Lifebit logo
BlogUncategorizedHomomorphic Encryption in Health Research: Uses and Limits

Homomorphic Encryption in Health Research: Uses and Limits

Detailed close-up of blue soap foam showcasing abstract geometric patterns and texture.
Photo by Antonio Friedemann on Pexels

Homomorphic encryption is a form of encryption that lets a computer perform calculations on encrypted data and produce an encrypted result that, once decrypted, matches the result of running the same calculation on the original data. In health research, it allows sums, counts, and some statistical models to be computed on patient or genomic records without the analyst ever seeing them in plaintext. Its limits are cost and scope: it is still far slower than ordinary computation and practical only for narrow, well-defined analyses, so it works best as one component inside a broader privacy architecture rather than as a platform on its own.

Why homomorphic encryption is back on the agenda

For most of its history, homomorphic encryption was a theoretical curiosity. Partially homomorphic schemes, which support one operation, have existed for decades. The Paillier cryptosystem supports addition on encrypted values, and textbook RSA supports multiplication. The breakthrough came in 2009, when Craig Gentry published the first fully homomorphic encryption (FHE) scheme, able in principle to evaluate any computation on encrypted data. That first construction was far too slow for real use.

The years since have brought faster schemes, open-source libraries, and a community standardization effort. Schemes such as BGV and BFV support exact integer arithmetic, CKKS supports approximate arithmetic on real numbers (well suited to statistics and machine learning), and TFHE supports fast operations on bits. Libraries including Microsoft SEAL, OpenFHE, HElib, and Lattigo have made the math accessible to engineering teams. The iDASH secure genome analysis competition, run by the academic privacy community, has included homomorphic encryption tracks for tasks such as genome-wide association testing, which produced a body of published benchmarks on real genomic workloads.

At the same time, regulators have raised expectations. The General Data Protection Regulation (GDPR) and the European Health Data Space (EHDS) regulation push health data custodians toward technical measures that reduce exposure during secondary use. Privacy-enhancing technologies, homomorphic encryption among them, are now named in regulator guidance such as the UK Information Commissioner’s Office guidance on privacy-enhancing technologies. That has moved the question from “is this possible” to “where does this actually fit.”

How homomorphic encryption works in practice

Encrypt, compute, decrypt

A data holder encrypts values with a public key. Anyone holding the ciphertexts can then apply permitted operations, such as addition and multiplication, without the secret key. The result is still encrypted. Only the holder of the secret key can decrypt it, and what they see is the answer to the computation, not the inputs.

Noise and bootstrapping

Modern schemes are built on lattice problems, most commonly Ring Learning With Errors. Each ciphertext carries a small amount of random noise that keeps it secure. Every operation increases that noise, and multiplications increase it quickly. If noise grows too large, decryption fails. Bootstrapping is a procedure that refreshes a ciphertext and resets its noise, allowing unlimited computation, but it is expensive. Many practical systems avoid it by limiting the depth of the computation in advance, an approach called leveled homomorphic encryption.

Why the cost is high

Ciphertexts are much larger than the values they encrypt, and each operation involves polynomial arithmetic over large numbers. The result is overhead that is commonly described as several orders of magnitude compared with plaintext computation, depending on the scheme and workload. Comparisons, divisions, and non-linear functions (the building blocks of many clinical models) are especially costly and usually need approximations.

Post-quantum properties

Because lattice-based schemes rely on problems believed to resist quantum attack, homomorphic encryption shares a mathematical foundation with the post-quantum algorithms standardized by the US National Institute of Standards and Technology. For long-lived genomic data, that is a real advantage over older public-key methods.

The federation angle: encrypt the computation, or move it

Homomorphic encryption solves a specific problem: letting an untrusted party compute on data it must not see. The usual picture is a hospital that encrypts records and sends them to a cloud service for analysis. That picture still involves moving data, only in encrypted form. The encrypted copy exists outside the custodian’s control, and its security depends on key management holding up for as long as the data stays sensitive, which for genomic data is effectively forever.

A federated Trusted Research Environment (TRE) takes the opposite approach. Rather than shipping encrypted data to the computation, it sends the computation to the data. Each custodian runs the analysis inside its own environment, data never leaves the source, and only reviewed aggregate results pass through an airlock. Federation delivers most of what health research needs (counts, regressions, survival models, model training) at ordinary computing speed.

Where homomorphic encryption earns its place in a federated design is at the aggregation step. When several sites return intermediate statistics, such as partial sums or model gradients, even those aggregates can be sensitive in small cohorts. Encrypting them additively means a coordinating server can combine the contributions without seeing any single site’s values. That is a narrow, cheap use of the technology, and it plays to its strengths: simple addition, few operations, small data volumes.

Uses and limits: a practical comparison

Health research taskHomomorphic encryption fitWhyUsual alternative
Secure aggregation of site-level counts or gradientsStrongOnly addition is needed; data volumes are smallSecure multi-party computation
Cohort counting and feasibility queriesGoodSimple sums over encrypted indicatorsFederated query with disclosure control
Private lookup of a variant or biomarkerGoodWell-studied private information retrieval patternsQuery inside a TRE
Genome-wide association testingModerateDemonstrated in research benchmarks, but heavy computeFederated GWAS with meta-analysis
Training deep learning modelsPoorNon-linear functions and depth make costs prohibitiveFederated learning, confidential computing
Exploratory, iterative analysisPoorEvery new question needs a new encrypted pipelineGoverned analysis inside a federated TRE

The pattern is consistent. The more a task looks like “add up numbers from many places,” the better homomorphic encryption fits. The more it looks like a researcher exploring data and changing direction, the worse it fits.

A framework for deciding when to use it

  1. Define the computation first. Homomorphic encryption requires the analysis to be fixed in advance. If the research question is still evolving, the technique is premature.
  2. Check the operations involved. Additions and a small number of multiplications are practical. Comparisons, sorting, and deep non-linear models usually are not.
  3. Estimate the data volume. Encrypting millions of genomic variants per participant multiplies storage and transfer costs. Encrypting a few thousand aggregate values does not.
  4. Decide who holds the keys. The value of the scheme depends entirely on the secret key staying with the right party. Threshold schemes, where several parties must cooperate to decrypt, reduce single points of failure.
  5. Keep output control. Decrypted results are still results. A correctly computed table can still disclose an individual if cells are small, so statistical disclosure control applies after decryption just as it does anywhere else.
  6. Compare against simpler controls. If a federated query with an airlock already meets the governance requirement, adding encryption may add cost without adding meaningful protection.

Where it shows up in real programs

Most published health uses of homomorphic encryption remain research demonstrations rather than production services. The iDASH competitions are the clearest public record, showing that tasks such as logistic regression and association testing on genomic data can be run on encrypted inputs within practical time limits for fixed problems. Academic groups have also published secure aggregation protocols for federated learning that use additively homomorphic encryption to hide individual contributions.

In production health data infrastructure, the dominant pattern is governed access rather than encrypted computation. National programs such as Genomics England, a Lifebit customer, and population cohorts such as Canada’s CanPath rely on controlled environments, approved researchers, and output review. Homomorphic encryption, where used, tends to appear inside specific protocols (secure aggregation, private set operations) rather than as the user-facing platform.

Common pitfalls and objections

“Encrypted data can be shared freely”

Encrypted health data is generally still personal data under GDPR, because the key holder can re-identify it. Encryption reduces risk but does not change the legal basis required for processing.

“The result is private because the inputs were encrypted”

Homomorphic encryption hides inputs from the party doing the computation. It says nothing about what the output reveals. A count of one is a disclosure whether it was computed on ciphertext or plaintext.

“It will replace secure environments”

For fixed, simple computations it can reduce reliance on trusted infrastructure. For the everyday work of health research, including cleaning, harmonization, exploration, and modeling, a governed environment remains faster and more flexible.

“Approximate schemes are inaccurate”

CKKS produces approximate results by design, with controllable precision. For statistics that are reported to a few decimal places, the approximation error is usually negligible, but it should be validated against plaintext results on synthetic data before use.

What to do next

Treat homomorphic encryption as a precision tool. Start from the architecture: keep data at each custodian with a federated Trusted Research Environment, and use output controls for everything that leaves. Then look for the specific steps, most often aggregation across sites, where encrypting intermediate values adds protection at acceptable cost. Teams building a broader privacy toolkit should compare it with differential privacy, which protects outputs rather than inputs, and with secure multi-party computation, which solves a similar problem with different trade-offs.

Frequently asked questions

What is homomorphic encryption in simple terms?

It is encryption that allows calculations to be performed on encrypted data. The result stays encrypted, and when the key holder decrypts it, the answer matches what the same calculation would have produced on the original data.

What is the difference between partially and fully homomorphic encryption?

Partially homomorphic encryption supports one type of operation, such as addition in the Paillier scheme. Fully homomorphic encryption supports both addition and multiplication without limit, which in principle allows any computation, at much higher cost.

Is homomorphic encryption practical for genomic research?

For narrow, fixed tasks such as secure aggregation, cohort counts, and some association tests, it has been shown to work in published benchmarks. For exploratory analysis and large model training, it is currently too slow, and federated analysis is the more practical choice.

Does homomorphic encryption make health data anonymous?

No. Encrypted health data is usually still personal data under GDPR because it can be decrypted by the key holder. Encryption lowers risk but does not remove the need for a lawful basis and appropriate governance.

How does homomorphic encryption relate to federated learning?

Federated learning keeps data at each site and shares model updates. Homomorphic encryption can protect those updates during aggregation, so the coordinating server combines contributions without seeing any individual site’s values.

Is homomorphic encryption quantum-safe?

Modern schemes are built on lattice problems that are believed to resist quantum attacks, the same family of mathematics behind recently standardized post-quantum algorithms. That makes it a reasonable fit for data that must remain confidential for decades.