Inspiration

Medical records shouldn't require a fax machine to move between doctors, yet in 2024 that's still the norm for most patients. We kept coming back to the same statistic: over 133 million healthcare records were breached in 2023 alone, almost always because they were sitting unencrypted on some centralized server. At the same time, hospitals are racing to plug AI into clinical workflows — drug interaction checks, lab summarization — without asking what happens when a malicious string gets embedded inside a patient record and reaches that AI. We wanted to build the system we'd actually want our own medical history stored in: one where the patient holds the keys, not the hospital, and where AI can safely touch the data without being hijacked by it.

What it does

MediChain Shield lets patients encrypt their medical records client-side — in the browser, before anything ever touches our servers — using AES-256-GCM, with the symmetric key sealed to the recipient's X25519 public key via libsodium. Patients grant doctors time-bounded, revocable access (capped at 90 days) through an Ethereum smart contract, and can revoke that access instantly. Every grant, access, and revocation is logged as an immutable on-chain event, so there's a tamper-evident audit trail of exactly who saw what and when. On top of that, a 3-layer AI Guard sits between clinical AI features and the raw record data — scanning for prompt-injection patterns, wrapping untrusted content in isolation tags, and enforcing strict schema conformance on AI output — so the AI can help with clinical analysis without being tricked by adversarial content buried in a record.

How we built it

The frontend is Next.js 16 with the App Router, React 19, and Tailwind CSS v4, talking to an Express backend for wallet-challenge auth, IPFS relaying, and API proxying. The cryptography engine derives a deterministic X25519 keypair from an EIP-191 wallet signature via HKDF-SHA256, keeping private keys in volatile memory only. Records are encrypted with AES-256-GCM, binding the record ID as authenticated additional data to stop ciphertext-swap attacks between patients, then the AES key is wrapped with crypto_box_seal for the recipient. AccessRegistry.sol, written in Solidity and deployed with Hardhat to Ethereum Sepolia, handles the public key registry, record registration, grant/revoke logic, and EIP-712 gasless permits so patients can authorize access without paying gas. Encrypted bytes live on IPFS; the contract only ever stores hashes and wrapped keys. The AI Guard layer is a custom Node service that pre-screens inputs, sandboxes them in XML isolation tags, and validates AI output against a Zod schema before it's trusted.

Challenges we ran into

Binding the record ID as AAD in the AES-GCM encryption sounds simple but took real care to get right end-to-end — get it wrong and you either break legitimate decryption or leave a gap where one patient's ciphertext could be swapped for another's. Getting EIP-712 gasless permits working correctly with nonce and deadline validation, without opening a replay-attack window, took several iterations and a dedicated attack-simulation test suite to actually prove it was closed. On the AI Guard side, the hardest part wasn't catching obvious injection strings — it was catching obfuscated ones: base64-encoded payloads, hidden zero-width Unicode characters, and instructions disguised as clinical language.

Accomplishments that we're proud of

We didn't just build the happy path — we built 135 automated tests across the whole system: 36 for the cryptography engine, 38 for the smart contract, 44 for the AI Guard, and 17 dedicated adversarial attack simulations covering expired-grant denial, forged-grant rejection, replay-attack mitigation, and stolen-CID protection. Proving the system holds up under deliberate attack, not just demonstrating that it works, is what we're most proud of.

What we learned

Zero-knowledge architecture forces a different kind of discipline — you can't patch a privacy hole after the fact if the server never had the plaintext to begin with, so every design decision has to be right at the client boundary. We also learned that securing an AI feature isn't a bolt-on afterthought; it needs the same layered, adversarial-testing mindset as securing a smart contract, because the record itself is untrusted input the moment AI reads it.

What's next for MediChain Shield

We want to move from Sepolia testnet to a gas-optimized mainnet deployment with batched access grants, build an HL7/FHIR adapter so real hospital systems can bridge existing records in rather than requiring a clean-slate migration, and open up the AI Guard as a standalone integration for any clinical AI tool that needs to safely process untrusted patient data — not just ours.

Built With

Share this project:

Updates

Submission history