Information sharing system and program

JP2026063165A5Pending Publication Date: 2026-05-29HIGASHI NIHON MEDICOM

Patent Information

Authority / Receiving Office
JP · JP
Patent Type
Applications
Current Assignee / Owner
HIGASHI NIHON MEDICOM
Filing Date
2026-01-14
Publication Date
2026-05-29

AI Technical Summary

Technical Problem

Existing information management systems fail to appropriately share user information across multiple processes, lacking the ability to manage and control viewing conditions effectively.

Method used

An information sharing system that manages viewing conditions based on user settings, allowing controlled sharing of health information across different processes through a network of first and second processing units, user terminals, and information management devices, utilizing blockchain technology for secure and distributed management of access conditions.

Benefits of technology

Enables secure, controlled, and efficient sharing of user information across multiple processes, enhancing confidentiality, integrity, and reducing operational costs while reflecting user preferences.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 00000000_0000_ABST
    Figure 00000000_0000_ABST
Patent Text Reader

Abstract

User information is appropriately shared across multiple processes. [Solution] The information sharing system S comprises a viewing condition management unit 452, a determination unit 453, and a viewing control unit 454. The viewing condition management unit 452 manages the viewing conditions for health information, which is information relating to the user's health, based on the user's settings. When the determination unit 453 receives a request from the second processing unit 20 to view first health information, which is at least a part of the health information used by the first processing unit 10 for processing, it determines whether or not to allow viewing based on the viewing conditions managed by the viewing condition management unit 452. If viewing is permitted by the determination unit 453, the viewing control unit 454 allows the second processing unit 20 to view the first health information.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to an information sharing system, an information sharing method, and a program.

Background Art

[0002] Conventionally, technologies for managing various information related to users and utilizing this information are known. For example, Patent Document 1 discloses a technology for analyzing a user's lifestyle pattern based on the user's health information. According to the technology disclosed in this Patent Document 1, based on information such as the user's exercise time and bedtime, the quality of the user's lifestyle pattern can be scored, and this score can be presented to the user.

Prior Art Documents

Patent Documents

[0003]

Patent Document 1

Summary of the Invention

Problems to be Solved by the Invention

[0004] However, in a general technology such as that disclosed in Patent Document 1, information related to a user is managed only for the purpose of performing a specific process (for example, a process of scoring the user's lifestyle pattern). That is, when performing a plurality of various processes other than a specific process, sharing information related to the user in these plurality of processes was not assumed.

[0005] The present invention has been made in view of such a situation. And the problem of the present invention is to appropriately share information related to a user in a plurality of processes.

Means for Solving the Problems

[0006] To solve the above problems, an information sharing system according to one aspect of the present invention is: A management means for managing the viewing conditions of health information, which is information related to the user's health, based on the user's settings, When a request to view first health information, which is at least a part of the health information used by the first processing means for processing, is received from the second processing means, a determination means determines whether or not to permit viewing based on the viewing conditions managed by the management means, A viewing means that, when viewing is permitted by the determination means, causes the second processing means to view the first health information, It is characterized by having the following features. [Effects of the Invention]

[0007] According to the present invention, it becomes possible to appropriately share user information across multiple processes. [Brief explanation of the drawing]

[0008] [Figure 1] This is a schematic diagram illustrating the process by which the information sharing system S according to an embodiment of the present invention appropriately shares information about a user across multiple processes. [Figure 2] This figure shows the system configuration of an information sharing system S according to one embodiment of the present invention. [Figure 3] This diagram shows the hardware configuration of the information processing devices 800 that constitute each device included in the information sharing system S. [Figure 4] This is a block diagram showing the functional configuration of the first processing unit 10. [Figure 5] This is a block diagram showing the functional configuration of the second processing unit 20. [Figure 6] This is a block diagram showing the functional configuration of the user terminal 30. [Figure 7] This table shows an example of viewing conditions, which are set by the user terminal 30 and managed by the information management device 40. [Figure 8] This is a block diagram showing the functional configuration of the information management device 40. [Figure 9] It is a flowchart showing the operation flow during processing for information sharing executed by the first processing device 10. [Figure 10] It is a flowchart showing the operation flow during processing for information sharing executed by the second processing device 20. [Figure 11] It is a flowchart showing the flow of information sharing processing executed by the user terminal 30. [Figure 12] It is a flowchart showing the operation flow during processing for information sharing executed by the information management device 40. [Figure 13] It is a schematic diagram showing an example of the terminal operation screen 60 displayed on the user terminal 30 when registering user information or setting viewing conditions. [Figure 14] It is a schematic diagram showing an example of the viewing screen displayed on the second processing device 20 when outputting viewing information. [Figure 15] It is a schematic diagram showing another example of the viewing screen displayed on the second processing device 20 when outputting viewing information. [Figure 16] In Modification 5, it is a table showing an example of user management information and an example of viewing conditions managed by the information management device 40. [Figure 17] In Modification 6, it is a flowchart showing the operation flow during processing for information sharing executed by the information management device 40. [Figure 18] In Modification 6, it is a flowchart showing the operation flow during processing for information sharing executed by the user terminal 30.

Embodiments for Carrying Out the Invention

[0009] Hereinafter, embodiments of the present invention will be described with reference to the drawings.

[0010] [Processing Outline] FIG. 1 is a schematic diagram showing an overview of a process in which an information sharing system S according to an embodiment of the present invention appropriately shares information related to a user in a plurality of processes. In FIG. 1, the main components of the information sharing system S and the main information transmitted and received between these components are schematically shown.

[0011] The information sharing system S includes a first processing device 10, a second processing device 20, a user terminal 30, and an information management device 40. Each component of these information sharing systems S is connected to be communicable with each other.

[0012] Next, an overview of the process by the information sharing system S will be described. The first processing device 10 controls the first process executed on the user terminal 30 ( "(1) Control the first process" in the figure).

[0013] The user terminal 30 executes the first process based on the control of the first processing device 10, and accordingly, obtains first information that is at least a part of the information related to the user ( "(2) Obtain the first information" in the figure). Further, the first processing device 10 transmits the obtained first information to the user terminal 30 ( "(3) Transmit the first information" in the figure). The first processing device 10 manages the obtained first information.

[0014] In addition, the user terminal 30 sets a viewing condition for viewing this first information in the information management device 40 ( "(4) Set viewing information" in the figure). This viewing condition can be arbitrarily set by the user using the user terminal 30 based on their own will.

[0015] On the other hand, the second processing unit 20 executes a second process, which is a different process from the first process. In this case, the second processing unit 20 may acquire second information, which is at least a part of the information about the user. This second processing unit 20 is used, for example, by another person related to the user using the user terminal 30. Based on a request from this other person to view the first information, the second processing unit 20 sends a request to view the first information to the information management device 40 (indicated as "(5) Sending a viewing request" in the figure).

[0016] When the information management device 40 receives a viewing request, it determines whether or not to permit viewing based on the set viewing conditions. If the information management device 40 determines that viewing is permitted, it sends a transmission instruction for viewing information to the first processing device 10 (indicated as "(6) Transmission instruction for viewing information" in the figure).

[0017] The first processing unit 10 generates viewing information in response to an instruction to transmit viewing information. This viewing information is generated by extracting at least a portion of the first information and converting it into a predetermined format suitable for viewing. The first processing unit 10 then transmits the generated viewing information to the information management device 40 (indicated as "(7) Transmitting viewing information" in the figure).

[0018] The information management device 40 transmits the received viewing information to the second processing device 20 (indicated as "(8) Transmitting viewing information" in the figure). This allows another person to view the viewing information corresponding to the first information on the second processing device 20.

[0019] Thus, the information sharing system S enables information sharing by allowing the second processing unit 20, which performs other processing, to view the first information handled by the first processing unit 10. In this case, the information sharing system S does not allow the second processing unit 20 to view the information without restriction, but rather determines whether or not to allow viewing based on viewing conditions set by the user. This allows the user to arbitrarily choose where information about themselves can be viewed. Furthermore, the information sharing system S can share information across multiple processes while enhancing its confidentiality and availability by reflecting such user-based choices.

[0020] Furthermore, according to the information sharing system S, the information management device 40 can centrally manage the viewing conditions. Therefore, the first processing unit 10 and the second processing unit 20 can be made free from the need to perform processes such as managing viewing conditions or determining whether or not to permit viewing.

[0021] Furthermore, according to the information sharing system S, instead of the first information itself, users are allowed to view information extracted and converted from the first information. This achieves the objective of viewing on the second processing unit 20, and prevents the first health information itself from being accidentally edited on the information management device 40 or the second processing unit 20, or from being tampered with on the communication path, etc. Therefore, information integrity can be enhanced, and user information can be protected more appropriately.

[0022] Thus, according to the information sharing system S of the present invention, information about users can be appropriately shared across multiple processes.

[0023] The above describes the overview of the processing performed by the information sharing system S. Next, the details of the information sharing system S, which enables this processing, will be explained below.

[0024] [System Configuration] Figure 2 is a diagram showing the system configuration of an information sharing system S according to one embodiment of the present invention. As shown in Figure 2, the information sharing system S is composed of a plurality of first processing units 10, a plurality of second processing units 20, a user terminal 30, and a plurality of information management devices 40. These components of the information sharing system S are configured to communicate with each other via a network N. This network N can be implemented, for example, by the internet or a LAN (Local Area Network).

[0025] Here, i, j, and k, indicated at the end of the symbols of these components, are each arbitrary integer values ​​of 1 or more. That is, the number of first processing units 10, second processing units 20, and information management devices 40 are not particularly limited. Similarly, although only one user terminal 30 is shown in the diagram, the number of such terminals is not particularly limited. In the following explanation, when describing multiple identical components without distinguishing between them, the last suffix of the code will be omitted. For example, when describing the first processing unit 10-1, ..., and the first processing unit 10-i without distinguishing between them, the last suffix of the code will be omitted, and they will simply be referred to as the first processing unit 10.

[0026] Furthermore, as an example for illustrative purposes, we will assume that the information concerning the user (corresponding to the first and second information mentioned above, as shown in Figure 1) will be "health information," which is information concerning the user's health. Here, health information is assumed to include not only information obtained from general health checkups such as the user's height, weight, and blood pressure, but also a variety of other health and medical information, such as information on daily life including diet, sleep, and exercise intensity, various measured biometric data, guidance on medical diagnosis and treatment, pharmaceutical guidance and medication guidance, and observations related to rehabilitation and daily living assistance.

[0027] Such health information requires particularly careful handling among various types of personal information. Therefore, it is desirable to process this information using a system that can appropriately share user information across multiple processing steps, such as the information sharing system S. For this reason, health information is assumed to be the target of this user information. However, this is merely an example for illustrative purposes and is not intended to limit the scope of application of this embodiment.

[0028] The first processing unit 10 is used by a business that provides application software (hereinafter referred to as "app") corresponding to the first processing, and is composed of an information processing device such as a server computer managed by this business. The first processing unit 10 performs control over the app executed on the user terminal 30 as the first processing. As a result, the first processing unit 10 acquires first health information (corresponding to the first information described above, referring to Figure 1) via the user terminal 30.

[0029] Here, the multiple first processing units 10 control different applications provided by the same or multiple businesses. For example, first processing unit 10-1 controls the first application, while first processing unit 10-2 controls the second application. Therefore, the multiple first processing units 10 acquire different first health information corresponding to different applications.

[0030] The second processing unit 20 is used by medical professionals such as doctors, pharmacists, and physical therapists, as well as family members of users who use the user terminal 30, and the users themselves who use the user terminal 30 (hereinafter referred to as "viewers"). The second processing unit 20 consists of a server computer managed by a business operator that provides a business program corresponding to the second processing (hereinafter referred to as "business program"), and information processing devices such as personal computers owned by viewers. The second processing unit 20 then executes the business program as the second processing. As a result, the second processing unit 20 acquires second health information (corresponding to the second information described above, referring to Figure 1).

[0031] Here, the multiple second processing units 20 each execute different business programs provided by the same or multiple businesses. For example, second processing unit 20-1 executes the first business program, while second processing unit 20-2 executes the second business program. Therefore, each of the multiple second processing units 20 acquires different second health information corresponding to the business program it executed.

[0032] The user terminal 30 is used by the user who uses the user terminal 30, and consists of information processing devices such as a smartphone or wearable device owned by the user, or a measuring device installed in a designated facility (for example, a sports club, nursing home, municipal health facility, pharmacy, and hospital). The user terminal 30 then executes an application as the first process, based on the control of the first processing device 10. In other words, the first process is realized through the cooperation of the first processing device 10 and the user terminal 30. As a result, the first processing device 10 acquires first health information.

[0033] As mentioned above, there are multiple applications, each corresponding to one of the multiple first processing units 10. Therefore, the user terminal 30 obtains different first health information corresponding to each of the multiple applications it has executed.

[0034] Thus, in the information sharing system S, there are multiple applications executed by the user terminal 30 under the control of the first processing unit 10, and multiple business programs executed by the second processing unit 20. In other words, in the information sharing system S, multiple applications are executed as the first process, and multiple business programs are executed as the second process. The user can then set viewing conditions, specifying whether or not to allow viewing for each combination of applications (corresponding to the first processing unit 10) and each business program (corresponding to the second processing unit 20). This allows the information sharing system S to share user information more appropriately across a larger number of processes.

[0035] The information management device 40 is used by businesses that support the provision of information between businesses that provide applications and business programs, and is composed of information processing equipment such as a server computer managed by such businesses. The information management device 40 manages the viewing conditions set by the user and performs processing to realize viewing based on these viewing conditions.

[0036] Here, the multiple information management devices 40 are connected to each other via P2P (Peer to Peer), and this P2P network forms a distributed ledger called a blockchain BC. This blockchain BC stores the viewing conditions in a distributed manner across the multiple information management devices 40, and manages the viewing conditions based on the consistency of the distributed information stored. In this way, by using blockchain (BC) to manage the database (essentially a registry) where viewing conditions are stored as a distributed ledger, businesses that support the provision of information between various businesses can function as information providers.

[0037] Here, such a blockchain BC can be realized based on existing blockchain technology. In this case, for example, when storing access conditions in a distributed manner, hash values ​​are calculated to encrypt the access conditions and detect tampering or corruption of the access conditions. Furthermore, blockchain BC uses digital signatures to prevent impersonation and other theft. In addition, blockchain BC verifies the legitimacy of the distributedly stored access conditions based on consensus algorithms such as PoW (Proof of Work). Through this series of processes, blockchain BC properly manages access conditions.

[0038] As explained above with reference to Figure 2, the information sharing system S not only achieves the effects described above with reference to Figure 1, but also allows setting viewing conditions to determine whether or not to allow viewing for combinations of multiple applications and multiple business programs. This enables the sharing of user information across a larger number of processes.

[0039] Furthermore, according to the information sharing system S, multiple information management devices 40 collaborate to form a blockchain BC, which ensures higher security and reduces management and operational costs compared to managing viewing conditions with a typical server-client system. Therefore, the information sharing system S allows for more appropriate sharing of user information across multiple processes.

[0040] [Hardware configuration] Next, we will describe the hardware configuration of each device included in the information sharing system S. Each device and terminal included in the information sharing system S is composed of information processing devices such as server computers, personal computers, smartphones, wearable devices, or measuring devices installed in the facility, as described above, and their basic configurations are all the same.

[0041] Figure 3 shows the hardware configuration of the information processing device 800, which constitutes each device included in the information sharing system S. As shown in Figure 3, each information processing device 800 comprises a CPU (Central Processing Unit) 811, a ROM (Read Only Memory) 812, a RAM (Random Access Memory) 813, a bus 814, an input unit 815, an output unit 816, a storage unit 817, a communication unit 818, a drive 819, and a sensor unit 820.

[0042] The CPU 811 executes various processes according to the program recorded in the ROM 812 or the program loaded into the RAM 813 from the storage unit 817. RAM813 also stores data necessary for CPU811 to perform various processes.

[0043] The CPU 811, ROM 812, and RAM 813 are interconnected via a bus 814. The input unit 815, output unit 816, storage unit 817, communication unit 818, drive 819, and sensor unit 820 are connected to the bus 814.

[0044] The input unit 815 consists of various buttons and other controls, and inputs various information according to the instructions. The input unit 815 also includes a microphone to collect sound. The output unit 816 consists of a display, speakers, etc., and outputs images and sound.

[0045] The memory unit 817 consists of a hard disk or DRAM (Dynamic Random Access Memory), and stores various types of data managed by each server. The communication unit 818 controls communication with other devices via the network N.

[0046] A removable media 831, consisting of a magnetic disk, optical disk, magneto-optical disk, or semiconductor memory, is appropriately mounted in the drive 819. Programs read from the removable media 831 by the drive 819 are installed in the storage unit 817 as needed.

[0047] The sensor unit 820 is composed of various sensors and measures various types of information corresponding to those sensors. For example, the sensor unit 820 is composed of sensors that measure biometric information such as the user's heart rate, blood pressure, and body temperature, a GPS (Global Positioning System) sensor that measures location information, and acceleration sensors and gyroscope sensors that measure movement status.

[0048] Furthermore, if the information processing device 800 is configured as the first processing device 10 or the information management device 40, it is possible to omit the sensor unit 820. Also, if the information processing device 800 is configured as a smartphone or the like, it is possible to configure the input unit 815 as a touch sensor and place it on top of the display of the output unit 816 to provide a touch panel.

[0049] [Functional configuration] Next, the functional configuration of each device and terminal in the information sharing system S will be described.

[0050] [Functional configuration of the first processing unit 10] Figure 4 is a block diagram showing the functional configuration of the first processing unit 10. As shown in Figure 4, the CPU 811 of the first processing unit 10 functions as a first processing control unit 151 and a browsing information generation unit 152. Furthermore, as shown in Figure 4, the storage unit 817 of the first processing unit 10 includes a user information storage unit 171 and a first health information storage unit 172.

[0051] The first processing control unit 151 performs control over an application to be executed on the user terminal 30 as the first process. This control over the application includes, for example, the process of providing the application to the user terminal 30 and installing the application on the user terminal 30, and the process of managing various information related to the operation of the application by sending and receiving such information with the user terminal 30.

[0052] The application controlled by the first processing control unit 151 is not particularly limited, as long as it utilizes the first health information. For example, the application may simply perform processing to acquire the first health information, or it may perform further processing such as managing the acquired first health information or performing statistical analysis. For example, the application may be an application for managing health status and lifestyle, or an electronic medication record application.

[0053] The various types of information managed by the first processing control unit 151 include, for example, user information and first health information. User information includes identifiers and other information that identify the user, as well as user attributes such as the user's name, password, and email address. This user information is used for user registration in the app and for associating the user with primary health information. The first health information varies depending on the type of application, but it includes, for example, biometric information indicating the user's health status such as heart rate, blood pressure, and body temperature, information indicating the user's lifestyle such as exercise, sleep, and diet, and information included in the user's medical history, etc., which is acquired in relation to the application's functions. This first health information is not only used within the application, but is also used as data to be viewed by the second processing unit 20, as described above.

[0054] The first processing control unit 151 acquires user information through communication with the user terminal 30 in connection with application control and stores the acquired user information in the user information storage unit 171. In other words, the user information storage unit 171 functions as a storage unit that stores user information. Similarly, the first processing control unit 151 acquires first health information through communication with the user terminal 30 in connection with application control and stores the acquired first health information in the first health information storage unit 172. In other words, the first health information storage unit 172 functions as a storage unit that stores user information.

[0055] The browsing information generation unit 152 generates browsing information when it receives a transmission instruction for browsing information from the information management device 40. The browsing information generation unit 152 then transmits the generated browsing information to the information management device 40.

[0056] This viewing information is generated by extracting at least a portion of the first health information and converting it into a predetermined format suitable for viewing. The information to be extracted from this first health information and the predetermined format suitable for viewing (e.g., file format) are defined in advance based on the type of application, etc. This definition is determined, for example, by the application provider, the business program provider, or the business that manages the information management device 40 which acts as a provider between these businesses. In this way, instead of disclosing all information related to the application as viewing information, the scope of information to be disclosed as viewing information can be determined according to the application, making it easier for application providers to permit the disclosure of information they manage to other companies' business programs. In other words, it becomes easier for application providers to participate in the information sharing system S.

[0057] [Functional configuration of the second processing unit 20] Figure 5 is a block diagram showing the functional configuration of the second processing unit 20. As shown in Figure 5, the CPU 811 of the second processing unit 20 functions as follows: a second processing execution unit 251, a second health information acquisition unit 252, and a browsing request unit 253. Furthermore, as shown in Figure 5, the storage unit 817 of the second processing unit 20 includes a user information storage unit 271 and a second health information storage unit 272.

[0058] The second processing unit 251 executes a business program as the second process. This execution of the business program includes, for example, the process of obtaining the business program from an external server (not shown in the figure) managed by the business operator providing the business program and installing the business program on the second processing unit 20, the process of realizing functions corresponding to the business program, the process of managing various information related to the operation of the business program, and the process of viewing the first health information by making a request to the information management device 40 to view the first health information.

[0059] The business program executed by the second processing execution unit 251 is not particularly limited, as long as it utilizes the second health information. For example, the business program may simply perform processing to acquire the second health information, or it may further perform predetermined processing such as managing the acquired second health information or performing statistical analysis. For example, it may be a business program for the purpose of managing electronic medical records or medication history in a hospital, or a business program for mutually confirming the first and second health information among family members.

[0060] The various types of information managed by the second health information acquisition unit 252 include, for example, user information and second health information. User information includes identifiers and other information that identify the user, as well as user attributes such as the user's name, password, and email address. This user information is used for user registration in business programs and for associating users with second-party health information. Secondary health information varies depending on the type of business program, but it includes, for example, biometric information indicating the user's health status such as heart rate, blood pressure, and body temperature, as well as information included in electronic medical records and medication history, and other information acquired in relation to the functions of the business program. This secondary health information is used by the business program.

[0061] The second processing execution unit 251 acquires user information through user information input operations or communication with the user terminal 30 or information management device 40, etc., in conjunction with the execution of the business program, and stores the acquired user information in the user information storage unit 271. In other words, the user information storage unit 271 functions as a storage unit that stores user information. Similarly, the second processing execution unit 251 acquires second health information from the second health information acquisition unit 252 in conjunction with the execution of the business program, and stores the acquired second health information in the second health information storage unit 272. In other words, the second health information storage unit 272 functions as a storage unit that stores user information.

[0062] The second health information acquisition unit 252 acquires second health information in conjunction with the execution of the business program of the second processing execution unit 251. The second health information acquisition unit 252 then outputs the acquired second health information to the second processing execution unit 251. For example, if the second health information is various biometric information of the user, the second health information acquisition unit 252 acquires the various biometric information by controlling the measurement by the sensor unit 820. Alternatively, if the second health information is information included in the electronic medical record or information included in the medication history, the second health information acquisition unit 252 acquires this information via the input unit 815 and the communication unit 818.

[0063] When the viewing request unit 253 receives a transmission instruction for a viewing request for the first health information from a viewer using the second processing unit 20, it transmits the viewing request for the first health information to the information management device 40. This viewing request includes information to identify which second processing unit 20 is the source of the viewing request, and information to specify which user and which first processing unit 10's application the user wishes to view the first health information for.

[0064] Furthermore, when the viewing request unit 253 receives viewing information from the information management device 40 as a response to this viewing request, it outputs this viewing information to the viewer. On the other hand, when it receives a message from the information management device 40 indicating that viewing is not possible as a response to this viewing request, it outputs this message to the viewer. These outputs to the viewer are realized, for example, by displaying them on a display included in the output unit 810, or by printing them onto paper media from a printing device (not shown) connected via the communication unit 818.

[0065] [Functional configuration of user terminal 30] Figure 6 is a block diagram showing the functional configuration of the user terminal 30. As shown in Figure 6, the CPU 811 of the user terminal 30 functions as follows: a first processing execution unit 351, a first health information acquisition unit 352, and a browsing condition setting unit 353. Furthermore, as shown in Figure 6, the storage unit 817 of the user terminal 30 is formed with a user information storage unit 371 and a first health information storage unit 372.

[0066] The first processing unit 351 executes an application as its first process, based on the control of the first processing unit 10. This application execution includes, for example, the process of obtaining the application from the first processing unit 10 and installing it on the user terminal 30, the process of implementing functions corresponding to the application, the process of managing various information related to the operation of the application, and the process of transmitting this various information to the first processing unit 10. The application executed by the first processing unit 351 is not particularly limited, as long as it utilizes the first health information, as described above.

[0067] The various types of information managed by the first processing execution unit 351 include user information and first health information, similar to the first processing control unit 151 of the first processing device 10. The first processing execution unit 351 acquires user information through user information input operations during application execution and stores the acquired user information in the user information storage unit 371. In other words, the user information storage unit 371 functions as a storage unit that stores user information. Similarly, the first processing execution unit 351 acquires first health information from the first health information acquisition unit 352 during application execution and stores the acquired first health information in the first health information storage unit 372. In other words, the first health information storage unit 372 functions as a storage unit that stores user information. The first processing execution unit 351 also transmits this acquired user information and first health information to the first processing unit 10.

[0068] The first health information acquisition unit 352 acquires the first health information in conjunction with the execution of the application by the first processing execution unit 351. The viewing condition setting unit 353 then outputs the acquired first health information to the first processing execution unit 351. For example, if the first health information is various biometric information of the user, the first health information acquisition unit 352 acquires the various biometric information by controlling measurements by the sensor unit 820. Also, for example, if the first health information is information indicating the user's lifestyle such as exercise, sleep, and diet, the first health information acquisition unit 352 acquires this information by statistically analyzing the various biometric information. Furthermore, for example, if the first health information is information contained in a medication record book, the first health information acquisition unit 352 acquires the information contained in the medication record book via the input unit 815 and the communication unit 818.

[0069] When the viewing condition setting unit 353 receives an instruction from a user using the user terminal 30 to set viewing conditions for viewing the first health information, it sets the viewing conditions in the information management device 40. These viewing conditions can be arbitrarily set by the user using the user terminal 30 based on their own will. An example of these viewing conditions will be explained with reference to Figure 7. Here, Figure 7 is a table showing an example of viewing conditions that are set by the user terminal 30 and managed by the information management device 40.

[0070] As shown in Figure 7, this table has a column (row) for each of the multiple first health information entries as the information to be viewed. In addition, a record (column) is provided for each of the multiple second processing units 20 that can view the information to be viewed.

[0071] Here, the correspondence between the first processing unit 10 and the first health information may be a one-to-one relationship, or it may be a one-to-many relationship as shown in the figure. In other words, it may be possible to set whether or not to view the entire first health information obtained by one application executed by one first processing unit 10, or it may be possible to set whether or not to view this first health information in units that are further subdivided. By setting whether or not to view in these subdivided units, it is possible to make settings that more precisely reflect the user's intentions.

[0072] The viewing condition setting unit 353 then sets information indicating whether viewing is permitted or not, such as "viewable" or "viewable," for each field (cell) where a column and a record intersect, based on the setting instructions of the user using the user terminal 30. In this way, the viewing conditions are set to include whether or not to allow viewing for any combination of the first processing unit 10 (whichever first health information it acquires) and any second processing unit 20.

[0073] The viewing conditions set in this manner are managed by the information management device 40 in a format similar to this table. This table corresponds to the viewing conditions set for a single user; if there are multiple users, multiple tables similar to this one are created, one for each of these users.

[0074] [Functional configuration of the information management device 40] Figure 8 is a block diagram showing the functional configuration of the information management device 40. As shown in Figure 8, the CPU 811 of the information management device 40 functions as follows: User information management unit 451, browsing condition management unit 452, determination unit 453, browsing control unit 454, and 455. Furthermore, as shown in Figure 8, the storage unit 817 of the information management device 40 includes a user management information storage unit 471 and a browsing condition storage unit 472.

[0075] The User Information Management Unit 451 integrates user information from the entire information sharing system S and manages it as user management information. To this end, the User Information Management Unit 451 periodically communicates with the first processing unit 10, the second processing unit 20, and the user terminal 30 at predetermined update timings to acquire user information stored in these devices. The User Information Management Unit 451 then updates the user management information based on the user information acquired from these devices. Here, the first processing unit 10, the second processing unit 20, and the user terminal 30 each manage user information corresponding to different applications and different business programs. Therefore, the content of each user's information is not necessarily identical. Accordingly, the User Information Management Unit 451 identifies which user's information each acquired by communication from each device belongs to, for example by assigning unique identification information to each user, and updates the user management information so that each user's information is consistent. The user information management unit 451 then stores the user management information in the user management information storage unit 471 each time it is updated. In other words, the user management information storage unit 471 functions as a storage unit that stores user management information.

[0076] The browsing conditions management unit 452 manages the browsing conditions set from the user terminal 30. The browsing conditions management unit 452 stores the set browsing conditions in a format such as the table shown in Figure 7, and distributes them to the browsing conditions storage units 472 of each of the multiple information management devices 40 that form the blockchain BC. In other words, the browsing conditions storage unit 472 functions as a storage unit that stores the set browsing conditions. Furthermore, the viewing conditions management unit 452 manages these set viewing conditions using blockchain BC, as described above. In other words, the viewing conditions are appropriately managed through the cooperation of multiple information management devices 40.

[0077] When the determination unit 453 receives a request to view the first health information from the second processing unit 20, it determines whether to permit viewing based on the viewing conditions managed by the viewing condition management unit 452 using blockchain BC. As described above, the viewing request includes information to identify which second processing unit 20 is the source of the viewing request, and information specifying which user and which first processing unit 10's application the user wishes to view the first health information for. Based on this information, the determination unit 453 identifies the user, first processing unit 10, and second processing unit 20 corresponding to this viewing request. It then determines whether, in the viewing conditions for this user, at least a portion of the first health information of the first processing unit 10 is permitted to be viewed by the second processing unit 20.

[0078] The browsing control unit 454 controls the browsing of the first health information based on the determination result of the determination unit 453. If the determination unit 453 determines that browsing is permitted, the browsing control unit 454 sends a transmission instruction for browsing information to the first processing unit 10 corresponding to the browsing request. Then, when the browsing control unit 454 receives the browsing information from the first processing unit 10, it transmits this browsing information as a response to the browsing request to the second processing unit 20, the source of the browsing request.

[0079] Thus, in the information sharing system S, the first health information is managed by the first processing unit 10, and the viewing control unit 454, when permission to view is granted, retrieves the first health information from the first processing unit 10 and allows the second processing unit 20 to view the retrieved first health information. As a result, the information management device 40 and the second processing device 20 do not need to manage the first health information that the first processing device 10 handles for processing. This eliminates the need for the information management device 40 and the second processing device 20 to store the first health information or to update the first health information in synchronization with the first processing device 10.

[0080] In this case, the viewing control unit 454 may transmit the received viewing information to the second processing unit 20 as is, or it may transmit the received viewing information to the second processing unit 20 after converting it. For example, if the viewing information is editable text data, this viewing information may be accidentally edited by the second processing unit 20. Therefore, the viewing control unit 454 may convert the viewing information into image data that is difficult to edit, or into PDF (Portable Document Format) data with editing disabled, etc., before transmitting it to the second processing unit 20. This prevents the viewing information from being accidentally edited by the second processing unit 20. Then, as described above, the viewing information corresponding to the first health information is output to the viewer by the second processing unit 20. This realizes the viewing in this embodiment.

[0081] On the other hand, if the determination unit 453 determines that viewing is not permitted, the viewing control unit 454 sends a message indicating that viewing is not permitted as a response to the viewing request to the second processing unit 20, the source of the viewing request. Then, as described above, the second processing unit 20 outputs this message indicating that viewing is not permitted to the viewer. This realizes the restriction of viewing that reflects the user's intentions in this embodiment.

[0082] [Operation] Next, we will explain the operation of each device included in the information sharing system S during processing for information sharing.

[0083] [Operation of the first processing unit 10] Figure 9 is a flowchart showing the flow of operations performed by the first processing unit 10 during information sharing processing. The operation of the first processing unit 10 begins when the first processing unit 10 is started up.

[0084] In step S11, the first processing control unit 151 determines whether or not user information for a user using the user terminal 30 is registered. If user information is registered, the determination in step S11 is Yes, and the process proceeds to step S13. On the other hand, if user information is not registered, the determination in step S11 is No, and the process proceeds to step S12.

[0085] In step S12, the first processing control unit 151 acquires user information through communication with the user terminal 30 and stores the acquired user information in the user information storage unit 171. Thus, the first processing control unit 151 registers the user information.

[0086] In step S13, the first processing control unit 151 performs control related to the application executed on the user terminal 30 as the first process.

[0087] In step S14, the first processing control unit 151 acquires first health information from the user terminal 30 and stores the acquired first health information in the first health information storage unit 172.

[0088] In step S15, the viewing information generation unit 152 determines whether or not it has received a transmission instruction for viewing information from the information management device 40. If it has received a transmission instruction for viewing information, it is determined to be Yes in step S15, and the process proceeds to step S16. On the other hand, if it has not received a transmission instruction for viewing information, it is determined to be No in step S15, and the process proceeds to step S17.

[0089] In step S16, the browsing information generation unit 152 generates browsing information. The browsing information generation unit 152 then transmits the generated browsing information to the information management device 40.

[0090] In step S17, the first processing control unit 151 determines whether or not to terminate the first process (in this case, control related to the application executed on the user terminal 30). If the first process is to be terminated, the determination in step S17 is Yes, and the process ends. Then, the process restarts from step S11. On the other hand, if the first process is not to be terminated, the determination in step S17 is No, and the process is repeated from step S13.

[0091] [Operation of the second processing unit 20] Figure 10 is a flowchart showing the flow of operations performed by the second processing unit 20 during information sharing processing. The operation of the second processing unit 20 begins when the second processing unit 20 is started up.

[0092] In step S21, the second processing execution unit 251 determines whether or not user information for a user using the user terminal 30 is registered. If user information is registered, the determination is Yes in step S22, and the process proceeds to step S23. On the other hand, if user information is not registered, the determination is No in step S21, and the process proceeds to step S22.

[0093] In step S22, the second processing execution unit 251 acquires user information through user information input operations or communication with the user terminal 30 or information management device 40, etc., and stores the acquired user information in the user information storage unit 271. In this way, the second processing execution unit 251 registers the user information.

[0094] In step S23, the second processing unit 251 executes the business program as the second process.

[0095] In step S24, the second health information acquisition unit 252 acquires the second health information and stores the acquired second health information in the second health information storage unit 272.

[0096] In step S25, the viewing request unit 253 determines whether or not it has received a request to send a viewing request from a viewer using the second processing unit 20. If it has received a request to send a viewing request, it determines Yes in step S25 and proceeds to step S28. On the other hand, if it has not received a request to send a viewing request, it determines No in step S25 and proceeds to step S30.

[0097] In step S26, the access request unit 253 transmits an access request for the first health information to the information management device 40.

[0098] In step S27, the access request unit 253 determines whether the response to this access request contains access information. If it contains access information, the result in step S27 is determined to be Yes, and the process proceeds to step S28. On the other hand, if it does not contain access information, the result in step S27 is determined to be No, and the process proceeds to step S29.

[0099] In step S28, the viewing request unit 253 outputs viewing information to the viewer. This realizes the viewing process in this embodiment.

[0100] In step S29, the access request unit 253 outputs a message to the viewer indicating that access is not permitted. This realizes the restriction of access that reflects the user's wishes in this embodiment.

[0101] In step S30, the second processing execution unit 251 determines whether or not to terminate the second process (in this case, the execution of the business program). If the second process is to be terminated, the determination in step S30 is Yes, and this process is terminated. Then, this process is restarted from step S21. On the other hand, if the second process is not to be terminated, the determination in step S30 is No, and the process is repeated from step S23.

[0102] [Operation of user terminal 30] Figure 11 is a flowchart showing the flow of operations performed by the user terminal 30 during information sharing processing. The operation on the user terminal 30 begins in response to the user terminal 30 receiving a command from the user to start the application.

[0103] In step S31, the first processing execution unit 351 determines whether or not user information for a user using the user terminal 30 is registered. If user information is registered, the determination in step S31 is Yes, and the process proceeds to step S33. On the other hand, if user information is not registered, the determination in step S31 is No, and the process proceeds to step S32.

[0104] In step S32, the first processing execution unit 351 acquires user information through an input operation for user information and stores the acquired user information in the user information storage unit 371. Thus, the first processing execution unit 351 registers the user information.

[0105] In step S33, the first processing execution unit 351 executes the application as the first process.

[0106] In step S34, the first health information acquisition unit 352 acquires the first health information and stores the acquired first health information in 373. The first health information acquisition unit 352 also transmits the acquired first health information to the first processing unit 10.

[0107] In step S35, the viewing condition setting unit 353 determines whether or not it has received an instruction from the user using the user terminal 30 to set viewing conditions for viewing the first health information. If an instruction to set viewing conditions has been received, the determination in step S35 is Yes, and the process proceeds to step S36. On the other hand, if an instruction to set viewing conditions has not been received, the determination in step S35 is No, and the process proceeds to step S37.

[0108] In step S36, the browsing condition setting unit 353 communicates with the information management device 40 to set browsing conditions in a format such as the table shown in Figure 7.

[0109] In step S37, the first processing execution unit 351 determines whether or not to terminate the first process (in this case, the execution of the application). If the first process is to be terminated, the determination in step S37 is Yes, and the process is terminated. Then, the process is restarted from step S31. On the other hand, if the first process is not to be terminated, the determination in step S37 is No, and the process is repeated from step S33.

[0110] [Operation of Information Management Device 40] Figure 12 is a flowchart showing the flow of operations performed by the information management device 40 during information sharing processing. The operation of the information management device 40 begins when the information management device 40 is started up.

[0111] In step S41, the user information management unit 451 determines whether a predetermined update timing has arrived for updating user management information. If the update timing has arrived, the determination in step S41 is Yes, and the process proceeds to step S42. On the other hand, if the update timing has not arrived, the determination in step S41 is No, and the process proceeds to step S43.

[0112] In step S42, the user information management unit 451 acquires user information stored in the first processing unit 10, the second processing unit 20, and the user terminal 30. Then, the user information management unit 451 updates the user management information based on the user information acquired from these devices.

[0113] In step S43, the browsing condition management unit 452 determines whether or not new browsing conditions have been set from the user terminal 30. If new browsing conditions have been set, the determination in step S43 is Yes, and the process proceeds to step S44. On the other hand, if no new browsing conditions have been set, the determination in step S43 is No, and the process proceeds to step S45.

[0114] In step S44, the browsing condition management unit 452 adds the newly set browsing conditions as new items to be managed. Specifically, the browsing condition management unit 452 stores these newly set browsing conditions in the browsing condition storage units 472 of each of the multiple information management devices 40. The browsing condition management unit 452 then manages these set browsing conditions using the distributed ledger blockchain BC, as described above.

[0115] In step S45, the determination unit 453 determines whether or not it has received a request to view the first health information from the second processing unit 20. If the request to view the first health information has been received, the determination in step S45 is Yes, and the process proceeds to step S46. On the other hand, if the request to view the first health information has not been received, the determination in step S45 is No, and this process ends. Then, the process restarts from step S41.

[0116] In step S46, the determination unit 453 determines whether or not to allow viewing based on the viewing conditions managed by the viewing condition management unit 452 using blockchain BC.

[0117] In step S47, the access control unit 454 determines whether the determination unit 453 has permitted access. If access is permitted, the determination in step S47 is Yes, and the process proceeds to step S48. On the other hand, if access is not permitted, the determination in step S47 is No, and the process proceeds to step S50.

[0118] In step S48, if the determination unit 453 determines that viewing is permitted, the viewing control unit 454 sends a transmission instruction for viewing information to the first processing unit 10 corresponding to the viewing request. The viewing control unit 454 then receives the viewing information from the first processing unit 10.

[0119] In step S49, the browsing control unit 454 transmits the received browsing information to the second processing unit 20, the source of the browsing request. This terminates the process once. The process then restarts from step S41.

[0120] In step S50, the browsing control unit 454 sends a message to the second processing unit 20, the source of the browsing request, indicating that browsing is not possible. This terminates the process once. The process then restarts from step S41.

[0121] As described above, the operation of each device included in the information sharing system S during processing for information sharing is achieved by allowing the first health information handled by the first processing unit 10 to be viewed by the second processing unit 20, which performs other processing. In this case, the information sharing system S does not allow the second processing unit 20 to view the information without restriction, but rather determines whether or not to allow viewing based on viewing conditions set by the user. This allows the user to arbitrarily choose where information about themselves can be viewed. Furthermore, the information sharing system S can share information across multiple processes while enhancing its confidentiality and availability by reflecting such user-based choices. Therefore, the information sharing system S allows for the appropriate sharing of user information across multiple processes.

[0122] [Example Display] Next, we will describe an example of a screen display that includes various information and a user interface, as shown in the information sharing system S. Figure 13 is a schematic diagram showing an example of a terminal operation screen 60 displayed on the user terminal 30 when registering user information (corresponding to step S32 in Figure 11) or when setting viewing conditions (corresponding to step S36 in Figure 11). Figure 13 shows three example operation screens as an example. As shown in Figures 13(A), 13(B), and 13(C), the terminal operation screen 60 includes an operation instruction area 61, a main operation area 62, and a transition button display area 63 as display areas. Note that in Figure 13(A), the transition button display area 63 is omitted.

[0123] The terminal operation screen 60 shown in Figure 13(A) is a menu screen. In this case, the operation instruction area 61 displays text prompting the user to select a menu. The user selects a menu by following this text and selecting one of the various buttons displayed in the main operation area 62. These various buttons include, for example, an "App Start" button to select the application to be executed, a "Health Information Confirmation" button to check the acquired first health information on the user terminal 30, a "User Registration" button to register user information, and a "Browsing Conditions" button to set browsing conditions. If the user selects the "User Registration" button, the screen transitions to the user information registration screen shown in Figure 13(B). If the user selects the "Browsing Conditions Settings" button, the screen transitions to the browsing conditions settings screen shown in Figure 13(C).

[0124] The terminal operation screen 60 shown in Figure 13(B) is the screen for registering user information (corresponding to step S32 in Figure 11). In this case, the operation instruction area 61 displays text prompting the user to register user information. The user enters their own information in each item displayed in the main operation area 62 according to this text. For example, they enter information indicating the user's attributes such as name, phonetic name, and date of birth, as well as information such as password and email address. After the user has finished entering the information, they select the "Execute Registration" button displayed in the transition button display area 63. This executes the registration of user information on the user terminal 30. On the other hand, if the user wishes to cancel the registration of user information midway, they select the "Menu Screen" button displayed in the transition button display area 63. This transitions the screen to the menu screen shown in Figure 13(A).

[0125] The terminal operation screen 60 shown in Figure 13(C) is a screen for setting viewing conditions (corresponding to step S36 in Figure 11). In this case, the operation instruction area 61 displays text prompting the user to set viewing conditions. The user sets the viewing conditions by selecting from the items displayed in the main operation area 62 according to this text. The viewing conditions include whether or not to allow viewing for any combination of any first processing unit 10 (or any first health information acquired by it) and any second processing unit 20, as shown in Figure 6. In this display, the application name provided by the first processing unit 10 is shown, rather than the name of the first processing unit 10 (for example, information corresponding to a code such as 10-1), in order to make it easier for the user to understand. Similarly, the business program name provided by the second processing unit 20 is shown, rather than the name of the second processing unit 20 (for example, information corresponding to a code such as 20-1).

[0126] The user selects the application to be viewed and the viewing business program that is permitted to view the first health information acquired by this application. This determines the combination to be permitted to view this time. Furthermore, the user selects the range of the first health information acquired by this application that is permitted to be viewed. After the user has finished making selections, the user selects the "Execute Settings" button displayed in the transition button display area 63. This executes the setting of viewing conditions on the user terminal 30. By repeating this operation, the user can permit viewing for various combinations within any viewing range. On the other hand, if the user wishes to cancel the setting of viewing conditions midway, for example, the user selects the "Menu Screen" button displayed in the transition button display area 63. This transitions the screen to the menu screen shown in Figure 13(A). In this way, by providing various screens on the user terminal 30, users can easily register user information and set viewing conditions.

[0127] Figures 14 and 15 are schematic diagrams showing an example of a browsing screen displayed in the second processing unit 20 when browsing information is output (corresponding to step S28 in Figure 10).

[0128] The browsing screen 70 shown in Figure 14 is a menu screen. As shown in Figure 14, the browsing screen 70 includes a login status display area 71 and a target selection area 72 as display areas. The login status display area 71 shows the viewer (in this case, "△-san") who has logged into the business program running on the second processing unit and is about to view the first health information. In this example, a scenario is assumed in which the first health status of each family member is viewed, and the logged-in viewer is one of these family members. This viewer selects whose first health information to view from the target selection area 72. In this case, the target to be viewed may be the viewer themselves or a family member of the viewer. Furthermore, in this case, the target person that the viewer can view and the range of first health information that can be viewed are determined by the viewing conditions set by each family member as a user.

[0129] In this example, let's assume the viewer selects the "△Tai-kun" button. The screen then transitions to the viewing screen 80 shown in Figure 15. If the viewer selects the "Logout" button from the target selection area 72, the login status is terminated and the viewing ends.

[0130] The browsing screen 80 shown in Figure 15 is the first health information browsing screen. As shown in Figure 15, the browsing screen 80 includes a login status display area 81 and an information display area 82 as display areas. The login status display area 81, like the login status display area 71 described above, displays the viewer who is trying to view the first health information (in this case, "△-san").

[0131] The information display area 82 displays the first health information of "△Futa-kun," who has been selected as the person to view the first health information. As described above, the first health information in this embodiment is assumed to include not only information obtained from tests in a general health checkup, but also a variety of other information related to health and medical care, such as information on daily life such as diet, sleep, and exercise intensity, various measured biological information, guidance on medical diagnosis and treatment, guidance on pharmaceuticals and medication, and observations on rehabilitation and daily living assistance. Therefore, the information display area 82 displays these diverse first health information items in a list, categorized as, for example, "basic information," "lifestyle information," and "medical information."

[0132] In this case, the first health information may be displayed as a numerical value, as a statement indicating the condition such as "abnormal" or "normal," or as a graph or other format to easily grasp changes over time, such as "height changes" or "weight changes." It may also be displayed in text form, such as "Message from the pharmacist." Furthermore, in this case, a message intended to facilitate communication may also be displayed in text form.

[0133] In addition, only the first health information may be displayed, or the second health information obtained by the business program may also be displayed. Furthermore, buttons such as a "Detailed Information" button to transition to a screen displaying more detailed information may be displayed in the information display area 82. If the viewer selects the "Logout" button from the information display area 82, the login status will be canceled and viewing will end. Also, if the viewer selects the "Menu Screen" button from the information display area 82, the screen will transition to the menu screen shown in Figure 14.

[0134] By viewing the first and second health information in this way, viewers (in this case, "Mr. △") can understand not only their own health status but also that of their family members. This allows family members to monitor each other's health and manage their health more appropriately. Furthermore, by viewing the first and second health information in this way, healthcare professionals (for example, doctors, pharmacists, home helpers, and physical therapists) can share various medical information among themselves and provide more appropriate medical guidance and treatment. Therefore, for example, the information sharing system S can be effectively used when families mutually check each other's health status, or when various healthcare professionals and family members are involved in providing comprehensive community care for a single individual.

[0135] [Differentiation] It should be noted that the present invention is not limited to the embodiments described above, and any modifications, improvements, etc., that can achieve the objectives of the present invention are included in the present invention. In this case, the embodiments described above and their modifications, improvements, etc. are included in the scope and gist of the invention as described herein, etc., and are also included in the scope of the invention and its equivalents as described in the claims. As an example, the embodiments of the present invention described above may be modified as follows.

[0136] [Example 1] The configuration of the information sharing system S in the above-described embodiment is merely an example and is not limited thereto. For example, in the above-described embodiment, a business operator acting as a provider manages a plurality of information management devices 40, and these plurality of information management devices 40 form a blockchain BC. That is, the blockchain BC is formed in a manner referred to as private, using only the devices managed by this business operator. However, it is not limited to this, and for example, the blockchain BC may also be formed by including devices managed by businesses other than this business operator (e.g., the first processing unit 10 and the second processing unit 20) and devices used by users (e.g., user terminals 30). That is, the blockchain BC may be formed in a manner referred to as consortium type or public type. Alternatively, the information management device 40 may manage viewing conditions in a secure manner other than blockchain BC. Furthermore, in the embodiments described above, the application was executed as the first process and the business program was executed as the second process, but this is not limited to this. The first and second processes may be implemented by executing other software other than the application or business program.

[0137] [Differentiation 2] In the embodiments described above, a scenario was described in which the first health information acquired by the first processing unit 10 is viewed by the second processing unit 20 based on viewing conditions set by the user, but the embodiment is not limited to this. For example, the first health information acquired by the first processing unit 10 may be made viewable by other first processing units 10 based on viewing conditions set by the user. In addition, the second health information acquired by the second processing unit 20 may be made viewable by other second processing units 20 or the first processing unit 10 based on viewing conditions set by the user.

[0138] [Difference 3] In the embodiment described above, the user using the user terminal 30 is responsible for setting the viewing conditions, and it was assumed that this user would arbitrarily set the viewing conditions for their own first health information based on their own will. However, this is not limited to this, and for example, other persons besides this user may be allowed to set the viewing conditions for some of the first health information. This would allow other persons, such as medical professionals who provide medical guidance or treatment to the user, or the user's family, to set the viewing conditions. Therefore, health information that is undesirable for the user to manage themselves (for example, a disease name before it is disclosed to the user, or the results of specialized tests that the user does not need to know) can be appropriately managed by another person by setting viewing conditions.

[0139] [Differentiation Example 4] In the embodiment described above, the viewing conditions were set to include whether or not to allow viewing for any combination of the first processing unit 10 (which first health information acquired by it) and any combination of the second processing unit 20. However, the viewing conditions are not limited to this, and can be set in more detail. For example, the first health information that can be viewed may differ depending on who the viewer using the second processing unit 20 is.

[0140] For example, as described above with reference to Figures 14 and 15, if the second processing unit 20 is used to allow family members to view primary health information, the primary health information that can be viewed may differ depending on which family member the viewer identified as the logged-in user is. For example, if the viewer is the father, they may be able to view the primary health information of all family members, but if the viewer is a child, they may only be able to view their own primary health information. Similarly, if the viewer is a healthcare professional, they may only be able to view primary health information related to their job. This makes it possible to set viewing conditions that better reflect the purpose of viewing the content and the user's intentions.

[0141] [Difference 5] In the embodiment described above, as shown in Figure 7, for each combination of the application that acquires the first health information (corresponding to the first processing unit 10) and the business program that views this first health information (corresponding to the second processing unit 20), whether or not to allow viewing was set as a viewing condition based on the user's will. This is not the only way to set viewing conditions; other information may also be used. For example, the viewing conditions may be set to determine whether or not to allow viewing based on the "attributes" of the viewer who made the viewing request using the second processing unit 20.

[0142] In this case, first, the user information stored in the user information storage unit 171, user information storage unit 271, and user information storage unit 371 is further enhanced with attribute information, which indicates the attributes of the viewer. Then, the user information management unit 451 integrates this user information, which includes the attribute information, and stores it as user management information in the user management information storage unit 471. An example of user management information in this case will be explained with reference to Figure 16(a). Here, Figure 16(a) is a table showing an example of user management information managed by the information management device 40.

[0143] As shown in Figure 16(a), this table provides a column (row) for each of the multiple users as user management information. In addition, a record (column) is provided for each of the user identifiers and attribute information. In this case, the multiple users include not only users who use the user terminal 30, but also other persons who request to view the first health information using the second processing unit 20.

[0144] A user identifier is a unique identifier assigned to each user to distinguish them from other users. Attribute information, on the other hand, is information that indicates the attributes of each user. There are no particular limitations on what information constitutes attribute information; it can be arbitrarily determined according to the purpose of the information sharing system S. For example, as illustrated in the above-described embodiment, if the purpose is for a healthcare professional to view the first health information, then each piece of information indicating the characteristics of the healthcare professional, such as the healthcare professional's medical qualifications, medical specialty, length of experience in medical work, location of the medical facility where they work, and gender, would be considered attribute information.

[0145] Furthermore, the correspondence between users and attribute information may be a one-to-one relationship, or it may be a one-to-many relationship as shown in the diagram. In other words, it may be possible to set only one attribute piece of information for a single user (for example, only medical qualifications), or it may be possible to set multiple attribute pieces of information (for example, medical qualifications, medical specialty, and location of the medical facility where they work). This allows for setting viewing conditions from various perspectives based on various attribute pieces of information, enabling settings that more precisely reflect the user's intentions.

[0146] The user information management unit 451 then sets attribute information indicating each user's attributes in each field (cell) where a column and a record intersect, based on the user information obtained from each device, such as the first processing unit 10, the second processing unit 20, and the user terminal 30. For example, if attribute A is "medical qualification," then attribute information indicating the medical qualifications held by each user (for example, "A-1" for a doctor, "A-2" for a pharmacist, ..., "A-10" for a home helper, etc.) is set in the column for attribute A and each user's field (cell).

[0147] The user management conditions set in this manner are managed by the information management device 40 in a format similar to that shown in this table. Although not shown in the diagram, authentication information such as passwords and contact information such as email addresses may also be included in the user management information.

[0148] Next, the viewing conditions in this modification will be explained. When the viewing condition setting unit 353 receives an instruction from a user using the user terminal 30 to set viewing conditions for viewing the first health information, it sets the viewing conditions in the information management device 40. These viewing conditions can be set arbitrarily by the user using the user terminal 30 based on their own will. An example of these viewing conditions will be explained with reference to Figure 16(b). Here, Figure 16(b) is a table showing an example of viewing conditions that are set by the user terminal 30 and managed by the information management device 40 in this modification.

[0149] As shown in Figure 16(b), this table has a column (row) for each of the multiple first health information entries as the viewed information. In addition, a record (column) is provided for each attribute of the viewer who can view the viewed information using the second processing unit 20.

[0150] The viewing condition setting unit 353 then sets information indicating whether viewing is permitted or not, such as "viewable" or "viewable," for each field (cell) where a column and a record intersect, based on the setting instructions of the user using the user terminal 30. For example, if a user wants to allow doctors and pharmacists to view the first health information a, but does not want other medical professionals to view it, they would set attributes A-1 and A-2 to "viewable" and attributes A-3 to A-10 to "viewable". Thus, the viewing conditions are set to include whether or not to allow viewing for any combination of any first processing device 10 (or any first health information acquired by it) and any viewer having any of the attributes.

[0151] The viewing conditions set in this manner are managed by the information management device 40 in a format similar to this table. This table corresponds to the viewing conditions set for a single user; if there are multiple users, multiple tables similar to this one are created for each of these users. Furthermore, although this table is set for attribute A, similar tables may be created for other attributes (for example, attributes B to N).

[0152] Then, when performing the series of processes for information sharing described above with reference to Figures 9 to 12, in this modified example, the request to view the first health information transmitted from the second processing unit 20 further includes the viewer's user identifier as information to identify which user the viewer is. Upon receiving this viewing request, the determination unit 453 identifies the viewer's attributes by referring to user management information as illustrated in Figure 16(a). Based on the identified viewer's attributes and the viewing conditions as illustrated in Figure 16(b), the determination unit 453 determines whether at least a portion of the requested first health information is permitted for viewing by this viewer. In this modified version, it becomes possible to decide whether or not to grant access based on the attributes of the person who requested the access. Therefore, the destination of health information can be set more flexibly, and it becomes easier to reflect the user's wishes.

[0153] Furthermore, this modified example may be further modified. For example, access may be permitted only if all of multiple attributes are determined to be "viewable". For instance, suppose a user wants to allow access only to viewers who meet multiple conditions, such as having a medical qualification as a "home helper" and being of the "same gender" as the user. In this case, access would be permitted only if the attribute indicating medical qualification is determined to be "viewable" and the attribute indicating gender is also determined to be "viewable". Alternatively, access may be permitted only if various attributes, such as having the same chronic illness as the user, being close in age to the user, having given birth, or having similar test results in disease-related tests to the user's, are determined to be "viewable". By considering multiple attributes in this way, it becomes possible to reflect the user's wishes in more detail. For example, it becomes possible to reflect the user's wish to have their primary health information viewed by healthcare professionals in similar circumstances and to be treated by such professionals.

[0154] Furthermore, as mentioned above, attribute information can be arbitrarily determined according to the purpose of the information sharing system S. For example, consider a case where the purpose of the information sharing system S is to form a community by allowing patients suffering from the same disease to refer to each other's primary health information. In this case, information indicating the disease a person has is managed as attribute information. The user then makes their information (e.g., the user's contact information) "viewable" only to viewers who suffer from the same disease. This allows for the formation of a community where patients suffering from the same disease can refer to each other's primary health information. In particular, when the disease is unusual, mutual viewing of primary health information makes it possible to collect useful information for patients and the healthcare professionals who deal with them. Furthermore, in cases where a community is formed by mutually viewing primary health information, it can be beneficial to also collect the progress of primary health information after a user's illness has been cured. Therefore, even after attribute information changes due to a user's illness being cured, it may be possible to allow mutual viewing of primary health information for a certain period of time.

[0155] Another example is when a user requests a service from a specialist. In this case, attribute information, specifically information indicating the specialist's skills, is managed as attribute information. The user's information (e.g., the user's contact information) is then made "viewable" only to viewers who are suitable for the service the user requests (i.e., viewers who possess the relevant skills as attribute information). This ensures that the contact information of the user who wants to request a service is only viewable by the appropriate viewers. In other words, the user's information can only be viewed by specialists who are capable of accepting the request. In this way, by appropriately setting attribute information, the information sharing system S can be used for a wider range of purposes, allowing users to view information that reflects their intentions.

[0156] [Modification 6] In the embodiment described above, whether or not to allow viewing was set as a viewing condition for each combination of the first processing unit 10 and the second processing unit 20. Alternatively, in the modified example 5 described above, whether or not to allow viewing was set as a viewing condition for each combination of the first processing unit 10 and the attributes of the viewer. In this way, by setting viewing conditions in advance, it is possible to appropriately ensure that users can view information that reflects their intentions. However, it may be difficult to set whether or not viewing is permitted for all possible combinations in advance. Also, there may be cases where it is necessary to review the viewing permissions afterward.

[0157] Therefore, for example, if the viewing conditions determine that viewing is not permitted, a request for permission to view may be sent to the user. This eliminates the need for users to pre-determine whether to allow viewing for all possible combinations; they only need to decide whether to allow viewing when a viewing permission request is received. Furthermore, users can review their viewing permission settings when a viewing permission request is received. In this case, the operation of the information management device 40 and the operation of the user terminal 30 can be modified as shown in Figures 17 and 18 below.

[0158] Figure 17 is a flowchart showing the flow of operations performed by the information management device 40 during information sharing processing in this modified example. In the following explanation referring to Figure 17, redundant explanations will be omitted for processes that are common to the process in Figure 12 described above (i.e., processes with the same reference numerals attached to the steps).

[0159] If, in step S47, the viewing condition was "Viewing not permitted," and the determination unit 453 did not permit viewing, then the result in step S47 is determined to be "No," and the process proceeds to step S61.

[0160] In step S61, the browsing control unit 454 sends a browsing permission request to the user terminal 30 in order to request permission to browse the first health information to the user corresponding to the first health information for which a browsing request has been made.

[0161] In step S62, the access control unit 454 determines whether the response to the access permission request is to grant access. If access is granted, the determination in step S62 is Yes, and the process proceeds to step S48. Then, as described above, the processing from step S48 onward is performed, and the first health information is accessed. On the other hand, if access is not permitted (i.e., access is not allowed), the result is determined as No in step S62, and the process proceeds to step S29. Then, as described above, the processing from step S50 onward is carried out, and access to the first health information is not performed.

[0162] Figure 18 is a flowchart showing the flow of operations performed by the user terminal 30 during information sharing processing in this modified example. In the following explanation referring to Figure 18, redundant explanations will be omitted for processes that are common to the process in Figure 11 described above (i.e., processes that share the same symbols in the steps).

[0163] In step S71, the viewing condition setting unit 353 determines whether or not it has received a request from the information management device 40 for permission to view the first health information. If a request for permission to view the first health information has been received, the determination in step S71 is Yes, and the process proceeds to step S72. On the other hand, if a request for permission to view the first health information has not been received, the determination in step S71 is No, and the process proceeds to step S37.

[0164] In step S72, the viewing condition setting unit 353 informs the user that it has received a request for permission to view the first health information and accepts the user's setting instructions regarding whether or not to grant permission to view. The viewing condition setting unit 353 then determines whether or not the setting instructions received from the user grant permission to view the first health information. If the user grants permission to view the first health information, the determination in step S72 is Yes, and the process proceeds to step S74. On the other hand, if the user does not grant permission to view the first health information (i.e., viewing is not permitted), the determination in step S72 is No, and the process proceeds to step S73.

[0165] In step S73, the browsing condition setting unit 353 sends a message to the information management device 40 indicating that browsing is not permitted, as a response to the request for permission to browse. In step S74, the browsing condition setting unit 353 sends a message to the information management device 40 indicating that browsing is permitted as a response to the request for permission to browse.

[0166] In step S75, the browsing condition setting unit 353 communicates with the information management device 40 to set the browsing conditions so that the combination for which browsing was permitted this time is set to "viewable". As a result, the combination for which browsing was permitted this time is reflected in the browsing conditions, and browsing will be permitted thereafter. If you want to allow access this time, but require a separate permission request for future access, you may omit step S75 and not set the access conditions.

[0167] Thus, with this modification, the user does not need to decide in advance whether to allow viewing for all combinations; they only need to decide whether to allow viewing when a viewing permission request is made. Furthermore, the user can review whether to allow viewing when a viewing permission request is made.

[0168] [Example Configuration] As described above, the information sharing system S according to this embodiment comprises a viewing condition management unit 452, a determination unit 453, and a viewing control unit 454. The viewing conditions management unit 452 manages the viewing conditions for health information, which is information related to the user's health, based on the user's settings. When the determination unit 453 receives a request from the second processing unit 20 to view first health information, which is at least a part of the health information used by the first processing unit 10 for processing, it determines whether or not to allow viewing based on the viewing conditions managed by the viewing condition management unit 452. The browsing control unit 454, when permission to browse is granted by the determination unit 453, causes the second processing unit 20 to browse the first health information.

[0169] Thus, the information sharing system S enables information sharing by allowing the second processing unit 20, which performs other processing, to view the first health information handled by the first processing unit 10. In this case, the information sharing system S does not allow the second processing unit 20 to view the information without restriction, but rather determines whether or not to allow viewing based on viewing conditions set by the user. This allows the user to arbitrarily choose where to view health information, which requires particularly careful handling among various types of personal information. Furthermore, the information sharing system S can share health information across multiple processing units while enhancing the confidentiality and availability of the information, reflecting such user-based choices. In addition, the viewing control unit 454 of the information sharing system S can centrally manage viewing conditions. Therefore, the first processing unit 10 and the second processing unit 20 do not need to perform processing to manage viewing conditions or to determine whether or not to allow viewing. Therefore, according to the information sharing system S of the present invention, information about users can be appropriately shared across multiple processes.

[0170] The first health information is managed by the first processing unit 10. When access is permitted, the browsing control unit 454 obtains the first health information from the first processing unit 10 and allows the second processing unit 20 to view the obtained first health information. As a result, the browsing control unit 454 and the second processing unit 20 do not need to manage the first health information that the first processing unit 10 handles for processing. This eliminates the need for the browsing control unit 454 and the second processing unit 20 to store the first health information or to update the first health information in synchronization with the first processing unit 10.

[0171] The browsing control unit 454 enables browsing by displaying the image converted from the first health information on the second processing unit 20. This allows the objective of viewing the information in the second processing unit 20 to be achieved, while also preventing the first health information itself from being accidentally edited in the viewing control unit 454 or the second processing unit 20, or from being tampered with in the communication path, etc. Therefore, health-related information can be protected more appropriately while enhancing the integrity of the information.

[0172] There may be multiple instances of either or both of the first processing unit 10 and the second processing unit 20. The browsing condition management unit 452 manages whether or not to allow browsing for each combination of the first processing unit 10 and each second processing unit 20 as a browsing condition. This allows for more appropriate sharing of user information across a larger number of processes.

[0173] The browsing condition management unit 452 manages whether or not to allow browsing based on attribute information, which is information about the attributes of the user who made the browsing request using the second processing unit 20, as a browsing condition. This allows for decisions on whether or not to grant access based on criteria such as whether or not the person making the access request possesses certain attributes. Therefore, the destination of health information can be set more flexibly, making it easier to reflect the user's wishes.

[0174] If the determination unit 453 does not permit viewing, the viewing control unit 454 requests permission to view from the user corresponding to the first health information for which viewing was requested. If viewing is permitted in the response to the permission request, the second processing unit 20 is instructed to view the first health information. This eliminates the need for users to pre-determine whether or not to allow viewing of all second processing units 20; they only need to decide whether or not to allow viewing when a viewing request is made. In other words, it makes it easier for users to set viewing conditions.

[0175] The first processing unit 10 performs processing related to a predetermined function of the terminal used by the user, and acquires first health information in the processing related to the predetermined function. This makes it possible to obtain primary health information in relation to processing related to the functions of the device used by the user.

[0176] The browsing conditions management unit 452 allows another person, other than the user, to set at least some of the browsing conditions managed by the browsing conditions management unit 452 on behalf of the user. This will enable healthcare professionals who provide medical guidance and treatment to users, as well as the users' families, etc. Furthermore, individuals other than the user can set viewing conditions. Therefore, health information that the user does not want to manage (for example, a diagnosis before informing the user, or test results from specialized tests that the user does not need to know) can be managed by other individuals.

[0177] The browsing conditions management unit 452 stores browsing conditions in a distributed manner across multiple information processing devices and manages the browsing conditions based on the consistency of the distributed information stored among them. This allows for the management of viewing conditions while ensuring high security, for example, by using technologies such as blockchain.

[0178] The series of processes described above can be executed by hardware or by software. In other words, the functional configuration in the above-described embodiment is merely illustrative and not particularly limited. That is, it is sufficient that any computer constituting the information sharing system S is equipped with a function that can execute the series of processes described above as a whole, and the specific functional blocks used to realize this function are not limited to the examples shown. Furthermore, a single functional block may consist of hardware alone, software alone, or a combination of both.

[0179] Furthermore, the recording medium containing the program for executing the series of processes described above consists not only of removable media distributed separately from the main unit to the user in order to provide the program, but also of recording media provided to the user in a state where they are pre-installed in the main unit.

[0180] Furthermore, the effects described in the embodiments above are merely a list of the most preferred effects arising from the present invention, and the effects of the present invention are not limited to those described in these embodiments. [Explanation of symbols]

[0181] 10 First processing unit, 20 Second processing unit, 30 User terminal, 40 Information management device, 151 First processing control unit, 152 Browsing information generation unit, 171, 271, 371 User information storage unit, 172, 372 First health information storage unit, 251 Second processing execution unit, 252 Connection execution unit, 253 Browsing request unit, 272 Second health information storage unit, 351 First processing execution unit, 352 First health information acquisition unit, 353 Browsing condition setting unit, 451 User information management unit, 452 Browsing condition management unit, 453 Determination unit, 454 Browsing control unit, 471 User management information storage unit, 472 Browsing condition storage unit, 800 Information processing unit, 811 CPU, 812 ROM, 813 RAM, 814 Bus, 815 Input unit, 816 Output unit, 817 Storage unit, 818 Communication unit, 819 Drive, 820 Sensor unit, 831 Removable media, BC Blockchain, N Network, S Information sharing system

Claims

1. A management means for managing the viewing conditions of health information, which is information related to the user's health, based on the user's settings, The system provides a function to acquire at least a portion of the health information as first health information on a user terminal used by the user, and a first processing means for acquiring the first health information acquired by the user terminal through the acquisition function from the user terminal. When a request to view the first health information is received from the second processing means, a determination means determines whether or not to permit viewing based on the viewing conditions managed by the management means, When access is permitted by the determination means, access means obtains the first health information from the first processing means and allows the second processing means to access the obtained first health information, Equipped with, There are multiple first processing means, When the determination means receives a request from another first processing means to view the first health information acquired by one of the first processing means, it determines whether or not to permit viewing based on the viewing conditions managed by the management means. The viewing means, when viewing is permitted by the determination means, obtains the first health information from one of the first processing means and allows the other first processing means to view the obtained first health information. An information sharing system characterized by the following features.

2. A management means for managing the viewing conditions of health information, which is information relating to the user's health, based on the user's settings, The system provides a function to acquire at least a portion of the health information as first health information on a user terminal used by the user, and a first processing means for acquiring the first health information acquired by the user terminal through the acquisition function from the user terminal. When a request to view the first health information is received from the second processing means, a determination means determines whether or not to permit viewing based on the viewing conditions managed by the management means, When access is permitted by the determination means, access means obtains the first health information from the first processing means and allows the second processing means to access the obtained first health information, Equipped with, There are multiple second processing means, and each of the multiple second processing means acquires second health information through the processing it performs. When the determination means receives a request from another second processing means to view second health information acquired by one of the second processing means, it determines whether or not to permit viewing based on the viewing conditions managed by the management means. The viewing means, when viewing is permitted by the determination means, obtains the second health information from one of the second processing means and allows the other second processing means to view the obtained second health information. An information sharing system characterized by the following features.

3. A management means for managing the viewing conditions of health information, which is information relating to the user's health, based on the user's settings, The system provides a function to acquire at least a portion of the health information as first health information on a user terminal used by the user, and a first processing means for acquiring the first health information acquired by the user terminal through the acquisition function from the user terminal. When a request to view the first health information is received from the second processing means, a determination means determines whether or not to permit viewing based on the viewing conditions managed by the management means, When access is permitted by the determination means, access means obtains the first health information from the first processing means and allows the second processing means to access the obtained first health information, Equipped with, The second processing means acquires the second health information through the processing it performs, When the determination means receives a request to view the second health information from the first processing means, it determines whether or not to permit viewing based on the viewing conditions managed by the management means. The viewing means, when viewing is permitted by the determination means, obtains the second health information from the second processing means and allows the first processing means to view the obtained second health information. An information sharing system characterized by the following features.

4. A management means for managing the viewing conditions of health information, which is information relating to the user's health, based on the user's settings, The system provides a function to acquire at least a portion of the health information as first health information on a user terminal used by the user, and a first processing means for acquiring the first health information acquired by the user terminal through the acquisition function from the user terminal. When a request to view the first health information is received from the second processing means, a determination means determines whether or not to permit viewing based on the viewing conditions managed by the management means, When access is permitted by the determination means, access means obtains the first health information from the first processing means and allows the second processing means to access the obtained first health information, Equipped with, The management means sets multiple attribute pieces of information, which are information indicating the attributes of the viewer themselves, for each of the multiple viewers who make the viewing request using the second processing means, and manages whether or not to allow the viewing for each of the multiple attribute pieces of information as the viewing condition. The determination means determines, based on all attribute information related to the determination, that it will grant permission for viewing to viewers who are permitted to view. An information sharing system characterized by the following features.

5. A management function that manages the viewing conditions for health information, which is information related to the user's health, based on the user's settings, The user terminal used by the user is provided with a function to acquire at least a portion of the health information as first health information, and a first processing function to acquire the first health information acquired by the user terminal through the acquisition function from the user terminal. When the second processing function receives a request to view the first health information, the management function determines whether or not to allow viewing based on the viewing conditions managed by the management function, A viewing function that, when viewing is permitted by the aforementioned determination function, obtains the first health information from the first processing function and allows the second processing function to view the obtained first health information, To make this possible on a computer, Multiple instances of the aforementioned first processing function exist. The determination function, when it receives a request from another first processing function to view the first health information acquired by any of the first processing functions, determines whether or not to permit viewing based on the viewing conditions managed by the management function. The browsing function, when browsing is permitted by the determination function, obtains the first health information from one of the first processing functions and allows the other first processing function to view the obtained first health information. A program characterized by the following features.

6. A management function that manages the viewing conditions for health information, which is information relating to the user's health, based on the user's settings, The user terminal used by the user is provided with a function to acquire at least a portion of the health information as first health information, and a first processing function to acquire the first health information acquired by the user terminal through the acquisition function from the user terminal. When the second processing function receives a request to view the first health information, the management function determines whether or not to allow viewing based on the viewing conditions managed by the management function, A viewing function that, when viewing is permitted by the aforementioned determination function, obtains the first health information from the first processing function and allows the second processing function to view the obtained first health information, To make this possible on a computer, There are multiple second processing functions, and each of these multiple second processing functions acquires second health information through the processing it performs. The determination function, upon receiving a request from another second processing function to view second health information acquired by any of the second processing functions, determines whether or not to permit viewing based on the viewing conditions managed by the management function. The viewing function, when permission to view is granted by the determination function, obtains the second health information from one of the second processing functions and allows the other second processing function to view the obtained second health information. A program characterized by the following features.

7. A management function that manages the viewing conditions for health information, which is information relating to the user's health, based on the user's settings, The user terminal used by the user is provided with a function to acquire at least a portion of the health information as first health information, and a first processing function to acquire the first health information acquired by the user terminal through the acquisition function from the user terminal. When the second processing function receives a request to view the first health information, the management function determines whether or not to allow viewing based on the viewing conditions managed by the management function, A viewing function that, when viewing is permitted by the aforementioned determination function, obtains the first health information from the first processing function and allows the second processing function to view the obtained first health information, To make this possible on a computer, The second processing function acquires the second health information through the processing it performs, When the determination function receives a request to view the second health information from the first processing function, it determines whether or not to permit viewing based on the viewing conditions managed by the management function. The browsing function, when browsing is permitted by the determination function, obtains the second health information from the second processing function and allows the first processing function to view the obtained second health information. A program characterized by the following features.

8. A management function that manages the viewing conditions for health information, which is information relating to the user's health, based on the user's settings, The user terminal used by the user is provided with a function to acquire at least a portion of the health information as first health information, and a first processing function to acquire the first health information acquired by the user terminal through the acquisition function from the user terminal. When the second processing function receives a request to view the first health information, the management function determines whether or not to allow viewing based on the viewing conditions managed by the management function, A viewing function that, when viewing is permitted by the aforementioned determination function, obtains the first health information from the first processing function and allows the second processing function to view the obtained first health information, To make this possible on a computer, The management function sets multiple attribute pieces of information, which are information indicating the attributes of the viewer themselves, for each of the multiple viewers who make the viewing request using the second processing function, and manages whether or not to allow the viewing for each of the multiple attribute pieces of information as the viewing condition. The determination function determines, based on all attribute information related to the determination, that it will grant permission for viewing to viewers who are permitted to view. A program characterized by the following features.