Systems and methods for asynchronous communication
Patent Information
- Application Number
- EP2024749453
- Authority / Receiving Office
- EP · EP
- Patent Type
- Applications
- Current Assignee / Owner
- Priority Date
- 2023-01-31
- Filing Date
- 2024-01-29
- Publication Date
- 2025-12-10
AI Technical Summary
Current communication systems in medical, legal, and financial contexts often face inefficiencies and security concerns when handling confidential information, particularly due to limitations in access control and the risk of data tampering or unauthorized sharing.
An asynchronous messaging system that allows individuals to control access to confidential information by granting specific permissions to view but not download sensitive data, ensuring integrity and confidentiality through a secure, consent-based approach.
Enables secure and efficient sharing of confidential information while maintaining data integrity by allowing authorized access without risking uncontrolled externalization, transforming access management from a 'deny all' to a 'deny all except authorized individuals' model.
Smart Images

Figure CA2024050101_08082024_PF_FP
Abstract
Description
[0001] SYSTEMS AND METHODS FOR ASYNCHRONOUS COMMUNICATION
[0002] FIELD
[0003] This disclosure relates generally to telecommunications and, more particularly, to systems and methods for asynchronous communication which may involve confidential information.
[0004] BACKGROUND
[0005] Communications in medical, legal, financial and / or other contexts may be impacted by confidentiality, resource availability, and / or other factors related to their nature, which may sometimes make them inefficient, impractical, and / or otherwise suboptimal.
[0006] For example, medicine is often a top-down activity largely dictated by capabilities and restrictions of physicians and other care providers, in which patients can end up as passive voices in decisions and chains of events. Doctors have knowledge, records, limited availability, etc., and patients typically have to wait to consult them, get medical test results, etc. Moreover, in some cases, limitations imposed by a relatively low number of healthcare professionals and significant resources required for each medical consultation put a logistic and financial pressure on healthcare systems and patients.
[0007] Although telecommunications can potentially improve interactions between patients and healthcare professionals (e.g., to make appointments, convey test results, follow up on specific issues, etc.), confidential, sensitive and / or other particular aspects of these interactions can remain of concern. For instance, communication of patients’ health records could involve duplicating and / or creating copies of the health records, and control over these copies may be limited once they are provided to the patients or third parties, putting confidentiality at risk. In some cases, transmission of health records and confidential information may be used with fraudulent motives (e.g., as evidence of medical conditions have been hidden or otherwise tampered with, proofs of vaccination have been fraudulently manipulated and reproduced, etc.).
[0008] Similar challenges can also arise in other contexts, including those where confidential information is shared between different parties, such as in financial (e.g., banking), legal, engineering industries and / or other situations.
[0009] For at least these and other reasons, improvements directed to communication which may involve confidential information would be welcomed.
[0010] SUMMARY
[0011] According to various aspects, this disclosure relates to asynchronous messaging, i.e., texting, instant messaging, chatting, and / or other electronic messaging other than emailing, between participants of online conversations in medical, legal, financial, technical, and / or other contexts, which may involve conveying confidential information (e.g., medical information, legal information, financial information, technical information, etc.), efficiently and securely.
[0012] For instance, in various embodiments, an asynchronous messaging system may enable an individual (e.g., a patient or client), who is using his / her communication device (e.g., smartphone) that identifies and authenticates him / her (e.g., as his / her smartphone can be used as an identity proxy and consent manager) at a backend of the asynchronous messaging system, to effectively control various aspects of a conversation with one or more other participants, including: participation in the conversation, such as who is / are the one or more other participants; sharing of confidential information regarding the individual with the one or more other participants, such as by granting to another participant a right to view confidential information regarding the individual that is stored in a source system (e.g., a medical system, a legal system, a financial system, a technical system, etc.) and that would otherwise be inaccessible to the other participant (e.g., which right to view may be perpetual or limited, such as for a limited period of time and / or a limited number of views, and may be retracted or otherwise withdrawn by the individual) to allow a communication device of the other participant to display the confidential information regarding the individual (e.g., but potentially not download the confidential information regarding the individual) while the confidential information regarding the individual remains unaltered in the source system, thereby preserving integrity (e.g., accuracy, veracity, trustworthiness, etc.) of the confidential information regarding the individual in the source system and avoiding its uncontrolled externalization yet allowing the other participant to view the confidential information regarding the individual as consented to, authorized and triggered by the individual himself / herself (e.g., which may transform management of access to confidential information about the individual in the source system from “deny all information about the individual, to all except possibly the individual, at all times” to “deny all information about the individual, to all except the individual and only a few specific others chosen by the individual under particular conditions, at all times”); etc.
[0013] For example, according to one aspect, this disclosure relates to a system for asynchronous messaging. The system comprises: an interface configured to communicate with a communication device of an individual and a communication device of a participant over a network; and a processing entity comprising a processor and configured to: transmit messages between the communication device of the individual and the communication device of the participant to establish a conversation between the individual and the participant via a graphical user interface (GUI) of the communication device of the individual; allow the individual to share confidential information regarding the individual with the participant in the conversation; and restrict access to the confidential information regarding the individual by the participant in the conversation.
[0014] According to another aspect, this disclosure relates to a computer-implemented method for asynchronous messaging. The computer-implemented method comprises: communicating with a communication device of an individual and a communication device of a participant over a network; transmitting messages between the communication device of the individual and the communication device of the participant to establish a conversation between the individual and the participant via a graphical user interface (GUI) of the communication device of the individual; allowing the individual to share confidential information regarding the individual with the participant in the conversation; and restricting access to the confidential information regarding the individual by the participant in the conversation.
[0015] According to another aspect, this disclosure relates to non-transitory computer-readable storage media storing instructions executable by a processing apparatus to perform a method for asynchronous messaging. When executed by the processing apparatus, the instructions cause the processing apparatus to: communicate with a communication device of an individual and a communication device of a participant over a network; transmit messages between the communication device of the individual and the communication device of the participant to establish a conversation between the individual and the participant via a graphical user interface (GUI) of the communication device of the individual; allow the individual to share confidential information regarding the individual with the participant in the conversation; and restrict access to the confidential information regarding the individual by the participant in the conversation.
[0016] According to another aspect, this disclosure relates to a system for asynchronous messaging. The system comprises: an interface configured to communicate with a communication device of an individual, a communication device of a participant, and a source system over a network; and a processing entity comprising a processor and configured to: transmit messages between the communication device of the individual and the communication device of the participant to establish a conversation between the individual and the participant via a graphical user interface (GUI) of the communication device of the individual; receive an indication that the individual desires to share confidential information regarding the individual stored in the source system with the participant in the conversation; and convey at least part of the confidential information regarding the individual to the communication device of the participant for display of the confidential information regarding the individual on the communication device of the participant in the conversation. According to another aspect, this disclosure relates to a computer-implemented method for asynchronous messaging. The computer-implemented method comprises: communicating with a communication device of an individual, a communication device of a participant, and a source system over a network; transmitting messages between the communication device of the individual and the communication device of the participant to establish a conversation between the individual and the participant via a graphical user interface (GUI) of the communication device of the individual; receiving an indication that the individual desires to share confidential information regarding the individual stored in the source system with the participant in the conversation; and conveying at least part of the confidential information regarding the individual to the communication device of the participant for display of the confidential information regarding the individual on the communication device of the participant in the conversation.
[0017] According to another aspect, this disclosure relates to non-transitory computer-readable storage media storing instructions executable by a processing apparatus to perform a method for asynchronous messaging. When executed by the processing apparatus, the instructions cause the processing apparatus to: communicate with a communication device of an individual, a communication device of a participant, and a source system over a network; transmit messages between the communication device of the individual and the communication device of the participant to establish a conversation between the individual and the participant via a graphical user interface (GUI) of the communication device of the individual; receive an indication that the individual desires to share confidential information regarding the individual stored in the source system with the participant in the conversation; and convey at least part of the confidential information regarding the individual to the communication device of the participant for display of the confidential information regarding the individual on the communication device of the participant in the conversation.
[0018] According to another aspect, this disclosure relates to a system for asynchronous messaging. The system comprises: an interface configured to communicate with a communication device of an individual, a communication device of a participant, and a source system over a network; and a processing entity comprising a processor and configured to: transmit messages between the communication device of the individual and the communication device of the participant to establish a conversation between the individual and the participant via a graphical user interface (GUI) of the communication device of the individual; allow the individual to grant to the participant a right to view confidential information regarding the individual that is stored in the source system in the conversation; and convey at least part of the confidential information regarding the individual to the communication device of the participant in the conversation.
[0019] According to another aspect, this disclosure relates to a computer-implemented method for asynchronous messaging. The computer-implemented method comprises: communicating with a communication device of an individual, a communication device of a participant, and a source system over a network; transmitting messages between the communication device of the individual and the communication device of the participant to establish a conversation between the individual and the participant via a graphical user interface (GUI) of the communication device of the individual; allowing the individual to grant to the participant a right to view confidential information regarding the individual that is stored in the source system in the conversation; and conveying at least part of the confidential information regarding the individual to the communication device of the participant in the conversation
[0020] According to another aspect, this disclosure relates to non-transitory computer-readable storage media storing instructions executable by a processing apparatus to perform a method for asynchronous messaging. When executed by the processing apparatus, the instructions cause the processing apparatus to: communicate with a communication device of an individual, a communication device of a participant, and a source system over a network; transmit messages between the communication device of the individual and the communication device of the participant to establish a conversation between the individual and the participant via a graphical user interface (GUI) of the communication device of the individual; allow the individual to grant to the participant a right to view confidential information regarding the individual that is stored in the source system in the conversation; and convey at least part of the confidential information regarding the individual to the communication device of the participant in the conversation.
[0021] According to another aspect, this disclosure relates to a system for asynchronous messaging. The system comprises: an interface configured to communicate with a communication device of an individual, a communication device of a participant, and a plurality of source systems that are uninteroperable over a network; and a processing entity comprising a processor and configured to: transmit messages between the communication device of the individual and the communication device of the participant to establish a conversation between the individual and the participant via a graphical user interface (GUI) of the communication device of the individual; receive an indication that the individual desires to share confidential information regarding the individual stored in respective ones of the source systems with the participant in the conversation; and convey at least part of the confidential information regarding the individual to the communication device of the participant for display of the confidential information regarding the individual on the communication device of the participant in the conversation.
[0022] According to another aspect, this disclosure relates to a computer-implemented method for asynchronous messaging. The computer-implemented method comprises: communicating with a communication device of an individual, a communication device of a participant, and a plurality of source systems that are uninteroperable over a network; transmitting messages between the communication device of the individual and the communication device of the participant to establish a conversation between the individual and the participant via a graphical user interface (GUI) of the communication device of the individual; receiving an indication that the individual desires to share confidential information regarding the individual stored in respective ones of the source systems with the participant in the conversation; and conveying at least part of the confidential information regarding the individual to the communication device of the participant for display of the confidential information regarding the individual on the communication device of the participant in the conversation.
[0023] According to another aspect, this disclosure relates to non-transitory computer-readable storage media storing instructions executable by a processing apparatus to perform a method for asynchronous messaging. When executed by the processing apparatus, the instructions cause the processing apparatus to: communicate with a communication device of an individual, a communication device of a participant, and a plurality of source systems that are uninteroperable over a network; transmit messages between the communication device of the individual and the communication device of the participant to establish a conversation between the individual and the participant via a graphical user interface (GUI) of the communication device of the individual; receive an indication that the individual desires to share confidential information regarding the individual stored in respective ones of the source systems with the participant in the conversation; and convey at least part of the confidential information regarding the individual to the communication device of the participant for display of the confidential information regarding the individual on the communication device of the participant in the conversation.
[0024] These and other aspects of this disclosure will now become apparent to those of ordinary skill in the art upon review of a description of embodiments that follows in conjunction with accompanying drawings.
[0025] BRIEF DESCRIPTION OF DRAWINGS
[0026] A detailed description of embodiments is provided below, by way of example only, with reference to accompanying drawings, in which:
[0027] Figure 1 shows an embodiment of a system comprising a messaging manager configured to allow asynchronous messaging between participants of online conversations; Figure 2 shows an embodiment of a source system that may store confidential information regarding one or more of the participants;
[0028] Figures 3 to 6 show embodiments of a database of the source system;
[0029] Figures 7A and 7B show embodiments of the messaging manager in the system of Figure 1 ;
[0030] Figure 8 shows an embodiment of an identity management hub of the messaging manager;
[0031] Figure 9 shows an embodiment of an intermediation hub and a conversation hub of the messaging manager;
[0032] Figure 10 shows an embodiment of the conversation hub comprising a database accessible to the messaging manager;
[0033] Figures 11 A and 1 1 B show embodiments of the system in a medical context;
[0034] Figure 12 shows an embodiment of a clinic system;
[0035] Figure 13 shows an embodiment of possible components of a conversation;
[0036] Figure 14 shows a variant of graphical elements displayed on a graphical user interface (GUI) of a communication device for creating a conversation;
[0037] Figures 15 to 23 show examples of graphical elements of a conversation between the participants displayed on GUIs of communication devices of the respective ones of the participants; Figure 24 shows an embodiment for providing an attachment as part of the conversation;
[0038] Figure 25 shows a hierarchy between related conversations according to an embodiment;
[0039] Figure 26 shows an embodiment of the intermediation comprising data associating a user account of the system with corresponding user accounts of different source systems; and
[0040] Figure 27 shows an embodiment of a processing apparatus.
[0041] It is to be expressly understood that the description and drawings are only for purposes of illustrating certain embodiments and are an aid for understanding. They are not intended to be and should not be limiting.
[0042] DETAILED DESCRIPTION OF EMBODIMENTS
[0043] Figure 1 shows an embodiment of a system 1 10 comprising a communication apparatus 120 implementing a messaging manager 130 configured to allow asynchronous messaging, i.e., texting, instant messaging, chatting, and / or other electronic messaging other than emailing, between participants, including users 210 and other participants 310, of online conversations in medical, legal, financial, technical, and / or other contexts, which may involve conveying confidential information (e.g., medical information, legal information, financial information, technical information, etc.), such as confidential information that may be stored in source systems 510, efficiently and securely. Communication is asynchronous in that it is not required to occur in real-time as each of the users 210 and the other participants 310 is free to start, pause and resume online conversations when they want.
[0044] The users 210 are individuals, such as patients in medical situations, clients in legal, financial, technical, or other situations, and / or other people, who are communicating with the other participants 310 for services, tasks, and / or other purposes. For example, in some embodiments, the other participants 310 may include professionals such as medical professionals (e.g., physicians, nurses and / or other clinicians, laboratory workers, medical administrators, pharmacists, etc.), legal professionals (e.g., lawyers, paralegals, legal administrators, etc.), financial professionals (e.g., bankers, financial administrators, insurers, etc.), technical professionals (e.g., engineers, architects, designers, etc.), and / or other professionals. In some embodiments, the other participants 310 may include chatbots (i.e. , software configured to conduct online chat conversations).
[0045] Communication devices 220 of the users 210 and communication devices 320 of the other participants 310 can communicate with the messaging manager 130 and with one another over a network 140, which may be implemented by one or more of a data network (e.g., the Internet, an intranet), a wireless network (e.g., a cellular network, a satellite network, etc.), and / or any other telecommunications network. Respective ones of the communication devices 220, 320 and / or the messaging manager 130 can thus communicate with one another, i.e., receive and / or transmit information (e.g., data, signals, etc.) from and / or to one another, over one or more communication links of the network 140 that may each be wireless, wired, or partly wireless and partly wired (e.g., WiFi or other wireless LAN, WiMAX or other wireless WAN, cellular, satellite, Bluetooth or other short-range or near-field wireless connectivity, Universal Serial Bus (USB), etc.).
[0046] As further discussed herein, in this embodiment, the messaging manager 130 is configured to enable a user 210 (e.g., a patient or client), who is using his / her communication device 220 (e.g., smartphone) that identifies and authenticates him / her (e.g., as his / her smartphone can be used as an identity proxy and consent manager) at the messaging manager 130 and / or other backend components of the system 1 10, to effectively control various aspects of a conversation with one or more other participants 310, including: participation in the conversation, such as who is / are the one or more other participants 310; sharing of confidential information regarding the user 210 with the one or more other participants 310, such as by granting to another participant 310 a right to view confidential information regarding the user 210 that is stored in a source system 510 and that would otherwise be inaccessible to the other participant 310 (e.g., which right to view may be perpetual or limited, such as for a limited period of time and / or a limited number of views, and may be retracted or otherwise withdrawn by the user 210) to allow a communication device 320 of the other participant 310 to display the confidential information regarding the user 210 (e.g., but potentially not download the confidential information regarding the user 210) while the confidential information regarding the user 210 remains unaltered in the source system 510, thereby preserving integrity (e.g., accuracy, veracity, trustworthiness, etc.) of the confidential information regarding the user 210 in the source system 510 and avoiding its uncontrolled externalization yet allowing the other participant 310 to view the confidential information regarding the user 210 as consented to, authorized and triggered by the user 210 himself / herself (e.g., which may transform management of access to confidential information about the user 210 in the source system 510 from “deny all information about the user 210, to all except possibly the user 210, at all times” to “deny all information about the user 210, to all except the user 210 and only a few specific others chosen by the user 210 under particular conditions, at all times”); etc.
[0047] For example, in some embodiments, a communication device 220 of a user 210 may be a smartphone, a tablet, laptop or other personal computer, a smartwatch or other wearable device, or any other communication device carried (e.g., worn, held, or otherwise transported) by or otherwise associated with the user 210. Similarly, in some embodiments, a communication device 320 of another participant 310 may be a smartphone, a tablet, laptop or other personal computer, a smartwatch or other wearable device, or any other communication device carried (e.g., worn, held, or otherwise transported) by or otherwise associated with the participant 310. The communication device 220 or 320 may include a user interface comprising one or more input elements (e.g., buttons, dials, and / or other manual controls which may be physical and / or virtual, a microphone, a camera, etc.) configured to receive input (e.g., commands, information, etc.) from the user 210 or participant 310 and one or more output elements (e.g., a display, a speaker, etc.) configured to convey output (e.g., information, etc.) to the user 210 or participant 310. In some embodiments, the user interface of the communication device 220 or 330 may comprise a graphical user interface (GUI) configured to graphically convey output (e.g., information) to and graphically receive input (e.g., commands, information, etc.) from the user 210 or participant 310 via a display of the communication device 220 or 320. In some cases, the user interface of the communication device 220 or 320 may implement a biometric identification unit to identify the user 210 or participant 310 with a biometric (e.g., face, eye (e.g., iris or retina), voice, fingerprint, DNA, vein pattern, etc.) of the user 210 or participant 310 (e.g., as a camera for facial, iris, retina, etc. recognition, a fingerprint scanner, a microphone for voice recognition, etc.).
[0048] As another example, in some embodiments, a communication device 320 of another participant 310 may be a server or other computer (e.g., implementing a website and / or an application) associated with the participant 310. In some examples, the server or other computer 320 may be part of a computer system including one or more other servers and / or other communication devices 320 associated with the participant 310.
[0049] In some cases, such as where a communication device 220 or 320 is a smartphone, tablet, smartwatch, or other communication device carried by a user 210 or another participant 310, communication between the messaging manager 130 and the communication device 220 or 320 may be direct, i.e., without any intermediate communication device. In other cases, such as where a communication device 320 is a server, communication with the communication device 320 may be indirect, e.g., through one or more additional communication devices. For example, in some embodiments, the communication device 320 may communicate with a WiFi hotspot or cellular base station, which may provide access to the Internet or another network, thereby allowing the communication device 320 to communicate.
[0050] In some embodiments, such as where a communication device 220 or 320 is a smartphone, tablet, smartwatch, or other communication device carried by a user 210 or another participant 310, the user 210 or participant 310 may download an application (app) from a repository (e.g., Apple App Store, Google Play, etc.) onto the smartphone, tablet, smartwatch, or other communication device. Upon activation of the app on the smartphone, tablet, smartwatch, or other communication device, the user 210 or participant 310 may use functionalities relating to the messaging manager 130 locally on the smartphone, tablet, smartwatch, or other communication device. In addition, a data connection can be established over the network 140 with the messaging manager 130 that may execute a complementary server-side application.
[0051] In this embodiment, the source systems 510 are configured to store and process confidential information that may be exchanged during online conversations between the users 210 and the other participants 310. Each of the source systems 510 is an authoritative data source for confidential information that is trusted by the users 210 and the other participants 310. In that sense, the source systems 510 may also be referred to as trusted sources of confidential information.
[0052] For instance, in some embodiments, as shown in Figure 2, a source system 510 is a computer system (e.g., comprising one or more servers and / or other computers) implementing a data manager 520 that has access to a database 530 storing confidential information and is configured to communicate with external communication equipment, such as the messaging manager 130, the communication devices 220 of the users 210, the communication devices 320 of the other participants 310, and / or other communication equipment (e.g., servers or other computers of other organizations, smartphones, tablets, laptops or other personal computers of other persons, etc.), over the network 140. In some cases, the database 530 may contain records 540 associated with different persons (e.g., respective ones of the users 210), where each record 540 includes confidential information regarding a given one of these different persons (e.g., a given one of the users 210). In some examples, the server or other computer 320 may be part of a computer system including one or more other servers and / or other communication devices 320 associated with the participant 310.
[0053] As an example, in some embodiments, in a medical context, a source system 510 may be an electronic health record (EHR) system configured to store and process confidential information that is medical information regarding respective ones of the users 210 who are patients of a healthcare organization (e.g., a private or public healthcare establishment including one or more hospitals, clinics, and / or other healthcare facilities). As shown in Figure 3, each record 540 in the database 530 of the EHR system 510 is an electronic health record about a patient 210 that includes medical information regarding the patient 210, such as an identity (e.g., name, date of birth, etc.), a medical history, diagnoses (e.g., diseases, injuries, and / or other conditions), medical tests (e.g., images from radiography, ultrasonography, magnetic resonance imaging, or other radiology, bloodwork, genetic testing, and / or other tests conducted in laboratories or medical facilities), treatments (e.g., prescriptions and other medications), and / or other data about the patient 210.
[0054] As another example, in some embodiments, in a financial context, a source system 510 may be a financial system of a bank or other financial institution configured to store and process confidential information that is financial information regarding respective ones of the users 210 who are clients of the bank or other financial institution. As shown in Figure 4, each record 540 in the database 530 of the financial system 510 includes financial information regarding a client 210, such as an identity (e.g., name, date of birth, etc.), financial account data (e.g., account number, balance, etc.), financial documentation (e.g., one or more contracts, such as mortgages, title documents, and / or any other agreements, certificates, etc.), and / or other data about the client 210.
[0055] As yet another example, in some embodiments, in a legal context, a source system 510 may be a legal system of a law firm or other legal institution configured to store and process confidential information that is legal information regarding respective ones of the users 210 who are clients of the law firm or other legal institution. As shown in Figure 5, each record 540 in the database 530 of the legal system 510 includes legal information regarding the client 210, such as an identity (e.g., name, date of birth, etc.), legal documentation (e.g., one or more contracts, such as wills, leases, title documents, and / or any other agreements, certificates, etc.), and / or other data about the client 210.
[0056] As yet another example, in some embodiments, in a technical context, a source system 510 may be a technical system of an engineering company, architectural firm or other technical institution configured to store and process confidential information that is technical information regarding respective ones of the users 210 who are clients of the engineering company, architectural firm or other technical institution. As shown in Figure 6, each record 540 in the database 530 of the technical system 510 includes technical information regarding the client 210, such as an identity (e.g., name, date of birth, etc.), technical documentation (e.g., plans, designs, etc. relating to projects involving the client 210), and / or other data about the client 210.
[0057] The messaging manager 130 is configured to communicate with the communication devices 220 of the users 210 and the communication devices 320 of the other participants 310 over the network 140 and allow asynchronous messaging, including online conversations, between the users 210 and the other participants 310. More precisely, in this embodiment, the messaging manager 130 may be configured to be essential to the online conversations between the users 210 using the communications devices 220 and the other participants 310 using the communication devices 320, such as when the online conversations may have confidentiality requirements. For instance, the system 1 10 may be configured to prevent direct communication (i.e., communication that is not going through the messaging manager 130) between the communications devices 220 of the users 210 and the communication devices 320, particularly when it would have a confidential nature.
[0058] In this embodiment, the messaging manager 130 is configured to communicate with the source systems 510 to allow confidential information stored in the source systems 510 to be conveyed to the users 210 and / or the other participants 310, as part of their online conversations, when desired by whoever among these participants controls that confidential information. For example, in some embodiments, as part of an online conversation between a particular user 210 and another participant 310, the messaging manager 130 may allow the user 210 to share confidential information regarding himself / herself stored in a source system 510 with the other participant 310. For instance, in some cases, the messaging manager 130 may be configured to cause a communication device 320 of the other participant 310 to display the confidential information regarding the user 210 so that the other participant 310 can view it, while the confidential information regarding the user 210 remains unaltered in the source system 510, thereby preserving its integrity (e.g., accuracy, veracity, trustworthiness, etc.). Thus, the messaging manager 130 may allow the user 210 to grant the other participant 310 a right to view the confidential information regarding the user 210 while, in some cases, precluding the participant 310 from downloading a file or other part of a record 540 containing that confidential information in the source system 510. In some embodiments, the right to view the confidential information regarding the user 210 may be permanent or otherwise perpetual, and in other embodiments, the right to view the confidential information regarding the user 210 may be limited (e.g., temporary). For instance, in some cases, the messaging manager 130 may allow the user 210 to grant the other participant 310 a right to view that is limited in time and / or in a number of views of the confidential information. Also, in some cases, the messaging manager 130 may allow the user 210 to retract or otherwise withdraw the right to view the confidential information granted to the participant 310.
[0059] In this embodiment, as shown in Figures 7A and 7B, the messaging manager 130 may comprise a router 132, an identity management hub 134 and an intermediation hub 136. In some embodiments, also, the messaging manager 130 may have access to (e.g., include and / or be connected to) a conversation hub 138.
[0060] The router 132 may be configured to provide an interface and to manage routing, consent intermediation, audit trails and workflows between the communication devices 220, 320, the identity management hub 134 and the intermediation hub 136. For instance, the router 132 and the communication devices 220, 320 may be configured to convey information relating to an activation of a user account, a connection of the user account, notifications, conversation data, etc., to one another through signals 41 1. When a connection from one of the communication devices 220, 320 occurs, the router 132 and the identity management hub 134 may be configured to convey identity and user account information to one another by exchanging signals 423. In particular, the router 132 may be configured to generate a signal 423 representative of data of the user account to the identity management hub 134 upon connection with the communication device 220. The identity management hub 134 is in communication with the router 132 and may be configured to identify user accounts and reconciliate user accounts with identities. That is, in this embodiment, as shown in Figure 8, the identity management hub 134 is configured to associate each user account with an identity and to reject suspicious accounts such as duplicate accounts on specific identities upon a first connection of the user account to the system 1 10. The identity management hub 134 is also configured to store information about relationships (e.g., family relationships, legal representative relationships (e.g., a surrogacy relationship), etc.) between identities associated with user accounts. To these ends, the identity management hub 134 may be in communication with one or more identification verification providers 190 which may be governmental systems, private systems, etc. The identity verification providers 190 may hold confidential and / or non-confidential identity data associated with each identity. In some embodiments, the identity verification providers 190 may be fully automated, while in some embodiments, the providers involve human input (e.g., identification verification agents) to assess whether there is a match between the data of the user account and a specific identity.
[0061] The intermediation hub 136 is configured to provide a source-system interface to the source systems 510 and to manage logs, audit trails and payload tunnels between the router 132, the conversation hub 138 and the source systems 510. For instance, in this embodiment, the intermediation hub 136 and the router 132 may be configured to convey information to each other by exchanging signals 435. In this embodiment, the intermediation hub 136 and a source system 510 may be configured to convey information to each other by exchanging signals 459. In particular, the intermediation hub 136 may be configured to emit a signal 459 conveying information relative to a client (e.g., a specific one of the users 210 and other participants 310) having a user account in the system 1 10. The source system 510, for its part, may be configured to convey information such as records, documents, conversations, etc., to the intermediation hub 136 through the signal 459. In some examples, the intermediation hub 136 may comprise mostly metadata relating to the conversations established via the conversation hub 138 and to the records of source systems 510. This may advantageously decrease memory requirements of the intermediation hub 136 in addition to avoiding duplication of confidential information. More specifically, in this embodiment, the intermediation hub 136 does not hold any conversation data.
[0062] Rather, in this embodiment, the conversation hub 138 may be configured to hold the conversation data. In particular, in this embodiment, the conversation hub 138 may be configured to hold ledgers 139 of the conversations. More specifically, in this embodiment, the conversation hub 138 is configured for storing records 170 containing information regarding online conversations between the users 210 and the other participants 310 through the messaging manager 130, such as the ledgers 139. For example, as further discussed below, in some cases, the ledger 139 of a conversation may contain identities of participants of a given conversation, messages transmitted between the participants during the given conversation, and / or any other information regarding the given conversation. As another example, in some cases, a record 170 may contain a listing of one or more conversations involving a given user 210 or other participant 310, and / or any other information regarding the one or more conversations involving a given user 210 or other participant 310.
[0063] As shown in Figure 9, the intermediation hub 136 and the conversation hub 138 may be in communication with one another through a signal 447 conveying conversation data (e.g., such as messages, attachments, records 170, etc.) In some embodiments, the conversation hub 138 may be part of the messaging manager 130, while in other embodiments, the conversation hub 138 may be external to the messaging manager 130 and may be in communication with the intermediation hub 136 of the messaging manager 130 over the network 140.
[0064] The communication apparatus 120 implementing the messaging manager 130 may comprise one or more servers and / or other computers. For instance, in various embodiments, the router 132, the identity management hub 134, the intermediation hub 136 and the conversation hub 138 may be implemented by a single server or other computer or by two or more common or distinct servers and / or other computers.
[0065] For example, as shown in Figure 10, in some embodiments, the conversation hub 138 may comprise a database 160 which, as mentioned above, may be part of the messaging manager 130 or may be external to the messaging manager 130.
[0066] The ledger 139 of a conversation is a structured record of information exchanged between the participants, such as one or more of the users 210 and / or one or more of the other participants 310, of the conversation. The ledger 139 may contain information about at least some of (i.e., some of, a majority of, or all of) the aspects of the life-cycle of the conversation. For example, in some embodiments, this may include one or more of:
[0067] - a formal information exchange between the participants of the conversation.
[0068] - a topic of the conversation, such as, for example: a health-care episode of a patient; a financial transaction; an asset acquisition transaction; a call for tenders; a formal interaction record between a clinical trial team and an enrolled participant; etc.
[0069] - details of each participant of the conversation, for whom specific rights and responsibilities have been identified (and recorded) in regard to the conduct or the information exchanges carried in the conversation. In some embodiments, these details may also contain data relative to a life cycle of each participant in the conversation (e.g., added / removed / assigned by whom, when, with whose consent).
[0070] - a proof of identity of each participant of the conversation, including information such as: how the proof of identity was established; by whom the proof of identity was established; based on which recognizable identifying documents the proof of identity was established; etc.
[0071] - assignation details, including which participant is assigned the responsibility of responding next, at which time, etc. - a location of the conversation. In some embodiments, a single conversation may exist simultaneously in multiple locations, and each location may have one or more participants tasked to responding next.
[0072] - messages of the conversation. In some embodiments, each message may be plain texts authored by a participant, or a form of questionnaire issued by one of the participants, that may be completed by a specific set of participants.
[0073] - details of each message, such as: who authored each message, when, where (location), to whom (consented audience of participants), etc.
[0074] - status details of each message, such as: a message delivery date to each participant; details (time, location, etc.) regarding which participant saw and / or acknowledged receipt of each message, etc.
[0075] - acknowledgement details, such as a list of items (messages, attachments) requiring an acknowledgement, a participant and a deadline for making such acknowledgement, etc. In some embodiments, acknowledgement details may include a listing of fallback mechanisms set for each acknowledgement.
[0076] - etc.
[0077] In this embodiment, each ledger 139 may be human-readable. That is, the ledger 139 may be configured to be readable and understandable by a human and may be written in human language (e.g., English, French, Spanish, Mandarin, etc.). In this embodiment, also, the ledger 139 may be configured to advantageously improve auditability. For instance, the ledger 139 may be visible and accessible to participants of the conversation it is associated with. Furthermore, in this embodiment, the ledger 139 may be configured to advantageously improve traceability. For instance, every access to a message, a status entry, or document may be recorded in the ledger 139 when executed. In this embodiment, the ledger 139 may be permanent, i.e., the messaging manager 130 may be configured to prevent deleting parts or all of the ledger 139. Furthermore, in this embodiment, the ledger 139 may be configured to advantageously improve accountability. For instance, for some entries (message, document, other) in the conversation, the author of the entries may require that specific accesses take place (for example an author may require that a user 210 or other participant 310 acknowledge receipt of the entry). As another example, as further discussed below, the conversation hub 138 may be configured to advantageously implement fallback access mechanisms to ensure that appropriate actions take place when required.
[0078] In some embodiments, the communication apparatus 120 implementing the messaging manager 130 may also implement additional functional modules. For instance, in some embodiments, the communication apparatus 120 may implement one or more functional modules allowing the users 210 and / or the other participants 310 to use their communication devices 220 and / or 320 to: access (e.g., view) their confidential information stored in the source systems 510, outside of any online conversation that may be occurring through the messaging manager 130; share at least part of their confidential information stored in the source systems 510 with one or more third parties, outside of any online conversation that may be occurring through the messaging manager 130; be notified when modifications to their confidential information stored in the source systems 510 occur (e.g., new confidential information is added to their records 540 in the source systems 510) via notifications sent to their communication devices 220 and / or 320; etc.
[0079] More specifically, in this embodiment, the system 1 10 may be configured to advantageously maintain integrity of the confidential information stored in the source system 510. In particular, documents and messages originating from the source system 510 may remain in the source system 510 and not be alterable. Also, in this embodiment, information exchanged in the conversations is consent-based. In particular, only consented messages and consented confidential information (e.g., attachments conveying confidential information) can be viewed by participants to whom a read consent is granted. When a consent is revoked, access is not provided moving forward.
[0080] In this embodiment, also, the ledger 139 may contain other information relative to the conversation, including:
[0081] - acknowledgement details on attachments including confidential information.
[0082] - attachment details, such as a name and a description of each attachment, an indication of which participant to the conversation added it, at what time, from where, how, with access consents granted to whom, etc. In some examples, the attachments may originate from the source system 510 and be accessible to be consulted by specific participants. Non-limiting examples of attachments may include: a medical record; a laboratory report; annotations that a MD can place in a patient's file within their electronic medical records system; a draft notarial act; a contract draft; a signed contract; a technical plan or design; etc.
[0083] - attachment access details, such as an indication of which participant to the conversation accessed each attachment, at what time, from where, how, with access consents granted by whom, etc.
[0084] - details regarding a consent to access attachments, such as an indication of when the consent is registered, by whom, for what reason, until when, how many times executable, etc.
[0085] Although separately shown, in some embodiments, the communication apparatus 120 implementing the messaging manager 130 may be part of another component of the system 110, such as a given one of the source systems 510 or another computer system (e.g., associated with a participant).
[0086] Specific examples of operation of the messaging manager 130 for asynchronous messaging between users 210 and other participants 310 will now be discussed in relation to some embodiments in a medical context where the users 210 are patients and the other participants 310 are medical professionals (e.g., physicians, nurses and / or other clinicians, laboratory workers, medical administrators, etc.) and / or medical chatbots (e.g., Al software to book appointments, deliver test results, invite human participants, provide documentation, etc.) providing medical services to the patients 210. It is to be understood that similar principles apply in other embodiments in legal, financial, technical, and / or other contexts.
[0087] With reference to Figures 1 1 A and 1 1 B, in some embodiments, a patient 210 with a smartphone 220 is followed by a physician of a clinic associated with a clinic system 610 having access to (e.g., including and / or connected to) an EHR system 510 storing medical information regarding the patient 210, one or more communication devices 320 (e.g., servers or other computers, smartphones, tablets, laptops or other personal computers, etc.), and the communication apparatus 120 implementing the messaging manager 130.
[0088] The clinic system 610 and the messaging manager 130 allow online conversations between the patient 210 and one or more other participants 310, including the physician of the patient 210 and possibly one or more other participants, such as an administrator of the clinic, a chatbot associated with the clinic, one or more other individuals working or otherwise associated with the clinic, and / or one or more other participants unassociated with the clinic (e.g., one or more other physicians associated with another medical establishment, laboratory workers, pharmacists, etc.).
[0089] In addition to facilitating online conversations between the patient 210 and one or more other participants 310, in this embodiment, the clinic system 610 may be configured such that the patient 210 can use his / her smartphone 220 to: access (e.g., view) his / her medical information stored in the EHR system 510, outside of any online conversation that may be occurring through the messaging manager 130; share at least part of his / her medical information stored in the EHR system 510 with one or more third parties, outside of any online conversation that may be occurring through the messaging manager 130; be notified when modifications to his / her medical information stored in the EHR system 510 occur (e.g., new medical information is added to his / her record 540 in the EHR system 510) via notifications sent to his / her smartphone 220; etc. For example, in some embodiments, the clinic system 610 may implement functionalities described in U.S. Patent Application Publication 2021 / 0343382 and / or International Application Publication WO2021 237345, which are incorporated by reference herein.
[0090] As shown in Figure 12, the clinic system 610 may include a database 630 containing records 640 for patients of the clinic, including the patient 210. In some embodiments, such as where the clinic system 610 is distinct from the EHR system 510, the database 630 and the records 640 of the clinic system 610 may be respectively distinct from the database 530 and the records 540 of the EHR system 510. In other embodiments, such as where the clinic system 610 comprises the EHR system 510, the database 630 and the records 640 of the clinic system 610 may be respectively correspond to the database 530 and the records 540 of the EHR system 510.
[0091] In this embodiment, to enable online conversations through the messaging manager 130 and other functionalities provided by the clinic system 610, the patient 210 can be identified and authenticated using his / her smartphone 220. Thus, the patient’s smartphone 220 can be used as an identity proxy and consent manager for him / her.
[0092] For instance, in this embodiment, during a provisioning (e.g., registration) phase, the patient 210 can use his / her smartphone 220 to download an app and register for functionalities of the messaging manager 130 and the clinic system 610. More particularly, in this embodiment, the app may prompt the smartphone 220 to communicate with the router 132 of the messaging manager 130 over the network 140 through a signal 41 1 for allowing the messaging manager 130 to create a user account 212 for the patient 210.
[0093] As part of this process, the patient 210 provides identification information including his / her name, date of birth, and possibly other information about himself / herself to establish his / her identity as well as evidence of his / her identity. For example, in some cases, this evidence may include information from a driver’s license, a healthcare card, a passport, and / or other government-issued identification document, which may be inputted via the user interface of the smartphone 220 (e.g., by manually entering it, by taking a picture of the government-issued identification document) or may be presented (e.g., physically shown or displayed on-screen) to a human IVA of the identity verification providers 190. Also, in some cases, the patient 210 may biometrically identify himself / herself with the biometric identification unit of the smartphone 220.
[0094] The router 132 may then communicate with the identity management hub 134 to authenticate the user account 212 and to associate the user account 212 with the identity 214 of the patient 210. This may be achieved by verifying whether the data of the user account 212 of the patient 210 matches the corresponding data provided by one or more of the identity verification providers 190. Once the identity verification providers 190 matches the identity 214 with the user account 212 of the patient 210 and communicates the match to the identity management hub 134, the identity management hub 134 conveys the identity 214 of the patient 210 to the router 132 and the patient 210 is registered and identified by the messaging manager 130. Based on the patient 210 registering and identifying himself / herself, the identity management hub 134 of the messaging manager 130 updates the identity 214 associated with the user account 212 of the patient 210 in its records to authorize the patient 210 to engage in online conversations through the messaging manager 130 and use other functionalities provided by the system 1 10. Notably, the patient 210 can use his / her smartphone 220 to identify and authenticate himself / herself, such that the messaging manager 130 can trust that the patient 210 is a valid user. Other aspects for registration, identification, and authentication of the patient 210 that may be implemented by the messaging manager 130 in some embodiments may be as described in U.S. Patent Application Publication 2021 / 0343382 and / or International Application Publication WO2021237345, which are incorporated by reference herein.
[0095] In this example, as shown in Figures 13 to 23, the messaging manager 130 allows the patient 210 to participate in conversations with one or more other participants 310 that may include personnel of the clinic such as his / her physician, potentially one or more other physicians, nurses, therapists, etc., a chatbot, and / or one or more external participants such as external physicians (e.g., specialists), pharmacists, etc. As more specifically shown in Figure 13, in some embodiments, a conversation 260 may include entries that may be made by the patient 210 and / or one or more other participants 310. For example, different types of entries that may exist for a conversation 260 may include: a text message; a voice message; an attachment; a change of an entry status (e.g., to indicate an urgency, to resolve a conversation thread, etc.); a change of status of the conversation; a change of title and / or topic of the conversation; a change of location of the conversation; a change in a participant list of the conversation; a change in participants roles and rights to participate in the conversation; a change in administration (e.g., administrative privileges) of the conversation; a question; an answer; a reminder; a change in other conversation properties; any combination of the foregoing; and / or any other suitable entry for the conversation. In this embodiment, each entry may have details such as an author, a time and date, an audience, a delivery status for each participant of the conversation, etc., which may be accessible to anyone in the conversation. Entries and other data about a conversation 260 may be recorded in a ledger 139 of the database 160.
[0096] As further discussed below, in this embodiment, the patient 210 and one or more other participants 310, such as his / her physician and / or other personnel of the clinic, can discuss and share information, which may include confidential information from the EHR system 510, in conversations through the messaging manager 130 while avoiding uncontrollably externalizing that information (e.g., from the EHR system 510), thus protecting that information and, consequently, the patient 210 (e.g., by guaranteeing authenticity of the information, preventing fraud, etc.). Information exchanged as part of the conversation 260 therefore remains within the messaging manager 130 and / or where it was sourced from, such as the EHR system 510 and / or the clinic system 610.
[0097] For instance, in this embodiment, the patient 210 may create a conversation 260. More particularly, in this embodiment, the patient 210 may connect his / her smartphone 220 to the messaging manager 130 via the app on the smartphone 220. By virtue of the patient 210 having previously identified and registered himself / herself, the identity management hub 134 and the router 132 of the messaging manager 130 recognize the smartphone 220 which serves to authenticate the patient 210, whose identity is now confirmed. At this point, the smartphone 220 of the patient 210 may be in communication with the intermediation hub 136 of the messaging manager 130 through the router 132. The patient 210 can then select an option or otherwise input a command via the app on the smartphone 220, such as by acting on a graphical element (e.g., a button), to create the conversation 260. As part of this, the app on the smartphone 220 enables the patient 220 to specify a contact, which is another participant 310, for the conversation 260. As an example, in some embodiments, the app on the smartphone 220 may allow the patient 220 to enter a name of the other participant 310 via a “To:” field, such as by typing the name of the other participant 310 and / or selecting it from a list of contacts (e.g., which may appear as a dropdown menu). As another example, in some embodiments, as shown in Figure 14, the app on the smartphone 220 may allow the patient 220 to select from different medical categories, such as general medicine and / or one or more medical specialties (e.g., cardiology, dermatology, gastroenterology, oncology, gynecology, psychiatry, surgery, etc.), via graphical elements (e.g., text, icons, etc.) corresponding to these medical categories, for the conversation 260, which have been assigned respective contacts in the messaging manager 130 by the clinic. For purposes of this example, the patient 210 may contact the clinic about a recent development (e.g., he / he may have done a blood test or other medical test) to follow up with his / her physician, so that the other participant 310 is his / her physician. In response, the intermediation hub 136 may prompt the conversation hub 138 to create the conversation 260 and the ledger 139 of the conversation and to store the conversation data in a record 170 of the database 160. The intermediation hub 136 may also create metadata of the conversation 260 (e.g., pointers indicative of the location of the conversation 260, pointers indicative of the location of confidential records of the patient 210 in the database 630 of the clinic system 610, etc.) and store the metadata in its records.
[0098] Once the conversation 260 is created, the patient 210 may use the app on his / her smartphone 220 to view a content (e.g., messages and / or attachments as they arise) of the conversation 260 and add messages, attachments, and / or other entries to the conversation 260. In this embodiment, the patient 210 may upload attachments in one or more pre-selected file formats (e.g., png, jpeg, pdf, etc.). When uploaded by the patient 210, an attachment may be stored in the database 160 of the conversation hub 138 as conversation information 170, if relevant (e.g., as determined by the patient 610 and / or another participant 310, such as his / her physician or an administrator of the clinic). In other embodiments, the messaging manager 130 may prevent the patient 210 from uploading attachments into the conversation 260 (e.g., to avoid viruses, breaches and / or other security issues or problems). In some embodiments, the patient 210 may be able to directly reach (i.e., reach without conversing with another person or chatbot) the physician 310 through the conversation 260. The physician 310 may then use his / her communication device 320 to respond and interact with the patient 310, such as by viewing the content (e.g., messages and / or attachments as they arise) of the conversation 260 and add messages, attachments, and / or other entries to the conversation 260. In this example, the communication device 320 of the physician 310 is a smartphone running an app for interacting with the messaging manager 130, similar to that running on the smartphone 220 of the patient 210.
[0099] Alternatively, in other embodiments, depending on a configuration of the messaging manager 130 based on one or more preferences (e.g., one or more communication protocols and / or other workflows to manage conversations) of the clinic, even though the patient 210 reached out to the physician 310 in the conversation 260, the messaging manager 130 may route one or more initial messages and / or other entries of the patient 210 in the conversation 260 to another participant 310 associated with the clinic, say an administrator, a nurse, a chatbot, etc., that may handle an initial inquiry by the patient 210. For instance, this may be useful if the physician 310 is unavailable and / or intervention of the physician 310 is not necessary, such as if the patient’s inquiry is more administrative in nature (e.g., requires an appointment to be made, confirms that tests were conducted, etc.). In those cases, the administrator, nurse, chatbot, etc. may then use his / her / its communication device 320 to respond and interact with the patient 310, such as by viewing the content (e.g., messages and / or attachments as they arise) of the conversation 260 and add messages, attachments, and / or other entries to the conversation 260. Eventually, depending on how the conversation 260 evolves, the messaging manager 130 may allow the physician 310 to join the conversation 260, such as if the physician 310 becomes available and / or intervention of the physician 310 becomes necessary.
[0100] Each of the patient 210 and the physician 310 (and / or any other participant 310 such as an administrator, nurse, chatbot, etc.) may pause the conversation 260 (e.g., by leaving the app running on his / her smartphone 220, their communication device 310) and resume it (e.g., by adding a new message and / or attachment) when they desire, possibly after a prolonged period of time.
[0101] In some embodiments, the messaging manager 130 may monitor the conversation 260 to detect when no entry to the conversation 260 has been made for some time and potentially take action, such as prompting the patient 210 and / or the physician 310 (and / or any other participant 310 such as an administrator, nurse, chatbot, etc.) to respond. For example, in some embodiments, upon detecting that no entry to the conversation 260 has been made for a predetermined period of time, which may be established based on the status of the conversation 260, whether there is an expectation of a response from the patient 210 and / or the physician 310 (and / or any other participant 310 such as an administrator, nurse, chatbot, etc.), the patient 210 not having reviewed an attachment (e.g., test result) added to the conversation 260 by the physician 310 (and / or any other participant 310 such as an administrator, nurse, chatbot, etc.), and / or any other relevant factor, the messaging manager 130 may send a notification to the patient 210 and or the physician 310 (and / or any other participant 310 such as an administrator, nurse, chatbot, etc.) to notify them that the conversation 260 needs their attention.
[0102] When he / she wants, in this embodiment, the patient 210 may close the conversation 260. For instance, in this embodiment, the patient 210 may use the app on the smartphone 220 to select the conversation 260 and select an option or otherwise input a command, such as by acting on a graphical element (e.g., a button), to close the conversation 260. In response, the messaging manager 130 may close the conversation 260. In this embodiment, the data relative to the conversation 260 may be archived in the record 170 of the database 160. Similarly, in this embodiment, the physician 310 (and / or any other participant 310 such as an administrator, nurse, chatbot, etc.) may also close the conversation 260 when desired.
[0103] In this embodiment, with additional reference to Figures 18 to 21 and 23, the patient 210 may use his / her smartphone 220 to access, such as view and / or export, details of a conversation 260, which may be open (e.g., ongoing) or closed, at any time. For instance, in some cases, these details of the conversation 260 may include contents (e.g., messages and / or attachments) of the conversation 260, a time and date of each message of the conversation 260, a time and date of creation of the conversation 260, participants of the conversation 260, a participant associated with each message of the conversation 260, a participant associated with the creation of the conversation 260, a delivery status 291 of each entry for each participant of the conversation, etc., which may be accessible to anyone in the conversation, a participant associated with closure of the conversation 260 if closed, labels (e.g., “tags”) associated with the conversation 260, and / or any other data relative to the conversation 260 that is stored in the corresponding ledger 139 of database 160.
[0104] For example, in this embodiment, some of the details of the conversation 260 may be provided on a “home” or “default” page of the conversation, but for some of the details of the conversation, the patient 210 may use the app on the smartphone 220 to select an option or otherwise input a command, such as by acting on a graphical element (e.g., a button), to access the details of the conversation 260. In response, the messaging manager 130 may generate a read-only display of the details of the conversation 260 and / or generate a document conveying the details of the conversation 260 which may be exported to (e.g., downloaded by) the patient 210 (e.g., onto the smartphone 220 and / or an email address of the patient 210). In some embodiments, the messaging manager 130 may generate data (e.g., a time and date, an IP address, etc.) indicative that the patient 210 requested access to the details of the conversation 260 and that these details were provided to the patient 210 (e.g., via a displayable page and / or a downloadable document), and may store this data in a record in the database 160.
[0105] Also, in this embodiment, the patient 210 may use his / her smartphone 220 to access, such as view and / or export, a list (e.g., a history) of all conversations 260 involving the patient 210, including open (e.g., ongoing) ones and closed ones. For instance, in this embodiment, the patient 210 may use the app on the smartphone 220 to select an option or otherwise input a command, such as by acting on a graphical element (e.g., a button), to access the list of conversations 260. In response, the messaging manager 130 may generate a read-only display of the list of conversations 260 and / or may generate a document conveying the list of conversations 260 which may be exported to (e.g., downloaded by) the patient 210 (e.g., onto the smartphone 220 and / or an email address of the patient 210). In this embodiment, the messaging manager 130 may generate data (e.g., a time and date, an IP address, etc.) indicative that the patient 210 requested access to the list of conversations 260 and which were provided to the patient 210 (e.g., via a displayable page and / or a downloadable document), and may store this data in a document in a record of the database 160.
[0106] In a similar manner to that described above, in this embodiment, the physician 310 (and / or any other participant 310 such as an administrator, nurse, chatbot, etc.) may use their communication device 320 to: access, such as view and / or export, details of a conversation 260, which may be open (e.g., ongoing) or closed, at any time; and / or access, such as view and / or export, a list (e.g., a history) of all conversations 260 involving the patient 210 with the clinic, including open (e.g., ongoing) ones and closed ones.
[0107] To preserve and protect confidentiality, in this embodiment, when a conversation 260 involves medical information regarding the patient 210 (e.g., diagnoses, diseases, treatments, test results, etc.), which may be stored in the record 540 of the patient 210 in the EHR system 510 and / or in the record of 640 of the patient 210 in the clinic system 610, the messaging manager 130 may restrict access to the medical information regarding the patient 210 from the conversation 260.
[0108] For instance, in some embodiments, when medical information regarding the patient 210 stored in the record 540 of the patient 210 in the EHR system 510 and / or in the record of 640 of the patient 210 in the clinic system 610 is to be conveyed to the patient 210 or the other participants 310 during the conversation 260, the messaging manager 130 may allow the patient 210 to add an attachment 264 to the conversation 260. In particular, the patient 210 may use the app on the smartphone 220 to select an option or otherwise input a command, such as by acting on a graphical element (e.g., a button), to add the attachment 264 to the conversation 260. The app may allow the patient 210 to select who is consented to access the attachment 264 and to define other consent options (such as a timeframe like a period of time during which the attachment 264 can be viewed, a permitted number of views of the attachment 264, etc.). In response, the intermediation hub 136 may convey an address of the attachment 136 to the conversation hub 138, and an attachment entry representative of the address of the attachment 264 and the selected consent options may be registered in the ledger 139 of the conversation 260. In this embodiment, the messaging manager 130 may also allow the physician and other participants 130 to add the attachment 264 to the conversation 260 in a similar fashion.
[0109] In some embodiments, as shown in Figure 22, when medical information regarding the patient 210 stored in the record 540 of the patient 210 in the EHR system 510 and / or in the record of 640 of the patient 210 in the clinic system 610 is to be conveyed to the patient 210, to the physician and / or to other participants 310 during the conversation 260 (e.g., after being added to the conversation 260 by one of the patient 210, physician and / or other participants 310), the messaging manager 130 may pull the attachment 264 including at least part of the medical information regarding the patient 210, directly from the EHR system 510 or from the clinic system 610 such as to ensure that the attachment 264 is authentic. For instance, the patient 210 may use the app on the smartphone 220 to select an option or otherwise input a command, such as by acting on a graphical element (e.g., a button), to access the attachment 264 of the conversation 260, and in response, the messaging manager 130 may pull the attachment 264 including at least part of the medical information regarding the patient 210, directly from the EHR system 510 or from the clinic system 610 such as to ensure that the attachment 264 is authentic. In this example, for instance, the patient 210 may click or touch a preview 271 of the attachment 264 shown in the conversation 260.
[0110] As an example, in some embodiments, the messaging manager 130 may pull the attachment 264 from the EHR system 510 or from the clinic system 610 and transmit it to the patient 210, to the physician and / or to other participants 310 during the conversation 260 only if the patient 210 previously consented to transmission of attachments containing medical information during conversations through the messaging manager 130 (e.g., as part of the provisioning phase and / or in settings of the app running on the smartphone 220).
[0111] As another example, in some embodiments, the messaging manager 130 may prevent downloading of the attachment 264, i.e., make the attachment 264 viewable on the smartphone 220 of the patient 210 but undownloadable. For instance, in some embodiments, the messaging manager 130 may allow the patient 210 to use his / her smartphone 220 to view at least part of (e.g., some of, a majority of, or all of) a content of the attachment 264 including the medical information regarding the patient 210 from the conversation 260 but preclude the attachment 264 from being downloaded.
[0112] More particularly, as shown in Figure 24, in some embodiments, the patient 210 may use the app on the smartphone 220 to select an option or otherwise input a command, such as by acting on a graphical element (e.g., the preview 271 ), to access the attachment 264 of the conversation 260. In response, the messaging manager 130 may pull the attachment 264 from the EHR system 510 or from the clinic system 610 so that it contains data processable to display a read-only image 266 of the medical information regarding the patient 210 on the GUI of the smartphone 220. Thus, the messaging manager 130 may transmit the data processable by the smartphone 220 of the patient 220 solely to display the medical information regarding the patient 210. Thus, upon receiving the data from the messaging manager 130, a graphical processing function of the smartphone 220 may process the data to display the read-only image 266 of the medical information regarding the patient 210 on the GUI of the smartphone 220, but the data is insufficient or otherwise unusable for creating a local copy of the medical information regarding the patient 210 and is wiped from memory of the smartphone 220 when the GUI of the smartphone 220 displays a subsequent different image as the patient 220 interacts with the smartphone 220. In other embodiments, the messaging manager 130 may allow the patient 210 to use his / her smartphone 220 to download the attachment 264 of the conversation 260. In some cases, this may occur only if the patient 210 previously consented to downloading of attachments containing medical information during conversations through the messaging manager 130 (e.g., as part of the provisioning phase and / or in settings of the app running on the smartphone 220). For instance, in this embodiment, the patient 210 may use the app on the smartphone 220 to select an option or otherwise input a command, such as by acting on a graphical element (e.g., a button), to download the attachment 264 of the conversation 260. In response, the messaging manager 130 may be configured to generate a copy of the attachment 264 downloadable by the patient 210 onto the smartphone 220 (e.g., possibly with the watermark 268). In this embodiment, the messaging manager 130 may generate data (e.g., a time and date, an IP address, etc.) indicative that the patient 210 requested download of the attachment 264 and that the attachment 264 was provided to the patient 210 (e.g., via a downloadable document), and may store this data in the record 170 of the database 160.
[0113] In some cases, the messaging manager 130 may hide at least part of the content of the attachment 264 when generating the read-only image 266 of the attachment 264 and / or when generating a copy of the attachment 264. For example, the messaging manager 130 may be configured to redact part of the medical information regarding the patient 210 stored in the EHR system 510 (e.g., which may be useless to the patient 210) so that this part is not included in what is transmitted to the smartphone 220 of the patient 210.
[0114] Additionally or alternatively, in some cases, the messaging manager 130 may add and display a watermark 268 as part of the read-only image 266 of the attachment 264 (e.g., to prevent fraudulent reproduction of the attachment 264). For instance, in some embodiments, the watermark 268 may include a time and date, an indication such as “This document is not official”, “Do not print”, “Do not reproduce”, etc., and / or any other information indicating that information displayed should not be reproduced or otherwise considered to be official. In this embodiment, the messaging manager 130 may generate data (e.g., a time and date, an IP address, etc.) indicative that the patient 210 requested access to the attachment 264 and that its content was displayed to the patient 210, and may store this data in the record 170 of the database 160.
[0115] In this embodiment, the messaging manager 130 may allow the patient 210 to manage the participants 310 of the conversation 260, for example, to remove a participant 310 from the conversation 260, or to invite an additional participant 310 to the conversation 260, such as to permit the additional participant 310 to add messages, attachments, and / or other entries to the conversation 260 and / or to witness the conversation 260 (e.g., without adding any message, attachment, and / or other entry to the conversation 260).
[0116] For instance, in this embodiment, and assuming that in this example the conversation 260 already includes the patient 210 and the physician 310, who will be denoted 310A with his / her smartphone denoted 320A, the patient 210 may use his / her smartphone 220 to select an option or otherwise input a command, such as by acting on a graphical element (e.g., a button) to remove a participant 310 from the conversation 260, or to invite the additional participant 310. In the example shown in Figure 21 , for instance, the patient 210 may click or touch a button 281 offering the option to manage participants, which may prompt an options window to appear. The patient 210 may click or touch an icon 283 of the prompted window to remove a participant 310 from the conversation 260, and the patient may click or touch a button 285 of the prompted window offering the option to add participants in order to invite the additional participant 310, who is denoted 310B, to the conversation 260. As part of this, the app on the smartphone 220 enables the patient 220 to specify a contact, which is the additional participant 310B, for the conversation 260. In some cases, the app on the smartphone 220 may allow the patient 220 to enter a name of the additional participant 310B via a “To:” field, such as by typing the name of the additional participant 310B and / or selecting it from a list of contacts (e.g., which may appear as a dropdown menu). For purposes of this example, the patient 210 may wish to bring the additional participant 310B who is a specialist doctor (e.g., cardiologist, dermatologist, gastroenterologist, oncologist, gynecologist, psychiatrist, surgeon, etc.) treating the patient 310 to confirm, clarify or otherwise discuss with his / her physician 310A. In response, the messaging manager 130 may be configured to generate a notification transmitted to a communication device 320B of the specialist doctor 31 OB via the network 140 to invite the specialist doctor 31 OB into the conversation 260. The specialist doctor 31 OB may then use his / her communication device 320B to respond and interact with the patient 310 and the physician 310A, such as by viewing the content (e.g., messages and / or attachments as they arise) of the conversation 260 and add messages, attachments, and / or other entries to the conversation 260. In this example, the communication device 320B of the specialist doctor 310B is a smartphone running an app for interacting with the messaging manager 130, similar to that running on the smartphone 220 of the patient 210 and that running on the smartphone 320A of the physician 310A.
[0117] Additionally and / or alternatively, in this embodiment, in a manner similar to that described above, the messaging manager 130 may allow the physician 310 to invite an additional participant 310 (e.g., the specialist doctor 310B) to the conversation 260, such as to permit the additional participant 310 to add messages, attachments, and / or other entries to the conversation 260 and / or to witness the conversation 260 (e.g., without adding any message, attachment, and / or other entry to the conversation 260).
[0118] In this embodiment, the messaging manager 130 may also allow the physician 310 and / or any other participant 310 (e.g., an administrator, nurse, chatbot, etc.) associated with the clinic to create and participate in a conversation 260, as discussed above in respect of the patient 210 creating and participating in a conversation 260. Therefore, everything (e.g., principles, features, functionalities, etc.) described herein in respect of the patient creating and participating in a conversation 260 also applies to the physician 310 and / or any other participant 310 associated with the clinic creating and participating in a conversation 260.
[0119] In addition, in this embodiment, the messaging manager 130 may provide the physician 310 and / or any other participant 310 associated with the clinic with privileges to take actions in respect of conversations that are impossible for other participants such as the patient 210.
[0120] For example, in some embodiments, the physician 310 and / or any other participant 310 associated with the clinic with privileges may be able to add and / or edit confidential records of the patient 210 to the database 630 of the clinic system 610.
[0121] As another example, in some embodiments, when creating a conversation 260, the messaging manager 130 may allow the physician 310 and / or any other participant 310 associated with the clinic to designate a location (e.g., a file directory) where the conversation 260 is recorded. For instance, in some embodiments, the database 160 accessible to the messaging manager 130 may comprise different file directories depending on one or more attributes of the conversation 260, such as: an originator of the conversation 260 (e.g., the patient 210 or the physician 310 and / or any other participant 310 associated with the clinic); the status of the conversation 260 (e.g., open, closed, requiring a response from the patient 210 or the physician 310 and / or any other participant 310 associated with the clinic); an administrative region of the clinic and / or patient 210, a gender of the patient 210, an age classification of the patient 210, a medical specialization related to a health situation of the patient 210, a classification of a health situation of the patient 210, etc. Designating the location may prompt the messaging manager 130 to command the database 530 to allocate memory space to the conversation 260 at the location.
[0122] In this embodiment, the physician 310 and / or any other participant 310 associated with the clinic may change the location (e.g., file directory) of the conversation 260. For instance, in this embodiment, the physician and / or any other participant 310 associated with the clinic may select an option or otherwise input a command via the app on their communication device 320, such as by acting on a graphical element (e.g., a button) to move the conversation 260 in another location (e.g., file directory). In response, the messaging manager 130 may allocate memory space and store the conversation 260 at the new location in the database 160 and / or update the pointer indicative of the location of the conversation 260 in the record 640 of the patient 210 in the database 630 of the clinic system 610.
[0123] In some embodiments, with additional reference to Figure 25, one or more conversations 260 involving the patient 210 that is / are more recent and will be denoted 260N may be related to a prior conversation 260 involving the patient 210 that is an older and will be referred to as a “parent” conversation and denoted 260P. As an example, the prior conversation 260P may have originally been initiated by the patient 210 as a general discussion pertaining to a general health situation of the patient 210, while the one or more conversations 260N may have been initiated by the physician 310 and / or any other participant 310 associated with the clinic when specific issues arose so that one or more specialist doctors, laboratory workers (e.g., to conduct tests) pharmacists, and / or other participants 310 became involved. In some embodiments, the messaging manager 130 may allow the physician 310 and / or any other participant 310 associated with the clinic to link the conversations 260N and 260P. For instance, in some cases, each conversation 260N may be a “sub-conversation” to the parent conversation 260P.
[0124] In such embodiments, when a plurality of conversations is linked, the messaging manager 130 may classify the conversations in a hierarchy and the data of each conversation stored in the database 160 and / or the database 630 may include an indication of the hierarchy. The messaging manager 130 may implement rules relating to the hierarchy of each conversation to determine an access of each participant in the different conversations. For instance, in the example discussed above, the parent conversation 260P may have a higher hierarchy level than the conversations 260N. In some embodiments, the participants in the parent conversation 260P may automatically have a participant access to the conversations 260N, allowing each of them to participate in the conversations 260N In other embodiments, the messaging manager 130 may prevent some of the participants of the conversations 260N to automatically have a participant access to the parent conversation 260P. For instance, some participants (such as the physician 310 and another one of the participants) of the parent conversation 260P may create the “child” conversation 260N and prevent the patient 210 from viewing and participating in the conversation 260N, e.g., to create a confidential channel of communication linked with the parent conversation 260P.
[0125] The system 1 10, including the communication apparatus 120 and the messaging manager 130, may be implemented in various other ways in other embodiments.
[0126] For example, in some embodiments, the patient 210, the physician 310 and / or any other participant 310 associated with the clinic with privileges may have the option to invite an unregistered person (e.g., a specialist, a health care professional, a caretaker, a legal representative, a surrogate decision maker, etc.) in the conversation 260 and vouch for its identity. This person is unregistered in that he / she has not been registered with the messaging manager 130 like the patient 210, the physician 310 and / or any other participant 310 registered with the messaging manager 130. For instance, in this example, the physician 310 may use the app on the device 320 to select the conversation 260 and select an option or otherwise input a command, such as by acting on a graphical element (e.g., a button), to invite the unregistered person 410 in the conversation 260. In some cases, the physician 310 may be required to provide a phone number or an email address of the unregistered person 410. In other cases, the physician 310 may access his / her contact list on the device 320 to identify the unregistered person. In response, the messaging manager 130 may send a notification (e.g., an email, a text message) to the unregistered person 410. The unregistered person may download the app and register himself / herself before joining the conversation, but in specific cases where authentication requires too much time for the matter at stake, the physician 310 may select an option to vouch for the identity of the unregistered person 410, and the unregistered person 410 may participate to the conversation using a communication device (e.g. a computer, a smartphone, a tablet, etc.) without being authenticated and / or associated with an identity by the identity management hub 134 and / or the identity verification providers 190. In such cases, vouching of the identity of the unregistered person 410 by the physician 310 is noted in the ledger 139 for that conversation. In some embodiments, the system 1 10 may provide mechanisms to facilitate overtaking conversations of the patient 210 by a surrogate decision maker of the patient. For instance, upon registering to the system 1 10, the surrogate decision maker may submit legal documents assessing his / her surrogate decision maker status to the application. This data may be conveyed to the identity verification providers 190 through the identity management hub 134, and once this relationship is verified by the identity verification providers 190, the identity management hub 134 may save and associate this relationship with the user accounts of the patient 210 and of the surrogate decision maker. Subsequently, the surrogate decision maker may have access to at least some of (i.e., some of, a majority of, or all of) the conversations 260 of the patient 210 and the data or record of the patient 210 stored in the messaging manager 130, in the source system 510 or in the clinic system 610. In some cases, the participants 310 in the conversations 260 of the patient 210 may be advised by the messaging manager 230 (e.g., via a notification) that the surrogate decision maker has been registered and has taken control of the conversations of the patient 210.
[0127] As mentioned earlier, although in the embodiments described above the source system 510 is an electronic health record (EHR) system configured to store and process confidential information that is medical information regarding respective ones of the users 210 who are patients of a healthcare organization (e.g., a private or public healthcare establishment including one or more hospitals, clinics, and / or other healthcare facilities), in some embodiments, the source system 510 may be another type of source system and may be configured for different purposes. As shown in Figure 26, in some embodiments, confidential information concerning the user 210 may be stored in different source systems 510. For instance, in the context of medical information, the source systems 510 may comprise different EHR systems each corresponding to specific medicine specialties (e.g., general medicine, radiology, cardiology, pneumology, orthopedy, dermatology, oncology, etc.), medical institutions (e.g., clinics, hospitals), administrations (e.g., state, regional or provincial administrations), or health care type (medicine, physiotherapy, dental care, etc.), etc. In the context of banking, the source systems may comprise different financial source systems each corresponding to a specific institution or industry (e.g., banking, investment, insurance, etc.), administrations (e.g., state, national, regional or provincial administrations), and so on.
[0128] Since they are developed individually, often in different languages and protocols, different source systems are often not interoperable. That is, different source systems may not be capable of and / or configured for communicating with one another in an efficient or seamless fashion. For example, the format of the confidential information stored in the different source systems may vary such that a given source system, when provided with a file providing from a different source system, may not be capable of processing it correctly.
[0129] In this embodiment, the source systems 510 may be uninteroperable, i.e., not interoperable between them, and the messaging manager 130 is configured to be simultaneously compatible with the source systems 510. In particular, in this embodiment, the intermediation hub 136 is configured to interface with each of the source systems 510 through the signals 459. For instance, as described above, in response to the user 210 using the app on the smartphone 220 to select an option or otherwise input a command, to add or access the attachment 264 of the conversation 260, the intermediation hub 136 of the messaging manager 130 may pull the attachment 264 from the corresponding source system 510 and convey the attachment to the ledger 139. Since the ledger 139 is provided in a human language, it can be understood by anyone (given that they speak the language) regardless of the programming of the source systems 510 the messaging manager 130 relies on. In this embodiment, the identity management hub 134 is configured to associate the user account 212 and the identity 214 of the user 210 with a single user account from each of the source systems 510, thus coordinating the records of the different source systems 510. In other embodiments, this functionality may be implemented by another component 1 10 (e.g., the intermediation hub 136) of the communication apparatus implementing the messaging manager 130.
[0130] For example, in a specific example of implementation, the source systems 510 may be different EHR systems each corresponding to specific medicine specialties, and the user 210 may be a patient in a specific situation (e.g., a cancer) requiring the input from and the coordination of different specialists 310 (e.g., pneumologists, hemato-oncologists, radiologist, physician, etc.), each recording medical information of the user 210 in a different specific EHR system 510. In this embodiment, based on the patient 210 registering and identifying himself / herself and the identity management hub 134 of the messaging manager 130 associating the identity 214 with the user account 212 of the patient 210, the intermediation hub 136 may be configured to search each of the source systems 510 to identify, for each of the source systems 510, one or more potential user account candidate belonging to the patient 210. Once potential user account candidates are identified, the identity management hub 134 may be configured to challenge the data of the user account candidates based on the data of the user account 212, and when a match is confirmed, the intermediation hub 136 may be configured to associate the corresponding user account of the source system 510 with the user account 212 of the patient 210. Once the user account 212 of the system 1 10 and the user accounts of the source systems 510 belonging to the patient 210 are reconciliated, the user 210 and the specialists 310 may engage the conversation 260 and add attachments 264 which may be pulled from the user account of the patient 210 of any of the source systems 510, thus allowing the specialists 310 and the patient 210 to coordinate.
[0131] In another specific example of implementation, the source systems 510 may be different systems of financial and / or accounting institutions, and the user 210 may be a client involved in a transaction or in an audit, requiring the input from and the coordination of financial and / or accounting institutions, each recording financial information of the user 210 in a different specific source system 510. In this embodiment, based on the client 210 registering and identifying himself / herself and the identity management hub 134 of the messaging manager 130 associating the identity 214 with the user account 212 of the client 210, the client 210 may provide the system 1 10 with his / her user account information for each of the source systems 510, and the intermediation hub 136 may be configured to associate the corresponding user accounts of the source systems 510 with the user account 212 of the client 210. Once the user account 212 of the system 1 10 and the user accounts of the source systems 510 belonging to the client 210 are reconciliated, the client 210 and the institutions 310 may engage the conversation 260 and add attachments 264 which may be pulled from the user account of the patient 210 of any of the source systems 510, thus allowing the client 210 and the institutions 310 to coordinate. For instance, the institutions 310 may have access to thrusted financial information, allowing them to evaluate the financial situation of the client 210 and / or audit the client 210 more efficiently.
[0132] In various embodiments, as shown in Figure 27, any part of the system 1 10, including any part of the communication apparatus 120 implementing the messaging manager 130, any part of a communication device 220 or 320, any part of a source system 510, and / or any part of the clinic system 610, may comprise a processing apparatus 1 100 (i.e., a computing or other processing apparatus) configured to implement functionality of that part of the system 1 10. For example, the processing apparatus 1 100 may comprise an interface 1 120, a processing entity 1 130, and memory 1 140, which are implemented by suitable hardware and / or software.
[0133] The interface 1 120 comprises one or more inputs and outputs allowing the processing apparatus 1 100 to receive input signals from and send output signals to other components to which the processing apparatus 1100 is connected (i.e., directly or indirectly connected).
[0134] The processing entity 1 130 comprises one or more processors for performing processing operations that implement functionality of the processing apparatus 1 100. A processor of the processing entity 1 130 may be a general-purpose processor executing program code stored in the memory 1 140. Alternatively, a processor of the processing entity 1 130 may be a specific-purpose processor comprising one or more preprogrammed hardware or firmware elements (e.g., application-specific integrated circuits (ASICs), electrically erasable programmable read-only memories (EEPROMs), etc.) or other related elements. The memory 1 140 comprises one or more memory elements for storing program code executed by the processing entity 1 130 and / or data used during operation of the processing entity 1 130. The memory 1 140 may also be used for storing data. A memory element of the memory 1 140 may be a semiconductor medium (including, e.g., a solid- state memory), a magnetic storage medium, an optical storage medium, and / or any other suitable type of memory. A memory element of the memory 1 140 may be read-only memory (ROM) and / or random-access memory (RAM), for example.
[0135] In some embodiments, two or more elements of the processing apparatus 1100 may be implemented by devices that are physically distinct from one another and may be connected to one another via a bus (e.g., one or more electrical conductors or any other suitable bus) or via a communication link which may be wired, wireless, or both. In other embodiments, two or more elements of the processing apparatus 1 100 may be implemented by a single integrated device.
[0136] In some examples of implementation, any feature of any embodiment described herein may be used in combination with any feature of any other embodiment described herein.
[0137] Certain additional elements that may be needed for operation of some embodiments have not been described or illustrated as they are assumed to be within the purview of those of ordinary skill in the art. Moreover, certain embodiments may be free of, may lack and / or may function without any element that is not specifically disclosed herein.
[0138] In case of any discrepancy, inconsistency, or other difference between terms used herein and terms used in any document incorporated by reference herein, meanings of the terms used herein are to prevail and be used.
[0139] Although various embodiments and examples have been presented, this was for purposes of description, but should not be limiting. Various modifications and enhancements will become apparent to those of ordinary skill in the art.
Claims
CLAIMS1 . A system for asynchronous messaging, the system comprising:- an interface configured to communicate with a communication device of an individual and a communication device of a participant over a network; and- a processing entity comprising a processor and configured to:- transmit messages between the communication device of the individual and the communication device of the participant to establish a conversation between the individual and the participant via a graphical user interface (GUI) of the communication device of the individual;- allow the individual to share confidential information regarding the individual with the participant in the conversation; and- restrict access to the confidential information regarding the individual by the participant in the conversation.
2. The system of claim 1 , wherein: the confidential information regarding the individual is stored in a source system; and the interface is configured to communicate with the source system over the network.
3. The system of claim 2, wherein the processing entity is configured to maintain the confidential information regarding the individual unaltered in the source system.
4. The system of claim 2, wherein the processing entity is configured to preserve integrity of the confidential information regarding the individual in the source system.
5. The system of any one of claims 2 to 4, wherein, to restrict access to the confidential information regarding the individual by the participant in the conversation, the processing entity is configured to allow the individual to grant to the participant a right to view the confidential information regarding the individual that is stored in the source system.
6. The system of claim 5, wherein the right to view the confidential information regarding the individual that is stored in the source system is perpetual.
7. The system of claim 5, wherein the right to view the confidential information regarding the individual that is stored in the source system is limited.
8. The system of claim 7, wherein the right to view the confidential information regarding the individual that is stored in the source system is for a limited period of time.
9. The system of claim 7, wherein the right to view the confidential information regarding the individual that is stored in the source system is for a limited number of views.
10. The system of any one of claims 5 to 9, wherein the processing entity is configured to allow the individual to withdrawn from the participant the right to view the confidential information regarding the individual that is stored in the source system.1 1 . The system of any one of claims 1 to 10, wherein, to restrict access to the confidential information regarding the individual by the participant in the conversation, the processing entity is configured to transmit data processable by the communication device of the participant solely to display at least part of the confidential information regarding the individual.
12. The system of any one of claims 1 to 10, wherein, to restrict access to the confidential information regarding the individual by the participant in the conversation, the processing entity is configured to transmit data processable by the communication device of the participant to display at least part of the confidential information regarding the individual but preclude downloading of the confidential information regarding the individual onto the communication device of the participant.
13. The system of any one of claims 1 to 10, wherein, to restrict access to the confidential information regarding the individual by the participant in the conversation, the processing entity is configured to make at least part of the confidential informationregarding the individual viewable on but undownloadable onto the communication device of the participant.
14. The system of any one of claims 1 to 10, wherein, to restrict access to the confidential information regarding the individual by the participant in the conversation, the processing entity is configured to make at least part of the confidential information regarding the individual viewable on the communication device of the participant and add a watermark to the at least part of the confidential information regarding the individual viewable on the communication device of the participant.
15. The system of any one of claims 1 to 10, wherein, to restrict access to the confidential information regarding the individual by the participant in the conversation, the processing entity is configured to transmit at least part of the confidential information regarding the individual to the communication device of the participant only if the individual previously consented to transmission of the at least part of the confidential information regarding the individual.
16. The system of any one of claims 1 to 15, wherein the conversation is established via the GUI of the communication device of the individual and the GUI of the communication device of the participant.
17. The system of any one of claims 1 to 16, wherein: the participant is one of a plurality of participants; the interface is configured to communicate with communication devices of the participants over the network; and the processing entity is configured to:- transmit messages between the communication device of the individual and the communication devices of the participants to establish the conversation between the individual and the participants via the GUI of the communication device of the individual;- allow the individual to share the confidential information regarding the individual with the participants in the conversation; andrestrict access to the confidential information regarding the individual by the participants in the conversation.
18. The system of any one of claims 1 to 17, wherein the communication device of the individual is a smartphone of the individual.
19. The system of any one of claims 1 to 18, wherein: the individual is a patient; the participant is a medical professional associated with the patient; and the confidential information regarding the individual is medical information regarding the patient.
20. The system of any one of claims 1 to 18, wherein: the individual is a client; the participant is a financial professional associated with the client; and the confidential information regarding the individual is financial information regarding the client.
21. The system of any one of claims 1 to 18, wherein: the individual is a client; the participant is a legal professional associated with the client; and the confidential information regarding the individual is legal information regarding the client.
22. A computer-implemented method for asynchronous messaging, the computer- implemented method comprising:- communicating with a communication device of an individual and a communication device of a participant over a network;- transmitting messages between the communication device of the individual and the communication device of the participant to establish a conversation between the individual and the participant via a graphical user interface (GUI) of the communication device of the individual;- allowing the individual to share confidential information regarding the individual with the participant in the conversation; and- restricting access to the confidential information regarding the individual by the participant in the conversation.
23. Non-transitory computer-readable storage media storing instructions executable by a processing apparatus to perform a method for asynchronous messaging, wherein, when executed by the processing apparatus, the instructions cause the processing apparatus to:- communicate with a communication device of an individual and a communication device of a participant over a network;- transmit messages between the communication device of the individual and the communication device of the participant to establish a conversation between the individual and the participant via a graphical user interface (GUI) of the communication device of the individual;- allow the individual to share confidential information regarding the individual with the participant in the conversation; and- restrict access to the confidential information regarding the individual by the participant in the conversation.
24. A system for asynchronous messaging, the system comprising:- an interface configured to communicate with a communication device of an individual, a communication device of a participant, and a source system over a network; and- a processing entity comprising a processor and configured to:- transmit messages between the communication device of the individual and the communication device of the participant to establish a conversation between the individual and the participant via a graphical user interface (GUI) of the communication device of the individual;- receive an indication that the individual desires to share confidential information regarding the individual stored in the source system with the participant in the conversation; and- convey at least part of the confidential information regarding the individual to the communication device of the participant for display of the confidential information regarding the individual on the communication device of the participant in the conversation.
25. A computer-implemented method for asynchronous messaging, the computer- implemented method comprising:- communicating with a communication device of an individual, a communication device of a participant, and a source system over a network;- transmitting messages between the communication device of the individual and the communication device of the participant to establish a conversation between the individual and the participant via a graphical user interface (GUI) of the communication device of the individual;- receiving an indication that the individual desires to share confidential information regarding the individual stored in the source system with the participant in the conversation; and- conveying at least part of the confidential information regarding the individual to the communication device of the participant for display of the confidential information regarding the individual on the communication device of the participant in the conversation.
26. Non-transitory computer-readable storage media storing instructions executable by a processing apparatus to perform a method for asynchronous messaging, wherein, when executed by the processing apparatus, the instructions cause the processing apparatus to:- communicate with a communication device of an individual, a communication device of a participant, and a source system over a network;- transmit messages between the communication device of the individual and the communication device of the participant to establish a conversation between the individual and the participant via a graphical user interface (GUI) of the communication device of the individual;- receive an indication that the individual desires to share confidential information regarding the individual stored in the source system with the participant in the conversation; and- convey at least part of the confidential information regarding the individual to the communication device of the participant for display of the confidential information regarding the individual on the communication device of the participant in the conversation.
27. A system for asynchronous messaging, the system comprising:- an interface configured to communicate with a communication device of an individual, a communication device of a participant, and a source system over a network; and- a processing entity comprising a processor and configured to:- transmit messages between the communication device of the individual and the communication device of the participant to establish a conversation between the individual and the participant via a graphical user interface (GUI) of the communication device of the individual;- allow the individual to grant to the participant a right to view confidential information regarding the individual that is stored in the source system in the conversation; and- convey at least part of the confidential information regarding the individual to the communication device of the participant in the conversation.
28. A computer-implemented method for asynchronous messaging, the computer- implemented method comprising:- communicating with a communication device of an individual, a communication device of a participant, and a source system over a network;- transmitting messages between the communication device of the individual and the communication device of the participant to establish a conversation between the individual and the participant via a graphical user interface (GUI) of the communication device of the individual;- allowing the individual to grant to the participant a right to view confidential information regarding the individual that is stored in the source system in the conversation; andconveying at least part of the confidential information regarding the individual to the communication device of the participant in the conversation29. Non-transitory computer-readable storage media storing instructions executable by a processing apparatus to perform a method for asynchronous messaging, wherein, when executed by the processing apparatus, the instructions cause the processing apparatus to:- communicate with a communication device of an individual, a communication device of a participant, and a source system over a network;- transmit messages between the communication device of the individual and the communication device of the participant to establish a conversation between the individual and the participant via a graphical user interface (GUI) of the communication device of the individual;- allow the individual to grant to the participant a right to view confidential information regarding the individual that is stored in the source system in the conversation; and- convey at least part of the confidential information regarding the individual to the communication device of the participant in the conversation.
30. A system for asynchronous messaging, the system comprising:- an interface configured to communicate with a communication device of an individual, a communication device of a participant, and a plurality of source systems that are uninteroperable over a network; and- a processing entity comprising a processor and configured to:- transmit messages between the communication device of the individual and the communication device of the participant to establish a conversation between the individual and the participant via a graphical user interface (GUI) of the communication device of the individual;- receive an indication that the individual desires to share confidential information regarding the individual stored in respective ones of the source systems with the participant in the conversation; and- convey at least part of the confidential information regarding the individual to the communication device of the participant for display of the confidential information regarding the individual on the communication device of the participant in the conversation.
31. A computer-implemented method for asynchronous messaging, the computer- implemented method comprising:- communicating with a communication device of an individual, a communication device of a participant, and a plurality of source systems that are uninteroperable over a network;- transmitting messages between the communication device of the individual and the communication device of the participant to establish a conversation between the individual and the participant via a graphical user interface (GUI) of the communication device of the individual;- receiving an indication that the individual desires to share confidential information regarding the individual stored in respective ones of the source systems with the participant in the conversation; and- conveying at least part of the confidential information regarding the individual to the communication device of the participant for display of the confidential information regarding the individual on the communication device of the participant in the conversation.
32. Non-transitory computer-readable storage media storing instructions executable by a processing apparatus to perform a method for asynchronous messaging, wherein, when executed by the processing apparatus, the instructions cause the processing apparatus to:- communicate with a communication device of an individual, a communication device of a participant, and a plurality of source systems that are uninteroperable over a network;- transmit messages between the communication device of the individual and the communication device of the participant to establish a conversation between theindividual and the participant via a graphical user interface (GUI) of the communication device of the individual;- receive an indication that the individual desires to share confidential information regarding the individual stored in respective ones of the source systems with the participant in the conversation; and- convey at least part of the confidential information regarding the individual to the communication device of the participant for display of the confidential information regarding the individual on the communication device of the participant in the conversation.