# Overview

### The Need for a Dedicated Healthcare Blockchain

Availability of healthcare data is critical for advancements in health and medicine, such as drug discovery. Obtaining sufficient high-quality data involves addressing certain challenges. These challenges include balancing privacy and utilization, securing adequate consent, incentivizing data sharing, understanding data rights, and maintaining reliable records.

To tackle these issues, Hippocrat set out to establish a collaborative protocol for healthcare data. This protocol will focus on patient data self-determination, decentralized governance, and a sustainable incentive model.

Since its rebranding in 2023, Hippocrat has been committed to transforming healthcare data usage by empowering patients with control over their data. Through innovative platforms like Hippodoc (which will be upgraded into Data Hippo), a telemedicine solution for underserved regions, and strategic partnerships with industry leaders including Saluscare, Saint Mary’s Hospital, and Asan Medical Institute, Hippocrat has built a robust decentralized healthcare ecosystem. Currently, the network supports over 4 million unique health check-up recipients, with 1.4 million updating their data annually, positioning it as a leader in decentralized healthcare data solutions.

However, despite this progress, significant challenges remain. The reliance on existing blockchain infrastructure limits customization for healthcare-specific needs, making integration with legacy systems difficult. Additionally, transaction costs on Ethereum mainnet hinder scalability, while the lack of decentralized storage solutions compliant with healthcare regulations creates bottlenecks for data management. Lastly, compliance with standards such as HL7 and data privacy regulations regarding healthcare data remains a challenge.This is particularly due to the absence of a native data processing module that ensures privacy and security.

To address these limitations and fully realize its vision, Hippocrat is launching Hippo Protocol, a Layer 1 blockchain specifically designed for healthcare data. Hippo Protocol will provide a secure, scalable, and user-centric infrastructure that enables seamless data exchange while ensuring privacy and compliance with healthcare regulations.. This transition will also elevate the HP coin into a core utility asset powering a decentralized healthcare economy.

### Empowering patient data sovereignty

To date, numerous internet companies have exploited their users' data, stored on internal servers, to enhance their advertising algorithms and develop more lucrative ad products. While this business model has made services convenient and cost-effective for users, the downside is that users have surrendered considerable control over their information and data.

The non-profit international organization,[ mydata.org](https://www.mydata.org/), introduced the concept of "MyData" to address this issue. They introduced 'MyData' as part of a technological domain known as Self-Sovereign Identity (SSI), which expands into the realm of identity and allows individuals to use the internet while retaining sovereignty over their personal identity and data. This concept involves:

* 1\. Replacing the current organization-centric system of managing and processing personal data with a human-centric one.
* 2\. Treating personal data as a resource that individuals can access and control.

At Hippo Protocol, We adopt the philosophy of MyData and self-sovereign identityy, and we aspire to actualize this in healthcare. In the healthcare sector, specifically, it is critical to enable data subjects to make informed decisions to ensure their complete protection while facilitating reasonable use of their data. If this is achieved, it could propel the innovation of the internet and digital technology within the healthcare sector.

### Data ecosystems with incentives and open collaboration

The process of generating, adding value to, and utilizing healthcare data involves the collaboration of various stakeholders, including not only data subjects such as patients, but also healthcare organizations, public agencies, and companies. All of these processes involve costs to produce added value, and without the right incentives (such as financial rewards or value-added services) to motivate each stakeholder, this collaboration will not be sustainable.

Hippo Protocol provides a protocol that allows data to be traded and utilized based on the self-determination of the data subject, and when financial compensation is generated in the process, the compensation is also distributed to the stakeholders who contributed to the creation and processing of the data, including the data subject. In addition, all information in the distribution process from the creation to utilization of data will be transparent and recorded on the blockchain without risk of tampering or forgery.so an environment will be created in which we can fully cooperate without relying on the trust of third parties.

These protocols are also not determined by any particular centralized entity, but by an open, collaborative system. The tools and services you use are developed with open standards and open source, and policies and standards are determined by open discussion and consensus of those participating in governance. We aim to foster global collaboration to advance human health outcomes.


# 1. Introduction

### 1.1 Vision & Mission of Hippo Protocol

Healthcare data is one of the most valuable yet fragmented and underutilized assets in the digital economy. Patients, healthcare providers, and researchers struggle with inefficiencies caused by data silos, regulatory restrictions, and privacy concerns, while centralized entities continue to hold control over sensitive health information.

Hippo Protocol is a Layer 1 blockchain designed to address these challenges by empowering patients, decentralizing data ownership, and enabling secure and compliant data transactions for healthcare and AI applications. By integrating privacy-preserving cryptographic models, decentralized identity (DID), and scalable data storage & computation, Hippo Protocol is revolutionizing the way healthcare data is managed, shared, and monetized in the Web3 era.

Our mission is to create a global decentralized healthcare data network where individuals and institutions can securely interact, exchange insights, and drive AI-powered innovation without compromising privacy, security, or regulatory compliance.

### 1.2 The Need for a Dedicated Healthcare Blockchain

Since its rebranding in 2023, Hippocrat has been committed to transforming healthcare data usage through decentralization and patient empowerment. Over the years, we have built a strong network of over  4 million+ unique health check-up recipients, 1.4 million of whom renew their data annually. We have partnered with industry leaders, including Saluscare (Korea’s #1 B2B health check solution provider), Ever Medical Technologies (the fastest growing EMR service in the emerging markets), Saint Mary’s Hospital, and Asan Medical Institute, to create a trusted ecosystem for healthcare data exchange.

However, existing blockchain infrastructure poses critical limitations that hinder scalability, usability, and compliance for healthcare applications. Some of the primary challenges include:

* High Transaction Costs
* Lack of Customization for Healthcare Data Needs
* Data Storage & Processing Bottlenecks
* Regulatory & Privacy Barriers
* Complexity of Blockchain for Non-Crypto Users

To overcome these limitations, Hippo Protocol strives to achieve Chain Abstraction, ensuring users can interact with the protocol without needing to understand blockchain or cryptocurrency mechanics. Healthcare providers and patients can seamlessly use Hippo Protocol like any other application, with blockchain complexities—including wallet management, transaction signing, and gas fees— fully abstracted from the user experience..

### 1.3 How Hippo Protocol Solves These Challenges

Hippo Protocol is designed to be a healthcare-optimized Layer 1 blockchain, incorporating solutions for privacy, compliance, interoperability, and decentralized computing. The protocol leverages chain abstraction, decentralized storage, zero-knowledge proofs (ZK-Proofs), secure AI computations, and compliant data handling mechanisms. More details on these innovations are covered in the Technical Overview section.

### 1.4 The Future of Healthcare Data with Hippo Protocol

With millions of users ready to onboard, global partnerships in motion, and cutting-edge AI-powered applications under development, Hippo Protocol is set to become the foundational blockchain for healthcare data exchange and AI research.

By leveraging privacy-preserving AI, decentralized computing, and scalable blockchain technology, Hippo Protocol enables:&#x20;

* Patients to have sovereign control over their healthcare data.&#x20;
* Healthcare providers & AI researchers to access compliant and high-quality datasets for innovation.&#x20;
* Validators and Hippo Data Nodes to earn incentives while securing the decentralized healthcare data ecosystem.

As we move toward mainnet launch, we invite developers, healthcare institutions, AI researchers, and the Web3 community to join Hippo Protocol in shaping the future of decentralized healthcare data.

### 1.5 Key Benefits of Hippo Protocol

* Data Sovereignty: Patients gain full control over their health data, eliminating reliance on centralized entities.
* Interoperability: Seamless data exchange between healthcare providers, researchers, and patients while ensuring privacy and security.
* Low-Cost Transactions: Optimized microtransactions enable efficient, real-time data transfers.
* Decentralized Governance: A community-driven network where validators and ecosystem stakeholders influence decision-making.
* Enhanced Security & Compliance: Built-in features such as zero-knowledge proofs (ZK proofs) and HL7/FHIR compliance for secure, regulation-ready data handling.

With millions of users poised to join the ecosystem, Hippo Protocol represents a critical step in redefining how healthcare data is managed, shared, and monetized in the Web3 era.


# 2. Challenges and Solutions

### Challenge 1: Securing the Data Protocol

Data security is fundamental to Hippo Protocol, which employs DIDComm andElliptic Curve Cryptography (ECIES & ECDH) to encrypt and securely transmit data. Hippo Protocol empowers users with self-sovereign identity (SSI) by registering decentralized identifiers (DIDs) with the World Wide Web Consortium (W3C) and issuing millions of DIDs in partnership with leading healthcare institutions, thereby establishing a secure foundation for healthcare data storage and exchange.

### Challenge 2: Scaling the Data Protocol

If users encrypt and transmit data directly, this process can lead to inefficiencies and duplication. To solve this, Hippo Protocol introduces Hippo Data Nodes, which offer cryptographic and decentralized data storage. DID holders can delegate data access control using cryptographic signatures (e.g., ECDSA, Schnorr), ensuring transparency through public recording on the Hippo Protocol Blockchain.

But how can we trust Hippo Data & Computation Nodes?

Hippo Data & Computation Nodes operate as a decentralized network of resources, preventing any single entity from manipulating encrypted data. Encryption and decryption require key aggregation from multiple nodes, ensuring security and scalability.&#x20;

### Challenge 3: Incentivizing Data Providers While Ensuring Usability

A key challenge is incentivizing data providers while keeping the data usable. The industry struggles with standardization and pricing of healthcare data, especially when it's encrypted and not directly visible to buyers.

### Solution 1: Standardizing Data Format

Hippo Protocol adopts HL7-FHIR, a widely recognized standard in healthcare technology. We actively utilize AI to process and format the user data according to the HL7-FHIR.&#x20;

### Solution 2: Data Valuation Method &#x20;

There is no established method for determining data value. Also, since data is encrypted at the individual level, so that Hippo Protocol does not have access to the content, Hippo Protocol has to find innovative methods to evaluate the value of the contributed data.

Option 1 (current): Under GDPR or similar regulation frameworks, healthcare data can only be sold to a third party if it is both de-identified and traceable, which makes it very difficult to give different contributors of data varying rewards based on the value of their data. Under HIPAA, healthcare data can be traded as long as it is de-identified and under consent. Therefore, the valuation is heavily dependent on the jurisdiction the owner of the data is in. Hippo Protocol will tackle the issue by dividing the proceeds from the data equally among all the contributors. In this model, users are compensated regardless of their individual data’s contribution to the outcome. &#x20;

Option 2 (future): Hippo Protocol will leverage Privacy-Preserving AI (e.g., Federated Learning) to determine data value. The system evaluates individual data’s value based on its contribution to the result, ensuring data providers receive fair incentives.


# 3. Technical Overview

### Hippo Protocol: A Healthcare-Specific Layer 1 Blockchain

Hippo Protocol will incorporate cutting-edge blockchain innovations to meet the needs of healthcare providers, patients, and researchers. The core technological advancements include:

### 3.1 Chain Abstraction & Gas Fee Abstraction

To support users unfamiliar with cryptocurrency technology, Hippo Protocol will abstract blockchain complexities by removing the need for direct interaction with cryptographic wallets, transactions, and gas fees. This ensures that healthcare providers and patients can utilize the platform without technical barriers.

### 3.2 Decentralized Storage and Computation for Healthcare Data.&#x20;

To support the secure and scalable storage and computation of electronic medical records (EMR), personal healthcare records (PHR), and other real-world data (RWD), Hippo Protocol will integrate a decentralized storage and computation solution designed specifically for healthcare. The Hippo Protocol mainnet will be governed by a decentralized network of data & computing nodes operated by community members and key ecosystem stakeholders. This will ensure a transparent and inclusive decision-making process for network upgrades, parameter adjustments, and policy changes. This ensures compliance with global healthcare regulations while preserving data integrity and privacy.&#x20;

### 3.3 Data Privacy with De-Identification & Zero-Knowledge Proofs (ZK Proofs)

Hippo Protocol tackles the compliance issues by pre-processing the data with de-identification and encryption technology. To protect sensitive health data, Hippo Protocol will leverage:

* De-Identification Mechanisms: Removing personally identifiable information (PII) while preserving data usability.
* DID-Based Encryption: Personally identifiable information (PII) is replaced with decentralized identifiers (DIDs). We utilize decentralized identity (DID) as a foundation for secure encryption and authentication mechanisms.
* ECIES (Elliptic Curve Integrated Encryption Scheme): A hybrid encryption model combining elliptic curve cryptography (ECC) with symmetric key encryption to ensure robust security and efficiency.
* Zero-Knowledge Proofs (ZK Proofs): Enabling privacy-preserving transactions and data-sharing, ensuring compliance with regulations such as HIPAA. ZK proofs enable verifiable computations without exposing raw data.
* Trusted Execution Environments (TEE): Enhancing secure data processing for AI-driven healthcare applications.

### 3.4 Embedded Data Processing Module

A dedicated Hippo Data Processing Module will ensure seamless integration of healthcare data standards by implementing following measures during the data onboarding :

* HL7 & FHIR Compliance: Enabling interoperability with existing medical record systems.
* HIPAA-Compliant Data Handling: Ensuring regulatory adherence for U.S.-based healthcare providers.
* Secure Data Transactions: Facilitating low-cost, real-time data exchanges between stakeholders.
* zkFilter for Data Labeling: A novel mechanism for data labeling that enhances data usability without compromising security. This allows for efficient indexing and retrieval of health data for research and AI-driven applications while maintaining user privacy.
* Vector Embedding for AI Applications: Facilitating the training of AI and machine learning applications based on healthcare data on Hippo Protocol. This will open door for healthcare AI agents with functions such as:&#x20;
  * Personalized Healthcare Recommendations based on real-time user data analysis.
  * AI-Driven Drug / Treatment Discovery by structuring and analyzing vast datasets.
  * Smart Diagnostics and Monitoring powered by the user's healthcare data.

### 3.5  Escrow Technology for Secure Data Transactions

To facilitate trusted healthcare data exchanges, Hippo Protocol incorporates:

* Multi-Signature Data Escrow: Ensuring controlled and conditional data access.
* Smart Contract-Based Payments: Automating transactions based on predefined compliance criteria.
* Auditable Consent Mechanisms: Ensuring all data transactions remain fully transparent and permissioned.

### 3.6 Key Differentiators of Hippo Protocol’s Mainnet Architecture

Hippo Protocol’s mainnet differentiates itself from existing blockchain infrastructures through its unique structural components:

* Modular Layered Architecture Designed for Healthcare Data: A dedicated Layer 1 blockchain optimized for healthcare data, integrating decentralized identity (DID), storage, and computational frameworks.
* Specialized Smart Contracts: Purpose-built contracts ensuring seamless integration with healthcare applications while maintaining compliance with global healthcare standards.
* Chain Abstraction for Interoperability: Ensuring cross-chain compatibility and seamless interaction with existing healthcare IT infrastructure.

Hippo Protocol’s tokenomics structure is designed to incentivize active participation within the ecosystem:

* Majority Reward Allocation to Hippo Data Nodes: Given their crucial role in data processing, decentralized storage and AI computations, Hippo Data Nodes receive the highest share of coin rewards.
* Data Transaction Incentives: Healthcare institutions and users are rewarded for compliant, secure data contributions.
* Adaptive Staking Model: Encouraging long-term participation through a deflationary half-life reward schedule.

Hippo Protocol employs a Delegated Proof of Stake  (DPoS) consensus mechanism:

* Data Storage & Computing: Unlike conventional DPoS networks, Hippo Data Nodes also contribute to healthcare data storage and data processing.
* Dynamic Validator Selection: Ensuring a balance between decentralization and computational efficiency.

Incentivized Processing: Node operators receive rewards not only for validating transactions but also for performing AI-related computational tasks.


# 4. Hippo Data Nodes

### 4.1 Revolutionizing Decentralized Healthcare Data Storage & Computing

Hippo Protocol introduces a novel approach to blockchain nodes, moving beyond passive transaction record storage. Hippo Data Nodes play an active role in providing decentralized data storage and computational power for healthcare-related applications, particularly in AI-driven analysis and secure data processing.

### 4.2 Key Features of Hippo Data Nodes

* Decentralized Data Storage: Nodes participate in storing and securing healthcare data, ensuring resilience and privacy in a regulatory-compliant manner.
* Computational Workload Distribution: Nodes contribute to data processing and AI-related computing tasks, including model training, real-time diagnostics, and precision medicine analytics.
* HIPAA & HL7 Compliance: Ensuring regulatory adherence through secure and privacy-preserving computational mechanisms.
* Dynamic Node Participation: Both institutional partners and community members can operate nodes if they fulfil the requirements, contributing to a decentralized and scalable ecosystem.

### 4.3 Incentives for Node Operators

Since nodes are a pivotal component of the Hippo Protocol ecosystem, they receive the majority share of the coin rewards. These rewards are allocated based on the storage and computational resources contributed, ensuring a sustainable and incentivized participation model.

### 4.4 How to Participate as a Node

Partners and community members can join as nodes by:

1. Providing Storage Resources: Hosting encrypted healthcare data within a decentralized infrastructure.
2. Contributing Computational Power: Supporting AI-driven healthcare applications through secure, privacy-compliant processing.

Hippo Protocol’s node ecosystem represents a paradigm shift in blockchain technology, integrating decentralized computing with real-world healthcare applications. This innovation ensures that patient data remains sovereign, secure, and usable for advanced medical research and personalized healthcare solutions.


# 5. Ecosystem Overview

### 5.1 Participants in the Hippo Protocol Ecosystem

Hippo Protocol is built on a multi-stakeholder model, ensuring a robust and scalable healthcare data economy. Hippo Protocol aims to provide a healthcare data blockchain for following key participants:

#### 5.1.1 Data Providers / Validators

* Users, Healthcare Institutions, Health Service Providers
  * Examples: Hospitals, diagnostic centers, individual users with wearable health data.
* Individuals and institutions who generate and own healthcare data. They can choose to store, manage, and selectively share their data in exchange for rewards.
* They want to benefit by consolidating their data in a secure single point of management.
* They can choose to provide access to their data for various benefits, while keeping their data sovereignty.
* Validators participate in securing the Hippo Protocol blockchain, ensuring trust and reliability in the ecosystem.

#### 5.1.2 Data Users / Buyers

* Organizations, researchers and companies who leverage healthcare data for R\&D, clinical trials, AI model training, healthcare analytics, service improvement and product development.
  * Examples: Personalized Healthcare Solution Providers, Fitness Apps, Pharmaceutical Companies, Insurance Companies, Diet Supplements Producers, Skincare / Aesthetics Companies.
* They access privacy-preserving, compliant data via smart contracts and decentralized mechanisms.
* Any entity that wants to utilize data in a compliant manner for various applications.
* Potential Use Case of the Data include:
  * Pharmaceutical companies purchasing data for R\&D and clinical trial selection.
  * Personalized healthcare service providers using data to offer tailored health and wellness solutions.
  * Insurance companies leveraging healthcare data for risk assessment and personalized policy pricing.
  * Aesthetic and skincare brands utilizing data for customized recommendations and product development.

#### 5.1.3 Hippo Protocol Validator

* Responsible for validating transactions and maintaining the security of the Hippo Protocol blockchain.
* Validators play a crucial role in ensuring network integrity, governance, and decentralization.

#### 5.1.4 Hippo Data Nodes

* Decentralized storage and computation nodes dedicated to processing encrypted healthcare data.
* These nodes store, validate, and compute healthcare-related datasets, enabling secure data analytics and AI processing. They provide decentralized encrypted storage and computing power for AI-driven healthcare applications.
* They play a key role in HIPAA & FHIR-compliant processing, federated learning, and secure AI computations.
* These nodes are run by hospitals, clinics, and healthcare service providers to maintain data integrity and security.
* Node operators receive incentives for supporting AI applications, federated learning, and privacy-preserving computations.

### 5.2 Ecosystem Partners

Hippo Protocol is powered by a diverse network of strategically aligned ecosystem partners who play key roles in data provisioning, validation, and utilization. These partners help establish a secure, interoperable, and decentralized healthcare data ecosystem. The ecosystem is categorized into the following groups:

#### 5.2.1 Data Providers & Node Operators

Organizations that onboard and validate healthcare data onto Hippo Protocol by operating storage and compute nodes. These entities ensure data integrity, compliance, and decentralization.

* Hospitals & Clinics – Medical institutions such as Asan Medical Institute, Saint Mary’s Hospital that securely store and validate patient data.
* Healthcare Service Providers – Companies such as Saluscare that facilitate corporate health checks and decentralized data collection.
* Wellness & Preventative Health Platforms – Digital health services such as Lilius that contribute user-generated health data (e.g., personal health records, diagnostic reports, and genomic data).

#### 5.2.2 Data Consumers & Buyers

Entities that utilize compliant, privacy-preserving healthcare data for research, AI training, and product development.

* Pharmaceutical Companies – Utilize data for drug discovery, clinical trials, and precision medicine.
* AI & Research Institutions – Partners like Phoenix.AI, BitDoctor leverage decentralized healthcare data for AI-driven diagnostics, medical research, and federated learning.
* Insurance Providers – Use health data for risk assessment and personalized policy offerings.
* Personalized Healthcare & Wellness Companies – Tailor services like Vitaport based on user-consented health data (e.g., dietary supplements, skincare, and longevity research).

#### 5.2.3 Infrastructure & Technology Partners

Projects that provide critical infrastructure and integrations to enhance Hippo Protocol’s functionality and interoperability.

* Decentralized Storage Networks – Integration with Filecoin, AIOZ and similar partners to store encrypted healthcare data securely.
* Wearable & IoT Data Providers – Companies like Cudis that supply real-time life-log / biometric data from smartwatches and wearables.
* Identity & Compliance Solutions – Collaborations with DID (Decentralized Identity) and regulatory-compliant data-sharing frameworks.

These ecosystem partners play a vital role in ensuring Hippo Protocol’s success by contributing real-world data, computational resources, and technical integrations, enabling a trustless, decentralized, and AI-powered healthcare future.


# 6. HP Coin ($HP)

### 6.1 Summary

The HP coin is the core asset powering the Hippo Protocol ecosystem, designed to facilitate decentralized healthcare data storage, AI-driven services, and governance participation. Data users, AI providers, and healthcare institutions will use HP coin to access network services and data.

Following the transition from HPO ($HPO) to HP ($HP), Hippo Protocol introduces a new Layer 1 blockchain infrastructure, extending its use cases beyond data-sharing incentives to a mainnet coin powering AI-powered applications and real-world healthcare services.

Upon the launch of Hippo Protocol mainnet, HP coin will be allocated annually based on a deflationary half-life schedule, ensuring long-term sustainability and equitable rewards for network participants.

### 6.2 Coin Distribution & Inflation Model

To fuel the Hippo Protocol ecosystem, newly minted HP coin will be allocated as follows:

* 80% of annual inflation allocated to network rewards
  * 90% of rewards to nodes – Ensuring adequate compensation for storage and computing nodes contributing to healthcare data integrity and security.
  * 10% of rewards to validators – Incentivizing network participants who validate transactions and secure the blockchain.
* 10% for ecosystem growth & liquidity incentives – Supporting new partnerships, liquidity providers, and protocol adoption initiatives.
* 5% for development grants – Funding developer teams contributing to Hippo Protocol’s technology stack, with grants proposed and voted on by the community.
* 5% for airdrops and marketing – Community expansion initiatives, with allocations determined by community governance.

Community Tax Fund Allocation

* In addition to validator rewards, all remaining newly minted coins are allocated to the Community Tax Fund.
* The Community Tax Fund is fully governed by the Hippo Protocol community through on-chain voting to ensure transparent and fair allocation of resources.
* Future proposals for fund usage will be submitted, reviewed, and voted on by HP coin holders, ensuring full decentralization and transparency.

This governance-driven allocation model ensures that Hippo Protocol remains self-sustaining, community-led, and adaptable to evolving ecosystem needs while reinforcing long-term network resilience.

### 6.3 HP Coin Inflation Schedule

| Year   | Inflation Rate | New Supply Minted | Total Supply  |
| ------ | -------------- | ----------------- | ------------- |
| Year 1 | 25%            | 271,183,568       | 1,355,917,841 |
| Year 2 | 20%            | 271,183,568       | 1,627,101,410 |
| Year 3 | 8.33%          | 135,591,784       | 1,762,693,194 |
| Year 4 | 7.69%          | 135,591,784       | 1,898,284,978 |
| Year 5 | 3.57%          | 67,795,892        | 1,966,080,870 |
| Year 6 | 3.45%          | 67,795,892        | 2,033,876,762 |

* Accelerated Inflation in the First 4 Years: Encourages early adoption, node participation, and ecosystem growth.
* Deflationary Model Long-Term: As ecosystem adoption increases, utility-driven demand will counteract inflation, leading to a deflationary effect driven by increased token utility and network fee consumption.

### 6.4 Key Coin Utilities

* Transaction Fees & Gas-Free Abstraction – Enables low-cost, seamless transactions within the Hippo Protocol ecosystem.
* Staking & Validator Rewards – Stakers and validators earn HP for securing the network and validating transactions.
* Hippo Data Nodes Rewards – Node operators earn HP by providing computing and storage resources to the network.
* AI Agents – Users can pay HP Coins for:
  * Health Summary AI – Summarizes health data and medical records. Analyzes health records to generate personalized insights and respond to user-specific health queries.
  * Consultation AI – Supports medical consultations, session documentation, and SOAP note generation.
  * Data Upload AI – Converts PDFs, images, and medical reports into structured, machine-readable data.
* Healthcare & Ecosystem Services – HP coins enable telemedicine, consultations, secondary opinions, clinical trial matching, and personalized recommendations.
* Governance & Voting Rights – HP coin holders participate in protocol upgrades, policy decisions, and funding allocations through DAO governance.

Hippo Protocol fosters a sustainable, community-driven healthcare ecosystem by ensuring a fair balance between utility and reward in the $HP coin tokenomics. Hippo Protocol envisions a self-sustaining and community-driven decentralized healthcare ecosystem.

### 6.5 HP Coin Swap&#x20;

Upon mainnet launch, HP coins will be natively integrated into Hippo Protocol's Layer 1 blockchain. Coin holders will be able to verify and manage HP coins across:

* Hippo Wallets & Multi-chain Wallets
* Ecosystem Partner Applications & AI Services
* Exchange Listings & DEX Integrations

A detailed guide for adding HP coins to wallets and supported exchanges will be provided upon mainnet launch.

* HP coins can be purchased and used throughout the Hippo Protocol ecosystem. They can also be earned by participating in activities that support protocol growth, such as using Data Hippo for healthcare data management or staking personal healthcare data to the shared data pool.
* HP is a rebranded version of HPO token ([contract](https://etherscan.io/address/0xfe39c384d702914127a005523f9915addb9bd59b)).The swap and mainnet migration are scheduled for Q2 2025 following the official launch. More information can be found in the section titled ‘HPO→HP Coin Swap and Mainnet Migration.
* As of the end of March 2025, the total circulating supply is 1,034,734,274.38 HP coins. Of these, 50,000,000 coins are currently locked and will be distributed according to the distribution plan ([See detail](https://whitepaper.hippocrat.io/index/whatis/hpo)).
* Hippo Protocol will comply with digital asset regulations currently being finalized in major jurisdictions. The utility of the coin may evolve based on decisions made by the community and DAO to serve the best interests of the ecosystem.


# 7. Governance Model

Hippo Protocol is governed by a decentralized autonomous organization, in which HP coin holders participate in key decision-making processes. This decentralized governance structure enables HP coin holders, validators, and other ecosystem participants to actively shape the protocol. The governance framework is designed to ensure network security, decentralization, and community-driven decision-making. Governance is executed through:

### 7.1 Governance Participation & Voting Rights

* HP Coin Holders: Participate in on-chain governance, voting on protocol upgrades, reward allocations, ecosystem grants, and policy decisions.
* Validators: Secure the network and approve major governance proposals, including changes to consensus mechanisms and validator selection processes.
* Node Operators: Healthcare institutions, service providers, and financial institutions operating Hippo Data Nodes contribute to governance.

### 7.2 On-Chain Voting Mechanisms

* Proposal Submission: Any HP coin holder can submit a governance proposal.
* Validator Council Approval: Proposals that affect core protocol functions must receive approval through validator voting.
* Community Voting: Coin holders vote proportionally based on staked HP coins.

### 7.3 Decision-Making & Treasury Management

* Ecosystem Grants: 5% of coin inflation is allocated to ecosystem grants, which fund development teams and technical contributions. These grants are proposed and voted on by the community.
* Airdrop & Community Expansion: 5% of inflation is reserved for marketing and community growth incentives, with airdrop distributions subject to governance approval.
* Liquidity & Network Growth: 10% of coin inflation is directed toward liquidity providers and ecosystem expansion efforts.

### 7.4 Long-Term Decentralization Plan

* Early Foundation-Led Governance: During the initial phase, governance will be led by the Hippo Protocol Foundation and its early backers.
* Community-Led DAO Evolution: Over time, governance authority will fully transition to the Hippo Protocol DAO, enabling the community to make all protocol decisions.

This governance model ensures security, transparency, and sustainability, while enabling healthcare institutions, AI researchers, and Web3 participants to collaborate within a trustless and decentralized healthcare data ecosystem.


# 8. Roadmap

### 1Q 2025

* Preparation for Mainnet Transition
  * Finalize development and testing of the Hippo Protocol mainnet based on Cosmos SDK.
  * Publish a technical whitepaper detailing the mainnet architecture, features, and benefits for healthcare providers.
  * Conduct internal testing with partner institutions to ensure regulatory compliance and scalability.
* Community Engagement & Education
  * Announce partnerships with key medical institutions and healthcare providers to onboard 1.5 million users during 2025.
  * Launch a pre-mainnet education campaign for healthcare providers and institutions about the benefits of blockchain in healthcare.

### 2Q 2025

* Mainnet Launch & Rebranding
  * Officially rebrand Hippocrat as Hippo Protocol and launch the Hippo Protocol mainnet.
  * Host a mainnet launch airdrop event to incentivize users to explore the protocol’s capabilities through demonstrations of real-world use cases.
* User Onboarding & Ecosystem Growth
  * Begin onboarding users, prioritizing seamless integration of Hippo SDK with existing systems used by healthcare providers and institutions.
  * Deploy Hippo SDK v2 (v1 was on Solana and Ethereum) to enable developers and institutions to integrate with the Hippo Protocol.
* Regulatory Compliance
  * Release a framework for compliance with major healthcare data regulations, such as HIPAA, GDPR, and other regional requirements.
  * Collaborate with regulators to ensure the protocol aligns with evolving standards.

### 3Q 2025

* Scalability & Interoperability
  * Launch interoperability features to connect Hippo Protocol with other blockchain networks and legacy healthcare IT systems..
  * Introduce a scaling solution to support higher transaction volumes resulting from medical institution onboarding.
* Adoption Incentives
  * Introduce grants for institutions and projects adopting the protocol, as well as developers building applications in the Hippo ecosystem.
  * Roll out Hippo SDK v3 with advanced data-sharing and privacy-preserving functionalities.

### 4Q 2025

* Real-Life Use Cases
  * Release initial results from partnerships with medical institutions showcasing real-world use cases for the protocol, such as:
    * Cross-institutional healthcare data transfers.
    * Privacy-preserving data monetization and trading.
* Ecosystem Expansion
  * Onboard 5 additional healthcare providers and institutions to the protocol.
  * Deploy dApps for applications such as secure data exchange and healthcare data marketplaces.
* Global Outreach
  * Host DeSci Seoul 2025 as a follow-up to the 2024 event, with a continued focus on developing DeSci projects and infrastructure.

***

### 1Q 2026

* Platform Optimization
  * Release an update to the mainnet focusing on enhanced security, and compliance tools.
  * Expand integration tools or SDK for healthcare IoT devices, wearables, and electronic medical record (EMR) systems.
* Scaling Adoption
  * Begin onboarding smaller clinics and independent healthcare providers to the protocol, aiming to onboard an additional 1.5 million users.
  * Deploy region-specific solutions to cater to the unique regulatory and technical requirements of different countries.

### 2Q 2026

* AI and Data Analytics
  * Launch a decentralized AI module for personalized healthcare services, leveraging anonymized patient data on the protocol.
  * Partner with research institutions to enable secure access to healthcare data for public health research and innovation.
* Partnership Expansion
  * Collaborate with pharmaceutical companies to facilitate secure data sharing for drug development and clinical trials.
  * Onboard an additional 20 healthcare institutions, targeting regions with limited blockchain adoption in healthcare.

### 3Q 2026

* Global Reach & Advocacy
  * Host the Hippo Protocol Global Impact Summit to highlight success stories and innovations from the ecosystem.
  * Launch a global advocacy campaign for health data sovereignty, emphasizing the role of blockchain in empowering patients.
* Technical Innovation
  * Introduce cross-chain compatibility with other Cosmos SDK-based blockchains and additional interoperable networks.
  * Release version 3 of the SDK with features for real-time data sharing, enhanced security, and compliance monitoring.

### 4Q 2026

* DAO Evolution & Decentralized Governance
  * Fully decentralize governance of Hippo Protocol through DAO mechanisms, with participation from all ecosystem stakeholders.
* Ecosystem Maturity
  * Achieve full integration with over fifty healthcare providers and more than ten regional or national health systems..
  * Publish a comprehensive impact report showing the protocol’s contribution to improving healthcare delivery, patient outcomes, and data security.
* Vision for the Future
  * Announce the 2027–2030 roadmap, focusing on scaling to over 10 million+ users, expanding partnerships, and introducing advanced decentralized healthcare services.
  * Plan the launch of a decentralized global healthcare registry powered by the protocol.
* Global Outreach
  * Host DeSci Seoul 2026 as a continuation of the 2025 event, with a focus on advancing DeSci infrastructure and initiatives.


# 9. Deeper Insight Into Healthcare Data and Data Sovereignty

### 9.1 Importance of Healthcare Data&#x20;

Over the past decade, the world has talked about big data, machine learning, deep learning, LLMs (Large Language Models) and many other data-related innovations and possibilities, so most people know that data matters.

In healthcare, in particular, utilizing data measured scientifically and systematically has been in place for decades. A prime example is clinical trials, which use data to evaluate the safety and effectiveness of new treatments. Typical data generated during clinical trials are lab values measured by hospital testing equipment, gene sequences, and more. These data can be organized into well-structured spreadsheets that can be used to validate the efficacy and safety of certain medications, discover new statistical findings, and more.

In recent years, healthcare data has included data generated in hospitals and data that can be collected from wearable devices, smartphone sensors, patient self-reporting, and other sources that are part of a patient's daily life outside the hospital. These different types of data can be used to create a holistic understanding of a patient's health, considering factors beyond prescribed medications. This is called real-world data, and it's gaining traction with recent research into COVID-19 vaccines ([see](https://pharmanewsintel.com/news/real-world-evidence-confirms-efficiency-of-mrna-covid-19-vaccines)) and digital therapies ([see](https://pubmed.ncbi.nlm.nih.gov/33140981/)).

As mentioned above, data is already playing an important role in healthcare. In the next chapter, we'll explore the specific types of healthcare data and the challenges of acquiring and utilizing it.

### 9.2 Types of Healthcare Data&#x20;

There are many definitions and categorizations of healthcare data. In this chapter, we will introduce the concepts and methods of categorizing healthcare data used in this paper.

#### Classification upon the identifiability&#x20;

Most major countries, including the U.S., include personally identifiable data as an important criterion for data classification. While it's important to avoid the risk of privacy breaches, health data, in particular, can combine various valuable data to drive new innovations that improve patient and individual health. This requires a delicate approach that distinguishes between privacy and utilization.

The most prominent laws that follow this approach are the HIPAA/HITECH laws in the U.S. These two laws set out fundamental principles for the protection and use of health information and categorize health information into three categories. Health information that does not fall into one of these categories is still basically subject to general privacy laws.

| Data type                                           | Identifiability                                              | Consent for use required                  | Use for research purposes                                                  |
| --------------------------------------------------- | ------------------------------------------------------------ | ----------------------------------------- | -------------------------------------------------------------------------- |
| <p>PHI(Protected Health Information)</p><p><br></p> | O                                                            | O                                         | Possible after IRB evaluation                                              |
| DHI(De-identified health information)               | X                                                            | X                                         | Possible after IRB evaluation                                              |
| LDS(Limited Data Sets)                              | <p>X<br>(applying somewhat relaxed condition)</p><p><br></p> | <p>X<br>(Exempt for research purpose)</p> | Possible after submission of a non-identification agreement and IRB review |

**PHI (Protected Health Information)**

PHI is defined as individually identifiable health information that is created, collected, transmitted, or maintained by a healthcare entity, payment entity, or healthcare-related entity that is covered by HIPAA and that includes information about an individual's (1) past, present, or future physical or mental health condition, (2) health insurance information, or (3) medical expense status.

PHI must be utilized, corrected, and exported for purposes other than treatment only with the patient's consent, except in some exceptional cases such as public interest. Research organizations and others may utilize protected health information for research purposes through an institutional review board (IRB).

**DHI (De-identified Health Information)**

DHI is recognized under two methods: 1) the Safe Harbor method and 2) the Expert Determination method. The Safe Harbor approach removes the 18 types of identifiers listed below. The subject of the Expert Determination method is a person with appropriate knowledge and expertise in the field of statistics or science regarding identifiability or identification methods. They must determine that the information poses a very small risk of identifying an individual, even when combined with other information, and document their reasons and findings.

Institutions regulated by HIPAA are prescribed that they can use and release DHI freely. Nonetheless, in this procedure, if the information is identifiable, it is considered PHI.

\
Identifiers Type:&#x20;

Name, Address, Dates related to an individual(date of birth, date of insured, date of terminating the insurance, date of death, etc), Contact number, VIN(Vehicle Identification Number), Fax number, Device identifiers and serial numbers, E-mail address, Online access address(URLs), SSN(Social Security Number), Internet access address(IP), Medical record number, Biological fingerprint or voiceprint, Health plan beneficiary number, Photographic image, Bank account number, Suggested information to be re-identifying possible, Certification/qualification information, Possibly recognizable information moreover.

**LDS (Limited Data Sets)**

LDS is similar to DHI under the Safe Harbor approach in that it is information that has been stripped of identifiers, but it is subject to more relaxed standards and may include some date information (date of birth, date of admission, date of discharge, etc.) and information such as zip code and place of residence (state, city).

Instead, it requires users of the information, such as researchers, to submit the consent prohibiting data re-identification that outlines how they intend to prevent data abuse, and stipulates that if the information is used for certain purposes (research, public health, health care delivery), it can be used without the patient's consent and after going through an IRB. In other words, it puts the onus of re-identification on the user and makes it easier to put the information to valuable use.

#### Classification of the data contents

In addition to individually identifiable possibilities, there are many other ways to categorize data, such as whether it is structurable, who created it and how, what it is used for, and what it is about. However, rather than applying strict classification criteria or describing all types in detail, this whitepaper focuses on introducing representative types that are important in terms of their use value and helping you understand how each data type is utilized.

**Clinical Data**

It is the most representative healthcare data and a type including patient information generated when medical centers like hospitals and so on proceed with the diagnosis, injection, running tests, surgery, etc. Therefore, from the structured test numerical value to medical records to the digital screening and image(X-ray, CT, MRI, sonogram, endoscopy, etc) written in natural language, various detailed items are existing.

This information is called EMR(Electronic Medical Record) when saved electronically. Furthermore, the total personal medical information stored in many places is called EHR(Electronic Health Record). Clinical Data is PHI(Protected Health Information) at the generating stage, and strictly prohibited to access and utilize this data for other institutes except for the patient under the duty and responsibility of medical centers to store under the law.

Claim data, derived from clinical data, is based on the information submitted when making an insurance claim from the medical center to the insurance institute. Here, the patient's privacy, diagnosis, and medication information are included. In Korea, the single insurance system is adopted, HIRA(Health Insurance Review & Assessment Service) and NHIS(National Health Insurance Service) established and have opened the public data based on the whole nation's data ([Healthcare Bigdata Hub](https://opendata.hira.or.kr/home.do),[ Sharing service of NHUS materials](https://nhiss.nhis.or.kr/), etc). Korean pharmaceutical company, HK Inno-N utilized this and launched a new medicine called K-CAB for gastroesophageal reflux disease([reference](https://www.docdocdoc.co.kr/news/articleView.html?idxno=1046804)).

**Omics data**

It means a data set of total concepts including the biomaterials like genome, transcriptome, proteome, metabolome, and microbiome. These biomaterials each have distinctive features and expect to be personalized medical services when the related data can be accumulated and analyzed on a large scale.

Genome data is the most representative omics data and means data to represent a genetic code recorded on DNA deciding the personal features through sequencing listing by combining alphabets A, T, G, G like a cryptogram. In fact, analyzing genome data seems like decoding the cryptogram, and the main task is to analyze what makes a difference between individuals depending on a single or plural nucleotide at a certain spot. In particular, more than 80% of the cause for the rare disease is a genetic mutation, so decoding the cryptogram is important to figure out the gene causing the disease.

Recently, the progress of technology for machine learning and analyzing big data can make it possible to utilize clinical data and analyze it complexly. Through this, it is possible to make an early diagnosis and utilize for finding a biomarker used for predicting and measuring the treatment reaction.

**PGHD (Person-generated Health Data)**

Without depending on the external institutes, it is data generated from the various sensors from wearable devices, cellphones, etc, possessed by patients or individuals or data including self-uploaded postings on SNS or surveys. These data have a feature to be collected frequently from routine life without visiting hospitals.

PGHD seems to be not related to the disease, but it is possible to find new discoveries about the disease when it combines with clinical and other data. Actually, in recent new medicine clinical trials, it tends to keep trying actively to utilize PGHD as RWD(Real-world Data)([Reference](https://d3.harvard.edu/platform-rctom/submission/evaluating-new-drugs-with-wearable-technology/)).

**SDOH (Social Determinants of Health)**

SDOH is data affecting the health among decided social or economic external factors by nature like population statistics information, social or political factors, climate, or environment.

[Gravity Project](https://thegravityproject.net/) is an actual case to utilize SDOH data. This project regulates the social or economic factors (education, job, home, income, social safety), physical environment, health(smoking, eating habits, alcohol, sexual life), and public health(access to medical center) as the staple factors and aims to analyze the influence on health.

**Research Data**

It is data generated to develop the new treatment method from the laboratories and pharmaceutical companies or hospitals related to Medicine, Pharmacy, or Life Science. Typically there is data to be the result of clinical trials or research. Clinical data or Omics data generated already can also be research data in case of being re-utilized or collected for the research.

Research data is necessary to cooperate with the various institutes to secure enough participants for research progress. It is not easy to communicate with people who speak different languages. If other institutes use the titles and units for equal data differently, it will be difficult to communicate and cooperate. Therefore, research data is mostly well structured and collected under the unified rules between institutions conducting the research together. Consistently, an effort on standardization like CDM([Common data model](https://en.wikipedia.org/wiki/Electronic_health_record#Common_data_model_\(in_health_data_context\))) is continuing the integrative analysis for patients' data accumulated through integrative analysis or various types of research targeting the internal data from different hospitals.

Mostly, research data is scientifically strict, designed for systematic collecting, and verified by academia and reviewing institutions. Also, before conducting the research, it is distinctive to have high-quality data enough to get reviewed regarding the legality and suitability for data collecting subjects and collecting methods from reviewing committees like IRB, etc.

**Other Data**

Moreover, there is meaningful data when combined with other healthcare data and analyzed even though it is not related to health itself, like personal payment information. For example, payment details of personal regular fitness centers seem not to be related to health itself. However, certain health-related figures are improved or worsened. We can try to predict the change in the personal health index by relating and analyzing the payment information.

Like this data, its value can be much higher when combining different data types. Therefore, when certain data is combined with the generally-known healthcare data, it is a very important future task to utilize it worthwhile.

### 9.3 Problems to be solved for Individual Healthcare Data Control & Management&#x20;

Data is being used to enhance health outcomes and pave the way for new advances in disease treatment. However, despite the immense amounts of money invested and the potential benefits promised by technologies empowered by big data, the actual results have not met expectations. The primary reasons for this shortfall include a lack of data that is reliable, collected over an extended period, and correlated.

In simpler terms, beyond artificial intelligence or big data technologies, the quality and quantity of the foundational data are crucial for innovation in healthcare. In this chapter, we will explore the challenges associated with obtaining sufficient, high-quality healthcare data.

#### 9.3.1. Adequate balance between protection and utilization of data

**Type 1. Difficulties in Combining and Analyzing Data Due to Anonymization**

An individual's medical information is one of the most sensitive types of personal data. It is increasingly mandated by laws worldwide to be protected in very rigorous ways. The most prevalent protections are pseudonymization and anonymization. These processes de-identify data, making it challenging or even impossible to identify an individual, thereby reducing the risk of harm from data breaches or misuse. De-identified data, when securely anonymized or pseudonymized, can be freely used for certain purposes, such as research to develop new drugs and treatments. Consequently, major countries are enacting legislation that allows data to be used for valuable purposes while minimizing the risk of personal identification.

Nevertheless, these privacy measures inevitably pose limitations when it comes to extracting value from the information. When data sets are combined, they can be analyzed more comprehensively, thus creating new value. However, pseudonymized data either abstracts or categorizes data values. For instance, a 33-year-old individual is described as being 30 years old, a person weighing 87 kilograms is described as weighing between 80-90 kilograms, and so forth. Depending on the purpose of data usage, this can be inappropriate. Furthermore, combining data sets often enables us to achieve results that would not be possible with individual datasets alone, and anonymizing data makes this very difficult.

<figure><img src="https://lh7-rt.googleusercontent.com/docsz/AD_4nXcWkKEnbU8h0cZvttlBNbspVI7cb7p_f_Pq3eqW3aYRiNxa7we_Hh80JGV-KS3y9nKZsjeBSqA8CLCjOoW731xQ_I9c3LW2HIAgYW27nv2uGem_ZrD5fZZcjiE-LBjJsFKkD5RYVQ?key=fUWQ9eDkcrmDnZr3M9bUxbfG" alt=""><figcaption></figcaption></figure>

**Type 2. The difficulty transmitting and utilizing data under the graded protection based on data generating location**

Even if the data is not personally identifiable, it may face rigorous protection simply because it was generated in a hospital or pertains to genetic information, thus creating significant obstacles in its practical use. For instance, as of November 2022, in South Korea, if a patient measures their blood sugar at home with a personal device, it is categorized as health information and can be freely transmitted and used for any purpose. However, if the same blood sugar information is collected in a hospital and stored in an Electronic Medical Record (EMR), it falls under the Medical Act's jurisdiction. In such a scenario, even if a patient requests it, the hospital cannot directly send the data to another organization providing blood sugar analysis services. Currently, the only way to transfer this data is by the patient personally visiting the hospital, receiving the information, and delivering it to another organization.

Data subjects should have the self-determination right to decide who will know their information, to what extent, and how it will be used. For general personal information, laws such as the Personal Data Protection Act guarantee this right. However, medical information is governed by the Healthcare Act, which only guarantees self-determination rights as part of the data subject's data portability right (access rights, the usage of structured data formats, and the right to request transfer to a third party).

The frustration originates from how organizations, like hospitals, manage and account for patient data. While the original intention was to protect sensitive medical information, it inadvertently made it challenging for patients to access quality medical and health services, as they cannot transfer or aggregate their data to other organizations at their discretion. Consequently, patients' medical data becomes fragmented and stored by individual healthcare organizations. In such a situation, it becomes virtually impossible to provide customized services such as precision medicine for each individual patient. Thankfully, laws concerning 'my data' have first been implemented in the financial sector, and discussions are in progress to enact legislation to actualize the portability right and complete self-determination of personal medical information.

#### 9.3.2. The way of retaining proper agreement and providing the post-right of control

As explained above, the extent of data currently available for use without explicit patient consent is limited to a select few purposes, like research and statistics. Additionally, the quality of such data may be compromised. To amass as much data as possible without these issues, it's essential to inform and secure consent from data subjects such as patients, concerning the types of data to be gathered, its purpose, and the usage terms.

**Type 1. Consent Acquisition Issues**

Securing this consent is a fundamental prerequisite for any organization seeking to use the data. Consequently, these organizations will aim to get patient consent to maximize the unrestricted use of data. However, the downside is that consent might be procured in a way that inadequately safeguards the data subject. In fact, both EU ([case: German Consumer Federation v. Planet49](https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX%3A62017CJ0673)) and Korean courts ([case: 1mm notice on sweepstakes tickets](https://www.law.go.kr/%ED%8C%90%EB%A1%80/\(2016%EB%8F%8413263\))) have ruled that passive consent, such as via a pre-selected checkbox, or consent gathered in a manner that is not easily recognizable to the data subject, is invalid.

Nevertheless, the cause of such "inadequate consent" is not necessarily attributed to the organization's ill intentions. It could be due to the complexity of the language used in terms of service and privacy policies, which could make it difficult for most people to comprehend. Alternatively, the very act of consent, intended to protect privacy, might paradoxically become burdensome for individuals, causing them to agree or disagree mindlessly, rather than ensuring the terms and conditions align with their best interests. Hence, even if an organization's intention is to better safeguard privacy (at least in terms of complying with the law in good faith), the outcome might still be inadequate consent.

On the flip side, a patient's understanding of how their data will be beneficial and the potential risks involved could also influence consent acquisition. The greater the perceived personal benefit from using their data, and the more they comprehend the risks, the more likely they are to provide informed consent.

<figure><img src="https://lh7-rt.googleusercontent.com/docsz/AD_4nXcYRaH9YjW1BQuOH0KH9Ge-ejj1RAYnEw3-nl1vZEZzR8O8N9Ieb-EGDT17ggbMY_rtDR7c6u7jKG9hsbv1ztiIsWG9MEkMMpei-F0XW_iRHnopgdynfv0kR082GvliEMvJ9Yza-A?key=fUWQ9eDkcrmDnZr3M9bUxbfG" alt=""><figcaption><p>It is important to get consent judged by the information subject not forced.</p></figcaption></figure>

\
**Type 2. Needed to provide the authority to control the data after consent**

On January 20, 2020, the U.S. Department of Health and Human Services (HHS) altered the Common Rule, allowing for the secondary use of data without additional consent, even if the data is identifiable and not used for research purposes. This condition is fulfilled if an informed, blanket consent is obtained initially. This modification aims to boost research efficiency and data value by eliminating the time and cost involved in acquiring patient consent each time, except when specific risk factors are present. It could also be beneficial to gather data with consent for a broader purpose, as plausible uses often cannot be anticipated until after the data collection.

However, it's crucial to offer patients access to complete histories of their data use and disclosure, as well as the right to revoke consent for the use of their data. An alternative approach is to implement a dynamic-consent system that collects data upfront but gives patients the chance to view more details at the usage point, and the option to either opt-in or opt-out at any moment, even after consent has been granted.

Securing informed consent and preserving the right to manage data post-consent is vital for protecting privacy and extracting value from data utilization. Achieving this will deliver a positive experience in terms of information transparency and system trust, expectations that will only increase in the future. This is a crucial consideration for organizations aiming to acquire patients and users, regardless of the legal dimensions. Thus, solutions that facilitate informed consent-based data management and usage are required from the perspectives of patients, organizations aiming to use data, and organizations managing data on behalf of patients.

#### 9.3.3. Absence of incentives for data sharing

Major countries are implementing laws to strike a balance between privacy and data utilization through patient data self-determination. A notable instance is the[ 21st Century Cures Act](https://www.fda.gov/regulatory-information/selected-amendments-fdc-act/21st-century-cures-act) in the U.S., which mandates healthcare organizations to ensure that patients' medical information, stored within these organizations, is interoperable, and that patients can access, exchange, and use their medical information in their chosen applications. Non-compliance can result in penalties up to $1 million per violation.

However, numerous healthcare organizations still share data in formats that are challenging to read and utilize electronically. Other companies and researchers are legally prevented from sharing data with patients, even with consent, or are hesitant to supply data due to data protection concerns, even in countries where such laws do not exist ([Reference 1](https://www.raps.org/news-and-articles/news-articles/2022/5/commission-proposes-european-health-data-space-to),[ Reference 2](https://www.cnbc.com/2020/02/05/epic-about-60-hospitals-sign-letter-opposing-hhs-proposed-data-rules.html)).

In South Korea, the Ministry of Health and Welfare is advocating for MyData legislation and a pilot service in the medical field called MyHealthway.[ Recent reports](https://www.etnews.com/20220518000216) indicate that medical institutions will not be compelled to comply with patient information transfer requests, but voluntary participation will be encouraged to improve service quality for individuals and patients. Private companies other than medical institutions will be eligible to participate after 2024, but this is still far from realizing the right to strict data self-determination.

As such, data self-determination can only be achieved through legal obligations or penalties. Ideally, it would be propelled by the voluntary motivation of ecosystem stakeholders. However,[ a survey by the U.S. National Academy of Medicine](https://nam.edu/sharing-health-data-publication-social-media-toolkit/) found that executives from healthcare organizations reported a lack of economic incentives to share data, alongside concerns about losing a competitive edge by external data sharing. In reality, data sharing measures such as data structuring, standardization, quality control, and data archiving often require the resources and expertise of the data-generating healthcare organization, while the benefits are more likely to be reaped by the data-using organization. This misalignment of incentives complicates voluntary participation by data generators.

Required actions for sharing data<br>

* Data Structuring and Standardization
  * Clinical data often presents inconsistencies in the terminology used in unstructured text formats. The challenge here is to structure this data so that it is comprehensible to a computer.
  * Additional efforts should be made to standardize data types, terminology, and formats to facilitate collaboration via data sharing.
  * Introduce searchable metadata to determine the existence of duplicate data and to identify combinable data.
* Quality Control
  * Identify and rectify mistakes such as patients with multiple health conditions only entering the diagnoses necessary for insurance claims, or unintentional omission of information or erroneous entries during manual record keeping.
  * Endeavor to resolve issues of accuracy with measurement devices, including inconsistent results depending on the proficiency of the user.
* Storing Data
  * Store and manage up to 200 GB of genomic data per individual ([note](https://medium.com/precision-medicine/how-big-is-the-human-genome-e90caa3409b0)).
  * Employ technologies that facilitate the storage, management, and transfer of data in a compact form, making it easily reanalyzable.

<figure><img src="https://lh7-rt.googleusercontent.com/docsz/AD_4nXcPz36EElxBKKHEZvWAPftxdz3nXmGusiZRB5abcyEyRUIpTl_fwSozooTaqqKgwEKP-FzFpclO26_ySvaTqk0_XNxehJUFrL6yzQIg64Wyp9dNVR5rDqRvkJjxH8ES4UEZ8vInRQ?key=fUWQ9eDkcrmDnZr3M9bUxbfG" alt=""><figcaption><p>The cooperation with many people is required to create the data.</p></figcaption></figure>

#### 9.3.4. The understanding of data rights and the absence of reliable records

The concept of incentives is closely tied to consensus on data rights. It's widely agreed that patients should have autonomy over their data. However, the idea of ownership, which is intricately linked to incentives, is more complex. Generally, the notion of ownership applies to physical assets like real estate or objects. For intangible assets, there are intellectual property rights like copyright and patents, but these are only recognized when there's creative input involved. Therefore, copyright only applies to compiled databases, not to raw information or data as such.

Creating a patient's medical data involves substantial work. Beyond the basic data primarily gathered by healthcare professionals and machines in medical institutions, a significant portion is produced through expert evaluation or interpretation, such as diagnoses or positive-negative test results. Furthermore, several steps need to be taken before the data can be shared and used in a meaningful way. Sometimes, additional effort is needed to merge separate data. The outcome is a dataset compiled with significant investment and expertise from medical professionals.

Moreover, it's worth mentioning that healthcare data is public, supported either by a health insurance system or a publicly-funded healthcare system. Therefore, rather than securing exclusive revenue and usage rights for a specific entity, it would be more advantageous for the public and the data subjects to guarantee non-rivalry, that is, one entity's use of data doesn't limit its usage by others. This would permit more extensive data use.

Currently, there's no reliable method to document this history of ownership, data sharing, and usage, and to make it openly available and usable for all stakeholders.

### 9.4 Self Sovereign Identity and MyData

Self Sovereign Identity (SSI) is a new model suggested to represent an individual's identity online. The technologies enabling this model, Decentralized Identifiers (DIDs) and Verifiable Credentials (VCs), were officially accepted as web standards by the World Wide Web Consortium (W3C) in July 2022. ([Reference](https://www.w3.org/2022/07/pressrelease-did-rec.html.en))

Instead of making individuals trust a company (or agree to terms to use a service) and entrust their personal data to be managed on their behalf, self-sovereign identity technology allows companies to request the individual's consent to access and use their data. Crucially, the individual maintains full control over their information.

This represents a paradigm shift in which individuals can actively decide to share only the information they want and control its use. Furthermore, it creates a landscape where hackers can only attack one individual at a time. In contrast, previously, they only needed to infiltrate a centralized server once to steal vast amounts of personal information, ranging from dozens to millions of records. This reduced incentive to hack individual data makes the system ultimately more privacy-protective.

Leveraging self-sovereign identity technology, Hippo Protocol aims to actualize the concept of 'MyData'. This concept permits individuals to exercise self-determination not only over their personal identity information but also their medical data.

<figure><img src="https://lh7-rt.googleusercontent.com/docsz/AD_4nXeQA3hM4gLHjN_NhFeWN-rg7Uo49TN4vq4-a-Vp5llszA9cyPRmYS-Csj9GISDmtj0zEmDbpYiIl4_U58IXlGo3LlFnDtyB16wilzvpoUwZbevakZa7jvda04_Kn5ohqL5DNDahQg?key=fUWQ9eDkcrmDnZr3M9bUxbfG" alt=""><figcaption><p>MyData model can fix the problems of the API  model becoming excessively complex and the platform model without incentives for intercompatibility.</p></figcaption></figure>

#### 9.4.1 DID: Identifier for self-sovereignty

The MyData model addresses the complications of convoluted API and platform models that lack incentives for data interoperability. Source: mydata.org

Up until now, our digital identities have been solely determined by accounts we hold on servers of services offered by specific companies. This arrangement necessitates the creation of a new account each time we opt for a new service. Furthermore, if identity verification is required, the process must be repeated for each service. Consequently, many people have defaulted to using accounts from larger services like Google and Facebook to log in. However, this practice results in an accumulation of personal data on a single server, heightening the risk of hacking. As our dependence on a specific service grows, so does our vulnerability to account suspension or restrictions, particularly if we are perceived as breaching the company's policies. This was recently exemplified by the US-based payment service Paypal, which attempted to implement a policy enabling it to impose a $2,500 penalty on accounts of users found in violation of its regulations. ([reference](https://news.yahoo.com/paypal-policy-permits-company-fine-143946902.html?guce_referrer=aHR0cHM6Ly93d3cuZ29vZ2xlLmNvbS8\&guce_referrer_sig=AQAAAM42UWnNy1hmC1hkIIlf4SKW3rCgvDkLJIbkmNzwnpFqcrsmcUoHK7pnrKMaL7nFuyQnb0aOI2kGoh4-k6lwitsmJ9ESAx1QbMm53F7gjgajsU-x1w6SRSRqnYec_HzK7wcakI0o58AZjvjqUfQQMt-cKuHCU0n5oANPclq0yy1r&_guc_consent_skip=1684991969))

DID (Decentralized Identifier) offers a solution to these issues. A DID is a unique identifier, created independently using mathematics and cryptography, and can be used freely across the internet. The concept is akin to assigning a unique number to every atom in the universe and randomly selecting one to be given a password (private key). This key enables control over the ID generated from that unique number and its associated information. Personal account details and associated data are stored on a blockchain, with access and control limited to the private key owner. This approach enables us to construct and manage our identities independently, free from government or corporate influence. This method is particularly advantageous in healthcare, a sector necessitating high privacy levels. As long as all computers and the internet connected to the blockchain persist, our identity record and control over it can remain secure, thus actualizing the self-sovereign identity envisioned by Hippo Protocol.

\
**9.4.2 VC(verifiable Credential): All things proving myself**

Birth certificates, college degrees, passports, driving licenses, employee IDs, gym memberships, hospital registration cards, and prescriptions all describe and validate specific details about me. For instance, when I visit a pharmacy and show my prescription, I am able to demonstrate that a specific medication for a particular condition was prescribed to me by a certain doctor at a particular hospital. This reassures the pharmacist to dispense the medication with the certainty that the prescription is valid, and the receipt I get from the pharmacy affirms that I indeed received the prescribed medication. When these documents are collectively submitted to your insurance provider, they enable you to make a claim based on a validated record.

A Verifiable Credential (VC) comprises specific information that describes and validates certain facts about you. The data contained in a VC includes the issuer (the DID of the issuer), the subject of the credential (the DID of the data subject), and the claim being made (such as age, relationship, diagnosis, etc.), and the holder (the DID of the holder, often the same as the data subject, but a guardian could be the holder if the data subject is a minor). All this information must be verifiable, including who issued it, whether it has been tampered with, and whether it has expired or been revoked.

The traditional physical credentials referred to in the initial example are all susceptible to forgery and pose significant challenges for online verification. To address this issue, separate attestation devices and verification authorities like signatures and holograms have been used, but they fall short in privacy protection and have many cost and technical limitations for online use on a global scale. As VCs are issued on a blockchain that can be transparently verified by anyone, they can be authenticated online much quicker and at a significantly lower cost. Owing to these advantages, DID and VC were developed with financial support from the US Department of Homeland Security among others, and were adopted as open global standards in July 2022.

The importance of VC is also evident in realizing the collaborative healthcare data ecosystem that Hippo Protocol aims to establish. If patient data could be verified without the need for an intermediary, it would minimize the friction in the distribution and utilization of the data, thus cultivating a more dynamic ecosystem.

#### 9.4.3 Exchanging safe healthcare data

As previously discussed, blockchains are most effectively used to store a minimal amount of data in a highly secure and trusted repository, like an asset register or an identity ledger. However, while certain information can be recorded on a blockchain, the storage of large amounts of healthcare data, such as PGHD (Patient-Generated Health Data), which can span from a few hundred GB of genomic data to several TB, is neither practical nor necessary on a blockchain.

In such a situation, a viable solution could be allowing data to be transmitted and received through the Elliptic Curve Integrated Encryption Scheme (ECIES). This is a standard framework for data encryption delivery that utilizes the Elliptic Curve Diffie-Helman (ECDH)-based multi-signature technology as per the[ DIDComm](https://didcomm.org/) standard. This ensures that data is securely encrypted and decrypted, making it inaccessible except by the two parties explicitly involved in the data exchange, and bypasses any intermediary servers. This means patients can exchange large volumes of data directly with healthcare organizations and data utilization entities without reliance on other entities. Consequently, the data distribution pathway can be made highly efficient, minimizing the risk of privacy breaches. Coupling this with appropriate incentives can make data trading a reality.

An alternative solution is leveraging the InterPlanetary File System ([IPFS](https://ipfs.tech/)), a protocol for distributed storage and sharing of files. When a file is uploaded to an IPFS network, it gets distributed across multiple nodes. Simultaneously, a unique identifier - the Content Identifier (CID) - is generated from the file's hash value that serves to link the distributed files. If a large patient-specific dataset is encrypted using the patient's public key, uploaded to IPFS, and issued with the CID in a VC (Verifiable Credential), the patient can confidently share the data with another organization, which can then verify the data's integrity by ensuring the CID hasn't changed.

Lastly, secure data exchange can also be facilitated through numerous personal devices and relays, interconnected peer-to-peer with cryptographic key pairs, like[ DWN](https://identity.foundation/decentralized-web-node/spec/) and Nostr.

Secure data exchange can be executed in various ways, and the methods outlined above are not the only ones that Hippo Protocol will consider. We plan to design the protocol in conjunction with the community to ensure it remains open and receptive to improved solutions.

### 9.5 Issuing and utilization of data

#### 9.5.1 Issuing data

Organizations or entities that issue data can do so via verifiable credentials (VCs). This issuance can either be done individually upon receiving requests from data subjects, or in bulk by inputting the subjects' DIDs into an internal admin page. Either way, it requires transforming the data model so that internal agency data can be released in the form of VCs. Currently, VCs can be issued in two syntactic representations: JSON-LD and JWT. Alternatively, one can encrypt the data file with the data subject's secret key, upload it to distributed storage, and incorporate the file's hash value into the VC without transitioning to these data models.

<figure><img src="https://lh7-rt.googleusercontent.com/docsz/AD_4nXe_4hNIytUv1En58hHjANg-pOm5kvkUyFWQZqenuaULG6fsyuX-JG8T0ExC_WrS4GwzZDLPgVlsL6LeaOrPV45PZ37vj1vXcediAxeeRxA49BqXHOuiOkSciL3pA3hsBBD9A1ITgg?key=fUWQ9eDkcrmDnZr3M9bUxbfG" alt=""><figcaption></figcaption></figure>

Another significant detail included in the VC is the commission rate that will be allocated to the issuing organization's share when the issued data is sold. Up until now, data issuing organizations have had no feasible way to earn from their share of data that exits the organization. However, with VCs, all data is subject to the patient's decision to circulate, and any data that is traded for a fee with the patient's consent is automatically divided between the patient and the issuing organization. This enables the issuing organization to gain incentives from data use, besides the data issuance fee. This mechanism motivates issuing organizations to prepare and issue more reliable and usable data.

#### 9.5.2 Data Utilization

Organizations developing AI healthcare solutions, leveraging existing ones to offer data-driven healthcare services, or aiming to screen clinical trial participants, can use Hippo Protocol to harness trusted, consented data. The first step requires preparing a data wallet (Data Hippo) and a Decentralized Identifier (DID) for the organization intending to use the data. They must also integrate a software development kit (SDK) tailored to data utilization into their internal services, readying them for data usage.

The process of data enrichment involves linking the individual's DID with the utilizing organization's DID. Typically, the individual is asked to scan a QR code for login, authentication, or connection purposes, at which point they provide their consent. The organization doesn't need to request all data at once. Initially, it can request only the information needed for basic service usage. Further data requiring a higher level of user consent can be requested separately. This method ensures that the right data is available at each user conversion stage.

In order to obtain consent, the organization must clearly communicate to the individuals who they are, what permissions are being requested, and what data will be used under what conditions. This is similar to presenting and obtaining legal notices for data collection and use, like conventional terms and conditions and privacy policies. However, the key difference is that organizations can use standardized terms certified by a governance framework.

This approach has several advantages. Individuals aren't burdened with fine-tuning legal notices every time, as discussed in the management of consent (signatures) in the data wallet. Furthermore, organizations can adopt licenses that meet specific compliance requirements for different countries and contexts. This significantly reduces the cost and time associated with legal review, making it easier to obtain informed consent.

<figure><img src="https://lh7-rt.googleusercontent.com/docsz/AD_4nXcmCfqId1MJkPpSaNmS-8GWzRxsJOsLJZmSrz7xv_4aGpVvqrcOIyOZCvoDVqcUWneTCAguSmdMhwH-WG69HOJGFuF4wY8Bl_Cb0cxjJwvY1-dc4nZuNt0dNdA-_9LbRJ4uxJTeQQ?key=fUWQ9eDkcrmDnZr3M9bUxbfG" alt=""><figcaption></figcaption></figure>

Data user institutes can use the standardized protocol of Hipp Protocol DAO and license through CompliantData SDK.

The features mentioned above could initially be implemented in Data Hippo. Along with the use of a data utilization SDK, patients could access healthcare and community services through the data stored in their personal data wallets. This SDK is freely integrable into other for-profit and non-profit products, requiring no contracts.

Data Hippo could be the initial use case for the Hippo Protocol ecosystem, enabling patients to take advantage of their data wallets. Data Hippo offers trusted, personalized information, healthcare solutions, and community experiences to patients. This is achieved by using data gathered with informed consent. Additionally, patient-derived health data generated during service use, as well as clinical data submitted via the wallet, can be processed into a format that can be used by other data-requiring organizations like pharmaceutical companies. This will allow for value-added data sales. The entire process is based on patient consent, and the revenue generated serves as a shared compensation source between the patient and the data issuing organization. This promotes sustainable data compensation and usage.

To make this scenario work, conditions for data use and compensation are included in the patient's consent. Depending on the degree of privacy disclosure, data can be categorized into protected health information, de-identified health information, and limited datasets. Alternatively, it can be classified into identified health information, anonymous health information, and pseudonymous health information. Generally, the greater the privacy level and information requested, the higher the reward. However, this also increases the likelihood of a patient declining to protect their privacy. Consequently, organizations wishing to use the data will strive to obtain only the essential data required to persuade patients. Moreover, since data creation requires significant public resources, the system can be designed to distribute a larger reward percentage for public purposes, the more pseudonymous or anonymous the information is and the more it's used for scientific research. This mechanism could potentially enhance the quality of public healthcare.

<figure><img src="https://lh7-rt.googleusercontent.com/docsz/AD_4nXdsCINTeiP-azVdJlHkLzGvVD6-5DFkVBJ2TBr6qAvvr7pfPY9TXtQd7Oo7eUDqVih4mqwVnzsPdIcMvQnv9nc8PxHozHoVkADr2urd647DbFkjJkllt0mZJN-UtgcE_aVkjp9bUg?key=fUWQ9eDkcrmDnZr3M9bUxbfG" alt=""><figcaption><p>The more compensation for data, the more possibilities to get the consent of sharing data as less risky for privacy infringement.</p></figcaption></figure>

## 9.6 Hippo SDK

The Hippo SDK is an open-source development kit that empowers data subjects to construct data wallets that govern their identity, data acquired from organizations, and rewards earned from data sharing. Keeping a person's data in a data wallet is akin to holding a key card or receipt that grants access to that data, rather than storing the original data itself. This is comparable to owning a wallet that contains not just cash or credit cards, but also IDs, membership cards, tickets, blood donation records, keys, receipts, and more, which can be accessed whenever needed. If you misplace your wallet, you lose everything in it, indicating you have complete control and, consequently, full responsibility. The same principle applies to data wallets.

In this section, we'll present the primary features we aim to incorporate in the Hippo SDK. The majority of these are grounded on open standards and open source, enabling us to add value centered on the problem Hippo Protocol is tackling, rather than reinventing the wheel, using already proven technology. This strategy minimizes potential intentional and unintentional bugs that might occur in new software while still enjoying the ongoing enhancements and innovations facilitated by open standards. Moreover, it allows the user's assets and data in a wallet developed with the Hippo SDK to be accessed through various applications, augmenting the user's utility.

### Generation and Management of Private Keys

The Hippo SDK's fundamental function is to securely generate and store the private keys required for accessing and managing your assets, data, and decentralized identity (DID). Owing to its compatibility with the Cosmos SDK standard, it offers the same level of security as most blockchain wallets for private key generation and mnemonic code recovery. Hence, the Hippo SDK can also be utilized to implement basic blockchain wallet functionality. The device's trusted execution environment (TEE) can be deployed for added security in private key storage.

### Connection, Authentication, and Sign-in

Once a DID is established, it facilitates peer-to-peer connections with the organization accessing your data without any intermediaries. All data and messages shared between the two parties are encrypted end-to-end, ensuring that only those involved can view the contents, thus minimizing the risk of privacy breaches during communication. The initial connection is usually initiated by scanning a QR code or clicking a button on the organization's app or website. Users then verify and approve information about their connection partner, including permissions and data requests. Once connected, the relationship is remembered as a trusted association unless terminated by either party.

In the healthcare context, hospitals often require patients to register as new patients during their first visit. This involves pressing a registration button and scanning a QR code with their data wallet, which requests them to share their legal identity: name, social security number, photo, gender, etc. If the patient consents, a hospital representative verifies the patient's identity from their data wallet, and the patient is registered.

This approach eliminates traditional logins and other authentication methods, eradicating the need for users to generate and remember usernames and passwords for every service they wish to connect to. It allows users to log in, authenticate, send and receive assets and data, and more, simply by recognizing a QR code. The data wallet application can also use additional security measures such as PINs and biometrics in tandem with the private key, providing effective multi-factor authentication (MFA) and a much higher level of security than typical login methods.

<figure><img src="https://lh7-rt.googleusercontent.com/docsz/AD_4nXeyj81s9i18OnQb7FsKmCe5FaDB_whMn402lY-ZDStJWIn57GeMR8efHkymy310R_lsQhXBRgunVAKybsNB1cvWU0qx1XucTkgG0DSfFbIagqLw2ckqMfoeT7oklrF3hhalLWbPQA?key=fUWQ9eDkcrmDnZr3M9bUxbfG" alt=""><figcaption><p>Log in, authenticate, and transfer assets and data just by scanning a QR code.</p></figcaption></figure>

### Data(VC) management

When linked to an entity, say a hospital, through a data wallet, original data or its certificates can be mutually exchanged as per your request or when the other party sees fit. Usually, when a hospital dispenses data like medical records, they undergo an authentication process to confirm the patient's identity before issuing it as a VC to the patient's data wallet. A notification and a message alerting of the new data issuance requiring authorization is then received by the data wallet. Upon authorization, the data becomes accessible. Unlike conventional cloud storage, the user's encryption key secures all data.

Such data can be showcased wherever required. For instance, a data-driven healthcare service might ask the patient to scan a QR code to obtain particular data necessary for service provision. On scanning the QR code, the patient views data usage details and the terms of use by the service provider. If approved, the data is shared with the service provider, who then verifies if the data hash matches the issuer's hash and if the issuer is trusted. Upon validation, the patient gets the necessary service. This process, though intricate, is handled by automated software at high speed, making it seem like a simple authentication process for the patient.

In certain situations, you can choose to share only some parts of your data, avoiding the need to disclose potentially personal information. Consider a case where you need to verify that you're the legal guardian of your child. Initially, you have information about your child and your relationship with them in your data wallet. A representative at the hospital will request you to scan a QR code to confirm your guardianship. After scanning and authorizing the QR code, the system only confirms your registration as the patient's guardian, without exposing any personal data. This approach, called zero-knowledge proof, is sufficient because the hospital staff only needs to verify the actual guardian and not their personal information.

<figure><img src="https://lh7-rt.googleusercontent.com/docsz/AD_4nXc3MwOr72jCg7DI-xoLJrFjYqAbBSvbV6HPpHMcbq94dNStjs25LfwDATJ6B3fZ2Xm6iY12JePe3me92W3Y7aZuZDe1N56Rw7-66NtlK_yrHWV-4L6R3dFOwXublva8IaAgOvqzow?key=fUWQ9eDkcrmDnZr3M9bUxbfG" alt=""><figcaption></figcaption></figure>

### Consent(Signature) Management

Consent only requires the user to click the consent button. However, with a data wallet, you can easily view what you've consented to, and if you want to withdraw consent, you can do so at any point. Traditional methods often require cumbersome processes or even separate forms to withdraw consent. In contrast, a data wallet offers maximum control over your data even after you've given consent.

Furthermore, any data a user consents to share can be signed with the user's cryptographic key as a type of watermark. This ensures that any organization possessing data without this watermark will have to prove their legal acquisition of it. This strengthens the security of data circulation.

The inherent issue with traditional consent acquisition is that users are "forced" to accept terms and conditions to evidence consent, which primarily safeguards the service provider rather than the data subject. Lengthy and complex terms of service and privacy policies often discourage users from meticulously reading and assessing them, leading to 'insufficient consent'.

To tackle this, Hippo Protocol will introduce a standardized policy license that balances data subject protection and reasonable usage. If multiple services share identical privacy policies, users can be assured of uniformity without painstakingly reading each one. Once read properly, users can accept the same privacy policy license across different services, even setting it to auto-accept if desired. This enhances user convenience, protection, and companies' consent acquisition rates.

Any non-standard terms or previously unagreed terms in the policy will be isolated for separate consent. Users only need to review the changes or additions, fostering more confidence in their consent decision. These licenses will be overseen by a decentralized governance framework to guarantee trustworthiness, which will be elaborated on under Governance and DAOs.

### Asset Management

Healthcare data, to reach its full potential, needs to be collected and utilized on a global scale. This can be accomplished by providing data subjects with value-added services that arise from the use of their information, or, where there is no immediate service to offer, by compensating them accordingly. In this regard, it's essential to support assets that enable quick and cost-effective data transfer on a global scale over the internet and to store and exchange it via data wallets.

Hippo Protocol mainnet coin $HP and dollar-pegged stablecoins serve as the best assets for this purpose, particularly with the institutional adoption of stablecoins, which facilitates the transmission of small amounts of money worldwide at credit-card-payment speeds, with fees of less than 0.0x dollars. Moreover, IBC (Inter-Blockchain Communication Protocol) will facilitate the management and transfer of stablecoins and $HP across the Cosmos ecosystem. Consequently, Hippo Protocol and the Hippo SDK will be developed to align with these technologies, enabling global rewards through data collection and utilization in a form of assets preferred by users or businesses.

### Backup and Restoration

Since data wallets contain an individual's valuable assets and data, a secure method to back up and restore them is also crucial. By default, users can back up the mnemonic code displayed during the creation of a data wallet by BIP-39 by writing it down in a secure location. However, this method may be unfamiliar, and many individuals might be uncomfortable bearing full responsibility for it. To address this concern, we plan to support the encryption of your mnemonic code with a password of your choice and storing it in your preferred personal cloud storage, such as iCloud or Google Drive.

While this method is generally unsuitable for storing large sums of money, it may be an acceptable compromise for most data wallet users, as it reduces the risk of losing the mnemonic code. Of course, users can opt for a more secure method and avoid storing it in private cloud storage. As we adhere to blockchain wallet standards, methods to enhance the security of blockchain wallets, such as multi-sig wallets and adding passphrases, can be implemented in almost the same way.

### Notification

Notifications are necessary to ensure that users see required notices or consent requests in a timely manner. To effectively get the user's attention, we will only utilize the device's system notification features when consent and signatures are required.

### Agent・Guardian

While wallet owners and data subjects are typically the same, many patients may find it difficult to manage their own data wallet for reasons such as health or technical literacy. In these cases, you can provide the ability to designate a proxy at the data wallet level to allow someone else to make decisions about consent and data sharing on behalf of the patient. In this case, the wallet user with the proxy status can have the ability to store and control the data subject's data in the wallet on their behalf.

These representatives can be individuals, such as guardians, as well as entities. Extending this functionality, it is also possible to implement a guardian to take over the patient's assets and data upon the patient's death. While further verification is required to ensure that this is permissible under national laws, identity authentication for representatives and guardians can be implemented electronically through the verifiable credentials (VCs) described earlier.


# 10. Disclaimer

This document is written to convey specific information about the platform being planned and developed by *Hippocrat DAO Foundation*. This document is for informational purposes only and does not guarantee the accuracy or reliability of any information herein. The information in this document has been obtained from sources deemed reliable by *Hippocrat DAO Foundation*, but *Hippocrat DAO Foundation* does not guarantee the accuracy or suitability of such information. In other words, *HippocratDAO Foundation* is not legally liable for any loss or damage arising from information related to the company or the *Hippo Protocol* platform. The information contained in this document complies with judgment as of now and is subject to change without notice. *Hippocrat DAO Foundation* has no obligation to revise, modify or update this document. Each recipient must rely solely on their knowledge, research, judgment, and evaluation of the information in this document, and the company, employees, and shareholders will not be liable for any claims, suggestions, and information discussed, indicated, occurred, included, or derived. *Hippocrat DAO Foundation* has endeavored to include accurate facts in this document, and the estimates of the likelihood in the document are based on subjective predictions. They should not be construed as statements representing the actual likelihood of occurrence. This document is not intended for citizens or residents of any state, country, or other jurisdiction where distribution, publication, or use is prohibited. This document is available only at [www.hippoprotocol.ai](http://www.hippoprotocol.ai) and may not be redistributed, copied, forwarded, or published to any person, in whole or in part, without the prior written consent of *Hippocrat DAO Foundation* for any purpose.


# 개요

### 헬스케어 전용 블록체인의 필요성&#x20;

헬스케어 데이터의 활용은 신약 개발 등 의학 및 보건 분야 발전에 필수적입니다. 그러나 양질의 데이터를 확보하기 위해서는 개인정보의 보호와 활용의 균형, 충분한 동의 확보, 데이터 공유를 위한 인센티브, 데이터 권리에 대한 이해와 신뢰할 수 있는 기록 등 다양한 과제가 존재합니다.

히포크랏의 목표는 위의 과제들을 해결하기 위해 환자의 데이터 자기결정권, 탈중앙 거버넌스, 그리고 지속 가능한 인센티브 모델을 통해 헬스케어 데이터를 위한 협력 프로토콜을 실현하는 것입니다.

2023년 리브랜딩 이후, 히포크랏은 환자들에게 데이터 주권을 부여함으로써 헬스케어 데이터 활용 방식을 혁신하기 위해 노력해 왔습니다. Hippodoc(추후 Data Hippo로 업그레이드 예정)과 같은 소외 지역 대상 원격진료 솔루션을 개발하고, Saluscare, 성모병원, 서울아산병원 등 업계 선두 기업들과 전략적 파트너십을 맺어 견고한 탈중앙화 헬스케어 생태계를 구축했습니다. 현재 히포크랏 네트워크는 400만 명 이상의 건강검진 수검자를 확보하고 있으며, 이 중 140만 명은 매년 데이터를 갱신하고 있습니다. 이를 통해 히포크랏은 탈중앙화 헬스케어 데이터 솔루션 분야의 선두주자로 자리매김했습니다.&#x20;

그러나 여전히 해결해야 할 중요한 과제들이 존재합니다. 현재 블록체인 인프라는 헬스케어의 특수한 요구사항을 충족하기 어렵고, 기존 시스템과의 통합에 한계가 있습니다. 특히 이더리움 메인넷의 높은 거래 비용은 확장성을 저해하며, 의료 규정을 준수하는 탈중앙화 저장 솔루션이 부족하여 데이터 관리에 병목현상이 발생합니다. 또한 HL7과 같은 의료 데이터 표준 및 프라이버시 규정 준수를 위한 자체 데이터 처리 모듈이 부재한 것도 심각한 문제로 남아 있습니다.

이러한 한계를 극복하고 비전을 실현하기 위해, 히포크랏은 헬스케어 데이터 전용 레이어 1 블록체인인 ‘Hippo Protocol’을 출시합니다. Hippo Protocol은 엄격한 프라이버시 관리와 규제 준수를 보장하면서 원활한 데이터 교환을 가능하게 하는 안전하고 확장 가능한 사용자 중심 인프라를 제공합니다. 또한 이 변화는 HP 코인이 탈중앙화된 헬스케어 생태계의 핵심 유틸리티 자산으로 자리매김하는 계기가 될 것입니다.

### 환자의 데이터 자기주권 실현

현재까지 많은 인터넷 기업의 비즈니스 모델은 기업 내부 서버에 축적된 사용자들의 데이터를 활용하여 더 좋은 광고 알고리즘을 개발하고 수익성 높은 광고 상품을 만드는 것이라 할 수 있습니다. 이러한 비즈니스 모델은 사용자가 편리하고 저렴하게 서비스를 사용할 수 있게 했지만 그 반대급부로 사용자는 자신의 정보와 데이터에 대한 주권을 상당 부분 포기해야 했습니다.

비영리 글로벌조직[ 마이데이터 글로벌(mydata.org)](https://www.mydata.org/)은 이러한 문제의식에 대한 해답으로 '마이데이터'라는 이름의 개념을 제안하고 다음과 같이 정의하였습니다. 이는 신원의 영역으로 확장되어 개인 신원과 데이터에 대한 주권을 가지고 인터넷을 사용할 수 있게 하는 자기주권신원(Self sovereign identity, SSI)이라는 기술 분야의 탄생 배경이 되었습니다.<br>

1. 개인 데이터의 관리 및 처리에 있어 현재 조직 중심적 체계(organization-centric system)를 사람 중심적 체계(human-centric system)로 바꾸고자 하는 새로운 실천적 운동
2. 개인이 접근하고 통솔할 수 있는 자원으로서의 개인데이터

Hippo Protocol 은 마이데이터 및 자기주권신원과 동일한 철학을 공유하며 이를 헬스케어 분야에서 실현하는 것에 집중하고자 합니다. 특히 헬스케어 분야에서 개인을 충분히 보호하면서도 데이터의 합리적인 활용이 가능하게 하기 위해서는 정보 주체에 의한 결정이 꼭 필요합니다. 이것이 실현된다면 인터넷과 디지털 기술의 혁신이 헬스케어 분야에서도 비로소 가속화될 수 있을 것입니다.

### 인센티브와 개방형 협력을 통한 데이터 생태계 구축

헬스케어 데이터의 생성에서부터 부가가치가 더해지고 활용되기까지는 환자와 같은 정보주체 뿐만 아니라 의료 기관, 공공 기관, 기업 등 다양한 이해관계자의 협력이 수반됩니다. 이 모든 과정에서는 부가가치를 생산하기 위한 비용이 투입됩니다. 따라서 각 이해관계자의 동기를 충족시킬 수 있는 적절한 인센티브(금전적 보상 혹은 부가가치가 더해진 서비스 등)가 없다면 이 협력은 지속될 수 없을 것입니다.&#x20;

Hippo Protocol은 정보 주체의 자기결정권에 의해 데이터가 거래 및 활용되도록 하고, 이 과정에서 금전적 보상이 발생할 경우 정보 주체를 포함하여 데이터의 생성과 가공 과정에 기여한 이해관계자에게도 보상이 배분되는 프로토콜을 제공합니다. 또한 데이터의 생성부터 활용까지 유통 과정의 모든 정보는 투명하고 위·변조 위험 없이 블록체인에 기록되므로 제3자의 신뢰에 의존하지 않고도 충분히 협력할 수 있는 환경이 마련될 것입니다.&#x20;

이러한 프로토콜도 특정 중앙화된 주체에 의해 결정되는 것이 아니라 개방형 협력 체계에 의해 결정됩니다. 사용자들이 사용하는 도구와 서비스는 개방형 표준과 오픈소스로 개발되고, 정책과 표준은 공개적인 토론과 거버넌스 참여 구성원들의 합의로 결정됩니다. 이러한 방식을 통해 인류의 건강 증진을 위한 글로벌 단위의 협력을 가능케 하고자 합니다.


# 1. 서론

### 1.1 Hippo Protocol의 비전과 미션

헬스케어 데이터는 디지털 경제에서 매우 가치 있는 자산이지만, 현재는 분산되어 제대로 활용되지 못하고 있습니다. 환자와 의료 제공자, 연구자들은 데이터 사일로, 규제 제약, 프라이버시 문제로 인해 많은 비효율성을 경험하고 있으며, 민감한 건강 정보가 여전히 중앙화된 기관의 통제 아래에 놓여 있습니다.

Hippo Protocol은 환자의 데이터 주권을 강화하고 데이터 소유를 탈중앙화하여, 헬스케어 및 인공지능(AI) 애플리케이션에 안전하고 규제를 준수하는 데이터 거래 환경을 제공하는 레이어 1 블록체인입니다. 프라이버시 보호 암호화 기술과 탈중앙화된 신원(DID), 확장 가능한 데이터 저장 및 연산 기능을 통합하여 헬스케어 데이터의 관리, 공유 및 수익화 방식을 혁신합니다.

우리의 미션은 개인과 기관이 프라이버시, 보안, 규제 준수를 유지하면서 안전하게 상호작용하고 정보를 교류하며, AI 기반 혁신을 주도할 수 있는 글로벌 탈중앙화 헬스케어 데이터 네트워크를 구축하는 것입니다.

### 1.2 헬스케어 전용 블록체인의 필요성

2023년 리브랜딩 이후, 히포크랏은 탈중앙화와 환자의 데이터 주권 강화를 통해 헬스케어 데이터 활용 방식을 혁신하고자 노력해 왔습니다. 현재까지 400만 명 이상의 건강검진 이용자 네트워크를 구축했으며, 이 중 140만 명이 매년 데이터를 갱신하고 있습니다. 또한 Saluscare(한국의 대표 건강검진 예후관리 솔루션 ‘비타포트’ 운영사), Ever Medical Technologies(신흥 시장에서 급성장 중인 EMR 서비스), 서울성모병원 및 서울아산병원과 같은 업계 선두 기업과의 협력을 통해 신뢰할 수 있는 헬스케어 데이터 생태계를 조성했습니다.

그러나 기존의 블록체인 인프라는 헬스케어 데이터의 확장성, 사용성 및 규제 준수를 충족하는 데 여러 가지 한계를 가지고 있습니다. 주요한 도전 과제는 다음과 같습니다.

* 높은 거래 비용
* 헬스케어 데이터 특성에 맞는 맞춤형 서비스 부족
* 데이터 저장 및 처리의 병목 현상
* 규제 및 프라이버시 문제로 인한 장벽
* 블록체인 기술의 복잡성으로 인해 비전문 사용자들의 접근 어려움

Hippo Protocol은 이러한 한계를 극복하기 위해 사용자가 블록체인이나 암호화폐의 복잡한 메커니즘을 이해하지 않아도 쉽게 접근할 수 있도록 '체인 추상화(Chain Abstraction)'를 도입합니다. 의료 제공자와 환자는 지갑 관리, 거래 서명, 가스 수수료 등의 복잡성을 인식하지 않고, 일반적인 애플리케이션과 같은 방식으로 Hippo Protocol을 이용할 수 있습니다.

### 1.3 Hippo Protocol의 해결 방안

Hippo Protocol은 프라이버시 보호, 규정 준수, 상호 운용성, 탈중앙화된 연산을 위한 솔루션을 통합한 헬스케어 전용 레이어 1 블록체인입니다. 이를 위해 체인 추상화, 탈중앙화된 저장소, 영지식 증명(ZK-Proofs), 안전한 AI 연산 및 규제 준수 데이터 처리 메커니즘을 활용합니다. 각 기술에 대한 세부 사항은 기술 개요 섹션에서 설명합니다.

### 1.4 Hippo Protocol과 함께하는 헬스케어 데이터의 미래

Hippo Protocol은 수백만 명의 사용자 온보딩, 글로벌 파트너십 확대, 최첨단 AI 기반 애플리케이션 개발을 통해 헬스케어 데이터 교환 및 AI 연구를 위한 핵심 블록체인으로 자리매김할 것입니다.

Hippo Protocol은 프라이버시 보호 AI, 탈중앙화된 연산, 확장 가능한 블록체인 기술을 활용하여 다음과 같은 목표를 실현합니다.

* 환자가 자신의 헬스케어 데이터에 대한 주권적 통제권 확보
* 의료 제공자와 AI 연구자가 규제 준수 및 고품질 데이터셋 접근을 통해 혁신 촉진
* 검증자와 데이터 & 계산 노드 운영자가 탈중앙화 헬스케어 데이터 생태계를 보호하고 인센티브를 얻음

Hippo Protocol은 메인넷 출시를 앞두고 개발자, 의료 기관, AI 연구자 및 웹3 커뮤니티의 적극적인 참여를 기대합니다.

### 1.5 Hippo Protocol의 주요 이점

1. 데이터 주권: 중앙 기관에 의존하지 않고 환자가 자신의 건강 데이터에 대해 완전한 통제권 확보 가능
2. 상호 운용성: 의료 제공자, 연구자 및 환자 간 원활하고 안전한 데이터 교환 가능
3. 낮은 거래 비용: 최적화된 소액 거래를 통해 효율적이고 빠른 데이터 전송 실현
4. 탈중앙화 거버넌스: 커뮤니티 중심의 의사 결정 구조를 통해 검증자와 참여자들이 직접 네트워크 관리
5. 강화된 보안 및 규정 준수: 영지식 증명(ZK-Proofs), HL7/FHIR 준수 등 내장된 보안 및 규제 준수 기능 제공


# 2. 도전 과제와 해결책

### 도전 과제 1: 데이터 프로토콜의 보안성 확보

데이터 보안은 필수적입니다. Hippo Protocol은 Elliptic Curve Cryptography(ECIES & ECDH) 기반의 DIDComm을 사용하여 데이터를 암호화하고 안전하게 전송합니다. 또한 Hippo Protocol은 World Wide Web Consortium(W3C)에 DID를 등록하고 주요 헬스케어 기관들과 협력하여 수백만 개의 DID를 발급하여 사용자에게 자기주권 신원(SSI)을 제공합니다. 이를 통해 헬스케어 데이터를 안전하게 저장하고 공유할 수 있는 기반을 구축합니다.

### 도전 과제 2: 데이터 프로토콜의 확장성

사용자가 데이터를 개별적으로 암호화하여 전송하면 효율이 떨어지고 불필요한 중복이 발생할 수 있습니다. 이를 해결하기 위해 Hippo Protocol은 암호화되고 탈중앙화된 데이터 저장소를 제공하는 노드를 도입합니다. DID 소유자는 암호화 서명(예: ECDSA, Schnorr)을 사용하여 데이터 접근 권한을 위임 할 수 있으며, 위임내역은 Hippo Protocol 블록체인에 공개적으로 기록되어 투명성을 보장합니다.

어떻게 Hippo Protocol의 노드를 신뢰할 수 있을까요?

Hippo Protocol의 노드는 탈중앙화된 네트워크 자원으로 운영되기 때문에 특정 주체가 암호화된 데이터를 임의로 조작할 수 없습니다. 암호화 및 복호화 과정에서 여러 노드 간 키 분산 관리를 요구하므로 보안성과 확장성을 동시에 확보할 수 있습니다.

### 도전 과제 3: 데이터 제공자 인센티브와 사용성 유지

데이터 제공자에게 적절한 인센티브를 부여하면서 데이터의 사용성을 유지하는 것이 중요한 과제입니다. 특히 암호화된 데이터는 구매자가 직접 확인할 수 없어 데이터 표준화 및 가격 책정에 어려움이 있습니다.

### 해결책 1: 데이터 형식 표준화

Hippo Protocol은 헬스케어 기술 분야에서 널리 인정받는 HL7-FHIR 표준을 채택합니다. 또한 AI를 활용하여 사용자 데이터를 HL7-FHIR 표준에 맞춰 자동으로 처리하고 표준화합니다.

### 해결책 2: 데이터 가치 평가 방법

현재 데이터의 가치를 정확하게 평가할 수 있는 명확한 방법이 존재하지 않습니다. Hippo Protocol은 개별적으로 암호화된 데이터에 접근할 수 없기 때문에 데이터 기여도를 평가하기 위한 혁신적인 방법이 필요합니다.

옵션 1 (현재): GDPR 및 유사 규제 환경에서는 헬스케어 데이터를 제3자에게 판매할 때 반드시 비식별화되고 추적 가능한 형태여야 합니다. 이로 인해 데이터 기여자 간에 차등적인 보상을 제공하기가 매우 어렵습니다. HIPAA 규정에 따르면, 데이터가 비식별화되고 명확한 동의가 있는 경우 거래가 가능합니다. 따라서 데이터의 가치는 데이터 소유자의 법적 관할권에 크게 의존합니다. 현재 Hippo Protocol은 데이터로부터 얻은 수익을 모든 데이터 기여자에게 균등하게 배분하여 보상하는 방식을 채택하고 있습니다. 이 모델에서는 사용자가 데이터 풀에 기여했는지 여부만으로 보상을 받으며, 개별 데이터의 기여도는 고려되지 않습니다.

옵션 2 (미래): Hippo Protocol은 프라이버시 보호 AI(예: 연합 학습, Federated Learning)를 활용하여 데이터의 가치를 평가할 예정입니다. 이 시스템은 개별 데이터가 결과에 기여한 정도를 평가하여 데이터 제공자에게 보다 공정한 인센티브를 제공합니다.

<br>


# 3. 기술 개요

### Hippo Protocol: 헬스케어 특화 레이어 1 블록체인

Hippo Protocol은 헬스케어 제공자, 환자 및 연구자의 요구를 충족시키기 위해 최첨단 블록체인 기술을 적용한 헬스케어 전용 레이어 1 블록체인입니다. 주요 기술적 특장점은 다음과 같습니다.

### 3.1 체인 추상화(Chain Abstraction) 및 가스 수수료 추상화

Hippo Protocol은 블록체인 기술에 익숙하지 않은 사용자도 쉽게 이용할 수 있도록 설계되었습니다. 사용자는 복잡한 지갑 관리, 거래 처리 및 가스 수수료 납부와 같은 블록체인의 기술적 사항을 의식할 필요 없이 프로토콜을 사용할 수 있습니다.

### 3.2 헬스케어 데이터의 탈중앙화 저장 및 연산

Hippo Protocol은 전자 의료 기록(EMR), 개인 건강 기록(PHR), 실제 임상 데이터(RWD)의 안전한 저장과 확장 가능한 연산을 위한 전용 솔루션을 제공합니다. 이는 주요 생태계 이해관계자들과 커뮤니티 구성원이 운영하는 데이터 저장 및 연산 노드 (Hippo Data Node) 네트워크를 통해 이루어집니다. 탈중앙화된 네트워크 관리 방식을 통해 글로벌 헬스케어 규정 준수, 데이터 무결성 및 프라이버시를 유지하며, 정책 변경이나 네트워크 업그레이드 과정에서의 투명하고 개방적인 의사 결정을 보장합니다.

### 3.3 비식별화 및 영지식 증명(ZK Proofs)을 활용한 데이터 프라이버시 보호

Hippo Protocol은 데이터 프라이버시 및 규제 준수를 위해 비식별화 및 암호화 기술을 활용하여 민감한 데이터를 보호합니다. 구체적인 기술은 다음과 같습니다.

* 비식별화 메커니즘: 개인 식별 정보를 제거하면서 데이터의 활용성 유지
* DID 기반 암호화: 개인 식별 정보를 탈중앙화 신원(DID)으로 대체하여 안전한 데이터 암호화 및 인증 체계 구축
* ECIES(타원 곡선 통합 암호화 체계): ECC와 대칭키 암호화의 하이브리드 방식으로 데이터 전송 시 강력한 보안과 효율성 제공
* 영지식 증명(ZK Proofs): 원본 데이터를 노출하지 않으면서 검증 가능한 연산 수행을 지원하여, HIPAA 등 엄격한 프라이버시 규정을 준수하면서 안전한 데이터 공유 가능
* 신뢰 실행 환경(TEE): 민감한 헬스케어 데이터의 AI 연산 과정에서 데이터 처리의 보안성 강화

### 3.4 내장 데이터 처리 모듈

Hippo Protocol은 데이터 처리 모듈을 통해 헬스케어 데이터 표준과의 원활한 통합을 지원합니다. 주요 기능은 다음과 같습니다.

* HL7 및 FHIR 표준 준수: 기존 의료 시스템과의 상호 운용성 지원
* HIPAA 준수 데이터 처리: 미국 의료 제공자들을 위한 규제 준수 데이터 처리 보장
* 안전한 데이터 거래: 이해관계자 간 저비용의 실시간 데이터 거래 지원
* zkFilter 기반 데이터 라벨링: 데이터의 보안성을 유지하면서 데이터 사용성을 높이고, 연구 및 AI 애플리케이션에서 효율적 색인화 및 검색 지원
* AI 응용을 위한 벡터 임베딩: Hippo Protocol을 기반으로 의료 데이터를 활용한 AI 및 머신러닝 응용의 학습을 지원합니다. 이를 통해 다음과 같은 기능을 갖춘 의료 AI 에이전트의 가능성이 열립니다.
  * 실시간 사용자 데이터 분석을 기반으로 한 개인 맞춤형 건강 관리 추천
  * 방대한 데이터셋을 구조화하고 분석하여 AI 기반 신약 및 치료법 발견
  * 사용자의 의료 데이터를 활용한 스마트 진단 및 모니터링

### 3.5 안전한 데이터 거래를 위한 에스크로 기술

Hippo Protocol은 데이터 거래의 신뢰성을 높이기 위해 다음과 같은 기술을 활용합니다.

* 멀티 시그니처 데이터 에스크로: 데이터 접근에 조건을 설정하여 안전한 거래 환경 구축
* 스마트 컨트랙트 기반 결제: 규제 기준에 따라 자동화된 거래 결제 시스템 제공
* 감사 가능한 동의 메커니즘: 데이터 거래 내역의 투명성을 확보하고 모든 참여자의 명시적 허가 보장

### 3.6 Hippo Protocol 메인넷 아키텍처의 주요 차별화 요소

Hippo Protocol 메인넷은 기존 블록체인 인프라와 구별되는 고유한 구조적 특장점을 가지고 있습니다.

* 헬스케어 데이터 전용 모듈형 계층 아키텍처: DID, 저장소 및 연산 프레임워크를 갖춘 헬스케어 전용 블록체인
* 특화된 스마트 컨트랙트: 글로벌 헬스케어 표준 준수 및 애플리케이션과의 원활한 연동을 위한 맞춤형 컨트랙트 제공
* 상호 운용성을 위한 체인 추상화: 기존 헬스케어 IT 인프라 및 타 블록체인과 원활한 연결을 지원

Hippo Protocol의 토크노믹스 구조는 생태계 내 적극적인 참여를 유도하도록 설계되었습니다.

* Hippo Data Node에 대한 보상 우선 배분: 인프라의 핵심적 역할인 데이터 처리, 저장 및 AI 연산을 수행하는 Hippo Data Node에게 가장 많은 코인 보상 지급
* 데이터 거래 인센티브: 의료기관과 사용자가 안전하고 규제 준수를 따르는 데이터 기여 시 보상 제공
* 적응형 스테이킹 모델: 디플레이션적 반감기 스케줄을 통해 장기 참여 유도

Hippo Protocol은 위임 지분 증명(DPoS) 합의 메커니즘을 사용합니다:

* 데이터 저장 및 연산 노드: 기존 DPoS와 달리 Hippo Data Node 노드는 헬스케어 데이터의 저장 및 연산 처리 작업도 수행
* 동적 검증자 선정: 탈중앙화와 효율성 사이에서 최적의 균형 유지
* 연산 작업 인센티브화: 전통적인 스테이킹 보상과 함께 AI 및 연산 작업에 대한 추가 보상 제공


# 4. Hippo Data Node

### 4.1 탈중앙화 헬스케어 데이터 저장 및 컴퓨팅 혁신

Hippo Protocol은 블록체인 노드를 단순한 거래 기록 저장소에서 벗어나 보다 적극적인 역할을 수행하도록 설계했습니다. Hippo Data Node는 탈중앙화된 데이터 저장소 및 연산력을 제공하며, 특히 AI 기반 분석 및 안전한 데이터 처리와 같은 헬스케어 관련 애플리케이션을 지원하는 핵심 요소로 기능합니다.

### 4.2 Hippo Data Node의 주요 특징

* 탈중앙화된 데이터 저장: 헬스케어 데이터를 분산 저장하여 데이터의 복원력(resilience)과 규제 준수, 프라이버시 보호를 보장합니다.
* 연산 작업 분산: AI 모델 훈련, 실시간 진단, 정밀 의료 분석과 같은 헬스케어 특화 연산 업무를 탈중앙화된 방식으로 처리합니다.
* 규제 준수 (HIPAA 및 HL7): 내장된 보안 및 프라이버시 보호 메커니즘을 통해 HIPAA 및 HL7과 같은 헬스케어 규정을 철저히 준수합니다.
* 동적이고 개방된 노드 운영 참여: 기관 파트너와 커뮤니티 회원 누구나 요구 조건만 충족하면 노드를 운영할 수 있어 생태계의 탈중앙화 및 확장성을 보장합니다.

### 4.3 노드 운영자 인센티브

Hippo Data Node는 Hippo Protocol 생태계의 핵심 구성 요소로서 코인 보상의 대부분을 할당받습니다. 보상은 제공한 자원의 기여도에 따라 분배되며, 이를 통해 지속 가능한 인센티브 참여 모델을 구축합니다.

### 4.4 노드 참여 방법

Hippo Protocol은 다음과 같은 방식으로 노드 참여를 지원합니다.

* 데이터 저장 자원 제공: 헬스케어 데이터를 탈중앙화된 인프라 내에서 암호화된 형태로 호스팅
* 컴퓨팅 자원 기여: AI 기반 헬스케어 애플리케이션의 데이터 컴퓨팅 작업이 안전하고 프라이버시 보호를 준수하는 형태로 진행 될 수 있도록 지원

Hippo Protocol의 노드 생태계는 헬스케어 분야에서 블록체인의 실제적 활용성을 입증하며, 탈중앙화된 연산과 환자 데이터 주권 확보, 첨단 의료 연구 및 개인 맞춤형 헬스케어 솔루션의 혁신을 촉진합니다.


# 5. 생태계 개요

### 5.1 Hippo Protocol 생태계 참여자

Hippo Protocol은 다양한 이해관계자가 참여하는 다중 이해관계자 모델을 기반으로 헬스케어 데이터 경제를 구축합니다. 주요 참여자는 다음과 같습니다.

#### 5.1.1 데이터 제공자 및 검증자

* 사용자, 의료 기관, 건강 서비스 제공자
  * 예시: 병원, 진단 센터, 웨어러블 건강 데이터를 보유한 개인 사용자
* 의료 데이터를 생성하고 소유하는 개인 및 기관. 이들은 데이터를 저장, 관리하며 선택적으로 공유하여 보상을 받을 수 있습니다.
* 이들은 안전한 단일 데이터 관리 포인트를 통해 데이터를 통합하여 혜택을 얻기를 원합니다.
* 이들은 데이터 주권을 유지하면서도 다양한 혜택을 위해 데이터 접근 권한을 제공할 수 있습니다.
* 검증자(Validators)는 Hippo Protocol 블록체인의 보안을 유지하며, 생태계의 신뢰성과 안정성을 보장하는 역할을 합니다.

#### 5.1.2 데이터 사용자 및 구매자

* 의료 데이터를 활용하여 연구개발(R\&D), 임상시험, AI 모델 학습, 의료 분석, 서비스 개선 및 제품 개발을 진행하는 조직, 연구자 및 기업.
  * 예시) 개인 맞춤형 헬스케어 솔루션 제공업체, 피트니스 앱, 제약회사, 보험회사, 건강 보조식품 제조업체, 스킨케어 / 미용 관련 기업
* 이들은 스마트 컨트랙트 및 탈중앙화 메커니즘을 통해 개인정보 보호 및 규정을 준수하는 데이터를 안전하게 접근할 수 있습니다.
* 데이터를 규정을 준수하는 방식으로 다양한 활용 목적에 맞게 활용하려는 모든 기관이 포함됩니다.
* 데이터의 잠재적 활용 사례:
  * 제약회사가 연구개발 및 임상시험 대상 선정 목적으로 데이터 구매
  * 개인 맞춤형 헬스케어 서비스 제공업체가 데이터 활용하여 맞춤형 건강 및 웰니스 솔루션 제공
  * 보험회사가 의료 데이터를 활용하여 리스크 평가 및 개인 맞춤형 보험료 책정
  * 미용 및 스킨케어 브랜드가 데이터를 활용하여 맞춤형 추천 및 제품 개발

#### 5.1.3 Hippo Protocol 검증자

* Hippo Protocol 블록체인의 거래를 검증하고 보안을 유지하는 역할을 담당합니다.
* 검증자는 네트워크의 무결성, 거버넌스, 탈중앙화를 보장하는 데 핵심적인 역할을 합니다.

#### 5.1.4 Hippo Data Node

* 암호화된 의료 데이터를 처리하는 탈중앙화 데이터 저장 및 연산 노드입니다.
* 이러한 노드는 의료 관련 데이터셋을 저장, 검증, 연산하여 안전한 데이터 분석 및 AI 처리를 가능하게 합니다. AI 기반 의료 응용 프로그램을 위한 탈중앙화된 암호화 데이터 저장 및 연산을 제공합니다.
* HIPAA 및 FHIR 규정을 준수하는 데이터 처리, 연합 학습(Federated Learning), 보안 AI 연산을 지원하는 핵심 인프라 역할을 합니다.
* 병원, 클리닉, 헬스케어 서비스 제공업체가 운영하여 데이터 무결성과 보안을 유지합니다.
* 노드 운영자는 AI 응용 프로그램 지원, 연합 학습, 개인정보 보호 연산을 수행하는 대가로 보상을 받습니다.

### 5.2 생태계 파트너

Hippo Protocol은 데이터 제공, 검증 및 활용에 중요한 역할을 수행하는 다양한 전략적 생태계 파트너로 구성됩니다. 이들은 안전하고 상호 운용 가능하며 탈중앙화된 헬스케어 데이터 생태계를 구축하는 데 도움을 줍니다. 생태계는 다음과 같은 그룹으로 분류됩니다:

#### 5.2.1 데이터 제공자 및 노드 운영자&#x20;

데이터를 온보딩하고 Hippo Protocol에 데이터를 검증하여 Hippo Data Node를 운영하는 조직입니다. 이들은 데이터 무결성, 규제 준수 및 탈중앙화를 보장합니다.&#x20;

* 병원 및 클리닉 – 서울아산병원, 서울성모병원과 같은 의료 기관들이 환자 데이터를 안전하게 저장 및 검증합니다.&#x20;
* 헬스케어 서비스 제공자 – Saluscare와 같은 기업들이 기업 건강검진과 탈중앙화된 데이터 수집을 촉진합니다.
* 웰니스 및 예방 건강 플랫폼 – Lillius와 같은 디지털 헬스 서비스가 사용자 생성 건강 데이터를 제공합니다.

#### 5.2.2 데이터 소비자 및 구매자&#x20;

연구, AI 훈련 및 제품 개발을 위해 규정을 준수하고 프라이버시가 보호되는 헬스케어 데이터를 활용하는 기업과 기관입니다.&#x20;

* 제약 회사 – 약물 개발, 임상시험, 정밀 의료를 위한 데이터 활용&#x20;
* AI 및 연구 기관 – Phoenix.AI, BitDoctor와 같은 파트너들이 헬스케어 데이터를 AI 기반 진단 및 의학 연구에 활용&#x20;
* 보험 제공자 – 개인 맞춤형 정책 제공 및 위험 평가를 위한 데이터 활용&#x20;
* 개인 맞춤형 헬스케어 및 웰니스 기업 – Vitaport와 같은 서비스가 사용자 동의 하에 수집된 건강 데이터를 기반으로 서비스를 맞춤화합니다.

#### 5.2.3 인프라 및 기술 파트너&#x20;

Hippo Protocol의 기능성과 상호 운용성을 강화하는 중요한 인프라와 통합을 제공하는 프로젝트들입니다.&#x20;

* 탈중앙화 스토리지 네트워크 – Filecoin, AIOZ 등과의 협력으로 암호화된 헬스케어 데이터를 안전하게 저장합니다.&#x20;
* 웨어러블 및 IoT 데이터 제공자 – Cudis와 같은 회사들이 실시간 생체 데이터를 제공합니다.&#x20;
* 신원 및 규정 준수 솔루션 – 탈중앙화 신원(DID)과 규제 준수 데이터 공유 프레임워크와 협력합니다.

이러한 생태계 파트너들은 실제 데이터 제공, 컴퓨팅 자원 기여, 기술적 통합을 통해 Hippo Protocol의 성공에 중추적인 역할을 수행하며, 신뢰할 수 있고 탈중앙화된 AI 기반의 헬스케어 미래를 실현합니다.


# 6. HP 코인 ($HP)

### 6.1 요약

HP 코인은 Hippo Protocol 생태계를 구동하는 핵심 자산으로, 탈중앙화 헬스케어 데이터 저장소, AI 기반 서비스 및 거버넌스 참여를 촉진하도록 설계되었습니다. HP 코인은 데이터 사용자, AI 서비스 제공자, 의료기관 및 생태계 참여자들이 데이터를 접근하고 활용하는 데 사용됩니다.

HPO($HPO)에서 HP($HP)로 전환되면서, Hippo Protocol은 새로운 레이어 1 블록체인 인프라를 도입하며, 데이터 공유 인센티브를 넘어 AI 기반 애플리케이션 및 실질적인 헬스케어 서비스의 주요 메인넷 코인으로서의 활용도를 확대합니다.

Hippo Protocol 메인넷 출시 이후 HP 코인은 디플레이션적 반감기 스케줄에 따라 매년 발행되어 장기적으로 지속 가능한 생태계 운영과 네트워크 참여자들에 대한 공정한 보상을 보장합니다.

### 6.2 코인 분배 및 인플레이션 모델

Hippo Protocol 생태계의 성장을 위해 새롭게 발행된 HP 코인은 다음과 같이 할당됩니다.

* 연간 인플레이션의 80%를 네트워크 보상으로 할당
  * 노드 보상 (90%): 헬스케어 데이터의 무결성과 보안 유지에 기여하는 Hippo Data Node에게 지급
  * 검증자 보상 (10%): 트랜잭션 검증 및 블록체인 보안을 유지하는 참여자에게 지급
* 생태계 성장 및 유동성 인센티브에 10% 할당 - 신규 파트너십, 유동성 제공자 및 프로토콜 채택 지원
* 개발자 보조금에 5% 할당 - Hippo Protocol의 기술 개발에 기여하는 개발자 팀을 지원하며, 커뮤니티 제안 및 투표로 결정
* 에어드롭 및 마케팅에 5% 할당 - 커뮤니티 확장 활동에 사용되며, 커뮤니티 거버넌스에 의해 할당이 결정됨

커뮤니티 세금 펀드(Community Tax Fund)

* 검증자 보상을 제외한 나머지 신규 발행 코인은 커뮤니티 세금 펀드로 편성됩니다.
* 커뮤니티 세금 펀드는 Hippo Protocol 커뮤니티가 온체인 투표를 통해 완전하게 관리하며, 투명하고 공정한 자원 분배를 보장합니다.
* 펀드 사용에 관한 모든 제안은 HP 코인 보유자의 투표를 통해 결정되어 생태계의 완전한 탈중앙화 및 투명성을 유지합니다.

이러한 거버넌스 중심 분배 모델을 통해 Hippo Protocol은 장기적으로 자립적이고 커뮤니티 중심적이며, 변화하는 생태계의 요구에 민첩하게 대응할 수 있는 지속 가능한 네트워크로 유지됩니다.

### 6.3 HP 코인 인플레이션 스케줄

| Year   | Inflation Rate | New Supply Minted | Total Supply  |
| ------ | -------------- | ----------------- | ------------- |
| Year 1 | 25%            | 271,183,568       | 1,355,917,841 |
| Year 2 | 20%            | 271,183,568       | 1,627,101,410 |
| Year 3 | 8.33%          | 135,591,784       | 1,762,693,194 |
| Year 4 | 7.69%          | 135,591,784       | 1,898,284,978 |
| Year 5 | 3.57%          | 67,795,892        | 1,966,080,870 |
| Year 6 | 3.45%          | 67,795,892        | 2,033,876,762 |

* 초기 4년 간 가속화된 인플레이션: 초기 채택 및 노드 참여, 생태계 성장을 촉진합니다.
* 장기적인 디플레이션 모델: 생태계 채택 증가에 따라 코인 수요 증가 및 네트워크 수수료 발생으로 인플레이션 효과를 상쇄하여 장기적으로 디플레이션 효과가 발생하도록 설계되었습니다.

### 6.4 주요 코인 유틸리티

* 거래 수수료 및 가스비 추상화: Hippo Protocol 내에서 저비용의 원활한 거래 지원
* 스테이킹 및 검증자 보상: 네트워크 보안과 거래 검증 참여자에게 HP 보상 지급
* 저장 및 컴퓨팅 노드 보상: 저장 및 연산 자원을 제공하는 노드 운영자에게 HP 보상 지급
* AI 서비스 결제:
  * 건강 요약 AI: 건강 데이터와 의료 기록을 요약하고 개인 맞춤형 의료 인사이트 제공
  * 의료 상담 AI: 의료 상담 및 SOAP 문서 작성 지원
  * 데이터 업로드 AI: PDF, 이미지, 보고서를 구조화된 데이터로 변환
* 헬스케어 및 생태계 서비스 결제: 원격진료, 2차 소견, 임상시험 매칭, 개인 맞춤형 추천 서비스
* 거버넌스 및 투표 권한: DAO 거버넌스를 통한 프로토콜 업그레이드, 생태계 정책 결정 및 자금 할당 참여

Hippo Protocol은 HP 코인의 다양한 유틸리티 제공을 통해 보상과 활용 사이에 균형을 유지하여 지속 가능하고 커뮤니티 주도적인 탈중앙화 헬스케어 생태계를 구축하고자 합니다.

### 6.5 HP 코인 스왑

메인넷 출시 후 HP 코인은 Hippo Protocol의 레이어 1 블록체인에 네이티브 코인으로 통합됩니다. 코인 보유자는 다음과 같은 방법으로 HP 코인을 관리할 수 있습니다.

* Hippo Wallet 및 Multi-chain Wallets
* 생태계 파트너 애플리케이션 및 AI 서비스
* 거래소 및 DEX 통합 지원

HP 코인 추가 및 지원 거래소에 대한 자세한 가이드는 메인넷 출시 시 제공됩니다.

* HP 코인은 Hippo Protocol 생태계 내에서 다양한 목적으로 구매 및 사용이 가능합니다. Data Hippo를 통해 헬스케어 데이터를 관리하거나 데이터 풀에 자신의 헬스케어 데이터를 스테이킹하는 등, 프로토콜의 성장을 위한 활동에 참여하여 HP 코인을 획득할 수도 있습니다.
* HP 코인은 기존 HPO([컨트랙트](https://etherscan.io/address/0xfe39c384d702914127a005523f9915addb9bd59b)) 토큰에서 리브랜딩된 코인으로, 메인넷 출시에 따라 2025년 2분기에 스왑 및 메인넷 전환이 예정되어 있습니다. 보다 자세한 정보는 "HPO→HP 코인 스왑 및 메인넷 전환" 섹션을 참조하십시오.
* 2025년 3월 말 기준 총 유통량은 1,034,734,274.38개이며, 현재 50,000,000개의 코인이 락업 상태로, 계획에 따라 향후 배분될 예정입니다 ([상세](https://whitepaper.hippocrat.io/index/korean/whatis/hpo)).
* Hippo Protocol은 주요 국가의 디지털 자산 규제를 준수하며, 생태계와 DAO의 결정을 통해 코인의 유틸리티가 미래에 변경될 수 있으며 이는 생태계의 최적 이익을 보장합니다.


# 7. 거버넌스 모델

Hippo Protocol은 탈중앙화된 자율 조직(DAO)에 의해 운영되며, HP 코인 보유자들이 주요 의사결정 과정에 참여합니다. 이 거버넌스 구조는 HP 코인 보유자, 검증자, 생태계 참여자들이 프로토콜 형성에 적극적으로 참여할 수 있도록 설계되었습니다. 이를 통해 네트워크 보안, 탈중앙화, 커뮤니티 중심의 의사결정을 보장합니다. 거버넌스는 다음과 같은 방식으로 실행됩니다:

### 7.1 거버넌스 참여 및 투표 권한

* HP 코인 보유자: 온체인 거버넌스에 참여하여 프로토콜 업그레이드, 보상 분배, 생태계 지원금, 정책 결정 등에 대한 투표를 진행합니다.
* 검증자: 네트워크를 보호하고 합의 메커니즘 변경 및 검증자 선정 절차와 같은 주요 거버넌스 제안 승인에 참여합니다.
* 노드 운영자: 헬스케어 기관, 서비스 제공자 및 금융 기관 등 Hippo Data Node를 운영하는 주체들이 거버넌스에 기여합니다.

### 7.2 온체인 투표 메커니즘

* 제안 제출: 모든 HP 코인 보유자가 거버넌스 제안을 제출할 수 있습니다.
* 검증자 협의회 승인: 핵심 프로토콜 기능에 영향을 주는 제안은 검증자의 투표 승인이 필요합니다.
* 커뮤니티 투표: 코인 보유자는 스테이킹된 HP 코인의 양에 비례하여 투표권을 행사합니다.

### 7.3 의사결정 및 재정 관리

* 생태계 지원금: 코인 인플레이션의 5%는 개발팀과 기술적 기여를 위한 지원금으로 배정되며, 제안은 커뮤니티 투표로 승인됩니다.
* 에어드랍 및 커뮤니티 확장: 인플레이션의 5%는 마케팅 및 커뮤니티 인센티브에 할당되며, 에어드랍 배포는 거버넌스를 통해 승인됩니다.
* 유동성 및 네트워크 성장: 코인 인플레이션의 10%는 유동성 공급자와 생태계 확장 활동에 사용됩니다.

### 7.4 장기적인 탈중앙화 계획

* 초기 재단 주도 거버넌스: 초기 전환기 동안 Hippo Protocol 재단과 초기 후원자들이 거버넌스를 감독합니다.
* 커뮤니티 주도의 DAO 발전: 시간이 지남에 따라 거버넌스 권한은 전적으로 Hippo Protocol DAO로 이양되며, 모든 결정이 커뮤니티에 의해 이루어집니다.

이 거버넌스 모델은 보안, 투명성 및 지속 가능성을 보장하며, 헬스케어 기관, AI 연구자, 웹3 참여자들이 신뢰할 수 있고 탈중앙화된 헬스케어 데이터 생태계 내에서 협력할 수 있도록 지원합니다.


# 8. 로드맵

### 2025년 1분기&#x20;

* 메인넷 전환 준비&#x20;
  * Cosmos SDK 기반 Hippo Protocol 메인넷 개발 및 테스트 완료&#x20;
  * 의료 제공자를 위한 메인넷 구조, 특징 및 이점을 상세히 설명한 기술 백서 발간&#x20;
  * 규제 준수 및 확장성 보장을 위해 파트너 기관과 내부 테스트 진행&#x20;
* 커뮤니티 참여 및 교육&#x20;
  * 주요 의료기관과 파트너십 발표 및 2025년 중 150만 사용자 온보딩 목표&#x20;
  * 의료 제공자 및 기관을 위한 블록체인 혜택에 대한 메인넷 사전 교육 캠페인 런칭

### 2025년 2분기&#x20;

* 메인넷 출시 및 리브랜딩&#x20;
  * 히포크랏을 Hippo Protocol로 공식 리브랜딩 및 메인넷 출시&#x20;
  * 실제 사용 사례 시연과 함께 사용자 참여를 독려하는 메인넷 출시 에어드랍 이벤트 개최&#x20;
* 사용자 온보딩 및 생태계 성장&#x20;
  * 의료 제공자 시스템과 Hippo SDK의 원활한 통합을 우선으로 사용자 온보딩 시작&#x20;
  * 개발자와 기관들이 Hippo Protocol과 통합할 수 있도록 Hippo SDK v2 배포(v1은 솔라나와 이더리움 기반)&#x20;
* 규제 준수&#x20;
  * HIPAA, GDPR 및 기타 지역 규제 준수를 위한 프레임워크 발표&#x20;
  * 프로토콜이 진화하는 표준에 부합하도록 규제 당국과 협력

### 2025년 3분기&#x20;

* 확장성 및 상호운용성&#x20;
  * Hippo Protocol과 타 블록체인 및 기존 의료 시스템 간 상호 운용성 기능 출시&#x20;
  * 의료 기관 온보딩으로 인한 트랜잭션 증가를 처리하기 위한 확장성 솔루션&#x20;
* 도입 채택 인센티브&#x20;
  * 프로토콜을 채택하는 기관 및 생태계 애플리케이션 개발자 대상 보조금 제도 도입&#x20;
  * 고급 데이터 공유 및 프라이버시 보호 기능을 갖춘 Hippo SDK v3 출시

### 2025년 4분기&#x20;

* 실제 활용 사례&#x20;
  * 의료 기관 파트너십을 통한 프로토콜의 실제 사례 공개:&#x20;
    * 기관 간 의료 데이터 전송&#x20;
    * 프라이버시 보호 데이터 수익화 및 거래&#x20;
* 생태계 확장&#x20;
  * 추가 의료 제공자 및 기관 5곳 프로토콜에 온보딩
  * 탈중앙 데이터 교환 및 헬스 데이터 마켓플레이스와 같은 탈중앙화 애플리케이션(dApps) 배포&#x20;
* 글로벌 확장&#x20;
  * DeSci 서울 2025 개최(2024년 DeSci 서울 후속 행사)

### 2026년 1분기&#x20;

* 플랫폼 최적화&#x20;
  * 보안 강화 및 규제 준수 도구에 초점을 둔 메인넷 업데이트 발표&#x20;
  * 헬스케어 IoT 기기, 웨어러블 및 전자 의료 기록(EMR) 시스템용 통합 도구 또는 SDK 확장&#x20;
* 도입 가속화&#x20;
  * 소규모 클리닉 및 독립 의료 제공자 온보딩 시작, 추가 사용자 150만 명 목표&#x20;
  * 국가별 규제 및 기술 요구사항에 맞춘 지역 특화 솔루션 배포

### 2026년 2분기&#x20;

* AI 및 데이터 분석&#x20;
  * 익명화된 환자 데이터를 활용한 개인 맞춤형 의료 서비스를 위한 탈중앙 AI 모듈 출시&#x20;
  * 공중 보건 연구 및 혁신을 위해 의료 데이터에 안전한 접근을 지원하는 연구기관과 파트너십&#x20;
* 파트너십 확장&#x20;
  * 약물 개발 및 임상 시험을 위한 안전한 데이터 공유 촉진을 위해 제약 회사와 협력&#x20;
  * 블록체인 채택이 미흡한 지역을 중심으로 추가 의료기관 20곳 온보딩

### 2026년 3분기&#x20;

* 글로벌 영향력 확대&#x20;
  * 생태계 내 성공 사례와 혁신을 강조하는 Hippo Protocol 글로벌 임팩트 서밋 개최&#x20;
  * 환자 권한 강화를 위한 블록체인의 역할을 강조하는 글로벌 캠페인 전개&#x20;
* 기술 혁신&#x20;
  * 타 Cosmos SDK 기반 블록체인 및 기타 블록체인과의 크로스 체인 호환성 도입&#x20;
  * 실시간 데이터 공유, 보안 강화, 규제 준수 모니터링 기능을 갖춘 SDK v3 출시

### 2026년 4분기&#x20;

* DAO 진화 및 탈중앙 거버넌스&#x20;
  * 생태계 이해관계자가 모두 참여하는 DAO 메커니즘을 통해 Hippo Protocol 거버넌스 완전 탈중앙화&#x20;
* 생태계 성숙&#x20;
  * 의료 제공자 50곳 이상 및 지역/국가 보건 시스템 10곳 이상과 완전한 통합 달성&#x20;
  * 의료 서비스 개선, 환자 결과 향상 및 데이터 보안 강화에 대한 프로토콜 기여를 종합한 임팩트 보고서 발간&#x20;
* 미래 비전&#x20;
  * 사용자 1천만 명 이상 확장, 파트너십 확대 및 고급 탈중앙 의료 서비스 도입에 중점을 둔 2027-2030 로드맵 발표&#x20;
  * 프로토콜 기반의 탈중앙 글로벌 의료 레지스트리 출시 계획&#x20;
* 글로벌 확장&#x20;
  * DeSci 서울 2026 개최(2025년 DeSci 서울 후속 행사)


# 9. 의료 데이터와 데이터 주권에 대한 이해

### 9.1 헬스케어 데이터의 중요성

지난 10년간 전 세계는 빅데이터, 머신러닝, 딥러닝 등 데이터와 관련된 수많은 혁신 사례와 그 가능성을 끊임없이 이야기해 왔습니다. 그래서 대부분의 사람들은 이미 데이터가 중요하다는 사실을 인지하고 있을 것입니다.

특히 의료 분야는 수십 년 전부터 과학적이고 체계적인 방법으로 측정한 데이터를 활용하는 프로세스가 자리잡혀 있습니다. 데이터를 활용하여 새로운 치료제의 안전성과 유효성을 평가하는 임상시험이 대표적인 예시입니다. 임상시험 과정에서 만들어지는 대표적인 데이터는 병원 검사 장비로 측정된 각종 검사 수치나 유전자 염기서열 등입니다. 이 데이터들은 잘 구조화된 스프레드시트와 같은 형태로 정리될 수 있는데, 이는 특정 약물 사용에 대한 유효성 및 안전성을 검증하거나 새로운 통계적 사실 등을 발견하는 데 활용될 수 있습니다.

최근에는 병원에서 만들어지는 데이터뿐만 아니라 웨어러블 디바이스나 스마트폰 센서, 환자 자가 보고 자료 등 병원을 벗어난 환자의 일상생활 속에서 상시로 수집될 수 있는 데이터도 의료 데이터로 활용되고 있습니다. 이렇게 다양한 방식으로 수집된 데이터를 함께 이용하면, 처방 약물 외에도 다양한 요인을 고려하여 환자 개개인에 대한 총체적 이해를 바탕으로 한 치료 방법을 마련할 수 있습니다. 이는 실제임상자료(Real-World Data)라는 이름으로 최근 COVID-19 백신([참고](https://pharmanewsintel.com/news/real-world-evidence-confirms-efficiency-of-mrna-covid-19-vaccines))과 디지털 치료제([참고](https://pubmed.ncbi.nlm.nih.gov/33140981/)) 연구에 활용되며 주목받고 있습니다.

위와 같이 헬스케어 분야에서 데이터는 이미 중요한 역할을 하고 있습니다. 다음 장에서는 헬스케어 데이터의 구체적인 종류와 이러한 데이터를 확보하고 활용하는 과정에서 해결해야 할 과제가 무엇인지 알아보겠습니다.

### 9.2 헬스케어 데이터의 종류

헬스케어 데이터의 정의와 분류 기준은 다양합니다. 이번 장에서는 본 백서에서 사용될 헬스케어 데이터의 분류 방법과 그 개념을 소개하겠습니다.

#### 개인의 식별가능성에 따른 분류

미국을 비롯한 대부분 주요 국가는 개인의 식별가능성을 데이터 분류의 중요한 기준으로 포함하고 있습니다. 특히 의료 데이터의 식별가능성은 개인 정보 침해의 위험이 있기에 이를 방지하는 것도 중요하지만, 가치 있는 다양한 데이터를 결합해 환자와 개인의 건강을 개선하는 새로운 혁신을 이끌어 내는 데 활용되기도 합니다. 따라서 개인정보 보호와 활용 사이에서 적정선을 유지할 수 있는 섬세한 접근이 필요합니다. 이러한 접근 방식을 따르고 있는 가장 대표적인 법은 미국의 HIPAA/HITECH법입니다. 이 두 법은 의료정보(Health Information)의 보호와 활용에 관한 기초적인 원칙을 제시하며 의료정보를 아래 3가지로 분류하고 있습니다. 이 분류에 포함되지 않는 의료정보도 기본적으로는 개인정보 보호 관련 일반법을 따릅니다.

| 데이터 종류                        | 식별가능성                                            | 환자의 활용 동의 필요                | <p>연구 목적 활용</p><p><br></p>  |
| ----------------------------- | ------------------------------------------------ | --------------------------- | --------------------------- |
| <p>보호의료정보(PHI)</p><p><br></p> | O                                                | O                           | IRB 심사 후 가능                 |
| 비식별의료정보(DHI)                  | X                                                | X                           | 자유롭게 가능                     |
| 한정데이터세트(LDS)                  | <p>X<br>(다소 완화된 조건 적용)</p><p><br></p><p><br></p> | <p>X<br>(연구 등 목적으로는 면제)</p> | 재식별 금지 합의서 제출 및 IRB 심사 후 가능 |

**보호의료정보(Protected health information, PHI)**

보호의료정보는 HIPAA가 적용되는 의료 기관, 지불 기관, 의료 관련 기관에서 생성, 수집, 전송, 보관되는 개인의 (1) 과거, 현재, 미래의 물리적, 정신적 건강 상태, (2) 건강보험 정보, (3) 의료비 지출 상황 등에 대한 정보로서 개인이 식별되는 의료정보(individually identifiable health information)라고 정의됩니다.

보호의료정보는 공익 등 일부 예외적인 경우를 제외하면 치료 외 목적으로는 환자의 동의를 받아야만 활용, 정정, 반출할 수 있도록 규정되어 있습니다. 연구 기관 등은 연구 목적으로 기관생명윤리위원회(Institutional review board, IRB)를 거쳐 보호의료정보를 활용할 수 있습니다.

**비식별의료정보 DHI (De-identified Health Information)**

비식별의료정보는 1) 세이프하버(Safe harbor) 방식과 2) 전문가 판단 방식 두 가지에 의해 인정됩니다. 세이프하버 방식은 아래 18가지 유형의 식별자를 제거하는 방식을 말합니다. 전문가 판단 방식의 주체는 식별가능성 또는 식별방법에 관하여 통계, 과학 분야의 적절한 지식과 전문성을 갖춘 사람입니다. 해당 정보가 다른 정보와 결합하더라도 개인을 식별할 수 있는 리스크가 매우 적다고 판단하고, 그 이유와 결과를 문서로 기록해야만 인정됩니다.

HIPAA에서 규정한 기관들은 비식별의료정보를 자유롭게 사용하거나 공개할 수 있도록 규정되어 있습니다. 만약 이러한 조치에도 불구하고 식별가능한 것으로 판단될 경우, 보호의료정보(PHI)로 간주됩니다.

\
식별자 유형:&#x20;

이름, 주소, 개인에 대한 날짜(생년월일, 보험 가입일, 보험 해지일, 사망일 등), 전화번호, 자동차 등록 번호, 팩스 번호, 기기 시리얼 번호 및 식별 정보, 이메일 주소, 온라인 접속 주소(URLs), 사회 보장 번호(SSN), 인터넷 접속(IP) 주소, 의료 기록 숫자, 생물학적 지문 또는 성문), 건강보험 정보, 개인 식별 가능성이 있는 사진, 계좌 정보, 재식별가능 정보로 제안된 정보, 인증/자격 정보, 그 밖에 인지 가능성이 있는 정보

**한정데이터세트(Limited data sets, LDS)**

한정데이터세트는 세이프하버 방식을 따른 비식별의료정보(DHI)처럼 의료정보에서 식별자를 제거한 정보라는 점에서는 유사하나, 좀 더 완화된 기준이 적용되어 일부 날짜 정보(생년월일, 입원일, 퇴원일 등) 및 우편번호, 거주지(주, 시)정도의 정보를 포함할 수 있습니다.

대신 연구자 등 정보 이용자에게 데이터 남용을 방지하고자 하는 내용을 담은 데이터 재식별 금지 합의서를 제출하게 하고, 특정 목적(연구, 공중 보건, 의료 서비스 제공)으로 정보를 활용하는 경우 환자의 동의가 없어도 IRB를 거친 뒤에 활용할 수 있다고 규정하고 있습니다. 즉, 정보 이용자에게 재식별 책임을 부과하고 그 대신 정보의 가치 있는 활용을 좀 더 용이하게 한 유형입니다.

#### 데이터 내용에 따른 분류

개인의 식별가능성 외에도 데이터를 분류하는 기준은 구조화 가능 여부, 생성 주체 및 방식, 활용 목적, 대상물의 종류 등 다양합니다. 하지만 본 백서에서는 엄밀하게 구분되는 분류 기준을 적용하거나 모든 유형을 상세히 설명하는 것보다는 활용 가치 측면에서 중요한 의미를 가지는 대표적인 유형들을 선별하여 소개하고, 각각의 데이터가 활용되는 방식에 대한 이해를 돕는 것 무게 중심을 두고자 합니다.

**임상 데이터 (Clinical data)**

가장 대표적인 헬스케어 데이터로, 병원 등 의료 기관이 진단, 투약, 검사, 수술 등을 진행하면서 생성되는 환자 정보를 포함하는 유형입니다. 따라서 구조화된 검사 수치 데이터부터 자연어로 작성된 의무 기록, 의료 영상 및 이미지(X-ray, CT, MRI, 초음파, 내시경 등)까지 매우 다양한 세부 항목이 존재합니다.

이러한 정보를 전자적으로 저장하면 EMR(Electronic Medical Record)이라 하고, 나아가 여러 곳에 저장되어 있는 한 개인의 의료 정보 총체를 EHR(Electronic Health Record)이라 합니다. 임상 데이터는 대부분 생성 시점에는 보호의료정보(PHI)에 해당하며 법에 의해 의료 기관이 안전하게 보관할 의무와 책임을 가지고 환자 외에 다른 기관이 이 데이터에 접근하고 활용하는 것은 엄격히 금지되고 있습니다.

임상 데이터에서 파생되는 데이터로는 의료 기관에서 보험 기관에 비용 청구를 할 때 제출하는 정보를 기반으로 한 청구 데이터가 있습니다. 여기에는 환자의 개인 정보, 진단명, 투약 정보, 검사 정보 등이 포함됩니다. 한국의 경우 단일 보험 체제를 채택하고 있어, 건강보험심사평가원과 국민건강보험공단은 전국민의 데이터를 기반으로 공공 데이터를 구축하여 공개하고 있습니다([보건의료빅데이터 개방시스템](https://opendata.hira.or.kr/home.do),[ 국민건강보험자료 공유 서비스](https://nhiss.nhis.or.kr/bd/ay/bdaya001iv.do) 등). 한국의 제약사 HK이노엔은 이를 활용하여 위·식도 역류 질환 신약 케이캡을 개발하기도 했습니다([참고](https://www.docdocdoc.co.kr/news/articleView.html?idxno=1046804)).

**오믹스 데이터 (Omics data)**

유전체(genome), 전사체(transcriptome), 단백질체(proteome), 대사체(metabolome), 마이크로바이옴(microbiome) 등 생체 물질을 포괄하는 총체적인 개념의 데이터 세트를 말합니다. 이 생체 물질은 개인마다 고유의 특성을 가지고 있어, 이에 대한 데이터를 대규모로 축적하고 분석할 경우 개인 맞춤형 의료가 가능해질 것으로 기대되고 있습니다.

유전체 데이터는 가장 대표적인 오믹스 데이터로, 마치 암호문처럼 알파벳 A,T,G,C를 조합하여 개인의 특성을 결정짓는 DNA에 기록된 유전 정보를 염기서열로 표현한 데이터를 말합니다. 실제로 유전체 데이터를 분석하는 것은 마치 암호문을 해독하는 것과도 같은데, 특정 자리의 단일 혹은 복수의 염기가 무엇인지에 따라 개인간에 어떠한 차이를 만드는지 등을 분석해 내는 것이 주된 과제입니다. 특히 희귀질환의 원인은 약 80% 이상이 유전자 변이이기 때문에 발병의 원인이 되는 유전자를 알아내기 위한 암호 해독이 중요합니다.

최근에는 머신러닝과 빅데이터 분석 기술의 발전으로, 유전체 및 다양한 생체물질 데이터를 임상 데이터와 함께 활용하여 복합적으로 분석할 수 있게 되었습니다. 이를 통해 질환을 조기에 진단하고, 치료 반응 예측과 측정에 사용되는 표지자(바이오마커)를 발견하는 데 활용되고 있습니다.

**사람 유래 건강 데이터 (Person-generated health data, PGHD)**

외부 기관에 의존하지 않고 환자 또는 개인이 소지한 웨어러블 디바이스, 휴대폰 등의 다양한 센서로부터 생성되는 데이터 또는 소셜 서비스 등에 스스로 올린 포스팅이나 설문 등을 포함하는 데이터를 말합니다. 이러한 데이터들은 병원에 방문하지 않고도 일상생활에서 상시로 수집될 수 있다는 특징이 있습니다.

사람 유래 건강 데이터는 질환과 다소 무관해 보일 수 있지만 임상 데이터 및 다른 데이터와 결합하면 질환과 관련된 새로운 발견이 이루어질 가능성이 있습니다. 실제로 최근 신약 임상시험에서도 실제임상자료(Real-world data, RWD)로써 PGHD를 적극 활용하는 시도([참고](https://digital.hbs.edu/platform-rctom/submission/evaluating-new-drugs-with-wearable-technology/))들이 계속되는 추세입니다.

**건강의 사회적 결정 요인(Social Determinants of Health, SDOH)**

건강의 사회적 결정 요인은 인구 통계 정보, 사회·정치적 요건, 기후·환경 등 태생적으로 결정되는 사회·경제적인 외부 요인 중 건강에 영향을 미치는 데이터를 말합니다.

SDOH 데이터를 실제로 활용하는 사례로는[ Gravity Project](https://thegravityproject.net/)가 있습니다. 이 프로젝트에서는 사회·경제적 요인(교육, 직업, 가정, 소득, 사회 안전), 물리적 환경, 건강(흡연, 식습관, 알코올, 성생활), 보건의료(의료 기관 접근성)를 주요 요인으로 규정하고 건강에 미치는 영향을 분석하는 것을 목표로 하고 있습니다.

**연구 데이터 (Research data)**

의약학 및 생명과학 관련 실험실이나 제약사 및 병원에서 신약 등의 새로운 치료법을 개발할 때 생성되는 데이터에 해당합니다. 대표적으로 임상시험 및 연구 결과로 나오는 데이터가 있습니다. 이미 생성되어 있는 임상 데이터나 오믹스 데이터 등도 연구 목적으로 재활용하거나 수집되는 경우 연구 데이터라고 할 수 있습니다.

연구 데이터는 연구 진행에 필요한 참가자를 충분히 확보하기 위해 다양한 기관과 협력하는 것이 필수적입니다. 서로 다른 언어를 사용하는 사람들 사이의 의사소통이 쉽지 않듯, 서로 다른 기관이 동일한 데이터에 대해서 명칭이나 단위 등을 다르게 사용한다면 연구 과정에서 소통과 협력이 어려울 것입니다. 따라서 연구 데이터는 대체로 잘 구조화되어 있고 공동으로 연구를 수행하는 기관 간에는 통일된 규칙하에 수집됩니다. 서로 다른 병원 내의 데이터들을 대상으로 한 통합적 분석이나 다양한 연구를 통해 축적된 환자 데이터의 통합적 분석을 위해[ 공통 데이터 모델](https://en.wikipedia.org/wiki/Electronic_health_record#Common_data_model_\(in_health_data_context\))(Common data model, CDM)과 같은 표준화 노력도 지속되고 있습니다.

연구 데이터는 대체로 과학적으로 엄밀하고 체계적으로 수집될 수 있도록 설계되고 학계와 심사 기관에 의해 검증됩니다. 또한 연구를 실시하기 전에 데이터 수집 대상과 수집 방법의 적법성, 적합성을 IRB 등 심의위원회에 의해 심사받기에 데이터의 품질이 높다는 점이 특징입니다.

**기타 데이터**

그 밖에도 개인의 결제 정보와 같이 그 자체로는 건강과 큰 관련은 없지만, 다른 헬스케어 데이터와 결합되어 분석되었을 때 유의미하게 활용될 수 있는 데이터가 있습니다. 예를 들어 개인의 정기적인 피트니스 센터 결제 내역이 있다고 할 때, 결제 정보는 그 자체로만 보면 건강과 관련이 없어 보일 수 있습니다. 하지만 어떤 건강 관련 수치가 개선되거나 악화될 경우, 이를 결제 정보와 연관시켜 분석함으로써 개인의 건강 지표의 변화를 예측해 볼 수 있습니다.

이와 같이 데이터는 다른 종류의 데이터와 결합되었을 때 더 가치가 높아질 수 있습니다. 따라서 어떤 데이터를 일반적으로 알려진 헬스케어 데이터와 결합되었을 때 가치 있게 활용할 수 있을지 알아내는 것이 앞으로의 중요한 과제일 것입니다.

### 9.3 개인 의료 데이터 관리 및 통제를 위한 해결해야 할 문제

이처럼 데이터는 건강 수준을 향상시키고 질환 치료의 새로운 돌파구를 만들어 내는 데 활용되고 있습니다. 하지만 지금까지 천문학적으로 투자된 금액과 빅데이터 활용 기술이 약속한 이상에 비해 실제 성과는 그에 못 미치는 것도 사실입니다. 이에 대한 주요 이유는 1. 신뢰할 수 있고 2. 장기적으로 수집되고 3. 상호 연결된 데이터가 충분하지 않다는 것입니다.([참고](https://www.mckinsey.com/industries/life-sciences/our-insights/better-data-for-better-therapies-the-case-for-building-health-data-platforms))

즉, AI나 빅데이터 기술보다도 그 밑바탕이 되는 데이터의 질과 양적인 문제를 해결하는 것이 의료 혁신의 핵심입니다. 이번 장에서는 충분한 크기의, 질 높은 의료 데이터 확보를 위해 해결해야 하는 과제에는 무엇이 있는지 알아보겠습니다.

#### 9.3.1. 데이터 보호와 활용의 적절한 균형

**유형 1. 익명화로 인한 데이터 결합과 분석의 어려움**

개인의 의료정보는 민감한 개인정보 중 하나로, 전 세계적으로 법에 의해 매우 엄격하게 보호될 수 있도록 규정되는 추세입니다. 가장 흔한 보호 조치는 가명화 및 익명화이고, 이렇게 비식별화 조치가 취해진 데이터는 개인을 식별하는 것이 현실적으로 매우 어렵거나 불가능하여 개인정보 유출이나 남용에 의한 피해를 줄일 수 있게 됩니다. 안전하게 익명화 또는 가명화되었다고 판단된 비식별화된 데이터는 신약 및 새로운 치료법 개발 등을 위한 연구 등 일부 목적에 한해서 자유롭게 활용될 수 있습니다. 이와 같이 주요 국가들은 개인 식별의 위험을 최소화한 상태에서 데이터가 더 가치있게 활용될 수 있는 법률을 제정하고 있습니다.

하지만 이러한 개인정보 보호 조치가 정보의 활용을 통한 가치 창출 측면에서 한계로 작용하는 것은 불가피합니다. 데이터는 서로 결합되었을 때 더 풍부하게 분석될 수 있고 새로운 가치 창출이 용이해집니다. 하지만 가명화된 데이터는 데이터값이 추상화 또는 범주화됩니다. 예를 들면 33세는 30대로, 87kg은 80-90kg나 90kg로 표현되는 식입니다. 이는 실제 수치와 차이가 있기 때문에, 데이터의 활용 목적에 따라 부적합할 수 있습니다. 또한 데이터를 결합하면 개별 데이터세트만으로는 할 수 없었던 일이 가능해지는 경우가 많은데, 데이터 익명화는 데이터 결합을 매우 어렵게 만듭니다.

<figure><img src="https://lh7-rt.googleusercontent.com/docsz/AD_4nXcVkHzsWcVDm-wZUwULt1LyS46DjYs8jd4Yqv-fNPH1lKllN41w7n4xpJh2STIl-XfrYmG9RI_mdLrroti5nQgu8JAeaDhfBmscf8h47WYoFEOwNcNj7lEjQ5lxs2lQGzMstcYHrA?key=fUWQ9eDkcrmDnZr3M9bUxbfG" alt=""><figcaption></figcaption></figure>

**유형 2. 데이터 생성 장소에 기반한 차등적 보호에 따른 데이터 전송과 활용의 어려움**

또한 개인 식별 가능성이 없더라도 병원에서 생성된 데이터이거나 유전 정보라는 이유만으로도 일괄적으로 엄격한 보호 대상이 되어 현실적으로 활용이 매우 어려워지기도 합니다. 단적으로, 2022년 11월 한국에서는 환자의 개인 기기로 집에서 혈당을 측정하면 건강 정보로 분류되어 원하는 대상에 자유롭게 전송하고 활용할 수 있습니다. 하지만 같은 혈당 정보라고 하더라도 병원에서 혈당을 측정하고 EMR에 저장되면 의료법이 적용되는 정보로 분류됩니다. 이 경우, 환자가 요청하더라도 병원이 직접 혈당 측정치 분석 서비스를 제공하는 다른 기관으로 데이터를 전송 하는 것은 불가능합니다. 현재 데이터 전송이 가능한 유일한 방법은 환자가 직접 병원에 방문하여 해당 정보를 반출받고 직접 다른 기관으로 전달하는 것입니다.

이는 개인정보와 의료정보의 ‘자기결정권’ 보장 범위가 다르기 때문입니다. 자기결정권이란 정보 주체의 권리로, 자신의 정보가 누구에게 어느 범위까지 알려지고 어떻게 이용되도록 할 것인지 스스로 결정할 수 있는 권리입니다. 일반적인 개인정보의 경우 이러한 자기결정권이 개인정보보호법과 같은 법률에 의해 보장됩니다. 반면 의료정보는 의료법을 따르고, 의료법에서는 정보 주체의 자기결정권 중 개인정보 이동권(열람권, 구조화된 데이터 포맷 사용, 제3자 전송 요구권)의 일부인 열람권만 보장하고 있습니다.

이러한 불편함은 환자의 데이터를 병원 등의 기관이 관리하고 책임지도록 하는 방식에서 비롯됩니다. 본래의 의도는 개인의 민감한 의료정보를 보호하기 위한 선한 목적이었겠지만, 환자가 주체적인 판단하에 자신의 데이터를 다른 기관으로 전송하거나 취합할 수 없어 양질의 의료 및 건강 서비스를 활용하기 어려워지는 부작용도 낳았습니다. 그 결과, 개별 의료 기관마다 환자의 의료 데이터가 파편화되어 보관만 되는 상황이 지속되고 있습니다. 이러한 상황에서는 환자 개인에게 맞춤화된 정밀 의료 등의 서비스를 제공하는 것이 거의 불가능합니다. 다행히 현재 금융 분야에서 마이데이터 관련 법이 먼저 시행되었고, 이와 같이 개인의 의료정보도 이동권과 온전한 자기결정권을 실현하기 위한 법제화 논의가 활발히 진행되고 있습니다.

#### 9.3.2. 적절한 동의 확보 방법과 사후 통제권 제공

앞에서 설명한 바와 같이 현재 환자로부터 별도의 동의를 받지 않고도 활용할 수 있는 데이터는 그 활용 목적이 연구, 통계 작성 등 일부 목적으로만 한정되어 있고, 활용되는 데이터 또한 그 품질이 훼손되는 문제가 있습니다. 이러한 문제 없이 데이터를 최대한 있는 그대로 확보하려면 환자 등 정보 주체로부터 수집하려는 데이터 항목과 활용 목적, 활용 조건에 대해 알리고 동의를 받아야만 합니다.

**유형 1. 동의 확보 과정의 문제**

이렇게 동의를 얻는 것은 데이터를 활용하려는 기관 입장에서 적법성을 갖추기 위한 최소한의 요건입니다. 그 때문에 기관 입장에서는 최대한 제약 없이 데이터를 활용할 수 있는 조건으로 환자의 동의를 받고자 할 것입니다. 이는 반대로 말하면 정보 주체를 충분히 보호하지 못하는 방식으로 동의를 받게 될 수도 있다는 것입니다. 실제로 EU([판례: 독일소비자단체연합 대 플래닛49 사건](https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX%3A62017CJ0673))와 한국의 사법 기관([판례: 경품 응모권 1mm 글씨 고지 사건](https://www.law.go.kr/%ED%8C%90%EB%A1%80/\(2016%EB%8F%8413263\)))에서는 미리 선택된 체크박스를 통한 동의와 같은 수동적 동의나 정보 주체가 인식하기 어려운 방식으로 수집하는 동의는 유효한 동의가 아니라고 판단하고 있습니다.

그렇지만 그러한 '불충분한 동의'의 이유가 꼭 기관의 불순한 의도 때문만은 아닐 수 있습니다. 서비스 이용 약관 및 개인정보 보호 정책에 대한 고지 내용이 방대하고 어려운 용어들로 작성되어 대부분의 사람들이 그 내용을 이해하기 어렵다는 점 때문일 수도 있습니다. 또한 개인정보를 철저히 보호하고자 내용을 세분화하여 동의를 받는 형식 자체가 역설적으로 개인에게는 번거롭게 느껴질 수도 있고, 이 때문에 약관 등의 내용이 환자 본인에게 최선인지 확인하는 노력을 들이기보다 무신경하게 동의나 거절을 해버릴 수도 있습니다. 이와 같이 기관이 개인정보를 더 철저히 보호(적어도 법률을 성실히 따르는 차원에서)하려는 의도였다 하더라도 결과적으로는 불충분한 동의가 될 수 있습니다.

한편, 환자 입장에서 데이터가 활용되었을 때 본인에게 어떤 이익이 있는지, 이 과정에서의 잠재적인 위험은 무엇이 있는지에 대한 이해의 정도도 동의 확보에 영향을 주는 요인이 될 수 있습니다. 즉, 데이터 활용으로 인한 개인적 이익이 크다고 기대될수록, 데이터의 리스크에 대한 이해 수준이 높을수록 충분한 동의를 받을 가능성이 커질 것입니다.<br>

<figure><img src="https://lh7-rt.googleusercontent.com/docsz/AD_4nXf4PMnC74yE9kpTr5yIEF8OfsRU47-ECV2AujUqOCk-vbizPtbP0Dem63XSvs-NFwiYxhsL9KrViH3txDaR_-ym53BHK0c6pmbyrqpCcSsWpqBwj5H-tk8a5yS7KZKYzli6-Xmv3w?key=fUWQ9eDkcrmDnZr3M9bUxbfG" alt=""><figcaption><p>강요가 아니라 정보 주체의 판단하에 동의를 얻는 것이 중요합니다.</p></figcaption></figure>

\
**유형 2. 동의 후 데이터 통제 권한 제공 필요**

미국 보건복지부(HHS)는 2020년 1월 20일 커먼룰(Common Rule)을 개정하면서 충분한 고지를 전제로 한 포괄적 동의를 받으면, 식별 가능하고 연구 목적이 아닌 경우에도 추가 동의 없이 데이터를 이차적으로 활용하는 것을 허용하였습니다. 이는 특별한 위험 요소가 없다면 매번 환자로부터 동의를 받아야 하는 비용과 시간을 절약함으로써 연구의 효율과 데이터의 활용 가치를 높이는 순기능을 이끌어 내기 위함입니다. 또한 데이터를 수집한 이후에야 합리적인 사용 목적을 고민할 수 있는 경우가 많기 때문에 다소 포괄적인 목적으로 동의를 받아 데이터를 수집하는 것이 효율적일 수 있습니다.

하지만 이런 경우 환자에게 모든 데이터 활용 및 공개 이력에 대한 접근성과, 데이터 활용 동의를 철회할 수 있는 권리도 함께 제공하는 것이 중요합니다. 혹은 일단 데이터부터 수집하되, 실제 활용이 이루어지는 시점에 환자가 더 세부적인 내용을 확인하고 활용에 대한 동의를 하거나(Opt-in), 동의를 한 이후에도 언제든지 철회(Opt-out) 할 수 있는 동적 동의(Dynamic-consent) 시스템을 제공하는 방법도 있습니다.

이와 같이 사전에 충분한 동의를 받고 사후에도 데이터를 통제할 수 있는 권한을 보장하는 것은 개인정보를 보호하면서도 데이터 활용으로 가치를 창출할 수 있도록 하는 매우 중요한 요소입니다. 이를 실현할 경우 정보의 투명성과 시스템의 신뢰 측면에서 긍정적인 경험을 제공할 수 있을 것이고, 이는 점차 당연한 기대치로 작용하여 법적 측면을 떠나 기관 입장에서도 환자와 사용자 확보를 위해 필수적으로 고려해야 할 요인으로 작용할 것입니다. 따라서 환자, 데이터를 활용하려는 기관, 환자 대신 데이터를 관리해 주는 기관 모두의 입장에서 충분한 동의 기반의 데이터 관리와 활용을 가능케 하는 솔루션이 필요한 상황입니다.

#### 9.3.3. 데이터 공유에 대한 인센티브 부족

주요 국가들은 환자의 데이터 자기결정권 실현을 통해 개인정보 보호와 데이터 활용의 균형을 이루기 위하여 관련 법을 제정하고 있습니다. 그 대표적인 사례가 미국의 21세기 치료법([21st Century Cures Act](https://www.fda.gov/regulatory-information/selected-amendments-fdc-act/21st-century-cures-act))입니다. 이 법에서는 의료 기관에 저장된 환자의 의료정보가 상호 호환되도록 하고 환자가 원하는 애플리케이션에서 의료정보에 접근, 교류, 활용할 수 있도록 하고 있습니다. 이를 준수하지 않을 경우 건당 백만 달러 이하의 벌금이 부과됩니다.

하지만 여전히 많은 의료 기관은 전자적으로 읽고 활용하기 어려운 형태로 데이터를 공유하고 있습니다. 그 외 기업이나 연구자에게는 환자에게 동의를 받더라도 데이터를 공유할 수 없도록 법적으로 제한되어 있거나 그러한 법이 적용되지 않는 국가라 할지라도 데이터 보호를 이유로 데이터 제공을 꺼리는 것은 전 세계 공통적인 현상입니다.([참고1](https://www.raps.org/news-and-articles/news-articles/2022/5/commission-proposes-european-health-data-space-to),[ 참고2](https://www.cnbc.com/2020/02/05/epic-about-60-hospitals-sign-letter-opposing-hhs-proposed-data-rules.html))

한국의 경우도 보건복지부에서 의료 분야의 마이데이터 법제화와 시범 서비스인 마이헬스웨이를 추진 중인데, 최근 보도된 바([참고](https://www.etnews.com/20220518000216))에 따르면 환자의 정보 전송 요구에 대해 의료 기관의 참여를 강제하지 않고 개인과 환자에 대한 서비스 질 향상을 목표로 자발적 참여를 유도하겠다고 말했습니다. 또한 의료 기관 외에 민간 기업은 2024년 이후에 참여가 가능하도록 하여 엄밀한 의미의 데이터 자기결정권 실현과는 아직 거리가 먼 상황입니다.

이처럼 법적인 의무나 처벌에 의해 데이터 자기결정권을 실현하는 것은 한계가 있습니다. 더 이상적인 것은 생태계 내 이해관계자들의 자발적인 동기에 의해서 데이터 자기결정권이 실현되는 것입니다. 하지만[ 미국 국립 의학 아카데미의 조사 결과](https://nam.edu/sharing-health-data-publication-social-media-toolkit/)에 따르면 의료 기관 경영진들은 데이터 공유에 대한 경제적인 동인은 부족한 반면 데이터를 외부에 공유함으로써 경쟁력을 잃게 되는 것에 대해 우려하고 있다고 응답했습니다. 실제로 데이터 구조화 및 표준화, 품질 관리, 데이터 보관 등 데이터 공유를 위한 조치들은 주로 데이터를 생성하는 의료 기관의 비용과 전문성이 수반되는 일들인 반면 그 이득은 오히려 데이터를 활용하는 기관이 보게 될 가능성이 높습니다. 이와 같은 인센티브 불균형으로 인해 데이터 생성 기관의 자발적인 동참이 쉽지 않은 상황입니다.

* 데이터 구조화 및 표준화
  * 임상 데이터의 경우 비정형 텍스트 형식에 사용하는 용어도 일관되지 않은 경우가 많은데 이를 컴퓨터가 읽고 이해할 수 있도록 구조화하는 작업
  * 데이터 공유를 통해 여러 사람이 협력하기 용이하도록 데이터 종류, 용어, 형식의 표준화를 위한 추가 작업
  * 중복 데이터의 존재 여부 확인 및 결합 가능한 데이터의 발견을 위한 검색 메타 데이터 추가 작업
* 품질 관리
  * 여러 질환을 동시에 가진 환자가 보험 청구에 필요한 진단명만 넣은 것, 수기 작성 과정에서 의도치 않게 정보가 누락되거나 잘못된 정보가 입력된 사항들 검수 및 정정
  * 측정 장비의 정확도 문제, 장비 사용의 숙련도에 따라 결과가 일관되지 않은 문제 해결 노력
* 데이터 보관
  * 1인당 최대 200GB 정도에 이르는 유전체 데이터 보관 및 관리 ([참고](https://medium.com/precision-medicine/how-big-is-the-human-genome-e90caa3409b0))
  * 재분석이 용이하면서도 적은 용량으로 데이터를 보관, 관리, 전송하는 기술

<figure><img src="https://lh7-rt.googleusercontent.com/docsz/AD_4nXdD1ZmQGrrch169Cskjzn0a5ZKOZm5S68jUG334ynAE3tqLpqnedwEgedlpsYr-NHdcWbdJGeVRq-blf9HDdrpzrzV5bPGzPUNMZIsh17hyy4Usa2PrP-PO4onTnc89onFjyR2b?key=fUWQ9eDkcrmDnZr3M9bUxbfG" alt=""><figcaption><p>데이터를 생성하려면 많은 이해관계자들의 협력이 필요합니다.</p></figcaption></figure>

#### 9.3.4. 데이터 권리에 대한 이해와 신뢰할 수 있는 기록의 부재

인센티브와 함께 고려해야 하는 점은 데이터에 대한 권리의 공감대 형성입니다. 데이터의 자기결정권이 정보 주체인 환자에게 있어야 한다는 사실에는 큰 이견이 없을 것입니다. 하지만 인센티브와 밀접하게 연관된 개념인 소유권은 그리 단순하지 않습니다. 소유권이라는 개념은 일반적으로 부동산이나 물건 같은 유형물의 재화에만 적용되는 개념입니다. 무형물에 배타적 권리를 부여하는 개념으로는 저작권, 특허와 같은 지적 재산권이 있으나 이 권리는 창작의 노력이 들어가야 인정됩니다. 따라서, 정보나 데이터 그 자체가 아닌 편집의 노력이 들어간 데이터베이스의 경우에만 배타적 권리인 저작권이 인정되고 있습니다.

환자의 의료 데이터가 생성되기까지는 수많은 노력이 필요합니다. 일차적으로 의료 전문가와 의료 기관의 장비를 통해 측정되는 단순 데이터 그 자체뿐만 아니라, 진단명이나 양성·음성 여부와 같이 전문성에 기초한 판단이나 해석에 의해 생성되는 데이터도 많습니다. 또한 데이터가 공유되어 의미 있게 활용되려면 앞에서 언급한 조치들을 취해야 합니다. 경우에 따라서는 서로 다른 데이터를 결합하는 노력도 추가로 필요합니다. 이 모든 과정을 통해 만들어진 데이터세트는 적지 않은 비용과 의료 전문가의 상당한 전문성을 통해 편집된 결과라고 할 수 있습니다.

또한 의료 데이터는 의료보험 제도나 공공 재원이 투입되어 만들어진 의료 시스템에 의해 뒷받침되어 공공성을 지니고 있다는 점도 간과할 수 없습니다. 따라서 특정 주체에게 배타적인 수익권과 사용권을 보장하는 것보다는, 비경합성, 즉 한 주체가 소비한다고 해서 다른 주체가 소비할 기회가 줄어들지 않는 특성을 보장하는 것이 정보 주체 당사자뿐만 아니라 공공에 더 이익이 되고 데이터를 더 활발하게 활용할 수 있을 것입니다.

이러한 소유권, 데이터 공유와 활용에 대한 이력들이 신뢰할 수 있는 방식으로 기록되고, 이 기록에 모든 이해관계자가 자유롭게 접근하고 활용할 수 있는 방법이 아직은 부재한 상황입니다.

### 9.4 자기주권신원과 마이데이터

자기주권신원(Self Sovereign Identity, SSI)은 인터넷에서 개인의 신원을 나타내기 위해 제안된 새로운 모델이며 이를 실현하기 위한 기술인 탈중앙화신원증명(Decentralized Identifier, DID)과 검증가능한 자격증명(Verifiable Credentials, VC)은 2022년 7월, W3C에 의해 웹 표준으로 채택되었습니다.([참고](https://www.w3.org/2022/07/pressrelease-did-rec.html.en))

자기주권신원 기술은 개인이 어떤 기업을 믿고(혹은 서비스를 사용하기 위해 어쩔 수 없이 약관에 동의하고) 자신의 정보를 위탁하여 대신 관리하도록 하는 것이 아니라, 정보 주체가 자신의 정보 통제권을 완전히 유지하는 상태에서 기업이 정보 주체에게 정보 접근과 이용에 대한 동의를 구하도록 합니다.

그러면 꼭 필요한 정보만 정보 주체가 주도적으로 공유하고 그 활용을 통제하는 식으로 패러다임을 바꿀 수 있습니다. 또한 이전에는 해커가 중앙화된 서버를 한 번만 해킹하면 수십에서 수백만에 이르는 개인 정보를 탈취할 수 있었지만, 이제는 한 번에 한 명에 대해서만 공격이 가능하므로 해킹 동기를 떨어뜨리며 결과적으로 개인 정보가 더욱 효과적으로 보호되는 환경을 만들 수 있습니다.

Hippo Protocol은 자기주권신원 기술을 기반으로 정보 주체가 개인의 신원 정보뿐만 아니라 의료 데이터까지 포함하여 자기결정권을 행사할 수 있는[ 마이데이터](https://www.mydata.org/publication/mydata-introduction-to-human-centric-use-of-personal-data/) 개념을 실현하고자 합니다.<br>

<figure><img src="https://lh7-rt.googleusercontent.com/docsz/AD_4nXcrvPNx1YJb2n8_beeMbaqbtddL1IZpjjWWZVUeVjmt-35I6T7E7QncE6G6I2uAp8WiqObvGAPu0lOogeqtIWA7A-vYBdV-kIDEe-40N-ePzBBf-I2k4ABhkIGmSjEXZ7zpcH9bsA?key=fUWQ9eDkcrmDnZr3M9bUxbfG" alt=""><figcaption><p>마이데이터 모델은 지나치게 복잡도가 높아지는 API 모델과 데이터 상호호환성에 대한 인센티브가 없는 플랫폼 모델의 문제를 해결합니다.</p></figcaption></figure>

#### 9.4.1 DID: 자기주권신원을 위한 식별자

지금까지 인터넷상에서 우리의 신원은 특정 기업이 제공하는 서비스 서버 내 계정의 형태로만 식별할 수 있었습니다. 그 때문에 새로운 서비스에 가입할 때마다 새로운 계정을 만들어야 하고, 본인 인증이 필요한 경우 서비스마다 매번 같은 과정을 반복해야 하는 불편함이 있었습니다. 그래서 구글이나 페이스북 같은 대규모 서비스의 계정으로 로그인하는 방법이 널리 채택됐지만, 이는 하나의 서버에 개인정보가 과중하게 몰리는 결과로 이어져 해킹 시의 리스크를 심화시켰습니다. 또한 특정 서비스에 대한 의존도가 높아질수록, 해당 기업의 정책에 위배된다고 '판단'되었을 때 계정이 언제든지 정지되거나 제한될 위협에서 취약해집니다. 이는 최근 미국의 간편 결제 서비스 Paypal이 자사 정책에 부합하지 않는 사용자의 계정에 2,500달러를 '벌금'으로 부과할 수 있다는 정책을 시도한 사례에서 단적으로 드러납니다([참고](https://news.yahoo.com/paypal-policy-permits-company-fine-143946902.html?guccounter=1\&guce_referrer=aHR0cHM6Ly93d3cuZ29vZ2xlLmNvbS8\&guce_referrer_sig=AQAAAM42UWnNy1hmC1hkIIlf4SKW3rCgvDkLJIbkmNzwnpFqcrsmcUoHK7pnrKMaL7nFuyQnb0aOI2kGoh4-k6lwitsmJ9ESAx1QbMm53F7gjgajsU-x1w6SRSRqnYec_HzK7wcakI0o58AZjvjqUfQQMt-cKuHCU0n5oANPclq0yy1r)).

DID는 이러한 문제에 대한 솔루션을 제공합니다. DID는 제3자의 도움 없이 수학과 암호학을 기반으로 생성하여 인터넷 어디서든 자유롭게 사용할 수 있는 자신만의 고유한 ID(신원 식별자)입니다. 이는 우주에 존재하는 모든 원자에 고유 번호를 부여하고 그중 하나를 무작위로 선택하여 해당 고유 번호로부터 생성된 아이디와 이에 연결된 정보를 통제할 수 있는 암호(개인키)를 할당받는 것과 같습니다. 그리고 개인 계정과 그 계정에 연결된 정보는 블록체인에 기록되는데, 이를 조회하고 통제할 수 있는 권한은 개인키를 소유한 사용자에게만 주어집니다. 이를 통해 우리는 정부나 기업의 도움이나 통제에서 벗어나 자유롭게 나의 신원을 생성하고 관리할 수 있습니다. 이 방법은 특히 높은 수준의 개인정보 보호를 요구하는 의료 분야에서 탁월하게 쓰일 수 있으며, 신원에 대한 기록과 그 통제 권한 역시 블록체인에 연결된 모든 컴퓨터와 인터넷이 사라지지 않는 한 안전하게 지킬 수 있으므로 Hippo Protocol의 비전에 필요한 자기주권신원을 실현할 수 있습니다.

#### 9.4.2 VC(검증가능한 자격증명): 나를 증명하는 모든 것

출생증명서, 대학 졸업장, 여권, 운전면허증, 사원증, 피트니스 센터 이용권, 병원 등록 카드, 처방전 등은 나에 대한 특정 사실을 설명하고 증명합니다. 예를 들어 약국에 가서 처방전을 제시하면, 내가 어떤 질병으로 인해 어떤 약을 어느 병원의 어느 의사에 의해 처방받았는지 설명하고 증명할 수 있습니다. 이를 통해 약사는 이 처방이 적절하다는 것을 신뢰하고 약을 제조할 수 있습니다. 그리고 약국으로부터 받은 약제비 영수증을 통해 실제로 처방받은 약을 받았음을 증명할 수 있습니다. 이러한 서류를 모아 보험사에 제출하면 증명된 기록을 바탕으로 보험금을 받을 수 있습니다.

검증가능한 자격증명(Verifiable Credential, VC)은 이렇게 나에 대한 특정 사실을 설명하고 증명하는 구체적인 정보들을 말합니다. VC에 담기는 정보는 발급자(의 DID), 자격증명의 주체(정보 주체의 DID), 그리고 증명하고자 하는 주장(나이, 관계, 진단명 등), 이 자격증명을 보관하는 보유자(의 DID. 보통은 정보 주체와 보유자가 동일하나 미성년자 자녀가 정보 주체인 경우 보호자가 보유자일 수 있음)로 구성됩니다. 그리고 이 정보들은 모두 누가 발급했는지, 조작되지는 않았는지, 만료되거나 해지되지는 않았는지 등을 검증할 수 있어야 합니다.

처음 예시에서 언급한 전통적인 물리적 자격증명은 모두 위조의 가능성이 있으며, 인터넷으로 검증하기 어려운 내용이 많았습니다. 이를 해결하고자 서명이나 홀로그램 같은 증명 장치나 검증 기관이 별도로 존재했지만, 개인정보 보호 측면에서 불완전하였고, 글로벌 단위로 인터넷상에서 사용하기에는 비용이나 기술 면에서 한계가 많았습니다. VC는 누구나 투명하게 검증할 수 있는 블록체인상에 발급되어 인터넷상에서 훨씬 빠른 속도로 검증이 가능하며 비용도 크게 절감됩니다. 이러한 가능성을 바탕으로 DID와 VC는 미국 국토안보부(US Department of Homeland Security) 등으로부터 자금을 지원받아 개발되었고 2022년 7월에 개방형 글로벌 표준으로 채택되었습니다.

Hippo Protocol이 집중하고 있는 협력적인 헬스케어 데이터 생태계를 실현하는 데에도 VC는 필수적인 요소입니다. 어떤 환자에 대한 데이터를 중개인 없이도 검증할 수 있다면 데이터의 유통과 활용 과정에서 발생하는 마찰이 최소화되어 더 활발한 생태계가 만들어질 수 있을 것입니다.

#### 9.4.3 안전한 헬스케어 데이터 교환

앞서 설명했듯이 블록체인은 자산이나 신원에 대한 등기부처럼 중요성이 높고 신뢰할 수 있는 저장소가 반드시 필요한 최소한의 정보를 담는 목적으로 사용되어야 적합합니다. 그런데 일부 데이터는 블록체인상에 기록될 수도 있지만, 수백 GB의 유전체 데이터에서 수 TB에 달할 수 있는 PGHD([참고](https://medium.com/precision-medicine/how-big-is-the-human-genome-e90caa3409b0))와 같은 많은 헬스케어 데이터의 경우 블록체인에 저장하는 것은 현실적이지 않으며 그만큼 많은 복사본이 꼭 필요한 것은 아닙니다.

이 경우 고려해볼 수 있는 솔루션은[ DIDComm](https://didcomm.org/) 표준에 따라 ECDH(Elliptic Curve Diffie-Helman) 기반 다중 서명 기술을 활용하는 데이터 암호화 전달을 위한 표준 프레임워크인 ECIES(Elliptic Curve Integrated Encryption Scheme)을 통해 데이터를 주고받을 수 있게 하는 것입니다. 이러한 방식을 이용하면 중개자의 서버를 별도로 거치지 않고, 데이터 교환을 위해 명시적으로 연결된 두 당사자 외에는 데이터를 열어볼 수 없도록 데이터가 안전하게 암호화·복호화되어 교환됩니다. 이것이 의미하는 바는 환자가 다른 기관에 의존하지 않고도 대용량의 데이터를 의료 기관 및 데이터 활용 기관과 직접 안전하게 교환할 수 있고, 개인정보 유출 위험 없이 데이터의 유통 경로가 매우 효율적으로 개선될 수 있다는 것입니다. 이에 적절한 인센티브 장치를 결합하면 데이터 거래가 가능해집니다.

이외에도 파일을 분산하여 저장하고 공유하기 위한 프로토콜인[ IPFS](https://ipfs.tech/)(InterPlanetary File System)를 활용하는 방법도 고려할 수 있습니다. 어떤 파일이 IPFS 네트워크에 올라오면 여러 노드에 분산되어 저장되며, 분산된 파일을 연결하는 역할을 하는 고유 식별자 CID(Content IDentifier)가 파일의 해시값으로부터 만들어집니다. 환자에 대한 특정 대용량 데이터세트를 환자의 공개키로 암호화하여 IPFS에 올리고 그 CID를 VC에 담아 발급하면, 이후 환자가 그 데이터를 다른 기관에 공유할 때 그 기관은 CID가 변경되지 않았는지를 확인함으로써 원본과 동일한 파일임을 확신할 수 있습니다.

마지막으로[ DWN](https://identity.foundation/decentralized-web-node/spec/),[ Nostr](https://github.com/nostr-protocol/nostr)와 같이 암호키쌍과 P2P로 연결된 수많은 개인 기기와 릴레이를 통해서도 구현될 수 있습니다.

상기에 설명한 방법 외에도 안전한 데이터 교환은 다양한 방식으로 구현될 수 있으며, Hippo Protocol이 채택할 방식은 이뿐만이 아닙니다. Hippo Protocol은 커뮤니티와 함께 더 좋은 솔루션을 열어 놓고 수용할 수 있도록 프로토콜을 설계할 계획입니다.

### 9.5 데이터 발급 및 활용

#### 9.5.1 데이터 발급

데이터 발급 기관 또는 주체는 검증가능한 자격증명(VC)의 형태로 데이터를 발급할 수 있습니다. 데이터는 정보 주체로부터 요청을 받아 건별로 발급되거나 내부 관리자 페이지에서 발급 대상의 DID를 입력해 일괄 발급도 가능합니다. 두 방법 모두 기관 내부 데이터를 VC 형태로 발급할 수 있도록 데이터 모델을 변환해야 합니다. 현재 JSON-LD와 JWT 두 가지 구문 표현을 사용해 VC를 발급할 수 있습니다. 한편, 이러한 데이터 모델로 변환하지 않고 데이터 파일을 정보 주체의 암호키로 암호화해 분산 저장소에 업로드 후 그 파일의 해시값을 VC에 포함하는 방법도 있습니다.&#x20;

<figure><img src="https://lh7-rt.googleusercontent.com/docsz/AD_4nXedWSukcThbpwAvBv3U2LmcweW_xqL6jLVIrq53OJYAlAGqZeAcWpNoIy3hBL2X1bSMZhRkC9uZDhbji2aL28UTUW3VnSKnpwq_KfyDOBhkpYfrlg4KtA6zRMglyWZRjybiBDdaOA?key=fUWQ9eDkcrmDnZr3M9bUxbfG" alt=""><figcaption></figcaption></figure>

VC에 포함되는 또 다른 중요한 정보는 발급된 데이터가 거래되었을 때 발급 기관의 몫으로 배분될 수수료율입니다. 지금까지 데이터 발급 기관은 기관 외부로 반출된 데이터에 대한 몫을 청구할 방법이 현실적으로 없었습니다. VC를 활용한다면 모든 데이터는 환자의 결정이 있어야 유통될 수 있고, 환자 동의하에 유료로 거래된 데이터에 대한 금액은 환자와 발급 기관에 자동으로 배분됩니다. 이를 통해 데이터 발급 기관은 데이터 발급 수수료 외에 데이터 활용으로 발생하는 인센티브를 확보할 수 있습니다. 이러한 메커니즘은 발급 기관으로 하여금 보다 신뢰할 수 있고 활용하기 좋은 데이터를 준비하고 발급하는 데 동기 부여가 됩니다.

#### 9.5.2 데이터 활용

인공지능 헬스케어 솔루션을 개발하거나 이미 개발된 솔루션을 활용해 데이터 기반 헬스케어 서비스를 제공하는 기관, 또는 임상시험에 적합한 참여자를 스크리닝하려는 등의 목적을 가진 기관은 Hippo Protocol을 통해 충분한 동의가 이뤄져 신뢰할 수 있는 데이터를 활용할 수 있습니다. 이를 위해선 우선 데이터 활용 기관에서 사용할 데이터 지갑과 DID를 준비합니다. 그리고 데이터 활용 SDK를 기관 내부 서비스에 통합해야 합니다. 그러면 데이터 활용을 위한 준비가 완료됩니다.

데이터 활용을 위해선 정보 주체의 DID와 활용 기관의 DID를 연결하는 작업이 필요합니다. 이는 일반적으로 정보 주체에게 로그인, 인증, 연결 등의 목적으로 QR코드 스캔을 요청하고, 정보 주체가 이를 스캔 후 동의하는 과정으로 이뤄집니다. 활용 기관은 모든 정보를 한 번에 요청할 필요는 없으며, 초기 단계에서는 기본적인 서비스 이용에 필요한 정보만 요청하고, 더 높은 수준의 사용자 동의가 필요한 정보는 별도로 요청하는 방법으로 데이터를 확보할 수 있습니다. 이러한 방법을 활용하면 사용자 전환이 이뤄지는 퍼널별로 적합한 데이터를 확보할 수 있습니다. 동의를 확보할 때 정보 주체에게 전달해야 할 정보는 활용 기관의 정보, 요청하는 권한의 내용, 어떤 데이터를 어떤 조건으로 활용하고자 하는지 등을 포함합니다. 이는 기존의 이용 약관, 개인정보보호 정책 등 데이터 수집과 활용을 위한 법적 고지문을 제시하고 동의받는 단계에 해당하는 것입니다. 차이점은 활용 기관이 거버넌스 프레임워크에 의해 인증된 표준화된 약관을 채택할 수 있다는 것입니다. 이러한 방식의 장점은 데이터 지갑의 동의(서명) 관리에서도 설명했듯이 정보 주체 입장에서는 매번 법적 고지문을 세세히 확인하는 노력을 들일 필요가 없다는 것이고, 기관 입장에서는 국가별, 상황별로 적합한 컴플라이언스 요건을 갖춘 라이센스를 채택하면 된다는 것입니다. 이는 법률 검토를 위한 비용과 시간을 크게 절감하고, 충분한 동의를 확보하는 데 한층 수월할 것입니다.<br>

<figure><img src="https://lh7-rt.googleusercontent.com/docsz/AD_4nXfbAi9iRaEzqia6EF_2nMs4_OuTXWM7MA-foa31fXfdqaeGuyS3t8UuAqmnv5W9sQpGYKdruwXE_oxbv_0OHf319fKSYm8EmPqNf99KX4WrR9lCpiruCb1YgrGyenUGPaXrX4jCNA?key=fUWQ9eDkcrmDnZr3M9bUxbfG" alt=""><figcaption></figcaption></figure>

데이터 사용자 기관은 Hipp Protocol DAO의 표준화된 프로토콜을 활용하고, CompliantData SDK를 통해 라이선스를 획득할 수 있습니다.

위 기능들은 Data Hippo에 최초로 적용되어 데이터 활용 SDK와 함께 실제 환자가 자신의 데이터 지갑에 보관된 데이터를 통해 건강 관리 및 커뮤니티 서비스를 이용할 예정입니다. SDK는 다른 영리/비영리 제품에도 별도 계약 없이 자유롭게 통합될 수 있습니다.

Data Hippo는 초기 Hippo Protocol 생태계에 환자가 데이터 지갑을 활용할 수 있는 사용처를 제공할 것입니다. Data Hippo는 환자에게 충분한 동의를 받아 확보한 데이터를 기반으로 신뢰할 수 있는 맞춤 정보와 건강 관리 솔루션, 커뮤니티 경험을 제공합니다. 나아가 환자가 서비스 사용 과정에서 생성한 환자 유래 건강 데이터와 지갑을 통해 제출한 임상 데이터 등을 통합하고, 이를 제약사와 같은 또 다른 데이터 수요 기관에서 활용하기 좋은 형태로 가공한다면 부가가치가 높은 데이터 판매가 가능해질 것입니다. 이 과정은 환자의 동의를 기반으로 하며, 발생한 수익은 환자와 데이터 발급 기관에 배분되는 보상의 원천이 되어 지속가능한 데이터 보상과 활용을 가능하게 합니다.

이 시나리오를 구현하려면 데이터 활용 및 보상에 대한 조건이 환자가 동의하는 내용에 포함됩니다. 특히 개인정보 공개 수준에 따라 데이터는 보호의료정보·비식별의료정보·한정데이터세트 또는 식별의료정보·익명의료정보·가명의료정보 등으로 나뉠 수 있습니다. 일반적으로 높은 수준의 개인정보와 더 많은 정보를 요구할수록 보상 금액이 커지지만, 환자가 개인정보를 보호하고자 거절할 가능성 또한 높아집니다. 이에 따라 데이터 활용 기관은 환자를 설득할 수 있는 꼭 필요한 데이터만 확보하려 노력할 것입니다. 또한 데이터는 생성 과정에서 공공 재원이 많이 투입되기 때문에 가명 또는 익명정보일수록, 과학적 연구 목적으로 활용될수록, 공공의 목적으로 배분되는 보상의 비율이 커지게끔 설계할 수 있습니다. 이러한 메커니즘은 공공 보건의료 서비스의 품질을 높이는 데 기여할 수 있습니다.

<figure><img src="https://lh7-rt.googleusercontent.com/docsz/AD_4nXc4X1Oeqg7khOK65K584XeiNf971kVC07oMR_Q25MyuEE0f-gELfEjfhXSCkqxBciD-3hkmPoqOmRgc8X3XP8HrNrZVL9yCUEiBSTA18bPGw7jGiexucRFHw2uPW20J50Yxsxx8?key=fUWQ9eDkcrmDnZr3M9bUxbfG" alt=""><figcaption><p>데이터에 대한 보상이 클수록, 개인정보 침해에 대한 위험이 적을수록 데이터 공유에 대한 동의를 받을 수 있는 가능성이 커집니다.</p></figcaption></figure>

## 9.6 Hippo SDK

Hippo SDK는 정보 주체가 자신의 신원과 기관으로부터 받은 데이터, 그리고 데이터 공유 보상 등으로 획득한 자산을 관리하는 데이터 지갑을 개발할 수 있게 하는 오픈소스 개발키트입니다. 데이터 지갑에서 개인의 데이터를 보관하는 방식은 원본 데이터 자체를 보관하는 것이 아니라 그 데이터에 접근할 수 있는 카드키나 영수증을 보관하는 것과 유사합니다. 마치 지갑에 현금이나 신용카드 뿐만 아니라 신분증, 멤버십 카드, 티켓, 헌혈증, 카드키, 영수증 등을 보관했다가 필요할 때마다 꺼내 쓰는 것과 같습니다. 지갑을 분실하면 그 안에 있는 것도 함께 잃어버리듯 지갑은 지갑 소유자에게 온전한 통제권이 있으며, 바꿔 말하면 온전한 책임 또한 지갑 소유자에게 있습니다. 데이터 지갑도 마찬가지입니다.

본 장에서는 Hippo SDK에서 제공하고자 계획을 세우고 있는 핵심 기능들을 소개할 것입니다. 그 대부분은 개방형 표준과 오픈소스를 기반으로 구현되는데 이는 바퀴를 새로 발명하는 대신, 이미 충분히 검증된 기술을 기반으로 Hippo Protocol이 해결하려는 문제에 초점을 둔 부가가치를 더하는 데 집중하기 위함입니다. 이러한 방식은 새로운 소프트웨어에서 발생할 수 있는 의도적/비의도적 결함을 최소화하면서도 개방형 표준에서 지속되는 개선과 혁신을 그대로 누릴 수 있다는 장점이 있습니다. 또한 이러한 방식은 Hippo SDK를 기반으로 개발된 지갑에 담긴 사용자의 자산과 데이터에 다양한 애플리케이션을 통해 접근할 수 있게 개방하여 사용자가 누리는 효용이 더욱 커질 수 있게 합니다.

### 개인키 생성 및 관리

Hippo SDK의 기본 기능은 자산, 데이터 및 탈중앙화 신원(DID)에 접근하고 관리하는 데 필요한 개인 키를 안전하게 생성하고 저장하는 것입니다. Cosmos SDK 표준과의 호환성을 통해, 대부분의 블록체인 지갑과 동일한 수준의 보안을 제공하며, 개인 키 생성 및 니모닉 코드 복구 기능을 지원합니다. 따라서 Hippo SDK는 기본적인 블록체인 지갑 기능을 구현하는 데에도 활용될 수 있습니다. 추가 보안을 위해, 디바이스의 신뢰 실행 환경(TEE)을 적용하여 개인 키 저장을 강화할 수 있습니다.

### 연결, 인증, 로그인

자신의 DID가 생성되면 이를 통해 중개자 없이 데이터에 접근하는 기관과 P2P로 연결할 수 있습니다. 이 사이에 오가는 모든 데이터와 메시지는 종단 간 암호화되어 당사자 외에는 그 내용을 볼 수 없습니다. 이러한 방식을 이용하면 통신 과정에서 발생하는 개인정보 노출 위험을 최소화할 수 있습니다.

최초 연결은 보통 기관의 애플리케이션이나 웹 사이트에서 연결을 위한 QR코드를 스캔하거나 버튼을 누른 후, 사용자가 연결하려는 대상에 대한 정보와 요청 권한 및 데이터 등을 확인한 후 승인하는 방식으로 이뤄집니다. 이렇게 한 번만 연결하면 어느 한쪽에서 종료하지 않는 이상 신뢰 관계로 기억되어 연결이 유지됩니다.

헬스케어 상황을 생각해 보면 일반적으로 병원은 최초 방문 시 신규 환자로 등록해야 합니다. 이때 환자는 등록 버튼을 누르고 본인 데이터 지갑으로 QR코드를 스캔하면 본인임을 확인할 수 있는 이름, 주민등록번호, 사진, 성별 등 법정 신원에 대한 공유 요청을 받습니다. 환자가 이를 승인하면 병원 측 담당자가 환자의 데이터 지갑으로부터 환자 본인임을 확인한 후 환자 등록이 이뤄집니다.

이러한 방식은 로그인이나 다른 인증 수단을 대체하기 때문에 사용자가 연결하려는 서비스마다 아이디와 암호를 생성하고 기억해야 하는 불편함을 해소합니다. 또한 QR코드 인식만으로 간편하게 로그인, 인증, 자산 및 데이터 송수신 등을 할 수 있습니다. 그뿐만 아니라 데이터 지갑 애플리케이션 자체에 PIN, 생체인식 등 추가적인 보안 수단을 개인키와 조합하면 사실상 멀티팩터 인증(Multi-factor Authentication, MFA)으로서 일반적인 로그인 방식보다 훨씬 높은 수준의 보안성을 갖출 수 있습니다.

<figure><img src="https://lh7-rt.googleusercontent.com/docsz/AD_4nXfmrzYGn3F5wWxqt46uq4YBy_UVeiVUw2OJSO7YyyOjXphFBznjXlLd1tjq8KZsrPUzhnbUuQeapOHipv7m9qqKpadgQFFaTbE9343tn8ZlVLcwcm1b3CGybPG7dIe9-Ac2ND8QRg?key=fUWQ9eDkcrmDnZr3M9bUxbfG" alt=""><figcaption><p>QR코드 인식만으로 간편하게 로그인, 인증, 자산 및 데이터 송수신을 할 수 있습니다.</p></figcaption></figure>

### 데이터 관리

데이터 지갑을 통해 병원과 같은 상대방과 연결된 상태에서는 사용자가 요청할 때마다 혹은 상대방이 필요하다고 판단할 때마다 원본 데이터 혹은 그 증명서를 상호간에 전송할 수 있습니다.

전형적인 시나리오로는 병원에서 의무기록과 같은 데이터를 발급할 때 환자 본인임을 확인하는 인증 절차를 거친 뒤, 환자의 데이터 지갑에 VC 형태로 발급하는 것입니다. 그러면 데이터 지갑에 데이터가 발급되었으며 이를 승인하겠냐는 알림과 메시지가 도착하고, 승인 후에는 데이터를 확인할 수 있게 됩니다. 일반적인 클라우드 스토리지와 달리, 데이터는 모두 사용자의 암호키에 의해 암호화되어 저장됩니다.

이렇게 발급된 데이터는 필요한 곳에 제시할 수 있습니다. 예를 들어 데이터를 활용한 건강 관리 서비스를 이용하려면 환자에게 서비스를 제공하기 위해 특정 데이터에 접근이 필요하다며, QR코드 스캔을 요청합니다. 환자가 QR코드를 스캔하면 어떤 데이터를 활용하는지 서비스 제공자에 대한 상세 정보와 이용 조건 등을 확인할 수 있고, 이를 승인하면 서비스 제공자에게 데이터를 공유합니다. 그러면 서비스 제공자는 해당 데이터의 해시가 발급자가 제공한 데이터의 해시와 동일한지, 발급자는 신뢰할 수 있는 기관인지 등을 검증합니다. 검증을 마치면 환자에게 필요한 서비스가 제공됩니다. 다소 복잡해 보이지만, 이 모든 과정은 자동화된 소프트웨어가 빛의 속도로 처리하기 때문에 환자는 일반적인 간편 인증 과정처럼 느낄 것입니다.

경우에 따라 데이터 전체를 공유하지 않고 원하는 데이터만 선택해서 공유할 수 있습니다. 심지어 개인정보가 노출될 수 있는 데이터를 상대방에게 공유하지 않고도 목적을 달성할 수 있습니다. 본인이 자녀의 법정 대리인(보호자)임을 증명해야 하는 상황을 예로 들어보겠습니다. 우선 본인 데이터 지갑에 자녀에 대한 정보와 자녀와의 관계가 담긴 정보가 보관되어 있어야 합니다. 병원 담당자는 본인에게 자녀의 보호자가 맞는지 확인하고자 QR코드를 스캔해 달라고 요청할 것입니다. QR코드를 스캔하고 승인하면 시스템은 이름, 생년월일, 성별, 주소 등 개인정보는 노출하지 않은 채 해당 환자의 보호자로 등록되어 있는지만 확인하고 맞다 틀리다 결과만 알려줍니다. 이러한 방법을[ 영지식 증명](https://en.wikipedia.org/wiki/Zero-knowledge_proof)(Zero-knowledge proof)이라고 합니다. 병원 담당자는 개인정보가 아니라 실제 보호자인지만 확인하면 되기 때문에 목적을 달성할 수 있습니다.

<figure><img src="https://lh7-rt.googleusercontent.com/docsz/AD_4nXcXDr8TBlGEYbhnVPlcqMMRwccrtvFiGu5yXNkQbanCepidbX135BT_v_OZXZOC080u7g5frb_OTcMEImpCJTVnmkJYYHhDQgH8OUjagWM-DC8s9o7IQWe1cxip4gdU3E8tvCZsCw?key=fUWQ9eDkcrmDnZr3M9bUxbfG" alt=""><figcaption></figcaption></figure>

### 동의(서명) 관리

동의 자체는 기존 방식도 큰 문제가 없습니다. 이미 위의 인증, 로그인, 데이터 관리에서 사용자가 동의 버튼을 누르면 되는 것으로 설명했고, 이는 기존 방식과 비슷합니다.

차이점은 데이터 지갑에서는 이미 동의한 내역을 한번에 확인할 수 있고, 더 이상 상대방에게 권한을 주고 싶지 않은 경우에는 언제든지 철회할 수 있다는 것입니다. 기존 방식은 일일이 해당 서비스를 방문해야 하고, 동의 철회는 대체로 쉽지 않으며, 심지어는 별도 서류를 작성해야 하는 등 번거롭습니다. 이와 달리, 데이터 지갑은 동의 이후에도 사용자에게 정보에 대한 자기결정권을 최대한으로 제공합니다.

또한 사용자가 공유하겠다고 동의한 모든 데이터에는 사용자의 암호키로 일종의 워터마크와 같은 서명을 남길 수 있습니다. 이를 활용하면 특정 기관이 보유한 데이터에 워터마크가 없는 경우, 해당 기관은 해당 데이터를 어떻게 적법하게 가졌는지 증명해야 할 것입니다. 이로써 정보 주체의 데이터가 더 안전한 방식으로 유통될 수 있게 됩니다.

한편, 기존 방식의 본질적인 문제는 ‘나는 약관의 내용을 읽고 동의합니다.’와 같은 문구를 표시하고, 이에 대한 증거로 동의 버튼을 누르도록 ‘강요’하는 동의 확보 방법에 있습니다. 이는 정보 주체보다 서비스를 제공하는 기업을 보호하기 위한 것에 가깝습니다. 서비스 약관 및 프라이버시 정책 등은 내용이 너무 길고 복잡하기 때문에 현실적으로 사용자가 모든 내용을 면밀히 읽고 불합리한 조항이 있는지 검토하기란 어렵습니다. ‘불충분한 동의’가 발생할 수밖에 없는 이유이기도 합니다.

이를 해결하기 위해 Hippo Protocol에서는 정보 주체를 충분히 보호하면서도 합리적으로 활용하는 데 문제가 없는 정책에 대한 표준화된 라이센스를 도입할 예정입니다. 만약 여러 서비스가 같은 정보보호 정책을 갖추고, 자세히 읽어보지 않아도 모든 내용이 동일하다는 것을 신뢰할 수 있다면 사용자는 여러 서비스를 쓰더라도 한 번만 제대로 읽어보면 될 것입니다. 그 다음부터는 동일한 정보보호 정책 라이센스를 사용한다는 것만 확인하면 그저 동의 버튼만 누르거나 또는 사용자가 원하면 자동으로 동의하도록 설정할 수도 있을 것입니다. 이는 사용자 편의성, 사용자 보호, 기업의 동의 확보율 등 모든 측면에서 도움이 될 것입니다.

만약 표준에 존재하지 않거나 기존에 사용자가 동의한 적이 없는 조항이 담긴 정책의 경우, 동의를 별도로 받아야 하는 약관으로 분리할 수 있습니다. 이러한 경우, 사용자는 변경되거나 새로운 내용만 확인하면 되기에 더욱 확신을 갖고 동의 여부를 결정할 수 있게 됩니다.

이러한 라이센스는 탈중앙 거버넌스 프레임워크에서 관리되어 신뢰성을 갖출 것입니다.

### 자산 관리

Hippo Protocol 메인넷 코인 $HP와 달러 연동 스테이블코인은 이 목적에 가장 적합한 자산으로 활용될 수 있습니다. 특히, 기관 차원의 스테이블코인 도입이 증가함에 따라, 신용카드 결제 속도로 전 세계 소액 결제가 가능하며, 수수료는 0.0X 달러 이하로 유지될 수 있습니다.

또한, IBC(Inter-Blockchain Communication Protocol)를 통해 Cosmos 생태계 내에서 스테이블코인 및 $HP의 관리 및 전송이 더욱 원활해질 것입니다. 이에 따라, Hippo Protocol 및 Hippo SDK는 이러한 기술과 연계하여 개발되며, 사용자가 선호하는 형태의 자산으로 데이터를 수집 및 활용한 보상을 받을 수 있도록 설계됩니다. 이를 통해 글로벌 보상 시스템이 구현될 것입니다.

### 백업과 복원

데이터 지갑에는 개인의 소중한 자산과 데이터가 포함되어 있으므로, 이를 안전하게 백업하고 복구할 수 있는 방법 또한 필수적입니다. 기본적으로, 사용자는 BIP-39에 따라 데이터 지갑 생성 시 표시되는 니모닉 코드를 안전한 장소에 기록하여 백업할 수 있습니다. 그러나 이러한 방식은 일부 사용자에게 생소할 수 있으며, 모든 책임을 개인이 부담해야 한다는 점에서 부담을 느낄 가능성이 높습니다.

이를 해결하기 위해, 니모닉 코드를 사용자가 선택한 비밀번호로 암호화하여 iCloud 또는 Google Drive와 같은 개인 클라우드 저장소에 보관할 수 있도록 지원할 예정입니다. 이 방식은 대규모 자산을 보관하는 용도로는 적합하지 않을 수 있지만, 대부분의 데이터 지갑 사용자에게는 니모닉 코드 분실 위험을 줄이는 실용적인 대안이 될 수 있습니다.

물론, 사용자는 보다 높은 보안 수준을 유지하기 위해 클라우드 저장소에 니모닉 코드를 저장하지 않는 선택도 가능합니다. 또한, 블록체인 지갑 표준을 준수하는 만큼, 멀티시그(Multi-Sig) 지갑 및 패스프레이즈 추가와 같은 보안 강화 기능을 유사한 방식으로 구현할 수 있습니다.

### 알림

필수적인 고지 내용이나 동의 요청을 사용자가 적시에 확인하려면 알림 기능이 필요합니다. 효과적으로 사용자의 주의를 끌 수 있도록 동의와 서명이 필요할 때만 기기의 시스템 알림 기능을 활용할 것입니다.

### 대리인・후견인

일반적으로는 지갑 소유자와 정보 주체가 동일하지만, 많은 환자가 건강이나 기술 이해도 등의 이유로 스스로 데이터 지갑을 관리하기 어려울 수 있습니다. 이러한 경우에는 타인이 환자를 대신해 동의와 데이터 공유에 대한 의사 결정을 할 수 있도록 데이터 지갑 수준에서 대리인을 지정하는 기능을 제공할 수 있습니다. 이때, 대리인 자격을 가진 지갑 사용자는 정보 주체의 데이터를 지갑에 대신 보관하고 통제할 수 있는 권한을 가질 수 있습니다.

이러한 대리인은 보호자와 같은 개인뿐만 아니라 단체가 될 수도 있습니다. 또한 이 기능을 확장하면 환자가 사망했을 때 환자의 자산과 데이터를 후견인이 넘겨받을 수 있도록 구현할 수도 있습니다. 각국 법률에서 이러한 방식이 허용되는지는 추가적인 확인이 필요하지만, 대리인과 후견인에 대한 신원 인증은 앞서 설명한 검증가능한 자격증명(VC)을 통해 전자적 방식으로 구현이 가능합니다.


# 10. 면책 조항

본 문서는 Hippocrat DAO Foundation이 계획하고 개발 중인 플랫폼에 대한 구체적인 정보를 전달하기 위해 작성되었습니다. 본 문서는 정보 제공만을 목적으로 하며, 본 문서에 포함된 정보의 정확성이나 신뢰성을 보장하지 않습니다. 본 문서에 포함된 정보는 Hippocrat DAO Foundation이 신뢰할 수 있다고 간주하는 출처에서 입수한 것이지만, Hippocrat DAO Foundation은 해당 정보의 정확성이나 적합성을 보장하지 않습니다. 즉, Hippocrat DAO Foundation은 회사 또는 Hippo Protocol 플랫폼과 관련된 정보로 인해 발생하는 손실이나 손해에 대해 법적인 책임을 지지 않습니다. 본 문서에 포함된 정보는 현재 시점에서의 판단을 따르며 사전 통지 없이 변경될 수 있습니다. Hippocrat DAO Foundation은 본 문서를 수정, 수정 또는 업데이트할 의무가 없습니다. 각 수신자는 본 문서의 정보에 대한 지식, 연구, 판단 및 평가에 전적으로 의존해야 하며, 회사, 직원 및 주주는 논의, 표시, 발생, 포함 또는 파생된 모든 주장, 제안 및 정보에 대해 책임을 지지 않습니다. Hippocrat DAO Foundation은 본 문서에 정확한 사실을 포함하기 위해 노력했으며, 본 문서의 가능성 추정치는 주관적인 예측에 근거한 것으로 실제 발생 가능성을 나타내는 진술로 해석해서는 안 됩니다. 이 문서는 배포, 게시 또는 사용이 금지된 주, 국가 또는 기타 관할권의 시민 또는 거주자를 대상으로 하지 않습니다. 본 문서는 [www.hippoprotocol.ai](http://www.hippoprotocol.ai) 에서만 확인할 수 있으며, Hippocrat DAO Foundation의 사전 서면 동의 없이 어떤 목적으로든 문서의 전체 또는 일부를 다른 사람에게 재배포, 복사, 전달 또는 게시할 수 없습니다.


