Full-scene-oriented medical data security collection method, system and equipment and medium
By combining dynamic strategy contracts, a trusted computing engine, and an audit and evidence storage chain, the system addresses the issues of insufficient privacy protection and compliance in medical data sharing, enabling secure data sharing and collaborative computing across institutions.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- GUANGXI MEDICAL UNIVERSITY
- Filing Date
- 2025-12-11
- Publication Date
- 2026-04-21
AI Technical Summary
Existing methods for sharing and collaborative computing in the medical field suffer from insufficient data privacy protection, contradictions in multi-center data collaboration, and a lack of trusted computing and auditing mechanisms, making it difficult to guarantee data leakage and compliance.
By establishing dynamic policy contracts, deploying a trusted computing engine, and an audit and evidence storage chain, real-time monitoring and transparent tracking of medical data can be achieved, ensuring the security and compliance of data processing.
It enables secure data sharing and collaborative computing across institutions and platforms, ensuring data privacy and compliance, preventing data leakage and tampering, and providing traceable operation records.
Smart Images

Figure CN121905397A_ABST
Abstract
Description
Technical Field
[0001] This invention relates to the fields of medical information technology and data security technology, and in particular to a method, system, device and medium for secure collection of medical data for all scenarios. Background Technology
[0002] With the increasing demand for data sharing in the healthcare field, especially the rise of multi-center clinical research, public health decision-making, and AI-driven medical innovation, the security, privacy, and compliance issues of medical data have become increasingly prominent. Medical data involves sensitive personal health information, such as medical records, examination reports, and diagnostic records. The leakage of this data can lead to serious consequences. However, existing data sharing and collaborative computing methods have the following drawbacks: Insufficient data privacy protection: Traditional data sharing models often rely on centralized storage and transmission of sensitive data, which, while meeting data sharing needs, is highly susceptible to data leaks and privacy violations. Conflicts in multi-center data collaboration: In multi-center data collaboration, medical institutions often adopt a "data not leaving the hospital" strategy, meaning medical data is processed and stored locally without external transmission. While this strategy ensures data privacy, it poses significant challenges to cross-institutional and cross-platform data collaboration. Lack of trusted computing and auditing mechanisms: Current medical data sharing and collaborative computing mostly rely on traditional trust mechanisms, depending on centralized computing platforms or intermediaries to process and aggregate data. However, this model has significant trust risks, especially without robust auditing and compliance verification mechanisms, making it difficult to ensure the transparency and traceability of data processing. As data usage and processing scenarios become increasingly complex, existing technologies struggle to effectively track every step of the data usage process, leading to difficulties in ensuring compliance. Summary of the Invention
[0003] In view of the aforementioned existing problems, the present invention is proposed.
[0004] Therefore, the technical problem solved by this invention is: how to achieve secure data sharing and collaborative computing across institutions and platforms while ensuring the privacy and compliance of medical data, and to achieve dynamic monitoring, transparent tracking and real-time compliance verification of medical data through trusted computing and auditing mechanisms to effectively prevent risks such as data leakage, privacy infringement and system instability.
[0005] To address the aforementioned technical problems, this invention provides the following technical solution: a method for secure collection of medical data across all scenarios, comprising, Connect to the information systems of medical institutions to obtain their original medical information data in real time; Based on the data privacy protection and management requirements of medical institutions, a strategy generation engine is established to generate dynamic strategy contracts. Execute dynamic strategy contracts, establish and train clinical natural language processing models, perform sensitivity identification on raw medical information data, and obtain desensitized medical information data; Based on the de-identified medical information data, a semantic mapping model is established to perform semantic analysis on the de-identified medical information data to obtain encrypted medical information data. Based on encrypted medical information data, deploy a trusted computing engine to make a trustworthy judgment on the encrypted medical information data; Based on the dynamic strategy contract generation process and the trusted computing engine judgment process, an audit and evidence storage chain is established to verify process compliance.
[0006] As a preferred embodiment of the comprehensive medical data security aggregation method described in this invention, the method includes: establishing a strategy generation engine to generate dynamic strategy contracts based on the data privacy protection and management requirements of medical institutions, including: Receive and analyze the data privacy protection and management requirements of medical institutions, and clarify the protection and management objectives; Develop data access control and processing rules based on protection and management objectives; Based on data access control and processing rules, a strategy generation engine is established to output dynamic strategy contracts.
[0007] This invention addresses the challenges of data privacy protection by clearly defining the data privacy protection and management objectives of medical institutions and developing targeted data access control and processing rules. Through the generation of dynamic policy contracts, it enables flexible responses to different data access and processing scenarios, allowing data processing rules to be executed automatically and adjusted according to actual needs. Furthermore, it facilitates cross-institutional and cross-platform data sharing and collaborative computing, resolving the inherent contradictions in data privacy protection.
[0008] As a preferred embodiment of the comprehensive medical data security aggregation method described in this invention, the method includes: deploying a trusted computing engine to perform a trust assessment on the encrypted medical information data, including: Establish a trusted computing engine and deploy it on the local server of the medical institution; After the trusted computing engine is deployed, it is trained locally at the medical institution; Based on the trained trusted computing engine, the obtained encrypted medical information data is assessed for trustworthiness.
[0009] This invention deploys a trusted computing engine to perform trust assessments on encrypted medical information data, thereby achieving secure monitoring of the data processing process and ensuring the privacy of encrypted data during transmission and storage. This solution can identify in real time whether data meets predetermined privacy protection requirements and verify the data processing process to prevent data leakage or tampering. It establishes a trusted computing environment in the process of medical data sharing and collaborative computing, ensuring that data operations by all parties are transparent and traceable.
[0010] As a preferred embodiment of the medical data security collection method for all scenarios described in this invention, the method includes: establishing an audit and evidence storage chain for process compliance verification based on the dynamic strategy contract generation process and the trusted computing engine judgment process, including: Based on the dynamic strategy contract generation and execution process and the trusted computing engine's judgment process, key behaviors are automatically recorded. Establish an audit evidence storage chain based on the recorded key behaviors to store the key behaviors; An audit is initiated based on the audit evidence chain to verify the compliance of the collection process.
[0011] This invention establishes an audit and evidence storage chain based on the dynamic strategy contract generation and execution process and the judgment process of the trusted computing engine to verify process compliance, achieving comprehensive auditing and compliance checks of the data processing process. By recording all key operations in the data processing and transmission process in real time and ensuring tamper-proof data traceability through the audit and evidence storage chain, this solution can provide verifiable compliance records at every stage of data processing and sharing, effectively preventing data leakage or misuse.
[0012] This invention provides a medical data security collection system for all scenarios.
[0013] To address the aforementioned technical problems, this invention provides the following technical solution: a medical data security collection system for all scenarios, comprising: a collection module, a strategy generation module, a standardization module, a semantic analysis module, a trust judgment module, and a compliance verification module; The acquisition module connects to the information system of medical institutions to acquire raw medical information data from medical institutions in real time. The strategy generation module is based on the data privacy protection and management requirements of medical institutions, and establishes a strategy generation engine to generate dynamic strategy contracts. The standardization module executes dynamic strategy contracts, establishes and trains a clinical natural language processing model, performs sensitive identification on raw medical information data, and obtains desensitized medical information data. The semantic analysis module establishes a semantic mapping model based on the de-identified medical information data to perform semantic analysis on the de-identified medical information data, thereby obtaining encrypted medical information data. The trust judgment module is based on encrypted medical information data and deploys a trusted computing engine to perform trust judgment on the encrypted medical information data. The compliance verification module establishes an audit and evidence storage chain to verify process compliance based on the dynamic strategy contract generation process and the trusted computing engine judgment process.
[0014] The present invention provides a computer device, including a memory and a processor, wherein the memory stores a computer program, characterized in that the processor executes the computer program to implement the steps of the aforementioned method for secure collection of medical data for all scenarios.
[0015] The present invention provides a computer-readable storage medium having a computer program stored thereon, characterized in that, when the computer program is executed by a processor, it implements the steps of the aforementioned method for secure collection of medical data across all scenarios.
[0016] The beneficial effects of this invention are as follows: This invention enables flexible definition of data access and processing rules through the automated generation of dynamic policy contracts. A trusted computing engine ensures the trustworthiness and integrity of data processing by performing trust assessments on encrypted data. By combining the dynamic policy contract generation and execution process with the trusted computing engine's assessment process, an audit and evidence storage chain is established for process compliance verification, solving the problems of insufficient data privacy protection and compliance in traditional medical data sharing and collaborative computing. Ultimately, this invention achieves secure collection of medical data across all scenarios. Attached Figure Description
[0017] To more clearly illustrate the technical solutions of the embodiments of the present invention, the drawings used in the following description of the embodiments will be briefly introduced. Obviously, the drawings described below are only some embodiments of the present invention. For those skilled in the art, other drawings can be obtained based on these drawings without creative effort.
[0018] Figure 1 This is a schematic diagram of the overall process of a medical data security collection method for all scenarios according to an embodiment of the present invention. Detailed Implementation
[0019] To make the above-mentioned objects, features, and advantages of the present invention more apparent and understandable, specific embodiments of the present invention will be described in detail below with reference to the accompanying drawings. Obviously, the described embodiments are only a part of the embodiments of the present invention, and not all of them. Based on the embodiments of the present invention, all other embodiments obtained by those skilled in the art without creative effort should fall within the protection scope of the present invention.
[0020] Example 1, referring to Figure 1This is one embodiment of the present invention, which provides a method for secure collection of medical data across all scenarios, including: It should be noted that with the increasing demand for medical data sharing, particularly in multi-center clinical research, public health decision-making, and AI-driven medical innovation, the issues of privacy protection and compliance of medical data have become increasingly prominent. Existing methods for medical data sharing and collaborative computing typically rely on centralized data storage and transmission, which can easily lead to data leaks and privacy violations, and lack the ability to adjust and automatically execute dynamic data access and processing rules in real time. Existing methods often employ traditional trust mechanisms that rely on intermediaries or computing platforms for data processing and aggregation, lacking robust auditing and compliance verification mechanisms, making it difficult to track and verify each step of the data processing process in real time, thus compromising compliance.
[0021] Therefore, addressing the aforementioned issues of insufficient data privacy protection, contradictions in multi-center data collaboration, and lack of trusted computing and auditing mechanisms in existing medical data sharing and collaborative computing methods, the following steps (S1-S6) are proposed: real-time acquisition of raw medical information data from medical institutions; generation of dynamic policy contracts based on the data privacy protection and management requirements of medical institutions; execution of dynamic policy contracts to obtain anonymized medical information data; semantic analysis of the anonymized medical information data to obtain encrypted medical information data. This resolves the problems of insufficient data privacy protection and contradictions in multi-center data collaboration in existing methods. Furthermore, a trusted computing engine is deployed to make trustworthy judgments on the encrypted medical information data, and an audit and evidence storage chain is established for process compliance verification, thus resolving the problem of the lack of trusted computing and auditing mechanisms in existing methods.
[0022] S1: Connects to the information systems of medical institutions to obtain raw medical information data from medical institutions in real time; S2: Based on the data privacy protection and management requirements of medical institutions, a strategy generation engine is established to generate dynamic strategy contracts; S3: Execute dynamic strategy contracts, establish and train clinical natural language processing models, perform sensitive identification on raw medical information data, and obtain desensitized medical information data; S4: Based on the de-identified medical information data, establish a semantic mapping model to perform semantic analysis on the de-identified medical information data to obtain encrypted medical information data; S5: Based on encrypted medical information data, deploy a trusted computing engine to make a trust judgment on the encrypted medical information data; S6: Based on the dynamic strategy contract generation process and the trusted computing engine judgment process, establish an audit and evidence storage chain to verify process compliance.
[0023] Example 2, an embodiment of the present invention, provides a method for secure collection of medical data across all scenarios, based on the previous embodiment, including: In step S1, the system connects to the medical institution's information system to obtain the institution's original medical information data in real time, including the following steps A1-A3: A1: Establish a data communication interface based on the medical institution's information system.
[0024] This invention first deploys a lightweight agent module locally in each participating medical institution, establishing a data communication interface to connect with information systems such as HIS, LIS, and PACS, automatically acquiring structured or semi-structured data. Structured data has a fixed format, such as the department where the patient is registered, the consultation time, or blood test results. Semi-structured data does not have a fixed format but has clear content, such as the description of the patient's condition in an imaging report or text recording the patient's past medical history.
[0025] A2: Based on the data communication interface, obtain structured and semi-structured medical information data from the medical institution's information system in real time.
[0026] A3: Integrate structured and semi-structured medical information data to obtain raw medical information data.
[0027] In step S2, based on the data privacy protection and management requirements of medical institutions, a strategy generation engine is established to generate dynamic strategy contracts, including the following steps B1-B3: B1: Receive and analyze the data privacy protection and management requirements of medical institutions, and clarify the protection and management objectives.
[0028] Medical institutions' input data privacy protection and management requirements are documents that clearly define research objectives, inclusion criteria, observation indicators, and data requirements.
[0029] B2: Develop data access control and processing rules based on protection and management objectives.
[0030] B3: Based on data access control and processing rules, establish a strategy generation engine to output dynamic strategy contracts.
[0031] In this embodiment of the application, the specific steps in step B3 of establishing the dynamic strategy contract output by the strategy generation engine are as follows: The strategy generation engine uses NLP technology to parse documents, extracting key entities such as hypertension and myocardial infarction, data manipulation requirements such as grouping statistics and incidence calculations, and compliance constraints such as anonymization and category retention. The engine then compiles these natural language requirements into a machine-executable JSON-formatted dynamic strategy contract and outputs it.
[0032] In an alternative implementation, the dynamic policy contract output by the policy generation engine in step B3 can also be based on a policy management system. The policy management system defines data access control rules, data processing rules, and privacy protection requirements. Based on the collected privacy protection requirements and management objectives, the policy management system automatically generates the dynamic policy contract.
[0033] In another alternative implementation, the dynamic policy contract output by the policy generation engine in step B3 can also be built using a method based on smart contracts and blockchain technology. This involves collecting specific data privacy requirements from medical institutions and developing dynamic smart contracts on a blockchain platform. These smart contracts define data access rules, privacy protection policies, and data processing procedures. It should be noted that this invention, through a policy generation engine, can automatically generate dynamic policy contracts based on the privacy protection requirements and compliance standards of medical institutions. These dynamic policy contracts can be flexibly adjusted according to different actual situations to meet the needs of various data sharing, processing, and analysis scenarios, avoiding the complexity and error risks of traditional manual contract writing. The policy generation engine enables centralized management of various data processing and access rules, while also supporting cross-platform and cross-system data collaboration.
[0034] In step S3, a dynamic strategy contract is executed to establish and train a clinical natural language processing model, and sensitive identification is performed on the original medical information data to obtain de-sensitized medical information data, including the following steps C1-C3: C1: Collect publicly available medical texts and perform manual cleaning to construct a medical language processing training dataset.
[0035] A large amount of publicly available medical texts were collected, and these materials were manually cleaned and processed by professional medical information personnel. First, keyword matching and manual inspection were used to remove duplicate and formatted content. The remaining text was then standardized to unify medical terminology, correct typos and punctuation, and check for text coherence, removing contradictory content. A medical language processing training dataset was then constructed.
[0036] C2: Establish a clinical natural language processing model and train the clinical natural language processing model based on the medical language processing training dataset.
[0037] C3: Based on the trained clinical natural language processing model, input dynamic strategy contract and raw medical information data, and output anonymized medical information data.
[0038] Based on the trained clinical natural language processing model, the input dynamic policy contract and raw medical information data are used to scan the text and identify sensitive health information. The clinical natural language processing model not only identifies sensitive health information, but also combines the research semantic analysis data fragments defined in the dynamic policy contract to analyze the context.
[0039] For example, when studying rare genetic diseases, even if a gene sequence itself does not contain direct identifiers such as names and ID numbers, the clinical natural language processing model will identify it as a "high-sensitivity quasi-identifier" based on the strategy contract and automatically trigger the highest level of desensitization strategy. In contrast, in routine epidemiological statistics, this information may only be processed by interval.
[0040] Furthermore, based on the identified sensitive health information, the clinical natural language processing model dynamically combines desensitization methods from a predefined rule base to desensitize the sensitive health information and output desensitized medical information data.
[0041] For example, when processing basic patient information, if the strategy requires retaining the age range and anonymizing the name, the system will convert "Zhang San, 110101199001011234, 35 years old" into "Patient A, 110101****1234, 30-40 years old". When processing diagnostic records, if the strategy requires retaining the diagnostic category but anonymizing the medical record number, the system will convert "Hypertension, 202301001" into "Cardiovascular Disease, D_8a7b6c5d".
[0042] Furthermore, if the strategy contract stipulates that this study does not focus on specific complications, the system will use a clinical natural language processing model to identify and suppress "comorbid diabetes" information in hypertension with diabetes, achieving more refined privacy protection.
[0043] In this embodiment of the application, the specific steps for establishing the clinical natural language processing model in step C2 are as follows: A clinical natural language processing model was established using ClinicalBERT (natural language processing algorithm). The input to the model was a dynamic policy contract and raw medical information data. The raw medical information data consisted of UTF-8 encoded medical text data, including unstructured text such as clinical electronic medical records, doctor's diagnosis records, patient complaints, and medical examination reports. The text was processed and sensitive health information was annotated by experts.
[0044] In an optional implementation, step C2, establishing the clinical natural language processing model, can also employ a rule-based sensitive information identification method to construct a rule base containing common sensitive information terms. Potential sensitive information is extracted from clinical text using regular expressions. Semantic analysis is used to evaluate the extracted content, and contextual analysis is employed to filter out potentially mismatched content, thus annotating the sensitive information.
[0045] In another optional implementation, step C2, establishing the clinical natural language processing model, can also employ a sensitive information identification method based on traditional machine learning algorithms. This involves preparing a labeled dataset containing clinical texts with sensitive information. Sensitive data types are labeled, and text features are extracted. These features are then input into the machine learning algorithm for training. The trained model will then identify sensitive information in new clinical texts.
[0046] It should be noted that ClinicalBERT is an improved version based on the BERT model. Through training, it can better understand medical terminology and contextual features. Compared with traditional rule-based or machine learning algorithm-based methods, ClinicalBERT can capture contextual information and identify implicit or ambiguous sensitive information, especially in the processing of polysemous words and synonyms.
[0047] In step S4, based on the de-identified medical information data, a semantic mapping model is established to perform semantic analysis on the de-identified medical information data, resulting in encrypted medical information data, including the following steps D1-D3: D1: Establish a semantic mapping model to preprocess the anonymized medical information data and obtain the preprocessed anonymized medical information data.
[0048] A semantic mapping model is established to map expressions such as high blood sugar and myocardial infarction to the LOINC standard code through literal, semantic, and rule matching.
[0049] D2: Optimize the clinical natural language processing model and semantic mapping model by implementing a closed-loop optimization strategy based on the preprocessing process.
[0050] The semantic mapping model calculates confidence levels in real time during preprocessing. When the confidence level falls below a threshold, the system triggers manual verification. The administrator's manual corrections are structured and labeled as high-quality training samples and fed back to the local clinical natural language processing model and semantic mapping model in real time. The system uses these incremental samples for online learning or periodic fine-tuning. As collaborative tasks increase, each institution's local model becomes increasingly familiar with its local dialect and expression habits, continuously improving mapping accuracy and automation. This reduces the long-term cost of multi-center data collaboration from the outset. All operations in this process are recorded in an audit and evidence chain, ensuring the traceability of optimization.
[0051] D3: Encrypt and store the preprocessed de-identified medical information data to obtain encrypted medical information data.
[0052] In step S5, based on the encrypted medical information data, a trusted computing engine is deployed to perform a trust assessment on the encrypted medical information data, including the following steps E1-E3: E1: Establish a trusted computing engine and deploy it on the local server of the medical institution.
[0053] A trusted computing engine is established through a TEE (Trusted Execution Environment) and deployed to a local server in a medical institution.
[0054] E2: After the trusted computing engine is deployed, it is trained locally in the medical institution.
[0055] For training tasks, this invention employs TEE-enhanced federated learning. Each medical institution trains a trusted computing engine locally, but the aggregation of model parameters occurs within a TEE deployed by the coordinator. This means that even the coordinator cannot see the plaintext model parameters; aggregation is only completed within this black box of the TEE, further enhancing model security. Furthermore, the TEE can also be used to verify model updates uploaded by participants and prevent malicious participants from poisoning the system by running benchmark tests.
[0056] E3: Based on the trained trusted computing engine, perform a trust assessment on the obtained encrypted medical information data.
[0057] In this embodiment of the application, the specific steps for determining the trustworthiness of encrypted medical information data in step S5 are as follows: When a healthcare institution submits an SQL query or Python analysis script, it is first parsed outside the trusted computing engine and then compared with the dynamic policy contract. The security agent within the trusted computing engine automatically rewrites the query or script to ensure its behavior strictly conforms to the contract.
[0058] For example, the query command "SELECT AVG(age), diagnosis FROM table GROUP BY diagnosis" will be checked. If the policy prohibits outputting a specific diagnosis, the trusted computing engine agent will modify it to "SELECT AVG(age), diagnosis_category FROM table GROUP BY diagnosis_category", where diagnosis_category is a generalized diagnosis category allowed by the contract. Any operation that attempts to bypass the policy will be directly rejected by the trusted computing engine.
[0059] It should be noted that when performing statistical aggregation within the trusted computing engine, the system will automatically inject optimal differential privacy noise according to the privacy budget set in the dynamic policy contract. For analysis systems with high statistical significance requirements, a smaller privacy budget may be allocated, while for exploratory analysis, a larger budget will be allocated to achieve an intelligent balance between privacy protection and data utility.
[0060] In an optional implementation, the trustworthiness assessment of the encrypted medical information data in step S5 can also employ a Secure Multi-Party Computation (SMPC) method, which encrypts the data among multiple medical data processing parties. Each party participates in the computation using a secure computation protocol and provides the computation results without exposing the original data. The computation engine processes this encrypted data and returns the final computation result.
[0061] In another optional implementation, the trust assessment of the encrypted medical information data in step S5 can also be achieved by using a Hardware Security Module (HSM) to provide strong encryption protection for the data and execute all sensitive computational tasks within the module. The computation engine transmits the encrypted data and computational instructions to the HSM module, which verifies the legality and compliance of each computational step to ensure that no leakage or tampering occurs during data processing.
[0062] It should be noted that this invention uses a TEE (Trusted Execution Environment) to establish a trusted computing engine. The TEE provides hardware-level isolation protection to ensure that encrypted data is not leaked or tampered with during the computing process. Even if the system is attacked, the data can still be executed in a secure computing environment, preventing external malware or unauthorized access from illegally manipulating the data.
[0063] In step S6, based on the dynamic strategy contract generation process and the trusted computing engine judgment process, an audit and evidence storage chain is established to verify process compliance, including the following steps F1-F3: F1: Automatically records key behaviors based on the dynamic strategy contract generation and execution process and the trusted computing engine's judgment process.
[0064] F2: Establish an audit evidence storage chain based on the recorded key behaviors to store the key behaviors.
[0065] F3: Initiate an audit based on the audit evidence chain to verify the compliance of the collection process.
[0066] In this embodiment of the application, the specific steps for process compliance verification in step S6 are as follows: All critical actions, including the generation and version changes of strategy contracts, data access requests, rewriting of computational logic within the trusted computing engine, summaries of computational results, manual confirmation records, and model fine-tuning events, are packaged into immutable records and written to the audit and evidence storage chain in real time.
[0067] Medical institutions or regulatory agencies can initiate audits at any time, such as verifying whether all calculations of task X within time period Y comply with strategy Z. The on-chain smart contract or verification service will automatically backtrack the relevant records and provide a cryptographic proof, eliminating the need for manual log searching and improving the efficiency and credibility of compliance audits.
[0068] In an optional implementation, the process compliance verification in step S6 can also employ a scheme based on traditional database logs. The system automatically generates log records each time data is accessed, processed, or modified, and stores this log information in the database log table for regular backup and management. To ensure the log information is tamper-proof, the database administrator sets access permissions to restrict modification and deletion operations on the log table, and periodic log audits are performed to manually check each data operation to ensure compliance.
[0069] In another optional implementation, the process compliance verification in step S6 can also employ a centralized compliance monitoring platform. This integrates the medical data processing system with the compliance monitoring platform. The medical data processing system captures each operational event and sends it to the compliance monitoring platform in real time for storage and analysis. The compliance monitoring platform has a compliance rule base that judges whether the operation meets preset compliance standards based on the real-time recorded operation logs and triggers alarms.
[0070] It should be noted that this invention establishes an audit and evidence storage chain for process compliance verification. This chain utilizes blockchain technology, ensuring that all recorded critical data operations, once written to the chain, cannot be modified or deleted. Each operation is recorded in an encrypted manner, and any attempt to tamper with the data will be publicly revealed. All critical operations, including data access, processing, and modification, are recorded in real-time on the audit and evidence storage chain. Whether for historical data review or future compliance audits, every step of the data operation can be viewed through the audit and evidence storage chain.
[0071] In summary, this invention establishes an efficient and flexible data privacy protection and compliance management mechanism based on dynamic policy contracts, solving the problems of insufficient privacy protection and lack of dynamic compliance verification in traditional medical data sharing methods. By combining a trusted computing engine and an audit and evidence storage chain, it ensures the secure sharing and collaborative computing of medical data in an encrypted state. Furthermore, the real-time generation and execution of dynamic policy contracts solves the problem that traditional static rules cannot cope with diverse data usage scenarios.
[0072] Example 3 is an embodiment of the present invention, which provides a medical data security collection system for all scenarios, including: a collection module, a strategy generation module, a standardization module, a semantic analysis module, a trust judgment module, and a compliance verification module; The acquisition module connects to the information system of medical institutions to acquire raw medical information data from medical institutions in real time. The strategy generation module is based on the data privacy protection and management requirements of medical institutions, and establishes a strategy generation engine to generate dynamic strategy contracts. The standardization module executes dynamic strategy contracts, establishes and trains a clinical natural language processing model, performs sensitive identification on raw medical information data, and obtains desensitized medical information data. The semantic analysis module establishes a semantic mapping model based on the de-identified medical information data to perform semantic analysis on the de-identified medical information data, thereby obtaining encrypted medical information data. The trust judgment module is based on encrypted medical information data and deploys a trusted computing engine to perform trust judgment on the encrypted medical information data. The compliance verification module establishes an audit and evidence storage chain to verify process compliance based on the dynamic strategy contract generation process and the trusted computing engine judgment process.
[0073] This embodiment also provides an electronic device applicable to a method for secure collection of medical data across all scenarios, comprising: a memory and a processor; the memory is used to store computer-executable instructions, and the processor is used to execute the computer-executable instructions to implement the method for secure collection of medical data across all scenarios proposed in the above embodiment.
[0074] This embodiment also provides a storage medium on which a computer program is stored. When the program is executed by a processor, it implements a method for secure collection of medical data for all scenarios as proposed in the above embodiments.
[0075] The storage medium proposed in this embodiment and the method for secure collection of medical data for all scenarios proposed in the above embodiments belong to the same inventive concept. Technical details not described in detail in this embodiment can be found in the above embodiments, and this embodiment has the same beneficial effects as the above embodiments.
[0076] Based on the above description of the implementation methods, those skilled in the art can clearly understand that the present invention can be implemented using software and necessary general-purpose hardware, and of course, it can also be implemented using hardware, but in many cases the former is a better implementation method. Based on this understanding, the technical solution of the present invention, or the part that contributes to the prior art, can be embodied in the form of a software product. This computer software product can be stored in a computer-readable storage medium, such as a computer floppy disk, read-only memory (ROM), random access memory (RAM), flash memory, hard disk, or optical disk, etc., including several instructions to cause a computer device (which may be a personal computer, server, or network device, etc.) to execute the methods of the various embodiments of the present invention.
[0077] It should be noted that the above embodiments are only used to illustrate the technical solutions of the present invention and not to limit it. Although the present invention has been described in detail with reference to preferred embodiments, those skilled in the art should understand that modifications or equivalent substitutions can be made to the technical solutions of the present invention without departing from the spirit and scope of the technical solutions of the present invention, and all such modifications or substitutions should be covered within the scope of the claims of the present invention.
Claims
1. A method for secure collection of medical data across all scenarios, characterized in that: include, Connect to the information systems of medical institutions to obtain their original medical information data in real time; Based on the data privacy protection and management requirements of medical institutions, a strategy generation engine is established to generate dynamic strategy contracts. Execute dynamic strategy contracts, establish and train clinical natural language processing models, perform sensitivity identification on raw medical information data, and obtain desensitized medical information data; Based on the de-identified medical information data, a semantic mapping model is established to perform semantic analysis on the de-identified medical information data to obtain encrypted medical information data. Based on encrypted medical information data, deploy a trusted computing engine to make a trustworthy judgment on the encrypted medical information data; Based on the dynamic strategy contract generation process and the trusted computing engine judgment process, an audit and evidence storage chain is established to verify process compliance.
2. The method for secure collection of medical data across all scenarios as described in claim 1, characterized in that: The information system connected to the medical institution acquires the institution's original medical information data in real time, including: Establish data communication interfaces based on the information systems of medical institutions; Based on the data communication interface, structured and semi-structured medical records from the medical institution's information system are acquired in real time. Medical information data; Structured and semi-structured medical information data are integrated to obtain raw medical information data.
3. The method for secure collection of medical data across all scenarios as described in claim 2, characterized in that: Based on the data privacy protection and management requirements of medical institutions, a strategy generation engine is established to generate dynamic strategy contracts, including: Receive and analyze the data privacy protection and management requirements of medical institutions, and clarify the protection and management objectives; Develop data access control and processing rules based on protection and management objectives; Based on data access control and processing rules, a strategy generation engine is established to output dynamic strategy contracts.
4. The method for secure collection of medical data across all scenarios as described in claim 3, characterized in that: The execution of the dynamic strategy contract establishes and trains a clinical natural language processing model, performs sensitivity identification on the original medical information data, and obtains anonymized medical information data, including: We collected publicly available medical texts and manually cleaned them to construct a medical language processing training dataset. Establish a clinical natural language processing model and train the model using a medical language processing training dataset. Based on the trained clinical natural language processing model, the input is a dynamic strategy contract and raw medical information data, and the output is de-identified medical information data.
5. A method for secure collection of medical data across all scenarios as described in claim 4, characterized in that: The step involves establishing a semantic mapping model based on the de-identified medical information data to perform semantic analysis on the de-identified medical information data, resulting in encrypted medical information data, including: A semantic mapping model is established to preprocess the anonymized medical information data, resulting in preprocessed anonymized medical information data. Based on the preprocessing process, a closed-loop optimization strategy is implemented to optimize the clinical natural language processing model and semantic mapping model; The preprocessed, de-identified medical information data is encrypted and stored to obtain encrypted medical information data.
6. The method for secure collection of medical data across all scenarios as described in claim 5, characterized in that: The step of deploying a trusted computing engine to perform a trust assessment on the encrypted medical information data includes: Establish a trusted computing engine and deploy it on the local server of the medical institution; After the trusted computing engine is deployed, it is trained locally at the medical institution; Based on the trained trusted computing engine, the obtained encrypted medical information data is assessed for trustworthiness.
7. A method for secure collection of medical data across all scenarios as described in claim 6, characterized in that: The process of establishing an audit and evidence storage chain for compliance verification based on the dynamic strategy contract generation process and the trusted computing engine judgment process includes: Based on the dynamic strategy contract generation and execution process and the trusted computing engine's judgment process, key behaviors are automatically recorded. Establish an audit evidence storage chain based on the recorded key behaviors to store the key behaviors; An audit is initiated based on the audit evidence chain to verify the compliance of the collection process.
8. A medical data security collection system for all scenarios, employing the medical data security collection method for all scenarios as described in any one of claims 1-7, characterized in that, include: The system includes a data acquisition module, a policy generation module, a standardization module, a semantic analysis module, a trustworthiness assessment module, and a compliance verification module. The acquisition module connects to the information system of medical institutions to acquire raw medical information data from medical institutions in real time. The strategy generation module is based on the data privacy protection and management requirements of medical institutions, and establishes a strategy generation engine to generate dynamic strategy contracts. The standardization module executes dynamic strategy contracts, establishes and trains a clinical natural language processing model, performs sensitive identification on raw medical information data, and obtains desensitized medical information data. The semantic analysis module establishes a semantic mapping model based on the de-identified medical information data to perform semantic analysis on the de-identified medical information data, thereby obtaining encrypted medical information data. The trust judgment module is based on encrypted medical information data and deploys a trusted computing engine to perform trust judgment on the encrypted medical information data. The compliance verification module establishes an audit and evidence storage chain to verify process compliance based on the dynamic strategy contract generation process and the trusted computing engine judgment process.
9. A computer device comprising a memory and a processor, wherein the memory stores a computer program, characterized in that, When the processor executes the computer program, it implements the steps of the medical data security collection method for all scenarios as described in any one of claims 1 to 7.
10. A computer-readable storage medium having a computer program stored thereon, characterized in that, When the computer program is executed by the processor, it implements the steps of the medical data security collection method for all scenarios as described in any one of claims 1 to 7.