Skip to main content
Download PDF
- Main
Development of the authentication and authorization processes for the iAgree portal, a platform for patient-controlled data sharing across health systems.
- Soohoo, Spencer;
- Keller, Michelle;
- Chen, Yunan;
- Hu, Di;
- Huang, Shao-Chi;
- Kuo, Tsung-Ting;
- Leder, Chloe;
- Lu, Xi;
- Meeker, Daniela;
- Morse, Brad;
- Moyse, Harold;
- Nagaraj, Gayathri;
- Nguyen, An;
- Schilling, Lisa;
- Soares, Andrey;
- Whooley, Mary;
- Zheng, Kai;
- Ohno-Machado, Lucila
Published Web Location
https://doi.org/10.1093/jamiaopen/ooag111Abstract
Objective
To develop the authentication and authorization module for iAgree, a privacy-preserving platform that enables patients to manage consent preferences and share electronic health record (EHR) data across multiple health systems with researchers. The consent and blockchain modules are described elsewhere.Materials and methods
We developed the authentication and authorization module of iAgree. This module supports account creation and cross-institution identity binding as part of the iAgree workflow to enable patients to authenticate using federated credentials (eg, Google, Facebook). Patients link their identities across institutions by signing into each participating health systems patient portal. Identity attributes retrieved via a Fast Healthcare Interoperability Resources (FHIR®) application programming interface (API) are cryptographically transformed into de-identified tokens so no raw identifiers are stored. Consent preferences are recorded immutably using blockchain technology. iAgree guides patients through account creation, cross-institution identity binding, and selection of granular data-sharing preferences. In this paper, we describe the design and implementation of the authentication and authorization modules, not the full workflow of the platform.Results
We installed the iAgree platform in a test or proof-of-concept environment at three health systems: Cedars-Sinai Medical Center, University of Colorado, and University of California, San Francisco. Functional testing with test patients demonstrated that authentication, identity binding, and secure multi-site record linkage could safely bind the identities of patients across sites, enabling patients to manage their data sharing consent preferences.Discussion
The results demonstrate the feasibility of a privacy-preserving multi-institutional data-sharing architecture that employs federated login, secure privacy-preserving multi-site record linkage, and blockchain-based consent tracking to align with privacy regulations while increasing transparency and patient autonomy.Conclusion
This effort demonstrated that the authentication and authorization module enables iAgree to be a feasible and secure platform for patient-directed sharing of EHR data across health systems with researchers. Future work will evaluate usability, patient engagement, and future real-world deployment.Many UC-authored scholarly publications are freely available on this site because of the UC's open access policies. Let us know how this access is important for you.