Event tracking for advanced therapy medicinal products
By using a multi-node system of hosted blockchain in personalized medicine, the problem of single points of failure in the treatment process is solved, reliable event data storage and transmission are achieved, treatment continuity and data privacy are ensured, and the reliability and security of the system are improved.
Patent Information
- Application Number
- CN202080022830.8
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Priority Date
- 2019-03-22
- Filing Date
- 2020-03-23
- Publication Date
- 2026-01-09
- Estimated Expiration
- 2040-03-23
AI Technical Summary
In personalized medicine, especially cell and gene therapy, the treatment process is complex and time-critical, and the treatment sequence is easily interrupted due to human error or computer system failure, resulting in high costs and serious consequences. Existing systems cannot reliably track materials and processes, and there is a risk of single point of failure.
A multi-node system using a hosted blockchain, including sequence manager nodes and hub nodes, ensures reliable storage and transmission of event data through sequence manager contracts and hub contracts on the blockchain, achieving redundancy and data privacy protection, and avoiding single points of failure.
It achieves reliable tracking and data security in personalized medical treatment, avoids treatment interruptions caused by single points of failure, ensures the continuity of treatment and data privacy, and improves the reliability and security of the system.
Smart Images

Figure CN113711314B_ABST
Abstract
Description
TECHNICAL FIELD
[0001] The present invention relates to tracking events associated with medical treatment types commonly referred to as personalized medicine or advanced therapy medicinal products (ATMPs), such as cell and gene therapy (CGT). BACKGROUND
[0002] Advanced therapy medicinal products, including personalized medicine, precision medicine and theranostics, involve tailoring medical treatments (e.g. decisions, practices, interventions and / or products) to individual patients based on their predicted response to the treatment and / or their predicted risk of disease. In personalized medicine, diagnostic tests are used to select the best treatment based on a patient’s genetic makeup and / or other molecular or cellular analysis. Cell and gene therapy (CGT) is a specified type of personalized medicine in which immune cells are collected from a patient and reprogrammed to target the same patient’s cancer. CGT has been found to be effective in treating B-cell acute lymphoblastic leukemia, diffuse large B-cell lymphoma and primary mediastinal B-cell lymphoma, even in cases of advanced tumors and where other treatment options have been unsuccessful.
[0003] Personalized medicine, and more specifically CGT, is very complex, with a single treatment often requiring multiple treatment stages to be performed in sequence, often by multiple parties. CGT in particular is also time critical, such that a particular stage of treatment must be performed within specified time limits, otherwise the entire treatment sequence must be restarted. Furthermore, certain materials involved in the treatment must be kept strictly within specified temperature ranges, otherwise the entire treatment sequence must be restarted. Restarting the sequence in some cases can not be practical due to the high cost of the treatment and limited resources, resulting in serious consequences for the patient. Furthermore, for patients diagnosed with advanced cancer, survival can depend on whether the first attempt at treatment is successful.
[0004] The above considerations require a reliable system for tracking materials and processes at each stage of the treatment for personalized medicine. The system must not have any single point of failure, such as a failure caused by a human error by one of the parties involved in the treatment sequence or by a failure of one or more computer systems operated by the parties. SUMMARY
[0005] According to a first aspect of the application, there is provided a system for tracking events associated with a treatment of personalised medicine, the system comprising a plurality of nodes hosting a blockchain. The plurality of nodes comprises: a plurality of sequence manager nodes, each sequence manager node being associated with a respective sequence manager contract on the blockchain; and a hub node, associated with a hub contract on the blockchain. A first sequence manager contract of the sequence manager contracts is arranged to: receive first event data indicative of a first event associated with the treatment, and store the first event data on the blockchain in association with a first event sequence. The hub contract is arranged to store, on the blockchain, an association between the first event sequence and one or more other event sequences associated with the treatment.
[0006] According to a second aspect of the application, there is provided a method of tracking events associated with a treatment of personalised medicine using a blockchain hosted by a plurality of sequence manager nodes and a hub node, each sequence manager node having an associated sequence manager contract on the blockchain, the hub node having an associated hub contract on the blockchain. The method comprises: receiving, by a first sequence manager contract of the sequence manager contracts, first event data indicative of a first event associated with the treatment; storing, by the first sequence manager contract, the first event data on the blockchain in association with a first event sequence; and storing, by the hub contract, on the blockchain, an association between the first event sequence and one or more other event sequences associated with the treatment.
[0007] Further features and advantages of the application will become apparent from the following description of preferred embodiments of the application given by way of example only with reference to the accompanying drawings. BRIEF DESCRIPTION OF DRAWINGS
[0008] Figure 1 A system for tracking events associated with a treatment of cell and gene therapy is schematically illustrated.
[0009] Figure 2 is a schematic block diagram illustrating Figure 1 an example of a sequence manager smart contract used in the system of
[0010] Figure 3 is a schematic block diagram illustrating Figure 2 an example of data stored in association with the sequence manager smart contract illustrated in
[0011] Figure 4 is a schematic block diagram illustrating Figure 2 an example of a data structure stored in association with the sequence manager smart contract illustrated in
[0012] Figure 5 is a schematic block diagram illustrating Figure 1an example of a hub smart contract used in the system shown in FIG. 1.
[0013] Figure 6 is a schematic block diagram illustrating an example of data stored in association with a hub smart contract.
[0014] Figure 7 is a schematic block diagram illustrating an example of data stored in association with a hub smart contract. Figure 1 is an example of a sequence manager node of the system shown in FIG. 1.
[0015] Figure 8 is a schematic block diagram illustrating an example of data stored in association with a hub smart contract. Figure 1 is an example of a hub node of the system shown in FIG. 1.
[0016] Figure 9 is a flow diagram representing a method for storing event data associated with a treatment of a cell and gene therapy on a permissioned blockchain.
[0017] Figure 10 is a flow diagram representing a method for storing event data on a permissioned blockchain, the event data indicating receipt of physical materials related to a treatment of a cell and gene therapy.
[0018] Figure 11 illustrates an example of events associated with a single CGT treatment. DETAILED DESCRIPTION
[0019] Figure 1 illustrates an example of a system 100 for tracking events associated with a treatment of a cell and gene therapy. The system includes a plurality of sequence manager nodes 102a-f, hereinafter referred to as sequence manager nodes 102, and a hub node 104. In this example, the sequence manager nodes 102 and the hub node 104 are physical servers. In other examples, the sequence manager nodes and / or the hub node can instead be implemented as network-hosted web servers. The sequence manager nodes 102 and the hub node 104 are operated by different entities involved in the administration of a treatment of a cell and gene therapy. The entity operating the hub node 104 is responsible for coordinating the tracking of the entire treatment, and the entities operating the sequence manager nodes 102 perform specified tasks related to the treatment. As the various stages of the treatment progress, the responsibility for the regulatory (e.g., of physical materials associated with the treatment) and tracking of the treatment passes between the entities, which will be described in more detail below with reference to specific examples.
[0020] The sequence manager node 102 and hub nodes 104 are connected to a network 106 and record data associated with events during a treatment as transactions on a permissioned blockchain 108. The permissioned blockchain 108 has an associated state store 109 that stores the current state of the blockchain 108, including any smart contracts uploaded to the blockchain 108 and smart contract storage associated with those smart contracts. In this example, the permissioned blockchain 108 is based on Quorum, which is an Ethereum-based blockchain and smart contract platform. Quorum includes functionality to support private smart contracts and private transactions. Data stored in association with private smart contracts and private transactions can only be accessed by designated nodes in the network. Quorum smart contracts are typically written in a high-level programming language, such as Solidity, Serpent, or a class-Lisp language (LLL), and specify rules governing transactions between accounts with addresses on the blockchain 108, as well as messages sent between smart contracts themselves. Quorum is Turing complete, meaning that in principle, Quorum smart contracts can be programmed to perform any reasonable computational task, provided that sufficient computing resources (e.g., memory) are available.
[0021] When a smart contract is uploaded to the permissioned blockchain 108, the smart contract code is compiled into virtual machine code that is executed by nodes that download and validate the blocks forming the permissioned blockchain 108. Execution of the virtual machine code typically results in a change to the state of the permissioned blockchain 108. Multiple nodes (in this example, the sequence manager node 102 and hub nodes 104) execute the same virtual machine code associated with a given block and use a consensus algorithm such as Raft or Istanbul BFT to ensure consensus between the downloaded blocks. Consensus between the nodes builds redundancy into the system, such that there is no single point of failure within the tracking system 100.
[0022] Using a permissioned blockchain enables higher transaction throughput compared to alternative options that use a public blockchain (e.g., the Ethereum main chain). The blockchain 108 only needs to store transactions and smart contracts related to the tracking system 100. In contrast, the Ethereum main chain includes transactions and smart contracts related to a large number of entities, many of which are completely unrelated. Furthermore, data stored on the permissioned blockchain 108 is only accessible by the nodes that host the permissioned blockchain 108 (i.e., the sequence manager node 102 and hub nodes 104), resulting in improved data security compared to data security for public blockchains. However, a public blockchain can be used instead of the permissioned blockchain 108.
[0023] The sequence manager nodes 102 and the hub node 104 each have an associated blockchain account with an address on the permissioned blockchain 108. The address of a blockchain account is derived from a cryptographic public key associated with the account, which in turn is derived from a cryptographic private key associated with the account. Transactions sent from a given account are signed by the associated private key, allowing the recipient of the transaction (which can typically be another account or a smart contract) to verify that the transaction was in fact sent by the account.
[0024] Each sequence manager node 102x(where x is one of a-f) is associated with a respective sequence manager contract 110x on the permissioned blockchain 108. The sequence manager contracts 110x are instances of the same smart contract, collectively referred to as the sequence manager contract 110. Each sequence manager contract 110x stores a record of the blockchain address of the associated sequence manager node 102x and can only accept transactions from that sequence manager node 102x and not another sequence manager node 102y(where y is different from x) or the hub node 104. The hub node 104 is associated with a hub contract 112 on the permissioned blockchain 108. The hub contract 112 stores a record of the blockchain address associated with the hub node 104 and can only accept transactions from the hub node 104 and not from a sequence manager node 102.
[0025] Each sequence manager contract 110x has an address on the permissioned blockchain 108 and includes smart contract code and associated storage for storing event data on the permissioned blockchain 108. The sequence manager contract 110x is arranged to receive event data from the associated sequence manager node 102x, where the event data is indicative of events associated with a cell and gene therapy treatment and performed by an entity operating the associated sequence manager node 102x. By default, the sequence manager contract 110x is private to the sequence manager node 102x and the hub node 104, such that data stored by the sequence manager contract 110x on the permissioned blockchain 108 is encrypted and cannot be viewed by other sequence manager nodes 102y. In some cases, the sequence manager contract 110x can be configured to allow one or more additional sequence manager nodes 102y to view data stored by the sequence manager contract 110x. Privacy of data relating to a cell and gene therapy treatment is a fundamental requirement of the system 100. By ensuring that each party associated with a treatment can only interact with the associated sequence manager contract, data privacy between parties is ensured.
[0026] The content of the event data indicative of a given event depends on the event type of the event. The sequence manager contract 110x is arranged to perform a plurality of processing operations in response to receiving event data from the associated sequence manager node 102x, such that storage of the event data on the permissioned blockchain 108 depends on the outcome of these processing operations. The specified processing operations for storing a given event depend on the event type, as will be described in more detail below. The sequence manager contract 110x stores event data indicative of a given event in association with an event sequence. The event sequence comprises event data indicative of events relating to a single treatment and is received from the same sequence manager node 102x. In the present example, the event data in a given event sequence is indicative of events performed by an entity operating the corresponding sequence manager node 102x.
[0027] The hub contract 112 has an address on the permissioned blockchain 108 and comprises smart contract code and associated storage for storing associations between event sequences relating to a single treatment on the permissioned blockchain 108. More precisely, the hub contract 112 is arranged to store a plurality of segment groups, each segment group relating to a respective treatment. Each segment group comprises data indicative of one or more event sequences stored by one or more respective sequence manager contracts 110. In this way, the hub contract 112 links together events relating to a single treatment but performed by multiple entities.
[0028] As Figure 2The sequence manager contract 110x is shown as having an associated sequence manager contract storage 114. In this example, the sequence manager contract storage 114 is on-chain, meaning that it forms part of the global state of the permissioned blockchain 104 and is stored by each node that downloads and validates the associated blocks in the permissioned blockchain 104. In other examples, the sequence manager storage can be off-chain, meaning that it is stored independently of the permissioned blockchain 108. In either case, the sequence manager contract storage 114 is arranged such that validation of blocks of the permissioned blockchain 108 ensures the immutability of the data stored in the sequence manager contract storage 114. The sequence manager contract 110x can read data from and can write data to the sequence manager contract storage 114. The sequence manager contract 110x stores a record of the blockchain address 116 (sequence manager address 116) of the account associated with the corresponding sequence manager node 102x. The sequence manager contract 110x only accepts transactions from the specified address 116, so only the entity operating that sequence manager node 102x is able to upload event data to the blockchain 108 via the sequence manager contract 110x. The sequence manager contract 110x also includes the blockchain address 118 (hub contract address 118) of the hub contract 112. As will be explained in more detail below, the sequence manager contract 110x exchanges messages with the hub contract 112 for various reasons, including linking event sequences in segment groups.
[0029] The sequence manager contract 110x includes unlinked event validation code 120. This code is executed in response to the corresponding sequence manager node 102x sending event data to the sequence manager contract 110x via a transaction. The unlinked event validation code 120 validates the received event data without reference to any other event in an event sequence. In this example, the unlinked event validation includes determining that predetermined mandatory data fields are completed within the received event data. For any type of event, the predetermined mandatory data fields include a treatment identifier that is unique to the individual treatment and an event type. Further mandatory data fields depend on the event type and will be described in more detail below with reference to specified examples. If the event data fails to satisfy the unlinked event validation, the sequence manager contract 110x will not store the event data on the permissioned blockchain 108.
[0030] The sequence manager contract 110x also includes event linking code 122. When event data is successfully confirmed using the unlinked event confirmation code 120, the sequence manager contract 110x executes event linking code 122. If the event corresponds to a regulatory reception by a party associated with the operation's sequence manager node 102x (e.g., in the case of receiving physical materials associated with treatment), event linking code 122 generates a new sequence in the sequence manager contract storage 114. The new sequence is assigned a new, unique sequence identifier. For any event not corresponding to a regulatory reception, event linking code 122 searches the sequence manager contract storage 114 for an event sequence stored on the permissioned blockchain 108 with the same treatment identifier. If an event sequence with the same treatment identifier is located, event linking code 122 adds the event data to the located event sequence. If event linking fails, for example because the expected event sequence is not located, the sequence manager contract 110x will not store the event data on the permissioned blockchain 108.
[0031] The sequence manager contract 110x includes aggregation code 124. Aggregation code 124 is executed when the event type indicates debugging, receiving, or packaging of physical materials. When the event type indicates debugging or receiving physical materials, aggregation code 124 stores a new aggregation identifier associated with the new event sequence generated by event linking code 122. When the event type indicates packaging of physical materials, aggregation code 124 retrieves the aggregation identifier from the existing event sequence to which the event is added and stores aggregation data indicating that the physical material is packaged within a container. Both the physical material and the container have identifiers, and the aggregation data stores these identifiers hierarchically to indicate that the physical material is packaged within a container. Later, the container may be packaged within another container, in which case aggregation code 124 adds the identifier of the other container to the hierarchical aggregation data. Alternatively, the physical material may be unpacked from the container, in which case aggregation code 124 removes the association between the physical material's identifier and the container. The sequence manager contract 110x uses the aggregation data to check the consistency between events added to the event sequence, which will be described in more detail below.
[0032] like Figure 3 As shown, the sequence manager contract storage 114 is arranged to store multiple event sequences. Each event sequence is assigned a sequence identifier and associated with a single treatment having the aforementioned treatment identifier. The event sequence includes event data indicating events associated with that treatment and is executed by the operator of the associated sequence manager node 102. Each event sequence also includes hierarchical aggregated data indicating any packaging of physical materials associated with the treatment.
[0033] Figure 4An example of a data structure indicating an event is shown. The data structure includes a treatment identifier indicating which treatment the event relates to, and a patient identifier that is unique to the patient receiving the treatment. The treatment identifier is used by the sequence manager contract 110x to link the event to the event sequence, and is further used by the hub contract 112 to link event sequences together to form episode groups. The patient identifier is used in place of a name or any other personal information to ensure that the data stored on the permissioned blockchain 108 is anonymous, and that the parties performing various actions relating to the treatment cannot identify the patient to whom they are treating. As will be described in more detail below, only the party involved in the treatment, in this example the oncologist, has a record of the association between the patient identifier and the patient’s identity. In this way, the patient’s privacy is protected.
[0034] The event data includes a timestamp indicating the time at which the event occurred, and location data (e.g. longitude and latitude coordinates) indicating the location at which the event occurred. In the present example, the timestamp and location data are determined automatically when the event occurs, which will be described in more detail with reference to the specified types of events. The event data also includes the event type and additional event data dependent on the event type. As described above, if the event data includes mandatory event data dependent on the event type, then the event data will only be successfully stored on the permissioned blockchain 108.
[0035] Returning to Figure 2 The sequence manager contract 110x includes linked event validation code 126. The sequence manager contract 110x executes the linked event validation code 126 after the event linking code 122 (and, if the aggregation code 124 is executed, the sequence manager contract 110x executes after the aggregation code 124). In the present example, the linked event validation code 126 ensures that the event data is consistent with the events previously uploaded to the event sequence (i.e. in the correct order). If the event data fails to satisfy the linked event validation, then the sequence manager contract 110x will not store the event data on the permissioned blockchain 108. If the event data indicates the receipt of a regulatory, then the event validation code 126 causes a message to be exchanged with the hub contract 112 to determine whether the sequence manager contract 110x has been authorised to upload the event data, as will be described in more detail below.
[0036] The sequence manager contract 110x includes event condition code 128. The event condition code 128 is dependent on the event type of the event data uploaded, and includes the conditions that must be satisfied for the event to be successfully added to the event sequence. Examples of conditions associated with specified events will be described in more detail below.
[0037] The sequence manager contract 110x includes an alert code 130. The alert code 130 is executed if any of the conditions specified in the event condition code 128 are not met. The alert code 130 causes the sequence manager contract 110x to issue an alert event on the permissioned blockchain 108 and further sends a message to the hub contract 112 causing the hub contract 112 to issue an alert event on the permissioned blockchain 108. As will be described in more detail below, the sequence manager node 102x associated with the sequence manager contract 110x is arranged to listen for alert events issued by the sequence manager contract 110x so that the user of the sequence manager node 102x can be immediately alerted if the conditions specified by the event condition code 128 are not met. Similarly, the hub node 104 is arranged to listen for alert events issued by the hub contract 112 so that the user of the hub node 104 can be immediately alerted if the conditions specified by the event condition code 128 are not met.
[0038] As shown in Figure 5 The hub contract 112 has an associated hub contract store 132 on the permissioned blockchain 108. In the present example, the hub contract store 132 is on-chain. In other examples, the hub contract store can be off-chain. In either case, the hub contract store 132 is arranged so that verification of blocks of the permissioned blockchain 108 confirms the invariance of data stored in the hub contract store 132. The hub contract 112 can read data from the hub contract store 132 and can write data to the hub contract store 132. The hub contract 114 stores a record of the blockchain address 134 of the sequence manager contract 110 (the sequence manager address 134). The hub contract 114 exchanges messages with the sequence manager contract 110 to grant or deny permission to store certain event data on the permissioned blockchain 108 and to link event sequences in segment groups.
[0039] The hub contract 112 includes permission check code 136 which executes in response to the hub contract 112 receiving a message from the sequence manager contract 110x indicating that the operator of the associated sequence manager node 102x received supervision. The message constitutes a request for permission to store corresponding event data on the permissioned blockchain 108. The message includes the sequence identifier generated by the sequence manager contract 110x as described above, and a treatment identifier for the treatment. The permission check code 136 is arranged to determine whether the sequence manager contract 110x is permitted to store event data on the permissioned blockchain 108. In the present example, the permission check code determines whether the sequence manager contract 110x is permitted to store event data by querying a further sequence manager contract 110y for event data indicating that the sequence manager contract 110x is permitted to store event data (and correspondingly, that the operator of the sequence manager node 102y intends to pass supervision to the operator of the sequence manager node 102x).
[0040] The hub contract 112 includes segment linking code 138 which executes in response to the permission check code 136 determining that the sequence manager contract 110x is permitted to store event data on the permissioned blockchain 108. The segment linking code 138 searches the hub contract store 114 for a segment group having the same treatment identifier as the event data to be stored. If a segment group having the same treatment identifier is located, the segment linking code 138 adds the sequence to the located segment group.
[0041] As shown in Figure 6 , the hub contract store 132 is arranged to hold a plurality of segment groups. Each segment group is assigned a segment group identifier, and is associated with a single treatment having a treatment identifier as described above. The segment group includes data indicating sequences relating to the treatment, including a sequence identifier for each sequence, and data indicating the sequence manager contract 110x responsible for the sequence (e.g. the address of the sequence manager contract 110x on the permissioned blockchain 108).
[0042] Returning to Figure 5 , the hub contract 112 includes sequence query code 140. The sequence query code 140 executes in response to the hub contract 112 receiving a query from the hub node 104 regarding event data within a sequence in a given segment group. The sequence query code 140 also executes in response to the hub contract 112 receiving a message from one of the sequence manager contracts 110 requesting permission regarding supervision receipt associated with a treatment. The sequence query code 140 causes the hub contract 112 to send a message to the sequence manager contract 110x requesting event data stored by the sequence manager contract 110x.
[0043] Hub contract 112 includes alarm code 142. Alarm code 142 is executed in response to hub contract 112 receiving an alarm message from a sequence manager contract 110 indicating that one or more event conditions are not met. Alarm code 142 causes hub contract 112 to issue an alarm event on permissioned blockchain 108. Hub node 104 is configured to listen for alarm events issued by hub contract 112, so that users of hub node 104 can be immediately alerted when one or more event conditions are not met.
[0044] like Figure 7 As shown, the sequence manager node 102x includes a power supply 146 and a system bus 148. The system bus 148 is connected to: a CPU 150; an input / output device 152; a communication module 154; and memory 156. The input / output device 152 allows users to interact with the sequence manager node 102x and includes, for example, a keyboard, a monitor, and a mouse / touchpad. The memory 156 includes non-volatile memory and volatile memory, and stores: user interface code 158; event receiving code 160; blockchain application programming interface (API) code 162; and encryption keys 164.
[0045] When new event data is uploaded to the sequence manager node 102x, event reception code 156 is executed. For some events, the event data is manually entered by the user via the user interface of the sequence manager node 102x. For other events, event data is automatically generated and / or received via the communication module 154. One example of uploaded automatically generated event data is where the event data corresponds to a temperature measurement of a physical material associated with treatment by an automated temperature sensor, in which case the automated temperature sensor is configured to send the measured temperature along with other mandatory data (e.g., the time and location of the temperature measurement) to the sequence manager node. Another example of uploaded automatically generated event data is scanning the physical material using a scanning device (e.g., a quick response (QR) code scanning device or a near field communication (NFC) device) to determine an identifier associated with the physical material.
[0046] Blockchain API code 162 allows sequence manager node 102x to interact with permissioned blockchain 108. Blockchain API code 162 is configured to send transactions to sequence manager contract 110x and query data from sequence manager contract 110x upon user requests. In this example, blockchain API code 162 is also configured to listen for alert events issued by sequence manager contract 110x, where alert events can indicate that a given event submitted to sequence manager contract 110x has not yet met the conditions specified in event condition code 128.
[0047] The cryptographic key 164 includes a public key and a private key associated with an account of the sequence manager node 102x on the permissioned blockchain 108. The private key is used by the sequence manager node 102x to sign transactions, such as uploading event data to the sequence manager contract 1 lOx on the permissioned blockchain 108. The cryptographic key 164 also includes a public key and a private key used to implement privacy for the sequence manager contract 1 lOx (as previously mentioned, the sequence manager contract 1 lOx is private to the sequence manager node 102x and the hub node 108). In alternative implementations, the private key and public key associated with the account can also be used to implement privacy for the contract.
[0048] As shown, the hub node 104 includes a power supply 166 and a system bus 168. The system bus 168 is connected to: a CPU 170; input / output devices 172; and a memory 174. The input / output devices 172 allow a user to interact with the hub node 104 and include, for example, a keyboard, a monitor, and a mouse / trackpad. The memory 174 holds: user interface code 176; blockchain API code 178; and a cryptographic key 180. Figure 8
[0049] The blockchain API code 178 allows the hub node 104 to interact with the permissioned blockchain 108. The blockchain API code 178 is arranged to query the hub contract 112 for data according to a user’s request. In this example, the blockchain API code 178 is also arranged to listen for alert events emitted by the hub contract 112.
[0050] The cryptographic key 180 includes a public key and a private key associated with an account of the hub node 102x on the permissioned blockchain 108. The cryptographic key 164 also includes a public key and a private key used to implement privacy for the hub contract 112 and the sequence manager contract 110 (the hub contract 112 is private to the hub node 104, and the hub node 104 also has access to data stored by the sequence manager contract 110).
[0051] Figure 9 An example is shown in which the sequence manager node 102x receives event data indicating an event associated with a treatment of a cell and gene therapy. In this example, the event is not associated with receiving regulation from a different entity. At S902, the sequence manager node 102x receives the event data as a result of a user inputting the event data via a user interface of the sequence manager node 102x, or via a signal from a sensor device or a scanning device. At S904, the sequence manager node 102x sends the event data to the sequence manager contract 1 lOx via the blockchain API.
[0052] At S906, the sequence manager contract 110x receives the event data and performs unlinked event validation at S908. Unlinked event validation includes ensuring that the event data includes predetermined mandatory data. The predetermined mandatory data includes a patient identifier, a treatment identifier, and an event type. Other mandatory data depends on the event type. If the unlinked event validation is not successful, the sequence manager contract 110x does not store the event data on the permissioned blockchain 108.
[0053] At S910, if the unlinked event validation is successful, the sequence manager contract 110x links the event data. In this example, the event type does not indicate a receipt of a regulation, so to link the event data, the sequence manager contract 110x searches the associated sequence manager contract memory 114 for a sequence identifier stored in association with the same treatment identifier as the treatment identifier of the event data to be linked. If no such sequence identifier is located, the event data will not be stored on the permissioned blockchain 108. If a sequence identifier is located, the sequence manager contract 110x adds the event data to the located event sequence.
[0054] At S912, if the event linking is successful, the sequence manager contract 110x performs linked event validation. Linked event validation includes ensuring that the event type of the event data to be uploaded is consistent with the events previously uploaded to the event sequence. If the linked event validation is successful, the sequence manager contract 110x does not store the event data on the permissioned blockchain 108.
[0055] At S914, if the linked event validation is successful, the sequence manager contract 110x determines whether the event data satisfies event conditions depending on the event type of the event data to be stored. If none of the event conditions are satisfied, the sequence manager contract 110x issues an alert event on the permissioned blockchain 108 and sends an alert message to the hub contract 104. In this way, the operator of the sequence manager node 102x and the operator of the hub node 104 are immediately notified of the problem. At S916, the sequence manager contract 110a stores the event data.
[0056] Figure 10An example is shown in which event confirmation is performed in which a link is made to event data received from different entities related to the transfer of a regulation. At S1002, the first sequence manager 110x sends a message to the hub contract 112 requesting permission from the hub contract 112 to store event data. The message includes a treatment identifier related to the treatment of which the event data is related. At S1004, upon receiving the message, the hub contract 112 determines the address of the second sequence manager contract 110y on the permission blockchain 108. In this example, the hub contract 112 determines the address of the second sequence manager contract 110y by searching the hub contract storage 132 for a segment group associated with the same treatment identifier as the event data to be stored and determining the sequence manager contract 110x responsible for the most recent sequence in the segment group. In other examples, the hub contract can determine the address of the second sequence manager contract 110y from the address of the first sequence manager contract 110x.
[0057] After determining the address of the second sequence manager contract 110y, at S1006, the hub contract 112 queries the second sequence manager contract 110y for event data indicating the transfer of a regulation associated with the treatment and indicating that the operator of the first sequence manager contract 110x is the intended recipient of the regulation. At S1008, the second sequence manager contract 110y sends a response to the query from the hub contract 112 indicating whether the event data stored by the second sequence manager contract 110y indicates the transfer of a regulation associated with the treatment and whether the operator of the first sequence manager node 102x is the intended recipient of the regulation (e.g., by specifying an identifier associated with the operator of the first sequence manager node 102x, or the blockchain address of the first sequence manager contract 110x in the intended recipient field).
[0058] At S1010, the hub contract 112 determines whether to allow the first sequence manager contract 110x to store event data indicating the receipt of a regulation. The first sequence manager contract 110x is allowed to store the event data if the second sequence manager contract 110y stores event data indicating the first sequence manager contract 110x as the intended recipient of the transfer of the regulation. In other examples, the second sequence manager contract can determine whether to allow the first sequence manager contract to store the event data, in which case the second sequence manager contract sends the result of the determination to the hub contract 112. If the hub contract 112 determines not to allow the first sequence manager contract 110x to store the event data, the hub contract issues an alert event on the permission blockchain 108, thereby alerting the entity supervising the treatment that an error can have occurred.
[0059] At S1012, the hub contract 112 sends a message to the first sequence manager contract 110x indicating the result of the determination. If the message indicates that the first sequence manager contract 110x is not permitted to store event data, the first sequence manager contract 110x does not store event data on the permissioned blockchain 108. If the message indicates that the first sequence manager contract 110x is permitted to store event data, at S1014, the first sequence manager contract 110x sends sequence data to the hub contract 112. In the present example, the sequence data includes a sequence identifier associated with the sequence in which the event data will be stored. As described above, the first sequence manager contract generates the sequence identifier generated during the event linking process. At S1016, the hub contract 112 adds the sequence in which the event data will be stored to the segment group corresponding to the treatment.
[0060] Figure 11 An example of a sequence of events associated with a CGT treatment is shown. The events are uploaded to the sequence manager nodes 102a-f and relate to tasks performed by entities operating the sequence manager nodes. Figure 11 The dashed arrows in the figure represent the transfer of oversight between entities. The event details are as follows:
[0061] • Treatment registration - performed at the tumour surgery
[0062] S1101 : Selection and request for treatment
[0063] Includes generation of a unique treatment identifier and patient identifier.
[0064] S1102: Patient enrolment
[0065] Mandatory event data includes a hash of the completed patient enrolment form.
[0066] S1103: Appointment scheduling
[0067] Mandatory data includes the scheduled date and clinic identifier of the treatment centre.
[0068] Includes transfer of oversight to the treatment centre.
[0069] • Tissue collection - performed at the treatment centre
[0070] S1104: Management form certification
[0071] Mandatory event data includes a hash of the completed management form.
[0072] Includes checking of permissions to accept oversight.
[0073] S1105: Selection of kit commissioning
[0074] Mandatory data includes selection of kit identifier.
[0075] Including generating new aggregate identifier.
[0076] S1106: Kit check collection
[0077] Event conditions include check pass / fail.
[0078] S1107: Cell tissue collection
[0079] If kit check collection fails, reject event data.
[0080] S1108: Cryopreservation
[0081] Forced data includes start temperature and end temperature.
[0082] Event conditions include start temperature and end temperature within respective predetermined ranges, and time since previous step within predetermined range.
[0083] Including time offset check.
[0084] S1109: Aggregation (bag - cryoport)
[0085] Including storing aggregate data, temperature offset check, time offset check.
[0086] S1110 Aggregation (cryoport - shipping container)
[0087] Including storing aggregate data, temperature offset check, time offset check, passing custody to shipping company.
[0088] • Shipping - performed by shipping company
[0089] S1111: Pick-up
[0090] Including check for receipt of custody permission, temperature offset check, time offset check.
[0091] S1112: (Ongoing) Cold chain status check
[0092] Temperature measured by automated temperature sensor at predetermined times (e.g., periodically).
[0093] Including temperature offset check, time offset check.
[0094] S1113: Shipping and customs clearance
[0095] Including temperature offset check, time offset check.
[0096] Event conditions include customs clearance pass / fail.
[0097] S1114: Delivery
[0098] Including temperature excursion check, time excursion check, passing regulatory to pharmaceutical company.
[0099] • Organizational handling (CGT activation) - performed by pharmaceutical company
[0100] S1115: Cell / tissue product receipt
[0101] Including check for receipt of regulatory permissions, temperature excursion check, time excursion check.
[0102] S1116: Unpacking
[0103] Including temperature excursion check, time excursion check, aggregate data check.
[0104] S1117: Freeze-thaw
[0105] Including temperature excursion check, time excursion check.
[0106] S1118: Cell / tissue product handling
[0107] Including temperature excursion check, time excursion check.
[0108] S1119: Cell / tissue product release
[0109] Including temperature excursion check, time excursion check.
[0110] S1120: Storage
[0111] Including temperature excursion check, time excursion check.
[0112] S1121: Quality assurance
[0113] Including temperature excursion check, time excursion check.
[0114] Event conditions include pass / fail of quality tests.
[0115] S1122: Cryopreservation.
[0116] If collection kit check fails, reject event data.
[0117] Mandatory data includes start temperature and end temperature.
[0118] Event conditions include that start temperature and end temperature are within respective predetermined ranges, and that time since previous step is within predetermined range.
[0119] S1123: Aggregate (bag)
[0120] Including temperature excursion check, time excursion check.
[0121] S1124: Aggregation (Bag - Freezer Port)
[0122] Including temperature excursion check, time excursion check.
[0123] S1125: Aggregation (Freezer Port - Container)
[0124] Including temperature excursion check, time excursion check, passing of regulatory to logistics company.
[0125] • Logistics - performed by logistics company
[0126] S1126: Pick up
[0127] Including check for receipt of regulatory approval, temperature excursion check, time excursion check.
[0128] S1127: (Ongoing) Cold Chain Status Check
[0129] Temperature measured by automated temperature sensor at predetermined times (e.g. periodically).
[0130] Including temperature excursion check, time excursion check.
[0131] S1128: Transport and Customs Clearance
[0132] Including temperature excursion check, time excursion check.
[0133] Event conditions include pass / fail of customs clearance.
[0134] S1129: Delivery
[0135] Including temperature excursion check, time excursion check, passing of regulatory to treatment center.
[0136] • Management of treatment - performed at treatment center
[0137] S1130: Cell / Tissue Product Reception
[0138] Including check for receipt of regulatory approval, temperature excursion check, time excursion check.
[0139] S1131: Unpacking
[0140] Including temperature excursion check, time excursion check, aggregation data check.
[0141] S1132: Cryo-Thawing
[0142] Including temperature excursion check, time excursion check.
[0143] S1133: Administration to Patient
[0144] S1134: Patient follow-up
[0145] This includes passing the custody to the treatment follow-up center.
[0146] • Treatment follow-up - performed at the treatment follow-up center
[0147] S1135: Inspection
[0148] This includes receiving an inspection with custody permission
[0149] S1136: Pharmaceutical company update
[0150] S1137: Destruction of backup samples
[0151] The time offset check involves determining the difference between a timestamp associated with an event and a timestamp associated with an earlier event. Depending on the event type, the earlier event can be the most recent event or a predetermined earlier event. In some cases, the earlier event and the later event are stored by the same sequence manager contract 110x. In other cases, the earlier event is stored by a different sequence manager contract 110y. If the earlier event is stored by a different sequence manager contract 110y, the sequence manager contract queries the hub contract 112, which queries the earlier timestamp from the sequence manager contract 110y. The sequence manager contract 110x receiving the later event data is arranged to issue an alert event on the permission blockchain 108 and send an alert message to the hub contract when the difference between the timestamps exceeds a threshold duration.
[0152] The temperature offset check involves a temperature sensor (e.g. an automated temperature sensor) measuring the temperature of a physical material (e.g. a cell / tissue product) and sending the measured temperature as part of the event data to be uploaded to the associated sequence manager node 102x. The sequence manager contract 110x is arranged to issue an alert event on the permission blockchain 108 and send an alert message to the hub contract 112 when the measured temperature lies outside a predetermined range.
[0153] In the appointment arrangement of step S1103, the sequence manager node associated with a tumor surgery, etc. can use an API to access the arrangement information from the pharmaceutical company. In this way, the tumor surgery can reserve time for various operations involved in the treatment process at the pharmaceutical company.
[0154] As mentioned above, the physical material can be associated with a unique QR code that is scanned each time custody is handed over for a change in custody. This QR code will store a unique patient identifier.
[0155] During tissue collection, a unique Sample QR code is generated and a printable label including the unique Sample QR code is generated and a printed copy of the Sample QR code is attached to the packaging associated with the collected tissue. For example, the printed Sample QR code can be attached to the tube holding the collected tissue or to the outside of the delivery box. If a tissue sample needs to be replaced, a new Sample QR code is issued. To highlight that this is a different sample, a visible indication can be included on the printed QR label. For example, the number“02” can be added.
[0156] During tissue processing, a Treatment QR code is generated and a printed copy of the Treatment QR code is attached to the packaging associated with the treatment product. Again, the printed Treatment QR code can be attached to the tube holding the treatment product or to the outside of the delivery box.
[0157] Finally, to assist in tracking the chain of custody, a unique Person QR code is associated with each person in the chain of custody, such as the nurse for the tumor surgery, the courier for the courier company, and the laboratory technician working at the pharmaceutical company. These QR codes are printed and scanned during a change of custody. For example, the courier taking the tissue sample scans the Sample QR code for the sample and the Person QR code for the nurse receiving the sample, and the nurse scans the Sample QR code for the sample and the Person QR code for the courier. Similar operations occur each time there is a change of custody for a tissue sample and a change of custody for a treatment product.
[0158] In view of the three different types of QR codes, in an example, each type of QR code is printed in a given color to avoid confusion. For example, the Sample QR code can be printed in blue, the Treatment QR code can be printed in green, and the Person QR code can be printed in black.
[0159] The example embodiments can utilize a mobile application on a smartphone, tablet, or the like to assist in collating event data. For example, the mobile application can control the scanning of QR codes during a change of custody. It will be appreciated that the mobile application can be tailored to the role of the stakeholder, such that, for example, the mobile application for a courier only deals with events associated with the courier.
[0160] While the use of QR codes is convenient, it will be appreciated that other marking technologies can be used, such as RFID codes, NFC chips, or Internet of Things (IoT) devices.
[0161] The above examples should be understood as illustrative of the application. Further embodiments of the application are envisaged. For example, the system according to the application can be used to track events relating to different types of therapy, such as homologous or allogeneic cell and gene therapy, stem cell therapy or another form of treatment through personalised medicine. Similarly, in other embodiments, the application can be applied to blood and organ transplants. In some examples, one of the entities involved in carrying out certain stages of the therapy can also be responsible for overseeing the therapy (e.g. the entity registering the patient for the therapy). In this case, the hub node can be combined with the sequence manager node, and / or the hub contract can be combined with the sequence manager contract. In some examples, the data stored on the permissioned blockchain can be anchored to a public blockchain, such as the Ethereum main chain, for example, to improve security.
[0162] Although the illustrated embodiments use Quorum, it will be appreciated that the application is not blockchain-specific and can use other blockchain platforms, such as R3 Cardano, IBM Hyperledger or Oracle blockchain platforms. While there are advantages to using a permissioned blockchain as described above, the application can be implemented on a public blockchain.
[0163] It will be appreciated that any feature described in relation to any one embodiment can be used alone, or in combination with other features described, and can also be used in combination with one or more features of any other of the embodiments, or any combination of any other of the embodiments. Furthermore, equivalents and modifications not described above can also be employed without departing from the scope of the application, which is defined in the claims attached hereto.
Claims
1. A system for tracking events associated with treatment in personalized medicine, the system comprising: An automatic temperature sensor is arranged to measure the temperature of the physical material associated with the treatment; as well as Multiple nodes hosting the blockchain, said multiple nodes including: Multiple sequence manager nodes, each associated with a corresponding sequence manager contract on the blockchain; and Hub nodes are associated with hub contracts on the blockchain. in: The automatic temperature sensor is arranged to send the measured temperature of the physical material to a first sequence manager node among the plurality of sequence manager nodes; The first sequence manager node is configured to send first event data to a first sequence manager contract associated with the first sequence manager node, the first event data indicating a first event associated with the treatment and indicating the measured temperature of the physical material; The first sequence manager contract is configured as follows: Receive the first event data; Determine whether the measured temperature is within a predetermined range; In the event that the measured temperature is determined to be outside the predetermined range, an alarm message is sent to the hub contract; and The first event data is stored on the blockchain in association with the first event sequence, and The hub contract is configured as follows: The association between the first event sequence and one or more other event sequences associated with the treatment is stored on the blockchain; and In response to receiving the alarm message from the first sequence manager contract, an alarm event is issued on the blockchain.
2. The system according to claim 1, wherein: The first event data indicates the receipt of monitoring associated with the treatment; The first sequence manager contract is configured to send first sequence data to the hub contract, the first sequence data identifying the first event sequence; and The association between the first event sequence and the one or more other event sequences is stored in response to the hub contract receiving the first sequence data.
3. The system according to claim 2, wherein: The first sequence manager contract is configured to request permission from the hub contract to store the first event data on the blockchain; and The hub contract is configured to, in response to receiving the permission request, determine to allow the first sequence manager contract to store the first event data on the blockchain.
4. The system of claim 3, wherein, Determining whether to allow the first sequence manager contract to store the first event data includes querying a second sequence manager contract of the sequence manager contract that indicates a second event data transmission associated with the receipt of the regulation, the second event data indicating that the first sequence manager contract is allowed to store the first event data.
5. The system according to claim 1, wherein: The first event data indicates that the physical materials associated with the treatment are packaged into a container; and The first sequence manager contract is arranged to store aggregated data on the blockchain in association with the first event sequence, the aggregated data comprising an identifier of the physical material and an identifier of the container.
6. The system of any preceding claim, wherein: The first event data comprises an identifier of a physical material associated with the treatment; and Storing the first event data on the blockchain is contingent on the first sequence manager contract determining that the identifier is consistent with aggregated data stored in association with the first event sequence.
7. The system of claim 1, wherein, Storing the first event data on the blockchain is contingent on the first sequence manager contract determining that a predetermined mandatory data field is completed within the first event data, the predetermined mandatory data field being contingent on an event type of the first event.
8. The system of claim 1, wherein, Storing the first event data on the blockchain comprises determining, by the first sequence manager contract, that a difference between a timestamp associated with the first event and a timestamp associated with an earlier event associated with the treatment does not exceed a threshold duration.
9. The system of claim 8, wherein: The first event data comprises a timestamp associated with the first event; and The first sequence manager contract is arranged to send an alert message to the hub contract when a difference between the timestamp associated with the first event and a timestamp associated with an earlier event associated with the treatment exceeds a threshold duration.
10. The system of claim 1, wherein, Storing the first event data on the blockchain comprises encrypting the first event data and storing the encrypted first event data on the blockchain.
11. The system of claim 1, wherein, The blockchain is a permissioned blockchain.
12. The system of claim 1, wherein, The treatment of the personalized medicine is a treatment by cell and gene therapy.
13. A method of tracking events associated with a treatment of an advanced pharmaceutical product therapy using a blockchain hosted by a plurality of sequence manager nodes and a hub node, each of the sequence manager nodes having an associated sequence manager contract on the blockchain, the hub node having an associated hub contract on the blockchain, the method comprising: measuring a temperature of a physical material associated with the treatment using an automated temperature sensor; sending, by the automated temperature sensor, the measured temperature of the physical material to a first sequence manager node of the plurality of sequence manager nodes; sending, by the first sequence manager node, first event data to a first sequence manager contract associated with the first sequence manager node, the first event data indicating a first event associated with the treatment and indicating the measured temperature of the physical material; determining, by the first sequence manager contract, whether the measured temperature is within a predetermined range; in an event of determining that the measured temperature is outside the predetermined range, sending an alert message from the first sequence manager contract to the hub contract; storing, by the first sequence manager contract, the first event data on the blockchain in association with a first event sequence; and issuing, by the hub contract, an alert event on the blockchain responsive to receiving the alert message from the first sequence manager contract; and storing, by the hub contract, an association between the first event sequence and one or more other event sequences associated with the treatment on the blockchain.
Citation Information
Patent Citations
A medical gauze monitoring method and device
CN109242067A