Diagnostic Test Equipment and Cloud System for Storing Test Results

By adopting a combination of GUID and encryption keys in medical testing equipment, combining transparent data encryption and modular design, data transmission security and compliance issues are solved, and the secure and reliable data transmission and automated processing of medical testing equipment is achieved.

CN115550043BActive Publication Date: 2025-07-04BECTON DICKINSON & CO
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202211223520.X
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Priority Date
2016-09-23
Filing Date
2017-09-21
Publication Date
2025-07-04
Estimated Expiration
2037-09-21

AI Technical Summary

Technical Problem

The lack of encryption measures for existing medical testing equipment when transmitting data remotely, resulting in insufficient data security and difficulty in meeting compliance and traceability requirements.

Method used

Using a combination of global unique identifier (GUID) and encryption keys, transparent data encryption (TDE) ensures the communication between the assay device and the central database, and uses a modular design to realize barcode scanning and network connection functions to ensure the security and compliance of data transmission.

Benefits of technology

It realizes the security and compliance of data transmission of medical testing equipment, reduces human errors, and improves the traceability and automated processing capabilities of test results.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN115550043B_ABST
    Figure CN115550043B_ABST
Patent Text Reader

Abstract

Certain aspects relate to encryption systems and methods for medical devices. The medical device can include a connection module for establishing a communication channel with a cloud system. After obtaining test results, the device can generate an unencrypted data block including a device identifier and use an encryption key associated with the device identifier to generate an encrypted data block including the device's serial number and the test results. The unencrypted data block and the encrypted data block are transmitted to the cloud system via the communication channel, thereby enabling the device to securely send the test results to the cloud system.
Need to check novelty before this filing date? Find Prior Art

Description

[0001] This application is a divisional application of the patent application with the application number 201780058332.7 and the invention title "Encryption System for Medical Devices" which entered the Chinese national stage from the PCT international application PCT / US2017 / 052807 filed on September 21, 2017.

[0002] Related Applications

[0003] This application claims the priority of U.S. Provisional Application No. 62 / 399,197 filed on September 23, 2016. The entire content of this related application is hereby incorporated by reference in its entirety. Technical Field

[0004] The systems and methods disclosed herein relate to systems and methods for encrypting transmissions from medical tests, and more particularly to lateral flow assay devices. Background Art

[0005] In the field of patient care, immunoassay techniques provide a simple and relatively rapid means of determining the presence of an analyte in a subject's sample. An analyte is a substance of interest or a substance of clinical significance that may be present in a biological or non-biological fluid. Analytes can include antibodies, antigens, drugs, or hormones.

[0006] Typically, the analyte of interest is detected by reacting with a capture agent, thus forming a device that is easier to detect and measure than the original analyte. Detection methods can include changes in absorbance, color, fluorescence, luminescence, surface potential, changes in other optical properties, or any other easily measurable physical property indicating the presence or absence of the analyte in the sample.

[0007] Certain medical systems may be located far from a central server that stores and analyzes the measured analytes. For example, some systems may be located in a doctor's office but transmit data to a central server via a wired or wireless connection. Summary of the Invention

[0008] Immunoassay devices play an important role in fields such as clinical chemistry and have been made into portable devices for use in this field. By routinely performing assays, the presence of specific analytes present in a human or non-human subject suffering from a particular disease or condition can be detected. For example, assays as described herein can be used to detect whether a patient has influenza A, influenza B, RSV, group A streptococcus, or other diseases, whether they are ovulating or pregnant, or whether a particular drug or chemical compound is present in their body, and so on.

[0009] Such assay and assay reader devices are used by skilled clinicians and laypersons and can be located remotely from the location where sample analysis is performed. Such assay and assay reader devices can be located remotely from the system required to maintain a complete patient history and can also be located remotely from other medical record keeping systems (such as pharmacies) that can be used for patient treatment activities. Thus, for example, the assay reader device according to the present disclosure is designed to include a module that communicates directly with a central server system via a wired or wireless connection, thereby providing simplicity and reliability. The assay reader device can also enable simple barcode scanning input of any required additional information while minimizing the number of steps required by the user during sample application and result notification. Since barcode scanning input enables clinics, laboratories, etc. to implement customized test result recording standards, a high level of traceability and compliance can be provided. Some examples can enforce compliance with these standards at the reader level, for example, by pre-configuring the reader to require the input of a specified type of information before transmitting results. As another example, communication between the reader and a centralized database can be used to determine whether the transmitted test data complies with these standards, and if not, an instruction can be sent back to the reader device to prompt the user for any missing information. Any data or instructions transmitted between the assay device and the centralized database can be ensured to be secure by encrypting these communications. In addition, such assay and assay reader devices can be used in a variety of scenarios both inside and outside the clinical environment. Thus, the assay reader device according to the present disclosure can include a module that provides network connectivity to provide test results to one or more centralized databases. BRIEF DESCRIPTION OF THE DRAWINGS

[0010] Aspects of the disclosure will be described below in conjunction with the accompanying drawings, which are provided for illustration and not limitation of the disclosed aspects, where like reference numerals represent like elements.

[0011] Figure 1A A set of exemplary components of an assay reader system is shown.

[0012] Figure 1B Shows Figure 1A the modules and an exemplary assembled reader of the assay reader system of

[0013] Figure 2 A schematic block diagram of an exemplary data network including the disclosed assay reader system is shown.

[0014] Figure 3 A schematic block diagram of an exemplary assay reader device is shown.

[0015] Figure 4is a flowchart depicting an exemplary operational process of the assay reader device disclosed herein.

[0016] Figure 5A Shows an exemplary hospital workflow without a wireless point-of-care testing solution.

[0017] Figure 5B Shows an exemplary hospital workflow implementing a streamlined workflow via the disclosed assay reader device providing a wireless point-of-care testing solution.

[0018] Figure 6 Shows an exemplary data flow of the disclosed assay reader system in an exemplary environment.

[0019] Figure 7 Shows an exemplary data flow of the disclosed assay reader system, which shows that the communication channel is encrypted.

[0020] Figure 8 Shows a schematic diagram of an encrypted channel for transmitting encrypted and non-encrypted data over a communication network 808.

[0021] Figure 9 Shows various examples of display text that can be presented to an operator on the display screen of the assay reader device described herein. Detailed Description

[0022] Embodiments of the present disclosure relate to systems and methods for a modular assay reader device. In one embodiment, the modular assay reader device is configured to receive a plurality of different modules within its housing. In one example, the modules can include a barcode scanning input device and optional network connectivity capabilities. Embodiments of the reader device can be portable, e.g., relatively small and relatively light, and can be powered by a battery or other local electrical storage means. The disclosed reader device can be used in hospitals, clinics, doctor's offices, and other patient care facilities to quickly detect and identify multiple types of biological conditions, such as the presence of antibodies (indicating the presence of a disease-causing agent). The network connectivity module can standardize, track, and electronically connect test results from reader devices across the network, thereby improving patient care outcomes.

[0023] One embodiment of the present invention is a medical or laboratory device as described herein, which uses encrypted communication to ensure the security of any data or instructions transmitted between the laboratory device and the central database. In one embodiment, a globally unique identifier (GUID) is assigned to each laboratory device, and this GUID is permanently stored or burned into a dedicated circuit within the laboratory device. During the communication between the laboratory device and the central database system, the laboratory device can be verified by the database system in the following manner: First, confirm that the globally unique identifier is valid and matches the GUID stored in the database of authentic globally unique identifiers. To protect the globally unique identifier from being copied to an illegal device, the GUID can be transmitted to the central database over an encrypted channel. For example, during any verification transmission of the globally unique identifier to the central database, it can be transmitted over an encrypted channel that implements transparent data encryption (TDE). Otherwise, the GUID may be unencrypted.

[0024] During manufacturing, the GUID of the laboratory device can be associated with the device serial number and an encryption key. When verifying a transmission, the serial number encrypted with the associated encryption key can be transmitted to the central database using the GUID. If the GUID received by the central database is determined to be a valid GUID, the encryption key associated with the GUID can be used to decrypt the received encrypted serial number. If the decrypted serial number matches the serial number associated with the GUID, the device can be verified to the central database system.

[0025] A type of reader device is configured to read or otherwise analyze lateral flow assays, which can test for various medical and environmental conditions or compounds. For example, a lateral flow assay can rely on an immunoassay format in which a test sample flows along a solid matrix by capillary action. A lateral flow assay reader device can read a lateral flow assay strip to detect the presence of hormones, metabolites, toxins, or pathogen-derived antigens. This reading can be accomplished by using a detector that includes one or more sensing elements, such as, but not limited to, PIN detectors, linear array detectors, CMOS imagers, and CCD-based imaging devices, which are configured to detect the presence or absence of lines on the lateral flow assay based on the presence or absence of visible lines on the assay. Some tests performed by the assay reader device are designed to make quantitative determinations, but in many cases, these tests are designed to return or indicate a positive / negative qualitative indication. Examples of assays that can perform such qualitative analysis include blood type tests, most types of urine analysis, pregnancy tests, and HIV / AIDS tests. The assay reader device can identify the results of these tests by autonomously following a pre-programmed decision process or rules. In addition to reader devices configured to analyze lateral flow assays, embodiments of the diagnostic reader devices described herein can analyze other types of assays (such as, but not limited to, molecular assays) and provide diagnostic test results.

[0026] The assay reader device can be a single-step device, where the user only needs to apply the sample before viewing the results and optionally transmit the results to an appropriate hospital, laboratory, or medical record database. Such a single-step device eliminates the need to perform complex and time-consuming processing steps that can lead to errors in the final result. For example, the user can press a single button on the assay reader device to activate the device. Thereafter, the sample cartridge is inserted into the device, which automatically activates the reading process to determine and display the test result based on the sample cartridge, without further user input. In some embodiments with network connectivity capabilities, the determined test result can additionally be automatically sent without the need to transmit further user input to a remote storage device (e.g., to a centralized database) and then from the centralized database to a designated clinician or another database (such as a hospital information system (HIS), a laboratory information system (LIS), or a database maintained by public health agencies such as the CDC, FDA, and WHO). In some embodiments with network connectivity capabilities, the determined test result can be sent directly to a designated clinician or database. As used herein, a remote storage device can be a centralized database, HIS, LIS, a public health agency database, a device of a designated clinician, or any other data storage device that is not physically coupled to the assay reader device.

[0027] The disclosed portable assay device may include a basic assay analyzer having a compartment for receiving a plurality of different modules, e.g., a basic assay reader device. One module may include a barcode scanner for allowing a user to input any desired additional information, e.g., patient identification information, test type, device operation mode, sample information, and any other additional test or patient information related to tests performed by the IVD device. In some embodiments, the device operation mode may be set by the number of clicks or mode of a single button of the basic assay analyzer. Another module may include a barcode scanner and additional network connection elements. This modular design approach enables the assay reader device to expand its functionality, e.g., providing barcode scanning and wireless connectivity while maintaining its portability and cost advantages. By selecting different modules, the user can flexibly determine the optimal functionality required for the settings or applications of the modules themselves. The modules may be optional accessories for the basic assay analyzer, and the basic assay analyzer can also function without a module inserted for reading the inserted assay (e.g., a lateral flow assay test strip). The modules may be exchanged between various analyzers. After insertion, the module can become an integral part of the analyzer.

[0028] As described above, one of the modules may include a barcode reader and a communication component for network connection, e.g., via a wireless connection such as a cellular modem, satellite connection, or Wi-Fi, or via a wired connection. When such a module is inserted into the compartment of the assay reader device and establishes electronic communication with the device's memory and / or processor, the assay reader device is able to send or upload data to a remote repository via the network. Thus, the test data of such an assay reader device can be stored and analyzed by remote devices or personnel individually or collectively. A module with a cellular or satellite modem provides a built-in mechanism for accessing a publicly available network (such as a telephone network or cellular network), thereby enabling the assay reader device to communicate directly with network elements or other IVD devices to achieve electronic test result transmission, storage, analysis, and / or dissemination without separate intervention or action by the user of the device. For example, in certain cases, electronic test result transmission, storage, analysis, and / or dissemination occur automatically when the assay reader device analyzes a patient sample. In another example, electronic test result transmission, storage, analysis, and / or dissemination occur immediately after the assay reader device analyzes a patient sample. In some embodiments, the module may provide a connection to a cloud database (e.g., a server-based data repository). The cloud-based connection module can enable ubiquitous connectivity of the assay reader device without the involvement of a local network infrastructure.

[0029] By using a barcode scanner, a device user can customize the assay reader device to perform a variety of workflows that best suit their environment and compliance requirements. This barcode scanning method provides an easy and error-free way for end-users to customize the diagnostic device. For example, the device operation mode can be set or the type of information required can be specified by scanning a barcode to meet requirements such as, for example, healthcare organization standards, compliance standards, documentation standards, reporting standards, or any other requirements applicable to the test environment.

[0030] In some embodiments, the device operation mode can additionally or alternatively be set by the number of clicks or mode of a single button on the underlying assay analyzer. For example, in some implementations, a single press of the button can start the underlying assay analyzer and set the analyzer to the default operation mode, and the device can implement the default operation mode when a cartridge is inserted. Double-clicking the button can start an alternate operation mode different from the default operation mode. Other numbers of presses or modes of the single button by the user can provide instructions to the device's processor regarding the desired operation mode. Embodiments of the underlying assay analyzer are described herein in connection with a single button, however, other features that enable a user to select and switch between device operation modes are also possible (e.g., but not limited to: a single switch, knob, joystick, or handle).

[0031] An example of a device operation mode is the endpoint reading mode. In the endpoint reading mode, the user prepares and incubates the assay outside the underlying assay analyzer and tracks the development time of the assay. For example, the development time of a flu assay can be 10 minutes, so the user applies the sample to the assay and waits 10 minutes. At the end of 10 minutes, the user inserts the assay into the underlying assay analyzer to obtain the test result. Thus, when operating in the endpoint reading mode, the underlying assay analyzer can provide instructions (e.g., audibly or on a visual display) that direct the user to wait a predetermined time after applying the sample to the assay before inserting the assay into the underlying assay analyzer. In other embodiments, when operating in the endpoint reading mode, the underlying assay analyzer may not display any instructions but may only read the assay after it is inserted into the underlying assay analyzer. After the assay is inserted into the underlying assay analyzer, the device's optical reader can collect image data that represents the assay being analyzed to determine the assay result. In some embodiments, the endpoint reading mode can be the default operation mode of the underlying assay analyzer.

[0032] Another example of an operating mode of the device is the departure mode. Thus, when operating in the departure mode, the basic assay analyzer can provide instructions to the user to insert the assay either immediately after applying the sample or during the application of the sample. In the departure mode according to one embodiment, the user can apply the sample to the assay and immediately insert the assay into the basic assay analyzer. The assay will develop inside the basic assay analyzer, and the basic assay analyzer can record the time elapsed since the assay was inserted. After the end of a predetermined development time, the basic assay analyzer can collect image data representing the assay, analyze the image data to determine the test result, and report the test result to the user. The assay development time can be unique for each test. For example, the influenza assay development time can be 10 minutes, while the streptococcus assay development time can be 5 minutes. In some embodiments, the departure mode can be set by double-clicking a single button on the basic assay analyzer. Further input can indicate to the reader device the assay development time. For example, a barcode scanned by a barcode reader of an inserted module, or a barcode provided on the assay or on the cartridge used to hold the assay, can indicate to the device the type of assay inserted and the development time of the assay. Based on the type of assay, the basic assay analyzer can wait a predetermined amount of time after sample application and insertion before collecting image data representing the assay.

[0033] In the embodiments of the basic assay analyzer described herein, many advantages can be found associated with the ability of the user to select and switch between operating modes of the device. The endpoint reading mode is convenient for use in large laboratories or healthcare service facilities where personnel typically process multiple tests in batches. The departure mode can come into play when performing a single test or when the end user does not want to track the assay development time (or, is not aware of how to accurately track the assay development time or has not been trained in this regard). The departure mode can advantageously reduce or eliminate the occurrence of false test results due to the assay being inserted and imaged too quickly (very early before the assay development time has expired) or too slowly (a long time after the assay development time has expired). Additionally, in the departure mode, the assay reader can operate to capture multiple images of the assay at predetermined time intervals, for example, when a dynamic graph of the assay readings is needed.

[0034] One embodiment of the disclosed basic assay analyzer (e.g., the basic assay reader device described in detail below) includes only a single button on its housing, e.g., a single power button to turn off and turn on the basic assay analyzer. Embodiments of the disclosed basic assay analyzer also implement two different device operation modes (however, more than two device operation modes are also possible). To enable an end user to select and switch between the two device operation modes, the basic assay analyzer may include instructions to implement a double-click function on the power button. After receiving an input to turn on the device by single-pressing the button, an assay cartridge is inserted, which can automatically trigger the endpoint reading mode. When the processor of the device receives an input of double-clicking the power button from the user, the stored instructions can be launched to implement the departure mode. This double-click function provides an end user with a simple and intuitive means to switch between different operation modes of the basic assay analyzer. The double-click function also enables the user to configure the device to operate in the departure mode in real time without any additional configuration steps or additional programming by the user for the basic assay analyzer. It should be understood that as an alternative or supplement to double-clicking to trigger an auxiliary (non-default) device operation mode, instructions for recognizing other click patterns may be provided for the basic assay analyzer, e.g., instructions for recognizing that the user presses the button any predetermined number of times, instructions for recognizing that the button is pressed in a predetermined pattern, and / or instructions for recognizing that the button is held down for a predetermined length of time.

[0035] As described above, other examples of barcode use include providing additional data associated with test result data, including patient identification information, test type, device operation mode, sample information, and any other additional test or patient information related to the tests performed by the IVD device. Certain barcodes can unlock device functions. Certain barcodes can provide or update various types of information that the device uses to analyze assays, determine test results, or perform functions. For example, a scanned barcode can provide assay or reader calibration information to the reader device, which is useful or essential for performing the test. In embodiments where the device does not have wireless network connectivity, test results can be stored in the device's memory, and to access the stored test results, the user can use a barcode scanner to scan a password barcode.

[0036] Although the disclosed device is generally described herein as an assay reader device, it should be understood that the modular system design and network connection aspects described herein can be implemented in any suitable in vitro diagnostic device. For example, the features described herein can be implemented in a reader device that analyzes other types of assays (e.g., but not limited to molecular assays) and can provide diagnostic test results.

[0037] For purposes of illustration, various embodiments will be described below in conjunction with the accompanying drawings. It should be understood that many other implementations of the disclosed concepts are possible and that various advantages can be achieved using the disclosed embodiments.

[0038] Overview of Exemplary Assay Reader Devices and Operations

[0039] Figure 1A A set of exemplary components of the assay reader system 100 is shown. The set of components includes a barcode module 120 and a barcode and connection module 110, which can be lockingly inserted into a compartment 132 of a base assay reader device 130. The set of components also includes a cartridge 140 for securing an assay 144 for insertion into the base assay reader device 130. Figure 1B An exemplary assembly of the base assay reader device 130 and the barcode module 120 is shown, where the cartridge 140 is inserted into a cartridge receiving aperture 134 of the reader 130. Figure 1A and Figure 1B The components of will be discussed together in the following discussion.

[0040] The base assay reader device 130 includes a compartment 132 for lockingly and optionally releasably receiving one of a plurality of different modules, a cartridge receiving aperture 134, a display 136, and a single button 138. The compartment 132 can include two mechanical features for lockingly mating with corresponding mechanical features of the inserted module and electrical features for establishing electronic data communication with the components of the inserted module. The base assay reader device 130 is capable of providing basic assay analysis and data storage functions without any inserted module, and an inserted module can be selected and inserted to expand the basic functions. In embodiments where no module is inserted, a cover can be provided over the opening of the compartment 132. For example, the device 130 can initially be provided with a cover, which can then be removed to insert one of the interchangeable modules.

[0041] The size and shape of the cartridge receiving aperture 134 can be configured such that when an assay is inserted through the cartridge receiving aperture 134, the test region of the assay is aligned with a detector or detector array disposed within the device 130. For example, if the assay is a lateral flow assay test strip, the test region can include one or more of a control region and a test region, where these regions have immobilized compounds that can specifically bind to a target analyte. The detector can implement an adaptive reading technique to improve the specificity of the test results and reduce false positive results by compensating for background and non-specific binding. The basic assay reader device 130 can be configured to achieve fast and accurate assay performance, such as a digital immunoassay configured to detect influenza A + influenza B, RSV, and group A streptococcus within 10 minutes or less. This helps to enable rapid diagnosis and provides more convenience in terms of testing and course of action while the patient is in the office.

[0042] The display 136 of the basic assay reader device 130 can be an LED, LCD, OLED, or other suitable digital display, and in some embodiments can implement touch-sensitive technology. The button 138 can be a mechanical button for activating the basic assay reader device 130. As described above, the device can include instructions that recognize the press pattern of the single button 138 to select the device operation mode. As discussed in more detail below, when the connection module is inserted into the compartment 132 of the device, the button 138 can provide the user with secure one-touch wireless electronic medical record synchronization. For example, with a single press (or press pattern) of the one-touch button, the basic assay reader device 130 can be made ready for use, the test result data can be stored in the device memory, and the test results can be transmitted to the patient's electronic medical record via the connection module. Other embodiments of the device 130 can power on and be ready for use automatically when plugged in or otherwise powered, and thus the button 138 can be omitted. In other embodiments, multiple buttons can be provided on the device 130. The assay reader device can also include a processor and at least one memory, as discussed in more detail below. The basic assay reader device 130 can have data storage and printing capabilities.

[0043] The barcode module 120 includes a barcode scanner 122. The barcode scanner 122 may include one or more photodetectors and an optional light emitting device for reading a barcode. For example, an embodiment of the barcode scanner 122 may include a light source, a lens for focusing the light source onto an object, and a light sensor for receiving light reflected from the object and converting the received light into an electrical signal. Some embodiments of the sensor of the barcode scanner 122 may include an array of many tiny light sensors so that the voltage pattern generated by the array is substantially the same as the pattern in the barcode. The barcode scanner 122 may also include a decoder circuit or software for analyzing the image data provided by the sensor, identifying the barcode pattern in the image data, determining the content associated with the barcode pattern and outputting the content to a processor of, for example, an assay reader device. The barcode module 120 may also include mechanical features for lockingly engaging corresponding features in the compartment 132 of the basic assay reader device 130, and electronic features for establishing electronic data communication with the components of the basic assay reader device 130.

[0044] Although not shown, the barcode module 120 may include information elements, such as memory devices or other active or passive electronic components. Passive information elements may include transistor networks, PROMs, ROMs, EPROMs or other programmable memories, EEPROMs or other reprogrammable memories, gate arrays and PLAs, etc. The information elements may be used to identify the capabilities of the barcode module 120 to an assay reader and / or to verify the barcode scanning capabilities of the barcode module 120 as a module from a particular source or manufacturer.

[0045] The barcode module 120 can ensure high-level traceability and quality control by means of customizable document recording functions, data storage / download and printing capabilities, while also reducing manual transcription and reducing the risk of errors. As used herein, traceability can refer to the ability to verify the location, time, personnel, patient or other information associated with the test performed using the reader device by means of recorded information. Many entities can advantageously access the recorded information in a variety of ways described herein. As described above, a barcode scanner can be used to input test-related data, change device settings, unlock data access or other functions, or change device mode. Test-related data can include user ID, clinician or test administrator ID, sample ID and test kit batch number and / or expiration date, and other test-related information described herein. The multiple operating modes of the assay reader device provide a flexible workflow implemented by barcode scanning.

[0046] In terms of traceability, hospitals, clinics, laboratories, or other healthcare organizations can have internal standards that specify the types of information to be recorded for each test performed to bring test results into compliance with applicable regulations. A barcode scanner can enable a clinician administering a test to enter the required information by scanning a barcode. In some embodiments, the barcode scanning module can be pre-programmed to output a list of the required type of information associated with each test, or to output a prompt to the user to enter any required information that has not been scanned before the test results are sent for storage. In some embodiments, a barcode scanning module with connectivity capabilities can communicate with a centralized database to provide a list of the required type of information. The required type of information can be wirelessly transmitted from the centralized database to the underlying laboratory reader device and displayed to the user. The user can use the barcode scanning module to scan one of a plurality of available barcodes provided to the user to enter the required type of information. Once a barcode associated with the required type of information is scanned, the test results can be associated with the entered information and securely, and in some cases automatically and / or wirelessly, sent to a laboratory information system and / or an electronic medical record. Thus, the test results transmitted to the laboratory information system and / or the electronic medical record are seamlessly and automatically associated with information (such as but not limited to: user ID, clinician or test administrator ID, sample ID, and test kit lot number and / or expiration date), thereby greatly enhancing the traceability of the test results obtained using the methods and systems described herein.

[0047] In some embodiments, the basic assay reader device may allow the end user to configure preset functions, such as whether a patient ID barcode scan or an operator ID barcode scan is required at the start of each test. The configuration of these preset functions can be done by scanning a configuration barcode, which, once decoded by the device, includes instructions for the scan configuration of the preset functions. In one implementation, the healthcare facility administrator can first select one or more barcodes from a set of printed barcodes that correspond to the type of information needed for the administrator's desired configuration of a particular reader device; after such an initial configuration selection, the users within the healthcare facility using the particular reader device can scan the appropriate barcode to enter information corresponding to the preselected functions of the reader device. The reader device can transmit all available information related to the test to a centralized server, e.g., via a connection module, or via a wired connection to another computing device. In one implementation, compliance at the reader level may not be mandatory, and if the end user provides the patient ID via barcode scan, that information will be transmitted along with the test results, otherwise the patient ID field will be left blank. Other implementations may prompt the end user for missing information. If the reader does not have wireless or cellular connectivity capabilities, then local data storage, download, and print options can help ensure compliance and traceability.

[0048] To illustrate the advantageous customization options with a non-limiting example, an administrator within a doctor's office can select data categories A, B, and C and configure the reader device within the office to transmit a report that includes data corresponding to categories A, B, and C, while an administrator at an acute care center can select data categories A, B, D, and E and configure the reader device within the center to transmit a report that includes data corresponding to categories A, B, D, and E. The report customization capability can significantly reduce administrative and record-keeping time. The data obtained is more frequently in compliance with applicable compliance standards because the chance of human error in the report is reduced.

[0049] Figure 9 Exemplary display text that can be presented to the operator of an assay reader device is shown. As described above, embodiments of the systems and methods described herein can allow the end user to customize the type of information that will be stored in association with test results on a particular assay reader device, thereby significantly enhancing the compliance and traceability of test results and reducing transcription and recording errors. In embodiments that include wireless or cellular connectivity capabilities, customized reports that include test results associated with the selected information categories can be automatically transmitted to a remote server. Figure 9The top display in the first column shown exemplarily indicates the display of the assay reader device, which prompts the user to scan a configuration barcode, thereby associating a specific type of information with the test result or prohibiting a specific type of information from being associated with the test result. In this non-limiting example, after reading the "Scan Configuration Barcode" prompt, the user scans a barcode indicating that the assay reader device enables the operator ID function (if the user wishes to associate and store operator ID information with the test result), or the user scans a barcode indicating that the assay reader device disables the operator ID function (if the user does not wish to associate and store operator ID information with the test result). After the user scans the barcode indicating the user's selection, the assay reader device displays text confirming the user's selection. In this non-limiting example, the assay reader device displays to the user "Operator ID Scan Enabled" or "Operator ID Scan Disabled". Then, the assay reader device may request the user to enable or disable other types of information functions, such as but not limited to: sample ID and kit lot ID (e.g., see the exemplary display test in Figure 9 ).

[0050] In the case where the operator ID function is enabled, the assay reader device will now prompt the user to scan the barcode associated with the operator ID for each test event. For example, before prompting the user to insert the assay test strip into the assay reader device for analysis, the assay reader device will display to the user "Scan Operator ID", indicating that the user scans the barcode associated with the user's operator ID. The assay reader device may sequentially query the user for input of a specific type of information according to the previously selected custom configuration settings of the assay reader device. For example, after the user scans the barcode associated with the operator ID, the assay reader device may next prompt the user to scan the barcode associated with the sample ID of the test event (e.g., see the "Scan Sample ID" display in Figure 9 ), provided that the device is configured to request sample ID information. In some cases, the assay reader device will not prompt the user to insert the assay test strip for analysis until all the information required by the specific configuration settings has been entered. In some cases, the assay reader device may display a summary of the configuration settings (e.g., see the exemplary display at the top of the middle column in Figure 9 ).

[0051] The customizable reporting function can be processed on the server side or by one or more remote computing devices that are physically separated from the reader device but receive information from the reader device. For example, test result data and related information from scanned barcodes can be stored in a database of one or more remote computing devices (e.g., a server system), and the remote computing device can generate a customized report that only contains fields of interest to the end user. The end user can include, but is not limited to, the user of the reader device, the administrator who uses the reader device in a healthcare facility, the entity that manages the remote server system, and a public health organization.

[0052] Non-compliant test results can be flagged in the database (e.g., there are blank fields for any information required by internal standards or applicable regulations within a healthcare group). In some examples, statistical analysis can be performed on non-compliant results to identify common sources of non-compliance, such as, but not limited to, non-compliant test results generated from test strips of a specific batch or lot number, non-compliance information transmitted together with test results or test locations of a specific healthcare provider, and non-compliance in reporting frequency or some other defect. In some embodiments, such information can be automatically provided to the healthcare organization administrator to assist in formulating plans to better meet compliance standards. Meeting the requirements of specified information types helps to achieve more meaningful statistical analysis of compliant test results (by standardizing information collected from many different operators, facilities, or healthcare groups), thereby identifying and tracking infectious disease trends and formulating disease management plans.

[0053] Reference Figure 1A , the barcode and connection module 110 also includes the barcode reader 112 as described above and additional connection devices (graphically represented by the connection marker 114). The connection device can be a wireless communication device (such as a cellular modem) for accessing a publicly available and publicly maintained data network. The publicly available network can be a public telephone network, a public cellular network, or other suitable types of publicly available data networks. The barcode and connection module 110 can also include mechanical features for locking and engaging corresponding features within the compartment 132 of the base assay reader device 130, and electronic features for establishing electronic data communication with the components of the base assay reader device 130. This can reduce the management burden and overhead, and also helps to reduce or minimize errors associated with manual result documentation and recording.

[0054] Although not shown, the barcode and connection module 110 may include the information element as described above. The information element may be used to identify the barcode and connection module 110's barcode scanning and network connection capabilities to the assay reader device and / or to authenticate the barcode and connection module 110 as a module from a specific source or manufacturer.

[0055] The barcode and connection module 110 may provide all the functions and advantages of the barcode module 120 and, additionally, provide cellular wireless connectivity or other wireless connectivity. Such connectivity may be used to record test results at multiple sites and integrate them with electronic medical records (EMRs), HIS, LIS, and / or other health record databases. For example, in some embodiments, test results may be sent to a server-based centralized database and then routed to the appropriate medical record, hospital, or laboratory database. The automatic transmission of test results may ensure that the results are automatically recorded in the patient record. Additionally, the automatic transmission of test results may provide real-time alerts to designated medical personnel (e.g., the patient's doctor) of potentially dangerous health conditions of the patient, enabling rapid diagnosis and treatment. Furthermore, the automatic transmission of test results to public health organizations may enable the real-time aggregation and analysis of test result data, thereby identifying infectious disease trends and potentially controlling such trends. Such medical information transmission may be accomplished via a secure end-to-end connection compliant with HIPAA, HITECH, ISO 27001:2013 cybersecurity guidelines, or other industry standards, and the data may be encrypted prior to transmission. Cellular or satellite connectivity may even enable the rapid transmission of test results from locations outside of the standard clinical environment.

[0056] The cartridge 140 can ensure that the assay 144 is correctly aligned within the base assay reader 130. As shown, the cartridge 140 can include a window for exposing the test area of the assay 144. The assay 144 can be, for example, an immunoassay that implements colloidal metal particle technology to provide sensitivity and robust test performance. Alternatively, the assay 144 can be a biological assay, a ligand binding assay, or any other type of diagnostic test that can perform optical imaging to determine the test result. The cartridge 140 can also include a barcode 142 for providing test information (e.g., the type of test), which in some embodiments can be used to configure an automated process run by the device 130 to determine the assay result. The user can scan the barcode 142 of the cartridge 140 using a barcode scanner of a module that engages lockingly with the base assay reader 130 (such as the barcode module 120 or the barcode scanner of the barcode and connection module 110) as a way of inputting information to the base assay reader device 130. Such information can include one or more of patient and / or doctor identification information, information related to the assay test, a barcode password for unlocking the functions of the base assay reader device 130, etc.

[0057] The base assay reader device 130 can include one or more additional data communication ports (not shown), e.g., a USB port. The port can be provided as a general hardware interface of the base assay reader device 130. In the case of using this interface, the base assay reader device 130 can support external peripheral devices, e.g., a printer or a keyboard. The port can enable the base assay reader device to connect to a PC for data downloading. For example, when the base assay reader device is connected to a PC via the USB interface, the reader device can function like a USB drive. In addition, the end user can update the reader device firmware by connecting a USB drive containing the latest firmware revision to the USB port. Further, the USB port provides a convenient way to upload assay calibration data (e.g., calibration data for a particular batch) into the reader device.

[0058] Although not shown, additional module options are available, such as a connection module without barcode features, a wired connection module, and a module with power storage features for extending the battery life of the device, and so on. In some embodiments, the module can be or can include a printer. In some embodiments, the module can be or can include a separate detection unit. Such a detection unit module can be used to run tests of the same or different types as the base assay reader device 130. In some embodiments, the module can be an incubator for culturing an assay before determining the test result. For example, for a lateral flow assay, an incubator module can be used to immobilize the assay and track the development time, and then provide a reminder or indication to the user to remove the cartridge and insert it into the base assay reader device 130 for reading. For a molecular assay, the incubator module can be used for sample preparation and culturing.

[0059] Exemplary Data Network

[0060] Reference is now made to Figure 2 , which shows a schematic diagram of a networked embodiment of the system 200. In the illustrated embodiment, the arrows between certain devices and a cloud 220, such as a public wide area network (WAN) or a public network, indicate that such devices are configured for two-way communication via such a network. If Figure 2 the network element shown in is associated with the arrows pointing to the network element and the cloud 220, then the device is configured to send data to another device via the cloud 220 and receive data from another device via the cloud 220. For example, the arrow 226 indicates that the in vitro diagnostic (IVD) device 204d can be configured for two-way communication with another device on the cloud 220. Although Figure 2 certain devices configured for two-way communication are shown, this is merely illustrative and not intended to be limiting. For example, the in vitro diagnostic (IVD) device 204d can be configured for one-way communication with another device via the cloud 220.

[0061] Figure 2An exemplary schematic diagram representing a patient care facility 202 is shown. The patient care facility 202 may represent a patient facility that administers or provides one or more diagnostic tests to a patient, such as a hospital, a doctor's office, or a clinic. In the illustrated embodiment, the patient care facility 202 is shown to include or incorporate a hospital information system (HIS) or a laboratory information system (LIS) database 203. That is, in the illustrated embodiment, the patient care facility 202 maintains or otherwise provides access to the HIS or LIS database 203. In the illustrated embodiment, the HIS or LIS database 203 is a repository for test results, summary reports, or other data related to patients using the patient care facility 202. In various embodiments, the HIS or LIS database 203 is additionally coupled to one or more processors (not shown) for performing certain processing tasks, such as analyzing data stored in the HIS or LIS database 203.

[0062] In the illustrated embodiment, the patient care facility 202 further includes a plurality of in vitro diagnostic (IVD) devices 204a, 204b, and 204c. However, as shown by the IVD device 204d, the network environment 200 may also include IVD devices located outside the patient care facility environment. In one embodiment, the IVD device is a diagnostic test device, such as a device configured to optically image a lateral flow assay test strip of a biological sample having an application and determine diagnostic test result information based on the image data representing the test strip. It should be understood that any suitable IVD device may be advantageously used with the disclosed system.

[0063] As Figure 2 further shown, each of the IVD devices 204a, 204b, 204c, and 204d may respectively include a network communication device 205a, 205b, 205c, or 205d. For example, the network communication devices 205a, 205b, 205c, and 205d may be provided by a pluggable accessory module that includes a cellular modem or another transceiver device configured to communicate with the cloud 220. In one embodiment, the IVD devices 204a, 204b, 204c, or 204d may establish an encrypted channel with another device on the cloud 220. For example, the IVD device 204a may communicate with Figure 8The cloud system 816 therein establishes an encrypted channel 084. The IVD devices 204a, 204b, 204c, or 204d can transmit test results to the cloud system 816 on the cloud 220 via the encrypted channel. The cloud system 816 can store the test results in the HIS or LIS database 203. In another embodiment, the network communication devices 205a, 205b, 205c, and 205d enable the corresponding IVD devices to communicate with each other or with another network element, as disclosed herein. Additionally, in one embodiment, the network communication devices 205a, 205b, 205c, and 205d enable the corresponding IVD devices to transmit data representing diagnostic test results to a remote resource (such as, the HIS or LIS database 203) for storage and / or further analysis. Although not shown, some IVD devices can be equipped with a barcode scanner module, such as the barcode module 120. In one implementation, the results stored by these devices can be sent to the patient computer 206. In another implementation, the network communication devices 205a - 205d can be connected to the IDV devices 204a - 204d via a USB connection.

[0064] Figure 2 The system 200 is represented by an arrow 221: The patient care facility 202 (and the IVD devices / HIS or LIS database contained therein) is configured to communicate via the cloud 220. In one embodiment, access to the network is at least partially restricted by one or more of a public wide area network and a public network. Additionally, in one embodiment, the disclosed system 200 enables communication between patient care facilities via an encrypted data transfer protocol or other secure data transfer protocol, as described herein.

[0065] The system 200 further includes a patient computer 206, a health institution computer 208, an insurance provider computer 210, and a device manufacturer computer 212. Each of these network elements can communicate with each other directly or indirectly through one or more other devices, and communicate with the patient care facility 202 via the cloud 220, as shown by arrows 222, 223, 224, and 225 respectively. In one implementation, the public wide area network can communicate with another type of public network such as the Internet. For example, Figure 2 the devices shown therein can be configured to communicate with each other via a public wide area network, a public network, or some combination thereof.

[0066] In the illustrated embodiment, each computer enables different parties to communicate with the device manufacturer computer 212 and the IVD devices 204a, 204b, 204c and the HIS or LIS database 203. For example, the patient computer 206 enables a patient to communicate with the device manufacturer computer 212, the health institution computer 208 enables one or more health institutions to communicate with the patient care facility 202, the insurance provider computer 210 enables an insurance provider to communicate with the patient care facility 202, and the device manufacturer computer 212 enables a manufacturer of IVD devices to communicate with the patient care facility 202. The device manufacturer computer 212 may enable the IVD devices 204a, 204b, 204c and 204d to communicate with a data server 212a coupled to the device manufacturer computer 212, particularly to receive necessary data as needed, such as calibration data, firmware or other software and data upgrades. In another embodiment, the IVD devices 204a - 204d communicate securely with a cloud system, such as, Figure 8 the cloud system 816 shown in

[0067] In various embodiments, the system 200 enables the transfer and exchange of data, which includes test results and additional data sent together with the test results. For example, the data transferred between the various network elements of the system 200 may include diagnostic data and information, network information, hardware information and environmental information as described above. In one embodiment, some or all of the data transferred between the various elements of the illustrated system 200 is encrypted to prevent unauthorized access to the transferred data. In addition to protecting the data from interception and unauthorized consumption, such encryption may also verify or maintain the integrity of the transferred data, for example, by providing a checksum mechanism or other mechanism to ensure that all of the transferred data has been received.

[0068] In one embodiment, the patient computer 206, the healthcare institution computer 208, the insurance provider computer 210, and the device manufacturer computer 212 are standard desktop or laptop computers that are suitably accessible. In another embodiment, one or more of the patient computer 206, the healthcare institution computer 208, the insurance provider computer 210, and the device manufacturer computer 212 are mainframe or server computers configured to handle large amounts of data and / or provide complex processing and analysis routines. In this embodiment, the appropriate entity responsible for the computer device shown (e.g., the insurance company responsible for the insurance provider computer) can access some or all of the data uploaded from the IVD device and stored within the system (depending on the purpose of user access). In another embodiment, one or more of the patient computer 206, the healthcare institution computer 208, the insurance provider computer 210, and the device manufacturer computer 212 are portable computers, such as a personal digital assistant (PDA) or a cellular phone, configured to enable a user to access data from a handheld portable device. In an embodiment not shown, one or more medical professionals (e.g., healthcare providers employed at the patient care facility 202) use an appropriate handheld device (such as a PDA, cellular phone, or other handheld portable device) to access data transmitted by the IVD devices 204a, 204b, 204c, and 204d. In this embodiment, after analyzing a patient sample using a diagnostic test of the IVD device, the appropriate healthcare provider can immediately access or be proactively informed of the patient data. It should be understood that in various embodiments, entities other than the Figure 2 entities of the network elements shown in can access the data uploaded by the IVD device as needed to perform the corresponding tasks of those entities.

[0069] In one embodiment, as described above, the IVD device is configured to upload data to one or more database servers. The database servers can be configured to archive test results, aggregate test results into summary reports, or analyze the spatial, temporal, or other correlations of test results. These database servers can additionally be configured to perform other analyses on the data in a suitable manner, depending on the type of data uploaded and the goals of the parties managing and implementing the database servers. The ability of the IVD device to upload data directly to the database servers via the disclosed connection module provides many advantages to the disclosed system. First, patient care facilities can obtain test results from the database servers via a secure Internet or other network connection and store the retrieved results in their own databases (e.g., their own HIS or LIS databases). Additionally, aggregated test reports resulting from the processing by the database servers are highly valuable to public health agencies such as the CDC, FDA, and WHO. Since the disclosed IVD device can transmit diagnostic test result data directly and automatically to the database servers, such reports can be provided in real time.

[0070] Exemplary Assay Reader Device

[0071] Figure 3 FIG. shows a schematic block diagram of a possible embodiment of the internal components of an exemplary assay reader device 300. These components can include a processor 310 linked to and in electronic communication with a memory 315, a working memory 355, a cartridge reader 335, a module interface 345, and a display 350.

[0072] The module interface 345 can include circuitry for reading information from an information element of an inserted module and transmitting the information to the processor 310 for analysis or verification. Thus, the module interface 345 can provide a first signal path that can be used by the device 300 to identify the characteristics of the connection module, the characteristics indicating the presence of a barcode scanner in the connection module and the connection capabilities of the connection module. The module interface 345 can also include paths for establishing electronic communication with a barcode reader, a network transceiver, a power supply, or other electronic components of the inserted module. Thus, the module interface 345 can provide a second signal path configured to receive barcode data from the connection module, the barcode data representing the barcode imaged by the connection module and / or the information or instructions represented by the barcode.

[0073] The cartridge reader 335 can include one or more photodetectors 340 for reading assays stored in the inserted cartridge and any information on the optional inserted cartridge, such as a barcode printed on the cartridge. The cartridge reader 335 can send image data from the one or more photodetectors to the processor 310 for analyzing the image data representing the imaged assay to determine the test results of the assay. The cartridge reader 335 can also send image data representing the imaged cartridge from the one or more photodetectors for determining which of a plurality of automated operation processes is to be implemented for imaging the assay and / or analyzing the image data of the assay. The photodetector 340 can be any device suitable for generating an electrical signal representing incident light, such as a PIN diode or a PIN diode array, a charge-coupled device (CCD), or a complementary metal-oxide semiconductor (CMOS) sensor, and so on. The cartridge reader 335 can also include components for detecting cartridge insertion, such as a mechanical button, an electromagnetic sensor, or other cartridge sensing devices. An indication from this component can instruct the processor 310 to start the automated assay reading process without any further input or instruction from the user of the device 300.

[0074] The processor 310 can be configured to perform various processing operations on the image data received from the cartridge reader 335 and / or the module interface 345 to determine and store the test result data, as will be described in more detail below. The processor 310 can be a general-purpose processing unit implementing the assay analysis function, or can be a processor specifically designed for assay imaging and analysis applications. The processor 310 can be a microcontroller, a microprocessor, or an ASIC, and so on, and in some embodiments can include multiple processors.

[0075] As shown, the processor 310 is connected to the memory 315 and the working memory 355. In the illustrated embodiment, the memory 315 stores the module identification component 320, the test result determination component 325, the data communication component 330, and the test data repository 305. These modules include instructions for configuring the processor 310 of the device 300 to perform various module interface connection, image processing, and device management tasks. The processor 310 can use the working memory 355 to store a set of working processor instructions included in the modules of the memory 315. Alternatively, the processor 310 can also use the working memory 355 to store dynamic data generated during the operation of the device 300.

[0076] As described above, the processor 310 can be configured by a number of modules stored in the memory 315. The module identification component 320 can include instructions that control the electronic communication between the processor and the module interface 345. For example, the module identification component 320 can include instructions that call a subroutine to configure the processor 310 to read information elements of an inserted module to verify the module as compatible with the device 300 and determine the capabilities of the inserted module. The test result determination component 325 can include instructions that call a subroutine to configure the processor 310 to analyze assay image data received from the photodetector 340 to determine the assay result. For example, the processor can compare the image data with a plurality of templates or pre-identified patterns to determine the test result. In some embodiments, the test result determination component 325 can configure the processor 310 to perform an adaptive reading process on the image data from the photodetector(s) 340, thereby increasing the specificity of the test result and reducing false positive results by compensating for background and non-specific binding.

[0077] The data communication component 330 can determine whether a module has been inserted into a device enabled for wireless data transmission and can manage the transmission of test result data to the identified person and / or remote database. For example, the test result data transmission can be based on barcode data received together with the assay image, where the assay image is used to generate the test result and is stored in association with the test result, and where the barcode data is further stored in association with the test result. If the device 300 is not coupled to a module enabled for network communication, the data communication component 330 can implement local storage of the test result and associated information in the test data repository 305. If a local wired or wireless connection is established between the device 300 and another computing device (e.g., a hospital, clinician, or patient computer), the data communication component 330 can prompt the user of the device 300 to scan a password barcode with the inserted module in order to access the data in the repository 305.

[0078] For example, the processor 310 can be configured to control the display 350 to display the captured image data, imaged barcodes, test results, and user instructions. The display 350 can include a flat panel display, e.g., an LCD screen, an LED screen, or other display technology, and can implement touch-sensitive technology.

[0079] The processor 310 may write the following data to the data repository 305, such as data representing a captured image of a barcode and an assay, instructions or information associated with the imaged barcode, and the determined test results. Although the data repository 305 is graphically represented as a conventional disk device, those skilled in the art will understand that the data repository 305 may be configured as any storage medium device. For example, the data repository 305 may include a disk drive (such as a hard disk drive, an optical disk drive, or a magneto-optical disk drive) or solid-state memory (such as flash memory, RAM, ROM, and / or EEPROM). The data repository 305 may also include multiple memory units, and any one of the memory units may be configured to be within the assay reader device 300 or may be external to the device 300. For example, the data repository 305 may include a ROM memory that contains system program instructions stored within the assay reader device 300. The data repository 305 may also include a memory card or high-speed memory that can be removed from the device 300 and is configured to store captured images.

[0080] Although Figure 3 a device is depicted having separate components to include a processor, a cassette reader, a module interface, and a memory, those skilled in the art will recognize that these separate components may be combined in various ways to achieve a particular design goal. For example, in an alternative embodiment, to save costs and improve performance, the memory component may be combined with the processor component.

[0081] Additionally, although Figure 3 multiple memory components are shown (including memory 315 that contains several modules and a separate memory 355 that contains working memory), those skilled in the art will recognize several embodiments that employ different memory architectures. For example, at design time, ROM or static RAM memory may be utilized to store processor instructions for implementing the modules contained in memory 315. The processor instructions may be loaded into RAM to facilitate execution by the processor 310. For example, the working memory 355 may include RAM memory into which instructions are loaded before being executed by the processor 310.

[0082] Exemplary Operating Procedure of Assay Reader Device

[0083] Figure 4 is a flowchart depicting an exemplary operation process 400 of the assay reader device disclosed herein. In some embodiments, the process 400 may be implemented by the assay reader device 130 and / or the processor 310.

[0084] At block 405, the processor 310 may receive a power-on indication, for example, in response to a user pressing a single button located on the assay reader device.

[0085] At block 410, the processor can identify whether a module is inserted into a bay of the assay reader device, and if so, can identify the capabilities of the inserted module. As described above, these capabilities can include one or more of barcode scanning and network connectivity (including cellular or satellite network connectivity).

[0086] At decision block 415, the processor 310 can identify whether the capabilities of the inserted module include barcode scanning or barcode scanning and network connectivity.

[0087] If the capabilities of the inserted module include barcode scanning, process 400 can transition to block 420 to receive input via the barcode scanner of the inserted module. Such input can include information stored in association with test results and / or information for configuring the operation of the assay reader device, e.g., instructions related to an imaging procedure for obtaining image data of the inserted assay. In some embodiments, device operation can be configured via the button press mode described above. At block 425, process 400 can include: receiving an assay test holding cartridge in a receiving aperture within the assay reader device, imaging the assay, and determining a test result based on the image data representative of the assay. Block 425 can be implemented as any of the disclosed reader operation modes, such as but not limited to: endpoint read mode or away mode. At block 430, the processor 310 can display and locally store the test result and any associated data.

[0088] At decision block 435, the processor can determine whether to perform an additional test, e.g., by receiving an indication that an additional barcode has been scanned (by looping back to block 420) or an additional cartridge has been inserted (by looping back to block 425). In such a case, the process can loop back to blocks 420 - 430 in the order shown or with blocks 420 and 425 swapped.

[0089] If the inserted module capabilities include bar code scanning and network connectivity, process 400 can transition to block 440 to receive input via the bar code scanner of the inserted module. Such input can include information stored in association with test results and / or information for configuring the operation of the assay reader device, e.g., instructions related to an imaging procedure for obtaining image data of the inserted assay, or instructions related to the location where test result data should be transmitted. In some embodiments, device operation can be configured via the button press mode described above. At block 445, process 400 can include: receiving an assay test holding cartridge in a receiving aperture within the assay reader device, imaging the assay, and determining a test result based on the image data representative of the assay. Block 445 can be implemented as any of the disclosed reader operation modes, e.g., but not limited to: end point read mode or leave mode.

[0090] At block 450, processor 310 can display and locally store the test result and any associated data, e.g., the assay image used to generate the test result and additional information provided by the scanned bar code. Additionally or alternatively, processor 310 can display the test result and optional any associated data via the network and transmit it to a destination database or contact. For example, in some embodiments, this can be achieved by a connection module 110 inserted into and in electronic communication with the base assay reader device 130.

[0091] At decision block 455, the processor can determine whether to perform an additional test, e.g., by receiving an indication that an additional bar code has been scanned (by looping back to block 440) or an additional cartridge has been inserted (by looping back to block 445). In such a case, the process can loop back to blocks 440 - 450 in the order shown or with blocks 440 and 445 swapped.

[0092] If processor 310 determines at either block 435 or 455 not to perform an additional test (e.g., based on no activity from any sensors of the assay reader device), process 300 can transition to block 460. At block 460, processor 310 can wait for a predetermined period of time before turning off the assay reader device.

[0093] Exemplary Hospital Workflow

[0094] Figure 5AAn exemplary hospital workflow without a wireless point-of-care testing solution is shown. As shown, samples are collected and test results are provided at the point of care. Embodiments of the reader devices described herein can provide test results in ten minutes or less. Subsequently, for manual recording of the results, the results are manually recorded in a log and then manually entered into a laboratory information system or an electronic medical record. After the results are entered into the laboratory information system or the electronic medical record, the doctor can access the test results and provide patient care. In such a workflow, the doctor must wait for the manual recording to be completed before being able to view the test results and provide patient care.

[0095] Figure 5B An exemplary hospital workflow that implements a streamlined workflow via the disclosed assay reader device that provides a wireless point-of-care testing solution is shown. As shown, samples are collected and test results are provided at the point of care. Embodiments of the reader devices including a network communication enabling module described herein can provide test results in ten minutes or less. The results are automatically transmitted directly from the point of care via the network to the laboratory information system or the electronic medical record. The doctor can directly view the transmitted results at the point of care via the laboratory information system or the electronic medical record, thus facilitating earlier patient care. In this workflow, the doctor can access the patient's test results while the patient is still in the office without having to wait for the manual recording of the test results, thus enabling faster treatment of the patient.

[0096] One advantage of the basic assay reader device described herein is that each device can be upgraded at any time, for example, by equipping it with new modules, thus providing a scalable platform to meet the growing needs of the healthcare community. The basic assay reader device can receive compartments via modules to incorporate other test platforms and instruments. In addition, a single assay reader device can be used for multiple functions with the aid of interchangeable modules. In one example, a healthcare provider can purchase and use the basic assay reader device without any of the aforementioned modules. As the provider continues to expand the capabilities of the reader device, requiring more functions or being able to purchase additional resources, the provider can purchase one or more modules as needed to meet its specific requirements. The functionality of the device can be quickly and easily expanded by inserting the modules into the basic assay reader device without making any modifications to the previously acquired basic assay reader device. As another example, a healthcare provider can purchase a kit with the basic assay reader device and one or more modules, and then develop a new barcode scanner module with additional functions. The provider can purchase a new barcode scanner at any time and use the previously acquired basic assay reader device after replacing the old module with the new one. In another example, some other components in the barcode scanner or the module may malfunction or be damaged. Spare parts can be used with the basic assay reader device while the first barcode scanner is being repaired.

[0097] Other advantages of the disclosed basic assay reader device with a network connection module are as follows: Integration with a single access point to electronic medical records and laboratory information systems enables the rapid provision of test results, so that decisions can be made while the patient is on-site. Such automated recording allows doctors to access test results in advance, helping to speed up the patient care process. Thus, results can be provided to doctors almost immediately after the test is completed, regardless of the test location. Compared with systems that require manual entry of identification information, the disclosed basic assay reader device with a barcode scanning module reduces transcription errors.

[0098] Exemplary Workflow and Environment

[0099] One embodiment is a diagnostic assay device that communicates with a cloud-based server system. The cloud-based server includes a cloud connection solution that enables an assay reader system or an in vitro diagnostic device (e.g., BD Veritor TM Plus Analyzer) to automatically record test results in the patient health record stored in the hospital or laboratory LIS or EMR. The connection solution has in-laboratory components and cloud components. The test results received from the connected assay reader system are verified and processed and transmitted to the EMR, LIS, or intermediate device of the patient care facility.Figure 6 An exemplary data flow of the disclosed assay reader system in an exemplary environment is shown.

[0100] In Figure 6 , an assay reader system is shown that communicates with an operator's cloud system via a cellular wireless network. The cloud system includes a customer database for aggregating and storing test result data from multiple connected assay devices, where these assay devices belong to a specific customer but are located both inside and outside a patient care facility. The data in the customer database can be used for future analysis related to clinical or operational investigations of devices that belong only to that customer. The cloud system may also include an aggregation database for aggregating and storing data from multiple connected assay devices of multiple customers. For example, this can be used for future analysis to determine geographical or other data related to specific infection patterns. Thus, if, for example, a viral infection is spreading in the southwestern United States, the aggregation database can determine the location and spread of the infection based on aggregated data from many assay devices indicating the infection rate and the known address locations of the assay devices. The cloud system also includes a solutions database that can be used to store information related to the customers and owners of assay reader systems on the market. An encryption system or module that ensures communication between the assay reader system and the operator cloud system may also be included in the cloud system.

[0101] Figure 6 A patient care facility linked to the cloud system via an LIS module is also shown. This enables the patient care facility to receive data and information related to its patients from the cloud system. Thus, if an assay reader system is used to test a patient at a patient care facility, the data is securely transmitted to the cloud system along with the patient identifier. The patient care facility system can securely read or send the results of assays running on the assay reader system so that it can store and manage the care of its patients. For example, the results of any tests performed on the assay reader system can be transmitted to the patient care facility to notify the healthcare workers within the facility, and the healthcare worker can take appropriate steps to inform the patient and address the patient's healthcare needs. As described in more detail below, securing and encrypting the communication between the assay reader system and the cloud system and between the patient care facility and the cloud system can result in more robust communication and help the system comply with HIPAA and other legal requirements for maintaining the confidentiality of patient information. The protocol for encrypting the communication between the assay reader system, the cloud system, and the patient care facility can be based on the Secure Hypertext Transfer Protocol (HTTPS) protocol and the Advanced Encryption Standard (AES) 256-bit encryption.

[0102] Figure 7Shows an exemplary data flow of the disclosed assay reader system, which shows that the communication channel is encrypted. As shown, multiple assay readers are connected to the operator cloud system via an encrypted Secure Hypertext Transfer Protocol (HTTPS) or Transport Layer Security (TLS) channel. Data is sent to a series of servers that can store the data in an encrypted data file within the cloud system. Additionally, any data received can be stored in an encrypted format. For example, Transparent Data Encryption (TDE) (TDE is a technique for securely encrypting database files before storage) can be used to encrypt the received test results. TDE provides file-level encryption so that the "at rest" data is encrypted without the need to transfer data between two components to encrypt it.

[0103] Virtual Machine

[0104] Applications within the laboratory can be installed on virtual servers. The specifications of an exemplary virtual machine are listed below.

[0105] Hardware Specifications

[0106] The cloud infrastructure of the shown cloud connection solution employs redundant virtual machines in a high-availability environment that optimizes performance and uptime. The operator of the cloud connection solution is responsible for managing these machines, including backup and monitoring of their performance.

[0107] The cloud connection solution can include one virtual machine or physical machine installed on the infrastructure of a patient care facility to process test results and pass them on to the LIS, EMR, or intermediate device. The requirements for this machine can be as follows:

[0108] Dual-core processor;

[0109] Minimum 8GB RAM (16GB recommended);

[0110] Windows Server 2012 R2;

[0111] .NET 4.5.1;

[0112] IIS v8.5;

[0113] ASP.NET (installed as part of IIS);

[0114] Microsoft SQL 2012 Enterprise or MS SQL 2014 Enterprise with mixed-mode authentication enabled (an instance of the patient care facility can be used);

[0115] 250GB disk storage space;

[0116] Internet access; and / or

[0117] Google Chrome or IE 11.0.

[0118] In one embodiment, the patient care facility is responsible for controlling access to this machine. In some embodiments, it is recommended that access to the machine be restricted to only necessary users and that remote access be disabled. If service is required, authenticated remote access can be enabled for the service call and then removed immediately after the service is completed. The default password should be changed, and the use of removable media should be restricted.

[0119] Operating System

[0120] Windows Server 2012 R2 can be used for all cloud and on-premise machines.

[0121] Network Ports and Services - Cloud Computer

[0122] Cloud virtual machines can use standard Internet ports 80 and 443. Additionally, port 4155 is used for remote updates. Ports 3389 (Remote Desktop Protocol (RDP)) and 8172 (Web Deployment) are only opened when needed.

[0123] The following services are deployed on the cloud virtual machines:

[0124] Splunk forwarder for app-level monitoring;

[0125] Operations Management Suite (OMS) agent for transferring server data to OMS (and System Center Operations Manager (SCOM));

[0126] Snort agent for intrusion detection;

[0127] Shavlik for remote updates; and / or

[0128] Windows Antimalware for virus and malware protection.

[0129] Network Ports and Services - On-Premises Machine

[0130] Site (on-premise) virtual machines or physical machines only need to have the standard Internet port 443 open. For any other ports on this machine, it can be recommended that the patient care facility not open them.

[0131] The following additional services are required for on-premise virtual machines or physical machines other than those loaded with IIS v8.5 as part of Windows Server 2012 R2 on-premise virtual machines or physical machines.

[0132] Sensitive Data Transmitted

[0133] In one embodiment, due to concerns regarding data privacy and the security of sensitive data, the cloud connection solution supports the following standards:

[0134] Defense Intelligence Agency Security Technical Implementation Guide;

[0135] NSA Information Assurance Guide;

[0136] FDA Cybersecurity Guide;

[0137] Health Insurance Portability and Accountability Act (1996); and / or

[0138] Health Information Technology for Economic and Clinical Health Act.

[0139] The following sensitive data elements can be transmitted from the assay reader system to the BD Cloud and from the BD Cloud to the site machine:

[0140] Sample ID - configured to capture the accession number or the patient's medical record number (MRN); and / or

[0141] Operator ID.

[0142] In some embodiments, the cloud connection service treats all data as sensitive data. During transmission, all data can be encrypted using TLS over HTTPS. Data sent from the device uses TLS 1.1. All other network traffic uses TLS 1.2.

[0143] Sensitive Data Stored

[0144] In one example, due to concerns regarding data privacy and the security of sensitive data, the cloud connection solution supports the following standards:

[0145] Defense Intelligence Agency Security Technical Implementation Guide;

[0146] NSA Information Assurance Guide;

[0147] FDA Cybersecurity Guide;

[0148] Health Insurance Portability and Accountability Act (1996); and / or

[0149] Health Information Technology for Economic and Clinical Health Act.

[0150] The cloud connection solution stores the following sensitive data elements based on the results sent by the assay reader system:

[0151] Sample ID - configured to capture the registration number or the patient's MRN; and / or

[0152] Operator ID

[0153] In some embodiments, the cloud - connected solution treats all data as sensitive data. Static encryption of all data is performed using MS SQL TDE with 256 - bit encryption. This includes temporary storage such as queues.

[0154] Malware Protection

[0155] As an example, due to malware protection involved, the cloud - connected solution can support the following standards:

[0156] Defense Intelligence System Agency Security Technical Implementation Guide;

[0157] NSA Information Assurance Guide;

[0158] FDA Cybersecurity Guide; and / or

[0159] Health Information Technology for Economic and Clinical Health Act.

[0160] Malware Protection - Cloud Computer

[0161] The cloud - connected solution can use Windows Defender for anti - malware protection on all cloud virtual machines. The cloud virtual machines receive updates for virus and malware definitions monthly. The cloud computers can also use AppLocker to control access to the installation and running of applications.

[0162] Malware Protection - On-Premises Machine

[0163] Anti - malware for on - premise assets can be managed by the patient care facility, including regular updates. It is recommended to use AppLocker or other mechanisms to control access to the running of applications.

[0164] Verify Authorization

[0165] In one embodiment, due to verification and authorization involved, the cloud - connected solution can support the following standards:

[0166] Defense Intelligence System Agency Security Technical Implementation Guide;

[0167] National Institute of Standards and Technology (NIST) "Framework for Improving Critical Infrastructure Cybersecurity" February 12, 2014;

[0168] NSA Information Assurance Guide;

[0169] FDA Cybersecurity Guidance;

[0170] Health Insurance Portability and Accountability Act (1996); and / or

[0171] Health Information Technology for Economic and Clinical Health Act.

[0172] In some embodiments, the operator of the cloud connection solution implements best practices for certificate management and verification. For access, two-factor identification using Active Directory Federation Services (ADFS) is required. A strong password policy is mandatory for the operator, including minimum length, hashing, forced reset, lockout, and timeout. Access rights are revoked for employees with terminated relationships or changed roles. Application components are protected by whitelisting and access tokens. TLS encryption can be used to secure all communications.

[0173] The operator of the cloud connection solution uses role-based access control (RBAC) for authorization. Each role has a specific and limited scope of functions, and each user is assigned a role.

[0174] Network Control

[0175] Due to network control involved, the cloud connection solution supports the following standards:

[0176] Defense Intelligence Agency Security Technical Implementation Guide; and / or

[0177] NSA Information Assurance Guide.

[0178] The cloud servers including the system comply with the Defense Intelligence Agency Security Technical Implementation Guide (DISA STIG) and are maintained accordingly for all supported Windows operating system versions.

[0179] The operator of the cloud connection solution can use virtual networks and IP restrictions to prevent access to application services that process sensitive data or communicate with repositories. All network traffic is TLS 1.2 over HTTPS. Servers are protected by a firewall system and scanned regularly to ensure that vulnerabilities are found and patched quickly. The operator can perform annual penetration tests to ensure security is maintained when vulnerabilities are discovered in the industry. All services have quick failover points and redundancy to safeguard your data security.

[0180] The on-premises machine may not require an Internet endpoint facing the public. Applications running at the client location do not require inbound ports to traverse data between remote applications, services, and devices and cloud application services. Outbound communication via TLS (port 443) is used for hybrid cloud and on-premises communication. For the purpose of virtual or physical machines provided by the institution, it is recommended that patient care facilities comply with the Defense Intelligence Agency Security Technical Implementation Guide (DISA STIG).

[0181] Encryption

[0182] Due to encryption involved, the cloud connection solution can support the following standards:

[0183] Defense Intelligence Agency Security Technical Implementation Guide;

[0184] National Institute of Standards and Technology (NIST) "Framework for Improving Critical Infrastructure Cybersecurity" February 12, 2014;

[0185] NSA Information Assurance Guide;

[0186] FDA Cybersecurity Guide;

[0187] Health Insurance Portability and Accountability Act (1996); and / or

[0188] Health Information Technology for Economic and Clinical Health Act.

[0189] MS SQL TDE with 256-bit encryption can be used to encrypt all stored data. This includes temporary storage such as queues.

[0190] All test results sent from the assay reader system are encrypted using TLS 1.1 with AES 128-bit encryption.

[0191] TLS 1.2 with AES 256-bit encryption is used to encrypt all other data network traffic.

[0192] Figure 8 A schematic diagram of an encrypted channel 804 for transmitting encrypted and unencrypted data via a communication network 808 is shown. Figure 2 The cloud 220 in is an example of the communication network 808. The network can include a public network (e.g., a cellular network) and / or a public wide area network. The encrypted channel 804 can use an encryption method to securely transmit data 812 from the assay reader system 204 to the cloud system 816. The cloud system 816 can implement Figures 6 to 7The cloud connection solution shown in [Figure 0]. The encryption method used by the assay reader system 204 to create the encrypted channel 804 includes symmetric key or asymmetric key public key cryptography. For example, Transport Layer Security (TLS) 1.1 or 1.2 with 256-bit encryption of the Advanced Encryption Standard (AES) can be used to create the encrypted channel 804. As another example, TLS 1.1 with 128-bit AES encryption can be used to encrypt the test results from the assay reader system 204, and other data between the assay reader system 204 and the cloud system 816 can be encrypted using TLS 1.2 with 256-bit AES encryption. An encryption key unique to the assay reader system 204 can be used to create the encrypted channel 804, so that no other assay reader system 204 can use this key to create an encrypted channel with the cloud system 816. In some embodiments, more than one assay reader system shares an encryption key for creating the encrypted channel.

[0193] The data 812 transmitted through the encrypted channel 804 can include multiple data blocks. These data blocks can include a globally unique ID (GUID) or a universally unique ID (UUID) 820, the serial number 824 of the assay reader system 204, and the test results 828. Additionally or alternatively, the transmitted data 812 can include a manufacturer code, the model of the assay reader system 204, the catalog number of the test, patient information including the patient's name, or technician information including the name of the technician who has performed the test. The GUID 820 can be unique to the assay reader system 204, so that no two assay reader systems have the same GUID 820. The GUID can have universal uniqueness. The GUID 820 may be invisible on the assay reader system 204.

[0194] The serial number 824 can be unique to the assay reader system 204, so that no two assay reader systems can have the same serial number. The serial number 824 can be visible on the assay reader system 204. In some embodiments, it may be advantageous to encrypt the serial number (e.g., because the serial number 824 can be visible on the assay reader system 204). The encryption key used to encrypt the serial number 824 can be unique to the assay reader system 204, so that no other assay reader system can use this key to encrypt its serial number. In some embodiments, other data blocks (e.g., manufacturer code, model, or catalog number of the test) can be encrypted.

[0195] The cloud system 816 can associate the GUID 820, the serial number 824, and the encryption key used to encrypt the serial number 824 with the assay reader system 204. The cloud system 816 can store this association in a database configured to store authentication information. Thus, the assay reader system 204 can be authenticated. For example, the cloud system 816 can use the GUID 820 to determine the unique encryption key for the analyzer and use it to decrypt the encrypted serial number and the received encrypted test results to obtain the serial number 824 and the test result 828. Since the GUID 820 is uniquely associated with the encryption key used to encrypt the serial number 824 and the test result 828, the cloud system 816 can obtain the serial number 824 and the test result 828 by decrypting the encrypted serial number and the test result. To successfully authenticate the reader system 204 before processing, any one of the received test result 828, GUID 820, serial number 824, and the encryption key used to encrypt the serial number must all match the corresponding one of the assay reader system 204 stored in the database. As another example, each device 204 has two unique identifiers. One of the unique identifiers is the serial number 824 of the device, which is located outside the device and visible to the user. The other identifier is the GUID 820, which is embedded in the device 204 and can only be accessed programmatically. These two numbers are paired during manufacturing and can only be seen by authorized personnel. Additionally, there is a unique encryption key that is private and assigned during manufacturing and associated with the serial number 824 and the GUID 820. Encryption algorithms (such as the AES 256 encryption algorithm) can be used to encrypt the test results before secure transmission to the cloud system 816. Thus, in some embodiments, secure cellular communication enables the assay reader system 204 and the cloud system 816 to automate the result recording in the patient health record (LIS / EMR) via the cloud connection solution implemented by the cloud system 816.

[0196] After successful verification of the assay reader system 204, the cloud system 816 can store the test results 828 in a database configured to store test results. Subsequently, the test results can be accessed or retrieved by the assay reader system 204. The assay reader system 204 needs to provide the GUID 820 and the encrypted serial number to access or retrieve the test results 828. The assay reader system 204 can provide the information identifying the test results 828 to the cloud system 816 for accessing or retrieving the test results 828. Such information identifying the test results 828 can include the manufacturer code identifying the manufacturer of the assay reader system 204, the model of the assay reader system 204, the catalog number of the test performed to generate the test results 828, patient information, and technician information. The stored test results 828 can be associated with other identifying information, such as the catalog number of the test performed, the patient name, and / or the name of the technician performing the test.

[0197] Audit Logging

[0198] Reference Figure 6 and Figure 7 Since it involves logging and traceability, the cloud connection solution supports the following standards:

[0199] Defense Intelligence Agency Security Technical Implementation Guide;

[0200] NSA Information Assurance Guide;

[0201] FDA Cybersecurity Guide; and / or

[0202] Health Information Technology for Economic and Clinical Health Act.

[0203] The logging function of the system is described below:

[0204] Record all security events, such as user logins, logouts, access requests, user invitations and permissions, or role changes. This includes both successes and failures.

[0205] Record all database create, read, update, and delete (CRUD) operations.

[0206] Record all non-security-based system activities.

[0207] Computer logs (Cyber Log) controlled by the healthcare institution can be enabled on the laboratory machines, thereby writing all logs to a separate institution-specified database. The institution controls the location and access rights of this database, and BD users cannot view or modify this log.

[0208] Debug logging (disabled by default) can be turned on to record a finer granularity of system processing and details related to program execution (for troubleshooting abnormal operations).

[0209] All logs can be encrypted using MS SQL Transparent Data Encryption (TDE) with 256 AES encryption. Access Control Levels (ACLs) are used to restrict the logging code from applications to only write user accounts. Read-only user accounts are used for application code that reads or generates log reports. This is restricted by access control to appropriate accounts.

[0210] All security, activity, and change logs are saved for at least 90 days. Debug logs are saved as long as necessary to resolve issues. Network logs controlled by healthcare facilities are maintained by the facility.

[0211] The cloud connectivity solution records important details, including users, dates and times, events, results (if applicable), process / computer or other location information.

[0212] Remote Connection

[0213] Remote installation and support can be the primary method for on-site machine setup, configuration, and troubleshooting.

[0214] Remote installation requires access to a virtual or physical machine to install on-site components. Remote access should follow the healthcare facility's remote access IT recommendations.

[0215] Implementation, configuration, and post-go-live support activities are performed by authorized service specialists of the cloud connectivity solution operator. These activities are performed with the help of the operator's Remote Support Services (RSS) tool.

[0216] RSS enables the operator to provide remote customer service. All communications (including remote access) occur within an SSL encrypted session over port 443 (inbound rules only).

[0217] Service Handling

[0218] Service specialists are trained in data privacy and PHI handling. Service specialists are granted appropriate role-based access to cloud and / or on-site components. Primary support staff can access sensitive and operational data but not PHI. Additionally, installation, maintenance, and normal support activities do not anticipate and do not require PHI exposure. Service specialists are trained on the operator's policies regarding PHI handling, including procedures for unintentional exposure. All such interactions between service specialists and cloud connectivity solution components can be audited in addition to remote activities performed using RSS.

[0219] End of Life and End of Support

[0220] Cloud connectivity solutions may not have an end-of-life / end-of-support plan.

[0221] Secure Coding Standard

[0222] Operators of cloud connectivity solutions can adopt design controls to ensure that security is embedded in the core software infrastructure. The operator complies with current or future industry best security coding standards (including the Open Web Application Security Project (OWASP) security coding standards) and regularly runs static code analysis and vulnerability scans to ensure that the code complies with the standards. The operator uses CheckMarx and HP Fortify for static code analysis. BD uses Tenable Nessus and OpenVAS for vulnerability scans.

[0223] System Hardening Standard

[0224] All cloud virtual machines support the Defense Intelligence Agency Security Technical Implementation Guide (DISA STIG) and the NSA configuration standards for Department of Defense Information Assurance (DOD IA) and IA-enabled devices / systems for Windows Server 2012 R2.

[0225] Patient care facilities are responsible for the security of on-premises virtual or physical machines according to their IT policies. It may be advisable for the operator to follow the Defense Intelligence Agency Security Technical Implementation Guide (DISA STIG) and the NSA configuration standards for DOD IA and IA-enabled devices / systems for Windows Server 2012 R2.

[0226] Risk Summary

[0227] Cachable HTTPS responses may not be disabled.

[0228] Unless otherwise indicated, browsers can store local cache copies of the content received from web servers. Some browsers (including Internet Explorer) cache content accessed via HTTPS. If sensitive information in an application response is stored in the local cache, then this can be retrieved by other users who access the same computer in the future.

[0229] Implementation Systems and Terminology

[0230] The embodiments disclosed herein provide systems, methods, and apparatuses for a modular reconfigurable assay reader. Those skilled in the art will recognize that these embodiments can be implemented in hardware or in a combination of hardware and software and / or firmware.

[0231] The assay reader device may include one or more image sensors, one or more image signal processors, and a memory including instructions or modules for performing the above processes. The device may also have a processor for data, loading instructions and / or data from the memory, one or more communication interfaces, one or more input devices, one or more output devices (such as a display device), and a power supply / interface. The device may additionally include a transmitter and a receiver. The transmitter and the receiver may be collectively referred to as a transceiver. The transceiver may be coupled to one or more antennas for transmitting and / or receiving wireless signals.

[0232] The functions described herein may be stored as one or more instructions on a processor-readable or computer-readable medium. The term "computer-readable medium" refers to any available medium that can be accessed by a computer or a processor. By way of example and not limitation, such a medium may include RAM, ROM, EEPROM, flash memory, CD-ROM or other optical disk storage, magnetic disk storage or other magnetic storage devices, or any other medium that can be used to store the desired program code in the form of instructions or data structures and that can be accessed by a computer. As used herein, disk and optical disk include compact disc (CD), laser disc, optical disc, digital versatile disc (DVD), floppy disk, and Blu-ray disc, where disks typically reproduce data magnetically, while optical discs reproduce data optically by laser. It should be noted that the computer-readable medium can be tangible and non-transitory. The term "computer program product" refers to a computing device or processor combined with code or instructions (e.g., "program") that can be executed, processed, or computed by the computing device or processor. As used herein, the term "code" may refer to software, instructions, code, or data that can be executed by a computing device or processor.

[0233] The various illustrative logical blocks and modules described in connection with the embodiments disclosed herein can be implemented or performed by a machine, such as, a general purpose processor, a digital signal processor (DSP), an application specific integrated circuit (ASIC), a field programmable gate array (FPGA) or other programmable logic device, discrete gate or transistor logic, discrete hardware components, or any combination thereof designed to perform the functions described herein. The general purpose processor may be a microprocessor, or, the processor may be a controller, a microcontroller or a state machine, combinations thereof, etc. The processor may also be implemented as a combination of computing devices, e.g., a combination of a DSP and a microprocessor, a plurality of microprocessors, one or more microprocessors in conjunction with a DSP core, or any other such configuration. Although mainly described in connection with digital technologies herein, the processor may also include primarily analog components. For example, any of the signal processing algorithms described herein may be implemented in an analog circuit. The computing environment may include any type of computer system, including but not limited to: a microprocessor-based computer system, a mainframe computer, a digital signal processor, a portable computing device, a personal organizer, a device controller, and a computing engine within an appliance, etc.

[0234] The methods disclosed herein include one or more steps or acts for implementing the described methods. The method steps and / or acts may be interchanged with one another without departing from the scope of the claims. In other words, unless a particular order of steps or acts is required for proper operation of the method being described, the order and / or use of specific steps and / or acts may be modified without departing from the scope of the claims.

[0235] It should be noted that the terms “couple”, “coupling”, “coupled” or other variations of the word couple as used herein may mean an indirect connection or a direct connection. For example, if a first component is “coupled” to a second component, the first component may be indirectly connected to the second component or directly connected to the second component. As used herein, the term “plurality” means two or more. For example, a plurality of components means two or more components.

[0236] The term “determine” encompasses a variety of actions, and thus, “determine” may include calculating, computing, processing, deriving, investigating, looking up (e.g., looking up in a table, a database, or other data structure), ascertaining, etc. Moreover, “determine” may include receiving (e.g., receiving information), accessing (e.g., accessing data in a memory), etc. Moreover, “determine” may include parsing, selecting, choosing, establishing, etc. Unless otherwise expressly stated, the phrase “based on” does not mean “based only on”. In other words, the phrase “based on” describes both “based only on” and “based at least on”.

[0237] The foregoing description of the disclosed embodiments is provided to enable any person skilled in the art to make or use the present invention. Various modifications to these embodiments will be readily apparent to those skilled in the art, and the generic principles defined herein may be applied to other embodiments without departing from the spirit or scope of the invention. Thus, the invention is not intended to be limited to the embodiments shown herein but is to be accorded the widest scope consistent with the principles and novel features disclosed herein.

Claims

1. A diagnostic testing device, comprising: A connection module configured to establish a communication channel with a cloud system; A computer-readable memory storing a globally unique identifier of the diagnostic testing device and a serial number of the diagnostic testing device, wherein the globally unique identifier is associated with the serial number; And One or more hardware-based processors programmed by executable instructions to perform a method, the method comprising: obtaining a test result; Generating an encrypted data block including the serial number of the diagnostic testing device and the test result using an encryption key associated with the globally unique identifier and the serial number; and Transmitting the globally unique identifier of the diagnostic testing device and the encrypted data block to the cloud system via the communication channel for verifying the diagnostic testing device by: determining that the globally unique identifier is valid, decrypting the encrypted serial number using an encryption key associated with the globally unique identifier, and matching the decrypted serial number with the serial number associated with the globally unique identifier, Wherein the globally unique identifier is transmitted to the cloud system as an unencrypted data block.

2. The diagnostic testing device according to claim 1, wherein the encrypted data block further includes a manufacturer code identifying the manufacturer of the diagnostic testing device.

3. The diagnostic testing device according to claim 1, wherein the encrypted data block includes information selected from the group consisting of: a model of the diagnostic testing device, a catalog number of a test performed to generate the test result, patient information, and technician information.

4. The diagnostic testing device according to claim 1, wherein the connection module includes a cellular modem.

5. The diagnostic testing device according to claim 1, wherein the hardware-based processor is programmed by the executable instructions to perform the method, the method further comprising: Determining whether there is an error in establishing the communication channel with the cloud system; And If the error is detected, storing the test result in the memory.

6. The diagnostic testing device according to claim 5, wherein the stored test result includes the encrypted data block.

7. The diagnostic testing device according to claim 1, wherein the communication channel includes an encrypted communication channel.

8. The diagnostic testing device according to claim 7, wherein the encrypted communication channel includes a Secure Hypertext Transfer Protocol HTTPS or a Transport Layer Security TLS channel.

9. The diagnostic testing device according to claim 1, further comprising a sensor for detecting a change in one or more characteristics of a diagnostic assay.

10. The diagnostic testing device according to claim 9, wherein the sensor is configured to generate a signal indicating a detected change in a characteristic of the assay.

11. The diagnostic testing device according to claim 10, wherein obtaining the test result includes determining the test result based at least in part on the signal generated by the sensor.

12. A cloud system for storing test results, comprising: A computer-readable memory storing executable instructions; And One or more hardware-based processors, the processors being programmed by executable instructions to perform a method, the method comprising: Receiving, via a communication channel, a globally unique identifier and an encrypted data block of the diagnostic test device from the diagnostic test device, wherein the encrypted data block includes a received serial number of the diagnostic test device and a test result, and wherein the received serial number is associated with the globally unique identifier; Determining that the globally unique identifier is valid; Obtaining a stored serial number and an encryption key, both associated with the globally unique identifier; Decrypting the encrypted data block using the encryption key to obtain the received serial number and the test result; Determining that the received serial number and the stored serial number are the same; and Storing the test result in a storage device, wherein the globally unique identifier is received as an unencrypted data block.

13. The cloud system according to claim 12, wherein the test result is stored together with information selected from the group consisting of: a manufacturer code in the storage device identifying the manufacturer of the diagnostic test device, a model of the diagnostic test device, a catalog number of the test performed to generate the test result, patient information, and technician information.

14. The cloud system according to claim 12, wherein the communication channel comprises an encrypted communication channel.

15. The cloud system according to claim 14, wherein the encrypted communication channel comprises a Secure Hypertext Transfer Protocol HTTPS or a Transport Layer Security TLS channel.

16. The cloud system according to any one of claims 12-15, wherein the hardware-based processor is programmed by the executable instructions to perform the method, the method further comprising: Receiving a second globally unique identifier and a second encrypted data block from a second device, wherein the second encrypted data block includes a second received serial number and test result identification information; Obtaining a second stored serial number and a second encryption key associated with the second globally unique identifier; Decrypting the second encrypted data block using the second encryption key to obtain the second received serial number and the test result identification information; Determining that the second received serial number and the second stored serial number are the same; Retrieving the test result from the storage device using the test result identification information; and Sending the test result encrypted with the second encryption key to the second device.

17. The cloud system according to claim 16, wherein the test result identification information is selected from the group consisting of: a manufacturer code in the storage device identifying the manufacturer of the diagnostic test device, a model of the diagnostic test device, a catalog number of the test performed to generate the test result, patient information, and technician information.

18. The cloud system according to claim 17, wherein the second device comprises the diagnostic test device.

19. The cloud system according to claim 16, wherein the second device comprises the diagnostic test device.

Citation Information

Patent Citations

  • Computer system for storing and retrieval of encrypted data items, client computer, computer program product and computer-implemented method

    EP2731040A1

  • Wireless system for near real time surveillance of disease

    WO2015143309A1