Information processing system, information processing method, and program
The information processing system enhances patient authentication accuracy and reduces burden by selecting appropriate methods based on disease and examination information, employing multiple authentication techniques.
Patent Information
- Authority / Receiving Office
- JP · JP
- Patent Type
- Patents
- Current Assignee / Owner
- CANON KK
- Filing Date
- 2022-03-09
- Publication Date
- 2026-04-13
AI Technical Summary
Existing patient authentication methods in medical settings are prone to errors, leading to incorrect medical information display and increased authentication burden, and there is a need for improved accuracy and reduced burden in patient authentication processes.
An information processing system that selects an authentication method based on disease and examination information, using multiple authentication methods to enhance accuracy and reduce burden, including IC card, password, fingerprint, iris, and vein authentication.
The system achieves improved authentication accuracy and reduces the burden associated with patient authentication in medical procedures by utilizing a method selection mechanism and multiple authentication techniques.
Smart Images

Figure 0007844198000001 
Figure 0007844198000002 
Figure 0007844198000003
Abstract
Description
Technical Field
[0004] , ,
[0001] The present invention relates to an information processing system, an information processing method, and a program.
Background Art
[0002] Patent Document 1 discloses that when a patient corresponding to an ID number read by a non-contact IC card reader / writer is stored in a storage device, information on predetermined items among the medical information of the patient is displayed on a display terminal for the patient. As the medical information displayed on this display terminal, Patent Document 1 shows conditions related to the movement of the patient, restrictions related to the posture and diet of the patient, and a symbol indicating the risk of falling. Further, Patent Document 1 shows that instead of a non-contact IC card reader / writer, a barcode reader that reads a barcode attached to the patient's arm or the like, or a biometric information reader that reads the biometric information of the patient may be used.
Prior Art Documents
Patent Documents
[0003]
Patent Document 1
Summary of the Invention
Problems to be Solved by the Invention
[0004] However, in the technology disclosed in Patent Document 1, the authentication method actually used to authenticate a patient is a predetermined single method. Therefore, there is a risk that errors may occur in the patient authentication results. For example, in the technology disclosed in Patent Document 1, if the link between the patient's ID number and the patient's medical information is incorrect, there is a risk that the medical information of another patient may be displayed on the display terminal. In this case, there is a risk that medical treatment may be performed on a patient based on the medical information of a patient other than the patient in question. On the other hand, if the authentication method used to authenticate a patient becomes more complex, there is a risk that the burden of authentication will increase. For example, there is a risk that the burden of the work performed to authenticate a patient and the burden of information processing for authenticating a patient will increase.
[0005] This invention has been made in view of the above-mentioned problems, and aims to achieve both improved authentication accuracy for those receiving medical-related procedures and reduced burden associated with such authentication. [Means for solving the problem]
[0006] The information processing system of the present invention is An information processing system, wherein the information processing system is registered Persons receiving medical-related procedures A setting means for setting information regarding the risks incurred by a person receiving a medical-related procedure, based on at least one of the following: information determined according to the illness or injury and information determined according to the medical-related procedure received by the person receiving the medical-related procedure; and information regarding the risks incurred by a person receiving a medical-related procedure, set by the setting means. Based on this, the system is characterized by having a selection means for selecting a method of authentication for a person receiving the medical-related procedure from among multiple authentication methods, and an authentication means for performing authentication of the person receiving the medical-related procedure using the authentication method selected by the selection means. [Effects of the Invention]
[0007] According to the present invention, it is possible to achieve both improved authentication accuracy for persons receiving medical-related procedures and reduced burden associated with such authentication. [Brief explanation of the drawing]
[0008] [Figure 1] This is a diagram showing an information processing system. [Figure 2] This is a diagram showing the configuration of a computer. [Figure 3] This is a diagram showing the configuration of the inspection device. [Figure 4] This diagram shows the configuration of the inspection data acquisition device. [Figure 5] This is a flowchart illustrating the pre-preparation process for an information processing system. [Figure 6] This is a flowchart illustrating the processing steps of an information processing system. [Figure 7] This diagram shows the structure of the authentication method database. [Modes for carrying out the invention]
[0009] This embodiment will be described below with reference to the drawings. First, we will explain an example of an information processing system with reference to Figure 1. Figure 1 is a block diagram showing an example of an overview of an information processing system. The information processing system 100 includes a testing device 101, an information terminal 102, an authentication method server 103, a hospital information system 104, and a clinical laboratory information system 105. In Figure 1, to avoid complexity in notation, only the main lines connecting the testing device 101, the information terminal 102, the authentication method server 103, the hospital information system 104, and the clinical laboratory information system 105 are shown. However, the testing device 101, the information terminal 102, the authentication method server 103, the hospital information system 104, and the clinical laboratory information system 105 are connected to each other so that they can communicate with one another. Furthermore, the hospital information system 104 and the clinical laboratory information system 105 may be located outside the information processing system 100.
[0010] A Hospital Information System (HIS) 104 is a general term for systems (network systems) aimed at improving the efficiency of medical care and accounting operations throughout a hospital. For example, ordering systems, medical accounting systems, electronic medical record systems, and hospital reception systems are also included in the Hospital Information System 104. The Hospital Information System 104 is a system aimed at improving operational efficiency, revitalizing information sharing within the hospital, revitalizing information sharing between the hospital and external parties, and supporting intelligent medical care, and has been introduced in various hospitals. Since the Hospital Information System 104 itself is implemented using publicly known technologies, a detailed explanation of the Hospital Information System 104 will be omitted here.
[0011] The Clinical Laboratory Information System (LIS) 105 is a comprehensive laboratory system (network system) related to clinical testing, and is installed, for example, in hospital laboratory departments and testing centers. The Clinical Laboratory Information System 105 has, for example, a processing function for managing data for each laboratory department and an integrated management function for requesting the use of laboratories and centrally managing test data. In this embodiment, it is assumed that a device for storing test data is included in the Clinical Laboratory Information System 105. Since the Clinical Laboratory Information System 105 itself is implemented using known technology, a detailed explanation of the Clinical Laboratory Information System 105 is omitted here.
[0012] In this embodiment, we illustrate the case where the test is a clinical test. Note that clinical tests include physiological function tests and specimen tests. In the following description, clinical tests will be abbreviated as "tests" as needed. However, tests are not limited to clinical tests, as long as they are medically relevant. For example, the information processing system 100 of this embodiment may be applied when tests for testing or research purposes (e.g., tests in clinical trials such as drug trials) are performed in place of or in addition to clinical tests.
[0013] Next, we will explain the general function of the information processing system 100. In this embodiment of the information processing system 100, authentication of a patient scheduled for examination (not shown) is performed by the information terminal 102, and after the patient's authentication is complete, the examination is performed by the examination device 101. When the examination is completed, the examination data obtained from the examination is transmitted to the clinical laboratory information system 105. In the following description, a patient scheduled for examination will be abbreviated as "patient" as needed.
[0014] Furthermore, this embodiment illustrates a case in which the authentication method server 103 selects a patient's authentication method before patient authentication is performed. To do this, the authentication method server 103 first receives disease information from the hospital information system 104 and receives examination information from the examination device 101, at least one of the above. Then, based on the information from at least one of the disease information and the examination information, the authentication method server 103 selects a patient's authentication method for each patient and transmits information indicating the selected patient's authentication method to the information terminal 102.
[0015] Disease information is information about an individual patient, and includes, for example, information determined according to the patient's disease. Specifically in this embodiment, disease information includes patient identification information (patient ID) and identification information of the patient's disease (disease ID). More specifically in this embodiment, disease information includes information stored in the patient disease table 730, which will be described later with reference to Figure 7.
[0016] The examination information is information of an individual patient, and includes, for example, information determined according to the examination the patient undergoes. Specifically, in the present embodiment, the examination information includes identification information of the examination the patient undergoes. More specifically, in the present embodiment, the examination information includes an examination ID. The examination ID is identification information that identifies each examination device 101 and the examination date and time by the examination device 101. Also, in the present embodiment, it is assumed that there may be a case where information indicating whether the examination the patient undergoes is a pre-operative examination is included in the examination information. Note that the information included in the disease information and the information included in the examination information may partially overlap. For example, the patient identification information (patient ID) may be included in the examination information. Also, in the present embodiment, an example is given where the "pre-operative examination" described later while referring to FIG. 7 is information stored in the patient disease table 730 and is information included in the disease information, but the "pre-operative examination" is also considered to be examination information.
[0017] The information terminal 102 authenticates the patient using the patient authentication method received from the authentication method server 103. When the patient is authenticated (that is, when the patient authentication is successful), the examination device 101 performs the examination of the patient based on the operation of the user (examiner) on the examination device 101. Also, the information terminal 102 transmits information indicating the patient authentication result to the hospital information system 104. When the patient is not authenticated (that is, when the patient authentication fails), the administrative terminal included in the hospital information system 104 displays information indicating that it is necessary to manually confirm the identity of the patient and re-register the authentication information of the patient on the display device. The authentication information is information that is compared with the patient's information at the time of patient authentication. The authentication information is linked to each patient. Also, the examination device 101 transmits the patient's examination data to the clinical examination information system 105.
[0018] Next, while referring to FIG. 1, an example of the functional configuration of the inspection device 101, the information terminal 102, and the authentication method server 103 will be described. An example of the hardware configuration of the inspection device 101, the information terminal 102, and the authentication method server 103 will be described later while referring to FIGS. 2 to 4. In FIG. 1, one inspection device 101 and one information terminal 102 are shown respectively. However, at least one of the inspection device 101 and the information terminal 102 may be plural.
[0019] First, an example of the functional configuration of the inspection device 101 will be described. The inspection device 101 includes an inspection data acquisition unit 111, an inspection ID acquisition unit 112, and an output unit 113.
[0020] As described above, the inspection device 101 performs an inspection of the patient based on an operation of the inspection device 101 by an examiner (user). The inspection data acquisition unit 111 acquires inspection data of the patient. In the present embodiment (FIG. 4 described later), the case where the inspection device 101 is a digital camera is exemplified. Also, in the present embodiment, the case where the inspection data when the inspection device 101 is a digital camera includes image data including the affected area and data indicating the size of the affected area is exemplified. Also, in the present embodiment, the case where the inspection includes an inspection for measuring the size of the affected area is exemplified. Specifically, in the present embodiment, the size of the affected area is assumed to be specified based on a process (for example, region division) performed on the inspection data (image data) obtained by the inspection data acquisition unit 111. In the following description, this inspection is referred to as a camera image inspection as necessary.
[0021] Note that the inspection is not limited to the camera image inspection. Therefore, when the inspection device 101 is a device that performs an inspection different from the camera image inspection, the inspection data acquisition unit 111 included in the inspection device 101 acquires inspection data corresponding to the content of the inspection. The inspection may include at least one of, for example, a blood pressure inspection, a body temperature measurement, an ultrasonic examination of blood vessels, an intraocular pressure inspection, a contrast CT inspection, and a colonoscopy.
[0022] The inspection ID acquisition unit 112 acquires an inspection ID. As mentioned above, the inspection ID is identification information that identifies, for example, each inspection device 101 and the date and time of inspection performed by the inspection device 101. The inspection ID may also be a string formed by concatenating, for example, the MAC address of the inspection device 101 and the date and time of inspection. The output unit 113 transmits information to an external device located outside the testing device 101. For example, the output unit 113 transmits the test ID to the information terminal 102 and the authentication method server 103, and transmits the test data to the clinical laboratory information system 105.
[0023] Next, an example of the functional configuration of the information terminal 102 will be described. The information terminal 102 includes an information acquisition unit 121, an authentication unit 122, a display unit 123, and an output unit 124. The information terminal 102 may be, for example, a smart device or a computer other than a smart device.
[0024] The information acquisition unit 121 acquires information input to the information terminal 102. The information acquisition unit 121 acquires information that includes, for example, information transmitted from an external device located outside the information terminal 102 and information input to the information terminal 102 through user operations on the information terminal 102. Specifically, the information acquisition unit 121 acquires identification information (patient ID) that identifies the patient, transmitted from the hospital information system 104, and information indicating the patient's authentication method, transmitted from the authentication method server 103. The information acquisition unit 121 also acquires the examination ID of the examination device 101, transmitted from the examination device 101. Alternatively, the information acquisition unit 121 may read a two-dimensional code that stores information including the examination ID of the examination performed by the examination device 101, and acquire the examination ID from the read two-dimensional code.
[0025] The authentication unit 122 authenticates the patient using the patient authentication method acquired by the information acquisition unit 121. It is preferable that the multiple authentication methods include one that requires multiple authentications, as this allows for more reliable patient authentication. Furthermore, if multiple authentications are performed, it is preferable that the means used for each authentication are different, as this allows for even more reliable patient authentication. Therefore, it is preferable that the authentication unit 122 has multiple means for performing authentication. In this embodiment, if at least one of the types of information to be compared during authentication, the authentication algorithm, and the authentication hardware is different, then the multiple means used for authentication are assumed to be different from each other.
[0026] However, if multiple authentications are performed, the means used for each authentication may be the same. For example, if a password is used as the information (type) to be verified during authentication, each of the multiple authentications may be performed by verifying multiple different passwords. Alternatively, each of the multiple authentications may be performed by repeatedly verifying the same password.
[0027] The authentication that the authentication unit 122 can perform includes, for example, at least one of the following: IC card authentication, password authentication, fingerprint authentication, iris authentication, facial authentication, and vein authentication. In this case, the authentication information is the information of the query destination when performing each authentication, and includes, for example, biometric information, password, and patient ID. The display unit 123 displays the patient authentication result performed by the authentication unit 122. The output unit 124 transmits information to an external device located outside the information terminal 102. For example, the output unit 124 transmits information indicating the patient's authentication result to the hospital information system 104.
[0028] Next, we will describe an example of the functional configuration of the authentication method server 103. The authentication method server 103 includes an information acquisition unit 131, an authentication method selection unit 132, an authentication information management unit 133, an authentication method database 134, and an output unit 135.
[0029] The information acquisition unit 131 acquires information input to the authentication method server 103. The information acquisition unit 131 acquires information including, for example, information transmitted from an external device outside the authentication method server 103 and information input to the authentication method server 103 through user operations on the authentication method server 103. Specifically, the information acquisition unit 131 acquires disease information transmitted from the hospital information system 104 as information to be stored in the authentication method database 134, which will be described later with reference to Figure 7. The information acquisition unit 131 also acquires other information to be stored in the authentication method database 134, which will be described later with reference to Figure 7, through user operations on the authentication method server 103. In the following description, the information stored in the authentication method database 134 will be referred to as authentication method selection information as needed. The information acquisition unit 131 also acquires authentication information through user operations on the authentication method server 103. The information acquisition unit 131 also acquires the test ID transmitted from the testing device 101.
[0030] The authentication method selection unit 132 selects an authentication method for a patient scheduled for examination from among multiple authentication methods, based on information determined according to the patient scheduled for examination. Specifically, this embodiment illustrates a case where the authentication method selection unit 132 selects an authentication method for a patient from among multiple authentication methods based on at least one of disease information and examination information. More specifically, this embodiment illustrates a case where the authentication method selection unit 132 sets the risk level of the examination based on at least one of disease information and examination information, and selects an authentication method for the patient from among multiple authentication methods based on the set risk level of the examination. The risk level of the examination is information indicating the degree of risk that the patient will face as a result of performing the examination. In this embodiment, an example is given where the risk level of the examination is set based on the type of disease the patient has and the type of examination. In addition, this embodiment also illustrates a case where the risk level of the examination is set based on whether or not the examination the patient receives is a pre-operative examination, regardless of the type of disease the patient has and the type of examination.
[0031] The authentication information management unit 133 stores and manages authentication information. As mentioned above, authentication information is the information to be queried during patient authentication and is correct information about the patient in question. If authentication information is stored in the hospital information system 104, the authentication information management unit 133 may request the hospital information system 104 to retrieve some or all of the authentication information via the information retrieval unit 131. In this case, the authentication information management unit 133 stores and manages the authentication information obtained by the information retrieval unit 131 from the hospital information system 104.
[0032] The authentication method database 134 is a database that the authentication method selection unit 132 refers to when selecting an authentication method. A specific example of the authentication method database 134 will be described later with reference to Figure 7. The output unit 135 transmits information to an external device located outside the authentication method server 103. For example, the output unit 135 transmits information indicating the authentication method for the patient selected by the authentication method selection unit 132 to the information terminal 102.
[0033] Next, an example of the hardware configuration of the information terminal 102 and the authentication method server 103 will be described. The hardware of the information terminal 102 and the authentication method server 103 is configured, for example, by using the computer 200 shown in Figure 2. In this embodiment, we will illustrate the case where the information terminal 102 has a smart device and the authentication method server 103 has a computer server. The smart device is, for example, a smartphone and a tablet. In addition to the configuration shown in Figure 2, the information terminal 102 also has hardware (not shown) for performing authentication. The hardware for performing authentication is the hardware necessary to realize the authentication method described later. The information terminal 102 has hardware corresponding to the authentication performed on the information terminal 102 as the hardware for performing authentication. For example, the information terminal 102 has at least one of a fingerprint authentication device and an IC card reader as the hardware for performing authentication. The hardware for performing authentication may be included in the computer 200 or connected to the computer 200.
[0034] The functions of the information terminal 102 and the authentication method server 103 are performed, for example, by using a computer 200. In Figure 2, the computer 200 includes an arithmetic processing unit 211, a storage device 212, an input device 213, an output device 214, and a communication device 215.
[0035] The storage device 212 includes a main memory 212a and an auxiliary storage device 212b. The main memory 212a has, for example, a main memory for work, such as RAM (Random Access Memory). The auxiliary storage device 212b of a smart device has, for example, flash memory. The auxiliary storage device 212b of a computer server has, for example, at least one of a magnetic disk drive and an SSD (Solid State Drive).
[0036] The input device 213 has a user interface. The input device 213 may have, for example, a mouse and a keyboard. In addition to these, or instead, the input device 213 may have a touch panel or the like that is installed on the display device of the output device 214.
[0037] The output device 214 has a display device that displays various types of information. Examples of display devices include a TFT (Thin Film Transistor) liquid crystal display and an organic EL display. The input device 213 and the output device 214 are configured to communicate with each other using at least one of the following methods: wired or wireless. Specific examples of networks for wireless communication include networks based on the Wi-Fi® standard and wireless LANs (Local Area Networks). Specific examples of networks for wired communication include wired LANs. Furthermore, the input device 213 and the output device 214 may also perform wired communication based on the USB (Universal Serial Bus) standard.
[0038] The communication device 215 has a communication interface for the computer 200 to communicate with an external device via at least one of a wired network and a wireless network (not shown). Specific examples of the wireless communication network and the wired communication network are described as specific examples of the communication network for the input device 213 and the output device 214. However, from the viewpoint of usability of the information terminal 102, it is desirable that the connection between the information terminal 102 and the authentication method server 103 be a wireless LAN.
[0039] The arithmetic processing unit 211 functions as a component of the computer 200 (information terminal 102, authentication method server 103) by executing programs stored in the storage device 212. Furthermore, the arithmetic processing unit 211 controls the order in which processing is executed in each component of the computer 200 (information terminal 102, authentication method server 103). The arithmetic processing unit 211 includes, for example, a CPU (Central Processing Unit).
[0040] The computer 200 may have one arithmetic processing unit 211 and one storage device 212. For example, at least one arithmetic processing unit 211 and at least one storage device 212 may be connected to each other in a manner that allows them to communicate with one another. In this case, the computer 200 functions as shown in Figure 2 by having at least one arithmetic processing unit 211 execute a program stored in at least one storage device 212. The arithmetic processing unit may have at least one of an FPGA (Field Programmable Gate Array) and an ASIC (Application Specific Integrated Circuit). In this case, the arithmetic processing unit may or may not have a CPU. Furthermore, the hardware of information processing devices such as the aforementioned office terminals, the hospital information system 104 and the clinical laboratory information system 105 are also configured, for example, by using the computer 200 shown in Figure 2.
[0041] Next, Figure 3 shows an example of the hardware configuration of the inspection device 101. The inspection device 101 includes an inspection data acquisition device 311 and an inspection device computer 312. The connection interface between the inspection data acquisition device 311 and the inspection device computer 312 is determined, for example, by the use case. The connection between the inspection data acquisition device 311 and the inspection device computer 312 may be a wired connection or a wireless connection.
[0042] The inspection data acquisition device 311 is the main body of the inspection apparatus 101. The inspection data acquisition device 311 acquires inspection data and transmits the inspection data to the inspection apparatus computer 312. The computer 312 for the testing device receives testing data from the testing data acquisition device 311 and transmits it to an external device such as the clinical laboratory information system 105. The computer 312 for the testing device also generates a testing ID and transmits it to the information terminal 102 and the authentication method server 103.
[0043] The hardware of the inspection device computer 312 is configured, for example, by using computer 200. Therefore, a detailed description of the hardware of the inspection device computer 312 is omitted here.
[0044] Furthermore, the inspection data acquisition device 311 and the inspection device computer 312 may be separate or contained within the same housing. When the inspection data acquisition device 311 and the inspection device computer 312 are contained within the same housing, handling the inspection device 101 becomes easier. For example, the connection work between the inspection data acquisition device 311 and the inspection device computer 312 becomes unnecessary. Also, it becomes unnecessary to manage the inspection data acquisition device 311 and the inspection device computer 312 separately. On the other hand, separating the inspection data acquisition device 311 from the inspection device computer 312 allows the inspection data acquisition device 311 to be made smaller, thus improving work efficiency during inspection. For example, if the processing load, such as post-processing of inspection data, is high, having the inspection device computer 312, which exists separately from the inspection data acquisition device 311, perform such processing allows the inspection data acquisition device 311 to be made smaller. Therefore, work efficiency during inspection is improved. Furthermore, for example, if the inspection data acquisition device 311 has an inspection probe, the inspection probe can be made smaller. Therefore, the workability during inspection is improved.
[0045] Next, Figure 4 shows an example of the hardware configuration of the inspection data acquisition device 311. In Figure 4, the inspection data acquisition device 311 of the inspection apparatus 101 has a digital camera, and the inspection is a camera image inspection.
[0046] The inspection data acquisition device 311 includes an imaging unit 411, a zoom control unit 412, a distance measuring system 413, an image processing unit 414, a communication unit 415, a system control unit 416, and a storage unit 417. The inspection data acquisition device 311 also includes an external memory 418, a display unit 419, an operation unit 420, a common bus 421, an AF control unit 422, and an image analysis unit 423.
[0047] The imaging unit 411 includes a lens 411a, a shutter 411b, and an image sensor 411c. The function of the inspection data acquisition device 311 in the inspection apparatus 101 is realized, for example, by the operation of the imaging unit 411. The lens 411a forms an optical image of the subject on the image sensor 411c. The image sensor 411c converts the optical image into an electrical signal. The image sensor 411c may be, for example, a charge-accumulating solid-state image sensor. A charge-accumulating solid-state image sensor may be, for example, a CCD (Charge-Coupled Device) image sensor or a CMOS (Complementary Metal Oxide Semiconductor) image sensor. The image sensor 411c outputs RAW image data.
[0048] In the area where lens 411a is installed, there is an aperture (not shown) that determines the aperture value for adjusting the amount of exposure. The shutter 411b performs an opening and closing operation. The opening and closing operation of the shutter 411b exposes and shields the image sensor 411c from light, and controls the shutter speed. Note that the shutter 411b is not limited to a mechanical shutter, but may also be an electronic shutter. If the shutter 411b is an electronic shutter and the image sensor 411c is a CMOS image sensor, the image sensor 411c performs the following processing, for example. First, a reset scan is performed to set the accumulated charge of each pixel to zero, either for each individual pixel or for each region consisting of multiple pixels (for example, each line). Then, after a predetermined time has elapsed since the reset scan, a scan is performed to read out the electrical signal based on the charge accumulated in the pixel, either for each pixel that underwent the reset scan or for each region that underwent the reset scan.
[0049] The zoom control unit 412 controls the drive of the zoom lens included in the lens 411a. The zoom control unit 412 drives the zoom lens via a zoom motor (not shown) according to instructions from the system control unit 416. This performs the magnification change. The distance measuring system 413 has the function of deriving the subject distance (distance from the digital camera to the subject) for each of the multiple blocks in a screen that is divided into multiple blocks, each consisting of multiple pixels. The distance measuring system 413 may derive the subject distance using, for example, a TOF (Time Of Flight) sensor. Alternatively, the distance measuring system 413 may derive the subject distance using a PSD (Position Sensitive Device). The distance measuring system 413 may derive the subject distance using other known methods. The subject distance information only needs to be information that identifies the subject distance for each of the multiple blocks.
[0050] The AF control unit 422 automatically adjusts the focus. The AF control unit 422 performs automatic focus adjustment using a focus control method, for example. When performing automatic focus adjustment using a focus control method, the AF control unit 422 performs the following processes. First, the AF control unit 422 extracts the high-frequency components of the imaging signal (video signal). Next, the AF control unit 422 searches for the position of the focus lens included in the lens 411a where the integral value of the high-frequency components of the imaging signal is maximized. Next, the AF control unit 422 automatically adjusts the focus by controlling the focus lens based on the searched position. The focus control method is also called TV-AF (Auto Focus) or contrast AF. The focus control method has the characteristic of achieving highly accurate focusing.
[0051] The focus control method is not limited to contrast AF, but may also be phase-detection AF or other AF methods. Furthermore, the method for automatic focus adjustment is not limited to the focus control method, but may also be other methods. The AF control unit 422 may also detect the amount of focus adjustment or the position (movement) of the focus lens and derive the subject distance based on the detected result. The derivation of the subject distance may also be performed by either the AF control unit 422 or the distance measuring system 413 alone. For example, if the subject distance is detected by the AF control unit 422, the distance measuring system 413 may be omitted.
[0052] The image processing unit 414 performs image processing on the RAW image data output from the image sensor 411c and the image data stored in the storage unit 417, which will be described later. Image processing includes, for example, white balance adjustment, gamma correction, color interpolation or demosaicing, and filtering. The image processing unit 414 also performs compression processing on the image data based on standards such as JPEG (Joint Photographic Experts Group).
[0053] The image analysis unit 423 extracts the affected area of the subject from the image data and measures the size of the affected area. The image analysis unit 423 may perform region segmentation on the image data when extracting the affected area. One method of region segmentation is semantic region segmentation using deep learning. In this method, for example, a training computer (not shown) generates a trained model by training a neural network model. When training, for example, multiple training data sets are used. The training data includes, for example, image data that includes the actual affected area. The affected area is, for example, the area of a pressure ulcer. The image analysis unit 423 estimates the affected area from the input image based on the trained model. One example of a neural network model is a fully convolutional network (FCN), which is a deep learning-based segmentation model. Here, the deep learning inference process may be performed by a GPU (Graphics Processing Unit) which excels at parallel execution of multiply-accumulate operations. The inference process may also be performed by an FPGA or ASIC, etc. Furthermore, region segmentation may be achieved using deep learning models other than neural network models. Also, the region segmentation method is not limited to deep learning; for example, methods using graph cuts, edge detection, or superpixel-based region segmentation may also be used.
[0054] The image analysis unit 423 converts the size of the affected area in the image data to its actual size. This conversion is performed, for example, based on information regarding the field of view of the image data, information regarding the number of pixels (pixel size) of the image sensor 411c, and information regarding the distance to the subject. This conversion provides information regarding the actual size of the affected area.
[0055] As mentioned above, the information output from the distance measuring system 413 or the AF control unit 422 is used as subject distance information. Here, the image analysis unit 423 may derive the actual distance from the digital camera to the subject included in the image data when deriving the actual size of the affected area. Furthermore, the image analysis unit 423 does not necessarily need to use the aforementioned information as long as it can derive the actual size of the affected area. For example, the image analysis unit 423 may derive information regarding the actual size of the affected area using only one of the following: information regarding the field of view of the image data and information regarding the number of pixels (pixel size) of the image sensor 411c.
[0056] The size of the affected area may be its length or its area. The affected area may be approximated to a predetermined shape, for example. For example, if the affected area is represented by an ellipse, the length of the affected area may be at least one of its major and minor axes. Alternatively, the length of the affected area may be a representative length of the affected area. If the affected area is represented by an ellipse, the representative length of the affected area may be calculated using its major and minor axes. The information used to determine the size of the affected area should be determined according to the purpose of the examination and treatment. The image analysis unit 423 may be included in the inspection data acquisition device 311 or in the inspection device computer 312.
[0057] The communication unit 415 has a communication interface for communicating with external devices such as the inspection device computer 312 via at least one of a wired network and a wireless network (not shown). The communication interface may be a communication interface for wired communication or an interface for wireless communication. The wireless communication interface has a wireless communication module corresponding to the network for which wireless communication is performed. Note that communication using Wi-Fi (registered trademark) may be implemented via a router. Furthermore, a wired LAN is an example of a network for wired communication. Furthermore, the wired communication interface may be a communication interface for wired communication based on the USB standard.
[0058] The system control unit 416 includes, for example, a CPU. The system control unit 416 controls each part of the inspection data acquisition device 311 (digital camera) according to a program stored in the memory unit 417, thereby performing overall control of the inspection data acquisition device 311. The system control unit 416 also performs overall control of the AF control unit 422, the imaging unit 411, the zoom control unit 412, the distance measuring system 413, and the image processing unit 414, etc.
[0059] The storage unit 417 temporarily stores various types of information. For example, the storage unit 417 temporarily stores various setting information necessary for the operation of the inspection data acquisition device 311. This setting information includes information such as the focus position when capturing images. The storage unit 417 also temporarily stores, for example, RAW image data output from the imaging unit 411 and image data processed by the image processing unit 414. The storage unit 417 may also temporarily store image data received by the communication unit 415 by communicating with the inspection device computer 312, and analysis data output from the image analysis unit 423. This analysis data includes, for example, information regarding the size of the affected area. The storage unit 417 has, for example, a non-volatile storage medium that allows data to be rewritten. Examples of storage media for the storage unit 417 include flash memory and SDRAM (Synchronous Dynamic Random Access Memory). The information stored in the storage unit 417 does not necessarily have to be temporary.
[0060] The external memory 418 has a non-volatile storage medium. The external memory 418 may be loadable into the inspection data acquisition device 311 (digital camera) body, or it may be fixed inside the inspection data acquisition device 311. Examples of non-volatile storage mediums for the external memory 418 include SD (Secure Digital) cards and CF (CompactFlash) cards. The external memory 418 stores, for example, image data including image data processed by the image processing unit 414, data received by the communication unit 415 by communicating with an external device, and analysis data including analysis data output from the image analysis unit 423. When an external device plays back image data stored in the external memory 418, the image data stored in the external memory 418 is read from the external memory 418 and output to the external device.
[0061] The display unit 419 displays various types of information. The information displayed by the display unit 419 includes, for example, data such as image data temporarily stored in the storage unit 417 and image data stored in the external memory 418, disease information, examination data, alert information, and the setting screen of the examination data acquisition device 311. The display unit 419 may have, for example, a TFT (Thin Film Transistor) liquid crystal display, an organic EL display, or an EVF (Electronic View Finder).
[0062] The operation unit 420 has a user interface. The operation unit 420 has, for example, buttons, switches, keys, and a mode dial. The buttons, switches, keys, and mode dial are attached to, for example, the inspection data acquisition device 311. In addition to these, or instead, the operation unit 420 may have a touch panel or the like installed on the display unit 419. Commands from the user, such as various mode settings and shooting operations such as shutter release, are output to the system control unit 416 via the operation unit 420. The imaging unit 411, zoom control unit 412, distance measuring system 413, image processing unit 414, communication unit 415, and system control unit 416 are connected to the common bus 421. The storage unit 417, external memory 418, display unit 419, operation unit 420, AF control unit 422, and image analysis unit 423 are also connected to the common bus 421. The common bus 421 is a signal line for each part of the inspection data acquisition device 311 to send and receive signals. Furthermore, the digital camera used for camera image inspection is implemented using publicly known technology and is not limited to the one shown in Figure 4.
[0063] Next, an example of the pre-preparation process for the information processing system 100 of this embodiment will be described with reference to the flowchart shown in Figure 5. The pre-preparation process for the information processing system 100 includes registering the information necessary for processing by the information processing system 100 in the information processing system 100 before the processing according to the flowchart shown in Figure 6, which will be described later, begins.
[0064] First, in S501, the authentication method selection information is registered. For example, a user inputs the authentication method selection information into the authentication method server 103 by operating the input device 213 provided by the authentication method server 103. Users are, for example, users on the hospital management side, SEs, and medical personnel. The information acquisition unit 131 acquires the authentication method selection information input into the authentication method server 103 in this way. The authentication method database 134 stores the authentication method selection information acquired by the information acquisition unit 131. As mentioned above, in this embodiment, we will illustrate the case where the authentication method selection information is information stored in the authentication method database 134, which will be described later with reference to Figure 7. Specifically, we will illustrate the case where the authentication method selection information stored in the authentication method database 134 is information stored in the default examination risk table 710, the disease-examination risk definition table 720, and the risk authentication method table 750. The information acquisition unit 131 may also receive the authentication method selection information from an external device such as the hospital information system 104.
[0065] Next, in S502, a determination is made as to whether or not the authentication information has been registered. For example, the authentication information management unit 133 determines whether or not the authentication information has already been registered and whether or not there is no need to change the authentication information. This determination may be made, for example, based on whether or not the user has performed an operation to instruct the input device 213 of the authentication method server 103 to register the authentication information.
[0066] As a result of this determination, if at least one of the following conditions is met—that the authentication information has not already been registered, or that the registered authentication information needs to be changed—the authentication information is registered in S503. For example, a user inputs authentication information into the authentication method server 103 by operating the input device 213 provided by the authentication method server 103. As mentioned above, users include hospital administrators, system engineers, and medical personnel. The information acquisition unit 131 acquires the authentication information entered into the authentication method server 103 in this manner. The authentication information management unit 133 stores the authentication information acquired by the information acquisition unit 131. Then, in S504, disease information is registered.
[0067] On the other hand, if authentication information has already been registered and there is no need to change the authentication information, the process in S503 is skipped and disease information is registered in S504. In S504, for example, the information acquisition unit 131 receives disease information from the hospital information system 104. The patient disease table 730 of the authentication method database 134 stores the disease information acquired by the information acquisition unit 131. The information acquisition unit 131 may also query the hospital information system 104 to receive the latest disease information. The timing at which the information acquisition unit 131 queries the hospital information system 104 for the availability of the latest disease information is not particularly limited. The query for the availability of the latest disease information from the hospital information system 104 may be performed periodically, or when predetermined conditions are met. For example, when a user performs an operation to instruct the input device 213 of the authentication method server 103 to query for disease information, it may be determined that predetermined conditions have been met. In S504, when the registration of disease information is completed, the pre-preparation process according to the flowchart in Figure 5 is completed.
[0068] Next, an example of the processing of the information processing system 100 of this embodiment will be explained with reference to the flowchart shown in Figure 6. The processing shown in the flowchart in Figure 6 starts after the preliminary processing shown in the flowchart in Figure 5 has been completed.
[0069] First, in S601, a notification of a request to select an authentication method is issued. For example, the user (examiner) performs an operation to instruct the input device 213 of the information terminal 102 to output a request to select a patient's authentication method. Based on this operation, the output unit 113 sends information indicating the request to select a patient's authentication method to the authentication method server 103. The flowchart shown in Figure 6 illustrates the case where this request to select a patient's authentication method triggers the patient authentication process. If the information processing system 100 has multiple information terminals 102, the process according to the flowchart in Figure 6 is executed based on the request to select a patient's authentication method (transmission of information indicating the request to select a patient's authentication method) from each information terminal 102. In this case, the patient's authentication method is selected individually for each information terminal 102.
[0070] Next, in S602, the information acquisition unit 121 acquires identification information (patient ID) to identify the patient. For example, if there is a patient examination order, the information acquisition unit 121 receives the patient ID from the hospital information system 104. For example, the information acquisition unit 121 receives a list containing the patient's patient ID as a patient examination order from the hospital information system 104 and displays it on the output device 214 (display device). The user (examiner) of the information terminal 102 selects a patient from the list. The information acquisition unit 121 acquires the patient ID of the patient selected in this way. The output unit 124 transmits the information including the patient ID acquired by the information acquisition unit 121 to the authentication method server 103.
[0071] On the other hand, if, for example, there is no examination order for a patient, the information acquisition unit 121 acquires the patient ID received when the patient entered into the hospital reception system. In this case, the information acquisition unit 121 acquires the patient ID of the patient received by the hospital information system 104. For example, the information acquisition unit 121 receives a list from the hospital information system 104 that includes the patient ID of the patient in question as a list of patients received by the hospital information system 104, and displays it on the output device 214 (display device). The user (examiner) of the information terminal 102 selects a patient from this list. The information acquisition unit 121 acquires the patient ID of the patient selected in this way. The output unit 124 transmits the information including the patient ID acquired by the information acquisition unit 121 to the authentication method server 103.
[0072] Furthermore, obtaining the patient ID does not necessarily have to be done in the manner described above. For example, a user (examiner) may be able to ascertain the patient's ID based on patient information managed separately by the medical facility from the hospital information system 104. In this case, the user (examiner) identifies the patient's ID based on patient information managed separately by the medical facility from the hospital information system 104. The user (examiner) then inputs the identified patient ID into the information terminal 102 by operating the input device 213 on the information terminal 102. The information acquisition unit 121 then acquires the patient ID entered into the information terminal 102.
[0073] Next, in S603, the examination ID is obtained. For example, the information acquisition unit 131 receives the examination ID of the examination device 101 obtained by the examination ID acquisition unit 112. Here, the information acquisition unit 131 obtains the examination ID of the examination to be received by the patient from the examination device 101 used for the examination to be received by the patient identified by the patient ID obtained in S602. The user (examiner) is aware of the examination device 101 used for the examination to be received by the patient. Therefore, for example, the information acquisition unit 121 obtains the examination ID of the examination to be received by the patient from the examination device 101 used for the examination to be received by the patient, based on the user's (examiner's) operation on the input device 213 of the information terminal 102. As mentioned above, the acquisition of the examination ID may be performed, for example, by receiving information transmitted from the examination device 101, or by reading a 2D code. Then, the output unit 124 transmits the information including the examination ID obtained by the information acquisition unit 121 to the authentication method server 103. At this time, the output unit 124 may send information linking the patient ID obtained in S602 and the test ID obtained in S603 to the authentication method server 103. In this way, the authentication method server 103 can determine which test ID corresponds to which patient ID (i.e., which test is for which patient). The information acquisition unit 131 acquires the test IDs transmitted from the output unit 124 (information terminal 102) in this manner.
[0074] Next, in S604, the authentication method is selected. For example, the authentication method selection unit 132 refers to the authentication method database 134 and selects the authentication method for the patient identified by the patient ID obtained in S602.
[0075] Figure 7 shows an example of the authentication method database 134 and the tables contained within it. An example of the process for selecting a patient's authentication method will be explained with reference to Figure 7. The authentication method database 134 is stored in the main memory 212a via the auxiliary storage device 212b of the computer 200, which is the hardware of the authentication method server 103. While the database is stored in the main memory 212a, information is written to, read from, and updated in the authentication method database 134. In this embodiment, the authentication method database 134 is used to collectively manage information used for selecting a patient's authentication method.
[0076] The authentication method database 134 includes a default test risk table 710, a disease-test risk definition table 720, a patient disease table 730, a patient-specific test risk table 740, and a risk authentication method table 750. The default test risk table 710, the disease-test risk definition table 720, the patient disease table 730, and the risk authentication method table 750 are created before the processing shown in the flowchart in Figure 6 begins. On the other hand, the patient-specific test risk table 740 is created in S604.
[0077] The default test risk table 710 stores default (standard) information for each type of test, including the risk level of the test. In this embodiment, an example is given where the tests stored in the default test risk table 710 are tests that require patient authentication before the test is performed. The information stored in the default test risk table 710 is included in the authentication method selection information obtained in S501, and is stored in the default test risk table 710 in S501. Figure 7 illustrates a case where the default test risk table 710 includes a test ID as the primary key, and test name and risk level as other columns.
[0078] As mentioned above, the risk level of the test is information indicating the degree of risk to the patient as a result of performing the test. In this embodiment, as an example, the risk level of the test is set in three stages: low, medium, and high. However, the method of setting the risk level of the test is not limited to this method. For example, the number of stages indicating the risk level of the test is not limited to three. Also, the risk level of the test may be expressed numerically.
[0079] In this embodiment, we illustrate a case where the level of risk for an examination is determined by the invasiveness of the examination. In the default examination risk table 710, blood pressure measurement, weight measurement, camera imaging, and vascular ultrasound are non-invasive examinations. Therefore, in the default examination risk table 710, the risk level for these examinations is set to "low". Intraocular pressure measurement is a non-contact examination. However, air pressure is applied to the eyeball during intraocular pressure measurement. Therefore, in the default examination risk table 710, the risk level for intraocular pressure measurement is set to "medium". Computed tomography (CT) and colonoscopy are invasive examinations. Therefore, in the default examination risk table 710, the risk level for these examinations is set to "high". Note that the criteria for determining the level of risk are not limited to the invasiveness of the examination.
[0080] The disease-test risk definition table 720 stores information for each type of test, including the degree of risk of testing if the patient has a specific disease. The information stored in the disease-test risk definition table 720 is included in the authentication method selection information obtained in S501, and is stored in the disease-test risk definition table 720 in S501. Figure 7 illustrates a case where the disease-test risk definition table 720 includes a disease-test ID as the primary key, and other columns include disease ID, disease name, test ID, test name, and risk degree. The disease-test ID, one of the columns in the disease-test risk definition table 720, is a composite key of disease ID and test ID.
[0081] When a patient has a specific disease, there are cases where the patient faces a risk that exceeds the risk level of the test stored in the default test risk table 710. Figure 7 illustrates the case where hypertension and glaucoma are included as disease names in the disease-test risk definition table 720. The treatment strategy for patients with hypertension is greatly influenced by the results of blood pressure and vascular ultrasound examinations. Therefore, these tests are of high importance for patients with hypertension. Similarly, the treatment strategy for patients with glaucoma is greatly influenced by the results of intraocular pressure tests. Therefore, intraocular pressure tests are of high importance for patients with glaucoma.
[0082] A patient mix-up in such an important examination could lead to a major problem. Therefore, in this embodiment, the risk level of a specific examination (for example, an examination of high importance to the patient) determined according to the patient's disease is the risk level stored in the disease-examination risk definition table 720. In this case, the risk level of examinations stored in the default examination risk table 710 is not used as the risk level of a specific examination determined according to the patient's disease.
[0083] The patient-disease table 730 stores disease information. The disease information stored in the patient-disease table 730 is included in the authentication method selection information obtained in S501, and is stored in the patient-disease table 730 in S501. Figure 7 illustrates a case where the patient-disease table 730 includes a patient-disease ID as the primary key, and other columns include patient ID, patient name, age, gender, date, department, pre-operative examination, disease ID, and disease name. The disease-patient ID, one of the columns in the patient-disease table 730, is a composite key of disease ID and patient ID. Note that the disease-patient ID does not have to be included in the disease information. In this case, the disease-patient ID is created, for example, using patient ID and disease ID. In addition, the columns of the patient-disease table 730 may include the examination ID and examination name of the examinations the patient receives.
[0084] The Patient Disease Table 730 includes a column for "Preoperative Examination." Since the results of preoperative examinations affect the surgical procedure, they are considered highly important. Therefore, in Patient Disease Table 730, if "yes" is stored in the Preoperative Examination column, the risk level of that preoperative examination is maximized and set to "High." The Date and Time and Department columns in Patient Disease Table 730 serve to identify the surgical procedure.
[0085] The patient-specific test risk table 740 stores information including the degree of test risk for each patient and each type of test. In this embodiment, an example is given where the degree of test risk is determined based on at least one of the disease information and the test information. Specifically, in this embodiment, an example is given where the degree of test risk is determined based on the content of the test the patient undergoes, the patient's disease, and whether or not the test the patient undergoes is a pre-operative test. In addition, in this embodiment, an example is given where the information stored in the patient-specific test risk table 740 is determined based on the information stored in the default test risk table 710, the disease-test risk definition table 720, and the patient disease table 730.
[0086] Figure 7 illustrates a case where the patient-specific test risk table 740 includes a patient-test ID as the primary key, and other columns include patient ID, patient name, test ID, test name, and risk level. The patient-test ID, one of the columns in the patient-specific test risk table 740, is a composite key of patient ID and test ID. In this embodiment, we illustrate a case where the patient-specific test risk table 740 is created in S604. A specific example of how to create the patient-specific test risk table 740 will be described later.
[0087] The Risk Authentication Method Table 750 stores information including the patient's authentication method for each level of risk associated with the examination. The information stored in the Risk Authentication Method Table 750 is included in the authentication method selection information obtained in S501, and is stored in the Risk Authentication Method Table 750 in S501. Figure 7 illustrates a case where the Risk Authentication Method Table 750 includes the risk level as the primary key, and authentication policy and authentication method as other columns.
[0088] The risk authentication method table 750 is used by the authentication method selection unit 132 to determine the patient's authentication method according to the risk level of the examination. Figure 7 illustrates the case where the risk level is "low," the authentication policy is one-factor authentication based on "possession," and the authentication method is IC card authentication. Figure 7 also illustrates the case where the risk level is "medium," the authentication policy is two-factor authentication based on "possession" and "knowledge," and the authentication method is an authentication method that combines IC card authentication and date of birth authentication. Furthermore, Figure 7 illustrates the case where the risk level is "high," the authentication policy is two-factor authentication based on "possession" and "biometrics," and the authentication method is an authentication method that combines IC card authentication and fingerprint authentication.
[0089] By storing the above information in the Risk Authentication Method Table 750, when a patient undergoes a low-risk examination, the patient can be authenticated efficiently. On the other hand, when a patient undergoes a high-risk examination, a more reliable authentication can be performed for that patient. Generally, the more authentication methods there are, the higher the reliability of the authentication. Also, generally, biometric authentication is more reliable than knowledge and possession authentication. Furthermore, the "Guidelines for the Secure Management of Medical Information Systems, Version 5.1, Ministry of Health, Labour and Welfare, January 2021" provides guidelines on authentication for operators (staff and related parties) of medical information systems. These guidelines list "memory," "biometric information," and "physical media" as elements of authentication. The aforementioned "knowledge," "biometrics," and "possession" correspond to "memory," "biometric information," and "physical media," respectively.
[0090] As described above, two-factor authentication refers to a method of authentication that combines two independent factors. It is preferable to include authentication that combines multiple independent factors in a single authentication method, as this allows for more reliable authentication. However, for example, a single authentication method may include multiple authentications that belong to the same factor but use mutually different means to perform authentication (so-called multi-factor authentication such as two-step authentication). For example, a single authentication method may include multiple authentications that belong to the same factor, "knowledge," but differ only in the type of information checked during authentication. A concrete example of an authentication method in this case is an authentication method that uses password authentication and date of birth authentication.
[0091] Furthermore, the means used for authentication are not limited to means that differ only in the type of information to be verified during authentication. As mentioned above, in this embodiment, if at least one of the following differs—the type of information to be verified during authentication, the authentication algorithm, and the authentication hardware—then the means used for authentication are considered to be different from each other. Here, different authentication hardware means that the combinations of authentication hardware do not match perfectly. For example, when password authentication and date of birth authentication are performed, hardware including a computer 200 is used. When IC card authentication is performed, hardware including an IC card reader / writer and a computer 200 is used as the authentication hardware. When fingerprint authentication is performed, hardware including a fingerprint authentication device and a computer 200 is used. In such examples, the computer 200 is used regardless of whether password authentication, IC card authentication, or fingerprint authentication is performed. However, the combinations of authentication hardware do not match perfectly. Therefore, these authentication hardware are considered to be different. Furthermore, even if multiple authentication methods use the same hardware for authentication, if the algorithms used for authentication are different, the means used for authentication will be considered different from each other. For example, an algorithm that uses fingerprint information directly from a human finger and an algorithm that includes removing noise from fingerprint information from a human finger will be considered different algorithms for fingerprint authentication.
[0092] Furthermore, a single authentication method may include multiple authentications performed using the same means. For example, to prevent accidental authentication success, the user may be prompted to enter the same information two or more times for verification.
[0093] It should be noted that the content of the authentication policy and authentication method are not limited to those shown in Figure 7. The content of the authentication policy and authentication method may be determined, for example, according to the authentication policy established by each medical facility or the equipment of the authentication system that the medical facility possesses.
[0094] Furthermore, the column items in the default test risk table 710, disease-test risk definition table 720, patient disease table 730, patient-specific test risk table 740, and risk authentication method table 750 are examples only and are not limited to those shown in Figure 7.
[0095] Next, an example of the procedure in which the authentication method selection unit 132 selects a patient's authentication method using the authentication method database 134 in S604 will be described. The authentication method selection unit 132 extracts a patient record from the patient disease table 730. The patient is identified based on the patient ID obtained in S602. Figure 7 illustrates the case where a record for Taro Yamada, whose patient ID is "A0001", is extracted from the patient disease table 730. Based on the disease ID ("S0001", "S0002") or disease name in Taro Yamada's record, it is identified that Taro Yamada has hypertension and glaucoma.
[0096] Next, the authentication method selection unit 132 retrieves information on the risk level corresponding to the test ID obtained in S603 from the "risk level" column of the default test risk table 710. Figure 7 illustrates a case where the patient, Taro Yamada, has hypertension and glaucoma, and the tests corresponding to these diseases are blood pressure testing, vascular ultrasound testing, and intraocular pressure testing. Therefore, from the default test risk table 710, "low" is retrieved as the risk level corresponding to "K0001", "low" is retrieved as the risk level corresponding to "K0004", and "medium" is retrieved as the risk level corresponding to "K0005". Note that which tests a patient identified by a patient ID will undergo is determined, as mentioned above, for example, by associating the patient ID with the test ID obtained in S603.
[0097] Furthermore, the authentication method selection unit 132 obtains test information (test IDs) corresponding to the patient's disease information (information from the patient's record extracted from the patient disease table 730) from the disease-test risk definition table 720. Figure 7 illustrates the case where "K0001", "K0004", and "K0005" are obtained from the disease-test risk definition table 720 as test IDs for tests that Taro Yamada will receive. If there is no test information corresponding to the patient's disease information in the disease-test risk definition table 720, the acquisition of test information corresponding to the patient's disease information will not be performed.
[0098] Next, the authentication method selection unit 132 obtains the risk level of the test corresponding to the patient's disease information from the "risk level" column of the disease-test risk definition table 720. Figure 7 illustrates a case in which the following test risk levels are obtained from the disease-test risk definition table 720. Specifically, it illustrates a case in which "High" is obtained as the test risk level corresponding to "K0001", "High" is obtained as the test risk level corresponding to "K0004", and "High" is obtained as the test risk level corresponding to "K0005".
[0099] Here, the risk level of a test corresponding to the same test ID may differ between the risk level obtained from the default test risk table 710 and the risk level obtained from the disease-test risk definition table 720. In this case, the risk level obtained from the disease-test risk definition table 720 is used, rather than the risk level obtained from the default test risk table 710. Figure 7 illustrates the case where "High," stored in the disease-test risk definition table 720, is used as the risk level of the tests corresponding to the test IDs ("K0001", "K0004", and "K0005") that Taro Yamada receives.
[0100] Furthermore, if, among the patient records extracted from the patient disease table 730, there is a test ID associated with a disease ID in a record where "pre-operative examination" is yes, the importance of the examination identified by that test ID is high. Therefore, the authentication method selection unit 132 sets the risk level of the examination corresponding to that test ID to "high" if, among the patient records extracted from the patient disease table 730, there is a test ID associated with a disease ID in a record where "pre-operative examination" is yes. In this case, the risk level of the examination will be "high" regardless of the risk level of the examination obtained from the default test risk table 710 and the disease-test risk definition table 720. In Figure 7, there are no records where "pre-operative examination" is yes among the records of Taro Yamada extracted from the patient disease table 730. Therefore, as mentioned above, "high," stored in the disease-test risk definition table 720, is used as the risk level of the examinations corresponding to the test IDs ("K0001", "K0004", and "K0005") of the examinations that Taro Yamada will undergo.
[0101] Furthermore, the authentication method selection unit 132 may set the risk level of examinations received by patients with the same patient ID as the patient ID of a record where "Pre-operative examination" is yes, extracted from the patient disease table 730, to "High," regardless of the disease ID. In this way, for example, if a patient undergoing a pre-operative examination also undergoes examinations other than those considered to be of high importance in the default examination risk table 710 and the disease-examination risk definition table 720, the risk level of those examinations will also be set to "High." The patient disease table 730 may also have a column for information that identifies pre-operative examinations. For example, the patient disease table 730 may have a column for examination ID that identifies the examination device 101 that performs the pre-operative examination, and the date and time of the examination performed by the examination device 101. In this way, the authentication method selection unit 132 can identify the content of "Pre-operative examination" from the patient disease table 730. Furthermore, the authentication method selection unit 132 may set the risk level of examinations corresponding to the patient ID and examination ID in the record where "Pre-operative examination" is yes to "High." In this way, the risk level of a "preoperative examination" will be "high" regardless of whether or not it is considered a high-importance examination in the disease-examination risk definition table 720. Therefore, for example, even if a preoperative examination is one of the examinations other than those considered high-importance in the disease-examination risk definition table 720, the risk level of that examination can be set to "high". On the other hand, the risk levels of the remaining examinations (i.e., examinations other than preoperative examinations) among the examinations received by the patient identified by the patient ID will be determined based on the default examination risk table 710 or the disease-examination risk definition table 720, and may be something other than "high".
[0102] The authentication method selection unit 132 creates a patient-specific test risk table 740 based on the patient record information extracted from the patient disease table 730, the test ID obtained in S603, and the risk level determined as described above.
[0103] The patient-specific test risk table 740 thus created has the degree of test risk set for each patient and for each type of test. As mentioned above, the degree of test risk is determined based on, for example, the content of the test the patient receives, the content of the disease the patient has, and whether or not the test the patient receives is a pre-operative test. In this embodiment, we illustrate a case in which the degree of test risk is identified based on the information stored in the patient-specific test risk table 740.
[0104] The authentication method selection unit 132 creates a patient-specific test risk table 740 as described above. The authentication method selection unit 132 reads the test risk level stored in the patient-specific test risk table 740, which is associated with the test ID obtained in S603, from the patient-specific test risk table 740. This reading of the test risk level is performed for each test ID obtained in S603.
[0105] The authentication method selection unit 132 reads the authentication method stored in the risk authentication method table 750, which is associated with the risk level of the examination read from the patient-specific examination risk table 740. This reading of the authentication method is performed for each examination ID obtained in S603.
[0106] In Figure 7, the examination ID for the camera imaging examination is "K0003," and the risk level of this camera imaging examination is "low" (see Default Examination Risk Table 710). Also, the examination that patient Taro Yamada is receiving is not a pre-operative examination (see Patient Disease Table 730). Furthermore, the camera imaging examination (examination ID "K0003") is not stored in the Disease-Examination Risk Definition Table 720. Therefore, if the examination that Taro Yamada is receiving is a camera imaging examination, the risk (risk level) of the examination the patient is receiving is "low" (see Patient-Specific Examination Risk Table 740). In addition, the Risk Authentication Method Table 750 stores "IC card" as the authentication method for patients receiving examinations with a "low" risk level. Therefore, if the examination that Taro Yamada is receiving is a camera imaging examination, IC card authentication is selected as the authentication method.
[0107] In this embodiment, the authentication method selection unit 132 selects the patient authentication method in S604 as described above. If the information processing system 100 has multiple information terminals 102, the authentication method selection unit 132 individually selects the patient authentication method to be performed at each information terminal 102 in accordance with the patient authentication method selection request from each information terminal 102 in S601 as described above. The output unit 135 then transmits information indicating the patient authentication method selected by the authentication method selection unit 132 to the information terminal 102.
[0108] Returning to the explanation of Figure 6, in S605, patient authentication is performed. For example, in S604, the information acquisition unit 121 acquires information indicating the patient's authentication method transmitted from the authentication method server 103 (output unit 135). The authentication unit 122 authenticates the patient according to the patient's authentication method indicated in the information. If the patient's authentication method indicated in the information is an authentication method that requires multiple authentications, authentication is successful (authentication OK) if all authentications (the multiple authentications) are successful, and authentication fails (authentication NG) otherwise. The display unit 123 displays information indicating the authentication result by the authentication unit 122.
[0109] Next, in S606, the authentication result is notified. For example, the output unit 124 transmits information indicating the authentication result in S605 to the hospital information system 104. At this time, it is preferable that the information terminal 102 transmits to the hospital information system 104 the patient ID and the test ID of the test the patient will undergo, in addition to the information indicating the patient's authentication result.
[0110] Next, in S607, the authentication result is determined. For example, in S605, it is determined whether or not the patient has been authenticated (whether or not the authentication was successful). The determination in S607 is made, for example, by the user of the information terminal 102 (e.g., the examiner, etc.) and the user of the hospital information system 104 (e.g., users of the hospital administration, SEs, and medical personnel, etc.). For example, the user of the information terminal 102 determines whether or not the patient has been authenticated by checking the information indicating the authentication result displayed on the display unit 123 in S605. Also, for example, if the information indicating the authentication result is displayed on an office terminal (not shown) included in the hospital information system 104, the user of the office terminal determines whether or not the patient has been authenticated by checking the information. However, the subject of the determination in S607 is not limited to a user (person). The determination in S607 may be made, for example, by at least one of the information terminal 102 and the office terminal included in the hospital information system 104.
[0111] If, in S607, it is determined that the patient has been authenticated (successful patient authentication), then in S608, the examination is performed. For example, the examination device 101 performs the examination of the patient based on the examiner's operation of the examination device 101. For example, if the examination device 101 has a digital camera and the examination is a camera image examination, the examination device 101 acquires data as examination data, which includes image data including the affected area and data indicating the size of the affected area. The data indicating the size of the affected area and information about the scale on the subject of the image may be stored as image metadata. The output unit 113 of the testing device 101 then transmits the test data to the clinical laboratory information system 105.
[0112] The output unit 135 of the authentication method server 103 may also transmit information including the patient's test data, information indicating the patient's authentication method, and information indicating the patient's authentication result to the clinical laboratory information system 105. In this case, the clinical laboratory information system 105 may store the patient's test data, the information indicating the patient's authentication method, and the information indicating the patient's authentication result in a related manner. This allows for later tracking of the patient's authentication method for each patient and each test. Furthermore, the results of the tracking can be used as evidence of the patient's authentication. Once the processing of S608 is completed in this manner, the processing according to the flowchart in Figure 6 is completed.
[0113] In S607, if it is determined that the patient was not authenticated (patient authentication failed), the patient's identity is verified in S609. In S609, for example, an office terminal included in the hospital information system 104 obtains information indicating the patient's authentication result that was transmitted to the hospital information system 104 from the information terminal 102 (output unit 124) in S606. In S608, information is obtained indicating that the patient was not authenticated (patient authentication failed). The office terminal included in the hospital information system 104 displays information indicating that identity verification of the unauthenticated patient and re-registration of the patient's authentication information are required. Based on this display, manual identity verification is performed. Identity verification is performed using information that can reliably identify the person, such as date of birth, address, and identification documents.
[0114] Next, in S610, the authentication information is re-registered. For example, the information acquisition unit 131 acquires the authentication information of a patient whose identity has been verified through a user operation on the authentication method server 103. The authentication information management unit 133 stores the authentication information of the verified patient. If the authentication information management unit 133 has already stored the authentication information of the verified patient, it updates the authentication information of that patient to the latest information. As described above, by newly storing the patient's authentication information, if the reason for authentication failure was a deficiency in the authentication information, that deficiency can be corrected. Once the process in S610 is completed in this manner, the process shown in the flowchart in Figure 6 is finished.
[0115] Here, the authentication unit 122 may perform authentication for the same patient for multiple tests at once. For example, if multiple tests are performed on the same patient by multiple testing devices 101 in the same room, and the authentication method for the patient is the same for all of these tests, the authentication unit 122 may omit the authentication of the patient for all of these tests at once.
[0116] A concrete example of this process, which involves performing patient authentication for multiple tests simultaneously, will be explained with reference to Figure 7. In the example shown in Figure 7, the examinations that Taro Yamada undergoes, other than the camera imaging examination, are blood pressure measurement, temperature measurement, and vascular ultrasound examination (see Patient-Specific Examination Risk Table 740). The risk level for the blood pressure measurement, temperature measurement, and vascular ultrasound examinations that Taro Yamada undergoes is "low," which is the same as the risk level for the camera imaging examination. Therefore, the authentication method for Taro Yamada for the camera imaging examination is the same as the authentication method for Taro Yamada for the blood pressure measurement, temperature measurement, and vascular ultrasound examination, and is IC card authentication (see Risk Authentication Method Table 750).
[0117] Therefore, in S605, when the authentication unit 122 authenticates Taro Yamada for the camera image inspection, it also authenticates Taro Yamada for the blood pressure test, body temperature measurement, and vascular ultrasound examination, which are performed using the examination device 101 located in the same room as the examination device 101. Then, the processing in S606 to S608 is performed for the camera image inspection that Taro Yamada undergoes. After the processing according to the flowchart in Figure 6 is completed in this way, the processing according to the flowchart in Figure 6 is performed for the blood pressure test, body temperature measurement, and vascular ultrasound examination as described above. However, the authentication unit 122 performs the following processing between S603 and S604.
[0118] First, the authentication unit 122 determines whether or not Yamada Taro has been authenticated for the examination identified by the examination ID obtained in S603. If, as a result of this determination, Yamada Taro has not been authenticated for the examination identified by the examination ID obtained in S603, the process in S604 described above is performed. On the other hand, if Yamada Taro has been authenticated for the examination identified by the examination ID obtained in S603, the processes in S604 to S607 are omitted and the process in S608 is performed. In S608, an examination (blood pressure test, body temperature measurement, or vascular ultrasound examination) is performed by an examination device located in the same room as the camera image inspection device 101. Here, the presence of multiple examination devices 101 in the same room can be determined, for example, by the information terminal 102 obtaining information on the installation location of the examination device 101 used for each examination. For example, by adding a column for information on the installation location of the examination device 101 to the default examination risk table 710, the installation location of the examination device 101 and the examination ID may be stored in relation to each other. In this case, the information terminal 102 may obtain, for example, information about the installation location of each inspection device 101 by receiving it from the authentication method server 103.
[0119] The above is an example of an embodiment of the information processing system. The “Guidelines for the Secure Management of Medical Information Systems, Version 5.1, Ministry of Health, Labour and Welfare, January 2021” provides guidelines for authentication for operators (staff and related parties) who operate medical information systems. However, there are no provisions for patient authentication, and when confirming a patient, it is basically done by human verification, such as by speaking to them. Therefore, there is a risk of misidentification of a patient, for example, if there are patients with the same name, or if the patient or the person performing the verification mishears or misunderstands what the other person is saying. For example, in high-risk examinations for patients, such as invasive examinations or examinations of high importance whose results affect treatment plans, misidentifying a patient could lead to a serious accident. On the other hand, there are also examinations that pose a low risk to patients. If complex authentication is performed even for such examinations, there is a risk of increasing the burden of work required to authenticate patients and increasing the burden of information processing for patient authentication. Therefore, in this embodiment, the information processing system 100 selects a patient authentication method based on at least one of disease information and examination information. Therefore, it is possible to achieve both improved patient authentication accuracy and reduced burden associated with authentication.
[0120] As described above, this embodiment exemplifies the case of authenticating a patient undergoing an examination. Therefore, this embodiment exemplifies the case where the information determined according to the illness or injury of the person receiving the medical-related procedure is disease information, and the information determined according to the medical-related procedure the person receiving the medical-related procedure is examination information. However, the information processing system described in this embodiment may also authenticate persons receiving medical-related procedures other than examinations. For example, the information processing system described in this embodiment may authenticate a patient receiving at least one of surgery, treatment, diagnosis, and medication in lieu of or in addition to an examination. Furthermore, persons receiving medical-related procedures are not limited to patients (persons suffering from illness), but may be persons suffering from illness or injury (at least one of illness and injury). Also, persons receiving medical-related procedures (procedures performed in relation to medical care) are not limited to persons suffering from illness or injury. For example, persons receiving medical-related procedures may be persons undergoing regular checkups or health examinations, or persons undergoing clinical trials (e.g., clinical trials).
[0121] Furthermore, this embodiment illustrates a case where the degree of risk of an examination is determined based on the content of the examination the patient undergoes and the content of the patient's disease. In this case, the authentication method server 103 selects a patient authentication method for each patient based on both disease information and examination information. However, the patient authentication method may be selected based on only one of either the disease information or the examination information. For example, as mentioned above, the patient authentication method for pre-operative examinations is selected solely from the examination information. Also, for example, if the patient's disease is a specific disease (for example, a serious disease), an authentication method corresponding to a "high" degree of risk of the examination may be selected regardless of the examination the patient undergoes. In this case, the patient authentication method is selected solely from the disease information. Furthermore, this embodiment illustrates a case where the authentication method selection unit 132 identifies the degree of risk of an examination based on disease information and examination information. However, the degree of risk of an examination may be included in the patient's disease information, for example. In this case, the authentication method selection unit 132 may identify the degree of risk of an examination by extracting it from the disease information.
[0122] Furthermore, this embodiment illustrates a case where the authentication method is selected from multiple authentication methods based on the risks incurred by the patient as a result of the examination. However, by selecting the authentication method for each individual patient according to their circumstances, it is possible to differentiate the authentication method for patients who prioritize improved authentication accuracy and those who prioritize reducing the burden of authentication. Therefore, the patient's authentication method only needs to be selected from multiple authentication methods based on information determined for each patient undergoing the examination. For example, the patient's authentication method may be selected from multiple authentication methods based on the cost of the examination received by the patient, in addition to or in lieu of the risks incurred by the patient as a result of the examination. Also, as mentioned above, medical-related procedures are not limited to examinations. When the medical-related procedure is something other than an examination, information corresponding to that medical-related procedure is determined as information determined for each person receiving the medical-related procedure. For example, when the medical-related procedure is treatment, the patient's authentication method may be selected from multiple authentication methods based on at least one of the risks incurred by the patient as a result of the treatment and the cost of the treatment. The risks incurred by the patient as a result of the treatment may be determined, for example, according to the invasiveness of the treatment the patient receives. Furthermore, if the medical-related act is the administration of medication, the method of verifying the patient's identity may be selected from multiple verification methods based on at least one of the risks to the patient resulting from the medication and the cost of the medication. The risks to the patient resulting from the medication may be determined, for example, according to the severity of the side effects caused by the medication.
[0123] Furthermore, in this embodiment, the case is illustrated in which the testing device 101, information terminal 102, authentication method server 103, hospital information system 104, and clinical laboratory information system 105 are separated from each other and connected to each other via wired or wireless communication. However, this is not necessarily required. The functions of the testing device 101, information terminal 102, and authentication method server 103 may be located anywhere in the information processing system 100. For example, the functions of the information terminal 102 and the authentication method server 103 may be contained in the same enclosure (a single device). For example, the functions of the authentication method server 103 may be included as software in the information terminal 102. This is preferable when the information terminal 102 is a smart device. For example, since operations for communication with the authentication method server 103 become unnecessary, the usability for the user operating the information terminal 102 by holding it in their hand is improved. Also, the functions of the authentication method server 103 may be included as software in the hospital information system 104.
[0124] (Other examples) The present invention can also be realized by supplying a program that implements one or more of the functions of the above-described embodiments to a system or device via a network or storage medium, and by having one or more processors in the computer of that system or device read and execute the program. It can also be realized by a circuit (e.g., an ASIC) that implements one or more functions. Furthermore, the embodiments of the present invention described above are merely examples of how the invention can be implemented, and the technical scope of the invention should not be interpreted as being limited by them. In other words, the present invention can be implemented in various forms without departing from its technical concept or its main features. [Explanation of Symbols]
[0125] 100: Information processing system, 101: Inspection device, 102: Information terminal, 103: Authentication method server
Claims
1. An information processing system, A setting means for setting information regarding the risks incurred by a person receiving a medical-related procedure, based on at least one of the following: information determined according to the illness or injury of a person receiving a medical-related procedure, which is registered in the information processing system; and information determined according to the medical-related procedure that the person receiving the medical-related procedure receives. Based on information regarding the risks incurred by the person receiving the medical-related procedure, set by the setting means, a selection means selects an authentication method for the person receiving the medical-related procedure from among multiple authentication methods, An authentication means for authenticating a person receiving the medical-related procedure using the authentication method selected by the selection means, An information processing system characterized by having the following features.
2. The information processing system according to claim 1, characterized in that at least one of the plurality of authentication methods includes an authentication method that requires multiple authentications.
3. The information processing system according to claim 2, characterized in that the means used to perform at least two of the aforementioned multiple authentications are mutually different means.
4. The authentication means is included in each of the multiple devices, The information processing system according to any one of claims 1 to 3, characterized in that the selection means individually selects from a plurality of authentication methods the authentication method performed by the authentication means included in the device in response to a request from the device including the authentication means.
5. The information processing system according to any one of claims 1 to 4, further comprising a management means for managing information used for selecting the aforementioned authentication method.
6. The information processing system according to any one of claims 1 to 5, further comprising a storage means for storing in a storage medium, in relation to the following: information relating to a medical-related act performed on a person receiving the medical-related act; information relating to an authentication method used to authenticate the person receiving the medical-related act; and information relating to the authentication result of the person receiving the medical-related act.
7. The information processing system according to any one of claims 1 to 6, further comprising an output means that outputs information including the fact that if a person receiving a medical-related procedure is not authenticated by the authentication means, manual identity verification of the person receiving the medical-related procedure is required.
8. The information processing system according to any one of paragraphs 1 to 7, characterized in that the authentication means authenticates one of the two or more medical-related acts as an authentication for a person receiving a medical-related act, while omitting authentication for the other medical-related acts among the two or more medical-related acts.
9. The information processing system according to claim 8, characterized in that the two or more medical-related procedures are determined based on information determined for each person receiving the medical-related procedures.
10. The information processing system according to any one of claims 1 to 9, characterized in that the aforementioned medical-related activity includes an examination.
11. A setting step in which setting means sets information regarding the risks that will be incurred by the person receiving the medical-related procedure as a result of receiving the medical-related procedure, based on at least one of the following: information determined according to the illness or injury of the person receiving the medical-related procedure, which is registered in the information processing system; and information determined according to the medical-related procedure that the person receiving the medical-related procedure receives. The selection means includes a selection step in which, based on information regarding the risks incurred by the person receiving the medical-related procedure set in the setting step, the authentication method for the person receiving the medical-related procedure is selected from among multiple authentication methods, The authentication means includes an authentication step in which an authentication is performed using the authentication method selected in the selection step to authenticate the person receiving the medical-related procedure, An information processing method characterized by having the following features.
12. A program for causing a computer to function as each means of the information processing system according to any one of claims 1 to 10.
Citation Information
Patent Citations
Medical information provision system
JP2007188290A
Constant display type medical information display system
JP2012118782A
Imaging device, authentication method, and program
JP2017216005A