AvaCloud

How AIBTRUST is putting medical data sovereignty back in patients' hands.

AIBTRUST logo

Medical records have been trapped inside hospital systems for decades. AIBTRUST is rebuilding the consent layer underneath, onchain, patient-controlled, and revocable in real time.

HealthcareData SovereigntyDynamic ConsentSovereign L1

The Consent Problem

Patients sign a form once. Their data gets reused for years.

Healthcare data sharing runs on static consent: a paper form at intake, an opaque chain of downstream uses no patient ever sees. AIBTRUST is rebuilding that layer so consent is granular, revocable, and verifiable on every access.

Real-time

Patients grant, scope, or revoke access in the moment, not on a paper form filed at intake five years ago.

Per-purpose

Consent is scoped to specific data types, recipients, and use cases. Research access is not the same as care access is not the same as insurance access.

Auditable

Every access checks against onchain permissions before data moves. The audit trail isn't promised by the operator, it's enforced by the chain.

AvaCloud Solved the Problem

A dedicated L1 for medical consent, isolated, compliant, sovereign.

Healthcare data is among the most sensitive material a chain can govern. AIBTRUST chose a sovereign Avalanche L1 on AvaCloud rather than a tenancy on shared infrastructure: full control over validators, fees, and the compliance posture required to operate inside hospital systems.

The L1 doesn't store medical records themselves, it governs access to them. Smart contracts encode dynamic consent: who is allowed to see what, for which purpose, for how long, and with what revocation rules. Hospitals, researchers, and insurance partners check against the chain before any data moves.

Patients see a clear, plain-language consent surface in the AIBTRUST app. Every grant they make becomes an onchain commitment. Every revocation takes effect immediately, network-wide. Every access against their data is logged. Trust stops being a promise and becomes infrastructure.

"In healthcare, consent is the contract. If the consent layer can't be audited, nothing built on top of it can be trusted.",

Architecture

One sovereign L1, three layers, a verifiable consent graph in the middle.

The AIBTRUST L1 governs permissions, not records. Patient apps and provider systems check against the chain; data itself stays inside the source-of-truth systems where it already lives.

Layer 03Patient & provider apps
AppPatient consent UIAIBTRUST
AppHospital EMRIntegrated
AppResearch portalsPermissioned
AppInsurance & payerScoped access
Layer 02AIBTRUST L1
L1Dynamic consent contractsAvalanche
L1Permission checksPre-access
L1Real-time revocationNetwork-wide
L1Onchain audit trailEnforced
Layer 01AvaCloud Ops
OpsValidator management24/7
OpsCompliance postureHealthcare-tuned
OpsMonitoring & uptimeAround the clock
OpsExpert Web3 supportAva Labs team
Application surfaceSovereign L1 (AIBTRUST)AIBTRUST sovereigntyManaged by AvaCloud

Static vs. Dynamic Consent

Same patient. Same data. A different control surface.

Static consent is a snapshot in time, signed once, reused forever. Dynamic consent is a living contract, patients can rescope, restrict, or revoke at any moment, and the chain enforces the change immediately.

Before · Static Consent

Paper forms and bilateral data agreements

One-time
A signature at intake, then opaque downstream sharing.
  • Consent captured once and reused indefinitely.
  • Patients have no view into who accesses their data, or why.
  • Revocation is slow, manual, often functionally impossible.
  • Audit trails depend on each system maintaining its own logs.
  • Cross-institution sharing requires bespoke legal agreements.
After · Dynamic Consent

AIBTRUST onchain consent

Real-time
A living contract patients control from their phone.
  • Consent is granular: scoped to data type, recipient, and purpose.
  • Patients see every active grant and every prior access.
  • Revocation is instant and enforced network-wide by the chain.
  • The audit trail is onchain, not maintained by individual operators.
  • Cross-institution sharing runs against shared, verifiable rules.

The Network AIBTRUST Joined

Sensitive-data domains are converging on sovereign L1s.

Healthcare, public records, payments, identity, the industries where data sovereignty is non-negotiable are choosing the same architectural pattern: their own AvaCloud-managed chain, not a tenancy on shared infrastructure.

Healthcare
AIBTRUST

Onchain medical data sovereignty. Smart-contract-driven dynamic consent gives patients real-time control of their records.

AIBTRUST L1 · Live
Public Records
Deloitte

Close As You Go™ replaces fragmented FEMA reimbursement workflows with a permissioned chain for compliant, auditable disaster-recovery records.

Permissioned L1 · Live
Payments
NHN KCP

Korea's largest payment processor moved settlement onchain on AvaCloud, $38B annual volume, sub-second finality, encryption-native privacy.

Payment Chain · 2026
Capital Markets
Broadridge

Distributed Ledger Repo (DLR) settles trillions in repo volume monthly on Avalanche, collateral mobility with intraday repricing.

DLR · Live

What This Delivered

The economics of replacing the consent layer of healthcare.

From patient agency to research throughput, the move to AvaCloud-managed L1 infrastructure changed what's possible, and gave AIBTRUST a sovereign foundation for a healthcare data ecosystem patients can actually trust.

Consent model
Static → Dynamic
Revocation latency
Real-time, network-wide
Audit trail
Onchain, enforced
Patient visibility into access
Every grant, every access
Compliance posture
Healthcare-tuned, sovereign
Validator capex & ops complexity
Eliminated by AvaCloud
Sovereignty over consent rules & roadmap
Retained by AIBTRUST

Your data-sovereignty layer could be running this stack.

AIBTRUST didn't put medical records onchain, it put the consent governing them onchain, and made revocation enforceable network-wide. The same pattern works anywhere a sensitive-data ecosystem needs verifiable, real-time control. On AvaCloud-managed L1 infrastructure.

More Case Studies