Message systems and mobile programs

The message system and program facilitate secure and reliable message transmission in medical and confidential facilities by using a mobile terminal and facility-installed devices to set message destinations, addressing confidentiality and security issues in existing methods.

JP7777928B2Active Publication Date: 2025-12-01USEN-ALMEX CO LTD
View PDF 5 Cites 0 Cited by

Patent Information

Application Number
JP2021091975
Authority / Receiving Office
JP · JP
Patent Type
Patents
Current Assignee / Owner
Filing Date
2021-05-31
Publication Date
2025-12-01
Estimated Expiration
2041-05-31

AI Technical Summary

Technical Problem

Medical facilities face challenges in securely transmitting messages to patients while maintaining confidentiality, as existing methods like email require storing message content on external servers and are prone to errors in address entry, leading to potential breaches of patient information.

Method used

A message system and program that utilize a mobile terminal, a facility-installed message management device, and a reception device to enable secure message transmission by setting message destinations based on registered user information, without the need for manual email address entry, and include features like public key encryption and confirmation of program status.

Benefits of technology

Ensures secure and reliable message transmission to patients, maintaining confidentiality by avoiding external servers and reducing errors, thus enhancing information security and reliability in medical and other confidential information handling facilities.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 0007777928000001
    Figure 0007777928000001
  • Figure 0007777928000002
    Figure 0007777928000002
  • Figure 0007777928000003
    Figure 0007777928000003
Patent Text Reader

Abstract

To provide a message system and mobile terminal-purpose program that can transmit messages in a facility such as a medical facility and the like.SOLUTION: A reception system is a message system that includes: a mobile terminal-purpose program implementable by a mobile terminal; a message program implementable by a message management device installed in facilities; and reception devices 1a, 1b installed in the facility. The mobile-purpose program is configured to implement function addition processing, setting processing, and message processing. The function addition processing is configured to, by a user's use of the reception device, register facility user relevant information in the mobile terminal. The setting processing is configured to implement setting required for the message processing between the mobile terminal and the message management device corresponding to the facility user relevant information on the basis of the registered facility user relevant information. The message processing is configured to, after the setting processing is completed, receive a message transmitted from the message management device, or transmit the message to the message management device.SELECTED DRAWING: Figure 1
Need to check novelty before this filing date? Find Prior Art

Description

[Technical Field]

[0001] The present invention relates to a message system that enables users to send messages to and from their mobile terminals in various facilities, and a message program that can be executed on the mobile terminals. [Background technology]

[0002] Traditionally, medical treatment at hospitals, clinics, and other medical facilities has typically been conducted in the following order: first consultation, appointment, and follow-up visit. After the first consultation or follow-up visit, patients make a next appointment, ensuring smooth medical treatment.

[0003] However, some patients may forget to go to a medical facility when they return to Japan. In such cases, the medical facility or the patient will need to make another appointment. In addition, there may be empty seats when the patient returns to Japan, which could hinder smooth medical treatment.

[0004] Furthermore, large medical facilities such as general hospitals tend to be crowded due to the large number of outpatients, and there are situations in which outpatients have to wait between reception and seeing the doctor. Taking such situations into consideration, Patent Document 1 discloses a consultation guidance system that includes a return-examination reception terminal that accepts return-examination requests from outpatients, a medical department reception terminal that accepts visits to a medical department from the outpatient after the return-examination is accepted, a mobile terminal carried by the outpatient, and a patient information management server that, if the return-examination request is not accepted at the medical department reception terminal within a predetermined time after the return-examination request is accepted at the return-examination reception terminal, causes the mobile terminal to send a push notification informing the medical department of the visit. [Prior art documents] [Patent documents]

[0005] [Patent Document 1] Japanese Patent Application Laid-Open No. 2017-120470 Summary of the Invention [Problem to be solved by the invention]

[0006] Incidentally, in medical facilities, it is essential to keep information about patients as customers confidential, and careless leaking of such information could cause a loss of credibility for the medical facility. Patent Document 1 discloses sending reception information via push notification, and also discloses sending an email if the patient does not show up at the reception desk after receiving the reception information. Sending an email requires the message content to be stored on an external email server, which is not necessarily desirable from the perspective of information security.

[0007] For these reasons, it is difficult for medical facilities to send messages to their customers (patients, etc.). Furthermore, when using email, email addresses must be registered, but this is usually done by having the patient or other user write it down on paper, so if the email address is entered incorrectly or misread, messages may not be sent or may be sent to the wrong person.

[0008] The present invention has been made in consideration of such circumstances, and aims to enable safe and reliable message transmission to customers such as patients in medical facilities, etc. The present invention can be used not only in medical facilities, but also in various other facilities where customer information must be kept confidential, such as financial institutions such as banks and securities companies. [Means for solving the problem]

[0009] The message system according to the first-first configuration is A message system including a mobile terminal, a message management device installed in a facility, and a reception device installed in the facility, The mobile terminal executes a function addition process, a setting process, and a message process, The function addition process is performed by the user using the reception device. Contains mobile device identification information Register facility user information, The setting process executes settings necessary for message processing between the facility user and the message management device corresponding to the registered facility user related information, based on the registered facility user related information; The message processing allows the device to receive messages sent from the message manager or to send messages to the message manager after the setting process is completed. The setting process is performed to set the destination of a message sent by a message program executed by the message management device. Information about As, Identification information of the mobile terminal, identification information of the facility user, and The relationship of the facility users Message Management Device setting death , In the message processing, when a facility user is selected, the relationship of the facility user set in the setting processing is selected, and the mobile terminal of the relationship of the facility user is set as the destination of the message. R .

[0010] Furthermore, in the message system according to the first-second configuration, The function addition process registers facility user-related information in the mobile terminal by having the reception device read the facility's usage ticket.

[0011] Furthermore, in the message system according to the first to third configurations, The portable program is capable of executing function addition processing, setting processing, and message processing for each facility.

[0012] Furthermore, in the message system according to the first to fourth configurations, The portable program enables function addition processing, setting processing, and message processing to be executed for each facility user.

[0014] Furthermore, in the message system according to the first to sixth configurations, The message program is A confirmation process for confirming the running status of a mobile program on the mobile terminal that is the destination of the transmission; When the portable program is in an activated state, a transmission process is executed to transmit a message that can be notified by the portable program of the portable terminal to the portable terminal.

[0015] In addition, the portable program according to the first to seventh configurations is A portable program executable on a portable terminal, The mobile program causes the mobile terminal to execute a function addition process, a setting process, and a message process, The function addition process is carried out by using a reception device installed in the facility. Contains mobile device identification information Register facility user information, The setting process executes settings necessary for message processing between the facility user and the message management device corresponding to the registered facility user related information, based on the registered facility user related information; The message processing allows the device to receive messages sent from the message manager or to send messages to the message manager after the setting process is completed. The setting process is performed to set the destination of a message sent by a message program executed by the message management device. Information about As, Identification information of the mobile terminal, identification information of the facility user, and The relationship of the facility users Message Management Device setting vinegar R 。 Furthermore, the message management device according to the first to eighth configurations is A message management device used in a message system including a mobile terminal and a message management device installed in a facility, The mobile device is Destination of messages sent by message programs executed on the message management device Information about As, Identification information of the mobile terminal, identification information of the facility user, and Execute a setting process to set the relationship of the facility user in the message management device; The message management device After the setting process is completed, the message manager is enabled to send messages. When a facility user is selected, by selecting the relationship of the facility user set in the setting process, the mobile device of the relationship of the facility user is set as the destination of the message to be sent. R Perform message processing. Furthermore, the message management device according to the first to ninth configurations A message program executed on a message management device used in a message system including a mobile terminal and a message management device installed in a facility, The mobile device is Destination of messages sent by message programs executed on the message management device Information about As, Identification information of the mobile terminal, identification information of the facility user, and Execute a setting process to set the relationship of the facility user in the message management device; The message program is After the setting process is completed, the message manager is enabled to send messages. When a facility user is selected, by selecting the relationship of the facility user set in the setting process, the mobile device of the relationship of the facility user is set as the destination of the message to be sent. R Perform message processing.

[0016] The message system disclosed in this specification has the following configurations 2-1 to 2-8.

[0017] The message system according to the second-first configuration is A message system including a portable program executable on a portable terminal and a message program executable on a message management device installed in a facility, The message program is A confirmation process for confirming the running status of a mobile program on the mobile terminal that is the destination of the transmission; When the portable program is in an activated state, a transmission process is executed to transmit a message that can be notified by the portable program of the portable terminal to the portable terminal.

[0018] Furthermore, in the message system according to the second-second configuration, If the portable program is not running, a notification process is performed to send a notification to the portable terminal to prompt the portable program to start up.

[0019] Furthermore, in the message system according to the second-third configuration, The message program executes a public key acquisition process to acquire the public key of the portable program; In the sending process, when a message is sent, encryption is performed based on the acquired public key.

[0020] Furthermore, in the message system according to the second to fourth configuration, In the public key acquisition process, a public key is acquired from a message server that manages public keys for portable programs.

[0021] Furthermore, in the message system according to the second to fifth configuration, The public key acquisition process is executed when message acquisition settings are made in the portable program.

[0022] Furthermore, in the message system according to the second to sixth configuration, The recipient of the message can be set by a combination of name and relationship.

[0023] Furthermore, in the message system according to the second to sixth configuration, It is possible to set whether or not a message can be sent for each recipient.

[0024] In addition, the message program related to the configuration 2-7 is A message program executed on a message management device installed in a facility, A confirmation process for confirming the running status of a mobile program on the mobile terminal that is the destination of the transmission; When the portable program is in an activated state, a transmission process can be executed to transmit a message that can be notified by the portable program of the portable terminal to the portable terminal.

[0025] The message system disclosed in this specification has the following configurations 3-1 to 3-3.

[0026] The message system according to the third-first configuration is A message system including a portable program executable on a portable terminal and a message program executable on a message management device, The portable program is assigned subscriber information including user identification information and a relationship to the user; The message program allows a user to select a user's identification information and a relationship to the user, thereby sending a message to a portable program to which the corresponding subscriber information has been assigned.

[0027] Furthermore, in the message system according to the third-second configuration, The message program registers the subscriber information sent from the portable program, and allows the user to select user identification information and the relationship to the user from the registered subscriber information.

[0028] Furthermore, in the message system according to the third-third configuration, The portable program stores information on a plurality of subscribers. [Effects of the Invention]

[0029] According to the message system and mobile program of the first configuration (configurations 1-1 to 1-6), by performing a function addition process and a setting process, it becomes possible to easily send messages between a mobile terminal and a message management device without the need to transmit an email address by handwriting, etc. Furthermore, since a reception device installed in the facility is used, it is possible to set up messages safely.

[0030] Furthermore, according to the message system, message management device, and message program relating to the second configuration (configurations 2-1 to 2-8), the running status of the portable program is checked, and if the portable program is running, a message that can be notified by the portable program on the mobile terminal is sent to the mobile terminal. Therefore, it is possible to send (or receive) messages directly between the mobile terminal and the message management device, thereby making it possible to increase the confidentiality of personal information handled within the facility.

[0031] Furthermore, according to the message system of the third configuration (configurations 3-1 to 3-3), by registering the user's identification information (user ID or at least one of the user's name) and the user's relationship to the user (self, spouse, parent, child, etc.) as subscriber information in the mobile terminal, the message program can send messages specifying the user's identification information and relationship to the user. In particular, in medical facilities, it is possible to send messages specifying the user (patient) and their relationship to the user. Therefore, it is possible to send messages for the same patient based on their relationship to the patient, such as messages to be conveyed to the patient and their relatives, messages to be conveyed only to the patient, or messages to be conveyed only to their relatives. [Brief explanation of the drawings]

[0032] [Figure 1] FIG. 1 is a diagram showing the configuration of a reception system according to an embodiment of the present invention; [Figure 2] FIG. 10 is a front view of the reception device according to the present embodiment. [Figure 3] FIG. 1 is a block diagram showing the configuration of a reception device according to the present embodiment. [Figure 4] FIG. 1 is a block diagram showing the configuration of a mobile terminal according to an embodiment of the present invention; [Figure 5] FIG. 10 is a diagram showing an initial screen of the reception device according to the embodiment; [Figure 6] FIG. 10 is a diagram showing an outpatient screen of the reception device according to the present embodiment. [Figure 7] FIG. 10 is a flowchart showing check-in processing according to the present embodiment. [Figure 8]FIG. 10 is a diagram showing a check-in confirmation screen according to the embodiment; [Figure 9] FIG. 10 is a diagram showing various data configurations used in the reception system according to the present embodiment. [Figure 10] FIG. 10 is a flowchart showing a function acceptance process according to the present embodiment; [Figure 11] 10A to 10C are diagrams showing various screens of a mobile terminal according to the present embodiment; [Figure 12] 10A to 10C are diagrams showing various screens of a mobile terminal according to the present embodiment; [Figure 13] FIG. 1 is a block diagram showing the configuration of a message system according to an embodiment of the present invention. [Figure 14] 10A to 10C are diagrams showing various screens of a mobile terminal according to the present embodiment; [Figure 15] FIG. 10 is a flowchart showing initial registration processing of a mobile terminal according to the present embodiment; [Figure 16] FIG. 10 is a flowchart showing a handshake process according to the present embodiment. [Figure 17] FIG. 10 is a diagram showing various data configurations used in the message system according to the present embodiment. [Figure 18] FIG. 10 is a flowchart showing a transmission process (when a program for a mobile terminal is started) according to the present embodiment. [Figure 19] FIG. 10 is a flowchart showing a transmission process according to the present embodiment (when the mobile terminal program is not running). [Figure 20] FIG. 10 is a diagram showing a message client screen according to the present embodiment; [Figure 21] FIG. 10 is a diagram showing a message client screen according to the present embodiment; [Figure 22] 10A to 10C are diagrams showing various screens of a mobile terminal according to the present embodiment; DETAILED DESCRIPTION OF THE INVENTION

[0033] 1 is a diagram showing the configuration of a reception system according to this embodiment. The reception system according to this embodiment is installed in a lobby located near an entrance / exit 72 of a medical facility. The reception system comprises reception devices 1a and 1b that are placed in the lobby and operated by users, and a management computer 3 that is placed in the hospital reception 71 or the like and operated by an employee. Note that multiple reception devices 1a and 1b (two in this embodiment) are installed so that services can be provided to multiple users simultaneously.

[0034] The reception devices 1a and 1b and the management computer 3 are connected to each other so that they can communicate with each other via a LAN 51. The management computer 3 is connected to a monitor 42 for displaying various information, and input devices 41 such as a keyboard and a mouse for receiving input from employees. Also connected are a receipt printer 44 for printing on receipt-type paper, and a card reader 43 for reading (or potentially writing) information stored on a patient registration card.

[0035] 2 is a front view of the reception device 1 according to this embodiment. The reception device 1 is a device that can provide various services to a user who sits face-to-face and operates it, such as new patient reception and returning patient reception (also called check-in). The reception device 1 of this embodiment is configured with a touch panel monitor 12, a card reader 14, a scanner 15a, a two-dimensional barcode reader 15b, a receipt printer 16a, a printer 16b, a camera 13a, and an infrared camera 13b. These components function as a user interface for a user who operates the reception device 1.

[0036] Touch panel monitor 12 displays visual information to a face-to-face user who operates the device, and is capable of receiving touch operations from the user. Camera 13a and infrared camera 13b are provided above touch panel monitor 12, and are capable of capturing an image of an area including the face of the face-to-face user who operates the device. Camera 13a is provided for capturing an image of the face of the user who uses the device, and infrared camera 13b is provided for capturing an image of the face of the user who uses the device and for performing a temperature measurement process to detect the user's body temperature.

[0037] Card reader 14 reads various information, such as patient ID, stored on a magnetic card or IC card (corresponding to a facility use ticket) held by the user. The card reader may also have a function for reading credit cards used for paying medical expenses. Scanner 15a is a flatbed type provided for reading health insurance cards, and is used to read the health insurance card held by the user when presentation of the health insurance card is required, such as at the time of a return visit or the first consultation of the month.

[0038] The two-dimensional barcode reader 15b is capable of reading various two-dimensional barcodes, such as two-dimensional barcodes printed on printed materials or two-dimensional barcodes displayed on the mobile terminal 2. Note that the object to be read may be a one-dimensional barcode or other form of reading various code information, instead of a two-dimensional barcode, and in that case, a code reader (code reading device) suitable for the object to be read is used instead of the two-dimensional barcode reader 15b. Also, instead of providing both the scanner 15a and the two-dimensional barcode reader 15b, a common reading unit, such as a camera, may be used.

[0039] The reception device 1 of this embodiment is equipped with a receipt printer 16a and a printer 16b to provide paper media to users. The receipt printer 16a is a simple printer that prints on thermal paper used as receipts, and is used to print reception completion lists issued when receiving repeat visitors, or reservation lists issued when receiving reservations, etc. The printer 16b is a laser printer, inkjet printer, or other printer that prints on regular paper using toner or ink, medical care It is used to print medical details, receipts, etc. issued at the time of payment.

[0040] 3 is a block diagram showing the configuration of the reception device 1 according to this embodiment. Similar to a typical computer, the reception device 1 is configured with a CPU 11a as a control unit, a ROM 11b, a RAM 11c, an image processing unit 11d, and an audio processing unit 11e. It also has a storage unit such as a hard disk 18 for storing various types of information. Furthermore, a card reader 14, a scanner 15a, a two-dimensional barcode reader 15b, a receipt printer 16a, a printer 16b, a camera 13a, an infrared camera 13b, and a LAN communication unit 17 are connected via an interface 19, and can be controlled by the control unit.

[0041] The image processing unit 11d is connected to a touch panel monitor 12. The touch panel monitor 12 is configured to include a display unit 122 that displays various information to the user, and a touch panel 121 that accepts touch operations by the user. The touch panel 121 is connected to an interface 19, and is capable of transmitting touch operations by the user to the control unit. The audio processing unit 11e is connected to a speaker that transmits auditory information to the user.

[0042] The interface 19 is connected to the camera 13a, infrared camera 13b, card reader 14, receipt printer 16a, printer 16b, scanner 15a, two-dimensional barcode reader 15b, and touch panel 121 described in Figure 2, and performs various processes under the control of the control unit. In addition, a LAN communication unit 17 is connected to the interface 19 as a means for performing various communications. The LAN communication unit 17 is connected to a LAN 51, and can communicate with various information processing devices on the LAN, such as the management computer 3 described in Figure 1, or with the Internet via a router 52.

[0043] As described above, various services can be provided to users by using the reception system described with reference to Figures 1 and 2. Here, the configuration of the mobile terminal 2 possessed by the user will be described. The mobile terminal 2 is a smartphone, a tablet terminal, or the like, and is a terminal that is owned, carried, and used by the user.

[0044] 4 is a block diagram showing the configuration of a mobile terminal 2 according to this embodiment. The mobile terminal 2 is configured to include a CPU 21a as a control unit, a ROM 21b, a RAM 21c, an image processing unit 21d, and an audio processing unit 21e. The mobile terminal 2 also has a non-volatile storage unit 22 such as a flash memory. In addition, various communication means such as a mobile line communication unit 26a, a wireless LAN communication unit 26b, and a Bluetooth communication unit 26c (short-range wireless communication unit) are connected via an interface 23, as well as an input switch 27, which can be controlled by the control unit.

[0045] A touch panel monitor 25 and a camera 24 are connected to the image processing unit 21d. The touch panel monitor 25 is configured to include a display unit 252 that displays various information to the user, and a touch panel 251 that accepts touch operations by the user. The camera 24 is arranged on the back surface of the mobile terminal 2, etc., and is capable of taking still images and videos. Note that multiple cameras 24 may be arranged, for example, on the front surface as well as the back surface. A speaker 28a that conveys auditory information to the user and a microphone 28b that acquires acoustic information are connected to the audio processing unit 21e. Note that the touch panel monitor 25 and input switches function as a mobile terminal-side user interface for the user operating the mobile terminal 2.

[0046] FIG. 5 is a diagram showing an initial screen displayed on the touch panel monitor 12 of the reception device 1 according to this embodiment. The initial screen displays buttons 121a to 121c that ask the user whether they are an outpatient, an inpatient, or a visitor, a button 121d for adding functions to the smartphone (mobile terminal 2), and a button 121e for switching to a language other than Japanese. When the user selects one of buttons 121a to 121e, the corresponding process is executed. Note that these various services may be disabled depending on the time of day. For example, it is preferable that only button 121a, which handles various receptions for outpatients, be selectable immediately after the medical facility opens. The reception device 1 executes processes other than reception of returning patients, making it possible to prevent the queue of users waiting at the reception device 1 from being filled up.

[0047] The following describes the functions used for outpatients on the initial screen in Fig. 5, i.e., the functions when button 121a displayed in Fig. 5 is selected. When button 121a for selecting outpatient is pressed on the initial screen, the screen transitions to the outpatient screen shown in Fig. 6. On this outpatient screen, buttons 122a to 122d labeled "New Patient Reception," "Returning Patient Reception," "Medical Fee Payment," and "Reservation Request" are displayed, as well as button 122e for returning to the initial screen.

[0048] Here, the various services displayed on each of the buttons 122a to 122d will be explained. When button 122a (new patient reception) is touched and selected, the new patient reception process for a new patient, that is, a patient visiting this medical facility for the first time, begins. In the new patient reception process, the scanner 15a of the reception device 1 is used to read an identification card such as a My Number card or a driver's license, and an insurance card. A message is displayed on the touch panel monitor 12 informing the user to wait until registration is complete, and the new patient reception process on the reception device 1 side is completed. The read information is sent to the management computer 3, and after processing by a clerical staff member or the like, is registered as basic patient information in the medical facility's database.

[0049] The process that starts by touching and selecting button 122c (revisit reception) is a process (check-in process) for accepting medical treatment when a patient visits a medical facility for the second or subsequent time. The revisit reception process of this embodiment is targeted at users who have made a medical appointment in advance, such as at a previous visit, but it may also be possible to accept users who have not made an appointment. For this reason, the revisit reception process will be called the check-in process.

[0050] The process that starts when button 122b (medical fee payment) is selected by touching is a process for making payment of medical fees for a user whose medical treatment has ended. The reception device 1 of this embodiment allows payment by credit card using the card reader 14, but may also be provided with a cash handling function to allow payment by cash. The process that starts when button 122d (request appointment) is selected is a process for reserving the next medical date and time.

[0051] The process that starts by selecting button 121d (adding a function to a smartphone) on the initial screen described in FIG. 5 is a process of adding a function to a portable program (also called an "app") that runs on the portable terminal 2 owned by the user. The user downloads the portable program to be used at medical institutions to the portable terminal 2 via an Internet connection and uses it. As a basic function, this portable program can obtain basic information such as the locations of various medical institutions, or use waiting numbers to notify the user of the current progress of medical treatment at each medical institution.

[0052] Furthermore, various additional functions can be added to the mobile terminal 2, such as the repeat visit reception (check-in process), medical fee payment, and reservation request executed by the reception device 1, as described in FIG. 5. Such additional functions require identification of the user (patient, etc.) using the mobile terminal 2, and important information such as the patient ID must be handled by the mobile terminal 2. Therefore, incorporating such additional functions as basic functions of the program is not desirable from the perspective of ensuring security. Furthermore, adding functions only to the mobile terminal 2 is not desirable from the perspective of security. There is also the possibility of unauthorized use by exploiting security flaws. Therefore, in this embodiment, when adding functions to a portable program executed by the mobile terminal 2, the reception device 1 is used.

[0053] Fig. 7 is a flow diagram showing check-in processing according to this embodiment. The check-in processing is executed by the reception device 1, and is performed when the user faces the reception device 1 and operates the touch panel monitor 12 or the like. The check-in processing is started by operating the button 122c (return visit reception) on the outpatient screen of Fig. 6. Note that the normal check-in processing at the reception device 1 is started when the reception start time set by the medical facility arrives, or by an operational instruction given by a medical facility employee or the like.

[0054] When the check-in process begins, a guide screen is displayed on the touch panel monitor 12, prompting the user to insert their patient ID card or to hold the two-dimensional barcode displayed by the patient ID card function of the portable terminal 2 over the two-dimensional barcode reader 15b (S100). The patient ID card function of the portable terminal 2 will be described in detail later. When the user inserts the patient ID card into the card reader 14 (S101: Yes), the card reader 14 reads the patient ID stored on the patient ID card (S102). When the two-dimensional barcode displayed on the portable terminal 2 is read by the two-dimensional barcode reader 15b (S101: Yes), the reception device 1 reads the patient ID from the two-dimensional barcode. The reception device 1 sends a check-in request including the read patient ID to the management computer 3 (S103).

[0055] Fig. 9 shows various data configurations used in the reception system according to this embodiment. Basic patient information registered in advance, such as at the time of the first consultation, is recorded in the management computer 3. As shown in Fig. 9(A), the basic patient information includes information about the patient as a user, such as the patient ID, facility ID, name, address, sex, date of birth, personal identification information, and health insurance card information.

[0056] In this embodiment, a patient ID and a medical facility ID are combined and used as a system ID. The reception system of this embodiment is premised on being usable at multiple medical facilities. Therefore, by referencing the system ID, which is a combination of a patient ID and a medical facility ID, it is possible to identify the medical facility and the patient.

[0057] Personal identification information is various information that can identify an individual, such as the number written on a driver's license or My Number card presented by a patient at the time of initial consultation, or a copy image of such a card. Health insurance card information includes the health insurance card type, health insurance card number, expiration date, etc. If a My Number card can be used as a health insurance card, personal identification information and health insurance card information can be integrated with information related to the My Number card.

[0058] Reservation information regarding medical appointments is also registered in the management computer 3. As shown in Figure 9(B), the reservation information is composed of a patient ID, reservation date, reservation time slot, medical department ID, and doctor ID. In this embodiment, the reservation format is one in which the reservation date and reservation time slot are specified, but the reservation format is not limited to this format. Various formats can be adopted, such as specifying only the reservation date, or specifying the reservation date and reservation time, and the information in the reservation information will be changed as appropriate depending on the reservation format of the medical facility.

[0059] When the management computer 3 receives the check-in request, it references the patient ID included in the check-in request and searches for the corresponding reservation information. If there is no reservation information corresponding to the patient ID, or if the reservation date of the reservation information corresponding to the patient ID is not for the current day, it sends error information to the reception device 1. If error information is received (S104: Yes), the reception device 1 displays a check-in error screen on the touch panel monitor 12 notifying that there is no reservation and the request could not be accepted (S114).

[0060] On the other hand, if the management computer 3 finds reservation information that corresponds to the patient ID and has a reservation date of the current day, the management computer 3 sends reservation confirmation information to the reception device 1. The reservation confirmation information includes various information based on the reservation information, such as the patient name, reservation date, reservation time slot, name of the medical department, and name of the doctor. When the reception device 1 receives the reservation confirmation information (S105: Yes), it displays a check-in confirmation screen based on the received reservation confirmation information (S108). In this embodiment, the infrared camera 13b is used to take the user's temperature before displaying the check-in confirmation screen.

[0061] As described in FIG. 2, the reception device 1 is provided with an infrared camera 13b capable of capturing an image of an area including the user. Temperature is measured using this infrared camera 13b (S106). In this embodiment, the body temperature near the temples of a person, which allows for accurate temperature measurement, is used. Furthermore, to improve the accuracy of the temperature measurement result, the body temperature near the temples is corrected based on the temperature distribution of a wide area of ​​the face and used as the temperature measurement result. Furthermore, camera 13a may also be used to accurately detect the temple position. If the temperature measurement result is abnormal (S107: No), that is, if the person is thought to have a high fever due to influenza or other infections, a fever warning screen is displayed on the touch panel monitor 12 (S112), and fever warning information is sent to the management computer 3 (S113).

[0062] The fever warning screen displays a message indicating that the user has a fever and is being asked to move to an isolation space or similar location. Furthermore, upon receiving the fever warning information, the management computer 3 notifies employees that a patient with an abnormal fever has been detected, along with the identification information of the reception device 1. By taking measures at check-in, such as isolating a user with influenza when accepting a returning patient, it is possible to prevent hospital infections and other issues. The reception device 1 may be provided with a notification means for sending notifications around the reception device 1 in addition to the fever warning screen. For example, a notification light may be provided on the top of the reception device 1, and the light may be turned on to notify employees waiting around the reception device 1, or a notification means such as an audio notification may be provided. Furthermore, the temperature measurement using the infrared camera 13b is not limited to the timing described in this embodiment, but may also be performed at an appropriate timing during the normal check-in process.

[0063] Furthermore, if the temperature measurement result is abnormal (S107: No), the use of the reception device 1 may be temporarily suspended. The suspension of use of the reception device 1 continues until the medical facility administrator completes disinfection. A message such as "Please wait until cleaning is completed" is displayed on the touch panel monitor 12, preventing the next user from using the reception device. If the medical facility administrator receives a notification from the management computer 3 or the status of the notification light indicates that cleaning of the reception device 1 is necessary, the administrator thoroughly cleans the touch panel monitor 12 of the reception device 1 and then resumes suspension of the reception device 1. The reception device 1 can be resumed by performing a predetermined operation on the reception device 1 or by remotely canceling the operation from the management computer 3. In this way, even if a user suspected of infection is using the reception device, the spread of infection can be prevented by temporarily suspending use.

[0064] On the other hand, if the temperature measurement result is normal (S107: Yes), the reception device 1 displays a check-in confirmation screen on the touch panel monitor 12 based on the received appointment confirmation information (S108). FIG. 8 is a diagram showing the check-in confirmation screen according to this embodiment. The check-in confirmation screen displays a consultation content display field 123a including the medical department, doctor's name, and appointment time slot, a cancel button 123b, and a confirm button 123c. As can be seen from the check-in confirmation screen displayed in FIG. 7, in this embodiment, it is possible to visit multiple departments in a single visit. In this case, the check-in confirmation screen is displayed based on the corresponding multiple appointment information (S108). If there are no problems with the consultation content, the user operates the confirm button 123c to confirm the consultation content for that day (S109: Yes). On the other hand, if the user wants to cancel the consultation content, the user can select the item (such as the department) to be canceled and operate the cancel button 123b to cancel the appointment corresponding to the item.

[0065] If the confirmation button 123c is touched (S109: Yes), the reception device 1 sends confirmation instruction information to the management computer 3 (S110). Based on the reception of the confirmation instruction information, the management computer 3 adds the corresponding appointment information to the medical treatment queue as consultation information. A medical treatment queue is provided for each doctor in the corresponding medical department, and medical treatment is basically carried out in the order of this medical treatment queue. In addition, the reception device 1 uses the receipt printer 15 to print out a reception completion slip for the user (S111).

[0066] The reception completion slip is printed with the department, doctor's name, and reservation time slot included in the reservation information, a waiting number corresponding to the order of reception, and a two-dimensional barcode. When a patient visits multiple departments as in this embodiment, a waiting number may be issued for each department. Here, the two-dimensional barcode printed on the reception completion slip is information for confirmation by an information processing device (not shown) located in the medical department at the time of examination. The information processing device located in the medical department is connected to the management computer 3 via LAN 51 for communication, and the two-dimensional barcode read by the information processing device can be used to verify the patient's identity.

[0067] The above has described the check-in process executed by the reception device 1. Next, we will explain the function addition process using the reception device 1. The function addition process is a process for adding various functions, such as a patient registration card function and a message function, to the mobile terminal 2 carried by the user. In this embodiment, these additional functions are not performed by operating the mobile terminal 2 alone, but are performed in cooperation with the reception device 1 installed in the medical facility, thereby improving the security of various information.

[0068] FIG. 10 is a flow diagram showing the function addition process according to this embodiment. This process is started by selecting button 121d labeled "Add Function to Smartphone" in FIG. 5 on reception device 1. When the process starts, a screen prompting the user to insert their patient ID card is displayed on touch panel monitor 12. When the user inserts the patient ID card into card reader 14 (S201: Yes), card reader 14 reads the patient ID stored on the patient ID card (S202). Furthermore, reception device 1 starts taking images using camera 13a (S203). Note that camera 13a continues to take images (video or multiple still images), and later, the best shot suitable for identifying the patient is selected from the images taken.

[0069] The reception device 1 transmits the read patient ID to the management computer 3 and acquires the basic patient information corresponding to the patient ID from the management computer 3 (S204). Note that the acquired basic patient information does not necessarily have to be all of the information contained therein, but may be only a necessary portion of the information. Thereafter, a function addition confirmation screen including a two-dimensional barcode to be read by the mobile terminal 2 is displayed on the touch panel monitor 12 (S205). This two-dimensional barcode includes information for identifying the patient (corresponding to the "facility user related information" according to the present invention). Note that the patient ID in the two-dimensional barcode is preferably encrypted.

[0070] The user uses the launched mobile program (app) to have the camera 24 of the mobile terminal 2 read the 2D barcode displayed on the touch panel monitor 12 (this corresponds to a function addition process on the mobile terminal 2 side). Figure 9 (C1) shows one form of the data configuration contained in the 2D barcode, which includes the patient ID, medical facility ID (system ID), name, date of birth, and device ID for identifying the reception device 1 being used. The 2D barcode read by the camera 24 is decrypted and converted into information by the mobile terminal 2. Of the read information, the patient ID, medical facility ID, name, date of birth, and other information necessary for using the mobile terminal 2 as a patient registration card are stored (registered) in the mobile terminal 2 as patient registration card information.

[0071] 11 and 12 are diagrams showing various screens of the mobile terminal 2 according to this embodiment. FIG. 11(A) is an initial screen displayed on the touch panel monitor 25 of the mobile terminal 2. The initial screen displays the currently selected medical facility name 251a as well as various buttons 251b to 251j. Button 251b is a button for using the mobile terminal 2 as a patient registration card (patient registration card function), and by completing the function addition process described in FIG. 10, the mobile terminal 2 can be used as a patient registration card that can be accepted by the reception device 1. The mobile terminal 2 can display a two-dimensional barcode as a patient registration card on its touch panel monitor 25 for check-in.

[0072] Button 251c is a button for paying medical expenses, and after treatment, the user can operate this button 251c to select payment by credit card, payment at a convenience store, etc. Therefore, by using this function, it is possible to pay medical expenses without having to stop by the reception device 1 or the reception desk.

[0073] Button 251d is a button that allows a hospitalized user to send information for issuing a visiting pass to relatives, friends, acquaintances, etc. by email. Using this function, a hospitalized user can send emails to relatives, friends, acquaintances, and other people who are permitted to visit. The email contains information for issuing a visiting pass, such as a two-dimensional barcode or a web address for obtaining the two-dimensional barcode, and a visiting permission number. The visitor can receive a visiting pass that allows the visit by having the reception device 1 read this information or by entering it.

[0074] Button 251e is a button for switching the target medical facility. The program of this embodiment can be used at multiple medical facilities. By operating button 251e, available medical facilities are displayed, and the target medical facility can be selected. After selection, the medical facility name 251a is changed to the selected one.

[0075] Button 251f is a function that can be executed after the function addition process is performed, and is a message function for receiving messages from medical facilities and sending messages to medical facilities. This message function is a function for safely sending and receiving messages to medical facilities, and will be described in detail later.

[0076] Button 251g is a function that can be executed after the function addition process has been performed, and it is possible to make an appointment for the next consultation date and time at the selected medical facility. Note that in the initial screen of FIG. 11(A), buttons indicated by dashed lines are functions that are not used at the selected medical facility. This takes into consideration the different specifications of each medical facility. In this embodiment, the reservation request using button 251g cannot be used.

[0077] Button 251h is a button for referring to instructions on how to use the mobile program (application). Button 251j is a button for switching to a language other than Japanese.

[0078] Next, the screen transitions when button 251b used for the function addition process is operated will be explained. When using the mobile terminal 2 in place of a patient registration card, it is necessary to execute the function addition process with the reception device 1 and register information such as a patient ID in the mobile terminal 2. When button 251b is operated, if no information has yet been registered in the mobile terminal 2, the terms of use in FIG. 11(B) will be displayed first. Although only "Terms of Use" is displayed in FIG. 11(B), the details of the terms of use will actually be displayed here. Also displayed are button 252a indicating "Agree" and button 252b indicating "Do not agree." A user who agrees to the displayed terms of use operates button 252a to proceed to the screen in FIG. 11(C).

[0079] FIG. 11(C) shows a screen in a state where the patient registration card has not yet been registered. The user operates button 253 labeled "Register Patient Card" to proceed to the screen of FIG. 12(D). FIG. 12(D) is a screen that prompts operation on the reception device 1 side. This screen also displays button 254 labeled "Read 2D Barcode." Operating this button 254 transitions to the reading screen of FIG. 12(E). The reading screen displays a monitor field 256a that displays the image being captured by camera 24, and a cancel button 256. While checking the image in monitor field 256a, the user captures the function addition confirmation screen that is displayed in the processing of S205 during the function addition processing executed by reception device 1.

[0080] The mobile terminal 2, which has read the two-dimensional barcode displayed on the reception device 1, uses the mobile line communication unit 26a to transmit registration request information to a management server (not shown) on the Internet. FIG. 9(D) is a diagram showing the data configuration of the registration request information. The registration request information includes the patient ID, medical facility ID, and terminal ID associated with the mobile terminal 2. The terminal ID may be an ID unique to the mobile terminal 2 or an ID unique to the mobile program (app). The management server receives the registration request information from the mobile terminal 2 via the mobile line network and the Internet, and transmits it to the management computer 3 of the reception system that uses the reception device 1 having the device ID. The management computer notifies the reception device 1 of the device ID included in the registration request information that it has received the registration request information.

[0081] When the reception device 1 confirms that the management computer 3 has received the registration request information (S206: Yes), the reception device 1 selects the best shot that properly captures the user's face from the video or multiple still images continuously taken by the camera 13a, records it as shooting information (S207), sends it to the management computer 3 (S208), and ends the function addition process.

[0082] Upon receiving the imaging information, the management computer 3 registers the mobile device registration information based on the previously received registration request information and imaging information. Figure 9(E) shows the data structure of the mobile device registration information. The mobile device registration information includes a patient ID, a medical facility ID, a terminal ID of the mobile device 2, a device ID of the reception device 1, a registration date and time indicating the date and time of registration, and imaging information captured by the camera 13a. The mobile device registration information is used to identify whether the mobile device 2 is valid, using the terminal ID included therein. If a problem occurs after adding a function, the mobile device registration information can be referenced and used as a history of when and who registered the function.

[0083] On the other hand, if the reception device 1 cannot receive the terminal ID of the portable terminal 2 (S206: No), the function addition process ends after a certain timeout period has elapsed (S209: Yes). In this case, the photographic information captured by the camera 13a is discarded (S210).

[0084] As described above, in this embodiment, when adding a function such as a patient registration card function to the mobile terminal 2, the user is required to perform a function addition process by operating face-to-face at the reception device 1. This makes it possible to prevent various problems such as security and fraudulent use when using the mobile terminal 2. In particular, the mobile terminal 2 stores information that requires accuracy and confidentiality, such as a patient ID and a system ID, and by providing this information from the reception system to the mobile terminal 2 as in this embodiment, it is possible to ensure accuracy and confidentiality.

[0085] FIG. 12(F) shows the screen of the mobile terminal 2 when the function addition process is complete. This screen is transitioned to by operating button 251b shown in FIG. 11(A). In this embodiment, it is possible to register patient card information for multiple people, including not only the user himself / herself but also the user's relatives or the care recipients of the user (nursing provider). In the example of FIG. 12(F), two patient card display areas 255a and 255b are displayed, and patient cards for two people are registered. The user can move the patient card display area 255a or 255b to the foreground and use it by touching the patient card display area 255a or 255b to be used. In the example of FIG. 12(F), the patient card display area 255a is displayed in the foreground and is ready for use.

[0086] The patient appointment card display area 255a displays a button 255c labeled "Message Settings," a button 255d labeled "Delete," and a two-dimensional barcode 255e. Operating button 255c configures settings related to the message function, which will be described later. Operating button 255d makes it possible to delete the selected patient appointment card display area 255a and the information corresponding to it. The two-dimensional barcode 255e is a two-dimensional barcode version of the patient appointment card information registered in the mobile terminal 2. In this embodiment, the two-dimensional barcode 255e can also be used as a patient appointment card by having the reception device 1 read it.

[0087] In this embodiment, various information is transmitted and received by displaying a two-dimensional barcode on the reception device 1 and reading it with the mobile terminal 2, but instead of this, a two-dimensional barcode including a terminal ID may be displayed on the mobile terminal 2 and read by the two-dimensional barcode reader 15b on the reception device 1. In this case, various information required for adding functions (at least a patient ID, a medical facility ID, etc. required to identify the user) will be transmitted from the reception system to the mobile terminal 2 identified by the terminal ID using a mobile line network.

[0088] Alternatively, the two-dimensional barcode may not include the information shown in Fig. 9(C1), but may instead include the device ID of the reception device 1 or the like as shown in Fig. 9(C2) as authentication information. The mobile terminal 2 that receives the two-dimensional barcode transmits the mobile terminal authentication information to the reception system via a mobile network or the Internet, and receives information necessary for adding functions from the reception system (at least the patient ID, medical facility ID, etc. required to identify the user). This type of configuration eliminates the need to display confidential information in a two-dimensional barcode, making it possible to prevent information leakage caused by photographing or copying the two-dimensional barcode.

[0089] Next, the message function of this embodiment will be described. Figure 13 is a block diagram showing the configuration of the message system of this embodiment. The message system of this embodiment is configured with management computers 3a and 3b (corresponding to the "message management device" of the present invention) installed in each medical facility, and a message server 62. In addition, the external configuration of the message system includes a mobile terminal 2a (first OS), a mobile terminal 2b (second OS), a first notification server 61a (for the first OS), and a second notification server 61b (for the second OS).

[0090] Management computers 3a and 3b (corresponding to the "message management device" according to the present invention) are installed in each medical facility and perform various processes such as creating, sending, and receiving messages. In addition to the management computers 3a and 3b, information processing devices capable of performing various processes related to messages may also be installed in the medical facility. These information processing devices are connected to the network within the medical facility and, like the management computers 3a and 3b, are capable of checking messages received from the mobile terminals 2a and 2b or sending messages to the mobile terminals 2a and 2b.

[0091] The management computers 3a and 3b are connected to the Internet via routers 52a and 52b, and are also connected for communication with a message server 62 using a VPN (Virtual Private Network).

[0092] As described above, users such as patients own the mobile terminals 2a and 2b and can use various functions using portable programs on the mobile terminals 2a and 2b. In this embodiment, it is assumed that the mobile terminals 2a and 2b have two types of operating systems (OS), and a first notification server 61a (for the first OS) and a second notification server 61b (for the second OS) corresponding to each OS of the mobile terminals 2a and 2b are provided. These first notification server 61a (for the first OS) and second notification server 61b (for the second OS) are managed by the management company of the corresponding OS, and can check various statuses of the mobile terminals 2a and 2b on which the corresponding OS is installed, or can send notifications to the mobile terminals 2a and 2b.

[0093] The message server 62 is a server provided on the Internet to implement the message function according to this embodiment. In this embodiment, secure message transmission and reception is implemented between the management computers 3a, 3b and the mobile terminals 2a, 2b. The message server 62 according to this embodiment has the function of connecting the mobile terminal 2 (or the management computer 3) that is the message sender with the management computer 3 (or the mobile terminal 2) that is the message destination, and does not store or preserve the message to be sent. In other words, it functions as a tunnel between the mobile terminal 2 and the management computer 3.

[0094] Conventionally, when sending an email using a mobile terminal 2, an address is provided to the recipient and the email is sent to that address. When a medical facility wants to send an email message to the mobile terminals 2a and 2b, it can be thought of as asking the email address of a user such as a patient in advance and then sending the email to the asked email address.

[0095] Here, the following problems can be considered with conventional email transmission. E-mail addresses are obtained from users such as patients by having them write them down on paper, but it is possible that the written email address is incorrect or misread, making it impossible to obtain the email address accurately. Even if the email address is obtained, there is a problem that important messages cannot be sent.

[0096] Furthermore, conventional email transmission is performed via a mail server installed on the Internet. The mail server temporarily stores the email to be sent before sending it, and the email is sent via multiple mail servers. Therefore, information handled by medical facilities is exposed on the Internet, which raises security concerns.

[0097] Although there is a desire in medical facilities to easily convey messages to patients, etc., it has been difficult to send messages by email due to the above circumstances. This embodiment takes these circumstances into consideration and aims to realize a highly secure messaging function by reliably identifying the recipients of messages, such as patients.

[0098] The message function of this embodiment makes it possible to send and receive messages between the management computers 3a and 3b in the medical facility and the user's portable terminal 2. This message function requires, as a prerequisite, that a function addition process has been performed between the user's portable terminal 2 and the reception device 1, and that the patient card of the medical facility has been registered in the portable terminal 2.

[0099] 12(F), a patient appointment card is registered on a mobile terminal 2 that has completed the function addition process using a reception device 1 installed in a medical facility. A button 255c labeled "Message Settings" is provided in the patient appointment card display area 255a, and operating this button 255c sets a message for the patient appointment card.

[0100] Figure 14(G) shows the screen that appears when button 255c displayed in patient card display area 255a in Figure 12(F) is operated, and displays message setting field 256c. This message setting field 256c displays the name of the medical facility (hospital name), patient name, and patient ID for the selected patient card. The user checks this message setting field 256c, and if they wish to use the message function, they operate button 256e labeled "Receive." If they do not wish to use the message function, they can return to the previous screen by operating button 256d.

[0101] When button 256e is operated, relationship setting field 257a in FIG. 14(H) is displayed. Here, it is conceivable that the user of portable terminal 2 is not the patient himself / herself. For example, it is conceivable that the user of portable terminal 2 is a relative, guardian, or caregiver of the patient. In this embodiment, as described above, even a user other than the patient corresponding to the patient's medical card can register the medical card in place of or in addition to the patient.

[0102] For this reason, when setting up the message function, it is possible to register the relationship indicating who is in relation to the patient. The registered relationship can be referenced by the management computers 3a and 3b in the medical facility that send and receive messages, making it possible to confirm who the message is about. In addition, since it is conceivable that a patient may have multiple guardians and caregivers, it is also possible to set up the message function for multiple mobile terminals 2 for a given patient.

[0103] In the relationship setting field 257a of this embodiment, it is possible to set the patient, spouse, parent, child, relative, friend, or provider (such as a care provider), and relationship selection buttons 257b corresponding to each of these are provided. Note that when button 257c is operated, the screen returns to the previous screen. When any relationship is selected with the relationship selection button 257b, a confirmation field 258a shown in FIG. 14(I) is displayed. This confirmation field 258a displays the medical facility name (hospital name), patient name, patient ID, and the relationship selected with the relationship selection button 257b ("Person" in the case of FIG. 14(I)).

[0104] After checking the settings of the message function in the confirmation field 258a, the user operates the button 258c labeled "OK" to complete the settings of the message function. Note that if the button 258b is operated, the screen will return to the previous screen.

[0105] In this manner, in this embodiment, it is possible to set messages for each patient card registered in the mobile terminal 2 in the function addition process. When the message function is set in the mobile terminal 2, various processes for setting the message function are executed between the mobile terminal 2, the message server 62, and the management computer 3. Figures 15 and 16 are flow diagrams showing the processes for setting these message functions (corresponding to the "setting process" according to the present invention), and Figure 17 is a diagram showing various data configurations used in the message system according to this embodiment. Here, the process between the mobile terminal 2a and the management computer 3a installed in medical facility A will be described.

[0106] 15 is a flow diagram showing the initial registration process for a mobile terminal according to this embodiment. Here, the description will be given taking a mobile terminal 2a using a first OS as an example. The mobile terminal 2a uses a corresponding first notification server 61a. In the case of a mobile terminal 2b using a second OS, the corresponding second notification server 61b is used.

[0107] When a portable program (app) is installed in the portable terminal 2a and the portable program is launched for the first time (S301), the portable terminal 2a notifies the first notification server 61a that the app is being launched for the first time. The first notification server 61a assigns an app ID to the portable terminal 2a, stores it, and notifies the portable terminal 2a (S302). The portable terminal 2a stores the received app ID in its mobile-side setting information.

[0108] Next, the mobile terminal 2a transmits an initial registration request to the message server 62. At that time, the application ID assigned by the first notification server 61a is transmitted to the message server 62. The message server 62 generates information required for setting up the mobile terminal 2a (S303). The information required for setting up includes an M_JID, an M password, an M public key, and an M private key. Of these, the M_JID, the M password, the M public key, and the received application ID are registered as server-side mobile information (S303). The M_JID is identification information for the mobile terminal 2a, and is also used as a destination. The M password is a password required for logging in to the message server 62. The M public key is key information used when performing encryption on the mobile terminal 2a.

[0109] The message server 62 transmits the M_JID, M password, and M public key, among the information required for the generated settings, to the mobile terminal 2a that made the initial registration request. The mobile terminal 2a registers the received information in the mobile-side setting information (S305). The mobile-side setting information includes the M_JID, M password, M private key, and application ID.

[0110] Next, the mobile terminal 2a logs in to the message server 62 using the M_JID and M password. After confirming the login, the message server 62 officially registers the server-side mobile information of the mobile terminal 2a (S306). Then, it notifies the mobile terminal 2a that the login was successful. Upon receiving the notification of the login success, the mobile terminal 2a officially registers the mobile-side setting information (S307).

[0111] By executing the above initial registration process, the mobile terminal 2a becomes able to use the message function using the message server 62. Next, a handshake process for setting up the message function with each medical facility will be described.

[0112] FIG. 16 is a flow diagram showing the handshake process performed between the mobile terminal 2a and the management computer 3a installed in the medical facility selected by adding the message function. By executing this handshake process, information about the mobile terminal 2a is registered in the management computer 3a, public keys are exchanged between the two, and message transmission and reception becomes possible. Here, the management computer 3a executes a setting process with the message server 62 and stores facility-side setting information. The facility-side setting information includes a medical facility ID, H_JID, H password, and H private key. The H_JID is identification information for the management computer 3a installed in the medical facility and is also used as the destination. The H private key is the private key of the management computer 3a and is used to decrypt information encrypted with the H public key.

[0113] The handshake process is executed when button 258c is operated in confirmation field 258a described in Figure 14(I). In the handshake process, mobile terminal 2a logs in to message server 62 (S351), and based on the selected patient card, mobile terminal 2a sends a patient card setting request to message server 62 (S352). The setting request includes a medical facility ID indicating the medical facility for the selected patient card. Message server 62 pre-stores server-side setting information for the medical facility.

[0114] The server-side setting information includes a medical facility ID, an H_JID, and an H public key. The medical facility ID is identification information that can identify a medical facility. The H_JID is identification information for the management computer 3a installed in the medical facility, and is also used as the destination. The H public key is the public key of the management computer 3a.

[0115] Upon receiving the setting request from the mobile terminal 2a, the message server 62 sends the H_JID and H public key (S353) to the mobile terminal 2a. The mobile terminal 2a registers the H_JID and H public key as patient card related information. The patient card related information includes the medical facility ID, H_JID, H public key, and subscriber information. The subscriber information is information related to the patient card, and includes the patient ID, patient name, and relationship selected in Figure 14 (H).

[0116] The mobile terminal 2a sends a setting request to the management computer 3a. The setting request is sent via the message server 62. The message server 62 connects the M_JID of the mobile terminal 2a, which is the sender, with the H_JID of the management computer 3a, which is the destination, enabling direct communication between the two. The setting request includes the M_JID of the mobile terminal 2a, and upon receiving the setting request, the management computer 3a requests the M public key from the message server 62 (S355). The message server 352 references the server-side mobile information and sends the M public key corresponding to the M_JID to the management computer 3a (S356).

[0117] The management computer 3a registers the received M_JID in the facility's mobile information (S357). The facility's mobile information includes the M_JID and M public key. The management computer 3a sends a subscription notification to the mobile terminal 2a. Upon receiving the subscription notification, the mobile terminal 2a sends subscriber information to the management computer 3a. By registering the received subscriber information in the facility's mobile information (S358), the management computer 3a becomes able to create and send messages by referencing the recipient's patient ID, patient name, and relationship, or to refer to the patient ID, patient name, and relationship of a received message.

[0118] Completion of the handshake process between the mobile terminal 2a and the management computer 3a enables message transmission between the two. The handshake process allows messages to be exchanged without specifying the destination M_JID and H_JID, which prevents messages from being interrupted or sent incorrectly due to incorrect email addresses, as was the case with conventional email. Furthermore, there is no need to exchange email addresses by hand, making setup easy.

[0119] The message server 62 also manages the public keys of the mobile terminal 2 and the management computer 3. The mobile terminal 2a and the management computer 3a also receive each other's public keys (H public key, M public key) from the message server 62. In other words, the message server 62 functions as a key bank. The mobile terminal 2 and the management computer 3 communicate directly, but this direct communication is all encrypted, ensuring sufficient security.

[0120] 18 and 19 are flow diagrams showing the transmission process according to this embodiment. In this embodiment, it is possible to send messages between the mobile terminal 2a and the management computer 3a, just like conventional email. In this case, the message server 62 simply functions as a tunnel connecting the sender and the destination, and in effect, it is a direct communication between the mobile terminal 2a and the management computer 3a, thereby improving security. Note that the mobile terminal 2a and the management computer 3a are logged in to the message server 62.

[0121] Here, in the transmission process for transmitting a message from the management computer 3a to the mobile terminal 2a, the running state of a mobile program (application) on the mobile terminal 2a is checked before transmitting the message. Fig. 18 is a flow diagram showing the transmission process (when the mobile terminal program is running) according to this embodiment, and Fig. 19 is a flow diagram showing the transmission process (when the mobile terminal program is not running) according to this embodiment.

[0122] First, the management computer 3a creates a message (S401). Figure 20 is a diagram showing a message client screen according to this embodiment. The message client (corresponding to the "message program" according to the present invention) is a program executed by the management computer 3a for sending and receiving messages.

[0123] The message client screen is provided with a search field 421a, a search result display button 421b, a new message creation button 421c, a send message selection button 421d, a destination list 421e, a text view field 421f, and a data view field 421g.

[0124] In the search field 421a, it is possible to input the patient ID and patient name to which a message is to be sent. The search results are displayed using the search result display button 421b. The operator of the management computer 3 selects the patient to whom the message is to be sent from the search results. In the example of Figure 20, the selected patient ID and patient name fields are displayed with diagonal lines ("Patent Taro" is selected). A message for the selected patient can be created by operating the new message creation button 421c.

[0125] When the new message creation button 421c is operated, a new message creation field 421h is displayed as shown in Fig. 21. The new message creation field 421h is provided with a title input field 421i, a patient ID, a patient name, a recipient relationship selection button 421j, a text input field 421k, an attachment data input field 421m, and a send button 421n.

[0126] The recipient relationship selection button 421j displays the relationship of the mobile terminal 2 registered in the handshake process to the selected patient. In the example of FIG. 21, three mobile terminals 2 are registered for the patient "Patent Taro": "Patent," "Spouse," and "Child." The user uses this recipient relationship selection button 421j to set one or more relationships. Then, the user enters a desired message in the title input field 421i and text input field 421k, and, if necessary, registers a file as attached data, and operates the send button 421n to start transmission.

[0127] In this embodiment, three mobile terminals 2 are registered for each patient: the patient's "self," "spouse," and "child." Depending on the content of the message to be sent about the same patient, it is possible to select the recipients by relationship, such as addressing all of the patient, "self," "spouse," and "child," or only the patient, "spouse," or only the "spouse" and "child," making it easy to manage message sending in medical facilities.

[0128] As shown in FIG. 20, on the message client screen, messages that have already been sent are displayed as a sent message selection button 421d. This sent message selection button 421d displays the creation date and time of the message and its title. Furthermore, by selecting the sent message selection button 421d, a list of recipients 421e of the message and a text view field 421f showing the content of the message are displayed. The example in FIG. 20 shows that a message with the title "Next medical examination notice" has been sent to the relationships "Self" and "Spouse." Of these, the status for "Self" is "Delivered," indicating that delivery has been made to the active mobile device 2. Furthermore, the status for "Spouse" is "Not delivered (5 attempts)," indicating that the mobile device 2 is not active and that the notification described in FIG. 19 has been made five times.

[0129] Furthermore, if any attached data has been added to a message that has already been sent, the data view field 421g displays the file name, data content, etc. Attached data sent from a medical facility may include a referral letter, a medical certificate, medical examination results, health check results, etc. However, since the message function of this embodiment has improved security, it is also possible to send such confidential documents.

[0130] When message creation is completed (S401) and the send button is pressed, the management computer 3a does not immediately send the message, but first makes a confirmation request to the message server 62 (S402). The confirmation request is a request to confirm whether a portable program (app) is running on the portable terminal 2a, which is the destination of the message. The following two patterns are considered for the launch of a portable program (app) on the portable terminal 2a (similarly for 2b). The patterns differ depending on the OS used. In the first pattern, the portable program (app) is in the running state not only when the screen of the portable program (app) is displayed on the portable terminal 2a, but also when it is running in the background. In the second pattern, the portable program (app) is in the running state only when the screen of the portable program (app) is displayed on the portable terminal 2a. These running states can be confirmed by the first notification server 61a and the second notification server 61b of the corresponding OS.

[0131] In this embodiment, it is assumed that two types of OS are used in the mobile terminal 2, and therefore the message server 62 determines the OS of the mobile terminals 2a, 2b to be the transmission target based on a confirmation request from the management computer 3a (S404). This determination can be made based on the application ID in the mobile-side setting information of the management computer 3a. In the examples of FIGS. 18 and 19, the message server 62 determines that the mobile terminal 2a to be the transmission target is running the first OS, and therefore sends a confirmation request to the first notification server 61a for the first OS (S404).

[0132] The first notification server 61a that has received the confirmation request checks whether the portable program (application) is running on the portable terminal 2a (S405). In the example of Fig. 18, the portable program (application) is running (S406), so the first notification server 61a checks whether the portable program (application) is running (S407) and notifies the message server 62 of the running status (S408). The message server 62 that has received the running status transmits the running status to the management computer 3a that made the confirmation request (S409).

[0133] The management computer 3a, having confirmed the activation status of the mobile terminal 2a to be the destination (S410), sends a message to the mobile terminal 2a (S411). At this time, the message can be sent safely by encrypting it using the M public key of the mobile terminal 2a. The message is sent via the message server 62, but the message server 62 simply connects the H_JID of the management computer 3a as the source and the M_JID of the mobile terminal 2a as the destination, and does not store or preserve the message; it functions as a tunnel, so to speak. In effect, direct communication is possible between the management computer 3a and the mobile terminal 2a.

[0134] The mobile terminal 2a that has received the message decrypts the message using the M private key and displays the message (S413). Figure 22(J) is a diagram showing a message display screen on which the message received by the mobile terminal 2a is displayed. The message display screen displays a message display field 259b. The message display field 259b displays the name of the medical facility (hospital name) to which the message is to be sent, the patient's name, the patient ID, the relationship to the patient, the message body, a reply button 259c, and a close button 259d.

[0135] The user can check the message from the medical facility based on the message display field 259b. Also, by operating the reply button 259c, the user can send a reply to the management computer 3a installed in the sending medical facility. In this embodiment, when sending a message from the management computer 3a to the mobile terminal 2a, it was necessary to check the application activation status on the mobile terminal 2a, but since the message client on the management computer 3a is basically always activated, the activation status is not checked.

[0136] The above is the transmission process when the portable program (app) is in an activated state in the portable terminal 2a. Next, a case where the portable program (app) is in an inactivated state in the portable terminal 2a will be described. Fig. 19 shows a case where the portable program (app) is in an inactivated state (S451) in the portable terminal 2a. The process is the same as Fig. 18 up to the application activation check (S405) in the first notification server 61a.

[0137] 19, since the portable program (application) is in a non-running state (S451), the first notification server 61a confirms that the portable program (application) is in a non-running state (S452) and notifies the message server 62 of the non-running state (S453). The message server 62, which has received the non-running state, transmits the non-running state to the management computer 3a (S454). When the management computer 3a confirms that the portable program (application) is in a non-running state on the destination mobile terminal 2a (S455), it does not send the message, but waits for a predetermined time to elapse (S456: Yes), and then executes the confirmation request again (S403).

[0138] Meanwhile, the message server 62 transmits a notification to the mobile terminal 2a (S457). This notification transmission (S457) is a process performed at the OS level of the mobile terminal 2a, and is executed via the first notification server 61a. In this embodiment, a notification is sent to prompt the user to start a mobile program (app) based on the reception of the message. The mobile terminal 2a displays the received message (S457). In this embodiment, the message server 62 can identify the management computer 3a (facility) by referring to the logged-in H_JID, and can therefore notify the user of which facility the message is from.

[0139] FIG. 22(K) is a diagram showing the home screen of the mobile terminal 2a, showing a situation in which a notification is being made. The home screen displays icons for various applications. The mobile program (application) used in this embodiment is also displayed as a patient registration card application 259a. A notification display field 259e is displayed above this home screen (or another application screen). The notification display field 259e displays a notification message stating, "A new message has been received from Almex Hospital. Please launch the patient registration card application." The user refers to this notification message and launches the patient registration card application 259a.

[0140] When the patient registration card application 259a is started on the mobile terminal 2a, it becomes possible to receive and display a message from the medical facility, as shown in FIG. 22(J), according to the transmission process described in FIG.

[0141] The above describes various embodiments of the invention relating to the present invention, but the present invention is not limited to these various embodiments, and forms formed by appropriately combining the configurations of each of the various embodiments also fall within the scope of the present invention.

[0142] The present invention can be used not only in medical facilities, but also in financial institutions such as banks, golf courses, and other facilities where confidentiality of customer information is required. At financial institutions such as banks, cash cards are used as facility tickets, and ATMs are used as reception devices. At golf courses, membership cards are used as facility tickets, and function addition processing is performed using reception devices installed on the golf courses. [Explanation of symbols]

[0143] 1 (1a, 1b): Reception device 61a: First notification server 2 (2a, 2b): Mobile terminal 61b: Second notification server 3 (3a, 3b): Management computer 62: Message server 11a:CPU 71:Hospital Reception 11b: ROM 72: Doorway 11c:RAM 121:Touch panel 11d: Image processing unit 122: Display unit 11e: Audio processing unit 123a: Examination details display field 12: Touch panel monitor 123b: Cancel button 13a: Camera 123c: Confirm button 13b: Infrared camera 251: Touch panel 14: Card reader 251a: Name of medical facility 15: Receipt printer 252: Display unit 15a: Scanner 255a, 255b: Patient card display area 15b: 2D barcode reader 255e: 2D barcode 16a: Receipt printer 256: Cancel button 16b: Printer 256a: Monitor column 17: LAN communication section 256c: Message setting section 18: Hard disk 257a: Relationship setting field 19: Interface 257b: Relationship selection button 21a:CPU 258a:Confirmation field 21b:ROM 259a:Medical Card App 21c:RAM 259b:Message display field 21d: Image processing unit 259c: Reply button 21e: Audio processing unit 259d: Button 22: Storage section 259e: Notification display field 23: Interface 352: Message Server 24: Camera 421a: Search field 25: Touch panel monitor 421b: Search result display button 26a: Cellular line communication unit 421c: New message creation button 26b: Wireless LAN communication unit 421d: Send message selection button 26c: Communication section 421e: Destination list 27: Input switch 421f: Text view field 28a: Speaker 421g: Data view column 28b: Microphone 421h: New message creation field 41: Input device 421i: Title input field 42: Monitor 421j: Recipient relationship selection button 43: Card reader 421k: Text input field 44: Receipt printer 421m: Attachment data input field 52(52a, 52b): Router 421n: Send button

Claims

1. A message system including a mobile terminal, a message management device installed in a facility, and a reception device installed in the facility, The mobile terminal executes a function addition process, a setting process, and a message process, The function addition process involves a user using the reception device to register facility user-related information, including identification information of the mobile terminal, in the mobile terminal; The setting process executes settings necessary for message processing between the facility user and the message management device corresponding to the registered facility user related information, based on the registered facility user related information; The message processing allows the device to receive messages sent from the message manager or to send messages to the message manager after the setting process is completed. The setting process sets, in the message management device, identification information of the mobile terminal, identification information of the facility user, and the relationship of the facility user as information regarding the destination of a message to be sent by a message program executed in the message management device; In the message processing, when a facility user is selected, the relationship to the facility user set in the setting processing is selected, and the mobile device of the relationship to the facility user is set as the message destination. Message system.

2. A portable program executable on a portable terminal, The mobile program causes the mobile terminal to execute a function addition process, a setting process, and a message process, The function addition process uses a reception device installed in the facility to register facility user related information, including identification information of the mobile terminal, in the mobile terminal; The setting process executes settings necessary for message processing between the facility user and the message management device corresponding to the registered facility user related information, based on the registered facility user related information; The message processing allows the device to receive messages sent from the message manager or to send messages to the message manager after the setting process is completed. The setting process sets, in the message management device, the identification information of the mobile terminal, the identification information of the facility user, and the relationship of the facility user as information regarding the destination of a message sent by a message program executed in the message management device. Portable program.

3. A message management device used in a message system including a mobile terminal and a message management device installed in a facility, The mobile device is executes a setting process for setting, in the message management device, identification information of the mobile terminal, identification information of the facility user, and the relationship of the facility user as information regarding the destination of a message sent by a message program executed in the message management device; The message management device After the setting process is completed, the message manager is enabled to send messages. When a facility user is selected, a message process is executed to set a mobile device of the facility user's relationship as the destination of a message to be sent by selecting the relationship of the facility user set in the setting process. Message management device.

4. A message program executed on a message management device used in a message system including a mobile terminal and a message management device installed in a facility, The mobile device is executes a setting process for setting, in the message management device, identification information of the mobile terminal, identification information of the facility user, and the relationship of the facility user as information regarding the destination of a message sent by a message program executed in the message management device; The message program is After the setting process is completed, the message manager is enabled to send messages. When a facility user is selected, a message process is executed to set a mobile device of the facility user's relationship as the destination of a message to be sent by selecting the relationship of the facility user set in the setting process. Message program.

Citation Information

Patent Citations

  • Method of controlling e-mail delivery and mail server

    JP2006254467A

  • Reception guide system and reception guide method

    JP2017120470A

  • Patient registration method for outpatient guide system

    JP2019074870A

  • Reception system for medical treatment facility

    JP2020086551A

  • Cryptographically secure mechanism for remotely controlling an autonomous vehicle

    WO2020197730A1