Every time a wearable fitness band logs a heartbeat, a smart glucose monitor transmits a reading, or a mobile health app uploads a symptom diary, a new fragment of medical data is born outside the walls of a hospital. In the emerging model of consumer-centric e-healthcare, patients themselves—not clinics or insurers—hold and share these records, often through blockchain-based platforms that promise security, interoperability, and genuine patient control. Yet a new study published in Cluster Computing argues that the provenance layer of these systems, the machinery that records who accessed what data, when, and why, remains dangerously underdeveloped. The research team, led by Gulshan Kumar and Rahul Saha of Lovely Professional University together with Mauro Conti of the University of Padua, has unveiled SANITA, short for Shared dAta proveNance for Interoperable healThcare Blockchains, a decentralized provenance system designed to make every use of medical data traceable, verifiable, and resistant even to quantum-scale attacks.
The problem SANITA targets is subtle but consequential. When patients manage their own medical records, they become the custodians of data they may not have the technical expertise to police. Consent decisions, access logs, and usage histories can drift into inconsistency, and those inconsistencies translate directly into degraded healthcare quality when clinicians rely on incomplete or unverifiable records. The authors observe that existing healthcare blockchain solutions typically bolt on provenance mechanisms as an afterthought, lacking comprehensive multi-level access controls, post-access validation, and robust privacy safeguards backed by verifiable and accountable consent management. In practice, that means a record might be shared with a specialist, copied into an analytics pipeline, or aggregated by a research consortium without any tamper-evident trail that the patient—or an auditor—can later inspect.
Provenance, in the data-management sense, is the documented lineage of information: where it originated, how it was transformed, and who touched it along the way. In clinical settings, provenance is not a luxury. Clinical data registries depend on context to be meaningful, and systematic reviews of health information systems have repeatedly flagged provenance management as a weak link. The SANITA team’s contribution is to treat provenance as a first-class citizen of the blockchain itself rather than an external log. The system records not just the fact that data was accessed, but the full hierarchical chain of usage—preserving the lineage of medical records as they move across interoperating institutions and applications, so that a laboratory result derived from a wearable reading, for example, carries its ancestry with it.
At the technical heart of SANITA sits a smart contract, self-executing code deployed on the blockchain that automates the provenance workflow. When a request to use medical data arrives, the contract evaluates the request against the access-control policy, records the consent decision, and then—crucially—continues to monitor the interaction after access has been granted. This post-access provenance is the feature the authors single out as their answer to a gap in comparable systems: most blockchain health platforms verify identity before unlocking a record and then go quiet. SANITA’s contract instead captures what happens to the data after the door opens, and it does so, according to the team’s experiments, in comparable time to systems that offer far weaker guarantees. The smart contract architecture also supports upgradeability patterns, an engineering consideration the authors examined carefully, since immutable contracts that cannot evolve become liabilities in a regulatory landscape that shifts as fast as healthcare technology.
Interoperability is the second pillar. Healthcare data rarely lives in one place; it flows between hospitals, pharmacies, insurers, wearable vendors, and national e-health infrastructures such as Estonia’s widely cited electronic health record system. A provenance system that only works inside a single blockchain silo would miss most of the story. SANITA is designed to maintain hierarchical provenance across interoperating healthcare blockchains, meaning that usage records remain coherent and verifiable even when data crosses institutional boundaries. The authors argue this is essential for consumer-centric e-healthcare, where the data feeding a clinician’s dashboard may have been generated by a dozen different consumer devices, each with its own trust domain and its own chain of custody.
To find out whether these design ambitions survive contact with reality, the researchers ran a series of experiments benchmarking SANITA against state-of-the-art models in the field. The headline numbers are striking: SANITA delivered 25 percent better throughput while reducing latency by 30 percent relative to the comparison systems. In blockchain terms, throughput measures how many provenance transactions the network can process per unit of time, while latency measures the delay between a data-use event and the moment its provenance record is immutably committed. Both matter enormously in clinical practice. A provenance system that slows record retrieval to a crawl will be abandoned by clinicians; one that lags behind real-time access cannot prevent or even promptly detect misuse. The evaluation used synthetic patient records generated with Synthea, an open-source simulation platform that produces realistic synthetic electronic health records, allowing the team to stress-test the system at scale without exposing any real patient data.
Security analysis formed the other half of the evaluation, and here the authors report that SANITA achieved what they describe as 100 percent attack resistance capability across the threat scenarios they modeled, alongside efficiency suitable for deployment on healthcare blockchains. The formal analysis drew on the Dolev–Yao adversary model, a standard abstraction in which an attacker can intercept, replay, and forge messages but cannot break the underlying cryptography itself. Within that model, the team assessed how the system withstands eavesdropping, tampering, and impersonation attempts against both the provenance records and the consent-management workflow. The multi-level access-control design, combined with verifiable consent records anchored on-chain, is what allows every access decision to be audited after the fact without revealing the contents of the medical data itself.
Perhaps the most forward-looking aspect of the work is its embrace of post-quantum cryptography. Quantum computers of sufficient scale, should they arrive, would shred the elliptic-curve cryptography protecting most of today’s blockchains, exposing archived medical records to retroactive decryption—a scenario security researchers call harvest now, decrypt later. SANITA sidesteps this threat by building on CRYSTALS-Kyber and CRYSTALS-Dilithium, the lattice-based key-encapsulation and digital-signature schemes selected by standardization bodies as the leading post-quantum primitives. Both schemes derive their hardness from problems on mathematical lattices, structures whose worst-case difficulty is believed to reduce to their average-case difficulty, giving cryptographers unusually strong confidence in their resilience. The authors note that these schemes resist quantum attacks while maintaining efficient performance, meaning the quantum-proofing does not come at the price of the throughput gains that make SANITA practical.
The significance of the work extends beyond one protocol. Healthcare blockchain deployments are proliferating, from pharmaceutical supply networks like MediLedger to patient-centric storage frameworks built on the Interplanetary File System, and regulatory pressure around data breaches continues to intensify under regimes such as HIPAA. Yet surveys of blockchain applications in electronic health records consistently identify consent management and provenance as the weakest architectural layers. By demonstrating that post-access provenance, hierarchical interoperability, and post-quantum security can coexist with better performance than existing alternatives, SANITA offers a template for what the next generation of patient-controlled health platforms should look like. The authors, who declare no competing interests and conducted the research without specific grant funding, position the system as a step toward secure, transparent, and scalable healthcare data management built around the consumer rather than the institution.
Challenges remain before systems like SANITA reach production. Real-world deployment would need to confront the governance of cross-chain interoperability, the onboarding of patients who lack technical proficiency, and the operational costs of running lattice-based cryptography on resource-constrained wearable devices. The authors themselves frame consumer-managed provenance as a challenge of accuracy, security, and privacy that no single mechanism fully solves. Still, the study’s experimental results suggest that the trade-off long assumed between strong provenance guarantees and acceptable performance may be false. If healthcare blockchains are to earn the trust that patient-centered medicine demands, the ledger will need to remember not just who owns a record, but every hand it has passed through—and SANITA’s smart contracts are designed to make sure it never forgets.
Subject of Research: A decentralized smart-contract-based data usage provenance system with post-quantum cryptography for patient-controlled healthcare blockchains.
Article Title: SANITA: decentralized data usage provenance system for healthcare blockchains
Article References: Kumar, G., Saha, R., Conti, M., Markendey, V., & Thomas, R. (2026). SANITA: decentralized data usage provenance system for healthcare blockchains. Cluster Computing, 29(14), Article 809. https://doi.org/10.1007/s10586-026-06586-9
Image Credits: AI Generated
DOI: 10.1007/s10586-026-06586-9
Keywords: blockchain, healthcare, data provenance, smart contracts, post-quantum cryptography, CRYSTALS-Kyber, CRYSTALS-Dilithium, e-health, patient data privacy, interoperability, electronic health records, consent management
Cite Scienmag News
APA
MLA
Chicago
Katie Riggs. (October 2, 2026). SANITA Brings Quantum-Safe Data Provenance to Patient-Controlled Healthcare Blockchains. Scienmag. https://scienmag.com/sanita-brings-quantum-safe-data-provenance-to-patient-controlled-healthcare-blockchains/
Katie Riggs. “SANITA Brings Quantum-Safe Data Provenance to Patient-Controlled Healthcare Blockchains.” Scienmag, 2 October 2026, https://scienmag.com/sanita-brings-quantum-safe-data-provenance-to-patient-controlled-healthcare-blockchains/. Accessed 2 October 2026.
Katie Riggs. “SANITA Brings Quantum-Safe Data Provenance to Patient-Controlled Healthcare Blockchains.” Scienmag. October 2, 2026. https://scienmag.com/sanita-brings-quantum-safe-data-provenance-to-patient-controlled-healthcare-blockchains/
Copy citation
Download RIS
Tags: blockchainblockchain for transparent health information managementblockchain-based patient-controlled health recordsconsent managementCRYSTALS-DilithiumCRYSTALS-Kyberdata provenancedecentralized medical data tracking systeme-healthelectronic health recordsHealthcarehealthcare data interoperability challengesinteroperabilityinteroperable healthcare blockchainsmedical data traceability and verificationpatient data access and consent managementpatient data privacypost-quantum cryptographyprovenance layer in e-healthcarequantum-safe healthcare data provenanceresistance to quantum attacks in healthcare datasecure medical data sharing platformssmart contractswearable health device data security


