Medical data viewing system, method, and program

The medical data browsing system addresses the issues of identity verification and consent by requiring user identification and verification before accessing medical data, ensuring secure and authorized use and sharing within the system.

JP7674304B2Active Publication Date: 2025-05-09SUMITOMO MITSUI BANKING CORP +1
View PDF 8 Cites 0 Cited by

Patent Information

Application Number
JP2022104510
Authority / Receiving Office
JP · JP
Patent Type
Patents
Current Assignee / Owner
Filing Date
2022-06-29
Publication Date
2025-05-09
Estimated Expiration
2042-06-29

AI Technical Summary

Technical Problem

Existing medical data browsing systems lack accurate patient identity verification, consent mechanisms, and secure sharing protocols, leading to potential misuse of medical data across multiple institutions and third-party access.

Method used

A medical data browsing system that includes a server for storing medical data and a terminal for requesting access, which requires user identification and identity verification before allowing data access, ensuring consent is obtained for data sharing and usage.

Benefits of technology

The system ensures accurate identity verification and consent for medical data access, preventing unauthorized use and enabling secure sharing among multiple medical institutions and third-party organizations.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 0007674304000001
    Figure 0007674304000001
  • Figure 0007674304000002
    Figure 0007674304000002
  • Figure 0007674304000003
    Figure 0007674304000003
Patent Text Reader

Abstract

To provide a system, a method, and a program for viewing medical data for verifying personal identification of a patient accurately and viewing, sharing, and using medical data on the basis of the consent of the patient.SOLUTION: A system for viewing medical data includes: a server for storing medical data of at least one user; and a first information terminal connected to the server for communications. The system for viewing medical data is formed to perform the steps of: receiving a first viewing request, which requests a first user to view first medical data, from a first information terminal; determining whether the first viewing request satisfies a first requirement; and permitting the first user to view the first medical data when the satisfaction of the first requirement is determined.SELECTED DRAWING: Figure 4
Need to check novelty before this filing date? Find Prior Art

Description

[Technical field]

[0001] The present invention relates to a medical data viewing system, method, and program for viewing, sharing, and using medical data. [Background technology]

[0002] Conventionally, the use of data called Personal Health Records (hereinafter simply referred to as PHRs), which are patient information collected in an integrated manner and stored centrally on a server (such as a cloud server), has been promoted. This PHR generally includes the patient's medical data (e.g., medical interview information, various test results, etc.) stored across multiple medical institutions. Patients can view this PHR and / or related information via devices such as smartphones. (Patent Document 1) [Prior art documents] [Patent documents]

[0003] [Patent Document 1] Patent Publication No. 2021-68178 Summary of the Invention [Problem to be solved by the invention]

[0004] The technology of Patent Document 1 discloses a technology in which a mobile terminal device transmits a request to view medical information to a medical information management server that accumulates medical information from multiple medical institutions, and if the user identification information is authenticated, the mobile terminal device permits viewing of the user's medical information. If viewing is permitted, the mobile terminal device displays the user's medical information accumulated in the medical information management server as a life chart integrated in chronological order. This allows the user to view the user's medical information managed by multiple medical institutions as integrated medical information.

[0005] (1) However, in conventional technologies such as Patent Document 1 and other PHR-related technologies, there are cases where accurate identity verification functions are not performed or are not even provided. This may lead to the possibility of medical data being viewed, collected, stored, shared, and / or utilized (hereinafter simply referred to as utilization) with inaccurate or no patient identity verification. Such inaccurate identity verification entails the risk of erroneously sending one patient's medical data to a completely different patient (for example, by sending medical data with only confirmation from the medical institution).

[0006] (2) In addition, in the conventional technology, when data of multiple patients (such as the patient's parents, siblings, and children) is collected on a single patient's device and stored on a specified server, it may be operated without obtaining clear consent from the multiple patients. For example, with only the consent of a patient (husband), it may be possible to allow the system to utilize medical data of the patient's parents, wife, children, brothers, sisters, etc. In other words, there is a possibility that data collection may be carried out against the will of multiple patients.

[0007] (3) In addition, in the past, from the perspective of handling medical data and contracts, many services only collect and store medical data from medical institutions, and there are no services that allow medical data to be viewed from one medical institution to another through a dedicated system. Therefore, medical data cannot be smoothly shared between medical institutions.

[0008] (4) In addition, there is a need to view, analyze, and process personal medical data, for example. However, in the conventional technology, there is no means for an individual patient to provide his / her own medical data to a third party other than a medical institution. For this reason, the collection and integration of medical data was completed only by the medical industry. From the viewpoint of protecting personal information, it is desirable to provide medical data to a third party in an appropriately anonymized state as necessary, but it is difficult for an individual patient to do this. In addition, it is not realistic for each medical institution to appropriately anonymize the medical data of patients, as this would put a strain on the medical business, which is their main business. Therefore, the current situation is that the needs for utilization in industries other than the medical industry as described above are not being adequately met.

[0009] (5) In addition, in the conventional technology, a parent may have the qualification to permit a medical institution or the like to utilize the medical data of the child, but the parent-child relationship may not be accurately confirmed. In such a case, the permission for utilization may be granted by a person who does not have the above-mentioned qualification, and the medical data may be utilized against the will of the child. In addition, when a child becomes an adult, the above-mentioned qualification should be lost and / or the qualification should be transferred to the child, but the conventional technology does not have such a function.

[0010] As described above, the conventional technology has several problems. Each of these problems requires a solution as follows.

[0011] In response to the above (1) and (2), the objective is to provide a medical data viewing system, method, and program for viewing, sharing, and using medical data after performing accurate patient identity verification and obtaining the patient's consent.

[0012] In response to (3) above, the objective is to provide a medical data viewing system, method, and program that enables multiple medical institutions to view, share, and use medical data through a dedicated system.

[0013] In response to (4) above, the objective is to provide a medical data viewing system, method, and program that enables a third-party institution other than a medical institution to view, analyze, and process anonymized medical data through a dedicated system.

[0014] In response to (5) above, the objective is to provide a medical data viewing system, method, and program that enables patients to view, share, and use medical data after verifying their identity and the relationship between patients.

[0015] The present invention has been made to solve these problems, and aims to provide a medical data viewing system, method, and program for viewing, sharing, and using medical data after performing accurate patient identity verification and obtaining the patient's consent.

[0016] In another aspect of the present invention, an object is to provide a medical data viewing system, method, and program that allows a plurality of medical institutions to view, share, and use medical data through a dedicated system.

[0017] In yet another aspect of the present invention, an object is to provide a medical data viewing system, method, and program that allows a third party institution other than a medical institution to view, analyze, and process anonymized medical data as necessary through a dedicated system.

[0018] In yet another aspect of the present invention, an object is to provide a medical data viewing system, method, and program that allows patients to view, share, and use medical data after verifying their identity and the relationships between patients. [Means for solving the problem]

[0019] One aspect of the present invention is a medical data viewing system that includes a server that stores medical data of one or more users, and a first information terminal that is communicatively connected to the server, and is characterized in that the system performs the following steps: receiving a first viewing request from the first information terminal to view first medical data of the first user, wherein the first viewing request includes at least one of a first user identification information of the first user and first personal identification information of the first user; determining whether the first viewing request satisfies a first requirement, wherein the first requirement is that the first viewing request includes at least one of the first user identification information and the first personal identification information; and if it is determined that the first requirement is satisfied, allowing the first user to view the first medical data. Effect of the Invention

[0020] According to the present invention, it is possible to provide a medical data viewing system, method, and program for viewing, sharing, and using medical data after performing accurate patient identification and obtaining the patient's consent.

[0021] Furthermore, according to the present invention, it is possible to provide a medical data viewing system, method, and program that allows a plurality of medical institutions to view, share, and use medical data through a dedicated system.

[0022] In addition, according to the present invention, a medical data viewing system, method, and program can be provided that allows a third-party institution other than a medical institution to view, analyze, and process anonymized medical data as needed through a dedicated system.

[0023] Furthermore, according to the present invention, it is possible to provide a medical data viewing system, method, and program that allows patients to view, share, and use medical data after verifying their identity and the relationship between patients. [Brief description of the drawings]

[0024] A more detailed understanding of the embodiments disclosed herein can be had from the following description, taken in conjunction with the accompanying drawings, in which: [Figure 1] FIG. 1 is a diagram showing the configuration of an entire system including a server 101 according to an embodiment of the present invention. [Diagram 2] FIG. 2 is a system configuration diagram of the server 101 according to the embodiment of the present invention. [Diagram 3] FIG. 3 is a flow diagram illustrating the medical data browsing process according to the present invention. [Figure 4] FIG. 4 is a flow diagram illustrating the process of granting viewing rights to medical data according to the present invention. [Diagram 5] FIG. 5 is a flow diagram illustrating the process of browsing medical data based on the browsing right according to the present invention. [Figure 6] FIG. 6 is a flow diagram illustrating a process for granting rights to medical data according to the present invention. [Figure 7] FIG. 7 is a flow diagram illustrating the medical data handover process according to the present invention. DETAILED DESCRIPTION OF THE PREFERRED EMBODIMENTS

[0025] (Definition of terms) In the present invention, a "medical institution" or "medical facility" may include hospitals, general clinics, dental clinics, pharmacies, nursing homes, ambulances, emergency medical helicopters, patients' homes where medical procedures may be performed such as visiting medical or nursing care, health checkup sites, vaccination sites, blood donation sites, and / or other medical facilities or medical sites.

[0026] In the present invention, a "patient user" may be a patient receiving medical treatment for an illness or injury, a healthy individual undergoing a medical checkup, a patient and / or a healthy individual participating in a clinical trial, a person in need of care receiving care, and their / their relatives, or other users of a medical data application described below. For the purpose of explanation in this specification, a general user who does not have any health problems is referred to as a "patient user". "Medical users" and "business users" other than patient users will be described later.

[0027] In the present invention, "medical data" may include all medical data that can be obtained from a patient user when performing a medical procedure or an equivalent procedure. For example, it may include interview information, various test results, drug prescription records, surgery records, vaccination information, image records, allergies, and treatment instructions from medical professionals. It may also include information provided by a patient user outside a medical institution or medical facility. For example, a patient user who is infected with the novel coronavirus and is recuperating at home may report his or her condition to a doctor from home via a medical data app described below. In this way, one or more of the medical conditions reported via the medical data app described below may be treated as medical data.

[0028] In the present invention, the "medical user" may be a user of the medical data application described below who mainly works at the above medical institution. For example, the user may be a doctor, dentist, public health nurse, midwife, nurse, radiological technologist, clinical laboratory technician, physical therapist, occupational therapist, orthoptist, clinical engineer, prosthetist, dental hygienist, emergency medical technician, pharmacist, speech-language-hearing therapist, registered dietitian, social worker, care worker, mental health and welfare worker, judo therapist, massage therapist, acupuncturist, or the like who performs medical procedures or procedures equivalent thereto for patient users.

[0029] In the present invention, a "business user" may be an organization, business operator, third party organization, and / or a person belonging to any of these organizations who wishes to use medical data other than a medical institution, and / or a user of a medical data application described below. Examples of business users may include pharmaceutical companies, medical device companies, research institutes, clinical trial agents, and / or organizations related to these.

[0030] Each of the above defined terms may include anything within the scope of the present invention.

[0031] Unless otherwise stated, in the following description of the present invention, "user" may include patient users, medical users, and business users.

[0032] [Embodiment 1] (Overall composition) 1 is a configuration diagram of an entire system including a server 101 according to an embodiment of the present invention. The server 101, medical institution server 102, medical institution server 103, information terminal 104, information terminal 105, information terminal 106, information terminal 107, and information terminal 108 are connected to each other so as to be able to communicate with each other via a well-known network 109 such as the Internet. In this specification, the server 101 is described as one device, but various processes executed by the server 101 may be configured to be distributed and executed by multiple devices. In FIG. 1, only one each of the information terminals 104 to 108 is shown, but multiple of these may exist.

[0033] The server 101 accepts various requests from the information terminals 104 to 108 and provides predetermined information to each information terminal. For example, when a request to view the medical data of patient user A is accepted from the information terminal 104 of patient user A and the view request matches a predetermined condition, one or more pieces of the medical data of patient user A can be transmitted to the information terminal 104. Also, for example, when there is consent and / or viewing permission information from patient user A, the server 101 can transmit the medical data of patient user A to the information terminals 105 to 108 within the permitted range.

[0034] For the purpose of explanation in this specification, it will be explained that medical institution server 102 is a local server installed in Hospital A (not shown), and medical institution server 103 is a local server installed in Hospital B (not shown). These are merely examples, and medical institution servers may not be installed in Hospitals A and B.

[0035] The medical institution servers 102 and 103 store medical data acquired at hospitals A and B, and can provide the medical data to the server 101. The medical data can be provided after obtaining consent and permission from the patient user. The medical data may be transmitted to the server 101 from an information terminal or the like used by the medical user via the network 109.

[0036] In this embodiment, for the purpose of explanation, it is assumed that patient user A is a patient who comes to hospital A for a medical examination, patient user B is a relative of patient user A, and medical user C is a doctor who examines patient user A at hospital A. In addition, in this embodiment, for the purpose of explanation, it is assumed that medical user D is a doctor working at hospital B, and business user E is an employee of a pharmaceutical company.

[0037] In this embodiment, it is assumed that patient user A uses information terminal 104, patient user B uses information terminal 105, medical user C uses information terminal 106, medical user D uses information terminal 107, and business user E uses information terminal 108.

[0038] Although the overall configuration of this embodiment has been described above, this is merely an example, and the above-mentioned overall configuration may be of any configuration as long as it does not deviate from the gist of the present invention.

[0039] (System Configuration) Fig. 2 is a system configuration diagram of a server 101 according to an embodiment of the present invention. As shown in Fig. 2, the server 101 includes a control unit 201, a main memory unit 202, an auxiliary memory unit 203, an interface (IF) unit 204, and an output unit 205, which are interconnected by a bus 212 or the like, like a general computer. The server 101 can also include an application 206, patient medical data 207, medical institution information 208, business information 209, user account information 210, and viewing right information 211 in the form of a file / database or the like.

[0040] The control unit 201 is also called a central processing unit (CPU), and controls each component of the server 101 and performs data calculations, and also reads out various programs stored in the auxiliary storage unit 203 into the main storage unit 202 and executes them. The main storage unit 202 is also called a main memory, and stores various received data, computer-executable instructions, and data after calculation processing according to the instructions. The auxiliary storage unit 203 is a storage device typified by a hard disk drive (HDD) and is used for long-term storage of data and programs.

[0041] 2 describes an embodiment in which the control unit 201, the main memory unit 202, and the auxiliary memory unit 203 are provided inside the same computer, but as another embodiment, the server 101 can be configured to realize parallel distributed processing by a plurality of computers by using a plurality of control units 201, main memory units 202, and auxiliary memory units 203. Also, as another embodiment, it is possible to provide an embodiment in which a plurality of servers for the server 101 are installed, and a single auxiliary memory unit 203 is shared by the plurality of servers.

[0042] The IF unit 204 plays the role of an interface when transmitting and receiving data to and from other systems and devices, and also provides an interface for receiving various commands and input data (various masters, tables, etc.) from a system operator. The output unit 205 provides a display screen for displaying processed data and a printing means for printing the data.

[0043] The application 206 stores a medical data sharing program (i.e., a medical data application) according to the present invention. The function of the medical data sharing program will be described later. The medical data sharing program can be provided by the server 101 to the information terminals 104 to 108.

[0044] The patient medical data 207 stores a user ID (identifier and / or identifier, hereinafter simply referred to as ID), medical data associated with the user ID, and a sharing level of each medical data. This medical data may be the medical data of the patient user provided from the medical institution servers 102 to 103 and / or the medical data provided by the user through the information terminals 104 to 108.

[0045] The sharing level is a setting for which classification of users the medical data will be shared with and to what extent in anonymized form. With the user's consent and permission, medical data can be shared with any user at the necessary sharing level. Details of consent and permission will be explained in the flow below. Examples of sharing levels include "only viewable by the user," "can be provided to users who have been granted viewing rights," "can be provided to medical users in anonymized form," and / or "can be provided to business users in anonymized form." The above are merely examples, and the operator of the medical data app can set any sharing level as desired.

[0046] In the medical data application of the present invention, in consideration of the protection of personal information, only users who have been granted the right to view the medical data of a patient user can view the medical data. Therefore, even family members or relatives cannot view the medical data of the patient user unless the patient grants the right to view the data. The same applies to medical users.

[0047] As described above, the medical data may include data when the patient user reports information on the progress of the illness to a doctor from outside the hospital. In this case, the patient user may transmit the report to the server 101 (and / or the medical institution servers 102 to 103) via an information terminal.

[0048] The medical institution information 208 stores information about medical institutions that have a contract to use the medical data application (hereinafter, simply referred to as contracted medical institutions). For example, one or more pieces of information such as the facility name, address, type of hospital, number of hospital beds, number of medical personnel working there, etc. These are merely examples, and information other than the above examples may be stored.

[0049] The business information 209 stores information about a business that has a contract to use the medical data application (hereinafter, simply referred to as a contract business). For example, one or more pieces of information such as a business name, an address, a contract business ID, and an employee number of an employee working for the contract business are stored. These are merely examples, and information other than the above examples may be stored.

[0050] The user account information 210 stores the account information of a user who uses the medical data application. In the medical data application described in this specification, a user inputs and registers predetermined information in the medical data application to open and create a user account. The predetermined information may include one or more pieces of information such as a user ID, name, age, sex, height, weight, telephone number, email address, occupation, address, medical history, illness or injury under treatment, family structure, lifestyle, user classification (patient, medical, business, etc.), consent to sharing of medical data, sharing level, viewing right ID, and / or utilization right granting ID. In addition, by registering information such as a bank account and credit card, it is also possible to pay medical expenses such as consultation fees and medicine fees via the medical data application. One or more of the above registered information may be treated as medical data. The viewing right ID will be described later. The utilization right granting ID will be described together when describing the second embodiment of the present invention.

[0051] In addition to the above specified information, medical users will register their medical licenses / qualifications and / or information about the medical institution / facility they work for in the medical data app. In addition to the above specified information, business users will register their business name, address, contracted business ID, etc. in the medical data app.

[0052] The viewing right information 211 stores information about the viewing right of each user. In the medical data application described in this specification, a patient user can grant another user the viewing right of his / her medical data. The viewing right information 211 may have, for example, one or more of a viewing right ID, a user ID of a user who granted the viewing right to another user, a user ID of a user who was granted the viewing right, a sharing level, and a viewing period.

[0053] The viewing right ID is an ID issued when a patient user grants viewing rights to his / her medical data to another user. The viewing right ID is associated with the user ID of the user who granted the viewing rights to the other user, the user ID of the user to whom the viewing rights were granted, the sharing level, the viewing period, etc. In addition, the viewing right ID may be enabled or disabled based on the viewing period, or may be disabled by a predetermined operation (for example, an operation by the user who granted the viewing rights to the other user).

[0054] 2, the medical institution servers 102-103 include a control unit 201, a main memory unit 202, an auxiliary memory unit 203, an interface (IF) unit 204, and an output unit 205, which are interconnected by a bus 212 or the like. The medical institution servers 102-103 may also include patient medical data 207 in the form of a file / database or the like. The functions of these components are similar to those described above, and therefore detailed description thereof will be omitted.

[0055] 2, the information terminals 104 to 108 include a control unit 201, a main memory unit 202, an auxiliary memory unit 203, an interface (IF) unit 204, and an output unit 205, all of which are interconnected by a bus 212 or the like. The functions of these components are similar to those described above, and therefore detailed explanations will be omitted.

[0056] The information terminals 104 to 108 may be computer devices (information processing devices) having at least a calculation function and a communication function. The information terminals 104 to 108 may be computers having a communication function, such as personal computers (PCs), smartphones, tablet devices, smart watches, and / or smart glasses, and are not limited to specific devices.

[0057] In the above, an embodiment has been described in which the server 101, the medical institution server 102, the medical institution server 103, and the information terminals 104 to 108 are connected to each other so as to be able to communicate with each other via the network 109, but the gist of the present invention can also be applied to other embodiments. For example, as seen in cloud services that have become widespread in recent years, the gist of the present invention can also be applied to an embodiment in which data and software required to implement the present invention are stored in an external computer, and the information terminals 104 to 108 access the computer to use the data and software.

[0058] (Opening a user account) Below, we will provide an overview of how to open a user account in the medical data sharing system.

[0059] The user downloads the medical data application from the server 101 via the information terminal 104. Next, the user starts the downloaded medical data application, and registers the above-mentioned predetermined information in the medical data application according to instructions from the medical data application.

[0060] Here, if "medical" is selected as the user category, the medical data application instructs the user to register information regarding medical licenses and qualifications held by the user. Also, if "business" is selected as the user category, the medical data application instructs the user to register information that proves that the user is a contracted business and / or a person belonging to a contracted business. Information that proves that the user is a contracted business and / or a person belonging to a contracted business can be, for example, a business ID and / or an employee number.

[0061] When the registration of the predetermined information is completed, the server 101 instructs the user to provide identity verification information via the medical data app. This identity verification information can be acquired, for example, by eKYC (electronic Know Your Customer) or the like (for example, by combining image data of an identity verification document with image data of the user's face to verify the identity). The user follows the instructions of the medical data app and transmits, for example, image data of an identity verification document and an image of the user's face to the server 101 via the medical data app. The server 101 executes identity verification processing based on the received identity verification information.

[0062] The above-mentioned methods of acquiring and processing identity verification information are merely examples, and any identity verification method may be included within the scope of the present invention. For example, a method of identity verification such as a public personal authentication service may be applied to the identity verification method of the present invention.

[0063] When the identity verification process is complete, the server 101 issues a user ID and stores it together with the user's registered information in the user account information 210. The server 101 notifies the user via the medical data application of the issued user ID and the completion of the user account opening.

[0064] A patient user may register the sharing level of medical data when or after opening an account, and can set the sharing level at any time. As described above, the sharing level can be set to determine which user and to what extent of medical data is shared. In addition to the examples of sharing levels described above, the sharing level can be set for each user, contracted medical institution, and contracted business, and / or for each type of medical data.

[0065] For example, it is possible to set medical data related to vaccination records for infectious diseases to be shared only with family, relatives, and the hospital where the patient is treated, and not to be provided to businesses. The types of settings to be provided can be set according to the wishes of the operator of the medical data app of the present invention.

[0066] In addition, the patient user can register the information of the patient card created at the contracted medical institution in the medical data application. This allows the patient user's account to be associated with the medical data stored in the medical institution servers 102 and 103 in the contracted medical institution.

[0067] (Process flow: Viewing medical data) 3 is a flow diagram illustrating a medical data viewing process according to the present invention. In this embodiment, the medical data sharing program stored in the application 206 is used, but the functions described may be performed by multiple programs.

[0068] The flow described below is premised on the assumption that the patient user A operates the medical data application via the information terminal 104 and transmits a request to view his / her own medical data to the server 101. In this embodiment, for the purpose of explanation, it is assumed that all medical data of the patient user A stored in the medical institution servers 102 and 103 is provided to the server 101.

[0069] In S301, the server 101 receives a viewing request from the information terminal 104. The viewing request may include, for example, one or more of the patient user A's user ID, name, age, sex, personal identification information, and desired viewing range. The desired viewing range is, for example, information such as date, symptoms, and medication.

[0070] The identity verification information may be face authentication, fingerprint authentication, SMS authentication, password information, or a combination thereof, and may be transmitted to the server 101 in any of the steps described below instead of S301.

[0071] In S302, the server 101 determines whether the received viewing request satisfies a predetermined requirement. The predetermined requirement may be, for example, whether the viewing request includes one or more pieces of information such as the patient user A's user ID, name, age, sex, personal identification information, and desired viewing range. If it is determined that the predetermined requirement is satisfied, the process proceeds to S303. If it is determined that the predetermined requirement is not satisfied, the server 101 notifies the patient user A that the predetermined requirement is not satisfied, and ends the process.

[0072] In S303, the server 101 checks the user ID included in the browse request against the user ID registered in the patient medical data 207.

[0073] In S304, the server 101 transmits the medical data associated with the user ID detected as a result of the matching to the information terminal 104. The range of medical data to be transmitted can be selected based on the above-mentioned "desired viewing range".

[0074] Through the above process, the patient user A can view his / her own medical data stored in the patient medical data 207 of the server 101.

[0075] When a medical user is granted a right to view medical data by a patient user, the medical user may view non-anonymized medical data. The granting of the right to view the medical data will be described later.

[0076] Similarly, business users can search for and view medical data whose sharing level is set to "can be provided to business users" as described above, in an anonymous state as necessary, by processing similar to S301 to S304.

[0077] The business user may also analyze and / or process such anonymized medical data in an independent computing environment, such as a sandbox environment, which may be provided, for example, by the medical data app of the present embodiment.

[0078] (Process flow: Granting permission to view medical data) 4 is a flow diagram for explaining the process of granting viewing rights to medical data according to the present invention. The flow explained below is based on the premise that patient user A (e.g., husband) grants viewing rights to medical data to patient user B (e.g., wife) in order to allow patient user B to view his / her own medical data. In addition, patient user A uses the information terminal 104, and patient user B uses the information terminal 105. It is assumed that patient users A and B have opened and are using accounts for the medical data app.

[0079] It is assumed that, prior to the flow described below, the patient user A operates the medical data application via the information terminal 104 and transmits a request for granting the right to view medical data.

[0080] In S401, the server 101 receives a request for granting viewing rights from the information terminal 104. The request for granting viewing rights may include, for example, the user ID, name, age, sex, sharing level, personal identification information, and / or information of a user to whom viewing is desired to be permitted, of patient user A. The information of a user to whom viewing is desired to be permitted may include, for example, one or more pieces of information such as the user ID, name, age, sex, relationship with patient user A, personal identification information, viewing permitted period, and / or viewing permitted range of patient user B. The viewing permitted range is, for example, specific information such as symptoms and medication.

[0081] One or more pieces of information about a user to be permitted to view can be acquired, for example, by reading a two-dimensional code displayed on the display of information terminal 104 with the camera of information terminal 105.

[0082] The personal identification information may be face authentication, fingerprint authentication, SMS authentication, password information, or a combination thereof, similar to the medical data browsing flow. The personal identification information may be transmitted to the server 101 in any of the steps described below, instead of S401.

[0083] In S402, the server 101 determines whether the received request for granting viewing rights meets predetermined requirements. The predetermined requirements may be, for example, whether the request includes the user ID, name, age, sex, sharing level, identity verification information, and / or information about the user to be permitted to view of the patient user A. If it is determined that the request meets the predetermined requirements, the process proceeds to S403. If it is determined that the request does not meet the predetermined requirements, the server 101 notifies the patient user A that the request does not meet the predetermined requirements, and ends the process.

[0084] In S403, the server 101 issues a viewing right ID based on the information included in the viewing right grant request, and associates the viewing right ID with each of the user IDs of the patient users A and B. For example, the issued viewing right ID is added to the information of the patient user A registered in the user account information 210. The same is true for the patient user B.

[0085] In S404, the server 101 stores the viewing right ID in the viewing right information 211, notifies the patient users A and B of information such as the issued viewing right ID, sharing level, viewing period, etc., and ends the process.

[0086] Through the above process, the right to view the medical data of patient user A can be granted to patient user B.

[0087] In the above-described flow of granting the right to view, the patient user A sends a request to grant the right to view the medical data, but the patient user B may send a request to be granted the right to view the medical data. In this case, the server 101 accepts the request to request the right to view, and sends a notification to the patient user A that the patient user B wishes to be granted the right to view, and then proceeds to the process of S401.

[0088] That is, if the patient user A thinks that the viewing right may be granted to the patient user B, the patient user A transmits a viewing permission (a request for granting the viewing right in S401) to the server 101 via the information terminal 104.

[0089] (Process flow: Viewing medical data based on viewing rights) Fig. 5 is a flow diagram for explaining the browsing process of medical data based on the browsing right according to the present invention. Hereinafter, the flow of the patient user B who has been granted the browsing right browsing the medical data of the patient user A based on the browsing right ID will be explained while referring to Fig. 5.

[0090] The flow described below is based on the premise that the patient user B operates the medical data application via the information terminal 105 and transmits a request to the server 101 to view the medical data of the patient user A.

[0091] In S501, the server 101 receives a viewing request based on the viewing right from the information terminal 105. The viewing request based on the viewing right may include, for example, one or more of a viewing right ID, a user ID of the patient user B, a name, an age, a sex, personal identification information, a desired viewing range, and the like.

[0092] The identity verification information may be face authentication, fingerprint authentication, SMS authentication, password information, or a combination thereof, as in the above-described flow. The identity verification information may be transmitted to the server 101 in any of the steps described below, instead of S501.

[0093] In S502, the server 101 determines whether the viewing request based on the received viewing right meets predetermined requirements. The predetermined requirements may be, for example, whether the viewing request includes one or more pieces of information such as a viewing right ID, the patient user B's user ID, name, age, sex, personal identification information, and desired viewing range. If it is determined that the predetermined requirements are met, the process proceeds to S503. If it is determined that the predetermined requirements are not met, the server 101 notifies the patient user B that the predetermined requirements are not met, and ends the process.

[0094] In S503, the server 101 compares the viewing right ID included in the viewing request based on the viewing right with the viewing right ID registered in the viewing right information 211, and detects information such as the user IDs, sharing level, and viewing period of patient users A to B associated with the viewing right ID.

[0095] In S504, the server 101 checks the user ID of the patient user A associated with the viewing right ID against the user ID registered in the patient medical data 207.

[0096] In S505, the server 101 detects the user ID of the patient user A registered in the patient medical data 207 as a result of the matching, and transmits the medical data associated with the user ID of the patient user A to the information terminal 105. The medical data to be transmitted can be selected based on the desired viewing range described above, etc.

[0097] Through the above process, the patient user B can view the medical data of the patient user A stored in the patient medical data 207 of the server 101 within the scope of the sharing level.

[0098] As described above, the right to view can also be granted to medical users. The basic processing and steps are the same as those of S401 to 404 and S501 to 505 described above. For example, in order to view medical data related to the medical examination of patient user A, who is currently undergoing treatment, at hospital B, medical user C transmits a request for the right to view the medical data of patient user A on the medical data app. Patient user A grants the right to view to medical user C, and can allow medical user C to view his / her own medical data to any extent.

[0099] As described above, the medical data application of the present invention is suitable for use in, for example, a second opinion service, since it allows the patient user's medical data to be viewed and searched across contracted medical institutions. For example, assume that patient user A is examined by medical user C at hospital A for a certain symptom, and then goes to another medical institution, hospital B, for further examination. Medical user D working at hospital B is granted viewing rights by patient user A via the medical data application, and can view the medical data including the examination results of medical user C at hospital A based on the viewing rights.

[0100] [Embodiment 2] In the above-mentioned embodiment 1, the process of the patient user viewing his / her own medical data and granting the viewing right to other users to view it has been described. In the above-mentioned embodiment 1, if the patient user is, for example, a minor or other person who cannot properly express his / her own will, it may be difficult for the patient user to properly view his / her own medical data or to allow other users to view it. For example, there is a risk that information that should not be provided may be mistakenly provided to other users.

[0101] In the second embodiment of the present invention, taking such a situation into consideration, it is possible to grant the right to utilize the medical data of a certain patient (e.g., a minor), grant viewing rights, set the sharing level, etc. to another patient user (e.g., a guardian). In this embodiment, the right to utilize medical data, grant viewing rights, set the sharing level, etc. is simply referred to as the "medical data utilization right" for the purpose of explanation. In this embodiment, it is assumed that the "medical data utilization right" to the medical data of a specific person (e.g., a minor) is granted to a specific patient user (e.g., a guardian).

[0102] The above are merely examples, and the medical data utilization rights may be set within the scope of the present invention. The medical data utilization rights granted to other patient users may be set based on the intentions of each user, the administrator of the medical data, the scope of the present invention, etc.

[0103] In this embodiment, the "person who cannot express his / her will appropriately" may be a minor, an elderly person, and / or a person who does not have the ability to make appropriate judgments for some reason, etc. The above are merely examples, and any person may be included within the scope of the present invention.

[0104] In this embodiment, medical data related to a "person who cannot properly express his / her will" may be managed in association with a user account of a patient user who has been granted the right to utilize medical data. In consideration of the risk of medical data being utilized against the will of the patient, it is preferable that the medical data app of the present invention does not allow a "person who cannot properly express his / her will" to open a user account. In this embodiment, the explanation is given consistently on the assumption that a "person who cannot properly express his / her will" will not open a user account.

[0105] As will be described later, "a person who is unable to express his / her own will appropriately" (e.g., a minor child) may open his / her own user account when he / she becomes able to express his / her own will appropriately (e.g., when he / she becomes an adult). The newly opened user account can take over the medical data that was previously managed by a patient user (e.g., a guardian) who has been granted the right to utilize medical data.

[0106] In the description of the second embodiment, matters common to the first embodiment will be omitted.

[0107] (Process flow: Granting the right to use medical data) 6 is a flow diagram for explaining the process of granting medical data utilization rights according to the present invention. For the purpose of explanation, the flow will be explained below assuming that patient user A, who is a guardian, requests the granting of medical data utilization rights for his / her child (e.g., an infant, hereinafter simply referred to as child B).

[0108] For the purpose of explanation, the flow described below assumes that patient user A is using the information terminal 104 and has already opened and is using a medical data application account. Child B assumes that he has not opened a medical data application account. The above is merely an example and does not limit the present invention.

[0109] In the flow described below, it is assumed that patient user A operates the medical data application via the information terminal 104 and transmits a right grant request for the right to utilize the medical data of child B.

[0110] In S601, the server 101 receives a right granting request from the information terminal 104. The right granting request may include, for example, the user ID, name, age, sex, and personal identification information of the patient user A, the name, age, sex of the child B, the relationship between the patient user A and the child B, information proving the relationship, and / or the scope of the medical data utilization right to be granted. The information proving the relationship may be, for example, an image of a document such as a certified copy of a family register, an extract from a family register, and / or a resident's card that can be obtained from a public institution. It should be noted that the above information that may be included in the right granting request is merely an example, and may include various other information.

[0111] The identity verification information may be face authentication, fingerprint authentication, SMS authentication, password information, or a combination thereof, and may be transmitted to the server 101 in any of the steps described below instead of S601.

[0112] In S602, the server 101 determines whether the received right grant request satisfies predetermined requirements. The predetermined requirements may be, for example, whether the request includes information such as the user ID of the patient user A, the patient user A's personal identification information, the relationship between the patient user A and the child B, information proving the relationship, and / or the scope of the medical data utilization right to be granted. If it is determined that the predetermined requirements are met, the process proceeds to S603. If it is determined that the predetermined requirements are not met, the server 101 notifies the patient user A that the predetermined requirements are not met, and ends the process.

[0113] In S603, the server 101 generates a grant record and a utilization right grant ID indicating that the right to utilize medical data of child B has been granted to patient user A, and stores them in the user account information 210. The medical data utilization right ID may be stored in association with the above-mentioned various information (e.g., information that may be included in the right grant request) provided by patient user A. Next, the server 101 notifies patient user A that the grant of the medical data utilization right has been completed, and ends the process.

[0114] Through the above process, the right to utilize the medical data of child B can be granted to patient user A. After the right is granted, the medical data of child B is stored in the patient medical data 207 in a state associated with the utilization right granting ID. Furthermore, patient user A can view child B's medical data, grant viewing rights, set the sharing level, and so on, via the medical data app, based on the medical data utilization right ID associated with his / her own user ID.

[0115] In the above explanation, the right to utilize medical data of child B is granted to patient user A, who is the guardian. However, the person to whom the right to utilize medical data can be granted is not limited to family members or relatives. For example, the right to utilize medical data may be granted even in the relationship between a guardian and a ward. The relationship and the extent to which the right to utilize medical data can be granted may be determined based on the operator of the medical data app, the gist of the present invention, etc.

[0116] As described above, the right to utilize medical data of child B is granted to patient user A, who is the guardian. In the present invention, as described above, a "person who cannot properly express his / her own will" (e.g., a minor child) may open his / her own user account again when he / she becomes able to properly express his / her own will (e.g., when he / she becomes an adult). The newly opened user account can take over the medical data that was managed by the patient user (e.g., guardian) who has been granted the right to utilize medical data, and the patient user (former minor child) can utilize his / her own medical data.

[0117] For example, when Child B, who was an infant (minor), becomes an adult, the adult Child B can open his / her own user account and transfer the medical data of Child B that was managed by Patient User A, who is the guardian, to the opened user account. The transfer of medical data will be described below.

[0118] (Process flow: Medical data transfer) 7 is a flow diagram for explaining a medical data handover process according to the present invention. For the purpose of explanation, the flow will be explained below assuming that medical data of child B managed by patient user A, who is the guardian, is handed over to a user account opened by child B.

[0119] For the purpose of explanation, it is assumed that patient user A has already opened and is using an account for the medical data application using the information terminal 104. It is assumed that child B has newly opened his / her own user account for the medical data application using the information terminal 105. Hereinafter, child B will be referred to as patient user B. For the purpose of explanation, it will be explained that a user account is opened and / or medical data is handed over when a minor becomes an adult, but the present invention is not limited thereto.

[0120] The opening of a user account and / or the transfer of medical data may be performed when a "person unable to properly express his / her own will" is in a situation in which he / she is able to properly manage his / her own medical data. What situation corresponds to "a situation in which he / she is able to properly manage his / her own medical data" may be based on the scope of the gist of the present invention, the intention of the operator of the medical data app, the wishes and intentions of each user, etc.

[0121] In S701, the server 101 receives a medical data transfer request from the information terminal 105. The medical data transfer request may include, for example, the user ID, name, age, sex, personal identification information, the relationship between patient users B and A, information proving the relationship, and / or a utilization right granting ID associated with patient users B and A. The information proving the relationship may be, for example, an image of a document such as a certified copy of a family register, an extract from a family register, and / or a resident's card that can be obtained from a public institution. It should be noted that the above information that may be included in the medical data transfer request is merely an example and may include various other information.

[0122] The identity verification information may be face authentication, fingerprint authentication, SMS authentication, password information, or a combination thereof, and may be transmitted to the server 101 in any of the steps described below instead of S701.

[0123] In S702, the server 101 determines whether the received medical data transfer request satisfies predetermined requirements. The predetermined requirements may be, for example, whether the request includes information such as the user ID, name, age, sex, personal identification information, the relationship between patient users B and A, information proving the relationship, and / or a utilization right granting ID associated with patient users B and A. If it is determined that the predetermined requirements are met, the process proceeds to S703. If it is determined that the predetermined requirements are not met, the server 101 notifies patient user B that the predetermined requirements are not met, and ends the process.

[0124] In S703, the server 101 stores a medical data utilization right invalidation record indicating that the medical data utilization right granted to the patient user A has been invalidated in the user account information 210. After that, the patient user A cannot utilize the medical data of the child B (i.e., the patient user B), grant the viewing right, set the sharing level, and so on.

[0125] In S704, the server 101 associates the user ID of patient user B with the medical data of child B (i.e., patient user B) stored in the patient medical data 207 associated with the utilization right grant ID. Next, the server 101 notifies patient users B and A that the transfer of medical data from the user account of patient user A to the user account of patient user B has been completed, and ends the process. The order of the processes from S703 to S704 above may be any order, and they may be executed simultaneously.

[0126] After the user ID of patient user B is associated, the medical data of child B (patient user B) can be treated in the same way as the medical data of normal patient user B.

[0127] Through the above process, the medical data of child B (patient user B) that was managed by patient user A can be transferred to the user account opened by patient user B. After the transfer, patient user B can view his / her own medical data that was collected before the user account was opened, grant viewing rights, set the sharing level, etc. through the medical data app (handling it in the same way as regular medical data).

[0128] The above medical data transfer process has been described assuming that patient user B has opened a user account in advance, but the medical data transfer process may also be executed at the same time that patient user B opens a user account.

[0129] [Other embodiments] The medical data application of the present invention can be linked to a remote medical care service provided by the operator of the medical data application or a third party.

[0130] In another embodiment, the patient user can submit the questionnaire to the medical user by inputting it into the medical data application. At this time, the information registered in the user account information 210 of the medical data application may be automatically input, and the patient user may input only the necessary information.

[0131] In another embodiment, the medical data app can be linked to systems, programs, and / or applications that handle medical and health data operated by local governments, companies, etc. For example, there are applications that manage medicine notebooks, and it is possible to share medical data with such applications.

[0132] In another embodiment, in the medical data app, the patient user can provide his / her own medical data for a clinical trial of new drug development. This is possible by setting the patient user to permit the provision of medical data for clinical trials on the medical data app. In addition, the patient user can also participate in a survey on the actual situation of medical care in each local government with his / her consent. Such patient users who provide data to clinical trials or participate in a survey on the actual situation of local governments may be provided with a burden reduction fee or points that can be used for payment at specific stores via the medical data app. This may be implemented based on information such as a bank account registered in the user account information 210.

[0133] In another embodiment, it is also possible to apply for medical expense deductions and medical-related subsidies to government agencies via the medical data app.

[0134] In another embodiment, information on insurance provided by an insurance company or the like can be registered in the medical data app. For example, a patient user can register information on a medical insurance service of the insurance company to which the patient user is a subscriber in the medical data app. In addition, when the patient user receives treatment that satisfies the requirements for insurance payment through the medical insurance service, it is also possible to automatically transmit information required for insurance payment to the insurance company via the medical data app. The patient user can apply for insurance payment without any work on his / her own or by simply inputting a small amount of additional information into the medical data app.

[0135] In another embodiment, the medical data application may detect the patient user's pre-disease status or risk of illness that may occur in the near future from registered information such as age, sex, height, weight, medical history, illness or injury being treated, lifestyle habits, etc., and notify the patient user. The notification may include information on improving and preventing the pre-disease status or potential illness, and / or a recommendation to visit a medical institution.

[0136] In another embodiment, the medical data application may have a function of managing medicines prescribed to the patient user. For example, the medical data application can automatically notify the patient user of when, which medicine, and how many pills he or she needs to take. In addition to managing medicines, the medical data application can notify the patient user of treatment instructions from a medical professional. [Explanation of symbols]

[0137] 101 Server 102 Medical institution server 103 Medical institution server 104 Information terminal 105 Information terminal 106 Information terminal 107 Information terminal 108 Information terminal 109 Network 207 Patient Medical Data 208 Medical Institution Information 209 Business information 210 User Account Information 211 Viewing Rights Information

Claims

1. a server for storing medical data of one or more users; A first information terminal communicatively connected to the server; A medical data browsing system capable of browsing medical data of the one or more users, comprising: Receiving a first viewing request from a first patient user via the first information terminal to view first medical data of the first patient user, the first viewing request including at least first user identification information of the first patient user; determining whether the first browsing request satisfies a first requirement, the first requirement being that the first browsing request includes at least first user identification information stored in the server; permitting the first patient user to view the first medical data when it is determined that the first requirement is satisfied; configured to run The medical data browsing system includes: receiving, via the first information terminal, a right granting request for granting a right to utilize the second medical data of a first related party to the first patient user, the right granting request including at least the first user identification information of the first patient user, user relationship information indicating a relationship between the first patient user and the first related party, and information certifying the relationship; When it is determined that the right grant request includes at least the first user identification information, the user relationship information, and information proving the relationship, which are stored in the server, a right grant record proving that the utilization right has been granted to the first patient user is stored in the server. Medical data viewing system.

2. The server stores one or more user identities, the one or more user identities being associated with medical data of the one or more users, and the medical data browsing system further comprises: matching the first user identification information with the one or more user identification information to detect the first user identification information from the one or more user identification information; transmitting the first medical data associated with the detected first user identification information to the first information terminal; The medical data viewing system of claim 1 , further configured to execute:

3. The medical data browsing system further comprises a second information terminal of a second patient user communicably connected to the server and the first information terminal, and a sharing level is set for each of the medical data of the one or more users, the sharing level indicating which type of data is to be shared with which classification of users, and the medical data browsing system further comprises: receiving, via the first information terminal, a request for granting a viewing right to grant a second patient user a viewing right permitting viewing of the first medical data, the request for granting the viewing right including at least the first user identification information, second user identification information of the second patient user, and the sharing level; determining whether the request for granting the viewing right satisfies a second requirement, the second requirement being that the request for granting the viewing right includes at least the first user identification information stored in the server and the second user identification information stored in the server; granting the viewing right to the second patient user when it is determined that the second requirement is satisfied; and The medical data viewing system of claim 2 , further configured to execute the following:

4. The medical data browsing system includes: generating browsing right identification information based on the request for granting the browsing right; Associating the generated viewing right identification information with the first user identification information and the second user identification information; storing the viewing right identification information associated with the identification information of the first patient user and the identification information of the second patient user in the server; The medical data viewing system of claim 3 , further configured to execute the following:

5. The medical data browsing system includes: receiving a second viewing request from the second patient user via the second information terminal to request viewing of the first medical data, the second viewing request including at least the viewing right identification information, the second user identification information, and the sharing level; determining whether the second browsing request satisfies a third requirement, the third requirement being that the second browsing request includes at least the second user identification information stored in the server; and permitting the second patient user to view the first medical data when it is determined that the third requirement is satisfied; and The medical data viewing system of claim 4 , further configured to execute the following:

6. The medical data browsing system includes: Matching the browsing right identification information with one or more browsing right identification information stored in the server, and detecting the browsing right identification information from the one or more stored browsing right identification information; Matching the first user identification information associated with the detected browsing right identification information with the one or more user identification information stored on the server; transmitting, to the second patient user, only the first medical data that matches the sharing level from among the first medical data associated with the first user identification information detected as a result of the matching; The medical data viewing system of claim 5 , further configured to execute the following:

7. The medical data browsing system according to claim 6 , further configured to execute transmitting the first medical data with some information deleted according to the sharing level.

8. The medical data browsing system includes: storing utilization right identification information associated with said utilization right in said server; storing the second medical data in the server in association with the utilization right identification information; The medical data viewing system of claim 1 , further configured to execute the following:

9. a third information terminal communicably connected to the server and the first information terminal, the first related person being a third user; The medical data browsing system includes: The third user receives a medical data handover request via the third information terminal, the medical data handover request requesting handover of the second medical data to the third user, the medical data handover request including at least third user identification information of the third user, the utilization right identification information, the user relationship information, and information proving the relationship; determining whether the medical data handover request satisfies a fifth requirement, the fifth requirement being that the medical data handover request includes at least the third user identification information stored in the server, the utilization right identification information stored in the server, the user relationship information, and information proving the relationship; When it is determined that the fifth requirement is satisfied, transferring the second medical data associated with the utilization right identification information to the third user; and The medical data viewing system of claim 8 , further configured to execute the following:

10. The handover of the second medical data to the third user includes: storing in the server a utilization right invalidation record attesting that the utilization right granted to the first patient user has been invalidated; Associating the third user identification information with the second medical data stored in the server in association with the utilization right identification information; The medical data viewing system according to claim 9 .

11. 1. A computer-implemented method comprising: Receiving a first viewing request from a first patient user via a first information terminal to view first medical data of the first patient user, the first viewing request including at least first user identification information of the first patient user; Determining whether the first browsing request satisfies a first requirement, the first requirement being that the first browsing request includes at least first user identification information stored in a server; permitting the first patient user to view the first medical data when it is determined that the first requirement is satisfied; Including, The method comprises: receiving, via the first information terminal, a right granting request for granting a right to utilize the second medical data of a first related party to the first patient user, the right granting request including at least the first user identification information of the first patient user, user relationship information indicating a relationship between the first patient user and the first related party, and information certifying the relationship; When it is determined that the right grant request includes at least the first user identification information, the user relationship information, and information proving the relationship stored in the server, a right grant record proving that the utilization right has been granted to the first patient user is stored in the server.

12. A program for causing a computer to execute the method according to claim 11.

Citation Information

Patent Citations

  • Medical information system

    JP2010026899A

  • A system to manage access to medical data

    JP2016529768A

  • Personal medical information management method, personal medical information management server and program

    JP2018092463A

  • Method, system, and program for health care and nursing care information management

    JP2018163518A

  • Medical information browsing system and medical information browsing method

    JP2021068178A