The global Electronic Health Record (EHR) market is growing dramatically and
expected to reach 39.7billionsby2022.Tosafe−guardsecurityandprivacyofEHR,accesscontrolisanessentialmechanismformanagingEHRdata.ThispaperproposesahybridarchitecturetofacilitateaccesscontrolofEHRdatabyusingbothblockchainandedgenode.Withinthearchitecture,ablockchain−basedcontrollermanagesidentityandaccesscontrolpoliciesandservesasatamper−prooflogofaccessevents.Inaddition,off−chainedgenodesstoretheEHRdataandapplypoliciesspecifiedinAbbreviatedLanguageForAuthorization(ALFA)toenforceattribute−basedaccesscontrolonEHRdataincollaborationwiththeblockchain−basedaccesscontrollogs.WeevaluatetheproposedhybridarchitecturebyutilizingHyperledgerComposerFabricblockchaintomeasuretheperformanceofexecutingsmartcontractsandACLpoliciesintermsoftransactionprocessingtimeandresponsetimeagainstunauthorizeddataretrieval.