Medical information management system and management method

By adopting data partition isolation storage and encryption technology in the medical information management system and combining access rights control, the problem of insufficient confidentiality of users' medical information in the existing system is solved, and higher information security and confidentiality are achieved.

CN119939619APending Publication Date: 2025-05-06ZHONG SHAN PEOPLES HOSPITAL
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202411853293.8
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2024-12-16
Publication Date
2025-05-06

AI Technical Summary

Technical Problem

The existing medical information management system has defects in the confidentiality of user medical information, which can easily lead to information leakage and cannot effectively protect user medical privacy.

Method used

A medical information management system is designed, using data partition isolation storage and encryption technology, restricting staff's viewing rights through access rights control, and using encryption to protect the privacy of users' medical information.

Benefits of technology

It improves the security and confidentiality of user medical information, prevents information leakage, and ensures comprehensive protection and leakage protection of user medical information.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119939619A_ABST
    Figure CN119939619A_ABST
Patent Text Reader

Abstract

The invention discloses a medical information management system, and the system comprises a data collection module which inputs user information through a computer terminal for collection; the data processing module is used for preprocessing the collected data information; the data analysis module is used for classifying and concluding the processed data information; the data isolation storage module is used for performing partition isolation storage on the classified data; by controlling the access authority and encrypting the medical data of the user, the security and confidentiality of the medical information of the user are improved, leakage can be prevented, data leakage can be avoided when the data are damaged, and therefore protection and leakage prevention are comprehensively carried out on the medical data; different medical information is separated and stored in a partition isolation mode, so that query and storage are facilitated, leakage is prevented, and the important medical information can be further protected according to different access permissions.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of medical technology, and in particular to a medical information management system and a management method. Background Art

[0002] Medical information management system is a frontier science that integrates medicine, information, management, computer and other disciplines. It has been widely used in developed countries and has created good social and economic benefits. Medical information management system is the necessary technical support and infrastructure for modern hospital operations. The purpose of implementing medical information management system is to strengthen hospital management, improve hospital work efficiency, and improve medical quality with more modern, scientific and standardized means, thereby establishing a new image of modern hospitals. This is also the inevitable direction of future hospital development. User medical information needs to be managed through the management system;

[0003] At present, the confidentiality measures for users' medical information in the medical information management system are poor. It is easy for different staff to retrieve user information at will due to the simple opening method and unlimited opening permissions, resulting in the leakage of medical information and the failure to protect the privacy of users' medical care;

[0004] In view of the above technical defects, a solution is now proposed. Summary of the invention

[0005] The purpose of the present invention is to provide a medical information management system and management method, which has good confidentiality, can partition and isolate the medical information used for storage, and limit the viewing of staff according to the setting of access rights, while protecting the privacy of user medical information in an encrypted manner, so as to solve the problems raised in the above-mentioned background technology.

[0006] To achieve the above object, the present invention provides the following technical solution: a medical information management system, comprising:

[0007] Data collection module, which collects user information by inputting it through a computer terminal;

[0008] Data processing module, pre-processing the collected data information;

[0009] Data analysis module, which classifies and summarizes the processed data information;

[0010] Data isolation storage module, which partitions and isolates the classified data for storage;

[0011] Data access control module, which opens the data information stored in partition isolation by verifying the visitor information;

[0012] The data encryption module encrypts the user's medical data information and uses the secret key to open and query the user's detailed information.

[0013] Exemplarily, the data isolation storage module includes a data partition isolation module and a data storage module, which first partitions and isolates the collected different data information, and divides the data to be stored into several groups of data blocks according to predetermined rules for storage.

[0014] Exemplarily, the data storage module includes a physical backup unit and a cloud backup unit;

[0015] Includes data files and log files that need to be backed up in the database;

[0016] The physical backup unit directly copies the database files and logs to complete the backup;

[0017] Monitor Redo log changes: Before the backup starts, continuously monitor the changes in the Redo log and record the changes in the data;

[0018] Copy data files: Send data files to backup storage through data streams, monitor changes in Redo logs, and back up changed data to storage;

[0019] Back up Binlog log files: Back up Binlog log files to storage to ensure the integrity of the logs;

[0020] Write original data information: After the backup is completed, the backup metadata information is written to the backup storage to form a complete time point.

[0021] Exemplary, differential backup is also included:

[0022] Back up incremental data blocks based on the last successful full backup; when restoring to the differential backup time point, you only need to apply the differential backup data blocks to the full backup data, and finally restore the full backup data to the MySQL data directory and start the database service.

[0023] Exemplarily, the cloud backup unit includes:

[0024] The data information is transmitted via the network to a remote cloud server for storage, and the data information is encrypted and compressed during the storage process.

[0025] Exemplarily, in the data access control module, role-based access control (RBAC) and session management are used to limit user access rights, set and collect user names, passwords, IP address ranges, user roles, etc.

[0026] Exemplarily, when inputting information access rights, the user information includes the user identification, the group to which the user belongs, the user terminal type, and at least a medical information management system in the department to which the user belongs.

[0027] Exemplarily, when accessing information files, the files are opened by inputting a user name and password, a magnetic card, a fingerprint, or any combination of other medical information management systems.

[0028] Exemplarily, the data encryption module includes: generating a unique identifier and a timestamp for each piece of user data, including: data encryption and hash generation: encrypting each piece of identified and extracted user-related information.

[0029] The medical information management method comprises the following steps:

[0030] S1: User medical data collection, collecting user medical information data through data terminals;

[0031] S2: Data processing, pre-processing the collected user medical data;

[0032] S3: Data analysis, classifying and summarizing the pre-processed user medical data;

[0033] S4: Data isolation storage, partitioning and isolating the classified data;

[0034] S5: Data access control, opening the data information stored in partition isolation by verifying the visitor information;

[0035] S6: Data encryption: Encrypt user medical data information, and use the secret key to open and query user details.

[0036] Compared with the prior art, the present invention has the following beneficial effects:

[0037] The present invention improves the security and confidentiality of user medical information by controlling access rights and encrypting user medical data. It can not only prevent leakage, but also avoid data leakage when data is damaged, thereby comprehensively protecting and preventing leakage of medical data. Secondly, partition isolation is used to separate storage for different uses, so as to facilitate query and storage as well as prevent leakage. Different access rights can further protect the medical information of important users. The encryption method can be used to encrypt the medical information of each user, and medical personnel outside the department cannot open it with the corresponding secret key, thereby realizing the confidentiality and security protection of medical users' information in multiple directions.

[0038] Other features and advantages of the present invention will be described in the following description, and partly become obvious from the description, or be understood by practicing the present invention. The purpose and other advantages of the present invention can be realized and obtained by the structures pointed out in the description and the drawings. BRIEF DESCRIPTION OF THE DRAWINGS

[0039] Figure 1 is a system block diagram of the present invention;

[0040] Figure 2 The figure is a flow chart of the method of the present invention. DETAILED DESCRIPTION

[0041] The following will be combined with the drawings in the embodiments of the present invention to clearly and completely describe the technical solutions in the embodiments of the present invention. Obviously, the described embodiments are only part of the embodiments of the present invention, not all of the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by ordinary technicians in this field without creative work are within the scope of protection of the present invention.

[0042] The present invention provides a medical information management system, comprising:

[0043] Data collection module, which collects user information by inputting it through a computer terminal;

[0044] Data processing module, pre-processing the collected data information;

[0045] Data analysis module, which classifies and summarizes the processed data information;

[0046] Data isolation storage module, which partitions and isolates the classified data for storage;

[0047] Data access control module, which opens the data information stored in partition isolation by verifying the visitor information;

[0048] The data encryption module encrypts the user's medical data information and uses the secret key to open and query the user's detailed information.

[0049]

[0050] Among them, x i represents the i-th archive data after normalization, X i represents the i-th original archive data, X max , X min Respectively represent the maximum and minimum values ​​of the original archive data;

[0051] The data analysis module (300) extracts data features and analyzes abnormal data based on the normalized archive data;

[0052] The feature extraction is as follows:

[0053] After preprocessing, we obtain the archive data set x, which contains L characteristic attributes:

[0054] x=p(L)+r(L)

[0055] Among them, p(l) is the characteristic attribute parameter of the archive data, and r(l) is the discrete parameter;

[0056] Decompose the characteristic attribute parameter p(l) and extract the archive characteristic data p i :

[0057]

[0058] p i =p q +p l

[0059] Among them, A(w i ) is the set of rule vectors of discrete ranges, α is the number of discrete ranges, p q 、p l is the qth and lth characteristic attributes in the characteristic attribute parameters, r i is the eigenvalue vector of the i-th (i∈(1,M)) archive data, r is the centroid of the archive data, (r i -r) T Represents data r i - transpose of r, w i is the weight of the i-th archive data;

[0060] In the process of abnormal data analysis, the improved particle swarm algorithm is used to traverse the archive feature data points, and the cluster center point is selected with the minimum distance between the archive feature data point and the cluster center point as the fitness function; the particle population is initialized, and the particles are iteratively updated through the following algorithm to find the optimal solution:

[0061]

[0062] in, represents the speed of the nth particle at the t+1th iteration, represents the speed of the nth particle at the tth iteration, represents the position of the nth particle at the t+1th iteration, represents the position of the nth particle at the tth iteration, ω is the inertia weight of the particle, r1 and r2 are both random numbers between [0,1], represents the individual's best historical position; represents the optimal position of the group;

[0063] ω changes according to the number of iterations:

[0064]

[0065] Among them, ω max is the maximum weight, ω min is the minimum weight, is the chaotic variable, u is the number of chaotic iterations, v is the variable dimension, t max Indicates the maximum number of iterations.

[0066] The improved particle algorithm divides the input D-dimensional archival feature data into N categories. The number of archival data feature clustering centers after division is D×N. The archival data is clustered:

[0067]

[0068] Among them, p dj is the j-th category archive data feature of the d-th dimension (d∈[1,D]), n dj is the number of features of the j-th category archive data in the d-th dimension, c dj is the cluster center of the j-th data feature in the d-th dimension;

[0069] Based on the softmax classifier, the abnormal threshold is divided to identify the abnormality of the archival data based on the clustering results of the archival data;

[0070] Preferred:

[0071] The data isolation storage module includes a data partition isolation module and a data storage module. Different collected data information is first partitioned and isolated, and the data to be stored is divided into several groups of data blocks according to predetermined rules for storage.

[0072] Store the above data in the preset database and divide it reasonably, such as partitioning or establishing an independent database, to achieve data isolation between different modules;

[0073] At the same time, container technologies, such as Docker, will be used to encapsulate each module into an independent container to improve system availability;

[0074] in:

[0075] The data storage module includes a physical backup unit and a cloud backup unit;

[0076] Includes data files and log files that need to be backed up in the database;

[0077] The physical backup unit directly copies the database files and logs to complete the backup;

[0078] Monitor Redo log changes: Before the backup starts, continuously monitor the changes in the Redo log and record the changes in the data;

[0079] Copy data files: Send data files to backup storage through data streams, monitor changes in Redo logs, and back up changed data to storage;

[0080] Back up Binlog log files: Back up Binlog log files to storage to ensure the integrity of the logs;

[0081] Write original data information: After the backup is completed, the backup metadata information is written to the backup storage to form a complete time point.

[0082] Data recovery: In the event of data loss or damage, data can be quickly restored through physical backup to ensure continuous operation of the system

[0083] Disaster recovery: Physical backup is one of the prerequisites for system disaster recovery, which can provide protection in the event of hardware failure or human error.

[0084] Efficiency and real-time performance: Physical backup is located below the file system and above the hardware disk drive, ignoring files and structures. The processing process is simple, the backup performance is high, and efficient real-time backup can be achieved.

[0085] Support various file systems: Physical backup is not limited by the file system and can support various file systems, including RAW partitions;

[0086] Additionally, differential backups are included:

[0087] Back up incremental data blocks based on the last successful full backup; when restoring to the differential backup time point, you only need to apply the differential backup data blocks to the full backup data, and finally restore the full backup data to the MySQL data directory and start the database service.

[0088] Save storage space: Differential backup only records the changed data since the last full backup, so the backup file is usually much smaller than the full backup, which effectively saves storage space, especially when the data does not change much;

[0089] Improve backup speed: Since differential backup only records changed data, the backup process is much faster than full backup, reducing the impact of backup operations on system performance;

[0090] Speed ​​up recovery: When restoring a database, you only need to restore the last full backup first, and then apply the latest differential backup, which greatly simplifies the recovery process and improves the recovery speed;

[0091] Reduce the possibility of errors: By restoring the full backup first and then applying the differential backup, the possibility of errors during the recovery process is reduced.

[0092] Further, the cloud backup unit includes:

[0093] The data information is transmitted via the network to a remote cloud server for storage, and the data information is encrypted and compressed during the storage process.

[0094] Data protection: The primary purpose of cloud backup is to protect data from various potential threats, including hardware failure, human error, malicious attacks, etc. By backing up data to the cloud, even if local data is damaged or lost, it can be quickly restored from the cloud to ensure data integrity and availability;

[0095] Disaster recovery: In unforeseen events such as natural disasters, fires, and floods, local data backups are often unavoidable. Cloud backups, however, can effectively resist these catastrophic events because data is stored on remote servers, ensuring that enterprises can quickly resume business operations after a disaster.

[0096] Business continuity guarantee: For critical businesses, any data loss or interruption may lead to serious economic losses and customer trust crisis. Cloud backup ensures business continuity and stability by providing instant data recovery capabilities, reducing the risk of business interruption caused by data problems;

[0097] Cost optimization: Compared with traditional local backup solutions, cloud backup has significant advantages in hardware investment, maintenance costs, personnel training, etc. You can flexibly select backup capacity and service level according to actual needs to achieve cost optimization.

[0098] Furthermore, in the data access control module, role-based access control (RBAC) and session management are used to limit user access rights, set and collect user names, passwords, IP address ranges, and user roles.

[0099] Authentication: Before users access data, they need to authenticate their identities and permissions. Authentication can be performed using usernames, passwords, certificates, etc., and sensitive information such as passwords is encrypted to ensure the security of user information.

[0100] Permission control: Control the user's access to data based on the user's identity and permissions. You can use roles or access control lists to implement permission control to ensure that only authorized users or applications can access data;

[0101] Audit log: records information about user access to data in order to monitor and audit user access behavior. Audit logs can record user identity, access time, access content and other information, while protecting audit logs to prevent them from being tampered with or deleted;

[0102] Prevent data leakage and illegal operations: Through strict permission control, users' data operation permissions can be limited to prevent sensitive data from being illegally obtained or tampered with, thus ensuring data availability;

[0103] Improve system security: Through mechanisms such as identity authentication, permission control and audit logs, the security of the system can be effectively improved to prevent unauthorized access and operation;

[0104] Among them, when inputting information access rights, the user information includes the user identification, the user group, the user terminal type, and at least the medical information management system in the user's department. Each department cannot access each other, and its permissions are blocked, so as to better realize the protection of medical use in each department.

[0105] In addition, when information is accessed, the file can be opened by entering a user name and password, magnetic card, fingerprint, or any other medical information management system or a combination thereof. It can be opened according to the user name and password, magnetic card, fingerprint, or any other medical information management system or a combination thereof that is specially equipped for different medical personnel in each department. And because partitioned and isolated storage is performed during the storage process, each area is equipped with corresponding medical personnel for information, and only the corresponding responsible medical staff can open it. It can be opened by a single method or by a combination of the above methods.

[0106] Finally, the data encryption module includes: generating a unique identifier and timestamp for each piece of user data, including: data encryption and hash generation: encrypting each piece of identified and extracted user-related information.

[0107] Use a pair of keys: a public key and a private key. The public key is used to encrypt data, while the private key is used to decrypt data. The characteristic of this encryption method is that different keys are used for encryption and decryption, thus ensuring the security of data;

[0108] Key generation: Asymmetric encryption algorithms generate a pair of keys: a public key and a private key. The public key can be made public, while the private key must be kept secret.

[0109] Encryption process: The sender uses the receiver's public key to encrypt the data. Since only the receiver has the corresponding private key, only the receiver can decrypt the data.

[0110] Decryption process: The receiver uses his own private key to decrypt the encrypted data and restore the original data.

[0111] The medical information management method comprises the following steps:

[0112] S1: User medical data collection, collecting user medical information data through data terminals;

[0113] S2: Data processing, pre-processing the collected user medical data;

[0114] S3: Data analysis, classifying and summarizing the pre-processed user medical data;

[0115] S4: Data isolation storage, partitioning and isolating the classified data;

[0116] S5: Data access control, opening the data information stored in partition isolation by verifying the visitor information;

[0117] S6: Data encryption: Encrypt user medical data information, and use the secret key to open and query user details.

[0118] Although embodiments of the present invention have been shown and described, it will be appreciated by those skilled in the art that various changes, modifications, substitutions and variations may be made to the embodiments without departing from the principles and spirit of the present invention, and that the scope of the present invention is defined by the appended claims and their equivalents.

Claims

1. A medical information management system, characterized in that: include: Data collection module, which collects user information by inputting it through a computer terminal; Data processing module, pre-processing the collected data information; Data analysis module, which classifies and summarizes the processed data information; Data isolation storage module, which partitions and isolates the classified data for storage; Data access control module, which opens the data information stored in partition isolation by verifying the visitor information; The data encryption module encrypts the user's medical data information and uses the secret key to open and query the user's detailed information.

2. The medical information management system according to claim 1, characterized in that: The data isolation storage module includes a data partition isolation module and a data storage module. Different collected data information is first partitioned and isolated, and the data to be stored is divided into several groups of data blocks according to predetermined rules for storage.

3. The medical information management system according to claim 2, characterized in that: The data storage module includes a physical backup unit and a cloud backup unit; Includes data files and log files that need to be backed up in the database; The physical backup unit directly copies the database files and logs to complete the backup; Monitor Redo log changes: Before the backup starts, continuously monitor the changes in the Redo log and record the changes in the data; Copy data files: Send data files to backup storage through data streams, monitor changes in Redo logs, and back up changed data to storage; Back up Binlog log files: Back up Binlog log files to storage to ensure the integrity of the logs; Write original data information: After the backup is completed, the backup metadata information is written to the backup storage to form a complete time point.

4. The medical information management system according to claim 3, characterized in that: Differential backups are also included: Back up incremental data blocks based on the last successful full backup; When restoring to the differential backup time point, you only need to apply the differential backup data blocks to the full backup data, and finally restore the full backup data to the MySQL data directory and start the database service.

5. The medical information management system according to claim 3, characterized in that: The cloud backup unit comprises: The data information is transmitted via the network to a remote cloud server for storage, and the data information is encrypted and compressed during the storage process.

6. The medical information management system according to claim 1, characterized in that: In the data access control module, role-based access control (RBAC) and session management are used to limit user access rights, set and collect user names, passwords, IP address ranges, user roles, etc.

7. The medical information management system according to claim 6, characterized in that: When inputting information access rights, the user information includes the user identification, the group to which the user belongs, the user terminal type, and at least the medical information management system in the department to which the user belongs.

8. The medical information management system according to claim 7, characterized in that: When accessing information files, the files can be opened by entering username and password, magnetic card and fingerprint, etc., in any medical information management system or a combination thereof.

9. The medical information management system according to claim 1, characterized in that: The data encryption module includes: generating a unique identifier and a timestamp for each piece of user data, including: data encryption and hash generation: encrypting each piece of identified and extracted user-related information.

10. A medical information management method, comprising the medical information management system according to any one of claims 1 to 9, characterized in that: The steps include: S1: User medical data collection, collecting user medical information data through data terminals; S2: Data processing, pre-processing the collected user medical data; S3: Data analysis, classifying and summarizing the pre-processed user medical data; S4: Data isolation storage, partitioning and isolating the classified data; S5: Data access control, opening the data information stored in partition isolation by verifying the visitor information; S6: Data encryption: Encrypt user medical data information, and use the secret key to open and query user details.