Automated Consent Management System and Method for Managing Automatic Reply Messages to Incoming Calls

The automated consent management system addresses inefficiencies in managing user consents for communication channels by integrating consent verification with auto-reply message generation, ensuring compliance with laws and reducing the risk of penalties.

JP2025520095APending Publication Date: 2025-07-01RHINOGRAM INC
View PDF 1 Cites 0 Cited by

Patent Information

Application Number
JP2024570285
Authority / Receiving Office
JP · JP
Patent Type
Applications
Current Assignee / Owner
Priority Date
2022-05-31
Filing Date
2023-05-03
Publication Date
2025-07-01

AI Technical Summary

Technical Problem

Existing systems face inefficiencies and manual burdens in managing user consents for communication channels like phone calls and text messages, particularly in compliance with laws such as TCPA, HIPAA, and GDPR, leading to potential violations and financial penalties.

Method used

A system and method for automated consent management that integrates with the generation and transmission of auto-reply messages, verifying user consents before sending messages on different communication channels, using a consent management system to ensure compliance with laws and regulations.

Benefits of technology

Automates the process of user consent verification and message generation, reducing the risk of non-compliance and financial penalties by ensuring that auto-reply messages are sent only after obtaining necessary user consents, thus enhancing efficiency and compliance.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 2025520095000001_ABST
    Figure 2025520095000001_ABST
Patent Text Reader

Abstract

The systems and methods disclosed herein provide automated consent management to ensure compliance with laws, rules, and / or regulations of user consent, integrated with the automated generation and transmission of auto-reply messages. According to the disclosed embodiments, a computer system may be configured to communicate with a user on both a first communication channel and a second communication channel, and the system requires the user's consent before it can communicate with the user on the second communication channel. The system may receive an incoming communication, such as a phone call, from the user on the first communication channel. The computer system may automatically generate an auto-reply message, such as a text message, to be sent to the user on the second communication channel in response to the incoming communication if the computer system automatically determines that the user has provided all the necessary user consent for the computer system to send an auto-reply message on the second communication channel.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention generally relates to consent management, and more particularly, to sending an automatic reply message in response to an incoming call in accordance with applicable laws, rules, and / or regulations that require consent before such an automatic reply can be sent, and to a system and method for managing the same.

Background Art

[0002] In 1991, Congress enacted the Telephone Consumer Protection Act (TCPA) to limit unwanted telemarketing phone calls to consumers. The TCPA protects consumers from receiving unwanted “robocalls” by imposing restrictions on when and how such automated calls can be made and by enabling consumers to opt out of receiving such calls. In accordance with the TCPA, the Federal Trade Commission (FTC) established a national “do not call” registry to protect consumers who do not wish to be contacted. Short Message Service (SMS) text messages sent to a consumer's cellular phone are considered “calls” for the purposes of the TCPA. However, as described herein, a telephone call includes voice information and, in some cases, additional information and / or metadata, and is thus sometimes referred to as a voice call, while a text message is a text-based message that does not include voice information.

[0003] Under the TCPA, and the related Federal Communications Commission (FCC) rules, a telemarketer or other entity must obtain a consumer's prior express consent before making an unsolicited call or text message to a consumer in a manner that would otherwise violate TCPA restrictions. In some communications, including those containing unsolicited advertisements, the consumer's prior express consent must be in writing. As a practical matter, TCPA regulations generally mean that an entity sending marketing and advertising materials must receive express written consent from an individual before sending a text message to that individual.

[0004] In some cases, an individual's consent under the TCPA may be implied based on the individual's actions, even without receiving express consent. For example, a customer's consent to receive a telephone call from a business may be implied if the customer provides the business with a telephone number without a limiting instruction as to whether or how the business may contact the customer using the provided number. A customer's consent to receive a telephone call from a business may also be implied if the customer makes the first call to the business and leaves a message requesting a response. Similarly, a customer's consent to receive a text message may be implied under the TCPA if the customer initiates a conversation with the business using the text message, such as by sending a request that requires a response or another text message first.

[0005] However, generally, a customer's consent for a business to use text messages to contact the customer is not implied solely based on the customer making an initial phone call to the business. Instead, for the customer to receive a text message in response to a phone call, the customer must either have previously provided their express consent to receive text messages from the business or otherwise established their implied consent. As used herein, "business" broadly refers to any company, enterprise, organization, association, institution, partnership, joint venture, or other entity of any type, size, or structure that can communicate with one or more individuals, whether private or public and whether for profit or non - profit.

[0006] For example, when a health care provider wishes to send a patient a text message, the health care provider must first obtain the patient's consent as required by the TCPA. The health care provider must also give the patient the option to opt out of text message communications later, and if the patient selects to opt out, the provider can no longer send the patient text messages. As a result, a health care provider without the required TCPA consent from the patient cannot use a text message response to answer an incoming phone call from the patient. For this reason, employees at a health care practice are generally tasked with manually answering each incoming phone call by making a separate callback to each patient, which can be extremely time - consuming and can take employees away from other necessary tasks at the health care practice. This same problem exists for other types of businesses that must comply with TCPA (or similar) consent requirements.

[0007] In 1996, President Clinton signed into law the Health Insurance Portability and Accountability Act (HIPAA), which protects the security and privacy of patients' health information when it is owned by third parties such as physicians or other healthcare providers. For example, HIPAA requires patients' written permission before their protected health information (PHI) can be used or disclosed for marketing purposes. HIPAA security and privacy protections also cover electronic protected health information (ePHI) created, stored, transmitted, or received in any electronic format, including, for example, via text messages.

[0008] In addition to obtaining a patient's TCPA consent to receive text messages, healthcare providers must also obtain a separate prior written consent from the patient, as required by HIPAA, to begin exchanging ePHI with the patient using text messages. In some cases, additional patient consent may also be required to comply with the European Union's General Data Protection Regulation (GDPR) data protection requirements and / or U.S. data privacy laws. In short, healthcare providers who wish to communicate with their patients using text messages may need to collect and manage multiple user consents, including, for example, several different types of consent (e.g., TCPA, HIPAA, etc.) for many patients.

[0009] Furthermore, different types of communication channels can be subject to different user consent requirements. As used herein, "communication channel" refers to a physical or logical connection for communicating information between two or more entities. A communication channel can transmit analog and / or digital information. In some cases, a communication channel can be implemented as an end-to-end communication session established over a public or private network using one or more network protocols. A single communication channel can comprise one or more different types of communication channels that collectively provide end-to-end communication between communication entities. The types of communication channels can include, but are not limited to, telephone calls, text messages, email messages, instant messages, and end-to-end connections for data or voice communication over any wireless or wireline protocol. Thus, a telephone call and a text message can correspond to different types of communication channels that are subject to different user consent requirements.

[0010] In view of the above, user consent management in healthcare providers and in other types of enterprises can be an extremely complex and cumbersome process that is generally managed manually through data entry. For example, each user consent is typically manually entered as a binary value (e.g., "yes" or "no" consent). However, frequent changes and updates to various user consents can quickly become an error-prone and difficult-to-handle process. The opportunity for data entry errors increases with the number of users. As used herein, a "user" is any person or group of persons for whom another entity must provide user consent before that other entity can create, send, receive, and / or store the user's information in accordance with one or more laws, rules, policies, and / or regulations (regardless of how or by whom defined). User consent may be required based on government laws, rules, or regulations, but it need not be. For example, one or more user consents may be required to comply with a company's policies or with some contractual terms or conditions. As used herein, "user consent" is an indication of a user's permission or authorization for another entity to perform related actions.

[0011] Failure to obtain the required user consent can result in severe financial penalties. For example, violations of the TCPA are enforced by the FCC, which can impose fines of over $18,000 per violation. Consent and opt-out management violations are common reasons for TCPA fines. Therefore, it is important for healthcare providers, as well as other types of enterprises, to comply with the user consent requirements of the TCPA and other laws, rules, and regulations that require user consent for some types of communications.

Prior Art Documents

Patent Documents

[0012]

Patent Document 1

Summary of the Invention

Problems to be Solved by the Invention

[0013] There is a current need for a more efficient way to manage, for organizations such as healthcare providers, corporations, government agencies, or other entities, communication with remote users on different types of communication channels, such as using phone calls and text messages, in compliance with the TCPA and other laws, rules, and regulations that require user consent before communicating on one or more of those communication channels.

Means for Solving the Problems

[0014] The present invention overcomes the drawbacks of the prior art by providing a system and method for managing user consent related to sending an automated reply message to a user. As used herein, "automated reply message" or "automated reply" refers to a message automatically generated by a computer system in response to a received communication from a user. The automated reply message can be sent as a text message, an email message, an instant message, etc. In some cases, the computer system may not be able to send an automated reply message to a user if the system has not received one or more user consents. For example, if the automated reply is a text message, the user may need to provide TCPA consent, and if the automated reply contains ePHI, the computer system may need to confirm that the user has provided HIPAA consent. Unlike existing systems and methods, the disclosed embodiments are configured to integrate automated user consent compliance for TCPA, HIPAA, GDPR, and / or other laws, rules, and regulations related to the automatic generation and sending of automated reply messages.

[0015] According to the disclosed embodiments, a computer system may be configured to communicate with a user on both a first communication channel and a second communication channel, and the system requires the user's consent before it can communicate with the user on the second communication channel. The system may receive an incoming communication, such as a phone call, from the user on the first communication channel. In the disclosed embodiments, a consent management system determines whether the user has provided all the necessary user consents for the computer system to send an auto-reply message, such as a text message, to the user on the second communication channel. The computer system may automatically generate an auto-reply message and send it to the user on the second communication channel if the consent management system determines that the user has provided all the necessary user consents for sending the auto-reply message on the second communication channel.

[0016] In some embodiments, the consent management system may be configured not only to determine whether all the necessary user consents have been received from the user before an auto-reply message can be sent to the user on the second communication channel, but also to generate and / or send the auto-reply message itself. In other embodiments, the consent management system may be coupled to separate hardware and / or software in the computer system that is configured to automatically generate and send the auto-reply. In some embodiments, the auto-reply message may be a pre-defined message, either for all users or for one or more specific users. In some embodiments, the content and / or metadata (including addressing) of the auto-reply message may be automatically determined based on at least a portion of the communication received from the user on the first communication channel.

[0017] For example, a computer system in a health care provider may include a communication interface (such as a cellular network interface) and a phone application configured to receive incoming telephone calls from patients. The phone application may identify a caller identification ("caller ID") information received with the incoming call for identifying the patient, based on, for example, a name or phone number included in the caller ID information. In this example, the computer system may also include (or be coupled to) a consent management system that receives from the phone application certain information corresponding to the patient's identification information, which may or may not be the same as the caller ID information, to determine whether the patient has previously provided consent to receive text messages from the health care provider. The consent management system may also determine for the patient whether any other consent, such as HIPAA consent, has been received. If the patient has provided one or more required consents, the consent management system, the phone application, and / or a separate messaging application may automatically generate and send an automated reply text message to the patient. The phone number for the automated reply text message may be determined from the caller ID information and / or other stored contact information associated with the patient.

[0018] In some embodiments, the auto-reply message may acknowledge receipt of the user's phone call. In other embodiments, the auto-reply message may be customized or personalized for a particular user. In yet other embodiments, a messaging application or another application on the computer system may process a transcribed (e.g., voice-to-text) version of the voice message from the user and then dynamically prepare an auto-reply message based on the content of the transcribed message. For example, if the user's voice message includes the word "appointment" or the phrase "schedule an appointment", an auto-reply text message indicating that "Someone will contact you soon about your appointment inquiry" may be automatically generated. In some embodiments, one or more machine learning and / or natural language processing engines may be used to extract and / or identify words, phrases, and content from the user's voice message to generate an appropriate auto-reply message to send to the user.

[0019] The disclosed embodiments are not limited to a particular type of entity, consent, or user. That is, the consent management system and method of the present invention can advantageously be used by any entity, whether it is a healthcare provider, a corporate entity, a government agency, a non-profit, or any other business, for managing consent for one or more users. Other aspects, advantages, and features of the present invention will become apparent to those skilled in the art based on the various exemplary embodiments disclosed in the following detailed description of the invention and the related drawings.

[0020] Certain features and advantages of the present invention will become apparent from the following description taken in conjunction with the accompanying drawings in which like reference numerals identify the same or functionally similar elements. The following figures illustrate the details of the disclosed embodiments. Since the accompanying drawings are provided by way of example only, the present invention is not limited to the exact arrangements shown in these figures.

Brief Description of the Drawings

[0021]

Figure 1

Figure 2

Figure 3

Figure 4

Figure 5

Best Mode for Carrying Out the Invention

[0022] FIG. 1 shows an exemplary network configuration 100 by which a user 110 and an enterprise 120 can communicate according to some disclosed embodiments of the present invention. In this exemplary embodiment, the user 110 can communicate with the enterprise by placing a telephone call to a telephone number associated with the enterprise 120. The telephone call can be established using the Public Switched Telephone Network (PSTN) or on any other wired and / or wireless telecommunications network that supports GSM, LTE, and / or other telecommunications protocols and standards. In some embodiments, an incoming call can be a telephone call sent over a public or private network using a standard networking protocol, such as a Voice over Internet Protocol (VoIP) call received on a packet-based or circuit-based network.

[0023] In the exemplary embodiment of FIG. 1, an incoming telephone call includes a voice-based communication from the user 110, and the voice-based communication is received by the enterprise 120 over any communication channel that connects the user and the enterprise. The incoming telephone call can include real-time and / or pre-recorded voice data from the user 110. The telephone call received at the enterprise 120 can include an analog signal, a digital signal, or a combination thereof.

[0024] In FIG. 1, an incoming telephone call of a user can be received or routed by one or more computer systems owned, operated, and / or controlled by enterprise 120. The enterprise can include, without limitation, a healthcare provider, a corporation, a government agency, or any other entity that communicates with the user and manages user consent. In some embodiments, one or more computer systems in enterprise 120 that receive and process the received telephone calls can be dedicated to receiving the user call, checking user consent, and / or generating an automated response. In other embodiments, one or more computer systems in enterprise 120 can be further configured to provide additional functionality in addition to call processing, consent management, and automated response generation.

[0025] In the exemplary embodiment of FIG. 1, enterprise 120 can receive an incoming telephone call from user 110 and automatically generate an automated response message that enterprise 120 returns to the user in response to the incoming call. Unlike conventional systems and methods, enterprise 120 can integrate an automated consent management system with the generation and transmission of the automated response message and be configured to automatically check one or more user consents before sending the automated response message to user 110 in response to the incoming call in FIG. 1. For example, an incoming call, such as a telephone call over a cellular network, can be received by enterprise 120 on a first communication channel, but the automated response message can be formatted as a text message or another type of message that requires user consent before it can be sent on a second communication channel, such as through an SMS system, a Multimedia Message Service (MMS) system, or another messaging system.

[0026] Advantageously, one or more computer systems in enterprise 120 may comprise a consent management system configured to interact with a phone application, a messaging application, and / or other applications to automate the steps of processing an incoming user call, verifying receipt of all necessary user consents before sending an automated reply message to the user, and generating and sending an automated reply message after verifying that all user consents required to send the automated reply have been received.

[0027] According to some exemplary embodiments, one or more computer systems in enterprise 120 may comprise a consent management server as disclosed in U.S. Application No. 17 / 133,454, filed Dec. 23, 2020, entitled "Automated Consent Management Systems and Methods for Using Same" by K. Dressler et al., which is hereby incorporated by reference in its entirety as if fully set forth herein.

[0028] FIG. 2 is a schematic block diagram of an exemplary computer system 200 that may be implemented and used in enterprise 120, according to an example described herein. The exemplary computer system 200 may include one or more communication interfaces 210 (e.g., wired, wireless, etc.), one or more processors 220, a memory 230, and a non-volatile memory 240, interconnected by a system bus 250. The computer system 200 may also include other components, such as a power supply, one or more memory controllers, a display / monitor, a keyboard, a mouse, a printer, etc., not shown in FIG. 2 for clarity. Further, those skilled in the art will appreciate that the hardware and software components of the exemplary computer system 200 described below may be deployed in a single computer or, alternatively, may be distributed among multiple interconnected computers, such as one or more computers interconnected over a local area network or an enterprise network used by an enterprise.

[0029] One or more communication interfaces 210 include mechanical, electrical, and signaling circuits for communicating data, such as incoming telephone calls and outgoing automatic reply messages shown in the network configuration 100 of FIG. 1, without limitation. The interface 210 can be configured to transmit and / or receive data using a variety of different communication protocols and data formats, and can include any wireless or wired / physical connection or medium configured to communicate over different types of networks. For example, the communication interface 210 can include at least one wireless interface for communicating over cellular, WiFi, Bluetooth, and / or other wireless networks. In some embodiments, the interface 210 can include an interface for connecting to a telephone, Ethernet, and / or coaxial cable. The communication interface can include dedicated processors, memory, logic, circuits, software, and firmware (not shown) for processing and formatting communications via the interface 210.

[0030] (For convenience, one or more processors 220, processor 220, or processors 220 are also interchangeably referred to herein) One or more physical processors 220 can be configured to provide information processing capabilities in an exemplary computer system 200. One or more processors 220 can comprise one or more of a microprocessor, a microcontroller, a central processing unit, an application specific integrated circuit, a field programmable gate array, or any other circuit, state machine, and / or other mechanism configured to electrically process information according to the disclosed embodiments herein.

[0031] The memory 230 comprises a plurality of storage locations that can be addressed by one or more processors 220 and / or a communication interface 210 for storing software programs and data structures related to the embodiments described herein. The one or more processors 220 may comprise hardware elements or hardware logic adapted to execute software programs in the memory 230 and to manipulate data structures. The software programs and data may be loaded from the non-volatile memory 240 into the memory 230, and the non-volatile memory 240 may be a hard drive, a solid state drive, a random access memory with battery backup, or any other form of persistent memory, as is known in the art. Similarly, software and / or data modified in the memory 230 may be entrusted to be stored in the non-volatile memory 240 for a longer term. Each of the memory 230 and the non-volatile memory 240 may comprise one or more interconnected memories.

[0032] One or more processors 220 may be configured to execute one or more computer-readable instructions stored in memory 230 to provide, at least, the functions of consent manager 232, phone application 234 (the "phone app"), message application 236 (the "message app"), and one or more other applications (the "other apps") 238, according to the disclosed embodiments. The consent manager 232 may be used to automate user consent management, as further described herein. The phone app 234 may be configured to process incoming phone calls received by the communication interface 210. The phone app 234 may also be configured to interact with the consent manager 232, for example, to identify caller ID information and provide at least a portion of the identified caller ID information to the consent manager 232. The consent manager 232 may use the caller ID information to ensure that the computer system 200 does not send an automated response message to the user unless the calling user has provided all necessary consents.

[0033] The message app 236 may be configured to generate an auto - reply message in the computer system 200. The message app may be further configured to cooperate with the consent manager 232 to ensure that, for example, the auto - reply message is not sent to the user unless the consent manager 232 provides an indication that the user has provided all the necessary consents to receive the auto - reply message. In some embodiments, the consent manager 232 determines which one or more user consents are required before an auto - reply message can be sent from the computer system 200 to the user. The consent manager 232 may identify the required consent based on the type of the auto - reply message to be sent (e.g., an SMS message or an MMS message) and / or based on the content of the scheduled auto - reply message. In some embodiments, the message app 236 provides at least a portion of the content of the auto - reply message to the consent manager to enable the consent manager to identify which user consents should be checked for the auto - reply message. In other embodiments, the message app 236 or another app 238 provides the consent manager 232 with information that enables the consent manager to identify which one or more user consents should be checked for the auto - reply message.

[0034] In some embodiments, the consent manager 232, the phone app 234, the message app 236, and the other apps 238 may be implemented as separate applications. In alternative embodiments, one or more of the consent manager 232, the phone app 234, the message app 236, and the other apps 238 may be combined or otherwise integrated into a single monolithic software program. Further, in embodiments where the computer system 200 is deployed in a cloud-based network architecture, the consent manager 232 may be implemented as one or more cloud-based services, and at least a portion of the consent manager functionality described herein may be accessible over a network, such as the Internet, using the cloud-based services.

[0035] Further, the memory 230 may also include other computer-readable instructions (not shown in FIG. 2) that, when executed by one or more processors 220, provide, for example, an operating system, a network protocol stack, and other software processes, services, and applications. The memory 230 may store various data, such as user consent data 300, that may be accessed and / or updated by the consent manager 232. The user consent data 300 may be loaded into the memory 230 from a copy of the user consent data stored in the non-volatile memory 240. During operation, modifications to the user consent data 300 in the memory 230 may be entrusted to one or more processors 220 to be more persistently stored in the non-volatile memory 240.

[0036] FIG. 3 is a schematic block diagram of user consent data 300 that can be used by the consent manager 232 according to some disclosed embodiments. The user consent data 300 preferably includes a separate file or record 305 (hereinafter, user record 305) that stores the consent information of each user for the consent management system. The user consent data 300 can be stored, for example, as part of a database in the memory 230 and / or the non-volatile memory 240. In the exemplary embodiment of FIG. 3, each user record 305 is configured to include fields that store, for example, a user ID 310, a group ID 320, user consent 330, user contact information 340, and other fields 350. The ordering and arrangement of the exemplary fields in FIG. 3 are exemplary, and those skilled in the art will understand that other data formats can be used in accordance with the disclosed embodiments.

[0037] The user ID 310 is a unique identifier value associated with a particular user 110. The consent manager 232 and / or the campaign manager preferably use the user ID value to index the data record 305 of the associated user. The group ID 320 is an optional field that preferably stores a value used to associate one or more users 110 belonging to a common group. In some embodiments, for example, the group ID can be used to associate groups of connected parties such as individuals in the same family, employees of the same company, members of the same organization, etc. In such embodiments, connected parties can be identified by filtering the user's data record 305 based on the group ID value.

[0038] The user consent 330 includes one or more user consent values 332-338 corresponding to different types of user consent. For example, in the example of FIG. 3, the user record 305 includes a TCPA consent value 332, a HIPAA consent value 334, a payment consent value 336, and a marketing consent value 338. In this example, the TCPA consent value 332 may indicate whether the user has consented to text message communication, the HIPAA consent value 334 may indicate whether the user has consented to communication containing the user's ePHI, the payment consent value 336 may indicate whether the user has consented to receive electronic billing and / or payments, and the marketing consent value 338 may indicate whether the user has consented to receive communication with marketing or targeted advertising content.

[0039] The specific user consent values 332-338 associated with each user may vary from user to user and / or depend on a particular consent management implementation in some embodiments. For example, a group that does not maintain ePHI for individual users may not need to obtain a HIPAA consent value. Other groups may only need to track GDPR consent values for the users of that group. Thus, the specific consent values shown in FIG. 3 are merely representative and not limiting. The user's data record 305 may include other types of user consent values in addition to the exemplary user consent values shown in FIG. 3.

[0040] According to some disclosed embodiments, each user consent value may be associated with one of at least two possible values, including a first value indicating that the user has given consent or a second value indicating that the user has refused consent. In some embodiments, the second value may also indicate that the user has revoked a previously given consent. Further, in some embodiments, one or more of exemplary user consent values 332-338 may also be associated with a third value indicating that the user has not yet responded with a grant or refusal of consent. The consent manager 232 may, for example, first assign any or all of user consent values 332-338 equal to the third value as default values. Then, after the user has indicated a grant or refusal of a particular user consent, the consent manager 232 may update the corresponding user consent value 332-338 in the user's record 305 to either the first value or the second value, depending on whether the user has granted or refused consent.

[0041] In some embodiments, the consent manager 232 may be configured to filter user consent values 332-338 in the user's record 305 assigned the third value and automatically send a message requesting one or more consents from the user or cause the message to be sent to another application or process. The consent manager may, for example, be configured to send a single message requesting one or more user consents to the user for the purpose of updating the consent value in the user's record 305. In some embodiments, the consent manager 232 may be configured to continuously scan each user record 305 to identify users having a third value assigned to a particular type of consent, such as a TCPA consent value 332, and then send a separate user consent request to each such identified user. In the disclosed embodiments, the consent manager 232 may asynchronously scan and filter user consent values 332-338 in the user record 305 periodically, at a predetermined time, or at the start of a new campaign or upon the occurrence of one or more predetermined events during a campaign.

[0042] The user record 305 may also store various user contact information 340 related to the associated user 110 of the record. Such user contact information 340 may include, for example, the user's phone number (for example, for telephone or text message communication), one or more email addresses, one or more physical mailing addresses, and / or other contact information. The record 305 may also include one or more other fields 350 that store various data, such as, for example, but not limited to, the date of creation of the user record, the date of last update, the identification and date of the last user consent request sent, etc.

[0043] Figure 4 is a flowchart showing an exemplary sequence of steps that may be implemented in computer system 200 to automatically generate an auto-reply message in response to a received telephone call from remote user 110, according to some disclosed embodiments. The sequence begins at step 400 and proceeds to step 410 where the computer system receives an incoming telephone call from the user. For example, computer system 200 may include a cellular network interface 210 configured to receive incoming calls, and the call may be processed by a phone app 234 running on one or more processors 220 of computer system 200. In some embodiments, computer system 200 may be implemented as one or more servers at a healthcare provider, such as a clinic, and the calling user may be a patient. Those skilled in the art will appreciate that the computer system 200 used according to the exemplary steps of FIG. 4 may include one or more computers in any enterprise or other entity configured to communicate with a remote user, such as in an exemplary enterprise 120 configured to communicate with remote user 110 in the network configuration of FIG. 1.

[0044] Next, at step 420, computer system 200 may be configured to identify caller ID information associated with an incoming call. The caller ID information may include, for example, the calling user's telephone number and / or name or other identifier. In some embodiments, the phone app 234 is configured to identify such caller ID information and provide the caller ID information to the consent manager 232 on the computer system 200. The consent manager 232 may be configured to use at least a portion of the caller ID information to access a user record 305 associated with the calling user. The accessed user record 305 may be stored in the memory 230, non-volatile memory 240, or one or more remote databases (not shown in FIG. 2) accessible to the computer system 200 through the communication interface 210, along with user consent data 300.

[0045] In some embodiments, the consent manager 232 may be configured to compare the caller ID information received from the phone app 234 with some information stored in the user record 305 to determine or verify the identity information of the calling user. The accessed user record 305 may include one or more consents 330 previously provided by the user, including, for example, a TCPA consent value 332 indicating whether the user has consented to receive text messages from a company or other entity associated with the computer system 200.

[0046] In step 430, the consent manager 232 in the computer system 200 determines whether the calling user has provided consent to receive text messages. If the consent manager determines that the user has not provided such consent, the sequence proceeds to step 480, where the computer system 200 does not send an auto - reply message to the user, and the sequence ends in step 490. On the other hand, in step 430, if the consent manager 232 determines that the calling user has provided consent to receive text messages, the consent manager 232 may communicate with the message app 236 to indicate that an auto - reply text message can be sent to the calling user. In some embodiments, the message app 236 may be separate from the phone app 234. In other embodiments, the exemplary phone app 234 and the message app 236 may be implemented as a single application in the computer system 200.

[0047] In step 440, the message app 236 automatically generates an auto - reply message to be sent to the calling user, for example, in a text message to be sent to that user via SMS. In some embodiments, the phone app 234 or the consent manager 232 may communicate information for identifying the calling user to the message app 236. In such embodiments, the message app 236 may be configured to generate an auto - reply message based on the identification information of the user by looking up a predefined auto - reply message for the user in, for example, a database (not shown in FIG. 2) stored in the memory 230, the non - volatile memory 240, or a remote database accessible through the communication interface 210. In some embodiments, the message app 236 may be configured to generate the same auto - reply message for all calling users. In other embodiments, the message app 236 may be configured to dynamically generate an auto - reply message, or at least a portion of an auto - reply message, for the calling user.

[0048] In some embodiments, for example, the message app 236 may use the calling user's phone number identified from the caller ID information of the incoming call (in step 420) or from the accessed user record 305 to address the auto-reply message. In some implementations, the message app 236 may be configured to include a dynamically generated greeting based on the name of the calling user identified from the caller ID information or from the user's record 305. In yet other embodiments, if the message app 236 can determine the content of the incoming phone call, such as using NLP (natural language processing) capabilities accessible through a local natural language processing engine or through a remote NLP cloud service, the message app 236 may dynamically generate at least a portion of the content of the auto-reply message based on the content of the received incoming call. In such embodiments, the NLP engine or cloud service may provide a transcription of at least a portion of the incoming call to the phone app 234 and / or the message app 236, and the phone app 234 and / or the message app 236 may perform pattern matching or other processing to identify one or more words or phrases in the incoming user call. For example, a machine learning or other artificial intelligence engine may reside in the memory 230 of the computer system 200 to process and analyze the content of the incoming call, or may be accessible to the computer system 200 via a cloud service through the communication interface 210.

[0049] In step 450, the message app 236 in the computer system 200 may determine whether additional user consent is required before sending the auto - reply message to the calling user. For example, if the auto - reply message contains advertising, marketing, ePHI, or billing information, the message app 236 may cooperate with the consent manager 232 to determine whether the user has provided one or more additional user consents required before sending the auto - reply message. For example, in some embodiments, the consent manager 232 may determine, based on the information it receives from the message app 236, whether additional user consent is required in step 450. In an alternative embodiment, the message app 236 may make the determination in step 450 and may require the consent manager 232 to confirm that the user has provided the corresponding user consent 330.

[0050] In step 450, if it is determined that additional user consent is required to send the auto - reply message, in step 460, the consent manager 232 may be configured to check whether the user record 305 for the calling user indicates that the user has provided additional consent. If the user record 305 for the calling user indicates that the user has provided additional consent, the process returns to step 450 to determine whether another user consent may be required to send the auto - reply. In step 460, if the user record 305 indicates that the calling user has not provided the required additional consent, in step 480, the computer system 200 does not send the auto - reply message. In this case, the message app 236 may be configured to discard the auto - reply message or, otherwise, delete it from the memory 230. The sequence ends in step 490.

[0051] If all additional user consents are verified in steps 450 - 460, the sequence proceeds from step 450 to step 470, and computer system 200 sends an auto - reply message to the calling user on the appropriate communication interface 210. The sequence then ends at step 490. Advantageously, as described above, computer system 200 can be configured not only to automatically generate and send an auto - reply message in response to receiving an incoming call from a remote user, but also to automatically verify that all necessary user consents have been obtained from the user before the auto - reply message can be sent. In this way, computer system 200 integrates an automated consent management system with the generation of the auto - reply message, thereby ensuring that the transmission of the auto - reply message to the calling user complies with laws, regulations, and rules that require user consent.

[0052] Figure 5 is a flowchart showing an exemplary sequence of steps that may be implemented in computer system 200 to automatically generate an auto - reply message in response to a received voice message from a remote user, according to some disclosed embodiments. In some embodiments, computer system 200 may be implemented as one or more servers in a healthcare provider, such as a clinic, and the calling user may be a patient. Those skilled in the art will also understand that the computer system used, according to the exemplary steps of Figure 5, may comprise one or more computers in any enterprise or other entity configured to communicate with a remote user.

[0053] The sequence in FIG. 5 starts at step 500 and proceeds to step 510 where computer system 200 receives a voice message from a user. For example, computer system 200 may include a cellular network interface 210 configured to receive an incoming call, which call may be processed by a phone app 234 running on the computer system. Phone app 234 may be configured to prompt the user to leave a message and may further be configured to record the user's voice message as an audio file in memory 230. Alternatively, phone app 234 may be configured to obtain the user's voice message from a telecommunications carrier that provides telephone service to an enterprise or other entity associated with computer system 200. In such an embodiment, phone app 234 may be configured to retrieve the user's recorded voice message stored by the telecommunications carrier from a voicemail box.

[0054] At step 520, computer system 200 may be configured to identify caller ID information and / or other metadata associated with the voice message from the user. For example, in some embodiments, a computer file containing the user's voice message may include some caller ID information, such as a phone number and / or name or other identifier of the user who left the voice message, stored in a file header or at one or more predetermined locations in the file, file name, or file path. In embodiments where the voice message is stored by a telecommunications carrier, the caller ID information associated with the user's recorded voice message may be downloaded separately or together with the voice message.

[0055] In some embodiments, the phone app 234 is configured to identify such caller ID information and provide the caller ID information to the consent manager 232 on the computer system 200. The consent manager 232 may be configured to use at least a portion of the caller ID information to access a user record 305 associated with the user who left the voice message. The accessed user record 305 may be stored in the memory 230, non-volatile memory 240, or one or more remote databases (not shown in FIG. 2) accessible to the computer system 200 through the communication interface 210, together with user consent data 300.

[0056] In some embodiments, the consent manager 232 may be configured to compare the caller ID information received from the phone app 234 with some information stored in the user record 305 to verify the identification information of the user who left the voice message. The accessed user record 305 may include one or more consents 330 previously provided by the user, including, for example, a TCPA consent value 332 indicating whether the user consented to receive text messages from a company or other entity associated with the computer system 200.

[0057] In step 530, the consent manager 232 in the computer system 200 determines whether the user who left the voice message has provided consent to receive text messages. If the consent manager determines that the user has not provided such consent, the sequence proceeds to step 590, where the computer system 200 does not send an automated reply message to the user, and the sequence ends in step 595. On the other hand, if in step 530 the consent manager 232 determines that the user has provided consent to receive text messages, the consent manager 232 may communicate with the message app 236 to indicate that an automated reply text message can be sent to the user who left the voice message. In some embodiments, the message app 236 may be separate from the phone app 234. In other embodiments, the phone app 234 and the message app 236 may be implemented as a single application in the computer system 200.

[0058] In step 540, the phone app 234, the message app 236, or another application 238 may be configured to transcribe the voice message, preferably as a transliteration of the user's voice recording into a desired language such as English. For example, in some embodiments, the phone app 234 or the message app 236 may employ NLP functionality accessible through a local NLP engine or through a remote NLP cloud service. In such embodiments, the local or remote NLP engine may provide the phone app 234 and / or the message app 236 with the transcription of at least a portion of the user's voice message. Alternatively, the NLP functionality may be integrated directly into either the phone app or the message app.

[0059] Next, in step 550, the message app 236 automatically generates an auto-reply message to be sent to the user who left the voice message, for example, in a text message to be sent to the user via SMS. In some embodiments, the phone app 234 or the consent manager 232 may communicate information for identifying the user to the message app 236. In such embodiments, the message app 236 may be configured to generate an auto-reply message based on the identification information of the user by looking up a predefined auto-reply message for the user in, for example, a database (not shown in FIG. 2) stored in the memory 230, the non-volatile memory 240, or in a remote database accessible through the communication interface 210. In some embodiments, the message app 236 may be configured to generate the same auto-reply message for all users. In other embodiments, the message app 236 may be configured to dynamically generate an auto-reply message, or at least a portion of the auto-reply message, based on the content of the received voice message and / or caller ID information or metadata associated with the voice message.

[0060] In some embodiments, for example, the message app 236 may use the user's phone number identified from the caller ID information or other metadata associated with the received voice message (in step 520), or from the accessed user record 305, to address the auto-reply message. In some implementations, the message app 236 may be configured to include a dynamically generated greeting based on the name of the calling user identified from the caller ID information or other metadata associated with the voice message, or from the user's record 305. In other embodiments, the message app 236 may dynamically generate at least a portion of the content of the auto-reply message based on the transcribed content of the voice message obtained in step 540. In such embodiments, a local or remote NLP engine may provide the transcription of at least a portion of the voice message to the phone app 234 and / or the message app 236, and the phone app 234 and / or the message app 236 may perform pattern matching or other processing to identify one or more words or phrases in the user's voice message. For example, a machine learning or other artificial intelligence engine may reside in the memory 230 of the computer system 200 to process and analyze the content of the transcribed voice message, or may be accessible to the computer system 200 via a cloud service through the communication interface 210.

[0061] In step 560, the message app 236 in the computer system 200 may determine whether additional user consent is required before sending an auto-reply message to the user who left the voice message. For example, if the auto-reply message includes advertising, marketing, ePHI, or billing information, the message app 236 may cooperate with the consent manager 232 to determine whether the user has provided one or more additional user consents required before sending the auto-reply message. For example, based on the information it receives from the message app 236, the consent manager 232 may determine in step 560 whether additional user consent is required. In other embodiments, the message app 236 may make the determination in step 560 and may require the consent manager 232 to confirm that the user has provided the corresponding user consent 330.

[0062] In step 560, if it is determined that additional user consent is required to send the auto-reply message, in step 570, the consent manager 232 may be configured to check whether the user record 305 for the user who left the voice message indicates that the user has provided additional consent. If the user record 305 for the user who left the voice message indicates that the user has provided additional consent, the process returns to step 560 to determine whether another user consent may be required to send the auto-reply. In step 570, if the user record 305 indicates that the user has not provided the required additional consent, in step 590, the computer system 200 does not send the auto-reply message. In this case, the message app 236 may be configured to discard the auto-reply message or, otherwise, delete it from the memory 230. The sequence ends in step 595.

[0063] If all additional user consents are verified in steps 560 - 570, the sequence proceeds from step 560 to step 580, where computer system 200 sends an auto - reply message on the appropriate communication interface 210 to the user who left the voice message. The sequence then ends at step 595. As in the embodiment described with reference to FIG. 4, in this alternative embodiment of FIG. 5, computer system 200 can be configured not only to automatically generate and send an auto - reply message in response to receiving an incoming call from a remote user, but also to automatically verify that all necessary user consents have been obtained from the user before the auto - reply message can be sent. In this way, computer system 200 integrates an automated consent management system with the generation of the auto - reply message, thereby ensuring that the sending of the auto - reply message to the calling user complies with laws, rules, and regulations that require user consent.

[0064] The foregoing description has been directed to specific embodiments. However, it will be apparent that other variations and modifications can be made to the described embodiments, with some or all of their advantages achieved. For example, it is expressly contemplated that the components and / or elements described herein can be implemented as software stored on a tangible (non - transitory) computer - readable medium (e.g., disk / CD / RAM / EEPROM, etc.) having program instructions executable on a computer, hardware, firmware, or a combination thereof. It will also be apparent to those skilled in the art that other processor and memory types, including various computer - readable media, can be used to store and execute the program instructions related to the technology described herein. Further, the present invention is not limited to a particular hardware platform or set of software functions.

[0065] The disclosed embodiments illustrate various processes, and it is expressly contemplated that the various processes may be embodied as modules configured to operate in accordance with the techniques herein (e.g., in accordance with the functions of similar processes). Further, although some processes are shown or described separately, those skilled in the art will understand that the disclosed processes may be routines or modules within other processes.

[0066] Further, it is expressly contemplated that the exemplary sequences of steps described with reference to FIGS. 4 and 5 may be performed in an order different from the exemplary order shown in these figures. By way of example and not limitation, in some embodiments, the steps of automatically generating an auto-reply message (steps 440 and 550) may be performed after all required user consents have been verified (steps 430, 450 - 460 and 530, 560 - 570). In such alternative embodiments, for example, the type of user consent required to send an auto-reply message may be known in advance by consent manager 232, message app 236, or any other application in order to enable consent manager 232 to check all required user consents prior to generation of an auto-reply message by message app 236.

[0067] Accordingly, this description should be taken as illustrative only and not as specifically limiting the scope of the embodiments herein. Accordingly, it is the purpose of the appended claims to cover all modifications and variations that fall within the true spirit and scope of the embodiments herein.

Claims

1. A method for integrating an automated consent management system with the automatic generation and transmission of auto-reply messages in a computer system, the computer system having one or more communication interfaces for communicating with one or more users on a first communication channel and a second communication channel, the method comprising: receiving an incoming communication from a user on the first communication channel at the one or more communication interfaces; identifying the user based on information received with the incoming communication; using the automated consent management system to determine whether the identified user has provided consent to receive a message from the computer system on the second communication channel; using the automated consent management system to determine whether the identified user has provided additional consent required to receive a message from the computer system on the second communication channel; if the automated consent management system determines that the identified user has provided both the consent and the additional consent to receive a message from the computer system on the second communication channel, transmitting an auto-reply message to the user on the second communication channel through the one or more communication interfaces A method as described above.

2. The method according to claim 1, wherein the incoming communication is a telephone call and the auto-reply message is transmitted to the user in a text message.

3. The method according to claim 2, wherein the first communication channel corresponds to a voice call connection from the user to the computer system and the second communication channel corresponds to a text message connection from the computer system to the user.

4. The method according to claim 2, wherein the one or more communication interfaces include a cellular network interface configured to receive the telephone call from the user and to transmit the auto-reply message to the user in a text message.

5. The method according to claim 1, wherein the consent indicates that the user has consented to receive a text message from the computer system.

6. The method of claim 5, wherein the consent indicates that the user has provided consent to receive text messages in accordance with the Telephone Consumer Protection Act (TCPA). **Claim 7** The method of claim 1, wherein the additional consent indicates that the user has provided consent to the computer system to communicate the user's health information. **Claim 8** The method of claim 1, wherein the incoming communication includes a voice message from the user, and the automated response message is transmitted to the user in a text message. **Claim 9** transcribing the voice message from the user; automatically generating the automated response message to be sent to the user based on at least a portion of the content of the transcribed voice message from the user The method of claim 8, further comprising: **Claim 10** The method of claim 1, wherein the computer system is implemented in a healthcare provider. **Claim 11** The method of claim 1, wherein the computer system is configured to send the same automated response message to each of the one or more users. **Claim 12** A computer system configured to integrate an automated consent management system with the automated generation and transmission of automated response messages, the computer system comprising: one or more communication interfaces configured to communicate with a user on a first communication channel and a second communication channel, the one or more communication interfaces being configured to receive an incoming communication from the user on the first communication channel; one or more processors; a memory configured to store one or more user records and further configured to store computer-executable instructions that, when executed by the one or more processors, implement a consent manager, a phone application, and a message application; comprising, execution of the computer-executable instructions: identifying, by the phone application, information corresponding to the user's identification information based on information received with the incoming communication at the one or more communication interfaces; The phone application provides the consent manager with the information corresponding to the user's identification information; Based on the information corresponding to the user's identification information provided by the phone application, the consent manager accesses user records from the one or more user records; The consent manager determines whether the accessed user record indicates that the user has provided consent to receive messages from the computer system on the second communication channel; The consent manager determines whether the accessed user record indicates that the user has provided additional consent to receive messages from the computer system on the second communication channel; In response to the consent manager determining that the user has provided the consent and the additional consent to receive messages from the computer system on the second communication channel, the message application automatically generates an auto-reply message to be sent to the user; When the automated consent management system determines that the user has provided both the consent and the additional consent to receive messages from the computer system on the second communication channel, the generated auto-reply message is transmitted to the user on the second communication channel through the one or more communication interfaces; A computer system further configured to cause the computer system to perform the above.

13. The computer system according to claim 12, wherein the incoming communication is a phone call and the auto-reply message is transmitted to the user in a text message.

14. The computer system according to claim 13, wherein the first communication channel corresponds to a voice call connection from the user to the computer system, and the second communication channel corresponds to a text message connection from the computer system to the user.

15. The computer system of claim 13, wherein the one or more communication interfaces are configured to receive the telephone call from the user and to send the automated reply message to the user in a text message, and include a cellular network interface.

16. The computer system of claim 12, wherein the consent indicates that the user has consented to receiving a text message from the computer system.

17. The computer system of claim 12, wherein the additional consent indicates that the user has provided consent to the computer system to communicate the user's health information.

18. The computer system of claim 12, wherein the incoming communication includes a voice message from the user, and the automated reply message is sent to the user in a text message.

19. A non-transitory computer-readable medium including a set of computer-executable instructions that, when executed by one or more processors of a computer system, integrate an automated consent management system with the automated generation and sending of an automated reply message, wherein the computer system has one or more communication interfaces for communicating with one or more users on a first communication channel and a second communication channel, and the execution of the computer-executable instructions causes receiving, at the one or more communication interfaces, an incoming communication from a user on the first communication channel; identifying the user based on information received with the incoming communication; using the automated consent management system to determine whether the identified user has provided consent to receive a message from the computer system on the second communication channel; using the automated consent management system to determine whether the identified user has provided additional consent required to receive a message from the computer system on the second communication channel; If the automated consent management system determines that the identified user has provided both the consent and the additional consent for the user to receive messages from the computer system on the second communication channel, sending an automated reply message to the user on the second communication channel through the one or more communication interfaces A non-transitory computer-readable medium that configures the computer system to perform the above. **Claim 20** The computer-readable medium according to claim 19, wherein the incoming communication is a telephone call and the automated reply message is a text message.

Citation Information

Patent Citations

  • Automated Consent Management Systems and Methods for Using Same

    US20220198465A1