Preprint
Article

This version is not peer-reviewed.

Digital Pathology Archives as Long-Term Clinical Memory: A Self-Sovereign Identity-Based Governance Model

A peer-reviewed version of this preprint was published in:
Healthcare 2026, 14(18), 2892. https://doi.org/10.3390/healthcare14182892

Submitted:

19 August 2026

Posted:

20 August 2026

You are already at the latest version

Abstract
Digital pathology is transforming diagnostic workflows through whole-slide imaging, digital archiving, AI-assisted analysis, and remote consultation. Existing literature only partly addresses access to pathology records and cross-institutional sharing within a holistic governance framework. This study proposes a Self-Sovereign Identity (SSI)-based conceptual governance model that treats digital pathology archives as long-term clinical memory with patient-managed access. Eighty publicly available complaints from the Şikayetvar platform were examined using thematic content analysis. National Health Service (NHS) Written Complaints data and academic, regulatory, and technical materials were examined as complementary evidence. The main problems were missing or inaccessible pathology results (66.3%) and records remaining unavailable despite notifications that results were ready (55.0%). Synthesizing these findings with complementary sources identified 11 governance requirements for secure, interoperable, auditable, and patient-centered digital pathology management. Developed through Design Science Research, the model integrates verifiable credentials, a patient digital wallet, purpose- and time-limited authorization, dynamic consent and access revocation, secure off-chain storage, and blockchain-based integrity and auditing. A scenario-based comparison of traditional, centralized digital, and SSI-based workflows indicates the model’s potential to address access, verifiable sharing, selective disclosure, portability, and auditability holistically. Establishing traceability among patient complaints, governance requirements, and model components extends digital pathology research beyond diagnostic technologies.
Keywords: 
;  ;  ;  ;  ;  ;  

1. Introduction

Pathology is a critical healthcare service that guides diagnosis, treatment, oncological follow-up, surgical decision-making, molecular testing, and second-opinion processes [1,2]. In traditional pathology, glass slides prepared from tissue samples are stored in the physical archives of laboratories, while pathology reports are typically stored in the information systems of healthcare institutions [1,3]. This storage model has long supported diagnostic reliability. However, this model, which relies on physical archives and institution-based information systems, creates limitations regarding patients’ ability to access their previous pathology reports and associated glass slides for clinical purposes during subsequent care processes, the transfer of these records between institutions, ensuring continuity of care, and patients’ ability to reuse their own pathology history [4,5,6].
Digital pathology expands the traditional pathology workflow through whole-slide imaging (WSI), digital reporting, remote consultation, digital archiving, image management systems, and AI-powered analysis. WSI technology enables the conversion of physical glass slides into high-resolution digital images, allowing these images to be used for education, research, quality control, telepathology, diagnostic support, and large-scale computational analysis [3,7,8]. Recent studies demonstrate that digital pathology, when combined with artificial intelligence, holds significant potential in terms of diagnostic accuracy, precision oncology, and computational pathology [2,7,9]. However, the transition to digital pathology should not be limited to a mere technical shift from the microscope to the screen. This transformation is a multidimensional process that requires high-capacity digital infrastructure, secure storage, quality control, regulatory compliance, sustainable institutional workflows, and data governance [10,11,12].
The transition to digital pathology has brought to the fore new governance questions concerning who may access pathology records, for what purposes and under which permissions, for how long, and through which verifiable mechanisms. The digitization of pathology reports and WSI files does not in itself provide patients with meaningful access to these records, control over their sharing, portability across institutions, revocable sharing, or the ability to verify record integrity. Digital pathology improves laboratory workflows and diagnostic processes; however, because records remain within institution-centric, fragmented, and platform-dependent systems, patients’ ability to access these records, manage their sharing, revoke access, and have their integrity verified remains limited [4,6,13]. This article addresses the governance of digital pathology archives held within institutional data structures as patient-managed access long-term clinical memory. In this context, governance is understood as the integrated management of cross-institutional access to pathology records, authorization, consent to data sharing, access revocation, portability, verification, privacy, and auditability.
Continuity of care refers to the ability to sustain a patient’s diagnostic, treatment, follow-up, and second-opinion processes across different times and healthcare institutions through uninterrupted, consistent, and accessible clinical information [14]. In the context of digital pathology, this continuity is directly related to the ability to access a patient’s previous pathology reports, associated glass slides, or WSI files when needed and to reliably reuse these records in second-opinion consultations, oncological follow-up, molecular evaluation, and treatment planning. The fragmentation of health records across institutions may make it difficult to integrate patient records and may create a risk of incomplete information in clinical decision-making [4,5]. This situation may have particularly significant consequences in pathology because pathology reports serve as a basis for a patient’s future diagnosis, second opinions, oncological follow-up, molecular interpretation, and treatment decisions [2]. When previous pathology reports or associated WSI files cannot be accessed across institutions in a fast, reliable, and verifiable manner—or when these records cannot be shared or verified—delays may occur in the patient’s clinical care due to missing information. For this reason, pathology records should not be viewed solely as archival documents stored within a single institution. These records should be regarded as components of clinical memory that possess long-term value and are reusable [2,8]. For this reason, this study proposes that digital pathology archives be considered as components of patient-managed access long-term clinical memory. In this study, the concept refers to a patient-centered governance approach in which clinically controlled, long-term clinical memory can be securely stored, accessed, verified, linked, and reused for the purpose of maintaining continuity of care, drawing on pathology records produced at different times and within different healthcare institutions. Under this approach, the patient retains meaningful oversight over decisions regarding access to those records and any sharing that is permitted, while ensuring that clinical and legal responsibilities remain protected. This approach does not imply that patients need to store all clinical documents or WSI files themselves. Instead, pathology records are positioned as patient-managed access long-term clinical memory components. Under governance mechanisms that are verifiable and auditable, these components can be stored securely, shared selectively, and reused across long-term clinical workflows.
Existing digital health governance frameworks provide important foundations for supporting this approach. The European Health Data Space (EHDS) strengthens individuals’ access to certain electronic health data free of charge and, as a rule, without delay, as well as the cross-border availability of such data; however, limited delays may be permitted for reasons related to patient safety or ethics [15]. The rights of access, rectification, and erasure recognized under the General Data Protection Regulation (GDPR) are also exercised within the framework of applicable legal conditions, public-interest grounds, and health record retention obligations [16]. In Türkiye, health data are classified as special categories of personal data requiring stronger protection under Personal Data Protection Law No. 6698 (KVKK) [17]. e-Nabız provides a national digital health infrastructure through which individuals can access their health data and manage certain permissions for sharing these data [18]. However, these regulations and platforms may not fully address pathology-specific requirements such as WSI linking, verifiable report portability, cryptographic proof of record integrity, dynamic data-sharing consent, revocation of access, and cross-organizational sharing based on verifiable identity information. Therefore, without eliminating existing clinical data repositories, there is a need for a complementary governance layer that supports authorization and verifiable sharing mechanisms to facilitate a patient-managed access clinical memory approach [6,13,19].
Self-sovereign identity (SSI), decentralized identifiers (DIDs), verifiable credentials (VCs), smart contracts, and blockchain-based auditability offer significant opportunities for this complementary governance layer. SSI initiatives in the healthcare sector are being discussed as a significant approach in terms of patient-centered identity management, secure data sharing, data-sharing consent, access control, and revocation of access [13,20,21]. In the field of digital pathology, SSI can enable the verifiable representation—under patient control—of the existence, source, integrity, validity status, and access conditions of pathology records. In this regard, SSI can be positioned as a governance layer that integrates consent, access, revocation of access, and verifiable sharing processes in the management of digital pathology archives as patient-managed access long-term clinical memory.
In this way, the study proposes an SSI-based governance model for managing digital pathology archives as patient-managed access clinical memory. The proposed model is based on a hybrid governance approach. Clinical content—such as pathology reports, WSI files, annotations, and molecular findings—remains in secure institutional or authorized health data repositories. The blockchain, however, is used solely as a limited trust and control layer for hashes, timestamps, access logs, consent status, access revocation, and integrity verification. While clinical content related to large and sensitive health records is kept off-chain, only hashes or minimal verification information is stored on-chain. This architecture provides a secure design approach [13,20,21,22].
Studies focusing on digital pathology generally address whole-slide imaging, AI-assisted analysis, digital archiving, standardization, and clinical integration [3,9,10,11]. Blockchain-based studies offer various mechanisms for access control, auditability, data integrity, consent management, and patient-centered interoperability in the context of general health data sharing. However, these studies also raise several risks related to privacy, scalability, regulatory compliance, and governance [23,24,25,26]. Healthcare research based on SSI, verifiable credentials, digital wallets, and smart contracts also offers important opportunities for patient-centered identity management, verifiable sharing, dynamic consent, access revocation, and the traceability of data use [13,19,20,22,27,28].
Blockchain research specific to the field of pathology offers important technical approaches to storing, protecting privacy, and ensuring the security of digital pathology data [29,30]. However, despite the increasing research into blockchain, artificial intelligence, and other next-generation technologies in diagnostic medicine, governance models that enable patient-managed access to digital pathology archives are limited in these studies. Specifically, current research lacks a pathology-specific governance model encompassing self-sovereign identity, dynamic permission, access revocation, selective disclosure, verifiable inter-institutional sharing, portability, interoperability, and auditability. To address this research gap, this study integrates a Design Science Research (DSR) approach with multi-source qualitative analysis. Within this scope, complaints published on the Şikayetvar platform that relate to pathology records in e-Nabız were thematically analyzed. NHS Written Complaints data were examined to provide a complementary official healthcare governance context. Academic literature, policy and regulatory documents, and technical standards and specifications were synthesized from conceptual, legal, and technical perspectives.
Thematic findings were translated into governance implications and evaluated in conjunction with other data sources to identify gaps in digital pathology governance and the R1–R11 requirements. These requirements were used as design inputs for a layered and hybrid SSI-based governance model. The model was examined through requirement–model traceability and a scenario-based conceptual assessment covering traditional, centralized digital, and proposed SSI-based workflows.
The study is guided by the following research questions:
RQ1: Which problem areas are most prominent in publicly available pathology-related complaints posted on the Şikayetvar platform in terms of record access and visibility, data sharing, continuity of care, privacy, and patients’ control over access and sharing decisions?
RQ2: How do the selected NHS Written Complaints categories contextualize the problem areas identified in RQ1 from an official health governance perspective?
RQ3: What governance gaps does the multi-source assessment reveal regarding the management of digital pathology archives as components of patient-managed access long-term clinical memory, and into which governance requirements are these gaps translated?
RQ4: How can the identified governance requirements be reflected in a layered and hybrid SSI-based governance model?
RQ5: To what extent do traditional, centralized digital, and proposed SSI-based workflows conceptually address the R1–R11 governance requirements?
The study makes three main contributions. First, patient-reported complaints are considered alongside the complementary official health governance framework provided by national health service data. This assessment identifies the main problem areas related to access, record visibility, data sharing, continuity of care, privacy, and patient control in digital pathology. Second, the study establishes the following traceable relationship between the analytical findings and model design and evaluation:
Analytical basis → governance gap → governance requirement → model component → evaluation criterion
Third, the study proposes a layered and hybrid SSI governance model. The model integrates a secure off-chain clinical data storage approach, Decentralized Identifiers (DID), Verifiable Credentials (VC), Verifiable Presentations (VP), a patient digital wallet, authorization and consent policies, and blockchain-based trust and auditing functions within a single framework. This approach positions digital pathology archives as more than institutional data repositories. The archives are redefined as components of patient-managed access long-term clinical memory that patients can access and share in a verifiable manner throughout long-term care.
The following sections of the article are organized as follows. Section 2 reviews the literature on digital pathology archives, health data governance, SSI, and blockchain technology. Section 3 describes the research methodology. Section 4 presents the thematic findings derived from the complaint corpus and the complementary official governance context. This section also identifies governance gaps and the R1–R11 requirements. Section 5 presents the proposed SSI-based governance model. Section 6 includes a scenario-based conceptual evaluation of the model. Section 7 covers the results and recommendations for implementation.

2. Literature Review

The traditional workflow of pathology services includes the physical processing of tissue specimens, preparation of glass slides, microscopic examination, and generation of pathology reports within institutional laboratory systems. However, this workflow entails various limitations regarding long-term archiving, physical storage, the transfer of slides across institutions, institutional dependence, and patient access [1,2]. Digital pathology enhances this traditional workflow through whole-slide imaging, image management systems, laboratory information system integration, telepathology, digital reporting, digital archiving, and AI-assisted analysis. Whole-slide imaging converts glass slides into high-resolution digital images, making them available for education, research, quality control, telepathology, diagnostic support, and large-scale computational analyses [3,7,8].

2.1. Digital Pathology

The transition to digital pathology should not be limited to a technical change involving the conversion of glass slides into digital images and their examination on screens. It should be regarded as a multidimensional process requiring the establishment of high-capacity digital infrastructure, the secure long-term archiving and verification of WSI files, the development of standards, regulatory compliance, and institutional change management [10,11,12]. Digital pathology should therefore be understood as a sociotechnical transformation in the storage, access, sharing, verification, reuse, and governance of pathology records.
Artificial intelligence applications are enhancing the usability and contribution of digital pathology records in diagnosis. Furthermore, these records can be linked to contexts such as prognosis, biomarker analysis, treatment response, and precision oncology. This makes these records increasingly critical from the perspectives of privacy and data governance [2,7,9].
Federated learning has been used as a method for analyzing histopathology and gigapixel whole-slide images across institutions without centrally aggregating raw images. However, the method also carries risks related to model update leakage and poisoning [31].

2.2. Governance of Digital Pathology Archives

Digital pathology archives cover various types of records, including all slide images (WSI), pathology reports, annotations, metadata, molecular test results, and artificial intelligence outputs. These archives must provide secure access, data integrity, interoperability, and long-term governance. The Digital Imaging and Communications in Medicine (DICOM) standard and DICOMweb—the ecosystem of web-based services based on this standard—enable the standardized representation and transmission of images and their related metadata. Health Level Seven (HL7) Fast Healthcare Interoperability Resources (FHIR), on the other hand, supports the sharing of clinical data associated with pathology reports across health information systems [32,33,34,35].
The merely technical existence of a digital pathology archive does not mean that patient access is guaranteed, that data portability is possible, or that verifiable sharing occurs automatically. Even if pathology records are available within an institution’s system, patients may not be able to view them, transfer them to another institution, or verify their sources and current status [36]. Furthermore, the fragmented storage of records across different institutions can hinder the creation of a comprehensive clinical record and the maintenance of continuity of care [4,14]. To ensure the reliable reuse of pathology records, the report’s source, specimen type, dates, WSI link, and version history must be preserved [5].
Pathology reports do not consist solely of laboratory findings that confirm a previously performed diagnostic procedure. They serve as sources of clinical information that can be reused in treatment, follow-up, molecular evaluation, and second-opinion processes [1,2]. For example, in the context of head and neck cancer surgery, information gaps between stages of care may adversely affect clinical coordination [37]. Within the limits of its specific clinical context, this finding supports the importance of transferring pathology data to subsequent stages of care in a traceable manner and preserving the clinical context.
The EHDS aims to enable individuals to access certain electronic health data free of charge and without delay. Additionally, patient safety or ethical considerations may cause delays [15]. The rights to access, rectify, and erase data under the GDPR are also being implemented in accordance with applicable legal requirements and health record retention obligations [16]. In Turkey, health data is protected as special-category personal data under the Personal Data Protection Law [17]. e-Nabız, on the other hand, provides individuals with the ability to access certain health data and manage sharing permissions [18]. However, these infrastructures are not sufficient on their own to meet pathology-specific requirements such as WSI connectivity, verifiable report portability, dynamic consent, and verifiable cross-organizational sharing.
In this study, “patient data sovereignty” does not mean that the patient has the unrestricted right of ownership over records created by clinicians or the ability to modify or transform such records as they see fit. The concept refers to the patient’s ability to act in a way that ensures access to their data, to monitor sharing and usage processes, to give or withdraw consent when consent is the legal basis, and to revoke sharing permissions for future access [6,13]. Patient control does not eliminate the responsibilities that healthcare institutions assume regarding maintaining the integrity of records, storage, ensuring patient safety, and processing data in compliance with the law. Particularly in records concerning children and adolescents, personal control cannot be interpreted as unlimited data ownership due to the differing responsibilities shared among the patient, legal representative, clinician, and institution [38].

2.3. Blockchain-Based Health Data Governance

Blockchain can be used to verify record integrity, execute timestamping processes, track authorization statuses, and monitor events related to data sharing. However, blockchain alone does not guarantee patient data sovereignty or legal compliance. Furthermore, there are various risks related to privacy, scalability, interoperability, technical maturity, and regulatory compliance [25,26,39,40,41].
The storage of pathology reports and WSI files—which contain sensitive clinical information—directly on the blockchain may make it difficult to comply with obligations related to data minimization and the right to erasure [16,25]. Therefore, adopting a hybrid approach is more appropriate. In this approach, clinical content is stored in secure off-chain environments. On the blockchain, only minimal verification references in the form of cryptographic hashes are maintained [26,42]. In a similar integrity-focused architecture by Arslanoğlu and Karaköse [43], health data blocks remain in edge-cloud analytics while hashes and related metadata are recorded on a simulated blockchain. The study highlights the technical difference between off-chain data processing and on-chain integrity continuity and does not address patient identity or consent management issues.
In a pathology-specific study, a proof-of-concept application was developed for the storage and sharing of digital pathology data using smart contracts and decentralized file storage [29]. In another study, a technical approach to privacy-preserving pathology data sharing among remote parties was proposed [30]. These studies contribute significantly to the areas of storage, data transfer, access security, and privacy.
Moztarzadeh et al. [44] address the platform requirements for an imaging-focused blockchain and digital twins, including self-sovereign decentralized identity, interoperability, governance, and security. However, DID/VC workflows do not offer an operational process related to patient-mediated consent, access revocation, and archive governance.
SSI-based verifiable credentials, a patient digital wallet, dynamic consent, access revocation, the record-version lifecycle, auditable emergency access, and requirement–model traceability do not appear to have been addressed together within a single digital pathology governance framework. This study proposes an SSI-based conceptual model that integrates these components within a patient-managed access long-term clinical memory approach.

2.4. Self-Sovereign Identity

Self-sovereign identity supports a patient-centered approach to digital identity and data sharing. This approach enables individuals to manage verifiable digital credentials without relying on a centralized identity provider [13,20,21]. Decentralized Identifiers (DIDs) provide a technical infrastructure that enables individuals or organizations to create verifiable digital identities without depending on a centralized identity provider. The DID standard provides a technical foundation for managing identifiers, verification keys, and service endpoints associated with the identity holder in a decentralized manner. The Verifiable Credentials standard enables identity, authorization, or record information issued by an institution to be digitally signed, cryptographically verified, and presented in a tamper-resistant form [45,46].
Dynamic consent mechanisms can enable the updating of data-sharing preferences. These systems can also provide the option to withdraw consent for future data uses and support the trackable recording of data-use events [28]. When addressed in the context of digital pathology, self-sovereign identity is seen to offer its most significant contribution by enabling the representation of pathology-related rights and evidence without the need to disclose the full clinical record. This is related to the selective disclosure and cryptographic verification features of verifiable identity information. This is because the patient or record owner can provide the evidence necessary to the verifier without having to share the entire clinical content [46]. A pathology laboratory or hospital can create a verifiable identity that confirms the existence, issuer, timestamp, hash value, and status of a pathology report. The patient can then transmit this identity to another healthcare provider. The receiving institution can verify the identity. If authorization is granted, the receiving institution can access the relevant record stored off chain. This model supports portability, integrity verification, selective sharing, and patient-mediated data sharing [13,20,21].
Smart contracts can model a patient’s preferences regarding access to, sharing of, purpose restrictions on, time limits for, and revocation of access to their pathology records in the form of a data-sharing policy defined by the patient. The use of smart contracts in accessing health data can be regarded as an important governance tool in terms of the automatic implementation of consent and access policies, the logging of access activities, and the strengthening of accountability [27]. Inter-organizational document-sharing frameworks that utilize blockchain and attribute-based encryption can support patient autonomy, authorization control, and data sovereignty across organizations through dynamic data-sharing consent [19]. In the context of digital pathology, this approach is particularly important because it allows pathology records to be shared in a time- and purpose-limited manner across various use cases, such as second opinions, referrals, oncological follow-up, treatment planning, molecular assessment, and research. Therefore, a governance model developed for patient-managed access long-term clinical memory must address routine care, referrals, second opinions, research, emergency situations, and authorized representative access separately. Each type of access should be managed with separate authorization, access revocation, and accountability rules. The model should also include third-party access in this distinction when needed [19,27,41]. In this regard, smart contracts can be used to manage access duration, restrict access to specific purposes, revoke access, and maintain audit trails. This allows patients to share their pathology records with a second hospital for a specific period, revoke access later, or restrict sharing to specific purposes, such as a second opinion, treatment planning, or research.
Self-sovereign identity is an emerging approach in healthcare. Studies highlight challenges related to scalability, usability, regulatory compliance, institutional integration, identity recovery, digital literacy, accessibility, and user acceptance [20,21,47]. Therefore, rather than positioning self-sovereign identity as a complete technological solution, this study considers SSI a governance layer that must be integrated with institutional responsibility, legal compliance, clinical workflow requirements, and ethical boundaries.

3. Methodology

This study is a design-oriented research project that develops an SSI-based conceptual governance model for managing digital pathology archives as patient-managed access, long-term clinical memory. As part of the research, academic literature, policy and regulations, technical standards and specifications, publicly available patient complaints, and official health complaint data were evaluated together.

3.1. Research Design

Complaints relating to “E-Nabız Pathology Results” published on the Şikayetvar platform were examined using thematic content analysis based on a coding manual. In the initial analysis, codes developed inductively from the complaint texts were subsequently applied systematically to the entire final corpus. The analysis identified areas of patient concern. NHS Written Complaints data were examined to provide a complementary official healthcare governance context. Academic literature, policy and regulatory documents, as well as technical standards and specifications, were synthesized from conceptual, legal, and technical perspectives. The evaluations revealed governance gaps and governance requirements in digital pathology. The requirement identification process is presented in Figure 1. The identified governance requirements were used as design inputs in the developed layered SSI-based governance model. The DSR process involves defining the problem and design objectives, as well as identifying actors and data objects. Within the scope of the process, core mechanisms are developed using a layered governance architecture, and requirement–model traceability is established. DSR also encompasses the stages of scenario-based conceptual evaluation, clinical expert review, and model improvement.
The DSR-based model development, evaluation, and improvement process is shown in Figure 2. Thematic analysis is a methodology that includes various analytical and epistemological approaches [48]. In this study, rather than using reflexive thematic analysis, a code-book-based thematic content analysis—suitable for structured coding and the description of theme frequencies—was adopted [49].

3.2. Data and Document Sources

The study utilized Şikayetvar complaints, NHS Written Complaints data, academic literature, policy and regulatory texts, as well as technical standards and specifications.
Publicly available complaints published in the “E-Nabız Pathology Result” category on the Şikayetvar platform were analyzed [50]. Codebook-based thematic content analysis was used to examine patient-reported issues related to access to digital pathology records, record visibility, notification consistency, data sharing, and continuity of care. Aggregated NHS complaints data for 2022–23, 2023–24, and 2024–25 were examined through selected categories related to access to records, communication, record accuracy and loss, privacy, delays in diagnosis or referral, and pathology services [51,52,53].
The academic literature forms the conceptual and technical foundation of this study in terms of digital pathology, health data governance, blockchain, self-sovereign identity, verifiable identity credentials, and the secure sharing of health data. Policy and regulatory documents include the General Data Protection Regulation (GDPR), the Personal Data Protection Law No. 6698 (KVKK), and the European Health Data Space (EHDS). Technical standards and specifications were evaluated as part of this study. DICOM and DICOMweb were evaluated in terms of the management and exchange of medical image data [32]. HL7 FHIR was addressed in terms of the sharing of structured clinical data among health information systems [33]. W3C DID and VC were evaluated in the context of decentralized identity management and verifiable digital record sharing [45,46]. The roles of data and document sources in the study are presented in Table 1.

3.3. Complaint Corpus

In June 2026, 83 publicly available complaints published in the “E-Nabız Pathology Result” category on the Şikayetvar platform [50] underwent preliminary assessment. Three records that had been withdrawn from publication, were duplicates, or did not provide sufficient content for thematic analysis were excluded, resulting in a final analytical corpus of 80 complaints. Each complaint was assigned an anonymous research code, which was used throughout the analysis. The criteria for including and excluding complaints are presented in Table 2.
The thematic content analysis based on the code book was performed in three stages. In the first stage, complaint headings and texts were analyzed using an inductive approach. As a result of this analysis, recurring problem areas related to access, record visibility, delays, sharing, record integrity, privacy, continuity of care, and requests for resolution were identified. Following the evaluation, an initial codebook consisting of codes T1–T11, for which operational definitions were established, was developed. In the second stage, the codebook was systematically applied to all 80 complaints included in the final compilation. Since the codes were not defined as mutually exclusive categories, a single complaint meeting the operational definitions could be assigned multiple codes. As a result, the sum of code frequencies may exceed 80, and the total percentages may exceed 100%. In the third phase, the coding findings were evaluated across the dimensions of patient access, record visibility, record integrity, data sharing, privacy, continuity of care, and auditability, and were translated into governance-related insights.
Table 3. T1–T11 Thematic Content Analysis Codebook for Şikayetvar Complaints.
Table 3. T1–T11 Thematic Content Analysis Codebook for Şikayetvar Complaints.
Code Theme Operational Definition Governance
Implication
T1 Pathology result not visible or accessible The pathology result or report is not visible in the e-Nabız system, or the relevant record cannot be accessed. Strengthening patients’ timely access to pathology records
T2 Record not visible despite notification A notification indicates that the result is ready; however, the relevant result or report is not visible in the system. Ensuring consistency between notifications and record status, as well as record visibility
T3 Delayed availability of the result in the system Although the pathology examination has been completed by the healthcare institution, the result or report is not made available in the system in a timely manner. Supporting timely access and continuity of care
T4 Difficulty accessing related tests and diagnostic records Laboratory tests, imaging examinations, or other diagnostic records associated with the pathology record cannot be accessed. Ensuring integrated access to related tests and diagnostic records
T5 Record missing, incomplete, or inaccessible The pathology record cannot be found in the system, is displayed incompletely, or the relevant file cannot be opened. Ensuring record integrity and the traceability of the record lifecycle
T6 Disruption of continuity of care, second-opinion, or treatment processes The inability to access the pathology result adversely affects follow-up, referral, second-opinion, or treatment processes. Supporting record portability and continuity of care
T7 Cross-institutional record visibility or sharing problem The pathology record cannot be viewed or used by another physician or healthcare institution. Improving cross-institutional record sharing and interoperability
T8 Access restriction on privacy grounds Access to or sharing of the pathology record is restricted on privacy or confidentiality grounds. Establishing an appropriate balance between privacy protection and access requirements
T9 Technical, usability, or communication problem Problems arise when using the web or mobile application, locating records, or communicating with the relevant healthcare institution. Supporting reliable and usable digital access
T10 Patient request for access to and control over personal records The patient requests access to or the ability to view their pathology records or participate in decisions concerning their sharing. Strengthening patient participation and meaningful control over decisions concerning record access and sharing
T11 Request for correction or resolution The complainant explicitly requests a correction, explanation, or prompt resolution regarding a record or access problem. Making correction and resolution processes visible and traceable
The coding process focused solely on issues explicitly mentioned in the complaint texts. If a complaint statement matched the functional definitions of more than one code, all relevant codes were assigned to the same complaint record. A manual coding matrix was created in Microsoft Excel. Anonymous record codes, the assigned T1–T11 codes, and brief explanations of the coding decisions were entered into this matrix. Code frequencies and percentages were calculated using this matrix. Frequencies were not used to determine the clinical prevalence of problems or their prevalence in the general population. They were used solely to identify problem areas that stood out in the set of complaints under review.

3.4. Determination of Governance Requirements

The Şikayetvar themes were used to determine the governance requirements. These themes were assessed alongside results derived from NHS Written Complaints data, academic literature, policy and regulatory documents, and technical standards and specifications. The thematic findings were then mapped to governance implications and governance gaps. Using this multi-source synthesis, 11 governance requirements were determined for managing digital pathology archives as components of patient-managed access long-term clinical memory. These requirements were used as design inputs for the SSI-based governance model.

3.4.1. Development of the DSR-Based SSI Governance Model

DSR offers a problem-solving-oriented research approach for developing and evaluating appropriate design outputs related to a specific problem [54,55]. In this study, DSR was used to develop an SSI governance model for managing digital pathology archives as components of patient-managed access long-term clinical memory. During the model development process, the problem context and design objectives were defined, along with the actors and data objects. Subsequently, the core mechanisms were developed based on the layered governance architecture, and requirement–model traceability was established. The process concluded with scenario-based conceptual evaluation and model refinement.
The architectural layers of the proposed model were developed based on the R1–R11 requirements. The core design principles included data minimization, interoperability, verifiability, access limited by purpose and scope, auditability, and the secure storage of clinical data.
A pathologist conducted an internal clinical review of the model’s alignment with clinical terminology and digital pathology workflows. Based on the feedback received, the model’s clinical terminology, actor responsibilities, and related workflows were refined. Because the pathologist was a member of the research and author team, the review process constituted an internal clinical expert review that supported model development and refinement within the DSR framework. The DSR-based model development, evaluation, and refinement process is presented in Figure 2.

3.4.2. Scenario-Based Conceptual Evaluation

The proposed model was evaluated using a comparative, scenario-based assessment organized around R1–R11. Three analytical reference scenarios were employed: the traditional pathology workflow, the centralized digital pathology workflow, and the proposed SSI-based workflow for patient-managed access long-term clinical memory.
The traditional pathology workflow denotes a structure in which records are created, stored, and managed within individual institutions, whereas sharing depends primarily on manual procedures or interinstitutional exchanges upon request. The centralized digital pathology workflow describes access through centralized infrastructures, including hospital information systems, patient portals, and national health platforms. In that scenario, identity and access decisions remain governed by institutional or platform-level control.
The SSI-based workflow combines verifiable credentials, a patient digital wallet, purpose- and time-limited authorization, secure off-chain access to clinical data, and blockchain-based audit mechanisms within a single conceptual framework. Access decisions are assessed based on professional role, purpose, scope, duration, consent, or other legitimate legal grounds. Credential verification by itself does not grant automatic access to clinical content.
Because R1–R11 functioned as design inputs for the proposed model, the evaluation took the form of a conceptual review of requirement coverage and internal design coherence. Each workflow was examined against every requirement using three categories: “not defined,” meaning that no explicit governance mechanism addresses the requirement; “partially addressed,” meaning that some aspects of the requirement are supported, but limitations remain in scope or governance; and “conceptually addressed,” meaning that the relevant actors, components, or governance mechanisms are explicitly specified in the workflow under assessment.

3.4.3. Analytical Consistency and Traceability

Predefined inclusion and exclusion criteria, operational theme definitions, a structured coding matrix, and requirement–model traceability were used as the basis for the analysis. Coding decisions, theme–implication links, and model adaptations were evaluated at regular intervals throughout the study. This process strengthened analytical consistency and auditability. Analytical triangulation was conducted using complementary data and document sources. While the Şikayetvar corpus was used to identify patient-reported problem areas, NHS Written Complaints data were evaluated to support the establishment of a complementary official health governance context. Academic literature, policy and regulatory documents, and technical standards and specifications were used to establish the conceptual, legal, and technical foundations. In this way, the sources were used to serve distinct analytical functions.

3.4.4. Ethical Considerations and Methodological Limitations

Real clinical records not available to the public, personal e-Nabız data, actual pathology reports, all slide images, or identifiable patient files were not used. The Şikayetvar compilation consists of publicly available text. Since health narratives are considered ethically sensitive, information that could reveal a patient’s identity was excluded from the analysis. To reduce the risk of the texts being reidentified, direct quotations were not included. Additionally, the findings were aggregated and presented at the thematic level. The NHS Written Complaints data, meanwhile, consists of aggregated official statistics that do not contain identifiable records.

4. Findings

The themes identified from the Şikayetvar corpus highlight key problem areas in the patient experience regarding access to digital pathology records, record visibility, continuity of care, data sharing, and record reliability.

4.1. Thematic Findings from the Şikayetvar Corpus

Figure 3 presents the frequencies of the thematic codes identified in the complaint corpus, with each complaint eligible for assignment to more than one code.
The most frequent theme identified in the findings was the absence or inaccessibility of pathology results (T1; n=53; 66.3%). This was followed by records remaining unavailable in the system despite notification (T2; n=44; 55.0%). Delayed availability of results in the system (T3; n=35; 43.8%), requests for correction or resolution (T11; n=35; 43.8%), disruption of continuity of care or second-opinion processes (T6; n=32; 40.0%), difficulty accessing related clinical results (T4; n=31; 38.8%), and technical, usability, or communication problems (T9; n=30; 37.5%) also emerged as common themes.
Records being missing, incomplete, or inaccessible (T5; n=14; 17.5%), problems related to cross-institutional data sharing (T7; n=11; 13.8%), patients’ requests for access to and control over their own data (T10; n=7; 8.8%), and access restrictions imposed on privacy grounds (T8; n=1; 1.3%) were identified less frequently. The findings indicate that the complaints were concentrated primarily around record access, visibility, and timely availability.

4.2. Official Governance Context Provided by NHS Written Complaints Data

NHS Written Complaints data were examined to show how complaints concerning healthcare services are classified and monitored within official systems. The data were not used to make a direct cross-country comparison with the Şikayetvar corpus or to measure the prevalence of digital pathology problems. Instead, they were used to provide a complementary health governance context. Figure 4 shows the changes in the total number of written complaints recorded under Primary Care and Secondary Care during 2022–23, 2023–24, and 2024–25.
The total number of written complaints was 229,458 in 2022–23, 241,922 in 2023–24, and 256,777 in 2024–25 [51,52,53]. These increases correspond to growth rates of approximately 5.4% and 6.1%, respectively. However, because the aggregate indicators were not standardized by service-use volume and may be influenced by reporting behavior and recording practices, they were not interpreted as reflecting a direct change in service quality.
Communication processes, record accuracy and loss, access to health records, privacy, delays in diagnosis or referral, and categories related to pathology services that could be associated with digital pathology governance were also assessed. Accordingly, the selected categories and their corresponding governance implications are presented in Table 4.
The “Communications” category has the highest number of complaints among the selected categories over the three periods. While a slight decrease was observed in the record loss category during the 2024–25 period, an upward trend was noted across all periods in complaints related to record accuracy, denial of access to records, and pathology services. These results indicate that access, communication, record integrity, and continuity of care are key problem areas that need to be addressed within the framework of formal health governance.

4.3. Digital Pathology Governance Gaps

The joint assessment of the Şikayetvar themes, the official governance context provided by NHS Written Complaints data, academic literature, policy and regulatory documents, and technical standards and specifications identified five main governance gaps:
Access and data control: Patients have limited ability to access their pathology records in a timely manner, monitor record status, and manage decisions concerning the sharing of these records.
Record visibility and integrity: The status, source, currency, and version history of records are often insufficiently visible and may not be verifiable.
Cross-institutional portability and continuity of care: The ability to share pathology reports, whole-slide images, and associated clinical data across institutions in an integrated and verifiable manner depends on existing integration capacity.
Privacy, data minimization, purpose limitation, and consent management: Mechanisms for limiting access to clinical data by purpose, scope, and duration, as well as for managing consent dynamically and revocably, may remain inadequate.
Auditability, correction, and emergency access: Processes for tracking access and correction requests, managing record versions, and auditing exceptional access are not sufficiently clear.
The findings indicate that digital pathology governance cannot be limited to data storage and technical access functions alone. The identified gaps provide an analytical basis for the identification of the R1–R11 governance requirements listed in Table 5. They also support the foundation of the design of the SSI-based governance model developed in Section 5.

5. Proposed SSI-Based Governance Model for Digital Pathology

In this section, an SSI-based digital pathology governance model is presented, using the R1–R11 governance requirements identified during the analysis phase as design inputs. The model is based on a DSR-based conceptual framework. It covers requirement–model traceability, the definition of actors and roles, core data objects, a layered governance architecture, and authorization and consent mechanisms. It also addresses access, verification, and audit processes collectively. The model’s objective is to support patient access, verifiable cross-organizational sharing, data minimization, and accountability.

5.1. Requirement–Model Traceability

The governance requirements R1–R11 defined in Table 5 are mapped to the relevant layers, components, and governance mechanisms of the proposed model. This mapping demonstrates how the governance issues identified through multi-source review findings have been incorporated into the model’s design and which mechanisms within the model address each requirement. The requirement–model relationship is presented in Table 6.
Table 6 presents the scope of the model’s design and its analytical traceability. The matrix shows which components and mechanisms in the proposed model address each requirement.

5.2. Actors, Roles, and Core Data Objects

An SSI-based digital pathology ecosystem adapts the roles of Issuer, Holder, and Verifier to the digital pathology domain while accounting for clinical and institutional obligations in healthcare.
Pathology laboratories and authorized healthcare institutions are responsible for preparing and securely maintaining pathology records and issuing verifiable pathology credentials. Pathologists are qualified clinical actors responsible for clinically evaluating and finalizing reports and creating revised versions when necessary.
The patient holds the verifiable credential. The digital wallet serves as the primary point of interaction for receiving and managing verification evidence, generating verifiable presentations, viewing access requests, and monitoring sharing decisions and access history.
Recipient healthcare institutions and authorized healthcare professionals assume the roles of verifier and authorized data recipient. Recipient institutions verify the validity of the VC or VP presented and provide access to clinical data subject to conditions defined by purpose, scope, duration, and legal basis. Authorized representatives or caregivers may be granted limited and revocable access. Research institutions are also considered authorized data users in secondary-use scenarios in which the necessary ethical, legal, and institutional conditions are met.
The model keeps clinical data objects separate from identity, authorization, and audit objects. Clinical data objects comprise pathology reports, whole-slide images generated for diagnostic use, clinically validated annotations, clinical and technical metadata, and molecular findings. Governance and trust objects include VCs, VPs, secure clinical data references, record and credential statuses, authorization statuses, and pseudonymous audit-event references.
In the model, patient control is defined as the patient’s ability to access their own records, manage verifiable records, decide on the scope and duration of sharing in cases where authorization is granted, revoke access permissions, and monitor access events.

5.3. Layered SSI-Based Digital Pathology Governance Architecture

The model proposes a layered and hybrid governance architecture that treats digital pathology archives as components of patient-managed access long-term clinical memory. The architecture presented in Figure 5 is based on a structure in which clinical content, identity verification, authorization, consent management, data integration, and audit functions are separated but operate together. Actors and roles constitute the architecture’s high-level stakeholder structure. Governance functions are organized into four layers. The first is the SSI, authorization, and consent governance layer. The second is the secure off-chain clinical data layer. The third is the clinical data sources and interoperability layer. The fourth is the blockchain-based trust and audit layer.
Layer 1 – SSI, Authorization, and Consent Governance: This layer integrates decentralized identifiers with verifiable credentials and verifiable presentations. It also encompasses the patient digital wallet, verifiable credential status management, purpose- and time-limited authorization, access revocation, emergency access policies, and governance rules. Clinical data themselves are not stored in the patient digital wallet. VCs related to clinical records and secure data references are stored in the wallet. VPs are generated and presented when necessary. Access requests, authorization information, and access history are viewed and tracked through the wallet [13,28,45,46].
Layer 2 – Secure Off-Chain Clinical Data: Pathology reports, whole-slide images, annotations, clinical metadata, and molecular findings are stored securely. Access to clinical content is restricted according to verified credentials and the authorization decisions made in Layer 1 [26,42].
Layer 3 – Clinical Data Sources and Interoperability: This layer encompasses hospital information systems, laboratory information systems, picture archiving and communication systems, and digital pathology infrastructures. DICOM and DICOMweb support the management of whole-slide images and their accompanying image metadata [32]. HL7 FHIR supports the integration of structured clinical data across different health information systems [33].
Layer 4 – Blockchain-Based Trust and Audit: This layer supports the recording of references to record integrity, timestamps, verifiable credential and authorization status, access and revocation events, and audit trails. Clinical content or directly identifiable patient data are not stored on the blockchain. Instead, cryptographic hashes, timestamps, trust and status references, and minimal pseudonymous references to access, revocation, and emergency access events are recorded [13,26,42].
The architecture also supports authorized use scenarios such as second-opinion consultations, oncological follow-up, treatment planning, molecular assessment, and research applications where the necessary ethical and legal requirements are met. In these scenarios, access is managed in accordance with relevant identity verification, consent, authorization, and validation rules.

5.4. Authorization, Consent-Based Access, and Authentication Workflow

The workflow of the proposed model, which includes authorization, consent-based access, and verification procedures, is shown in Figure 6. The figure presents the sequence from the creation of clinical records and the issuance of verifiable credentials through credential verification, followed by an independent authorization evaluation, authorized or denied access, and an auditable record of the access outcome. Color coding is applied to differentiate the primary process phases: blue indicates credential creation and management, green indicates access and verification, orange indicates the authorization decision and denied-access handling, and purple indicates audit, revocation, and expiry processes.
In the first stage, a biopsy specimen is collected, or the pathology examination is completed (Step 1). The pathology report and whole-slide image are then generated (Step 2), and the clinical content is stored in a secure off-chain data environment (Step 3) [26,42]. After a cryptographic hash and timestamp are created for the record (Step 4), an authorized healthcare institution issues a verifiable credential (VC) for the pathology record (Step 5), which is managed in the patient’s digital wallet (Step 6) [45,46].
In the second stage, the patient transmits the VC for the pathology record to the recipient healthcare institution, either directly or through a verifiable presentation (VP) derived from the credential, as appropriate to the context of use (Step 7). The verifying institution then checks the validity of the digital signature, whether the issuer is trusted and authorized, the validity and revocation status of the VC, its validity period, and the integrity reference for the clinical record (Step 8) [45,46].
Verification of the credential does not automatically authorize access to clinical data. The access decision is made by considering the verified identity and professional role of the requesting actor, the purpose of access, the scope of the requested data, the authorization period, the patient’s consent status or other valid legal bases, and institutional access policies (Step 9) [15,16,17].
If the authorization conditions are met, access to the secure off-chain digital pathology record is granted only within the permitted scope (Step 10), and authorized access to the clinical data is carried out (Step 11). If these conditions are not met, the access request is denied (Step 9a), and the rejected attempt is recorded to ensure security and accountability (Step 10a).
A minimal pseudonymous audit-event record relating to successful or denied access is recorded in the blockchain-based trust and audit layer (Step 12) [13,26,42]. When the authorization expires or is revoked, subsequent access is restricted (Step 13). This stage does not eliminate healthcare institutions’ legal record-retention obligations, the institutional integrity of clinical records, or the existence of data previously accessed lawfully [15,16,17].

5.5. Design Scope and Limitations of the Model

The proposed model represents core clinical processes and governance mechanisms at a conceptual level. It is not designed to depend on any technology, blockchain platform, or software solution. Implementation choices may be determined considering national healthcare infrastructure, applicable legislation, organizational requirements, interoperability requirements, and security conditions.
If a digital wallet is lost or becomes inaccessible, the patient’s identity must be reverified. Following successful verification, the necessary verifiable credentials may be reissued by authorized issuers. Credentials, keys, or authorization references associated with the previous wallet may also be revoked or deactivated through controlled recovery processes. These processes must be supported by additional security controls to prevent identity theft, unauthorized credential issuance, and account-recovery attacks [21,45,46].
The model does not treat consent as the sole or absolute legal basis for data processing. The provision of clinical services, legal obligations, public health, emergencies, and other legal grounds established by applicable legislation must also be considered during authorization [15,16,17]. Accordingly, access decisions cannot be based solely on patient consent. Nor does the model envisage executing all authorization decisions through smart contracts. The approach is intended to allow sensitive decision variables—such as professional role, legal basis, clinical context, and the scope of the requested data—to be evaluated within secure off-chain policy services. The blockchain layer is limited to cryptographic integrity verification, timestamping, status references, and minimal audit trails [13,26,42].

6. Scenario-Based Conceptual Evaluation

Using the assessment procedure defined in Section 3.6, the traditional, centralized digital, and proposed SSI-based workflows were compared against R1–R11. The comparison examines the extent to which the governance mechanisms associated with each requirement are defined within each workflow. The resulting requirement-level comparison is presented in Table 7.
In the proposed SSI-based scenario, the governance mechanisms corresponding to R1–R11 are specified at a conceptual level. However, the implement ability of these mechanisms depends on conditions such as standards compliance, institutional integration, shared trust policies, access management, and legal regulations. Accordingly, the evaluation demonstrates the model’s requirement coverage and internal design consistency. It does not provide evidence regarding technical security, clinical feasibility, effects on patient safety, or real-world performance.
Table 7 indicates that traditional and centralized digital pathology scenarios may provide various mechanisms related to patient access, record visibility, and institutional data management. However, cross-institutional verifiable sharing, granular authorization, selective disclosure, and patient-visible access management may remain limited depending on the technical infrastructure used and institutional governance rules.

7. Conclusion and Recommendations

This study considers digital pathology archives beyond the boundaries of institutional clinical record systems and reconceptualizes them as components of patient-managed access long-term clinical memory that patients can access and share in a verifiable manner throughout diagnosis, follow-up, referral, second-opinion, and treatment processes. Patient control does not mean that patients can modify the content of clinical records. Nor does it entail transferring the clinical and legal responsibilities of healthcare institutions to patients. Rather, the concept refers to strengthening patients’ access to their own records, their visibility into sharing processes, and their control over permitted access decisions.
The R1–R11 governance requirements identified through the multi-source analysis of Şikayetvar complaints, NHS Written Complaints data, academic literature, policy and regulatory documents, and technical standards formed the basis of the SSI-based model developed through the DSR approach. The model presents a layered and hybrid architecture that separates clinical content from identity, verification, authorization, and audit functions. Clinical content is stored in secure off-chain environments. The blockchain layer is limited to minimal audit functions for verifying the integrity of clinical records, timestamping, and maintaining references to credential and authorization statuses. The validity of a verifiable credential does not automatically confer a right of access to clinical data. Decisions concerning access to clinical data are evaluated separately according to role, purpose, scope, duration, consent, and other valid legal bases.
The scenario-based conceptual evaluation showed that although traditional and centralized digital workflows include some governance mechanisms, cross-institutional verifiable sharing, granular authorization, selective disclosure, and patients’ ability to manage access processes depend on the infrastructure and institutional policies in use. In the proposed model, the mechanisms corresponding to R1–R11 are defined at a conceptual level. However, the findings do not provide empirical evidence regarding the model’s technical security, clinical feasibility, or institutional performance.
The main contribution of this study is that it establishes a traceable relationship among the analytical basis, governance requirements, governance gaps, and the model for digital pathology archives, grounded in patient experiences. This approach does not limit patients’ agency over their health data to access alone but extends it to verifiable sharing, consent management, access revocation, and accountability. The model thereby proposes a governance layer that complements existing institutional data infrastructures with patient-centered authorization and verifiable sharing mechanisms.
Healthcare institutions are advised to support patients’ end-to-end access to their records within digital pathology infrastructures, ensure the traceability of record status, enable verifiable data sharing across institutions, and jointly implement access mechanisms limited by purpose, scope, and duration. It is also important to identify trusted issuers of verifiable credentials, establish credential status management, define authorized representation mechanisms, develop digital wallet recovery processes, and establish explicit governance rules for emergency access.

Author Contributions

Conceptualization, A.K. and A.K.C.; methodology, A.K.C. and A.K.; data curation, A.K.C.; formal analysis, A.K.C. and A.K.; investigation, A.K. and A.K.C.; validation, A.K.; visualization, A.K.C.; project administration, A.K.; supervision, A.K.; writing—original draft preparation, A.K. and A.K.C.; writing—review and editing, A.K. and A.K.C. All authors have read and agreed to the published version of the manuscript.

Funding

This research received no external funding.

Acknowledgments

During the preparation of this manuscript, the authors used OpenAI ChatGPT (GPT-5.6, accessed in June 2026) for language refinement and editorial assistance, as well as for technical assistance with the preparation and organization of tables. The authors reviewed and edited all AI-assisted outputs and take full responsibility for the content of this publication.

Conflicts of Interest

The authors declare no conflicts of interest.

Appendix A

Structured Internal Clinical Expert Review and Summary of Model Refinement
Table A1. Structured Internal Clinical Expert Review and Summary of Model Refinement.
Table A1. Structured Internal Clinical Expert Review and Summary of Model Refinement.
Evaluation
Dimension
Focus of Review Affected Model Element Clarification Incorporated into the Model
Clinical terminology Conceptual distinction among pathology records, clinical content, health data, and governance data Conceptual definitions and data layers of the model Pathology reports, whole-slide images, clinical and technical metadata, and governance and trust objects were distinguished from one another.
Actors and responsibilities Clarity of the roles of the pathologist, pathology laboratory, healthcare institution, patient, recipient healthcare professional, and research institution Actors and roles Responsibility for creating and correcting clinical records was assigned to authorized healthcare institutions and clinical actors. It was clarified that patient control does not entail authority to modify the content of clinical records.
Pathology report–WSI relationship Joint interpretability of pathology reports and the associated whole-slide images Clinical data sources and interoperability layer The model provides for linking pathology reports and the associated whole-slide images through secure data references based on DICOM/DICOMweb and HL7 FHIR.
Clinical data objects Identification of the data objects considered clinical content within the model Secure off-chain clinical data layer Pathology reports, whole-slide images generated for diagnostic use, clinically validated annotations, clinical and technical metadata, and molecular findings were defined as clinical data objects.
Separation of clinical content and governance data Separation of clinical records from VCs, VPs, authorization statuses, and audit references Layered governance architecture Clinical content was retained in secure off-chain environments, while blockchain use was limited to cryptographic hashes, timestamps, status references, and minimal audit records.
Record lifecycle Distinction between clinical record status and verifiable credential status Record and credential status management The clinical record lifecycle and the validity, suspension, or revocation status of the VC were defined as separate but linkable processes.
Correction and reissuance Management of corrections and addendum reports relating to clinical records Versioning and audit mechanisms Rather than allowing patients to modify clinical records, the model provides for corrections and addendum reports to be created as new versions by the authorized healthcare institution and for previous versions to be retained in a traceable manner.
VC revocation and reissuance Management of the status of a VC associated with a corrected clinical record VC status management When a clinical record is corrected or reissued, the associated VC may be revoked where necessary, and a new VC may be issued for the current version of the record.
Second opinion and continuity of care Reuse of pathology records by different institutions and clinicians Authorization and sharing workflow Second opinions, referrals, oncological follow-up, molecular evaluation, and treatment planning were incorporated into the model as distinct authorized contexts of use.
Authorized representative access Limits of the representative’s role when the patient is unable to manage access Consent and representative access components Representative access was limited by the scope of authorization, purpose of access, and duration. The model provides for such access to be revocable and auditable.
Emergency access Access in exceptional clinical circumstances in which patient consent cannot be obtained Emergency access policy and audit layer Emergency access was made conditional on professional role verification, justification, the minimum necessary data, time limitations, mandatory audit logging, and post-incident review.
Risks related to clinical feasibility Alignment of the model with existing clinical workflows, patient safety, and institutional responsibilities Design scope and limitations of the model It was clarified that credential verification does not automatically provide access to clinical data. Access decisions must be evaluated separately according to clinical context, professional role, purpose, scope, duration, consent, and other legal bases.
Note. This table summarizes the structured internal clinical expert review conducted as part of the DSR-based model refinement process. The technical standards and model components referenced in the table are described and cited in Section 2 and Section 5. The review constitutes an internal model-refinement activity rather than an independent external validation.

Appendix B

Detailed Rationale for the Scenario-Based Conceptual Evaluation
Table B1. Rationale for the Scenario-Based Evaluation of R1–R11 Requirements.
Table B1. Rationale for the Scenario-Based Evaluation of R1–R11 Requirements.
Code Traditional Workflow Centralized Digital Workflow Proposed SSI-Based Workflow
R1 Access through institutional requests; institution-dependent sharing Portal access; platform-dependent scope and control Verifiable access through a digital wallet and VC/VP
R2 Institutional or manual tracking; limited patient visibility Status and time display; limited cross-institutional linkage Linkable record and VC statuses, timestamps, and lifecycle events
R3 Institutional integrity; limited versioning and cross-institutional verification Backup and versioning; infrastructure-dependent verification Secure off-chain storage and cryptographic integrity verification
R4 No image-linked, interoperable archive Digital archive; infrastructure- and vendor-dependent linkage Report–WSI linkage through DICOM/DICOMweb and HL7 FHIR
R5 Physical or request-based sharing with limited verifiability Electronic but platform-limited sharing DID, VC/VP, a shared trust framework, and secure access
R6 Institutional and manual permissions; limited granular policies Role-based access but limited cross-institutional policies Access based on purpose, scope, duration, role, legal basis, and the minimum necessary data
R7 Static consent; no dynamic lifecycle Sharing permissions; limited scope and withdrawal Dynamic, time-limited, representative-mediated, and revocable consent
R8 Institutional correction; limited version tracking Correction and versioning; limited linkage to VC status Linkage among correction, versioning, VC revocation, and reissuance
R9 Institutional requests; limited end-to-end tracking Centralized support; limited linkage to the lifecycle and audit trail Traceable request, response, and audit process
R10 No selective disclosure mechanism Field- or role-based restrictions; limited VC/VP support Selective disclosure of necessary claims or data fields
R11 Institutional emergency access; limited logging and review Policy-dependent “break-glass” mechanism Role, justification, minimum necessary data, time limits, audit, and post-incident review
Note. This table presents a conceptual synthesis based on the literature and technical context discussed in Section 2 and Section 3.6 and on the requirement–model traceability analysis presented in Section 5 and Section 6.

References

  1. Bhargava, R.; Madabhushi, A. Emerging themes in image informatics and molecular analysis for digital pathology. Annu. Rev. Biomed. Eng. 2016, 18, 387–412. [Google Scholar] [CrossRef] [PubMed]
  2. Bera, K.; Schalper, K.A.; Rimm, D.L.; Velcheti, V.; Madabhushi, A. Artificial intelligence in digital pathology—New tools for diagnosis and precision oncology. Nat. Rev. Clin. Oncol. 2019, 16, 703–715. [Google Scholar] [CrossRef] [PubMed]
  3. Al-Janabi, S.; Huisman, A.; van Diest, P.J. Digital pathology: Current status and future perspectives. Histopathology 2012, 61, 1–9. [Google Scholar] [CrossRef] [PubMed]
  4. Dong, Y.; Mun, S.K.; Wang, Y. A blockchain-enabled sharing platform for personal health records. Heliyon 2023, 9, e18061. [Google Scholar] [CrossRef] [PubMed]
  5. Margheri, A.; Masi, M.; Miladi, A.; Sassone, V.; Rosenzweig, J. Decentralised provenance for healthcare data. Int. J. Med. Inform. 2020, 141, 104197. [Google Scholar] [CrossRef] [PubMed]
  6. Gordon, W.J.; Catalini, C. Blockchain technology for healthcare: Facilitating the transition to patient-driven interoperability. Comput. Struct. Biotechnol. J. 2018, 16, 224–230. [Google Scholar] [CrossRef] [PubMed]
  7. Niazi, M.K.K.; Parwani, A.V.; Gurcan, M.N. Digital pathology and artificial intelligence. Lancet Oncol. 2019, 20, e253–e261. [Google Scholar] [CrossRef] [PubMed]
  8. Madabhushi, A.; Lee, G. Image analysis and machine learning in digital pathology: Challenges and opportunities. Med. Image Anal. 2016, 33, 170–175. [Google Scholar] [CrossRef] [PubMed]
  9. Xu, H.; Usuyama, N.; Bagga, J.; Zhang, S.; Rao, R.; Naumann, T.; Wong, C.; Gero, Z.; González, J.; Gu, Y.; Xu, Y.; Wei, M.; Wang, W.; Ma, S.; Wei, F.; Yang, J.; Li, C.; Gao, J.; Rosemon, J.; Bower, T.; Lee, S.; Weerasinghe, R.; Wright, B.J.; Robicsek, A.; Piening, B.; Bifulco, C.; Wang, S.; Poon, H. A whole-slide foundation model for digital pathology from real-world data. Nature 2024, 630, 181–188. [Google Scholar] [CrossRef] [PubMed]
  10. Jahn, S.W.; Plass, M.; Moinfar, F. Digital pathology: Advantages, limitations and emerging perspectives. J. Clin. Med. 2020, 9, 3697. [Google Scholar] [CrossRef] [PubMed]
  11. Hanna, M.G.; Ardon, O.; Reuter, V.E.; Sirintrapun, S.J.; England, C.; Klimstra, D.S.; Hameed, M.R. Integrating digital pathology into clinical practice. Mod. Pathol. 2022, 35, 152–164. [Google Scholar] [CrossRef] [PubMed]
  12. Eloy, C.; Fraggetta, F.; van Diest, P.J.; Polónia, A.; Curado, M.; Temprana-Salvador, J.; Zlobec, I.; Purqueras, E.; Weis, C.-A.; Matias-Guiu, X.; Schirmacher, P.; Ryška, A. Digital transformation of pathology: The European Society of Pathology expert opinion paper. Virchows Arch. 2025, 487, 971–981. [Google Scholar] [CrossRef] [PubMed]
  13. Houtan, B.; Hafid, A.S.; Makrakis, D. A survey on blockchain-based self-sovereign patient identity in healthcare. IEEE Access 2020, 8, 90478–90494. [Google Scholar] [CrossRef]
  14. Kern, L.M.; Bynum, J.P.W.; Pincus, H.A. Care fragmentation, care continuity, and care coordination: How they differ and why it matters. JAMA Intern. Med. 2024, 184, 236–237. [Google Scholar] [CrossRef] [PubMed]
  15. European Union. Regulation (EU) 2025/327 of the European Parliament and of the Council of 11 February 2025 on the European Health Data Space and amending Directive 2011/24/EU and Regulation (EU) 2024/2847. Off. J. Eur. Union 2025, 2025/327. Available online: https://eur-lex.europa.eu/eli/reg/2025/327/oj (accessed on 28 July 2026).
  16. European Union. Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data (General Data Protection Regulation). Off. J. Eur. Union 2016, L 119, 1–88. Available online: https://eur-lex.europa.eu/eli/reg/2016/679/oj (accessed on 28 July 2026).
  17. Personal Data Protection Authority. Guide on the Processing of Special Categories of Personal Data [in Turkish]. Available online: https://www.kvkk.gov.tr/Icerik/8184/Ozel-Nitelikli-Kisisel-Verilerin-Islenmesine-Iliskin-Rehber (accessed on 28 July 2026).
  18. Republic of Türkiye Ministry of Health. e-Nabız Personal Health System [in Turkish]. Available online: https://enabiz.gov.tr/ (accessed on 17 July 2026).
  19. Zhang, L.; Kan, H.; Huang, H. Patient-centered cross-enterprise document sharing and dynamic consent framework using consortium blockchain and ciphertext-policy attribute-based encryption. In Proceedings of the 19th ACM International Conference on Computing Frontiers, Turin, Italy, 17–22 May 2022; Association for Computing Machinery: New York, NY, USA, 2022; pp. 58–66. [Google Scholar] [CrossRef]
  20. Pokharel, A.; Kathayat, S. Blockchain-enabled self-sovereign identity applications in health care: Scoping review. J. Med. Internet Res. 2026, 28, e89574. [Google Scholar] [CrossRef] [PubMed]
  21. Seidi, S.; Abdellaoui, A. Securing and ensuring the confidentiality of medical data in the era of decentralized technologies: A blockchain and self-sovereign identity-based approach. J. Netw. Syst. Manag. 2025, 33, 81. [Google Scholar] [CrossRef]
  22. Harrell, D.T.; Usman, M.; Hanson, L.; Abdul-Moheeth, M.; Desai, I.; Shriram, J.; de Oliveira, E.; Bautista, J.R.; Meyer, E.T.; Khurshid, A. Technical design and development of a self-sovereign identity management platform for patient-centric health care using blockchain technology. Blockchain Healthc. Today 2022, 5, 196. [Google Scholar] [CrossRef] [PubMed]
  23. Azaria, A.; Ekblaw, A.; Vieira, T.; Lippman, A. MedRec: Using blockchain for medical data access and permission management. In Proceedings of the 2016 2nd International Conference on Open and Big Data (OBD), Vienna, Austria, 22–24 August 2016; IEEE: Piscataway, NJ, USA, 2016; pp. 25–30. [Google Scholar] [CrossRef]
  24. Dagher, G.G.; Mohler, J.; Milojkovic, M.; Marella, P.B. Ancile: Privacy-preserving framework for access control and interoperability of electronic health records using blockchain technology. Sustain. Cities Soc. 2018, 39, 283–297. [Google Scholar] [CrossRef]
  25. O’Donoghue, O.; Vazirani, A.A.; Brindley, D.; Meinert, E. Design choices and trade-offs in health care blockchain implementations: Systematic review. J. Med. Internet Res. 2019, 21, e12426. [Google Scholar] [CrossRef] [PubMed]
  26. Hasselgren, A.; Kralevska, K.; Gligoroski, D.; Pedersen, S.A.; Faxvaag, A. Blockchain in healthcare and health sciences: A scoping review. Int. J. Med. Inform. 2020, 134, 104040. [Google Scholar] [CrossRef] [PubMed]
  27. Al Amin, M.; Altarawneh, A.; Ray, I. Informed consent as patient driven policy for clinical diagnosis and treatment: A smart contract based approach. In Proceedings of the 20th International Conference on Security and Cryptography (SECRYPT 2023), Rome, Italy, 10–12 July 2023; De Capitani di Vimercati, S., Samarati, P., Eds.; SCITEPRESS: Setúbal, Portugal, 2023; Volume 1, pp. 159–170. [Google Scholar] [CrossRef]
  28. Welzel, C.; Ostermann, M.; Smith, H.L.; Minssen, T.; Kirsten, T.; Gilbert, S. Enabling secure and self determined health data sharing and consent management. npj Digit. Med. 2025, 8, 560. [Google Scholar] [CrossRef] [PubMed]
  29. Subramanian, H.; Subramanian, S. Improving diagnosis through digital pathology: Proof-of-concept implementation using smart contracts and decentralized file storage. J. Med. Internet Res. 2022, 24, e34207. [Google Scholar] [CrossRef] [PubMed]
  30. Wu, W.; Chen, F.; Yuan, P.; Wang, T.; Xie, D.; Zhao, C.; Wang, C.; Tang, D.; Li, J.; Zhang, J. Privacy-preserving pathological data sharing among multiple remote parties. Blockchain Res. Appl. 2024, 5, 100204. [Google Scholar] [CrossRef]
  31. Nazir, S.; Kaleem, M. Federated learning for medical image analysis with deep neural networks. Diagnostics 2023, 13, 1532. [Google Scholar] [CrossRef] [PubMed]
  32. National Electrical Manufacturers Association. DICOM Standard: Current Edition. Available online: https://www.dicomstandard.org/current (accessed on 17 July 2026).
  33. Health Level Seven International. HL7 FHIR Release 5, Version 5.0.0. Available online: https://hl7.org/fhir/R5/ (accessed on 28 July 2026).
  34. Blattgerste, C.; Legnar, M.; Weis, C.-A. Digital, DICOM, diagnostics—Unity over chaos: Data communication in digital pathology [in German]. Pathologie 2026, 47, 56–59. [Google Scholar] [CrossRef] [PubMed]
  35. Janowczyk, A.; Baumhoer, D.; Dirnhofer, S.; Grobholz, R.; Kipar, A.; de Leval, L.; Merkler, D.; Michielin, O.; Moch, H.; Perren, A.; Rottenberg, S.; Rubbia-Brandt, L.; Rubin, M.A.; Sempoux, C.; Tolnay, M.; Zlobec, I.; Koelzer, V.H. Towards a national strategy for digital pathology in Switzerland. Virchows Arch. 2022, 481, 647–652. [Google Scholar] [CrossRef] [PubMed]
  36. Alomar, D.; Almashmoum, M.; Eleftheriou, I.; Whelan, P.; Ainsworth, J. The impact of patient access to electronic health records on health care engagement: Systematic review. J. Med. Internet Res. 2024, 26, e56473. [Google Scholar] [CrossRef] [PubMed]
  37. Comess, S.R.; Joseph, J.K.; Yoon, M.; Sayeed, S.; Borkhetaria, P.; Stanisce, L.; Brandwein-Weber, M.; Karasick, M.; Urken, M.L. Identifying and closing information gaps in head and neck cancer surgery. Semin. Oncol. 2025, 52, 152362. [Google Scholar] [CrossRef] [PubMed]
  38. Bourgeois, F.C.; Taylor, P.L.; Emans, S.J.; Nigrin, D.J.; Mandl, K.D. Whose personal control? Creating private, personally controlled health records for pediatric and adolescent patients. J. Am. Med. Inform. Assoc. 2008, 15, 737–743. [Google Scholar] [CrossRef] [PubMed]
  39. Abu-elezz, I.; Hassan, A.; Nazeemudeen, A.; Househ, M.; Abd-alrazaq, A. The benefits and threats of blockchain technology in healthcare: A scoping review. Int. J. Med. Inform. 2020, 142, 104246. [Google Scholar] [CrossRef] [PubMed]
  40. Saeed, H.; Malik, H.; Bashir, U.; Ahmad, A.; Riaz, S.; Ilyas, M.; Bukhari, W.A.; Khan, M.I.A. Blockchain technology in healthcare: A systematic review. PLoS ONE 2022, 17, e0266462. [Google Scholar] [CrossRef] [PubMed]
  41. Rubeis, G. Ethical implications of blockchain technology in biomedical research. Ethik Med. 2024, 36, 493–506. [Google Scholar] [CrossRef]
  42. Kaushal, R.K.; Kumar, N.; Boonchieng, E.; Mapari, S.; Kukreja, V.; Verma, A. Convergence of blockchain and IoT for managing decentralized medical records. Sci. Rep. 2025, 15, 44512. [Google Scholar] [CrossRef] [PubMed]
  43. Arslanoğlu, K.; Karaköse, M. An efficient clinical decision support framework using IoMT based on explainable and trustworthy artificial intelligence with transformer model and blockchain-integrated chunking. Diagnostics 2026, 16, 7. [Google Scholar] [CrossRef] [PubMed]
  44. Moztarzadeh, O.; Jamshidi, M.; Sargolzaei, S.; Keikhaee, F.; Jamshidi, A.; Shadroo, S.; Hauer, L. Metaverse and medical diagnosis: A blockchain-based digital twinning approach based on MobileNetV2 algorithm for cervical vertebral maturation. Diagnostics 2023, 13, 1485. [Google Scholar] [CrossRef] [PubMed]
  45. World Wide Web Consortium. Decentralized Identifiers (DIDs) v1.0: Core Architecture, Data Model, and Representations; W3C Recommendation. 19 July 2022. Available online: https://www.w3.org/TR/did-core/ (accessed on 28 July 2026).
  46. World Wide Web Consortium. Verifiable Credentials Data Model v2.0; W3C Recommendation. 15 May 2025. Available online: https://www.w3.org/TR/vc-data-model-2.0/ (accessed on 28 July 2026).
  47. Siqueira, A.; da Conceição, A.F.; Rocha, V. Blockchains and self-sovereign identities applied to healthcare solutions: A systematic review. arXiv 2021, arXiv:2104.12298. [Google Scholar] [CrossRef]
  48. Braun, V.; Clarke, V. Toward good practice in thematic analysis: Avoiding common problems and be(com)ing a knowing researcher. Int. J. Transgend. Health 2023, 24, 1–6. [Google Scholar] [CrossRef] [PubMed]
  49. Vaismoradi, M.; Turunen, H.; Bondas, T. Content analysis and thematic analysis: Implications for conducting a qualitative descriptive study. Nurs. Health Sci. 2013, 15, 398–405. [Google Scholar] [CrossRef] [PubMed]
  50. Şikayetvar. E-Nabız Patoloji Sonucu Hakkında Şikayetler ve Yorumlar [in Turkish]. Available online: https://www.sikayetvar.com/e-nabiz/patoloji-sonucu (accessed on 17 July 2026).
  51. NHS England. Data on Written Complaints in the NHS, 2022–23. 26 October 2023. Available online: https://digital.nhs.uk/data-and-information/publications/statistical/data-on-written-complaints-in-the-nhs/2022-23 (accessed on 28 July 2026).
  52. NHS England. Data on Written Complaints in the NHS, 2023–24. 17 October 2024. Available online: https://digital.nhs.uk/data-and-information/publications/statistical/data-on-written-complaints-in-the-nhs/2023-24 (accessed on 28 July 2026).
  53. NHS England. Data on Written Complaints in the NHS, 2024–25. 16 October 2025. Available online: https://digital.nhs.uk/data-and-information/publications/statistical/data-on-written-complaints-in-the-nhs/2024-25 (accessed on 28 July 2026).
  54. Hevner, A.R.; March, S.T.; Park, J.; Ram, S. Design science in information systems research. MIS Q. 2004, 28, 75–105. [Google Scholar] [CrossRef]
  55. Peffers, K.; Tuunanen, T.; Rothenberger, M.A.; Chatterjee, S. A design science research methodology for information systems research. J. Manag. Inf. Syst. 2007, 24, 45–77. [Google Scholar] [CrossRef]
Figure 1. Identification of Digital Pathology Governance Gaps and Requirements.
Figure 1. Identification of Digital Pathology Governance Gaps and Requirements.
Preprints 229203 g001
Figure 2. DSR-Based Development, Evaluation, and Refinement of the SSI-Based Digital Pathology Governance Model.
Figure 2. DSR-Based Development, Evaluation, and Refinement of the SSI-Based Digital Pathology Governance Model.
Preprints 229203 g002
Figure 3. Distribution of Thematic Codes in the Şikayetvar Complaint Corpus.
Figure 3. Distribution of Thematic Codes in the Şikayetvar Complaint Corpus.
Preprints 229203 g003
Figure 4. Annual NHS Written Complaints Totals (2022–23 to 2024–25).
Figure 4. Annual NHS Written Complaints Totals (2022–23 to 2024–25).
Preprints 229203 g004
Figure 5. Layered SSI-Based Governance Architecture for Patient-managed access Digital Pathology Archives. Note: HIS: Hospital Information System; LIS: Laboratory Information System; PACS: Picture Archiving and Communication System.
Figure 5. Layered SSI-Based Governance Architecture for Patient-managed access Digital Pathology Archives. Note: HIS: Hospital Information System; LIS: Laboratory Information System; PACS: Picture Archiving and Communication System.
Preprints 229203 g005
Figure 6. Authorization- and Consent-Based Access and Verification Workflow for Patient-managed access Digital Pathology Records.
Figure 6. Authorization- and Consent-Based Access and Verification Workflow for Patient-managed access Digital Pathology Records.
Preprints 229203 g006
Table 1. Functions of Data and Document Sources in the Study.
Table 1. Functions of Data and Document Sources in the Study.
Source Source Type Form of Analysis / Review Function in the Study
Şikayetvar “E-Nabız Pathology Result” complaints Publicly available complaint texts Codebook-based thematic content analysis Identification of patient-reported problem areas
NHS Written Complaints data Aggregated official complaint statistics Category and trend analysis Establishment of a complementary official health governance context
Academic literature Conceptual and technical studies Conceptual and technical synthesis Establishment of the theoretical foundation and design implications
Policy and regulatory documents Documents related to the GDPR, KVKK, and EHDS Governance-focused document review Identification of legal principles and design boundaries
Technical standards and specifications DICOM/DICOMweb, HL7 FHIR, W3C DID, and VC Standards–requirements mapping Identification of interoperability, verifiability, and model components
Table 2. Inclusion and Exclusion Criteria for the Şikayetvar Corpus.
Table 2. Inclusion and Exclusion Criteria for the Şikayetvar Corpus.
Inclusion Criteria Exclusion Criteria
Related to a pathology result, record, or associated digital access process Not directly related to pathology
Contains at least one issue involving access, visibility, delay, sharing, record integrity, or data control Related solely to appointments, fees, physical services, or staff conduct
Publicly available, accessible, and sufficiently detailed for thematic content analysis Duplicate, withdrawn, inaccessible, or insufficiently detailed for coding
Can be safely de-identified Not suitable for reducing the risk of re-identification to an adequate level
Table 4. Evaluation of Selected NHS Complaint Categories from a Digital Pathology Governance Perspective.
Table 4. Evaluation of Selected NHS Complaint Categories from a Digital Pathology Governance Perspective.
NHS Complaint Category 2022–23 2023–24 2024–25 Governance Significance for Digital Pathology Related Requirement
Communications 47,301 51,403 56,180 Need for timely and reliable information on record status and the results process R2, R9
Confidentiality/
Privacy and Dignity
5,446 5,596 5,831 Limiting access to clinical data based on privacy, purpose, and scope R6
Delay in Diagnosis/Failure to Refer 4,953 5,580 6,617 Timely transfer of results to diagnostic, referral, second-opinion, and treatment processes R2, R5
Records: Inaccurate/Incorrect 1,719 2,232 3,112 Traceability for record integrity, correction, and versioning R3, R8
Refusal to Allow Access to Records 186 226 279 Supporting patients’ access to their own health records R1
Records: Loss of Records 182 225 216 Ensuring traceability of record integrity and lifecycle R3
Clinical Treatment: Pathology Group 206 267 336 Managing pathology records in an integrated and image-linked manner R4
Table 5. R1–R11 Governance Requirements for Digital Pathology Archives.
Table 5. R1–R11 Governance Requirements for Digital Pathology Archives.
Code Primary Analytical Basis Governance Requirement
R1 T1, T10; NHS Written Complaints data on refusal of access to records; EHDS, GDPR, KVKK Verifiable access to components of patient-managed access long-term clinical memory
R2 T2, T3; NHS Written Complaints data on communication and delays in diagnosis/referral Verifiable record status and timestamped tracking
R3 T5; NHS Written Complaints data on inaccurate and lost records Record integrity and an auditable record lifecycle
R4 T4; NHS Written Complaints data on pathology services; DICOM/DICOMweb, HL7 FHIR Integrated, image-linked, and interoperable digital pathology archive
R5 T6, T7; NHS Written Complaints data on delays in diagnosis/referral; continuity-of-care literature Portable and verifiable cross-institutional record sharing
R6 T8; NHS Written Complaints data on privacy; GDPR, KVKK, EHDS Access based on data minimization and limited by purpose, scope, and duration
R7 T10; e-Nabız sharing permissions; dynamic consent literature Dynamic, time-limited, and revocable consent
R8 T5, T11; NHS Written Complaints data on inaccurate records; VC status management Clinical record correction and version tracking with credential status management
R9 T9, T11; NHS Written Complaints data on the communication category Auditable request and resolution process
R10 T8, T10; W3C VC/VP; selective disclosure approach Verification using the minimum necessary data through selective disclosure
R11 Regulatory documents, ethics literature, and internal clinical expert review Auditable emergency access and post-incident review
Table 6. Requirement–Model Traceability Matrix.
Table 6. Requirement–Model Traceability Matrix.
Code Governance Requirement Model Layer/Component Proposed Governance Mechanism
R1 Verifiable access to components of patient-managed access long-term clinical memory Patient digital wallet, DID, VC/VP, and secure data access components Issuance of a verifiable credential for the pathology record by an authorized healthcare institution; management of this credential by the patient in a digital wallet and access to the relevant record under authorization conditions
R2 Verifiable record status and timestamped tracking Clinical record lifecycle, verifiable credential status management, timestamps, and audit layer Separate but linkable tracking of clinical record status, VC validity, timestamps, and related lifecycle events
R3 Record integrity and an auditable record lifecycle Secure off-chain clinical data layer, cryptographic hashes, provenance and version relationships, and audit layer Verification of record integrity through cryptographic hashes; tracking of record provenance, corrections, supplementary reports, and version changes
R4 Integrated, image-linked, and interoperable digital pathology archive Clinical data sources and interoperability layer Linking pathology reports, whole-slide images, annotations, and associated clinical and technical metadata through secure DICOM/DICOMweb- and HL7 FHIR-based data references
R5 Portable and verifiable cross-institutional record sharing DID verification, VC/VP sharing, secure data access, trust framework, and interoperability components Verification of the issuer’s authority, record source, and VC status; secure and interoperable sharing of authorized clinical content across institutions
R6 Access based on data minimization and limited by purpose, scope, and duration SSI, authorization and consent governance layer, and off-chain policy service Evaluation of access decisions based on the requesting actor’s identity and role, access purpose, legal basis, data scope, access duration, and the minimum necessary data principle
R7 Dynamic, time-limited, and revocable consent Patient digital wallet, consent and authorization status, representative access, and consent withdrawal components Granting consent, updating its scope and duration, managing it through an authorized representative, and withdrawing it with respect to future consent-based access
R8 Clinical record correction and version tracking with credential status management Clinical record source, authorized healthcare institution, VC status management, version relationships, and audit layer Creation of corrections and supplementary reports by the authorized healthcare institution, preservation of previous versions, and revocation and reissuance of the relevant VC when necessary
R9 Auditable request and resolution process Patient digital wallet, request and status management functions, authorization policy service, and audit trail Receipt of access, error, and correction requests; traceable recording of request statuses, responses provided, and actions performed
R10 Verification using the minimum necessary data through selective disclosure VC/VP presentation component, selective disclosure mechanism, and verification policy Disclosure of only the claims or data fields required for a specific verification purpose, provided that the VC format used supports this functionality
R11 Auditable emergency access and post-incident review Emergency access policy, professional role verification, authorization service, and audit layer Provision of justified exceptional access based on professional role verification, the minimum necessary data, time limitation, and a mandatory audit record, followed by post-incident review
Table 7. Levels of Governance Requirement Coverage across Reference Pathology Workflows.
Table 7. Levels of Governance Requirement Coverage across Reference Pathology Workflows.
Code Governance Requirement Scenario 1: Traditional Pathology Workflow Scenario 2: Centralized Digital Pathology Workflow Scenario 3: Proposed SSI-Based Workflow Primary Implementation Condition
R1 Verifiable access to components of patient-managed access long-term clinical memory Partially addressed Partially addressed Conceptually addressed Ensuring the availability of usable digital wallets, secure identity recovery processes, and institutional participation
R2 Verifiable record status and timestamped tracking Partially addressed Partially addressed Conceptually addressed Consistently linking the clinical record lifecycle with verifiable credential statuses
R3 Record integrity and an auditable record lifecycle Partially addressed Partially addressed Conceptually addressed Storing clinical content in secure off-chain environments and verifying its integrity through cryptographic hashes
R4 Integrated, image-linked, and interoperable digital pathology archive Not defined Partially addressed Conceptually addressed Ensuring interoperability compliant with DICOM/DICOMweb and HL7 FHIR standards
R5 Portable and verifiable cross-institutional record sharing Partially addressed Partially addressed Conceptually addressed Establishing a common trust framework and a registry of authorized verifiable credential issuers
R6 Access based on data minimization and limited by purpose, scope, and duration Partially addressed Partially addressed Conceptually addressed Establishing implementable and interoperable authorization policies across institutions
R7 Dynamic, time-limited, and revocable consent Not defined Partially addressed Conceptually addressed Clearly distinguishing consent from other legal bases and managing the consent lifecycle
R8 Clinical record correction and version tracking with credential status management Partially addressed Partially addressed Conceptually addressed Linking record corrections and addendum reports with VC revocation and reissuance processes
R9 Auditable request and resolution process Partially addressed Partially addressed Conceptually addressed Integrating status management for access, error, and correction requests into institutional processes
R10 Verification using the minimum necessary data through selective disclosure Not defined Partially addressed Conceptually addressed Adopting VC/VP formats and verification mechanisms that support selective disclosure
R11 Auditable emergency access and post-incident review Partially addressed Partially addressed Conceptually addressed Defining emergency access roles, access conditions, limits on duration and data scope, and post-incident review processes
Disclaimer/Publisher’s Note: The statements, opinions and data contained in all publications are solely those of the individual author(s) and contributor(s) and not of MDPI and/or the editor(s). MDPI and/or the editor(s) disclaim responsibility for any injury to people or property resulting from any ideas, methods, instructions or products referred to in the content.
Copyright: This open access article is published under a Creative Commons CC BY 4.0 license, which permit the free download, distribution, and reuse, provided that the author and preprint are cited in any reuse.