<?xml version="1.0" encoding="UTF-8"?>
<!DOCTYPE article PUBLIC "-//NLM//DTD Journal Publishing DTD v2.0 20040830//EN" "http://dtd.nlm.nih.gov/publishing/2.0/journalpublishing.dtd">
<article xmlns:xlink="http://www.w3.org/1999/xlink" article-type="review-article" dtd-version="2.0">
  <front>
    <journal-meta>
      <journal-id journal-id-type="publisher-id">JMIR</journal-id>
      <journal-id journal-id-type="nlm-ta">J Med Internet Res</journal-id>
      <journal-title>Journal of Medical Internet Research</journal-title>
      <issn pub-type="epub">1438-8871</issn>
      <publisher>
        <publisher-name>JMIR Publications</publisher-name>
        <publisher-loc>Toronto, Canada</publisher-loc>
      </publisher>
    </journal-meta>
    <article-meta>
      <article-id pub-id-type="publisher-id">v28i1e89574</article-id>
      <article-id pub-id-type="pmid">42190234</article-id>
      <article-id pub-id-type="doi">10.2196/89574</article-id>
      <article-categories>
        <subj-group subj-group-type="heading">
          <subject>Review</subject>
        </subj-group>
        <subj-group subj-group-type="article-type">
          <subject>Review</subject>
        </subj-group>
      </article-categories>
      <title-group>
        <article-title>Blockchain-Enabled Self-Sovereign Identity Applications in Health Care: Scoping Review</article-title>
      </title-group>
      <contrib-group>
        <contrib contrib-type="editor">
          <name>
            <surname>Zhuang</surname>
            <given-names>Yan</given-names>
          </name>
        </contrib>
      </contrib-group>
      <contrib-group>
        <contrib contrib-type="reviewer">
          <name>
            <surname>Krishnapatnam</surname>
            <given-names>Mahendra</given-names>
          </name>
        </contrib>
        <contrib contrib-type="reviewer">
          <name>
            <surname>Zandesh</surname>
            <given-names>Zahra</given-names>
          </name>
        </contrib>
        <contrib contrib-type="reviewer">
          <name>
            <surname>Akli</surname>
            <given-names>Assiya</given-names>
          </name>
        </contrib>
      </contrib-group>
      <contrib-group>
        <contrib id="contrib1" contrib-type="author" corresp="yes" equal-contrib="yes">
          <name name-style="western">
            <surname>Pokharel</surname>
            <given-names>Abha</given-names>
          </name>
          <degrees>MSc</degrees>
          <xref rid="aff1" ref-type="aff">1</xref>
          <address>
            <institution>Norwegian University of Science and Technology</institution>
            <addr-line>Gløshaugen, IT-bygget sydfløy, Sem Sælands vei 7</addr-line>
            <addr-line>Trondheim, Trøndelag, 7034</addr-line>
            <country>Norway</country>
            <phone>47 48619879</phone>
            <email>abha.pokharel@ntnu.no</email>
          </address>
          <ext-link ext-link-type="orcid">https://orcid.org/0009-0005-4841-0011</ext-link>
        </contrib>
        <contrib id="contrib2" contrib-type="author">
          <name name-style="western">
            <surname>Kathayat</surname>
            <given-names>Surya</given-names>
          </name>
          <degrees>PhD</degrees>
          <xref rid="aff1" ref-type="aff">1</xref>
          <ext-link ext-link-type="orcid">https://orcid.org/0009-0001-2615-1283</ext-link>
        </contrib>
      </contrib-group>
      <aff id="aff1">
        <label>1</label>
        <institution>Norwegian University of Science and Technology</institution>
        <addr-line>Trondheim, Trøndelag</addr-line>
        <country>Norway</country>
      </aff>
      <author-notes>
        <corresp>Corresponding Author: Abha Pokharel <email>abha.pokharel@ntnu.no</email></corresp>
      </author-notes>
      <pub-date pub-type="collection">
        <year>2026</year>
      </pub-date>
      <pub-date pub-type="epub">
        <day>26</day>
        <month>5</month>
        <year>2026</year>
      </pub-date>
      <volume>28</volume>
      <elocation-id>e89574</elocation-id>
      <history>
        <date date-type="received">
          <day>16</day>
          <month>12</month>
          <year>2025</year>
        </date>
        <date date-type="rev-request">
          <day>28</day>
          <month>2</month>
          <year>2026</year>
        </date>
        <date date-type="rev-recd">
          <day>1</day>
          <month>4</month>
          <year>2026</year>
        </date>
        <date date-type="accepted">
          <day>24</day>
          <month>4</month>
          <year>2026</year>
        </date>
      </history>
      <copyright-statement>©Abha Pokharel, Surya Kathayat. Originally published in the Journal of Medical Internet Research (https://www.jmir.org), 26.05.2026.</copyright-statement>
      <copyright-year>2026</copyright-year>
      <license license-type="open-access" xlink:href="https://creativecommons.org/licenses/by/4.0/">
        <p>This is an open-access article distributed under the terms of the Creative Commons Attribution License (https://creativecommons.org/licenses/by/4.0/), which permits unrestricted use, distribution, and reproduction in any medium, provided the original work, first published in the Journal of Medical Internet Research (ISSN 1438-8871), is properly cited. The complete bibliographic information, a link to the original publication on https://www.jmir.org/, as well as this copyright and license information must be included.</p>
      </license>
      <self-uri xlink:href="https://www.jmir.org/2026/1/e89574" xlink:type="simple"/>
      <abstract>
        <sec sec-type="background">
          <title>Background</title>
          <p>Self-sovereign identity (SSI) provides a decentralized approach to digital identity management, enabling individuals to control their personal data without reliance on centralized authorities. Blockchain technology offers a tamper-resistant and distributed infrastructure that can support secure and verifiable identity systems. In health care, where identity fragmentation, privacy risks, and interoperability challenges persist, blockchain-enabled SSI (BC-SSI) has been proposed as a potential solution. However, existing research remains heterogeneous, with varying levels of technical maturity and limited evidence of real-world deployment.</p>
        </sec>
        <sec sec-type="objective">
          <title>Objective</title>
          <p>This study conducts a scoping review to systematically map BC-SSI applications in health care and to analyze their application domains, development stages, study aims, targeted challenges, and technological infrastructures. In addition, this study aims to identify structural gaps in current research and assess the readiness of BC-SSI systems for clinical deployment.</p>
        </sec>
        <sec sec-type="methods">
          <title>Methods</title>
          <p>This review followed the PRISMA-ScR (Preferred Reporting Items for Systematic Reviews and Meta-Analyses Extension for Scoping Reviews) methodology. A comprehensive literature search conducted between September 2024 and August 2025 identified 37 peer-reviewed studies that met predefined inclusion criteria. Data were extracted and synthesized using descriptive and thematic analyses across application areas, system maturity, technological components, and reported challenges.</p>
        </sec>
        <sec sec-type="results">
          <title>Results</title>
          <p>The findings indicate that BC-SSI research in health care remains at an early stage of maturity, with most studies proposing conceptual models or prototype implementations and limited real-world validation. Applications predominantly focus on identity verification, credential management, and privacy-preserving data exchange across domains such as electronic health records, mobile health, and access control systems. Commonly used technologies include decentralized identifiers, verifiable credentials, smart contracts, and privacy-enhancing mechanisms such as zero-knowledge proofs and selective disclosure. Despite rapid technical development, persistent challenges include interoperability limitations, governance gaps, usability concerns, and insufficient integration with health care infrastructures. Notably, a structural gap was identified between technological capability and system-level readiness for clinical deployment.</p>
        </sec>
        <sec sec-type="conclusions">
          <title>Conclusions</title>
          <p>BC-SSI technologies demonstrate potential for enabling secure, interoperable, and patient-centric identity management in health care. However, current research is predominantly technology-driven and lacks sufficient system-level validation. This study highlights the need for integrated architectural approaches, governance frameworks, and real-world evaluation to bridge the gap between conceptual innovation and clinical implementation. Advancing BC-SSI toward health care adoption will require coordinated progress across technical, organizational, and regulatory dimensions.</p>
        </sec>
      </abstract>
      <kwd-group>
        <kwd>blockchain</kwd>
        <kwd>decentralization</kwd>
        <kwd>health care</kwd>
        <kwd>identity management</kwd>
        <kwd>privacy</kwd>
        <kwd>security</kwd>
        <kwd>self-sovereign identity</kwd>
      </kwd-group>
    </article-meta>
  </front>
  <body>
    <sec sec-type="introduction">
      <title>Introduction</title>
      <sec>
        <title>Overview</title>
        <p>Blockchain-enabled self-sovereign identity (SSI) applications in health care are attracting greater research attention as health data becomes increasingly digital and the need for secure, patient-focused identity management grows. Early blockchain projects in health care primarily focused on maintaining record immutability and enabling secure data exchange. More recently, researchers have explored the use of SSI to give patients greater control over their digital identities and health information [<xref ref-type="bibr" rid="ref1">1</xref>-<xref ref-type="bibr" rid="ref3">3</xref>]. The move from centralized to decentralized identity systems is driven by ongoing problems in current health care systems, such as limited interoperability, privacy risks, and fragmented access control [<xref ref-type="bibr" rid="ref4">4</xref>-<xref ref-type="bibr" rid="ref6">6</xref>]. These issues are especially evident in situations such as referrals, emergency care, and telehealth, where rapid and reliable identity verification is needed for effective clinical coordination [<xref ref-type="bibr" rid="ref7">7</xref>].</p>
        <p>The need for stronger digital identity systems is clear from the rise in health care data breaches. Growing regulatory demands, such as those under the General Data Protection Regulation (GDPR) and the Health Insurance Portability and Accountability Act (HIPAA), also underscore the need for better solutions [<xref ref-type="bibr" rid="ref1">1</xref>,<xref ref-type="bibr" rid="ref8">8</xref>,<xref ref-type="bibr" rid="ref9">9</xref>]. In this context, BC-SSI systems ensure this by enabling decentralized identity checks, secure credential management, and private data sharing among health care providers. Still, there are trade-offs between decentralization, scalability, governance, and system performance. These challenges are even more complex in regulated health care settings [<xref ref-type="bibr" rid="ref10">10</xref>,<xref ref-type="bibr" rid="ref11">11</xref>].</p>
        <p>Even though more research is being conducted on BC-SSI in health care, the studies remain scattered. Most studies focus on concepts or early prototypes [<xref ref-type="bibr" rid="ref1">1</xref>,<xref ref-type="bibr" rid="ref12">12</xref>,<xref ref-type="bibr" rid="ref13">13</xref>]. Few studies bring together architectural designs, technology choices, platforms, and governance to assess whether these systems are ready for real-world health care use. However, these studies have rarely examined how BC-SSI fits with clinical systems, regulations, and daily operations. As a result, there is an incomplete understanding of how practical these systems are in real-world health care settings. To fill this gap, this study makes 4 main contributions. First, it reviews peer-reviewed literature to map out BC-SSI applications in health care. Second, it looks at their technology, development stages, and use. Third, it brings together common architectural features. Fourth, it creates a layered architectural model and assesses the readiness of current BC-SSI systems for real-world health care and clinical use.</p>
      </sec>
      <sec>
        <title>Background</title>
        <sec>
          <title>SSI and Blockchain</title>
          <p>SSI is a decentralized identity model that enables individuals to create, manage, and selectively disclose digital credentials without reliance on centralized identity providers [<xref ref-type="bibr" rid="ref7">7</xref>,<xref ref-type="bibr" rid="ref13">13</xref>]. In SSI systems, identity attributes are not stored within institutional databases but are instead held by individuals as verifiable credentials (VCs), which can be presented when required. These systems operate within a trust framework involving issuers (eg, health care institutions), holders (eg, patients), and verifiers (eg, service providers), supported by governance mechanisms such as credential standards, trust registries, and revocation processes. In health care environments, traditional identity systems remain largely centralized and fragmented, requiring repeated identity verification across multiple organizations. This results in inefficiencies, data duplication, and increased risks of identity mismatch and unauthorized access, increasing vulnerability to data breaches. These limitations have driven interest in decentralized identity models such as SSI for health care applications.</p>
          <p>Blockchain technology provides the underlying infrastructure that supports SSI through immutable and verifiable record keeping [<xref ref-type="bibr" rid="ref10">10</xref>]. Within BC-SSI architectures, decentralized identifiers (DIDs) represent user-controlled identities, while VCs enable cryptographic validation of identity attributes without direct reliance on issuing authorities. Blockchain is typically used to anchor DID registries, credential schemas, and revocation mechanisms, while sensitive health data remains off chain to preserve privacy. This combination enables secure and tamper-evident identity verification across distributed health care systems. To operationalize these capabilities, BC-SSI architectures incorporate a set of supporting mechanisms. These include selective disclosure for controlled data sharing, zero-knowledge proofs (ZKPs) for privacy-preserving verification, and smart contracts for automated enforcement of access control and audit policies. Together, these mechanisms enable decentralized identity management while addressing key requirements of trust, security, and accountability in health care contexts.</p>
          <p>In studies of health care identity systems, security and privacy are closely related yet distinct concerns. Security focuses on ensuring confidentiality, integrity, and availability of identity and health data through mechanisms such as authentication and access control. Privacy emphasizes minimizing unnecessary disclosure of sensitive information and enabling individuals to control how their data are shared [<xref ref-type="bibr" rid="ref11">11</xref>,<xref ref-type="bibr" rid="ref12">12</xref>]. These concerns are particularly critical in health care due to the sensitivity of medical data and the complexity of cross-organizational data exchange [<xref ref-type="bibr" rid="ref1">1</xref>].</p>
        </sec>
        <sec>
          <title>SSI Frameworks and Blockchain Network Types</title>
          <p>SSI frameworks define the architectural components required for credential issuance, storage, verification, and trust management. Implementations commonly use platforms such as Hyperledger Indy and Aries to support decentralized identity registries and secure agent-based communication [<xref ref-type="bibr" rid="ref7">7</xref>,<xref ref-type="bibr" rid="ref12">12</xref>]. SSI architectures may operate on different blockchain network configurations depending on governance and trust requirements. Public (permissionless) networks such as Bitcoin and Ethereum enable unrestricted participation and transparent validation. Consortium networks restrict participation to authorized entities and are often deployed in multi-institutional collaborations. Private networks are centrally governed and typically implemented within a single organization. These models reflect varying trade-offs between decentralization, scalability, and governance control relevant to identity system design.</p>
        </sec>
        <sec>
          <title>Smart Contracts</title>
          <p>Smart contracts are programmable components deployed on blockchain platforms that automate identity-related operations. In health care contexts, they can enforce access control policies, manage consent conditions, and record auditable transaction logs without manual intervention [<xref ref-type="bibr" rid="ref13">13</xref>]. This supports transparent and accountable identity management across distributed health care systems.</p>
          <p>Despite increasing research activity in BC-SSI, existing studies remain heterogeneous in terms of application focus, architectural design, and implementation maturity. Many proposed solutions are limited to conceptual models or prototype implementations, with minimal evaluation in real-world health care environments. Furthermore, there is limited consolidated analysis of how BC-SSI mechanisms address health care-specific challenges such as interoperability, governance, and clinical workflow integration.</p>
          <p>To address this gap, this study conducts a scoping review to systematically map BC-SSI applications in health care, focusing on application domains, technological components, development stages, and the challenges these systems aim to address.</p>
        </sec>
      </sec>
    </sec>
    <sec sec-type="methods">
      <title>Methods</title>
      <sec>
        <title>Study Design</title>
        <p>We used the scoping review methodology to map existing proposals that integrate BC-SSI into health care. A scoping review is particularly appropriate because BC-SSI research is still an emerging area, conceptually diverse, and lacking consolidated empirical evidence. The review followed the framework of Arksey and O’Malley [<xref ref-type="bibr" rid="ref14">14</xref>], as enhanced by Levac et al [<xref ref-type="bibr" rid="ref15">15</xref>], and adhered to the PRISMA-ScR (Preferred Reporting Items for Systematic Reviews and Meta-Analyses Extension for Scoping Reviews) reporting guidelines [<xref ref-type="bibr" rid="ref16">16</xref>]. The completed PRISMA-ScR checklist is provided in <xref ref-type="supplementary-material" rid="app1">Multimedia Appendix 1</xref>. The methodology includes five stages: (1) defining research questions (RQs), (2) identifying relevant studies, (3) selecting eligible publications, (4) charting extracted data, and (5) synthesizing and reporting findings. The following 5 RQs guided the review:</p>
        <list list-type="bullet">
          <list-item>
            <p>RQ1: What BC-SSI application areas and data types are addressed in health care?</p>
          </list-item>
          <list-item>
            <p>RQ2: What development stages (proposal, architecture, and prototype) are used in BC-SSI studies?</p>
          </list-item>
          <list-item>
            <p>RQ3: What are the main aims of BC-SSI applications in health care?</p>
          </list-item>
          <list-item>
            <p>RQ4: What challenges do BC-SSI technologies aim to address?</p>
          </list-item>
          <list-item>
            <p>RQ5: What BC-SSI technologies, frameworks, and infrastructures are used?</p>
          </list-item>
        </list>
      </sec>
      <sec>
        <title>Search Strategy and Study Selection</title>
        <p>A comprehensive search was conducted across 6 databases, along with their distribution as illustrated in <xref ref-type="table" rid="table1">Table 1</xref>. Google Scholar was included to capture interdisciplinary publications that may not be indexed in domain-specific databases. The final search update was performed on August 15, 2025. Search strings combined free-text terms related to “self-sovereign identity,” “blockchain,” and “healthcare” using Boolean operators (“OR” within concept groups and “AND” between concept groups). Synonym groups (eg, health, eHealth, medical, hospital, and clinical) were expanded accordingly. Backward and forward snowballing were conducted to identify additional relevant studies [<xref ref-type="bibr" rid="ref17">17</xref>]. Full search strings are provided in <xref ref-type="supplementary-material" rid="app2">Multimedia Appendix 2</xref>. A total of 345 records were initially retrieved. The distribution of retrieved records by database is presented in <xref ref-type="table" rid="table1">Table 1</xref>.</p>
        <table-wrap position="float" id="table1">
          <label>Table 1</label>
          <caption>
            <p>Captured works of literature by source (N=345).</p>
          </caption>
          <table width="1000" cellpadding="5" cellspacing="0" border="1" rules="groups" frame="hsides">
            <col width="440"/>
            <col width="560"/>
            <thead>
              <tr valign="top">
                <td>Source</td>
                <td>Captured works, n</td>
              </tr>
            </thead>
            <tbody>
              <tr valign="top">
                <td>Scopus</td>
                <td>95</td>
              </tr>
              <tr valign="top">
                <td>Web of Science</td>
                <td>46</td>
              </tr>
              <tr valign="top">
                <td>Google Scholar</td>
                <td>133</td>
              </tr>
              <tr valign="top">
                <td>Embase</td>
                <td>19</td>
              </tr>
              <tr valign="top">
                <td>Medline</td>
                <td>13</td>
              </tr>
              <tr valign="top">
                <td>IEEE Xplore</td>
                <td>39</td>
              </tr>
            </tbody>
          </table>
        </table-wrap>
      </sec>
      <sec>
        <title>Eligibility Criteria and Study Selection</title>
        <p>Peer-reviewed studies published between 2015 and 2025 were considered eligible. Inclusion criteria included BC-SSI proposals addressing health domain problems (conceptual model, framework, proposal, prototype, experiment, implementation, and pilot), technical descriptions (eg, architecture, prototype, and framework), English-language peer-reviewed primary studies, and studies published between 2015 and 2025. Exclusion criteria included studies unrelated to health care, blockchain-only solutions without SSI components, nonprimary studies (eg, reviews and editorials) or abstract-only publications, and non-English publications.</p>
        <p>All references were imported into Zotero (Corporation for Digital Scholarship) for deduplication and screened using Rayyan [<xref ref-type="bibr" rid="ref18">18</xref>]. Two reviewers independently screened titles, abstracts, and full texts according to predefined criteria. Disagreements were resolved through discussion and consensus to ensure consistent interpretation.</p>
        <p>After duplicate removal and eligibility screening, 33 studies were retained. A total of 4 additional studies were identified through snowballing, resulting in 37 studies included in the final synthesis.</p>
      </sec>
      <sec>
        <title>Data Extraction and Charting</title>
        <p>Data were charted using a predefined extraction matrix consistent with PRISMA-ScR guidance. The first author performed data extraction, and the second author reviewed all entries. Discrepancies were resolved through discussion, and all final decisions were agreed jointly. The following data were extracted: general information, including author(s) ID and study; publication type, including journal, conference, proceedings, or book chapter; application area (eg, health records, mobile health [mHealth], wearable/embedded systems, health care services); data types handled (eg, medical data, credentials, vaccination records, and location data); and development stage, including proposal, architectural design, and prototype/experimental implementation.</p>
        <p>Extracted variables were mapped directly to the RQs: application areas and data types informed RQ1; development-stage classification addressed RQ2; thematic coding of study aims addressed RQ3; reported challenges informed RQ4; and BC-SSI–enabling technologies, blockchain platforms supporting SSI, blockchain types, smart contracts, and storage models were analyzed under RQ5.</p>
        <p>Following Petersen et al [<xref ref-type="bibr" rid="ref19">19</xref>], classification categories for application areas, data types, and development stages were iteratively developed and refined during the charting process. Categories were merged or adjusted as necessary to ensure conceptual consistency and reduce overlap across studies.</p>
      </sec>
      <sec>
        <title>Data Synthesis and Reporting</title>
        <p>After screening and data extraction, findings were synthesized descriptively and thematically, aligned with the 5 RQs (RQ1-RQ5). Descriptive statistics were used to summarize distributions across application areas, data types, development stages, and technological components. Thematic categorization was applied to study aims and reported challenges to identify recurring patterns across BC-SSI implementations. The complete list of included studies and their extracted characteristics is presented in the Results section.</p>
      </sec>
    </sec>
    <sec sec-type="results">
      <title>Results</title>
      <sec>
        <title>Overview of Included Studies</title>
        <p>A total of 37 studies met the inclusion criteria and were included in the final synthesis. <xref rid="figure1" ref-type="fig">Figure 1</xref> presents the PRISMA-ScR flow diagram summarizing the study selection process. <xref ref-type="table" rid="table2">Table 2</xref> presents the key characteristics of the included studies, including publication type, application area, data types addressed, and development stage.</p>
        <fig id="figure1" position="float">
          <label>Figure 1</label>
          <caption>
            <p>PRISMA-ScR (Preferred Reporting Items for Systematic Reviews and Meta-Analyses) flow diagram of study selection.</p>
          </caption>
          <graphic xlink:href="jmir_v28i1e89574_fig1.png" alt-version="no" mimetype="image" position="float" xlink:type="simple"/>
        </fig>
        <table-wrap position="float" id="table2">
          <label>Table 2</label>
          <caption>
            <p>Included research papers in the scoping review and their key characteristics.</p>
          </caption>
          <table width="1000" cellpadding="5" cellspacing="0" border="1" rules="groups" frame="hsides">
            <col width="40"/>
            <col width="300"/>
            <col width="260"/>
            <col width="200"/>
            <col width="200"/>
            <thead>
              <tr valign="top">
                <td>ID</td>
                <td>Study (type)</td>
                <td>Application area</td>
                <td>Data types</td>
                <td>Development stage</td>
              </tr>
            </thead>
            <tbody>
              <tr valign="top">
                <td>1</td>
                <td>Nasrin [<xref ref-type="bibr" rid="ref20">20</xref>] (conference)</td>
                <td>Health records</td>
                <td>Vaccination and credential</td>
                <td>Proposal</td>
              </tr>
              <tr valign="top">
                <td>2</td>
                <td>Hak et al [<xref ref-type="bibr" rid="ref21">21</xref>] (conference)</td>
                <td>Embedded and wearable systems</td>
                <td>Sensitive and credential</td>
                <td>Architecture</td>
              </tr>
              <tr valign="top">
                <td>3</td>
                <td>Fotopoulos et al [<xref ref-type="bibr" rid="ref22">22</xref>] (conference)</td>
                <td>Embedded and wearable systems</td>
                <td>Credential</td>
                <td>Proposal</td>
              </tr>
              <tr valign="top">
                <td>4</td>
                <td>Zou et al [<xref ref-type="bibr" rid="ref23">23</xref>] (journal)</td>
                <td>Embedded and wearable systems</td>
                <td>Credential</td>
                <td>Prototype/experimental</td>
              </tr>
              <tr valign="top">
                <td>5</td>
                <td>Bai et al [<xref ref-type="bibr" rid="ref24">24</xref>] (journal)</td>
                <td>Embedded and wearable systems</td>
                <td>Medical and credential</td>
                <td>Prototype/experimental</td>
              </tr>
              <tr valign="top">
                <td>6</td>
                <td>Bandara et al [<xref ref-type="bibr" rid="ref25">25</xref>] (conference)</td>
                <td>mHealth<sup>a</sup></td>
                <td>Location and sensitive</td>
                <td>Prototype/experimental</td>
              </tr>
              <tr valign="top">
                <td>7</td>
                <td>Kormiltsyn et al [<xref ref-type="bibr" rid="ref26">26</xref>] (conference)</td>
                <td>Health services</td>
                <td>Medical</td>
                <td>Architecture</td>
              </tr>
              <tr valign="top">
                <td>8</td>
                <td>Harrell et al [<xref ref-type="bibr" rid="ref12">12</xref>] (journal)</td>
                <td>mHealth</td>
                <td>Sensitive</td>
                <td>Architecture</td>
              </tr>
              <tr valign="top">
                <td>9</td>
                <td>George and Chacko [<xref ref-type="bibr" rid="ref27">27</xref>] (journal)</td>
                <td>mHealth</td>
                <td>Sensitive and credential</td>
                <td>Prototype/experimental</td>
              </tr>
              <tr valign="top">
                <td>10</td>
                <td>Sahi et al [<xref ref-type="bibr" rid="ref28">28</xref>] (conference)</td>
                <td>Health records</td>
                <td>Credential and sensitive</td>
                <td>Proposal</td>
              </tr>
              <tr valign="top">
                <td>11</td>
                <td>Kim et al [<xref ref-type="bibr" rid="ref29">29</xref>] (conference)</td>
                <td>mHealth</td>
                <td>Credential</td>
                <td>Architecture</td>
              </tr>
              <tr valign="top">
                <td>12</td>
                <td>Abid et al [<xref ref-type="bibr" rid="ref30">30</xref>] (journal)</td>
                <td>mHealth</td>
                <td>Sensitive</td>
                <td>Prototype/experimental</td>
              </tr>
              <tr valign="top">
                <td>13</td>
                <td>Popa et al [<xref ref-type="bibr" rid="ref31">31</xref>] (journal)</td>
                <td>Embedded and wearable systems</td>
                <td>Sensitive and credential</td>
                <td>Prototype/experimental</td>
              </tr>
              <tr valign="top">
                <td>14</td>
                <td>Saha et al [<xref ref-type="bibr" rid="ref32">32</xref>] (conference)</td>
                <td>Health records</td>
                <td>Credential</td>
                <td>Proposal</td>
              </tr>
              <tr valign="top">
                <td>15</td>
                <td>Rafid et al [<xref ref-type="bibr" rid="ref33">33</xref>] (conference)</td>
                <td>mHealth</td>
                <td>Credential and medical</td>
                <td>Proposal</td>
              </tr>
              <tr valign="top">
                <td>16</td>
                <td>Saragih et al [<xref ref-type="bibr" rid="ref4">4</xref>] (conference)</td>
                <td>Health records</td>
                <td>Sensitive and credential</td>
                <td>Proposal</td>
              </tr>
              <tr valign="top">
                <td>17</td>
                <td>Santos et al [<xref ref-type="bibr" rid="ref9">9</xref>] (journal)</td>
                <td>Health records</td>
                <td>Medical and credential</td>
                <td>Prototype/experimental</td>
              </tr>
              <tr valign="top">
                <td>18</td>
                <td>Song et al [<xref ref-type="bibr" rid="ref34">34</xref>] (journal)</td>
                <td>Embedded and wearable systems</td>
                <td>Sensitive and credential</td>
                <td>Prototype/experimental</td>
              </tr>
              <tr valign="top">
                <td>19</td>
                <td>Keil et al [<xref ref-type="bibr" rid="ref35">35</xref>] (conference)</td>
                <td>Embedded and wearable systems</td>
                <td>Credential</td>
                <td>Architecture</td>
              </tr>
              <tr valign="top">
                <td>20</td>
                <td>Freytsis et al [<xref ref-type="bibr" rid="ref36">36</xref>] (journal)</td>
                <td>Access control</td>
                <td>Credential</td>
                <td>Architecture</td>
              </tr>
              <tr valign="top">
                <td>21</td>
                <td>Zhuang et al [<xref ref-type="bibr" rid="ref37">37</xref>] (journal)</td>
                <td>mHealth</td>
                <td>Sensitive and credential</td>
                <td>Architecture</td>
              </tr>
              <tr valign="top">
                <td>22</td>
                <td>Al Muharif and Ahmed [<xref ref-type="bibr" rid="ref38">38</xref>] (conference)</td>
                <td>Health records</td>
                <td>Medical and credential</td>
                <td>Prototype/experimental</td>
              </tr>
              <tr valign="top">
                <td>23</td>
                <td>Pujari et al [<xref ref-type="bibr" rid="ref39">39</xref>] (conference)</td>
                <td>Health records</td>
                <td>Credential and sensitive</td>
                <td>Architecture</td>
              </tr>
              <tr valign="top">
                <td>24</td>
                <td>Tcholakian et al [<xref ref-type="bibr" rid="ref8">8</xref>] (journal)</td>
                <td>Health records</td>
                <td>Medical</td>
                <td>Architecture</td>
              </tr>
              <tr valign="top">
                <td>25</td>
                <td>Sami et al [<xref ref-type="bibr" rid="ref6">6</xref>] (conference)</td>
                <td>Health records</td>
                <td>Medical</td>
                <td>Proposal</td>
              </tr>
              <tr valign="top">
                <td>26</td>
                <td>Wang et al [<xref ref-type="bibr" rid="ref40">40</xref>] (journal)</td>
                <td>Health services</td>
                <td>Credential</td>
                <td>Prototype/experimental</td>
              </tr>
              <tr valign="top">
                <td>27</td>
                <td>Kang et al [<xref ref-type="bibr" rid="ref41">41</xref>] (journal)</td>
                <td>Health services</td>
                <td>Location and credential</td>
                <td>Architecture</td>
              </tr>
              <tr valign="top">
                <td>28</td>
                <td>Pujari et al [<xref ref-type="bibr" rid="ref42">42</xref>] (journal)</td>
                <td>Clinical research</td>
                <td>Credential</td>
                <td>Prototype/experimental</td>
              </tr>
              <tr valign="top">
                <td>29</td>
                <td>Manoj et al [<xref ref-type="bibr" rid="ref43">43</xref>] (journal)</td>
                <td>Health services</td>
                <td>Credential</td>
                <td>Prototype/experimental</td>
              </tr>
              <tr valign="top">
                <td>30</td>
                <td>Abubakar et al [<xref ref-type="bibr" rid="ref44">44</xref>] (conference)</td>
                <td>Health records</td>
                <td>Credential</td>
                <td>Prototype/experimental</td>
              </tr>
              <tr valign="top">
                <td>31</td>
                <td>Mchale et al [<xref ref-type="bibr" rid="ref45">45</xref>] (conference)</td>
                <td>Health records</td>
                <td>Vaccination</td>
                <td>Prototype/experimental</td>
              </tr>
              <tr valign="top">
                <td>32</td>
                <td>Guerar et al [<xref ref-type="bibr" rid="ref46">46</xref>] (journal)</td>
                <td>Health records</td>
                <td>Credential and medical</td>
                <td>Proposal</td>
              </tr>
              <tr valign="top">
                <td>33</td>
                <td>de Oliveira et al [<xref ref-type="bibr" rid="ref47">47</xref>] (conference)</td>
                <td>mHealth</td>
                <td>Credential and medical</td>
                <td>Prototype/experimental</td>
              </tr>
              <tr valign="top">
                <td>34</td>
                <td>Thirasak et al [<xref ref-type="bibr" rid="ref48">48</xref>] (journal)</td>
                <td>Health records</td>
                <td>Medical</td>
                <td>Prototype/experimental</td>
              </tr>
              <tr valign="top">
                <td>35</td>
                <td>Makina et al [<xref ref-type="bibr" rid="ref1">1</xref>] (conference)</td>
                <td>Health records</td>
                <td>Medical</td>
                <td>Architecture</td>
              </tr>
              <tr valign="top">
                <td>36</td>
                <td>Boi et al [<xref ref-type="bibr" rid="ref49">49</xref>] (journal)</td>
                <td>Health records</td>
                <td>Credential and medical</td>
                <td>Prototype/experimental</td>
              </tr>
              <tr valign="top">
                <td>37</td>
                <td>Saidi et al [<xref ref-type="bibr" rid="ref50">50</xref>] (journal)</td>
                <td>Health records</td>
                <td>Medical</td>
                <td>Prototype/experimental</td>
              </tr>
            </tbody>
          </table>
          <table-wrap-foot>
            <fn id="table2fn1">
              <p><sup>a</sup>mHealth: mobile health.</p>
            </fn>
          </table-wrap-foot>
        </table-wrap>
      </sec>
      <sec>
        <title>Descriptive Characteristics of Included Studies</title>
        <p>Across the 37 included studies, 49% (18/37) were conference publications and 51% (19/37) were journal articles. Google Scholar contributed the largest share of the initially retrieved records (133/345, 39%), whereas Embase contributed the smallest share (19/345, 6%). Among the final set of included publications, Scopus accounted for 65% (24/37) and IEEE Xplore for 19% (7/37). Publication activity peaked in 2022 for both conference papers (6/18, 33%) and journal papers (5/19, 26%), reflecting growing interest in BC-SSI solutions in health care.</p>
      </sec>
      <sec>
        <title>RQ1: BC-SSI Application Areas and Data Types</title>
        <p>The review identified 6 major BC-SSI application areas in health care. Health records constituted the largest category (16/37, 43%), encompassing applications related to personal health data management, medical record exchange, and credential verification. mHealth applications represented the second-largest category (8/37, 22%), reflecting the growing use of decentralized identity mechanisms in mHealth platforms and patient-facing applications.</p>
        <p>Embedded and wearable systems accounted for 19% (7/37) of the studies and included applications involving the Internet of Medical Things and smart medical devices. These systems often require secure device authentication and identity verification in distributed health care environments. The remaining application areas included health care services (4/37, 11%), clinical studies (1/37, 3%), and facility access control (1/37, 3%).</p>
        <p>The studies also addressed several types of health care–related data. Credential data were the most frequent type (27/37, 73%), highlighting the central role of identity verification and authorization in BC-SSI architectures. Medical and other sensitive personal data were commonly associated with health record management and wearable device applications. Location data appeared primarily in mHealth and contact-tracing scenarios, in which decentralized identity mechanisms were used to support privacy-preserving monitoring and verification.</p>
      </sec>
      <sec>
        <title>RQ2: Development Stages of BC-SSI Applications</title>
        <p>The reviewed studies demonstrate varying levels of development maturity in BC-SSI health care applications. Across 37 studies, 22% (8/37) presented conceptual proposals, 30% (11/37) provided architectural designs, and 49% (18/37) provided prototype or experimental implementations. Although more than one-half of the studies reported prototype-level implementations, most evaluations were limited to simulated environments or small-scale user testing, indicating early-stage technological validation. Only a small number reported real-world deployment or evaluation.</p>
      </sec>
      <sec>
        <title>RQ3: Aims of BC-SSI Studies</title>
        <p>Thematic analysis of the reviewed studies indicates that BC-SSI research is primarily driven by 3 major objectives. Privacy preservation was the most frequently reported aim, accounting for approximately 38% (14/37) of the studies, followed by secure data management (7/37, 19%) and patient-centric identity control (7/37, 19%). The distribution of these aims is summarized in <xref ref-type="table" rid="table3">Table 3</xref>.</p>
        <table-wrap position="float" id="table3">
          <label>Table 3</label>
          <caption>
            <p>Mapping of included studies to research objectives (research question 3 [RQ3]) and corresponding health care challenges (research question 4 [RQ4]).</p>
          </caption>
          <table width="1000" cellpadding="5" cellspacing="0" border="1" rules="groups" frame="hsides">
            <col width="40"/>
            <col width="560"/>
            <col width="400"/>
            <thead>
              <tr valign="top">
                <td>ID</td>
                <td>Study aim (RQ3)</td>
                <td>Challenges (RQ4)</td>
              </tr>
            </thead>
            <tbody>
              <tr valign="top">
                <td>1</td>
                <td>Vaccination verification and authentication</td>
                <td>I<sup>a</sup>, DI<sup>b</sup>, DP<sup>c</sup>, S<sup>d</sup></td>
              </tr>
              <tr valign="top">
                <td>2</td>
                <td>Anonymous cross-domain authentication</td>
                <td>I, P<sup>e</sup>, E<sup>f</sup>, DI, DP (IoMT<sup>g</sup>)</td>
              </tr>
              <tr valign="top">
                <td>3</td>
                <td>Device authentication and revocation (IoMT)</td>
                <td>DI, I, SC<sup>h</sup>, E, S</td>
              </tr>
              <tr valign="top">
                <td>4</td>
                <td>Privacy-aware authentication and data exchange</td>
                <td>I, DI, S, SC, E</td>
              </tr>
              <tr valign="top">
                <td>5</td>
                <td>Decentralized access control for health data</td>
                <td>AC<sup>i</sup>, SC, E, P, A<sup>j</sup></td>
              </tr>
              <tr valign="top">
                <td>6</td>
                <td>Privacy-aware contact tracing</td>
                <td>P, SC, I, T<sup>k</sup>, DP</td>
              </tr>
              <tr valign="top">
                <td>7</td>
                <td>Secure authentication for medical data exchange</td>
                <td>DM<sup>l</sup>, AC, S</td>
              </tr>
              <tr valign="top">
                <td>8</td>
                <td>Patient-centric data management and sharing</td>
                <td>IDM<sup>m</sup>, I, AC, A, DP</td>
              </tr>
              <tr valign="top">
                <td>9</td>
                <td>Credential issuance and access control</td>
                <td>AC, I, A, P, S, DP</td>
              </tr>
              <tr valign="top">
                <td>10</td>
                <td>Consent-based access control</td>
                <td>IDM, CM<sup>n</sup>, I, E, P, S</td>
              </tr>
              <tr valign="top">
                <td>11</td>
                <td>Identity tracking and transparency</td>
                <td>IDM, T, DP, A</td>
              </tr>
              <tr valign="top">
                <td>12</td>
                <td>Privacy-preserving certificate verification</td>
                <td>DI, DP, A, P</td>
              </tr>
              <tr valign="top">
                <td>13</td>
                <td>Consent-based identity sharing</td>
                <td>IDM, I, A, P, S</td>
              </tr>
              <tr valign="top">
                <td>14</td>
                <td>Decentralized credential verification</td>
                <td>IDM, P, S, E, DP, A</td>
              </tr>
              <tr valign="top">
                <td>15</td>
                <td>Identity management (rare diseases)</td>
                <td>IDM, S, E</td>
              </tr>
              <tr valign="top">
                <td>16</td>
                <td>Cross-institution authentication</td>
                <td>DM, S, P, I</td>
              </tr>
              <tr valign="top">
                <td>17</td>
                <td>Identity verification for service access</td>
                <td>DM, S, I, P</td>
              </tr>
              <tr valign="top">
                <td>18</td>
                <td>Identity management for users and devices</td>
                <td>IDM, A, P, S, DI</td>
              </tr>
              <tr valign="top">
                <td>19</td>
                <td>Attribute-based credential verification</td>
                <td>DM, A, P, S, I</td>
              </tr>
              <tr valign="top">
                <td>20</td>
                <td>Anti-profiling access control</td>
                <td>A, AC, P</td>
              </tr>
              <tr valign="top">
                <td>21</td>
                <td>Identity provisioning for newborns</td>
                <td>P, S</td>
              </tr>
              <tr valign="top">
                <td>22</td>
                <td>Patient-controlled identity and data</td>
                <td>P, S, I, A, E</td>
              </tr>
              <tr valign="top">
                <td>23</td>
                <td>Patient-centric credential preservation</td>
                <td>DM, P, A</td>
              </tr>
              <tr valign="top">
                <td>24</td>
                <td>Secure EHR<sup>o</sup> exchange</td>
                <td>DI, P, S, A</td>
              </tr>
              <tr valign="top">
                <td>25</td>
                <td>Fine-grained access control</td>
                <td>AC, P, S, E</td>
              </tr>
              <tr valign="top">
                <td>26</td>
                <td>Credential validation and access control</td>
                <td>IDM, P, S, A</td>
              </tr>
              <tr valign="top">
                <td>27</td>
                <td>Unlinkable contact tracing</td>
                <td>P, A, E</td>
              </tr>
              <tr valign="top">
                <td>28</td>
                <td>Identity verification for research access</td>
                <td>AC, IDM, I, DP, P</td>
              </tr>
              <tr valign="top">
                <td>29</td>
                <td>Secure identity validation</td>
                <td>IDM, DP, S, P, A</td>
              </tr>
              <tr valign="top">
                <td>30</td>
                <td>Identity management and authentication</td>
                <td>S, P, CM</td>
              </tr>
              <tr valign="top">
                <td>31</td>
                <td>Fraud-resistant certificate verification</td>
                <td>S, T, DP, A, DM</td>
              </tr>
              <tr valign="top">
                <td>32</td>
                <td>Identity recovery mechanisms</td>
                <td>IDM, S, A</td>
              </tr>
              <tr valign="top">
                <td>33</td>
                <td>Patient-centric data preservation</td>
                <td>IDM, P, I, A</td>
              </tr>
              <tr valign="top">
                <td>34</td>
                <td>Decentralized data access control</td>
                <td>P, S, AC, I</td>
              </tr>
              <tr valign="top">
                <td>35</td>
                <td>Transparent access control</td>
                <td>P, S, T</td>
              </tr>
              <tr valign="top">
                <td>36</td>
                <td>Scalable EHR access control</td>
                <td>S, E, SC</td>
              </tr>
              <tr valign="top">
                <td>37</td>
                <td>Privacy-aware access control</td>
                <td>AC, P, S, A</td>
              </tr>
            </tbody>
          </table>
          <table-wrap-foot>
            <fn id="table3fn1">
              <p><sup>a</sup>I: interoperability.</p>
            </fn>
            <fn id="table3fn2">
              <p><sup>b</sup>DI: data integrity.</p>
            </fn>
            <fn id="table3fn3">
              <p><sup>c</sup>DP: data provenance.</p>
            </fn>
            <fn id="table3fn4">
              <p><sup>d</sup>S: security.</p>
            </fn>
            <fn id="table3fn5">
              <p><sup>e</sup>P: privacy.</p>
            </fn>
            <fn id="table3fn6">
              <p><sup>f</sup>E: efficiency.</p>
            </fn>
            <fn id="table3fn7">
              <p><sup>g</sup>IoMT: Internet of Medical Things.</p>
            </fn>
            <fn id="table3fn8">
              <p><sup>h</sup>SC: scalability.</p>
            </fn>
            <fn id="table3fn9">
              <p><sup>i</sup>AC: access control.</p>
            </fn>
            <fn id="table3fn10">
              <p><sup>j</sup>A: autonomy.</p>
            </fn>
            <fn id="table3fn11">
              <p><sup>k</sup>T: transparency.</p>
            </fn>
            <fn id="table3fn12">
              <p><sup>l</sup>DM: data management.</p>
            </fn>
            <fn id="table3fn13">
              <p><sup>m</sup>IDM: identity management.</p>
            </fn>
            <fn id="table3fn14">
              <p><sup>n</sup>CM: consent management.</p>
            </fn>
            <fn id="table3fn15">
              <p><sup>o</sup>EHR: electronic health record.</p>
            </fn>
          </table-wrap-foot>
        </table-wrap>
        <p>Privacy-related aims focus on enabling controlled disclosure of identity and health-related attributes during verification and data exchange processes. Secure data management aims emphasize strengthening authentication, credential validation, and integrity assurance within health care systems. Patient-centric identity control aims are centered on enabling individuals to manage their digital identities, credentials, and consent in interactions with health care providers.</p>
        <p>Less frequently, studies addressed objectives such as secure electronic health record (EHR) exchange, prevention of identity traceability, rare-disease identity management, and research identity verification. Overall, these findings indicate that BC-SSI research is primarily oriented toward enhancing privacy and identity assurance, with comparatively less emphasis on system-level integration and interoperability.</p>
        <p>To explicitly link the study aim (RQ3) to the underlying health care challenges (RQ4), <xref ref-type="table" rid="table3">Table 3</xref> provides a structured mapping of each included study to its primary aims and the corresponding challenges it addressed.</p>
      </sec>
      <sec>
        <title>RQ4: Privacy and Security Challenges Addressed by BC-SSI</title>
        <p>Privacy (27/37, 73%) and security (26/37, 70%) were the most frequently addressed challenges across the reviewed studies. These reflect persistent limitations in traditional health care identity and data management systems.</p>
        <p>Privacy-related challenges primarily involve overdisclosure of sensitive patient information, limited user control over data sharing, and the risk of identity linkability across health care providers. For example, vaccination and health certification systems [<xref ref-type="bibr" rid="ref30">30</xref>,<xref ref-type="bibr" rid="ref45">45</xref>] address the need for attribute-level verification without exposing full identity records through selective disclosure and the use of VCs. Similarly, decentralized access control frameworks [<xref ref-type="bibr" rid="ref39">39</xref>,<xref ref-type="bibr" rid="ref40">40</xref>,<xref ref-type="bibr" rid="ref50">50</xref>] emphasize patient-controlled identity and consent management, while contact tracing and IoMT scenarios [<xref ref-type="bibr" rid="ref25">25</xref>,<xref ref-type="bibr" rid="ref41">41</xref>] focus on reducing identity traceability using pseudonymous identifiers and privacy-preserving verification mechanisms.</p>
        <p>Security-related challenges center on weak authentication, unauthorized data access, and risks of credential forgery and tampering in distributed health care environments. Cross-domain authentication schemes [<xref ref-type="bibr" rid="ref21">21</xref>-<xref ref-type="bibr" rid="ref23">23</xref>] address identity verification weaknesses across health care systems, whereas blockchain-based access control and audit mechanisms [<xref ref-type="bibr" rid="ref48">48</xref>,<xref ref-type="bibr" rid="ref50">50</xref>] enhance accountability and authorization. In addition, vaccination systems and fraud-resilient health care platforms [<xref ref-type="bibr" rid="ref30">30</xref>,<xref ref-type="bibr" rid="ref45">45</xref>,<xref ref-type="bibr" rid="ref47">47</xref>] mitigate credential forgery through VCs and immutable blockchain registries.</p>
        <p>Overall, the findings indicate that BC-SSI research is primarily driven by confidentiality, integrity, and identity assurance requirements, whereas challenges related to scalability and operational performance remain comparatively less explored.</p>
      </sec>
      <sec>
        <title>RQ5: BC-SSI Technologies and Infrastructures</title>
        <sec>
          <title>DIDs, VCs, and Digital Wallets</title>
          <p>Across the reviewed literature, DIDs serve as identity anchors for patients, providers, and devices, enabling portable, cryptographically verifiable claims across institutional boundaries, as illustrated in <xref rid="figure2" ref-type="fig">Figure 2</xref>. VCs encode health care attributes, including vaccination status, professional qualifications, and access permissions. Selective disclosure mechanisms were widely used to support privacy-preserving verification.</p>
          <fig id="figure2" position="float">
            <label>Figure 2</label>
            <caption>
              <p>Blockchain-Enabled Self-Sovereign Identity (BC-SSI) technologies applied in health care. DID: decentralized identifier; VC: verifiable credential.</p>
            </caption>
            <graphic xlink:href="jmir_v28i1e89574_fig2.png" alt-version="no" mimetype="image" position="float" xlink:type="simple"/>
          </fig>
          <p>Digital wallets were used to manage keys, credentials, and DID-based connections. Both custodial (server-managed) and noncustodial (client-side) models were observed, reflecting trade-offs between usability and security control.</p>
        </sec>
        <sec>
          <title>Blockchain Platforms Supporting SSI</title>
          <p>As illustrated in <xref ref-type="table" rid="table4">Table 4</xref> , Hyperledger Indy, often combined with Hyperledger Aries, was the most frequently reported SSI-supporting platform (10/37, 27%). Hyperledger Fabric (8/37, 22%) was commonly selected for permissioned consortium settings. Ethereum-based solutions (6/37, 16%) leveraged smart-contract programmability but raised privacy and cost concerns. Notably, 32% (12/37) of studies did not explicitly specify the BC platform, limiting reproducibility and comparative assessment.</p>
          <table-wrap position="float" id="table4">
            <label>Table 4</label>
            <caption>
              <p>Blockchain platforms and characteristics of blockchain-enabled self-sovereign identity (BC-SSI) implementations.</p>
            </caption>
            <table width="1000" cellpadding="5" cellspacing="0" border="1" rules="groups" frame="hsides">
              <col width="240"/>
              <col width="230"/>
              <col width="530"/>
              <thead>
                <tr valign="top">
                  <td>BC platform</td>
                  <td>Studies</td>
                  <td>Key characteristics</td>
                </tr>
              </thead>
              <tbody>
                <tr valign="top">
                  <td>Hyperledger Indy (often with Hyperledger Aries)</td>
                  <td>[<xref ref-type="bibr" rid="ref3">3</xref>], [<xref ref-type="bibr" rid="ref5">5</xref>], [<xref ref-type="bibr" rid="ref8">8</xref>], [<xref ref-type="bibr" rid="ref9">9</xref>], [<xref ref-type="bibr" rid="ref21">21</xref>], [<xref ref-type="bibr" rid="ref25">25</xref>], [<xref ref-type="bibr" rid="ref28">28</xref>], [<xref ref-type="bibr" rid="ref29">29</xref>], [<xref ref-type="bibr" rid="ref30">30</xref>]</td>
                  <td>Self-sovereign identity–oriented identity management, decentralized identifiers, verifiable credentials, and permissioned identity ecosystems</td>
                </tr>
                <tr valign="top">
                  <td>Hyperledger Fabric</td>
                  <td>[<xref ref-type="bibr" rid="ref1">1</xref>], [<xref ref-type="bibr" rid="ref49">49</xref>], [<xref ref-type="bibr" rid="ref10">10</xref>], [<xref ref-type="bibr" rid="ref11">11</xref>], [<xref ref-type="bibr" rid="ref13">13</xref>], [<xref ref-type="bibr" rid="ref15">15</xref>], [<xref ref-type="bibr" rid="ref29">29</xref>]</td>
                  <td>Permissioned consortium blockchain, modular architecture, enterprise access control, and privacy-preserving transactions</td>
                </tr>
                <tr valign="top">
                  <td>Hyperledger Besu</td>
                  <td>[<xref ref-type="bibr" rid="ref16">16</xref>]</td>
                  <td>Ethereum-compatible permissioned blockchain supporting enterprise deployment</td>
                </tr>
                <tr valign="top">
                  <td>Ethereum blockchain</td>
                  <td>[<xref ref-type="bibr" rid="ref7">7</xref>], [<xref ref-type="bibr" rid="ref8">8</xref>], [<xref ref-type="bibr" rid="ref10">10</xref>], [<xref ref-type="bibr" rid="ref19">19</xref>], [<xref ref-type="bibr" rid="ref31">31</xref>]</td>
                  <td>Smart contract programmability, decentralized application support, and public blockchain infrastructure</td>
                </tr>
                <tr valign="top">
                  <td>Not specified (N/A)</td>
                  <td>[<xref ref-type="bibr" rid="ref14">14</xref>], [<xref ref-type="bibr" rid="ref17">17</xref>], [<xref ref-type="bibr" rid="ref18">18</xref>], [<xref ref-type="bibr" rid="ref20">20</xref>], [<xref ref-type="bibr" rid="ref22">22</xref>], [<xref ref-type="bibr" rid="ref23">23</xref>], [<xref ref-type="bibr" rid="ref50">50</xref>], [<xref ref-type="bibr" rid="ref26">26</xref>], [<xref ref-type="bibr" rid="ref27">27</xref>], [<xref ref-type="bibr" rid="ref2">2</xref>], [<xref ref-type="bibr" rid="ref32">32</xref>]</td>
                  <td>Platform details not explicitly reported</td>
                </tr>
              </tbody>
            </table>
          </table-wrap>
        </sec>
        <sec>
          <title>Blockchain Types, Smart Contracts, and Storage Models</title>
          <p>Private or permissioned blockchains were used in approximately 51% (19/37) of the reviewed studies. Public blockchain and consortium models were reported less frequently, whereas 43% (16/37) of studies did not explicitly specify the blockchain type. Smart contracts were implemented in 43% (16/37) of studies, primarily for consent management, credential issuance, revocation, and access control.</p>
          <p>To reduce on-chain exposure of sensitive health data, 16% (6/37) of studies adopted a hybrid storage architecture. In these approaches, blockchain was used to store identifiers, hashes, or audit logs, whereas medical records were maintained off chain using distributed storage systems such as Interplanetary File System or institutional databases. Privacy-enhancing cryptographic techniques were reported in 35% (13/37) of studies, including ZKPs and selective-disclosure mechanisms that support attribute verification without revealing full data sets.</p>
        </sec>
      </sec>
      <sec>
        <title>Comparative Evaluation of BC-SSI Platforms</title>
        <p><xref ref-type="table" rid="table5">Table 5</xref> summarizes the comparative characteristics of BC-SSI platforms identified in the reviewed studies. Hyperledger Indy was most frequently used in identity-centric implementations and provides native support for DIDs and VCs. Hyperledger Fabric was commonly selected in permissioned consortium settings but does not natively implement World Wide Web Consortium DID/VC standards. Ethereum-based solutions provide programmability for smart contracts and public-chain deployment models. Hyperledger Besu supports both permissioned and public configurations and is Ethereum compatible. uPort, built on Ethereum, provides decentralized identity functionality through wallet-based implementations. A notable proportion of studies did not explicitly specify the underlying blockchain platform or SSI framework.</p>
        <table-wrap position="float" id="table5">
          <label>Table 5</label>
          <caption>
            <p>Comparative evaluation of blockchain-enabled self-sovereign identity (BC-SSI) platforms used in the literature.</p>
          </caption>
          <table width="1000" cellpadding="5" cellspacing="0" border="1" rules="groups" frame="hsides">
            <col width="140"/>
            <col width="80"/>
            <col width="80"/>
            <col width="140"/>
            <col width="120"/>
            <col width="220"/>
            <col width="220"/>
            <thead>
              <tr valign="top">
                <td>Framework</td>
                <td>DID<sup>a</sup></td>
                <td>VC<sup>b</sup></td>
                <td>Chain</td>
                <td>Smart contract</td>
                <td>Health care suitability</td>
                <td>Key limitations</td>
              </tr>
            </thead>
            <tbody>
              <tr valign="top">
                <td>Hyperledger Indy</td>
                <td>Strong</td>
                <td>Strong</td>
                <td>Permissioned</td>
                <td>Limited</td>
                <td>High (privacy-first and identity-centric)</td>
                <td>No general-purpose smart contracts</td>
              </tr>
              <tr valign="top">
                <td>Hyperledger Fabric</td>
                <td>Indirect</td>
                <td>Limited</td>
                <td>Permissioned</td>
                <td>Yes</td>
                <td>High (enterprise-grade and consortium use)</td>
                <td>No native DID/VC support</td>
              </tr>
              <tr valign="top">
                <td>Ethereum</td>
                <td>Strong</td>
                <td>Strong</td>
                <td>Public</td>
                <td>Yes</td>
                <td>Medium (high programmability)</td>
                <td>Gas fees and public ledger visibility</td>
              </tr>
              <tr valign="top">
                <td>Hyperledger Besu</td>
                <td>Strong</td>
                <td>Strong</td>
                <td>Permissioned or public</td>
                <td>Yes</td>
                <td>Medium-high</td>
                <td>Deployment and performance complexity</td>
              </tr>
              <tr valign="top">
                <td>uPort</td>
                <td>Strong</td>
                <td>Strong</td>
                <td>Public Ethereum</td>
                <td>Yes</td>
                <td>Medium</td>
                <td>Dependent on Ethereum scalability</td>
              </tr>
              <tr valign="top">
                <td>Not specified or custom models</td>
                <td>Varies</td>
                <td>Varies</td>
                <td>Mixed</td>
                <td>Varies</td>
                <td>Not assessable</td>
                <td>Low reproducibility and unclear stack</td>
              </tr>
            </tbody>
          </table>
          <table-wrap-foot>
            <fn id="table5fn1">
              <p><sup>a</sup>DID: decentralized identifier.</p>
            </fn>
            <fn id="table5fn2">
              <p><sup>b</sup>VC: verifiable credential.</p>
            </fn>
          </table-wrap-foot>
        </table-wrap>
        <p>Taken together, the technologies, infrastructures, and governance elements identified across the reviewed studies suggest that BC-SSI health care systems consist of several interacting technical and operational components. These recurring elements are synthesized into a conceptual layered architecture for BC-SSI deployment in health care contexts.</p>
      </sec>
    </sec>
    <sec sec-type="discussion">
      <title>Discussion</title>
      <sec>
        <title>Reflection on Principal Findings</title>
        <p>This scoping review identified 37 peer-reviewed studies investigating BC-SSI applications in health care, revealing a rapidly growing yet structurally fragmented research landscape and indicating uneven development across technical and operational dimensions. Although publication activity has increased substantially since 2020, most contributions remain conceptual models, architectural proposals, or prototype implementations evaluated in controlled environments. Large-scale deployments, cross-institutional pilots, and longitudinal evaluations remain rare. This demonstrates that current BC-SSI research remains largely disconnected from real-world health care implementation. This review addresses the identified gap by providing a system-level synthesis of BC-SSI architectures and their readiness for health care deployment.</p>
        <p>Across the reviewed literature, BC-SSI systems primarily focus on identity verification, credential management, consent-based access control, and privacy-preserving data exchange. These objectives correspond to longstanding challenges in health care identity management, including fragmented identity infrastructures and centralized trust models. However, a clear translational gap emerges between theoretical benefits and practical deployment, indicating that the proposed solutions have not yet been validated in operational health care settings. While many studies emphasize improved privacy, autonomy, and secure credential exchange, empirical evidence demonstrating integration with health care workflows, regulatory compliance, and cross-organizational interoperability remains limited, indicating insufficient evidence for real-world applicability and system-level integration.</p>
        <p>Importantly, technical feasibility does not necessarily translate into operational readiness. Although several studies demonstrate working credential issuance and verification workflows, most systems have not evaluated within real clinical environments or integrated with EHR infrastructures. As a result, the readiness of BC-SSI systems for operational health care deployment remains uncertain, highlighting a lack of clinical validation and feasibility.</p>
      </sec>
      <sec>
        <title>Security and Privacy Mechanism in Operational Context</title>
        <p>A recurring theme in the reviewed studies is the use of cryptographic mechanisms, including DIDs, VCs, selective disclosure, ZKPs, and smart contracts, to enhance privacy and security. However, these mechanisms are often discussed in the abstract without sufficiently examining their operational implications for health care systems, limiting understanding of their behavior in real-world health care settings. In a real health care setting, selective disclosure enables patients to demonstrate specific attributes, such as vaccination status and professional authorization, without revealing full identity records. ZKPs can support verification while minimizing unnecessary data exposure, potentially reducing the risk of large-scale data breaches. Smart contracts may automate consent enforcement and audit logging, theoretically enhancing traceability and accountability. Yet, these technical advantages introduce new risk vectors, demonstrating that enhanced privacy mechanisms may also increase system complexity and operational risk. Wallet compromise, key loss, credential revocation complexity, cross-institutional correlation attacks, and emergency override requirements represent unresolved operational challenges. Few studies systematically evaluate how these mechanisms perform under health care-specific constraints such as high patient turnover, emergency access demands, and strict compliance frameworks. Notably, to our knowledge, no studies have systematically evaluated these risks in emergency or high-pressure clinical scenarios, which represents a critical gap in the literature.</p>
        <p>While the BC-SSI architecture may mitigate risks associated with centralized identity repositories, it also redistributes responsibility between users and institutions, requiring careful governance and usability design. This trade-off demonstrates that security mechanisms must be evaluated not only for technical robustness but also for their impact on patient safety and clinical workflow reliability.</p>
      </sec>
      <sec>
        <title>Platform Selection and Architectural Trade-Offs</title>
        <p>The comparative evaluation of the blockchain platforms reveals significant architectural divergences. Hyperledger Indy, often combined with Aries, dominates identity-centric implementations because of its native support for DIDs and VCs. Permissioned platforms such as Hyperledger Fabric and Besu offer enterprise-grade governance and controlled participation models, aligning more naturally with regulated health care environments. Public Ethereum-based solutions provide programmability and a mature smart contract ecosystem but raise concerns about transaction transparency, scalability, and regulatory suitability. These choices are not merely technical preferences but reflect underlying governance assumptions, trust models, and regulatory constraints.</p>
        <p>In addition, nearly one-third of the studies failed to clearly specify their blockchain infrastructure, thereby limiting reproducibility and technical assessment. This lack of architectural transparency constitutes a methodological weakness in the current literature and limits the ability to assess the suitability of proposed solutions for real-world health care deployment. This demonstrates that platform selection is a critical architectural decision that directly shapes privacy guarantees, interoperability potential, and regulatory alignment.</p>
      </sec>
      <sec>
        <title>Stakeholder Implications and Systemic Constraints</title>
        <p>The potential of BC-SSI cannot be evaluated solely through a technical lens. Its feasibility depends on stakeholder alignment across patients, providers, regulators, and system developers.</p>
        <p>For patients, SSI promises granular control over identity attributes and consent. However, user-facing challenges, including wallet management, credential recovery, cognitive load, and emergency override procedures, are rarely evaluated through formal usability studies. For example, in acute care scenarios, delayed identity recovery or inaccessible credentials could directly affect continuity of care. The limited exploration of recovery frameworks and emergency access models represents a critical gap between conceptual autonomy and practical safety.</p>
        <p>For health care providers, integration with established clinical workflows remains largely unaddressed. Limited studies demonstrated integration with existing EHR or hospital information systems, or comprehensive alignment with standards such as Health Level Seven (HL7) and Fast Healthcare Interoperability Resources (FHIR). Without such integration, BC-SSI remains peripheral to routine care delivery, limiting its practical impact on health care operations.</p>
        <p>For regulators and policymakers, the distinction between technical privacy preservation and demonstrable legal compliance is crucial. Although the BC-SSI architecture conceptually aligns with GDPR and HIPAA principles, few studies have evaluated audit mechanisms, credential revocation governance, issuer accreditation models, or the legal enforceability of VCs. Governance design, particularly schema ownership, trust registries, and cross-jurisdictional interoperability, remains underdeveloped. This demonstrates that governance is a primary barrier to adoption rather than a secondary design consideration.</p>
        <p>Taken together, these findings indicate that BC-SSI maturity is constrained less by cryptographic capabilities than by governance, interoperability, and human-centered implementation challenges.</p>
      </sec>
      <sec>
        <title>Conceptual BC-SSI Health Care Architecture</title>
        <p>This section presents a novel contribution of this review by moving beyond descriptive analysis toward an integrated architectural perspective. The synthesis of the reviewed studies indicates that BC-SSI implementations in health care can be understood as a multilayered architecture integrating identity infrastructure, blockchain platforms, privacy-preserving mechanisms, health care system interoperability, and governance structures. While many studies emphasize decentralized identity technologies and cryptographic mechanisms, these components are often addressed in isolation rather than as integrated systems.</p>
        <p>Based on the recurring elements identified across the literature, <xref rid="figure3" ref-type="fig">Figure 3</xref> illustrates a conceptual BC-SSI health care architecture that synthesizes these patterns into a unified system-level perspective.</p>
        <fig id="figure3" position="float">
          <label>Figure 3</label>
          <caption>
            <p>Conceptual multilayered blockchain-enabled self-sovereign identity (BC-SSI) health care architecture. FHIR: Fast Healthcare Interoperability Resources; GDPR: General Data Protection Regulation; HIPAA: Health Insurance Portability and Accountability Act; HL7: Health Level Seven; IoT: internet of things.</p>
          </caption>
          <graphic xlink:href="jmir_v28i1e89574_fig3.png" alt-version="no" mimetype="image" position="float" xlink:type="simple"/>
        </fig>
        <p>At the foundational level, the identity layer includes DIDs, VCs, and digital wallets that enable patients, providers, and health care devices to manage decentralized digital identities. These identities are supported by the blockchain infrastructure layer, which maintains credential schemas, revocation registries, and verification records using distributed-ledger platforms such as Hyperledger Indy, Fabric, and Ethereum-based systems.</p>
        <p>A privacy and cryptographic layer enables secure verification through mechanisms such as selective disclosure, ZKPs, and cryptographic signatures, allowing health care attributes to be validated without exposing unnecessary personal data. These capabilities interact with the health care system integration layer, in which BC-SSI identity verification interfaces with EHR, hospital information systems, and health care interoperability standards such as HL7 and FHIR.</p>
        <p>Finally, a governance and compliance layer provides the regulatory and organizational framework necessary for health care adoption. This layer encompasses credential governance policies, issuer accreditation, trust registries, and compliance with regulatory frameworks such as GDPR and HIPAA.</p>
        <p>This layered perspective highlights that current research lacks a holistic architectural approach, limiting its ability to support end-to-end health care identity systems.</p>
      </sec>
      <sec>
        <title>From Prototype Innovation to Clinical Readiness</title>
        <p>When interpreted through the conceptual architecture illustrated in <xref rid="figure3" ref-type="fig">Figure 3</xref>, the findings reveal a structural imbalance in current BC-SSI health care research, with a disproportionate focus on technical components rather than system-level integration. Most reviewed studies concentrate on the lower layers of the architecture, particularly the identity and blockchain infrastructure layers, in which DIDs, VCs, and distributed ledger technologies have been widely implemented and experimentally validated.</p>
        <p>In contrast, the upper layers of architecture remain comparatively underdeveloped. Integration with clinical infrastructures, including EHR systems and interoperability standards such as HL7 and FHIR, is rarely demonstrated in existing prototypes. Similarly, governance mechanisms, including credential trust registries, issuer accreditation models, revocation governance, and regulatory alignment with frameworks such as GDPR and HIPAA, are frequently discussed conceptually but seldom implemented or evaluated in operational environments. This demonstrates that current research does not adequately address the requirements for real-world health care deployment.</p>
        <p>These observations suggest that the maturity of BC-SSI in health care is constrained less by cryptographic capability than by challenges related to governance design, interoperability alignment, and human-centered implementation. While technical innovation in decentralized identity and credential architectures is advancing rapidly, real-world health care deployment remains limited due to insufficient evaluation of cross-institution workflows, credential lifecycle management, emergency access mechanisms, and usability of patient-facing identity tools.</p>
        <p>Rather than evaluating BC-SSI systems solely in terms of functional capabilities, this review demonstrates that clinical readiness depends on system-level integration, governance alignment, and real-world validation. This indicates that the primary barrier to BC-SSI adoption is not technological feasibility but the absence of coordinated validation across technical, organizational, and regulatory dimensions.</p>
      </sec>
      <sec>
        <title>Synthesis Across Research Questions</title>
        <p>Taken together, the findings of this review provide a coherent response to the RQs. RQ1 and RQ2 are addressed by demonstrating that BC-SSI applications are concentrated in identity-centric use cases and remain largely at the conceptual or prototype stage, with limited progression toward real-world deployment. RQ3 is addressed by identifying the dominant study aims, particularly privacy preservation, secure data exchange, and patient-centric identity control. RQ4 is addressed by revealing that the challenges targeted by these studies, primarily privacy, security, and interoperability, are approached predominantly through technical mechanisms, with limited consideration of operational, governance, and integration constraints.</p>
        <p>The discussion further extends these findings by demonstrating that the key limitation of current BC-SSI research is not a lack of technical capability but the absence of system-level validation, governance alignment, and integration with health care infrastructures. This synthesis reinforces the central gap identified in this study and highlights the conditions necessary for advancing BC-SSI toward clinical readiness.</p>
      </sec>
      <sec>
        <title>Limitations</title>
        <p>This scoping review has several limitations. First, it included only peer-reviewed English-language publications from 2015 to 2025. Relevant gray literature, industrial white papers, pilot deployments, or non-English studies may therefore not be represented. Given the rapidly evolving nature of blockchain and SSI ecosystems, some practical implementations may exist outside academic reporting.</p>
        <p>Second, consistent with scoping review methodology, this study did not perform a formal quality appraisal or risk-of-bias assessment of included studies. The objective was to map the breadth and characteristics of BC-SSI research rather than evaluate intervention effectiveness. As a result, findings should be interpreted as a structured synthesis of existing proposals and implementations rather than a quantitative assessment of performance or security robustness.</p>
        <p>Third, heterogeneity in terminology across BC-SSI research may have influenced retrieval. Although comprehensive Boolean search strategies and snowballing were used, emerging terminology or alternative phrasing may have led to the exclusion of the relevant studies.</p>
        <p>Despite these limitations, adherence to the Arksey and O’Malley framework and PRISMA-ScR guidelines enhances transparency and reproducibility, providing a systematic overview of current BC-SSI health care research. The conceptual architecture presented in this study should therefore be interpreted as a synthesis derived from the reviewed literature rather than as an empirically validated system design.</p>
      </sec>
      <sec>
        <title>Implications and Future Research Directions</title>
        <p>The findings of this review have important implications for both research and practice. First, it demonstrates that advancing BC-SSI in health care requires a shift from technology-centric development toward system-level design and validation. While current studies successfully demonstrate cryptographic feasibility, their limited integration with health care workflows, governance frameworks, and regulatory requirements constrains their practical applicability. This suggests that future BC-SSI research must adopt a sociotechnical perspective that considers not only technical performance but also usability, interoperability, and organizational alignment.</p>
        <p>Second, the proposed conceptual architecture highlights the need for coordinated development across multiple layers, including identity infrastructure, blockchain platforms, privacy-preserving mechanisms, health care system integration, and governance frameworks. This layered perspective provides a structured foundation for designing and evaluating BC-SSI systems in health care and may serve as a reference model for future implementations.</p>
        <p>Future research should prioritize multi-institutional pilot deployments that evaluate BC-SSI systems under realistic health care conditions. This includes assessing interoperability across health care providers, integration with EHR systems, and alignment with established standards such as HL7 and FHIR. Longitudinal evaluations are particularly important for assessing system scalability, performance, and usability over time.</p>
        <p>Governance development represents a critical research frontier. Formal trust frameworks, credential schema governance models, revocation mechanisms, and issuer accreditation processes must be systematically designed and validated. In addition, regulatory mapping studies are required to explicitly align decentralized identity operations with frameworks such as GDPR and HIPAA, moving beyond conceptual compliance toward demonstrable accountability.</p>
        <p>Human-centered evaluation is equally essential. Future studies should examine usability challenges related to identity wallets, credential recovery, and emergency access mechanisms to ensure that patient autonomy does not compromise safety or continuity of care. Security assessments should also consider real-world threat scenarios, including wallet compromise, key loss, correlation attacks, and cross-institutional vulnerabilities.</p>
        <p>Collectively, these directions highlight that the future of BC-SSI in health care depends not only on advancing cryptographic techniques but also on achieving integration, governance maturity, and clinical validation.</p>
      </sec>
      <sec>
        <title>Conclusion</title>
        <p>This scoping review systematically analyzed 37 peer-reviewed studies investigating BC-SSI applications in health care. The findings indicate that, while research activity has increased significantly in recent years, the field remains characterized by conceptual and prototype-driven development, with limited evidence of real-world deployment or clinical validation. The review demonstrates that BC-SSI research is primarily focused on identity-centric use cases, including credential verification, authentication, and privacy-preserving data exchange. These applications directly address longstanding challenges in health care identity management, particularly those related to privacy, security, and fragmented trust models. However, a clear gap persists between technical capability and operational readiness.</p>
        <p>By synthesizing findings across studies, this review shows that the primary limitation of current BC-SSI research is not technological feasibility but the lack of integration with health care systems, governance frameworks, and regulatory requirements. This study therefore advances current literature by bridging the gap between fragmented technical proposals and system-level understanding required for health care implementation. This gap is further highlighted through the proposed conceptual multilayered architecture, which reveals a structural imbalance between well-developed technical components and underdeveloped system-level elements such as interoperability, governance, and clinical integration.</p>
        <p>In addressing the RQs, this study provides a comprehensive mapping of BC-SSI applications (RQ1), identifies their developmental maturity (RQ2), analyzes their primary aims (RQ3), and examines the challenges they seek to address (RQ4). Beyond descriptive synthesis, this review contributes an analytical perspective by reframing BC-SSI maturity in terms of translational readiness, emphasizing the importance of system-level validation and real-world applicability.</p>
        <p>BC-SSI technologies hold significant potential to enhance patient-centric identity management and secure data exchange in health care. However, their successful adoption will depend on coordinated progress across technical, organizational, and regulatory domains. Future research must therefore move beyond isolated technical innovation toward integrated, governance-aware, and clinically validated identity systems. Only through such efforts can BC-SSI transition from conceptual promise to a reliable foundation for health care identity infrastructures.</p>
      </sec>
    </sec>
  </body>
  <back>
    <app-group>
      <supplementary-material id="app1">
        <label>Multimedia Appendix 1</label>
        <p>PRISMA-ScR checklist.</p>
        <media xlink:href="jmir_v28i1e89574_app1.pdf" xlink:title="PDF File  (Adobe PDF File), 248 KB"/>
      </supplementary-material>
      <supplementary-material id="app2">
        <label>Multimedia Appendix 2</label>
        <p>Full search strings.</p>
        <media xlink:href="jmir_v28i1e89574_app2.docx" xlink:title="DOCX File , 14 KB"/>
      </supplementary-material>
    </app-group>
    <glossary>
      <title>Abbreviations</title>
      <def-list>
        <def-item>
          <term id="abb1">BC-SSI</term>
          <def>
            <p>blockchain-enabled SSI</p>
          </def>
        </def-item>
        <def-item>
          <term id="abb2">DID</term>
          <def>
            <p>decentralized identifier</p>
          </def>
        </def-item>
        <def-item>
          <term id="abb3">EHR</term>
          <def>
            <p>electronic health record</p>
          </def>
        </def-item>
        <def-item>
          <term id="abb4">FHIR</term>
          <def>
            <p>Fast Healthcare Interoperability Resources</p>
          </def>
        </def-item>
        <def-item>
          <term id="abb5">GDPR</term>
          <def>
            <p>General Data Protection Regulation</p>
          </def>
        </def-item>
        <def-item>
          <term id="abb6">HIPAA</term>
          <def>
            <p>Health Insurance Portability and Accountability Act</p>
          </def>
        </def-item>
        <def-item>
          <term id="abb7">HL7</term>
          <def>
            <p>Health Level Seven</p>
          </def>
        </def-item>
        <def-item>
          <term id="abb8">mHealth</term>
          <def>
            <p>mobile health</p>
          </def>
        </def-item>
        <def-item>
          <term id="abb9">PRISMA-ScR</term>
          <def>
            <p>Preferred Reporting Items for Systematic Reviews and Meta-Analyses Extension for Scoping Reviews</p>
          </def>
        </def-item>
        <def-item>
          <term id="abb10">RQ</term>
          <def>
            <p>research question</p>
          </def>
        </def-item>
        <def-item>
          <term id="abb11">SSI</term>
          <def>
            <p>self-sovereign identity</p>
          </def>
        </def-item>
        <def-item>
          <term id="abb12">VC</term>
          <def>
            <p>verifiable credential</p>
          </def>
        </def-item>
        <def-item>
          <term id="abb13">ZKP</term>
          <def>
            <p>zero-knowledge proof</p>
          </def>
        </def-item>
      </def-list>
    </glossary>
    <notes>
      <sec>
        <title>Funding</title>
        <p>This study received no external funding.</p>
      </sec>
    </notes>
    <notes>
      <sec>
        <title>Data Availability</title>
        <p>All data analyzed in this study were derived from published peer-reviewed literature. The extracted data supporting the findings of this study are available from the corresponding author on reasonable request.</p>
      </sec>
    </notes>
    <fn-group>
      <fn fn-type="con">
        <p>AP conceptualized the study, designed the methodology, conducted the literature search and screening, performed data extraction and analysis, created the visualizations, and drafted the original manuscript. SK contributed to the study design, critically reviewed and edited the manuscript, and provided supervision and methodological guidance. Both authors reviewed and approved the final version of the manuscript.</p>
      </fn>
      <fn fn-type="conflict">
        <p>None declared.</p>
      </fn>
    </fn-group>
    <ref-list>
      <ref id="ref1">
        <label>1</label>
        <nlm-citation citation-type="confproc">
          <person-group person-group-type="author">
            <name name-style="western">
              <surname>Makina</surname>
              <given-names>H</given-names>
            </name>
            <name name-style="western">
              <surname>Letaifa</surname>
              <given-names>AB</given-names>
            </name>
            <name name-style="western">
              <surname>Rachedi</surname>
              <given-names>A</given-names>
            </name>
          </person-group>
          <article-title>A blockchain and self-sovereign identity-based platform for electronic health records management under GDPR</article-title>
          <year>2024</year>
          <conf-name>Proceedings of the 2024 20th International Conference on Wireless and Mobile Computing, Networking and Communications (WiMob)</conf-name>
          <conf-date>October 21-23, 2024</conf-date>
          <conf-loc>Paris</conf-loc>
          <publisher-name>IEEE</publisher-name>
          <fpage>118</fpage>
          <lpage>123</lpage>
          <pub-id pub-id-type="doi">10.1109/wimob61911.2024.10770361</pub-id>
        </nlm-citation>
      </ref>
      <ref id="ref2">
        <label>2</label>
        <nlm-citation citation-type="confproc">
          <person-group person-group-type="author">
            <name name-style="western">
              <surname>Honório da Silva</surname>
              <given-names>ML</given-names>
            </name>
            <name name-style="western">
              <surname>Velasco</surname>
              <given-names>G</given-names>
            </name>
            <name name-style="western">
              <surname>Pimentel</surname>
              <given-names>VN</given-names>
            </name>
            <name name-style="western">
              <surname>Martins</surname>
              <given-names>M</given-names>
            </name>
            <name name-style="western">
              <surname>Ribeiro</surname>
              <given-names>GSP</given-names>
            </name>
            <name name-style="western">
              <surname>Carvalho</surname>
              <given-names>ST</given-names>
            </name>
          </person-group>
          <article-title>Blockchain and self-sovereign identity: a healthcare use case</article-title>
          <year>2025</year>
          <conf-name>Proceedings of the Workshop em Blockchain: Teoria, Tecnologias e Aplicações (WBlockchain)</conf-name>
          <conf-date>May 19-22, 2025</conf-date>
          <conf-loc>Natal, Rio Grande do Norte</conf-loc>
          <fpage>154</fpage>
          <lpage>167</lpage>
          <pub-id pub-id-type="doi">10.5753/wblockchain.2025.9506</pub-id>
        </nlm-citation>
      </ref>
      <ref id="ref3">
        <label>3</label>
        <nlm-citation citation-type="journal">
          <person-group person-group-type="author">
            <name name-style="western">
              <surname>Yue</surname>
              <given-names>X</given-names>
            </name>
            <name name-style="western">
              <surname>Wang</surname>
              <given-names>H</given-names>
            </name>
            <name name-style="western">
              <surname>Jin</surname>
              <given-names>D</given-names>
            </name>
            <name name-style="western">
              <surname>Li</surname>
              <given-names>M</given-names>
            </name>
            <name name-style="western">
              <surname>Jiang</surname>
              <given-names>W</given-names>
            </name>
          </person-group>
          <article-title>Healthcare data gateways: found healthcare intelligence on blockchain with novel privacy risk control</article-title>
          <source>J Med Syst</source>
          <year>2016</year>
          <volume>40</volume>
          <issue>10</issue>
          <fpage>218</fpage>
          <pub-id pub-id-type="doi">10.1007/s10916-016-0574-6</pub-id>
          <pub-id pub-id-type="medline">27565509</pub-id>
          <pub-id pub-id-type="pii">10.1007/s10916-016-0574-6</pub-id>
        </nlm-citation>
      </ref>
      <ref id="ref4">
        <label>4</label>
        <nlm-citation citation-type="confproc">
          <person-group person-group-type="author">
            <name name-style="western">
              <surname>Saragih</surname>
              <given-names>TK</given-names>
            </name>
            <name name-style="western">
              <surname>Tanuwijaya</surname>
              <given-names>E</given-names>
            </name>
            <name name-style="western">
              <surname>Wang</surname>
              <given-names>G</given-names>
            </name>
          </person-group>
          <article-title>The use of blockchain for digital identity management in healthcare</article-title>
          <year>2022</year>
          <conf-name>Proceedings of the 2022 10th International Conference on Cyber and IT Service Management (CITSM)</conf-name>
          <conf-date>September 20-21, 2022</conf-date>
          <conf-loc>Yogyakarta</conf-loc>
          <publisher-name>IEEE</publisher-name>
          <fpage>1</fpage>
          <lpage>6</lpage>
          <pub-id pub-id-type="doi">10.1109/citsm56380.2022.9935935</pub-id>
        </nlm-citation>
      </ref>
      <ref id="ref5">
        <label>5</label>
        <nlm-citation citation-type="journal">
          <person-group person-group-type="author">
            <name name-style="western">
              <surname>Al Mamun</surname>
              <given-names>A</given-names>
            </name>
            <name name-style="western">
              <surname>Azam</surname>
              <given-names>S</given-names>
            </name>
            <name name-style="western">
              <surname>Gritti</surname>
              <given-names>C</given-names>
            </name>
          </person-group>
          <article-title>Blockchain-based electronic health records management: a comprehensive review and future research direction</article-title>
          <source>IEEE Access</source>
          <year>2022</year>
          <volume>10</volume>
          <fpage>5768</fpage>
          <lpage>5789</lpage>
          <pub-id pub-id-type="doi">10.1109/access.2022.3141079</pub-id>
        </nlm-citation>
      </ref>
      <ref id="ref6">
        <label>6</label>
        <nlm-citation citation-type="book">
          <person-group person-group-type="author">
            <name name-style="western">
              <surname>Sami</surname>
              <given-names>KT</given-names>
            </name>
            <name name-style="western">
              <surname>Toorani</surname>
              <given-names>M</given-names>
            </name>
          </person-group>
          <person-group person-group-type="editor">
            <name name-style="western">
              <surname>Abie</surname>
              <given-names>H</given-names>
            </name>
            <name name-style="western">
              <surname>Gkioulos</surname>
              <given-names>V</given-names>
            </name>
            <name name-style="western">
              <surname>Katsikas</surname>
              <given-names>S</given-names>
            </name>
            <name name-style="western">
              <surname>Pirbhulal</surname>
              <given-names>S</given-names>
            </name>
          </person-group>
          <article-title>Blockchain-based access control for electronic health records</article-title>
          <source>Secure and Resilient Digital Transformation of Healthcare</source>
          <year>2024</year>
          <publisher-loc>Cham</publisher-loc>
          <publisher-name>Springer</publisher-name>
          <fpage>1884</fpage>
        </nlm-citation>
      </ref>
      <ref id="ref7">
        <label>7</label>
        <nlm-citation citation-type="journal">
          <person-group person-group-type="author">
            <name name-style="western">
              <surname>Siqueira</surname>
              <given-names>A</given-names>
            </name>
            <name name-style="western">
              <surname>da Conceição</surname>
              <given-names>AF</given-names>
            </name>
            <name name-style="western">
              <surname>Rocha</surname>
              <given-names>V</given-names>
            </name>
          </person-group>
          <article-title>Blockchains and self-sovereign identities applied to healthcare solutions: a systematic review</article-title>
          <source>ArXiv</source>
          <comment>Preprint posted online on April 26, 2021</comment>
          <pub-id pub-id-type="doi">10.48550/arXiv.2104.12298</pub-id>
        </nlm-citation>
      </ref>
      <ref id="ref8">
        <label>8</label>
        <nlm-citation citation-type="journal">
          <person-group person-group-type="author">
            <name name-style="western">
              <surname>Tcholakian</surname>
              <given-names>M</given-names>
            </name>
            <name name-style="western">
              <surname>Gorna</surname>
              <given-names>K</given-names>
            </name>
            <name name-style="western">
              <surname>Laurent</surname>
              <given-names>M</given-names>
            </name>
            <name name-style="western">
              <surname>Kaffel Ben Ayed</surname>
              <given-names>H</given-names>
            </name>
            <name name-style="western">
              <surname>Naghmouchi</surname>
              <given-names>M</given-names>
            </name>
          </person-group>
          <article-title>Self-sovereign identity for consented and content-based access to medical records using blockchain</article-title>
          <source>Security and Communication Networks</source>
          <year>2023</year>
          <volume>2023</volume>
          <fpage>6025789</fpage>
          <pub-id pub-id-type="doi">10.1155/2023/6025789</pub-id>
        </nlm-citation>
      </ref>
      <ref id="ref9">
        <label>9</label>
        <nlm-citation citation-type="journal">
          <person-group person-group-type="author">
            <name name-style="western">
              <surname>de R dos Santos</surname>
              <given-names>Y</given-names>
            </name>
            <name name-style="western">
              <surname>de Oliveira</surname>
              <given-names>NR</given-names>
            </name>
            <name name-style="western">
              <surname>Barbosa</surname>
              <given-names>GNN</given-names>
            </name>
            <name name-style="western">
              <surname>Reis</surname>
              <given-names>LHA</given-names>
            </name>
            <name name-style="western">
              <surname>Mendes</surname>
              <given-names>ACR</given-names>
            </name>
            <name name-style="western">
              <surname>de Oliveira</surname>
              <given-names>MT</given-names>
            </name>
            <name name-style="western">
              <surname>de Medeiros</surname>
              <given-names>DSV</given-names>
            </name>
            <name name-style="western">
              <surname>Mattos</surname>
              <given-names>DMF</given-names>
            </name>
          </person-group>
          <article-title>Decentralized security in blockchain-based digital health systems: self-sovereign identity, access control, and auditing with smart contracts</article-title>
          <source>Cluster Comput</source>
          <year>2025</year>
          <volume>28</volume>
          <issue>15</issue>
          <fpage>940</fpage>
          <pub-id pub-id-type="doi">10.1007/s10586-025-05669-3</pub-id>
        </nlm-citation>
      </ref>
      <ref id="ref10">
        <label>10</label>
        <nlm-citation citation-type="journal">
          <person-group person-group-type="author">
            <name name-style="western">
              <surname>Martínez</surname>
              <given-names>AL</given-names>
            </name>
            <name name-style="western">
              <surname>Naghmouchi</surname>
              <given-names>M</given-names>
            </name>
            <name name-style="western">
              <surname>Laurent</surname>
              <given-names>M</given-names>
            </name>
          </person-group>
          <article-title>Empower healthcare through a self-sovereign identity infrastructure for secure electronic health data access</article-title>
          <source>ArXiv</source>
          <comment>Preprint posted online on January 21, 2025</comment>
          <pub-id pub-id-type="doi">10.48550/arXiv.2501.12229</pub-id>
        </nlm-citation>
      </ref>
      <ref id="ref11">
        <label>11</label>
        <nlm-citation citation-type="journal">
          <person-group person-group-type="author">
            <name name-style="western">
              <surname>Torongo</surname>
              <given-names>AA</given-names>
            </name>
            <name name-style="western">
              <surname>Toorani</surname>
              <given-names>M</given-names>
            </name>
          </person-group>
          <article-title>Blockchain-based decentralized identity management for healthcare systems</article-title>
          <source>ArXiv</source>
          <comment>Preprint posted online on July 31, 2023</comment>
          <pub-id pub-id-type="doi">10.48550/arXiv.2307.16239</pub-id>
        </nlm-citation>
      </ref>
      <ref id="ref12">
        <label>12</label>
        <nlm-citation citation-type="journal">
          <person-group person-group-type="author">
            <name name-style="western">
              <surname>Harrell</surname>
              <given-names>DT</given-names>
            </name>
            <name name-style="western">
              <surname>Usman</surname>
              <given-names>M</given-names>
            </name>
            <name name-style="western">
              <surname>Hanson</surname>
              <given-names>L</given-names>
            </name>
            <name name-style="western">
              <surname>Abdul-Moheeth</surname>
              <given-names>M</given-names>
            </name>
            <name name-style="western">
              <surname>Desai</surname>
              <given-names>I</given-names>
            </name>
            <name name-style="western">
              <surname>Shriram</surname>
              <given-names>J</given-names>
            </name>
          </person-group>
          <article-title>Technical design and development of a self-sovereign identity management platform for patient-centric health care using blockchain technology</article-title>
          <source>Blockchain Healthc Today</source>
          <year>2022</year>
          <volume>5</volume>
          <comment>
            <ext-link ext-link-type="uri" xlink:type="simple" xlink:href="https://europepmc.org/abstract/MED/36779027"/>
          </comment>
          <pub-id pub-id-type="doi">10.30953/bhty.v5.196</pub-id>
          <pub-id pub-id-type="medline">36779027</pub-id>
          <pub-id pub-id-type="pii">196</pub-id>
          <pub-id pub-id-type="pmcid">PMC9907400</pub-id>
        </nlm-citation>
      </ref>
      <ref id="ref13">
        <label>13</label>
        <nlm-citation citation-type="book">
          <person-group person-group-type="author">
            <name name-style="western">
              <surname>Kumar</surname>
              <given-names>D</given-names>
            </name>
          </person-group>
          <article-title>Blockchain technology for healthcare and self-sovereign identity</article-title>
          <source>Blockchain Technology for Cyber Defense, Cybersecurity, and Countermeasures</source>
          <year>2025</year>
          <publisher-loc>Boca Raton</publisher-loc>
          <publisher-name>CRC Press</publisher-name>
          <fpage>69</fpage>
          <lpage>93</lpage>
        </nlm-citation>
      </ref>
      <ref id="ref14">
        <label>14</label>
        <nlm-citation citation-type="journal">
          <person-group person-group-type="author">
            <name name-style="western">
              <surname>Arksey</surname>
              <given-names>H</given-names>
            </name>
            <name name-style="western">
              <surname>O'Malley</surname>
              <given-names>L</given-names>
            </name>
          </person-group>
          <article-title>Scoping studies: towards a methodological framework</article-title>
          <source>Int J Soc Res Methodol</source>
          <year>2005</year>
          <volume>8</volume>
          <issue>1</issue>
          <fpage>19</fpage>
          <lpage>32</lpage>
          <pub-id pub-id-type="doi">10.1080/1364557032000119616</pub-id>
        </nlm-citation>
      </ref>
      <ref id="ref15">
        <label>15</label>
        <nlm-citation citation-type="journal">
          <person-group person-group-type="author">
            <name name-style="western">
              <surname>Levac</surname>
              <given-names>D</given-names>
            </name>
            <name name-style="western">
              <surname>Colquhoun</surname>
              <given-names>H</given-names>
            </name>
            <name name-style="western">
              <surname>O'Brien</surname>
              <given-names>KK</given-names>
            </name>
          </person-group>
          <article-title>Scoping studies: advancing the methodology</article-title>
          <source>Implement Sci</source>
          <year>2010</year>
          <volume>5</volume>
          <fpage>69</fpage>
          <comment>
            <ext-link ext-link-type="uri" xlink:type="simple" xlink:href="https://implementationscience.biomedcentral.com/articles/10.1186/1748-5908-5-69"/>
          </comment>
          <pub-id pub-id-type="doi">10.1186/1748-5908-5-69</pub-id>
          <pub-id pub-id-type="medline">20854677</pub-id>
          <pub-id pub-id-type="pii">1748-5908-5-69</pub-id>
          <pub-id pub-id-type="pmcid">PMC2954944</pub-id>
        </nlm-citation>
      </ref>
      <ref id="ref16">
        <label>16</label>
        <nlm-citation citation-type="journal">
          <person-group person-group-type="author">
            <name name-style="western">
              <surname>Tricco</surname>
              <given-names>AC</given-names>
            </name>
            <name name-style="western">
              <surname>Zarin</surname>
              <given-names>W</given-names>
            </name>
            <name name-style="western">
              <surname>Ghassemi</surname>
              <given-names>M</given-names>
            </name>
            <name name-style="western">
              <surname>Nincic</surname>
              <given-names>V</given-names>
            </name>
            <name name-style="western">
              <surname>Lillie</surname>
              <given-names>E</given-names>
            </name>
            <name name-style="western">
              <surname>Page</surname>
              <given-names>MJ</given-names>
            </name>
          </person-group>
          <article-title>Same family, different species: methodological conduct and quality varies according to purpose for five types of knowledge synthesis</article-title>
          <source>J Clin Epidemiol</source>
          <year>2018</year>
          <volume>96</volume>
          <fpage>133</fpage>
          <lpage>142</lpage>
          <pub-id pub-id-type="doi">10.1016/j.jclinepi.2017.10.014</pub-id>
          <pub-id pub-id-type="medline">29103958</pub-id>
          <pub-id pub-id-type="pii">S0895-4356(17)30191-9</pub-id>
        </nlm-citation>
      </ref>
      <ref id="ref17">
        <label>17</label>
        <nlm-citation citation-type="journal">
          <person-group person-group-type="author">
            <name name-style="western">
              <surname>Levy</surname>
              <given-names>Y</given-names>
            </name>
            <name name-style="western">
              <surname>Ellis</surname>
              <given-names>TJ</given-names>
            </name>
          </person-group>
          <article-title>A systems approach to conduct an effective literature review in support of information systems research</article-title>
          <source>InformingSciJ</source>
          <year>2006</year>
          <volume>9</volume>
          <fpage>181</fpage>
          <lpage>212</lpage>
          <pub-id pub-id-type="doi">10.28945/479</pub-id>
        </nlm-citation>
      </ref>
      <ref id="ref18">
        <label>18</label>
        <nlm-citation citation-type="journal">
          <person-group person-group-type="author">
            <name name-style="western">
              <surname>Ouzzani</surname>
              <given-names>M</given-names>
            </name>
            <name name-style="western">
              <surname>Hammady</surname>
              <given-names>H</given-names>
            </name>
            <name name-style="western">
              <surname>Fedorowicz</surname>
              <given-names>Z</given-names>
            </name>
            <name name-style="western">
              <surname>Elmagarmid</surname>
              <given-names>A</given-names>
            </name>
          </person-group>
          <article-title>Rayyan-a web and mobile app for systematic reviews</article-title>
          <source>Syst Rev</source>
          <year>2016</year>
          <volume>5</volume>
          <issue>1</issue>
          <fpage>210</fpage>
          <comment>
            <ext-link ext-link-type="uri" xlink:type="simple" xlink:href="https://systematicreviewsjournal.biomedcentral.com/articles/10.1186/s13643-016-0384-4"/>
          </comment>
          <pub-id pub-id-type="doi">10.1186/s13643-016-0384-4</pub-id>
          <pub-id pub-id-type="medline">27919275</pub-id>
          <pub-id pub-id-type="pii">10.1186/s13643-016-0384-4</pub-id>
          <pub-id pub-id-type="pmcid">PMC5139140</pub-id>
        </nlm-citation>
      </ref>
      <ref id="ref19">
        <label>19</label>
        <nlm-citation citation-type="journal">
          <person-group person-group-type="author">
            <name name-style="western">
              <surname>Petersen</surname>
              <given-names>K</given-names>
            </name>
            <name name-style="western">
              <surname>Vakkalanka</surname>
              <given-names>S</given-names>
            </name>
            <name name-style="western">
              <surname>Kuzniarz</surname>
              <given-names>L</given-names>
            </name>
          </person-group>
          <article-title>Guidelines for conducting systematic mapping studies in software engineering: an update</article-title>
          <source>Inf Softw Technol</source>
          <year>2015</year>
          <volume>64</volume>
          <fpage>1</fpage>
          <lpage>18</lpage>
          <pub-id pub-id-type="doi">10.1016/j.infsof.2015.03.007</pub-id>
        </nlm-citation>
      </ref>
      <ref id="ref20">
        <label>20</label>
        <nlm-citation citation-type="confproc">
          <person-group person-group-type="author">
            <name name-style="western">
              <surname>Nasrin</surname>
              <given-names>S</given-names>
            </name>
          </person-group>
          <article-title>Securing vaccination data using self-sovereign identity, hyperledger fabric and zero trust model</article-title>
          <year>2023</year>
          <conf-name>2023 International Conference on Information and Communication Technology for Sustainable Development (ICICT4SD)</conf-name>
          <conf-date>September 21-23, 2023</conf-date>
          <conf-loc>Dhaka</conf-loc>
          <publisher-name>IEEE</publisher-name>
          <fpage>290</fpage>
          <lpage>294</lpage>
          <pub-id pub-id-type="doi">10.1109/icict4sd59951.2023.10303620</pub-id>
        </nlm-citation>
      </ref>
      <ref id="ref21">
        <label>21</label>
        <nlm-citation citation-type="confproc">
          <person-group person-group-type="author">
            <name name-style="western">
              <surname>Hak</surname>
              <given-names>L</given-names>
            </name>
            <name name-style="western">
              <surname>Fugkeaw</surname>
              <given-names>S</given-names>
            </name>
            <name name-style="western">
              <surname>Sato</surname>
              <given-names>H</given-names>
            </name>
          </person-group>
          <article-title>LSAC: a lightweight, scalable, and anonymous cross-domain authentication scheme in IoMT</article-title>
          <year>2024</year>
          <conf-name>2024 IEEE Intelligent Mobile Computing (MobileCloud)</conf-name>
          <conf-date>April 22-24, 2024</conf-date>
          <conf-loc>Tokyo</conf-loc>
          <publisher-loc>IEEE</publisher-loc>
          <publisher-name>IEEE</publisher-name>
          <fpage>8</fpage>
          <lpage>15</lpage>
          <pub-id pub-id-type="doi">10.1109/mobilecloud62079.2024.00009</pub-id>
        </nlm-citation>
      </ref>
      <ref id="ref22">
        <label>22</label>
        <nlm-citation citation-type="confproc">
          <person-group person-group-type="author">
            <name name-style="western">
              <surname>Fotopoulos</surname>
              <given-names>F</given-names>
            </name>
            <name name-style="western">
              <surname>Malamas</surname>
              <given-names>V</given-names>
            </name>
            <name name-style="western">
              <surname>Dasaklis</surname>
              <given-names>TK</given-names>
            </name>
            <name name-style="western">
              <surname>Kotzanikolaou</surname>
              <given-names>P</given-names>
            </name>
            <name name-style="western">
              <surname>Douligeris</surname>
              <given-names>C</given-names>
            </name>
          </person-group>
          <article-title>A blockchain-enabled architecture for IoMT device authentication</article-title>
          <year>2020</year>
          <conf-name>2020 IEEE Eurasia Conference on IoT, Communication and Engineering (ECICE)</conf-name>
          <conf-date>October 23-25, 2020</conf-date>
          <conf-loc>Yunlin</conf-loc>
          <publisher-name>IEEE</publisher-name>
          <fpage>89</fpage>
          <lpage>92</lpage>
          <pub-id pub-id-type="doi">10.1109/ecice50847.2020.9301913</pub-id>
        </nlm-citation>
      </ref>
      <ref id="ref23">
        <label>23</label>
        <nlm-citation citation-type="journal">
          <person-group person-group-type="author">
            <name name-style="western">
              <surname>Zou</surname>
              <given-names>S</given-names>
            </name>
            <name name-style="western">
              <surname>Cao</surname>
              <given-names>Q</given-names>
            </name>
            <name name-style="western">
              <surname>Huangqi</surname>
              <given-names>C</given-names>
            </name>
            <name name-style="western">
              <surname>Huang</surname>
              <given-names>A</given-names>
            </name>
            <name name-style="western">
              <surname>Li</surname>
              <given-names>Y</given-names>
            </name>
            <name name-style="western">
              <surname>Wang</surname>
              <given-names>C</given-names>
            </name>
            <name name-style="western">
              <surname>Xu</surname>
              <given-names>G</given-names>
            </name>
          </person-group>
          <article-title>A physician’s privacy-preserving authentication and key agreement protocol based on decentralized identity for medical data sharing in IoMT</article-title>
          <source>IEEE Internet of Things J</source>
          <year>2024</year>
          <volume>11</volume>
          <issue>17</issue>
          <fpage>29174</fpage>
          <lpage>29189</lpage>
          <pub-id pub-id-type="doi">10.1109/jiot.2024.3406561</pub-id>
        </nlm-citation>
      </ref>
      <ref id="ref24">
        <label>24</label>
        <nlm-citation citation-type="journal">
          <person-group person-group-type="author">
            <name name-style="western">
              <surname>Bai</surname>
              <given-names>P</given-names>
            </name>
            <name name-style="western">
              <surname>Kumar</surname>
              <given-names>S</given-names>
            </name>
            <name name-style="western">
              <surname>Aggarwal</surname>
              <given-names>G</given-names>
            </name>
            <name name-style="western">
              <surname>Mahmud</surname>
              <given-names>M</given-names>
            </name>
            <name name-style="western">
              <surname>Kaiwartya</surname>
              <given-names>O</given-names>
            </name>
            <name name-style="western">
              <surname>Lloret</surname>
              <given-names>J</given-names>
            </name>
          </person-group>
          <article-title>Self-sovereignty identity management model for smart healthcare system</article-title>
          <source>Sensors (Basel)</source>
          <year>2022</year>
          <volume>22</volume>
          <issue>13</issue>
          <fpage>4714</fpage>
          <comment>
            <ext-link ext-link-type="uri" xlink:type="simple" xlink:href="https://www.mdpi.com/resolver?pii=s22134714"/>
          </comment>
          <pub-id pub-id-type="doi">10.3390/s22134714</pub-id>
          <pub-id pub-id-type="medline">35808211</pub-id>
          <pub-id pub-id-type="pii">s22134714</pub-id>
          <pub-id pub-id-type="pmcid">PMC9269346</pub-id>
        </nlm-citation>
      </ref>
      <ref id="ref25">
        <label>25</label>
        <nlm-citation citation-type="book">
          <person-group person-group-type="author">
            <name name-style="western">
              <surname>Bandara</surname>
              <given-names>E</given-names>
            </name>
            <name name-style="western">
              <surname>Liang</surname>
              <given-names>x</given-names>
            </name>
            <name name-style="western">
              <surname>Foytik</surname>
              <given-names>P</given-names>
            </name>
            <name name-style="western">
              <surname>Shetty</surname>
              <given-names>S</given-names>
            </name>
          </person-group>
          <article-title>Connect: blockchain and self-sovereign identity empowered contact tracing platform</article-title>
          <source>Wireless Mobile Communication and Healthcare</source>
          <year>2021</year>
          <publisher-loc>Cham</publisher-loc>
          <publisher-name>Springer</publisher-name>
          <fpage>208</fpage>
          <lpage>223</lpage>
        </nlm-citation>
      </ref>
      <ref id="ref26">
        <label>26</label>
        <nlm-citation citation-type="book">
          <person-group person-group-type="author">
            <name name-style="western">
              <surname>Kormiltsyn</surname>
              <given-names>A</given-names>
            </name>
            <name name-style="western">
              <surname>Norta</surname>
              <given-names>A</given-names>
            </name>
            <name name-style="western">
              <surname>Nisar</surname>
              <given-names>S</given-names>
            </name>
            <name name-style="western">
              <surname>Dwivedi</surname>
              <given-names>V</given-names>
            </name>
          </person-group>
          <person-group person-group-type="editor">
            <name name-style="western">
              <surname>Chbeir</surname>
              <given-names>R</given-names>
            </name>
            <name name-style="western">
              <surname>Benslimane</surname>
              <given-names>D</given-names>
            </name>
            <name name-style="western">
              <surname>Zervakis</surname>
              <given-names>M</given-names>
            </name>
            <name name-style="western">
              <surname>Manolopoulos</surname>
              <given-names>Y</given-names>
            </name>
            <name name-style="western">
              <surname>Nguyen</surname>
              <given-names>NT</given-names>
            </name>
            <name name-style="western">
              <surname>Tekli</surname>
              <given-names>J</given-names>
            </name>
          </person-group>
          <article-title>Preventing data-security breaches and patient-safety risks in cross-blockchain e-healthcare systems</article-title>
          <source>Management of Digital Ecosystems</source>
          <year>2024</year>
          <publisher-loc>Cham</publisher-loc>
          <publisher-name>Springer</publisher-name>
        </nlm-citation>
      </ref>
      <ref id="ref27">
        <label>27</label>
        <nlm-citation citation-type="journal">
          <person-group person-group-type="author">
            <name name-style="western">
              <surname>George</surname>
              <given-names>M</given-names>
            </name>
            <name name-style="western">
              <surname>Chacko</surname>
              <given-names>AM</given-names>
            </name>
          </person-group>
          <article-title>Health passport: a blockchain-based PHR-integrated self-sovereign identity system</article-title>
          <source>Front Blockchain</source>
          <year>2023</year>
          <volume>6</volume>
          <fpage>1075083</fpage>
          <pub-id pub-id-type="doi">10.3389/fbloc.2023.1075083</pub-id>
        </nlm-citation>
      </ref>
      <ref id="ref28">
        <label>28</label>
        <nlm-citation citation-type="confproc">
          <person-group person-group-type="author">
            <name name-style="western">
              <surname>Sahi</surname>
              <given-names>N</given-names>
            </name>
            <name name-style="western">
              <surname>Liang</surname>
              <given-names>A</given-names>
            </name>
            <name name-style="western">
              <surname>Van</surname>
              <given-names>DW</given-names>
            </name>
            <name name-style="western">
              <surname>Oikonomou</surname>
              <given-names>K</given-names>
            </name>
            <name name-style="western">
              <surname>Zhang</surname>
              <given-names>P</given-names>
            </name>
          </person-group>
          <article-title>Self-sovereign identity in semi-permissioned blockchain networks leveraging ethereum and hyperledger fabric</article-title>
          <year>2023</year>
          <conf-name>Proceedings of the 2023 IEEE International Conference on Digital Health (ICDH)</conf-name>
          <conf-date>July 2-8, 2023</conf-date>
          <conf-loc>Chicago</conf-loc>
          <publisher-name>IEEE</publisher-name>
          <fpage>315</fpage>
          <lpage>321</lpage>
          <pub-id pub-id-type="doi">10.1109/icdh60066.2023.00053</pub-id>
        </nlm-citation>
      </ref>
      <ref id="ref29">
        <label>29</label>
        <nlm-citation citation-type="confproc">
          <person-group person-group-type="author">
            <name name-style="western">
              <surname>Kim</surname>
              <given-names>J</given-names>
            </name>
            <name name-style="western">
              <surname>Choi</surname>
              <given-names>M</given-names>
            </name>
            <name name-style="western">
              <surname>Lee</surname>
              <given-names>C</given-names>
            </name>
            <name name-style="western">
              <surname>Woo</surname>
              <given-names>JWK</given-names>
            </name>
            <name name-style="western">
              <surname>Hong</surname>
              <given-names>J</given-names>
            </name>
          </person-group>
          <article-title>Service applicable blockchain-based self-sovereign identity management system</article-title>
          <year>2023</year>
          <conf-name>Proceedings of the 2023 IEEE International Conference on Blockchain and Cryptocurrency (ICBC)</conf-name>
          <conf-date>May 15-18, 2023</conf-date>
          <conf-loc>Dubai</conf-loc>
          <publisher-name>IEEE</publisher-name>
          <fpage>1</fpage>
          <lpage>5</lpage>
          <pub-id pub-id-type="doi">10.1109/icbc56567.2023.10174875</pub-id>
        </nlm-citation>
      </ref>
      <ref id="ref30">
        <label>30</label>
        <nlm-citation citation-type="journal">
          <person-group person-group-type="author">
            <name name-style="western">
              <surname>Abid</surname>
              <given-names>A</given-names>
            </name>
            <name name-style="western">
              <surname>Cheikhrouhou</surname>
              <given-names>S</given-names>
            </name>
            <name name-style="western">
              <surname>Kallel</surname>
              <given-names>S</given-names>
            </name>
            <name name-style="western">
              <surname>Jmaiel</surname>
              <given-names>M</given-names>
            </name>
          </person-group>
          <article-title>NovidChain: blockchain-based privacy-preserving platform for COVID-19 test/vaccine certificates</article-title>
          <source>Softw Pract Exp</source>
          <year>2022</year>
          <volume>52</volume>
          <issue>4</issue>
          <fpage>841</fpage>
          <lpage>867</lpage>
          <comment>
            <ext-link ext-link-type="uri" xlink:type="simple" xlink:href="https://europepmc.org/abstract/MED/34226768"/>
          </comment>
          <pub-id pub-id-type="doi">10.1002/spe.2983</pub-id>
          <pub-id pub-id-type="medline">34226768</pub-id>
          <pub-id pub-id-type="pii">SPE2983</pub-id>
          <pub-id pub-id-type="pmcid">PMC8242505</pub-id>
        </nlm-citation>
      </ref>
      <ref id="ref31">
        <label>31</label>
        <nlm-citation citation-type="journal">
          <person-group person-group-type="author">
            <name name-style="western">
              <surname>Popa</surname>
              <given-names>M</given-names>
            </name>
            <name name-style="western">
              <surname>Stoklossa</surname>
              <given-names>SM</given-names>
            </name>
            <name name-style="western">
              <surname>Mazumdar</surname>
              <given-names>S</given-names>
            </name>
          </person-group>
          <article-title>ChainDiscipline - towards a blockchain-IoT-based self-sovereign identity management framework</article-title>
          <source>IEEE Trans Serv Comput</source>
          <year>2023</year>
          <volume>16</volume>
          <issue>5</issue>
          <fpage>3238</fpage>
          <lpage>3251</lpage>
          <pub-id pub-id-type="doi">10.1109/tsc.2023.3279871</pub-id>
        </nlm-citation>
      </ref>
      <ref id="ref32">
        <label>32</label>
        <nlm-citation citation-type="book">
          <person-group person-group-type="author">
            <name name-style="western">
              <surname>Saha</surname>
              <given-names>S</given-names>
            </name>
            <name name-style="western">
              <surname>Nova</surname>
              <given-names>SN</given-names>
            </name>
            <name name-style="western">
              <surname>Iqbal</surname>
              <given-names>MI</given-names>
            </name>
          </person-group>
          <article-title>Healthcare professionals credential verification model using blockchain-based self-sovereign identity</article-title>
          <source>Proceedings of the Fourth International Conference on Trends in Computational and Cognitive Engineering</source>
          <year>2022</year>
          <publisher-loc>Singapore</publisher-loc>
          <publisher-name>Springer</publisher-name>
          <fpage>381</fpage>
          <lpage>392</lpage>
        </nlm-citation>
      </ref>
      <ref id="ref33">
        <label>33</label>
        <nlm-citation citation-type="confproc">
          <person-group person-group-type="author">
            <name name-style="western">
              <surname>Rafid</surname>
              <given-names>FA</given-names>
            </name>
            <name name-style="western">
              <surname>Benissan</surname>
              <given-names>E</given-names>
            </name>
            <name name-style="western">
              <surname>Murr</surname>
              <given-names>L</given-names>
            </name>
            <name name-style="western">
              <surname>Ermakov</surname>
              <given-names>I</given-names>
            </name>
            <name name-style="western">
              <surname>Oikonomou</surname>
              <given-names>K</given-names>
            </name>
            <name name-style="western">
              <surname>Zhang</surname>
              <given-names>P</given-names>
            </name>
          </person-group>
          <article-title>A decentralized identity system for accelerating medical communications within rare disease communities</article-title>
          <year>2022</year>
          <conf-name>Proceedings of the 2022 IEEE International Conference on Blockchain, Smart Healthcare and Emerging Technologies (SmartBlock4Health)</conf-name>
          <conf-date>November 3-5, 2022</conf-date>
          <conf-loc>New York</conf-loc>
          <publisher-name>IEEE</publisher-name>
          <fpage>1</fpage>
          <lpage>8</lpage>
          <pub-id pub-id-type="doi">10.1109/smartblock4health56071.2022.10034646</pub-id>
        </nlm-citation>
      </ref>
      <ref id="ref34">
        <label>34</label>
        <nlm-citation citation-type="journal">
          <person-group person-group-type="author">
            <name name-style="western">
              <surname>Song</surname>
              <given-names>X</given-names>
            </name>
            <name name-style="western">
              <surname>Xu</surname>
              <given-names>G</given-names>
            </name>
            <name name-style="western">
              <surname>Huang</surname>
              <given-names>Y</given-names>
            </name>
            <name name-style="western">
              <surname>Dong</surname>
              <given-names>J</given-names>
            </name>
          </person-group>
          <article-title>DID-HVC-based web3 healthcare data security and privacy protection scheme</article-title>
          <source>Future Gener Comput Syst</source>
          <year>2024</year>
          <volume>158</volume>
          <fpage>267</fpage>
          <lpage>276</lpage>
          <pub-id pub-id-type="doi">10.1016/j.future.2024.04.015</pub-id>
        </nlm-citation>
      </ref>
      <ref id="ref35">
        <label>35</label>
        <nlm-citation citation-type="confproc">
          <person-group person-group-type="author">
            <name name-style="western">
              <surname>Keil</surname>
              <given-names>KR</given-names>
            </name>
            <name name-style="western">
              <surname>Bochnia</surname>
              <given-names>R</given-names>
            </name>
            <name name-style="western">
              <surname>Gudymenko</surname>
              <given-names>I</given-names>
            </name>
            <name name-style="western">
              <surname>Köpsell</surname>
              <given-names>S</given-names>
            </name>
            <name name-style="western">
              <surname>Anke</surname>
              <given-names>J</given-names>
            </name>
          </person-group>
          <article-title>Gaining back the control over identity attributes: access management systems based on self-sovereign identity</article-title>
          <year>2024</year>
          <conf-name>Proceedings of Open Identity Summit</conf-name>
          <conf-date>May 6-7, 2024</conf-date>
          <conf-loc>Aachen</conf-loc>
          <fpage>61</fpage>
          <lpage>72</lpage>
          <pub-id pub-id-type="doi">10.18420/OID2024_05</pub-id>
        </nlm-citation>
      </ref>
      <ref id="ref36">
        <label>36</label>
        <nlm-citation citation-type="journal">
          <person-group person-group-type="author">
            <name name-style="western">
              <surname>Freytsis</surname>
              <given-names>M</given-names>
            </name>
            <name name-style="western">
              <surname>Barclay</surname>
              <given-names>I</given-names>
            </name>
            <name name-style="western">
              <surname>Radha</surname>
              <given-names>SK</given-names>
            </name>
            <name name-style="western">
              <surname>Czajka</surname>
              <given-names>A</given-names>
            </name>
            <name name-style="western">
              <surname>Siwo</surname>
              <given-names>GH</given-names>
            </name>
            <name name-style="western">
              <surname>Taylor</surname>
              <given-names>I</given-names>
            </name>
            <name name-style="western">
              <surname>Bucher</surname>
              <given-names>S</given-names>
            </name>
          </person-group>
          <article-title>Development of a mobile, self-sovereign identity approach for facility birth registration in Kenya</article-title>
          <source>Front Blockchain</source>
          <year>2021</year>
          <volume>4</volume>
          <fpage>631341</fpage>
          <pub-id pub-id-type="doi">10.3389/fbloc.2021.631341</pub-id>
        </nlm-citation>
      </ref>
      <ref id="ref37">
        <label>37</label>
        <nlm-citation citation-type="journal">
          <person-group person-group-type="author">
            <name name-style="western">
              <surname>Zhuang</surname>
              <given-names>Y</given-names>
            </name>
            <name name-style="western">
              <surname>Shyu</surname>
              <given-names>CR</given-names>
            </name>
            <name name-style="western">
              <surname>Hong</surname>
              <given-names>S</given-names>
            </name>
            <name name-style="western">
              <surname>Li</surname>
              <given-names>P</given-names>
            </name>
            <name name-style="western">
              <surname>Zhang</surname>
              <given-names>L</given-names>
            </name>
          </person-group>
          <article-title>Self-sovereign identity empowered non-fungible patient tokenization for health information exchange using blockchain technology</article-title>
          <source>Comput Biol Med</source>
          <year>2023</year>
          <volume>157</volume>
          <fpage>106778</fpage>
          <comment>
            <ext-link ext-link-type="uri" xlink:type="simple" xlink:href="https://linkinghub.elsevier.com/retrieve/pii/S0010-4825(23)00243-3"/>
          </comment>
          <pub-id pub-id-type="doi">10.1016/j.compbiomed.2023.106778</pub-id>
          <pub-id pub-id-type="medline">36934533</pub-id>
          <pub-id pub-id-type="pii">S0010-4825(23)00243-3</pub-id>
        </nlm-citation>
      </ref>
      <ref id="ref38">
        <label>38</label>
        <nlm-citation citation-type="confproc">
          <person-group person-group-type="author">
            <name name-style="western">
              <surname>Al Muharif</surname>
              <given-names>MHA</given-names>
            </name>
            <name name-style="western">
              <surname>Ahmed</surname>
              <given-names>S</given-names>
            </name>
          </person-group>
          <article-title>Towards a pervasive paradigm: Enabling patients privacy through decentralized identity and data control in e-health</article-title>
          <year>2024</year>
          <conf-name>Proceedings of the 2024 2nd International Conference on Advancement in Computation &#38; Computer Technologies (InCACCT). IEEE</conf-name>
          <conf-date>April 25-26, 2024</conf-date>
          <conf-loc>Gharuan</conf-loc>
          <publisher-name>IEEE</publisher-name>
          <fpage>750</fpage>
          <lpage>754</lpage>
          <pub-id pub-id-type="doi">10.1109/incacct61598.2024.10551158</pub-id>
        </nlm-citation>
      </ref>
      <ref id="ref39">
        <label>39</label>
        <nlm-citation citation-type="confproc">
          <person-group person-group-type="author">
            <name name-style="western">
              <surname>Pujari</surname>
              <given-names>C</given-names>
            </name>
            <name name-style="western">
              <surname>Muniyal</surname>
              <given-names>B</given-names>
            </name>
            <name name-style="western">
              <surname>Chandrakala</surname>
              <given-names>CB</given-names>
            </name>
            <name name-style="western">
              <surname>Rajarajan</surname>
              <given-names>M</given-names>
            </name>
          </person-group>
          <article-title>A user-centric self-sovereign identity-based authentication framework for decentralized data management in healthcare settings</article-title>
          <year>2023</year>
          <conf-name>International Conference on Recent Advances in Information Technology for Sustainable Development (ICRAIS)</conf-name>
          <conf-date>December 6-7, 2023</conf-date>
          <conf-loc>Bangalore</conf-loc>
          <publisher-name>IEEE</publisher-name>
          <fpage>89</fpage>
          <lpage>94</lpage>
          <pub-id pub-id-type="doi">10.1109/icrais59684.2023.10367127</pub-id>
        </nlm-citation>
      </ref>
      <ref id="ref40">
        <label>40</label>
        <nlm-citation citation-type="journal">
          <person-group person-group-type="author">
            <name name-style="western">
              <surname>Wang</surname>
              <given-names>D</given-names>
            </name>
            <name name-style="western">
              <surname>Chen</surname>
              <given-names>X</given-names>
            </name>
            <name name-style="western">
              <surname>Zhang</surname>
              <given-names>L</given-names>
            </name>
            <name name-style="western">
              <surname>Fang</surname>
              <given-names>Y</given-names>
            </name>
            <name name-style="western">
              <surname>Huang</surname>
              <given-names>C</given-names>
            </name>
          </person-group>
          <article-title>A blockchain-based human-to-infrastructure contact tracing approach for COVID-19</article-title>
          <source>IEEE Internet of Things J</source>
          <year>2022</year>
          <volume>9</volume>
          <issue>14</issue>
          <fpage>12836</fpage>
          <lpage>12847</lpage>
          <pub-id pub-id-type="doi">10.1109/jiot.2021.3138971</pub-id>
        </nlm-citation>
      </ref>
      <ref id="ref41">
        <label>41</label>
        <nlm-citation citation-type="journal">
          <person-group person-group-type="author">
            <name name-style="western">
              <surname>Kang</surname>
              <given-names>Y</given-names>
            </name>
            <name name-style="western">
              <surname>Park</surname>
              <given-names>YB</given-names>
            </name>
          </person-group>
          <article-title>Secure access control realization based on self-sovereign identity for cloud CDM</article-title>
          <source>Applied Sciences</source>
          <year>2022</year>
          <volume>12</volume>
          <issue>19</issue>
          <fpage>9833</fpage>
          <pub-id pub-id-type="doi">10.3390/app12199833</pub-id>
        </nlm-citation>
      </ref>
      <ref id="ref42">
        <label>42</label>
        <nlm-citation citation-type="journal">
          <person-group person-group-type="author">
            <name name-style="western">
              <surname>Pujari</surname>
              <given-names>C</given-names>
            </name>
            <name name-style="western">
              <surname>Muniyal</surname>
              <given-names>B</given-names>
            </name>
            <name name-style="western">
              <surname>Chandrakala</surname>
              <given-names>CB</given-names>
            </name>
            <name name-style="western">
              <surname>Rao</surname>
              <given-names>A</given-names>
            </name>
            <name name-style="western">
              <surname>Sadiname</surname>
              <given-names>V</given-names>
            </name>
            <name name-style="western">
              <surname>Rajarajan</surname>
              <given-names>M</given-names>
            </name>
          </person-group>
          <article-title>Identity resilience in the digital health ecosystem: a key recovery-enabled framework</article-title>
          <source>Comput Biol Med</source>
          <year>2023</year>
          <volume>167</volume>
          <fpage>107702</fpage>
          <comment>
            <ext-link ext-link-type="uri" xlink:type="simple" xlink:href="https://linkinghub.elsevier.com/retrieve/pii/S0010-4825(23)01167-8"/>
          </comment>
          <pub-id pub-id-type="doi">10.1016/j.compbiomed.2023.107702</pub-id>
          <pub-id pub-id-type="medline">37976822</pub-id>
          <pub-id pub-id-type="pii">S0010-4825(23)01167-8</pub-id>
        </nlm-citation>
      </ref>
      <ref id="ref43">
        <label>43</label>
        <nlm-citation citation-type="journal">
          <person-group person-group-type="author">
            <name name-style="western">
              <surname>Manoj</surname>
              <given-names>T</given-names>
            </name>
            <name name-style="western">
              <surname>Makkithaya</surname>
              <given-names>K</given-names>
            </name>
            <name name-style="western">
              <surname>VG</surname>
              <given-names>N</given-names>
            </name>
          </person-group>
          <article-title>A blockchain based decentralized identifiers for entity authentication in electronic health records</article-title>
          <source>Cogent Engineering</source>
          <year>2022</year>
          <volume>9</volume>
          <issue>1</issue>
          <pub-id pub-id-type="doi">10.1080/23311916.2022.2035134</pub-id>
        </nlm-citation>
      </ref>
      <ref id="ref44">
        <label>44</label>
        <nlm-citation citation-type="confproc">
          <person-group person-group-type="author">
            <name name-style="western">
              <surname>Abubakar</surname>
              <given-names>M</given-names>
            </name>
            <name name-style="western">
              <surname>McCarron</surname>
              <given-names>P</given-names>
            </name>
            <name name-style="western">
              <surname>Jaroucheh</surname>
              <given-names>Z</given-names>
            </name>
            <name name-style="western">
              <surname>Al</surname>
              <given-names>DA</given-names>
            </name>
            <name name-style="western">
              <surname>Buchanan</surname>
              <given-names>B</given-names>
            </name>
          </person-group>
          <article-title>Blockchain-based platform for secure sharing and validation of vaccination certificates</article-title>
          <year>2021</year>
          <conf-name>14th International Conference on Security of Information and Networks (SIN)</conf-name>
          <conf-date>December 15-17, 2021</conf-date>
          <conf-loc>Piscataway</conf-loc>
          <fpage>1</fpage>
          <lpage>8</lpage>
          <pub-id pub-id-type="doi">10.1109/sin54109.2021.9699221</pub-id>
        </nlm-citation>
      </ref>
      <ref id="ref45">
        <label>45</label>
        <nlm-citation citation-type="confproc">
          <person-group person-group-type="author">
            <name name-style="western">
              <surname>Mchale</surname>
              <given-names>S</given-names>
            </name>
            <name name-style="western">
              <surname>Murr</surname>
              <given-names>L</given-names>
            </name>
            <name name-style="western">
              <surname>Zhang</surname>
              <given-names>P</given-names>
            </name>
          </person-group>
          <article-title>Using decentralized identifiers and interPlanetary file system to create a recoverable rare disease patient identity framework</article-title>
          <year>2023</year>
          <conf-name>2023 7th International Conference on Medical and Health Informatics (ICMHI)</conf-name>
          <conf-date>May 12-14, 2023</conf-date>
          <conf-loc>New York</conf-loc>
          <publisher-name>Association for Computing Machinery</publisher-name>
          <fpage>142</fpage>
          <lpage>149</lpage>
          <pub-id pub-id-type="doi">10.1145/3608298.3608325</pub-id>
        </nlm-citation>
      </ref>
      <ref id="ref46">
        <label>46</label>
        <nlm-citation citation-type="journal">
          <person-group person-group-type="author">
            <name name-style="western">
              <surname>Guerar</surname>
              <given-names>M</given-names>
            </name>
            <name name-style="western">
              <surname>Migliardi</surname>
              <given-names>M</given-names>
            </name>
            <name name-style="western">
              <surname>Russo</surname>
              <given-names>E</given-names>
            </name>
            <name name-style="western">
              <surname>Khadraoui</surname>
              <given-names>D</given-names>
            </name>
            <name name-style="western">
              <surname>Merlo</surname>
              <given-names>A</given-names>
            </name>
          </person-group>
          <article-title>SSI-MedRx: a fraud-resilient healthcare system based on blockchain and SSI</article-title>
          <source>Blockchain Res Appl</source>
          <year>2025</year>
          <volume>6</volume>
          <issue>1</issue>
          <fpage>100242</fpage>
          <pub-id pub-id-type="doi">10.1016/j.bcra.2024.100242</pub-id>
        </nlm-citation>
      </ref>
      <ref id="ref47">
        <label>47</label>
        <nlm-citation citation-type="confproc">
          <person-group person-group-type="author">
            <name name-style="western">
              <surname>de Oliveira</surname>
              <given-names>NR</given-names>
            </name>
            <name name-style="western">
              <surname>dos Santos</surname>
              <given-names>YDR</given-names>
            </name>
            <name name-style="western">
              <surname>Barbosa</surname>
              <given-names>GNN</given-names>
            </name>
            <name name-style="western">
              <surname>Reis</surname>
              <given-names>LHA</given-names>
            </name>
            <name name-style="western">
              <surname>Mendes</surname>
              <given-names>ACR</given-names>
            </name>
            <name name-style="western">
              <surname>Tuler de Oliveira</surname>
              <given-names>M</given-names>
            </name>
          </person-group>
          <article-title>Distributed data security in digital health: Self-sovereign identity, access control, and blockchain-based log records</article-title>
          <year>2024</year>
          <conf-name>6th International Conference on Blockchain Computing and Applications (BCCA)</conf-name>
          <conf-date>November 27-29, 2024</conf-date>
          <conf-loc>Abu Dhabi</conf-loc>
          <publisher-loc>In</publisher-loc>
          <publisher-name>IEEE</publisher-name>
          <fpage>558</fpage>
          <lpage>565</lpage>
          <pub-id pub-id-type="doi">10.1109/bcca62388.2024.10844453</pub-id>
        </nlm-citation>
      </ref>
      <ref id="ref48">
        <label>48</label>
        <nlm-citation citation-type="journal">
          <person-group person-group-type="author">
            <name name-style="western">
              <surname>Thirasak</surname>
              <given-names>K</given-names>
            </name>
            <name name-style="western">
              <surname>Chainarong</surname>
              <given-names>D</given-names>
            </name>
            <name name-style="western">
              <surname>Chuaphanngam</surname>
              <given-names>T</given-names>
            </name>
            <name name-style="western">
              <surname>Fugkeaw</surname>
              <given-names>S</given-names>
            </name>
          </person-group>
          <article-title>SSX-EHRs: secure and scalable cross-domain EHRs sharing with blockchain sharding and dynamic proxy re-encryption</article-title>
          <source>EURASIP J on Info Security</source>
          <year>2025</year>
          <volume>2025</volume>
          <issue>1</issue>
          <fpage>15</fpage>
          <pub-id pub-id-type="doi">10.1186/s13635-025-00200-y</pub-id>
        </nlm-citation>
      </ref>
      <ref id="ref49">
        <label>49</label>
        <nlm-citation citation-type="journal">
          <person-group person-group-type="author">
            <name name-style="western">
              <surname>Boi</surname>
              <given-names>B</given-names>
            </name>
            <name name-style="western">
              <surname>Cirillo</surname>
              <given-names>F</given-names>
            </name>
            <name name-style="western">
              <surname>De Santis</surname>
              <given-names>M</given-names>
            </name>
            <name name-style="western">
              <surname>Esposito</surname>
              <given-names>C</given-names>
            </name>
          </person-group>
          <article-title>Soulbound tokens: enabler for privacy-aware and decentralized authentication mechanism in medical data storage</article-title>
          <source>Blockchain Healthc Today</source>
          <year>2024</year>
          <volume>7</volume>
          <pub-id pub-id-type="doi">10.30953/bhty.v7.334</pub-id>
          <pub-id pub-id-type="medline">39649415</pub-id>
          <pub-id pub-id-type="pii">334</pub-id>
          <pub-id pub-id-type="pmcid">PMC11624496</pub-id>
        </nlm-citation>
      </ref>
      <ref id="ref50">
        <label>50</label>
        <nlm-citation citation-type="journal">
          <person-group person-group-type="author">
            <name name-style="western">
              <surname>Saidi</surname>
              <given-names>H</given-names>
            </name>
            <name name-style="western">
              <surname>Labraoui</surname>
              <given-names>N</given-names>
            </name>
            <name name-style="western">
              <surname>Ari</surname>
              <given-names>AAA</given-names>
            </name>
            <name name-style="western">
              <surname>Maglaras</surname>
              <given-names>LA</given-names>
            </name>
            <name name-style="western">
              <surname>Emati</surname>
              <given-names>JHM</given-names>
            </name>
          </person-group>
          <article-title>DSMAC: privacy-aware decentralized self-management of data access control based on blockchain for health data</article-title>
          <source>IEEE Access</source>
          <year>2022</year>
          <volume>10</volume>
          <fpage>101011</fpage>
          <lpage>101028</lpage>
          <pub-id pub-id-type="doi">10.1109/access.2022.3207803</pub-id>
        </nlm-citation>
      </ref>
    </ref-list>
  </back>
</article>
