System
The system addresses the challenge of anonymizing medical data by using AI tools for efficient acquisition, identification, storage, and organization, ensuring compliance and rewarding data providers, thus facilitating secure and efficient data utilization.
Patent Information
- Application Number
- JP2024120573
- Authority / Receiving Office
- JP · JP
- Patent Type
- Applications
- Current Assignee / Owner
- Filing Date
- 2024-07-25
- Publication Date
- 2026-02-05
AI Technical Summary
Current systems face challenges in efficiently and safely anonymizing medical information due to the complexity of data handling and the risk of human error, while also lacking mechanisms to reward data providers for its use.
A system that includes means for acquiring, identifying, anonymizing, verifying, securely storing, organizing, and providing interfaces for medical information, along with calculating and distributing rewards, utilizing AI tools for efficient and secure data management.
Enables safe and efficient anonymization and utilization of medical data, ensuring compliance with privacy laws and facilitating data-driven research while rewarding data providers.
Smart Images

Figure 2026019164000001_ABST
Abstract
Description
[Technical Field]
[0001] The technology of the present disclosure relates to a system. [Background technology]
[0002] Patent document 1 discloses a persona chatbot control method performed by at least one processor, the method including the steps of receiving a user utterance, adding the user utterance to a prompt including an instruction sentence related to a description of the chatbot character, encoding the prompt, and inputting the encoded prompt into a language model to generate a chatbot utterance in response to the user utterance. [Prior art documents] [Patent documents]
[0003] [Patent Document 1] Japanese Patent Publication No. 2022-180282 Summary of the Invention [Problem to be solved by the invention]
[0004] In the current era of big data, the utilization of medical data is being promoted. However, under the Personal Information Protection Act, medical information such as "medical history" is classified as sensitive personal information, and there are significant restrictions on how it can be handled. While the appropriate use of medical information contributes to the realization of a society in which people live longer and healthier lives, its use requires advanced specialized knowledge and skills, making it difficult to use. Furthermore, manual data anonymization is time-consuming and labor-intensive, and there is a risk of human error. This means that the potential value of medical data is not being fully realized. Therefore, there is a need for a system that can anonymize medical information and utilize it safely and efficiently. [Means for solving the problem]
[0005] To solve the above-mentioned problems, the present invention provides a system having the following features. The system of the present invention includes a means for acquiring medical information, a means for identifying elements from the acquired medical information that can identify an individual, a means for anonymizing the identified elements in accordance with the Personal Information Protection Act, a means for verifying whether the anonymized information meets predetermined standards, a means for securely storing the anonymized information, a means for receiving and systematically organizing the anonymized medical information, a means for providing an interface for searching and viewing the organized medical information, and a means for calculating compensation based on data usage and distributing it to data providers. This system enables the anonymization and utilization of medical information to be performed efficiently and safely, fully realizing the potential value of medical data and allowing it to be used safely from the perspective of personal information protection.
[0006] "Medical information" refers to data related to an individual's health that is held by a medical institution or pharmacy, such as a patient's medical history, medical records, and prescription information.
[0007] A "personally identifiable element" is data such as name, address, or date of birth that can be used alone or in combination with other information to identify an individual.
[0008] "Anonymization" refers to the conversion or processing of data so that it cannot identify individuals, in accordance with the Personal Information Protection Act.
[0009] "Means of acquisition" refers to interfaces for collecting data, such as through APIs, file uploads, form input, etc.
[0010] "Means of identification" refers to a method of extracting elements from data that can identify an individual using natural language processing algorithms, etc.
[0011] "Conversion methods" refer to methods that convert names, addresses, etc. into random identifiers and mask or obscure certain dates and medical history information.
[0012] "Verification measures" refers to the process of checking whether the anonymized data meets predetermined standards.
[0013] "Secure storage means" refers to mechanisms for protecting anonymized data using access rights management and encryption technologies.
[0014] "Means of receiving" refers to a method of securely obtaining data from another system, and is done using an interface.
[0015] "Organization" refers to the process of systematically classifying received data and normalizing and indexing it to make it easier to search and view.
[0016] "Means for providing an interface" refers to a user interface that allows users to easily search and view anonymized medical data.
[0017] "Means for calculating and allocating rewards" refers to algorithms or mechanisms that automatically calculate and appropriately allocate rewards to providers based on data usage. [Brief explanation of the drawings]
[0018] [Figure 1] 1 is a conceptual diagram showing an example of the configuration of a data processing system according to a first embodiment. [Figure 2] 1 is a conceptual diagram showing an example of main functions of a data processing device and a smart device according to a first embodiment. [Figure 3] FIG. 10 is a conceptual diagram showing an example of the configuration of a data processing system according to a second embodiment. [Figure 4] FIG. 10 is a conceptual diagram showing an example of main functions of a data processing device and smart glasses according to a second embodiment. [Figure 5] FIG. 10 is a conceptual diagram showing an example of the configuration of a data processing system according to a third embodiment. [Figure 6]FIG. 11 is a conceptual diagram showing an example of main functions of a data processing device and a headset-type terminal according to a third embodiment. [Figure 7] FIG. 10 is a conceptual diagram showing an example of the configuration of a data processing system according to a fourth embodiment. [Figure 8] FIG. 10 is a conceptual diagram showing an example of main functions of a data processing device and a robot according to a fourth embodiment. [Figure 9] 1 shows an emotion map onto which multiple emotions are mapped. [Figure 10] 1 shows an emotion map onto which multiple emotions are mapped. [Figure 11] FIG. 3 is a sequence diagram showing a processing flow of the data processing system according to the first embodiment. [Figure 12] FIG. 10 is a sequence diagram showing the flow of processing in the data processing system in Application Example 1. [Figure 13] FIG. 10 is a sequence diagram showing the flow of processing in the data processing system according to the second embodiment when an emotion engine is combined. [Figure 14] FIG. 10 is a sequence diagram showing the flow of processing in the data processing system in Application Example 2 when an emotion engine is combined. DETAILED DESCRIPTION OF THE INVENTION
[0019] An example of an embodiment of a system according to the technology of the present disclosure will be described below with reference to the accompanying drawings.
[0020] First, the terms used in the following description will be explained.
[0021] In the following embodiments, a coded processor (hereinafter simply referred to as a "processor") may be a single arithmetic device or a combination of multiple arithmetic devices. Furthermore, a processor may be a single type of arithmetic device or a combination of multiple types of arithmetic devices. Examples of arithmetic devices include a CPU (Central Processing Unit), a GPU (Graphics Processing Unit), a GPGPU (General-Purpose computing on Graphics Processing Units), and an APU (Accelerated Processing Unit).
[0022] In the following embodiments, a coded RAM (Random Access Memory) is a memory in which information is temporarily stored and is used as a working memory by a processor.
[0023] In the following embodiments, the coded storage is one or more non-volatile storage devices that store various programs, various parameters, etc. Examples of non-volatile storage devices include flash memory (SSD (Solid State Drive)), magnetic disks (e.g., hard disks), and magnetic tapes.
[0024] In the following embodiments, a communication I / F (Interface) with a symbol is an interface including a communication processor, an antenna, etc. The communication I / F controls communication between multiple computers. Examples of communication standards applied to the communication I / F include wireless communication standards including 5G (5th Generation Mobile Communication System), Wi-Fi (registered trademark), Bluetooth (registered trademark), etc.
[0025] In the following embodiments, "A and / or B" is synonymous with "at least one of A and B." In other words, "A and / or B" means that it may be only A, only B, or a combination of A and B. Furthermore, in this specification, the same concept as "A and / or B" is also applied when three or more things are expressed connected by "and / or."
[0026] [First embodiment]
[0027] FIG. 1 shows an example of the configuration of a data processing system 10 according to the first embodiment.
[0028] 1, a data processing system 10 includes a data processing device 12 and a smart device 14. An example of the data processing device 12 is a server.
[0029] The data processing device 12 includes a computer 22, a database 24, and a communication I / F 26. The computer 22 is an example of a "computer" according to the technology of the present disclosure. The computer 22 includes a processor 28, a RAM 30, and a storage 32. The processor 28, the RAM 30, and the storage 32 are connected to a bus 34. The database 24 and the communication I / F 26 are also connected to the bus 34. The communication I / F 26 is connected to a network 54. Examples of the network 54 include a WAN (Wide Area Network) and / or a LAN (Local Area Network).
[0030] The smart device 14 includes a computer 36, a reception device 38, an output device 40, a camera 42, and a communication I / F 44. The computer 36 includes a processor 46, a RAM 48, and a storage 50. The processor 46, the RAM 48, and the storage 50 are connected to a bus 52. The reception device 38, the output device 40, and the camera 42 are also connected to the bus 52.
[0031] The reception device 38 includes a touch panel 38A, a microphone 38B, and the like, and receives user input. The touch panel 38A detects contact with an indicator (for example, a pen or a finger) to receive user input by the touch of the indicator. The microphone 38B detects the user's voice to receive user input by voice. The control unit 46A transmits data indicating the user input received by the touch panel 38A and the microphone 38B to the data processing device 12. In the data processing device 12, the specific processing unit 290 acquires the data indicating the user input.
[0032] The output device 40 includes a display 40A and a speaker 40B, and presents data to the user 20 by outputting the data in a form of expression that the user 20 can perceive (for example, audio and / or text). The display 40A displays visible information such as text and images in accordance with instructions from the processor 46. The speaker 40B outputs audio in accordance with instructions from the processor 46. The camera 42 is a compact digital camera equipped with an optical system including a lens, aperture, and shutter, and an imaging element such as a CMOS (Complementary Metal-Oxide-Semiconductor) image sensor or a CCD (Charge Coupled Device) image sensor.
[0033] The communication I / F 44 is connected to a network 54. The communication I / Fs 44 and 26 control the exchange of various information between the processor 46 and the processor 28 via the network 54.
[0034] FIG. 2 shows an example of the main functions of the data processing device 12 and the smart device 14.
[0035] 2, in the data processing device 12, a specific process is performed by the processor 28. A specific processing program 56 is stored in the storage 32. The specific processing program 56 is an example of a "program" according to the technology of the present disclosure. The processor 28 reads the specific processing program 56 from the storage 32 and executes the read specific processing program 56 on the RAM 30. The specific process is realized by the processor 28 operating as a specific processing unit 290 in accordance with the specific processing program 56 executed on the RAM 30.
[0036] The storage 32 stores a data generation model 58 and an emotion identification model 59. The data generation model 58 and the emotion identification model 59 are used by the identification processing unit 290.
[0037] In the smart device 14, the processor 46 performs the reception output process. The storage 50 stores a reception output program 60. The reception output program 60 is used in conjunction with the specific processing program 56 by the data processing system 10. The processor 46 reads the reception output program 60 from the storage 50 and executes the read reception output program 60 on the RAM 48. The reception output process is realized by the processor 46 operating as the control unit 46A in accordance with the reception output program 60 executed on the RAM 48.
[0038] Next, a description will be given of the specific processing performed by the specific processing unit 290 of the data processing device 12. In the following description, the data processing device 12 will be referred to as a "server" and the smart device 14 will be referred to as a "terminal."
[0039] MODE FOR CARRYING OUT THE INVENTION
[0040] This paper describes a system for safely anonymizing medical information and promoting its use. This system is broadly composed of an AI tool for anonymizing medical information and an AI tool for collecting, viewing, and consulting on medical information.
[0041] AI tool for anonymizing medical information
[0042] Data collection
[0043] The server receives patient data (medical records and medication information) in multiple formats from medical institutions and pharmacies. For example, it collects data via API or file upload and stores it in secure storage. If necessary, it performs preprocessing to unify the data format.
[0044] Personal Information Identification
[0045] The server automatically identifies personally identifiable information (such as name, address, date of birth, etc.) from the received data using natural language processing algorithms, using text analysis and pattern matching techniques, and then lists the results.
[0046] Data Conversion
[0047] The server anonymizes identified personal information in a manner compliant with the Personal Information Protection Act, for example, by replacing names and addresses with random identifiers and blurring birthdates and specific date data into ranges or general formats.
[0048] Data Check
[0049] The server verifies whether the converted data meets various standards, and if it does not meet certain anonymity standards, it performs additional anonymization processing.
[0050] Data storage
[0051] The server stores the verified and anonymized data in a secure database, which is protected by strict access controls and encryption technology.
[0052] AI tool for collection, viewing, and consultation
[0053] Data reception
[0054] The server receives the anonymized data provided by the medical information anonymization AI tool and checks the integrity of the data upon receipt.
[0055] Data organization
[0056] The server organizes the received anonymized data in a systematic manner, normalizing and indexing it for easy searching and browsing, thereby making data organization more cohesive and efficient.
[0057] Providing search and browsing functionality
[0058] The terminal (user device) provides an interface that allows users to search and view anonymized medical information. For example, if a user wants to search for information about a certain disease, they enter keywords, set search conditions, and retrieve data.
[0059] Reward Allocation
[0060] The server automatically calculates and distributes rewards to data providers according to the user's data usage. This involves analyzing the data access log and calculating the reward amount for each information provider.
[0061] Example
[0062] Example 1: Collecting and anonymizing patient data from medical institutions
[0063] The server receives patient medical record information from a medical institution using an API.
[0064] The server uses a natural language processing algorithm to identify the name, address, and date of birth from the received data.
[0065] The server converts these personal details into a random identifier and blurs the "birthday" information to a year.
[0066] The server automatically checks whether the anonymized data meets the standards and, if OK, stores it in a secure database.
[0067] Example 2: Pharmaceutical companies search and utilize anonymized data
[0068] Users (researchers at pharmaceutical companies) access the server using their own terminals.
[0069] The terminal provides the user with a search interface, and the user sets search conditions by entering the keyword "diabetes."
[0070] The server retrieves and displays relevant information from an indexed, anonymized database.
[0071] The server calculates and distributes remuneration to the medical institution that provided the data based on the data used.
[0072] Through the above steps, the present invention enables the anonymization and efficient utilization of medical information, and provides a solution for safely handling medical data.
[0073] The processing flow will be explained below.
[0074] AI tool for anonymizing medical information
[0075] Processing steps from data collection to anonymization
[0076] Step 1:
[0077] The server receives patient data from medical institutions and pharmacies via API or file upload. Upon receiving the data, it checks whether the data format is consistent and performs preprocessing as necessary to standardize the format.
[0078] Step 2:
[0079] The server identifies personally identifiable information (such as name, address, and date of birth) from the received patient data by analyzing the text using a natural language processing algorithm and compiling the information into an extracted list.
[0080] Step 3:
[0081] The server anonymizes the identified personal information. Specifically, in accordance with the Personal Information Protection Act, it converts names and addresses into random identifiers (e.g., UUIDs), and converts birthdays and specific dates into ranges or obscured information (e.g., leaving only the year of the date).
[0082] Step 4:
[0083] The server verifies the anonymized data, conducting automated checks to ensure that it meets the standards in terms of anonymity, and if there are any deficiencies, performs additional anonymization processes.
[0084] Step 5:
[0085] The server then stores the verified anonymized data in a secure database, where access control permissions are set and the data is protected using encryption technology.
[0086] AI tool for collection, viewing, and consultation
[0087] Processing steps from receiving data to allocating rewards
[0088] Step 1:
[0089] The server receives the anonymized data provided by the medical information anonymization AI tool, and upon receiving it performs a data integrity check to ensure there are no missing or incorrect data.
[0090] Step 2:
[0091] The server organizes the received anonymously processed data, normalizes the data, and performs indexing to make it easier to search and view, thereby enabling efficient data management.
[0092] Step 3:
[0093] The device provides a user interface for users to search and view anonymized medical information. Users can input keywords and set conditions to search for data.
[0094] Step 4:
[0095] The server displays the anonymized data as a search result and allows the user to view the details.
[0096] Step 5:
[0097] The server calculates and distributes rewards to data providers (medical institutions and pharmacies) based on the user's data usage. It analyzes the data access log and calculates the reward amount based on that.
[0098] Specific examples
[0099] Collection and anonymization of patient data from medical institutions
[0100] Step 1:
[0101] The server receives patient data via API from Medical Institution A. This data includes medical records and medication information.
[0102] Step 2:
[0103] The server analyzes the received data and uses natural language processing to identify personally identifiable information such as name, address, and date of birth.
[0104] Step 3:
[0105] The server converts names to random identification IDs, blurs addresses to the region level, and converts birthdates to years.
[0106] Step 4:
[0107] The server automatically checks whether the anonymization has been performed properly, and if there are any defects, it performs the anonymization process again.
[0108] Step 5:
[0109] The server then encrypts the anonymized data after checking and stores it in a secure database.
[0110] When pharmaceutical companies use anonymized data
[0111] Step 1:
[0112] Users (researchers at pharmaceutical companies) access the server using their own terminals.
[0113] Step 2:
[0114] The terminal provides a search interface to the user, allowing the user to input keywords to search for data relating to a particular disease.
[0115] Step 3:
[0116] The server quickly extracts data that matches the search criteria from the indexed, anonymized database.
[0117] Step 4:
[0118] The terminal displays the search results to the user, allowing the user to view the details.
[0119] Step 5:
[0120] The server analyzes the user's data usage log and distributes appropriate rewards to the data providers.
[0121] Example 1
[0122] Next, a description will be given of Example 1. In the following description, the data processing device 12 will be referred to as a "server" and the smart device 14 will be referred to as a "terminal."
[0123] Currently, it is difficult to safely anonymize medical information and use it efficiently. In particular, the process of acquiring medical information, standardizing it into a specific format, identifying personally identifiable elements using natural language processing, and then anonymizing it is complex, and there is no system that appropriately rewards users for using anonymized information. Therefore, while there is a need to simultaneously ensure the safety and usefulness of medical data, current technology does not adequately achieve this.
[0124] The specific processing by the specific processing unit 290 of the data processing device 12 in the first embodiment is realized by the following means.
[0125] In this invention, the server includes means for acquiring medical information, means for identifying elements that can identify an individual from the acquired medical information, means for anonymizing the identified elements in accordance with the Personal Information Protection Act, means for verifying whether the anonymized information meets predetermined standards, means for securely storing the anonymized information, means for receiving and systematically organizing the anonymized medical information, means for providing an interface for searching and viewing the organized medical information, means for calculating rewards based on data usage and distributing them to data providers, means for preprocessing the anonymized medical information, means for standardizing the format of the preprocessed information, means for converting the anonymized information into a random identifier and blurring specific dates to years, and means for verifying the integrity of the anonymized information using a checksum, thereby enabling safe anonymization and efficient use of medical information.
[0126] "Medical information" refers to health-related data recorded and managed by medical institutions and pharmacies, such as patient medical records and medication information.
[0127] "Means of acquisition" refers to the process of receiving information from medical institutions and pharmacies using methods such as APIs or file uploads.
[0128] "Means of identification" refers to techniques that use natural language processing algorithms and pattern matching to extract elements within the data that can identify an individual.
[0129] "Anonymization methods" are techniques that prevent the identification of individuals by replacing personally identifiable elements with random identifiers or blurring date data.
[0130] "Verification measures" are processes for checking whether anonymized information meets predetermined standards.
[0131] "Means for storage" refers to storage systems and security technologies for safely managing anonymized information.
[0132] "Systematization" refers to the process of normalizing incoming medical information and creating an index to make it easier to search and view.
[0133] The "means for providing an interface" refers to a technology that implements a user interface that allows users to search and view medical information.
[0134] The "means for calculating and allocating rewards" is a process for automatically calculating and allocating rewards to data providers based on the usage status of the data.
[0135] The "preprocessing means" refers to a data conversion technique for converting received medical information into a unified format.
[0136] "Format harmonization" is the process of converting medical data provided in different formats into a consistent data format.
[0137] A "random identifier conversion method" is a process that replaces personal information such as name and address with a randomly generated identifier.
[0138] "Year blurring" is the process of converting specific date information into year information to prevent personal identification.
[0139] "Means for verifying using a checksum" refers to a technique for verifying using a checksum to ensure the integrity of data.
[0140] This invention is a system designed to safely anonymize medical information and promote its use. This system consists of two main components: an AI tool for anonymizing medical information and an AI tool for collecting, viewing, and consulting medical information.
[0141] AI tool for anonymizing medical information
[0142] Data collection
[0143] The server receives patient data (medical records and medication information) from medical institutions and pharmacies via API or file upload. After receiving the data, the server stores the information in secure storage (e.g., AWS S3 bucket or Google Cloud Storage). It also performs checksum verification to ensure the integrity of the received data. It also performs preprocessing to convert data provided in different formats into a unified format.
[0144] Examples:
[0145] The server receives patient medical record information from a medical institution using an API.
[0146] The server stores the received medical record information in an AWS S3 bucket and verifies the integrity of the data using a checksum.
[0147] Personal Information Identification
[0148] The server uses natural language processing algorithms (e.g., SpaCy or NLTK) to extract personally identifiable information (e.g., name, address, date of birth) from the data it receives, and also uses pattern matching techniques to identify email addresses and phone numbers within the data.
[0149] Examples:
[0150] The server uses a natural language processing algorithm to extract "name," "address," and "date of birth" from the medical record information.
[0151] Data Conversion
[0152] The server performs anonymization processing in accordance with the Personal Information Protection Act, such as converting identified personal information into a random identifier and blurring birthday information to years.
[0153] Examples:
[0154] The server converts the extracted "name" into a random identifier and blurs the "birthday" to a year.
[0155] Data Check
[0156] The server verifies whether the converted data meets predetermined criteria, and if not, performs additional anonymization processing.
[0157] Examples:
[0158] The server verifies the anonymity of the anonymized data and performs the anonymization process again if the criteria are not met.
[0159] Data storage
[0160] The server stores the verified, anonymized data in a secure database (e.g., AWS RDS, MongoDB Atlas), which is protected by encryption and access controls.
[0161] Examples:
[0162] The server stores anonymized medical record information in AWS RDS and encrypts and controls access to the database.
[0163] AI tool for collection, viewing, and consultation
[0164] Data reception
[0165] The server receives the anonymized data provided by the medical information anonymization AI tool and checks the integrity of the data upon receipt.
[0166] Examples:
[0167] The server receives the data provided by the anonymization AI tool and verifies the integrity of the data using a checksum.
[0168] Data organization
[0169] The server normalizes the received anonymized data and indexes it for efficient search (e.g., using Elasticsearch).
[0170] Examples:
[0171] The server indexes the anonymized data using Elasticsearch and normalizes it into a unified format.
[0172] Providing search and browsing functionality
[0173] The device provides an interface for users to search and view anonymized medical information. Users can enter keywords and set search criteria to retrieve relevant data.
[0174] Examples:
[0175] A user (a researcher at a pharmaceutical company) accesses the server using his or her own terminal, enters the keyword "diabetes," and sets search conditions.
[0176] The terminal provides the user with a search interface and displays search results based on the user's input.
[0177] Reward Allocation
[0178] The server analyzes the access log according to the user's data usage, and calculates and distributes rewards to the data provider.
[0179] Examples:
[0180] The server calculates the amount of compensation to each information provider based on the data used and distributes the compensation to the medical institution that provided the data.
[0181] The above-mentioned method enables safe anonymization and efficient use of medical information, providing a comprehensive solution for using medical data with peace of mind.
[0182] The flow of the identification process in the first embodiment will be described with reference to FIG.
[0183] Step 1: Receiving data
[0184] The server receives patient data from medical institutions and pharmacies via API or file upload. Data is often provided in CSV or JSON format. Data is sent using API requests or FTP servers. API requests or files are given as input, and the received data is saved to storage.
[0185] Specific behavior:
[0186] The server receives medical record information sent by an API request from a medical institution.
[0187] The server stores the received data in an AWS S3 bucket.
[0188] Step 2: Verify data integrity
[0189] The server uses a checksum to verify the integrity of the received data. The received data and checksum information are given as input, and the output is a confirmation of the data integrity.
[0190] Specific behavior:
[0191] The server verifies the checksum of the received medical record information.
[0192] If the server is able to verify the integrity of the data, it proceeds to the next processing step.
[0193] Step 3: Data Preprocessing
[0194] The server performs preprocessing to convert data provided in different formats into a unified format. The received data is given as input, and data in the unified format is obtained as output.
[0195] Specific behavior:
[0196] The server converts the received CSV format medical record information into JSON format.
[0197] The server stores the converted data in temporary storage.
[0198] Step 4: Personal Identification
[0199] The server uses natural language processing algorithms (e.g., SpaCy or NLTK) to extract personally identifiable information from the data (e.g., name, address, date of birth). The preprocessed data is given as input, and personally identifiable information is obtained as output.
[0200] Specific behavior:
[0201] The server uses SpaCy to extract "name," "address," and "date of birth" from the medical record information.
[0202] The server stores the extraction results as a list.
[0203] Step 5: Data Transformation
[0204] The server converts the identified personal information into a random identifier and performs anonymization processing such as blurring birthdate information into years. The extracted personal identification information is given as input, and anonymized data is obtained as output.
[0205] Specific behavior:
[0206] The server converts the extracted "name" into a random identifier and blurs the "birthday" to a year.
[0207] The server stores the anonymized data in temporary storage.
[0208] Step 6: Verify the anonymized data
[0209] The server verifies whether the converted data meets the specified criteria. The anonymized data is given as input, and the verification result indicating whether the criteria are met is obtained as output.
[0210] Specific behavior:
[0211] The server verifies the anonymity of the anonymized data.
[0212] If the criteria are not met, the server performs the anonymization process again.
[0213] Step 7: Save Data
[0214] The server stores the verified anonymized data in a secure database. The input is the verified anonymized data, and the output is the anonymized data stored in the database.
[0215] Specific behavior:
[0216] The server stores the anonymized medical record information in AWS RDS.
[0217] The server enforces encryption and access control on the database.
[0218] Step 8: Data reception and integrity check
[0219] The server receives the anonymized data provided by the medical information anonymization AI tool and performs a consistency check. The anonymized data is given as input, and the consistency check result is obtained as output.
[0220] Specific behavior:
[0221] The server receives the data provided by the medical information anonymization AI tool.
[0222] The server uses the checksum to verify the integrity of the data.
[0223] Step 9: Data organization
[0224] The server normalizes the received anonymized data and indexes it using Elasticsearch. The anonymized data is given as input, and the indexed data is obtained as output.
[0225] Specific behavior:
[0226] The server normalizes the anonymized data and indexes it using Elasticsearch.
[0227] Step 10: Search and Browse Functions
[0228] The terminal provides an interface for users to search and view anonymized medical information. The terminal receives user search criteria as input and displays search results as output.
[0229] Specific behavior:
[0230] A user accesses the server using a terminal and inputs search criteria.
[0231] The terminal provides the user with a search interface and displays search results from the server.
[0232] Step 11: Reward Allocation
[0233] The server analyzes the access log based on the user's data usage, calculates and distributes rewards to data providers, and receives the access log as input and the reward distribution results as output.
[0234] Specific behavior:
[0235] The server calculates the amount of remuneration to each information provider based on the data used.
[0236] The server distributes the calculated remuneration to each medical institution.
[0237] Through the above processing steps, the present invention realizes safe anonymization and efficient use of medical information.
[0238] (Application example 1)
[0239] Next, a description will be given of Application Example 1. In the following description, the data processing device 12 will be referred to as a "server" and the smart device 14 will be referred to as a "terminal."
[0240] Medical information is highly confidential, and its handling requires strict privacy measures. However, real-time data acquisition and anonymization are difficult, and secure data handling is not ensured in many settings. Furthermore, there is a lack of interfaces for efficiently searching and viewing anonymized information, hindering progress in data utilization. Furthermore, there is a need for an efficient method for allocating rewards based on data usage.
[0241] The specific processing by the specific processing unit 290 of the data processing device 12 in the application example 1 is realized by the following means.
[0242] In this invention, the server includes means for acquiring medical information, means for identifying elements that can identify individuals from the acquired medical information, means for anonymizing the identified elements in accordance with the Personal Information Protection Act, means for verifying whether the anonymized information meets predetermined standards, means for securely storing the anonymized information, means for receiving and systematically organizing the anonymized medical information, means for providing an interface for searching and viewing the organized medical information, means for calculating rewards based on data usage and allocating them to data providers, and means for anonymizing and securely processing patient data in real time at medical sites using smart glasses, thereby enabling real-time anonymization, secure processing, and efficient utilization of medical information.
[0243] "Medical information" refers to personal medical records and health data held by medical institutions, such as patient charts and medication information.
[0244] "Means of acquisition" refers to methods or devices for collecting medical data via APIs, file uploads, etc.
[0245] A "personally identifiable element" is information that can be used to identify a specific individual, such as name, address, or date of birth.
[0246] "Anonymization means" refers to methods or technologies that convert personally identifiable information into random identifiers and anonymize data in accordance with the Personal Information Protection Act.
[0247] "Means of verification" refers to methods or techniques for verifying whether anonymized information meets predetermined standards.
[0248] "Secure storage means" refers to methods and technologies for safely storing anonymized data using encryption technology, strict access control, etc.
[0249] "Systematic organization means" refers to methods and technologies for normalizing and indexing the received anonymized medical data so that it can be easily searched and viewed.
[0250] A "search and browsing interface" is a user interface provided for users to search and browse anonymized medical information.
[0251] "Means for calculating and allocating rewards" means methods or technologies for automatically calculating and allocating rewards to data providers based on data usage.
[0252] "Means for real-time anonymization and secure processing of patient data using smart glasses" refers to methods and technologies for instantly anonymizing and securely processing patient data collected in medical settings using smart glasses.
[0253] The system embodying the present invention is designed to safely anonymize medical information and promote its use. This system is specifically realized by the following program.
[0254] The program's main components are a server, a device, and smart glasses. The server retrieves patient data from medical institutions and pharmacies via API or file upload. After retrieving the data, the server uses a natural language processing algorithm to identify personally identifiable information (such as name, address, and date of birth). The server then de-identifies the identified personal information by converting it into a random identifier and obscuring certain date information. The de-identified data is then verified to see if it meets predetermined criteria, and if so, stored in a secure database.
[0255] Furthermore, the anonymized medical information is systematically organized by the server. This organized data is normalized and indexed to facilitate search and viewing. Users can use an interface to search and view the anonymized medical information using their devices. Through this interface, users can quickly access the information they need by setting search conditions. When the data is used, the server calculates rewards based on the data usage and automatically distributes the rewards to the data provider.
[0256] Smart glasses are used in medical settings to anonymize and securely process patient data in real time. Doctors and medical staff wearing the smart glasses can process patient medical records in real time. A specific use case is to read patient data through the smart glasses, anonymize the information displayed on the screen in real time, and process it as securely shareable data. For example, a doctor at a hospital can use the smart glasses to read a patient's medical record information and share the data while protecting private information.
[0257] An example of a prompt is:
[0258] "I want to collect medical data from an API endpoint and identify and anonymize personal information in the returned data. Specifically, I want you to write a Python program that will replace names and addresses with "anonymous" and convert birthdates to "xxxx-xx-xx."
[0259] The above is a detailed embodiment of the present invention. This system realizes real-time anonymization of medical information, safe processing, and efficient data utilization.
[0260] The flow of the specific processing in the application example 1 will be described with reference to FIG.
[0261] Step 1:
[0262] The server retrieves patient data from medical institutions and pharmacies via API endpoints or file uploads. The inputs are the API endpoint URL and the uploaded file, and the output is the raw data stored on the server. Specifically, the server sends a request to the specified API endpoint and stores the returned data in secure storage.
[0263] Step 2:
[0264] The server uses a natural language processing algorithm to identify personally identifiable elements (such as name, address, and date of birth) from the acquired medical data. The input is raw data, and the output is a list of personally identifiable elements. Specifically, the server uses text analysis and pattern matching to extract personal information from the raw data and saves the identified elements in list format.
[0265] Step 3:
[0266] The server anonymizes the identified personal information in accordance with the Personal Information Protection Act. For example, it replaces names and addresses with random identifiers and blurs birthdays to a range. The input is a list of identified elements, and the output is anonymized data. Specifically, the server converts names and addresses to "anonymous" and birthdays to "xxxx-xx-xx."
[0267] Step 4:
[0268] The server verifies whether the anonymized information meets predetermined criteria. The input is the anonymized data, and the output is the verification result of whether the criteria are met. Specifically, the server performs an automatic check based on the anonymization guidelines, and if the criteria are not met, it performs additional anonymization processing.
[0269] Step 5:
[0270] The server stores the verified anonymized data in a secure database. The input is the verified anonymized data, and the output is the data stored in the database. Specifically, the server stores the data using encryption technology and strict access control.
[0271] Step 6:
[0272] The server receives and systematically organizes de-identified medical information. The input is existing de-identified data, and the output is organized data. Specifically, the server normalizes and indexes the data, converting it into a format that is easy to search and browse.
[0273] Step 7:
[0274] The device provides an interface that allows users to search and view anonymized medical information. The input is the user's search criteria, and the output is the search results displayed to the user. Specifically, the device accepts search criteria through the user interface, sends a query to the server, and retrieves and displays related information.
[0275] Step 8:
[0276] The server calculates rewards based on data usage and distributes them to data providers. The input is a data usage log, and the output is a reward calculation result. Specifically, the server analyzes the access log, calculates reward amounts based on the data used, and distributes them to each information provider.
[0277] Step 9:
[0278] Smart glasses are used to anonymize and securely process patient data in real time in medical settings. The input is the patient's medical record and treatment information, and the output is anonymized real-time data. Specifically, the smart glasses read the patient data, display personal information on the screen in an anonymized form, and convert the data into a format that can be safely shared when actually used.
[0279] Furthermore, an emotion engine that estimates the user's emotion may be combined. That is, the identification processing unit 290 may estimate the user's emotion using the emotion identification model 59 and perform identification processing using the user's emotion.
[0280] MODE FOR CARRYING OUT THE INVENTION
[0281] This paper describes a system that safely anonymizes medical information and promotes its use, and combines it with an emotion engine that recognizes user emotions. This system is broadly composed of an AI tool for anonymizing medical information, an AI tool for collecting, viewing, and consulting, and an emotion engine.
[0282] AI tool for anonymizing medical information
[0283] Data collection
[0284] The server receives patient data (medical record information and medication information) from medical institutions and pharmacies via API or file upload. When receiving the data, it checks whether the data format is consistent and performs preprocessing as necessary to standardize the format.
[0285] Personal Information Identification
[0286] The server automatically identifies personally identifiable information (such as name, address, and date of birth) from the received patient data using natural language processing algorithms, employing text analysis and pattern matching techniques, and then lists the results.
[0287] Data Conversion
[0288] The server then anonymizes the identified personal information, specifically converting names and addresses into random identifiers and blurring birthdates and specific date data into ranges or general formats in accordance with the Personal Information Protection Act.
[0289] Data Check
[0290] The server verifies whether the converted data meets various standards, and if it does not meet certain anonymity standards, it performs additional anonymization processing.
[0291] Data storage
[0292] The server then stores the verified anonymized data in a secure database, where access control permissions are set and the data is protected using encryption technology.
[0293] AI tool for collection, viewing, and consultation
[0294] Data reception
[0295] The server receives the anonymized data provided by the medical information anonymization AI tool, and upon receiving it performs a data integrity check to ensure there are no missing or incorrect data.
[0296] Data organization
[0297] The server systematically organizes the received anonymized data, normalizing and indexing it to make it easier to search and view, thereby enabling efficient data management.
[0298] Providing search and browsing functionality
[0299] The terminal (user device) provides an interface that allows users to search and view anonymized medical information. Users can enter keywords and set conditions to search data.
[0300] Reward Allocation
[0301] The server automatically calculates and distributes rewards to data providers according to the user's data usage. This involves analyzing the data access log and calculating the reward amount for each information provider.
[0302] Adding an Emotion Engine
[0303] emotion recognition
[0304] The device will activate an emotion engine through user input and operations to recognize the user's emotional state, possibly using algorithms that extract emotions from text nuances or voice data.
[0305] Customize search results based on sentiment
[0306] The server customizes search results based on the user's emotions as recognized by the emotion engine. For example, if the user is feeling stressed, data related to stress reduction will be displayed preferentially.
[0307] Providing emotional feedback
[0308] The device provides appropriate feedback based on the user's emotions. For example, if the user is feeling anxious, the device provides an interface offering support and additional information.
[0309] Specific examples
[0310] Collection and anonymization of patient data from medical institutions
[0311] The server receives patient data from a medical institution via API, including medical records and medication information.
[0312] The server analyzes the received data and uses natural language processing to identify personally identifiable information such as name, address, and date of birth.
[0313] The server converts names to random identification IDs, blurs addresses to the region level, and converts birthdates to years.
[0314] The server automatically checks whether the anonymization has been performed properly, and if there are any defects, it performs the anonymization process again.
[0315] The server then encrypts the anonymized data after checking and stores it in a secure database.
[0316] When pharmaceutical companies use anonymized data
[0317] Users (researchers at pharmaceutical companies) access the server using their own terminals.
[0318] The terminal provides a search interface to the user, allowing the user to input keywords to search for data relating to a particular disease.
[0319] The server quickly extracts data that matches the search criteria from the indexed, anonymized database.
[0320] The terminal displays the search results to the user, allowing the user to view the details.
[0321] The server analyzes the user's data usage log and distributes appropriate rewards to the data providers.
[0322] Use of emotion engine
[0323] While the user (a pharmaceutical company researcher) is using the data, the emotion engine detects the user's anxiety.
[0324] The server customizes search results based on the output of the emotion engine, prioritizing the display of data that may reduce anxiety.
[0325] Based on feedback from the emotion engine, the device provides support and additional information to the user, providing information to reduce anxiety.
[0326] Through the above steps, the present invention realizes anonymization and efficient use of medical information, and furthermore, by customizing search results taking into account the user's emotions, more personalized data utilization becomes possible.
[0327] The processing flow will be explained below.
[0328] AI tool for anonymizing medical information
[0329] Processing steps from data collection to anonymization
[0330] Step 1:
[0331] The server receives patient data (medical record information and medication information) from medical institutions and pharmacies via API or file upload. When receiving the data, it checks whether the data format is appropriate, preprocesses it as necessary, and standardizes the format.
[0332] Step 2:
[0333] The server automatically identifies personally identifiable information (such as name, address, and date of birth) from the received patient data using natural language processing algorithms, and then uses text analysis techniques to extract and compile this information into a list.
[0334] Step 3:
[0335] The server will anonymize the identified personal information by converting names and addresses into random identifiers (e.g., UUIDs) and converting birthdates and specific date data into ranges or years.
[0336] Step 4:
[0337] The server automatically verifies whether the anonymized data meets the standards of the Personal Information Protection Act, and if the anonymity is insufficient, it performs additional anonymization processing.
[0338] Step 5:
[0339] The server stores the verified and anonymized data in a secure database, which uses strict access controls and encryption technology to protect the data.
[0340] AI tool for collection, viewing, and consultation
[0341] Processing steps from receiving data to allocating rewards
[0342] Step 1:
[0343] The server receives the anonymized data provided by the medical information anonymization AI tool, and checks the data integrity upon receipt to ensure there are no missing or incorrect data.
[0344] Step 2:
[0345] The server normalizes the received anonymously processed data and indexes it for easy searching and browsing. It organizes each field into categories to achieve efficient data management.
[0346] Step 3:
[0347] The terminal (user device) provides an interface for users to search and view anonymized medical information. Users input keywords, set search conditions, search data, and obtain results.
[0348] Step 4:
[0349] The server quickly extracts anonymized data that matches the user's search criteria and displays it as a search result.
[0350] Step 5:
[0351] The server analyzes the user's data usage log and automatically calculates and distributes rewards to the data provider. The server calculates the reward amount based on the access log and distributes the reward to the specified account.
[0352] Use of emotion engine
[0353] Processing steps from emotion recognition to providing feedback
[0354] Step 1:
[0355] The device activates an emotion engine through user input and operations to recognize the user's emotional state, using algorithms that extract emotions from text nuances and voice data.
[0356] Step 2:
[0357] The server customizes search results based on the user's emotions as recognized by the emotion engine. For example, if the user is feeling stressed, data related to stress reduction will be displayed preferentially.
[0358] Step 3:
[0359] The device provides feedback based on the user's emotions based on the output of the emotion engine. For example, if the user is feeling anxious, the device provides an interface that presents appropriate support and additional information.
[0360] Specific examples
[0361] Collection and anonymization of patient data from medical institutions
[0362] Step 1:
[0363] The server receives patient data from medical institutions via API, including medical records and medication information.
[0364] Step 2:
[0365] The server analyzes the received data and uses natural language processing algorithms to identify personally identifiable information such as name, address, and date of birth, compiling them into a list.
[0366] Step 3:
[0367] The server converts the identified personal information into a random identification ID, blurs addresses to the region level, and converts birthdates to years.
[0368] Step 4:
[0369] The server automatically checks whether the anonymized data meets the standards for protecting personal information. If there are any deficiencies, the data is anonymized again.
[0370] Step 5:
[0371] Once the checks are complete, the server encrypts and stores the anonymized data in a secure database.
[0372] When pharmaceutical companies use anonymized data
[0373] Step 1:
[0374] Users (researchers at pharmaceutical companies) access the server using their own terminals.
[0375] Step 2:
[0376] The terminal provides a search interface to the user, allowing the user to input keywords to search for data relating to a particular disease.
[0377] Step 3:
[0378] The server quickly extracts data that matches the search criteria from the indexed, anonymized database.
[0379] Step 4:
[0380] The terminal displays the search results to the user, allowing the user to view the details.
[0381] Step 5:
[0382] The server analyzes the user's data usage log and distributes appropriate rewards to the data providers.
[0383] Use of emotion engine
[0384] Step 1:
[0385] While the user (a pharmaceutical company researcher) is using the data, the emotion engine detects the user's anxiety.
[0386] Step 2:
[0387] The server customizes search results based on the output of the emotion engine, prioritizing the display of data that may reduce anxiety.
[0388] Step 3:
[0389] Based on feedback from the emotion engine, the device provides the user with appropriate support and additional information to reduce anxiety.
[0390] Through the above steps, the present invention realizes anonymization and efficient use of medical information, and furthermore, by customizing search results taking into account the user's emotions, more personalized data utilization becomes possible.
[0391] Example 2
[0392] Next, a description will be given of Example 2. In the following description, the data processing device 12 will be referred to as a "server" and the smart device 14 will be referred to as a "terminal."
[0393] The importance of protecting personal information is increasing in modern medical information management. However, systems that safely anonymize medical data and promote its use are not widely available. Furthermore, the user experience is not fully satisfactory because there is no feedback or customized search results that take into account the user's emotional state when using the data. Therefore, a system that safely anonymizes medical data and provides information based on the user's emotional state is needed.
[0394] The identification process by the identification processing unit 290 of the data processing device 12 in the second embodiment is realized by the following means. In this invention, the server includes a means for acquiring medical information, a means for identifying elements that can identify an individual from the acquired medical information, and a means for anonymizing the identified elements in accordance with the Personal Information Protection Act. This makes it possible to safely anonymize medical information and provide information according to the user's emotional state.
[0395] "Medical information" refers to medical data such as patient medical records, prescription information, and test results.
[0396] "Anonymization" refers to the process of removing or transforming personally identifiable information so that the data provider cannot be identified.
[0397] "Natural language processing algorithms" refer to computational methods and technologies for automatically parsing, understanding, and generating human language.
[0398] "Anonymized Data" means data that has been made anonymous by removing or transforming personal information.
[0399] "Emotional state" refers to a psychological state that is determined based on a user's actions or inputs.
[0400] "Feedback" refers to the information or actions that a system provides in response to a user's behavior or state.
[0401] "Interface" refers to the screens and functions that allow users to interact with the system.
[0402] "Reward calculation" refers to the process of calculating rewards to data providers in accordance with the user's use of data.
[0403] "Access log" refers to data that records the history of users accessing a system.
[0404] A "database" refers to a system that stores information in an organized manner and makes it easy to search and manage.
[0405] "Random identifier" refers to a unique identification code that is randomly generated so as not to identify personal information.
[0406] This invention describes a system that safely anonymizes medical information and promotes its use, as well as a system that combines an emotion engine that recognizes user emotions. The detailed configuration and operation of this system are described below.
[0407] AI tool for anonymizing medical information
[0408] The AI tool for anonymizing medical information in this system runs on a server, primarily to perform the following processes:
[0409] 1. Data Collection:
[0410] The server receives patient data (medical record information and medication information) from medical institutions and pharmacies via API or file upload. For example, it obtains JSON format data from a medical institution's system, checks the integrity of the data upon reception, preprocesses it, and standardizes it into a standard format.
[0411] 2. Personal Information Identification:
[0412] The server uses natural language processing algorithms to automatically identify personally identifiable information (such as name, address, and date of birth) from the received data, and then uses text analysis and pattern matching techniques to extract and list personal information.
[0413] 3. Data conversion:
[0414] The server then anonymizes the identified personal information. Specifically, it converts names and addresses into random IDs and blurs birthdays to years. This ensures that the data is securely anonymized.
[0415] 4. Data Check:
[0416] The server verifies whether the converted data meets the anonymity criteria, and if not, performs additional anonymization processing.
[0417] 5. Data Retention:
[0418] The server then stores the verified anonymized data in a secure database, where access control permissions are set and the data is protected using encryption technology.
[0419] AI tool for collection, viewing, and consultation
[0420] This tool is designed to efficiently utilize anonymized medical data and performs the following processes:
[0421] 1. Data reception:
[0422] The server receives the anonymized data provided by the medical information anonymization AI tool and performs a consistency check to ensure there are no missing or incorrect data.
[0423] 2. Data reduction:
[0424] The server normalizes the anonymized data it receives and indexes it for easy searching and browsing.
[0425] 3. Providing search and browsing functionality:
[0426] The terminal (user device) provides an interface for searching and viewing anonymized medical information. Users can search for data by entering keywords or conditions.
[0427] 4. Reward Allocation:
[0428] The server calculates and automatically distributes rewards to data providers based on the user's data usage. It analyzes access logs and calculates reward amounts based on factors such as frequency of usage.
[0429] Adding an Emotion Engine
[0430] This system is integrated with an emotion engine that can recognize user emotions. The operation is shown below.
[0431] 1. Emotion recognition:
[0432] The device activates an emotion engine through user input and operations to recognize the user's emotional state, using algorithms that extract emotions from text nuances and voice data.
[0433] 2. Personalize search results based on sentiment:
[0434] The server customizes search results based on the user's emotions as recognized by the emotion engine. For example, if the user is feeling stressed, data related to stress reduction will be displayed preferentially.
[0435] 3. Providing emotional feedback:
[0436] The device provides appropriate feedback based on the user's emotions, for example, suggesting support information or additional resources if the user is feeling anxious.
[0437] Specific examples
[0438] Collection and anonymization of patient data from medical institutions
[0439] The server receives patient data from medical institutions via API, including medical records and medication information.
[0440] The server analyzes the received data and uses natural language processing to identify personally identifiable information such as name, address, and date of birth.
[0441] The server converts names to random identification IDs, blurs addresses to the region level, and converts birthdates to years.
[0442] The server automatically checks whether the anonymization has been performed properly, and if there are any deficiencies, performs the anonymization process again.
[0443] The server then encrypts the anonymized data after checking and stores it in a secure database.
[0444] When pharmaceutical companies use anonymized data
[0445] Users (researchers at pharmaceutical companies) access the server using their own terminals.
[0446] The terminal provides a search interface to the user, allowing the user to input keywords to search for data relating to a particular disease.
[0447] The server quickly extracts data that matches the search criteria from the indexed, anonymized database.
[0448] The terminal displays the search results to the user, allowing the user to view the details.
[0449] The server analyzes the user's data usage log and distributes appropriate rewards to the data providers.
[0450] Use of emotion engine
[0451] While the user (a pharmaceutical company researcher) is using the data, the emotion engine detects the user's anxiety.
[0452] The server customizes search results based on the output of the emotion engine, prioritizing the display of data that may reduce anxiety.
[0453] Based on feedback from the emotion engine, the device provides support and additional information to the user, providing information to reduce anxiety.
[0454] Example prompts to be input to the generative AI model
[0455] 1. Please explain the AI tool for anonymizing medical information.
[0456] 2. What are the specific steps to de-identify certain medical data?
[0457] 3. Please elaborate on how you use the sentiment engine to customize search results.
[0458] Through the above steps, the present invention realizes anonymization and efficient use of medical information, and furthermore, by customizing search results taking into account the user's emotions, more personalized data utilization becomes possible.
[0459] The flow of the identification process in the second embodiment will be described with reference to FIG.
[0460] AI tool for anonymizing medical information
[0461] Step 1:
[0462] The server receives patient data (medical record information and medication information) from medical institutions and pharmacies via API or file upload. It checks the format of the received data and performs preprocessing as necessary to unify the format.
[0463] Input: Patient data from a medical institution (e.g., JSON file)
[0464] Output: Patient data in a unified format
[0465] Specific operation: Check the format of the received data (for example, date format or name notation) and normalize and unify it.
[0466] Step 2:
[0467] The server uses natural language processing algorithms to automatically identify personally identifiable information (such as name, address, date of birth, etc.) from the received data.
[0468] Input: Patient data in a unified format
[0469] Output: Data listing personally identifiable information
[0470] Specific operation: Extracts names, addresses, and birthdays using regular expressions and text analysis, and saves them in list format.
[0471] Step 3:
[0472] The server anonymizes the identified personal information, converting names and addresses to random identifiers and blurring birth dates to years.
[0473] Input: Data listing personally identifiable information
[0474] Output: Anonymized data
[0475] Specific behavior: Converts names to random IDs, addresses to city level, and birthdays to year level. For example, converts "Tanaka Ichiro" to "User ID 12345."
[0476] Step 4:
[0477] The server verifies whether the converted data meets the anonymity criteria, and if it does not, it anonymizes the data again.
[0478] Input: Anonymized data
[0479] Output: Verified and anonymized data
[0480] What it does: Compare the results of the anonymization algorithm against a checklist and reprocess any gaps or deficiencies.
[0481] Step 5:
[0482] The server stores the verified and anonymized data in a secure database, with access control permissions and encryption technology to protect the data.
[0483] Input: Verified, anonymized data
[0484] Output: Securely stored data
[0485] What it does: Encrypts data using AES-256 encryption technology and stores it in a database with access controls.
[0486] AI tool for collection, viewing, and consultation
[0487] Step 1:
[0488] The server receives the anonymized data provided by the medical information anonymization AI tool and performs a consistency check to ensure there are no missing or incorrect data.
[0489] Input: Anonymously processed data
[0490] Output: Integrity checked data
[0491] What it does: Validates data integrity, checks for missing data and inconsistencies, and corrects them as needed.
[0492] Step 2:
[0493] The server normalizes the anonymized data it receives and indexes it for easy searching and browsing.
[0494] Input: Data that has been checked for consistency
[0495] Output: Normalized and indexed data
[0496] What it does: Normalizes database fields and performs indexing to facilitate keyword and criteria searches.
[0497] Step 3:
[0498] The device provides an interface for searching and viewing anonymized medical information.
[0499] Input: Keywords and conditions from the user
[0500] Output: Search results
[0501] What it does: Provides an interface that allows users to enter keywords in a search box, set conditions, and search for data.
[0502] Step 4:
[0503] The server calculates and automatically distributes rewards to data providers based on the user's data usage.
[0504] Input: User access log
[0505] Output: Reward calculation results, reward distribution information
[0506] Specific operation: Analyzes access logs, calculates reward amounts based on frequency of use and importance of data, and automatically distributes them to each provider.
[0507] Adding an Emotion Engine
[0508] Step 1:
[0509] The terminal activates an emotion engine through user input and operations to recognize the user's emotional state.
[0510] Input: User input and operation data
[0511] Output: Perceived emotional state
[0512] What it does: Analyzes user input text and voice data and applies algorithms to extract emotions.
[0513] Step 2:
[0514] The server customizes search results based on the user's emotions recognized by the emotion engine.
[0515] Input: Recognized emotional state, user search criteria
[0516] Output: Customized search results
[0517] What it does: It applies a customization algorithm based on your emotional state to prioritize relevant search results.
[0518] Step 3:
[0519] The terminal provides appropriate feedback based on the user's emotions.
[0520] Input: Perceived emotional state
[0521] Output: A feedback message to the user.
[0522] What it does: If the user is feeling anxious, provide an interface that suggests support information or additional resources.
[0523] (Application example 2)
[0524] Next, a description will be given of Application Example 2. In the following description, the data processing device 12 will be referred to as a "server" and the smart device 14 will be referred to as a "terminal."
[0525] In addition to anonymizing and securely storing medical information and making it easier to search and view, flexible feedback and electronic payment functions that take into account the user's emotions when using the data are required. In particular, it is a challenge to alleviate users' anxiety and provide a reassuring environment by enabling anonymous settlement of medical expenses and providing customized information based on the user's emotional state during use.
[0526] The identification process by the identification processing unit 290 of the data processing device 12 in Application Example 2 is realized by the following means. In this invention, the server includes means for acquiring medical information, means for identifying elements that can identify an individual from the acquired medical information, means for anonymizing the identified elements in accordance with the Personal Information Protection Act, means for verifying whether the anonymized information meets predetermined criteria, means for securely storing the anonymized information, means for receiving and systematically organizing the anonymized medical information, means for providing an interface for searching and viewing the organized medical information, means for calculating rewards based on data usage and allocating them to data providers, means for making payments based on the anonymized medical information, and means for activating an emotion engine that recognizes the user's emotional state and customizing search results. This enables anonymous settlement of medical expenses and provides information customized to the user's emotional state.
[0527] "Medical information" refers to patient medical records, medication information, and health status data.
[0528] "Personally identifiable information" refers to information that can identify a specific individual, such as name, address, or date of birth.
[0529] "Anonymizing" refers to the act of removing or converting personally identifiable information so that it is no longer possible to identify a specific individual.
[0530] "Verify" refers to the act of checking whether anonymized information meets specified standards.
[0531] "Storing" refers to the act of recording information in a certain place so that it will not be lost.
[0532] "Systematically organizing" refers to the act of classifying and arranging information according to certain rules so that it can be managed and used efficiently.
[0533] "Interface" refers to the screens and operating means through which users interact with the system.
[0534] "Calculating and allocating rewards" refers to the act of calculating the amount of rewards based on the use of data and distributing the rewards to appropriate providers.
[0535] "Making a payment" refers to the act of carrying out a transaction to pay for goods or services.
[0536] "Recognizing emotional state" refers to the act of the system detecting and judging the user's emotions (e.g., anxiety, relief, stress, etc.).
[0537] An "emotion engine" refers to a software component for analyzing emotions through user input and operations.
[0538] "Customize" refers to the act of changing or adjusting content or presentation to suit specific conditions or circumstances.
[0539] MODE FOR CARRYING OUT THE INVENTION
[0540] The system according to the present invention is configured as follows, and the specific implementation thereof will be described in detail below.
[0541] 1. System Program
[0542] overview
[0543] This system not only anonymizes medical information and securely stores and uses it, but also recognizes users' emotions to provide customized information.It also enables secure electronic payments using anonymized medical information.
[0544] 2. Explanation of program processing
[0545] Required Hardware and Software
[0546] Hardware:
[0547] Servers (e.g., high-performance computing servers)
[0548] User device (e.g., smartphone)
[0549] software:
[0550] Natural language processing engines (e.g. BERT)
[0551] Database management systems (e.g. MongoDB)
[0552] Encryption technology (e.g. AES encryption)
[0553] Emotion recognition algorithms (e.g., Sentiment Analysis API)
[0554] Acquisition and de-identification of medical information
[0555] The server receives patient data from healthcare providers via API. It uses a natural language processing engine to identify personally identifiable information and converts it into a random identifier. It also obscures certain dates and medical history information. The anonymized data is then securely stored in a database using AES encryption.
[0556] Search and browse anonymized data
[0557] Users access the server using their smartphones to search for anonymized medical data. The server indexes the received anonymized data and organizes it into a searchable and viewable format. Users can search for data by entering keywords, and the search results are displayed on the interface.
[0558] Use of emotion engine
[0559] When a user searches or browses data, an emotion recognition algorithm installed on the smartphone analyzes the user's emotions. If the emotion engine detects anxiety or stress, the server will provide customized search results corresponding to that emotion. For example, it will display support information to reduce anxiety or reassuring messages.
[0560] Making electronic payments
[0561] Medical expenses can be paid safely and anonymously based on anonymized medical data. Users complete the payment procedure using their smartphone, and the information is securely processed by the server.
[0562] 3. Specific Examples
[0563] Medical expense settlement scenario
[0564] After a user receives medical treatment at a medical institution, the medical expenses are settled using anonymized data via a smartphone app.
[0565] The server uses natural language processing to identify and anonymize personal information from the received billing data.
[0566] Electronic payments are made using anonymized information, which is then stored using AES encryption technology.
[0567] Feedback scenario using emotion recognition
[0568] The emotion engine detects anxiety while users are browsing medical information on their smartphones.
[0569] The server prioritizes displaying medical and support information to address anxiety, increasing the user's sense of security.
[0570] 4. Examples of prompts
[0571] Please explain the process by which users receive medical billing data from medical institutions via a smartphone app, securely settle bills, and how the anonymized medical data will be used afterwards. Please also include a function to analyze user sentiment and provide support information.
[0572] This system enables anonymization, secure storage, search and viewing of medical information, as well as customized information provision according to emotional state and secure electronic payment.
[0573] The flow of the specific processing in the application example 2 will be described with reference to FIG.
[0574] Step 1:
[0575] The server receives patient data from medical institutions via API. The received data includes medical records and medication information. The server checks whether the format of the received data is standardized, and performs preprocessing as necessary to standardize the data format. The input at this stage is patient data from medical institutions, and the output is data in a standardized format.
[0576] Step 2:
[0577] The server uses a natural language processing engine to identify personally identifiable elements (such as name, address, and date of birth) from the received data. Specifically, it uses text analysis and pattern matching techniques to create a list of these elements. The input to this stage is data in a standardized format, and the output is a list containing personally identifiable elements.
[0578] Step 3:
[0579] The server anonymizes the identified personally identifiable information by converting names and addresses into random identifiers and obscuring certain dates and medical history information. The input to this stage is a list of personally identifiable information, and the output is anonymized data.
[0580] Step 4:
[0581] The server verifies whether the anonymized information meets the predetermined criteria. If it does not meet the certain anonymity criteria, it performs additional anonymization processing. The input of this stage is the anonymized data, and the output is the verified anonymized data.
[0582] Step 5:
[0583] The server securely stores the anonymized data in a database using AES encryption. Database access control permissions are set during storage to enhance data protection. The input to this stage is the verified anonymized data, and the output is a database containing the encrypted data.
[0584] Step 6:
[0585] Users access the server using their smartphones to search for anonymized medical data. The device provides a search interface where users input keywords and conditions. The input at this stage is the user's search query, and the output is the search conditions sent to the server.
[0586] Step 7:
[0587] The server compares the indexed anonymized database based on the received search query and generates search results. The input at this stage is the user's search criteria, and the output is the search results that match the criteria.
[0588] Step 8:
[0589] The user's terminal displays the search results, allowing the user to view the data. The input at this stage is the search results sent from the server, and the output is a screen displaying the search results.
[0590] Step 9:
[0591] While the user is searching or browsing data, the device uses emotion recognition algorithms to analyze the user's emotional state. For example, emotions can be extracted from text nuances or voice data. The input at this stage is the user's operation data or input text, and the output is data indicating the user's emotional state.
[0592] Step 10:
[0593] The server customizes search results based on the user's emotions recognized by the emotion engine. For example, if the user is feeling anxious, support information that will alleviate the anxiety will be displayed preferentially. The input of this stage is the user's emotional data, and the output is customized search results.
[0594] Step 11:
[0595] The user's device displays customized search results and feedback, and provides appropriate support information to the user. Specifically, reassuring messages and notifications are displayed. The input of this stage is the customized search results and feedback information, and the output is the customized information displayed to the user.
[0596] Step 12:
[0597] Users use a smartphone app to make payments based on anonymized medical data. The server securely processes the payment data while maintaining its anonymity and stores it using AES encryption technology. The input at this stage is the user's payment information, and the output is securely processed payment completion data.
[0598] The specific processing unit 290 transmits the result of the specific processing to the smart device 14. In the smart device 14, the control unit 46A causes the output device 40 to output the result of the specific processing. The microphone 38B acquires audio indicating a user input regarding the result of the specific processing. The control unit 46A transmits audio data indicating the user input acquired by the microphone 38B to the data processing device 12. In the data processing device 12, the specific processing unit 290 acquires the audio data.
[0599] The data generation model 58 is a so-called generative AI (Artificial Intelligence). An example of the data generation model 58 is ChatGPT (Internet Search<URL: https: / / openai.com / blog / chatgpt> ), Gemini (Internet search <url: https: gemini.google.com ?hl="ja">) and other generation AIs. The data generation model 58 is obtained by performing deep learning on a neural network. A prompt including an instruction is input to the data generation model 58, and inference data such as voice data indicating voice, text data indicating text, and image data indicating an image is also input. The data generation model 58 performs inference on the input inference data in accordance with the instruction indicated by the prompt, and outputs the inference result in a data format such as voice data and text data. Here, inference refers to, for example, analysis, classification, prediction, and / or summarization.
[0600] In the above embodiment, an example in which the specific process is performed by the data processing device 12 has been given, but the technology of the present disclosure is not limited to this, and the specific process may be performed by the smart device 14.
[0601] [Second embodiment]
[0602] FIG. 3 shows an example of the configuration of a data processing system 210 according to the second embodiment.
[0603] 3, the data processing system 210 includes the data processing device 12 and smart glasses 214. An example of the data processing device 12 is a server.
[0604] The data processing device 12 includes a computer 22, a database 24, and a communication I / F 26. The computer 22 is an example of a "computer" according to the technology of the present disclosure. The computer 22 includes a processor 28, a RAM 30, and a storage 32. The processor 28, the RAM 30, and the storage 32 are connected to a bus 34. The database 24 and the communication I / F 26 are also connected to the bus 34. The communication I / F 26 is connected to a network 54. Examples of the network 54 include a WAN (Wide Area Network) and / or a LAN (Local Area Network).
[0605] The smart glasses 214 include a computer 36, a microphone 238, a speaker 240, a camera 42, and a communication I / F 44. The computer 36 includes a processor 46, a RAM 48, and a storage 50. The processor 46, the RAM 48, and the storage 50 are connected to a bus 52. The microphone 238, the speaker 240, and the camera 42 are also connected to the bus 52.
[0606] The microphone 238 receives instructions and the like from the user 20 by receiving voice uttered by the user 20. The microphone 238 captures the voice uttered by the user 20, converts the captured voice into audio data, and outputs it to the processor 46. The speaker 240 outputs audio in accordance with instructions from the processor 46.
[0607] Camera 42 is a small digital camera equipped with an optical system including a lens, aperture, and shutter, and an imaging element such as a CMOS (Complementary Metal-Oxide-Semiconductor) image sensor or a CCD (Charge Coupled Device) image sensor, and captures images of the surroundings of user 20 (for example, an imaging range defined by an angle of view equivalent to the field of vision of a typical healthy person).
[0608] The communication I / F 44 is connected to a network 54. The communication I / Fs 44 and 26 are responsible for the exchange of various information between the processor 46 and the processor 28 via the network 54. The exchange of various information between the processor 46 and the processor 28 using the communication I / Fs 44 and 26 is carried out in a secure state.
[0609] Fig. 4 shows an example of the main functions of the data processing device 12 and the smart glasses 214. As shown in Fig. 4, in the data processing device 12, a specific process is performed by the processor 28. A specific process program 56 is stored in the storage 32.
[0610] The specific processing program 56 is an example of a "program" according to the technology of the present disclosure. The processor 28 reads the specific processing program 56 from the storage 32 and executes the read specific processing program 56 on the RAM 30. The specific processing is realized by the processor 28 operating as a specific processing unit 290 in accordance with the specific processing program 56 executed on the RAM 30.
[0611] The storage 32 stores a data generation model 58 and an emotion identification model 59. The data generation model 58 and the emotion identification model 59 are used by the identification processing unit 290.
[0612] In the smart glasses 214, the processor 46 performs the reception output process. A reception output program 60 is stored in the storage 50. The processor 46 reads the reception output program 60 from the storage 50 and executes the read reception output program 60 on the RAM 48. The reception output process is realized by the processor 46 operating as the control unit 46A in accordance with the reception output program 60 executed on the RAM 48.
[0613] Next, a description will be given of the identification process performed by the identification processing unit 290 of the data processing device 12. In the following description, the data processing device 12 will be referred to as the "server" and the smart glasses 214 will be referred to as the "terminal."
[0614] MODE FOR CARRYING OUT THE INVENTION
[0615] This paper describes a system for safely anonymizing medical information and promoting its use. This system is broadly composed of an AI tool for anonymizing medical information and an AI tool for collecting, viewing, and consulting on medical information.
[0616] AI tool for anonymizing medical information
[0617] Data collection
[0618] The server receives patient data (medical records and medication information) in multiple formats from medical institutions and pharmacies. For example, it collects data via API or file upload and stores it in secure storage. If necessary, it performs preprocessing to unify the data format.
[0619] Personal Information Identification
[0620] The server automatically identifies personally identifiable information (such as name, address, date of birth, etc.) from the received data using natural language processing algorithms, using text analysis and pattern matching techniques, and then lists the results.
[0621] Data Conversion
[0622] The server anonymizes identified personal information in a manner compliant with the Personal Information Protection Act, for example, by replacing names and addresses with random identifiers and blurring birthdates and specific date data into ranges or general formats.
[0623] Data Check
[0624] The server verifies whether the converted data meets various standards, and if it does not meet certain anonymity standards, it performs additional anonymization processing.
[0625] Data storage
[0626] The server stores the verified and anonymized data in a secure database, which is protected by strict access controls and encryption technology.
[0627] AI tool for collection, viewing, and consultation
[0628] Data reception
[0629] The server receives the anonymized data provided by the medical information anonymization AI tool and checks the integrity of the data upon receipt.
[0630] Data organization
[0631] The server organizes the received anonymized data in a systematic manner, normalizing and indexing it for easy searching and browsing, thereby making data organization more cohesive and efficient.
[0632] Providing search and browsing functionality
[0633] The terminal (user device) provides an interface that allows users to search and view anonymized medical information. For example, if a user wants to search for information about a certain disease, they enter keywords, set search conditions, and retrieve data.
[0634] Reward Allocation
[0635] The server automatically calculates and distributes rewards to data providers according to the user's data usage. This involves analyzing the data access log and calculating the reward amount for each information provider.
[0636] Example
[0637] Example 1: Collecting and anonymizing patient data from medical institutions
[0638] The server receives patient medical record information from a medical institution using an API.
[0639] The server uses a natural language processing algorithm to identify the name, address, and date of birth from the received data.
[0640] The server converts these personal details into a random identifier and blurs the "birthday" information to a year.
[0641] The server automatically checks whether the anonymized data meets the standards and, if OK, stores it in a secure database.
[0642] Example 2: Pharmaceutical companies search and utilize anonymized data
[0643] Users (researchers at pharmaceutical companies) access the server using their own terminals.
[0644] The terminal provides the user with a search interface, and the user sets search conditions by entering the keyword "diabetes."
[0645] The server retrieves and displays relevant information from an indexed, anonymized database.
[0646] The server calculates and distributes remuneration to the medical institution that provided the data based on the data used.
[0647] Through the above steps, the present invention enables the anonymization and efficient utilization of medical information, and provides a solution for safely handling medical data.
[0648] The processing flow will be explained below.
[0649] AI tool for anonymizing medical information
[0650] Processing steps from data collection to anonymization
[0651] Step 1:
[0652] The server receives patient data from medical institutions and pharmacies via API or file upload. Upon receiving the data, it checks whether the data format is consistent and performs preprocessing as necessary to standardize the format.
[0653] Step 2:
[0654] The server identifies personally identifiable information (such as name, address, and date of birth) from the received patient data by analyzing the text using a natural language processing algorithm and compiling the information into an extracted list.
[0655] Step 3:
[0656] The server anonymizes the identified personal information. Specifically, in accordance with the Personal Information Protection Act, it converts names and addresses into random identifiers (e.g., UUIDs), and converts birthdays and specific dates into ranges or obscured information (e.g., leaving only the year of the date).
[0657] Step 4:
[0658] The server verifies the anonymized data, conducting automated checks to ensure that it meets the standards in terms of anonymity, and if there are any deficiencies, performs additional anonymization processes.
[0659] Step 5:
[0660] The server then stores the verified anonymized data in a secure database, where access control permissions are set and the data is protected using encryption technology.
[0661] AI tool for collection, viewing, and consultation
[0662] Processing steps from receiving data to allocating rewards
[0663] Step 1:
[0664] The server receives the anonymized data provided by the medical information anonymization AI tool, and upon receiving it performs a data integrity check to ensure there are no missing or incorrect data.
[0665] Step 2:
[0666] The server organizes the received anonymously processed data, normalizes the data, and performs indexing to make it easier to search and view, thereby enabling efficient data management.
[0667] Step 3:
[0668] The device provides a user interface for users to search and view anonymized medical information. Users can input keywords and set conditions to search for data.
[0669] Step 4:
[0670] The server displays the anonymized data as a search result and allows the user to view the details.
[0671] Step 5:
[0672] The server calculates and distributes rewards to data providers (medical institutions and pharmacies) based on the user's data usage. It analyzes the data access log and calculates the reward amount based on that.
[0673] Specific examples
[0674] Collection and anonymization of patient data from medical institutions
[0675] Step 1:
[0676] The server receives patient data via API from Medical Institution A. This data includes medical records and medication information.
[0677] Step 2:
[0678] The server analyzes the received data and uses natural language processing to identify personally identifiable information such as name, address, and date of birth.
[0679] Step 3:
[0680] The server converts names to random identification IDs, blurs addresses to the region level, and converts birthdates to years.
[0681] Step 4:
[0682] The server automatically checks whether the anonymization has been performed properly, and if there are any defects, it performs the anonymization process again.
[0683] Step 5:
[0684] The server then encrypts the anonymized data after checking and stores it in a secure database.
[0685] When pharmaceutical companies use anonymized data
[0686] Step 1:
[0687] Users (researchers at pharmaceutical companies) access the server using their own terminals.
[0688] Step 2:
[0689] The terminal provides a search interface to the user, allowing the user to input keywords to search for data relating to a particular disease.
[0690] Step 3:
[0691] The server quickly extracts data that matches the search criteria from the indexed, anonymized database.
[0692] Step 4:
[0693] The terminal displays the search results to the user, allowing the user to view the details.
[0694] Step 5:
[0695] The server analyzes the user's data usage log and distributes appropriate rewards to the data providers.
[0696] Example 1
[0697] Next, a description will be given of Example 1. In the following description, the data processing device 12 will be referred to as a "server" and the smart glasses 214 will be referred to as a "terminal."
[0698] Currently, it is difficult to safely anonymize medical information and use it efficiently. In particular, the process of acquiring medical information, standardizing it into a specific format, identifying personally identifiable elements using natural language processing, and then anonymizing it is complex, and there is no system that appropriately rewards users for using anonymized information. Therefore, while there is a need to simultaneously ensure the safety and usefulness of medical data, current technology does not adequately achieve this.
[0699] The specific processing by the specific processing unit 290 of the data processing device 12 in the first embodiment is realized by the following means.
[0700] In this invention, the server includes means for acquiring medical information, means for identifying elements that can identify an individual from the acquired medical information, means for anonymizing the identified elements in accordance with the Personal Information Protection Act, means for verifying whether the anonymized information meets predetermined standards, means for securely storing the anonymized information, means for receiving and systematically organizing the anonymized medical information, means for providing an interface for searching and viewing the organized medical information, means for calculating rewards based on data usage and distributing them to data providers, means for preprocessing the anonymized medical information, means for standardizing the format of the preprocessed information, means for converting the anonymized information into a random identifier and blurring specific dates to years, and means for verifying the integrity of the anonymized information using a checksum, thereby enabling safe anonymization and efficient use of medical information.
[0701] "Medical information" refers to health-related data recorded and managed by medical institutions and pharmacies, such as patient medical records and medication information.
[0702] "Means of acquisition" refers to the process of receiving information from medical institutions and pharmacies using methods such as APIs or file uploads.
[0703] "Means of identification" refers to techniques that use natural language processing algorithms and pattern matching to extract elements within the data that can identify an individual.
[0704] "Anonymization methods" are techniques that prevent the identification of individuals by replacing personally identifiable elements with random identifiers or blurring date data.
[0705] "Verification measures" are processes for checking whether anonymized information meets predetermined standards.
[0706] "Means for storage" refers to storage systems and security technologies for safely managing anonymized information.
[0707] "Systematization" refers to the process of normalizing incoming medical information and creating an index to make it easier to search and view.
[0708] The "means for providing an interface" refers to a technology that implements a user interface that allows users to search and view medical information.
[0709] The "means for calculating and allocating rewards" is a process for automatically calculating and allocating rewards to data providers based on the usage status of the data.
[0710] The "preprocessing means" refers to a data conversion technique for converting received medical information into a unified format.
[0711] "Format harmonization" is the process of converting medical data provided in different formats into a consistent data format.
[0712] A "random identifier conversion method" is a process that replaces personal information such as name and address with a randomly generated identifier.
[0713] "Year blurring" is the process of converting specific date information into year information to prevent personal identification.
[0714] "Means for verifying using a checksum" refers to a technique for verifying using a checksum to ensure the integrity of data.
[0715] This invention is a system designed to safely anonymize medical information and promote its use. This system consists of two main components: an AI tool for anonymizing medical information and an AI tool for collecting, viewing, and consulting medical information.
[0716] AI tool for anonymizing medical information
[0717] Data collection
[0718] The server receives patient data (medical records and medication information) from medical institutions and pharmacies via API or file upload. After receiving the data, the server stores the information in secure storage (e.g., AWS S3 bucket or Google Cloud Storage). It also performs checksum verification to ensure the integrity of the received data. It also performs preprocessing to convert data provided in different formats into a unified format.
[0719] Examples:
[0720] The server receives patient medical record information from a medical institution using an API.
[0721] The server stores the received medical record information in an AWS S3 bucket and verifies the integrity of the data using a checksum.
[0722] Personal Information Identification
[0723] The server uses natural language processing algorithms (e.g., SpaCy or NLTK) to extract personally identifiable information (e.g., name, address, date of birth) from the data it receives, and also uses pattern matching techniques to identify email addresses and phone numbers within the data.
[0724] Examples:
[0725] The server uses a natural language processing algorithm to extract "name," "address," and "date of birth" from the medical record information.
[0726] Data Conversion
[0727] The server performs anonymization processing in accordance with the Personal Information Protection Act, such as converting identified personal information into a random identifier and blurring birthday information to years.
[0728] Examples:
[0729] The server converts the extracted "name" into a random identifier and blurs the "birthday" to a year.
[0730] Data Check
[0731] The server verifies whether the converted data meets predetermined criteria, and if not, performs additional anonymization processing.
[0732] Examples:
[0733] The server verifies the anonymity of the anonymized data and performs the anonymization process again if the criteria are not met.
[0734] Data storage
[0735] The server stores the verified, anonymized data in a secure database (e.g., AWS RDS, MongoDB Atlas), which is protected by encryption and access controls.
[0736] Examples:
[0737] The server stores anonymized medical record information in AWS RDS and encrypts and controls access to the database.
[0738] AI tool for collection, viewing, and consultation
[0739] Data reception
[0740] The server receives the anonymized data provided by the medical information anonymization AI tool and checks the integrity of the data upon receipt.
[0741] Examples:
[0742] The server receives the data provided by the anonymization AI tool and verifies the integrity of the data using a checksum.
[0743] Data organization
[0744] The server normalizes the received anonymized data and indexes it for efficient search (e.g., using Elasticsearch).
[0745] Examples:
[0746] The server indexes the anonymized data using Elasticsearch and normalizes it into a unified format.
[0747] Providing search and browsing functionality
[0748] The device provides an interface for users to search and view anonymized medical information. Users can enter keywords and set search criteria to retrieve relevant data.
[0749] Examples:
[0750] A user (a researcher at a pharmaceutical company) accesses the server using his or her own terminal, enters the keyword "diabetes," and sets search conditions.
[0751] The terminal provides the user with a search interface and displays search results based on the user's input.
[0752] Reward Allocation
[0753] The server analyzes the access log according to the user's data usage, and calculates and distributes rewards to the data provider.
[0754] Examples:
[0755] The server calculates the amount of compensation to each information provider based on the data used and distributes the compensation to the medical institution that provided the data.
[0756] The above-mentioned method enables safe anonymization and efficient use of medical information, providing a comprehensive solution for using medical data with peace of mind.
[0757] The flow of the identification process in the first embodiment will be described with reference to FIG.
[0758] Step 1: Receiving data
[0759] The server receives patient data from medical institutions and pharmacies via API or file upload. Data is often provided in CSV or JSON format. Data is sent using API requests or FTP servers. API requests or files are given as input, and the received data is saved to storage.
[0760] Specific behavior:
[0761] The server receives medical record information sent by an API request from a medical institution.
[0762] The server stores the received data in an AWS S3 bucket.
[0763] Step 2: Verify data integrity
[0764] The server uses a checksum to verify the integrity of the received data. The received data and checksum information are given as input, and the output is a confirmation of the data integrity.
[0765] Specific behavior:
[0766] The server verifies the checksum of the received medical record information.
[0767] If the server is able to verify the integrity of the data, it proceeds to the next processing step.
[0768] Step 3: Data Preprocessing
[0769] The server performs preprocessing to convert data provided in different formats into a unified format. The received data is given as input, and data in the unified format is obtained as output.
[0770] Specific behavior:
[0771] The server converts the received CSV format medical record information into JSON format.
[0772] The server stores the converted data in temporary storage.
[0773] Step 4: Personal Identification
[0774] The server uses natural language processing algorithms (e.g., SpaCy or NLTK) to extract personally identifiable information from the data (e.g., name, address, date of birth). The preprocessed data is given as input, and personally identifiable information is obtained as output.
[0775] Specific behavior:
[0776] The server uses SpaCy to extract "name," "address," and "date of birth" from the medical record information.
[0777] The server stores the extraction results as a list.
[0778] Step 5: Data Transformation
[0779] The server converts the identified personal information into a random identifier and performs anonymization processing such as blurring birthdate information into years. The extracted personal identification information is given as input, and anonymized data is obtained as output.
[0780] Specific behavior:
[0781] The server converts the extracted "name" into a random identifier and blurs the "birthday" to a year.
[0782] The server stores the anonymized data in temporary storage.
[0783] Step 6: Verify the anonymized data
[0784] The server verifies whether the converted data meets the specified criteria. The anonymized data is given as input, and the verification result indicating whether the criteria are met is obtained as output.
[0785] Specific behavior:
[0786] The server verifies the anonymity of the anonymized data.
[0787] If the criteria are not met, the server performs the anonymization process again.
[0788] Step 7: Save Data
[0789] The server stores the verified anonymized data in a secure database. The input is the verified anonymized data, and the output is the anonymized data stored in the database.
[0790] Specific behavior:
[0791] The server stores the anonymized medical record information in AWS RDS.
[0792] The server enforces encryption and access control on the database.
[0793] Step 8: Data reception and integrity check
[0794] The server receives the anonymized data provided by the medical information anonymization AI tool and performs a consistency check. The anonymized data is given as input, and the consistency check result is obtained as output.
[0795] Specific behavior:
[0796] The server receives the data provided by the medical information anonymization AI tool.
[0797] The server uses the checksum to verify the integrity of the data.
[0798] Step 9: Data organization
[0799] The server normalizes the received anonymized data and indexes it using Elasticsearch. The anonymized data is given as input, and the indexed data is obtained as output.
[0800] Specific behavior:
[0801] The server normalizes the anonymized data and indexes it using Elasticsearch.
[0802] Step 10: Search and Browse Functions
[0803] The terminal provides an interface for users to search and view anonymized medical information. The terminal receives user search criteria as input and displays search results as output.
[0804] Specific behavior:
[0805] A user accesses the server using a terminal and inputs search criteria.
[0806] The terminal provides the user with a search interface and displays search results from the server.
[0807] Step 11: Reward Allocation
[0808] The server analyzes the access log based on the user's data usage, calculates and distributes rewards to data providers, and receives the access log as input and the reward distribution results as output.
[0809] Specific behavior:
[0810] The server calculates the amount of remuneration to each information provider based on the data used.
[0811] The server distributes the calculated remuneration to each medical institution.
[0812] Through the above processing steps, the present invention realizes safe anonymization and efficient use of medical information.
[0813] (Application example 1)
[0814] Next, a description will be given of Application Example 1. In the following description, the data processing device 12 will be referred to as a "server" and the smart glasses 214 will be referred to as a "terminal."
[0815] Medical information is highly confidential, and its handling requires strict privacy measures. However, real-time data acquisition and anonymization are difficult, and secure data handling is not ensured in many settings. Furthermore, there is a lack of interfaces for efficiently searching and viewing anonymized information, hindering progress in data utilization. Furthermore, there is a need for an efficient method for allocating rewards based on data usage.
[0816] The specific processing by the specific processing unit 290 of the data processing device 12 in the application example 1 is realized by the following means.
[0817] In this invention, the server includes means for acquiring medical information, means for identifying elements that can identify individuals from the acquired medical information, means for anonymizing the identified elements in accordance with the Personal Information Protection Act, means for verifying whether the anonymized information meets predetermined standards, means for securely storing the anonymized information, means for receiving and systematically organizing the anonymized medical information, means for providing an interface for searching and viewing the organized medical information, means for calculating rewards based on data usage and allocating them to data providers, and means for anonymizing and securely processing patient data in real time at medical sites using smart glasses, thereby enabling real-time anonymization, secure processing, and efficient utilization of medical information.
[0818] "Medical information" refers to personal medical records and health data held by medical institutions, such as patient charts and medication information.
[0819] "Means of acquisition" refers to methods or devices for collecting medical data via APIs, file uploads, etc.
[0820] A "personally identifiable element" is information that can be used to identify a specific individual, such as name, address, or date of birth.
[0821] "Anonymization means" refers to methods or technologies that convert personally identifiable information into random identifiers and anonymize data in accordance with the Personal Information Protection Act.
[0822] "Means of verification" refers to methods or techniques for verifying whether anonymized information meets predetermined standards.
[0823] "Secure storage means" refers to methods and technologies for safely storing anonymized data using encryption technology, strict access control, etc.
[0824] "Systematic organization means" refers to methods and technologies for normalizing and indexing the received anonymized medical data so that it can be easily searched and viewed.
[0825] A "search and browsing interface" is a user interface provided for users to search and browse anonymized medical information.
[0826] "Means for calculating and allocating rewards" means methods or technologies for automatically calculating and allocating rewards to data providers based on data usage.
[0827] "Means for real-time anonymization and secure processing of patient data using smart glasses" refers to methods and technologies for instantly anonymizing and securely processing patient data collected in medical settings using smart glasses.
[0828] The system embodying the present invention is designed to safely anonymize medical information and promote its use. This system is specifically realized by the following program.
[0829] The program's main components are a server, a device, and smart glasses. The server retrieves patient data from medical institutions and pharmacies via API or file upload. After retrieving the data, the server uses a natural language processing algorithm to identify personally identifiable information (such as name, address, and date of birth). The server then de-identifies the identified personal information by converting it into a random identifier and obscuring certain date information. The de-identified data is then verified to see if it meets predetermined criteria, and if so, stored in a secure database.
[0830] Furthermore, the anonymized medical information is systematically organized by the server. This organized data is normalized and indexed to facilitate search and viewing. Users can use an interface to search and view the anonymized medical information using their devices. Through this interface, users can quickly access the information they need by setting search conditions. When the data is used, the server calculates rewards based on the data usage and automatically distributes the rewards to the data provider.
[0831] Smart glasses are used in medical settings to anonymize and securely process patient data in real time. Doctors and medical staff wearing the smart glasses can process patient medical records in real time. A specific use case is to read patient data through the smart glasses, anonymize the information displayed on the screen in real time, and process it as securely shareable data. For example, a doctor at a hospital can use the smart glasses to read a patient's medical record information and share the data while protecting private information.
[0832] An example of a prompt is:
[0833] "I want to collect medical data from an API endpoint and identify and anonymize personal information in the returned data. Specifically, I want you to write a Python program that will replace names and addresses with "anonymous" and convert birthdates to "xxxx-xx-xx."
[0834] The above is a detailed embodiment of the present invention. This system realizes real-time anonymization of medical information, safe processing, and efficient data utilization.
[0835] The flow of the specific processing in the application example 1 will be described with reference to FIG.
[0836] Step 1:
[0837] The server retrieves patient data from medical institutions and pharmacies via API endpoints or file uploads. The inputs are the API endpoint URL and the uploaded file, and the output is the raw data stored on the server. Specifically, the server sends a request to the specified API endpoint and stores the returned data in secure storage.
[0838] Step 2:
[0839] The server uses a natural language processing algorithm to identify personally identifiable elements (such as name, address, and date of birth) from the acquired medical data. The input is raw data, and the output is a list of personally identifiable elements. Specifically, the server uses text analysis and pattern matching to extract personal information from the raw data and saves the identified elements in list format.
[0840] Step 3:
[0841] The server anonymizes the identified personal information in accordance with the Personal Information Protection Act. For example, it replaces names and addresses with random identifiers and blurs birthdays to a range. The input is a list of identified elements, and the output is anonymized data. Specifically, the server converts names and addresses to "anonymous" and birthdays to "xxxx-xx-xx."
[0842] Step 4:
[0843] The server verifies whether the anonymized information meets predetermined criteria. The input is the anonymized data, and the output is the verification result of whether the criteria are met. Specifically, the server performs an automatic check based on the anonymization guidelines, and if the criteria are not met, it performs additional anonymization processing.
[0844] Step 5:
[0845] The server stores the verified anonymized data in a secure database. The input is the verified anonymized data, and the output is the data stored in the database. Specifically, the server stores the data using encryption technology and strict access control.
[0846] Step 6:
[0847] The server receives and systematically organizes de-identified medical information. The input is existing de-identified data, and the output is organized data. Specifically, the server normalizes and indexes the data, converting it into a format that is easy to search and browse.
[0848] Step 7:
[0849] The device provides an interface that allows users to search and view anonymized medical information. The input is the user's search criteria, and the output is the search results displayed to the user. Specifically, the device accepts search criteria through the user interface, sends a query to the server, and retrieves and displays related information.
[0850] Step 8:
[0851] The server calculates rewards based on data usage and distributes them to data providers. The input is a data usage log, and the output is a reward calculation result. Specifically, the server analyzes the access log, calculates reward amounts based on the data used, and distributes them to each information provider.
[0852] Step 9:
[0853] Smart glasses are used to anonymize and securely process patient data in real time in medical settings. The input is the patient's medical record and treatment information, and the output is anonymized real-time data. Specifically, the smart glasses read the patient data, display personal information on the screen in an anonymized form, and convert the data into a format that can be safely shared when actually used.
[0854] Furthermore, an emotion engine that estimates the user's emotion may be further combined. That is, the identification processing unit 290 may estimate the user's emotion using the emotion identification model 59, and perform identification processing using the user's emotion.
[0855] MODE FOR CARRYING OUT THE INVENTION
[0856] This paper describes a system that safely anonymizes medical information and promotes its use, and combines it with an emotion engine that recognizes user emotions. This system is broadly composed of an AI tool for anonymizing medical information, an AI tool for collecting, viewing, and consulting, and an emotion engine.
[0857] AI tool for anonymizing medical information
[0858] Data collection
[0859] The server receives patient data (medical record information and medication information) from medical institutions and pharmacies via API or file upload. When receiving the data, it checks whether the data format is consistent and performs preprocessing as necessary to standardize the format.
[0860] Personal Information Identification
[0861] The server automatically identifies personally identifiable information (such as name, address, and date of birth) from the received patient data using natural language processing algorithms, employing text analysis and pattern matching techniques, and then lists the results.
[0862] Data Conversion
[0863] The server then anonymizes the identified personal information, specifically converting names and addresses into random identifiers and blurring birthdates and specific date data into ranges or general formats in accordance with the Personal Information Protection Act.
[0864] Data Check
[0865] The server verifies whether the converted data meets various standards, and if it does not meet certain anonymity standards, it performs additional anonymization processing.
[0866] Data storage
[0867] The server then stores the verified anonymized data in a secure database, where access control permissions are set and the data is protected using encryption technology.
[0868] AI tool for collection, viewing, and consultation
[0869] Data reception
[0870] The server receives the anonymized data provided by the medical information anonymization AI tool, and upon receiving it performs a data integrity check to ensure there are no missing or incorrect data.
[0871] Data organization
[0872] The server systematically organizes the received anonymized data, normalizing and indexing it to make it easier to search and view, thereby enabling efficient data management.
[0873] Providing search and browsing functionality
[0874] The terminal (user device) provides an interface that allows users to search and view anonymized medical information. Users can enter keywords and set conditions to search data.
[0875] Reward Allocation
[0876] The server automatically calculates and distributes rewards to data providers according to the user's data usage. This involves analyzing the data access log and calculating the reward amount for each information provider.
[0877] Adding an Emotion Engine
[0878] emotion recognition
[0879] The device will activate an emotion engine through user input and operations to recognize the user's emotional state, possibly using algorithms that extract emotions from text nuances or voice data.
[0880] Customize search results based on sentiment
[0881] The server customizes search results based on the user's emotions as recognized by the emotion engine. For example, if the user is feeling stressed, data related to stress reduction will be displayed preferentially.
[0882] Providing emotional feedback
[0883] The device provides appropriate feedback based on the user's emotions. For example, if the user is feeling anxious, the device provides an interface offering support and additional information.
[0884] Specific examples
[0885] Collection and anonymization of patient data from medical institutions
[0886] The server receives patient data from a medical institution via API, including medical records and medication information.
[0887] The server analyzes the received data and uses natural language processing to identify personally identifiable information such as name, address, and date of birth.
[0888] The server converts names to random identification IDs, blurs addresses to the region level, and converts birthdates to years.
[0889] The server automatically checks whether the anonymization has been performed properly, and if there are any defects, it performs the anonymization process again.
[0890] The server then encrypts the anonymized data after checking and stores it in a secure database.
[0891] When pharmaceutical companies use anonymized data
[0892] Users (researchers at pharmaceutical companies) access the server using their own terminals.
[0893] The terminal provides a search interface to the user, allowing the user to input keywords to search for data relating to a particular disease.
[0894] The server quickly extracts data that matches the search criteria from the indexed, anonymized database.
[0895] The terminal displays the search results to the user, allowing the user to view the details.
[0896] The server analyzes the user's data usage log and distributes appropriate rewards to the data providers.
[0897] Use of emotion engine
[0898] While the user (a pharmaceutical company researcher) is using the data, the emotion engine detects the user's anxiety.
[0899] The server customizes search results based on the output of the emotion engine, prioritizing the display of data that may reduce anxiety.
[0900] Based on feedback from the emotion engine, the device provides support and additional information to the user, providing information to reduce anxiety.
[0901] Through the above steps, the present invention realizes anonymization and efficient use of medical information, and furthermore, by customizing search results taking into account the user's emotions, more personalized data utilization becomes possible.
[0902] The processing flow will be explained below.
[0903] AI tool for anonymizing medical information
[0904] Processing steps from data collection to anonymization
[0905] Step 1:
[0906] The server receives patient data (medical record information and medication information) from medical institutions and pharmacies via API or file upload. When receiving the data, it checks whether the data format is appropriate, preprocesses it as necessary, and standardizes the format.
[0907] Step 2:
[0908] The server automatically identifies personally identifiable information (such as name, address, and date of birth) from the received patient data using natural language processing algorithms, and then uses text analysis techniques to extract and compile this information into a list.
[0909] Step 3:
[0910] The server will anonymize the identified personal information by converting names and addresses into random identifiers (e.g., UUIDs) and converting birthdates and specific date data into ranges or years.
[0911] Step 4:
[0912] The server automatically verifies whether the anonymized data meets the standards of the Personal Information Protection Act, and if the anonymity is insufficient, it performs additional anonymization processing.
[0913] Step 5:
[0914] The server stores the verified and anonymized data in a secure database, which uses strict access controls and encryption technology to protect the data.
[0915] AI tool for collection, viewing, and consultation
[0916] Processing steps from receiving data to allocating rewards
[0917] Step 1:
[0918] The server receives the anonymized data provided by the medical information anonymization AI tool, and checks the data integrity upon receipt to ensure there are no missing or incorrect data.
[0919] Step 2:
[0920] The server normalizes the received anonymously processed data and indexes it for easy searching and browsing. It organizes each field into categories to achieve efficient data management.
[0921] Step 3:
[0922] The terminal (user device) provides an interface for users to search and view anonymized medical information. Users input keywords, set search conditions, search data, and obtain results.
[0923] Step 4:
[0924] The server quickly extracts anonymized data that matches the user's search criteria and displays it as a search result.
[0925] Step 5:
[0926] The server analyzes the user's data usage log and automatically calculates and distributes rewards to the data provider. The server calculates the reward amount based on the access log and distributes the reward to the specified account.
[0927] Use of emotion engine
[0928] Processing steps from emotion recognition to providing feedback
[0929] Step 1:
[0930] The device activates an emotion engine through user input and operations to recognize the user's emotional state, using algorithms that extract emotions from text nuances and voice data.
[0931] Step 2:
[0932] The server customizes search results based on the user's emotions as recognized by the emotion engine. For example, if the user is feeling stressed, data related to stress reduction will be displayed preferentially.
[0933] Step 3:
[0934] The device provides feedback based on the user's emotions based on the output of the emotion engine. For example, if the user is feeling anxious, the device provides an interface that presents appropriate support and additional information.
[0935] Specific examples
[0936] Collection and anonymization of patient data from medical institutions
[0937] Step 1:
[0938] The server receives patient data from medical institutions via API, including medical records and medication information.
[0939] Step 2:
[0940] The server analyzes the received data and uses natural language processing algorithms to identify personally identifiable information such as name, address, and date of birth, compiling them into a list.
[0941] Step 3:
[0942] The server converts the identified personal information into a random identification ID, blurs addresses to the region level, and converts birthdates to years.
[0943] Step 4:
[0944] The server automatically checks whether the anonymized data meets the standards for protecting personal information. If there are any deficiencies, the data is anonymized again.
[0945] Step 5:
[0946] Once the checks are complete, the server encrypts and stores the anonymized data in a secure database.
[0947] When pharmaceutical companies use anonymized data
[0948] Step 1:
[0949] Users (researchers at pharmaceutical companies) access the server using their own terminals.
[0950] Step 2:
[0951] The terminal provides a search interface to the user, allowing the user to input keywords to search for data relating to a particular disease.
[0952] Step 3:
[0953] The server quickly extracts data that matches the search criteria from the indexed, anonymized database.
[0954] Step 4:
[0955] The terminal displays the search results to the user, allowing the user to view the details.
[0956] Step 5:
[0957] The server analyzes the user's data usage log and distributes appropriate rewards to the data providers.
[0958] Use of emotion engine
[0959] Step 1:
[0960] While the user (a pharmaceutical company researcher) is using the data, the emotion engine detects the user's anxiety.
[0961] Step 2:
[0962] The server customizes search results based on the output of the emotion engine, prioritizing the display of data that may reduce anxiety.
[0963] Step 3:
[0964] Based on feedback from the emotion engine, the device provides the user with appropriate support and additional information to reduce anxiety.
[0965] Through the above steps, the present invention realizes anonymization and efficient use of medical information, and furthermore, by customizing search results taking into account the user's emotions, more personalized data utilization becomes possible.
[0966] Example 2
[0967] Next, a description will be given of Example 2. In the following description, the data processing device 12 will be referred to as a "server" and the smart glasses 214 will be referred to as a "terminal."
[0968] The importance of protecting personal information is increasing in modern medical information management. However, systems that safely anonymize medical data and promote its use are not widely available. Furthermore, the user experience is not fully satisfactory because there is no feedback or customized search results that take into account the user's emotional state when using the data. Therefore, a system that safely anonymizes medical data and provides information based on the user's emotional state is needed.
[0969] The identification process by the identification processing unit 290 of the data processing device 12 in the second embodiment is realized by the following means. In this invention, the server includes a means for acquiring medical information, a means for identifying elements that can identify an individual from the acquired medical information, and a means for anonymizing the identified elements in accordance with the Personal Information Protection Act. This makes it possible to safely anonymize medical information and provide information according to the user's emotional state.
[0970] "Medical information" refers to medical data such as patient medical records, prescription information, and test results.
[0971] "Anonymization" refers to the process of removing or transforming personally identifiable information so that the data provider cannot be identified.
[0972] "Natural language processing algorithms" refer to computational methods and technologies for automatically parsing, understanding, and generating human language.
[0973] "Anonymized Data" means data that has been made anonymous by removing or transforming personal information.
[0974] "Emotional state" refers to a psychological state that is determined based on a user's actions or inputs.
[0975] "Feedback" refers to the information or actions that a system provides in response to a user's behavior or state.
[0976] "Interface" refers to the screens and functions that allow users to interact with the system.
[0977] "Reward calculation" refers to the process of calculating rewards to data providers in accordance with the user's use of data.
[0978] "Access log" refers to data that records the history of users accessing a system.
[0979] A "database" refers to a system that stores information in an organized manner and makes it easy to search and manage.
[0980] "Random identifier" refers to a unique identification code that is randomly generated so as not to identify personal information.
[0981] This invention describes a system that safely anonymizes medical information and promotes its use, as well as a system that combines an emotion engine that recognizes user emotions. The detailed configuration and operation of this system are described below.
[0982] AI tool for anonymizing medical information
[0983] The AI tool for anonymizing medical information in this system runs on a server, primarily to perform the following processes:
[0984] 1. Data Collection:
[0985] The server receives patient data (medical record information and medication information) from medical institutions and pharmacies via API or file upload. For example, it obtains JSON format data from a medical institution's system, checks the integrity of the data upon reception, preprocesses it, and standardizes it into a standard format.
[0986] 2. Personal Information Identification:
[0987] The server uses natural language processing algorithms to automatically identify personally identifiable information (such as name, address, and date of birth) from the received data, and then uses text analysis and pattern matching techniques to extract and list personal information.
[0988] 3. Data conversion:
[0989] The server then anonymizes the identified personal information. Specifically, it converts names and addresses into random IDs and blurs birthdays to years. This ensures that the data is securely anonymized.
[0990] 4. Data Check:
[0991] The server verifies whether the converted data meets the anonymity criteria, and if not, performs additional anonymization processing.
[0992] 5. Data Retention:
[0993] The server then stores the verified anonymized data in a secure database, where access control permissions are set and the data is protected using encryption technology.
[0994] AI tool for collection, viewing, and consultation
[0995] This tool is designed to efficiently utilize anonymized medical data and performs the following processes:
[0996] 1. Data reception:
[0997] The server receives the anonymized data provided by the medical information anonymization AI tool and performs a consistency check to ensure there are no missing or incorrect data.
[0998] 2. Data reduction:
[0999] The server normalizes the anonymized data it receives and indexes it for easy searching and browsing.
[1000] 3. Providing search and browsing functionality:
[1001] The terminal (user device) provides an interface for searching and viewing anonymized medical information. Users can search for data by entering keywords or conditions.
[1002] 4. Reward Allocation:
[1003] The server calculates and automatically distributes rewards to data providers based on the user's data usage. It analyzes access logs and calculates reward amounts based on factors such as frequency of usage.
[1004] Adding an Emotion Engine
[1005] This system is integrated with an emotion engine that can recognize user emotions. The operation is shown below.
[1006] 1. Emotion recognition:
[1007] The device activates an emotion engine through user input and operations to recognize the user's emotional state, using algorithms that extract emotions from text nuances and voice data.
[1008] 2. Personalize search results based on sentiment:
[1009] The server customizes search results based on the user's emotions as recognized by the emotion engine. For example, if the user is feeling stressed, data related to stress reduction will be displayed preferentially.
[1010] 3. Providing emotional feedback:
[1011] The device provides appropriate feedback based on the user's emotions, for example, suggesting support information or additional resources if the user is feeling anxious.
[1012] Specific examples
[1013] Collection and anonymization of patient data from medical institutions
[1014] The server receives patient data from medical institutions via API, including medical records and medication information.
[1015] The server analyzes the received data and uses natural language processing to identify personally identifiable information such as name, address, and date of birth.
[1016] The server converts names to random identification IDs, blurs addresses to the region level, and converts birthdates to years.
[1017] The server automatically checks whether the anonymization has been performed properly, and if there are any deficiencies, performs the anonymization process again.
[1018] The server then encrypts the anonymized data after checking and stores it in a secure database.
[1019] When pharmaceutical companies use anonymized data
[1020] Users (researchers at pharmaceutical companies) access the server using their own terminals.
[1021] The terminal provides a search interface to the user, allowing the user to input keywords to search for data relating to a particular disease.
[1022] The server quickly extracts data that matches the search criteria from the indexed, anonymized database.
[1023] The terminal displays the search results to the user, allowing the user to view the details.
[1024] The server analyzes the user's data usage log and distributes appropriate rewards to the data providers.
[1025] Use of emotion engine
[1026] While the user (a pharmaceutical company researcher) is using the data, the emotion engine detects the user's anxiety.
[1027] The server customizes search results based on the output of the emotion engine, prioritizing the display of data that may reduce anxiety.
[1028] Based on feedback from the emotion engine, the device provides support and additional information to the user, providing information to reduce anxiety.
[1029] Example prompts to be input to the generative AI model
[1030] 1. Please explain the AI tool for anonymizing medical information.
[1031] 2. What are the specific steps to de-identify certain medical data?
[1032] 3. Please elaborate on how you use the sentiment engine to customize search results.
[1033] Through the above steps, the present invention realizes anonymization and efficient use of medical information, and furthermore, by customizing search results taking into account the user's emotions, more personalized data utilization becomes possible.
[1034] The flow of the identification process in the second embodiment will be described with reference to FIG.
[1035] AI tool for anonymizing medical information
[1036] Step 1:
[1037] The server receives patient data (medical record information and medication information) from medical institutions and pharmacies via API or file upload. It checks the format of the received data and performs preprocessing as necessary to unify the format.
[1038] Input: Patient data from a medical institution (e.g., JSON file)
[1039] Output: Patient data in a unified format
[1040] Specific operation: Check the format of the received data (for example, date format or name notation) and normalize and unify it.
[1041] Step 2:
[1042] The server uses natural language processing algorithms to automatically identify personally identifiable information (such as name, address, date of birth, etc.) from the received data.
[1043] Input: Patient data in a unified format
[1044] Output: Data listing personally identifiable information
[1045] Specific operation: Extracts names, addresses, and birthdays using regular expressions and text analysis, and saves them in list format.
[1046] Step 3:
[1047] The server anonymizes the identified personal information, converting names and addresses to random identifiers and blurring birth dates to years.
[1048] Input: Data listing personally identifiable information
[1049] Output: Anonymized data
[1050] Specific behavior: Converts names to random IDs, addresses to city level, and birthdays to year level. For example, converts "Tanaka Ichiro" to "User ID 12345."
[1051] Step 4:
[1052] The server verifies whether the converted data meets the anonymity criteria, and if it does not, it anonymizes the data again.
[1053] Input: Anonymized data
[1054] Output: Verified and anonymized data
[1055] What it does: Compare the results of the anonymization algorithm against a checklist and reprocess any gaps or deficiencies.
[1056] Step 5:
[1057] The server stores the verified and anonymized data in a secure database, with access control permissions and encryption technology to protect the data.
[1058] Input: Verified, anonymized data
[1059] Output: Securely stored data
[1060] What it does: Encrypts data using AES-256 encryption technology and stores it in a database with access controls.
[1061] AI tool for collection, viewing, and consultation
[1062] Step 1:
[1063] The server receives the anonymized data provided by the medical information anonymization AI tool and performs a consistency check to ensure there are no missing or incorrect data.
[1064] Input: Anonymously processed data
[1065] Output: Integrity checked data
[1066] What it does: Validates data integrity, checks for missing data and inconsistencies, and corrects them as needed.
[1067] Step 2:
[1068] The server normalizes the anonymized data it receives and indexes it for easy searching and browsing.
[1069] Input: Data that has been checked for consistency
[1070] Output: Normalized and indexed data
[1071] What it does: Normalizes database fields and performs indexing to facilitate keyword and criteria searches.
[1072] Step 3:
[1073] The device provides an interface for searching and viewing anonymized medical information.
[1074] Input: Keywords and conditions from the user
[1075] Output: Search results
[1076] What it does: Provides an interface that allows users to enter keywords in a search box, set conditions, and search for data.
[1077] Step 4:
[1078] The server calculates and automatically distributes rewards to data providers based on the user's data usage.
[1079] Input: User access log
[1080] Output: Reward calculation results, reward distribution information
[1081] Specific operation: Analyzes access logs, calculates reward amounts based on frequency of use and importance of data, and automatically distributes them to each provider.
[1082] Adding an Emotion Engine
[1083] Step 1:
[1084] The terminal activates an emotion engine through user input and operations to recognize the user's emotional state.
[1085] Input: User input and operation data
[1086] Output: Perceived emotional state
[1087] What it does: Analyzes user input text and voice data and applies algorithms to extract emotions.
[1088] Step 2:
[1089] The server customizes search results based on the user's emotions recognized by the emotion engine.
[1090] Input: Recognized emotional state, user search criteria
[1091] Output: Customized search results
[1092] What it does: It applies a customization algorithm based on your emotional state to prioritize relevant search results.
[1093] Step 3:
[1094] The terminal provides appropriate feedback based on the user's emotions.
[1095] Input: Perceived emotional state
[1096] Output: A feedback message to the user.
[1097] What it does: If the user is feeling anxious, provide an interface that suggests support information or additional resources.
[1098] (Application example 2)
[1099] Next, a description will be given of Application Example 2. In the following description, the data processing device 12 will be referred to as a "server" and the smart glasses 214 will be referred to as a "terminal."
[1100] In addition to anonymizing and securely storing medical information and making it easier to search and view, flexible feedback and electronic payment functions that take into account the user's emotions when using the data are required. In particular, it is a challenge to alleviate users' anxiety and provide a reassuring environment by enabling anonymous settlement of medical expenses and providing customized information based on the user's emotional state during use.
[1101] The identification process by the identification processing unit 290 of the data processing device 12 in Application Example 2 is realized by the following means. In this invention, the server includes means for acquiring medical information, means for identifying elements that can identify an individual from the acquired medical information, means for anonymizing the identified elements in accordance with the Personal Information Protection Act, means for verifying whether the anonymized information meets predetermined criteria, means for securely storing the anonymized information, means for receiving and systematically organizing the anonymized medical information, means for providing an interface for searching and viewing the organized medical information, means for calculating rewards based on data usage and allocating them to data providers, means for making payments based on the anonymized medical information, and means for activating an emotion engine that recognizes the user's emotional state and customizing search results. This enables anonymous settlement of medical expenses and provides information customized to the user's emotional state.
[1102] "Medical information" refers to patient medical records, medication information, and health status data.
[1103] "Personally identifiable information" refers to information that can identify a specific individual, such as name, address, or date of birth.
[1104] "Anonymizing" refers to the act of removing or converting personally identifiable information so that it is no longer possible to identify a specific individual.
[1105] "Verify" refers to the act of checking whether anonymized information meets specified standards.
[1106] "Storing" refers to the act of recording information in a certain place so that it will not be lost.
[1107] "Systematically organizing" refers to the act of classifying and arranging information according to certain rules so that it can be managed and used efficiently.
[1108] "Interface" refers to the screens and operating means through which users interact with the system.
[1109] "Calculating and allocating rewards" refers to the act of calculating the amount of rewards based on the use of data and distributing the rewards to appropriate providers.
[1110] "Making a payment" refers to the act of carrying out a transaction to pay for goods or services.
[1111] "Recognizing emotional state" refers to the act of the system detecting and judging the user's emotions (e.g., anxiety, relief, stress, etc.).
[1112] An "emotion engine" refers to a software component for analyzing emotions through user input and operations.
[1113] "Customize" refers to the act of changing or adjusting content or presentation to suit specific conditions or circumstances.
[1114] MODE FOR CARRYING OUT THE INVENTION
[1115] The system according to the present invention is configured as follows, and the specific implementation thereof will be described in detail below.
[1116] 1. System Program
[1117] overview
[1118] This system not only anonymizes medical information and securely stores and uses it, but also recognizes users' emotions to provide customized information.It also enables secure electronic payments using anonymized medical information.
[1119] 2. Explanation of program processing
[1120] Required Hardware and Software
[1121] Hardware:
[1122] Servers (e.g., high-performance computing servers)
[1123] User device (e.g., smartphone)
[1124] software:
[1125] Natural language processing engines (e.g. BERT)
[1126] Database management systems (e.g. MongoDB)
[1127] Encryption technology (e.g. AES encryption)
[1128] Emotion recognition algorithms (e.g., Sentiment Analysis API)
[1129] Acquisition and de-identification of medical information
[1130] The server receives patient data from healthcare providers via API. It uses a natural language processing engine to identify personally identifiable information and converts it into a random identifier. It also obscures certain dates and medical history information. The anonymized data is then securely stored in a database using AES encryption.
[1131] Search and browse anonymized data
[1132] Users access the server using their smartphones to search for anonymized medical data. The server indexes the received anonymized data and organizes it into a searchable and viewable format. Users can search for data by entering keywords, and the search results are displayed on the interface.
[1133] Use of emotion engine
[1134] When a user searches or browses data, an emotion recognition algorithm installed on the smartphone analyzes the user's emotions. If the emotion engine detects anxiety or stress, the server will provide customized search results corresponding to that emotion. For example, it will display support information to reduce anxiety or reassuring messages.
[1135] Making electronic payments
[1136] Medical expenses can be paid safely and anonymously based on anonymized medical data. Users complete the payment procedure using their smartphone, and the information is securely processed by the server.
[1137] 3. Specific Examples
[1138] Medical expense settlement scenario
[1139] After a user receives medical treatment at a medical institution, the medical expenses are settled using anonymized data via a smartphone app.
[1140] The server uses natural language processing to identify and anonymize personal information from the received billing data.
[1141] Electronic payments are made using anonymized information, which is then stored using AES encryption technology.
[1142] Feedback scenario using emotion recognition
[1143] The emotion engine detects anxiety while users are browsing medical information on their smartphones.
[1144] The server prioritizes displaying medical and support information to address anxiety, increasing the user's sense of security.
[1145] 4. Examples of prompts
[1146] Please explain the process by which users receive medical billing data from medical institutions via a smartphone app, securely settle bills, and how the anonymized medical data will be used afterwards. Please also include a function to analyze user sentiment and provide support information.
[1147] This system enables anonymization, secure storage, search and viewing of medical information, as well as customized information provision according to emotional state and secure electronic payment.
[1148] The flow of the specific processing in the application example 2 will be described with reference to FIG.
[1149] Step 1:
[1150] The server receives patient data from medical institutions via API. The received data includes medical records and medication information. The server checks whether the format of the received data is standardized, and performs preprocessing as necessary to standardize the data format. The input at this stage is patient data from medical institutions, and the output is data in a standardized format.
[1151] Step 2:
[1152] The server uses a natural language processing engine to identify personally identifiable elements (such as name, address, and date of birth) from the received data. Specifically, it uses text analysis and pattern matching techniques to create a list of these elements. The input to this stage is data in a standardized format, and the output is a list containing personally identifiable elements.
[1153] Step 3:
[1154] The server anonymizes the identified personally identifiable information by converting names and addresses into random identifiers and obscuring certain dates and medical history information. The input to this stage is a list of personally identifiable information, and the output is anonymized data.
[1155] Step 4:
[1156] The server verifies whether the anonymized information meets the predetermined criteria. If it does not meet the certain anonymity criteria, it performs additional anonymization processing. The input of this stage is the anonymized data, and the output is the verified anonymized data.
[1157] Step 5:
[1158] The server securely stores the anonymized data in a database using AES encryption. Database access control permissions are set during storage to enhance data protection. The input to this stage is the verified anonymized data, and the output is a database containing the encrypted data.
[1159] Step 6:
[1160] Users access the server using their smartphones to search for anonymized medical data. The device provides a search interface where users input keywords and conditions. The input at this stage is the user's search query, and the output is the search conditions sent to the server.
[1161] Step 7:
[1162] The server compares the indexed anonymized database based on the received search query and generates search results. The input at this stage is the user's search criteria, and the output is the search results that match the criteria.
[1163] Step 8:
[1164] The user's terminal displays the search results, allowing the user to view the data. The input at this stage is the search results sent from the server, and the output is a screen displaying the search results.
[1165] Step 9:
[1166] While the user is searching or browsing data, the device uses emotion recognition algorithms to analyze the user's emotional state. For example, emotions can be extracted from text nuances or voice data. The input at this stage is the user's operation data or input text, and the output is data indicating the user's emotional state.
[1167] Step 10:
[1168] The server customizes search results based on the user's emotions recognized by the emotion engine. For example, if the user is feeling anxious, support information that will alleviate the anxiety will be displayed preferentially. The input of this stage is the user's emotional data, and the output is customized search results.
[1169] Step 11:
[1170] The user's device displays customized search results and feedback, and provides appropriate support information to the user. Specifically, reassuring messages and notifications are displayed. The input of this stage is the customized search results and feedback information, and the output is the customized information displayed to the user.
[1171] Step 12:
[1172] Users use a smartphone app to make payments based on anonymized medical data. The server securely processes the payment data while maintaining its anonymity and stores it using AES encryption technology. The input at this stage is the user's payment information, and the output is securely processed payment completion data.
[1173] The specific processing unit 290 transmits the result of the specific processing to the smart glasses 214. In the smart glasses 214, the control unit 46A causes the speaker 240 to output the result of the specific processing. The microphone 238 acquires audio indicating a user input regarding the result of the specific processing. The control unit 46A transmits audio data indicating the user input acquired by the microphone 238 to the data processing device 12. In the data processing device 12, the specific processing unit 290 acquires the audio data.
[1174] The data generation model 58 is a so-called generative AI (Artificial Intelligence). An example of the data generation model 58 is ChatGPT (Internet Search<URL: https: / / openai.com / blog / chatgpt> ), Gemini (Internet search <url: https: gemini.google.com ?hl="ja">) and other generation AIs. The data generation model 58 is obtained by performing deep learning on a neural network. A prompt including an instruction is input to the data generation model 58, and inference data such as voice data indicating voice, text data indicating text, and image data indicating an image is also input. The data generation model 58 performs inference on the input inference data in accordance with the instruction indicated by the prompt, and outputs the inference result in a data format such as voice data and text data. Here, inference refers to, for example, analysis, classification, prediction, and / or summarization.
[1175] In the above embodiment, an example in which the specific processing is performed by the data processing device 12 has been given, but the technology of the present disclosure is not limited to this, and the specific processing may be performed by the smart glasses 214.
[1176] [Third embodiment]
[1177] FIG. 5 shows an example of the configuration of a data processing system 310 according to the third embodiment.
[1178] 5, the data processing system 310 includes the data processing device 12 and a headset terminal 314. An example of the data processing device 12 is a server.
[1179] The data processing device 12 includes a computer 22, a database 24, and a communication I / F 26. The computer 22 is an example of a "computer" according to the technology of the present disclosure. The computer 22 includes a processor 28, a RAM 30, and a storage 32. The processor 28, the RAM 30, and the storage 32 are connected to a bus 34. The database 24 and the communication I / F 26 are also connected to the bus 34. The communication I / F 26 is connected to a network 54. Examples of the network 54 include a WAN (Wide Area Network) and / or a LAN (Local Area Network).
[1180] The headset type terminal 314 includes a computer 36, a microphone 238, a speaker 240, a camera 42, a communication I / F 44, and a display 343. The computer 36 includes a processor 46, a RAM 48, and a storage 50. The processor 46, the RAM 48, and the storage 50 are connected to a bus 52. The microphone 238, the speaker 240, the camera 42, and the display 343 are also connected to the bus 52.
[1181] The microphone 238 receives instructions and the like from the user 20 by receiving voice uttered by the user 20. The microphone 238 captures the voice uttered by the user 20, converts the captured voice into audio data, and outputs it to the processor 46. The speaker 240 outputs audio in accordance with instructions from the processor 46.
[1182] Camera 42 is a small digital camera equipped with an optical system including a lens, aperture, and shutter, and an imaging element such as a CMOS (Complementary Metal-Oxide-Semiconductor) image sensor or a CCD (Charge Coupled Device) image sensor, and captures images of the surroundings of user 20 (for example, an imaging range defined by an angle of view equivalent to the field of vision of a typical healthy person).
[1183] The communication I / F 44 is connected to a network 54. The communication I / Fs 44 and 26 are responsible for the exchange of various information between the processor 46 and the processor 28 via the network 54. The exchange of various information between the processor 46 and the processor 28 using the communication I / Fs 44 and 26 is carried out in a secure state.
[1184] Fig. 6 shows an example of the main functions of the data processing device 12 and the headset type terminal 314. As shown in Fig. 6, in the data processing device 12, a specific process is performed by the processor 28. A specific process program 56 is stored in the storage 32.
[1185] The specific processing program 56 is an example of a "program" according to the technology of the present disclosure. The processor 28 reads the specific processing program 56 from the storage 32 and executes the read specific processing program 56 on the RAM 30. The specific processing is realized by the processor 28 operating as a specific processing unit 290 in accordance with the specific processing program 56 executed on the RAM 30.
[1186] The storage 32 stores a data generation model 58 and an emotion identification model 59. The data generation model 58 and the emotion identification model 59 are used by the identification processing unit 290.
[1187] In the headset type terminal 314, a reception output process is performed by the processor 46. A reception output program 60 is stored in the storage 50. The processor 46 reads the reception output program 60 from the storage 50 and executes the read reception output program 60 on the RAM 48. The reception output process is realized by the processor 46 operating as the control unit 46A in accordance with the reception output program 60 executed on the RAM 48.
[1188] Next, a description will be given of the identification process performed by the identification processing unit 290 of the data processing device 12. In the following description, the data processing device 12 will be referred to as the "server" and the headset type terminal 314 will be referred to as the "terminal."
[1189] MODE FOR CARRYING OUT THE INVENTION
[1190] This paper describes a system for safely anonymizing medical information and promoting its use. This system is broadly composed of an AI tool for anonymizing medical information and an AI tool for collecting, viewing, and consulting on medical information.
[1191] AI tool for anonymizing medical information
[1192] Data collection
[1193] The server receives patient data (medical records and medication information) in multiple formats from medical institutions and pharmacies. For example, it collects data via API or file upload and stores it in secure storage. If necessary, it performs preprocessing to unify the data format.
[1194] Personal Information Identification
[1195] The server automatically identifies personally identifiable information (such as name, address, date of birth, etc.) from the received data using natural language processing algorithms, using text analysis and pattern matching techniques, and then lists the results.
[1196] Data Conversion
[1197] The server anonymizes identified personal information in a manner compliant with the Personal Information Protection Act, for example, by replacing names and addresses with random identifiers and blurring birthdates and specific date data into ranges or general formats.
[1198] Data Check
[1199] The server verifies whether the converted data meets various standards, and if it does not meet certain anonymity standards, it performs additional anonymization processing.
[1200] Data storage
[1201] The server stores the verified and anonymized data in a secure database, which is protected by strict access controls and encryption technology.
[1202] AI tool for collection, viewing, and consultation
[1203] Data reception
[1204] The server receives the anonymized data provided by the medical information anonymization AI tool and checks the integrity of the data upon receipt.
[1205] Data organization
[1206] The server organizes the received anonymized data in a systematic manner, normalizing and indexing it for easy searching and browsing, thereby making data organization more cohesive and efficient.
[1207] Providing search and browsing functionality
[1208] The terminal (user device) provides an interface that allows users to search and view anonymized medical information. For example, if a user wants to search for information about a certain disease, they enter keywords, set search conditions, and retrieve data.
[1209] Reward Allocation
[1210] The server automatically calculates and distributes rewards to data providers according to the user's data usage. This involves analyzing the data access log and calculating the reward amount for each information provider.
[1211] Example
[1212] Example 1: Collecting and anonymizing patient data from medical institutions
[1213] The server receives patient medical record information from a medical institution using an API.
[1214] The server uses a natural language processing algorithm to identify the name, address, and date of birth from the received data.
[1215] The server converts these personal details into a random identifier and blurs the "birthday" information to a year.
[1216] The server automatically checks whether the anonymized data meets the standards and, if OK, stores it in a secure database.
[1217] Example 2: Pharmaceutical companies search and utilize anonymized data
[1218] Users (researchers at pharmaceutical companies) access the server using their own terminals.
[1219] The terminal provides the user with a search interface, and the user sets search conditions by entering the keyword "diabetes."
[1220] The server retrieves and displays relevant information from an indexed, anonymized database.
[1221] The server calculates and distributes remuneration to the medical institution that provided the data based on the data used.
[1222] Through the above steps, the present invention enables the anonymization and efficient utilization of medical information, and provides a solution for safely handling medical data.
[1223] The processing flow will be explained below.
[1224] AI tool for anonymizing medical information
[1225] Processing steps from data collection to anonymization
[1226] Step 1:
[1227] The server receives patient data from medical institutions and pharmacies via API or file upload. Upon receiving the data, it checks whether the data format is consistent and performs preprocessing as necessary to standardize the format.
[1228] Step 2:
[1229] The server identifies personally identifiable information (such as name, address, and date of birth) from the received patient data by analyzing the text using a natural language processing algorithm and compiling the information into an extracted list.
[1230] Step 3:
[1231] The server anonymizes the identified personal information. Specifically, in accordance with the Personal Information Protection Act, it converts names and addresses into random identifiers (e.g., UUIDs), and converts birthdays and specific dates into ranges or obscured information (e.g., leaving only the year of the date).
[1232] Step 4:
[1233] The server verifies the anonymized data, conducting automated checks to ensure that it meets the standards in terms of anonymity, and if there are any deficiencies, performs additional anonymization processes.
[1234] Step 5:
[1235] The server then stores the verified anonymized data in a secure database, where access control permissions are set and the data is protected using encryption technology.
[1236] AI tool for collection, viewing, and consultation
[1237] Processing steps from receiving data to allocating rewards
[1238] Step 1:
[1239] The server receives the anonymized data provided by the medical information anonymization AI tool, and upon receiving it performs a data integrity check to ensure there are no missing or incorrect data.
[1240] Step 2:
[1241] The server organizes the received anonymously processed data, normalizes the data, and performs indexing to make it easier to search and view, thereby enabling efficient data management.
[1242] Step 3:
[1243] The device provides a user interface for users to search and view anonymized medical information. Users can input keywords and set conditions to search for data.
[1244] Step 4:
[1245] The server displays the anonymized data as a search result and allows the user to view the details.
[1246] Step 5:
[1247] The server calculates and distributes rewards to data providers (medical institutions and pharmacies) based on the user's data usage. It analyzes the data access log and calculates the reward amount based on that.
[1248] Specific examples
[1249] Collection and anonymization of patient data from medical institutions
[1250] Step 1:
[1251] The server receives patient data via API from Medical Institution A. This data includes medical records and medication information.
[1252] Step 2:
[1253] The server analyzes the received data and uses natural language processing to identify personally identifiable information such as name, address, and date of birth.
[1254] Step 3:
[1255] The server converts names to random identification IDs, blurs addresses to the region level, and converts birthdates to years.
[1256] Step 4:
[1257] The server automatically checks whether the anonymization has been performed properly, and if there are any defects, it performs the anonymization process again.
[1258] Step 5:
[1259] The server then encrypts the anonymized data after checking and stores it in a secure database.
[1260] When pharmaceutical companies use anonymized data
[1261] Step 1:
[1262] Users (researchers at pharmaceutical companies) access the server using their own terminals.
[1263] Step 2:
[1264] The terminal provides a search interface to the user, allowing the user to input keywords to search for data relating to a particular disease.
[1265] Step 3:
[1266] The server quickly extracts data that matches the search criteria from the indexed, anonymized database.
[1267] Step 4:
[1268] The terminal displays the search results to the user, allowing the user to view the details.
[1269] Step 5:
[1270] The server analyzes the user's data usage log and distributes appropriate rewards to the data providers.
[1271] Example 1
[1272] Next, a description will be given of Example 1. In the following description, the data processing device 12 will be referred to as a "server" and the headset type terminal 314 will be referred to as a "terminal."
[1273] Currently, it is difficult to safely anonymize medical information and use it efficiently. In particular, the process of acquiring medical information, standardizing it into a specific format, identifying personally identifiable elements using natural language processing, and then anonymizing it is complex, and there is no system that appropriately rewards users for using anonymized information. Therefore, while there is a need to simultaneously ensure the safety and usefulness of medical data, current technology does not adequately achieve this.
[1274] The specific processing by the specific processing unit 290 of the data processing device 12 in the first embodiment is realized by the following means.
[1275] In this invention, the server includes means for acquiring medical information, means for identifying elements that can identify an individual from the acquired medical information, means for anonymizing the identified elements in accordance with the Personal Information Protection Act, means for verifying whether the anonymized information meets predetermined standards, means for securely storing the anonymized information, means for receiving and systematically organizing the anonymized medical information, means for providing an interface for searching and viewing the organized medical information, means for calculating rewards based on data usage and distributing them to data providers, means for preprocessing the anonymized medical information, means for standardizing the format of the preprocessed information, means for converting the anonymized information into a random identifier and blurring specific dates to years, and means for verifying the integrity of the anonymized information using a checksum, thereby enabling safe anonymization and efficient use of medical information.
[1276] "Medical information" refers to health-related data recorded and managed by medical institutions and pharmacies, such as patient medical records and medication information.
[1277] "Means of acquisition" refers to the process of receiving information from medical institutions and pharmacies using methods such as APIs or file uploads.
[1278] "Means of identification" refers to techniques that use natural language processing algorithms and pattern matching to extract elements within the data that can identify an individual.
[1279] "Anonymization methods" are techniques that prevent the identification of individuals by replacing personally identifiable elements with random identifiers or blurring date data.
[1280] "Verification measures" are processes for checking whether anonymized information meets predetermined standards.
[1281] "Means for storage" refers to storage systems and security technologies for safely managing anonymized information.
[1282] "Systematization" refers to the process of normalizing incoming medical information and creating an index to make it easier to search and view.
[1283] The "means for providing an interface" refers to a technology that implements a user interface that allows users to search and view medical information.
[1284] The "means for calculating and allocating rewards" is a process for automatically calculating and allocating rewards to data providers based on the usage status of the data.
[1285] The "preprocessing means" refers to a data conversion technique for converting received medical information into a unified format.
[1286] "Format harmonization" is the process of converting medical data provided in different formats into a consistent data format.
[1287] A "random identifier conversion method" is a process that replaces personal information such as name and address with a randomly generated identifier.
[1288] "Year blurring" is the process of converting specific date information into year information to prevent personal identification.
[1289] "Means for verifying using a checksum" refers to a technique for verifying using a checksum to ensure the integrity of data.
[1290] This invention is a system designed to safely anonymize medical information and promote its use. This system consists of two main components: an AI tool for anonymizing medical information and an AI tool for collecting, viewing, and consulting medical information.
[1291] AI tool for anonymizing medical information
[1292] Data collection
[1293] The server receives patient data (medical records and medication information) from medical institutions and pharmacies via API or file upload. After receiving the data, the server stores the information in secure storage (e.g., AWS S3 bucket or Google Cloud Storage). It also performs checksum verification to ensure the integrity of the received data. It also performs preprocessing to convert data provided in different formats into a unified format.
[1294] Examples:
[1295] The server receives patient medical record information from a medical institution using an API.
[1296] The server stores the received medical record information in an AWS S3 bucket and verifies the integrity of the data using a checksum.
[1297] Personal Information Identification
[1298] The server uses natural language processing algorithms (e.g., SpaCy or NLTK) to extract personally identifiable information (e.g., name, address, date of birth) from the data it receives, and also uses pattern matching techniques to identify email addresses and phone numbers within the data.
[1299] Examples:
[1300] The server uses a natural language processing algorithm to extract "name," "address," and "date of birth" from the medical record information.
[1301] Data Conversion
[1302] The server performs anonymization processing in accordance with the Personal Information Protection Act, such as converting identified personal information into a random identifier and blurring birthday information to years.
[1303] Examples:
[1304] The server converts the extracted "name" into a random identifier and blurs the "birthday" to a year.
[1305] Data Check
[1306] The server verifies whether the converted data meets predetermined criteria, and if not, performs additional anonymization processing.
[1307] Examples:
[1308] The server verifies the anonymity of the anonymized data and performs the anonymization process again if the criteria are not met.
[1309] Data storage
[1310] The server stores the verified, anonymized data in a secure database (e.g., AWS RDS, MongoDB Atlas), which is protected by encryption and access controls.
[1311] Examples:
[1312] The server stores anonymized medical record information in AWS RDS and encrypts and controls access to the database.
[1313] AI tool for collection, viewing, and consultation
[1314] Data reception
[1315] The server receives the anonymized data provided by the medical information anonymization AI tool and checks the integrity of the data upon receipt.
[1316] Examples:
[1317] The server receives the data provided by the anonymization AI tool and verifies the integrity of the data using a checksum.
[1318] Data organization
[1319] The server normalizes the received anonymized data and indexes it for efficient search (e.g., using Elasticsearch).
[1320] Examples:
[1321] The server indexes the anonymized data using Elasticsearch and normalizes it into a unified format.
[1322] Providing search and browsing functionality
[1323] The device provides an interface for users to search and view anonymized medical information. Users can enter keywords and set search criteria to retrieve relevant data.
[1324] Examples:
[1325] A user (a researcher at a pharmaceutical company) accesses the server using his or her own terminal, enters the keyword "diabetes," and sets search conditions.
[1326] The terminal provides the user with a search interface and displays search results based on the user's input.
[1327] Reward Allocation
[1328] The server analyzes the access log according to the user's data usage, and calculates and distributes rewards to the data provider.
[1329] Examples:
[1330] The server calculates the amount of compensation to each information provider based on the data used and distributes the compensation to the medical institution that provided the data.
[1331] The above-mentioned method enables safe anonymization and efficient use of medical information, providing a comprehensive solution for using medical data with peace of mind.
[1332] The flow of the identification process in the first embodiment will be described with reference to FIG.
[1333] Step 1: Receiving data
[1334] The server receives patient data from medical institutions and pharmacies via API or file upload. Data is often provided in CSV or JSON format. Data is sent using API requests or FTP servers. API requests or files are given as input, and the received data is saved to storage.
[1335] Specific behavior:
[1336] The server receives medical record information sent by an API request from a medical institution.
[1337] The server stores the received data in an AWS S3 bucket.
[1338] Step 2: Verify data integrity
[1339] The server uses a checksum to verify the integrity of the received data. The received data and checksum information are given as input, and the output is a confirmation of the data integrity.
[1340] Specific behavior:
[1341] The server verifies the checksum of the received medical record information.
[1342] If the server is able to verify the integrity of the data, it proceeds to the next processing step.
[1343] Step 3: Data Preprocessing
[1344] The server performs preprocessing to convert data provided in different formats into a unified format. The received data is given as input, and data in the unified format is obtained as output.
[1345] Specific behavior:
[1346] The server converts the received CSV format medical record information into JSON format.
[1347] The server stores the converted data in temporary storage.
[1348] Step 4: Personal Identification
[1349] The server uses natural language processing algorithms (e.g., SpaCy or NLTK) to extract personally identifiable information from the data (e.g., name, address, date of birth). The preprocessed data is given as input, and personally identifiable information is obtained as output.
[1350] Specific behavior:
[1351] The server uses SpaCy to extract "name," "address," and "date of birth" from the medical record information.
[1352] The server stores the extraction results as a list.
[1353] Step 5: Data Transformation
[1354] The server converts the identified personal information into a random identifier and performs anonymization processing such as blurring birthdate information into years. The extracted personal identification information is given as input, and anonymized data is obtained as output.
[1355] Specific behavior:
[1356] The server converts the extracted "name" into a random identifier and blurs the "birthday" to a year.
[1357] The server stores the anonymized data in temporary storage.
[1358] Step 6: Verify the anonymized data
[1359] The server verifies whether the converted data meets the specified criteria. The anonymized data is given as input, and the verification result indicating whether the criteria are met is obtained as output.
[1360] Specific behavior:
[1361] The server verifies the anonymity of the anonymized data.
[1362] If the criteria are not met, the server performs the anonymization process again.
[1363] Step 7: Save Data
[1364] The server stores the verified anonymized data in a secure database. The input is the verified anonymized data, and the output is the anonymized data stored in the database.
[1365] Specific behavior:
[1366] The server stores the anonymized medical record information in AWS RDS.
[1367] The server enforces encryption and access control on the database.
[1368] Step 8: Data reception and integrity check
[1369] The server receives the anonymized data provided by the medical information anonymization AI tool and performs a consistency check. The anonymized data is given as input, and the consistency check result is obtained as output.
[1370] Specific behavior:
[1371] The server receives the data provided by the medical information anonymization AI tool.
[1372] The server uses the checksum to verify the integrity of the data.
[1373] Step 9: Data organization
[1374] The server normalizes the received anonymized data and indexes it using Elasticsearch. The anonymized data is given as input, and the indexed data is obtained as output.
[1375] Specific behavior:
[1376] The server normalizes the anonymized data and indexes it using Elasticsearch.
[1377] Step 10: Search and Browse Functions
[1378] The terminal provides an interface for users to search and view anonymized medical information. The terminal receives user search criteria as input and displays search results as output.
[1379] Specific behavior:
[1380] A user accesses the server using a terminal and inputs search criteria.
[1381] The terminal provides the user with a search interface and displays search results from the server.
[1382] Step 11: Reward Allocation
[1383] The server analyzes the access log based on the user's data usage, calculates and distributes rewards to data providers, and receives the access log as input and the reward distribution results as output.
[1384] Specific behavior:
[1385] The server calculates the amount of remuneration to each information provider based on the data used.
[1386] The server distributes the calculated remuneration to each medical institution.
[1387] Through the above processing steps, the present invention realizes safe anonymization and efficient use of medical information.
[1388] (Application example 1)
[1389] Next, a description will be given of Application Example 1. In the following description, the data processing device 12 will be referred to as a "server" and the headset type terminal 314 will be referred to as a "terminal."
[1390] Medical information is highly confidential, and its handling requires strict privacy measures. However, real-time data acquisition and anonymization are difficult, and secure data handling is not ensured in many settings. Furthermore, there is a lack of interfaces for efficiently searching and viewing anonymized information, hindering progress in data utilization. Furthermore, there is a need for an efficient method for allocating rewards based on data usage.
[1391] The specific processing by the specific processing unit 290 of the data processing device 12 in the application example 1 is realized by the following means.
[1392] In this invention, the server includes means for acquiring medical information, means for identifying elements that can identify individuals from the acquired medical information, means for anonymizing the identified elements in accordance with the Personal Information Protection Act, means for verifying whether the anonymized information meets predetermined standards, means for securely storing the anonymized information, means for receiving and systematically organizing the anonymized medical information, means for providing an interface for searching and viewing the organized medical information, means for calculating rewards based on data usage and allocating them to data providers, and means for anonymizing and securely processing patient data in real time at medical sites using smart glasses, thereby enabling real-time anonymization, secure processing, and efficient utilization of medical information.
[1393] "Medical information" refers to personal medical records and health data held by medical institutions, such as patient charts and medication information.
[1394] "Means of acquisition" refers to methods or devices for collecting medical data via APIs, file uploads, etc.
[1395] A "personally identifiable element" is information that can be used to identify a specific individual, such as name, address, or date of birth.
[1396] "Anonymization means" refers to methods or technologies that convert personally identifiable information into random identifiers and anonymize data in accordance with the Personal Information Protection Act.
[1397] "Means of verification" refers to methods or techniques for verifying whether anonymized information meets predetermined standards.
[1398] "Secure storage means" refers to methods and technologies for safely storing anonymized data using encryption technology, strict access control, etc.
[1399] "Systematic organization means" refers to methods and technologies for normalizing and indexing the received anonymized medical data so that it can be easily searched and viewed.
[1400] A "search and browsing interface" is a user interface provided for users to search and browse anonymized medical information.
[1401] "Means for calculating and allocating rewards" means methods or technologies for automatically calculating and allocating rewards to data providers based on data usage.
[1402] "Means for real-time anonymization and secure processing of patient data using smart glasses" refers to methods and technologies for instantly anonymizing and securely processing patient data collected in medical settings using smart glasses.
[1403] The system embodying the present invention is designed to safely anonymize medical information and promote its use. This system is specifically realized by the following program.
[1404] The program's main components are a server, a device, and smart glasses. The server retrieves patient data from medical institutions and pharmacies via API or file upload. After retrieving the data, the server uses a natural language processing algorithm to identify personally identifiable information (such as name, address, and date of birth). The server then de-identifies the identified personal information by converting it into a random identifier and obscuring certain date information. The de-identified data is then verified to see if it meets predetermined criteria, and if so, stored in a secure database.
[1405] Furthermore, the anonymized medical information is systematically organized by the server. This organized data is normalized and indexed to facilitate search and viewing. Users can use an interface to search and view the anonymized medical information using their devices. Through this interface, users can quickly access the information they need by setting search conditions. When the data is used, the server calculates rewards based on the data usage and automatically distributes the rewards to the data provider.
[1406] Smart glasses are used in medical settings to anonymize and securely process patient data in real time. Doctors and medical staff wearing the smart glasses can process patient medical records in real time. A specific use case is to read patient data through the smart glasses, anonymize the information displayed on the screen in real time, and process it as securely shareable data. For example, a doctor at a hospital can use the smart glasses to read a patient's medical record information and share the data while protecting private information.
[1407] An example of a prompt is:
[1408] "I want to collect medical data from an API endpoint and identify and anonymize personal information in the returned data. Specifically, I want you to write a Python program that will replace names and addresses with "anonymous" and convert birthdates to "xxxx-xx-xx."
[1409] The above is a detailed embodiment of the present invention. This system realizes real-time anonymization of medical information, safe processing, and efficient data utilization.
[1410] The flow of the specific processing in the application example 1 will be described with reference to FIG.
[1411] Step 1:
[1412] The server retrieves patient data from medical institutions and pharmacies via API endpoints or file uploads. The inputs are the API endpoint URL and the uploaded file, and the output is the raw data stored on the server. Specifically, the server sends a request to the specified API endpoint and stores the returned data in secure storage.
[1413] Step 2:
[1414] The server uses a natural language processing algorithm to identify personally identifiable elements (such as name, address, and date of birth) from the acquired medical data. The input is raw data, and the output is a list of personally identifiable elements. Specifically, the server uses text analysis and pattern matching to extract personal information from the raw data and saves the identified elements in list format.
[1415] Step 3:
[1416] The server anonymizes the identified personal information in accordance with the Personal Information Protection Act. For example, it replaces names and addresses with random identifiers and blurs birthdays to a range. The input is a list of identified elements, and the output is anonymized data. Specifically, the server converts names and addresses to "anonymous" and birthdays to "xxxx-xx-xx."
[1417] Step 4:
[1418] The server verifies whether the anonymized information meets predetermined criteria. The input is the anonymized data, and the output is the verification result of whether the criteria are met. Specifically, the server performs an automatic check based on the anonymization guidelines, and if the criteria are not met, it performs additional anonymization processing.
[1419] Step 5:
[1420] The server stores the verified anonymized data in a secure database. The input is the verified anonymized data, and the output is the data stored in the database. Specifically, the server stores the data using encryption technology and strict access control.
[1421] Step 6:
[1422] The server receives and systematically organizes de-identified medical information. The input is existing de-identified data, and the output is organized data. Specifically, the server normalizes and indexes the data, converting it into a format that is easy to search and browse.
[1423] Step 7:
[1424] The device provides an interface that allows users to search and view anonymized medical information. The input is the user's search criteria, and the output is the search results displayed to the user. Specifically, the device accepts search criteria through the user interface, sends a query to the server, and retrieves and displays related information.
[1425] Step 8:
[1426] The server calculates rewards based on data usage and distributes them to data providers. The input is a data usage log, and the output is a reward calculation result. Specifically, the server analyzes the access log, calculates reward amounts based on the data used, and distributes them to each information provider.
[1427] Step 9:
[1428] Smart glasses are used to anonymize and securely process patient data in real time in medical settings. The input is the patient's medical record and treatment information, and the output is anonymized real-time data. Specifically, the smart glasses read the patient data, display personal information on the screen in an anonymized form, and convert the data into a format that can be safely shared when actually used.
[1429] Furthermore, an emotion engine that estimates the user's emotion may be further combined. That is, the identification processing unit 290 may estimate the user's emotion using the emotion identification model 59, and perform identification processing using the user's emotion.
[1430] MODE FOR CARRYING OUT THE INVENTION
[1431] This paper describes a system that safely anonymizes medical information and promotes its use, and combines it with an emotion engine that recognizes user emotions. This system is broadly composed of an AI tool for anonymizing medical information, an AI tool for collecting, viewing, and consulting, and an emotion engine.
[1432] AI tool for anonymizing medical information
[1433] Data collection
[1434] The server receives patient data (medical record information and medication information) from medical institutions and pharmacies via API or file upload. When receiving the data, it checks whether the data format is consistent and performs preprocessing as necessary to standardize the format.
[1435] Personal Information Identification
[1436] The server automatically identifies personally identifiable information (such as name, address, and date of birth) from the received patient data using natural language processing algorithms, employing text analysis and pattern matching techniques, and then lists the results.
[1437] Data Conversion
[1438] The server then anonymizes the identified personal information, specifically converting names and addresses into random identifiers and blurring birthdates and specific date data into ranges or general formats in accordance with the Personal Information Protection Act.
[1439] Data Check
[1440] The server verifies whether the converted data meets various standards, and if it does not meet certain anonymity standards, it performs additional anonymization processing.
[1441] Data storage
[1442] The server then stores the verified anonymized data in a secure database, where access control permissions are set and the data is protected using encryption technology.
[1443] AI tool for collection, viewing, and consultation
[1444] Data reception
[1445] The server receives the anonymized data provided by the medical information anonymization AI tool, and upon receiving it performs a data integrity check to ensure there are no missing or incorrect data.
[1446] Data organization
[1447] The server systematically organizes the received anonymized data, normalizing and indexing it to make it easier to search and view, thereby enabling efficient data management.
[1448] Providing search and browsing functionality
[1449] The terminal (user device) provides an interface that allows users to search and view anonymized medical information. Users can enter keywords and set conditions to search data.
[1450] Reward Allocation
[1451] The server automatically calculates and distributes rewards to data providers according to the user's data usage. This involves analyzing the data access log and calculating the reward amount for each information provider.
[1452] Adding an Emotion Engine
[1453] emotion recognition
[1454] The device will activate an emotion engine through user input and operations to recognize the user's emotional state, possibly using algorithms that extract emotions from text nuances or voice data.
[1455] Customize search results based on sentiment
[1456] The server customizes search results based on the user's emotions as recognized by the emotion engine. For example, if the user is feeling stressed, data related to stress reduction will be displayed preferentially.
[1457] Providing emotional feedback
[1458] The device provides appropriate feedback based on the user's emotions. For example, if the user is feeling anxious, the device provides an interface offering support and additional information.
[1459] Specific examples
[1460] Collection and anonymization of patient data from medical institutions
[1461] The server receives patient data from a medical institution via API, including medical records and medication information.
[1462] The server analyzes the received data and uses natural language processing to identify personally identifiable information such as name, address, and date of birth.
[1463] The server converts names to random identification IDs, blurs addresses to the region level, and converts birthdates to years.
[1464] The server automatically checks whether the anonymization has been performed properly, and if there are any defects, it performs the anonymization process again.
[1465] The server then encrypts the anonymized data after checking and stores it in a secure database.
[1466] When pharmaceutical companies use anonymized data
[1467] Users (researchers at pharmaceutical companies) access the server using their own terminals.
[1468] The terminal provides a search interface to the user, allowing the user to input keywords to search for data relating to a particular disease.
[1469] The server quickly extracts data that matches the search criteria from the indexed, anonymized database.
[1470] The terminal displays the search results to the user, allowing the user to view the details.
[1471] The server analyzes the user's data usage log and distributes appropriate rewards to the data providers.
[1472] Use of emotion engine
[1473] While the user (a pharmaceutical company researcher) is using the data, the emotion engine detects the user's anxiety.
[1474] The server customizes search results based on the output of the emotion engine, prioritizing the display of data that may reduce anxiety.
[1475] Based on feedback from the emotion engine, the device provides support and additional information to the user, providing information to reduce anxiety.
[1476] Through the above steps, the present invention realizes anonymization and efficient use of medical information, and furthermore, by customizing search results taking into account the user's emotions, more personalized data utilization becomes possible.
[1477] The processing flow will be explained below.
[1478] AI tool for anonymizing medical information
[1479] Processing steps from data collection to anonymization
[1480] Step 1:
[1481] The server receives patient data (medical record information and medication information) from medical institutions and pharmacies via API or file upload. When receiving the data, it checks whether the data format is appropriate, preprocesses it as necessary, and standardizes the format.
[1482] Step 2:
[1483] The server automatically identifies personally identifiable information (such as name, address, and date of birth) from the received patient data using natural language processing algorithms, and then uses text analysis techniques to extract and compile this information into a list.
[1484] Step 3:
[1485] The server will anonymize the identified personal information by converting names and addresses into random identifiers (e.g., UUIDs) and converting birthdates and specific date data into ranges or years.
[1486] Step 4:
[1487] The server automatically verifies whether the anonymized data meets the standards of the Personal Information Protection Act, and if the anonymity is insufficient, it performs additional anonymization processing.
[1488] Step 5:
[1489] The server stores the verified and anonymized data in a secure database, which uses strict access controls and encryption technology to protect the data.
[1490] AI tool for collection, viewing, and consultation
[1491] Processing steps from receiving data to allocating rewards
[1492] Step 1:
[1493] The server receives the anonymized data provided by the medical information anonymization AI tool, and checks the data integrity upon receipt to ensure there are no missing or incorrect data.
[1494] Step 2:
[1495] The server normalizes the received anonymously processed data and indexes it for easy searching and browsing. It organizes each field into categories to achieve efficient data management.
[1496] Step 3:
[1497] The terminal (user device) provides an interface for users to search and view anonymized medical information. Users input keywords, set search conditions, search data, and obtain results.
[1498] Step 4:
[1499] The server quickly extracts anonymized data that matches the user's search criteria and displays it as a search result.
[1500] Step 5:
[1501] The server analyzes the user's data usage log and automatically calculates and distributes rewards to the data provider. The server calculates the reward amount based on the access log and distributes the reward to the specified account.
[1502] Use of emotion engine
[1503] Processing steps from emotion recognition to providing feedback
[1504] Step 1:
[1505] The device activates an emotion engine through user input and operations to recognize the user's emotional state, using algorithms that extract emotions from text nuances and voice data.
[1506] Step 2:
[1507] The server customizes search results based on the user's emotions as recognized by the emotion engine. For example, if the user is feeling stressed, data related to stress reduction will be displayed preferentially.
[1508] Step 3:
[1509] The device provides feedback based on the user's emotions based on the output of the emotion engine. For example, if the user is feeling anxious, the device provides an interface that presents appropriate support and additional information.
[1510] Specific examples
[1511] Collection and anonymization of patient data from medical institutions
[1512] Step 1:
[1513] The server receives patient data from medical institutions via API, including medical records and medication information.
[1514] Step 2:
[1515] The server analyzes the received data and uses natural language processing algorithms to identify personally identifiable information such as name, address, and date of birth, compiling them into a list.
[1516] Step 3:
[1517] The server converts the identified personal information into a random identification ID, blurs addresses to the region level, and converts birthdates to years.
[1518] Step 4:
[1519] The server automatically checks whether the anonymized data meets the standards for protecting personal information. If there are any deficiencies, the data is anonymized again.
[1520] Step 5:
[1521] Once the checks are complete, the server encrypts and stores the anonymized data in a secure database.
[1522] When pharmaceutical companies use anonymized data
[1523] Step 1:
[1524] Users (researchers at pharmaceutical companies) access the server using their own terminals.
[1525] Step 2:
[1526] The terminal provides a search interface to the user, allowing the user to input keywords to search for data relating to a particular disease.
[1527] Step 3:
[1528] The server quickly extracts data that matches the search criteria from the indexed, anonymized database.
[1529] Step 4:
[1530] The terminal displays the search results to the user, allowing the user to view the details.
[1531] Step 5:
[1532] The server analyzes the user's data usage log and distributes appropriate rewards to the data providers.
[1533] Use of emotion engine
[1534] Step 1:
[1535] While the user (a pharmaceutical company researcher) is using the data, the emotion engine detects the user's anxiety.
[1536] Step 2:
[1537] The server customizes search results based on the output of the emotion engine, prioritizing the display of data that may reduce anxiety.
[1538] Step 3:
[1539] Based on feedback from the emotion engine, the device provides the user with appropriate support and additional information to reduce anxiety.
[1540] Through the above steps, the present invention realizes anonymization and efficient use of medical information, and furthermore, by customizing search results taking into account the user's emotions, more personalized data utilization becomes possible.
[1541] Example 2
[1542] Next, a description will be given of Example 2. In the following description, the data processing device 12 will be referred to as a "server" and the headset type terminal 314 will be referred to as a "terminal."
[1543] The importance of protecting personal information is increasing in modern medical information management. However, systems that safely anonymize medical data and promote its use are not widely available. Furthermore, the user experience is not fully satisfactory because there is no feedback or customized search results that take into account the user's emotional state when using the data. Therefore, a system that safely anonymizes medical data and provides information based on the user's emotional state is needed.
[1544] The identification process by the identification processing unit 290 of the data processing device 12 in the second embodiment is realized by the following means. In this invention, the server includes a means for acquiring medical information, a means for identifying elements that can identify an individual from the acquired medical information, and a means for anonymizing the identified elements in accordance with the Personal Information Protection Act. This makes it possible to safely anonymize medical information and provide information according to the user's emotional state.
[1545] "Medical information" refers to medical data such as patient medical records, prescription information, and test results.
[1546] "Anonymization" refers to the process of removing or transforming personally identifiable information so that the data provider cannot be identified.
[1547] "Natural language processing algorithms" refer to computational methods and technologies for automatically parsing, understanding, and generating human language.
[1548] "Anonymized Data" means data that has been made anonymous by removing or transforming personal information.
[1549] "Emotional state" refers to a psychological state that is determined based on a user's actions or inputs.
[1550] "Feedback" refers to the information or actions that a system provides in response to a user's behavior or state.
[1551] "Interface" refers to the screens and functions that allow users to interact with the system.
[1552] "Reward calculation" refers to the process of calculating rewards to data providers in accordance with the user's use of data.
[1553] "Access log" refers to data that records the history of users accessing a system.
[1554] A "database" refers to a system that stores information in an organized manner and makes it easy to search and manage.
[1555] "Random identifier" refers to a unique identification code that is randomly generated so as not to identify personal information.
[1556] This invention describes a system that safely anonymizes medical information and promotes its use, as well as a system that combines an emotion engine that recognizes user emotions. The detailed configuration and operation of this system are described below.
[1557] AI tool for anonymizing medical information
[1558] The AI tool for anonymizing medical information in this system runs on a server, primarily to perform the following processes:
[1559] 1. Data Collection:
[1560] The server receives patient data (medical record information and medication information) from medical institutions and pharmacies via API or file upload. For example, it obtains JSON format data from a medical institution's system, checks the integrity of the data upon reception, preprocesses it, and standardizes it into a standard format.
[1561] 2. Personal Information Identification:
[1562] The server uses natural language processing algorithms to automatically identify personally identifiable information (such as name, address, and date of birth) from the received data, and then uses text analysis and pattern matching techniques to extract and list personal information.
[1563] 3. Data conversion:
[1564] The server then anonymizes the identified personal information. Specifically, it converts names and addresses into random IDs and blurs birthdays to years. This ensures that the data is securely anonymized.
[1565] 4. Data Check:
[1566] The server verifies whether the converted data meets the anonymity criteria, and if not, performs additional anonymization processing.
[1567] 5. Data Retention:
[1568] The server then stores the verified anonymized data in a secure database, where access control permissions are set and the data is protected using encryption technology.
[1569] AI tool for collection, viewing, and consultation
[1570] This tool is designed to efficiently utilize anonymized medical data and performs the following processes:
[1571] 1. Data reception:
[1572] The server receives the anonymized data provided by the medical information anonymization AI tool and performs a consistency check to ensure there are no missing or incorrect data.
[1573] 2. Data reduction:
[1574] The server normalizes the anonymized data it receives and indexes it for easy searching and browsing.
[1575] 3. Providing search and browsing functionality:
[1576] The terminal (user device) provides an interface for searching and viewing anonymized medical information. Users can search for data by entering keywords or conditions.
[1577] 4. Reward Allocation:
[1578] The server calculates and automatically distributes rewards to data providers based on the user's data usage. It analyzes access logs and calculates reward amounts based on factors such as frequency of usage.
[1579] Adding an Emotion Engine
[1580] This system is integrated with an emotion engine that can recognize user emotions. The operation is shown below.
[1581] 1. Emotion recognition:
[1582] The device activates an emotion engine through user input and operations to recognize the user's emotional state, using algorithms that extract emotions from text nuances and voice data.
[1583] 2. Personalize search results based on sentiment:
[1584] The server customizes search results based on the user's emotions as recognized by the emotion engine. For example, if the user is feeling stressed, data related to stress reduction will be displayed preferentially.
[1585] 3. Providing emotional feedback:
[1586] The device provides appropriate feedback based on the user's emotions, for example, suggesting support information or additional resources if the user is feeling anxious.
[1587] Specific examples
[1588] Collection and anonymization of patient data from medical institutions
[1589] The server receives patient data from medical institutions via API, including medical records and medication information.
[1590] The server analyzes the received data and uses natural language processing to identify personally identifiable information such as name, address, and date of birth.
[1591] The server converts names to random identification IDs, blurs addresses to the region level, and converts birthdates to years.
[1592] The server automatically checks whether the anonymization has been performed properly, and if there are any deficiencies, performs the anonymization process again.
[1593] The server then encrypts the anonymized data after checking and stores it in a secure database.
[1594] When pharmaceutical companies use anonymized data
[1595] Users (researchers at pharmaceutical companies) access the server using their own terminals.
[1596] The terminal provides a search interface to the user, allowing the user to input keywords to search for data relating to a particular disease.
[1597] The server quickly extracts data that matches the search criteria from the indexed, anonymized database.
[1598] The terminal displays the search results to the user, allowing the user to view the details.
[1599] The server analyzes the user's data usage log and distributes appropriate rewards to the data providers.
[1600] Use of emotion engine
[1601] While the user (a pharmaceutical company researcher) is using the data, the emotion engine detects the user's anxiety.
[1602] The server customizes search results based on the output of the emotion engine, prioritizing the display of data that may reduce anxiety.
[1603] Based on feedback from the emotion engine, the device provides support and additional information to the user, providing information to reduce anxiety.
[1604] Example prompts to be input to the generative AI model
[1605] 1. Please explain the AI tool for anonymizing medical information.
[1606] 2. What are the specific steps to de-identify certain medical data?
[1607] 3. Please elaborate on how you use the sentiment engine to customize search results.
[1608] Through the above steps, the present invention realizes anonymization and efficient use of medical information, and furthermore, by customizing search results taking into account the user's emotions, more personalized data utilization becomes possible.
[1609] The flow of the identification process in the second embodiment will be described with reference to FIG.
[1610] AI tool for anonymizing medical information
[1611] Step 1:
[1612] The server receives patient data (medical record information and medication information) from medical institutions and pharmacies via API or file upload. It checks the format of the received data and performs preprocessing as necessary to unify the format.
[1613] Input: Patient data from a medical institution (e.g., JSON file)
[1614] Output: Patient data in a unified format
[1615] Specific operation: Check the format of the received data (for example, date format or name notation) and normalize and unify it.
[1616] Step 2:
[1617] The server uses natural language processing algorithms to automatically identify personally identifiable information (such as name, address, date of birth, etc.) from the received data.
[1618] Input: Patient data in a unified format
[1619] Output: Data listing personally identifiable information
[1620] Specific operation: Extracts names, addresses, and birthdays using regular expressions and text analysis, and saves them in list format.
[1621] Step 3:
[1622] The server anonymizes the identified personal information, converting names and addresses to random identifiers and blurring birth dates to years.
[1623] Input: Data listing personally identifiable information
[1624] Output: Anonymized data
[1625] Specific behavior: Converts names to random IDs, addresses to city level, and birthdays to year level. For example, converts "Tanaka Ichiro" to "User ID 12345."
[1626] Step 4:
[1627] The server verifies whether the converted data meets the anonymity criteria, and if it does not, it anonymizes the data again.
[1628] Input: Anonymized data
[1629] Output: Verified and anonymized data
[1630] What it does: Compare the results of the anonymization algorithm against a checklist and reprocess any gaps or deficiencies.
[1631] Step 5:
[1632] The server stores the verified and anonymized data in a secure database, with access control permissions and encryption technology to protect the data.
[1633] Input: Verified, anonymized data
[1634] Output: Securely stored data
[1635] What it does: Encrypts data using AES-256 encryption technology and stores it in a database with access controls.
[1636] AI tool for collection, viewing, and consultation
[1637] Step 1:
[1638] The server receives the anonymized data provided by the medical information anonymization AI tool and performs a consistency check to ensure there are no missing or incorrect data.
[1639] Input: Anonymously processed data
[1640] Output: Integrity checked data
[1641] What it does: Validates data integrity, checks for missing data and inconsistencies, and corrects them as needed.
[1642] Step 2:
[1643] The server normalizes the anonymized data it receives and indexes it for easy searching and browsing.
[1644] Input: Data that has been checked for consistency
[1645] Output: Normalized and indexed data
[1646] What it does: Normalizes database fields and performs indexing to facilitate keyword and criteria searches.
[1647] Step 3:
[1648] The device provides an interface for searching and viewing anonymized medical information.
[1649] Input: Keywords and conditions from the user
[1650] Output: Search results
[1651] What it does: Provides an interface that allows users to enter keywords in a search box, set conditions, and search for data.
[1652] Step 4:
[1653] The server calculates and automatically distributes rewards to data providers based on the user's data usage.
[1654] Input: User access log
[1655] Output: Reward calculation results, reward distribution information
[1656] Specific operation: Analyzes access logs, calculates reward amounts based on frequency of use and importance of data, and automatically distributes them to each provider.
[1657] Adding an Emotion Engine
[1658] Step 1:
[1659] The terminal activates an emotion engine through user input and operations to recognize the user's emotional state.
[1660] Input: User input and operation data
[1661] Output: Perceived emotional state
[1662] What it does: Analyzes user input text and voice data and applies algorithms to extract emotions.
[1663] Step 2:
[1664] The server customizes search results based on the user's emotions recognized by the emotion engine.
[1665] Input: Recognized emotional state, user search criteria
[1666] Output: Customized search results
[1667] What it does: It applies a customization algorithm based on your emotional state to prioritize relevant search results.
[1668] Step 3:
[1669] The terminal provides appropriate feedback based on the user's emotions.
[1670] Input: Perceived emotional state
[1671] Output: A feedback message to the user.
[1672] What it does: If the user is feeling anxious, provide an interface that suggests support information or additional resources.
[1673] (Application example 2)
[1674] Next, a description will be given of Application Example 2. In the following description, the data processing device 12 will be referred to as a "server" and the headset type terminal 314 will be referred to as a "terminal."
[1675] In addition to anonymizing and securely storing medical information and making it easier to search and view, flexible feedback and electronic payment functions that take into account the user's emotions when using the data are required. In particular, it is a challenge to alleviate users' anxiety and provide a reassuring environment by enabling anonymous settlement of medical expenses and providing customized information based on the user's emotional state during use.
[1676] The identification process by the identification processing unit 290 of the data processing device 12 in Application Example 2 is realized by the following means. In this invention, the server includes means for acquiring medical information, means for identifying elements that can identify an individual from the acquired medical information, means for anonymizing the identified elements in accordance with the Personal Information Protection Act, means for verifying whether the anonymized information meets predetermined criteria, means for securely storing the anonymized information, means for receiving and systematically organizing the anonymized medical information, means for providing an interface for searching and viewing the organized medical information, means for calculating rewards based on data usage and allocating them to data providers, means for making payments based on the anonymized medical information, and means for activating an emotion engine that recognizes the user's emotional state and customizing search results. This enables anonymous settlement of medical expenses and provides information customized to the user's emotional state.
[1677] "Medical information" refers to patient medical records, medication information, and health status data.
[1678] "Personally identifiable information" refers to information that can identify a specific individual, such as name, address, or date of birth.
[1679] "Anonymizing" refers to the act of removing or converting personally identifiable information so that it is no longer possible to identify a specific individual.
[1680] "Verify" refers to the act of checking whether anonymized information meets specified standards.
[1681] "Storing" refers to the act of recording information in a certain place so that it will not be lost.
[1682] "Systematically organizing" refers to the act of classifying and arranging information according to certain rules so that it can be managed and used efficiently.
[1683] "Interface" refers to the screens and operating means through which users interact with the system.
[1684] "Calculating and allocating rewards" refers to the act of calculating the amount of rewards based on the use of data and distributing the rewards to appropriate providers.
[1685] "Making a payment" refers to the act of carrying out a transaction to pay for goods or services.
[1686] "Recognizing emotional state" refers to the act of the system detecting and judging the user's emotions (e.g., anxiety, relief, stress, etc.).
[1687] An "emotion engine" refers to a software component for analyzing emotions through user input and operations.
[1688] "Customize" refers to the act of changing or adjusting content or presentation to suit specific conditions or circumstances.
[1689] MODE FOR CARRYING OUT THE INVENTION
[1690] The system according to the present invention is configured as follows, and the specific implementation thereof will be described in detail below.
[1691] 1. System Program
[1692] overview
[1693] This system not only anonymizes medical information and securely stores and uses it, but also recognizes users' emotions to provide customized information.It also enables secure electronic payments using anonymized medical information.
[1694] 2. Explanation of program processing
[1695] Required Hardware and Software
[1696] Hardware:
[1697] Servers (e.g., high-performance computing servers)
[1698] User device (e.g., smartphone)
[1699] software:
[1700] Natural language processing engines (e.g. BERT)
[1701] Database management systems (e.g. MongoDB)
[1702] Encryption technology (e.g. AES encryption)
[1703] Emotion recognition algorithms (e.g., Sentiment Analysis API)
[1704] Acquisition and de-identification of medical information
[1705] The server receives patient data from healthcare providers via API. It uses a natural language processing engine to identify personally identifiable information and converts it into a random identifier. It also obscures certain dates and medical history information. The anonymized data is then securely stored in a database using AES encryption.
[1706] Search and browse anonymized data
[1707] Users access the server using their smartphones to search for anonymized medical data. The server indexes the received anonymized data and organizes it into a searchable and viewable format. Users can search for data by entering keywords, and the search results are displayed on the interface.
[1708] Use of emotion engine
[1709] When a user searches or browses data, an emotion recognition algorithm installed on the smartphone analyzes the user's emotions. If the emotion engine detects anxiety or stress, the server will provide customized search results corresponding to that emotion. For example, it will display support information to reduce anxiety or reassuring messages.
[1710] Making electronic payments
[1711] Medical expenses can be paid safely and anonymously based on anonymized medical data. Users complete the payment procedure using their smartphone, and the information is securely processed by the server.
[1712] 3. Specific Examples
[1713] Medical expense settlement scenario
[1714] After a user receives medical treatment at a medical institution, the medical expenses are settled using anonymized data via a smartphone app.
[1715] The server uses natural language processing to identify and anonymize personal information from the received billing data.
[1716] Electronic payments are made using anonymized information, which is then stored using AES encryption technology.
[1717] Feedback scenario using emotion recognition
[1718] The emotion engine detects anxiety while users are browsing medical information on their smartphones.
[1719] The server prioritizes displaying medical and support information to address anxiety, increasing the user's sense of security.
[1720] 4. Examples of prompts
[1721] Please explain the process by which users receive medical billing data from medical institutions via a smartphone app, securely settle bills, and how the anonymized medical data will be used afterwards. Please also include a function to analyze user sentiment and provide support information.
[1722] This system enables anonymization, secure storage, search and viewing of medical information, as well as customized information provision according to emotional state and secure electronic payment.
[1723] The flow of the specific processing in the application example 2 will be described with reference to FIG.
[1724] Step 1:
[1725] The server receives patient data from medical institutions via API. The received data includes medical records and medication information. The server checks whether the format of the received data is standardized, and performs preprocessing as necessary to standardize the data format. The input at this stage is patient data from medical institutions, and the output is data in a standardized format.
[1726] Step 2:
[1727] The server uses a natural language processing engine to identify personally identifiable elements (such as name, address, and date of birth) from the received data. Specifically, it uses text analysis and pattern matching techniques to create a list of these elements. The input to this stage is data in a standardized format, and the output is a list containing personally identifiable elements.
[1728] Step 3:
[1729] The server anonymizes the identified personally identifiable information by converting names and addresses into random identifiers and obscuring certain dates and medical history information. The input to this stage is a list of personally identifiable information, and the output is anonymized data.
[1730] Step 4:
[1731] The server verifies whether the anonymized information meets the predetermined criteria. If it does not meet the certain anonymity criteria, it performs additional anonymization processing. The input of this stage is the anonymized data, and the output is the verified anonymized data.
[1732] Step 5:
[1733] The server securely stores the anonymized data in a database using AES encryption. Database access control permissions are set during storage to enhance data protection. The input to this stage is the verified anonymized data, and the output is a database containing the encrypted data.
[1734] Step 6:
[1735] Users access the server using their smartphones to search for anonymized medical data. The device provides a search interface where users input keywords and conditions. The input at this stage is the user's search query, and the output is the search conditions sent to the server.
[1736] Step 7:
[1737] The server compares the indexed anonymized database based on the received search query and generates search results. The input at this stage is the user's search criteria, and the output is the search results that match the criteria.
[1738] Step 8:
[1739] The user's terminal displays the search results, allowing the user to view the data. The input at this stage is the search results sent from the server, and the output is a screen displaying the search results.
[1740] Step 9:
[1741] While the user is searching or browsing data, the device uses emotion recognition algorithms to analyze the user's emotional state. For example, emotions can be extracted from text nuances or voice data. The input at this stage is the user's operation data or input text, and the output is data indicating the user's emotional state.
[1742] Step 10:
[1743] The server customizes search results based on the user's emotions recognized by the emotion engine. For example, if the user is feeling anxious, support information that will alleviate the anxiety will be displayed preferentially. The input of this stage is the user's emotional data, and the output is customized search results.
[1744] Step 11:
[1745] The user's device displays customized search results and feedback, and provides appropriate support information to the user. Specifically, reassuring messages and notifications are displayed. The input of this stage is the customized search results and feedback information, and the output is the customized information displayed to the user.
[1746] Step 12:
[1747] Users use a smartphone app to make payments based on anonymized medical data. The server securely processes the payment data while maintaining its anonymity and stores it using AES encryption technology. The input at this stage is the user's payment information, and the output is securely processed payment completion data.
[1748] The specific processing unit 290 transmits the result of the specific processing to the headset type terminal 314. In the headset type terminal 314, the control unit 46A causes the speaker 240 and the display 343 to output the result of the specific processing. The microphone 238 acquires audio indicating a user input regarding the result of the specific processing. The control unit 46A transmits audio data indicating the user input acquired by the microphone 238 to the data processing device 12. In the data processing device 12, the specific processing unit 290 acquires the audio data.
[1749] The data generation model 58 is a so-called generative AI (Artificial Intelligence). An example of the data generation model 58 is ChatGPT (Internet Search<URL: https: / / openai.com / blog / chatgpt> ), Gemini (Internet search <url: https: gemini.google.com ?hl="ja">) and other generation AIs. The data generation model 58 is obtained by performing deep learning on a neural network. A prompt including an instruction is input to the data generation model 58, and inference data such as voice data indicating voice, text data indicating text, and image data indicating an image is also input. The data generation model 58 performs inference on the input inference data in accordance with the instruction indicated by the prompt, and outputs the inference result in a data format such as voice data and text data. Here, inference refers to, for example, analysis, classification, prediction, and / or summarization.
[1750] In the above embodiment, an example was given in which the specific processing is performed by the data processing device 12, but the technology of the present disclosure is not limited to this, and the specific processing may be performed by the headset type terminal 314.
[1751] [Fourth embodiment]
[1752] FIG. 7 shows an example of the configuration of a data processing system 410 according to the fourth embodiment.
[1753] 7, a data processing system 410 includes a data processing device 12 and a robot 414. An example of the data processing device 12 is a server.
[1754] The data processing device 12 includes a computer 22, a database 24, and a communication I / F 26. The computer 22 is an example of a "computer" according to the technology of the present disclosure. The computer 22 includes a processor 28, a RAM 30, and a storage 32. The processor 28, the RAM 30, and the storage 32 are connected to a bus 34. The database 24 and the communication I / F 26 are also connected to the bus 34. The communication I / F 26 is connected to a network 54. Examples of the network 54 include a WAN (Wide Area Network) and / or a LAN (Local Area Network).
[1755] The robot 414 includes a computer 36, a microphone 238, a speaker 240, a camera 42, a communication I / F 44, and a control target 443. The computer 36 includes a processor 46, a RAM 48, and a storage 50. The processor 46, the RAM 48, and the storage 50 are connected to a bus 52. The microphone 238, the speaker 240, the camera 42, and the control target 443 are also connected to the bus 52.
[1756] The microphone 238 receives instructions and the like from the user 20 by receiving voice uttered by the user 20. The microphone 238 captures the voice uttered by the user 20, converts the captured voice into audio data, and outputs it to the processor 46. The speaker 240 outputs audio in accordance with instructions from the processor 46.
[1757] Camera 42 is a small digital camera equipped with an optical system including a lens, aperture, and shutter, and an imaging element such as a CMOS (Complementary Metal-Oxide-Semiconductor) image sensor or a CCD (Charge Coupled Device) image sensor, and captures images of the surroundings of user 20 (for example, an imaging range defined by an angle of view equivalent to the field of vision of a typical healthy person).
[1758] The communication I / F 44 is connected to a network 54. The communication I / Fs 44 and 26 are responsible for the exchange of various information between the processor 46 and the processor 28 via the network 54. The exchange of various information between the processor 46 and the processor 28 using the communication I / Fs 44 and 26 is carried out in a secure state.
[1759] The control object 443 includes a display device, LEDs in the eyes, and motors for driving the arms, hands, and feet. The posture and gestures of the robot 414 are controlled by controlling the motors of the arms, hands, and feet. Some of the emotions of the robot 414 can be expressed by controlling these motors. In addition, the facial expressions of the robot 414 can also be expressed by controlling the light emission state of the LEDs in the eyes of the robot 414.
[1760] Fig. 8 shows an example of the main functions of the data processing device 12 and the robot 414. As shown in Fig. 8, in the data processing device 12, a specific process is performed by the processor 28. A specific process program 56 is stored in the storage 32.
[1761] The specific processing program 56 is an example of a "program" according to the technology of the present disclosure. The processor 28 reads the specific processing program 56 from the storage 32 and executes the read specific processing program 56 on the RAM 30. The specific processing is realized by the processor 28 operating as a specific processing unit 290 in accordance with the specific processing program 56 executed on the RAM 30.
[1762] The storage 32 stores a data generation model 58 and an emotion identification model 59. The data generation model 58 and the emotion identification model 59 are used by the identification processing unit 290.
[1763] In the robot 414, the processor 46 performs the reception output process. A reception output program 60 is stored in the storage 50. The processor 46 reads the reception output program 60 from the storage 50 and executes the read reception output program 60 on the RAM 48. The reception output process is realized by the processor 46 operating as the control unit 46A in accordance with the reception output program 60 executed on the RAM 48.
[1764] Next, a description will be given of the specific processing performed by the specific processing unit 290 of the data processing device 12. In the following description, the data processing device 12 will be referred to as a "server" and the robot 414 will be referred to as a "terminal."
[1765] MODE FOR CARRYING OUT THE INVENTION
[1766] This paper describes a system for safely anonymizing medical information and promoting its use. This system is broadly composed of an AI tool for anonymizing medical information and an AI tool for collecting, viewing, and consulting on medical information.
[1767] AI tool for anonymizing medical information
[1768] Data collection
[1769] The server receives patient data (medical records and medication information) in multiple formats from medical institutions and pharmacies. For example, it collects data via API or file upload and stores it in secure storage. If necessary, it performs preprocessing to unify the data format.
[1770] Personal Information Identification
[1771] The server automatically identifies personally identifiable information (such as name, address, date of birth, etc.) from the received data using natural language processing algorithms, using text analysis and pattern matching techniques, and then lists the results.
[1772] Data Conversion
[1773] The server anonymizes identified personal information in a manner compliant with the Personal Information Protection Act, for example, by replacing names and addresses with random identifiers and blurring birthdates and specific date data into ranges or general formats.
[1774] Data Check
[1775] The server verifies whether the converted data meets various standards, and if it does not meet certain anonymity standards, it performs additional anonymization processing.
[1776] Data storage
[1777] The server stores the verified and anonymized data in a secure database, which is protected by strict access controls and encryption technology.
[1778] AI tool for collection, viewing, and consultation
[1779] Data reception
[1780] The server receives the anonymized data provided by the medical information anonymization AI tool and checks the integrity of the data upon receipt.
[1781] Data organization
[1782] The server organizes the received anonymized data in a systematic manner, normalizing and indexing it for easy searching and browsing, thereby making data organization more cohesive and efficient.
[1783] Providing search and browsing functionality
[1784] The terminal (user device) provides an interface that allows users to search and view anonymized medical information. For example, if a user wants to search for information about a certain disease, they enter keywords, set search conditions, and retrieve data.
[1785] Reward Allocation
[1786] The server automatically calculates and distributes rewards to data providers according to the user's data usage. This involves analyzing the data access log and calculating the reward amount for each information provider.
[1787] Example
[1788] Example 1: Collecting and anonymizing patient data from medical institutions
[1789] The server receives patient medical record information from a medical institution using an API.
[1790] The server uses a natural language processing algorithm to identify the name, address, and date of birth from the received data.
[1791] The server converts these personal details into a random identifier and blurs the "birthday" information to a year.
[1792] The server automatically checks whether the anonymized data meets the standards and, if OK, stores it in a secure database.
[1793] Example 2: Pharmaceutical companies search and utilize anonymized data
[1794] Users (researchers at pharmaceutical companies) access the server using their own terminals.
[1795] The terminal provides the user with a search interface, and the user sets search conditions by entering the keyword "diabetes."
[1796] The server retrieves and displays relevant information from an indexed, anonymized database.
[1797] The server calculates and distributes remuneration to the medical institution that provided the data based on the data used.
[1798] Through the above steps, the present invention enables the anonymization and efficient utilization of medical information, and provides a solution for safely handling medical data.
[1799] The processing flow will be explained below.
[1800] AI tool for anonymizing medical information
[1801] Processing steps from data collection to anonymization
[1802] Step 1:
[1803] The server receives patient data from medical institutions and pharmacies via API or file upload. Upon receiving the data, it checks whether the data format is consistent and performs preprocessing as necessary to standardize the format.
[1804] Step 2:
[1805] The server identifies personally identifiable information (such as name, address, and date of birth) from the received patient data by analyzing the text using a natural language processing algorithm and compiling the information into an extracted list.
[1806] Step 3:
[1807] The server anonymizes the identified personal information. Specifically, in accordance with the Personal Information Protection Act, it converts names and addresses into random identifiers (e.g., UUIDs), and converts birthdays and specific dates into ranges or obscured information (e.g., leaving only the year of the date).
[1808] Step 4:
[1809] The server verifies the anonymized data, conducting automated checks to ensure that it meets the standards in terms of anonymity, and if there are any deficiencies, performs additional anonymization processes.
[1810] Step 5:
[1811] The server then stores the verified anonymized data in a secure database, where access control permissions are set and the data is protected using encryption technology.
[1812] AI tool for collection, viewing, and consultation
[1813] Processing steps from receiving data to allocating rewards
[1814] Step 1:
[1815] The server receives the anonymized data provided by the medical information anonymization AI tool, and upon receiving it performs a data integrity check to ensure there are no missing or incorrect data.
[1816] Step 2:
[1817] The server organizes the received anonymously processed data, normalizes the data, and performs indexing to make it easier to search and view, thereby enabling efficient data management.
[1818] Step 3:
[1819] The device provides a user interface for users to search and view anonymized medical information. Users can input keywords and set conditions to search for data.
[1820] Step 4:
[1821] The server displays the anonymized data as a search result and allows the user to view the details.
[1822] Step 5:
[1823] The server calculates and distributes rewards to data providers (medical institutions and pharmacies) based on the user's data usage. It analyzes the data access log and calculates the reward amount based on that.
[1824] Specific examples
[1825] Collection and anonymization of patient data from medical institutions
[1826] Step 1:
[1827] The server receives patient data via API from Medical Institution A. This data includes medical records and medication information.
[1828] Step 2:
[1829] The server analyzes the received data and uses natural language processing to identify personally identifiable information such as name, address, and date of birth.
[1830] Step 3:
[1831] The server converts names to random identification IDs, blurs addresses to the region level, and converts birthdates to years.
[1832] Step 4:
[1833] The server automatically checks whether the anonymization has been performed properly, and if there are any defects, it performs the anonymization process again.
[1834] Step 5:
[1835] The server then encrypts the anonymized data after checking and stores it in a secure database.
[1836] When pharmaceutical companies use anonymized data
[1837] Step 1:
[1838] Users (researchers at pharmaceutical companies) access the server using their own terminals.
[1839] Step 2:
[1840] The terminal provides a search interface to the user, allowing the user to input keywords to search for data relating to a particular disease.
[1841] Step 3:
[1842] The server quickly extracts data that matches the search criteria from the indexed, anonymized database.
[1843] Step 4:
[1844] The terminal displays the search results to the user, allowing the user to view the details.
[1845] Step 5:
[1846] The server analyzes the user's data usage log and distributes appropriate rewards to the data providers.
[1847] Example 1
[1848] Next, a description will be given of Example 1. In the following description, the data processing device 12 will be referred to as a "server" and the robot 414 will be referred to as a "terminal."
[1849] Currently, it is difficult to safely anonymize medical information and use it efficiently. In particular, the process of acquiring medical information, standardizing it into a specific format, identifying personally identifiable elements using natural language processing, and then anonymizing it is complex, and there is no system that appropriately rewards users for using anonymized information. Therefore, while there is a need to simultaneously ensure the safety and usefulness of medical data, current technology does not adequately achieve this.
[1850] The specific processing by the specific processing unit 290 of the data processing device 12 in the first embodiment is realized by the following means.
[1851] In this invention, the server includes means for acquiring medical information, means for identifying elements that can identify an individual from the acquired medical information, means for anonymizing the identified elements in accordance with the Personal Information Protection Act, means for verifying whether the anonymized information meets predetermined standards, means for securely storing the anonymized information, means for receiving and systematically organizing the anonymized medical information, means for providing an interface for searching and viewing the organized medical information, means for calculating rewards based on data usage and distributing them to data providers, means for preprocessing the anonymized medical information, means for standardizing the format of the preprocessed information, means for converting the anonymized information into a random identifier and blurring specific dates to years, and means for verifying the integrity of the anonymized information using a checksum, thereby enabling safe anonymization and efficient use of medical information.
[1852] "Medical information" refers to health-related data recorded and managed by medical institutions and pharmacies, such as patient medical records and medication information.
[1853] "Means of acquisition" refers to the process of receiving information from medical institutions and pharmacies using methods such as APIs or file uploads.
[1854] "Means of identification" refers to techniques that use natural language processing algorithms and pattern matching to extract elements within the data that can identify an individual.
[1855] "Anonymization methods" are techniques that prevent the identification of individuals by replacing personally identifiable elements with random identifiers or blurring date data.
[1856] "Verification measures" are processes for checking whether anonymized information meets predetermined standards.
[1857] "Means for storage" refers to storage systems and security technologies for safely managing anonymized information.
[1858] "Systematization" refers to the process of normalizing incoming medical information and creating an index to make it easier to search and view.
[1859] The "means for providing an interface" refers to a technology that implements a user interface that allows users to search and view medical information.
[1860] The "means for calculating and allocating rewards" is a process for automatically calculating and allocating rewards to data providers based on the usage status of the data.
[1861] The "preprocessing means" refers to a data conversion technique for converting received medical information into a unified format.
[1862] "Format harmonization" is the process of converting medical data provided in different formats into a consistent data format.
[1863] A "random identifier conversion method" is a process that replaces personal information such as name and address with a randomly generated identifier.
[1864] "Year blurring" is the process of converting specific date information into year information to prevent personal identification.
[1865] "Means for verifying using a checksum" refers to a technique for verifying using a checksum to ensure the integrity of data.
[1866] This invention is a system designed to safely anonymize medical information and promote its use. This system consists of two main components: an AI tool for anonymizing medical information and an AI tool for collecting, viewing, and consulting medical information.
[1867] AI tool for anonymizing medical information
[1868] Data collection
[1869] The server receives patient data (medical records and medication information) from medical institutions and pharmacies via API or file upload. After receiving the data, the server stores the information in secure storage (e.g., AWS S3 bucket or Google Cloud Storage). It also performs checksum verification to ensure the integrity of the received data. It also performs preprocessing to convert data provided in different formats into a unified format.
[1870] Examples:
[1871] The server receives patient medical record information from a medical institution using an API.
[1872] The server stores the received medical record information in an AWS S3 bucket and verifies the integrity of the data using a checksum.
[1873] Personal Information Identification
[1874] The server uses natural language processing algorithms (e.g., SpaCy or NLTK) to extract personally identifiable information (e.g., name, address, date of birth) from the data it receives, and also uses pattern matching techniques to identify email addresses and phone numbers within the data.
[1875] Examples:
[1876] The server uses a natural language processing algorithm to extract "name," "address," and "date of birth" from the medical record information.
[1877] Data Conversion
[1878] The server performs anonymization processing in accordance with the Personal Information Protection Act, such as converting identified personal information into a random identifier and blurring birthday information to years.
[1879] Examples:
[1880] The server converts the extracted "name" into a random identifier and blurs the "birthday" to a year.
[1881] Data Check
[1882] The server verifies whether the converted data meets predetermined criteria, and if not, performs additional anonymization processing.
[1883] Examples:
[1884] The server verifies the anonymity of the anonymized data and performs the anonymization process again if the criteria are not met.
[1885] Data storage
[1886] The server stores the verified, anonymized data in a secure database (e.g., AWS RDS, MongoDB Atlas), which is protected by encryption and access controls.
[1887] Examples:
[1888] The server stores anonymized medical record information in AWS RDS and encrypts and controls access to the database.
[1889] AI tool for collection, viewing, and consultation
[1890] Data reception
[1891] The server receives the anonymized data provided by the medical information anonymization AI tool and checks the integrity of the data upon receipt.
[1892] Examples:
[1893] The server receives the data provided by the anonymization AI tool and verifies the integrity of the data using a checksum.
[1894] Data organization
[1895] The server normalizes the received anonymized data and indexes it for efficient search (e.g., using Elasticsearch).
[1896] Examples:
[1897] The server indexes the anonymized data using Elasticsearch and normalizes it into a unified format.
[1898] Providing search and browsing functionality
[1899] The device provides an interface for users to search and view anonymized medical information. Users can enter keywords and set search criteria to retrieve relevant data.
[1900] Examples:
[1901] A user (a researcher at a pharmaceutical company) accesses the server using his or her own terminal, enters the keyword "diabetes," and sets search conditions.
[1902] The terminal provides the user with a search interface and displays search results based on the user's input.
[1903] Reward Allocation
[1904] The server analyzes the access log according to the user's data usage, and calculates and distributes rewards to the data provider.
[1905] Examples:
[1906] The server calculates the amount of compensation to each information provider based on the data used and distributes the compensation to the medical institution that provided the data.
[1907] The above-mentioned method enables safe anonymization and efficient use of medical information, providing a comprehensive solution for using medical data with peace of mind.
[1908] The flow of the identification process in the first embodiment will be described with reference to FIG.
[1909] Step 1: Receiving data
[1910] The server receives patient data from medical institutions and pharmacies via API or file upload. Data is often provided in CSV or JSON format. Data is sent using API requests or FTP servers. API requests or files are given as input, and the received data is saved to storage.
[1911] Specific behavior:
[1912] The server receives medical record information sent by an API request from a medical institution.
[1913] The server stores the received data in an AWS S3 bucket.
[1914] Step 2: Verify data integrity
[1915] The server uses a checksum to verify the integrity of the received data. The received data and checksum information are given as input, and the output is a confirmation of the data integrity.
[1916] Specific behavior:
[1917] The server verifies the checksum of the received medical record information.
[1918] If the server is able to verify the integrity of the data, it proceeds to the next processing step.
[1919] Step 3: Data Preprocessing
[1920] The server performs preprocessing to convert data provided in different formats into a unified format. The received data is given as input, and data in the unified format is obtained as output.
[1921] Specific behavior:
[1922] The server converts the received CSV format medical record information into JSON format.
[1923] The server stores the converted data in temporary storage.
[1924] Step 4: Personal Identification
[1925] The server uses natural language processing algorithms (e.g., SpaCy or NLTK) to extract personally identifiable information from the data (e.g., name, address, date of birth). The preprocessed data is given as input, and personally identifiable information is obtained as output.
[1926] Specific behavior:
[1927] The server uses SpaCy to extract "name," "address," and "date of birth" from the medical record information.
[1928] The server stores the extraction results as a list.
[1929] Step 5: Data Transformation
[1930] The server converts the identified personal information into a random identifier and performs anonymization processing such as blurring birthdate information into years. The extracted personal identification information is given as input, and anonymized data is obtained as output.
[1931] Specific behavior:
[1932] The server converts the extracted "name" into a random identifier and blurs the "birthday" to a year.
[1933] The server stores the anonymized data in temporary storage.
[1934] Step 6: Verify the anonymized data
[1935] The server verifies whether the converted data meets the specified criteria. The anonymized data is given as input, and the verification result indicating whether the criteria are met is obtained as output.
[1936] Specific behavior:
[1937] The server verifies the anonymity of the anonymized data.
[1938] If the criteria are not met, the server performs the anonymization process again.
[1939] Step 7: Save Data
[1940] The server stores the verified anonymized data in a secure database. The input is the verified anonymized data, and the output is the anonymized data stored in the database.
[1941] Specific behavior:
[1942] The server stores the anonymized medical record information in AWS RDS.
[1943] The server enforces encryption and access control on the database.
[1944] Step 8: Data reception and integrity check
[1945] The server receives the anonymized data provided by the medical information anonymization AI tool and performs a consistency check. The anonymized data is given as input, and the consistency check result is obtained as output.
[1946] Specific behavior:
[1947] The server receives the data provided by the medical information anonymization AI tool.
[1948] The server uses the checksum to verify the integrity of the data.
[1949] Step 9: Data organization
[1950] The server normalizes the received anonymized data and indexes it using Elasticsearch. The anonymized data is given as input, and the indexed data is obtained as output.
[1951] Specific behavior:
[1952] The server normalizes the anonymized data and indexes it using Elasticsearch.
[1953] Step 10: Search and Browse Functions
[1954] The terminal provides an interface for users to search and view anonymized medical information. The terminal receives user search criteria as input and displays search results as output.
[1955] Specific behavior:
[1956] A user accesses the server using a terminal and inputs search criteria.
[1957] The terminal provides the user with a search interface and displays search results from the server.
[1958] Step 11: Reward Allocation
[1959] The server analyzes the access log based on the user's data usage, calculates and distributes rewards to data providers, and receives the access log as input and the reward distribution results as output.
[1960] Specific behavior:
[1961] The server calculates the amount of remuneration to each information provider based on the data used.
[1962] The server distributes the calculated remuneration to each medical institution.
[1963] Through the above processing steps, the present invention realizes safe anonymization and efficient use of medical information.
[1964] (Application example 1)
[1965] Next, a description will be given of Application Example 1. In the following description, the data processing device 12 will be referred to as a "server" and the robot 414 will be referred to as a "terminal."
[1966] Medical information is highly confidential, and its handling requires strict privacy measures. However, real-time data acquisition and anonymization are difficult, and secure data handling is not ensured in many settings. Furthermore, there is a lack of interfaces for efficiently searching and viewing anonymized information, hindering progress in data utilization. Furthermore, there is a need for an efficient method for allocating rewards based on data usage.
[1967] The specific processing by the specific processing unit 290 of the data processing device 12 in the application example 1 is realized by the following means.
[1968] In this invention, the server includes means for acquiring medical information, means for identifying elements that can identify individuals from the acquired medical information, means for anonymizing the identified elements in accordance with the Personal Information Protection Act, means for verifying whether the anonymized information meets predetermined standards, means for securely storing the anonymized information, means for receiving and systematically organizing the anonymized medical information, means for providing an interface for searching and viewing the organized medical information, means for calculating rewards based on data usage and allocating them to data providers, and means for anonymizing and securely processing patient data in real time at medical sites using smart glasses, thereby enabling real-time anonymization, secure processing, and efficient utilization of medical information.
[1969] "Medical information" refers to personal medical records and health data held by medical institutions, such as patient charts and medication information.
[1970] "Means of acquisition" refers to methods or devices for collecting medical data via APIs, file uploads, etc.
[1971] A "personally identifiable element" is information that can be used to identify a specific individual, such as name, address, or date of birth.
[1972] "Anonymization means" refers to methods or technologies that convert personally identifiable information into random identifiers and anonymize data in accordance with the Personal Information Protection Act.
[1973] "Means of verification" refers to methods or techniques for verifying whether anonymized information meets predetermined standards.
[1974] "Secure storage means" refers to methods and technologies for safely storing anonymized data using encryption technology, strict access control, etc.
[1975] "Systematic organization means" refers to methods and technologies for normalizing and indexing the received anonymized medical data so that it can be easily searched and viewed.
[1976] A "search and browsing interface" is a user interface provided for users to search and browse anonymized medical information.
[1977] "Means for calculating and allocating rewards" means methods or technologies for automatically calculating and allocating rewards to data providers based on data usage.
[1978] "Means for real-time anonymization and secure processing of patient data using smart glasses" refers to methods and technologies for instantly anonymizing and securely processing patient data collected in medical settings using smart glasses.
[1979] The system embodying the present invention is designed to safely anonymize medical information and promote its use. This system is specifically realized by the following program.
[1980] The program's main components are a server, a device, and smart glasses. The server retrieves patient data from medical institutions and pharmacies via API or file upload. After retrieving the data, the server uses a natural language processing algorithm to identify personally identifiable information (such as name, address, and date of birth). The server then de-identifies the identified personal information by converting it into a random identifier and obscuring certain date information. The de-identified data is then verified to see if it meets predetermined criteria, and if so, stored in a secure database.
[1981] Furthermore, the anonymized medical information is systematically organized by the server. This organized data is normalized and indexed to facilitate search and viewing. Users can use an interface to search and view the anonymized medical information using their devices. Through this interface, users can quickly access the information they need by setting search conditions. When the data is used, the server calculates rewards based on the data usage and automatically distributes the rewards to the data provider.
[1982] Smart glasses are used in medical settings to anonymize and securely process patient data in real time. Doctors and medical staff wearing the smart glasses can process patient medical records in real time. A specific use case is to read patient data through the smart glasses, anonymize the information displayed on the screen in real time, and process it as securely shareable data. For example, a doctor at a hospital can use the smart glasses to read a patient's medical record information and share the data while protecting private information.
[1983] An example of a prompt is:
[1984] "I want to collect medical data from an API endpoint and identify and anonymize personal information in the returned data. Specifically, I want you to write a Python program that will replace names and addresses with "anonymous" and convert birthdates to "xxxx-xx-xx."
[1985] The above is a detailed embodiment of the present invention. This system realizes real-time anonymization of medical information, safe processing, and efficient data utilization.
[1986] The flow of the specific processing in the application example 1 will be described with reference to FIG.
[1987] Step 1:
[1988] The server retrieves patient data from medical institutions and pharmacies via API endpoints or file uploads. The inputs are the API endpoint URL and the uploaded file, and the output is the raw data stored on the server. Specifically, the server sends a request to the specified API endpoint and stores the returned data in secure storage.
[1989] Step 2:
[1990] The server uses a natural language processing algorithm to identify personally identifiable elements (such as name, address, and date of birth) from the acquired medical data. The input is raw data, and the output is a list of personally identifiable elements. Specifically, the server uses text analysis and pattern matching to extract personal information from the raw data and saves the identified elements in list format.
[1991] Step 3:
[1992] The server anonymizes the identified personal information in accordance with the Personal Information Protection Act. For example, it replaces names and addresses with random identifiers and blurs birthdays to a range. The input is a list of identified elements, and the output is anonymized data. Specifically, the server converts names and addresses to "anonymous" and birthdays to "xxxx-xx-xx."
[1993] Step 4:
[1994] The server verifies whether the anonymized information meets predetermined criteria. The input is the anonymized data, and the output is the verification result of whether the criteria are met. Specifically, the server performs an automatic check based on the anonymization guidelines, and if the criteria are not met, it performs additional anonymization processing.
[1995] Step 5:
[1996] The server stores the verified anonymized data in a secure database. The input is the verified anonymized data, and the output is the data stored in the database. Specifically, the server stores the data using encryption technology and strict access control.
[1997] Step 6:
[1998] The server receives and systematically organizes de-identified medical information. The input is existing de-identified data, and the output is organized data. Specifically, the server normalizes and indexes the data, converting it into a format that is easy to search and browse.
[1999] Step 7:
[2000] The device provides an interface that allows users to search and view anonymized medical information. The input is the user's search criteria, and the output is the search results displayed to the user. Specifically, the device accepts search criteria through the user interface, sends a query to the server, and retrieves and displays related information.
[2001] Step 8:
[2002] The server calculates rewards based on data usage and distributes them to data providers. The input is a data usage log, and the output is a reward calculation result. Specifically, the server analyzes the access log, calculates reward amounts based on the data used, and distributes them to each information provider.
[2003] Step 9:
[2004] Smart glasses are used to anonymize and securely process patient data in real time in medical settings. The input is the patient's medical record and treatment information, and the output is anonymized real-time data. Specifically, the smart glasses read the patient data, display personal information on the screen in an anonymized form, and convert the data into a format that can be safely shared when actually used.
[2005] Furthermore, an emotion engine that estimates the user's emotion may be further combined. That is, the identification processing unit 290 may estimate the user's emotion using the emotion identification model 59, and perform identification processing using the user's emotion.
[2006] MODE FOR CARRYING OUT THE INVENTION
[2007] This paper describes a system that safely anonymizes medical information and promotes its use, and combines it with an emotion engine that recognizes user emotions. This system is broadly composed of an AI tool for anonymizing medical information, an AI tool for collecting, viewing, and consulting, and an emotion engine.
[2008] AI tool for anonymizing medical information
[2009] Data collection
[2010] The server receives patient data (medical record information and medication information) from medical institutions and pharmacies via API or file upload. When receiving the data, it checks whether the data format is consistent and performs preprocessing as necessary to standardize the format.
[2011] Personal Information Identification
[2012] The server automatically identifies personally identifiable information (such as name, address, and date of birth) from the received patient data using natural language processing algorithms, employing text analysis and pattern matching techniques, and then lists the results.
[2013] Data Conversion
[2014] The server then anonymizes the identified personal information, specifically converting names and addresses into random identifiers and blurring birthdates and specific date data into ranges or general formats in accordance with the Personal Information Protection Act.
[2015] Data Check
[2016] The server verifies whether the converted data meets various standards, and if it does not meet certain anonymity standards, it performs additional anonymization processing.
[2017] Data storage
[2018] The server then stores the verified anonymized data in a secure database, where access control permissions are set and the data is protected using encryption technology.
[2019] AI tool for collection, viewing, and consultation
[2020] Data reception
[2021] The server receives the anonymized data provided by the medical information anonymization AI tool, and upon receiving it performs a data integrity check to ensure there are no missing or incorrect data.
[2022] Data organization
[2023] The server systematically organizes the received anonymized data, normalizing and indexing it to make it easier to search and view, thereby enabling efficient data management.
[2024] Providing search and browsing functionality
[2025] The terminal (user device) provides an interface that allows users to search and view anonymized medical information. Users can enter keywords and set conditions to search data.
[2026] Reward Allocation
[2027] The server automatically calculates and distributes rewards to data providers according to the user's data usage. This involves analyzing the data access log and calculating the reward amount for each information provider.
[2028] Adding an Emotion Engine
[2029] emotion recognition
[2030] The device will activate an emotion engine through user input and operations to recognize the user's emotional state, possibly using algorithms that extract emotions from text nuances or voice data.
[2031] Customize search results based on sentiment
[2032] The server customizes search results based on the user's emotions as recognized by the emotion engine. For example, if the user is feeling stressed, data related to stress reduction will be displayed preferentially.
[2033] Providing emotional feedback
[2034] The device provides appropriate feedback based on the user's emotions. For example, if the user is feeling anxious, the device provides an interface offering support and additional information.
[2035] Specific examples
[2036] Collection and anonymization of patient data from medical institutions
[2037] The server receives patient data from a medical institution via API, including medical records and medication information.
[2038] The server analyzes the received data and uses natural language processing to identify personally identifiable information such as name, address, and date of birth.
[2039] The server converts names to random identification IDs, blurs addresses to the region level, and converts birthdates to years.
[2040] The server automatically checks whether the anonymization has been performed properly, and if there are any defects, it performs the anonymization process again.
[2041] The server then encrypts the anonymized data after checking and stores it in a secure database.
[2042] When pharmaceutical companies use anonymized data
[2043] Users (researchers at pharmaceutical companies) access the server using their own terminals.
[2044] The terminal provides a search interface to the user, allowing the user to input keywords to search for data relating to a particular disease.
[2045] The server quickly extracts data that matches the search criteria from the indexed, anonymized database.
[2046] The terminal displays the search results to the user, allowing the user to view the details.
[2047] The server analyzes the user's data usage log and distributes appropriate rewards to the data providers.
[2048] Use of emotion engine
[2049] While the user (a pharmaceutical company researcher) is using the data, the emotion engine detects the user's anxiety.
[2050] The server customizes search results based on the output of the emotion engine, prioritizing the display of data that may reduce anxiety.
[2051] Based on feedback from the emotion engine, the device provides support and additional information to the user, providing information to reduce anxiety.
[2052] Through the above steps, the present invention realizes anonymization and efficient use of medical information, and furthermore, by customizing search results taking into account the user's emotions, more personalized data utilization becomes possible.
[2053] The processing flow will be explained below.
[2054] AI tool for anonymizing medical information
[2055] Processing steps from data collection to anonymization
[2056] Step 1:
[2057] The server receives patient data (medical record information and medication information) from medical institutions and pharmacies via API or file upload. When receiving the data, it checks whether the data format is appropriate, preprocesses it as necessary, and standardizes the format.
[2058] Step 2:
[2059] The server automatically identifies personally identifiable information (such as name, address, and date of birth) from the received patient data using natural language processing algorithms, and then uses text analysis techniques to extract and compile this information into a list.
[2060] Step 3:
[2061] The server will anonymize the identified personal information by converting names and addresses into random identifiers (e.g., UUIDs) and converting birthdates and specific date data into ranges or years.
[2062] Step 4:
[2063] The server automatically verifies whether the anonymized data meets the standards of the Personal Information Protection Act, and if the anonymity is insufficient, it performs additional anonymization processing.
[2064] Step 5:
[2065] The server stores the verified and anonymized data in a secure database, which uses strict access controls and encryption technology to protect the data.
[2066] AI tool for collection, viewing, and consultation
[2067] Processing steps from receiving data to allocating rewards
[2068] Step 1:
[2069] The server receives the anonymized data provided by the medical information anonymization AI tool, and checks the data integrity upon receipt to ensure there are no missing or incorrect data.
[2070] Step 2:
[2071] The server normalizes the received anonymously processed data and indexes it for easy searching and browsing. It organizes each field into categories to achieve efficient data management.
[2072] Step 3:
[2073] The terminal (user device) provides an interface for users to search and view anonymized medical information. Users input keywords, set search conditions, search data, and obtain results.
[2074] Step 4:
[2075] The server quickly extracts anonymized data that matches the user's search criteria and displays it as a search result.
[2076] Step 5:
[2077] The server analyzes the user's data usage log and automatically calculates and distributes rewards to the data provider. The server calculates the reward amount based on the access log and distributes the reward to the specified account.
[2078] Use of emotion engine
[2079] Processing steps from emotion recognition to providing feedback
[2080] Step 1:
[2081] The device activates an emotion engine through user input and operations to recognize the user's emotional state, using algorithms that extract emotions from text nuances and voice data.
[2082] Step 2:
[2083] The server customizes search results based on the user's emotions as recognized by the emotion engine. For example, if the user is feeling stressed, data related to stress reduction will be displayed preferentially.
[2084] Step 3:
[2085] The device provides feedback based on the user's emotions based on the output of the emotion engine. For example, if the user is feeling anxious, the device provides an interface that presents appropriate support and additional information.
[2086] Specific examples
[2087] Collection and anonymization of patient data from medical institutions
[2088] Step 1:
[2089] The server receives patient data from medical institutions via API, including medical records and medication information.
[2090] Step 2:
[2091] The server analyzes the received data and uses natural language processing algorithms to identify personally identifiable information such as name, address, and date of birth, compiling them into a list.
[2092] Step 3:
[2093] The server converts the identified personal information into a random identification ID, blurs addresses to the region level, and converts birthdates to years.
[2094] Step 4:
[2095] The server automatically checks whether the anonymized data meets the standards for protecting personal information. If there are any deficiencies, the data is anonymized again.
[2096] Step 5:
[2097] Once the checks are complete, the server encrypts and stores the anonymized data in a secure database.
[2098] When pharmaceutical companies use anonymized data
[2099] Step 1:
[2100] Users (researchers at pharmaceutical companies) access the server using their own terminals.
[2101] Step 2:
[2102] The terminal provides a search interface to the user, allowing the user to input keywords to search for data relating to a particular disease.
[2103] Step 3:
[2104] The server quickly extracts data that matches the search criteria from the indexed, anonymized database.
[2105] Step 4:
[2106] The terminal displays the search results to the user, allowing the user to view the details.
[2107] Step 5:
[2108] The server analyzes the user's data usage log and distributes appropriate rewards to the data providers.
[2109] Use of emotion engine
[2110] Step 1:
[2111] While the user (a pharmaceutical company researcher) is using the data, the emotion engine detects the user's anxiety.
[2112] Step 2:
[2113] The server customizes search results based on the output of the emotion engine, prioritizing the display of data that may reduce anxiety.
[2114] Step 3:
[2115] Based on feedback from the emotion engine, the device provides the user with appropriate support and additional information to reduce anxiety.
[2116] Through the above steps, the present invention realizes anonymization and efficient use of medical information, and furthermore, by customizing search results taking into account the user's emotions, more personalized data utilization becomes possible.
[2117] Example 2
[2118] Next, a description will be given of Example 2. In the following description, the data processing device 12 will be referred to as a "server" and the robot 414 will be referred to as a "terminal."
[2119] The importance of protecting personal information is increasing in modern medical information management. However, systems that safely anonymize medical data and promote its use are not widely available. Furthermore, the user experience is not fully satisfactory because there is no feedback or customized search results that take into account the user's emotional state when using the data. Therefore, a system that safely anonymizes medical data and provides information based on the user's emotional state is needed.
[2120] The identification process by the identification processing unit 290 of the data processing device 12 in the second embodiment is realized by the following means. In this invention, the server includes a means for acquiring medical information, a means for identifying elements that can identify an individual from the acquired medical information, and a means for anonymizing the identified elements in accordance with the Personal Information Protection Act. This makes it possible to safely anonymize medical information and provide information according to the user's emotional state.
[2121] "Medical information" refers to medical data such as patient medical records, prescription information, and test results.
[2122] "Anonymization" refers to the process of removing or transforming personally identifiable information so that the data provider cannot be identified.
[2123] "Natural language processing algorithms" refer to computational methods and technologies for automatically parsing, understanding, and generating human language.
[2124] "Anonymized Data" means data that has been made anonymous by removing or transforming personal information.
[2125] "Emotional state" refers to a psychological state that is determined based on a user's actions or inputs.
[2126] "Feedback" refers to the information or actions that a system provides in response to a user's behavior or state.
[2127] "Interface" refers to the screens and functions that allow users to interact with the system.
[2128] "Reward calculation" refers to the process of calculating rewards to data providers in accordance with the user's use of data.
[2129] "Access log" refers to data that records the history of users accessing a system.
[2130] A "database" refers to a system that stores information in an organized manner and makes it easy to search and manage.
[2131] "Random identifier" refers to a unique identification code that is randomly generated so as not to identify personal information.
[2132] This invention describes a system that safely anonymizes medical information and promotes its use, as well as a system that combines an emotion engine that recognizes user emotions. The detailed configuration and operation of this system are described below.
[2133] AI tool for anonymizing medical information
[2134] The AI tool for anonymizing medical information in this system runs on a server, primarily to perform the following processes:
[2135] 1. Data Collection:
[2136] The server receives patient data (medical record information and medication information) from medical institutions and pharmacies via API or file upload. For example, it obtains JSON format data from a medical institution's system, checks the integrity of the data upon reception, preprocesses it, and standardizes it into a standard format.
[2137] 2. Personal Information Identification:
[2138] The server uses natural language processing algorithms to automatically identify personally identifiable information (such as name, address, and date of birth) from the received data, and then uses text analysis and pattern matching techniques to extract and list personal information.
[2139] 3. Data conversion:
[2140] The server then anonymizes the identified personal information. Specifically, it converts names and addresses into random IDs and blurs birthdays to years. This ensures that the data is securely anonymized.
[2141] 4. Data Check:
[2142] The server verifies whether the converted data meets the anonymity criteria, and if not, performs additional anonymization processing.
[2143] 5. Data Retention:
[2144] The server then stores the verified anonymized data in a secure database, where access control permissions are set and the data is protected using encryption technology.
[2145] AI tool for collection, viewing, and consultation
[2146] This tool is designed to efficiently utilize anonymized medical data and performs the following processes:
[2147] 1. Data reception:
[2148] The server receives the anonymized data provided by the medical information anonymization AI tool and performs a consistency check to ensure there are no missing or incorrect data.
[2149] 2. Data reduction:
[2150] The server normalizes the anonymized data it receives and indexes it for easy searching and browsing.
[2151] 3. Providing search and browsing functionality:
[2152] The terminal (user device) provides an interface for searching and viewing anonymized medical information. Users can search for data by entering keywords or conditions.
[2153] 4. Reward Allocation:
[2154] The server calculates and automatically distributes rewards to data providers based on the user's data usage. It analyzes access logs and calculates reward amounts based on factors such as frequency of usage.
[2155] Adding an Emotion Engine
[2156] This system is integrated with an emotion engine that can recognize user em...
Claims
1. a means of obtaining medical information; a means of identifying personally identifiable elements from the medical information obtained; A means of anonymizing the identified elements in accordance with the Personal Information Protection Act; a means of verifying whether the anonymized information meets predetermined criteria; and A means of securely storing the anonymized information; and A means of receiving and systematically organizing de-identified medical information; a means for providing an interface for searching and viewing organized medical information; a means for calculating and allocating rewards to data providers based on data usage; A system including:
2. The system of claim 1 , wherein the system uses a natural language processing algorithm to identify personally identifiable information.
3. 10. The system of claim 1, further comprising means for converting medical information into random identifiers and obscuring certain dates and medical history information.
Citation Information
Patent Citations
Persona chatbot control method and system
JP2022180282A