Public authenticity checks for medical documents on Arbitrum. Only a SHA-256 fingerprint and an opaque ID go on-chain, no patient data. Issue, revoke, supersede, verify.




ConsensMed Verify: public authenticity checks for medical documents, without medical data on-chain.
The problem
Medical documents such as patient consents, referrals and certificates get altered or forged, and today the only way to check one is to call the clinic that issued it. Putting medical data on a public blockchain is not an option under GDPR.
How it works
- When a clinic finalises a document in ConsensMed, a random opaque document ID is printed in a QR code, then the PDF is frozen and hashed (SHA-256).
- The ConsensMedVerify contract stores only that ID and the 32-byte fingerprint. No names, no identifiers, no clinical data.
- Anyone can scan the QR code or drop the file on https://verify.consensmed.ro. The hash is computed in the browser (the file never leaves the device) and checked directly against the contract.
- Five states: Valid, Does not match (altered), Revoked, Superseded (with a link to the current version), Not registered.
Why on-chain
The proof does not depend on ConsensMed: if our database is compromised or we disappear, the record cannot be rewritten and verification keeps working.
Security
- The owner key (a hardware-backed wallet held by the company) is separate from the issuer key used by the service; a compromised issuer key can be revoked by the owner.
- 30 Foundry tests, 100% coverage, Slither: 0 findings. Source verified on Arbiscan and on the Robinhood Chain explorer.
Deployments (same address on both)
0x6F0aDfD3ef7befac17A6165A9Db07BFd54C2d285
- Arbitrum Sepolia: https://sepolia.arbiscan.io/address/0x6F0aDfD3ef7befac17A6165A9Db07BFd54C2d285
- Robinhood Chain Testnet: https://explorer.testnet.chain.robinhood.com/address/0x6F0aDfD3ef7befac17A6165A9Db07BFd54C2d285
Try it
- Verifier: https://verify.consensmed.ro
- Sample documents: https://github.com/MiniJe/consensmed-anchor/releases/tag/demo-samples
- Code: https://github.com/MiniJe/consensmed-anchor
How it was built
Built by BEYOND-SOFTWARE S.R.L. with Claude Code as an AI pair programmer. The team set the architecture and security constraints, wrote every work order as a verifiable spec, reviewed every result and made all deployment and key-management decisions.
ConsensMed is an existing healthcare platform; before the buildathon it anchored document hashes on another chain, with no public verification. During the buildathon we built:
- ConsensMedVerify (Solidity, OpenZeppelin Ownable): issue, revoke, supersede, verify with five states; 30 Foundry tests including fuzzing, 100% line/branch/function coverage, CI on every push; deployed on Arbitrum Sepolia and source-verified on Sourcify.
- A public verifier at verify.consensmed.ro: a single static page, client-side SHA-256, reads the contract over public RPC; no backend, no cookies, no analytics.
- An Arbitrum backend for ConsensMed's existing anchoring service (Go, go-ethereum), selectable by configuration, so platform documents are anchored and verifiable end-to-end.
- A demo generator producing synthetic GDPR consent PDFs with QR codes, plus original, altered, revoked and superseded samples published for judges.
- A threat model documenting what the chain guarantees and what it does not.
Bootstrapped by Beyond Software S.R.L. (Cluj-Napoca, Romania); no external funding raised to date. We are preparing EU non-dilutive applications (EIC Accelerator; Digital Europe EHDS calls) and are open to ecosystem grants and strategic partners.