I find your announcement a little bit contradicting each other, I thought the data stored will be private, as in only allowed to be accessed by the record owner's permission, yet insurance companies and public authority could access them?
A user has full data ownership of his records. Others cannot access the data by any means except for his/her permission.
I quote,
"Medical clinics and universities can purchase annonymized data for research"
If it require the owner's permission, it's not really annonymized as there are way to track said data, and if it didn't require owner's permission, thus the system deployed their customer's data without their consensus, it's a breach of privacy. Further, what will the customer get from this data purchase? Will they get certain percentage? If so, how to gain/give the proof of payment without revealing customer's identity? Will they didn't get anything other than a thank you letters for their constitution? Thus, probably securing their privacy but their data got monetized without beneficial feedback.