Unified health and medical information management system
The system addresses the lack of patient incentives in medical information disclosure by providing incentives and access control, promoting centralized management with secure professional access.
Patent Information
- Application Number
- JP2024086002
- Authority / Receiving Office
- JP · JP
- Patent Type
- Patents
- Current Assignee / Owner
- Filing Date
- 2024-05-28
- Publication Date
- 2025-08-15
- Estimated Expiration
- 2042-07-15
AI Technical Summary
Existing systems do not provide incentives to patients regarding the disclosure of their medical information, hindering centralized management of health and medical care-related information.
A centralized health and medical care-related information management system that includes an incentive function unit to provide incentives to individuals for allowing or denying the disclosure of their information, along with an access control unit to manage disclosure permissions and anonymization methods for different types of professionals.
Encourages individuals to participate in centralized management of their health and medical information by offering incentives, ensuring secure and controlled access based on professional type.
Smart Images

Figure 0007724020000001 
Figure 0007724020000002 
Figure 0007724020000003
Abstract
Description
[Technical Field]
[0001] The present invention relates to a health care related information unified management system for accumulating and unified managing health care related information, which is information relating to the health care of an individual. [Background technology]
[0002] Recently, systems and services that allow multiple medical institutions to share patient medical information have begun to be considered.
[0003] One example of such a system is the invention described in Patent Document 1. This invention provides a medical information management system that discloses only necessary items of medical information, such as electronic medical records created at a designated medical institution, to other doctors and medical institutions, while not disclosing items that the patient himself does not wish to disclose. [Prior art documents] [Patent documents]
[0004] [Patent Document 1] Patent Publication No. 2004-287774 Summary of the Invention [Problem to be solved by the invention]
[0005] However, the above-mentioned invention has a problem in that it does not disclose the possibility of providing incentives to patients regarding whether or not to disclose their medical information in order to encourage centralized management of medical information. [Means for solving the problem]
[0006] In light of the above-mentioned problems, the present invention aims to provide a unified management system for health and medical care-related information that provides incentives to individuals regarding whether or not to allow their health and medical care-related information to be made public, in order to encourage centralized management of health and medical care-related information.
[0007] Specifically, the present invention provides a centralized health and medical care-related information management system having a health and medical care-related information storage unit for storing and centrally managing health and medical care-related information about individuals, an access control unit for controlling the disclosure of the health and medical care-related information stored in the health and medical care-related information storage unit to third parties via a network, and an incentive function unit including at least an incentive management unit for providing incentives to individuals regarding whether or not to allow the disclosure of the health and medical care-related information about individuals in order to encourage centralized management of the health and medical care-related information.
[0008] In addition to the above features, the present invention also provides a health and medical care related information unified management system further comprising an access authentication processing unit that performs authentication for accessing the incentive management unit.
[0009] In addition to the above features, the present invention also provides a unified management system for health and medical-related information, which further includes a consent information acquisition unit that acquires consent information, which is information indicating consent to accept an incentive from the incentive management unit, after being authenticated by the access authentication processing unit.
[0010] In addition to the above features, the present invention also provides a unified management system for health and medical-related information, which further has an incentive processing unit for performing incentive processing, which is processing for providing incentives when consent information is acquired by the consent information acquisition unit.
[0011] The present invention also provides a unified health and medical care related information management system, which further includes a disclosure permission information storage unit that stores disclosure permission information indicating whether an individual permits disclosure of their own health and medical care related information to third parties.
[0012] The present invention also provides a unified health and medical related information management system having a third party identification information storage unit that stores third party identification information for identifying whether a third party is a medical professional or a non-medical professional.
[0013] The present invention also provides a centralized health and medical care related information management system in which an access control unit allows a medical professional to view the health and medical care related information stored in the health and medical care related information storage unit when the disclosure permission information stored in the disclosure permission information storage unit indicates that disclosure is permitted and the third party identification information stored in the third party identification information storage unit indicates that the medical professional is a medical professional.
[0014] The present invention also provides a centralized health and medical care-related information management system in which, when the disclosure permission information held in the disclosure permission information holding unit indicates that disclosure is permitted and the third party identification information held in the third party identification information holding unit indicates that the person is a non-medical professional, the access control unit allows non-medical professionals to view part (including all) of the health and medical care-related information stored in the health and medical care-related information storage unit, or health and medical care-related information that has been anonymized using a predetermined anonymization method.
[0015] The present invention also provides a unified management system for health and medical-related information, in which the anonymization method is at least one of the following anonymization methods: k (k is a natural number greater than or equal to 2), pseudonymization, generalization, top (bottom) coding, noise (error) addition, swapping (data exchange), sampling, and grouping, or a combination of these.
[0016] The present invention also provides a centralized management system for health and medical related information, wherein the medical professionals include at least one of doctors, dentists, pharmacists, public health nurses, midwives, nurses, licensed practical nurses, physiotherapists, occupational therapists, orthoptists, speech-language-hearing therapists, prosthetists, orthotists, diagnostic radiologists, diagnostic X-ray technicians, clinical laboratory technicians, medical laboratory technicians, clinical engineers, dental hygienists, dental technicians, emergency medical technicians, masseurs and shiatsu therapists, acupuncturists, moxibustion therapists, judo therapists, registered dietitians, nutritionists, mental health workers, social workers, care workers, certified psychologists, clinical psychologists, and medical administrators.
[0017] The present invention also provides a centralized management system for health and medical-related information, where the non-medical personnel include at least one of the following employees: life insurance companies, non-life insurance companies, securities companies, pharmaceutical companies, drug discovery venture companies, food companies, health equipment companies, fitness clubs, sports gyms, banks, credit unions, JA (agricultural cooperatives), union health insurance, Japan Health Insurance Association, mutual aid societies, municipal national health insurance, national health insurance societies, PR companies, general research institutes, universities and graduate schools (including affiliated research institutes), technical colleges, agriculture, forestry and fisheries companies, fertilizer manufacturers, government agencies, local governments, and independent administrative agencies. do.
[0018] Furthermore, to realize the above-mentioned unified management system for health and medical care related information, the present invention provides an operating method for the unified management system for health and medical care related information, which is a computer, and an operating program for the unified management system for health and medical care related information, which is written so as to be readable and executable by a computer.
[0019] Specifically, the present invention provides a method executed by a CPU in a centralized health and medical care related information management system, which includes: a health and medical care related information accumulation step for accumulating and centrally managing health and medical care related information about individuals; an access control step for controlling the disclosure of the health and medical care related information accumulated in the health and medical care related information accumulation step to third parties via a network; and an incentive function step including at least an incentive management step for providing incentives to individuals regarding whether or not to allow the disclosure of their health and medical care related information in order to encourage centralized management of health and medical care related information.
[0020] Specifically, the present invention provides an operating program for the centralized management system of healthcare and medical information, which is a method executed by a CPU in the centralized management system of healthcare and medical information, and which is a computer including: a healthcare and medical information accumulation step for accumulating and centrally managing healthcare and medical information about individuals; an access control step for controlling the disclosure of the healthcare and medical information accumulated in the healthcare and medical information accumulation step to third parties via a network; and an incentive function step including at least an incentive management step for providing incentives to individuals regarding whether or not to allow the disclosure of their healthcare and medical information in order to encourage centralized management of healthcare and medical information. [Effects of the Invention]
[0021] As described above, the present invention can provide a unified management system for healthcare-related information that provides incentives to individuals regarding whether or not to allow disclosure of healthcare-related information, in order to encourage unified management of healthcare-related information. [Brief explanation of the drawings]
[0022] [Figure 1] FIG. 1 is a diagram showing a hardware configuration applied to the present invention. [Figure 2a] A diagram showing the overall configuration of the unified management system for health and medical information in the present invention. [Figure 2b] FIG. 1 shows the functional configuration of a centralized health and medical information management system according to the first embodiment. [Figure 2c] FIG. 1 is a diagram showing the hardware configuration of a centralized health and medical information management system according to the first embodiment. [Figure 2d] FIG. 1 is a diagram showing a processing flow when using the unified health and medical information management system according to the first embodiment. [Figure 2e] FIG. 1 shows the functional configuration of a centralized health and medical information management system according to the first embodiment. [Figure 3a] FIG. 10 is a diagram showing the functional configuration of a centralized management system for health and medical care-related information in embodiment 2. [Figure 3b] FIG. 10 is a diagram showing the hardware configuration of a centralized health and medical information management system according to a second embodiment. [Figure 3c] FIG. 10 is a diagram showing the processing flow when using the unified health and medical information management system according to the second embodiment. [Figure 4a] FIG. 10 is a diagram showing the functional configuration of a centralized management system for health and medical care-related information in embodiment 3. [Figure 4b] FIG. 10 is a diagram showing the hardware configuration of a centralized health and medical information management system according to a third embodiment. [Figure 4c] FIG. 10 is a diagram showing the processing flow when using the unified health and medical information management system according to the third embodiment. [Figure 5a] FIG. 10 is a diagram showing the functional configuration of a centralized management system for health and medical care-related information in embodiment 4. [Figure 5b] FIG. 10 is a diagram showing the hardware configuration of a centralized health and medical information management system according to a fourth embodiment. [Figure 5c] FIG. 10 is a diagram showing a processing flow when using the unified health and medical information management system according to the fourth embodiment. [Figure 6a] FIG. 10 is a diagram showing the functional configuration of a centralized management system for health and medical care-related information in embodiment 5. [Figure 6b] FIG. 10 is a diagram showing an example of the functional configuration of a unified management system for health and medical care-related information in embodiment 5. [Figure 6c] FIG. 10 is a diagram showing the hardware configuration of a centralized health and medical information management system according to a fifth embodiment. [Figure 6d] FIG. 10 is a diagram showing a processing flow when the unified health and medical information management system according to the fifth embodiment is used. [Figure 7a] FIG. 14 is a diagram showing the functional configuration of a centralized management system for health and medical information in embodiment 6. [Figure 7b] FIG. 14 is a diagram showing the hardware configuration of a centralized health and medical information management system according to a sixth embodiment. [Figure 7c] FIG. 14 is a diagram showing a processing flow when the integrated health and medical information management system according to the sixth embodiment is used. [Figure 8a]FIG. 13 is a diagram showing the functional configuration of a centralized management system for health and medical care-related information in embodiment 7. [Figure 8b] FIG. 13 is a diagram showing the hardware configuration of a centralized health and medical information management system according to a seventh embodiment. [Figure 8c] FIG. 13 is a diagram showing a processing flow when the unified health and medical information management system according to the seventh embodiment is used. [Figure 9a] FIG. 13 is a diagram showing the functional configuration of a centralized management system for health and medical information in embodiment 8. [Figure 9b] FIG. 13 is a diagram showing the hardware configuration of a centralized health and medical information management system according to an eighth embodiment. [Figure 9c] FIG. 13 is a diagram showing a processing flow when the unified health and medical information management system according to the eighth embodiment is used. [Figure 10a] A diagram showing an example of anonymization method [Figure 10b] A diagram showing an example of anonymization method [Figure 10c] A diagram showing an example of anonymization method [Figure 11a] A diagram showing an example of the user interface of the health and medical information unified management system of the present invention. [Figure 11b] A diagram showing an example of the user interface of the health and medical information unified management system of the present invention. [Figure 11c] A diagram showing an example of the user interface of the health and medical information unified management system of the present invention. [Figure 11d] A diagram showing an example of the user interface of the health and medical information unified management system of the present invention. [Figure 11e] A diagram showing an example of the user interface of the health and medical information unified management system of the present invention. [Figure 11f] A diagram showing the user interface of the health and medical information unified management system of the present invention. <Hardware that can constitute the present invention>
[0023] FIG. 1 is a diagram showing a hardware configuration applied to the present invention.The present invention is, in principle, an invention that utilizes a computer, but it can also be realized by software, hardware, or the combination of software and hardware. The hardware that realizes all or part of the constituent elements of the present invention is composed of the basic components of a computer, such as a CPU, memory, bus, input / output devices, various peripheral devices, and a user interface. The various peripheral devices include storage devices, internet interfaces, internet devices, displays, keyboards, mice, speakers, cameras, videos, televisions, various sensors for monitoring production status in laboratories or factories (e.g., flow rate sensors, temperature sensors, weight sensors, liquid volume sensors, infrared sensors, shipment counters, package counters, foreign body inspection devices, defective product counters, radiation inspection devices, surface condition inspection devices, circuit inspection devices, motion sensors, worker work status monitoring devices (e.g., video, ID, PC work volume)), CD drives, DVD drives, Blu-ray drives, USB memory, USB memory interfaces, removable hard disks, general hard disks, projectors, SSDs, telephones, fax machines, copiers, printers, movie editing devices, and various sensor devices. The system does not necessarily have to be configured in a single enclosure; it can also be configured by connecting multiple enclosures via communication. Communication can be via LAN, WAN, Wi-Fi, Bluetooth (registered trademark), infrared communication, or ultrasonic communication. Furthermore, some of the components may be installed across borders. Furthermore, each of the multiple units may be operated by a different entity, or may be operated by a single entity. The system of the present invention may be operated by a single entity or multiple entities. The invention may also be configured as a system that includes, in addition to the present system, a terminal used by a third party, and a terminal used by yet another third party. These terminals may also be installed across borders. Furthermore, in addition to the present system and the terminals, devices may be provided for storing related information about third parties, registering related persons, and creating a database for recording the contents of registration. These may be provided in the present system, or may be provided outside the present system so that the present system can be configured to utilize this information.
[0024] As shown in this diagram, the computer is configured on a motherboard and comprises a chipset, CPU, non-volatile memory, main memory, various buses, BIOS, various interfaces such as USB, HDMI (registered trademark), and LAN, a real-time clock, etc. These operate in cooperation with an operating system, device drivers (for various interfaces such as USB and HDMI (registered trademark), and various built-in devices such as cameras, microphones, speakers or headphones, and displays), various programs, etc. The various programs and data that make up the present invention are configured to efficiently utilize these hardware resources to execute various processes. Chipset
[0025] A "chipset" is a set of large-scale integrated circuits (LSI) mounted on a computer's motherboard that integrates a communication function, or bridge function, between the CPU's external bus and the standard bus that connects memory and peripheral devices. Two chipset configurations are used, or one chipset configuration. The northbridge is located on the side closest to the CPU and main memory, and the southbridge is located on the side farther away, which interfaces with relatively slow external I / O.
[0026] (Northbridge) The northbridge includes a CPU interface, memory controller, and graphics interface. Most of the functions of a conventional northbridge can be performed by the CPU. The northbridge connects to the main memory slot via a memory bus, and to the graphics card slot via a high-speed graphics bus (AGP, PCI Express).
[0027] (Southbridge) The southbridge connects to the PCI interface (PCI slot) via the PCI bus and handles I / O functions such as ATA (SATA), USB, and Ethernet interfaces, as well as sound functions. Incorporating circuits to support features such as PS / 2 ports, floppy disk drives, serial ports, parallel ports, and ISA buses, which do not require or are not capable of high-speed operation, would hinder the speed of the chipset itself, so these can be separated from the southbridge chip and placed in a separate LSI called a super I / O chip. Buses are used to connect the CPU (MPU) to peripheral devices and various control units. Buses are connected by the chipset. The memory bus used to connect to main memory may instead use a channel structure for increased speed. A serial bus or a parallel bus can be used as the bus. While a serial bus transfers data one bit at a time, a parallel bus transmits the original data or multiple bits extracted from the original data as a single block over multiple communication paths simultaneously. A dedicated line for the clock signal runs parallel to the data line, synchronizing data demodulation on the receiving side. It is also used as a bus to connect the CPU (chipset) to external devices, and includes GPIB, IDE / (Parallel) ATA, SCSI, PCI, etc. Because there is a limit to how fast it can be made, in PCI Express, an improved version of PCI, and Serial ATA, an improved version of Parallel ATA, the data line can be a serial bus.
[0028] CPU
[0029] A CPU sequentially reads, interprets, and executes a sequence of instructions called a program stored in main memory, outputting signal-based information to the main memory. The CPU functions as the center of computation within a computer. A CPU consists of a CPU core, which is the center of computation, and its peripheral components, including registers, cache memory, an internal bus connecting the cache memory to the CPU core, a DMA controller, a timer, and an interface with the bus connecting to the north bridge. A single CPU (chip) may have multiple CPU cores. Processing may also be performed by a graphics interface (GPU) or FPU in addition to the CPU. While the embodiments are described as being of a two-core type, this is not limiting. Programs may also be embedded within the CPU.
[0030] <Non-volatile memory>
[0031] (HDD)
[0032] The basic structure of a hard disk drive consists of a magnetic disk, a magnetic head, and an arm on which the magnetic head is mounted. The external interface can be SATA (formerly ATA). A high-performance controller, such as SCSI, is used to support communication between hard disk drives. For example, when copying a file to another hard disk drive, the controller can read the sectors, transfer them to the other hard disk drive, and write them. This does not access the host CPU's memory, so there is no increase in the CPU load.
[0033] <Main memory>
[0034] The CPU directly accesses and executes various programs in main memory. Main memory is volatile memory and uses DRAM. Programs in main memory are expanded from non-volatile memory to main memory upon receiving a program startup command. The CPU then executes the program according to various execution commands and execution procedures within the program.
[0035] Operating System (OS)
[0036] An operating system is used to manage computer resources for use by applications, to manage various device drivers, and to manage the computer itself (the hardware). In small computers, firmware is sometimes used as the operating system.
[0037] ≪BIOS≫
[0038] The BIOS causes the CPU to execute procedures for starting up the computer hardware and running the operating system. It is most typically the hardware that the CPU reads first when it receives a computer startup command. The BIOS contains the address of the operating system stored on the disk (non-volatile memory), and the BIOS loaded into the CPU sequentially loads the operating system into main memory, putting it into operation. The BIOS also has a check function that checks the presence or absence of various devices connected to the bus. The check results are stored in main memory and made available to the operating system as appropriate. The BIOS may also be configured to check for external devices, etc. The above applies to all embodiments.
[0039] As shown in the figure, the present invention can basically be configured with a general-purpose computer program and various devices. The computer basically operates by loading a program recorded in non-volatile memory into main memory, and then executing processing using the main memory, CPU, and various devices. Communication with devices is performed via an interface connected to a bus line. Possible interfaces include a display interface, keyboard, and communication buffer. Below, an embodiment of the present invention will be described with reference to the illustrated examples.
[0040] <Fulfillment of the Laws of Nature of the Invention>
[0041] The present invention functions through the cooperation of a computer, communications equipment, and software. Specifically, it relates to a centralized healthcare information management system for accumulating and centrally managing healthcare information related to an individual's healthcare, in which various information and data are exchanged between third-party terminals and administrator terminals via a network using hardware resources. Therefore, from this perspective, if we judge the claimed invention based on the computer and other resources described in the claims and specification and the common general knowledge related to those matters, the claimed invention as a whole utilizes the laws of nature and falls under the category of a computer-software-related invention.
[0042] <The significance of utilizing the laws of nature required by patent law>
[0043] The Patent Act requires that an invention be industrially applicable and contribute to the development of industry. This requirement ensures that the invention is industrially applicable. In other words, the invention must be industrially useful; that is, the effects of the invention declared in the application must be reproducible with a certain degree of certainty through the practice of the invention. From this perspective, the application of the laws of nature is interpreted as the use of the laws of nature to achieve the functions of each of the invention's defining features (invention elements), which constitute the invention's effects. Furthermore, the effect of an invention is sufficient if it has the potential to provide a specific utility to users who use the invention, and should not be viewed in terms of how users feel or think about that utility. Therefore, even if the effect users gain from the system is a psychological effect, that effect itself does not fall within the scope of the required application of the laws of nature. DETAILED DESCRIPTION OF THE INVENTION
[0044] Hereinafter, embodiments of the present invention will be described with reference to the accompanying drawings. The relationships between the embodiments and the claims are as follows: The explanation of embodiment 1 mainly relates to claims 1, 12, and 13, the explanation of embodiment 2 to claim 2, the explanation of embodiment 3 to claim 3, the explanation of embodiment 4 to claim 4, the explanation of embodiment 5 to claim 5, the explanation of embodiment 6 to claim 6, the explanation of embodiment 7 to claim 7, and the explanation of embodiment 8 to claim 8. The present invention should not be limited to these embodiments in any way, and may be embodied in various forms without departing from the spirit of the invention.
[0045] <Overall configuration of the health and medical information unified management system of the present invention> FIG. 2a is a diagram showing an example of the overall configuration of the health and medical care related information unified management system according to the present invention. The health and medical related information unified management system 200 stores any of the following information: electronic medical record information, various test information (which may include medical checkups, medical examinations, etc.), prescription information, medication history information, medication status information, vital information (including at least, but not limited to, body temperature, blood pressure, pulse rate, heart rate, height, weight, blood glucose level, body fat percentage, arterial blood oxygen saturation, electroencephalogram, electrocardiogram, number of steps, respiratory rate, heart sounds, urine measurement information (e.g., urinary sugar, urinary protein, urinary occult blood, urobilinogen, pH, bilirubin, ketone bodies, nitrites, etc.), sleep time, etc.), information from a medical questionnaire, data from a health promotion app, and conversation data from an interactive health promotion SNS. The system is comprised of a healthcare-related information storage unit 201 that stores healthcare-related information including one or more pieces of information; an access control unit 202 that controls the disclosure of the healthcare-related information stored in the healthcare-related information storage unit 201 to third parties via a network; and an incentive function unit 204 that includes at least an incentive management unit 203 that provides incentives to individuals regarding whether or not to allow disclosure of their healthcare-related information to encourage centralized management of healthcare-related information, and that has functions such as access control to information related to incentives, consent information acquisition, and incentive processing. The unified healthcare-related information management system 200 is also configured to be electrically connected to a third-party terminal 206 and an administrator terminal 207 via a network 205 (e.g., the Internet, a WAN, a LAN, etc.). The third-party terminal 206 and the administrator terminal 207 may be electronic devices (e.g., personal computers, tablet terminals, smartphones, etc.) that can be connected to the network 205 via a wired or wireless interface (e.g., a communication cable, a Wi-Fi router, etc.). In the present invention, a "third party" refers to an individual (including, but not limited to, the patient himself / herself and his / her family), as well as medical professionals and non-medical professionals, as described below. An "administrator" refers to a person who is responsible for managing and operating the entire centralized health and medical information management system (for example, this may include an individual, or an institution, organization, or corporation to which the individual belongs. It may also include an employee of a government agency or local government, or an institution, organization, or corporation commissioned by a government agency or local government).) and may have the authority to edit, add, and delete various information in the centralized health and medical information management system.
[0046] In addition, "electronic medical record information" may include, for example, basic information about the patient (e.g., patient ID, name, date of birth, contact information, emergency contact information, family history, height and weight, allergy information, smoking and drinking status, medical history, etc.), information about the examination (e.g., patient's main complaint (subjective symptoms and complaints about physical condition, etc.), various test results, medication information, diagnosis, treatment plan, doctor's examination record, doctor's instructions, etc.), information about nursing and progress (e.g., vital signs information (e.g., body temperature, blood pressure, pulse, heart rate, height, weight, blood sugar level, body fat percentage, arterial blood oxygen saturation, electroencephalogram, electrocardiogram, number of steps, respiratory rate, heart sounds), urine measurement information (e.g., urinary sugar, urinary protein, urinary occult blood, etc.), etc.), It may also include, but is not limited to, information on blood pressure, blood sugar, blood sugar levels, blood sugar levels (including but not limited to blood sugar levels), ...
[0047] In addition, "prescription information" may include, for example, the insurer number, name, date of birth, gender, name of medical institution, contact information, name of the prescribing doctor, name of the medication, form of medication (tablet, capsule, liquid, powder, granule, etc.), amount of medication (amount to take per dose), number of times per day, timing of taking, information about switching to generic drugs, number of times dispensed medication, etc. Furthermore, "medication history information" may include, for example, the patient's name, date of birth, sex, My Number information or insurance card number, address, emergency contact information, name of the medical institution and physician that prescribed the prescription, prescription date, prescription content, key points of inquiries regarding the dispensing date and prescription content, the patient's constitution, allergy history, side effect history, key points of inquiries from the patient or their family, medication status, confirmation of remaining medication status, changes in physical condition while taking medication, concomitant medications, information on medical history including complications, whether the patient has visited other departments, whether there are symptoms that are suspected to be side effects, intake of food and drink (interactions with drugs), the patient's intentions regarding the use of generic drugs, status of information provided in the notebook, key points of medication instructions, and the name of the insurance pharmacist who provided the instructions.
[0048] In addition, "medication status information" may include, for example, information regarding the remaining amount of prescribed medication (including, for example, the amount of medication remaining if the patient accidentally forgets to take it or if the patient intentionally does not take it), timing information regarding visits to the hospital / pharmacy (for example, the period from the scheduled end date of the prescription (scheduled end date of medication) to the actual visit to the hospital / pharmacy (including, for example, if the patient visits the hospital / pharmacy earlier or later than scheduled)), and patient complaints about medication (including subjective symptoms and complaints about physical condition, such as developing hives after taking a certain medication for a long time, or if taking a certain medication causes it to be too effective and makes the patient feel dizzy).
[0049] "Health and medical-related information" may also include, for example, PHRs. Here, PHR stands for Personal Health Record and refers to information related to an individual's health, medical care, and nursing care. The goal is for individuals to manage and utilize their own health, medical care, and nursing care information chronologically throughout their lives, enabling them to receive high-quality services tailored to their health condition. For example, individuals have historically kept numerous records of health and medical information in various paper documents and notebooks. The media and locations where these records are kept vary depending on the life stage (milestone). For example, a "maternal and child health handbook" is used at birth, "school health checkup results" is used during schooling, and "regular health checkup results" are used upon employment. Depending on one's physical condition, individuals may manage their own health using a "disease management handbook" or "medication handbook," and as they age, they may record their health information in a "nursing care prevention handbook" or "family doctor linkage handbook." There is a concept and system in place that allows people to digitize this existing "planner culture" and centrally organize it as data, allowing them to manage and utilize it themselves, and this is expected to become even more widespread in the future.
[0050] In the present invention, the explanation is based on the premise that healthcare-related information storage unit 201 and access control unit 202 are configured to function on the same server, but this is not limiting, and each function may be performed by a separate server. Alternatively, multiple servers may be provided, and information and data may be exchanged between these servers to execute various functions in cooperation or collaboration. For example, healthcare-related information storage unit 201 and access control unit 202 may be configured as a cloud server.
[0051] Similarly, the present invention will be described on the assumption that the healthcare-related information storage unit 201, the access control unit 202, and the incentive function unit 204 including at least the incentive management unit 203 are configured to function on separate servers, but this is not limiting and each function may be performed on the same server. Alternatively, multiple servers may be provided, and these servers may exchange information and data with each other to execute various functions in cooperation or collaboration. For example, the healthcare-related information storage unit 201, the access control unit 202, and the incentive function unit 204 (including at least the incentive management unit 203) may be configured on a cloud server.
[0052] <Embodiment 1 (corresponding mainly to claims 1, 12, and 13)> <Outline of Embodiment 1> This embodiment provides a centralized healthcare and medical information management system that includes a healthcare and medical information storage unit for storing and centrally managing healthcare and medical information about individuals, an access control unit for controlling disclosure of the healthcare and medical information stored in the healthcare and medical information storage unit to third parties via a network, and an incentive function unit that includes at least an incentive management unit for providing individuals with incentives regarding whether or not to allow disclosure of their healthcare and medical information to encourage centralized management of their healthcare and medical information. To achieve this, the present embodiment also provides a method executed by a CPU in the centralized healthcare and medical information management system, and an operating program for the centralized healthcare and medical information management system that is written in a readable and executable format for a computer that is the centralized healthcare and medical information management system.
[0053] <Functional Configuration of Embodiment 1> 2b is a diagram showing the functional configuration of the healthcare-related information unified management system in embodiment 1. In this embodiment, the system includes a healthcare-related information storage unit, an access control unit, and an incentive function unit that includes at least an incentive management unit.
[0054] <Configuration of Embodiment 1: Healthcare-related Information Storage Unit> The "health and medical care related information storage unit" 201 is configured to have the function of storing health and medical care related information including one or more of the following information: electronic medical record information about an individual, various test information (which may include health checkups, medical examinations, etc.), prescription information, medication history information, medication status information, vital signs information (including at least, but not limited to, body temperature, blood pressure, pulse rate, heart rate, height, weight, blood glucose level, body fat percentage, arterial blood oxygen saturation, electroencephalogram, electrocardiogram, number of steps, respiratory rate, heart sounds, urine measurement information (e.g., urinary sugar, urinary protein, urinary occult blood, urobilinogen, pH, bilirubin, ketone bodies, nitrites, etc.), sleep time, etc.), questionnaire information, data from a health promotion app, and conversation data from an interactive health promotion SNS. "Electronic medical record information" includes, for example, basic information about the patient (e.g., patient ID, name, date of birth, contact information, emergency contact information, family history, height and weight, allergy information, smoking and drinking status, medical history, etc.), information about the examination (e.g., patient's chief complaint (subjective symptoms and complaints about physical condition, etc.), various test results, medication information, diagnosis, treatment plan, doctor's examination record, doctor's instructions, etc.), information about nursing and progress (e.g., vital signs information (e.g., body temperature, blood pressure, pulse, heart rate, height, weight, blood glucose level, body fat percentage, arterial blood oxygen saturation, electroencephalogram, electrocardiogram, number of steps, respiratory rate, heart sounds), urine measurement information (e.g., urinary glucose, urinary protein, urinary occult blood, urobilinogen, etc.) It is desirable that the record be configured to include at least, but not limited to, blood pressure, blood sugar, blood sugar levels, blood sugar levels (e.g., blood sugar levels ... It is desirable that the "prescription information" be configured to include, for example, the insurer number, name, date of birth, sex, name of medical institution, contact information, name of the prescribing doctor, name of the medicine, form of medicine (tablet, capsule, liquid, powder, granule, etc.), amount of medicine (amount to take per dose), number of times per day, timing of taking, information about switching to generic medicines, number of times dispensed medicines, etc. It is desirable that the "medication history information" be structured to include, for example, the patient's name, date of birth, sex, My Number information or insurance card number, address, emergency contact information, name of the medical institution and physician that prescribed the prescription, prescription date, prescription content, key points of inquiries regarding the dispensing date and prescription content, the patient's constitution, allergy history, side effect history, key points of inquiries from the patient or their family, medication status, confirmation of remaining medication status, changes in physical condition while taking medication, concomitant medications, information on medical history including complications, whether the patient has visited other departments, whether there are symptoms that are suspected to be side effects, intake of food and drink (interactions with drugs), patient's intentions regarding the use of generic drugs, status of information provided in the notebook, key points of medication instructions, and the name of the insurance pharmacist who provided the instructions. It is desirable that the "medication status information" be configured to include, for example, information regarding the remaining amount of prescribed medication (including, for example, the amount of medication remaining if the patient accidentally forgets to take it or if the patient intentionally does not take it), timing information regarding visits to the hospital / pharmacy (for example, the period from the scheduled end date of the prescription (scheduled end date of medication) to the actual visit to the hospital / pharmacy (including, for example, if the patient visits the hospital / pharmacy earlier or later than scheduled)), and patient complaints about medication (including subjective symptoms and complaints about physical condition, such as developing hives after taking a certain medication for a long time, or if taking a certain medication causes it to be too effective and makes the patient feel dizzy). In addition, in the present invention, My Number information or the health insurance card number to which the individual (user) is enrolled may be used to identify the individual (user), and health and medical related information about the individual may be associated with this and collected and stored.
[0055] "Health and medical-related information" may also include, for example, PHRs. Here, PHR stands for Personal Health Record and refers to information related to an individual's health, medical care, and nursing care. The goal is for individuals to manage and utilize their own health, medical care, and nursing care information chronologically throughout their lives, enabling them to receive high-quality services tailored to their health condition. For example, individuals have historically kept numerous records of health and medical information in various paper documents and notebooks. The media and locations where these records are kept vary depending on the life stage (milestone). For example, a "maternal and child health handbook" is used at birth, "school health checkup results" is used during schooling, and "regular health checkup results" are used upon employment. Depending on one's physical condition, individuals may manage their own health using a "disease management handbook" or "medication handbook," and as they age, they may record their health information in a "nursing care prevention handbook" or "family doctor linkage handbook." There is a concept and system in place that allows people to digitize this existing "planner culture" and centrally organize it as data, allowing them to manage and utilize it themselves, and this is expected to become even more widespread in the future.
[0056] <Configuration of Embodiment 1: Access Control Unit> The "access control unit" 202 is configured to have a function for controlling the disclosure of healthcare-related information stored in the healthcare-related information storage unit to third parties via a network. For example, as described below, it is desirable that the access control unit be configured to have a function for analyzing IP packets in response to access from a third-party terminal, a function for determining the destination IP address, a function for acquiring an access ID / user ID, a function for acquiring the access subject / user attributes, and a function for performing access control based on these.
[0057] <Configuration of Embodiment 1: Incentive Management Unit> The "incentive management unit" 204 is configured to have a function of providing incentives to individuals regarding whether or not to permit disclosure of their health and medical care-related information, in order to encourage centralized management of health and medical care-related information. FIG. 2e is a diagram showing an example of the functional configuration of the health and medical care related information unified management system according to the first embodiment. In this case, the information is stored and managed in a list format, associated with the individual (user) who accessed the system using a third-party terminal, i.e., the individual (user) who owns the My Number information "123456789012," and indicates whether the individual has consented to providing incentives for which health and medical-related information. If consent is given, the health and medical-related information is permitted to be disclosed to third parties, i.e., an incentive is granted. If consent is not given, the health and medical-related information is not disclosed to third parties, i.e., an incentive is not granted. It is desirable that the incentive information be kept up to date by the incentive management unit regularly exchanging it with the health and medical-related information storage unit. For example, in Figure 2e, whether or not an individual has given consent is stored and managed for each piece of health and medical-related information. A "★" indicates the individual's willingness to consent. Clicking, touching, or tapping on a display item listed in the health and medical-related information column (e.g., "Regular Health Checkup Results") on the device screen may display more detailed information in a pop-up screen or another transition screen. Clicking, touching, or tapping on the "★" in the consent or non-consent column on the device screen may also display the date and time of consent or non-consent in a pop-up screen. In particular, health and medical-related information marked with a "★" in the consent column is preferably stored and managed in association with the incentives described below. Health and medical-related information with no mark in the consent or non-consent column indicates that the individual (user) has not yet expressed their willingness to consent or non-consent.
[0058] <Configuration of Embodiment 1: Incentive Function Unit> The “incentive function unit” 205 includes at least the “incentive management unit” 204, and is configured to have functions such as controlling access to information related to incentives, acquiring consent information, and processing incentives, as described below. FIG. 2e is a diagram showing an example of the functional configuration of the health and medical care related information unified management system according to the first embodiment. In this case, the incentive function unit allows access when an individual enters their My Number information and password information into the appropriate fields and matching information exists in the system. In the case of this diagram, the method is explained in which the user directly inputs the information, but if the user uses a smartphone, for example, the smartphone's IC card reading function can be used, and the user can hold the My Number card up to the smartphone to automatically read and input specified information such as My Number information. For example, if the user fails to enter the My Number information and / or password information three times in a row, the device may be locked and the user may have to go to a local government (such as a city, ward, town, or village office) to have the lock removed. Alternatively, the device may be temporarily locked, and a warning message such as "Please try again the next day" may be displayed on the device, or the user may be notified by voice or a warning sound. It is also desirable that the information be stored and managed in a way that makes it easy to determine whether or not an individual (user) has consented to any health and medical care-related information. Furthermore, the incentive processing is preferably configured to process the level of incentive to be given for the health and medical care related information to which the user has given consent. For example, in the example shown in Figure 2e, 100 points (p) are calculated and awarded for each piece of health and medical information related to an individual based on predetermined calculation rules. The incentive calculation rules may also be weighted based on the importance, urgency, rarity, and usefulness of the health and medical information, allowing different incentives to be calculated and awarded for each piece of health and medical information. In particular, for malignant neoplasms (cancer), the leading cause of death among Japanese people; hypertension, diabetes, dyslipidemia, periodontal disease, or eye disease, which have a high prevalence; various infectious diseases defined under the Infectious Diseases Control Act, including COVID-19; and unique diseases with few cases worldwide, calculation rules may be set to provide greater (higher) incentives than for other diseases, given that disclosing such health and medical information to third parties can significantly contribute to medical advances. Furthermore, "incentive" simply means "motivation, reward," meaning intentional stimulation aimed at inducing some kind of action. In the present invention, "incentive" may include, in addition to the points mentioned above, personalized information services or general information services for information providers, provision of personalized medicines or supplements, provision of books or other products, provision of passwords or IDs for providing information, provision of items that can be used on a network, provision of rights, such as provision of the right to receive medical treatment, provision of the right to receive a diagnosis, provision of the right to receive an examination, provision of the right to receive various services on a network, provision of specific software (e.g., a health management app), provision of points for prepaid or postpaid electronic money, provision of product coupons, travel coupons, or cash. The present invention can be applied to both cases where an individual's health and medical-related information is already associated with and stored and managed as disclosure permission information indicating whether or not the information is permitted to be disclosed to a third party, and cases where an individual (user) newly registers their own health and medical-related information in the health and medical-related information storage unit, but the disclosure permission information has not yet been associated and stored and managed. That is, even if the centralized health and medical-related information management system does not store the individual's health and medical-related information, for example, if the individual's health and medical-related information is stored on a device owned by the individual and uploaded to the present system, the incentive function unit can be configured to provide an incentive based on the result of a formal check of the uploaded information if it is determined that the information is publicly available as health and medical-related information. In this case, the access control unit of the present system may be configured not to deny third parties access to view the health and medical-related information. However, it may also be configured to partially deny or restrict access depending on the type and qualifications of the third party. Uploading an individual's health and medical-related information to the present system may be a transfer, and the source of the transfer may not be the individual's device but may be a system storing other health and medical-related information. For example, health and medical care-related information stored in a maternal and child health handbook information server, a PHR (Personal Health Record), a nursing care information server, a dental care information server, a rehabilitation information server, etc. can be configured to be transferred to this system with the individual's consent. In this case, the incentive function unit can be configured to function once the individual's health and medical care-related information is uploaded from the maternal and child health handbook information server, etc., and a formal check is completed.
[0059] <Embodiment 1: Unified management system for health and medical information: Hardware configuration> The hardware configuration of the health and medical care related information unified management system according to this embodiment will be described with reference to the drawings.
[0060] Figure 2c is a diagram showing the hardware configuration of the unified healthcare and medical information management system of this embodiment. As shown in this figure, the unified healthcare and medical information management system of this embodiment comprises a "CPU (Central Processing Unit)" 211 that performs various types of calculation processing, and a "main memory" 212. It also comprises a "non-volatile memory" 213 that stores predetermined information, and a "network I / F (interface)" 214 that transmits and receives information to and from multiple third-party terminals 216 and an administrator terminal 217. These components are interconnected by a data communication path such as a "bus" 215, and perform information transmission and reception and processing.
[0061] Here, the "main memory" reads out programs that perform various processes to be executed by the "CPU," and also provides a work area for the programs. The "main memory" and "non-volatile memory" are each assigned multiple addresses, and programs executed by the "CPU" can exchange data and perform processing by identifying and accessing these addresses. In this embodiment, the programs stored in the "main memory" include a health and medical care-related information accumulation program, an access control program, and an incentive management program. The "main memory" and "non-volatile memory" also store health and medical care-related information, incentive management information, and the like.
[0062] The "CPU" executes the health and medical information storage program stored in the "main memory" and stores in the "main memory" and "non-volatile memory" health and medical information about an individual sent from a third-party terminal via the "network I / F," such as electronic medical record information, various test information, prescription information, medication history information, medication status information, and vital signs information (e.g., body temperature, blood pressure, heart rate, etc.). The "CPU" also executes the access control program stored in the "main memory" to control access to the health and medical information about an individual. The "CPU" also executes the incentive management program stored in the "main memory" to grant and manage incentives for an individual's desired health and medical information, and stores information about these incentives in the "main memory" and "non-volatile memory."
[0063] <Embodiment 1: Unified Healthcare and Medical Information Management System: Processing Flow> 2d shows the process flow when using the unified healthcare-related information management system of this embodiment. As shown in the figure, the processing method comprises a healthcare-related information accumulation step S221, an access control step S222, and an incentive management step S223. These processing methods are executed by a centralized health and medical care-related information management system having a health and medical care-related information storage unit for storing and centrally managing health and medical care-related information about individuals, an access control unit for controlling the disclosure of the health and medical care-related information stored in the health and medical care-related information storage unit to third parties via a network, and an incentive function unit including at least an incentive management unit for providing incentives to individuals regarding whether or not to allow the disclosure of the health and medical care-related information about individuals in order to encourage centralized management of the health and medical care-related information.
[0064] The "health and medical related information accumulation step" S221 is a step in which health and medical related information about an individual sent from a third-party terminal via a network, such as electronic medical record information, various test information, prescription information, medication history information, medication status information, and vital information (e.g., body temperature, blood pressure, heart rate, etc.), is accumulated.
[0065] The "access control step" S222 is a step for controlling access to the health care related information about an individual stored in the health care related information storage unit.
[0066] The "incentive management step" S223 is a stage in which incentives are given and managed for the health and medical care-related information desired by an individual.
[0067] <Summary> As described above, the present invention can provide a centralized management system for health and medical care-related information that provides incentives to individuals regarding whether or not to allow the disclosure of health and medical care-related information about individuals, in order to encourage centralized management of health and medical care-related information. Furthermore, the present invention provides incentives to individuals, allowing them to give permission for the disclosure of their health and medical care-related information to third parties, which will increase the opportunities for individuals to disclose their health and medical care-related information to third parties, thereby reducing medical costs nationwide and improving the health of the entire population, as well as reducing the time and money spent by research institutions and pharmaceutical companies on drug discovery, and ultimately contributing to the advancement of medicine. Here, "drug discovery" refers to the process from compounds and chemical substances (also called seeds) that are the basis for pharmaceuticals to becoming products and being sold. Furthermore, the following steps (1) to (5) are essential for compounds and chemical substances to become pharmaceuticals and be sold. (1) Select candidate drug discovery targets (compounds and chemical substances) (2) By screening the effects, candidate substances that will become the basis for pharmaceuticals are selected. There are various types of screening, including biotechnology techniques, combinatorial chemistry (techniques for creating compounds by combining multiple compounds), and highly efficient screening that utilizes AI robotics technology. (3) Animal experiments Safety and efficacy are investigated and confirmed in detail using animals or cultured cells. Drugs whose safety and efficacy have been confirmed at this stage are called "investigational drugs." (4) Clinical trials The investigational drug is actually used on humans to examine its effectiveness and safety in detail and determine whether it is useful for actual treatment. (5) Application for approval and review Drugs that pass all of the above tests (1) to (4) are submitted to the Ministry of Health, Labor and Welfare. After that, they are examined by the Pharmaceuticals and Medical Devices Agency and await approval from the Minister of Health, Labor and Welfare. Only after approval can the drug be sold as a product. Generally, drug discovery takes about 10 to 18 years, and the probability that a compound or chemical substance will become a new drug is about 1 in 10,000. It is also said that the total cost of successful drug discovery is close to 20 billion yen.
[0068] <Embodiment 2 (mainly corresponding to claim 2)> <Outline of Embodiment 2> This embodiment is characterized in that, in addition to the components of embodiment 1, it includes an access authentication processing unit that performs access authentication from a third-party terminal via a network to the incentive function unit of the centralized health and medical information management system. From here on, explanations of functions, hardware configurations, and processing flows that overlap with embodiment 1 will be omitted as appropriate.
[0069] <Configuration of Embodiment 2: Access Authentication Processing Unit> 3a is a diagram showing the functional configuration of the unified health and medical information management system. As shown in this figure, an “access authentication processing unit” 301 is included in the incentive function unit and is configured to have the function of authenticating whether or not an individual is permitted to access the incentive management unit. For example, Figure 11a shows an example of a user interface for the unified management system for healthcare and medical information of the present invention. Here, it is assumed that a third-party terminal accesses the unified management system for healthcare and medical information using a web browser. On this login screen, the user (individual) enters their own My Number information and password information in the appropriate fields, and if matching information exists in the system, access is granted. The example in the figure explains how the user directly inputs information, but if the user uses a smartphone, for example, the smartphone's IC card reading function can be used to hold the My Number card up to the smartphone to automatically read and input specified information such as My Number information. For example, if the user fails to enter the My Number information and / or password information three times in a row, the device may be locked and the user may have to go to a local government (such as a city, ward, town, or village office) to have the lock removed. Alternatively, the device may be temporarily locked, and a warning message such as "Please try again the next day" may be displayed on the device, or the user may be notified by voice or a warning sound.
[0070] <Embodiment 2: Unified management system for health and medical information: Hardware configuration> The hardware configuration of the health and medical care related information unified management system according to this embodiment will be described with reference to the drawings.
[0071] Figure 3b is a diagram showing the hardware configuration of the unified healthcare and medical information management system of this embodiment. As shown in this figure, the unified healthcare and medical information management system of this embodiment comprises a "CPU (Central Processing Unit)" 311 that performs various types of calculation processing, and a "main memory" 312. It also comprises a "non-volatile memory" 313 that stores predetermined information, and a "network I / F (interface)" 314 that transmits and receives information to and from multiple third-party terminals 316 and an administrator terminal 317. These components are interconnected by a data communication path such as a "bus" 315, and perform information transmission and reception and processing.
[0072] Here, the "main memory" reads out programs that perform various processes to be executed by the "CPU," and also provides a work area for the programs. The "main memory" and "non-volatile memory" are each assigned multiple addresses, and programs executed by the "CPU" can exchange data and perform processing by identifying and accessing these addresses. In this embodiment, the program stored in the "main memory" is an access authentication processing program. The "main memory" and "non-volatile memory" also store My Number information, password information, and the like.
[0073] The "CPU" executes the access authentication processing program stored in the "main memory," accepts input of My Number information and password information sent from a third-party terminal via the "network I / F," and verifies whether matching information exists. The "CPU" also stores the My Number information and password information in the "main memory" and "non-volatile memory."
[0074] <Embodiment 2: Unified management system for health and medical information: Processing flow> 3c is a diagram showing the flow of processing when the unified health and medical care related information management system of this embodiment is used. As shown in the figure, this is a processing method consisting of an access authentication processing step S301.
[0075] The "access authentication processing step" S301 is a stage in which input of My Number information and password information about the user sent from a third-party terminal is accepted, and authentication is performed to determine whether matching information exists in the system.
[0076] <Summary> As described above, in the present invention, by first performing access authentication on the login screen of the unified health and medical care related information management system, access to incentive-related information can be restricted to the individual (user) himself / herself.
[0077] <Embodiment 3 (mainly corresponding to claim 3)> <Outline of Embodiment 3> In addition to the features of embodiments 1 and 2, this embodiment includes a consent information acquisition unit that acquires consent information, which is information indicating consent to receiving an incentive from the incentive management unit. From here on, descriptions of functions, hardware configurations, and processing flows that overlap with those of embodiments 1 and 2 will be omitted as appropriate.
[0078] <Configuration of Third Embodiment: Consent Information Acquisition Unit> 4a is a diagram showing the functional configuration of the integrated health and medical information management system. As shown in this figure, a "consent information acquisition unit" 402 is included in the incentive function unit, and is configured to have the function of acquiring consent information, which is information indicating consent to accept an incentive from the incentive management unit, after authentication by the access authentication processing unit 401. FIG. 11b is a diagram showing an example of a user interface in the health and medical care related information unified management system of the present invention. In this case, the individual (user) enters their My Number information and password information in the appropriate fields, and after matching information is found in the system and access authentication is performed, they are taken to the function selection screen. Then, by clicking, touching, or tapping the OK button corresponding to "(A) Consent Processing," they are taken to a screen for obtaining the individual's (user's) consent. FIG. 11c is a diagram showing an example of a user interface in the health and medical care related information unified management system of the present invention. In this case, it is preferable to provide a user interface such as a checkbox in the consent or disagreement field, and by clicking, touching, or tapping there, a "★" mark, for example, is placed to indicate whether the user (individual) agrees or disagrees to accept the incentive. By clicking, touching, or tapping the OK button, the entered consent information is sent to the incentive management unit, where it is stored and managed. Note that by clicking, touching, or tapping the Exit button, you can return to the function selection screen in Figure 11b. FIG. 11b is a diagram showing an example of a user interface in the health and medical care related information unified management system of the present invention. In this case, the individual (user) enters their own My Number information and password information in the appropriate fields, and after matching information is found in the system and access authentication is performed, they are taken to a function selection screen where they can click, touch or tap the OK button corresponding to "(B) Viewing process" to transition to a screen where they can view the relationship between the individual's (user's) health and medical related information and the incentives granted. FIG. 11d is a diagram showing an example of a user interface in the health and medical care related information unified management system of the present invention. In this case, it is preferable to display the target individual's health and medical care-related information and the corresponding incentives granted in an easy-to-understand format, such as a list. This allows the user to see at a glance which health and medical care-related information the incentive granted at the time of viewing is associated with. Note that you can return to the function selection screen in Figure 11b by clicking, touching, or tapping the Exit button. FIG. 11b is a diagram showing an example of a user interface in the health and medical care related information unified management system of the present invention. In this case, the individual (user) enters their My Number information and password information in the appropriate fields, and after matching information is found in the system and access authentication is performed, they are taken to the function selection screen. Then, by clicking, touching, or tapping the OK button corresponding to "(C) Maintenance Processing," they are taken to a screen that displays the health and medical care-related information about the individual (user) that they have not yet consented to, as well as the health and medical care-related information that they have already consented to. FIG. 11f is a diagram showing an example of a user interface in the integrated health and medical care related information management system of the present invention. In this case, it is preferable to display the target individual's health and medical information and the corresponding consent or disagreement status in an easy-to-understand format, such as a list. For health and medical information for which consent or disagreement has not yet been entered at the time of viewing, the individual (user) can enter a "★" mark in the consent / disagreement checkbox and click, touch, or tap the OK button to process the provision of incentives, etc. For health and medical information for which consent or disagreement has already been entered, the individual (user) can review the information as needed, for example, by changing consent to disagreement or disagreement to consent, and then clicking, touching, or tapping the OK button to update it. Note that the user can return to the function selection screen in Figure 11b by clicking, touching, or tapping the Exit button.
[0079] <Embodiment 3: Unified Management System for Healthcare-Related Information: Hardware Configuration> The hardware configuration of the health and medical care related information unified management system according to this embodiment will be described with reference to the drawings.
[0080] Figure 4b is a diagram showing the hardware configuration of the unified healthcare and medical information management system of this embodiment. As shown in this figure, the unified healthcare and medical information management system of this embodiment includes a "CPU (Central Processing Unit)" 411 that performs various types of calculation processing, and a "main memory" 412. It also includes a "non-volatile memory" 413 that stores predetermined information, and a "network I / F (interface)" 414 that transmits and receives information to and from multiple third-party terminals 416 and an administrator terminal 417. These components are interconnected by a data communication path such as a "bus" 415, and perform information transmission and reception and processing.
[0081] Here, the "main memory" reads out programs that perform various processes to be executed by the "CPU," and also provides a work area for the programs. Furthermore, multiple addresses are assigned to the "main memory" and "non-volatile memory," and programs executed by the "CPU" can exchange data and perform processing by identifying and accessing these addresses. In this embodiment, the programs stored in the "main memory" are an access authentication processing program and a consent information acquisition program. Furthermore, the "main memory" and "non-volatile memory" store My Number information, password information, consent information, etc.
[0082] The "CPU" executes the access authentication processing program stored in the "main memory," accepts input of My Number information and password information sent from a third-party terminal via the "network I / F," and verifies whether matching information exists. The "CPU" also stores the My Number information and password information in the "main memory" and "non-volatile memory." The "CPU" also executes the consent information acquisition program stored in the "main memory" to acquire consent information indicating the individual's (user's) intention for each piece of health and medical-related information sent from the third-party terminal via the "network I / F." The consent information is then stored in the "main memory" and "non-volatile memory."
[0083] <Embodiment 3: Unified management system for health and medical information: Processing flow> 4c is a diagram showing the processing flow when using the unified health and medical care related information management system of this embodiment. As shown in the figure, the processing method comprises an access authentication processing step S401 and a consent information acquisition step S402.
[0084] The "consent information acquisition step" S402 is a stage in which, after authentication in the access authentication processing step, consent information is acquired, which is information indicating consent to receive an incentive from the incentive management unit.
[0085] <Summary> As described above, in the present invention, consent information, which is information indicating consent to receiving incentives for health and medical care-related information about an individual (user), can be acquired.
[0086] <Embodiment 4 (mainly corresponding to claim 4)> <Outline of Embodiment 4> In addition to the features of embodiments 1 to 3, this embodiment includes an incentive processing unit that performs incentive processing, which is processing for providing an incentive, when consent information is acquired by the consent information acquisition unit. Hereinafter, descriptions of functions, hardware configurations, and processing flows that overlap with those of embodiments 1 to 3 will be omitted as appropriate.
[0087] <Configuration of Embodiment 4: Incentive Processing Unit> 5A is a diagram showing the functional configuration of the health and medical care related information unified management system. As shown in this figure, an "incentive processing unit" 503 is included in the incentive function unit, and is configured to have the function of performing incentive processing to provide incentives when consent information is acquired by the consent information acquisition unit. FIG. 11d is a diagram showing an example of a user interface in the health and medical care related information unified management system of the present invention. In this example, the incentive to be automatically calculated and awarded based on a predetermined calculation rule is shown for health and medical-related information for which an individual (user) has indicated consent to disclosure and marked "★" in the consent field. Here, the incentive is calculated and awarded based on the predetermined calculation rule, with 100 points (p) being awarded for each piece of health and medical-related information for each individual. The incentive calculation rule may also be weighted based on the importance, urgency, rarity, and usefulness of the health and medical-related information, thereby calculating and awarding different incentives for each piece of health and medical-related information. In particular, for example, for malignant neoplasms (cancer), which are the leading cause of death among Japanese people; hypertension, diabetes, dyslipidemia, periodontal disease, or eye disease, various infectious diseases defined under the Infectious Diseases Act, including COVID-19, and unique diseases with few cases worldwide, the calculation rule may be set to provide higher incentives than for other diseases, given that disclosing such health and medical-related information to third parties can significantly contribute to medical advances. Furthermore, "incentive" simply means "motivation, reward," meaning intentional stimulation aimed at inducing some kind of action. In the present invention, "incentive" may include, in addition to the points mentioned above, personalized information services or general information services for information providers, provision of personalized medicines or supplements, provision of books or other products, provision of passwords or IDs for providing information, provision of items that can be used on a network, provision of rights, such as provision of the right to receive medical treatment, provision of the right to receive a diagnosis, provision of the right to receive an examination, provision of the right to receive various services on a network, provision of specific software (e.g., a health management app), provision of points for prepaid or postpaid electronic money, provision of product coupons, travel coupons, or cash. The present invention can be applied to both cases where an individual's health and medical-related information is already associated with and stored and managed as disclosure permission information indicating whether or not the information is permitted to be disclosed to a third party, and cases where an individual (user) newly registers their own health and medical-related information in the health and medical-related information storage unit, but the disclosure permission information has not yet been associated and stored and managed. That is, even if the health and medical-related information of an individual is not stored in the centralized health and medical-related information management system, for example, if the individual's health and medical-related information is stored on a device owned by the individual and uploaded to the present system, the incentive function unit described above can be configured to provide an incentive based on the result of a formal check of the uploaded information if it is determined that the information is publicly available as health and medical-related information. In this case, the access control unit of the present system may be configured not to deny third parties access to view the health and medical-related information. However, it may also be configured to partially deny or restrict access depending on the type and qualifications of the third party. Uploading an individual's health and medical-related information to the present system may be a transfer, and the source of the transfer may not be the individual's device but may be a system storing other health and medical-related information. For example, health and medical care-related information stored in a maternal and child health handbook information server, a PHR (Personal Health Record), a nursing care information server, a dental care information server, a rehabilitation information server, etc. can be configured to be transferred to this system with the individual's consent. In this case, the incentive function unit can be configured to function once the individual's health and medical care-related information is uploaded from the maternal and child health handbook information server, etc., and a formal check is completed. FIG. 11b is a diagram showing an example of a user interface in the health and medical care related information unified management system of the present invention. In this case, the individual (user) enters their own My Number information and password information in the appropriate fields, and after matching information is found in the system and access authentication is performed, they are taken to a function selection screen where they can click, touch or tap the OK button corresponding to "(B) Viewing process" to transition to a screen where they can view the relationship between the individual's (user's) health and medical related information and the incentives granted. FIG. 11d is a diagram showing an example of a user interface in the health and medical care related information unified management system of the present invention. In this case, it is preferable to display the target individual's health and medical care-related information and the corresponding incentives granted in an easy-to-understand format, such as a list. This allows the user to see at a glance which health and medical care-related information the incentive granted at the time of viewing is associated with. Note that you can return to the function selection screen in Figure 11b by clicking, touching, or tapping the Exit button. FIG. 11b is a diagram showing an example of a user interface in the health and medical care related information unified management system of the present invention. In this case, the individual (user) enters their My Number information and password information in the appropriate fields, and after matching information is found in the system and access authentication is performed, they are taken to the function selection screen. Then, by clicking, touching, or tapping the OK button corresponding to "(C) Maintenance Processing," they are taken to a screen that displays the health and medical care-related information about the individual (user) that they have not yet consented to, as well as the health and medical care-related information that they have already consented to. FIG. 11f is a diagram showing an example of a user interface in the integrated health and medical care related information management system of the present invention. In this case, it is preferable to display the target individual's health and medical information and the corresponding consent or disagreement status in an easy-to-understand format, such as a list. For health and medical information for which consent or disagreement has not yet been entered at the time of viewing, the individual (user) can enter a "★" mark in the consent / disagreement checkbox and click, touch, or tap the OK button to process the provision of incentives, etc. For health and medical information for which consent or disagreement has already been entered, the individual (user) can review the information, for example, by changing consent to disagreement or disagreement to consent, and then clicking, touching, or tapping the OK button to update it. Note that the user can return to the function selection screen in Figure 11b by clicking, touching, or tapping the Exit button.
[0088] <Embodiment 4: Unified Management System for Healthcare-Related Information: Hardware Configuration> The hardware configuration of the health and medical care related information unified management system according to this embodiment will be described with reference to the drawings.
[0089] Figure 5b is a diagram showing the hardware configuration of the unified healthcare and medical information management system of this embodiment. As shown in this figure, the unified healthcare and medical information management system of this embodiment comprises a "CPU (Central Processing Unit)" 511 that performs various types of calculation processing, and a "main memory" 512. It also comprises a "non-volatile memory" 513 that stores predetermined information, and a "network I / F (interface)" 514 that transmits and receives information to and from multiple third-party terminals 516 and an administrator terminal 517. These components are interconnected by a data communication path such as a "bus" 515, and perform information transmission and reception and processing.
[0090] Here, the "main memory" reads out programs that perform various processes to be executed by the "CPU," and also provides a work area that is a workspace for those programs. Furthermore, multiple addresses are assigned to the "main memory" and "non-volatile memory," and programs executed by the "CPU" can exchange data and perform processing by identifying and accessing those addresses. In this embodiment, the programs stored in the "main memory" are an access authentication processing program, a consent information acquisition program, and an incentive processing program. Furthermore, the "main memory" and "non-volatile memory" store My Number information, password information, consent information, incentive information, etc.
[0091] The "CPU" executes the access authentication processing program stored in the "main memory," accepts input of My Number information and password information sent from a third-party terminal via the "network I / F," and verifies whether matching information exists. The "CPU" also stores the My Number information and password information in the "main memory" and "non-volatile memory." The "CPU" also executes the consent information acquisition program stored in the "main memory" to acquire consent information indicating the individual's (user's) intention for each piece of health and medical-related information sent from the third-party terminal via the "network I / F." The consent information is then stored in the "main memory" and "non-volatile memory." The "CPU" also executes an incentive processing program stored in the "main memory" to perform incentive processing, which is a process for providing incentives when consent is obtained for health and medical care-related information about an individual.
[0092] <Embodiment 4: Unified management system for health and medical information: Processing flow> 5c is a diagram showing the processing flow when using the unified health and medical care-related information management system of this embodiment. As shown in the figure, the processing method comprises an access authentication processing step S501, a consent information acquisition step S502, and an incentive processing step S503.
[0093] The "incentive processing step" S503 is a stage in which, when consent information is acquired by the consent information acquisition unit, incentive processing is performed to provide an incentive.
[0094] <Summary> As described above, in the present invention, incentive processing, which is processing for providing incentives, can be performed for health and medical care-related information about an individual (user) when the individual consents, and appropriate incentive processing can be applied to health and medical care-related information about an individual.
[0095] <Fifth Embodiment (mainly corresponding to claim 5)> <Outline of Embodiment 5> This embodiment provides a centralized healthcare and medical information management system comprising: a healthcare and medical care related information storage unit that stores healthcare and medical care related information about individuals; and an access control unit that allows third parties to access the healthcare and medical care related information stored in the healthcare and medical care related information storage unit via a network. The access control unit comprises: IP packet analysis means that analyzes IP packets sent via the network; destination IP address determination means that extracts the destination IP address from the IP header of the IP packet and determines whether the IP address is addressed to the centralized healthcare and medical care related information management system's own; access ID / user ID acquisition means that, if the destination IP address is an IP address addressed to the centralized healthcare and medical care related information management system's own, acquires from the IP payload an access ID indicating the accessing entity and a user ID indicating the user belonging to the accessing entity; access entity user attribute acquisition means that acquires access entity information, user information, and user attribute information (here, information indicating whether the user is a healthcare professional or a non-healthcare professional) corresponding to the access ID and user ID; access control means that controls access to the healthcare and medical care related information from third parties; and disclosure permission information storage unit that stores disclosure permission information indicating whether an individual's healthcare and medical care related information is permitted to be disclosed to third parties. Note that the description of the same functions, hardware configurations, and processing flows as those in the first to fourth embodiments will be omitted where appropriate.
[0096] <Functional Configuration of Fifth Embodiment> 6a is a diagram showing the functional configuration of a health and medical care related information unified management system in embodiment 5. In this embodiment, the access control unit includes an IP packet analysis means, a destination IP address determination means, an access ID / user ID acquisition means, an access subject user attribute acquisition means, an access control means, and a disclosure permission information storage unit.
[0097] <Fifth embodiment: Configuration description: IP packet analysis means of access control unit> The "IP packet analysis means" 601 is configured to have the function of analyzing IP packets sent via a network (especially the Internet). Generally, an IP packet consists of an IP header section and an IP payload section, and various information and data are stored within these sections. The "IP packet analysis means" 601 is responsible for analyzing and examining what information and data are contained within these sections.
[0098] <Fifth embodiment: Configuration description: Destination IP address determination means of access control unit> The "destination IP address determination means" 602 is configured with the function of extracting the destination IP address from the header of a received IP packet and determining whether the IP address is addressed to its own centralized healthcare and medical information management system. Generally, an IP packet contains at least a source IP address indicating the sender and a destination IP address indicating the destination in the IP header. The "destination IP address determination means" 602 references the destination IP address extracted from the IP header to determine whether the IP packet was sent to its own centralized healthcare and medical information management system, and if it determines that the packet was addressed to itself, it proceeds to the next process. However, if it determines that the packet was not addressed to itself, it ignores the IP packet and does not perform any further operations.
[0099] <Configuration of the fifth embodiment: Access ID / user ID acquisition means of the access control unit> The "access ID / user ID acquisition means" 603 is configured to have the function of extracting and acquiring the access ID indicating the access subject stored in the IP payload and the user ID indicating the user belonging to the access subject when it is determined that the IP packet was sent to the centralized management system for health and medical related information.
[0100] <Configuration of Fifth Embodiment: Access Subject User Attribute Acquisition Means of Access Control Unit> The "access subject user attribute acquisition means" 604 is configured to have the function of acquiring access subject information corresponding to the access ID and user ID, user information belonging to the access subject, and user attribute information for the user (here, information indicating whether the user is a medical professional or a non-medical professional). The access subject information is information that specifically identifies the access subject, and is expressed, for example, by a name such as "Edogawa Central Hospital" or "Edogawa Pharmaceuticals." The user information is information that specifically identifies an employee or the like belonging to the access subject, and is expressed, for example, by a name such as "Ichiro Suzuki," an employee of "Edogawa Central Hospital," or "Fumiko Maeda," an employee of "Edogawa Pharmaceuticals." Furthermore, the user attribute information is attribute information associated with the user information and indicates whether the user is a medical professional or a non-medical professional, and is expressed, for example, by a "medical professional" (abbreviated as "medical") or a "non-medical professional" (abbreviated as "non-medical"). Here, "healthcare professionals" preferably includes at least doctors, dentists, pharmacists, public health nurses, midwives, nurses, licensed practical nurses, physical therapists, occupational therapists, orthoptists, speech-language-hearing therapists, prosthetists, radiological technologists, radiological x-ray technicians, clinical laboratory technicians, medical laboratory technicians, clinical engineers, dental hygienists, dental technicians, emergency medical technicians, masseurs and shiatsu therapists, acupuncturists, moxibustion therapists, judo therapists, registered dietitians, nutritionists, mental health workers, social workers, care workers, certified psychologists, clinical psychologists, medical administrators, etc. Among the "healthcare professionals" mentioned above, the role of so-called family healthcare professionals (e.g., family doctors, family pharmacists, family dentists) who regularly provide medical examinations and medication instructions to individuals (patients) is extremely important, and it is preferable that they be granted the authority to access an individual's health care-related information stored in the health care-related information storage unit and to edit, add, and delete the health care-related information as appropriate and necessary. For example, a "family doctor" is a doctor who can be consulted about anything, is well-versed in the latest medical information, can refer patients to specialists and specialized medical institutions when necessary, and has the comprehensive capabilities to provide local medical care, health, and welfare services as a reliable and close-knit doctor. A "family doctor" is someone who (1) understands the patient's lifestyle and provides appropriate medical treatment and health guidance in the course of daily medical practice, and is able to cooperate with local doctors, medical institutions, etc. to provide solutions when he or she is unable to provide medical treatment or guidance beyond his or her own area of expertise; (2) is able to share necessary information with local doctors, medical institutions, etc. so that the patient can continue to receive the best possible medical care even outside of his or her own medical practice hours, and through mutual cooperation, is able to establish a system in which patients can be treated on holidays and at night; (3) in addition to providing daily medical practice, is able to build relationships of trust with local residents and actively participate in social and administrative activities surrounding local medical care, such as health consultations, health checkups, cancer screenings, maternal and child health, school health, industrial health, and community health, as well as cooperate with health, nursing, and welfare professionals, and is also able to promote home medical care so that local elderly people can live in the community as long as possible; and (4) is able to provide patients and their families with appropriate and easy-to-understand information about medical care. For example, a "family pharmacist" is a pharmacist who has extensive knowledge and experience in matters such as pharmaceutical treatment, health, and nursing care, and who can provide consultations that meet the needs of patients and consumers. The role of a "family pharmacist" is (1) to manage the medication status of one patient at one pharmacy, and to continue to do so (for example, to ensure the safe and secure use of medications, the pharmacist keeps track of all the medications the patient is taking, including prescription and over-the-counter medications, in one place, and continually checks for overlaps and drug interactions, as well as whether the medications are working and whether there are any side effects), (2) to provide 24-hour support and visit patients' homes to provide in-home medical care (for example, to answer questions about medications, such as how to use them, and their side effects, over the phone, even outside the pharmacy's opening hours, such as on holidays and at night. In addition, the pharmacist can provide prescriptions at night and on holidays as needed). (2) Provide medications based on prescriptions. Visit the homes of elderly patients and other patients who have difficulty going out, explain the medications, and check for remaining medication (medicines remaining on hand), (3) Work in cooperation with prescribing physicians and medical institutions (for example, check the prescription contents and make inquiries or suggestions to the doctor as necessary. Monitor the patient's condition even after dispensing the medication, provide feedback to the prescribing physician, and check for remaining medication. Provide consultations on a wide range of health-related matters, not just medications, and recommend visiting a medical institution if necessary. Also, work in cooperation with local medical institutions to build relationships that allow the team to support patients on a daily basis). For example, a "family dentist" refers to a dentist who not only provides safe and secure dental care but also has a wide range of knowledge and insight regarding medical care and nursing, and who aims to maintain and improve the oral function of local residents throughout their lives, and who is able to fulfill his or her responsibilities as a part of local medical care. It is desirable for a "family dentist" to be a person who can fulfill the following roles: (1) provide appropriate dental treatment and health guidance for ongoing management and prevention of serious illness according to life stages from infancy to old age, thereby contributing to the maintenance and improvement of oral and overall health; (2) play a role in improving oral health for local residents through health activities such as dental checkups, in cooperation with local government and related organizations; and (3) cooperate with related local organizations and other industries to provide seamless home dental care and nursing care services in various treatment facilities for patients who have difficulty visiting a hospital, and actively participate in community-based comprehensive care. In addition, flag information that identifies a personal healthcare professional may be added to or associated with the third-party identification information described below. Note that the information indicating a personal healthcare professional may be set, changed, or deleted as appropriate or necessary by an individual (e.g., a patient), the company to which the individual belongs, the health insurance association to which the individual belongs, or the local government in which the individual resides, using a third-party terminal, or the administrator described above may be able to register, edit, or delete the information using the administrator terminal. Furthermore, it is preferable that "non-medical personnel" include at least employees of life insurance companies, non-life insurance companies, securities companies, pharmaceutical companies, drug discovery venture companies, food companies, health equipment companies, fitness clubs, sports gyms, banks, credit unions, JA (agricultural cooperatives), union health insurance, Japan Health Insurance Association, mutual aid associations, municipal national health insurance, national health insurance associations, PR companies, comprehensive research institutes, universities and graduate schools (including affiliated research institutes), technical colleges, agriculture, forestry and fisheries companies, fertilizer manufacturers, government agencies, local governments, and independent administrative agencies.
[0101] <Fifth embodiment: Description of configuration: Access control means of access control unit> The "access control means" 605 is configured to have a function of controlling access when a third party accesses the health and medical care related information storage unit via a network.
[0102] FIG. 6b is a diagram showing an example of the functional configuration of the health and medical care related information unified management system according to this embodiment. First, the IP packet analysis means analyzes the received IP packet 608 to check what information and data it contains. For example, it analyzes and checks whether the source IP address and destination IP address are included in the IP header of the IP packet. Next, the destination IP address determination means extracts the destination IP address contained in the received IP packet 608 and determines whether it is addressed to its own centralized healthcare and medical information management system. At this time, the access control unit 609 stores an IP address table 610, and references this table to determine whether it is addressed to its own centralized healthcare and medical information management system. If the stored IP address (e.g., 192.168.0.1) matches the destination IP address, it is determined to be addressed to its own centralized healthcare and medical information management system, and the process proceeds to the next step. If there is no match in the IP address table, the IP packet is ignored and no further processing is performed. Next, if the IP packet sent is addressed to the system's own centralized management system for health and medical related information, the access ID / user ID acquisition means extracts and acquires the access ID indicating the accessing entity stored in the IP payload of the IP packet and the user ID indicating the user belonging to the accessing entity. Next, the access subject user attribute acquisition means acquires access subject information, user information, and user attribute information from the extracted access ID and user ID. At this time, the access control unit 609 stores an access ID / user ID table 611, and references this table to acquire specific access subject information, user information, and user attribute information. Here, when the access ID is "A0001," the access subject information is "Edogawa Central Hospital." When the user ID is "C0001," the user information is "Ichiro Suzuki," and the user attribute information is "healthcare professional." When the access ID is "B0001," the access subject information is "Edogawa Pharmaceutical." When the user ID is "D0001," the user information is "Fumiko Maeda," and the user attribute information is "non-healthcare professional." Through the operations performed by the above means, it is possible to determine whether a third party accessing the health and medical information unified management system is a healthcare professional or a non-healthcare professional. Next, the access control means determines the scope of access to the health and medical care-related information depending on whether the third party is a medical professional or a non-medical professional. For example, if a user named "Ichiro Suzuki" who belongs to a third-party accessing entity (in this case, "Edogawa Central Hospital") has the attribute information "health and medical care professional," the access control means allows the user to access all of the health and medical care-related information related to the individual. On the other hand, if a user named "Fumiko Maeda" who belongs to a third-party accessing entity (in this case, "Edogawa Pharmaceutical") has the attribute information "non-health and medical care professional," the access control means allows the user to access some (including all) of the health and medical care-related information related to the individual, or health and medical care-related information anonymized using a predetermined anonymization method described below. In this way, it is possible to determine who the third-party user is and whether their attribute information is "health and medical care professional" or "non-health and medical care professional," thereby determining the scope of access to the health and medical care-related information related to the individual. It is preferable that the administrator responsible for managing and operating the centralized health and medical information management system can use an administrator terminal to register, edit, and delete information in these tables. It is also preferable that the access subject information, user information, and user attribute information ("healthcare professional" or "non-healthcare professional") are also associated with third-party identification information, which will be described later.
[0103] <Configuration of Fifth Embodiment: Disclosure Permission Information Storage Unit of Access Control Unit> As shown in FIG. 6a, the "disclosure permission information storage unit" 606 is configured to have the function of storing disclosure permission information indicating whether or not to disclose one's own health and medical-related information to a third party accessing the health and medical-related information via the network. Specifically, it is desirable to configure the system so that information indicating "disclosure permission" or "disclosure denial" can be set at the individual's discretion via the network 205 from a third-party terminal 206, as shown in FIG. 2b, to the access control unit 202 of the centralized health and medical-related information management system 200. For example, the disclosure permission information may be binary information (flag information) in which "disclosure permission" is "1" and "disclosure denial" is "0." The disclosure permission information may also be configured to determine whether or not to disclose a specific block of health and medical-related information. For example, it is conceivable that health and medical-related information related to internal medicine among medical departments is set to "disclosure permission," while health and medical-related information related to psychiatry is set to "disclosure denial." Furthermore, the disclosure permission information may be configured to distinguish between "disclosure permission" and "disclosure denial" when the third party is a specific medical professional, in combination with third-party identification information (described below). For example, if the third-party identification information represents a "doctor," the individual's health and medical related information may be "approved for disclosure," whereas if the third-party identification information represents a specific medical professional (e.g., an accountant or bookkeeper), the individual's health and medical related information may be "denied disclosure."
[0104] <Embodiment 5: Unified Management System for Healthcare-Related Information: Hardware Configuration> The hardware configuration of the health and medical care related information unified management system according to this embodiment will be described with reference to the drawings.
[0105] Figure 6c is a diagram showing the hardware configuration of the health and medical care related information unified management system in this embodiment. As shown in this figure, the access control unit in this embodiment includes a "CPU (Central Processing Unit)" 621 that performs various arithmetic processing, and a "main memory" 622. It also includes a "non-volatile memory" 623 that stores predetermined information, and a "network I / F (interface)" 624 that transmits and receives information to and from multiple third-party terminals 626 and an administrator terminal 627. These components are interconnected by a data communication path such as a "bus" 625, and perform information transmission, reception, and processing.
[0106] The "main memory" reads out programs that perform various processes and allows the "CPU" to execute them, while also providing a work area for the programs. The "main memory" and "non-volatile memory" are each assigned multiple addresses, allowing programs executed by the "CPU" to identify and access these addresses to exchange data and perform processing. In this embodiment, the programs stored in the "main memory" are a health and medical information storage program, an IP packet analysis program, a destination IP address determination program, an access ID / user ID acquisition program, an access subject user attribute acquisition program, a disclosure permission information retention program, and an access control program. The "main memory" and "non-volatile memory" also store health and medical information, IP address information, access ID information, user ID information, access subject information, user information, user attribute information, disclosure permission information, and other information.
[0107] The "CPU" executes the health and medical information storage program stored in the "main memory" to store in the "main memory" and "non-volatile memory" health and medical information about an individual sent from a third-party terminal via the "network I / F," such as electronic medical record information, various test information, prescription information, medication history information, and vital signs information (e.g., body temperature, blood pressure, heart rate, etc.). It also executes the IP packet analysis program stored in the "main memory" to analyze IP packets sent via a network (especially the Internet). It also executes the destination IP address determination program stored in the "main memory" to determine whether the sent destination IP address is an IP address addressed to its own health and medical information sharing system. If it determines that the IP address is addressed to itself, it stores the IP address in the "main memory" and "non-volatile memory." It also executes the access ID / user ID acquisition program stored in the "main memory" to extract and acquire the access ID indicating the accessing entity and the user ID indicating the user belonging to the accessing entity, which are stored in the IP payload of the sent IP packet, and store them in the "main memory" and "non-volatile memory." In addition, the access subject user attribute acquisition program stored in the "main memory" is executed to acquire access subject information, user information, and user attribute information (here, information indicating whether the user is a medical professional or a non-medical professional; for example, "medical professional" or "non-medical professional") corresponding to the access ID and user ID, and store them in the "main memory" and "non-volatile memory." In addition, the disclosure permission information retention program stored in the "main memory" is executed to acquire disclosure permission information indicating whether or not an individual's health and medical related information will be disclosed to third parties, and store this in the "main memory" and "non-volatile memory." In addition, the access control program stored in the "main memory" is executed to control access to health and medical related information about an individual.
[0108] <Embodiment 5: Unified management system for health and medical information: Processing flow> 6d shows the process flow when the unified health and medical care-related information management system of this embodiment is used. As shown in the figure, the processing method includes a health and medical care-related information accumulation step S601, an IP packet analysis step S602, a destination IP address determination step S603, an access ID / user ID acquisition step S604, an access subject user attribute acquisition step S605, a disclosure permission information retention step S606, and an access control step S607.
[0109] The "health and medical related information accumulation step" S601 is a stage in which health and medical related information about an individual sent from a third-party terminal via a network, such as electronic medical record information, various test information, prescription information, medication history information, and vital sign information (e.g., body temperature, blood pressure, heart rate, etc.), is accumulated.
[0110] The "IP packet analysis step" S602 is a stage in which IP packets sent via a network (particularly the Internet) are analyzed.
[0111] The "destination IP address determination step" S603 is a stage in which the destination IP address is extracted from the IP header of the IP packet and it is determined whether or not it is an IP address addressed to the health and medical care related information unified management system of the device.
[0112] The "Access ID / User ID Acquisition Step" S604 is a step in which, if the destination IP address is an IP address addressed to the user's own centralized management system for health and medical related information, the access ID indicating the accessing entity and the user ID indicating the user belonging to the accessing entity are acquired from the IP payload.
[0113] The "access subject user attribute acquisition step" S605 is a step in which access subject information, user information, and user attribute information (here, information indicating whether the user is a medical professional or a non-medical professional, for example, "medical professional" or "non-medical professional") corresponding to the access ID and user ID are acquired.
[0114] The "step of storing information on whether or not disclosure is permitted" S606 is a step of storing information on whether or not disclosure of personal health and medical care-related information to third parties is permitted.
[0115] The "access control step" S607 is a stage in which access to the unified health and medical information management system is controlled.
[0116] <Summary> As a result, disclosure permission information indicating whether or not health and medical care-related information about an individual (user) is permitted to be disclosed to third parties can be stored. In other words, an individual can select and set whether or not to permit disclosure based on their own will.
[0117] <Embodiment 6 (corresponding mainly to claim 6)> <Outline of Sixth Embodiment>
[0118] 7a is a diagram showing the functional configuration of a health and medical care related information unified management system according to embodiment 6. As shown in this figure, this embodiment is characterized in that, in addition to the components of embodiment 5, a third-party identification information storage unit is provided.
[0119] The functional configuration, hardware configuration, and processing flow of the health and medical care related information unified management system of this embodiment will be described below. From here on, descriptions of the same functions, hardware configuration, and processing flow as those of the fifth embodiment will be omitted as appropriate.
[0120] <Functional Configuration of Sixth Embodiment> 7A is a diagram showing the functional configuration of the health and medical care related information unified management system in this embodiment. In this embodiment, by including a third party identification information storage unit, it is possible to identify whether a third party is a medical professional or a non-medical professional.
[0121] <Embodiment 6: Unified management system for health and medical information: Functional configuration> 7A is a diagram showing the functional configuration of the health and medical care related information unified management system of this embodiment. Here, the differences from embodiment 5 will be mainly explained.
[0122] <Configuration of Sixth Embodiment: Third-Party Identification Information Storage Unit of Access Control Unit> The "third-party identification information storage unit" 707 is configured to have the function of storing third-party identification information for identifying whether a third party accessing the healthcare-related information stored in the healthcare-related information storage unit via a network is a healthcare professional or a non-healthcare professional. Here, the third-party identification information may be, for example, information created by combining 12-digit numbers, letters, symbols, etc., and may be information that can uniquely identify a third party. For example, specific information such as My Number information or a health insurance card number may be used. Furthermore, the third-party identification information is preferably associated with the access subject information, user information, and user attribute information ("healthcare professional" or "non-healthcare professional") described above. Furthermore, the third-party identification information may be registered, edited, and deleted by the administrator using the administrator terminal. In addition, by combining the above-mentioned disclosure permission information and third-party identification information, even if the disclosure permission information indicates ``disclosure permitted,'' if the third party is a specific medical professional, it may be possible to set whether access is permitted or not. For example, if the third-party identification information represents a "doctor," access to health and medical related information may be permitted, but if the third-party identification information represents a specific medical professional (e.g., an accountant or bookkeeper), access to health and medical related information may be denied. Furthermore, for example, information indicating the department to which the user belongs may be added to the third-party identification information, and the permission or denial of access to the health and medical care-related information may be controlled based on the information indicating the department. For example, permission or denial of access to the health and medical care-related information may be controlled based on information regarding the user's expertise identified by the third-party identification information (e.g., the specialty and years of experience of "doctor" or "nurse"). For example, the method by which third parties can obtain the health and medical care-related information (e.g., view-only, text conversion, copying, transfer, bulk download of anonymously processed information, etc.) may be changed based on a combination of disclosure permission information and the department and expertise related to the third-party identification information. If downloading is permitted, it is preferable to utilize digital watermarking technology or NFT (Non-Fungible Token) technology to prevent data tampering. For example, the permission or denial of access to the patient may be granted to a third party based on a combination of disclosure permission information and the department and expertise related to the third-party identification information. For example, it is expected that a medical professional who performs PCR testing will send the results of the PCR test to a third-party terminal used by a doctor, as well as to a third-party terminal used by the patient himself / herself. It is conceivable that the administrator mentioned above can use the administrator terminal to register these combinations of information in advance in a table format or the like in the access control unit mentioned above, so that they can be edited or deleted as appropriate and as needed. Furthermore, for example, examples of medical professionals include doctors, dentists, and pharmacists, and the third-party identification information for these may include, at least in part, the medical registry registration number (e.g., a six-digit number) listed on their medical license, the dentist registry registration number (e.g., a six-digit number) listed on their dentist license, or the pharmacist registry registration number (e.g., a six-digit number) listed on their pharmacist license. Similarly, for other medical professionals, the third-party identification information may include, at least in part, the number listed on their license. Furthermore, the third-party identification information may include at least the symbols and numbers (including branch numbers) printed on the health insurance card of the health insurance association to which the user belongs, the driver's license number, the My Number information printed on the My Number card, etc. Note that the user may be identified using third-party authentication by a platform such as Google (registered trademark) or Facebook (registered trademark).
[0123] <Embodiment 6: Unified Management System for Healthcare-Related Information: Hardware Configuration> Figure 7b is a diagram showing the hardware configuration of the unified health and medical information management system of this embodiment. As shown in this figure, the unified health and medical information management system of this embodiment includes a "CPU (Central Processing Unit)" 721 that performs various types of calculation processing, and a "main memory" 722. It also includes a "non-volatile memory" 723 that stores predetermined information, and a "network I / F" 724 that transmits and receives information to and from a third-party terminal 726 and an administrator terminal 727. These components are interconnected by a data communication path such as a "bus" 725, and perform information transmission and reception and processing.
[0124] Here, the "main memory" reads out programs that perform various processes to be executed by the "CPU," and also provides a work area for the programs. Furthermore, multiple addresses are assigned to the "main memory" and "non-volatile memory," and programs executed by the "CPU" can exchange data and perform processing by identifying and accessing these addresses. In this embodiment, the program stored in the "main memory" is a third-party identification information retention program in addition to the program in embodiment 5.
[0125] In addition to the information in the fifth embodiment, third-party identification information and the like are stored in the "main memory" and "non-volatile memory."
[0126] The "CPU" executes the third-party identification information retention program stored in the "main memory" and stores in the "main memory" and "non-volatile memory" third-party identification information for identifying whether a third party who has accessed the health and medical care-related information stored in the health and medical care-related information storage unit via the network is a medical professional or a non-medical professional.
[0127] <Embodiment 6: Unified management system for health and medical information: Processing flow> 7c is a diagram showing the flow of processing when the unified health and medical care related information management system of this embodiment is used. Here, the differences from embodiment 5 will be mainly explained. As shown in the figure, this is a processing method including a third-party identification information holding step S707.
[0128] The "third party identification information retention step" S707 is a step of retaining third party identification information to identify whether a third party who has accessed the health and medical care related information stored in the health and medical care related information storage unit via the network is a medical professional or a non-medical professional.
[0129] <Summary> From the above, it is possible to identify whether the third party is a medical professional or a non-medical professional.
[0130] <Embodiment 7 (mainly corresponding to claim 7)> <Outline of Embodiment 7>
[0131] 8a is a diagram showing the functional configuration of a health and medical care related information unified management system in embodiment 7. Hereafter, descriptions of functions, hardware configurations, and processing flows similar to those in embodiments 5 and 6 will be omitted as appropriate.
[0132] The functional configuration, hardware configuration, and processing flow of the health and medical care related information unified management system according to this embodiment will be described below.
[0133] <Seventh embodiment: Functional configuration> 7A is a diagram showing the functional configuration of the health and medical care-related information unified management system in this embodiment. With this configuration, when the disclosure permission information held in the disclosure permission information holding unit indicates that disclosure is permitted and the third-party identification information indicates that the person is a medical professional, the health and medical care-related information stored in the health and medical care-related information storage unit can be viewed.
[0134] <Embodiment 7: Unified management system for health and medical information: Functional configuration> FIG. 7a is a diagram showing the functional configuration of the health and medical care related information unified management system according to this embodiment.
[0135] <Seventh embodiment: Configuration description: Disclosure permission information storage unit of access control unit> The "disclosure permission information storage unit" 806 is configured to have a function for storing disclosure permission information indicating whether or not to disclose one's own health and medical-related information to a third party accessing the health and medical-related information via the network. Specifically, it is desirable to configure the system so that information indicating "disclosure permission" or "disclosure denial" can be set at the individual's discretion via network 205 from third-party terminal 206, as shown in FIG. 2b, to access control unit 202 of centralized health and medical-related information management system 200. For example, the disclosure permission information may be binary information (flag information) in which "disclosure permission" is "1" and "disclosure denial" is "0." The disclosure permission information may also be configured to determine whether or not to disclose a specific block of health and medical-related information. For example, it is conceivable that health and medical-related information related to internal medicine among medical departments is set to "disclosure permission," while health and medical-related information related to psychiatry is set to "disclosure denial." Furthermore, the disclosure permission information may be configured to distinguish between "disclosure permission" and "disclosure denial" when the third party is a specific medical professional, in combination with the third-party identification information described above. For example, if the third-party identification information represents a "doctor," the individual's health and medical related information may be "approved for disclosure," whereas if the third-party identification information represents a specific medical professional (e.g., an accountant or bookkeeper), the individual's health and medical related information may be "denied disclosure."
[0136] <Seventh embodiment: Configuration description: Third-party identification information storage unit of access control unit> The "third-party identification information storage unit" 807 is configured to have the function of storing third-party identification information for identifying whether a third party accessing the health and medical care-related information stored in the health and medical care-related information storage unit via a network is a medical professional or a non-medical professional. Here, the third-party identification information may be, for example, information made up of a combination of 12 digits of numbers, letters, symbols, etc., that can uniquely identify a third party. For example, specific information such as My Number information or health insurance card number may be used. Furthermore, it is preferable that the third-party identification information is associated with the above-mentioned access subject information, user information, and user attribute information ("healthcare worker" or "non-healthcare worker"). Furthermore, the above-mentioned administrator may be able to register, edit, and delete the third-party identification information using the administrator terminal. In addition, by combining the above-mentioned disclosure permission information and third-party identification information, even if the disclosure permission information indicates ``disclosure permitted,'' if the third party is a specific medical professional, it may be possible to set whether access is permitted or not. For example, if the third-party identification information represents a "doctor," access to health and medical related information may be permitted, but if the third-party identification information represents a specific medical professional (e.g., an accountant or bookkeeper), access to health and medical related information may be denied. Furthermore, for example, information indicating the department to which the user belongs may be added to the third-party identification information, and the permission or denial of access to the health and medical care-related information may be controlled based on the information indicating the department. For example, permission or denial of access to the health and medical care-related information may be controlled based on information regarding the user's expertise identified by the third-party identification information (e.g., the specialty and years of experience of "doctor" or "nurse"). For example, the method by which third parties can obtain the health and medical care-related information (e.g., view-only, text conversion, copying, transfer, bulk download of anonymously processed information, etc.) may be changed based on a combination of disclosure permission information and the department and expertise related to the third-party identification information. If downloading is permitted, it is preferable to utilize digital watermarking technology or NFT (Non-Fungible Token) technology to prevent data tampering. For example, the permission or denial of access to the patient may be granted to a third party based on a combination of disclosure permission information and the department and expertise related to the third-party identification information. For example, it is expected that a medical professional who performs PCR testing will send the results of the PCR test to a third-party terminal used by a doctor, as well as to a third-party terminal used by the patient himself / herself. It is conceivable that the administrator mentioned above can use the administrator terminal to register these combinations of information in advance in a table format or the like in the access control unit mentioned above, so that they can be edited or deleted as appropriate and as needed. Furthermore, for example, examples of medical professionals include doctors, dentists, and pharmacists, and the third-party identification information for these may include, at least in part, the medical registry registration number (e.g., a six-digit number) listed on their medical license, the dentist registry registration number (e.g., a six-digit number) listed on their dentist license, or the pharmacist registry registration number (e.g., a six-digit number) listed on their pharmacist license. Similarly, for other medical professionals, the third-party identification information may include, at least in part, the number listed on their license. Furthermore, the third-party identification information may include at least the symbols and numbers (including branch numbers) printed on the health insurance card of the health insurance association to which the user belongs, the driver's license number, the My Number information printed on the My Number card, etc. Note that the user may be identified using third-party authentication by a platform such as Google (registered trademark) or Facebook (registered trademark).
[0137] <Embodiment 7: Description of Configuration: Access Control Means of Access Control Unit> The “access control means” 705 is configured to have a function for controlling access when a third party accesses the health and medical care related information storage unit via a network, and to enable viewing of the health and medical care related information stored in the health and medical care related information storage unit when the disclosure permission information held in the disclosure permission information holding unit indicates that disclosure is permitted and the third party identification information indicates that the third party is a medical professional.
[0138] Seventh Embodiment: Unified Management System for Healthcare-Related Information: Hardware Configuration Figure 7b is a diagram showing the hardware configuration of the unified health and medical information management system of this embodiment. As shown in this figure, the unified health and medical information management system of this embodiment includes a "CPU (Central Processing Unit)" 721 that performs various types of calculation processing, and a "main memory" 722. It also includes a "non-volatile memory" 723 that stores predetermined information, and a "network I / F" 724 that transmits and receives information to and from a third-party terminal 726 and an administrator terminal 727. These components are interconnected by a data communication path such as a "bus" 725, and perform information transmission and reception and processing.
[0139] Here, the "main memory" reads out programs that perform various processes to be executed by the "CPU," and also provides a work area for the programs. Furthermore, multiple addresses are assigned to the "main memory" and "non-volatile memory," and programs executed by the "CPU" can exchange data and perform processing by identifying and accessing these addresses. In this embodiment, the programs stored in the "main memory" are a disclosure permission information storage program, a third-party identification information storage program, and an access control program.
[0140] Furthermore, the "main memory" and "non-volatile memory" store disclosure permission information, third-party identification information, and the like.
[0141] The "CPU" executes a disclosure permission information retention program stored in the "main memory" to store in the "main memory" and "non-volatile memory" disclosure permission information indicating whether or not to disclose one's own health and medical related information to a third party who accesses the health and medical related information about an individual via a network. The "CPU" also executes a third-party identification information retention program stored in the "main memory" to store in the "main memory" and "non-volatile memory" third-party identification information for identifying whether a third party who accesses the health and medical related information stored in the health and medical related information storage unit via a network is a medical professional or a non-medical professional. The "CPU" then executes an access control program stored in the "main memory" to enable viewing of the health and medical related information stored in the health and medical related information storage unit if the disclosure permission information indicates disclosure permission and the third-party identification information indicates a medical professional.
[0142] <Embodiment 7: Unified management system for health and medical information: Processing flow> FIG. 7c is a diagram showing the flow of processing when the health and medical care related information unified management system according to this embodiment is used. As shown in the figure, this processing method comprises a disclosure permission information holding step S706, a third party identification information holding step S707, and an access control step S708.
[0143] The "step of retaining disclosure permission information" S706 is a step of retaining disclosure permission information indicating whether or not one's own health and medical care related information is to be made public to a third party who has accessed the health and medical care related information of an individual via a network.
[0144] The "third party identification information retention step" S707 is a step of retaining third party identification information to identify whether a third party who has accessed the health and medical care related information stored in the health and medical care related information storage unit via the network is a medical professional or a non-medical professional.
[0145] The “access control step” S708 is a step in which, if the disclosure permission information held in the disclosure permission information holding unit indicates that disclosure is permitted and the third-party identification information indicates that the person is a medical professional, the health and medical care-related information stored in the health and medical care-related information storage unit is made viewable.
[0146] <Summary> From the above, if the disclosure permission information stored in the disclosure permission information storage unit indicates that disclosure is permitted and the third-party identification information indicates that the person is a medical professional, the health and medical care-related information stored in the health and medical care-related information storage unit can be viewed.
[0147] <Embodiment 8 (mainly corresponding to claim 8)> <Outline of Embodiment 8>
[0148] This embodiment is characterized in that it stores anonymization method information in addition to the features of embodiments 5 and 6. Hereinafter, descriptions of the same functions, hardware configurations, and processing flows as those of embodiments 5 and 6 will be omitted as appropriate.
[0149] The functional configuration, hardware configuration, and processing flow of the health and medical care related information unified management system of this embodiment will be described below, focusing on the differences from the fifth and sixth embodiments.
[0150] <Functional Configuration of Embodiment 8> 9A is a diagram showing the functional configuration of the unified health and medical information management system of this embodiment, which includes an anonymization method information storage unit in addition to the components of embodiments 5 and 6.
[0151] <Embodiment 8: Unified management system for health and medical information: Functional configuration> 8A is a diagram showing the functional configuration of the health and medical care related information unified management system of this embodiment. Here, the differences from embodiments 5 and 6 will be mainly explained.
[0152] <Embodiment 8: Configuration: Anonymization Method Information Storage Unit of Access Control Unit> The "anonymization method information storage unit" 908 is configured to have a function of storing information indicating the anonymization method. Here, the anonymization method information may be, for example, information created by combining six-digit numbers, letters, symbols, etc., and may be information that can uniquely identify the anonymization method. Note that the anonymization method information may be registered, edited, and deleted by the administrator using the administrator terminal.
[0153] There are several methods for anonymization, and these are often used alone or in combination. The main anonymization methods are briefly explained below. "k-anonymization" (where k is a natural number greater than or equal to 2) refers to the process of creating a data set that contains k or more attributes (such as gender, age, place of residence, occupation, etc.) that cannot be used alone to identify an individual, but that can be used in combination to identify an individual with a high degree of probability, regardless of the combination of attribute values. "Pseudonymization" means replacing information with other descriptions, etc., using a method that does not have any regularity that allows deletion or restoration. "Generalization" means replacing the value of an attribute with a higher value or concept, such as dividing the age into 10 years or making cucumber a higher concept vegetable. "Top (bottom) coding" refers to grouping numerical attributes into particularly large or small attribute values. For example, people over 100 years old can be labeled as "over 100 years old." "Noise (error) addition" means adding random noise that follows a certain distribution to a numerical attribute. "Swapping (data exchange)" refers to (probabilistically) exchanging attribute values between records for categorical attributes. It is also called data swap. "Sampling" means randomly extracting a certain percentage or number of data from the entire original data. "Grouping" refers to replacing detailed items in attributes or history with certain groups or divisions.
[0154] <Embodiment 8: Configuration: Access Control Means of Access Control Unit> The "access control means" 905 is configured to have a function for controlling access when a third party accesses the healthcare and medical care related information storage unit via a network, and to enable viewing of part (including all) of the healthcare and medical care related information stored in the healthcare and medical care related information storage unit, or healthcare and medical care related information that has been anonymized using a predetermined anonymization method, when the disclosure permission information held in the disclosure permission information holding unit indicates that disclosure is permitted and the third party identification information indicates that the third party is a non-healthcare professional.
[0155] <Embodiment 8: Unified Management System for Healthcare-Related Information: Hardware Configuration> Figure 9b is a diagram showing the hardware configuration of the unified health and medical information management system of this embodiment. As shown in this figure, the unified health and medical information management system of this embodiment includes a "CPU (Central Processing Unit)" 911 that performs various types of calculation processing, and a "main memory" 912. It also includes a "non-volatile memory" 913 that stores predetermined information, and a "network I / F" 914 that transmits and receives information to and from a third-party terminal 916 and an administrator terminal 917. These components are interconnected by a data communication path such as a "bus" 915, and perform information transmission, reception, and processing.
[0156] Here, the "main memory" reads out programs that perform various processes to be executed by the "CPU," and also provides a work area for the programs. Furthermore, multiple addresses are assigned to the "main memory" and "non-volatile memory," and the programs executed by the "CPU" can exchange data and perform processing by identifying and accessing these addresses. In this embodiment, the program stored in the "main memory" is an anonymization method information retention program in addition to the programs in embodiments 5 and 6.
[0157] In addition to the fifth and sixth embodiments, the "main memory" and "non-volatile memory" also store anonymization method information and the like.
[0158] The "CPU" executes the anonymization method information retention program stored in the "main memory" to store anonymization method information indicating the anonymization method in the "main memory" and the "non-volatile memory." Then, it executes the access control program stored in the "main memory," and when the disclosure permission information indicates that disclosure is permitted and the third-party identification information indicates that the person is a non-healthcare professional, it makes it possible to view part (including all) of the health care-related information stored in the health care-related information storage unit, or health care-related information that has been anonymized using a predetermined anonymization method.
[0159] <Embodiment 8: Unified management system for health and medical information: Processing flow> 8c is a diagram showing the flow of processing when the health and medical care related information unified management system of this embodiment is used. The following mainly describes the differences from the fifth and sixth embodiments. As shown in the figure, this processing method comprises an anonymization method information storage step S908 and an access control step S909.
[0160] The "anonymization method information storage step" S908 is a stage in which anonymization method information, which is information indicating a method for anonymizing health and medical care related information, is stored.
[0161] The "access control step" S909 is a step in which, when the disclosure permission information stored in the disclosure permission information storage unit indicates that disclosure is permitted and the third-party identification information indicates that the person is a non-healthcare professional, part (including all) of the health and medical care-related information stored in the health and medical care-related information storage unit, or health and medical care-related information that has been anonymized using a predetermined anonymization method, is made available for viewing.
[0162] <Explanation of an example of anonymization method> 10a to 10c are diagrams showing an example of an anonymization method, which will be used to briefly explain an example of the anonymization method. The table shown in Figure 10a is a list of patients at a fictitious medical institution in Minato Ward, Tokyo, Japan, who have not yet been anonymized. It contains six attributes (name, age, gender, place of residence, religion, and disease name) and data for 12 individuals. Of these, "name" is information that constitutes personal data and may potentially identify an individual by itself. Furthermore, "age," "gender," "place of residence," "religion," and "disease name" are also pieces of personal data that are not accumulated over time. While they cannot identify an individual by themselves, they may potentially identify an individual by combining them with other attributes or by matching them with external information. In particular, "disease name" is a highly sensitive attribute of personal data. This information corresponds to the individual's health and medical information stored in the health and medical information storage unit described above. In this case, the following process can be performed to achieve k-anonymity for a given value of k (k is a natural number greater than or equal to 2). First, a process called "pseudonymization" is performed, replacing certain values of an attribute with an asterisk "*." All or some of the values in that column are replaced with "*." In the table shown in Figure 10b, all values of "Name" and all values of "Religion" are replaced with "*." Next, a process called "generalization" is performed, replacing individual attribute values with a wider range. For example, for "age," "29 years old" is replaced with "20s," and "35 years old" is replaced with "30s." Also, for "place of residence," which is a value consisting of prefecture and city / ward / town / village, the city / ward / town / village is deleted and replaced with only prefecture. Figure 10b shows the anonymized table, where there are four equivalence classes with the same combination of quasi-identifiers ("age", "gender", and "place of residence"). Figure 10c shows the anonymized table grouped for easy understanding. As can be seen from this table, all groups (Group A to Group D) achieve 3-anonymity in terms of "age," "gender," and "place of residence." This is because any combination of these attributes results in three or more people. In this way, by anonymizing the health care related information about an individual stored in the health care related information storage unit, the risk of an individual being identified can be reduced.
[0163] <Summary> From the above, when the disclosure permission information stored in the disclosure permission information storage unit indicates that disclosure is permitted and the third-party identification information indicates that the person is a non-medical professional, it is possible to make viewable some (including all) of the health and medical care-related information stored in the health and medical care-related information storage unit, or health and medical care-related information that has been anonymized using a predetermined anonymization method. [Explanation of symbols]
[0164] Health and medical information centralized management system: 200 Health and Medical Information Storage Department: 201 Access control section: 202 Incentive Management Department: 203 Incentive Function Department: 204 Network: 205 Third party terminal: 206 Administrator terminal: 207
Claims
1. a health and medical care-related information storage unit for storing and centrally managing health and medical care-related information relating to an individual; an access control unit for controlling disclosure of the health and medical care related information stored in the health and medical care related information storage unit to a third party via a network; an incentive function unit including at least an incentive management unit for providing incentives to individuals in order to encourage centralized management of their health and medical care-related information regarding whether or not to allow the disclosure of said information; and The access control unit a disclosure permission information storage unit that stores disclosure permission information indicating whether an individual permits disclosure of his or her own health and medical care-related information to the third party; a user attribute information acquisition means for acquiring user attribute information of the third party who has accessed the site; an access control means for determining whether the third party is a medical professional or a non-medical professional based on the user attribute information; A centralized management system for health and medical information.
2. 2. The health and medical care related information unified management system according to claim 1, further comprising an access authentication processing unit that performs authentication for accessing the incentive management unit.
3. 3. The health and medical related information unified management system according to claim 2, further comprising a consent information acquisition unit that acquires consent information, which is information indicating consent to accept the incentive from the incentive management unit, after authentication by the access authentication processing unit.
4. 4. The health and medical care related information unified management system according to claim 3, further comprising an incentive processing unit for performing incentive processing, which is processing for providing an incentive when consent information is acquired by the consent information acquisition unit.
5. 2. The centralized health and medical care related information management system of claim 1, wherein the access control unit allows the medical care related information stored in the health and medical care related information storage unit to be viewed by the medical care related information if the disclosure permission information stored in the disclosure permission information storage unit indicates that disclosure is permitted and the determination result by the access control means indicates that the medical care related information is a medical care related information.
6. 2. The centralized health and medical care-related information management system of claim 1, wherein, when the disclosure permission information stored in the disclosure permission information storage unit indicates that disclosure is permitted and the determination result by the access control means indicates that the person is a non-medical worker, the access control unit allows the non-medical worker to view part (including all) of the health and medical care-related information stored in the health and medical care-related information storage unit, or health and medical care-related information that has been anonymized using a predetermined anonymization method.
7. 7. The health and medical care related information unified management system according to claim 6, wherein the anonymization method is at least one of the anonymization methods of k (k is a natural number of 2 or more)-anonymization, pseudonymization, generalization, top (bottom) coding, noise (error) addition, swapping (data exchange), sampling, and grouping, or a combination thereof.
8. 2. The centralized health and medical related information management system of claim 1, wherein the medical professionals include at least one of the following: doctors, dentists, pharmacists, public health nurses, midwives, nurses, licensed practical nurses, physical therapists, occupational therapists, orthoptists, speech-language-hearing therapists, prosthetists, radiological technologists, radiological x-ray technicians, clinical laboratory technicians, sanitary laboratory technicians, clinical engineers, dental hygienists, dental technicians, emergency medical technicians, masseurs and shiatsu therapists, acupuncturists, moxibustion therapists, judo therapists, registered dietitians, nutritionists, mental health workers, social workers, care workers, certified psychologists, clinical psychologists, and medical administrators.
9. 2. The centralized health and medical related information management system of claim 1, wherein the non-medical personnel include at least one of employees belonging to life insurance companies, non-life insurance companies, securities companies, pharmaceutical companies, drug discovery venture companies, food companies, health equipment companies, fitness clubs, sports gyms, banks, credit unions, JA (agricultural cooperatives), union health insurance, Japan Health Insurance Association, mutual aid associations, municipal national health insurance, national health insurance associations, PR companies, general research institutes, universities and graduate schools (including affiliated research institutes), technical colleges, agriculture, forestry and fisheries companies, fertilizer manufacturers, government agencies, local governments, and independent administrative agencies.
10. A method executed by a CPU in a centralized health and medical information management system, comprising: a health and medical care-related information accumulation step for accumulating and centrally managing health and medical care-related information about an individual; an access control step for controlling disclosure of the health and medical care-related information accumulated in the health and medical care-related information accumulation step to a third party via a network; an incentive function step including at least an incentive management step for providing an incentive to the individual regarding whether or not to permit disclosure of the health and medical care-related information of the individual in order to encourage centralized management of the health and medical care-related information; and The access control step includes: a disclosure permission information holding step for holding disclosure permission information indicating whether an individual permits disclosure of his / her own health and medical care-related information to the third party; a user attribute information acquisition substep of acquiring user attribute information of the third party who has accessed the site; an access control substep of determining whether the third party is a medical professional or a non-medical professional based on the user attribute information; A method having the following.
11. A method executed by a CPU in a centralized health and medical information management system, comprising: The method according to claim 10, further comprising an access authentication processing step for performing authentication for accessing said incentive management step.
12. A method executed by a CPU in a centralized health and medical information management system, comprising: The method according to claim 11, further comprising a consent information acquisition step of acquiring consent information, which is information indicating consent to receive the incentive, in the incentive management step after authentication in the access authentication processing step.
13. A method executed by a CPU in a centralized health and medical information management system, comprising: The method according to claim 12, further comprising an incentive processing step of performing incentive processing, which is processing for providing an incentive, when the consent information is acquired in the consent information acquisition step.
14. A method executed by a CPU in a centralized health and medical information management system, comprising:
11. The method according to claim 10, wherein the access control step allows the medical professional to view the health and medical care-related information accumulated in the health and medical care-related information accumulation step if the disclosure permission information stored in the disclosure permission information storage step indicates that disclosure is permitted and the determination result in the access control sub-step indicates that the person is a medical professional.
15. A method executed by a CPU in a centralized health and medical information management system, comprising: The method according to claim 10, wherein, when the disclosure permission information stored in the disclosure permission information storage step indicates that disclosure is permitted and the determination result in the access control sub-step indicates that the person is a non-medical worker, the access control step allows the non-medical worker to view part (including all) of the health and medical care-related information accumulated in the health and medical care-related information accumulation step, or health and medical care-related information that has been anonymized using a predetermined anonymization method.
16. A method executed by a CPU in a centralized health and medical information management system, comprising: The method according to claim 15, wherein the anonymization method is performed by at least one of the following anonymization methods: k (k is a natural number equal to or greater than 2)-anonymization, pseudonymization, generalization, top (bottom) coding, noise (error) addition, swapping (data exchange), sampling, and grouping, or a combination thereof.
17. A method executed by a CPU in a centralized health and medical information management system, comprising: The method of claim 10, wherein the medical professionals include at least one of a physician, dentist, pharmacist, public health nurse, midwife, nurse, licensed practical nurse, physical therapist, occupational therapist, orthoptist, speech-language-hearing therapist, prosthetist, radiological technologist, radiological technician, clinical laboratory technician, medical laboratory technician, clinical engineer, dental hygienist, dental technician, emergency medical technician, masseur, shiatsu therapist, acupuncturist, moxibustion therapist, judo therapist, registered dietitian, nutritionist, mental health worker, social worker, care worker, certified psychologist, clinical psychologist, and medical administrator.
18. A method executed by a CPU in a centralized health and medical information management system, comprising: The method of claim 10, wherein the non-medical personnel include at least one of employees belonging to a life insurance company, a non-life insurance company, a securities company, a pharmaceutical company, a drug discovery venture company, a food company, a health equipment company, a fitness club, a sports gym, a bank, a credit union, a JA (agricultural cooperative), a health insurance association, an insurance association for associations, a mutual aid association, a municipal national health insurance, a national health insurance association, a PR company, a general research institute, a university and a graduate school (including affiliated research institutes), a technical college, an agriculture, forestry and fisheries company, a fertilizer manufacturer, a government agency, a local government, and an independent administrative agency.
19. a health and medical care-related information accumulation step for accumulating and centrally managing health and medical care-related information about an individual; an access control step for controlling disclosure of the health and medical care-related information accumulated in the health and medical care-related information accumulation step to a third party via a network; an incentive function step including at least an incentive management step for providing an incentive to the individual regarding whether or not to permit disclosure of the health and medical care-related information of the individual in order to encourage centralized management of the health and medical care-related information; and The access control step includes: a disclosure permission information holding step for holding disclosure permission information indicating whether an individual permits disclosure of his / her own health and medical care-related information to the third party; a user attribute information acquisition substep of acquiring user attribute information of the third party who has accessed the site; an access control substep of determining whether the third party is a medical professional or a non-medical professional based on the user attribute information; and a program for operating the unified health and medical information management system, the program being written so as to be readable and executable by the unified health and medical information management system, which is a computer having the above-mentioned program.
20. 20. An operating program for a unified health and medical related information management system, written in a readable and executable manner on a computer that is the unified health and medical related information management system of claim 19, further comprising an access authentication processing step for performing authentication for accessing the incentive management step.
21. An operating program for a unified health and medical related information management system that is written in a readable and executable manner in a computer that is the unified health and medical related information management system described in claim 20, further comprising a consent information acquisition step that acquires consent information, which is information indicating agreement to accept the incentive, in the incentive management step after authentication in the access authentication processing step.
22. An operating program for a unified health and medical related information management system written in a readable and executable manner on the computer described in claim 21, which further has an incentive processing step for performing incentive processing, which is a process for providing an incentive, when consent information is acquired in the consent information acquisition step.
23. 20. An operating program for a unified health and medical care related information management system that is a computer according to claim 19, wherein the access control step allows the medical care worker to view the health and medical care related information accumulated in the health and medical care related information accumulation step if the disclosure permission information held in the disclosure permission information holding step indicates that disclosure is permitted and the determination result in the access control sub-step indicates that the person is a medical care worker.
24. 20. An operating program for a unified health and medical care related information management system that is a computer according to claim 19, wherein the access control step allows the non-medical worker to view part (including all) of the health and medical care related information accumulated in the health and medical care related information accumulation step, or the health and medical care related information that has been anonymized using a predetermined anonymization method, if the disclosure permission information held in the disclosure permission information holding step indicates that disclosure is permitted and the determination result in the access control sub-step indicates that the person is a non-medical worker.
25. The anonymization method is at least one of the following anonymization methods: k (k is a natural number of 2 or more): anonymization, pseudonymization, generalization, top (bottom) coding, noise (error) addition, swapping (data exchange), sampling, and grouping, or a combination thereof.
25. An operating program for a unified health and medical care related information management system that is a computer according to claim 24 and that is written in a manner that can be read and executed by the unified health and medical care related information management system.
26. 20. An operating program for a unified health and medical related information management system that is written in a readable and executable manner on a computer that is the unified health and medical related information management system of claim 19, wherein the medical professionals include at least one of the following: physicians, dentists, pharmacists, public health nurses, midwives, nurses, licensed practical nurses, physical therapists, occupational therapists, orthoptists, speech-language-hearing therapists, prosthetists, diagnostic radiologists, diagnostic X-ray technicians, clinical laboratory technicians, public health technicians, clinical engineers, dental hygienists, dental technicians, emergency medical technicians, masseurs and shiatsu therapists, acupuncturists, moxibustion therapists, judo therapists, registered dietitians, nutritionists, mental health workers, social workers, care workers, certified psychologists, clinical psychologists, and medical administrators.
27. 20. An operating program for a unified health and medical related information management system written in a readable and executable manner on a computer that is the unified health and medical related information management system described in claim 19, wherein the non-medical personnel include at least one of employees belonging to life insurance companies, non-life insurance companies, securities companies, pharmaceutical companies, drug discovery venture companies, food companies, health equipment companies, fitness clubs, sports gyms, banks, credit unions, JA (agricultural cooperatives), union health insurance, Japan Health Insurance Association, mutual aid associations, municipal national health insurance, national health insurance associations, PR companies, general research institutes, universities and graduate schools (including affiliated research institutes), technical colleges, agriculture, forestry and fisheries companies, fertilizer manufacturers, government agencies, local governments, and independent administrative agencies.
Citation Information
Patent Citations
Support server, information presentation system and information providing method using the same
JP2002007410A
System and method for medical information sharing
JP2002259573A
Medical information management system, method and program
JP2004287774A
Motivation for Wearable Technology Sensor Data Sharing
JP2018514831A
Medical information management apparatus and medical information sharing system
JP2019012385A