Rethinking Secure Patient Discovery: Matching Federation with Fine-Grained Consent

Johannes Lohmöller, Klaus Wehrle, Jan Pennekamp

Abstract

Electronic Health Records (EHRs) drive clinical care and medical research, yet hospitals, clinics, and research institutions routinely pool their records into central registries operated by a single party. Such centralization enlarges the attack surface, concentrates trust in the operator, and offers limited protection against misbehavior. Decentralized alternatives mitigate these risks but lack dynamic, fine-grained consent, and their multi-party protocols resist adaptation to this need. We present FeCaD, a deployable architecture that couples decentralized patient discovery through homomorphic encryption with dynamic, per-record consent enforcement. FeCaD allows researchers to submit encrypted predicates over distributed cohorts and to obtain encrypted indicator vectors of matching records without exposing sensitive attributes during processing. Distinctively, a per-query cryptographic consent token authorizes query classes against attribute subsets, replacing enrollment-time policies with cryptographic enforcement at evaluation time. We evaluate our open-source prototype across three representative cohorts, a clinical workload (MIMIC-IV), a domain-specific nuclear-medicine cohort, and a hospital-discharge benchmark (HCUP NIS), and find that consent-bound equality queries over 10 000 records complete on a single provider in 36 s. A hundred-provider federation returns within 14 min, placing biobank-scale discovery in the order of minutes.

Cite this paper
@inproceedings{2026-acsac,
  author = {Lohmöller, Johannes AND Wehrle, Klaus AND Pennekamp, Jan},
  title = {{Rethinking Secure Patient Discovery: Matching Federation with Fine-Grained Consent}},
  booktitle = {{Proceedings of the 42nd Annual Computer Security Applications Conference}},
  year = {2026},
  publisher = {{IEEE}},
  note = {{Accepted}},
}