Inspiration
We were inspired by a critical situation in healthcare: what happens when a patient arrives at a hospital unconscious and cannot explain their medical history or provide consent?
In an emergency, doctors may need critical information such as allergies, medications, blood type, and existing medical conditions. At the same time, medical information must remain private and accessible only to authorized healthcare professionals.
This inspired us to create CAREID (Care & Digital Identity), a healthcare identity and secure medical access platform that combines Web3 principles and blockchain technology to balance emergency accessibility, patient privacy, and accountability.
What it does
CAREID provides patients with a Digital Medical Identity that can be accessed through a QR-based identification mechanism.
Sensitive medical records are stored in encrypted off-chain storage, while blockchain and smart contracts are used to manage consent, healthcare-provider authorization, emergency access, and access auditing.
In normal situations, healthcare professionals need patient consent to access medical information.
In emergency situations, when a patient is unconscious or unable to provide consent, verified healthcare professionals can use Emergency Break-Glass Access to retrieve only predefined critical information, such as allergies, medications, blood type, and critical medical conditions.
Every access event is recorded on the blockchain as an immutable audit trail.
How we built it
CAREID uses a hybrid Web2-Web3 architecture.
The frontend is designed for patients and healthcare professionals to manage digital identities, consent, medical information, and access requests.
The backend handles authentication, role-based access control, business logic, data encryption, and communication with the medical database.
Sensitive medical records are stored in an encrypted off-chain database using PostgreSQL/Supabase. Blockchain technology is used as a trusted layer through Solidity-based smart contracts to manage patient consent, authorization rules, emergency access, and access logs.
The system is designed so that sensitive medical records are not stored directly on the blockchain. Instead, the blockchain records the authorization and access activity required for accountability.
Challenges we ran into
Our main challenge was balancing fast emergency access with patient privacy.
Giving healthcare professionals unrestricted access could expose sensitive medical information, while requiring patient consent in every situation could become impractical when a patient is unconscious.
We addressed this challenge by designing the Break-Glass Access mechanism. Emergency access is limited to predefined critical information and requires verification of the healthcare professional and emergency-access rules. The access event is also recorded on the blockchain for accountability.
Another challenge was determining the appropriate role of blockchain. We learned that blockchain should not simply be used as a medical database. Instead, it is more suitable as a trusted layer for authorization, access control, and auditing.
Accomplishments that we're proud of
We are proud of developing a healthcare concept that combines Digital Medical Identity, encrypted medical records, smart contracts, and blockchain auditing into one system.
We also developed a clear distinction between normal and emergency access. This allows CAREID to protect patient privacy during normal situations while still providing a controlled mechanism for accessing critical information during emergencies.
Most importantly, we designed CAREID with a practical approach to blockchain: sensitive medical data remains off-chain, while blockchain is used where immutability, transparency, and accountability provide the most value.
What we learned
Through CAREID, we learned that solving a real-world problem with Web3 requires more than simply adding blockchain to an application.
We learned the importance of separating identity, authorization, data storage, and auditing.
We also learned that sensitive healthcare information should be protected through encrypted off-chain storage, while blockchain can provide a reliable mechanism for recording access and enforcing predefined authorization rules.
Most importantly, we learned that technology should adapt to the needs of users. In healthcare, security and privacy must be balanced with the need for timely access to critical information.
What's next for CAREID
Our next step is to develop a functional MVP of CAREID with the core features: Digital Medical Identity, secure medical records, consent-based access, Emergency Break-Glass Access, and blockchain-based access auditing.
In the future, CAREID could be expanded beyond a single hospital to connect hospitals, clinics, laboratories, pharmacies, and other healthcare facilities.
We also envision CAREID integrating with existing healthcare information systems and interoperability platforms, allowing it to become an additional identity, authorization, and audit layer rather than replacing existing healthcare infrastructure.
Built With
- blockchain
- encryption
- ethers.js
- evm
- express.js
- next.js
- node.js
- postgresql
- qr-code
- react
- rest-api
- smart-contracts
- solidity
- supabase
- tailwind-css
- viem
- web3
Log in or sign up for Devpost to join the conversation.