Systems and methods for confidential analysis of personally identifiable information
By deploying a virtual container with a confidential computing enclave on a remote system, the method addresses security and compliance challenges in analytic services, ensuring secure and efficient analysis of confidential patient data within the customer's environment.
Patent Information
- Application Number
- PCT/US2025/022581
- Authority / Receiving Office
- WO · WO
- Patent Type
- Applications
- Current Assignee / Owner
- Priority Date
- 2024-04-01
- Filing Date
- 2025-04-01
- Publication Date
- 2025-10-09
AI Technical Summary
Traditional analytic services for healthcare payors require transmitting confidential patient data outside their secure network, posing security challenges, compliance issues with varying customer requirements, and potential cyber-attacks, with complex security configurations and high insurance premiums.
Deploying a virtual container with a confidential computing enclave on a remote system to execute analytics applications within the customer's secure environment, ensuring data remains encrypted and proprietary algorithms are protected, without the analytics firm accessing the data.
Ensures data confidentiality and proprietary algorithms remain secure, eliminating the need for data transmission and reducing cyber risks, while providing secure and efficient analysis of personally identifiable information.
Smart Images

Figure US2025022581_09102025_PF_FP_ABST
Abstract
Description
SYSTEMS AND METHODS FOR CONFIDENTIAL ANALYSIS OF PERSONALLY IDENTIFIABLE INFORMATIONCROSS REFERENCE TO RELATED APPLICATIONS
[0001] This application claims priority’ to U.S. Provisional Patent Application No. 63 / 572,695, filed on April 1, 2024, which is incorporated herein by reference in its entirety.FIELD OF THE DISCLOSURE
[0002] The present disclosure is directed towards secure delivery of company managed proprietary analytics application to execute within the customer’s eco-system while being colocated with the customer’s data.BACKGROUND
[0003] Traditional engagements providing analytic services as a vendor for healthcare payors required the customer (healthcare payor) to transmit outside their secure network or environment confidential patient data including several pieces of identifiable information to the analytics vendor. This transmission of the confidential patient data is commonly performed over a Secure File Transfer Protocol (SFTP).
[0004] As such, the vendor maintains the proprietary analytics code and associated algorithms in its own environment, but is also burdened with providing security for data on behalf of its customers. This is complicated even further with different customers having different security requirements regarding their data, retention periods, and guidelines for keeping data separated between not only different companies, but also different sections or markets for each company.
[0005] Additionally, data transfer can often be a point of disruption in business flow and a potential target for cyber-attack. These services require a significant amount of security configurations including hefty cyber insurance premiums and can be complex to maintain reliable connections between entities.SUMMARY
[0006] The present disclosure provides new methods, systems, and computer programs for confidential analysis of personally identifiable information, within a customer’s secure computing environment.
[0007] In accordance with one innovative aspect of the present disclosure, a method for confidential analysis of personally identifiable information is disclosed. In one aspect, the method can include actions of deploying, using one or more computers, a virtual container hosted by a remote computing system, providing, using the one or more computers, an analytics application to the deployed within the virtual container, and executing, using the one or more computers, the analytics application within a confidential computing enclave of the virtual container hosted by the remote computing system. In some implementations, execution of the analytics application within the confidential computing enclave of the virtual container can include obtaining, within the confidential computing enclave of the deployed virtual container, encry pted personally identifiable information corresponding to one or more entities from data storage of a customer, decrypting, within the confidential computing enclave of the deployed virtual container, the obtained personally identifiable information, processing, within the confidential computing enclave of the deployed virtual container, the decrypted personally identifiable information using the analytics application to generate output data, and providing, from the confidential computing enclave of the deployed virtual container, the generated output data to the data storage of the customer.
[0008] Other versions include corresponding systems, apparatus, and computer programs to perform the actions of methods defined by instructions encoded on computer readable storage devices.
[0009] These and other versions may optionally include one or more of the following features. For instance, in some implementations, the method can further include instructing, using the one or more computers, the remote computing system to delete the deployed virtual container.
[0010] In some implementations, the remote computing system comprises one or more computers hosted in a cloud-computing environment.
[0011] In some implementations, the remote computing system comprises one or more computers hosted on a different local area network (LAN) than the network hosting the one or more computers that deployed the virtual container.
[0012] In some implementations, providing, using one or more computers, the analytics application to the deployed virtual container can include installing, using one or more computers, the analytics software into a virtual computing environment hosted by the container.
[0013] In some implementations, providing, using one or more computers, the analytics application to the deployed virtual container comprises transmitting the analytics applicationto the remote computing system hosting the deployed virtual container to which the analytics application was provided.
[0014] In some implementations, the analytics application is a proprietary analytics application.
[0015] In some implementations, the proprietary analy tics application is a computer program whose mode of operation cannot be revealed to an entity seeking output data generated by the proprietary analytics application
[0016] In some implementations, the proprietary analytics application is a computer program whose mode of operation and software code is confidential.
[0017] According to another innovative aspect of the present disclosure, a method for confidential analysis of personally identifiable information is disclosed. In one aspect, the method can include actions of receiving, using one or more computers, instructions to deploy a virtual container from a computer of an analytics firm, generating, using the one or more computers, a virtual container in response to the received instructions, receiving, using the one or more computers, an analytics application into the generated virtual container, and executing, using the one or more computers, the analytics application within a confidential computing enclave of the generated virtual container. In some implementations, execution of the analytics application within the confidential computing enclave of the generated virtual container can include obtaining, within the confidential computing enclave of the generated virtual container and using the one or more computers, encrypted personally identifiable information corresponding to one or more entities from a first memory device that is outside of the virtual container, decrypting, within the confidential computing enclave of the generated virtual container and using the one or more computers, the obtained personally identifiable information, processing, within the confidential computing enclave of the generated virtual container and using the one or more computers, the decrypted personally identifiable information using the analytics application to generate output data; storing, within the confidential computing enclave of the generated virtual container and using the one or more computers, the generated output in a second memory device that is outside of the generated virtual container.
[0018] Other versions include corresponding systems, apparatus, and computer programs to perform the actions of methods defined by instructions encoded on computer readable storage devices.
[0019] These and other versions may optionally include one or more of the following features. For instance, in some implementations, the method can further include receiving.using the one or more computers, an instruction to delete the generated virtual container, and deleting, using the one or more computers, the deployed virtual container.
[0020] In some implementations, the one or more computers include one or more computers of a cloud-computing environment.
[0021] In some implementations, the one or more computers include one or more computers of a local area network (LAN).
[0022] In some implementations, method can further include installing, using one or more computers, the analytics software into a virtual computing environment of the generated virtual container.
[0023] In some implementations, the analytics application is a proprietary analytics application.
[0024] In some implementations the proprietary analytics application is a computer program whose mode of operation cannot be revealed to an entity seeking output data generated by the proprietary analytics application.
[0025] In some implementations, the proprietary analytics application is a computer program whose mode of operation and software code is confidential.
[0026] In some implementations, the first memory device and the second memory device are the same memory device.
[0027] According to another innovative aspect of the present disclosure, a method for predicting a likelihood that an entity is going to develop a medical condition is disclosed. In one aspect, the method can include actions of obtaining, using one or more computers, encry pted personally identifiable information corresponding to the entity from data storage, decrypting, within a confidential computing enclave of a generated virtual container and using the one or more computers, the obtained personalty identifiable information, mapping, within the confidential computing enclave and using the one or more computers, the decry pted personally identifiable information of the entity' to a predefined schema, identifying, within the confidential computing enclave and using the one or more computers, one or more codes in the mapped information associated with the entity’s medical history, generating, within the confidential computing enclave and using the one or more computers, input data that includes the identified one or more codes associated with the entity’s medical history' providing, within the confidential computing enclave and using the one or more computers, the generated input data as an input to a machine learning model that has been trained to generate output data indicating a likelihood that the entity’ will develop one or more medical conditions based on processing of input data corresponding to one or more codesassociated with the entity’s medical history', processing, within the confidential computing enclave and using the one or more computers, the provided input data through one or more layers of the machine learning model to generate output data indicating a likelihood that the entity' will develop one or medical conditions, determining, within the confidential computing enclave and using the one or more computers, whether the entity' is likely to develop one or more medical conditions in the future based on the determined one or more likelihoods in the generated output data, and based on a determination that the entity is likely to develop one or more medical conditions in the future, generating, within the confidential computing enclave and using the one or more computers, a report that includes information identifying the one or more medical conditions.
[0028] Other versions include corresponding systems, apparatus, and computer programs to perform the actions of methods defined by instructions encoded on computer readable storage devices.
[0029] These and other versions may optionally include one or more of the following features. For instance, in some implementations, the method can further include storing, using the one or more computers, the generated report within a database without transmitting the report across a publicly accessible network.
[0030] In some implementations, the one or more computers and the confidential computing enclave are hosted within a local area network (LAN).
[0031] In some implementations, the method can further include storing, using the one or more computers, the generated report within a database that is hosted by the local area network (LAN).
[0032] In some implementations, determining, within the confidential computing enclave and using the one or more computers, whether the entity is likely to develop one or more medical conditions in the future based on the determined one or more likelihoods in the generated output data can include for each of a plurality' of different medical conditions: determining, within the confidential computing enclave and using the one or more computers, whether a determined likelihood for the medical condition satisfies a predetermined threshold, and based on a determination that the determined likelihood for the medical condition satisfies the predetermined threshold, determining that the entity is likely to develop the medical condition.
[0033] In some implementations, determining, within the confidential computing enclave and using the one or more computers, whether the entity is likely to develop one or more medical conditions in the future based on the determined one or more likelihoods in thegenerated output data can include for each of a plurality of different medical conditions: determining, within the confidential computing enclave and using the one or more computers, whether a determined likelihood for the medical condition satisfies a predetermined threshold, and based on a determination that the determined likelihood for the medical condition does not satisfy the predetermined threshold, determining that the entity is not likely to develop the medical condition.
[0034] In some implementations, the one or more codes in the mapped information associated with the entity’s medical history include International Classification of Disease (ICD) diagnosis codes.
[0035] In some implementations, the one or more codes in the mapped information associated with the entity’s medical history comprise Current Procedural Terminology (CPT) codes.
[0036] In some implementations, the generated input data also includes additional information describing the entity .
[0037] In some implementations, the additional information describing the entity comprises demographic data, insurance data, or financial data associated with the entity.
[0038] In some implementations, the machine learning model comprises one or more neural networks.
[0039] These and other innovative aspects of the present disclosure are readily apparent in view of the detailed description, the accompanying drawings, and the claims.BRIEF DESCRIPTION OF THE DRAWINGS
[0040] FIG. 1 is a schematic of an example of a system that can be used to perform confidential analysis of personally identifiable information, in accordance with one aspect of the present disclosure.
[0041] FIG. 2 is another schematic of an example of a system that can be used to perform confidential analysis of personally identifiable information, in accordance with one aspect of the present disclosure.
[0042] FIG. 3 is a flowchart of an example of a process for confidential analysis of personally identifiable information, in accordance with one aspect of the present disclosure.
[0043] FIG. 4 is a flowchart of an example of a process for applying an analytics application to personally identifiable information within a confidential computing enclave, in accordance with one aspect of the present disclosure.
[0044] FIG. 5 is another flowchart of an example of a process for confidential analysis of personally identifiable information, in accordance with one aspect of the present disclosure.
[0045] FIG. 6 is another flowchart of an example of a process for applying an analytics application to personally identifiable information within a confidential computing enclave, in accordance with one aspect of the present disclosure.
[0046] FIG. 7A is a flowchart of an example of a process for predicting a likelihood that an entity is going to develop a medical condition, in accordance with one aspect of the present disclosure.
[0047] FIG. 7B is a flowchart that continues the process of FIG. 7A.
[0048] FIG. 8 is a block diagram of system components that can be used to implement a system for performing confidential analysis of personally identifiable informationDETAILED DESCRIPTION
[0049] The present disclosure is directed towards systems, methods, and computer programs for confidential analysis of personally identifiable information maintained at a remote location. In particular, a computer system executing the present disclosure can deploy a virtual container utilizing a confidential computing enclave onto one or more computers of a remote network. Then, the computer system can install analytics software within the deployed virtual container that can be used to obtain and analyze encrypted personally identified information within the container using the confidential computing enclave. Data generated as a result of this analyze may then be transmitted back to a database of the owner / possessor of the encrypted personally identifiable information.
[0050] The present disclosure improves upon known systems in multiple ways. First, the present disclosure does not require the transmission by the customer, e.g., a healthcare provider or health insurance provider, of personally identifiable information to the analytics firm. This helps to ensure that the personally identifiable information remains confidential. In addition, the encrypted personally identifiable information is decrypted only within a secure, confidential computing enclave of the deployed virtual container within the customer’s computing system or the customer’s remote or virtual, e.g., cloud -based, computing system. Thus, the analytics team analyzing the data will be not able to access the personally identifiable information. Separately, the present disclosure also protects the proprietary nature of the analytics software being used to analyze personally identifiable information. For example, the computing environment is deployed and managed by the operator of the analytics firm (and not the entity that possesses the personally identifiable information). Thus, the analytics software used to analyze the encrypted personally identifiable information does not need to be revealed to the data provide and, instead, can bekept proprietary'. Furthermore, in some implementations, the confidential, personally identifiable information and data is decrypted and re-encrypted all within the virtual container, and thus not even the analytics firm can access or review the confidential, personally identifiable information.
[0051] The present disclosure provides a multi-view, machine learning (ML) tool for high- risk population management that includes identification and risk stratification for one or more medical conditions, e.g.. dementia / AD RD, Maternity Care Management, cancer, and arthritis. In some implementations, the present disclosure analyzes various data sets from a healthcare plan daily, including medical claims, pharmacy claims, membership and eligibility information, and care management data. In some implementations, this can include, for example identification and analysis of ICD codes such as ICD-9 and ICD-10 codes in the medical claims data using one or more machine learning models .
[0052] The present disclosure can be used to execute one or more machine learning algorithms to process the health plan’s data, including ICD codes, and identify patients diagnosed with a particular medical condition such as, e.g., dementia / ADRD or Maternity Care Management, and those at risk of developing the condition, or those with a condition, but are at risk for becoming significantly worse. The present disclosure can be used to perform an initial risk assessment on each patient or entity at the initial identification and, in some implementations, the analysis can be updated periodically, e.g., daily, weekly, or monthly, as new healthcare data are processed, and the machine learning model of the present disclosure is trained on the new healthcare data. For purposes of the present disclosure, an entity' can include a person or animal. Animals can include, for example, domesticated animals, such as dogs, cats, cows, horses, goats, sheep, etc., or lab animals, such as mice, rabbits, monkeys, etc.
[0053] The presently disclosed methods and systems can be used to generate output data that includes targeted patient information and an associated risk assessment (e.g., a report indicating a likelihood that an entity will develop a particular medical condition in the future, or has a condition and will become significantly worse) can be provided to the health plan's care management team. In some implementations, such an associated risk assessment can be provided for one or more entities associated with the health plan daily so resources can be adjusted based on risk and potential impact.
[0054] In some implementations, the present disclosure is offered as an Analytics as a Service (AaaS) solution that ensures security of protected health information (PHI) utilizing a containerized approach. Specifically, the analytics application of the present disclosure canbe deployed as a temporal virtual container within a new subscription in the customer’s public cloud tenancy to mitigate the risk of moving PHI data across public networks. This eliminates the need to export any PHI data from the health plan’s environment for any reason.
[0055] FIG. 1 is an example of a system 100 of system components that can be used to perform confidential analy sis of personally identifiable information, in accordance with one aspect of the present disclosure. The system 100 includes a computer 110 of an analytics firm, a network 120. and one or more remote computers 130. e.g., a remote computing system (also referred to as “the remote computer 130”). The one or more remote computers 130 can provide computations resources that the computer 110 of the analytics firm can use to deploy a virtual container. Once deployed, the virtual container may reside within the one or more remote computers in a virtual container storage area. The computer 110 of the analytics firm can begin execution of the system 100 by transmitting a request 112 to deploy a virtual container in virtual container storage area 140 of the one or more remote computers 130.
[0056] The request 112 can include instructions to the one or more remote servers 130 to deploy the virtual container. For example, the request 112 can specify the computer resources that need to be allocated to the deployed virtual container in order to create the virtual computing environment needed to perform analysis of personally identifiable information of a customer. The specific computing resources can include, e.g.. an amount of memory, an amount of processing power, a request for a confidential computing enclave, or the like. In some implementations, the resources request may be selected using configurable options in a web portal accessed by the computer 110 and then submitted using a web form. However, the present disclosure is not so limited and the specific resources requested for the virtual computing environment of the virtual container can be provided in request 112 in any number of ways. The request 112 can be transmitted across the network 120 to the one or more remote computers 130. The network can include one or more of a wired ethemet network, a WI-FI network, a local area network (LAN), a wide area network (WAN), a cellular network, the Internet, or any combination or arrangement thereof.
[0057] The remote server 130 can receive the request 112 to deploy a virtual container in the virtual container storage area 140. Upon receive of the request 112, the remote server 120 can process the request 112 and allocate necessary resources to generate the virtual computing environment in the virtual container storage area 140 that was requested by the computer 110 as shown in FIG. 2. In some implementations, the remote server 130 can include a single computer (e.g., a server computer). In other implementations, the remotesen- er 130 can include multiple computers (e.g., multiple computers of a cloud-based computing platform).
[0058] Virtual computing environments within a virtual container deployed within the virtual container storage area can access the database 140 of encrypted personally identifiable information (PII). In some implementations, the virtual computing environment within a virtual container can make requests over the network 120 to obtain encrypted personally identifiable information stored in the database 140. In such implementations, the network 120 can include the Internet and such a request from the virtual computing environment to the database 140 would need be communicated over the public Internet. However, in other implementations, the network 120 may be a local area network (LAN) and. in such instances, the database 140 and the remote computer 130 may reside on the same LAN. Such a configuration would ensure that the encrypted personally identifiable information is not communicated over a publicly available network such as the Internet. In yet other implementations, the database 140 may be hosted within the remote computer 130 and request for encrypted personally identifiable information (PII) need to be communicated across any networks.
[0059] FIG. 2 is another example of a system 200 that can be used to perform confidential analysis of personally identifiable information, in accordance with one aspect of the present disclosure. The system of FIG. 2 is generally the same as the system of FIG. 1. However, in the example of FIG. 2. a virtual container 160 has been generated in the virtual container storage area 140 of the remote computer 130 in response to the request 1 12 from the computer 110 to deploy a virtual computing environment in a virtual container of the remote computer 130.
[0060] The remote computer 130 generates the virtual container 160 based on the request 1 12 to deploy a virtual container. In this example, the virtual container requested by the request 112 request virtual container 162 with a confidential computing enclave 162. The confidential computing enclave creates an encrypted memory 164 that is capable of securely- processing encrypted personally identifiable information. In particular, the confidential computing enclave 162 is a fully isolated virtual computing environment within the virtual container 1 0 that protects the confidentiality of information processed within the confidential computing enclave of the virtual container 160. In some implementations, for example, the confidential computing enclave can include a region of memory , which can be referred to as a ‘"secure enclave” or “secure enclave memory” that is configured as a black box regarding the processes running within the secure enclave and to other processes runningon the remote computer, including operating system of the remote computer, the operating system of the virtual container, and any processes that run outside of the secure enclave. This can be achieved in a number of ways include, for example, implementing the secure enclave using an encrypted memory to create an environment where the encrypted personally identifiable information (PII) can be stored, processed by the analytics firm’s proprietary software applications, encrypted, and transmitted back to its storage location without comprising the confidential nature of the personally identifiable information. The secure enclave functions to not only keep confidential the personally identifiable information, but also the propriety' software used by the analytics firm to analyst the personally identifiable information.
[0061] Once the virtual computing environment, including the confidential computing enclave 162 and the secure enclave memory 164, is generated, the computer 110 can provide the analytics firm’s analytics application 114 to the remote computer, across the network 120, 130 for storage in the secure enclave 164. Stored in the secure enclave memory' 164, the propriety nature of the analytics application 114 remains intact.
[0062] The analytics firm uses computer 110 to execute the analytics application 114. In some implementations, the analytics firm can use the computer 110 can interact with the analytics application 114 as if the analytics application 114 was installed on and executing on the computer 110. In other implementations, the computer 110 can merely cause, or trigger, execution of the analytics application 114. In such implementations, in response to the triggering execution of the analytics application 1 14 by the computer 1 10, the analytics application 114 can proceed to autonomously perform its programming functions until the analytics application has processed the necessary set of encrypted personally identifiable information for a particular customer or client.
[0063] Execution of the analytics application can begin with the analytics application 114 obtaining 144 encrypted personally identifiable information 142 from the database 140 and storing the encrypted personally identifiable information 142 in the secure enclave memory'. 163. corresponding to one or more entities from data storage of a client or customer (e.g., database 140). Of particular significance, the architecture of system 200 of FIG. 2 enables the analytics firm to analyze the personally identifiable information in the possession of a client or customer (e.g., in database 140) without the analytics firm ever possessing the personally identifiable information 142, as the computer 110 of the analytics firm does not ever receive the personally identifiable information 142.
[0064] The analytics application can continue execution by decrypting, within the confidential computing enclave of the deployed virtual container, the obtained personally identifiable information. Once decrypted, the analytics application can process, within the confidential computing enclave of the deployed virtual container, the decrypted personally identifiable information using the analytics application to generate output data Processing the decrypted personally identifiable information can include, for example, applying one or more analytics algorithms to the personally identifiable information. In some implementations, such process operations can include operations of FIGs. 7A-B such as, e.g., the operations of mapping (73), identifying (740), generating (750), providing (760), processing (770), determining (780, and / or generating (790) described with reference to FIGs. 7A-7B, as described in more detail below. Once the processing operations of the analytics application 114 are complete, the analytics application 114 can continue execution by providing the generated output data such as, e.g., a generated report for an entity whose personally identifiable information was processed, to the data storage of the client or customer (e.g., database 140).
[0065] FIG. 3 is a flowchart of an example of a process 300 for confidential analysis of personally identifiable information, in accordance with one aspect of the present disclosure. The process 300 will be described as being performed by one or more computers such as, e.g., the computer 110. Though the word computer can refer to a workstation such as the computer or workstation 110 of the analytics firm, for purposes of this disclosure, a computer should not be limited to the computer 110. Instead, the term computer, as used herein, can also refer to a processing device such as a central processing unit (CPU), graphics processing unit (GPU), or the like. In such instances, even the computer 110 can include multiple “computers.”
[0066] One or more computers can begin execution of the process 300 by deploying a virtual container hosted by a remote computing system (310).
[0067] The one or more computers can continue execution of the process 300 by providing an analytics application to the deployed virtual container (320).
[0068] The one or more computers can continue execution of the process 300 by causing execution of the analytics application within a confidential computing enclave of the virtual container hosted by the remote computing system. In some implementations, execution of the analytics application within the confidential computing enclave of the virtual container can include execution of the process 400 of FIG. 4.
[0069] In some implementations, the one or more computers can continue execution of the process 300 by instructing the remote computing system to delete the deployed virtual container.
[0070] In some implementations, the remote computing system can include one or more other computers hosted in a cloud-computing environment.
[0071] In some implementations, the remote computing system can include one or more other computers hosted on a different local area network (LAN) than the network hosting the one or more computers that deployed the virtual container.
[0072] In some implementations, the operation of providing the analytics application to the deployed virtual container can include installing the analytics software into a virtual computing environment hosted by the container.
[0073] In some implementations, providing the analytics application to the deployed virtual container can include transmitting the analytics application to the remote computing system hosting the deployed virtual container to which the analytics application was provided.
[0074] In some implementations, the analytics application is a proprietary analytics application.
[0075] In some implementations, the proprietary analytics application is a computer program whose mode of operation cannot be revealed to an entity' seeking output data generated by the proprietary analytics application.
[0076] In some implementations, the proprietary analytics application is a computer program whose mode of operation and software code is confidential.
[0077] FIG. 4 is a flowchart of an example of a process 400 for applying an analytics application to personally identifiable information within a confidential computing enclave, in accordance with one aspect of the present disclosure. The process 400 can be described as being performed by one or more computers such as, e.g., the computer 110 or the remote computer(s) 130.
[0078] One or more computers can begin execution of the process 400 by obtaining, within the confidential computing enclave of the deployed virtual container, encrypted personally identifiable information corresponding to one or more entities from data storage of a customer (410).
[0079] The one or more computers can continue execution of the process 400 by decrypting, within the confidential computing enclave of the deployed virtual container, the obtained personally identifiable information (420).
[0080] The one or more computers can continue execution of the process 400 by processing, within the confidential computing enclave of the deployed virtual container, the decrypted personally identifiable information using the analytics application to generate output data (430).
[0081] The one or more computers can continue execution of the process 400 by providing, from the confidential computing enclave of the deployed virtual container, the generated output data to the data storage of the customer (440).
[0082] FIG. 5 is another flowchart of an example of a process 500 for confidential analysis of personally identifiable information, in accordance with one aspect of the present disclosure. The process 500 will be described as being performed by one or more computers such as, e.g., the remote computer(s) 130.
[0083] One or more computers can begin execution of the process 500 by receiving instructions to deploy a virtual container from a a computer of an analytics firm (510).
[0084] One or more computers can continue execution of the process 500 by generating a virtual container in response to the received instructions (520).
[0085] One or more computers can continue execution of the process 500 by receiving an analytics application into the generated virtual container (530).
[0086] One or more computers can continue execution of the process 500 by executing the analytics application within a confidential computing enclave of the generated virtual container, wherein execution of the analytics application within the confidential computing enclave of the generated virtual container can include performing the process 600 of FIG. 6.
[0087] In some implementations, the one or more computers can continue execution of the process 500 by receiving an instruction to delete the generated virtual container, and deleting, using the one or more computers, the deployed virtual container.
[0088] In some implementations, the one or more computers include one or more computers of a cloud-computing environment.
[0089] In some implementations, the one or more computers include one or more computers of a local area network (LAN).
[0090] In some implementations, the one or more computers can continue execution of the process 500 by installing the analytics software into a virtual computing environment of the generated virtual container.
[0091] In some implementations, the analytics application is a proprietary analytics application.
[0092] In some implementations, the proprietary' analytics application is a computer program whose mode of operation cannot be revealed to an entity seeking output data generated by the proprietary analytics application.
[0093] In some implementations, the proprietary analytics application is a computer program whose mode of operation and software code is confidential.
[0094] In some implementations, the first memory’ device and the second memory device are the same memory' device.
[0095] FIG. 6 is another flowchart of an example of a process 600 for applying an analytics application to personally identifiable information within a confidential computing enclave, in accordance with one aspect of the present disclosure. The process 600 will be described as being performed by one or more computers such as. e.g., the remote computer(s) 130.
[0096] One or more computers can begin execution of the process 600 by obtaining, within the confidential computing enclave of the generated virtual container, encrypted personally identifiable information corresponding to one or more entities from a first memory device that is outside of the virtual container (610).
[0097] The one or more computers can continue execution of the process 600 by decrypting, yvithin the confidential computing enclave of the generated virtual container, the obtained personally identifiable information (620).
[0098] The one or more computers can continue execution of the process 600 by processing, within the confidential computing enclave of the generated virtual container, the decrypted personally identifiable information using the analytics application to generate output data (630).
[0099] The one or more computers can continue execution of the process 600 by storing, within the confidential computing enclave of the generated virtual container, the generated output in a second memory' device that is outside of the generated virtual container (640). [000100] FIG. 7A-7B illustrate a flowchart of an example of a process 700A-700B for predicting a likelihood that an entity is going to develop a medical condition, in accordance with one aspect of the present disclosure. The processes 700A and 700B will be described as being performed by one or more computers such as. e.g., the remote computer(s) 130.[000101] One or more computers begin execution of the process 700A by obtaining encrypted personally identifiable information corresponding to the entity' from data storage (710). Personally identifiable information can include records that particularly identify an entity and include information about an entity such as, for example, medical records of an entity, insurance records of an entity, or other records of an entity that include data indicating anaspect of the entity’s medical history. Such personally identifiable information can be maintained in any format such as, e.g., a database record, document, spreadsheet, or any other electronic file format.[000102] The one or more computers can continue execution of the process 700A by decrypting, within a confidential computing enclave of a generated virtual container, the obtained personally identifiable information (720).[000103] The one or more computers can continue execution of the process 700 A by mapping, within the confidential computing enclave, the decrypted personally identifiable information of the entity to a predefined schema (730). The predefined schema can be implemented using a data structure having one or more fields that each correspond to a type of data that is to be extracted from personally identifiable information of an entity. The mapping operation can include, for example, the one or more computers identifying particular types of information in the personally identifiable information such as, e.g., insurance codes, and inserting the extracted personally identifiable information in the appropriate field of the predefined schema for the extracted code. Such codes can include, e.g.. International Classification of Disease (ICD) codes. Current Procedural Terminology (CPT) codes, or any other code in personally identifiable information that is indicative of a medical condition associated with the entity.[000104] Health plans across the US boast comprehensive data sets that include a significant amount of clinical, social, and financial attributes. Their claims data include, e.g., the ICD diagnosis codes referenced above that are the standard for coding clinical terms for health and disease in primary, secondary, and tertiary' care; because of diagnostic guidance by category of ICD, the coding is standardized, reliable, highly specific, and normalized (World Health Organization, 2023). In contrast. Electronic Medical Record (EMR) data is typically not complete, consistent, or written using common nomenclature. These and other types of information may be extracted from the personally identifiable information and mapped to the predefined schema.[000105] The one or more computers can continue execution of the process 700A by identifying, within the confidential computing enclave, one or more codes in the mapped information associated with the entity’s medical history (740). The one or more codes can include International Classification of Disease (ICD) codes, Current Procedural Terminology' (CPT) codes, or any other code in personally identifiable information that is indicative of a medical condition associated with the entity.[000106] The one or more computers can continue execution of the process 700A by generating, within the confidential computing enclave, input data that includes the identified one or more codes associated with the entity’s medical history (750). The generated input data can include, for example, a feature vector that includes a field corresponding to each known code, or any subset thereof, known to be present in personally identifiable information. Such codes can include, for example, ICD codes, CPT codes, or any other code in personally identifiable information that is indicative of a medical condition associated with the entity. In some implementations, the feature vector can also include fields corresponding to a plurality of different demographic data, financial data of the entity associated with the personally identifiable information, or any combination thereof.[000107] The one or more can continue execution of the process 700A by providing, within the confidential computing enclave, the generated input data as an input to a machine learning model that has been trained to generate output data indicating a likelihood that the entity will develop one or more medical conditions based on processing of input data corresponding to one or more codes associated with the entity’s medical history (760). In some implementations, the machine learning model can include one or more neural networks. [000108] The machine learning model can be trained using a training data item data set of labeled training data items. In some implementations, for example, each training data item can be an example of a training data vector for a particular entity indicating each of the known code present in the entity’s personally identifiable information that is labeled with (i) one or more medical conditions or (ii) data indicating the entity did not develop any known medical conditions. To train the machine learning model, a plurality of training data having known labels can be processed through the machine learning model one at a time. Then, the output of the machine learning model can be compared to the label for the training data item that was processed through the machine learning model. Finally, one or more parameters of the machine learning model can be adjusted based on difference between the output generated by the machine learning model and the train label for the processed training data item. The model can continue to be trained on the training data items until the output generated by the machine learning model matches the label of the processed training data item that w as processed to generate the output.[000109] In some implementations, the machine learning model may be periodically trained. In such implementations, for example, the machine learning model may be trained once a month, once a week, multiple days a week, or the like, and then deployed with the analytics application once trained. However, the present disclosure is not so limited. Instead, in someimplementations, the machine learning model can be particular trained on customer data each time the present disclosure is deployed to analyze customer information.[000110] Expanding upon this notion of training with each deployment, the present disclosure may be used to analyze customer data on a daily basis. In such implementations, the computer 110 of FIG. 2 can request creation of a container, provide the analytics software, and then train the machine learning model on the customer's data prior to causing the analytics application to execute its algorithms on the customer’s data as described with reference to, e.g., the processes of 300, 400, 500, and 600 of FIGs. 3-6. When run daily, such daily training may, in fact, be required some implementations, as in some implementations, the generated virtual container that includes the confidential computing enclave is deleted upon completion of the analysis of the client or customer data for that day. In such implementations, the trained machine learning model would be lost when the container is destroyed. Thus, in implementations that destroy the container upon completion of the data analysis, daily training as part of the runtime algorithms of processes 300, 400, 500, 600, 700A, and / or 700B may be necessary. However, training as a precursor to each occurrence of using the present disclosure to analyze customer data has its own, independent, benefits. As, such training tailors the machine learning model to the particular client or customer’s data, since the model is being trained on the customer data. In addition, daily training allows the machine learning model to be finely tuned to changing in entity records as they occur.[000111] The one or more computers can continue execution of the process 700A at stage 770 of FIG. 7B by processing, within the confidential computing enclave, the provided input data through one or more layers of the machine learning model to generate output data indicating a likelihood that the entity will develop one or medical conditions (770).[000112] The one or more computers can continue execution of the process 700A at stage 780 of FIG. 7B by determining, within the confidential computing enclave, whether the entity is likely to develop one or more medical conditions in the future based on the determined one or more likelihoods in the generated output data (780).[000113] Then, based on a determination that the entity is likely to develop one or more medical conditions in the future, the one or more computers can continue execution of the process 700A at stage 790 of FIG. 7B by generating, within the confidential computing enclave, a report that includes information identifying the one or more medical conditions (790).[000114] In some implementations, the one or more computers can continue execution of the process 700A and 700B by storing the generated report within a database without transmitting the report across a publicly accessible network.[000115] In some implementations, the one or more computers and the confidential computing enclave are hosted within a local area network (LAN).[000116] In some implementations, the one or more computers can continue execution of the process 700A and 700B by storing, using the one or more computers, the generated report within a database that is hosted by the local area network (LAN).[000117] In some implementations, determining, within the confidential computing enclave, whether the entity is likely to develop one or more medical conditions in the future based on the determined one or more likelihoods in the generated output data can include for each of a plurality of different medical conditions: determining, within the confidential computing enclave and using the one or more computers, whether a determined likelihood for the medical condition satisfies a predetermined threshold, and based on a determination that the determined likelihood for the medical condition satisfies the predetermined threshold, determining that the entity is likely to develop the medical condition.[000118] In some implementations, determining, within the confidential computing enclave and using the one or more computers, whether the entity is likely to develop one or more medical conditions in the future based on the determined one or more likelihoods in the generated output data can include for each of a plurality of different medical conditions: determining, within the confidential computing enclave and using the one or more computers, whether a determined likelihood for the medical condition satisfies a predetermined threshold, and based on a determination that the determined likelihood for the medical condition does not satisfy the predetermined threshold, determining that the entity is not likely to develop the medical conditions.[000119] FIG. 8 is a block diagram of system components that can be used to implement a system for performing confidential analysis of personally identifiable information.[000120] Computing device 800 is intended to represent various forms of digital computers, such as laptops, desktops, workstations, personal digital assistants, servers, blade servers, mainframes, and other appropriate computers. Computing device 850 is intended to represent various forms of mobile devices, such as personal digital assistants, cellular telephones, smartphones, and other similar computing devices. Additionally, computing device 800 or 850 can include Universal Serial Bus (USB) flash drives. The USB flash drives can store operating systems and other applications. The USB flash drives can include input / outputcomponents, such as a wireless transmitter or USB connector that can be inserted into a USB port of another computing device. The components shown here, their connections and relationships, and their functions, are meant to be exemplary only, and are not meant to limit implementations of the inventions described and / or claimed in this document.[000121] Computing device 800 includes a processor 802, memory' 804, a storage device 806, a high-speed interface 808 connecting to memory 804 and high-speed expansion ports 810, and a low speed interface 812 connecting to low speed bus 814 and storage device 806. Each of the components 802, 804, 806, 808, 810, and 812, are interconnected using various busses, and can be mounted on a common motherboard or in other manners as appropriate. The processor 802 can process instructions for execution within the computing device 800, including instructions stored in the memory 804 or on the storage device 806 to display graphical information for a GUI on an external input / output device, such as display 816 coupled to high speed interface 808. In other implementations, multiple processors and / or multiple buses can be used, as appropriate, along with multiple memories and types of memory'. Also, multiple computing devices 800 can be connected, with each device providing portions of the necessary operations, e.g.. as a server bank, a group of blade servers, or a multi-processor system.[000122] The memory 804 stores information within the computing device 800. In one implementation, the memory 804 is a volatile memory' unit or units. In another implementation, the memory 804 is a non-volatile memory unit or units. The memory 804 can also be another form of computer-readable medium, such as a magnetic or optical disk. [000123] The storage device 806 is capable of providing mass storage for the computing device 800. In one implementation, the storage device 806 can be or contain a computer- readable medium, such as a floppy disk device, a hard disk device, an optical disk device, or a tape device, a flash memory or other similar solid state memory device, or an array of devices, including devices in a storage area network or other configurations. A computer program product can be tangibly embodied in an information carrier. The computer program product can also contain instructions that, when executed, perform one or more methods, such as those described above. The information carrier is a computer- or machine-readable medium, such as the memory 804, the storage device 806, or memory' on processor 802. [000124] The high speed controller 808 manages bandwidth-intensive operations for the computing device 800, while the low speed controller 812 manages lower bandwidth intensive operations. Such allocation of functions is exemplary only. In one implementation,the high-speed controller 808 is coupled to memory 804, display 816, e.g., through a graphics processor or accelerator, and to high-speed expansion ports 810, which can accept various expansion cards (not shown). In the implementation, low-speed controller 812 is coupled to storage device 806 and low-speed expansion port 814. The low-speed expansion port, which can include various communication ports, e.g., USB, Bluetooth, Ethernet, wireless Ethernet can be coupled to one or more input / output devices, such as a keyboard, a pointing device, mi crophone / speaker pair, a scanner, or a networking device such as a switch or router, e.g., through a network adapter. The computing device 800 can be implemented in a number of different forms, as shown in the figure. For example, it can be implemented as a standard server 820, or multiple times in a group of such servers. It can also be implemented as part of a rack server system 824. In addition, it can be implemented in a personal computer such as a laptop computer 822. Alternatively, components from computing device 800 can be combined with other components in a mobile device (not shown), such as device 850. Each of such devices can contain one or more of computing device 800, 850, and an entire system can be made up of multiple computing devices 800, 850 communicating with each other. [000125] The computing device 800 can be implemented in a number of different forms, as show n in the figure. For example, it can be implemented as a standard server 820, or multiple times in a group of such servers. It can also be implemented as part of a rack server system 824. In addition, it can be implemented in a personal computer such as a laptop computer 822. Alternatively, components from computing device 800 can be combined with other components in a mobile device (not shown), such as device 850. Each of such devices can contain one or more of computing device 800, 850, and an entire system can be made up of multiple computing devices 800, 850 communicating with each other.[000126] Computing device 850 includes a processor 852, memory 864, and an input / output device such as a display 854, a communication interface 866, and a transceiver 868, among other components. The device 850 can also be provided with a storage device, such as a micro-drive or other device, to provide additional storage. Each of the components 850, 852, 864, 854. 866, and 868, are interconnected using various buses, and several of the components can be mounted on a common motherboard or in other manners as appropriate. [000127] The processor 852 can execute instructions within the computing device 850, including instructions stored in the memory 864. The processor can be implemented as a chipset of chips that include separate and multiple analog and digital processors.Additionally, the processor can be implemented using any of a number of architectures. For example, the processor 810 can be a CISC (Complex Instruction Set Computers) processor, aRISC (Reduced Instruction Set Computer) processor, or a MISC (Minimal Instruction Set Computer) processor. The processor can provide, for example, for coordination of the other components of the device 850, such as control of user interfaces, applications run by device 850, and wireless communication by device 850.[000128] Processor 852 can communicate with a user through control interface 858 and display interface 856 coupled to a display 854. The display 854 can be, for example, a TFT (Thin-Film-Transistor Liquid Crystal Display) display or an OLED (Organic Light Emitting Diode) display, or other appropriate display technology. The display interface 856 can comprise appropriate circuitry for driving the display 854 to present graphical and other information to a user. The control interface 858 can receive commands from a user and convert them for submission to the processor 852. In addition, an external interface 862 can be provide in communication with processor 852, so as to enable near area communication of device 850 with other devices. External interface 862 can provide, for example, for wired communication in some implementations, or for w ireless communication in other implementations, and multiple interfaces can also be used.[000129] The memory 864 stores information within the computing device 850. The memory 864 can be implemented as one or more of a computer-readable medium or media, a volatile memory unit or units, or a non-volatile memory' unit or units. Expansion memory' 874 can also be provided and connected to device 850 through expansion interface 872, which can include, for example, a SIMM (Single In Line Memory Module) card interface. Such expansion memory 874 can provide extra storage space for device 850, or can also store applications or other information for device 850. Specifically, expansion memory 874 can include instructions to carry out or supplement the processes described above, and can include secure information also. Thus, for example, expansion memory 874 can be provide as a security module for device 850, and can be programmed with instructions that permit secure use of device 850. In addition, secure applications can be provided via the SIMM cards, along with additional information, such as placing identifying information on the SIMM card in a non-hackable manner.[000130] The memory can include, for example, flash memory and / or NVRAM memory, as discussed below. In one implementation, a computer program product is tangibly embodied in an information carrier. The computer program product contains instructions that, when executed, perform one or more methods, such as those described above. The information carrier is a computer- or machine-readable medium, such as the memory 864, expansionmemory' 874. or memory on processor 852 that can be received, for example, over transceiver 868 or external interface 862.[000131] Device 850 can communicate wirelessly through communication interface 866, which can include digital signal processing circuitry' where necessary7. Communication interface 866 can provide for communications under various modes or protocols, such as GSM voice calls, SMS, EMS, or MMS messaging, CDMA. TDMA, PDC, WCDMA, CDMA2000. or GPRS, among others. Such communication can occur, for example, through radio-frequency transceiver 868. In addition, short-range communication can occur, such as using a Bluetooth, Wi-Fi, or other such transceiver (not shown). In addition, GPS (Global Positioning System) receiver module 870 can provide additional navigation- and location- related wireless data to device 850, which can be used as appropriate by applications running on device 850.[000132] Device 850 can also communicate audibly using audio codec 860, which can receive spoken information from a user and convert it to usable digital information. Audio codec 860 can likewise generate audible sound for a user, such as through a speaker, e.g., in a handset of device 850. Such sound can include sound from voice telephone calls, can include recorded sound, e g., voice messages, music files, etc. and can also include sound generated by applications operating on device 850.[000133] The computing device 850 can be implemented in a number of different forms, as shown in the figure. For example, it can be implemented as a cellular telephone 880. It can also be implemented as part of a smartphone 882, personal digital assistant, or other similar mobile device.[000134] Various implementations of the systems and methods described here can be realized in digital electronic circuitry, integrated circuitry, specially designed ASICs (application specific integrated circuits), computer hardware, firmware, software, and / or combinations of such implementations. These various implementations can include implementation in one or more computer programs that are executable and / or interpretable on a programmable system including at least one programmable processor, which can be special or general purpose, coupled to receive data and instructions from, and to transmit data and instructions to, a storage system, at least one input device, and at least one output device.[000135] These computer programs (also known as programs, softw are, softw are applications or code) include machine instructions for a programmable processor, and can be implemented in a high-level procedural and / or object-oriented programming language, and / or in assembly / machine language. As used herein, the terms "machine-readable medium""computer-readable medium" refers to any computer program product, apparatus and / or device, e.g., magnetic discs, optical disks, memory, Programmable Logic Devices (PLDs). used to provide machine instructions and / or data to a programmable processor, including a machine-readable medium that receives machine instructions as a machine-readable signal. The term "machine-readable signal" refers to any signal used to provide machine instructions and / or data to a programmable processor.[000136] To provide for interaction with a user, the systems and techniques described here can be implemented on a computer having a display device, e.g., a CRT (cathode ray tube) or LCD (liquid crystal display) monitor for displaying information to the user and a keyboard and a pointing device, e.g., a mouse or a trackball by which the user can provide input to the computer. Other kinds of devices can be used to provide for interaction with a user as well; for example, feedback provided to the user can be any form of sensory feedback, e.g., visual feedback, auditory feedback, or tactile feedback; and input from the user can be received in any form, including acoustic, speech, or tactile input.[000137] The systems and techniques described here can be implemented in a computing system that includes a back end component, e.g., as a data server, or that includes a middleware component, e.g., an application server, or that includes a front end component, e.g., a client computer having a graphical user interface or a Web browser through which a user can interact with an implementation of the systems and techniques described here, or any combination of such back end. middleware, or front end components. The components of the system can be interconnected by any form or medium of digital data communication, e.g., a communication network. Examples of communication networks include a local area network ("LAN"), a wide area network ("WAN"), and the Internet.[000138] The computing system can include clients and servers. A client and server are generally remote from each other and typically interact through a communication network. The relationship of client and server arises by virtue of computer programs running on the respective computers and having a client-server relationship to each other.[000139] A number of embodiments have been described. Nevertheless, it will be understood that various modifications can be made without departing from the spirit and scope of the invention. In addition, the logic flows depicted in the figures do not require the particular order shown, or sequential order, to achieve desirable results. In addition, other steps can be provided, or steps can be eliminated, from the described flows, and other components can be added to, or removed from, the described systems. Accordingly, other embodiments are within the scope of the following claims.
Claims
CLAIMS1. A method for confidential analysis of personally identifiable information, the method comprising: deploying, using one or more computers, a virtual container hosted by a remote computing system; providing, using the one or more computers, an analytics application to the deployed within the virtual container; executing, using the one or more computers, the analytics application within a confidential computing enclave of the virtual container hosted by the remote computing system, wherein execution of the analytics application within the confidential computing enclave of the virtual container comprises: obtaining, within the confidential computing enclave of the deployed virtual container, encrypted personally identifiable information corresponding to one or more entities from data storage of a customer; decrypting, within the confidential computing enclave of the deployed virtual container, the obtained personally identifiable information; processing, within the confidential computing enclave of the deployed virtual container, the decrypted personally identifiable information using the analytics application to generate output data; and providing, from the confidential computing enclave of the deployed virtual container, the generated output data to the data storage of the customer.
2. The method of claim 1, further comprising: instructing, using the one or more computers, the remote computing system to delete the deployed virtual container.
3. The method of claim 1, wherein the remote computing system comprises one or more computers hosted in a cloud-computing environment.
4. The method of claim 1, wherein the remote computing system comprises one or more computers hosted on a different local area network (LAN) than the network hosting the one or more computers that deployed the virtual container.
5. The method of claim 1, wherein providing, using one or more computers, the analytics application to the deployed virtual container comprises installing, using one or more computers, the analytics software into a virtual computing environment hosted by the container.
6. The method of claim 1, wherein providing, using one or more computers, the analytics application to the deployed virtual container comprises transmitting the analytics application to the remote computing system hosting the deployed virtual container to which the analytics application was provided.
7. The method of claim 1, wherein the analytics application is a proprietary analytics application.
8. The method of claim 7, wherein the proprietary analy tics application is a computer program whose mode of operation cannot be revealed to an entity seeking output data generated by the proprietary analytics application.
9. The method of claim 7, wherein proprietary’ analytics application is a computer program whose mode of operation and software code is confidential.
10. A system for analyzing personally identifiable information using an analytics application, the system comprising: one or more computers; and one or more memory devices storing instructions that, when executed by the one or more computers, cause the one or more computers to perform the operations of method claims 1-9.
11. One or more computer-readable storage media storing instructions that, when executed by the one or more computers, cause the one or more computers to perform the operations of method claims 1-9.
12. (New) A method for confidential analysis of personally identifiable information, the method comprising:receiving, using one or more computers, instructions to deploy a virtual container from a computer of an analytics firm; generating, using the one or more computers, a virtual container in response to the received instructions; receiving, using the one or more computers, an analytics application into the generated virtual container; executing, using the one or more computers, the analytics application within a confidential computing enclave of the generated virtual container, wherein execution of the analytics application within the confidential computing enclave of the generated virtual container comprises: obtaining, within the confidential computing enclave of the generated virtual container and using the one or more computers, encrypted personally identifiable information corresponding to one or more entities from a first memory device that is outside of the virtual container; decrypting, within the confidential computing enclave of the generated virtual container and using the one or more computers, the obtained personally identifiable information; processing, within the confidential computing enclave of the generated virtual container and using the one or more computers, the decrypted personally identifiable information using the analytics application to generate output data; and storing, within the confidential computing enclave of the generated virtual container and using the one or more computers, the generated output in a second memory' device that is outside of the generated virtual container.
13. The method of claim 12, the method further comprising: receiving, using the one or more computers, an instruction to delete the generated virtual container; and, deleting, using the one or more computers, the deployed virtual container.
14. The method of claim 12, wherein the one or more computers include one or more computers of a cloud-computing environment.
15. The method of claim 12, wherein the one or more computers include one or more computers of a local area network (LAN).
16. The method of claim 12, the method further comprising: installing, using one or more computers, the analytics software into a virtual computing environment of the generated virtual container.
17. The method of claim 12, wherein the analytics application is a proprietary analytics application.
18. The method of claim 12, wherein the proprietary analytics application is a computer program whose mode of operation cannot be revealed to an entity seeking output data generated by the proprietary analytics application.
19. The method of claim 12, wherein the proprietary analytics application is a computer program whose mode of operation and software code is confidential.
20. The method of claim 12, wherein the first memory device and the second memory device are the same memory device.
21. A system for analyzing personally identifiable information using an analytics application, the system comprising: one or more computers; and one or more memory devices storing instructions that, when executed by the one or more computers, cause the one or more computers to perform the operations of method claims 12-20.
22. One or more computer-readable storage media storing instructions that, when executed by the one or more computers, cause the one or more computers to perform the operations of method claims 12-20.
23. A method for predicting a likelihood that an entity is going to develop a medical condition, the method comprising: obtaining, using one or more computers, encrypted personally identifiable information corresponding to the entity from data storage;decrypting, within a confidential computing enclave of a generated virtual container and using the one or more computers, the obtained personally identifiable information; mapping, within the confidential computing enclave and using the one or more computers, the decrypted personally identifiable information of the entity to a predefined schema; identifying, within the confidential computing enclave and using the one or more computers, one or more codes in the mapped information associated with the entity’s medical history; generating, within the confidential computing enclave and using the one or more computers, input data that includes the identified one or more codes associated with the entity’s medical history; providing, within the confidential computing enclave and using the one or more computers, the generated input data as an input to a machine learning model that has been trained to generate output data indicating a likelihood that the entity will develop one or more medical conditions based on processing of input data corresponding to one or more codes associated with the entity’s medical history; processing, within the confidential computing enclave and using the one or more computers, the provided input data through one or more layers of the machine learning model to generate output data indicating a likelihood that the entity will develop one or medical conditions; determining, within the confidential computing enclave and using the one or more computers, whether the entity is likely to develop one or more medical conditions in the future based on the determined one or more likelihoods in the generated output data; and based on a determination that the entity is likely to develop one or more medical conditions in the future, generating, within the confidential computing enclave and using the one or more computers, a report that includes information identifying the one or more medical conditions.
24. The method of claim 23, the method further comprising: storing, using the one or more computers, the generated report within a database without transmitting the report across a publicly accessible network.
25. The method of claim 23, wherein the one or more computers and the confidential computing enclave are hosted within a local area network (LAN).
26. The method of claim 25, the method further comprising: storing, using the one or more computers, the generated report within a database that is hosted by the local area network (LAN).
27. The method of claim 23, wherein determining, within the confidential computing enclave and using the one or more computers, whether the entity is likely to develop one or more medical conditions in the future based on the determined one or more likelihoods in the generated output data comprises: for each of a plurality of different medical conditions: determining, within the confidential computing enclave and using the one or more computers, whether a determined likelihood for the medical condition satisfies a predetermined threshold; and based on a determination that the determined likelihood for the medical condition satisfies the predetermined threshold, determining that the entity is likely to develop the medical condition.
28. The method of claim 23, wherein determining, within the confidential computing enclave and using the one or more computers, whether the entity is likely to develop one or more medical conditions in the future based on the determined one or more likelihoods in the generated output data comprises: for each of a plurality of different medical conditions: determining, within the confidential computing enclave and using the one or more computers, whether a determined likelihood for the medical condition satisfies a predetermined threshold; and based on a determination that the determined likelihood for the medical condition does not satisfy the predetermined threshold, determining that the entity is not likely to develop the medical condition.
29. The method of claim 23, wherein the one or more codes in the mapped information associated with the entity’s medical history include International Classification of Disease (ICD) diagnosis codes.
30. The method of claim 23, wherein the one or more codes in the mapped information associated with the entity’s medical history comprise Current Procedural Terminology (CPT) codes.
31. The method of claim 23, wherein the generated input data also includes additional information descnbing the entity.
32. The method of claim 23, wherein the additional information describing the entity comprises demographic data, insurance data, or financial data associated with the entity.
33. The method of claim 23, wherein the machine learning model comprises one or more neural networks.
34. A system for predicting a likelihood that an entity is going to develop a medical condition, the system comprising: one or more computers; and one or more memory devices storing instructions that, when executed by the one or more computers, cause the one or more computers to perform the operations of method claims 22-33.
35. One or more computer-readable storage media storing instructions that, when executed by the one or more computers, cause the one or more computers to perform the operations of method claims 22-33.
Citation Information
Patent Citations
System and method for providing secure execution environments using virtualization technology
US20200134171A1
Systems and methods for computing with private healthcare data
US20230044294A1