Identification method, device, system and corresponding program
The cryptographic association of patient identity and bracelet identifier data in healthcare settings addresses patient fraud, ensuring secure and reliable patient identification, thereby enhancing safety and reducing errors.
Patent Information
- Application Number
- FR2024002473
- Authority / Receiving Office
- FR · FR
- Patent Type
- Applications
- Current Assignee / Owner
- Filing Date
- 2024-03-12
- Publication Date
- 2025-09-19
- Estimated Expiration
- 2044-03-12
AI Technical Summary
Healthcare institutions face challenges in patient management due to patient fraud, where a non-insured individual impersonates an insured patient, leading to potential health hazards, incorrect diagnoses, and financial misallocation of care, with current identification methods relying on human judgment being unreliable.
A data processing method using cryptographic association of patient identity and bracelet identifier data, encoded in specific formats, ensures secure patient identification through encrypted data transmission and authentication, ensuring the integrity and confidentiality of patient information.
Enhances patient safety by preventing fraud and ensuring accurate care delivery, reducing medical errors and financial risks, while maintaining patient freedom.
Smart Images

Figure 00000000_0000_ABST
Abstract
Description
Title of the invention: Identification method, device, system and corresponding program
[0001] 1. Domain
[0002] The invention relates to the field of identification. The invention relates more particularly to the field of patient identification within healthcare establishments. The invention aims more particularly to guarantee the identification, within a healthcare establishment, of a patient at the same time as his registration within the establishment.
[0003] 2. Prior art
[0004] In recent years, healthcare institutions have been the target of much criticism, particularly regarding their management of patient data. Many institutions around the world have been the target of targeted attacks aimed at paralyzing the services of these institutions or obtaining patient data, which is then resold on the black market. These attacks and the problems that followed have been the subject of numerous publications and are well known. However, healthcare institutions also face many challenges in terms of patient management, these challenges involving many security issues, as well. For example, many institutions face phenomena of patient fraud. To a certain extent, fraud problems are also caused by the healthcare institutions themselves.Fraud attributed to patients, essentially, is due to the use by a non-socially insured patient of a treatment slot in place of the insured patient whose place they have, with their complicity or not, taken. More specifically, a person arrives at the establishment accompanied by a legitimate socially insured person and takes their place at the time of the consultation or at the time of the treatment. This situation is problematic for the healthcare establishment, for several reasons: the first reason, the most important, relates to the commitment of the healthcare establishment's responsibility with regard to the care it provides.Indeed, if it happens that the person pretending to be the legitimate patient has a medical history that is not known by the healthcare establishment and the care provided is not in line with this medical history, a series of subsequent health hazards is possible, which could ultimately lead to the death of the fraudster, for example when an antibiotic is prescribed and the fraudster is allergic to it. In certain cases, depending on the legislation in force, the healthcare establishment may even be considered responsible for the situation and face penalties. The . The second problem is the mixing of the legitimate patient's health data with the fraudster's health data. Here again, this situation can lead to incorrect diagnoses for the legitimate social security insured person when they enter the healthcare establishment, which can also lead to their death and the healthcare establishment being held liable. The third problem is of lesser importance, since it concerns the financial allocation of care to a legitimate social security insured person (and for the healthcare establishment) when it should not have been provided, this situation can again lead to the establishment being condemned.
[0005] To address this issue, more and more healthcare establishments are requesting, when registering a patient (i.e. upon arrival at a registration desk), an identity document that allows the future patient to be identified. When the registration clerk considers this identity document to be valid, the patient registration formalities continue. This technique is relatively unreliable, as it essentially depends on the facial recognition ability of a single person (i.e. the registration clerk) and it does not prevent the substitution between the legitimate social security insured and the fraudster from occurring once registration has been completed (i.e. for example in the waiting room).
[0006] The invention improves the situation.
[0007] 3. Summary
[0008] Thus, the invention aims to improve patient care within healthcare establishments by preserving the freedom of legitimate patients and by limiting the possibilities of fraud potentially leading to medical errors. To do this, the invention discloses a method for registering patients.
[0009] More particularly, a data processing method is described, the method being implemented upon the arrival of a patient within a healthcare establishment, the method being at least partially implemented by means of at least one electronic device comprising a processor and a memory, the method comprising at least the following steps:
[0010] - obtaining data representative of a patient's identity, said data re presentation of the patient's identity being encoded according to a first predetermined encoding format;
[0011] - obtaining data representative of an identifier of a bracelet to be associated with the patient, said representative data being encoded according to a second predetermined encoding format;
[0012] - cryptographic association of the data representing the patient's identity and of the data representative of the identifier of a bracelet to be associated with the patient;
[0013] - recording the result of said cryptographic association within a database authentication data.
[0014] According to a particular characteristic, the step of obtaining the data representative of the identity of a patient comprises:
[0015] - recording, by a recording terminal, of the patient's arrival at the of the healthcare establishment, including obtaining, from a patient identification device, data representing the patient's identity;
[0016] - the standardized encoding of the data representing the patient's identity according to the first encoding format;
[0017] - the transmission of the data representative of the patient's identity encoded to a authentication server connected to the registration terminal via a communication network.
[0018] According to a particular characteristic, the step of obtaining the data representative of the identifier of the bracelet to be associated with the patient comprises:
[0019] - the selection, from a set of bracelets, of the bracelet to be associated with the patient;
[0020] - the transmission of a request for provision of identifier, by a terminal recording, using a near field communication interface, to the bracelet to be associated with the patient;
[0021] - the standardized encoding of the data representing the identifier of a bracelet to be associated with the patient according to the second encoding format;
[0022] - the transmission of the data representative of the identifier of a bracelet to be associated to the patient encoded to an authentication server connected to the recording terminal by a communication network.
[0023] According to a particular characteristic, the step of cryptographic association of the data representative of the identity of the patient and the data representative of the identifier of a bracelet to be associated with the patient comprises:
[0024] - determining a cryptographic material to be used for the data represented representative of the patient's identity and / or data representing the identifier of a bracelet to be associated with the patient;
[0025] - the implementation of the cryptographic material on the data representative of the identity of the patient and / or on the data representing the identifier of a bracelet to be associated with the patient providing encrypted identification data.
[0026] According to a particular characteristic, the step of cryptographic association of the data representative of the identity of the patient and the data representative of the identifier of a bracelet to be associated with the patient further comprises:
[0027] - Transmission of the encrypted identification data to the bracelet assigned to the patient
[0028] - Recording of the encrypted identification data within the assigned bracelet to the patient.
[0029] According to another aspect, the invention also relates to a data processing method, the method being implemented during a patient's journey within a healthcare establishment, said patient being provided with a bracelet associating at least one piece of data representative of the patient's identity and one piece of data representative of the bracelet's identifier (different or identical to that described previously), the method being at least partially implemented by means of at least one electronic device comprising a processor and a memory, the method comprising at least the following steps:
[0030] - Obtaining, by a processing device, the data representing the identity of the patient and / or the data representing the bracelet identifier;
[0031] - Authentication of the data representing the identity of the patient and / or the data representative of the bracelet identifier; and
[0032] - When the authentication of the data representing the identity of the patient and / or of the data representative of the bracelet identifier delivers a positive result, a step of transmission, to a display device, of a visual verification signal of the patient's identity.
[0033] According to a particular characteristic, this method further comprises, after the transmission of the visual verification signal of the patient's identity, and when a confirmation of the patient's identity is received, at least one step of recording, within a database, at least one association between the patient and at least one data item representative of a medical act carried out on said patient.
[0034] According to a particular characteristic, the authentication of the data representative of the patient's identity and / or of the data representative of the bracelet's identifier comprises at least one step of verification, by an authentication server, of a validity period of the association between the data representative of the patient's identity and the data representative of the bracelet's identifier.
[0035] According to another aspect, the invention also relates to a system for implementing a method as previously described.
[0036] According to another aspect, the invention also relates to computer programs capable of implementing the method(s) described as well as to a data medium for recording these computer programs.
[0037] The devices have the architecture of a computer. They are equipped with one or more processors capable of executing all types of computer programs, from operating systems to application software, written in compiled or interpreted languages. The different components of the device are connected to each other by a communication bus. The device is equipped with a communication system communication to communicate via protocols such as Bluetooth, Ethernet or WiFi with other systems and connect to mobile or non-mobile telecommunications networks. The device also includes memory components that will store the data and programs necessary for the operation of the device. The device is also modified so that it can perform management operations relating to a large number of vehicles and manage several thousand simultaneous operations per second, in particular by parallel implementation of route calculations.
[0038] The data carriers may be any entity or device capable of storing the programs. For example, the carriers may comprise a storage means, such as a ROM, for example a CD-ROM or a microelectronic circuit ROM, or a magnetic recording means such as a hard disk, or more often a Flash memory. On the other hand, the carriers may be transmissible carriers such as an electrical or optical signal, which may be conveyed via an electrical or optical cable, by radio or by other means. The programs according to the invention may in particular be downloaded from a network such as the Internet. Alternatively, the information carrier may be an integrated circuit in which the program is incorporated, the circuit being adapted to execute or to be used in the execution of the method in question.
[0039] 4. Drawings
[0040] Other characteristics and advantages of the invention will appear more clearly on reading the following description of a particular embodiment, given as a simple illustrative and non-limiting example, and the appended drawings, among which:
[0041] - [Fig.l] illustrates a system for implementing the methods of the invention;
[0042] - [Fig.2] represents the main steps of the patient registration process;
[0043] - [Fig.3] represents the main steps of the patient authentication process.
[0044] 5. Description of an embodiment
[0045] In relation to [Fig.l], an architecture of a system is presented in which the patient registration method and the patient authentication method can be implemented. In this system SYST, an authentication server ServA is connected to a communication network NTWK of the healthcare facility. The communication network can be a wired network, a wireless network (Wi-Fi type) or a combination of these types of networks. At least one registration terminal TermE is also connected to the communication network NTWK. The registration terminal is used to register patients entering the healthcare facility to receive care, by implementing the patient registration method according to the present disclosure. The system SYST also comprises at least one transactional server ServT. The transactional server is also connected to the communication network NTWK. It is usedconcurrently with the authentication server, in particular for consolidation operations, as described below. The SYST system also comprises at least one Brld identification bracelet. The identification bracelet comprises at least data processing means and near-field communication means of the RFID or NFC type. The Brld identification bracelet is provided to the patient when implementing the patient registration method. The SYST system also comprises at least one DiTr processing device. The processing device is made available to the practitioner. Depending on the configurations, a DiTr processing device can be shared between several practitioners or each practitioner can have their own processing device or a combination of these two cases.The processing device is equipped with data processing means but also means of interaction with the Brld identification bracelet, mainly comprising an NFC reader and / or an RFID reader, as well as optionally image capture means. The SYST system optionally comprises MDetc detection means for the Brld identification bracelet. These MDetc detection means may be in the form of bracelet reading terminals, connected to the NTWK communication network, which transmit data resulting from interrogations which are transmitted to the various near-field devices present in one or more specific areas of the healthcare facility, depending on the configurations. The data obtained by these terminals are transmitted to a ServD detection server, which is also connected to an NTWK communication network.Depending on the implementation, the ServT transactional server, the ServA authentication server, the optional ServD detection server can constitute a single server or be virtualized or a combination of these architectures.
[0046] In relation to [Fig. 2], a patient registration method according to the disclosure is described. Such a method is mainly implemented by the authentication server ServA, the registration terminal TermE and an identification bracelet Brld assigned to a patient. The purpose of the registration method is to associate the identity of a patient who enters the healthcare establishment with the identification bracelet Brld, in a scheme for the security of the healthcare establishment, the security of the care delivered to the patient and the detection / prevention of fraud, whether intentional or the result of negligence.
[0047] The main steps of this method include obtaining the patient and bracelet data (obtaining data representative of the patient's identity encoded according to a first predefined format, obtaining data representative of the identifier of a bracelet to be associated with the patient, encoded according to a second predefined format, cryptographic association of the patient and bracelet data, recording this association in an authentication database). Among these steps: recording the patient's identity includes: recording the patient's arrival via a terminal, obtaining the patient's data, standardized encoding of the patient's data and transmission to the authentication server; Obtaining the wristband identifier includes: selecting the wristband to be associated with the patient from a selection, transmitting an identifier request to the wristband via a terminal, standardized encoding of the wristband identifier and transmitting to the authentication server; Cryptographic association includes: determining the cryptographic material to be used; Encrypting the patient and / or wristband data to obtain encrypted identification data; Transmission and recording includes transmitting the encrypted data to the wristband assigned to the patient and recording the encrypted data in the wristband assigned to the patient. This method aims to secure the identification of patients and the wristbands associated with them upon admission to a healthcare facility, using cryptographic techniques to ensure the integrity and confidentiality of the data.The first and second predetermined encoding formats are used to ensure the uniqueness, in the authentication system, of the association data recorded therein. This may more particularly be a base 64 encoding (for the wristband identifier) or a Unicode encoding for patient identification. In the following, we consider that we are working on data encoded according to one or more predefined formats making it possible to guarantee the uniqueness of the data.
[0048] Thus, the method comprises, in an exemplary embodiment, the following steps:
[0049] - the recording E01, by the recording terminal TermE, of the arrival of the patient within the healthcare establishment, this recording providing data representative of the identity of the DPat patient;
[0050] - the transmission E02 of the data representing the identity of the patient DPat, by the TermE registration terminal, to the ServA authentication server;
[0051] - the transmission E03 of an IdB bracelet identifier by the terminal TermE registration terminal, to the ServA authentication server; the bracelet whose identifier is transmitted corresponds to the bracelet selected by the patient registration attendant; the bracelet can be taken at random by the attendant, in a receptacle provided for this purpose, then placed on an NFC type reading / recording device connected to the TermE registration terminal and the Brld identification bracelet transmits its IdB bracelet identifier to the TermE registration terminal, which then transmits this identifier to the ServA authentication server.
[0052] The two transmission steps may be simultaneous or constitute a single transmission step.
[0053] - Reception E04, from the authentication server ServA, of a key temporary access TaK, encrypted using the public key of the Brld identification bracelet;
[0054] - Transmission E05, to the identification bracelet Brld, of the temporary access key Encrypted TaK;
[0055] - Decryption E06, by the Brld identification bracelet, of the access key temporary TaK encrypted, using its private key, followed by the E07 recording of this temporary access key decrypted as well as the data representing the identity of the patient DPat.
[0056] This method ensures that the bracelet is cryptographically linked to a single patient identity. In addition to, or as a substitute for, the recording step E07, a step of encrypting the data representing the identity of the patient DPat using the temporary access key TaK can be implemented by the identification bracelet Brld to ensure even greater security. In which case, neither the temporary access key nor the data representing the identity of the patient DPat are retained and only the data representing the identity of the patient DPat using the temporary access key TaK is recorded within the bracelet. In addition, the step of encrypting the data representing the identity of the patient DPat using the temporary access key TaK can be implemented by the authentication server ServA.In this case, the authentication bracelet does not even need to perform this encryption and simply decrypts the data received from the server using its private key.
[0057] Depending on the operational implementation conditions, the recording E01, by the recording terminal TermE, of the arrival of the patient within the healthcare establishment may include several characteristics.
[0058] In an exemplary embodiment, this registration is carried out using a patient's social security card. More particularly, the TermE registration terminal is equipped with a reader for such an insurance card (which is for example a smart card, as in France, Germany or the United States, or a dematerialized card on a smartphone). The following registration method is then implemented: the TermE registration terminal transmits, to the social security card, a request to obtain identification data, which may include obtaining the surname, first name, date and place of birth and social security number, as well as the photograph of the insured.
[0059] Equipped with all or part of this data, the registration terminal TermE can transmit it as it is to the authentication server ServA, during the transmission step E02. It can also preprocess it to derive synthetic data representing the identity of the patient. This preprocessing can consist of a concatenation of the data received from the card, in a character string, an encoding, for example in base 64 of the data of the character string, giving a encoded string and the application of a signature algorithm (SHA-3) on the encoded character string. The data obtained then constitutes the data representative of the identity of the DPat patient. This preprocessing can also be carried out by the ServA authentication server.According to the disclosure, the method also comprises obtaining by the authentication server ServA, a photo of the patient: this photo is provided by the social security card and the registration terminal TermE, or a photograph is taken upon the arrival of the patient by the registration terminal TermE, during the collection of information concerning him, or a photograph is retrieved from the processing server ServT (from a previous visit of the patient within the healthcare establishment) or the authentication server ServA already has, in the database, a photograph associated with the data representative of the identity of the patient DPat already in the possession of the authentication server ServA.As an alternative to using a social security card, or in addition, all or part of the data mentioned above can be entered into a patient registration application at the TermE registration terminal.
[0060] Upon receipt of these elements, the ServA authentication server is able to determine a temporary access key for the patient. Cleverly, the temporary access key is determined randomly or pseudo-randomly and includes, for example: obtaining random or pseudo-random data, in the form of a character string (for example coded in base 64), determining a time limit for use of the bracelet (date / time) [for example linked to the care that the patient comes to receive within the healthcare establishment, in particular, for example, in relation to a scheduled appointment time, as well as a maximum duration associated with this appointment].These data (random string and treatment deadline time / date) are for example concatenated to the data representing the identity of the DPat patient or to data derived from the data representing the identity of the DPat patient (for example data resulting from the encryption, by the authentication server, using its private key, of the data representing the identity of the DPat patient). The concatenated string obtained is then encoded and for example undergoes hashing using a suitable algorithm (SHA-3). This encoded and hashed string then constitutes the temporary access key. This temporary access key, the time limit for its use and the data representing the patient's identity are then recorded in the authentication server's database for subsequent verification, as described below.
[0061] Depending on the operational implementation conditions, the recording E01, by the recording terminal TermE, of the arrival of the patient can be simplified, for example by transmitting the data representative of the identity of the patient DPat and the IdB bracelet identifier to the ServA authentication server; and by entrusting the ServA authentication server with the function of securing the link between these two pieces of information, without necessarily transmitting data to the bracelet, although this procedure is suboptimal.
[0062] In an alternative, the bracelet whose identifier is transmitted corresponds to that of a bracelet preselected by the recording device from among a set of available bracelets; in which case, at least some of the bracelets have warning means (such as an apparent LED, for example, but also autonomous data transmission means, i.e. not receiving energy from an NFC or RFID antenna) making it possible to signal / recognize the bracelet to be selected from among the set of available bracelets.
[0063] As explained above, an object of the invention is to allow the healthcare establishment to ensure that the person who presents himself to receive one or more treatments is indeed who he claims to be. The objective is to ensure on the one hand that the healthcare establishment delivers care that is adapted to the patient and on the other hand that the patient is indeed who he claims to be.
[0064] This data processing method is used during a patient's journey in the healthcare facility, where the patient wears a bracelet associating identity and identifier data. Implemented by electronic devices, it includes obtaining the patient and bracelet data, authenticating them, and if successful, transmitting a visual verification signal of the patient's identity to a display device. This process aims to ensure secure and reliable identification of patients throughout their medical stay, thus strengthening care management and patient safety. Other secondary objectives are also pursued, as explained below. With this in mind, once the patient has arrived in the treatment or examination room, a patient authentication process is implemented. This process is tripartite. It makes it possible to meet the two previously mentioned objectives.More specifically, the method comprises, in an exemplary embodiment, the following steps: .
[0065] - the transmission V01, by the processing device DiTr, of a request to obtain data representing the patient's identity (recorded in the patient's bracelet); optionally (and / or alternatively) the request for obtaining includes data representing the identifier of the DiTr treatment device;
[0066] - the transmission V02, by the patient's bracelet, of a response containing the data representative of the patient's identity encrypted using the temporary access key TaK; and optionally (and / or alternatively) containing the practitioner's terminal identifier encrypted using the temporary access key TaK;
[0067] - Upon receipt of this response, transmission V03, by the processing device DiTr, to the authentication server (SrvA), of an authentication confirmation request, comprising on the one hand the response provided by the patient's bracelet and on the other hand data representing the identifier of the DiTr processing device (optionally (and / or alternatively) encrypted using the private key of the DiTr processing device);
[0068] - verification V04, by the authentication server (SrvA), of the validity of the data transmitted, including:
[0069] - if it is encrypted by the private key of the processing device DiTr, the decryption of the patient's wristband identifier (IdB) using the public key of the DiTr treatment device held by the authentication server (SrvA);
[0070] - obtaining the temporary access key (TaK), using the wristband identifier (IdB) of the patient;
[0071] - decrypting the response provided by the patient's bracelet using the key temporary access key (TaK) of the authentication server (SrvA), when this temporary access key is obtained (i.e. the decryption of the data representing the patient's identity; and optionally (and / or alternatively) the obtaining request includes the data representing the identifier of the DiTr treatment device);
[0072] - the comparison of the data representative of the patient's identity decrypted with the one corresponding to the temporary TaK access key associated with the device and the patient
[0073] - optionally, the comparison of the data representative of the identifier of the DiTr processing device (provided by the response from the patient's bracelet) with that provided by the DiTr processing device itself (this feature making it possible to protect against "fraudulent" alteration of the patient's bracelet; and
[0074] - when the verification operations performed by the authentication server deliver a positive result, a step of transmission, to the DiTr processing device, of the data representing the patient's identity (optionally (and / or alternatively), this data is transmitted encrypted with the public key of the DiTr processing device) (optionally (and / or alternatively), the NULL value can be transmitted to the DiTr processing device, when the verification operations fail);
[0075] - reception V05, by the processing device DiTr, of the response from from the authentication server, this response including at least, if it is valid, the data representing the patient's identity;
[0076] - obtaining V06, by the processing device DiTr, of visual data (HRd) usable by the practitioner associated with the data representing the patient's identity, this visual data making it possible to confirm the patient's identity (this may be for example example of a photograph, or a copy of an official document: copy of insurance card, copy of identity document).
[0077] Depending on the operational implementation conditions, the patient's bracelet may simply transmit its identifier. In which case, the authentication server performs a verification of the patient's identity using the link between the bracelet's identifier and data representing the patient's identity, although this procedure is suboptimal. The practitioner can then receive, on the DiTr processing device, the visual data (HRd) usable by the practitioner and associated with the data representing the patient's identity.
[0078] Optionally (and / or alternatively), in response to the request to obtain the data representing the patient's identity, the bracelet can also transmit (and encrypt) the bracelet identifier (IdB), either as data directly from its memory, or indirectly, as explained below). This bracelet identifier can then be compared to a bracelet identifier expected by the authentication server, either in addition to, or instead of, the data representing the patient's identity. In which case, the steps of the authentication method previously presented are modified or added accordingly.
[0079] Obtaining the temporary access key (TaK), using the patient's wristband identifier (IdB), includes:
[0080] - a step of obtaining, within a data structure, the last access key temporary attributable to the patient's bracelet based on the identifier;
[0081] - a step of verifying the validity of the last temporary access key, in particular based on a date / time limit for use of this last temporary access key; and
[0082] - when the use-by date / time is greater than the current date / time, a step of providing the last temporary access key, which constitutes the temporary access key (TaK);
[0083] - when the use-by date / time is less than the current date / time, a NULL value is provided in place of the Temporary Access Key (TaK).
[0084] Thus, if a patient bracelet is presented outside of predefined time slots, decryption of the data transmitted by this patient bracelet by the authentication server is not possible, since no time data can be associated with this patient bracelet. Therefore, when scanning the bracelet of the patient who presents to receive care, the practitioner is informed of the impossibility of identifying the patient, either by means of a generic message displayed on the practitioner's terminal, or by a specific message indicating the reason for this impossibility of identification. Optionally (and / or alternatively), the practitioner has the possibility of overriding this identification, for example if the practitioner knows (well) the patient in question and that he is able to ensure (manually) that the patient is who he claims to be.
[0085] When the authentication is correctly performed (after scanning the patient's bracelet), the DiTr processing device is ready to associate the treatment data (entered or selected) by the practitioner with the correctly identified patient's file. This association can be performed by selecting, from a set of acts that can be associated with the patient, the acts that the practitioner performs. Optionally (and / or alternatively), the data relating to the acts that can be associated with the patient are extracted from a database of possible acts. This database of possible acts is for example filtered according to data representative of the patient (for example the pathology(ies) associated with the patient so as to retain only the acts that can actually be performed.The advantage of this methodology is that it is easy for a practitioner to ensure that the actions he performs are in line with the patient's state of health. This methodology also makes it possible to significantly reduce the risks of medical errors: in fact, by ensuring that the patient who consults him is actually the one he claims to be (or expects to be), the practitioner performs the correct actions on the one hand and is released from liability in the event of patient fraud (that is to say, if despite all the safeguards taken, the patient has still managed to confuse or defraud the system).
[0086] Thus, for example, provided with the patient identifier, and provided with a practitioner identifier, a human-machine interface is implemented to identify, within a database, the acts that can be associated with the patient, that is to say the acts which, taking into account the reason or reasons why the patient is present within the healthcare establishment, are carried out by the practitioner. The DiTr processing device makes a request to said at least one transactional server which, in response, transmits to it the data on acts that can be assigned to the patient. The practitioner makes a selection of the acts in question and the DiTr processing device creates a data record in which the patient identifier is inserted, as well as the practitioner identifier and the identifier of the act carried out. For example, a record of the following type is created and inserted into a database of acts carried out:
[0087] Id ;patient_id ;csarr_id;user_id;intervenor_id;observation;acte_duree_id;weighting;processed_at;c reated_at;updated_at
[0088] Cryptographic data can also be calculated based on all the data in the record, this cryptographic data being able for example to take the form of a hash of all or part of the (concatenated) data in the record. This hash is for example added as a field of the record, or inserted into another database table, in order to secure the content of the recording and trace any modification thereof, always with a security perspective: if one or more data in the recording (with the exception of observations) is subsequently modified, the hash of this data will be different from the initial hash, and fraud or attempted fraud will be discovered more easily. In addition, this hash can also be inserted as a transaction in a private blockchain, for example held by the healthcare establishment or by a trusted third party, making it possible to trace the various actions carried out in connection with the patient. In this context, the allocation of the bracelet to the patient during registration, and therefore the creation of cryptographic data relating to it, can also be the subject of a hash, which can also be inserted into a database table and / or into the blockchain explained above.
[0089] Optionally (and / or alternatively), the patient authentication method can be completed by obtaining, from the DiTr processing device, data printed on the patient's wristband, in particular from a QR code printed on the external surface of the patient's wristband. This QR code contains information (the wristband identifier (IdB)) which is encrypted using the wristband's public key. This encrypted identifier can only be correctly decrypted by the processor included in the wristband. From then on, the DiTr processing device is able to scan the QR Code and decode the information contained therein (identifier encrypted by public key).After decoding, the encrypted identifier obtained by this QR Code is transmitted to the patient's bracelet (for example when transmitting the request to obtain the data representing the patient's identity) and the patient's bracelet performs, using its private key, a decryption of this data. If successful, this decryption delivers the bracelet identifier (IdB). If unsuccessful, the value is different from that of the patient's bracelet identifier (IdB). Whatever the result of this operation, the data obtained (i.e., in the event of success, the bracelet identifier (IdB) entrusted to the patient) is injected into the authentication process described above and transmitted (alone or in combination with the data representing the patient's identity, as explained above).If the data does not match the patient's wristband identifier (IdB), the authentication process will fail and it may be concluded that the wristband is a counterfeit wristband or that it does not match a wristband from the healthcare facility or that the patient is not who he claims to be. Whatever the situation, a corresponding alert is raised at the DiTr treatment device and the practitioner can take note of this alert to take the necessary actions.
[0090] Another advantage of the proposed technology is that the patient can, potentially, return home while keeping the bracelet given to him at check-in upon arrival at the healthcare facility and return to the facility with this same bracelet to receive other treatments.
Claims
Claims
1. A method of processing data, the method being implemented upon the arrival of a patient within a healthcare establishment, the method being implemented via at least one electronic device (TermE, ServA) comprising a processor and a memory, the method comprising at least the following steps: - obtaining (E01, E02) data representing an identity of a patient (DPat), said data representing the identity of the patient being encoded according to a first predetermined encoding format; - obtaining (E03) data representing an identifier (IdB) of a bracelet (Brld) to be associated with the patient, said representative data being encoded according to a second predetermined encoding format; - cryptographic association (E04, E05) of the data representing the identity of the patient and the data representing the identifier of a bracelet to be associated with the patient;- recording the result of said cryptographic association within an authentication database;
2. Data processing method according to claim 1, characterized in that the step of obtaining (E01, E02) the data representative of the identity of a patient (DPat) comprises: - the recording (E01), by a recording terminal (TermE), of the arrival of the patient within the healthcare establishment, comprising obtaining, from a patient identification device, the data representative of the identity of the patient (DPat); - the standardized encoding of the data representative of the identity of the patient (DPat) according to the first encoding format; - the transmission (E02) of the data representative of the identity of the patient (DPat) encoded to an authentication server (ServA) connected to the recording terminal (TermE) by a communication network.
3. Data processing method according to claim 1, characterized in that the step of obtaining the data representative of the identifier (IdB) of the bracelet (Brld) to be associated with the patient comprises: - the selection, from a set of bracelets, of the bracelet (Brld) to be associated with the patient; - the transmission of a request for providing an identifier, by a registration terminal (TermE), using a near field communication interface, to the bracelet (Brld) to be associated with the patient; - the standardized encoding of the data representative of the identifier of a bracelet to be associated with the patient according to the second encoding format 9 - the transmission of the data representative of the identifier of a bracelet to be associated with the patient encoded to an authentication server (ServA) connected to the registration terminal (TermE) by a communication network.
4. Data processing method according to claim 1, characterized in that the step of cryptographic association (E04, E05) of the data representative of the identity of the patient and the data representative of the identifier of a bracelet to be associated with the patient comprises: - the determination of a cryptographic material to be used for the data representative of the identity of the patient and / or the data representative of the identifier of a bracelet to be associated with the patient; - the implementation of the cryptographic material on the data representative of the identity of the patient and / or on the data representative of the identifier of a bracelet to be associated with the patient delivering an encrypted identification data.
5. Data processing method according to claim 4, characterized in that the step of cryptographic association (E04, E05) of the data representative of the identity of the patient and the data representative of the identifier of a bracelet to be associated with the patient further comprises: - the transmission of the encrypted identification data to the bracelet assigned to the patient; - the recording of the encrypted identification data within the bracelet assigned to the patient.
6. Data processing method, the method being implemented during a patient's journey within a healthcare establishment, said patient being provided with a bracelet (Brld) associating at least one piece of data representative of the patient's identity (DPat) and one piece of data representative of the bracelet's identifier (IdB) according to one of claims 1 to 5, the method being at least partially implemented by means of at least one electronic device (DiTr, ServA) comprising a processor and a memory, the method comprising at least the following steps: - obtaining, by a DiTr processing device, the data representative of the patient's identity (DPat) and / or the data representative of the bracelet's identifier (IdB); - the authentication of the data representing the patient's identity (DPat) and / or the data representing the wristband identifier (IdB); and - when the authentication of the data representing the patient's identity (DPat) and / or the data representing the wristband identifier (IdB) delivers a positive result, a step of transmitting, to a display device, a visual verification signal of the patient's identity.
7. Data processing method according to claim 6, characterized in that it further comprises, after the transmission of the visual verification signal of the patient's identity, and when a confirmation of the patient's identity is received, at least one step of recording, within a database, at least one association between the patient and at least one data representative of a medical act carried out on said patient.
8. Data processing method according to claim 6, characterized in that the authentication of the data representative of the patient's identity (DPat) and / or of the data representative of the bracelet's identifier (IdB) comprises at least one step of verification, by an authentication server, of a validity period of the association between the data representative of the patient's identity (DPat) and the data representative of the bracelet's identifier (IdB).
9. System for implementing a method according to one of claims 1 to 8, characterized in that it comprises: - an authentication server (ServA) connected to a communication network (NTWK) of the healthcare establishment; - at least one registration terminal (TermE) is also connected to the communication network (NTWK); - at least one transactional server (ServT) connected to the communication network (NTWK); - at least one identification bracelet (Brld), comprising near-field communication means of the RFID or NFC type; - at least one processing device (DiTr), available to a practitioner comprising an NFC reader and / or an RFID reader.
10. Computer program comprising instructions for implementing a method according to one of claims 1 to 8, when said instructions are executed by a processor of a computer processing circuit
Citation Information
Patent Citations
Patient unique identifier
US20220270728A1