Data generator and program for data generation
The data generation device and program address the challenge of using personal data for unforeseen purposes by requesting re-consent and processing data efficiently, allowing for optimized utilization and reduced redundancy.
Patent Information
- Application Number
- JP2024029736
- Authority / Receiving Office
- JP · JP
- Patent Type
- Applications
- Current Assignee / Owner
- Filing Date
- 2024-02-29
- Publication Date
- 2025-09-10
AI Technical Summary
Existing methods struggle to utilize accumulated personal data for purposes other than those for which consent was initially obtained, leading to difficulties in re-obtaining consent and wasting previously collected data.
A data generation device and program that request re-consent from data providers for new uses, generate re-consented data based on the new consent, and process the data accordingly, determining the extent of replication and necessary data acquisition to facilitate usage for multiple purposes.
Enables the use of accumulated personal data for diverse purposes beyond initial consent, optimizing data utilization and reducing the need for redundant data collection.
Smart Images

Figure 2025132296000001_ABST
Abstract
Description
[Technical Field]
[0001] The present invention relates to a data generation device and a data generation program. [Background technology]
[0002] Medical institutions that collect individual medical data through health checkups collect the medical data from the data providers who have undergone the checkups, along with consent to use the medical data for personal health purposes such as diagnosis and treatment, and utilize the medical data for purposes consistent with the consent. Personal information protection laws in various countries, such as the General Data Protection Regulation (GDPR), envision the use of data provided by data providers collected at the will of the data controller, in accordance with the prior consent of the data provider. With the consent of the data provider, the utilization of collected medical data can also be extended to purposes other than personal health, such as contributing to industry.
[0003] Patent Document 1 describes that, regarding medical information used for diagnosis or treatment purposes at medical institutions, patient consent data regarding use for purposes other than the original purpose is stored, and the medical information is edited or processed based on the patient consent data. Specifically, it describes that when a patient's medical information is used for purposes other than diagnosis or treatment, such as clinical trials, research, or education, data processing of the medical information is performed using the patient consent data regarding use for the purposes other than the original purpose that has been stored in advance. [Prior art documents] [Patent documents]
[0004] [Patent Document 1] Japanese Patent Application Laid-Open No. 2006-201830 Summary of the Invention [Problem to be solved by the invention]
[0005] Meanwhile, Patent Document 1 describes obtaining and storing consent in advance to use medical information for purposes other than those intended, but does not describe how to use data for purposes for which consent was not obtained at the time of data collection. For uses other than diagnosis and treatment, the intended use and the countries to which the data will cross borders are determined after the data users are decided, so even if consent is obtained for an intended use when the intended use is not clear, it is often not possible to respond to newly emerging uses. For this reason, it is difficult to obtain consent for all intended uses from the beginning and utilize the data.
[0006] With conventional methods, in order to use medical data for newly identified purposes (unintended use), consent must be obtained again from the data provider and the data must be collected again. However, recollecting data from individuals is not easy. Furthermore, large amounts of data collected in the past cannot be utilized and are wasted. Therefore, there is a need to make it possible to use collected personal data for purposes other than those for which consent was given at the time of collection.
[0007] An object of the present invention is to provide a data generation device and a data generation program that enable accumulated personal data to be used for purposes other than those for which prior consent was obtained. [Means for solving the problem]
[0008] The data generation device of the present invention includes a processor that generates consented data for which consent to use of data for a first use has been obtained from the data provider, requests re-consent from the data provider for use of the consented data for a second use different from the first use, and generates re-consented data that is a copy of the consented data based on the obtained re-consent.
[0009] Preferably, the processor determines the extent to which the agreed-upon data is to be replicated according to the second use, and generates re-agreed data having a portion of the agreed-upon data based on the extent.
[0010] Preferably, the processor processes the re-consented data based on the second use to generate re-consented processed data.
[0011] If the re-agreed data is insufficient for use in the second use, the processor preferably acquires necessary data that is necessary for use in the second use.
[0012] The processor preferably combines the acquired required data with the re-agreed data to generate time-series data that is re-agreed processed data.
[0013] Preferably, the processor determines asset values of the consented data, re-consented data, and re-consented processed data, and determines the compensation to be paid to the data provider for use in the second use based on the asset values.
[0014] The processor preferably presents the re-agreed data and the re-agreed processed data together with the asset value to the data provider.
[0015] The processor preferably presents the consent and consented data to the data provider along with a request for re-consent.
[0016] Preferably, the processor utilizes the agreed-upon data for a second use if the second use is consistent with the first use.
[0017] Preferably, the processor processes the re-consented data based on the second use to perform data analysis.
[0018] The data generation program of the present invention enables a computer to realize the functions of generating consented data for which consent has been obtained from the data provider for data use for a specific first use, requesting the data provider to re-consent to use the consented data for a second use different from the first use, and generating re-consented data that is a copy of the consented data based on the obtained re-consent. [Effects of the Invention]
[0019] According to the present invention, a data generation device and a data generation program are provided that allow accumulated personal data to be used for purposes other than those for which prior consent was given. [Brief explanation of the drawings]
[0020] [Figure 1] FIG. 1 is a schematic diagram of a data generation system. [Figure 2] FIG. 2 is a block diagram showing the functions of the data generating device. [Figure 3] FIG. 10 is an explanatory diagram of the procedure performed by the data generation system before obtaining re-consent. [Figure 4] 1A and 1B are explanatory diagrams illustrating a case where only re-consent is obtained and a case where re-consent and necessary data are re-collected when using consented data for a second use that is inconsistent with the first use. [Figure 5] FIG. 10 is an explanatory diagram illustrating how re-agreed data is processed and provided in the first embodiment. [Figure 6] FIG. 10 is an explanatory diagram illustrating anonymization processing of data for which re-consent has been given. [Figure 7] FIG. 10 is an explanatory diagram illustrating how re-agreed data is processed and provided in the second embodiment. [Figure 8] FIG. 10 is an explanatory diagram illustrating how data is added to data for which re-consent has been given. [Figure 9] FIG. 11 is an explanatory diagram illustrating how re-agreed data is processed and provided in the third embodiment. [Figure 10] FIG. 13 is an explanatory diagram illustrating how re-agreed data is processed and provided in the fourth embodiment. [Figure 11] 10 is a flowchart showing a series of steps in data usage for which re-consent for a second use different from the first use has been obtained. DETAILED DESCRIPTION OF THE INVENTION
[0021] As shown in Fig. 1, the data generation system 10 is composed of a data generation device 11 that stores acquired personal data and consent data for the personal data, a provider terminal 12 that provides personal data to the data generation device 11, and a data utilization device 13 that utilizes the data provided by the data generation device 11. The data generation device 11, the provider terminal 12, and the data utilization device 13 are managed by individuals or constituent organizations with independent authority.
[0022] The data generation device 11 collects and stores personal data according to the intended use based on instructions from an administrator, and provides it to a data utilization device 13 managed by a third party based on consent data. The provider terminal 12 is a PC (Personal Computer) or smartphone owned by the data provider that can communicate with the data generation device 11, and is used to view the provider's own data and consent data, manage data, and create consent data. The data utilization device 13 is managed by a data user, such as a corporation, organization, or government, and utilizes personal data with consent.
[0023] Personal data includes personal identification information that can be used to identify or identify the data provider. Personal identification information includes information such as name, gender, date of birth, family history, medical history, address, email address, medical history, medication history, and the ID of each data. Personal identification information refers to all information that can be combined to identify an individual, such as personal image information such as rare areas contained in images, and rare numerical values and results in each data.
[0024] When the personal data is medical data, the data generation device 11 is a medical institution, a PHR (Personal Health Record) service provider, a medical equipment management company, etc., and acquires the personal data from an information terminal that records examinations at the medical institution or from medical equipment used by the patient (data provider). The data utilization device 13 is an analytical institution, research institution, pharmaceutical company, insurance company, medical equipment manufacturer, etc. The medical data includes the data provider's height and weight data, blood pressure data, blood data, urine test results, health checkup findings, diagnostic information, endoscopic examination results, and X-ray examination results. The endoscopic examination results and X-ray examination results include image data. The medical data can be used for purposes such as "diagnosis," "health analysis," "research," "insurance," "pharmaceuticals," "digital marketing," "clinical trial recruiting," and "learning data."
[0025] 2, the data generating device 11 includes a data management unit 20, a data transmission / reception unit 26, and a storage memory 27. The data management unit 20 includes a consent presentation unit 21, a consent recognition unit 22, a data collection unit 23, a data processing unit 24, and a price determination unit 25. The data generating device 11 also has the function of an input reception unit (not shown), and can receive input from a user who is an administrator of the organization to which the data generating device 11 belongs via a user interface (UI) such as a mouse operation or a keyboard operation. The input includes processing control and instructions for individual processing for each item.
[0026] The data generating device 11 is a computer such as a personal computer or a workstation on which application programs for realizing predetermined functions are installed. The computer is equipped with a CPU (Central Processing Unit) which is a processor, memory, storage, etc., and realizes various functions by programs stored in the storage. Using these functions, the data generating device 11 can utilize the collected data for purposes other than those for which prior consent was obtained.
[0027] The data management unit 20 stores and manages personal data collected from data providers and consent data linked to each personal data. It also determines the use of personal data, checks consent data in personal data, requests consent from recipients, processes data according to the use, and calculates the price of stored medical data.
[0028] The consent presentation unit 21 presents the license conditions to the data provider and requests consent based on a data usage request from the data generation device 11 or the data usage device 13 or an offer to provide data from the data provider. Consent is obtained when the data provider accepts the license conditions. The consent obtained may be for uncollected data to be collected after consent is obtained, or for collected data.
[0029] The license conditions are determined based on the intended use of the personal data provided by the data provider and destination information. The destination information includes information on the country or corporation to which the data utilization device 13 belongs. It may also include information that can determine whether the relationship with the output source is the same as that of the country or corporation.
[0030] The consent request function of the consent presentation unit 21 may be a function to send data to the provider terminal 12 in which the provider's intention regarding the license conditions can be entered, or a function to create a consent request document that presents the license conditions to the data provider on paper.The consent presentation unit 21 also presents a document or the like that fulfills accountability when presenting the license conditions to the data provider and requesting consent.
[0031] The request for consent from the same data provider may be repeated as new uses are added. For example, a request for consent to a second use from a data provider is made when a second use different from the first use arises for data for which consent has already been obtained for the first use, and when a third use different from the first and second uses arises, a request for consent to the third use is made from the data provider.
[0032] The consent recognition unit 22 recognizes the data provider's agreement to the license conditions and creates consent data indicating that consent to use has been obtained. The created consent data is added to the corresponding personal data. The consent data is classified as first-use consent data for data consent to use for the first purpose, second-use consent data for data consent to use for the second purpose, and third-use consent data for data consent to use for the third purpose. Data collection, data processing, and data provision are carried out based on the consent data.
[0033] The data collection unit 23 collects data based on the license terms agreed upon by the data provider and stores it in the storage memory 27. If the accumulated data is insufficient for a new use, such as a second use, the data collection unit 23 requests and collects the necessary data required for the second use from the data provider along with or after obtaining new consent. The recollected necessary data is stored in the storage memory 27. Note that the data to be recollected need only be data items required for the new use. The necessary data is, for example, the most recent personal data. Personal data such as an individual's physical condition and history becomes less accurate over time, so the more recent the data, the more useful it is. Therefore, the expiration date of the creation date of the raw data for the personal data is specified in the data use request, such as within one year. In addition to storing data in the storage memory 27, storing data in another device, such as a cloud server, may also be included. The data manager may optionally switch between storing data in the storage memory 27 and storing data in another device, or the data generation device 11 may automatically switch based on the intended use, etc.
[0034] The data processing unit 24 processes the personal data copied from the storage memory 27 based on the intended use. The personal data is stored in the storage memory 27, and processing is performed by copying the personal data to which the first use consent data has been added (consented data). Processing includes anonymization, accuracy reduction, information addition, and integration. Data that has been processed to suit the new intended use is stored in the storage memory 27 and can be treated as information assets.
[0035] When replicating consented data, the range of replication may be determined depending on the intended use, and replicated data containing only a portion of the consented data may be obtained. While the entire consented data may be used for the first intended use, only a portion of the consented data may be used for the second intended use. In this case, the range of replication of the consented data stored in the storage memory 27 is determined based on the second intended use, and re-consented data containing only a portion of the consented data is generated based on the determined range. By determining the range of replication and replicating the data to be used for the new intended use, the effort required to replicate unnecessary items in the consented data and the storage capacity required can be reduced. This is also more efficient than replicating and then partially deleting the data.
[0036] In anonymization, to prevent data users from identifying individuals who provided the data from personal data, personal identification information (personal information) that can identify individuals in personal data is replaced with meaningless characters or strings of characters, or information is removed, including masking by blacking out, etc. In images, too, if a patient ID is attached to the image, this part is masked. Rather than replacing or deleting every item of personal identification information, it is also possible to convert it into information that cannot identify individuals using precision reduction processing.
[0037] Precision reduction processing involves rounding test values to one or two significant digits by rounding or omitting fractions, and converting test values into categories based on their position in the normal range. For example, a date of birth is converted to just the year of birth or to age information such as "20-24 years old" or "20s," and addresses are categorized by municipality, such as "Tokyo." Precision reduction processing reduces data volume and protects personal information.
[0038] In the information addition process, information indicating confirmation by the data administrator and guarantee of reliability, as well as classification and analysis results obtained by classifying and analyzing measurement values and the like that contain personal data, are added. The information to be added may be created by applying data discrimination criteria, etc., held by the data generation device 11 or acquired from an external source, to numerical values such as measurement values. Alternatively, classification results obtained by a classifier trained by machine learning may be added.
[0039] In the integration process, multiple pieces of personal data are integrated and processed into one piece of data. The integration may be for the same person or for different people. The integration of personal data of the same person involves generating personal data by combining personal data with different items, or generating time-series data from data with the same items but different measurement dates. The integration of personal data of different people involves creating comparison data by extracting the same items contained in each personal data.
[0040] The compensation determination unit 25 determines the compensation to be paid to the data provider based on the value of the data provided to the data user, such as consented data, re-consented data, and re-consented processed data. The value of the data is an asset value determined by a price calculation standard determined, for example, in a data usage request by the data user. Even for the same data, the value varies depending on the usage, so the compensation is determined for each usage.
[0041] If the compensation determined by the compensation determination unit 25 is monetary, it is a price based on the determined asset value minus the share of the data generation device 11. The share of the data generation device 11 includes costs for data storage and processing. If the compensation is not monetary, it may be the results of research in response to the data provided, a service personalized for each data provider, or information created for the data provider.
[0042] The asset value of the data determined by the price determination unit 25 may be presented to the data provider via the provider terminal 12 together with the subject consented data, re-consented data, and re-consented processed data. By understanding the asset value, the data provider can manage and operate the data provided for each agreed-upon use as an information asset.
[0043] The following describes data use for a first purpose, which is executed before data use for a second purpose. As shown in Fig. 3, a pre-execution procedure 30 is executed before consent for the second purpose is obtained in the data generation system 10. The pre-execution procedure 30 includes a first purpose presentation procedure 31, a provider consent procedure 32, a data collection procedure 33, a data storage procedure 34, and a first purpose use procedure 35. After the pre-execution procedure 30 is completed, a second purpose compatibility determination procedure 36 is executed when either the data provider, data administrator, or data user proposes data use for a second purpose that is different from the first purpose.
[0044] In a first use presentation procedure 31, the data generation device 11 presents to the data provider the license conditions for the first use, which is to use the data for diagnostic or therapeutic purposes, in a provider consent procedure 32, the data provider's consent (permission) for the use of data for the first use is obtained by submitting a document or entering data, in a data collection procedure 33, the data to be used for the first use is collected from the provider terminal 12 or the testing equipment used by the data provider, in a data storage procedure 34, the consented data in which the consent data is added to the collected data is stored, and in a first use procedure 35, the stored consented data is used for the first use. Note that the pre-execution procedure 30 may be ended in the data storage procedure 34 without performing the first use use procedure 35.
[0045] In the first use procedure 35, the intended use and the contents of the agreement are consistent in order to use the data in accordance with the consent obtained in the provider consent procedure 32, but it is necessary to determine whether the second use is included in the contents of the agreement. In the second use consistency determination procedure 36, a consistency determination is made as to whether the second use is consistent with the contents of the agreement given for the first use.
[0046] In the consistency determination, it is determined whether the data use purpose and the data recipient match or are included in the consent details for data use for the first use. If it is determined to be "consistent," the consented data stored in pre-execution step 30 is used for the second use. In a "consistent" case, for example, the first use is "obesity drug pharmaceuticals" and the second use is "blood pressure drug pharmaceuticals," and the second use is to use blood pressure data and related information for pharmaceutical production, so it is included in the first use. If it is determined to be "inconsistent," consent is obtained again for the inconsistent content (re-consent is obtained). Note that regardless of the consistency determination result, if there is insufficient data to be used for the second use, the data is re-collected. For example, even if the first use and the second use are consistent, if the data at the time of consent acquisition for the first use is old and not suitable for use for the second use, the data is re-collected.
[0047] FIG. 4 is an explanatory diagram showing the procedure for using data for which consent for use for the first purpose has been obtained for a second purpose when the consistency determination results in a "non-consistency." FIG. 4(A) shows a re-consent acquisition procedure 40 in which re-consent is obtained when there is no missing data, and FIG. 4(B) shows a re-consent acquisition procedure 45 in which re-consent is obtained and necessary data is collected when there is missing data. In both the re-consent acquisition procedure 40 and the re-consent acquisition procedure 45, the consented data for which consent for data use for the first purpose has been obtained from the data provider is managed by the data generating device 11. Data management includes retaining the data by storing it in the storage memory 27, restricting data use based on the consent, and presenting the data provider with the data usage status.
[0048] As shown in FIG. 4(A), re-consent acquisition procedure 40 includes second use presentation procedure 41, provider re-consent procedure 42, data duplication procedure 43, and second use use procedure 44. In second use presentation procedure 41, consent presentation unit 21 presents a second use different from the first use to the data provider, and requests consent (re-consent) for data use for the second use of the consented data stored and managed by data generation device 11. Along with the request for re-consent, consent for the first use and the consented data are presented to the data provider. This allows the data provider to check the content of past consent, thereby accurately understanding the use for the second use.
[0049] In the provider re-consent procedure 42, the consent recognition unit 22 accepts written submission or data input by the data provider and obtains re-consent. In the data duplication procedure 43, the data processing unit 24 duplicates the stored consented data based on the acquisition of re-consent, and generates re-consented data with the re-consented data added. The re-consented data may also be processed based on the second use to generate re-consented processed data. In the second use procedure 44, the data transmission / reception unit 26 provides the re-consented data or re-consented processed data to the data utilization device 13 that uses it for the second use. By obtaining re-consent, existing personal data collected in the past and stored by the data generation device 11 can be used for the second use.
[0050] As shown in FIG. 4(B), the re-consent acquisition procedure 45 includes a provider re-consent procedure 42 in the re-consent acquisition procedure 40 and a necessary data collection procedure 46 for collecting necessary data from the data provider between the data duplication procedure 43. In the data duplication procedure 43, the necessary data stored in the necessary data collection procedure 46 is duplicated as re-consented data together with the data accumulated for the first use. The collected necessary data may be linked to the re-consent and stored as re-consented data.
[0051] An example will be described in which health checkup data used by a data generation device 11 belonging to a health checkup center for a first purpose, which is "health analysis," is utilized for a second purpose that is inconsistent with the first purpose. The examples will be described in terms of a first example (see FIG. 5) in which the second purpose is "cancer research," a second example (see FIG. 7) in which the second purpose is "insurance," a third example (see FIG. 9) in which the second purpose is "pharmaceuticals," and a fourth example (see FIG. 10) in which the second purpose is "digital marketing." Regardless of the purpose, the medical data is analyzed by a data utilization device 13. Furthermore, descriptions of the second to fourth examples common to the first example will be omitted.
[0052] As shown in FIG. 5, in the first use, data provider H, who is a recipient of a health checkup, agrees to the consent details (license conditions) for the "health analysis" use, which is the use for analyzing the recipient's own health, presented by data generating device 11, and provides health checkup data to data generating device 11. Data generating device 11 stores the provided health checkup data in storage memory 27 as consented data 50, and provides the consented data 50 to data utilizing device 13, which belongs to an analytical institution that will use the consented data 50 for the "health analysis" use. Data utilizing device 13 creates health analysis results by analyzing consented data 50, and transmits them to provider terminal 12 via data generating device 11 or directly. Health checkup data is personal medical data acquired for the purpose of contributing to the individual's health.
[0053] As shown in FIG. 5, in the first embodiment, data provider H re-agreed to a data usage request from a data user for data usage of consented data 50 for "cancer research," a second use that is inconsistent with the first use. The data generation device 11 duplicates the consented data 50 using the data processing unit 24 based on the acquired re-consent (second use consent data), and creates re-agreed data 52 to which the second use consent data has been added. For specific research uses such as cancer research, re-agreed processed data 53, generated by processing such as anonymization and deletion of unnecessary information, is provided to a data utilization device 13a belonging to a research institution. The re-agreed processed data 53 is also stored in storage memory 27.
[0054] The consideration determination unit 25 calculates the price of the re-agreed processed data 53 and determines the remuneration (consideration) to be paid to the data provider. The stored re-agreed processed data 53 can be used as valuable data for purposes such as "research" thereafter. If the re-agreed processed data 53 is to be provided for further use, the processing costs can be reduced.
[0055] As shown in Figure 6, the data processing unit 24 processes the re-consented data 52 by anonymizing it and deleting unnecessary information, thereby generating re-consented processed data 53. Information unnecessary for use in the second purpose, such as the first-purpose consent data, is deleted. The second-purpose consent data is converted into anonymous second-purpose consent data by anonymizing the personal identification information of the data provider.
[0056] The processing of test results is determined according to the test content. For example, test results necessary for the second use, such as blood test results (first test results), are retained without processing, and test results not required for the second use, such as visual acuity test results (second test results), are deleted. Test results necessary for research, such as endoscopic examination results, that contain personal identification information of data provider H (third test results) are anonymized and converted into processed endoscopic examination results (processed third test results). Note that when generating re-consented data 52 by copying consented data 50, the range of data to be copied is determined so that unnecessary data is not copied, and the generated re-consented processed data 52 may be subjected to only anonymization processing.
[0057] As shown in FIG. 7 , in the second embodiment, the data generating device 11 collects health checkup data from annual health checkups and uses the data for the first use, which is concurrent data, for the second use, such as insurance product development. A data utilization device 13b belonging to an insurance company requests consent to the use of three years' worth of health checkup data for the second use, according to the terms of use license. The data generating device 11 obtains consent (re-consent) from the data provider H for the use of data for the "insurance" use, for consented data 50, whose measurement date is recent, e.g., within one month, consented data 50a, whose measurement date is one year ago, and consented data 50b, whose measurement date is two years ago. Based on the second use, the data is processed into time-series data 55 having a disease risk score, which is a score indicating the disease risk.
[0058] The data generation device 11 duplicates the consented data 50, and performs score addition, which is an information addition process, on the re-consented data 52 to which the second-use consent data has been added, to generate re-consented processed data 54. It also generates re-consented data 52a from the consented data 50a, and processes it into re-consented processed data 54a. Similarly, it generates re-consented data 52b from the consented data 50b, and processes it into re-consented processed data 54b. The re-consented data 54, 54a, and 54b are integrated to generate time-series data 55. The re-consented processed data 54, 54a, 54b, and the time-series data 55 are each stored in the storage memory 27 as different re-consented processed data.
[0059] As shown in Figure 8, in score addition, a disease risk score 56 is created from the medical data included in the re-consented data 52, and is added to generate re-consented processed data 54. The disease risk score 56 is evaluated using a four-level scale, such as A to D, for bodily function based on the results of each test in the medical data. Score A indicates "normal," score B indicates "mild abnormality," score C indicates "requires observation," and score D indicates "requires treatment." A score of A or B indicates a low risk of disease, while a score of C or D indicates a high risk of disease. Scores are similarly added to the re-consented processed data 52a and 52b, and re-consented processed data 54a and 54b are obtained.
[0060] The data utilization device 13 that utilizes data for "insurance" purposes can utilize the time-series data 55 to calculate insurance premiums personalized for each patient and for insurance product development. Furthermore, since the time-series data 55 that can capture changes in the health condition of the data provider H is valuable to the insurance industry, the data provider H can also use the stored time-series data 55 with other insurance companies. The time-series data 55 that includes diagnostic results from multiple years will be priced higher than the total price of the individual re-consented processed data.
[0061] As shown in FIG. 9 , in the third embodiment, the consented data 50 used for the first use is used for the second use, which is "pharmaceuticals" related to blood glucose levels. The data utilization device 13c belonging to the pharmaceutical company requests medical checkup data including accurate blood glucose level data as a required item along with re-consent. If accurate blood glucose level data is not included in the consented data 50, the data is re-collected from the data provider H along with consent for the second use and stored in the storage memory 27 as required data 57. The required data 57 is duplicated together with the consented data 50 and integrated into re-consented data 52. A disease analysis is performed on the re-consented data 52 using reference data 58, and re-consented processed data 59 with the analysis results added is provided to the data utilization device 13c.
[0062] In the disease analysis, disease probability information indicating the possibility of data provider H having a disease is calculated as the analysis result, with pre-specified diseases and rare diseases with a prevalence rate of less than 0.1% in the population being set as specific diseases. Reference data 58 is medical data of patients with specific diseases aggregated from other medical institutions and provided via data utilization device 13c. In copying consented data 50, blood data, age, and gender information are selected within the scope of copying as data useful for "pharmaceuticals" related to blood glucose levels.
[0063] In the "pharmaceutical" application, medical data indicating the possibility of contracting a specific disease is more valuable than data that does not, so the price determination unit 25 calculates a price according to the possibility of contracting the specific disease. The price may be determined in advance for each specific disease. Also, in cases where the data generating device 11 cannot set a price, such as for rare diseases, the price may be determined based on the price offered by the pharmaceutical company. If the data provider H is a patient with a specific disease or has a high possibility of contracting the disease, the payment may also include the acquisition of a new drug corresponding to the specific disease. In addition to the acquisition of new drugs, information such as new drug development information and clinical trial recruitment proposals may also be paid.
[0064] 10, in the fourth embodiment, when data provider H agrees to the data usage of consented data 50 for the second use, "digital marketing," data generation device 11 classifies re-consented data 52, which is the partially copied consented data 50 to which second-use consent data has been added, and generates re-consented processed data 60 based on the classification result. The generated re-consented processed data 60 is provided to data utilization device 13d, which belongs to the medical device manufacturer.
[0065] If the second use uses specific test values and does not require accurate test values, such as for "digital marketing" purposes such as market research and service development, the range to be replicated is determined to be only age, sex, residential information and specific test results from the consented data 50, and the partially replicated re-consented data 52 is categorized by classification processing. For example, it is sufficient to determine the health condition, whether the test values measured in a health checkup are within the normal value range or whether they are higher or lower than the normal value range, and even if the test values are left, they are rounded by precision reduction processing.
[0066] In the classification process, for example, the type of hypertension (stage I hypertension, stage II hypertension, stage III hypertension, etc.) is classified from the blood pressure data included in the re-consented data 52, and the classification result is obtained. The re-consented processed data 60 is generated by replacing the classification result with the blood pressure data of the re-consented data 52.
[0067] The re-consented processed data 54, which does not include detailed test values and is represented as a classification result, can be used as valuable data for commercial purposes beyond medical device-related companies such as medical device manufacturers. For example, data can be provided to meet the demands of many commercial data users, such as sports-related companies such as fitness gyms and food-related companies such as health food manufacturers. The compensation determination unit 25 can receive compensation in the form of the provision of personalized services based on the provided data, such as medical device sales information, requests for further data based on the classification results, or the provision of marketing information.
[0068] By generating and using consented data, re-consented data, or re-consented processed data that is valuable and can be provided for various purposes and to various data users, each data or group of data can be turned into an asset.
[0069] 11, a series of operations for using data for which re-consent has been obtained for a second use different from the first use in the data generation system 10 of this embodiment will be described. The data generation device 11 collects consented data 50 for which consent for data use for the first use has been obtained from the data provider H, and stores and manages it in the storage memory 27 (step ST110). When the data provider H, the data generation device 11, or the data utilization device 13 proposes the use of the consented data 50 for a second use different from the first use, the data generation device 11 presents the license conditions for use of the consented data 50 for the second use to the data provider H and requests re-consent (step ST120). The data generation device 11 obtains re-consent for use for the second use from the data provider H (step ST130).
[0070] If the agreed-upon data 50 is insufficient for use in the second purpose (Y in step ST140), necessary data required for use in the second purpose is acquired from the data provider H (step ST150). The acquired necessary data is stored in the storage memory 27 as re-agreed data 52a having re-agreed data (step ST160). If the agreed-upon data 50 is not insufficient for use in the second purpose (N in step ST140), data acquisition is not performed.
[0071] The consented data 50 to be used for the second purpose stored in the storage memory 27 is copied to obtain the re-consented data 52 having the re-consented data (step ST170). If the re-consented data 52 or 52a needs to be processed for use in the second purpose (Y in step ST180), the data is processed based on the second purpose to generate the re-consented processed data 54 (step ST190). If the re-consented data 52 and 52a do not need to be processed for use in the second purpose (N in step ST180), no processing is performed.
[0072] The data management unit 20 provides the data suitable for the second use from among the re-agreed data 52, the re-agreed data 52a, and the re-agreed processed data 54 generated by the data management unit 20 to the data user (step ST200). The data utilization device 13 utilizes the data provided for the second use based on the provision of the re-agreed data by the data generation device 11.
[0073] As a result of the above, the stored data can be used for a purpose (second purpose) different from the purpose (first purpose) agreed upon in advance. Note that if the data generating device 11 can use data for the first purpose or the second purpose (including the functions and roles of the data utilizing device 13), the data generating system 10 may be realized by the provider terminal 12 and the data generating device 11.
[0074] A modified example of this embodiment will be described. In the above explanation, the data generation system 10 has been described as having the data generation device 11 installed at one location, but in cases where personal data of a huge number of people is handled, data generation devices 11 may be installed at multiple locations. In this case, a blockchain network is realized, and each personal data is managed in a distributed manner at multiple locations. When the distributedly managed personal data is processed, it is aggregated in the data generation device 11 at any location.
[0075] The data generation system 10 of the present invention can also be used for personal data other than medical data. For example, instead of medical data, it may be used for personal data related to facility usage information, career information, and electronic money usage history. In this case, the data utilization device 13 uses the data to create statistics and analyze each data.
[0076] In the above embodiment, the hardware structure of processing units that execute various processes, such as a central control unit (not shown), an input receiving unit (not shown), a data management unit 20, a data transmission / reception unit 26, and a storage memory 27, is made up of various processors as follows: The various processors include a CPU (Central Processing Unit), which is a general-purpose processor that executes software (programs) and functions as various processing units, a programmable logic device (PLD), such as an FPGA (Field Programmable Gate Array), whose circuit configuration can be changed after manufacture, and a dedicated electrical circuit, which is a processor with a circuit configuration designed specifically for executing various processes.
[0077] A single processing unit may be configured with one of these various processors, or may be configured with a combination of two or more processors of the same or different types (for example, multiple FPGAs, or a combination of a CPU and an FPGA). Also, multiple processing units may be configured with a single processor. Examples of multiple processing units configured with a single processor include, first, a configuration in which one processor is configured with a combination of one or more CPUs and software, as typified by client or server computers, and this processor functions as multiple processing units. Second, a configuration in which a processor is used to realize the functions of an entire system including multiple processing units on a single IC (Integrated Circuit) chip, as typified by a System on Chip (SoC). In this way, the various processing units are configured with one or more of the above-mentioned various processors as a hardware structure.
[0078] Furthermore, the hardware structure of these various processors is, more specifically, an electric circuit formed by combining circuit elements such as semiconductor elements, and the hardware structure of the memory unit is a storage device such as a hard disk drive (HDD) or a solid state drive (SSD).
[0079] Furthermore, from the above description, the data generating devices described in Supplementary Notes 1 to 10 below can be understood.
[0080] [Appendix 1] a processor; The processor: Store the consented data for which consent to the use of data for the first purpose has been obtained from the data provider; requesting the data provider to re-agree to use the consented data for a second use different from the first use; a data generation device that generates re-agreed data by duplicating the consented data based on the acquisition of the re-agreed data; [Appendix 2] The processor: determining the extent to which the consented data is to be replicated in accordance with the second use; The data generating device according to claim 1, which generates the re-agreed data having a portion of the agreed-upon data based on the range. [Appendix 3] The processor: A data generation device according to claim 1 or 2, which processes the re-agreed data based on the second use and generates re-agreed processed data. [Appendix 4] The processor: A data generation device according to Supplementary Note 3, which acquires necessary data required for the second use when the re-agreed data is insufficient for the second use. [Appendix 5] The processor: A data generation device according to appendix 4, which combines the acquired necessary data with the re-agreed data to generate time-series data that is the re-agreed processed data. [Appendix 6] The processor: determining asset values of the consented data, the re-consented data, and the re-consented processed data; 6. The data generation device according to any one of appendices 3 to 5, wherein a price to be paid to the data provider for the use of the data for the second purpose is determined based on the asset value. [Appendix 7] The processor: The data generation device according to claim 6, which presents the re-agreed data and the re-agreed processed data to the data provider together with the asset value. [Appendix 8] The processor: 8. The data generation device according to claim 1, wherein the consent and the consented data are presented to the data provider together with the request for re-consent. [Appendix 9] The processor: 9. The data generation device according to any one of appendices 1 to 8, wherein if the second use is consistent with the first use, the agreed-upon data is used for the second use. [Appendix 10] The processor: 10. The data generation device according to any one of appendices 3 to 9, wherein the re-agreed data is processed based on the second use, which performs data analysis. [Explanation of symbols]
[0081] 10 Data Generation System 11 Data generation device 12 Provider terminal 13 Data utilization device 13a Data utilization device 13b Data utilization device 13c Data utilization device 13d Data utilization device 20 Data Management Department 21 Consent Presentation Section 22 Consent Recognition Department 23 Data Collection Department 24 Data Processing Department 25. Pricing Department 26 Data transmission / reception unit 27 Storage Memory 30 Pre-execution steps 31 First use presentation procedure 32 Donor consent procedures 33 Data Collection Procedures 34 Data storage procedures 35 Procedures for first use 36 Procedure for determining conformity with second use 40 Re-consent Procedures 41 Secondary use presentation procedure 42 Provider re-consent procedure 43 Data Replication Procedures 44 Secondary Use Procedures 45 Re-consent Procedures 46 Required Data Collection Procedures 50 Consent Data 52 Re-Agreed Data 52a Re-consented Data 52b Re-consented Data 53 Re-consented processed data 54 Re-consented processed data 54a Re-consented processed data 54b Re-consented processed data 55 Time Series Data 56 Lesion Risk Score 57 Required Data 58 Reference Data 59 Re-Agreed Data 60 Re-Agreed Processed Data H Data provider ST110~200 steps
Claims
1. a processor; The processor: storing consented data for which consent to data use for the first purpose has been obtained from the data provider; requesting the data provider to re-agree to use the consented data for a second use different from the first use; a data generation device that generates re-agreed data by duplicating the consented data based on the acquisition of the re-agreed data;
2. The processor: determining a range of duplication of the agreed-upon data according to the second use; The data generating device according to claim 1 , wherein the re-agreed data including a part of the agreed-upon data is generated based on the range.
3. The processor: The data generating device according to claim 1 , further comprising: a data generating unit configured to process the re-agreed data based on the second use, and generate re-agreed processed data.
4. The processor: The data generating device according to claim 3 , wherein when the re-agreed data is insufficient for the second use, necessary data required for the second use is acquired.
5. The processor: The data generating device according to claim 4 , wherein the acquired necessary data is combined with the re-agreed data to generate time-series data that is the re-agreed processed data.
6. The processor: determining asset values of the consented data, the re-consented data, and the re-consented processed data; 6. The data generating device according to claim 2, wherein a fee to be paid to the data provider for the use of the data for the second purpose is determined based on the asset value.
7. The processor: The data generating device according to claim 6 , wherein the re-agreed data and the re-agreed processed data are presented to the data provider together with the asset value.
8. The processor: The data generating device according to claim 1 , wherein the consent and the consented data are presented to the data provider together with the request for re-consent.
9. The processor: The data generating device according to claim 1 , wherein, if the second purpose is consistent with the first purpose, the agreed-upon data is used for the second purpose.
10. The processor: The data generating device according to claim 2 , further comprising: a processor for processing the re-agreed data based on the second use for performing data analysis.
11. A function of storing consented data for which consent to use of data for a specific first use has been obtained from the data provider; a function of requesting the data provider to re-agree to use the consented data for a second use different from the first use; A data generation program that causes a computer to realize a function of generating re-agreed data that is a copy of the agreed-upon data based on the acquisition of the re-agreed data.
Citation Information
Patent Citations
Medical information management system and medical information management method
JP2006201830A