Data Consent Storage and Management System and Method
Through the data consent agent system to manage consent and data flow between user devices and third-party data consumers, the problem of opacity and underutilization of data during user data sharing is solved, and users control over data sharing and efficient use of data is achieved.
Patent Information
- Application Number
- CN202080032455.5
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Priority Date
- 2019-04-30
- Filing Date
- 2020-04-28
- Publication Date
- 2025-07-18
- Estimated Expiration
- 2040-04-28
AI Technical Summary
In the prior art, the user data sharing process lacks effective consent management, which makes it difficult for users to understand and control the data sharing terms, and the data is not fully monetized, making it difficult for third-party data consumers to obtain valuable user data efficiently.
A data consent proxy system is designed to generate user data that users can agree to share, including consent proxy servers and databases, manage the consent and data flow of user devices, provide API interfaces for third parties to obtain data, and support data warehouses and market-oriented processing.
It realizes transparent management and control of data sharing terms by users, improves the monetization potential of data, simplifies the third-party data acquisition process, and improves data utilization efficiency.
Smart Images

Figure CN113767383B_ABST
Abstract
Description
1 Background Art 1.1 Technical Field
[0003] This technology relates to data sharing, management consent, and data flow between different entities and devices.
[0004] 1.2 Description of Related Technologies
[0005] Various medical devices, wearables, and other devices can generate user data. Third parties or data consumers may be interested in obtaining this data because the user's data (or aggregating the data of multiple users) may be valuable to third - party consumers. However, the user (or patient as described herein) must consent to the third party sharing and using their data.
[0006] Devices that can generate user data include respiratory therapy devices, wearables, mobile devices, and other connected devices. These can include a variety of respiratory therapy devices, including CPAP devices and associated software and similar devices.
[0007] 1.2.1 The Human Respiratory System and Its Diseases
[0008] The respiratory system of the human body facilitates gas exchange. The nose and mouth form the patient's airway entrance.
[0009] The airway includes a series of branching tubes that become narrower, shorter, and more numerous as the bronchial tubes penetrate deeper into the lungs. The primary function of the lungs is gas exchange, allowing oxygen to move from the inhaled air into the venous blood and allowing carbon dioxide to move in the opposite direction. The trachea divides into the left and right main bronchi, which ultimately divide further into terminal bronchioles. The bronchi constitute the conducting airways but do not participate in gas exchange. Further branching of the airway leads to respiratory bronchioles and ultimately to alveoli. The alveolar region of the lungs is the area where gas exchange occurs and is called the respiratory zone. See "Respiratory Physiology", 9th edition, published by John B. West, Lippincott Williams & Wilkins in 2012.
[0010] There is a series of respiratory diseases. Some diseases can be characterized by specific events, such as apnea, hypopnea, and hyperpnea.
[0011] Examples of respiratory disorders include obstructive sleep apnea (OSA), Cheyne - Stokes respiration (CSR), respiratory insufficiency, obesity hypoventilation syndrome (OHS), chronic obstructive pulmonary disease (COPD), neuromuscular disease (NMD), and chest wall disorders.
[0012] 1.2.2 Treatments
[0013] A variety of therapies have been used to treat one or more of the above respiratory disorders, such as continuous positive airway pressure (CPAP) therapy, non-invasive ventilation (NIV), and invasive ventilation (IV).
[0014] 1.2.2.1 Respiratory pressure therapy
[0015] Continuous positive airway pressure (CPAP) therapy has been used to treat obstructive sleep apnea (OSA). The mechanism of action is that continuous positive airway pressure acts as a pneumatic splint and can prevent upper airway occlusion, such as by pushing the soft palate and tongue forward and away from the posterior oropharyngeal wall. The treatment of OSA by CPAP therapy can be voluntary, so if the patient finds the device used to provide such treatment to be any one or more of uncomfortable, difficult to use, expensive, and unaesthetic, the patient may choose not to comply with the treatment.
[0016] Non-invasive ventilation (NIV) provides ventilatory support to the patient through the upper airway to assist the patient's breathing and / or maintain sufficient oxygen levels in the body by performing some or all of the work of breathing. The ventilatory support is provided via a non-invasive patient interface. NIV has been used to treat CSR and respiratory failure, such as in the forms of OHS, COPD, NMD, and chest wall diseases. In some forms, the comfort and effectiveness of these treatments can be improved.
[0017] Invasive ventilation (IV) provides ventilatory support to patients who are unable to breathe effectively on their own and can be provided using a tracheostomy tube. In some forms, the comfort and effectiveness of these treatments can be improved.
[0018] 1.2.2.2 Flow therapy
[0019] Not all respiratory therapies are aimed at delivering a prescribed treatment pressure. Some respiratory therapies are aimed at delivering a prescribed respiratory volume, possibly by targeting a flow curve over a target duration. In other cases, the interface to the patient's airway is "open" (unsealed) and the respiratory therapy can only supplement the patient's own spontaneous breathing. In one example, high-flow therapy (HFT) provides a continuous, heated, and humidified airflow to the entrance of the airway through an unsealed or open patient interface at a "treatment flow" that remains substantially constant throughout the respiratory cycle. The treatment flow is nominally set to exceed the patient's peak inspiratory flow. HFT has been used to treat OSA, CSR, COPD, and other respiratory disorders. One mechanism of action is that the high-flow air at the airway entrance improves ventilation efficiency by flushing or washing out the exhaled CO2 from the patient's anatomic dead space. Therefore, HFT is sometimes referred to as dead space therapy (DST). In other flow therapies, the treatment flow can follow a curve that varies with the respiratory cycle.
[0020] Another form of mobile treatment is long-term oxygen therapy (LTOT) or supplementary oxygen therapy. A doctor can prescribe a continuous flow of oxygen-enriched gas to a patient's airway at a specific oxygen concentration (ranging from 21% of the oxygen fraction in ambient air to 100%) and at a specific flow rate (e.g., 1 liter per minute (LPM), 2 LPM, 3 LPM, etc.).
[0021] 1.2.2.3 Supplementary oxygen
[0022] For some patients, oxygen therapy can be combined with respiratory pressure therapy or HFT by adding supplementary oxygen to a pressurized gas stream. When oxygen is added to respiratory pressure therapy, this is called RPT with supplementary oxygen. When oxygen is added to HFT, the resulting therapy is called HFT with supplementary oxygen.
[0023] 1.2.3 Treatment system
[0024] These respiratory treatments can be provided by a treatment system or device. Such systems and devices can also be used for screening, diagnosing, or monitoring a condition without treating it.
[0025] A respiratory treatment system can include a respiratory pressure therapy device (RPT device), an air circuit, a humidifier, a patient interface, an oxygen source, and data management.
[0026] 1.2.3.1 Patient interface
[0027] The patient interface can be used to engage a respiratory device with its wearer, for example, by providing an air stream to the entrance of the airway. The air stream can be provided to the patient's nose and / or mouth via a mask, to the mouth via a tube, or to the patient's trachea via a tracheostomy tube. Depending on the treatment to be applied, the patient interface can form a seal with an area of the patient's face, for example, to facilitate the delivery of gas at a pressure with a sufficient difference from ambient pressure (e.g., a positive pressure of approximately 10 cmH2O relative to ambient pressure) to achieve the treatment. For other forms of treatment, such as oxygen delivery, the patient interface may not include a seal sufficient to facilitate the delivery of a gas supply at a positive pressure of approximately 10 cmH2O to the airway.
[0028] 1.2.3.2 Respiratory pressure therapy (RPT) device
[0029] The respiratory pressure therapy (RPT) device can be used alone or as part of a system to deliver one or more of the above-mentioned various treatments, for example, by operating the device to generate an air stream for delivery to an airway interface. The air stream can be pressure-controlled (for respiratory pressure therapy) or flow-controlled (for flow therapy such as HFT). Therefore, the RPT device can also be used as a mobile treatment device. Examples of RPT devices include CPAP devices and ventilators.
[0030] Pressure generators are known in a variety of applications, such as industrial-scale ventilation systems. However, pressure generators for medical applications have specific requirements that more general pressure generators cannot meet, such as the reliability, size, and weight requirements of medical devices. In addition, even devices designed for medical treatment may have drawbacks related to one or more of the following: comfort, noise, ease of use, efficacy, size, weight, manufacturability, cost, and reliability.
[0031] An example of a special requirement for some RPT devices is noise.
[0032] A known RPT device for treating sleep apnea is the S9 sleep therapy system manufactured by ResMed Limited. Another example of an RPT device is a ventilator. Ventilators, such as the ResMed Stellar TM series, can provide invasive and non-invasive non-dependent ventilation support for a range of patients to treat a variety of conditions, such as but not limited to NMD, OHS, and COPD.
[0033] The treated ResMed Elisée TM 150 ventilator and the treated ResMed VS III TM Ventilators can provide invasive and non-invasive dependent ventilation support suitable for adult or pediatric patients to treat a variety of conditions. These ventilators provide volume and pressure ventilation modes with single-limb or double-limb circuits. RPT devices generally include a pressure generator, such as a motor-driven blower or a compressed gas reservoir, and are configured to supply an air stream to a patient's airway. In some cases, the air stream can be provided to the patient's airway at positive pressure. The outlet of the RPT device is connected via an air circuit to a patient interface such as those described above.
[0034] 1.2.3.3 Data Management
[0035] There may be clinical reasons for obtaining data to determine whether a patient prescribed respiratory therapy has been "compliant", such as the patient has used their RPT device according to one or more "compliance rules". An example of a compliance rule for CPAP therapy is that, to be considered compliant, the patient is required to use the RPT device for at least 4 hours overnight for at least 21 days out of 30 consecutive days. To determine a patient's compliance, the provider of the RPT device (such as a healthcare provider) can manually obtain data describing the patient's treatment using the RPT device, calculate the usage over a predetermined period, and compare it with the compliance rule. Once the healthcare provider has determined that the patient has used their RPT device according to the compliance rule, the healthcare provider can notify a third party that the patient is compliant.
[0036] There may be other aspects of patient treatment that would benefit from communication to a third party or external system from the treatment data.
[0037] Existing processes for communicating and managing such data can be one or more of expensive, time-consuming, and error-prone.
[0038] 1.2.3.4 Ventilation techniques
[0039] Some forms of treatment systems can include vents to allow for flushing of exhaled carbon dioxide. The vents can allow gas to flow from an internal space of the patient interface, such as an inflation chamber, to the exterior of the patient interface, such as the surrounding environment.
[0040] 1.2.4 Screening, diagnostic, and monitoring systems
[0041] Polysomnography (PSG) is a conventional system for diagnosing and monitoring cardiopulmonary diseases and typically involves a clinical expert to apply the system. PSG typically involves placing 15 to 20 contact sensors on a patient to record various body signals, such as electroencephalogram (EEG), electrocardiogram (ECG), electrooculogram (EOG), electromyogram (EMG), etc. PSG for sleep disordered breathing involves observing the patient clinically for two nights, a pure diagnostic night and a second night for a clinician to titrate treatment parameters. Thus, PSG is expensive and inconvenient. In particular, it is not suitable for home screening / diagnosis / monitoring of sleep disordered breathing.
[0042] Screening and diagnosis generally describe identifying a disorder from the signs and symptoms of the disorder. Screening typically gives a true / false result indicating whether the patient's SDB is severe enough to warrant further study, while diagnosis can produce clinically actionable information. Screening and diagnosis tend to be one-time processes, while monitoring the progression of the condition can continue indefinitely. Some screening / diagnosis systems are only suitable for screening / diagnosis, while some can also be used for monitoring.
[0043] Clinical experts may be able to adequately screen, diagnose, or monitor a patient based on visually observed PSG signals. However, there are situations where clinical experts may not be available or may not be affordable. Different clinical experts may disagree on a patient's disorder. In addition, a given clinical expert may apply different criteria at different times. 2 Summary of the Invention
[0045] This technology is directed to managing consent for user data and devices regarding a third party.
[0046] A first aspect of this technology relates to various devices and software for generating user data that a user can consent to share. These include devices, methods, and software for screening, diagnosing, monitoring, improving, treating, or preventing respiratory disorders.
[0047] One aspect of certain forms of the present technology is to manage consent and data flows related to methods and / or devices for improving patient compliance with respiratory therapy.
[0048] One form of the present technology includes a server, a database, and software for managing consent of user devices and data generated by user devices that can be sent to third parties. Currently, when users sign up for new services that require sharing data to create an account, they must view and agree to a long list of terms and conditions related to sharing their data. Users or patients are unlikely to read these terms and conditions, and there is little or no way for them to revoke their consent to share data (once they have consented). Additionally, users have little or no way to monetize any valuable data they have, so valuable patient and other data for many users remains non-monetized and thus ultimately ends up not being shared. Further, users rarely understand the consent terms and have no way to selectively choose the terms they consent to, or choose a subset of the parties, end users, or ways in which they consent to share their data.
[0049] Accordingly, there are no systems and methods for effectively managing user consent to share data from their devices, software programs, accounts, and other data sources with third-party data consumers. Thus, the inventors have developed systems and methods to assist in managing consent and / or data flows between user devices and third-party data consumers.
[0050] In some examples, this can include a consent proxy server and a database storing unique identifiers representing each user, where the unique identifiers reference the user's individual consent preferences. Consent preferences can include data types, data generation devices for which the user consents, types of third parties with whom the user consents to share data, and other consent preferences. This will allow third parties to communicate with the consent proxy and determine whether the user consents to share their data. The third party can then store the consent, directly download data from the user, and use the data based on the terms to which the user has consented.
[0051] In another aspect of one form of the present technology, the proxy can act as an intermediary for data transfer between the third party and the user device. For example, the consent proxy can provide an API address to the third party receiving the data and can manage the data flow between the user and the third party. Once the user decides to terminate consent, this will allow the consent proxy to easily cut off access to the API.
[0052] In another aspect of one form of the present technology, an agent can download and store data from several different users to create a data warehouse and marketplace for third parties to download data. For example, a third party can send a request to the agent for a certain type of data for a certain type of use. The agent can then query the database to determine how much of that type of data is available for that use and send back the market price to the third party. The third party can then agree to receive the data at that price, and the agent can send the data to the third party.
[0053] The methods, systems, devices, and apparatuses described can be implemented to improve the functionality of a processor, such as the processor of a dedicated computer, a respiratory monitor, and / or a respiratory treatment device. Additionally, the methods, systems, devices, and apparatuses described can provide improvements in the technical field of the automated management, monitoring, and / or treatment of respiratory conditions, such as sleep disordered breathing.
[0054] Of course, some of these aspects can form sub - aspects of the present technology. In addition, the various aspects within the sub - aspects and / or aspects can be combined in various ways and also constitute other aspects or sub - aspects of the present technology.
[0055] Other features of the present technology will become apparent in view of the information contained in the following detailed description, the abstract, the drawings, and the claims. 3. Drawings
[0057] The present technology is illustrated in the drawings by way of example and not limitation, in which like reference numerals represent like elements and include:
[0058] 3.1 Treatment System
[0059] Figure 1A A system is shown in which a patient 1000 wearing a patient interface 3000 in the form of nasal pillows receives a supply of air under positive pressure from an RPT device 4000. The air from the RPT device 4000 is humidified in a humidifier 5000 and conveyed along an air circuit 4170 to the patient 1000. A bed partner 1100 is also shown. The patient is sleeping in a supine sleeping position.
[0060] Figure 1B A system is shown in which a patient 1000 wearing a patient interface 3000 in the form of a nasal mask receives a supply of air under positive pressure from an RPT device 4000. The air from the RPT device is humidified in a humidifier 5000 and conveyed along an air circuit 4170 to the patient 1000.
[0061] Figure 1CThere is shown a system including a patient 1000 wearing a patient interface 3000 in the form of a full face mask receiving a supply of air under positive pressure from an RPT device 4000. The air from the RPT device is humidified in a humidifier 5000 and conveyed along an air circuit 4170 to the patient 1000. The patient sleeps in a lateral sleeping position.
[0062] 3.2 Respiratory system and facial anatomy
[0063] Figure 2A There is shown a schematic diagram of the human respiratory system including the nasal and oral cavities, larynx, vocal cords, esophagus, trachea, bronchi, lungs, alveolar sacs, heart and diaphragm.
[0064] 3.3 Patient interface
[0065] Figure 3A There is shown a patient interface in the form of a nasal mask according to one form of the present technology.
[0066] 3.4 RPT device
[0067] Figure 4A There is shown an RPT device according to one form of the present technology.
[0068] Figure 4B is a schematic diagram of the pneumatic path of an RPT device according to one form of the present technology. The upstream and downstream directions are indicated with reference to the blower and the patient interface. The blower is defined as upstream of the patient interface and the patient interface is defined as downstream of the blower, regardless of the actual direction of flow at any particular moment. Articles within the pneumatic path between the blower and the patient interface are downstream of the blower and upstream of the patient interface.
[0069] 3.5 Humidifier
[0070] Figure 5A There is shown an isometric view of a humidifier according to one form of the present technology.
[0071] Figure 5B There is shown an isometric view of a humidifier according to one form of the present technology, showing the humidifier reservoir 5110 removed from the humidifier reservoir base 5130.
[0072] 3.6 Respiratory waveform
[0073] Figure 6A There is shown a typical respiratory waveform of a model of a person during sleep.
[0074] 3.7 Screening, diagnosis and monitoring system
[0075] Figure 7A There is shown a patient undergoing polysomnography (PSG). The patient sleeps in a supine sleeping position.
[0076] Figure 7B A monitoring device for monitoring a patient's condition is shown. The patient sleeps in a supine sleeping position.
[0077] 3.8 Data transmission
[0078] Figure 8 A block diagram of a system for storing and managing consent is shown.
[0079] Figure 9 A flowchart of an example method for managing consent is shown.
[0080] Figure 10 A block diagram of a system for storing and managing consent is shown.
[0081] Figure 11 A flowchart of an example method for managing consent and data is shown.
[0082] Figure 12 A flowchart of an example method for managing consent and data is shown. 4 Detailed implementation
[0084] Before describing the present technology in further detail, it should be understood that the present technology is not limited to the specific examples described herein, and the specific examples described herein may be changed. It should also be understood that the terms used in the present disclosure are only for the purpose of describing the specific examples described herein and are not intended to be limiting.
[0085] The following description is provided in relation to various examples that may share one or more common characteristics and / or features. It should be understood that one or more features of any one example may be combined with one or more features of another example or other examples. Additionally, in any of the examples, any single feature or combination of features may constitute another example.
[0086] 4.1 Treatment
[0087] In one form, the present technology includes a method for treating a respiratory disorder, the method including applying positive pressure to the airway inlet of a patient 1000.
[0088] In certain examples of the present technology, an air supply under positive pressure is provided to the nasal passages of the patient via one or both nostrils.
[0089] In certain examples of the present technology, mouth breathing is limited, restricted, or blocked.
[0090] 4.2 Treatment system
[0091] In one form, the present technology includes a device or apparatus for treating a respiratory disorder. The device or apparatus may include an RPT device 4000 for supplying pressurized air to a patient interface 3000 or 3800 to a patient 1000 via an air circuit 4170.
[0092] 4.3 Patient Interface
[0093] The non-invasive patient interface 3000 according to one aspect of the present technology includes the following functional aspects: a seal-forming structure 3100, an inflation chamber 3200, a positioning and stabilization structure 3300, a vent 3400, a form of connection port 3600 for connecting to the air circuit 4170, and a forehead support 3700. In some forms, the functional aspects may be provided by one or more physical components. In some forms, one physical component may provide one or more functional aspects. In use, the seal-forming structure 3100 is arranged to surround the entrance of the patient's airway to facilitate the supply of positive pressure air to the airway.
[0094] The unsealed patient interface 3800 in the form of a nasal cannula includes nasal prongs 3810a, 3810b which may deliver air to the respective nostrils of the patient 1000. Such nasal prongs typically do not form a seal with the inner or outer skin surface of the nostrils. Air may be delivered to the nasal prongs through one or more air supply lumens 3820a, 3820b coupled to the nasal cannula 3800. The lumens 3820a, 3820b lead from the nasal cannula 3800 to an RT device that generates a high-flow air stream. The "vent" at the unsealed patient interface 3800 is the passage from between the ends of the prongs 3810a and 3810b of the cannula 3800, through the patient's nostrils, to the atmosphere, through which excess air flow escapes to the surrounding environment.
[0095] 4.4 RPT Device
[0096] The RPT device 4000 according to one aspect of the present technology includes mechanical, pneumatic, and / or electrical components and is configured to execute one or more algorithms 4300, such as any of the methods described in whole or in part herein. The RPT device 4000 may be configured to generate an air stream for delivery to the patient's airway, such as for treating one or more respiratory conditions described elsewhere in this document.
[0097] 4.4.1 Electrical Components of the RPT Device
[0098] 4.4.1.1 Input Device
[0099] In one form of the present technology, the RPT device 4000 includes one or more input devices 4220 in the form of buttons, switches, or dials to allow a person to interact with the device. The buttons, switches, or dials can be physical devices or software devices accessible via a touch screen. The buttons, switches, or dials can be physically connected to the housing 4010 in one form or can wirelessly communicate with a receiver electrically connected to the central controller 4230 in another form.
[0100] In one form, the input device 4220 can be constructed and arranged to allow a person to select values and / or menu options.
[0101] 4.4.1.2 Central Controller
[0102] In one form of the present technology, the central controller 4230 is one or more processors adapted to control the RPT device 4000.
[0103] Suitable processors can include x86 INTEL processors, processors based on ARM Holdings' -M processors, such as the STM32 series microcontrollers of ST MICROELECTRONIC. In certain alternative forms of the present technology, 32-bit RISC CPUs (e.g., the STR9 series microcontrollers from ST MICROELECTRONICS) or 16-bit RISC CPUs (e.g., the processors of the MSP430 series microcontrollers manufactured by TEXAS INSTRUMENTS) are also applicable.
[0104] In one form of the present technology, the central controller 4230 is a dedicated electronic circuit.
[0105] In one form, the central controller 4230 is an application-specific integrated circuit. In another form, the central controller 4230 includes discrete electronic components.
[0106] The central controller 4230 can be configured to receive input signals from one or more transducers 4270, one or more input devices 4220, and the humidifier 5000.
[0107] The central controller 4230 can be configured to provide output signals to one or more of the output device 4290, the treatment device controller 4240, the data communication interface 4280, and the humidifier 5000.
[0108] In some forms of the present technology, the central controller 4230 is configured to implement one or more of the methods described herein, such as one or more algorithms 4300 represented as a computer program stored in a non-transitory computer-readable storage medium (such as the memory 4260). In some forms of the present technology, the central controller 4230 may be integrated with the RPT device 4000. However, in some forms of the present technology, some methods may be performed by remotely located devices. For example, a remotely located device may determine control settings of a ventilator or detect respiratory-related events by analyzing stored data (such as from any of the sensors described herein).
[0109] 4.4.1.3 Clock
[0110] The RPT device 4000 may include a clock 4232 connected to the central controller 4230.
[0111] 4.4.1.4 Treatment Device Controller
[0112] In one form of the present technology, the treatment device controller 4240 is a treatment control module 4330, which forms part of the algorithm 4300 executed by the central controller 4230.
[0113] In one form of the present technology, the treatment device controller 4240 is a dedicated motor control integrated circuit. For example, in one form, an MC33035 brushless DC motor controller manufactured by ONSEMI is used.
[0114] 4.4.1.5 Protection Circuit
[0115] One or more protection circuits 4250 according to the present technology may include an electrical protection circuit, a temperature and / or pressure safety circuit.
[0116] 4.4.1.6 Memory
[0117] In one form according to the present technology, the RPT device 4000 includes a memory 4260, such as a non-volatile memory. In some forms, the memory 4260 may include battery-powered static RAM. In some forms, the memory 4260 may include volatile RAM.
[0118] The memory 4260 may be located on the PCBA 4202. The memory 4260 may be in the form of an EEPROM or NAND flash memory.
[0119] Additionally or optionally, the RPT device 4000 includes a removable form of memory 4260, such as a memory card manufactured according to the Secure Digital (SD) standard.
[0120] In one form of the present technology, the memory 4260 acts as a non-transitory computer-readable storage medium on which computer program instructions are stored, which represent one or more methods described herein, such as one or more algorithms 4300.
[0121] 4.4.1.7 Data communication system
[0122] In one form of the present technology, a data communication interface 4280 is provided, which is connected to the central controller 4230. The data communication interface 4280 can be connected to a remote external communication network 4282 and / or a local external communication network 4284. The remote external communication network 4282 can be connected to a remote external device 4286. The local external communication network 4284 can be connected to a local external device 4288.
[0123] In one form, the data communication interface 4280 is part of the central controller 4230. In another form, the data communication interface 4280 is separate from the central controller 4230 and can include an integrated circuit or a processor.
[0124] In one form, the remote external communication network 4282 is the Internet. The data communication interface 4280 can use wired communication (e.g., via Ethernet or fiber optic) or wireless protocols (e.g., CDMA, GSM, LTE) to connect to the Internet.
[0125] In one form, the local external communication network 4284 utilizes one or more communication standards, such as Bluetooth or the consumer infrared protocol.
[0126] In one form, the remote external device 4286 is one or more computers, such as a cluster of networked computers. In one form, the remote external device 4286 can be a virtual computer rather than a physical computer. In either case, such a remote external device 4286 can be accessed by a properly authorized person such as a clinician.
[0127] The local external device 4288 can be a personal computer, a mobile phone, a tablet, or a remote control device.
[0128] 4.4.2 RPT device algorithm
[0129] As described above, in some forms of the present technology, the central controller 4230 can be configured to implement one or more algorithms 4300 represented as a computer program stored in a non-transitory computer-readable storage medium (e.g., the memory 4260). The algorithms 4300 are generally grouped into groups called modules.
[0130] 4.4.2.1 Preprocessing module
[0131] In one form of the present technology, the preprocessing module 4310 receives as input a signal from a transducer 4270 (e.g., a flow sensor 4274 or a pressure sensor 4272), and performs one or more processing steps to calculate one or more output values that will be used as input to another module (e.g., the therapy engine module 4320).
[0132] In one form of the present technology, the output values include the interface pressure Pm, the respiratory flow Qr, and the leak flow Ql.
[0133] In various forms of the present technology, the preprocessing module 4310 includes one or more of the following algorithms: interface pressure estimation 4312, ventilation flow estimation 4314, leak flow estimation 4316, and respiratory flow estimation 4318.
[0134] 4.4.2.2 Therapy Engine Module
[0135] In one form of the present technology, the therapy engine module 4320 receives as input one or more of the pressure Pm in the patient interface 3000 or 3800 and the respiratory flow Qr of air to the patient, and provides one or more therapy parameters as output.
[0136] In one form of the present technology, the therapy parameter is the therapy pressure Pt.
[0137] In one form of the present technology, the therapy parameter is one or more of the pressure change amplitude, the baseline pressure, and the target ventilation volume.
[0138] In various forms, the therapy engine module 4320 includes one or more of the following algorithms: phase determination 4321, waveform determination 4322, ventilation determination 4323, inspiratory flow limit determination 4324, apnea / hypopnea determination 4325, snore determination 4326, airway patency determination 4327, target ventilation determination 4328, and therapy parameter determination 4329.
[0139] 4.4.2.2.1 Determination of Apnea and Hypopnea
[0140] In one form of the present technology, the central controller 4230 executes the apnea / hypopnea determination algorithm 4325 to determine the presence of apnea and / or hypopnea.
[0141] In one form, the apnea / hypopnea determination algorithm 4325 receives the respiratory flow signal Qr as input and provides a flag indicating that apnea or hypopnea has been detected as output.
[0142] In one form, an apnea is considered to be detected when a function of the respiratory flow Qr drops below a flow threshold over a predetermined period of time. The function can determine peak flow, a relatively short-term average flow, or an intermediate flow between a relatively short-term average and peak flow, such as RMS flow. The flow threshold can be a relatively long-term measure of flow.
[0143] In one form, a hypopnea is considered to be detected when a function of the respiratory flow Qr drops below a second flow threshold over a predetermined period of time. The function can determine peak flow, a relatively short-term average flow, or an intermediate flow between a relatively short-term average and peak flow, such as RMS flow. The second flow threshold can be a relatively long-term flow measurement. The second flow threshold is greater than the flow threshold used to detect apnea.
[0144] 4.4.2.2.2 Determination of snoring
[0145] In one form of the present technology, the central controller 4230 executes one or more snoring determination algorithms 4326 for determining the degree of snoring.
[0146] In one form, the snoring determination algorithm 4326 receives the respiratory flow signal Qr as an input and provides a measure of the degree of snoring occurrence as an output.
[0147] The snoring determination algorithm 4326 can include steps of determining the intensity of the flow signal in the range of 30 - 300 Hz. Additionally, the snoring determination algorithm 4326 can include steps of filtering the respiratory flow signal Qr to reduce background noise (e.g., the sound of air flow in the system from a blower).
[0148] 4.5 Air circuit
[0149] An air circuit 4170 according to one aspect of the present technology is a conduit or tube that is configured and arranged in use to allow air flow to travel between two components such as the RPT device 4000 and the patient interface 3000 or 3800.
[0150] 4.6 Humidifier
[0151] 4.6.1 Humidifier overview
[0152] In one form of the present technology, a humidifier 5000 is provided (e.g., as Figure 5A shown) to change the absolute humidity of the air or gas to be delivered to the patient relative to the ambient air. Generally, the humidifier 5000 is used to increase the absolute humidity of the air flow and increase the temperature of the air flow (relative to the ambient air) before delivery to the patient's airway.
[0153] The humidifier 5000 may include a humidifier reservoir 5110, a humidifier inlet 5002 for receiving an air stream, and a humidifier outlet 5004 for delivering a humidified air stream. In some forms, as Figure 5A and Figure 5B shown, the inlet and outlet of the humidifier reservoir 5110 may be the humidifier inlet 5002 and the humidifier outlet 5004, respectively. The humidifier 5000 may further include a humidifier base 5006, which may be adapted to receive the humidifier reservoir 5110 and includes a heating element 5240.
[0154] 4.7 Respiratory waveform
[0155] Figure 6A Shows the typical respiratory waveform of a human model during sleep. The horizontal axis is time and the vertical axis is respiratory flow. While the parameter values may vary, a typical respiration may have the following approximate values: tidal volume Vt 0.5L, inspiratory time Ti 1.6s, peak inspiratory flow Qpeak 0.4L / s, expiratory time Te 2.4s, peak expiratory flow Qpeak -0.5L / s. The total duration of respiration Ttot is about 4s. A person typically breathes at a rate of about 15 breaths per minute (BPM), with a ventilation of Vent about 7.5L / min. The typical duty cycle, the ratio of Ti to Ttot, is about 40%.
[0156] 4.8 Screening, diagnosis, monitoring system
[0157] 4.8.1 Polysomnogram
[0158] Figure 7A Shows a patient 1000 undergoing a polysomnogram (PSG). The PSG system includes a flow cell 2000, which receives and records signals from the following sensors: EOG electrodes 2015; EEG electrodes 2020; ECG electrodes 2025; submental EMG electrodes 2030; snoring sensor 2035; respiratory inductive plethysmogram (respiratory effort sensor) 2040 on the chest strap; respiratory inductive plethysmogram (respiratory effort sensor) 2045 on the abdominal strap; an oral-nasal cannula 2050 with an oral thermistor; a photoplethysmograph (pulse oximeter) 2055; and a body position sensor 2060. The electrical signals are referenced to a ground electrode (ISOG) 2010 located at the center of the forehead.
[0159] 4.8.2 Unobtrusive monitoring system
[0160] Figure 7BShows an example of a monitoring device 7100 for monitoring the respiration of a sleeping patient 1000. The monitoring device 7100 includes a non-contact motion sensor generally directed at the patient 1000. The motion sensor is configured to generate one or more signals representative of the body movement of the patient 1000, from which signals a signal representative of the respiratory movement of the patient can be obtained.
[0161] 4.8.3 Respiratory polygraphy
[0162] Respiratory polygraphy (RPG) is a term for a simplified form of PSG without electro-signals (EOG, EEG, EMG), snoring, or body position sensors. The RPG includes at least thoracic motion signals from a respiratory inductive plethysmogram (motion sensor) on a chest strap (such as motion sensor 2040), a nasal pressure signal sensed via a nasal cannula, and an oxygen saturation signal from a pulse oximeter (such as pulse oximeter 2055). Similar to the PSG manifold 2000, the RPG manifold receives three RPG signals or channels.
[0163] In some configurations, the nasal pressure signal is a satisfactory representative of the nasal flow signal generated by a flow sensor in line with a sealed nasal mask, since the nasal pressure signal is comparable in shape to the nasal flow signal. If the patient's mouth remains closed, i.e., there is no mouth leak, then the nasal flow is equal to the respiratory flow.
[0164] Figure 8 Is a block diagram showing a screening / diagnosis / monitoring device 7200 that can be used to implement the RPG manifold in an RPG screening / diagnosis / monitoring system. The screening / diagnosis / monitoring device 7200 receives the above three RPG channels (a signal indicating thoracic motion, a signal indicating nasal flow, and a signal indicating oxygen saturation) at a data input interface 7260. The screening / diagnosis / monitoring device 7200 also includes a processor 7210 configured to execute encoded instructions. The screening / diagnosis / monitoring device 7200 also includes a non-transitory computer-readable memory / storage medium 7230.
[0165] The memory 7230 can be the internal memory of the screening / diagnosis / monitoring device 7200, such as RAM, flash memory, or ROM. In some implementations, the memory 7230 can also be a removable or external memory linked to the screening / diagnosis / monitoring device 7200, such as an SD card, a server, a USB flash drive, or an optical disc. In other implementations, the memory 7230 can be a combination of external and internal memories. The memory 7230 includes stored data 7240 and processor control instructions (code) 7250, and the processor control instructions (code) 7250 are adapted to configure the processor 7210 to perform certain tasks. The stored data 7240 can include RPG channel data received by the data input interface 7260, as well as other data provided as part of an application. The processor control instructions 7250 can also be provided as part of an application program. The processor 7210 is configured to read the code 7250 from the memory 7230 and execute the encoded instructions. In particular, the code 7250 can contain instructions adapted to configure the processor 7210 to perform a method of processing the RPG channel data provided by the interface 7260. One such method can be to store the RPG channel data as data 7240 in the memory 7230. Another such method can be to analyze the stored RPG data to extract features. The processor 7210 can store the result of such analysis as data 7240 in the memory 7230.
[0166] The screening / diagnosis / monitoring device 7200 can also include a communication interface 7220. The code 7250 can contain instructions configured to allow the processor 7210 to communicate with an external computing device (not shown) via the communication interface 7220. The communication mode can be wired or wireless. In one such implementation, the processor 7210 can transmit the stored RPG channel data from the data 7240 to a remote computing device. In such an implementation, the remote computing device can be configured to analyze the received RPG data to extract features. In another such implementation, the processor 7210 can transmit the analysis result from the data 7240 to the remote computing device.
[0167] Alternatively, if the memory 7230 is removable from the screening / diagnosis / monitoring device 7200, the remote computing device can be configured to connect to the removable memory 7230. In such an implementation, the remote computing device can be configured to analyze the RPG data retrieved from the removable memory 7230 to extract features.
[0168] 4.9 Data Transmission
[0169] Figure 8A block diagram is shown illustrating an implementation of a data consent broker system according to the present technology. For example, the system includes one or more user devices 4000 that generate data and may be associated with the account of a user or patient 1000. The account of patient 1000 may be managed from a mobile device 120 or other computing device to log in to a user account on a service associated with device 4000.
[0170] The user device 4000 can then provide consent data 8000 to various third parties that wish to utilize the user data. The consent data 8000 can particularly include:
[0171] · Date and timestamp;
[0172] · Terms to which the user consents;
[0173] · Third parties to which the user consents to share data;
[0174] · Types of data that the user consents to share;
[0175] · Time window for which the consent is valid; and
[0176] · And other relevant data.
[0177] The consent data can be provided by the user clicking accept on a user interface, using checkboxes on the user interface or other means on the computing device 120 to specify what terms the user accepts.
[0178] The user devices 4000 that generate data can include a variety of user devices, including: medical devices, mobile devices, personal computers, laptop computers, CPAP machines and associated software, humidifiers, other devices disclosed herein, wearables, software services running on various servers 7100 and computing devices, smartwatches, smart scales, smart wristbands, genetic data services, health data services, fitness equipment, etc.
[0179] Thus, the user data 10000 generated by device 4000 can include health data, genetic data, location data, metadata, treatment data, treatment settings, exercise data, profile data, age, weight, data from electronic health records, sleep quality data, apnea data, hypopnea, date and timestamp, and other types of data. The data 10000 can be sent in packets with metadata to indicate the type of data being sent.
[0180] The consent management system may also include a consent system 8100, which includes a server 7100 and a database 7200. The database 7200 may include a unique user identifier that references the terms to which user 1000 has consented, including: (1) the types of data that can be shared, (2) the types of data generation devices from which data can be shared, and (3) third parties to which user 1000 has consented to share data 185. In addition, the consent system 8100 may store other data fields that reference the unique user identifier, including all relevant items discussed above regarding user data 10000.
[0181] Additionally, a third-party system 8200 that includes at least the server 7100 and the database 7200 as data consumers may also be connected to the consent system 8100 of user 1000 and the computing device 120 via a network 7090. The network 7090 may be a wide area network 7090, such as the Internet, an intranet, the cloud, or the Internet. The connection to the network may be wired or wireless.
[0182] The patient computing device 120 may be a personal computer, a mobile phone, a tablet computer, or other device. The patient computing device 120 is configured to mediate between patient 1000 and the data server 7100 via the wide area network 7090.
[0183] In one implementation, this mediation is performed by a software application running on the patient computing device 120. The patient program may be a dedicated application known as a "patient application" that interacts with a complementary process hosted by the data server 7100. In another implementation, the patient program is a web browser that interacts with a website hosted by the data server 7100 via a secure portal. In yet another implementation, the patient program is an email client.
[0184] In other examples, the data generation device 4000 communicates with the patient computing device 120 via a local (wired or wireless) communication protocol, such as a local network protocol (e.g., Bluetooth). In an alternative implementation, the patient computing device 120 via the patient program is configured to mediate between patient 1000 and the data server 7100 on the network 7090 and also between the data generation device 4000 and the data server 7100 on the network 7090.
[0185] The consent data 8000 from the computing device 120 of user 1000 may be sent to the third-party system 8200 and stored in its database 7200, such that the third-party system 8200 can determine from which devices 4000 it can download data and the types of data that can be used and stored, etc.
[0186] Figure 9A flowchart showing an example method of managing consent. For example, first, the consent system 8100 can receive a request 9000 to access user data from a third party. Thus, in this case, the third party does not have to send a notification to the computing device 120 of the user 1000 to separately request user consent. Instead, the third party can send a data packet to the consent system 8100, and the consent system 8100 can respond as to whether the user 1000 consents to share the data.
[0187] The request may include data types, user identifiers, user device types, or other parameters including a request to consent to download data from the user computing device 120 or user data generating device 4000. In other examples, the request may include only the user identifier, and the consent system 8100 can send back the consent data 8000 along with a summary of the consent terms to which the user 1000 has consented.
[0188] In some examples, after receiving the request from the third party 9000, the system 8100 can query the database 7200 to determine whether the user identifier exists in the database 7200 and what type of consent is referenced to the user identifier 9100. For example, the consent system 8100 can retrieve the consent data 9100 that references the user identifier, which includes the data types 9450 that the user has consented to share, the authorized third parties 9460, and the authorized user devices 9470. The authorized user devices 9470 can be specified by various addresses, MAC addresses, or other identifiers.
[0189] Next, the system 8100 can respond 9200 to the third party system 8200 by sending the consent data 8000 from the server 7200 of the consent system 8100 to the server 7100 of the third party system 8200. This can include the type of consent that the user has consented to, or can simply return true or false as to whether the third party system 8200 can download and use data from the user device 4000.
[0190] Thus, if consent is confirmed in various ways over the network 7090, the third party system 8200 can then download data from the user device 4000. This can be for a period of time, a predetermined time window, or indefinitely.
[0191] In some examples, user 1000 will indicate on their computing device 120 that they wish to revoke a previously given consent and send the revoked consent data 8000 to the consent system 8100 at 9300. The consent system 8100 can then determine which third-party system 8200 sent the revoked consent data 8000 at 9400. The revoked consent data 8000 can include any combination of data fields that include a global revocation of the third party 8200 and the user data 10000, or a certain type or use of the data 10000.
[0192] Figure 10 An additional system is shown that represents another embodiment of the present disclosure. In this embodiment, the user data 10000 is routed through the consent system 8100 rather than being sent directly from the user computing device 120 or the user data generation device 4000 to the third party 8200. This is advantageous because it allows the consent system 8100 to effectively manage the consent process, revoke consent more easily by shutting off the data stream, increase the ability to anonymize data sources and the users associated with the data sources, and allows the consent system 8100 to act as a marketplace for selling data.
[0193] Figure 11 A flowchart of an example method for implementing Figure 10 the consent system is shown. For example, the consent system 8100 can send a request to the user device to request consent to share data 11000. This can be a global request that includes multiple types of data, data consumers, end users, uses, data sources, data generation devices. In other examples, it can include only one specific third-party 8200 data consumer or be prompted by it.
[0194] The system 8100 can then receive from the user computing device 120 a confirmation 11100 of consent to share data that can include a data type 9450, a time window for which the consent is valid 9470, and in some cases other factors and information including a specific requesting third-party system 8200. Then, once the consent is confirmed, the system 8100 can request and receive, for example, login data 11200 for the data generation device 4000 from the user's third-party account.
[0195] This will allow the server 7100 of the system to log in and receive data 11300 from the data generation device 4000 or its associated account, or other services or software, over the network 7090. Additionally, other embodiments can be implemented that similarly verify the user 1000's account credentials and download the data 11300.
[0196] Next, system 8100 and its server 7100 can process data to determine data type 11400 and other relevant characteristics of the data. This can include categories of data that reference consent types, such as location data, profile data, medical history, etc. In some examples, this can be performed through machine learning or other algorithms that recognize, for example, GPS coordinate formats. In other examples, system 8100 will process header information or other metadata to determine the data type.
[0197] Then, in some examples, the data will be stored in consent database 7200 that references a user identifier, or only references data type or data source 11500. In some cases, various other tags will be applied to the data so that database 7200 can be queried like a marketplace to determine the data types and amounts available to third - party system 8200 data consumers.
[0198] Consent System as a Data Pipeline
[0199] Figure 12 The flowchart shows an example of a method for facilitating the transfer of data from user data generation device 4000 to a third - party data consumer once consent has been granted and confirmed to a particular third - party. For example, in some of the above examples, consent system 8100 can simply manage consent, or the system can upload data 10000 from multiple users 1000 in order to aggregate and increase the value of the data.
[0200] However, if the system uploads data 10000 from multiple users 1000, a relatively large amount of storage space in database 7200 will be required. Therefore, in other examples, consent system 8100 can act as a pipeline to facilitate the transfer of data from data generation device 4000 to third - party system 8200. In this example, consent system 8100 will not be required to store large amounts of data, but will still be able to tightly manage the data flow and easily revoke consent and prevent the transfer of additional data once the user revokes consent.
[0201] For example, consent system 8100 can send an API address to a third - party to access data generated by data device 12000. Then, system 8100 can facilitate the transfer of data generated by the data device to the third - party through API 12100. For example, third - party 8200 can make periodic calls to the API address to request updates to the data, and then system 8100 can send or request additional data from data device 4000. In other examples, the system can periodically send data to third - party 8200 through the API.
[0202] In some examples, system 8100 may process data 10000 to identify the data type (e.g., based on specific characteristics of metadata or data structure). In such cases, the API of system 8100 or other internal processing software may screen all or part of the data generated by user device 4000 before sending it to third party 8200. In some examples, certain information may be removed from the data first before sending the data. This may include the username or other identifying information, which may be used to comply with the type of user consent or to comply with privacy laws related to patient data.
[0203] Data marketplace
[0204] In some examples, system 8100 may create a data marketplace where it may present the data type and price of the data to data consumers or third party 8200. Then, third party 8200 may purchase the type and quantity of data and, in some cases, may pay part of the purchase price to user 1000 to share their data 10000. In some examples, system 8100 may aggregate or catalog the data types available for purchase and determine various characteristics of the data that may be relevant to data consumers to determine whether the data is valuable to them, including:
[0205] (1) Data type (e.g., movement, location, etc.)
[0206] (2) Data source
[0207] (3) Profile characteristics (such as gender, age, etc.);
[0208] (4) Consent characteristics associated with the data; and
[0209] (5) Other characteristics.
[0210] In some examples, third party 8200 may send a data request, including for example the type of data requested, the threshold amount of data required, and the price that third party 8200 is willing to pay for the data. Then, system 8100 may query its database 7200 using server 7100 to determine whether the request can be fulfilled and the type, quantity, and price of any relevant data.
[0211] Then, in some examples, system 8100 may send a notification to third party 8200 including the available data and price. Then, third party 8200 may accept or reject the request, or in other examples, if the data identified on database 7200 meets the requirements of third party 8200, system 8200 may automatically send the data (or the API for access as described above).
[0212] In some examples, system 8100 can store public requests for data 10000 from third party 8200, and whenever a new user 1000 uploads or provides consent to share data 10000, system 8100 can determine whether the new data meets the requirements of any public requests. Then, if any open requests are met, the new data 10000 can be sent to the corresponding third party 8200.
[0213] Selected embodiments
[0214] Although the above description and the appended claims disclose multiple embodiments of the present invention, other alternative aspects of the present invention are disclosed in the additional embodiments below.
[0215] Embodiment 1. A system for managing consent, the system comprising:
[0216] A consent database having a user ID, including a unique identifier of a user account, the unique identifier of the user account referring to: a set of data types that the user consents to share; a set of devices that the user consents to share data generated by these devices; a set of consumers with whom the user consents to share data; a memory containing a machine-readable medium, which includes machine-executable code having instructions stored thereon for performing a method; a control system coupled to the memory, the control system including one or more processors, the control system being configured to execute the machine-executable code to cause the control system to: receive from a consumer a request to access data from a user, the data including a timestamp, a user ID associated with the account, and a first type of data; query the consent database to access the user ID and determine whether the user associated with the user ID consents to share the first type of data; and send to the consumer a response indicating whether the consumer is authorized to access the first type of data from the account referring to the user ID.
[0217] Embodiment 2. The system according to Embodiment 1, wherein the control system is further configured to: receive from the user a request indicating that the user has revoked consent to share the first type of data; and send to the consumer a notification indicating that the user has revoked consent to share the first type of data.
[0218] Embodiment 3. The system according to Embodiment 2, wherein the control system is further configured to: send to the user a request to update consent; receive from the user a confirmation of the updated consent; and send to the consumer a notification indicating that the user has updated consent.
[0219] Example 4. The system according to Example 1, wherein the control system is further configured to: send to a consumer an address where the consumer can access first type data; receive from the consumer a request to access the first type data at that address, establish a link between the consumer and a user database including first type data stored with reference to a user ID, and send to the consumer a set of first type data.
[0220] Example 5. The system according to Example 1, wherein the first type data is profile data, movement data, location data, health data, respiratory therapy data, vital sign data, wearable data, heart-related wearable data, gait data, genetic data, social media usage data, exercise data or fitness data.
[0221] Example 6. The system according to Example 1, wherein the types of the devices include mobile phones, wearable fitness trackers, heart rate monitors, pulse oximeters or respiratory therapy devices.
[0222] Example 7. The system according to Example 1, wherein the consent database further includes market rates with reference to each type of data stored.
[0223] Example 8. The system according to Example 1, wherein each of the group of consumers has a reference to the address.
[0224] Example 9. A system for managing third-party access to data, the system comprising: a consent database having a user ID, the consent database having a user ID including a unique identifier of a user account, the unique identifier of the user account referring to: a set of data that the user consents to share, which includes at least first and second type data; a set of devices that the user consents to share data generated by these devices; a memory including a machine-readable medium, which includes machine-executable code having instructions for performing a method stored thereon; a control system coupled to the memory, which includes one or more processors, the control system being configured to execute the machine-executable code to cause the control system to: send a request to share data to a user device associated with the user ID; receive from the user device a consent confirmation to share data, the consent confirmation including: consent to share first type data; a valid time window for consent to share; receive from the user device login information of a third-party account associated with the user ID and a first data device; send a request to retrieve data to the first data device; receive from the first data device a first set of data; process the first set of data to identify a set of first type data; and store the set of first type data in the consent database with reference to the user ID.
[0225] Example 10. The system according to Example 9, wherein processing the first set of data to identify a set of first type data further comprises processing the data to identify GPS coordinates.
[0226] Example 11. The system according to Example 10, wherein processing the first set of data to identify a set of first type data further comprises processing the data to identify data output from an accelerometer, a gyroscope, or a magnetometer.
[0227] Example 12. The system according to Example 10, wherein the control system is further configured to: query a consumer database that references a set of consumers and data receiving addresses to the types of data each consumer has agreed to receive within a threshold market price range, to identify any consumers among the set of consumers who have agreed to receive the first type of data at the current market price of the first type of data; and send the set of first type data to any identified consumers among the set of consumers at the referenced data receiving addresses.
[0228] Example 13. The system according to Example 12, wherein the consumer database references specific characteristics of the types of data that must be included in order to receive data at the market price.
[0229] Example 14. The system according to Example 13, wherein the characteristics include height, weight, and age.
[0230] Example 15. The system according to Example 13, wherein the characteristics include heart rate data.
[0231] Example 16. The system according to Example 14, wherein the characteristics characterize genetic data.
[0232] Example 17. The system according to Example 14, wherein the characteristics include a combination of genetic data and heart rate data.
[0233] Example 18. A system for managing consent, the system comprising: a consent database having a user ID, the consent database having a user ID including a unique identifier of a user account, the unique identifier of the user account referring to: a set of data types that the user consents to share; a set of devices that the user consents to share data generated by these devices; a set of consumer devices with which the user consents to share data; a memory containing a machine-readable medium, which includes machine-executable code having instructions stored thereon for performing a method; a control system coupled to the memory, which includes one or more processors, the control system being configured to execute the machine-executable code to cause the control system to: receive a request from a first of the set of consumer devices to access data from a user, the data including a timestamp, a user ID associated with the account, and a first type of data; query the consent database to access the user ID and determine whether the user associated with the user ID consents to share the first type of data with the first of the set of consumer devices; and send a response to the first of the set of consumer devices, the response indicating whether the first of the set of consumer devices is authorized to access the first type of data from the account referring to the user ID.
[0234] Example 19. The system according to Example 18, wherein the control system is further configured to: receive a request from the user indicating that the user has revoked consent to share the first type of data; and send a notification to the first of the set of consumer devices, the notification indicating that the user has revoked consent to share the first type of data.
[0235] Example 20. The system according to Example 19, wherein the control system is further configured to: send a request to the user to update consent; receive confirmation of updated consent from the user; and send a notification to the first of the set of consumer devices indicating that the user has updated consent.
[0236] Example 21. The system according to Example 20, wherein the control system is further configured to: send to the first of the set of consumer devices the address at which the first of the set of consumer devices can access the first type of data; receive a request from the first of the set of consumer devices to access the first type of data at that address, establish a link between the first of the set of consumer devices and a user database storing the first type of data referring to the user ID, and send a set of the first type of data to the first of the set of consumer devices.
[0237] Example 22. The system according to Example 20, wherein the first type of data is profile data, movement data, location data, health data, respiratory therapy data, vital sign data, wearable data, cardiac-related wearable data, gait data, genetic data, social media usage data, exercise data, or fitness data.
[0238] Example 23. The system according to Example 20, wherein the control system is further configured to: store the first of the group of consumer devices in the consent database as an authorized data consumer referencing the user ID and the consent time window; and once the time window expires, send a notice to the first of the group of consumer devices that the consent has been revoked.
[0239] Example 24. The system according to Example 18, wherein the types of the devices include mobile phones, wearable fitness trackers, heart rate monitors, pulse oximeters, or respiratory therapy devices.
[0240] Example 25. The system according to Example 18, wherein the consent database further includes market rates referencing each type of data stored.
[0241] Example 26. The system according to Example 18, wherein each of the group of consumer devices references an address.
[0242] Example 27. A method, comprising: receiving from a consumer a request to access data from a user, the request including a timestamp, a user ID associated with an account, and a first type of data; querying a consent database to access the user ID and determine whether the user associated with the user ID consents to share the first type of data; and sending to the consumer a response indicating whether the consumer is authorized to access the first type of data from the account referencing the user ID.
[0243] Example 28. The method according to Example 27, further comprising: receiving from the user a request indicating that the user has revoked consent to share the first type of data; and sending to the consumer a notice indicating that the user has revoked consent to share the first type of data.
[0244] Example 29. The method according to Example 27, further comprising: sending to the user a request to update consent; receiving from the user a confirmation of the updated consent; and sending to the consumer a notice indicating that the user has updated consent.
[0245] Example 30. The method according to Example 27 further includes: sending an address to a consumer where the consumer can access the first type of data; receiving from the consumer a request to access the first type of data at the address, establishing a link between the consumer and a user database that includes the first type of data stored with reference to a user ID, and sending a set of the first type of data to the consumer.
[0246] Example 31. The method according to Example 27, wherein the first type of data is profile data, movement data, location data, health data, respiratory therapy data, vital sign data, wearable data, heart-related wearable data, gait data, genetic data, social media usage data, exercise data, or fitness data.
[0247] Example 32. The method according to Example 27 further includes: storing in the consent database the consumer as an authorized data consumer who references the user ID and the time window of the consent; once the time window expires, sending a notice to the consumer that the consent has been revoked.
[0248] Example 33. The method according to Example 27, wherein the type of the device includes a mobile phone, a wearable fitness tracker, a heart rate monitor watch, a pulse oximeter, or a respiratory therapy device.
[0249] Example 34. The method according to Example 27, wherein the consent database further includes a market interest rate that references each type of data stored.
[0250] Example 35. The method according to Example 27, wherein each of the group of consumers references an address.
[0251] Example 36. A computer program product including instructions that, when executed by a control system, cause the computer to perform the method according to any one of Examples 27 to 35.
[0252] Example 37. The computer program product according to Example 36, wherein the computer program product is a non-transitory computer-readable medium.
Claims
1. A system for managing consent, the system comprising: A consent database having a user ID, including a unique identifier of a user account, the unique identifier of the user account referring to: A set of data types that the user consents to share; A set of devices for which the user consents to share the data generated by these devices; A set of consumers with whom the user consents to share data; and The price of the data; A memory containing a machine-readable medium, which includes machine-executable code having instructions stored thereon for performing a method; one or more processors coupled to the memory, the one or more processors being configured to execute the machine-executable code to cause the one or more processors to: Remove information identifying the user; Catalog the set of data types based on characteristics associated with at least one consumer in the set of consumers; Receive from a consumer a request to access data from a user, the data including a timestamp, a user ID associated with an account, and a first type of data; Query the consent database to access the user ID and determine whether the user associated with the user ID consents to share the first type of data; Send to the consumer a response indicating whether the consumer is authorized to access the first type of data from the account referencing the user ID; And In response to receiving a request from the consumer to purchase the first type of data, process payment from the consumer and send the first type of data to the consumer; and An application executed on a user device that stores the first type of data in the set of devices, wherein the application is configured to: In response to a request to purchase the first type of data, cause the first type of data to be sent to the consumer.
2. The system according to claim 1, wherein the one or more processors are further configured to: Receive from the user a request indicating that the user has revoked consent to share the first type of data; and Send to the consumer a notice indicating that the user has revoked consent to share the first type of data.
3. The system according to claim 1, wherein the one or more processors are further configured to: Send to the user a request to update consent; Receive from the user a confirmation of updated consent; and Send to the consumer a notice indicating that the user has updated consent.
4. The system according to claim 1, wherein the one or more processors are further configured to: Send to the consumer an address where the consumer can access the first type of data; Receive from the consumer a request to access the first type of data at the address; and Establish a link between the consumer and a user database including the first type of data stored with reference to the user ID, and send a set of the first type of data to the consumer.
5. The system according to claim 1, wherein the first type of data is profile data, mobility data, location data, health data, respiratory therapy data, vital sign data, wearable data, cardiac-related wearable data, gait data, genetic data, social media usage data, exercise data, or fitness data.
6. The system according to claim 1, wherein the one or more processors are further configured to: Store, in the consent database, the consumer as an authorized data consumer referencing the user ID and the time window of the consent. Once the time window expires, send a notice to the consumer that the consent has been revoked.
7. The system according to any one of claims 1-6, wherein the types of the devices include mobile phones, wearable fitness trackers, heart rate monitors, pulse oximeters, or respiratory therapy devices.
8. The system according to any one of claims 1-6, wherein the consent database further includes a market interest rate referencing each type of data stored.
9. The system according to any one of claims 1-6, wherein each of the group of consumers references an address.
10. A system for managing data access by a third party, the system comprising: A consent database having a user ID, including a unique identifier of a user account, the unique identifier of the user account referencing: A group of data that the user consents to share, which includes at least a first type of data and a second type of data; A group of devices that the user consents to share the data generated by these devices; And A first price associated with the first type of data and a second price associated with the second type of data; A memory containing a machine-readable medium, which includes machine-executable code having instructions stored thereon for executing a method; a control system coupled to the memory, the control system including one or more processors, the control system being configured to execute the machine-executable code to cause the control system to: Send a request to share data to a user device associated with the user ID; Receive, from the user device, a consent confirmation to share data, the consent confirmation including: Consent to share the first type of data; and The time window of the consent to share is valid; Receive, from the user device, login information of a third-party account associated with the user ID and a first data device; Send a request to retrieve data to the first data device, the request including the login information of the third-party account; Receive a first group of data from the first data device by logging in to the third-party account using the login information of the third-party account; Process the first group of data to identify a group of the first type of data; Store the group of the first type of data in the consent database referencing the user ID; and In response to receiving a request to purchase the group of the first type of data from a third party, process the payment from the third party and send the group of the first type of data to the third party.
11. The system according to claim 10, wherein processing the first group of data to identify a group of the first type of data further includes processing the data to identify GPS coordinates.
12. The system according to any one of claims 10-11, wherein processing the first group of data to identify a group of the first type of data further includes processing the data to identify data output from an accelerometer, a gyroscope, or a magnetometer.
13. The system according to any one of claims 10-11, wherein the control system is further configured to: Query a consumer database that references a set of consumers and data receiving addresses to the types of data that each consumer has agreed to receive within a threshold market price range, to identify any consumers in the set of consumers who have agreed to receive the first type of data at the current market price of the first type of data; and Send the set of first type of data to any identified consumers in the set of consumers at the referenced data receiving addresses.
14. The system according to claim 13, wherein the consumer database references specific characteristics of the types of data that must be included in order to receive data at the market price, and the characteristics include at least one of the following: height, weight, and age; heart rate data; genetic data; a combination of genetic data and heart rate data.
15. A system for managing consent, the system comprising: A consent database having a user ID, including a unique identifier of a user account, the unique identifier of the user account referencing: A set of data types that the user has consented to share; A set of devices for which the user has consented to share the data generated by these devices; A set of consumer devices with which the user has consented to share data; A memory containing a machine-readable medium, which includes machine-executable code having instructions stored thereon for performing a method; a control system coupled to the memory, the control system including one or more processors, the control system being configured to execute the machine-executable code to cause the control system to: Receive, from a first one of the set of consumer devices, a request to access data from the user, the data including a timestamp, a user ID associated with an account, and a first type of data; Query the consent database to access the user ID and determine whether the user associated with the user ID has consented to share the first type of data with the first one of the set of consumer devices; And Send a response to the first one of the set of consumer devices, the response indicating whether the first one of the set of consumer devices is authorized to access the first type of data from the account referencing the user ID; and A user device in the set of devices that stores the first type of data, wherein the user device is configured to: Send, in response to the first one of the set of consumer devices being authorized to access the first type of data from the account referencing the user ID, to the first one of the set of consumer devices.
16. The system according to claim 15, wherein the control system is further configured to: Receive, from the user, a request indicating that the user has revoked consent to share the first type of data; and Send a notification to the first one of the set of consumer devices, the notification indicating that the user has revoked consent to share the first type of data.
17. The system according to claim 16, wherein the control system is further configured to: Send a request to the user to update consent; Receive, from the user, a confirmation of updated consent; and Send a notification to the first one of the set of consumer devices indicating that the user has updated consent.
18. The system according to claim 17, wherein the control system is further configured to: Send the address at which the first of the group of consumer devices can access the first type of data to the first of the group of consumer devices; Receive a request from the first of the group of consumer devices to access the first type of data at the address, and Establish a link between the first of the group of consumer devices and a user database that includes the first type of data stored with reference to the user ID, and send a set of the first type of data to the first of the group of consumer devices.
19. The system according to claim 15, wherein the first type of data is profile data, mobility data, location data, health data, respiratory therapy data, vital sign data, wearable data, cardiac-related wearable data, gait data, genetic data, social media usage data, exercise data, or fitness data.
20. The system according to claim 15, wherein the control system is further configured to: Store the first of the group of consumer devices in the consent database as an authorized data consumer with reference to the user ID and the time window of the consent; Once the time window has expired, send a notice to the first of the group of consumer devices that the consent has been revoked.
21. The system according to claim 15, wherein the types of devices include mobile phones, wearable fitness trackers, heart rate monitors, pulse oximeters, or respiratory therapy devices.
22. The system according to claim 15, wherein the consent database further includes market rates with reference to each type of data stored.
23. The system according to claim 15, wherein each of the group of consumer devices references an address.
24. A method for managing consent, comprising: Receiving a set of data types that a user consents to share with a consumer; Removing information that identifies the user; Cataloging the set of data types based on characteristics associated with the consumer; Receiving from the consumer a request to access data from the user, the data including a timestamp, a user ID associated with an account, and a first type of data; Querying a consent database to access the user ID and determine whether the user associated with the user ID consents to share the first type of data with the consumer; Sending a response to the consumer indicating whether the consumer is authorized to access the first type of data from an account referencing the user ID; Processing a payment from the consumer and sending the first type of data to the consumer; and In response to a request to purchase the first type of data, causing the first type of data to be sent to the consumer via an application executed on a user device associated with the user.
25. The method according to claim 24, further comprising: Receiving from the user a request indicating that the user has revoked consent to share the first type of data; And Sending a notice to the consumer indicating that the user has revoked consent to share the first type of data.
26. The method according to claim 24, further comprising: Sending a request to the user to update the consent; Receiving confirmation from the user to update the consent; And Sending a notice to the consumer indicating that the user has updated the consent.
27. The method according to claim 24, further comprising: sending to the consumer an address where the consumer can access the first type of data; receiving from the consumer a request to access the first type of data at the address, and establishing a link between the consumer and a user database including the first type of data stored with reference to the user ID, and sending a set of the first type of data to the consumer.
28. The method according to any one of claims 24-27, wherein the first type of data is profile data, mobility data, location data, health data, respiratory therapy data, vital sign data, wearable data, cardiac-related wearable data, gait data, genetic data, social media usage data, exercise data, or fitness data.
29. The method according to claim 24, further comprising: storing in the consent database the consumer as an authorized data consumer referencing the user ID and the time window of the consent; and sending to the consumer a notice that the consent has been revoked once the time window expires.
30. The method according to any one of claims 24-27, wherein the type of the device includes a mobile phone, a wearable fitness tracker, a heart rate monitor watch, a pulse oximeter, or a respiratory therapy device.
31. The method according to any one of claims 24-27, wherein the consent database further includes a market rate referencing each type of data stored.
32. The method according to any one of claims 24-27, wherein each consumer references an address.
33. A system for managing consent, the system comprising: a consent database having a user ID, including a unique identifier of a user account, the unique identifier of the user account referencing: a set of data types that the user consents to share; a set of devices that the user consents to share data generated by these devices; a set of consumers with whom the user consents to share data; and the price of the data and a market rate referencing each type of data stored; a memory including a machine-readable medium, which includes machine-executable code having instructions stored thereon for performing a method; one or more processors coupled to the memory, the one or more processors being configured to execute the machine-executable code to cause the one or more processors to: remove information identifying the user; catalog the set of data types based on characteristics associated with at least one consumer in the set of consumers; receive from a consumer a request to access data from the user, the data including a timestamp, a user ID associated with an account, and a first type of data; query the consent database to access the user ID and determine whether the user associated with the user ID consents to share the first type of data; send to the consumer a response indicating the price of the first type of data of the account from the user ID; and in response to receiving a request from the consumer to purchase the first type of data, process payment from the consumer and send the first type of data to the consumer; and An application executed on a user device that stores the first type of data in the set of devices, wherein the application is configured to: Send an address to the consumer at which the consumer can access the first type of data; Receive from the consumer a request to access the first type of data at the address; Establish a link between the consumer and a user database that stores the first type of data referenced by the user ID, and send a set of the first type of data to the consumer; and In response to the processing of payment for the first type of data, cause the first type of data to be sent to the consumer.
Citation Information
Patent Citations
Image viewing system, reception-side handheld unit, image server, and image viewing method
CN103649928A
Medical data sharing method based on block chain
CN108717861A
Price assurance engine
US20140324549A1
Secure storage and transmission of medical information
US20160188801A1