ZTPIF-H: A Zero-Trust Patient Identity Engineering Framework for Healthcare Using AI and Blockchain
: Healthcare ecosystems face persistent identity-fragmentation challenges that undermine secure, interoperable data access across Electronic Health Records (EHR), telemedicine platforms and clinical Application Programming Interfaces (APIs). Existing Identity and Access Management (IAM) solutions rely on static role assignments and reactive audit mechanisms ill-suited to dynamic clinical environments. This paper presents the Zero-Trust Patient Identity Engineering Framework for Healthcare (ZTPIF-H), which integrates decentralised identity, Artificial Intelligence (AI)-driven adaptive authorisation, smart-contract-based consent governance and blockchain-based immutable auditability. The framework is organised around four pillars — Identity Assurance, Adaptive Trust Decisioning, Consent Governance and Immutable Accountability — operationalised through an eight-phase lifecycle. Relative to prior work, this version adds a multi-dimensional comparison with state-of-the-art healthcare IAM approaches, a reproducible experimental protocol, an explicit threat model with a systematic security analysis, and an AI-trustworthiness analysis covering interpretability, calibration, robustness and fail-safe behaviour aligned with the NIST AI Risk Management Framework (AI RMF) and the EU AI Act. A proof-of-concept (PoC) evaluation in a simulated secondary-care environment shows a 42% reduction in authorisation latency, a 62% reduction in false-positive denials and a 77% reduction in standing-privilege exposure versus a conventional IAM baseline. ZTPIF-H aligns with HL7 FHIR R4, OpenID Connect (OIDC), W3C Verifiable Credentials (VC) and NIST Zero Trust Architecture (ZTA) principles, offering a vendor-neutral, incrementally adoptable pathway to modern healthcare identity engineering