Methods, systems, and programs for providing medical services at online medical consultation facilities.
Patent Information
- Authority / Receiving Office
- JP · JP
- Patent Type
- Patents
- Current Assignee / Owner
- 金田 卓也
- Filing Date
- 2026-03-23
- Publication Date
- 2026-08-03
Smart Images

Figure 0007898793000001_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to a method, system, and program for providing medical services to users in facilities where online medical consultations can be received. In particular, in response to the amendment of the Medical Service Act to be implemented in April 2026, while meeting the legal requirements of online medical consultation receiving facilities (hereinafter referred to as "online consultation facilities"), it is related to a technology that integrally realizes device-independent BYOD support, compliance management, misrecognition prevention, fee separation, distribution among multiple parties, My Number linkage, nurse assistance, emergency response, security measures, automated notification and publication, application to mobile means, etc.
Background Art
[0002] In recent years, with the spread of online medical consultations, the opportunities for patients to receive online medical consultations at locations other than medical institutions have been increasing. Conventionally, it has been common for patients to receive consultations using their own smartphones or PCs at home or workplaces, but there have been issues such as ensuring privacy, instability of the communication environment, and concerns about information security.
[0003] To solve such problems, the installation of "online medical consultation receiving facilities" that provide dedicated booths or private rooms with ensured privacy has been promoted. However, since these facilities are not medical service-providing facilities but merely facilities that provide "consultation locations," appropriate displays and advertising regulations are required so that users do not misrecognize them as medical institutions.
[0004] With the amendment of the Medical Service Act implemented on April 1, 2026, online medical consultations and online consultation facilities are legally defined, and the following three main obligations are imposed. Notification obligation: Notify the prefectural governor, etc. of the location within 10 days after facility installation. Publication obligation: Publish the compliance information of the facility (cleanliness and safety, privacy isolation, information security measures). Compliance with standards: The administrator of the medical institution providing online medical consultations confirms the compliance of the facility, and if it is non-compliant, the medical consultation is terminated.
[0005] Furthermore, advertising regulations stipulate that online consultation facilities must clearly state that they do not provide medical care, and that misleading labeling is mandatory. In addition, it is recommended that facility usage fees and medical expenses be clearly separated and billed separately, and transparency in revenue sharing among multiple parties (medical institutions, platform operators, facility operators, etc.) is required.
[0006] In addition, a wide range of practical requirements have been outlined, including the use of online eligibility verification using My Number cards (for obtaining consent at home), the establishment of medical assistance by nurses and other medical professionals (D to P with N), securing an emergency response system for sudden changes in condition, and strengthening information security measures.
[0007] However, conventional technologies lacked a system that comprehensively met these legal requirements, requiring facility operators and medical institutions to take individual measures, resulting in an extremely high operational burden. [Overview of the Initiative] [Problems that the invention aims to solve]
[0008] The present invention was made to solve the problems of the prior art described above, and aims to provide a medical service delivery method, system, and program that comprehensively meets the legal requirements of online medical facilities, provides a device-independent and flexible medical consultation environment, and centrally realizes suitability management, prevention of misidentification, separation of expense items, distribution among multiple parties, linkage with My Number (social security number), nursing assistance, emergency response, security measures, automation of notification and publication, and application to means of transportation. [Means for solving the problem]
[0009] To achieve the above objective, the present invention provides a medical service provision method for establishing an online medical consultation at a medical consultation facility that provides a place for receiving online medical consultations, comprising the steps of: a server device acquiring suitability information relating to the medical consultation facility; the server device determining whether the suitability information meets predetermined suitability criteria; the server device permitting the establishment or continuation of an online medical consultation session if the determination is satisfactory, and restricting the establishment or continuation of an online medical consultation session if the determination is unsatisfactory; the server device displaying a misleading indication on the user terminal stating that the medical consultation facility is not a facility that provides medical care, and saving a consent log based on the consent operation for the indication; and the server device verifying the results of identity verification and / or insurance eligibility verification, and the terminal The method is characterized by including the steps of: obtaining at least one security attribute and restricting the establishment or continuation of the online medical consultation session if a predetermined condition is not met; the server device generating detailed data that categorizes accounting information related to the online medical consultation into medical expenses and non-medical expenses and presenting it to the user terminal, and saving a consent log based on the consent operation for said categorized details; the server device allocating at least a portion of the said expenses using the balance or usage limit related to the subscription contract, executing an additional charge or separate settlement if the balance or usage limit is insufficient, and saving the charge result as a charge ledger; and the server device causing the terminal to delete temporary cache or session-related data formed on the terminal side at the end of the session, or confirming the completion of the deletion, and saving a deletion trail log showing the result of the deletion.
[0010] Furthermore, the system of the present invention includes a patient consultation terminal, a brand owner terminal, a server terminal, a clinic terminal, a booth location provider terminal, and / or a facility management entity terminal, and performs the above method. Note that the brand owner terminal may be an optional element, and at least some of the platform operator, booth operator, clinic operator, and booth location provider may be the same entity.
[0011] Furthermore, the program of the present invention is a program for causing a computer to execute the above method. [Effects of the Invention]
[0012] According to the present invention, it is possible to provide a device-independent and flexible consultation environment while comprehensively satisfying the legal requirements for online consultation facilities (notification, publication, conformity management, misidentification prevention, expense item separation, etc.). Furthermore, because it enables real-time monitoring of conformity using sensor groups, mandatory display of misidentification prevention displays and obtaining consent, automation of subscription billing and distribution among multiple parties, eligibility verification through My Number linkage, nursing assistant task management, automatic notification in case of sudden changes, security profile verification, automation of notification and publication, application to means of transportation, and separate management of audit logs, the operational burden on facility operators and medical institutions can be significantly reduced, and patient safety and convenience can be improved. [Brief explanation of the drawing]
[0013] Figure 1 is a block diagram showing the overall configuration of a medical service provision system in an embodiment of the present invention. Figure 2 is a block diagram showing the internal configuration of the server terminal 100. Figure 3 is a block diagram showing the internal configuration of the receiving terminal 200. Figure 4 shows an example of the structure of a user database. Figure 5 shows an example of a brand database structure. Figure 6 shows an example of the structure of a clinic database. Figure 7 is a sequence diagram showing the overall processing flow. Figure 8 is a sequence diagram showing another example of the overall processing flow. Figure 9 is a sequence diagram showing the detailed processing flow. Figure 10 is a sequence diagram illustrating the subscription billing and multi-party distribution flow. [Modes for carrying out the invention]
[0014] 1. Overall System Configuration Figure 1 is a block diagram showing the overall configuration of a medical service provision system in an embodiment of the present invention. System 1 includes a patient terminal 200, a brand owner terminal 300, a server terminal 100, a clinic terminal 400, an SNS server 500, a sensor group 600, a PSP (payment service provider) 700, a facility operator terminal 800, and a booth installation location provider terminal 810.
[0015] The patient consultation terminal 200 is a fixed terminal installed at the online consultation facility, or a BYOD device such as a smartphone or tablet brought by the user. The brand owner terminal 300 is a terminal managed by the platform operator and is used for providing medical menus, accepting applications, managing advertisements, etc. The server terminal 100 is a control device that plays a major role in the present invention and oversees suitability management, misidentification prevention display control, accounting processing, distribution calculation, My Number linkage, nurse support management, emergency response, notification / publication management, audit log management, etc.
[0016] The clinic terminal 400 is a terminal used by medical institutions and is used for conducting online consultations, generating diagnostic information and prescriptions, and transmitting accounting information. The SNS server 500 is a server that distributes and collects medical questionnaire information. The sensor group 600 is a group of sensors that monitor the privacy status, cleanliness and safety status, and information security status within the facility. The PSP 700 performs payment processing and handles subscription balance management, additional charges, and refund processing. The facility operator terminal 800 is a terminal used by facility operators and is used for checking the facility's operating status and receiving revenue sharing. The booth installation location provider terminal 810 is a terminal used by stations, post offices, banks, convenience stores, commercial facilities, companies, local governments, and other installation location providers or facility managers and sends and receives at least part of the installation contract information, fee conditions, billing information, payment information, offsetting conditions, submitted documents, or evidence information. 2. Internal configuration of the server terminal
[0017] Figure 2 is a block diagram showing the internal configuration of the server terminal 100. The server terminal 100 includes a communication unit 110, a storage unit 120, and a control unit 130.
[0018] The communication unit 110 communicates with the receiving terminal 200, brand owner terminal 300, clinic terminal 400, SNS server 500, sensor group 600, PSP 700, facility operator terminal 800, and booth installation location provider terminal 810 via the network NW1.
[0019] The storage unit 120 includes a user database 121, a brand database 122, a clinic database 123, a conformity criteria database, a consent log database, a billing ledger database, a distribution ledger database, an audit log database, and the like. Furthermore, the storage unit 120 may also include a booth location provider database, a settlement rule database, a settlement ledger database, a contracting entity database, and an entity correspondence database. The settlement rule database holds information such as fee type, calculation criteria, payment direction, application period, minimum guaranteed amount, upper limit, lower limit, offsetting eligibility, and rule version information. The settlement ledger database may hold information such as total amount, deduction amount, offset amount, net payment amount, payee, payer, basis event identifier. Furthermore, the booth location provider database may hold information such as location provider identifier, location attributes, contract status, billing information, payee information, and welfare or attraction purposes. The contracting entity database may hold information such as identifier of the entity bearing the costs on behalf of the user, cost items to be borne, cost limits, application conditions, and settlement cycle. The aforementioned entity correspondence database may store combinations of booth operators, clinic operators, platform operators, booth location providers, and contracting entities, as well as identical entity flags, whether internal allocation is required, whether inter-entity payments can be omitted, and so on.
[0020] The control unit 130 includes an information reception unit 131, an information processing unit 132, an anti-misidentification display control unit 133, an accounting and billing management unit 134, an allocation and settlement management unit 135, a My Number cooperation unit 136, a nurse assistant management unit 137, an emergency response unit 138, a security verification unit 139, a data deletion management unit 140, a prescription and medicine locker management unit 141, a notification and publication management unit 142, an advertising compliance management unit 143, a remote operation management unit 144, a matching processing unit 145, a booth discovery processing unit 146, a means of transportation management unit 147, an audit log management unit 148, a subject response resolution unit 149, and a venue provider cooperation unit 150. The subject response resolution unit 149 may resolve the correspondence relationship between multiple subjects, replace the payment between the same subjects with internal allocation, or determine to omit the payment between subjects. The venue provider cooperation unit 150 may transmit and receive installation contract information, invoice information, payment information, offset conditions, settlement results, evidence information, etc. with the booth installation venue provider terminal 810. 3. Internal Structure of the Medical Examination Terminal
[0021] Figure 3 is a block diagram showing the internal structure of the medical examination terminal 200. The medical examination terminal 200 includes a communication unit 210, a display operation unit 220, a storage unit 230, and a control unit 240.
[0022] The communication unit 210 communicates with the server terminal 100 via the network NW1. The display operation unit 220 displays medical treatment menus, anti-misidentification displays, accounting information, etc. The storage unit 230 stores temporary cache data, which is automatically deleted after the medical treatment is completed. The control unit 240 receives the operations of the user and controls the communication with the server terminal 100. 4. Database Structure
[0023] Figure 4 shows an example of the structure of the user database. The user database 121 stores user IDs, names, dates of birth, genders, contact information, interrogation information, vital data, diagnosis results, prescription information, subscription contract information, etc.
[0024] Figure 5 shows an example of the structure of a brand database. Brand database 122 stores brand ID, brand name, services offered, list of affiliated medical institutions, distribution rules, advertising materials, approval status, etc.
[0025] Figure 6 shows an example of the structure of a clinic database. Clinic database 123 stores information such as clinic ID, medical institution name, medical specialty, operating status, available hours, whether or not emergency acceptance is possible, and whether or not My Number (social security number) eligibility verification is possible. 5. Compatibility management using sensor groups
[0026] Sensor group 600 includes the following sensors: Privacy sensors: Door opening / closing sensors, indoor noise sensors, and cameras (without facial recognition and designed for privacy) monitor the level of blocking of external views and sounds. Cleanliness and Safety Sensors: Disinfection logs, cleaning completion sensors, and temperature / humidity sensors monitor hygiene management status. Information security sensor: Monitors the encryption status of network communications, VPN connection status, secure boot status of terminals, and tamper detection status.
[0027] These sensor data are transmitted to the server terminal 100 in real time and used for suitability determination. 6. Misidentification Prevention Display Control
[0028] The server terminal 100 forces a large, highly visible misidentification prevention message (e.g., "This facility is not a medical facility. It provides a location for receiving online medical consultations") to be displayed in the center of the receiving terminal 200's screen, and obtains the user's consent. The consent is recorded using a checkbox and an electronic signature, encrypted, and stored in the consent log database.
[0029] Furthermore, the text-to-speech function ensures that misinterpretation prevention information is reliably conveyed to visually impaired and elderly individuals. This consent log is stored in a format that can be submitted during on-site inspections by prefectural governments. 7. Processing Flow (Figures 7 and 8)
[0030] Referring to Figure 7, the processing flow of a method for providing online medical consultations, executed by System 1 of this embodiment in which one or more brand owners, one or more clinics, and server terminal 100 cooperate, will be described.
[0031] First, as part of step S101, the user accesses the website of the brand owner terminal 300 using the web browser or application on each booth terminal 200, selects a desired diagnostic item (for example, the morning-after pill) from the medical treatment menu provided through the website, and submits a request to apply for an online medical consultation through a predetermined operation.
[0032] As part of step S102, when the brand owner terminal 300 receives an online medical consultation request from the booth terminal 200, it redirects (forwards) the access from the patient user booth terminal 200 to the SNS server 500 (for example, the server of the communication application).
[0033] Next, as part of step S103, the SNS server 500 sends an application acceptance message along with an input form for medical questionnaire information to the booth terminal 200, via the chat communication interface with the user displayed on the patient user booth terminal 200 as a screen for applying for online medical consultation.
[0034] Furthermore, before the start of the consultation, the booth terminal 200 transmits suitability information (sensor logs and checklist information such as shielding status, sound insulation status, door opening / closing, cleaning or disinfection performed, and terminal initialization completion) to the server terminal 100. The server terminal 100 permits the establishment of the online consultation session only if the suitability information meets the predetermined conditions. If the conditions are not met, the start of the consultation is suspended, and alternative means are offered, such as guidance to an alternative booth, booking for a later date, guidance to switch to an in-person consultation, or assistance in reconnecting after waiting for the communication status to be restored.
[0035] Furthermore, on the application screen or the screen before the start of treatment, a message stating that "this booth is not a facility that provides medical care" is displayed in a prescribed manner (for example, a large display in the center of the screen, audio guidance, a consent checkbox, etc.), and a user consent log is obtained and transmitted to and stored on the server terminal 100. In addition to the above misunderstanding prevention display, a set of explanatory items regarding conditions for switching to face-to-face treatment, consent regarding the presence of a third party, prohibition of recording and video recording, compliance matters such as updating the user terminal, and the sharing of security risks may be displayed in a prescribed manner, and an explanatory consent log based on the consent operation for this set of explanatory items may be stored in association with the version information of the displayed text.
[0036] As part of step S104, the SNS server 500 receives medical information (including the user's basic information) from the booth terminal 200. Here, the booth may also be equipped with measuring instruments such as a thermometer, blood pressure monitor, and pulse meter. If the patient user uses these to measure predetermined items, the communication device built into the measuring instrument can transmit the measured values obtained through the measurement to the SNS server 500 or server terminal 100, etc., via the booth terminal 200.
[0037] As part of step S105, the SNS server 500 or brand owner terminal 300 transmits the patient user's basic information and medical history information (which may include vital signs) to the server terminal 100.
[0038] As part of step S106, the information receiving unit 131 of the server terminal 100 receives the patient user's basic information and medical history information, and registers this information in the storage unit 120, such as the user data storage unit 121. The information processing unit 132 then determines an appropriate clinic to request treatment from based on the received medical history information, diagnostic items, or information from hospitals affiliated with the brand owner.
[0039] Furthermore, the server terminal 100 dynamically selects a clinic and records the assignment history based on the correspondence between booth IDs and clinic IDs (1:1, 1:N, N:1, N:N), medical services, region, time slot, physician availability, suitability score, etc. In this configuration, where the booth operator is a clinic, if the clinic (the first clinic) cannot cover the medical services (medical specialties, prescription availability, available time slots, etc.), the server terminal 100 can select another clinic (such as the second clinic) that is affiliated with the first clinic and have the user conduct an online medical consultation using that booth. For example, the server terminal 100 may search for affiliated clinics that can handle each medical service based on a brand database or a list of affiliated medical institutions, make an assignment considering availability, physician availability, suitability score, etc., and save the assignment history and selection basis as an audit log.
[0040] As part of step S107, the server terminal 100 transmits information to the selected clinic terminal 400, including basic patient user information, medical history information, diagnostic items, vital signs (if applicable), booth ID, etc., as information to instruct the clinic to perform medical treatment.
[0041] As part of step S108, the server terminal 100 sends screen information to the booth terminal 200 informing it that online medical consultation will begin.
[0042] As part of step S109, an online medical consultation is conducted between the clinic terminal 400 and the booth terminal 200. The online medical consultation may be conducted using a communication method (such as a video call) that includes at least real-time video and audio.
[0043] As part of the process in step S110, the clinic terminal 400 generates diagnostic information and accounting information based on the results of the online consultation with the patient user. The diagnostic information may include, for example, the diagnosis, the type, quantity, method of use, and dosage of the prescribed medication. The accounting information may include, for example, the total billing amount, which is the sum of the consultation fee and the cost of the prescribed medication.
[0044] As part of step S111, the clinic terminal 400 transmits diagnostic information and accounting information to the server terminal 100.
[0045] As part of step S112, the server terminal 100 receives diagnostic information and accounting information and registers them in the user data storage unit 121 and the clinic data storage unit 123, etc. The information processing unit 132 also determines the amount to be billed to the patient user based on the accounting information.
[0046] Furthermore, the server terminal 100 automatically categorizes accounting information into medical expenses (consultation fees, drug costs, etc.) and non-medical expenses (platform usage fees, booth usage fees, communication fees, etc.) and generates detailed statements.
[0047] As part of step S113, the server terminal 100 sends a message containing accounting information to the patient user booth terminal 200, for example, via the chat function of the SNS server 500.
[0048] Furthermore, the server terminal 100 checks whether a subscription contract exists and its balance, and if there is a shortfall, it executes an additional payment via the Payment Service Provider (PSP) 700. If the full amount is covered by the subscription, only the allocation process is performed.
[0049] Furthermore, as part of the process in step S114, the server terminal 100 sends a message to the patient user booth terminal 200 requesting the input of medication delivery address information, for example via the chat function of the SNS server 500, and obtains the delivery address information from the patient user. The server terminal 100 registers the obtained delivery address information in, for example, the user data storage unit 121, etc.
[0050] Furthermore, the server terminal 100 calculates the distribution or settlement amount to the brand owner, clinic, booth operator, booth location provider, and contracting entity based on the billing results, and sends distribution or settlement instructions to each entity. The distribution or settlement calculation is performed based on pre-set distribution or settlement rules (fixed percentage, variable percentage, hierarchical structure, combination of fixed and variable amounts, time-linked, linked to the number of units installed, linked to the number of uses, minimum guaranteed amount, upper limit amount, lower limit amount, bidirectional payment within the same period, net settlement after offsetting, etc.), and the calculation basis and distribution or settlement history are saved as audit logs. Here, the settlement or distribution rules may include monthly, initial lump sum, per-use, usage-based, revenue share, combination of fixed and variable amounts, revenue share with minimum guaranteed amount, settlement with upper or lower limit amount, prepayment, post-payment, periodic settlement, and any combination thereof. Furthermore, if multiple settlement relationships with conflicting payment directions coexist within the same settlement period, the server terminal 100 may calculate the settlement amount for each payment direction, then calculate the net payment amount by deduction, offsetting, or net calculation, and record it in the settlement ledger. In addition, if a company, local government, nursing care facility, booth installation location provider, or other contracting party bears all or part of the non-medical expenses on behalf of the user, they may bill the user or the other contracting party for the remaining amount after deducting such burden.
[0051] As part of step S115, the server terminal 100 provides the online pharmacy with information about the prescription issued by the clinic's doctor, and has the medication delivered to the delivery address entered by the patient user.
[0052] Figure 8 is a sequence diagram showing the detailed processing flow from step S109 (online medical consultation implementation) onwards in Figure 7. Figure 8 shows the detailed message exchange between each entity: booth terminal 200, brand owner terminal 300, clinic terminal 400, SNS server 500, and server terminal 100, in chronological order.
[0053] As part of step S201, the user initiates a medical consultation application via booth terminal 200.
[0054] As part of step S202, the booth terminal 200 accesses the website of the brand owner terminal 300 and performs a redirect process.
[0055] As part of step S203, the SNS server 500 displays the application screen and sends the medical questionnaire input form to the booth terminal 200.
[0056] As part of step S204, the user enters basic information (name, date of birth, contact information, etc.) and medical history information (chief complaint, symptoms, medical history, etc.).
[0057] As part of step S205, the booth terminal 200 transmits basic information and medical questionnaire information to the server terminal 100. In some cases, vital data (body temperature, blood pressure, pulse, etc.) obtained from the measuring device is also transmitted at this time.
[0058] As part of the process in step S206, the server terminal 100 registers the received basic information and medical questionnaire information in a database (user data storage unit 121, etc.) and sends it to the selected clinic terminal 400 for reference.
[0059] As part of step S207, the clinic terminal 400 refers to the basic information and medical history information and sends medical instructions (permission to start treatment, pre-confirmation items, etc.) to the server terminal 100.
[0060] As part of step S208, the server terminal 100 sends a medical consultation start notification to the booth terminal 200, informing it that preparations for establishing the online medical consultation session are complete.
[0061] As part of step S209, an online medical consultation (including at least real-time video and audio communication) is conducted between the user (patient) and the clinic (doctor).
[0062] As part of the process in step S210, the clinic terminal 400 generates diagnostic information (diagnosis, prescription details, medical findings, etc.) and accounting information (billing amounts for medical fees, drug costs, etc.) after the medical consultation is completed, and sends them to the server terminal 100.
[0063] As part of step S211, the server terminal 100 sends the received diagnostic information and accounting information to the SNS server 500 and prepares to notify the user.
[0064] As part of step S212, the SNS server 500 sends diagnostic information and accounting information to the booth terminal 200 so that the user can view it on the chat interface.
[0065] As part of step S213, the server terminal 100 registers the diagnostic information and accounting information in the database (user data storage unit 121, clinic data storage unit 123, etc.) and saves it as history.
[0066] As part of step S214, the server terminal 100 sends accounting information to the brand owner terminal 300 and performs accounting processing (charging, distribution calculation, etc.).
[0067] As part of step S215, the server terminal 100 sends accounting information (itemized details, subscription allocation results, whether or not additional payments were made, etc.) to the booth terminal 200.
[0068] As part of step S216, the booth terminal 200 completes the accounting process and displays accounting information (billing amount, payment completion notification, receipt, etc.) on the screen for the user. At this point, the user has completed the entire flow from medical treatment to payment.
[0069] The detailed processing flow (S201 to S216) shown in Figure 8 provides a more concrete extension of the overall flow in Figure 7, clarifying the timing and content of message exchanges between each entity. This provides design guidelines for implementing the system's operation. 8. Details of adaptive gate control (Figure 9)
[0070] Figure 9 is a functional flowchart illustrating the management concept of consultation gate control and advertising misrepresentation prevention display using suitability information for online medical consultation facilities.
[0071] In step S901, the user selects a medical treatment menu via booth terminal 200 and begins the application for online medical consultation.
[0072] In step S902, the booth terminal 200 displays a misidentification prevention UI (UI-9A) and explicitly indicates that "this booth is not a facility that provides medical care."
[0073] In step S903, the user's consent operation is obtained, and the consent log is saved to DB-9D in the server terminal 100.
[0074] In step S904, the sensor group 600 acquires environmental compatibility information within the booth (illuminance, noise level, door open / closed status, shielding status, cleaning status, terminal initialization status, etc.) in real time and transmits it to the server terminal 100.
[0075] In step S905, the server terminal 100 compares the received conformance information with the conformance criteria stored in DB-9C and performs a conformance determination.
[0076] In step S906, the gate control unit of the server terminal 100 decides whether or not to establish a medical session based on the results of the compatibility assessment. If the assessment result is "permission," the medical session is started; if it is "rejection" or "failback," alternative instructions are presented.
[0077] In step S907, if the judgment result is "permission", the server terminal 100 requests the clinic terminal 400 to establish a medical session. If the judgment result is "rejection", UI-9B is displayed to the booth terminal 200, offering alternative means such as guidance to an alternative booth, making a reservation for a later date, guidance to switch to an in-person consultation, or assistance in reconnecting after waiting for the communication status to recover.
[0078] In step S908, the server terminal 100 saves all processing events (application, consent acquisition, sensing, judgment result, alternative guidance, etc.) as audit logs to DB-9E.
[0079] The exchange of fees between booth operators, booth location providers, clinics, platform operators, contracting parties, and users may include at least the following two patterns: (Pattern 1: Payment from booth operator to booth location provider) A portion of the revenue earned by the booth operator (booth usage fees, a portion of platform usage fees, advertising revenue, etc.) is paid to the booth location provider (businesses such as train stations, post offices, banks, and convenience stores) as compensation for providing the location. Payment methods include monthly fees, per-use fees based on the number of uses, revenue-sharing linked to sales, and any other combination. (Pattern 2: Payment from booth location provider to booth operator) The booth location provider (company, event organizer, etc.) pays fees to the booth operator for purposes such as attracting visitors, providing ancillary services, and employee welfare. Payment methods include monthly payments, initial lump sum payments, per-use fees based on the number of uses, usage-based revenue sharing linked to sales, and other arbitrary combinations. Each of the above patterns may coexist within the same contract period, and the server terminal 100 may calculate the settlement amount corresponding to both payment directions, then perform deductions, offsets, or net calculations to calculate the net payment amount and record it in the settlement ledger. Furthermore, each of the above patterns is applicable to both "a scenario where the booth operator also operates the clinic" and "a scenario where the booth operator and the clinic are separate entities," and is also applicable to scenarios where there are five or more independent platform operators. The entity correspondence database may record the combination of entities, the same entity flag, whether internal allocation is required, and whether inter-entity payments can be omitted. Furthermore, a system may be adopted in which a company, local government, nursing care facility, booth installation location provider, or other contracting party bears all or part of the non-medical expenses on behalf of the user, and the amount borne and settlement relationship may be maintained in a settlement rule database. Furthermore, this method is also applicable when the booth operator and the booth location provider are the same entity, or when the platform operator and the booth operator or clinic operator are the same entity. The server terminal 100 may suppress inter-entity payments based on the entity correspondence database and replace them with recordings in the internal allocation ledger. The settlement rule database may hold calculation criteria such as time-linked, operating time-linked, number of installed units-linked, occupied area-linked, number of reservations-linked, number of completed consultations-linked, and number of visitors-linked.
[0080] Figure 10 is a flowchart illustrating the processing concepts of subscription billing and multi-party distribution (revenue sharing). While this example refers to subscription billing, it is not limited to this. The collection method for service usage fees provided by this system and the distribution method among the relevant parties are not limited to subscription, flat-rate, usage-based, per-use billing, or other specific methods. Any pricing and distribution system, either alone or in combination of multiple methods, can be adopted. Figure 10 is a conceptual diagram showing representative examples of subscription billing and multi-party distribution. For the sake of clarity, all or part of the processing related to settlement instructions to the booth location provider terminal 810, settlement requests or payment information from the booth location provider terminal 810, and the calculation and recording of the net payment amount after offsetting when both payment directions coexist within the same settlement period, may be executed as the same or equivalent processing as steps S1010 to S1012, even if not explicitly shown in Figure 10. Furthermore, in the implementation corresponding to Figure 10, the booth location provider terminal 810 may send settlement requests, billing information, payment information, offsetting conditions, and evidence information to the server terminal 100, and the server terminal 100 may send settlement instructions, payment instructions, offsetting result notifications, or net payment amount notifications to the booth location provider terminal 810.
[0081] First, in step S1001, after the medical consultation is completed, the booth terminal 200 transmits accounting information to the server terminal 100. In step S1002, the billing management unit of the server terminal 100 analyzes the received accounting information and performs expense item separation processing. Specifically, the total billed amount is automatically divided into medical expenses (consultation fees, drug costs, etc.), platform usage fees, booth usage fees, value-added service fees, etc.
[0082] In step S1003, the server terminal 100 displays UI-10A to the booth terminal 200, presenting the user with a detailed breakdown of expenses by category.
[0083] In step S1004, the booth terminal 200 displays UI-10A and obtains the user's consent to the expense item separation.
[0084] In step S1005, the user's consent log is sent to the server terminal 100.
[0085] In step S1006, the server terminal 100 refers to the subscription contract information stored in DB-10G and confirms the user's contract type, balance, expiration date, etc.
[0086] In step S1007, if the server terminal 100 has a shortfall in the subscription balance, it sends an additional payment request to the PSP 700.
[0087] In step S1008, the settlement result is received from the PSP700.
[0088] In step S1009, the server terminal 100 updates the billing ledger of DB-10F and saves records of subscription balance allocation and additional settlement.
[0089] In step S1010, the distribution and settlement management unit 135 of the server terminal 100 performs a dynamic distribution calculation or settlement calculation. This calculation applies distribution rules according to the correspondence between brands and clinics, and booths and clinics (1:1, 1:N, N:1, N:N), and calculates the distribution amount, settlement amount, deduction amount, offset amount, or net payment amount to each party.
[0090] In steps S1011a, S1011b, S1011c, and S1011d, the server terminal 100 sends distribution or settlement instructions to the clinic 400, brand owner 300, booth operator 800, and booth location provider terminal 810, indicating the respective distribution or settlement amounts. These distribution instructions are shown by thick arrows in Figure 10 to indicate that they are important processes. Here, if the brand owner and booth operator are the same operator, inter-entity payments may be omitted based on the entity correspondence database and replaced with an internal allocation ledger. Similarly, if the booth operator and the provider of the booth location are the same entity, or if the booth operator and the clinic operator are the same entity, inter-entity payments may be omitted and replaced with an internal allocation ledger.
[0091] In step S1012, the server terminal 100 records the distribution result, settlement result, offsetting result, net payment amount, payment direction, and underlying event identifier in the distribution ledger and / or settlement ledger of DB-10H.
[0092] In step S1013, the server terminal 100 saves the audit log of all events to DB-10I.
[0093] In steps S1014 and S1015, if the refund conditions are met, such as when the medical treatment is not completed or is interrupted, the server terminal 100 performs a refund condition check and, if necessary, coordinates with the PSP700 to perform the refund process.
[0094] In step S1016, if the refund process is executed, the server terminal 100 displays UI-10E to the booth terminal 200 to notify the user of the refund result. 10. Other Embodiments
[0095] Although the above embodiments mainly described cases where the booth is a fixed facility, the present invention is also applicable to booths installed on mobile vehicles (vehicles, buses, aircraft, ships, etc.) or booths installed as part of a public facility (stations, airports, schools, sports facilities, etc.).
[0096] Furthermore, in addition to the sensor group 600, it is also possible to use other means of acquiring conformity information, such as the results of periodic audits by booth operators or third-party organizations, user feedback, or the results of analysis of automatically captured images.
[0097] Furthermore, the distribution rules are not limited to fixed percentages; it is also possible to apply dynamic distribution rules that vary depending on the treatment menu, time of day, region, user attributes, frequency of use, etc.
[0098] In the above embodiment, the entity operating the brand owner terminal 300 (hereinafter referred to as the "brand owner") and the entity installing or operating the online consultation facility (booth) (hereinafter referred to as the "booth operator") may be different entities or the same entity. For example, this includes a configuration in which the brand owner installs and operates the booth itself, or a configuration in which the booth operator also handles brand management.
[0099] Furthermore, although the PSP (Payment Service Provider) 700 was exemplified as an external service provider in the above embodiment, the present invention is not limited thereto. For example, some or all of the payment processing functions performed by the PSP 700 may be implemented as functions of the server terminal 100, or as functions of the brand owner terminal 300 (or as system functions managed by the brand owner). In other words, the PSP 700 can be included as a logical functional block.
[0100] Furthermore, users can search for and reserve multiple on-site medical facilities (booths) using an application installed on their user terminal (e.g., a smartphone or tablet) or a web application. For example, the user terminal sends a search request to the server terminal 100 using at least one of the following as search criteria: medical treatment items, the user's current location information (which may include GNSS, base station information, or user-inputted location), the user's destination information, and medical treatment costs (which may include estimates or upper limits). The server terminal 100 can extract candidate booths by referring to a database that stores booth information (location, available medical treatment menus, price information, operating entity, etc.) and a database that stores operating status (reservation slots, downtime information, communication status, suitability status, etc.), and return the extraction results to the user terminal. The server terminal 100 may also use the booth discovery processing unit 146 and / or matching processing unit 145 to narrow down candidate booths, determine their order, and present alternative candidates according to the search criteria.
[0101] The user terminal application can display, as search results, at least the availability status (which may include available reservation slots and estimated waiting times), equipment information (e.g., presence or absence of measuring instruments, communication quality indicators, privacy protection measures, accessibility equipment, etc.), and evaluation information (which may include reviews, satisfaction ratings, or indications regarding the suitability of the facility) for each candidate booth. For example, the server terminal 100 can integrate reservation slot information and operational status information received from the facility operator terminal 800, environmental information received from the sensor group 600 (shielding, sound insulation, cleanliness, safety, security status, etc.), and evaluation information based on past usage logs or feedback to generate display data for each candidate booth and distribute it to the user terminal. When a user confirms a reservation, the user terminal sends a reservation confirmation request to the server terminal 100, and the server terminal 100 may lock the reservation slot for the target booth for a predetermined time to prevent duplicate reservations, while recording the reservation ledger (reservation ID, booth ID, user ID or temporary ID, medical treatment items, cost conditions, consent status, etc.) in the storage unit 120.
[0102] Furthermore, online consultation facilities (booths) are not medical facilities, but rather facilities that provide a place to receive online medical consultations, and are therefore positioned under the system as such. For this reason, from the perspective of preventing misunderstanding, it is desirable to clearly indicate to users in a way that they can understand that "this is not a facility that provides medical care" and to obtain the prescribed consent. For example, the misunderstanding prevention display control unit 133 or the advertising compliance management unit 143 of the server terminal 100 may force the display of a misunderstanding prevention display on the screen of the user terminal or booth terminal 200 before the reservation is confirmed and / or before the consultation begins, obtain consent based on checkbox operation, electronic signature, or one-time code, and encrypt and store the consent log (date and time of consent, version of the displayed text, booth ID, user identifier, terminal identifier, etc.) in the consent log database. In addition, to enhance auditability, the consent log may be accompanied by tamper detection information such as a timestamp and / or hash chain.
[0103] Furthermore, in order to publish suitability information for on-site consultation facilities (booths) (e.g., cleanliness and safety, ensuring privacy as a space isolated from the outside, compliance with information security measures, etc.) as information that can help users make their selections, the server terminal 100 may generate public data (which may include a public checklist, suitability status, confirmation date and time, confirmation body, version information, etc.) based on checklist information, sensor information, or audit information, and make it viewable via a website, QR code, or application screen. For the purpose of preventing tampering and ensuring accountability, the public data may be given an electronic signature, hash, or timestamp, and the public data and audit data may be managed separately. Furthermore, the server terminal 100 may exclude booths whose suitability assessment results do not meet predetermined conditions from search results, or perform gating processing that restricts the start of medical treatment even after a reservation has been confirmed.
[0104] Furthermore, if notification is required within a specified period regarding the establishment, suspension, resumption, abolition, or changes to the establishment details of an on-site consultation facility (booth), the server terminal 100 may manage notification details such as the installer information, facility name, installation location, drawing information, operational contact information, and collaborating medical institution information as master data, and may support the recording of change history, deadline management (including alert notifications), and the generation of notification documents (including form data conforming to standard formats).
[0105] Regarding accounting and billing, it is desirable that expenses related to the use of the online consultation facility (booth) (which may include location provision fees, terminal usage fees, communication fees, etc.) and medical expenses (consultation fees, drug fees, etc.) be presented separately from the perspective of preventing user misunderstanding and ensuring transparency. For example, the accounting / billing management unit 134 and distribution / settlement management unit 135 of the server terminal 100 may analyze the accounting information received from the medical institution terminal 400, generate detailed data that is automatically separated into medical expenses and non-medical expenses, present it to the user terminal or booth terminal 200, and obtain and store a user consent log for said details. Furthermore, the payment function can be implemented (logically embedded) as a function of the server terminal 100 and / or brand owner terminal 300, in addition to being linked with an external PSP 700. In addition, events such as separated details, consent, payment, and refund may be stored as a billing ledger and audit log. A system may be adopted in which a company, local government, nursing care facility, booth installation location provider, or other contracting party bears all or part of the non-medical expenses on behalf of the user, and the amount borne, the eligible expense items, the application conditions, and the settlement relationship may be maintained in a settlement rules database. Furthermore, events such as itemized details, consent, settlement, refund, distribution, settlement, and offsetting may be stored as a billing ledger, settlement ledger, and audit log. Furthermore, the settlement relationship includes payments from the booth operator to the booth location provider, payments from the booth location provider to the booth operator, and the coexistence of these bidirectional payments within the same period. The server terminal 100 may calculate the net payment amount based on the fee type, calculation criteria, payment direction, applicable period, minimum guaranteed amount, upper limit amount, lower limit amount, offsetting eligibility, rule version information, and contracting party burden information.
[0106] Furthermore, in configurations where an online consultation facility (booth) is co-located with or linked to a pharmacy, a neutral user interface for pharmacy selection may be implemented to prevent users from being unfairly directed to a particular pharmacy. For example, the server terminal 100 may apply a presentation logic based on neutral criteria such as geographical proximity, business hours, delivery availability, or user preference to the list of candidate pharmacies presented to the user terminal, suppressing unfair priority displays based on advertising or vested interests, and saving the basis for presentation and user selection logs as audit logs.
[0107] As described above, the present invention conforms to the institutional requirements of online medical facilities (booths) and integrates the following functions, centered on the server terminal 100: user-based booth search and reservation, misidentification prevention display and consent acquisition, generation, publication and gating of suitability information, expense item separation and distribution, and logical inclusion of payment functions. Furthermore, it integrates bidirectional settlement among multiple entities, including booth installation location providers, contracting entity burden, net settlement after offsetting, and substitution with internal allocation when the entities are the same.
[0108] Furthermore, in online consultation facilities, the system is not limited to built-in terminals such as booth terminals 200, but may also adopt a configuration in which user-provided terminals are used as the primary operating terminal (so-called BYOD configuration). Even in this case, the server terminal 100 can perform control and record-keeping related to identity verification, misidentification prevention display, privacy assurance, and information security assurance, regardless of the terminal configuration. For example, the server terminal 100 may request the user terminal to transmit attestation information indicating the terminal's security status (OS version, encryption status, tamper detection, VPN connection, etc.), and if the predetermined conditions are not met, it may restrict the start of consultation or display a message prompting the user to switch to booth terminal 200.
[0109] Furthermore, the institutional requirements for legal compliance (for example, the confirmation of the suitability of on-site medical facilities by the medical institution administrator and the suspension of medical services in the event of non-compliance) can be implemented as functional requirements of a compliance management system centered on the server terminal 100. For example, the server terminal 100 may be equipped with a suitability standard database and checklist version management and may integrally perform (i) documentation of confirmation trails, (ii) management of periodic confirmation schedules, (iii) remediation workflows when non-compliance is detected (assignment of corrective tasks to the facility operator terminal 800, collection of proof of completion of corrective actions, etc.), and (iv) preservation of audit logs. In addition, the confirmation trails may be separated into public data and audit data, and tamper detection information (hash, signature, timestamp, etc.) may be added.
[0110] Regarding cost transparency and separate billing, the server terminal 100 may implement a mechanism to separate medical fees (medical fees billed by medical institutions) and facility usage fees, etc. (non-medical expenses related to the operation of the online consultation facility) to prevent misunderstandings while retaining records of explanation, consent, and billing. For example, the server terminal 100 may present an estimated cost range at the time of booking, present a finalized breakdown after the consultation is confirmed, and acquire a consent log for each presentation event and save it in the billing ledger and audit log. Furthermore, if the refund conditions are met (e.g., communication failure, cancellation due to failure to meet compliance requirements), the refund determination and saving of the refund log may be automated.
[0111] To comply with regulations on pharmacy guidance, when providing pharmacy guidance from an online consultation facility, the server terminal 100 may implement a neutral route that suppresses guidance to specific pharmacies. For example, the presentation logic may use explainable criteria such as geographical proximity, business hours, availability of stock or delivery, and user preferences, and the basis data for determining the presentation order (input conditions, weights, candidate set, output order) can be saved as a log and used for future audits.
[0112] Based on the above additions, compliance controls (conformity verification, prevention of misidentification, cost transparency, audit logs, etc.) that meet the institutional requirements of on-site medical facilities can be implemented primarily on the server terminal 100, regardless of the terminal configuration (booth terminal 200 or user terminal), contributing to reduced operational burden and supervisory risk under the regulatory environment to be implemented in 2026.
[0113] (Example of input / output data for search and reservation) The server terminal 100 may provide a search interface (e.g., an API in the application layer or a communication protocol for a web application) for receiving booth search requests from user terminals. For example, the search request data that a user terminal sends to the server terminal 100 may include at least one of the following: (a) information identifying the medical item (medical menu ID, medical department code, etc.), (b) the user's current location information (latitude and longitude, positioning accuracy, means of acquisition, etc.), (c) the user's destination information (destination coordinates or destination area ID), and (d) cost conditions (maximum amount, desired price range, whether or not expenses are separated, payment method, etc.). In addition to these, it may also include: (e) desired time slot (desired start time, duration, priority), (f) accessibility requirements (wheelchair accessible, voice guidance, subtitles, etc.), (g) terminal attributes and security attributes (terminal type, OS version, encryption status, VPN connection status, attestation results, etc.), and (h) user identifier or temporary identifier (anonymized ID, session ID, etc.). Based on these inputs, the server terminal 100 may extract candidate booths using the booth discovery processing unit 146 and / or matching processing unit 145 and return search response data to the user terminal. The search response data may include, for example, for each candidate booth: (i) booth ID and location information, (j) distance or estimated time required, (k) availability (time slots for available reservations, locked status, estimated waiting time, etc.), (l) equipment information (presence or absence of measuring instruments, communication quality indicators, privacy protection measures, accessibility equipment, etc.), (m) suitability status (suitable / conditionally suitable / unsuitable, confirmation date and time, checklist version, etc.), (n) guidance information regarding misidentification prevention displays, (o) cost display (distinction between medical and non-medical expenses, estimated range, additional cost conditions, etc.), (p) evaluation information (score, number of reviews, etc.), (q) reference information to publicly available data (URL or QR code data), and (r) justification information (explanatory reasons such as "close distance," "meets desired cost conditions," or "updated suitability"). Furthermore, when a user confirms a reservation, the user terminal sends a reservation confirmation request (including the reserved booth ID, reservation slot, medical treatment items, cost conditions, consent status, etc.) to the server terminal 100, and the server terminal 100 may record the request details, lock processing results, and a reference to the consent log in the reservation ledger DB and audit log DB.
[0114] (Example of field differences between publicly available data and audit data) The server terminal 100 may generate public data for user selection and audit data for audit and accountability from the same source data, while separating the field configuration and access control for the conformity and operational information of the on-site medical facility (booth). For example, fields to be included in the public data may include (a) booth identification information (booth ID or public facility number), (b) conformity status (may include conformity / non-conformity indications by category such as cleanliness / safety, privacy, security), (c) confirmation date and time (last confirmation date and time, next confirmation scheduled, etc.), (d) checklist version information (version number, identifier of applicable standards, etc.), (e) user notes (summary of misleading display, terms of use, summary of emergency contact information, etc.), (f) summary of cost display (disclosure policy for medical and non-medical expenses, advance disclosure policy, etc.), and (g) tamper-proof information (hash of public data, electronic signature, timestamp, etc.), while audit data may include The fields to be included may include: (h) original checklist form (answers to questions, reference to attached documents, inputter, input time, etc.), (i) raw or near-raw data from sensor group 600 (time-series logs, thresholds, basis for judgment, missing information, etc.), (j) internal results of conformity judgment (version of judgment algorithm, weights, rule application history, etc.), (k) corrective action workflow history (non-conformity detection, corrective task assignment, completion trail, re-judgment results, etc.), (l) consent log reference (reference ID for misidentification prevention consent, expense item separation consent, etc.), (m) event log reference for reservations, billing, refunds, etc., (n) access log (who accessed or updated when), and (o) hash chain or signature chain information for evidence preservation. Furthermore, the server terminal 100 may provide public data to user terminals via URL or QR code, and apply access control to limit the provision of audit data to authorized entities (e.g., healthcare administrators, supervisory bodies, or facility operators).
[0115] (Automatic scanning of advertising materials and detection of prohibited content) The server terminal 100 may acquire advertising materials or display materials (which may include web pages, image data of print media, signage display data, etc.) from the advertising compliance management unit 143, analyze the text and / or images contained in the materials, and detect expressions that could cause misunderstanding that the online consultation facility is a facility that provides medical care, or prescribed prohibited expressions. For example, based on the detection results, the server terminal 100 may execute a workflow to return, request corrections to, or approve the materials, and save the approval results and reasons for return as audit logs.
[0116] (Generation, review, and distribution of facility names) The server terminal 100 may perform a conformity check on candidate names for on-site medical facilities based on name review rules (for example, whether the name contains words that could cause misunderstanding as a medical institution, whether the name can be combined with specified words, whether the name conflicts with similar names, etc.). Furthermore, based on the conformity check results, the server terminal 100 may approve or reject the candidate names, and reflect the approved facility names in signage, map displays, search result displays, and distribution targets such as public data. This review history may be saved as an audit log including the applicant, review date and time, applicable rule version, and approval status.
[0117] (Deadline management, phased notification, and submission trail management for notification procedures) The server terminal 100 may, triggered by the Notification and Publication Management Department 142, start counting down the deadline for notification procedures that must be carried out within a predetermined period, based on events related to the establishment, suspension, reopening, abolition, or changes to the establishment details of a medical facility. The server terminal 100 may also output alert notifications to multiple recipients, such as the person in charge, the facility operator headquarters, or the legal department, in stages as the deadline approaches. Furthermore, the server terminal 100 may store the submission evidence (which may include the reception number, copy data, and a copy of the transmission completion screen) obtained after the notification is submitted, linked to the notification event and the facility master, and make it available for reference as an audit log.
[0118] (Linking parking locations, travel schedules, and notifications for mobile or on-site medical consultation facilities) In an embodiment where the on-site medical facility is installed in a mobile vehicle or the like, the server terminal 100 may manage schedule information for parking locations and planned patrol areas using the mobility management unit 147, generate change differences in the notification document data in response to changes in the schedule information, and perform deadline management and submission trail management.
[0119] (Facility terminal completion flow and start of medical treatment conditions using My Number Home Application Web for eligibility verification) The server terminal 100 may, via the My Number linkage unit 136, read the URL or QR code issued by the medical institution for eligibility verification using the booth terminal 200 or a terminal installed at the facility, prompt the user to enter a PIN and read their card, and execute a process to obtain eligibility information after obtaining consent. Furthermore, the server terminal 100 may use the eligibility verification result, indicating that eligibility verification was successful, as a condition for establishing or continuing an online medical consultation session, and may restrict the start of medical consultation or guide the user to an alternative method if eligibility verification is incomplete or fails.
[0120] (Multi-factor unlocking, revocation, receipt tracking, and lot tracking in drug lockers) The server terminal 100 may generate unlocking information for the medication locker via the prescription / medication locker management unit 141, activate the unlocking information by linking it to at least one of several conditions such as completion of medical treatment, completion of payment, completion of identity verification, or final approval by the physician, and then expire it after a predetermined time. Furthermore, the server terminal 100 may record traceability information including the receipt signature, door opening sensor information, and lot number at the time of unlocking or receipt, and save it as an audit log.
[0121] In the business scheme related to on-site medical facilities (booths) in this embodiment, for example, the following entities may be involved. • Booth operator: The entity responsible for the installation, maintenance, and operation of the booth (cleaning, suitability checks, reservation slot management, etc.), including cases where the brand owner, clinic, or provider of the booth location also serves as the booth operator. • Booth location providers: Businesses that provide facility spaces such as train stations, post offices, banks, and convenience stores. • Clinics: Medical institutions that provide online consultations (including arrangements where multiple clinics collaborate and the person in charge switches on a per-treatment menu or per-time slot basis). • User: A user (patient) receiving online medical consultation at an online medical facility. Furthermore, if the booth operator and the clinic are the same entity, the above four parties may be merged into a three-party structure consisting of the clinic and the booth operator. The entry models for businesses related to online consultation facilities (booths) vary depending on the type of involvement of the booth installation / operating entity, platform (PF) operating entity, medical institutions, pharmacies, companies / nursing care facilities, local governments / public facilities, etc. The present invention can be applied regardless of the combination of operating entities, providing terminal-independent (including BYOD) identity verification, ensuring privacy and information security, compliance checks (checklists, sensors, evidence, audit logs, modification workflows, etc.), cost transparency and separate billing, and neutral guidance (presentation of pharmacy candidates, etc.) centered around a server terminal 100.
[0122] (Model 1: Booth network operator type (room rental focused)) In the booth network operator model, the booth operator sets up booths at multiple locations and provides consultation spaces to medical institutions or platform operators. In this case, the booth operator generates checklists for compliance verification, provides evidence, and electronically signs them, while the server terminal 100 handles version control, periodic checks, modification workflows, audit log preservation, and gating. Costs are presented separately for medical expenses and facility usage fees, and these are stored as consent logs and ledgers, thereby reducing supervisory risk.
[0123] (Model 2: PF + Booth Integrated (Revenue Sharing)) In a PF+booth integrated system, the PF operator also manages the booth network and distributes funds to medical institutions and booth operators upon successful treatment. Server terminal 100 performs tasks such as generating expense breakdowns, saving consent logs, processing payments, calculating distribution amounts, and recording distribution ledger entries, and may also save the basis for distribution as an audit log.
[0124] (Model 3: Healthcare-led satellite type) In the healthcare institution-led satellite model, healthcare institutions set up booths and operate them as satellite bases to improve access to medical care. Even in this case, since misleading display and consent acquisition, compliance verification and termination in case of non-compliance (gating), and evidence preservation are important, the server terminal 100 can be subject to the compliance management method (corresponding to claims 5 to 7).
[0125] (Model 4: Business / Care Facility B2B2C Type) In the B2B2C model for companies and nursing care facilities, companies or nursing care facilities set up booths as part of employee welfare or care, and allow employees or residents to use them. In this case, since users may use their own devices (BYOD), the server terminal 100 can ensure privacy and security by applying identity verification, acquisition of terminal security status, session isolation, and saving of deletion trails, regardless of the terminal type.
[0126] (Model 5: Remote area pharmacy attached) In the case of a remote pharmacy with an attached booth, a booth may be installed in a portion of the pharmacy space. To avoid unfair guidance to specific pharmacies, the server terminal 100 can use neutral criteria (distance, business hours, delivery availability, user preference, etc.) when presenting pharmacy candidates, and can save the basis for determining the order of presentation and the selection log as an audit log.
[0127] (Model 6: Municipal / Public Facilities Model) In the municipal / public facility model, booths are installed as sections of public facilities such as train stations, airports, city halls, schools, and sports facilities, contributing to improved access to local medical care. In this case, since multiple parties such as the public facility management entity, the booth operator, the platform operator, and medical institutions may be involved, the server terminal 100 can ensure accountability and transparency through separate billing of costs, distribution ledger recording, and audit log preservation.
[0128] (Cross-model: Common functions) In all of the above entry models, the following are commonly effective: (i) ensuring identity verification, privacy, and security regardless of terminal type; (ii) documenting compliance verification, periodic checks, modification workflows, and audit logs; (iii) ensuring cost transparency, differentiated billing, consent, and record-keeping; and (iv) providing neutral pathways such as suggesting pharmacy candidates and maintaining logs.
[0129] (An example of cost burden and distribution based on the entry model) Depending on the entry model, the server terminal 100 may calculate the payment amount, settlement amount, or net payment amount to at least one of the following: a medical institution, a platform operator, a booth operator, a public facility manager, a booth location provider, a company, or a nursing care facility, and record it in a distribution ledger or settlement ledger. For example, by saving consent logs and ledgers based on classifications such as medical expenses going to medical institutions, facility usage fees going to booth operators or facility managers, and platform usage fees going to platform operators, it is possible to prevent misidentification and reduce supervisory risks. Furthermore, if bidirectional payments coexist, the net amount after offsetting may be recorded.
[0130] Identity verification and insurance eligibility verification at online medical consultation facilities (hereinafter collectively referred to as "eligibility verification") may not only be used to perform verification processing, but also as predetermined conditions (gate conditions) for establishing or continuing an online medical consultation session. For example, the server terminal 100 may, based on the eligibility verification results obtained by the My Number linkage unit 136 (which may include valid / invalid, consent obtained / not obtained, identity matching / mismatch, eligibility verification completed / incomplete, etc.), permit the establishment or continuation of an online medical consultation session only if the eligibility verification results meet the predetermined conditions. If the conditions are not met, the server terminal 100 may suspend the start of the consultation and perform a gating process that involves re-executing the eligibility verification procedure or guiding the user to another verification method (in-person verification, procedure at a later date, etc.).
[0131] Regarding the aforementioned eligibility verification, the server terminal 100 may record the consent information (date and time of consent, version of consent text, means of consent (checkbox, electronic signature, one-time code, etc.), consent acquisition terminal identifier, etc.) obtained prior to the execution of eligibility verification, and the eligibility verification result (result code, acquisition time, response source identifier, error code, etc.), linked to the reservation ledger, session identifier, or user identifier. This allows the medical institution administrator or supervisory body to retrospectively verify, in an auditable manner, that the medical treatment session was started or continued on the premise that eligibility verification was completed.
[0132] The server terminal 100 can not only individually determine suitability (shielding / sound insulation, cleanliness / safety, information security, etc.), terminal security verification (attestion results, VPN connection status, etc.), and eligibility verification results, but can also evaluate these as integrated gate conditions. For example, a medical session may be established or continued only if all of the following conditions are met: (a) suitability meets predetermined conditions, (b) the security status of the terminal or network meets predetermined conditions, and (c) the eligibility verification results meet predetermined conditions. If any of these conditions are not met, the medical session may be temporarily suspended, a failback measure may be switched, or an alternative facility / alternative booth may be suggested.
[0133] From the perspective of ensuring privacy and information security in a device-independent manner (including BYOD), the data erasure management unit 140 of the server terminal 100 may, upon completion of medical treatment or session termination, execute the erasure of temporary caches, session keys, container areas, or temporary files formed on the patient terminal 200, or confirm the completion of the erasure. Furthermore, the server terminal 100 may save an erasure audit log (which may include the erasure target identifier, erasure method, erasure start / completion time, terminal identifier, session identifier, erasure result code, retry history in case of failure, etc.) showing the result of the erasure as an audit log.
[0134] The deletion log may be preserved by adding tamper detection information such as a timestamp, digital signature, hash, or hash chain, from the standpoint of accountability and compliance with on-site inspections. Furthermore, the server terminal 100 may manage the deletion log as audit data separate from the publicly available data and apply access control that allows viewing only by authorized entities.
[0135] For elderly users, visually impaired users, or users unfamiliar with the operation, the server terminal 100 may provide remote assistance (assist mode). For example, the server terminal 100 may allow the facility operator terminal 800 or the medical institution terminal 400 to share the user terminal screen, perform collaborative operation (co-browsing), or provide guidance displays (cursor guidance, procedural guidance, etc.). However, such remote assistance may be limited to certain functions such as identity verification, consent acquisition, connection assistance, and qualification verification procedures, from the perspective of minimizing authority, and viewing or editing medical content (medical interview content, etc.) may be restricted.
[0136] With regard to the aforementioned remote support, the server terminal 100 may obtain user consent prior to the start of support (support consent log) and save the scope of support execution (permitted functions, operation rights, support time, supporter identifier, etc.) and the support operation history (operation events, display events, whether or not files were transferred, etc.) as an audit log. This makes it possible to verify afterward that remote support is limited to assistance such as identity verification and that unnecessary viewing or operations have not been performed.
[0137] Access control to audit data (original compliance reports, sensor raw data, corrective action history, consent log reference, deletion trail log reference, qualification verification log reference, etc.) can be implemented not only by limiting access to "authorized entities," but also as role-based access control (RBAC) according to roles at the prefectural level, operating entity level (brand owners, booth operators, medical institutions, etc.), facility level, and role level (medical institution administrators, supervisory bodies, facility administrators, auditors, etc.). For example, the server terminal 100 may logically separate audit data by prefectural or administrative authority level and grant access, updating, and output permissions to each role.
[0138] The server terminal 100 may save the access history to the audit data (accessing entity, time, target data, operation type, whether output was generated, etc.) as an access log, and may output a report with attached evidence, including the compliance confirmation status for a predetermined period, corrective action history, qualification confirmation status, deletion evidence, and cost separation agreement. [Industrial applicability]
[0139] This invention is applicable to medical institutions that provide online medical consultations, businesses that operate online medical consultation platforms, and businesses that operate booth facilities, and contributes to improving access to medical care, automating legal compliance, and achieving transparent revenue sharing. [Explanation of symbols]
[0140] 1 System 100 server terminals 200 booth terminals 300 Brand Owner Terminals 400 clinic terminals 500 SNS servers 600 sensor group 700 PSP (Payment Service Provider) 800 Booth Operator Terminals NW1 Network
Claims
1. A method for providing medical services that provides online medical consultations to users at an online medical consultation facility, characterized in that a server device acquires suitability information regarding the online medical consultation facility, determines whether the suitability information satisfies predetermined conditions, permits the establishment of an online medical consultation session between the user and the medical institution's terminal if the suitability information satisfies the predetermined conditions, restricts the establishment or continuation of the online medical consultation session if the suitability information does not satisfy the predetermined conditions, presents the user with a misleading display indicating that the online medical consultation facility is not a facility that provides medical care, and saves a consent log based on the consent operation for the misleading display.
2. A method for providing medical services according to claim 1, characterized in that the suitability information includes at least a portion of the equipment information, environmental information, location information, communication quality information, identity verification information, and operational information of the online medical consultation facility.
3. A method for providing medical services according to claim 1, characterized in that the predetermined conditions include conditions relating to at least a part of sound insulation, illumination, communication quality, privacy assurance, equipment connection status, identity verification status, and emergency response capability status.
4. A method for providing medical services according to claim 1, characterized in that the server device determines the consistency between environmental information acquired from a group of sensors and checklist information entered by a facility manager or user, and includes the result of the consistency determination in the conformity information.
5. A method for providing medical services according to claim 1, characterized in that, if the server device does not meet the suitability information requirements, it prohibits the start of the online medical consultation session or stops the online medical consultation session that has already been started, and provides at least one of the following as an alternative: reconnection support, re-booking guidance, switching to in-person consultation guidance, or alternative booth guidance.
6. A method for providing medical services according to claim 1, characterized in that the server device stores at least a portion of the suitability information, consent log, session start information, session end information, and anomaly detection information as an audit log.
7. A method for providing medical services according to claim 1, characterized in that the server device generates public data and audit data separately relating to the online medical consultation facility, and controls the scope of access according to the authority.
8. A method for providing medical services according to claim 7, characterized in that the public data includes at least a portion of the facility name, location, available hours, equipment overview, suitability check date and time, and reservation availability, and the audit data includes at least a portion of the inspection history, consent history, anomaly history, deletion evidence, and corrective history.
9. A method for providing medical services according to claim 1, characterized in that, in response to the misidentification prevention display, the server device generates and stores an explanation consent log that includes at least a portion of the version information of the display text, the date and time of display, the date and time of consent, facility identification information, booth identification information, terminal identification information, and user identification information.
10. A method for providing medical services according to claim 1, characterized in that, after the termination of the online medical consultation session, the server device instructs the deletion of at least a portion of the image data, audio data, medical consultation-related input data, and authentication-related data temporarily stored in the receiving terminal or facility-installed terminal of the online medical consultation facility, and saves a deletion trail log showing the result of the deletion.
11. A method for providing medical services according to claim 1, wherein the suitability information includes at least one of the identity verification result based on identity verification information and the insurance eligibility verification result, and the server device permits or restricts the establishment or continuation of the online medical consultation session based on the identity verification result or the insurance eligibility verification result.
12. A method for providing medical services according to claim 1, characterized in that the server device generates corrective tasks corresponding to unfulfilled conditions and manages them in association with the person in charge, the deadline, and the results of implementation.
13. A method for providing medical services according to claim 1, characterized in that the server device selects a clinic to be in charge of the online medical consultation session based on the medical treatment menu selected by the user, and when the operator of the online medical consultation facility also operates the clinic, the server device can select the clinic as the first clinic, and when the first clinic does not cover the medical treatment menu, the server device selects another affiliated clinic and has the online medical consultation facility provide the online medical consultation to the user.
14. A server device for providing online medical consultations to users at an online medical consultation facility, comprising: a reception processing unit for acquiring suitability information relating to the online medical consultation facility; a suitability management unit for determining whether predetermined conditions are met based on the suitability information; a session control unit for permitting or restricting the establishment or continuation of an online medical consultation session according to the determination result; a display control unit for controlling misleading display and explanatory consent display indicating that the online medical consultation facility is not a facility that provides medical care; a log management unit for storing consent logs based on consent operations for the misleading display; and a settlement management unit for calculating payment amounts, deduction amounts, offset amounts or net payment amounts based on settlement rule data between at least some of the booth operators, booth location providers, clinics, platform operators, contracting parties and users, and storing them in a settlement ledger.
15. An online medical consultation facility comprising: an isolated space where users are accommodated; a consultation terminal or facility-provided terminal for online medical consultations by users; a group of sensors for acquiring suitability information regarding the online medical consultation facility; a display unit that displays a misleading indication that the online medical consultation facility is not a facility that provides medical care; and a gate control unit that controls the start or continuation of an online medical consultation session according to the suitability information.
16. A server device according to claim 14, wherein the display control unit displays a set of explanation items including at least a portion of the conditions for switching to face-to-face medical treatment, precautions regarding the presence of a third party, a policy for responding to sudden changes in condition, security precautions, and matters to be observed by the user, and stores an explanation consent log including version information thereof.
17. A server device according to claim 14, characterized in that the suitability management unit performs a composite condition determination based on at least two of the following: identity verification information, location verification information, and communication quality information.
18. A server device according to claim 14, characterized in that the server device separately generates public data and audit data, and displays different sets of items on the user screen and the administrator screen.
19. A server device according to claim 14, characterized in that the display control unit or the server device performs a name review process to determine whether the wording included in the facility name or guidance display is likely to cause misunderstanding that it is a medical institution or clinic.
20. A server device according to claim 14, characterized in that the session control unit requests the completion of at least one of insurance eligibility verification processing or identity verification processing prior to an online medical consultation session.
21. An online medical consultation facility according to claim 15, wherein the online medical consultation facility stores at least a portion of the suitability check results, explanation and consent results, session start or end results, and emergency response results as audit logs, and is configured to transmit said audit logs to an administrator terminal or server device.
22. An online medical consultation facility according to claim 15, characterized in that, when medical assistance is provided by a medical assistant including a nurse, at least a portion of the qualification information, role information, affiliation information, and consent information of the medical assistant is recorded.
23. An online medical consultation facility according to claim 15, characterized in that it detects signs of a sudden change in the user's condition based on information obtained from the sensor group or the consultation terminal, and notifies at least one of a medical institution, family, emergency contact, or potential destination for transport.
24. A program for causing a computer to function as the reception processing unit, suitability management unit, session control unit, display control unit, log management unit, and settlement management unit described in Claim 14.
25. A system for providing online medical consultations to users at an online medical consultation facility, characterized by comprising the server device described in claim 14, the online medical consultation facility described in claim 15, and a medical institution terminal.