims to align the review with specific guiding questions to amalgamate previous research and establish a future agenda. This method is a strategic plan for making healthcare blockchains that protect privacy, work with other systems, can grow, and follow the rules. This will help digital healthcare ecosystems grow [17, 18]. To achieve this our objective covered privacy, scalability, interoperability, and modern cryptography. This research paper centers on a number of factors such as privacy models, shared learning in addition to a number of systems collaborating with one another with interoperability. It further dwells on the new concepts such as zero-knowledge evidence and ring signatures, etc., that have been advanced by different researchers in their research toward enhancing the security of the system. We present this research work in an understandable manner, with privacy and healthcare data manipulation serving as the central themes. Rapid illustrations, statistical tendencies, and tabular comparisons are simplifying the realization of how well these new technologies are with blockchain or whether they are prepared to be used at all. Within the future direction section of this paper, we elaborate on the different existing problems and solutions to them. This study brings significant contributions to the future requirement of healthcare blockchains, which preserve privacy and provide interoperability.

2
Methodology

In this research paper, a systematic review methodology has been used based on PRISMA (Preferred Reporting Items of Systematic Reviews and Meta-Analyses) but modified in computing and healthcare informatics [18]. The purpose of the review was to be thorough and focus on identifying both the blockchain applications in the medical sector and the paradigms of privacy preservation and scaling improvement, respectively. The finer methodology will be discussed in this section.

2.1
Review Protocol: The review was done according to the following stages
  • a)

    Identification: Thorough searches in Scopus, IEEE Xplore, ACM Digital Library, SpringerLink, Elsevier Science Direct, and Web of Science were performed searching articles published since January 2019 and until August 2025. The year was selected because the adoption of blockchain within healthcare was gaining traction after 2018, as well as, there was an increased interest in federated learning and enhanced cryptography (e.g., zero-knowledge proofs, etc.).

  • b)

    Screening-None of the duplicated records were retained and the title and abstract were screened based on a preset criterion. Particular care was taken about the articles that directly covered the issue of healthcare privacy, scalability, interoperability, and cryptography.

  • c)

    Elaboration: The criterion used to assess the relevance of the full text articles in terms of technical relevance, the depth of the methodology, and the scope of this review was eligibility. The studies that did not address blockchain, as those referenced but not with significant attention to healthcare were left out.

  • d)

    The last corpus was composed of peer-reviewed journal articles and conference papers, which are divided between privacy models, scalability techniques, federated learning integrations, interoperability frameworks, and advanced cryptographic primitives (ZKPs and ring signatures).

This staged approach ensured the traceability of decisions and reduced bias, thereby strengthening the reliability of the review.

2.2
Data Sources: Due to the desire to have a comprehensive coverage,6 bibliographic databases were chosen
  • a)

    Scopus: It has a multidisciplinary area of inclusiveness, with high impact journals being indexed.

  • b)

    IEEE Xplore: It is the engineering field of computing, communication and engineered around blockchain.

  • c)

    ACM Digital Library: Distributed systems and security.

  • d)

    SpringerLink: Focus on medical informatics and interdisciplinary blockchain research.

  • e)

    Elsevier ScienceDirect: Focuses on cryptography, security and technologies in healthcare.

  • f)

    Web of Science (WoS): The tool allows citation tracking and validation of SCI/SCIE.

Other checks were done through Google Scholar alerts to arrive at early access and in press articles (now published).

2.3
Keyword Strategy: Search strings were built with the help of Boolean operators and narrowed down with the iterative use of these Boolean operators to strike the right balance between precision and recall

Keywords: Blockchain and Healthcare and Privacy.

Augmented terms: Federated Learning OR Zero-Knowledge Proofs OR Cross-Chain OR Ring Signatures OR Consensus

The sample queries included:

(“Blockchain” AND “Healthcare” AND “Privacy”)

(“Blockchain” AND “Healthcare” AND “Federated Learning”)

(“Blockchain” AND “Healthcare” AND “Zero-Knowledge Proofs”)

Medical records, EHR/EMR, privacy preserving, and scalability were the synonyms that were used in the screening process. This guaranteed the EHR systems cover, extended IoMT architectures, federated learning, and cryptography frameworks and scalability.

2.4
Inclusion and Exclusion Criteria: The studies were also chosen under four principles, which include relevance, quality, adaptability, and accessibility

Inclusion Criteria:

  • Peer-reviewed publications in SCI/SCIE journals and leading conferences.

  • Articles published in English between January 2019 and August 2025.

  • Studies directly addressing healthcare or generic blockchain methods adaptable to healthcare.

  • Works offering technical contributions (frameworks, protocols, experiments, or formal analyses).

Exclusion Criteria:

  • Patents, theses, white papers, and grey literature.

  • Non-English publications were excluded.

  • Scopes of studies have limited themselves to simple immutability/security, but not scalability, interoperability and high-level privacy.

2.5
Tools and Workflow

Reference management, bibliometrics, and custom visualization were integrated in the hybrid workflow. Mendeley is applied to manage references, make notes, and de-duplicate. VOSviewer and Biblioshiny (R) facilitated bibliometric mapping of co-authorship networks, keyword co-occurrence, and temporal trends. Python, specifically Pandas and Matplotlib, was used to generate publication trends and taxonomy diagrams. Each decision was meticulously logged, and exclusion rationales were documented to ensure auditability and reproducibility.

2.6
Outcome

The search process resulted in the identification of 1,347 records. Following the removal of duplicates and an initial screening, 272 articles were selected for full text review, of which 94 were ultimately included in the final corpus. The distribution of participants is as shown in Figure 2. The selection process is depicted in Figure 2, which presents a PRISMA-inspired flowchart from identification to inclusion.

Figure 2.

The PRISMA-inspired literature selection process was followed in this review

In this section we have analysed the trends in three dimensions which are: absolute publication trends shown in Figure 3, stacked area trends in Figure 4 and log scale trends in Figure 5. Absolute trends showed that the most common systems are privacy-preserving systems, and stacked area trends showed that federated learning systems and ZKP-based systems are relatively growing faster, even though they are of lower absolute count. Trends in the log scales provided evidence that use of specialized cryptographic techniques is on the rise as more research on them becomes more interesting.

Figure 3.

Publication Trends in Healthcare Blockchain (2019–2025)

Figure 4.

Publication Trends in Healthcare Blockchain (2019–2025) Stacked Area view

Figure 5.

Publication Trends in Healthcare Blockchain (2019-2025) Log Scale

In the next section 3, we have presented the Comparison tables and a stratified taxonomy to aggregate results between various perspectives. Analysis of comparative tables, layered taxonomy, and bibliometric trends revealed that privacy-centric, secure methods such as HE (homomorphic encryption), ZKPs, etc. require a considerable amount of computational power & resources; on the other hand, scalable solutions including differential privacy, off-chain storage, and consensus mechanisms may compromise confidentiality. The current solutions face fragmentation, as they can protect and provide privacy & security to a particular layer, but not the entire system. The trend also reveals that federated learning and ZKP-based approaches currently have lower absolute volume, but they are growing quickly and carving out the recent stage of research; the present research papers have already done a lot. The general aspects point out that none of the approaches are perfectly balanced to meet all aspects of privacy, scalability, interoperability, and readiness to adopt, and thus, it needs integrated frameworks. Such structures work and align at different levels that it requires integrated frameworks. These frameworks operate and coordinate across various layers.

3
Thematic Review and Taxonomy

This research paper presents the latest development of the art with reference to the concerns related to privacy, security, scalability, and interoperability in healthcare blockchain. Each section is evaluated based on the techniques used, its benefits, and various limitations and gaps. We have presented the previous work and also highlights potential directions for future research in the healthcare blockchain field.

3.1
Privacy-Preserving Models and Cryptographic Techniques

Healthcare data are very sensitive, and security breaches may various issues like clinical harm, discrimination, and loss of trust. The traditional EHR systems rely entirely on centralized access control, making them vulnerable to a single point of failure, limiting auditability, and reducing patient control. On the other hand, blockchain technology offers a promising foundation for privacy-preserving healthcare, with its decentralized and tamper-proof distributed ledger.

In this section, we have listed effective privacy-preserving approaches that must balance confidentiality, usability, interoperability, and performance while addressing the dominant privacy-preserving approaches.

  • a)

    Access Control and Attribute-Based Encryption (ABE): This is a smart contract-based fine grained access policy. ABE ties decryption keys to attributes rather than identities, and it facilitates multi-user sharing. These methods enhance patient autonomy but do not support interoperability much, as they can complicate emergency access and cross-chain consistency [1921].

  • b)

    Encryption and Homomorphic Encryption (HE): The computation is done directly on the encrypted data (privacy-preserving analytics). It is not like the traditional encryption that only secures data at rest. HE provides high confidentiality, but sometimes it lacks interoperability as it requires a lot of computational power, making it not feasible for real-world applications like live cardiac monitoring [2224].

  • c)

    Secure Multiparty Computation (SMPC): It facilitates interoperability (collaborative data analysis across various institutions) without sharing the actual data of the patients. This is very much suitable for multi-hospital trials and combined research. As the number of participating nodes grows, the communication overhead grows simultaneously. This is constraining scalability of the entire EHR [2527].

  • d)

    Hybrid Approaches: The combination of traditional healthcare architecture with the advanced cryptographic primitives (differential privacy [79, 80] pseudonymization, or off-chain storage) improves the scalability and practicality of the system/IoMT. One of the major points is relying on external repositories may introduce trust and linkability concerns [2830].

In this section, we have presented Table 1, this table shows that each privacy-preserving model has its principles, strengths, and limitations.

Table 1.

Privacy Models in Blockchain-Based Healthcare Systems (2019–2025)

TechniquePrinciplesStrengthsLimitationsRepresentative Studies
Access Control (Smart Contracts, ABE)Access policies enforced via smart contracts;ABE links access to roles/attributesFine-grained sharing; strong patient autonomyEmergency access complexity; crosschain interoperability issues[1921]
Homomorphic Encryption (HE)Computation performed directly on encrypted EHR dataEnables secure analytics and ML without decryptionHigh computational overhead; unsuitable for real-time monitoring[2224]
Secure Multi-Party Computation (SMPC)Collaborative computation without sharing raw datasetsPreserves privacy in multi-institution studiesCommunication latency; scalability limitations[2527]
Hybrid (Differential Privacy + Blockchain)Noise added to data prior to storage or analysisLightweight; protects IoMT data streamsReduced data utility; tuning complexity[2830]
Hybrid (Encryption + Off-chain Storage)Blockchain stores hashes/metadata; data stored off-chainScalable; efficient storage; auditableExternal trust dependency; linkability risks[31, 32]
3.2
Advanced Cryptography: ZKPs and Ring Signatures

The advanced cryptographic primitives fulfill complementary privacy requirements in healthcare blockchains. ZKPs enable the verification of agreements and mathematical calculations without revealing any personal information about the patient or user. Patients can share certain information (like lab results) without giving away their actual identity [3335]. In federated learning, ZKPs are also used to ensure that model updates follow agreed-upon rules without giving away private information [36].

The ring signatures let a group of people verify a transaction without giving away the identity of the person. This makes it possible to do things that can’t be linked, like prescriptions, insurance claims, or sensitive lab queries. Linkable ring signatures stop people from various illegal things in networks with more than one hospital (Like double spending problem etc) [37, 38].

The comparison of ZKPs and ring signatures in healthcare blockchains along with the advantages and limitations for the given set of literature reviews is presented below in Table 2.

Table 2.

Comparison of ZKPs and Ring Signatures in Healthcare Blockchains(2019–2025)

TechniquePrinciplesStrengthsLimitationsRepresentative Studies
Zero-Knowledge Proofs (ZKPs)Prover convinces verifier of a statement (e.g., consent, correct computation) without revealing underlying data.Strong selective disclosure (prove consent/qualification without revealing identity or content); enables verifiable off chain computation (e.g., FL update checks); ZK rollups can improve throughput while preserving privacy.Proof generation can be computationally expensive (hard for IoMT); verifier/transition costs add latency; engineering complexity (tooling, trusted setup for some ZK systems); sparse real EHR integrations.[3336]
Ring Signatures (including linkable variants)A signer produces a signature that proves membership in a set but conceals which member signed; linkable versions allow detection of double use without deanonymizing.Provides unlinkable transaction anonymity (prescriptions, claims); simpler and more compact verification than many HE/SMPC schemes; linkable variants add fraud detection while preserving anonymity.Larger signature sizes than classical ECDSA; key management in dynamic consortia is non trivial; linkability vs. accountability trade offs need governance rules; not broadly standardised on permissioned platforms.[3738]

It is necessary to create hybrid protocols based on the combination of zero-knowledge proofs with ring signatures. Also, implementing the dynamic key management schemes, development of cross-chain verification APIs, and legal de-anonymization schemes are required to make sure that the regulatory requirement is met. The ability of these cryptographic primitives with federated learning, adaptive consensus, and cross-chain interoperability is essential to building healthcare blockchains that ensure privacy protection. Table 3 provides an overview of the pros and cons of privacy-saving and scalability-focused methods considered between 2019 and 2025. Four criteria were used in the evaluation of the techniques; they are privacy, scalability, computational cost, and readiness to be adopted.

Table 3.

Comparative Analysis of Blockchain Techniques in Healthcare (2019–2025)

TechniquePrivacy StrengthScalabilityComputation CostAdoption ReadinessRepresentative Studies
Access Control + ABEModerate-High (fine grained control)Moderate (policies scale poorly across chains)Low-ModerateHigh (easy integration with EHRs)[1921]
Homomorphic EncryptionVery High (data never decrypted)Low (latency sensitive)Very High (orders of magnitude higher than plaintext ops)Low (few pilots)[2224]
SMPCHigh (multi hospital privacy preserved)Low-Moderate (communication bottlenecks)HighMedium (tested in multi hospital studies)[2527]
Differential Privacy + BlockchainModerate-High (depends on noise budget)High (lightweight)LowMedium-High (suitable for IoMT streams)[2830]
Hybrid On-chain/Off-chain StorageModerate (privacy tied to off chain trust)High (IPFS/cloud scalability)LowHigh (already tested in Hyperledger pilots)[3132]
ZKPs (Consent/Access Proofs)Very High (no disclosure of identity/data)ModerateModerate-High (proof generation overhead)Medium (prototype level)[3336]
Ring SignaturesHighModerate (signature size grows)ModerateLow-Medium (few healthcare pilots yet)[3738]
3.3
Scalability Techniques in Healthcare Blockchains

One of the obstacles to the adoption of blockchain in healthcare is the issue of scalability. Healthcare loads are extremely heterogeneous and massive, with constant inflows of Internet of Medical Things (IoMT) devices, like cardiac monitors that produce thousands of data points every second, and massive movements of electronic health records (EHRs) between institutions. The throughput needs of national-scale healthcare networks cannot be met with conventional blockchains such as Ethereum, which have a throughput of 15 to 30 transactions per second (TPS). Research has paid attention to the three main solutions to cope with these issues: Layer 2 solutions, sharding, and consensus optimization. All these will be discussed herein.

A layer 2 solution is a side network that assists the primary blockchain to operate more efficiently. IoMT data can be sent back and forth via state channels numerous times, and the results are saved on the main chain. Some of the jobs that can be done by sidechains include looking at pictures of cancer patients, which accelerates TPS and saves money. These approaches complicate the ability to trust Layer 2 operators and follow audit trails, potentially complicating adherence to the HIPAA or GDPR regulations. As an example, [39] relied on channel-based IoMT configuration to achieve a tenfold higher throughput, and [40] proposed channeling imaging data through ZKP sidechains in order to process it securely [41].

The blockchain is broken down into small groups, known as shards, through sharding, which allows transactions to occur simultaneously. The shards in healthcare typically represent hospitals or regional networks, and it is simpler to perform functions such as patient referral and long-term record keeping [42]. This design is compatible with federated hospital designs, and it grows nearly linearly with network size. Other issues include maintaining cross-shard consistency, exposure of data in case of shard hacking, and the latency in communication between institutions. The shattered EHR blockchain was introduced in [43] and reduced latency by 40 but introduced additional work when sending queries between hospitals [44].

The Consensus Optimization changes the usual protocols to accommodate healthcare needs with a focus of energy and communication overhead. Practical Byzantine Fault Tolerance (PBFT) offers strong security, but it doesn’t work well with more than about 20 nodes [45]. Proof of Authority (PoA) is a lightweight system that works well for government hospital networks, but it requires trusted validators [46]. Intel SGX is used by Proof of Elapsed Time (PoET) to save energy. It has been tested in telemedicine settings [47]. Hybrid models that mix PBFT with PoA or PoET let you switch between them based on how busy the system is, [48] proposed a nationwide EHR sharing model employing a PBFT-PoA hybrid, while [49] demonstrated the functionality of dynamic consensus switching across various hospitals.

Even with these methods, healthcare often needs more than 1000 TPS, which is way more than most financial systems can handle. To keep your information safe and private, blockchain isn’t enough. It needs to be able to be checked, follow the rules, and work well for it to work in the actual world. If off-chain transactions aren’t adequately anchored, layer 2 solutions can compromise the integrity of audit trails. Sharding may struggle with longitudinal EHR queries that span multiple shards. Consensus techniques need to make trade-offs. PBFT is safe but slow, PoA and PoET are faster but more centralized, and hybrid models are still primarily experimental.

Layer 2 solutions can manage IoMT data that comes in quickly, but they might not be compliant if transactions that aren’t on-chain aren’t fully anchored. Sharding is a good fit when the network is constituted of federated hospitals, but it has issues to maintain records in a uniform manner across shards, in particular those records that require a long period to be stored. The hybrid models appear to be a strong concept since they can be used to solve various kinds of tasks, but they are not actively used in the actual healthcare environment at the moment. Table 4 suggests that there are advantages and disadvantages of every strategy. This information can assist us to create healthcare blockchains that have the potential to develop and collaborate with other systems.

Table 4.

Comparison of ZKPs and Ring Signatures in Healthcare Blockchains (2019–2025)

TechniquePrinciplesStrengthsLimitationsRepresentative Studies
Layer 2 Solutions (Channels, Sidechains)Move frequent interactions off chain, anchor summaries on chain.High throughput; reduced latency; cost efficient for IoMT.Auditability concerns; relies on trusted off chain operators; regulatory compliance gap.[3941]
ShardingPartition blockchain into shards (e.g., hospital/regional clusters) for parallel processing.Linear scalability; natural fit for healthcare networks.Cross shard query consistency difficult; vulnerable if a shard is compromised; synchronization overhead.[4244]
Consensus Optimisation (PBFT, PoA, PoET)Modify or replace consensus to reduce communication or energy cost.Lower latency; energy efficient; tailored for permissioned healthcare settings.PBFT fails at large scale; PoA/PoET reduce decentralization; limited real-world validation.[4547]
Hybrid ModelsDynamically switch between consensus algorithms (e.g., PBFT ↔ PoA/PoET).Adaptive to workload; balances security and throughput; suitable for national EHR.Implementation complexity; security risks during switching; not tested at production scale.[48, 49]
3.4
Applications and Integrated Frameworks

This section focuses on architectural patterns and integrated design paradigms in the blockchain-based healthcare applications. The discussion emphasizes how federated learning, blockchain coordination, and cross-chain mechanisms are combined at a structural level to enable privacy-preserving and scalable analytics. Practical deployment constraints and systemic limitations are intentionally deferred to sections 3.5 and 3.6.

3.4.1
Federated Learning in Healthcare Blockchain Systems

Federated learning (FL) has become a feasible privacy-preserving paradigm of collaborative analytics in the healthcare system (capable of training machine learning models), allowing multiple institutions to collaborate without sharing actual patient information [50]. This technique of decentralized learning has been used on a variety of healthcare tasks, such as disease prediction, medical image analysis, and healthcare IoT monitoring, as well as in cases where regulatory limits limit centralized data aggregation [51]. Systematic reviews prove that FL offers significant risk reduction in data exposure, and its model performance is like centralized training, which is appropriate to be used in clinical settings [52].

Nevertheless, in case FL is implemented in independent healthcare organizations, the problem of trust, accountability, and model integrity appears, especially when unreliable parties are involved [53]. To address these issues, other research papers combine federated learning with blockchain systems, with the blockchain acting as a decentralization coordination and audit layer, but not as a computational engine [54]. In such architectures, there are training rounds, model updates, and participation records that are immutably logged, improving transparency and traceability in collaborative healthcare analytics. Experimental validation of blockchain-assisted FL frameworks has been done in healthcare monitoring devices and medical imaging tasks, showing increased trust and ensuring patient privacy [55].

Besides these strengths, scalability and efficiency are a challenge to existing blockchain-enabled FL systems [56]. Ledger maintenance overhead, longer communication latency, and lack of support of cross-heterogeneous healthcare network interoperability limit their application to large-scale, multiinstitutional applications [57]. These shortcomings encourage the quest to seek interoperable and crosschain interactions to facilitate the federated learning of domains across multiple blockchains [58].

Figure 6 shows a stratified taxonomy of federated learning and blockchain applications in healthcare, with data, learning, blockchain coordination, and application layers. The figure highlights how privacy is preserved through localized training of the models, while auditability and trust are ensured by utilizing blockchain-based verification. This stratified perspective reveals major integration loopholes in deployments associated with scalability and interoperability in clinical applications.

Figure 6.

Layered taxonomy of privacy-preserving blockchain architectures for healthcare

3.4.2
Cross-Chain Interoperability for Federated Healthcare Analytics

Cross-chain interoperability has been considered because it is viewed as a solution to the problem of the fragmentation of healthcare blockchain ecosystems, in which hospitals, laboratories, and regulatory entities can run separate distributed ledgers with different policies 59]. Interoperability mechanisms facilitate trustworthy sharing of proofs, metadata, and encrypted health records among non-homogeneous blockchains [60], which may serve a wide variety of applications, e.g., cross-hospital referrals, longitudinal patient records, and jurisdiction-sensitive consent enforcement [61].

Recent healthcare-related literature suggests secure interoperable models that can facilitate the exchange of electronic health records (EHR) among such platforms as Ethereum and Hyperledger Fabric [62]. These methods utilize the use of middleware layers or interoperability protocols to coordinate encrypted healthcare data and maintain access control and patient privacy. Systematic reviews also indicate that interoperability is the most important bottleneck in a blockchain-based healthcare system, especially in cases where two or more blockchains are present in the infrastructure of a region or a nation’s healthcare system.

General cross-chain protocols, such as relay-based, notary, and light-client verification protocols, are building blocks that are adaptable to healthcare data sharing. Nevertheless, currently existing solutions are susceptible to security threats of bridges, higher variety of cross-chain latency, and semantic inconsistency between healthcare data standards. Cross-chain interoperability, which involves federated learning, allows the local training of models in institutional blockchains and provides global coordination and validation across networks, therefore enhancing the applicability and scalability of privacy-preserving healthcare analytics [63].

Figure 7 plots available healthcare blockchain solutions on the privacy-interoperability axis. The figure also provides visual support for the comparison analysis in Table 5 by reflecting the trade-offs in preserving privacy and cross-network interoperability among federated learning, cross-chain, and hybrid frameworks. The positioning in Figure 7 reflects qualitative architectural characteristics derived from Table 5, rather than quantitative performance measurements.

Figure 7.

Positioning of Approaches: Privacy vs Interoperability

Table 5.

Comparative Analysis of Federated Learning and Cross-Chain Interoperability in Healthcare

ApproachCore ConceptHealthcare ApplicationsPrivacy PreservationInteroperability SupportKey LimitationsReferences
Federated Learning (FL)Distributed model training without data sharingDisease prediction, medical imagingHighLowTrust and auditability gaps[5052]
FL + BlockchainBlockchain based coordination and audit of FLMedical imaging, healthcare IoTHighLow-ModerateLedger overhead, latency[5355]
Blockchain-Assisted FLSecure logging of training rounds and updatesDevice monitoring, analyticsVery HighLowScalability constraints[5658]
Cross-Chain Healthcare SystemsInteroperable EHR exchange across blockchainsCross-hospital EHR sharingModerateHighBridge security risks[59, 60]
Integrated FL + InteroperabilityLocal FL with cross-chain coordinationMultiinstitution analyticsHighModerate-HighCross-chain latency, limited evaluation[6163]
3.5
Existing Frameworks and Use Cases

Between the years 2019 and 2025, blockchain in healthcare became an actual practice and not merely a concept. Some of them included EHR exchange, telemedicine, IoMT data integrity, federated learning, and cross-chain capability. Hyperledger Fabric-based solutions are the most appropriate to share enterprise EHRs [63]. These are permissioned, are modularly-consenting, and adhere to the HL7/FHIR rules. At the same time, they are not that easy to use by more people because of their scalability and complexity in deployment [64].

Ethereum-based platforms simplify the process of people receiving e-prescriptions, paying their bills, and conducting teleconsultations[65]. They would like to become open and provide patients with more control [6870]. ZKP-based sidechains can assist in certain issues that are currently present such as high transaction costs and privacy issues [6870]. Federated learning and blockchain enable AI to collaborate without un-processed data exchange, this enhances model logging and privacy [7173]. In contrast, it is susceptible to adversarial ML threats and it finds it difficult to expand. IoMT chains ensure sensor data is never wrong, whereas edge devices do not possess much power [7477]. Interoperability systems Cross-chain interoperability frameworks aim to enable smooth electronic health record (EHR) exchange across a variety of blockchains; yet, they are still mostly theoretical and face regulatory and security challenges. While Section 3.4 examines architectural integration patterns, this section 3.5 shifts focus to the real-world frameworks and reported use cases.

Hybrid architectures combining permissioned governance with privacy tools (such as ZKPs and ring signatures) and cross-chain interoperability. In this manner, compliance with the law and clinical usability are achieved. Table 6 indicates the platforms, areas of focus, strengths, weaknesses and preparation of representative frameworks to be used. Among others, the most significant ones are: Hyperledger fabrics EHR systems adhere to the rules and they are heavily controlled. Also, they are quite popular in pilot programs, despite this, they are unable to serve many users simultaneously. The development of telemedicine applications on Ethereum can be cost-intensive because of gas fees and network congestion. Federated Learning and blockchain collaborate to develop AI that would ensure the privacy of individual data of people. It is used by a great number of people but can be poisoned and experience latency problems. Cross-chain interoperability frameworks assist the electronic health records (EHRs) in transferring between institutions, yet they are in the research phase and present problems with security and complexity. ZKP-based chains provide high privacy and compliance guarantees and are currently under research and have only been experimented with a handful of times.

Table 6.

Comparative Overview of Blockchain Frameworks in Healthcare (2019–2025)

Framework / Use CasePlatform / ArchitectureFocus AreaStrengthsLimitationsAdoption ReadinessReference
Hyperledger Fabric EHR SystemsPermissioned blockchain (Fabric/Sawtooth) with off-chain storageSecure EHR exchange across hospitalsFine-grained access, audit trails, HL7/FHIR complianceScalability limits, complex deploymentHigh (pilot deployments exist)[6465]
Ethereum Telemedicine PlatformsPublic/consortium Ethereum smart contractsTeleconsultations, e-prescriptions, billingTransparency, patient-doctor trust, micropaymentsHigh gas cost, privacy issuesMedium (prototypes tested)[66, 67]
ZKP-Enhanced Healthcare ChainsPermissioned or hybrid blockchain with ZKPsConsent verification, anonymized accessStrong privacy, regulatory complianceProof size overhead, limited pilotsLow (research stage)[6870]
FL + Blockchain PrototypesHybrid blockchain + federated learningCollaborative AI without raw data sharingPrivacy-preserving AI, on-chain model loggingNon-IID data, poisoning attacks, latency issuesMedium (academic demos)[7173]
IoMT Data Integrity ChainsLightweight blockchain integrated with IoT gatewaysReal-time sensor/device dataReal-time auditing, integrity assuranceEdge resource constraints, latency for critical careMedium[7477]
Cross-Chain InteroperabilityCosmos/Polkadot-inspired relay frameworksEHR sharing across heterogeneous blockchainsInteroperability, patient record continuitySecurity of bridges, high complexityLow-Medium (early-stage research)[7880]
3.6
Limitations in Current Literature

The limitations described in this section are not based on other primary studies, but rather synthesised in the result of the empirical studies and architectural reviews in Sections 3.1-3.5. Based on the architectural trends outlined in the previous Section 3.4 and on the experience of the deployment of representative architectures and use cases as discussed in the literature on healthcare blockchain, this section pools cross-cutting constraints reported throughout the literature on healthcare blockchain.

Although blockchain adoption in healthcare has increased substantially between 2019 and 2025, the literature consistently reports several structural limitations that hinder its translation from experimental prototypes to real-world clinical deployment. One of the main issues is the difference between the prototypes and large scale clinical implementation. The majority of the research is/still is a proof-of-concept experiment conducted on small networks of less than fifty nodes. Some of the protocols like PBFT have high consistency, but at the cost of quadratic overhead, and other protocols like PoA or PoET have a better throughput, but at the cost of decentralization. In turn, the issues of reliability and latency in national-level hospital networks are still not investigated, and it is hard to apply them to the latency-sensitive setting like IoMT-enabled intensive care.

The other glaring drawback is the trade-off of privacy and scalability. Cryptography is used to provide high-level confidentiality assurances, such as homomorphic encryption (HE), secure multiparty computation (SMPC), and zero-knowledge proofs (ZKP) to ensure that sensitive data of the patients is never revealed throughout the computation or verification process. Despite this, such techniques are computationally and communicationally expensive and do not make them practical in real-time applications of healthcare. Lightweight solutions, including differential privacy (DP) or on-off-chain storage, are better throughput-improving and can be scaled more efficiently but tend to have lower data faithfulness or off-chain faith in trust. This is the constant conflict between privacy and scale, and this is why hybrid solutions are needed that can compromise between security and the realistic performance.

Interoperability is also an important obstacle. The idea of federated learning and cross-chains has shown to have potential to collaborative AI and data exchange in between hospital networks, but the majority of experiments have been done on laboratory datasets, such as MNIST or CIFAR, and few studies proved their performance on real EHR datasets, such as MIMIC-III or eICU. In addition, it is frequently not fully integrated with health care standards, such as HL7 FHIR, and issues related to non-IID data distributions, model poisoning, and heterogeneous IT infrastructures are not solved yet. These loopholes indicate that the existing frameworks are not ready yet to be deployed in the complex multi-institutional healthcare settings.

Another weakness is associated with regulatory and ethical compliance. Although some studies are conscious of GDPR, HIPAA or the guidelines of the DISHA used by India, few of them explicitly include those requirements in the smart contracts or blockchain logic. Clear accountability mechanisms are mostly not addressed and emergency access situations are known as break-glass. This regulatory non-integration erodes trust and hinders uptake of clinical system because healthcare providers will not invest in systems whose legality is unclear [8184].

Lastly, sustainability and energy efficiency, these problems are non-trivial in nature. The expensive cost and use of energy on consensus protocols and computationally intensive cryptography make them more costly and damaging to the environment, especially when large networks of hospitals or IoMT ecosystems are created. As an increasing number of healthcare IT designers consider green designs, designs not optimized with respect to energy efficiency may be hindered in their adoption over the long term.

Any of the most notable limitations found within the literature are summarized in Table 7 based on the technique or framework they use and representative studies published since 2019 and up to 2025. In general, the synthesis shows that there are four cross-cutting challenges, namely, (i) insufficient application of sophisticated cryptographic primitives to live healthcare networks, (ii) the tension between privacy and scalability remains unresolved in latency-sensitive applications, (iii) the poor interoperability between blockchain systems and healthcare standards, and (iv) the unregulated and energy-efficient design. These are some of the challenges that need to be addressed to create the next generation healthcare blockchain systems that are practical, compliant and sustainable.

Table 7.

Limitations in Blockchain based Healthcare Literature (2019–2025)

Technique / FrameworkObserved LimitationsAnalytical Implications for Healthcare Deployment
Scalability (PBFT, PoA, PoET, Hybrid Consensus)Evaluations restricted to small networks (<50 nodes); PBFT incurs quadratic communication overhead; PoA/PoET reduce decentralizationLimited evidence of reliability and latency performance in large hospital networks; unsuitable for nationwide or IoMT-intensive healthcare scenarios without adaptive or hierarchical consensus designs
Privacy Models (HE, SMPC, DP, ABE)HE and SMPC impose high computation and communication costs; DP reduces data utility; ABE complicates emergency accessStrong privacy guarantees come at the expense of real-time responsiveness; current designs struggle to balance confidentiality with clinical usability in latency sensitive environments
Federated Learning + BlockchainValidation mostly on synthetic or small-scale datasets; non-IID data and model poisoning insufficiently addressedTrust and auditability improve, but lack of real EHR validation limits clinical credibility; robustness against adversarial participants remains an open issue
Cross-Chain InteroperabilityPredominantly conceptual frameworks; absence of healthcare-specific interoperability standards; high coordination latencyEnables institutional autonomy but lacks semantic consistency and performance guarantees required for cross-hospital clinical workflows
ZKPs and Ring SignaturesHigh proof generation and verification cost; ring signatures scale poorly with participant sizeSuitable for selective verification and auditing, but impractical for continuous clinical transactions or large healthcare consortia without lightweight adaptations
Existing Platforms (Hyperledger, Ethereum, Bespoke Frameworks)Partial centralization in permissioned systems; high transaction cost in public blockchains; bespoke designs lack standardizationPlatform-level constraints limit portability and long term sustainability; healthcare-specific customization remains fragmented
Regulatory and Ethical ComplianceLimited embedding of GDPR, HIPAA, or DISHA requirements; emergency “break-glass” access poorly formalizedLegal ambiguity and unclear accountability reduce institutional trust and hinder clinical adoption despite technical feasibility
4
Discussion: Gaps and Future Directions

This section synthesizes the findings of the systematic review to identify persistent research gaps and emerging directions in blockchain-based healthcare systems. Rather than reiterating individual system-level limitations, the discussion summarizes cross-cutting issues found in architectures, deployment studies, and experimental assessments with the view of influencing future research and system design. As of 2021, blockchain-based healthcare has achieved a lot of advances since 2019, yet there remain some issues that prevent its application in many clinical practices. It has four key gaps, each of which is indicative of the way of creating a system that will be safe, useful, and rule-following.

4.1
Limited Adoption of Advanced Cryptography

Zero-knowledge proofs (ZKPs), homomorphic encryption (HE), and secure multiparty computation (SMPC) are developed privacy methods that remain largely only simulated and not commonly deployed in real and actual hospital operations. This gap reflects a broader disconnect between cryptographic innovation and clinical feasibility, indicating the need for lightweight, workflow-aware cryptographic integration rather than isolated proof-of-concept implementations.

4.2
Privacy and Scalability Trade-offs

Healthcare systems are habitually at the crossroads of privacy and efficiency. Delays caused by strong encryption can raise the concern of urgent care, and speedier strategies can compromise safety or decentralization. Dynamic consensus, Layer 2 rollups, and cross-shard verification are available examples of adaptive and hybrid solutions and need to be experimented on in clinics to ensure such a solution performs under stress. The continuing existence of this trade-off in a variety of system designs indicates that there is inadequate flexibility in the presence of static privacy or scalability optimization and encourages context-sensitive and adaptive architectures. The use of post-quantum cryptographic primitives is also becoming relevant in this regard because the security of a healthcare record can need longer-term confidentiality, which surpasses the projected security duration of classical public-key cryptography.

4.3
Issues with Interoperability

Interoperability Issues Most healthcare blockchains are not connected and cannot communicate or connect with interoperability standards, standard like the HL7 FHIR and DICOM. The establishment of standard interoperability structures that meet the regulations like secure cross-chain bridges as well as FHIR/DICOM adapters, will prove to be of high importance. These structures would also enable AI to share tasks with one another in order to learn and ZKPs would provide sufficient privacy and accountability of patients. These results show that the issue of interoperability should be handled as a semantic and governance not only as a challenge of technical data-exchange.

4.4
Regulation-Unaware Architectures

Architectures That Don’t Know about Rules It can only be expected that people do not take rights like these HIPAA and GDPR until they are compromised. The compliance will be by design to the future systems. This means that they should integrate consent management, minimization of data, ethical protection and energy-efficient architectures in order to handle the increasing amount of medical data responsibly. Lack of compliance-by-design is indicative of a major mismatch between the technical research and the healthcare regulatory reality.

4.5
Research Gaps Map

Figure 8 shows the research landscape by putting privacy/security rigor on one axis and interoperability/deployment readiness on the other. It draws attention to areas that need more research: Most of the time, lightweight ZKPs, scalable ring signatures, and privacy-preserving cross-chain solutions haven’t been tried yet. On the other hand, federated learning and governance need systems that can handle privacy, performance, and interoperability all at once. Figure 8 presents a synthesized research gaps map derived from the comparative analyses in Tables 57 and the thematic findings discussed in Sections 3 and 4.

Figure 8.

Research Gaps Map: Under explored intersections in blockchain enabled healthcare systems (2019–2025). Research landscape mapping blockchain in healthcare. The x axis represents interoperability and deployment readiness, while the y axis indicates privacy and security rigor

4.6
A Brief Overview of the Research Questions

The most important results from 2019 to 2025 are shown in Table 8. Research on blockchain in healthcare shows that there is a trade-off between strong cryptography (better privacy, less scalability) and lightweight methods (which work but are less secure). Scalability and federated learning have problems in the real-world and when they work with other systems. Cross-chain and advanced cryptography, on the other hand, are still mostly untested. Lightweight zero-knowledge proofs (ZKPs), adaptive consensus mechanisms, poison-resistant federated learning, post-quantum cryptography, and compliant, sustainable systems are all things that could happen in the future. To consolidate the discussion, Table 8 summarizes how the four research questions are addressed by the reviewed literature and highlights unresolved challenges that motivate future research.

Table 8.

Research Questions and Findings Summary

Research QuestionKey Findings
[RQ1].Privacy Models: Multiple models exist, including access control with Attribute-Based Encryption (ABE), Homomorphic Encryption (HE), Secure Multi-Party Computation (SMPC), differential privacy, and hybrid approaches. Strong cryptography (HE, SMPC) ensures high privacy but incurs high computation and limited scalability. Lightweight models (DP, hybrid off-chain storage) are usable but weaker in confidentiality. Hybrid models optimized for healthcare remain underdeveloped.
[RQ2].Scalability Strategies: Layer 2 solutions (channels, sidechains) and sharding improve throughput.Consensus optimizations (PBFT, PoA, PoET) reduce latency but trade decentralization. Hybrid consensus approaches (e.g., PBFT↔PoET switching) show promise but lack validation at production scale. Overall, real-world deployment at national or hospital network scales remains limited.
[RQ3].Emerging Technologies & Advanced Cryptography: Federated learning aided by blockchain allows collaborative AI without the exchange of raw data but suffers such problems as non-IID data and model poisoning. Cross-chain interoperability models are primarily prototypes which have latency and security issues. The probability of zero-knowledge proofs (ZKPs) and ring signatures offers selective disclosure of transactions and unlinkable transactions, but has seen very little real-world use. The combination of these methods with FL and adaptive consensus is mostly done on a case-by-case basis.
[RQ4].Research Gaps & Future Directions: Key gaps include: (i) limited deployment of advanced cryptography in real hospital networks; (ii) unresolved privacy-scalability trade-offs; (iii) weak interoperability with standards such as HL7 FHIR and DICOM; and (iv) lack of regulation-aware and sustainability-focused design. Future directions include lightweight ZKPs, poisoning-resistant federated learning, adaptive consensus mechanisms, post-quantum cryptography, and compliant, energy-efficient blockchain infrastructures.
5
Conclusion

In this research, it is emphasized that blockchain-based healthcare systems are still an area of academic discussion with only limited concepts and experimental prototypes. Lack of technical solutions is not a supreme dilemma, and the major challenge is fragmentation of the current approaches to privacy, scalability, interoperability, and regulatory compliance. Most existing systems consider these dimensions separately and provide architectures that are challenging to implement in practice in the clinical setting. One of the points noted during the analysis is the increased applicability of hybrid blockchain structures that integrate several complementary methods instead of making use of a single design paradigm. The traditional privacy mechanisms have disadvantages on performance that are being overcome by the lightweight cryptographic primitives, and the adaptive consensus strategies can be extended to a variety of clinical workloads. On the same note, federated learning and crosschain interoperability is applied to achieve the idea of data ownership of various types, as well as the incorporation of different infrastructures in hospitals.

Design-wise, the next generation of healthcare blockchain solutions should go beyond characteristics-based prototypes to compliance-conscious and clinically viable designs. It must include the regulatory principles, interoperability standards, including HL7 FHIR and DICOM, and energy efficient consensus mechanisms directly into system design.

According to the results of this review, a research roadmap will be formed with the following key points: (i) clinically validated deployments, (ii) standardized cross-chain interoperability frameworks, (iii) accountable and auditable federated learning models, and (iv) practical cryptographic mechanisms that may be useful in time-sensitive healthcare settings. The development of this roadmap is critical to the next phase of blockchain evolution as a testable technology for a stable infrastructure of reliable and interoperable healthcare systems.

DOI: https://doi.org/10.2478/ias-2026-0003 | Journal eISSN: 1554-1029 | Journal ISSN: 1554-1010
Language: English
Page range: 30 - 51
Published on: Jun 15, 2026
In partnership with: Paradigm Publishing Services
Publication frequency: 6 issues per year

© 2026 Garima Singh, Mohd. Haroon, published by Cerebration Science Publishing Co., Limited
This work is licensed under the Creative Commons Attribution-NonCommercial-ShareAlike 4.0 License.