Encryption of on-site medical consent for clinical trials

By encrypting medical data on-site using a retinal camera, the challenges of patient recruitment bias and privacy breaches in clinical trials are addressed, enhancing data security and efficiency while ensuring representative participant pools.

WO2026161641A1PCT designated stage Publication Date: 2026-07-30VERILY HEALTH INC
View PDF 0 Cites 0 Cited by

Patent Information

Authority / Receiving Office
WO · WO
Patent Type
Applications
Current Assignee / Owner
VERILY HEALTH INC
Filing Date
2026-01-23
Publication Date
2026-07-30

AI Technical Summary

Technical Problem

Clinical trials face challenges with patient recruitment bias, privacy concerns, and data integrity due to involvement of multiple third parties, leading to resource-intensive and time-consuming processes that may result in fragmented systems and potential privacy breaches.

Method used

A medical device, such as a retinal camera, generates and encrypts medical data at the point of generation, allowing for secure storage and release only with patient consent, facilitating efficient and representative clinical trial participation.

Benefits of technology

Enhances data security, reduces resource intensity, and expands outreach for diverse participant pools by ensuring data integrity and privacy, thus improving the representativeness and efficiency of clinical trials.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure US2026012265_30072026_PF_FP_ABST
    Figure US2026012265_30072026_PF_FP_ABST
Patent Text Reader

Abstract

Introduced here are approaches for dynamically guiding an operator through an operation in which a digital image of a patient is generated and transmitted. A diagnostic platform may initiate generation of digital images of a retina of a user and responsive to detecting that generation of the one or more digital images is completed, display an interface that contains a request for medical data comprising the one or more digital images of the retina of the user and other data. Once user consent is received, one or more explanatory statements may be displayed on an external display of the retinal camera to convey how to obtain data relating to the request. The data may be encrypted and packaged, e.g., for transmission.
Need to check novelty before this filing date? Find Prior Art

Description

PATENTAtorney Docket No. 124824.8124.WO01ENCRYPTION OF ON-SITE MEDICAL CONSENT FORCLINICAL TRIALSCROSS-REFERENCE TO RELATED APPLICATION(S)

[0001] This application claims priority to US Provisional Application No.63 / 749,822, titled “ENCRYPTION OF ON-SITE MEDICAL CONSENT FOR CLINICAL TRIALS” and filed on January 27, 2025, which is incorporated by reference herein in its entirety.TECHNICAL FIELD

[0002] Various embodiments concern computer programs and associated computer-implemented techniques for encrypting data at a medical device for downstream usage.BACKGROUND

[0003] Clinical trials are a cornerstone of medical research, serving as the foundation for developing new treatments, therapies, and medical devices. They provide an important link between the laboratory and clinical practice and ensure that interventions are effective and safe for widespread use. Clinical trials help assess the efficacy, dosage, and potential side effects of new treatments.

[0004] In recent years, third parties have become increasing prevalent in the management and execution of clinical trials, reshaping how these trials are conducted. Traditionally, clinical trials were largely managed by academic institutions or pharmaceutical companies themselves, but today, a wide range of third-party organizations play key roles in the process. These include patient recruitment and trial site management.

[0005] The growing reliance on third parties is driven by the complexity and scale of modern clinical trials. With the advent of personalized medicine, biologies, and more intricate therapeutic areas, trials are becoming more and more elaborate and necessitate more than one organization. This outsourcing model has enabled pharmaceutical companies to streamline their operations, reduce costs, and accelerate the timelines of clinical trials.PATENTAtorney Docket No. 124824.8124.WO01

[0006] However, involvement of third parties brings with it other challenges. For example, while outsourcing can make trials more efficient, it can also lead to issues with oversight as well as security, and privacy concerns. In particular, ensuring that data integrity is upheld can be difficult when several different entities and stakeholders are involved and access data from a single trial. Moreover, coordination between multiple parties can lead to communication gaps, delays, and increased costs if not carefully managed. For example, conventional systems for clinical trials often require patients to sign many paper documents, which can be both time and resource intensive as it requires the doctor and patient to expend time during the process.BRIEF DESCRIPTION OF THE DRAWINGS

[0007] This patent or application contains at least one drawing executed in color. Copies of this patent or application publication with color drawings will be provided by the Office upon request and payment of the necessary fee.

[0008] Figure 1 depicts an example of a medical imaging device - more specifically, a retinal camera - that may be used to obtain clinical trial data at the point of generation of the medical data, according to some embodiments.

[0009] Figures 2A-B include examples of digital images that illustrate how artifacts may be visually similar to pathological features, according to some embodiments.

[0010] Figure 3 illustrates a network environment that includes a diagnostic platform which may be used to obtain clinical trial data, according to some embodiments.

[0011] Figure 4 illustrates an example of a computing device that includes a diagnostic platform that may be used to obtain clinical trial data at the point of generation of the medical data, according to some embodiments.

[0012] Figure 5 depicts an example of a communication environment that includes a diagnostic platform configured to acquire data from one or more sources, according to some embodiments.

[0013] Figure 6 depicts a flow diagram of a process for obtaining clinical trial data at the point of generation of the medical data, according to some embodiments.PATENTAtorney Docket No. 124824.8124.WO01

[0014] Figure 7 depicts a data structure for an exemplary request for obtaining clinical trial data fora clinical trial, according to some embodiments.

[0015] Figure 8A depicts an exemplary interface that can be presented to an operator as part of a process for obtaining consent for participation in clinical trials, according to some embodiments.

[0016] Figure 8B depicts an exemplary interface that can be presented to an operator as part of a process for obtaining patient data, such as patient contact information, according to some embodiments.

[0017] Figure 8C depicts an exemplary interface that can be presented to an operator responsive to a patient’s indication to discontinue obtaining patient data, according to some embodiments.

[0018] Figure 8D depicts an exemplary interface that can be presented to an operator as part of a process for obtaining enrollment data, according to some embodiments.

[0019] Figure 8E depicts an exemplary interface that can be presented to an operator to induce obtaining imaging data, according to some embodiments.

[0020] Figure 8F depicts an exemplary interface that can be presented to an operator responsive to completion of obtaining imaging data, such as OCT data, according to some embodiments.

[0021] Figure 9 depicts an exemplary interface that can be presented to an operator for facilitating response to patient questions, according to some embodiments.

[0022] Figure 10 is a block diagram illustrating an example of a processing system in which at least some operations described herein can be implemented, according to some embodiments.

[0023] Various features of the technologies described herein will become more apparent to those skilled in the art from a study of the Detailed Description in conjunction with the drawings. Embodiments are illustrated by way of example and not limitation in the drawings, in which like references may indicate similar elements. While the drawings depict various embodiments for the purpose of illustration, those skilled in the art will recognize that alternative embodiments may be employed without departing fromPATENTAtorney Docket No. 124824.8124.WO01the principles of the technologies. Accordingly, while specific embodiments are shown in the drawings, the technology is amenable to various modifications.DETAILED DESCRIPTION

[0024] Clinical trials (or simply “trials”) have played a crucial role in advancing medicine by providing evidence-based data that contributes to medical innovation, improving patient care and health outcomes across diverse populations. It is essential that clinical trials are performed correctly and that the subjects involved in clinical trials are sufficiently representative of the population at large - or at least a large enough segment of a population of interest (e.g., for which a drug, treatment, or medical device is intended) - given that the results of such clinical trials can directly influence medical treatments and public health. For example, when clinical trials are representative of diverse populations, they provide data that is more applicable to real-world patients, ensuring that new therapies are effective and safe for everyone, thus enabling more equitable healthcare outcomes.

[0025] However, there are several issues with clinical trials, particularly around patient recruitment, privacy, and representativeness of data. Historical means of recruitment for clinical trials often involves multiple steps, for example, patient data may initially be generated at healthcare facilities and stored by the corresponding healthcare systems. From there, clinical trial sponsors (or simply “sponsors”) may reach out to third-party companies that request data and consent either indirectly (e.g., via healthcare facilities) or directly (e.g., via social media) from patients to enlist potential candidates directly.

[0026] This approach leads to fragmented systems where clinical trial sponsors may not have direct access to patient information and must instead rely on healthcare providers or another third party to reach participants. Doing so is not only resource intensive and time consuming but also raises significant privacy concerns. Since trial managers typically do not directly hold patient data. Instead, trial managers rely on intermediaries to provide contact information or gauge interest, which creates ambiguity and risk in how patient data is acquired, shared, and managed. Furthermore, the process also necessitates the flow of sensitive information, including patient identities and health records, between organizations that do not always have the appropriate infrastructure to safeguard this data, which can lead to potential privacy breaches.PATENTAtorney Docket No. 124824.8124.WO01

[0027] The traditional method of clinical trial recruitment also can lead to biased participant pools due to limited outreach. For example, using social media advertisements to attract volunteers may lead to specific demographics - for example, in terms of age, ethnicity, or location - to be over-represented while other demographics are under-represented. Furthermore, clinical trials often rely on patient advocacy groups or health networks, but if these networks are small or have limited resources, outreach efforts may not reach a broad audience. As a result, the data collected from such participants may not apply more broadly to a larger set of real-world patients, limiting the usefulness of the clinical trial in assessing the general population’s response to a drug or treatment.

[0028] To address the issues discussed herein, approaches are introduced here for reducing weak points between entities, for example, for better security and privacy, by packaging data that is needed for a clinical trial at the point of generation of the medical data, such as on the medical device. As further discussed below, a medical device or computing system to which the medical device is communicatively connected may generate, derive, or otherwise obtain first medical data. For example, a medical device - or more specifically, a medical imaging device like a retinal camera device -may be configured to generate medical data including sensor data (e.g., imaging data, lab results, biopsy or pathology reports, etc.), or the medical device may alternatively or additionally generate recommended treatment information, prescriptions, vital signs, clinical notes, and the like, when an individual such as a patient comes in for treatment. The medical device may be a fundus camera (also called a “retinal camera’’) as further discussed below, and the data may include retinal images that can be encrypted according to various standards.

[0029] Responsive to receiving an indication of consent to being included in a clinical trial - or an indication of interest in participating in a clinical trial - from a subject, the medical device or computing system may obtain or otherwise access second medical data that may be needed for the subject to participate in a clinical trial. For example, the computing system may obtain such data through an interaction at the medical device by a user (e.g., a healthcare professional or the subject herself), or at a different device that is communicatively coupled to the medical device. Second medical data may include data such as medical history (e.g., immunization records, lifestylePATENTAtorney Docket No. 124824.8124.WO01data), biomarker data, and the like, as well as data that is associated with the subject rather than her medical treatment per se, such as billing and insurance information, demographic data, and personal identifying information (PH) such as name, age, address, phone number, and Social Security Number.

[0030] The first and second medical data may be processed and packaged locally, such as on the medical device, or a computing system that is communicatively coupled to the medical device. The processing may include encryption and storage until patient consent regarding specific clinical trials is received. By doing so, patient data can be securely stored in one location, and released only when necessary and enabled by an individual (e.g., a clinical trial manager, a healthcare professional, or the patient herself). Furthermore, by asking patients whether they would like to be considered for various clinical research and trials immediately when their data is generated, outreach for clinical trials can be expanded and representativeness may also be expanded since further communication and transfers are no longer necessitated.

[0031] In some examples, responsive to request for clinical trial data from a device from a clinical trial manager or clinical sponsor, the computing system may access the medical data and share the encrypted data with the clinical trial, or at least part of the data to the device of the clinical trial manager or sponsor.

[0032] Such systems may improve security and efficiency, as described herein, and may also be easier, time-effective, and less intimidating for patients and other users. As opposed to conventional systems that are time and resource intensive, such as by requiring patients to sign many paper documents, the techniques described herein allow for data and patient consent to be obtained efficiently through a system that generates medical data or obtains medical data in tandem with other devices quickly.

[0033] Embodiments may be described with reference to particular diseases, imaging devices, computer programs, or the like. However, those skilled in the art will recognize that these features are similarly applicable to other diseases, imaging devices, computer programs, or the like. For example, embodiments may be described in the context of detection models that are designed to be applied to digital images generated by retinal cameras. However, the relevant features may be similarly applicable to detection models that are designed to be applied to digital images of other parts of the human body.PATENTAtorney Docket No. 124824.8124.WO01

[0034] While embodiments may be described in the context of computerexecutable instructions, aspects of the technology can be implemented via hardware, firmware, or software. As an example, a set of algorithms indicative of a detection model designed to detect abnormal digital features that may be representative of artifacts may be executed by a diagnostic platform. The diagnostic platform could be embodied as a software program that offers support for reviewing digital images, rendering diagnoses, and cataloging treatments. In particular, the diagnostic platform may prompt a processor to execute instructions for acquiring a digital image generated by a retinal camera, applying the detection model to the digital image to detect abnormal digital features, classifying each abnormal digital feature as either an artifact or a pathological feature, and then storing data related to those abnormal digital features classified as artifacts in a memory.Exemplary Medical Device

[0035] According to some examples, the medical device may be a fundus camera. Fundus photography involves capturing an image of the fundus to document the retina, which is the neurosensory tissue in the eye that translates optical images into the electrical impulses that can be understood by the brain. The fundus can include the retina, optic disc, macula, fovea, and posterior pole.

[0036] Fundus cameras (also referred to as “retinal cameras”) are designed to provide an upright, magnified view of the fundus. Figure 1 depicts an example of a retinal camera. Generally, subjects (also referred to as “patients”) will sit at the retinal camera with their chin set within a chin rest and their forehead pressed against a bar. An operator may be responsible for visually aligning the retinal camera and then pressing a shutter release that causes an image of the retina to be generated.

[0037] As shown in Figure 1 , light may be focused via a series of lenses through a masked aperture to form an annulus that passes through an objective lens onto the retina. The illuminating light rays are generated by one or more light sources, each of which is electrically coupled to a power source. When the objective lens is aligned with the retina, light reflected by the retina will pass through the un-illuminated hole in the annulus formed by the masked aperture. Those skilled in the art will recognize that the optics of the retinal camera are generally similar to those of an indirect ophthalmoscopePATENTAtorney Docket No. 124824.8124.WO01in that the illuminating light rays entering the eye and the imaging light rays exiting the eye follow dissimilar paths.

[0038] The imaging light rays exiting the eye may initially be guided toward a telescopic eyepiece that is used by the operator to assist in aligning / focusing the illuminating light rays. When the operator presses the shutter release, a first mirror can interrupt the path of the illuminating light rays and a second mirror can fall in front of the telescopic eyepiece, which causes the imaging light rays to be redirected onto a capturing medium. Examples of capturing mediums include film, digital charge-coupled devices (CCDs), and complementary metal-oxide-semiconductors (CMOSs).

[0039] Medical professionals, such as optometrists, ophthalmologists, and orthoptists, may use the images generated by a retinal camera to detect and / or monitor diseases. For instance, these images may be used to document indicators of diabetes, age-macular degeneration (AMD), glaucoma, and the like.Terminology

[0040] References in this description to “an embodiment” or “one embodiment” means that the particular feature, function, structure, or characteristic being described is included in at least one embodiment. Occurrences of such phrases do not necessarily refer to the same embodiment, nor are they necessarily referring to alternative embodiments that are mutually exclusive of one another.

[0041] Unless the context clearly requires otherwise, the words “comprise” and “comprising” are to be construed in an inclusive sense rather than an exclusive or exhaustive sense (i.e. , in the sense of “including but not limited to”). The term “based on” is also to be construed in an inclusive sense rather than an exclusive or exhaustive sense. Thus, unless otherwise noted, the term “based on” is intended to mean “based at least in part on.”

[0042] The terms “connected,” “coupled,” or any variant thereof is intended to include any connection or coupling between two or more elements, either direct or indirect. The connection / coupling can be physical, logical, or a combination thereof. For example, objects may be electrically or communicatively coupled to one another despite not sharing a physical connection.PATENTAtorney Docket No. 124824.8124.WO01

[0043] The term “module” refers broadly to software components, firmware components, and / or hardware components. Modules are typically functional components that generate output(s) based on specified input(s). A computer program may include one or more modules. Thus, a computer program may include multiple modules responsible for completing different tasks or a single module responsible for completing all tasks.

[0044] When used in reference to a list of multiple items, the word “or” is intended to cover all of the following interpretations: any of the items in the list, all of the items in the list, and any combination of items in the list.

[0045] The sequences of steps performed in any of the processes described here are exemplary. However, unless contrary to physical possibility, the steps may be performed in various sequences and combinations. For example, steps could be added to, or removed from, the processes described here. Similarly, steps could be replaced or reordered. Thus, descriptions of any processes are intended to be open-ended.Overview of Exemplary Diagnostic Platform

[0046] Figure 3 illustrates a network environment 300 that includes a diagnostic platform 302. According to some examples, diagnostic platform 302 may be configured to obtain clinical trial data. For example, the diagnostic platform 302 may receive requests from various clinical trial sponsors or research organizations for medical data (e.g., diagnoses, images, etc.) and / or subject data (e.g., demographic data, treatment data, etc.). The diagnostic platform 302 may then be used to facilitate guidance for capturing medical data such as digital images.

[0047] Alternatively or additionally, rather than collecting digital images, the diagnostic platform may be used to facilitate guidance for capturing medical data such as ocular data. Ocular data may include, for example, pupillometry data (e.g., pupil diameter, speed of constriction and dilation, latency of response to light stimuli), autorefractor (eye focusing) data (e.g., spherical power, cylindrical power), keratometry data, corneal topography data, optical coherence tomography data, visual field data, electroretinography data, intraocular data, or the like. Other data may include anterior eye imaging and visual fields data.PATENTAtorney Docket No. 124824.8124.WO01

[0048] Additionally, although the diagnostic platform 302 is described to facilitate guidance for capturing medical data such as digital images. In some embodiments, the diagnostic platform may be communicatively coupled to, or pair to, separate medical device(s) that may be configured to capture medical data. For example, the separate medical device(s) may obtain or capture medical data and transmit the data to the diagnostic platform 302 automatically, or may be configured to transmit the data responsive to a request from the diagnostic platform.

[0049] Once the medical data is captured, diagnostic platform 302 may be used to facilitate obtaining a subject’s consent for participation in a clinical trial, obtaining subject data relating to the clinical trial, and may also be used to generate a data package for transmittal comprising the medical data and / or subject data.

[0050] Individuals can interact with the diagnostic platform 302 via an interface 304. For example, medical professionals may access the interface 304 to review the digital images generated by an imaging device, such as a retinal camera, a mobile phone, or a digital camera (e.g., a digital single-lens reflex (DSLR) camera or a mirrorless camera), in order to diagnose the human bodies captured in those images. Moreover, medical professionals may access the interface 304 to review the outputs produced by diagnostic models that have been applied to those images.

[0051] Diagnostic models may be applied to images generated during a diagnostic session in order to identify the regions of pixels that are clinically or diagnostically relevant. When applied to a digital image, a diagnostic model may produce an output that is indicative of the health state of a corresponding subject. Some diagnostic models produce proposed diagnoses that can be examined by a medical professional, while other diagnostic models produce a visualization component (or simply “visualization”) intended to help the medical professional render a diagnosis. The term “health state” can refer to the physical health of the subject with respect to a given disease. For example, a diagnostic platform could be designed to identify digital features that are known to be indicative of diabetic retinopathy (DR), glaucoma, and the like.

[0052] The decisions made by medical professionals and the outputs produced by diagnostic models will only be appropriate if the analysis is limited to pathological features in the digital images, however, so it is important that the diagnostic platform 302 ensure that non-pathological features (also referred to as “artifacts”) are notPATENTAtorney Docket No. 124824.8124.WO01considered. Identifying the artifacts in digital images, therefore, may be a critical part of the diagnostic process.

[0053] To identify the artifacts in a digital image, the diagnostic platform 302 may apply a detection model to the digital image. This digital image could be generated before, during, or after a diagnostic session as further discussed below. When applied to the digital image, the detection model may produce an output that identifies digital features which could be representative of artifacts. Each digital feature may correspond to a segmented region of pixels in the digital image that the detection model has determined is abnormal or unexpected given an expected output. For example, a detection model may be trained to identify digital features in retinal images that are abnormal given the known physiology of the fundus. These abnormal digital features may be representative of either pathological features or artifacts, and therefore may be classified as such. The goal of the detection model may be to determine whether each digital feature is pathological or non-pathological and then ensure that artifacts are not considered (e.g., by diagnostic models or medical professionals) when diagnosing the health state.

[0054] As described herein, once medical data such as images, diagnoses, or visualization, or health state has been generated or otherwise obtained, the interface 304 may display an interface that contains a request for the medical data. For example, the diagnostic platform may recognize that the patient may be a good fit (e.g., match criteria) for participation for a clinical trial based on the patient’s medical data. The platform may display an interface that alerts an operator to an opportunity for the patient to participate. Alternatively or additionally, the platform may display, via the interface, various clinical trial opportunities for a patient and the operator may select one or more for further steps, such as next steps to receive the patient’s consent or to see the criteria needed for a patient to participate.

[0055] If a patient consents to participate in a clinical trial, (e.g., transmit medical data to a third party) the operator may use the interface to input an indication of consent. For example, the operator may simply press a button on a display to indicate that “yes” the patient would like to proceed with a clinical trial. Responsive to receiving the indication, the interface 304 may be used to display a second interface that contains explanatory statements that convey, to the operator, how to obtain subject data relatingPATENTAtorney Docket No. 124824.8124.WO01to the clinical trial. The platform may then generate a package including the medical data (e g., digital images) and / or subject data (e.g., demographic information). According to some examples, the package or constituent data may be encrypted according to various standards.

[0056] In some examples, based on receiving inputs for subject data like demographic information relating to the request, the system may automatically relocate explanatory statements for obtaining a remaining portion of the data for which inputs have not yet been received to the top, and remove explanatory statements for which data has been received (e.g., through inputs by the operator or subject). Once the system determines that all inputs for the data has been received, it may generate an encrypted package that includes the one or more digital images and the other data in response.

[0057] As described herein, diagnostic platform 302 may be communicatively coupled to or paired with one or more separate medical devices configured to obtain or capture and transmit medical data. In some examples, the subject data may include further measurements, imaging, diagnoses, or the like. The subject data may be able to be captured by one or more of the separate medical devices. In some embodiments, responsive to obtaining an indication of a patient’s consent, the platform may transmit a request for needed subject data to one or more medical devices. The devices may capture the data and transmit to the platform fordownstream processing and packaging as described herein.

[0058] For example, an operator may capture a retinal image or retinal data (e.g., such as through a retinal camera device) for a patient and the patient may qualify for a clinical trial. Upon consenting to the trial, the diagnostic platform may determine that subject data includes data that must be captured by various medical devices. In one example, the system may determine whether various medical devices are connected to the diagnostic platform by consulting a list of available devices, or may simply determine if the medical devices are connected to the network (e.g., via Bluetooth). For example, the subject data needed may include a weight or a blood pressure which may be obtained using a scale, or a blood pressure cuff. The interface may guide the operator such as through one or more statements, as described herein, to guide the patient through usage of each medical device and / or obtaining the necessary subject data.PATENTAtorney Docket No. 124824.8124.WO01

[0059] As shown in Figure 3, the diagnostic platform 302 may reside in a network environment 300. Thus, the diagnostic platform 302 may be connected to one or more networks 306a-b. The network(s) 306a-b can include personal area networks (PANs), local area networks (LANs), wide area networks (WANs), metropolitan area networks (MANs), cellular networks, the Internet, etc. Additionally or alternatively, the diagnostic platform 302 can be communicatively coupled to computing device(s) over a short-range wireless connectivity technology, such as Bluetooth® or Near Field Communication (NFC).

[0060] The interface 304 is preferably accessible via a web browser, desktop application, mobile application, or over-the-top (OTT) application. Accordingly, the interface 304 may be viewed on a personal computer, tablet computer, mobile workstation, mobile phone, game console, wearable electronic device (e.g., a watch or fitness accessory), network-connected (“smart”) electronic device, (e.g., a television or home assistant device), or virtual / augmented reality system (e.g., a head-mounted display).

[0061] Some embodiments of the diagnostic platform 302 are hosted locally. That is, the diagnostic platform 302 may reside on the computing device used to access the interface 304. For instance, the diagnostic platform 302 may be embodied as a mobile application executing on a mobile phone ora desktop application executing on a mobile workstation. Other embodiments of the diagnostic platform 302 are executed by a cloud computing service operated by, for example, Amazon Web Services® (AWS), Google Cloud Platform™, or Microsoft Azure®. In such embodiments, the diagnostic platform 302 may reside on a network-accessible server system 308 comprised of one or more computer servers. These computer servers can include images generated by imaging devices, subject information (e.g., age, sex, health diagnoses, etc.), imaging device information (e.g., resolution, expected file size, etc.), diagnostic models, detection models, and other assets. Those skilled in the art will recognize that this information could also be distributed amongst a computing device and a network-accessible server system.

[0062] While some embodiments are described in the context of network-accessible interfaces, those skilled in the art will recognize that the interfaces need not necessarily be accessible via a network. For example, a computing device may executePATENTAtorney Docket No. 124824.8124.WO01a self-contained computer program that does not require network access. Instead, the self-contained computer program may download assets (e g., images, diagnostic models, detection models, or processing operations) at a single point in time or on a periodic basis.

[0063] Figure 4 illustrates an example of a computing device 400 that includes a diagnostic platform 410 able to facilitate a guided process for capturing digital images and obtain patient consent for participation in a clinical trial. In some embodiments, the computing device 400 is representative of a medical device that is capable of generating physiological measurements or indicators (e.g., images) that are representative of physiological state or from which physiological state is derivable. For example, in the event that the computing device is an imaging device such as a retinal camera, the computing device 400 may be configured to obtain medical data such as digital images of a retina of a subject (e.g., patient), diagnoses detected based on imaging, and the like. In other embodiments, the computing device 400 is representative of a computing system that is communicatively connectable to a medical device. For example, the computing device 400 may be representative of a mobile phone, tablet computer, or laptop computer that is communicatively connected to an imaging device from which images are received via the communication module 408.

[0064] As further discussed below, if a patient consents to participation in a clinical trial, other data may be obtained from the patient, such as contact information or demographic information. The computing device 400 may generate a package for transmitting the data to one or more devices that are associated with the clinical trial, such as one or more devices of the clinical trial sponsor.

[0065] As shown in Figure 4, the computing device 400 can include a processor 402, a memory 404, one or more displays 406, and a communication module 408. Each of these components is discussed in greater detail below. Those skilled in the art will recognize that different combinations of these components may be present depending on the nature of the computing device 400. For example, some embodiments of the computing device 400 may include multiple displays, namely, an internal display that is observable by the patient while her eye is situated near the computing device 400 and an external display that is observable by the operator. However, if digital images, or analyses of the digital images, or other interfacing elements are to be viewed by thePATENTAtorney Docket No. 124824.8124.WO01operator on another computing device rather than the computing device 400, then the computing device 400 may not include the external display.

[0066] The processor 402 can have generic characteristics similar to general-purpose processors, or the processor 402 may be an application-specific integrated circuit (ASIC) that provides control functions to the computing device 400. The processor 402 can be coupled to all components of the computing device 400, either directly or indirectly, for communication purposes.

[0067] The memory 404 may be comprised of any suitable type of storage medium, such as static random-access memory (SRAM), dynamic random-access memory (DRAM), electrically erasable programmable read-only memory (EEPROM), flash memory, or registers. In addition to storing instructions that can be executed by the processor 402, the memory 404 can also store data generated by the processor 402 (e.g., when executing the modules of the diagnostic platform 410). Further, the memory 404 may store digital images generated by the computing device 400, for example, before the digital images are transmitted external to the computing device 400. Note that the memory 404 is merely an abstract representation of a storage environment. The memory 404 could be comprised of actual integrated circuits (also called “chips”).

[0068] Each display 406 can be any mechanism that is operable to visually convey information to a subject. For example, each display 406 may be a panel that includes light-emitting diodes (LEDs), organic LEDs, liquid crystal elements, or electrophoretic elements. In embodiments where the computing device 400 includes more than one display (e.g., an internal display and external display), the displays may not be identical to one another. For example, an external display may have larger dimensions or higher resolution than an internal display. As another example, the external display may be touch sensitive while the internal display may not be touch sensitive. Thus, the operator may be able to provide input to the diagnostic platform 410 by interacting with the external display, either directly or indirectly (e.g., via a control mechanism, such as a computer mouse, joystick, etc.). Meanwhile, the internal display is generally not interactable but is instead used to visually convey information to the patient as part of the imaging operation.PATENTAtorney Docket No. 124824.8124.WO01

[0069] The communication module 408 may be responsible for managing communications external to the computing device 400. The communication module 408 may be wireless communication circuitry that is able to establish wireless communication channels with other computing devices. Examples of wireless communication circuitry include 2.4 gigahertz (GHz) and 5 GHz chipsets compatible with Institute of Electrical and Electronics Engineers (IEEE) 802.11 - also referred to as “Wi-Fi chipsets.” Alternatively, the communication module 208 may be representative of a chipset configured for Bluetooth, NFC, and the like.

[0070] As described herein, the communication module 408 may be configured to receive requests from various devices associated with entities for obtaining clinical trial data (e.g., clinical trial managers, clinical trial sponsors). The requests may include various parameters that specify the quality of data needed for the clinical trial (e.g., accuracy, precision), types of data needed (e.g., types of imaging formats), demographics from which the data is needed (e.g., age, height, etc.), and specific formatting including for compliance with regulatory standards needed for the data. For example, Figure 7 depicts a data structure for an exemplary request 700 for obtaining clinical trial data for a clinical trial, according to some embodiments. The request may include a request identifier “requestjd” which may be used to identify the request. The request identifier may be a unique alphanumeric string according to some examples.

[0071] Request 700 may specify the data requested. In the example of figure 7, the request may be for a patient’s email “user_email”, patient’s name “user_name”, retinal images of the patient “[retinaljmages]”, a patient diagnosis “diagnosis”, patient age “user_age”, patient location “userjocation”, and a gender of the patient “user_gender”. The request may also specify requirements such as a required age of the patient, which is specified as between 17 and 65 “user_age > 17; user_age <65”, a quality and format of the retinal images “[retinaljmages]. quality >= 500, [retinal_images].format == ‘DICOM’” and whether or not encryption is required “[retinaljmages], encryption_flag = TRUE].”

[0072] For convenience, the diagnostic platform 410 is referred to as a computer program that resides in the memory 404. However, the diagnostic platform 410 could be comprised of hardware or firmware in addition to, or instead of, software. In accordance with some embodiments described herein, the diagnostic platform 410 mayPATENTAtorney Docket No. 124824.8124.WO01include a processing module 412, an analysis module 414, and a graphical user interface (GUI) module 416. These modules can be an integral part of the diagnostic platform 410. Alternatively, these modules can be logically separate from the diagnostic platform 410 but operate “alongside” it. Together, these modules may enable the diagnostic platform 410 to facilitate a guided process for generating digital images.

[0073] The processing module 412 may be responsible for both obtaining medical data and transmitting medical data responsive to patient consent. For example, the computing device 400 may initiate generation of medical data such as one or more digital images of a retina of a subject generated by a retinal camera. In some examples, an operator may interact through the external interface to initiate generation of medical data, e.g., through selection of one or more GUI options. Alternatively or additionally, the computing device 400 may automatically initiate generation of medical data by detecting a patient at the device. In particular, the computing device 400 may determine a time to initiate imaging based on opportune parameters such as minimal movement or maximum clarity that may be determined using sensors (e.g., accelerometers) on the device or based on algorithmic processing on the device. For example, if a predetermined threshold for movement is met and not exceeded, imaging may be performed.

[0074] In another example, the imaging may be performed response to an indication that the patient has correctly been aligned at the medical device, e.g., retinal camera. For example, the patient may be tasked with completing a visual game as part of the aligning operation which may trigger image capture. Specifically, the patient interface (e.g., internal interface) may include a pair of geometric shapes, and the patient may be tasked with matching, overlaying, or otherwise positioning one of the geometric shapes with respect to the other geometric shape. For example, the patient may be instructed - by the operator or patient interface - to overlay a first circle on a second circle by moving her head with respect to the retinal camera. To move the first circle, the patient can move her heard along the x-, y-, and z-axes, thereby shifting the location of the retinal with respect to the eyebox. As the patient moves her head from side to side, the first geometric shape may similarly move from side to side with respect to the second geometric shape. As the patient moves her eye nearer to, or further from, the retinal camera, the size of the first geometric shape can vary. For example, the firstPATENTAtorney Docket No. 124824.8124.WO01geometric shape can increase in size as the eye moves nearer to the retinal camera, and the first geometric shape can decrease in size as the eye moves further from the retinal camera.

[0075] When the patient moves her head such that the geometric shapes match, an indication of the match may be presented on the internal display. For example, a first geometric shape may initially be rendered in a first color (e.g., red) and a second geometric shape may initially be rendered in a second color (e.g., blue), and when the first and second geometric shapes overlay one another, the combined geometric shape may be rendered in a third color (e.g., purple). As another example, the first and second geometric shapes may initially be rendered in a first color (e.g., white), and when the first and second geometric shapes overlay one another, the combined geometric shape may be rendered in a second color (e.g., blue). When the first and second geometric shapes overlap one another, the diagnostic platform may produce, as output, a signal that prompts generation of a digital image. Accordingly, the retinal camera may generate a digital image after the patient causes the first geometric shape to match the second geometric shape.

[0076] After imaging is performed, the processing module 412 may process (e.g., denoise, filter, or otherwise alter) the pixel data of the image(s) so that it is usable by the other modules of the diagnostic platform 410. In some embodiments, the diagnostic platform 410 is configured to produce, as output, raw digital images that are generated by the computing device 400. In other embodiments, the diagnostic platform 410 is configured to produce, as output, data objects that include pixel data corresponding to the digital images that are generated by the computing device 400. One example of a data object is a Digital Imaging and Communications in Medicine (DICOM) data object. In embodiments where the diagnostic platform 410 outputs DICOM data objects, each DICOM data object can include the pixel data corresponding to a digital image and context data related to attributes of the digital image. The processing module 412 may be responsible for populating the pixel data and context data into each DICOM data object. The context data may include information regarding the patient whose eye is captured in the digital image, the computing device 400 responsible for generating the digital image, the imaging session in which the digital image was generated, or the digital image itself.PATENTAtorney Docket No. 124824.8124.WO01

[0077] When a session for obtaining medical data is completed, such as when generation of digital imaging is completed, or when a diagnosis or treatment plan is determined or entered into the computing device by the operator, the processing module 412 and GUI module 416 may be triggered to guide the operator to obtain patient consent for participation in a clinical trial. For example, GUI module 416 can generate interfaces that are viewable on the displays 406. Several examples of interfaces are discussed below. In addition to those examples, the GUI module 416 could generate interfaces through which the operator can interact with the diagnostic platform 410, view outputs produced by the diagnostic platform, and the like. Additionally, the GUI module 416 could generate interfaces through which information regarding the patient, the computing device 400, the imaging session, or individual digital images may be posted for presentation on the displays 406.

[0078] Responsive to detecting that a session for obtaining medical data is completed (e.g., generation of the one or more digital images is completed), the GUI module 416 may be used to generate a first interface that contains a request for medical data such as one or more digital images of the retina of the patient and / or other patient data. In some examples, patient data may include name, birthdate, ocular ailments, ocular medications, and the like. In some examples, the patient data may include session information include time, location, operator name, and the like. Additionally or alternatively, the data could include information regarding the retinal camera, such as model name, settings, resolution, and the like. For example, the GUI module 416 may generate and display a request that includes some or all of the data from the requests of the various devices associated with the clinical trial, such as devices of the clinical trial sponsor.

[0079] For example, the computing device 400 may recognize that the patient may be a good fit (e.g., match various criteria) for participation for a clinical trial based on the patient’s medical data. For example, the computing device 400 may compare obtained data for the patient to the requirements specified by the requests (e.g., request 700). In one example, computing device 400 may compare values of the subject data to values for the one or more specific parameters to determine a similarity score. Responsive to determining that the similarity score exceeds a predetermined value, the device may display an interface via an external display that alerts an operator to anPATENTAtorney Docket No. 124824.8124.WO01opportunity for the patient to participate. Alternatively or additionally, responsive to determining that the similarity score does not exceed a predetermined threshold, the device may generate and display another interface that contains an explanatory statement conveying, to the operator, that the subject is not a good match for the clinical trial.

[0080] According to some embodiments, determining whether a subject is a good match or good fit comprises comparing the obtained data to a group of subjects previously selected for the trial. For example, because diversity is important in clinical trials to ensure findings of such trials are representative of all groups, the system may identify whether or not values for the subjects, such as age, ethnicity, and the like are too similar or the same as subjects previously selected for the trial. In some examples, the system may do so by executing a script that compares values of specific parameters against each other and determining that the values associated with the subject are different enough from those previously selected (e.g., a Euclidean distance exceeds a predetermined threshold). Alternatively or additionally, the system may automatically identify diverse candidates, such as candidates from various locations and nonrepresentative populations, from a group of selected individuals such as through stratified sampling, or cluster sampling.

[0081] According to some embodiments, rather than identifying the clinical trials for which the subject is a good match, the diagnostic platform 410 may display, via the interface, all clinical trial opportunities for a patient and the operator may select one or more options to view further steps needed for each, such as to see next steps to receive the patient’s consent or to see the criteria needed for a patient to participate.

[0082] In some examples, one of the parameters of the request may include a minimum threshold value for quality (e.g., “[retinal mages], quality >= 500”) and analysis module 414 can be used to examine the digital image to determine quality of the digital image(s). For example, the analysis module 414 may implement an algorithm that determines, based on an analysis of the corresponding pixel data, whether quality of a digital image is sufficient for diagnostic purposes, or for clinical trial purposes. As further discussed below, the algorithm may examine metrics produced for the pixels of the digital image in order to determine quality of the digital image as a whole. Each metric may be indicative of quality of the corresponding pixel. For example, each metricPATENTAtorney Docket No. 124824.8124.WO01may be indicative of brightness of the corresponding pixel. Digital images that are “unusual but acceptable” may have features, such as spotting, that are visually noticeable though the quality (e.g., as measured in brightness or blurriness across the entire digital image) may otherwise be acceptable. Quality assessments are described further herein under “Guidance Regarding Quality of Digital Images Generated by Retinal Cameras.”

[0083] The analysis module 414 may identify that the metric for quality does not exceed a minimum threshold value. Responsive to determining that the metric for quality does not exceed the minimum threshold value, the GUI module may be used to generate and display an interface that contains a request for recapturing the one or more digital images. For example, the interface may direct the operator to explain to a patient why imaging should be performed again, as well as steps to perform reimaging.

[0084] As described herein, the device may display an interface via an external display that alerts an operator to one or more opportunities for clinical trials for the patient to participate or the device may display, via the interface, all clinical trial opportunities for a patient and the operator may select one or more options to view further steps needed for each. The display may contain one or more conversational statements, each of which is intended to help the operator engage with the patient. The device may also be configured to receive input from an operator or a patient indicating whether or not the patient consents to participate in the clinical trial, e.g., and consents to transmit the medical data.

[0085] Responsive to receiving input indicative of subject consent for transmitting the medical data, e.g., provided through the first interface the GUI module may be configured to display an interface that contains one or more explanatory statements on an external display of the retinal camera. The explanatory statements may convey, to the operator, how to obtain subject data relating to the request. In the example of Figure 7, the explanatory statements may convey how to obtain the patient’s contact information (e.g., “user_email”, “user_name”) and other patient information that is needed in the clinical trial (e.g., “user_age, userjocation, user_gender”).

[0086] As described herein, explanatory content may be designed to teach the operator how to obtain subject data, while other explanatory content may be designed to explain to the operator how to explain what kinds of patient data is needed and howPATENTAtorney Docket No. 124824.8124.WO01it might be used to the patient. Explanatory content may include statements explaining why certain types of data are needed, explain how the process might work, examples of how / when the data will be used, and / or the like. Often, the interface includes a combination of the aforementioned forms of explanatory content in order to assist the operator in several different ways.

[0087] As described herein, based on receiving inputs for subject data relating to the request, the system may automatically relocate explanatory statements. In one example, it may remove the explanatory statements automatically once a corresponding portion of data has been obtained or simply placed at the bottom of the queue on the display or on a different page. The remaining explanatory statements for which data has not yet been received (e.g., through inputs by the operator or subject) may be relocated to the top of the queue. Once the system determines that all inputs for the data has been received, it may generate an encrypted package.

[0088] For example, after obtaining the necessary data from the patient by an operator, the computing device 400 may generate an encrypted package comprising the one or more digital images and the subject data using encryption module 418. For example, the computing device may identify, from a request for clinical trial data, one or more standards for encryption, e.g., for personal identifiable information (Pll) and digital images of retinas. The encryption module 418 may subsequently encrypt, based on a data type, each of the one or more digital images and subject data separately to generate encrypted data and may aggregate the encrypted data to form the encrypted package.

[0089] In some examples, the encryption may include Advanced Encryption Standard (AES) such as AES-256, T ransport Layer Security (TLS) such as TLS 1.2 and TLS 1.3, Fully Homomorphic Encryption (FHE), DICOM encryption, Public Key Infrastructure (PKI), and / or the like. According to some examples, the encryption module 418 may comprise a machine learning model which may format the data in a requested format specified in the request. Additionally, the machine learning model may be used to format or generate requests for encrypting data according to various standards. For example, the input to the machine learning model may comprise a desired format from the request and the data needed and the output of the model may include a package or data structure in the desired format comprising the data.PATENTAtorney Docket No. 124824.8124.WO01

[0090] The encrypted package may be sent to a remote server for devices associated with the selected clinical trial(s). In some examples, the computing device 400 may track access to the encrypted package by embedding a device token for a device associated with the patient. For example, a device token may include a unique string generated by a service when an application on the mobile device is registered to receive notifications (e.g., push notifications). For example, when a patient consents to participating in the clinical trial, the operator may help the patient install an app on the patient’s mobile device and opt to receive notifications regarding their data. The application may request a device token which may be sent to the application’s backend server. The server may store this token and use it to send notifications, e.g., indicating when the encrypted data is accessed. Thus, whenever it is detected that a third party has accessed the encrypted package, the device token may be used to transmit a notification of access to the device associated with the subject.

[0091] According to some examples, the patient may subsequently determine to withdraw access to some or all of their data. For example, the computing device 400 may receive, from an authorized device, a request to withdraw consent for accessing medical data of the subject and cause removal from storage of the encrypted package.

[0092] Figure 5 depicts an example of a communication environment 500 that includes a diagnostic platform 502 configured to acquire data from one or more sources. Here, the diagnostic platform 502 may receive data from a retinal camera 506, laptop computer 508, or network-accessible server system 510 (collectively referred to as the “networked devices”). For example, the diagnostic platform 502 may obtain pixel data from the retinal camera 506 and other data (e.g., context data, detection models, processing operations) from the laptop computer 508 or network-accessible server system 510.

[0093] The networked devices can be connected to the diagnostic platform 502 via one or more networks 504a-c. The network(s) 504a-c can include PANs, LANs, WANs, MANs, cellular networks, the Internet, and the like. Additionally or alternatively, the networked devices may communicate with one another over a short-range wireless connectivity technology, such as Bluetooth or NFC. For example, if the diagnostic platform 502 resides on the network-accessible server system 510, data received from the network-accessible server system 510 need not traverse any networks. However,PATENTAtorney Docket No. 124824.8124.WO01the network-accessible server system 510 may be connected to the retinal camera 506 and laptop computer 508 via separate Wi-Fi communication channels.

[0094] Embodiments of the communication environment 500 may include a subset of the networked devices. For example, some embodiments of the communication environment 500 include a diagnostic platform 502 that receives pixel data from the retinal camera 506 (e.g., in the form of DICOM data objects) and additional data from the network-accessible server system 510 on which it resides. As another example, some embodiments of the communication environment 500 include a diagnostic platform 502 that receives pixel data from a series of retinal cameras located in different environments (e.g., different clinics).

[0095] Figure 6 depicts a flow diagram of a process for obtaining clinical trial data at the point of generation of the medical data, according to some embodiments. Initially, a diagnostic platform can initiate generation of one or more digital images of a retina of an individual, such as a subject or patient, generated by a retinal camera (step 601). Said another way, the diagnostic platform can acquire one or more digital image generated by a retinal image during an imaging session. Multiple digital images may be generated over the course of the imaging session, and each of these digital images can be analyzed.

[0096] In some embodiments the digital image is generated in conjunction with visible radiation (also referred to as “visible light”) emitted by the retinal camera, while in other embodiments the image is generated in conjunction with infrared radiation (also referred to as “infrared light”) emitted by the retinal camera. Infrared light is electromagnetic radiation with wavelengths longer than those of visible light. Wavelengths in the infrared spectrum range normally range from the nominal red edge of the visible spectrum at 700 nanometers (nm) to approximately 1 millimeter (mm).

[0097] Then, the diagnostic platform can, in response to a determination that generation of the one or more digital images is complete, display on a first interface a request for medical data (step 602). The request may be a request from a device of a clinical sponsor, for example, and indicate the types of information and criteria required to participate in the clinical trial.

[0098] The diagnostic platform can then receive, via the first interface, first input indicative of consent from the individual to transmit the medical data to a destinationPATENTAtorney Docket No. 124824.8124.WO01(step 603). For example, the diagnostic platform may receive an input such as an interaction of the operator or patient at the device indicating that the patient consents to providing their information for use in a clinical trial. The destination may include, for example, a computer server that is accessible via the Internet. In some examples, the destination is a computer server accessible through Internet by an entity device that generated the request.

[0099] The diagnostic platform may display, via a second interface, one or more explanatory statements, wherein each conveys, to an operator of the retinal camera, how to obtain the other data relating to the request (step 604). The platform may subsequently generate an encrypted package that includes the one or more digital images and the other data (step 605).

[0100] In some examples, the device may identify that the quality of images generated is not of a good enough quality for use in clinical trials. For example, the diagnostic platform may identify artifacts such as based on a comparison of the appearance of segmented region of pixels in a frame captured in conjunction with infrared light and a frame captured in conjunction with visible light. In some embodiments, this determination is based on how the corresponding segmented region of pixels varies as different light sources (e.g., light-emitting diodes) are illuminated. Some artifacts will noticeably vary when different light sources are illuminated.Promoting Engagement Through Dynamic Presentation of Visual Guides

[0101] Figures 8A-F and 9 include examples of interfaces that can be presented to an operator or patient as part of an imaging operation. As further discussed below, these interfaces may be shown in an effort to guide the operator or patient through different stages of the imaging operation. These stages can include a consent obtaining operation and an inquiry response operation. The consent obtaining operation is further described with reference to Figures 8A-F and the inquiry response operation is further described with reference to Figure 9.

[0102] Most of the interfaces are designed to be presented by the retinal camera on its external display for review by an operator. However, these interfaces could be presented by another computing device as discussed above. For example, these interfaces may be presented on a tablet computer that is communicative connected toPATENTAtorney Docket No. 124824.8124.WO01the retinal camera and accessible to the operator. Several of these interfaces are designed to be presented by the retinal camera on its internal display for review by a patient. Whether a given interface is generally presented on the external display or internal display may be readily determinable based on its content and intended audience.Approaches to Obtaining Patient Consent

[0103] To facilitate the review of digital images generated by a retinal camera, interfaces may be generated by the diagnostic platform and presented by the retinal camera as part of a reviewing operation. These interfaces may collectively define a “flow” that is intended to guide an operator through a consent obtaining operation and an optional inquiry response operation.

[0104] Initially, once digital imaging for a patient is completed, the operator may be shown an interface that indicates a consent obtaining operation has begun for the patient, as shown in Figure 8A. In some embodiments the consent obtaining operation begins immediately after the digital image is generated by the retinal camera, while in other embodiments the review operation begins in response to the retinal camera receiving, from the operator, input indicative of a request to initiate the operation. Alternatively or additionally, other information may first be obtained or generated prior to initiation of the consent obtaining operation.

[0105] In Figure 8A, the interface indicates that the screening (e.g., imaging, diagnosis, etc.) has been successfully completed and the patient may take part in a clinical trial if they wish to do so. For example, the interface of Figure 8A may display one or more statements the operator can repeat to the patient.

[0106] As shown in Figure 8A, the interface can include content that is meant to help the operator. Here, for example, the interface includes an explanatory statement (e.g., “Invite patient to connect with Verily”) along with one or more conversational statements (e.g., “Now that your screening’s done, I’d like to invite you to take part in future research with Verily”). Meanwhile, the conversational statements may be posted to the interface in an effort to help the operator interact with the patient. Together, the explanatory and conversational statements can help operators feel more engaged in imaging and consent obtaining sessions and connected to patients. This is especiallyPATENTAtorney Docket No. 124824.8124.WO01true for less experienced operators who may have little to no experience in using retinal cameras.

[0107] With the explanatory and conversational statements, the operator can more easily assist the patient in consenting to transmit medical and patient data as part of a clinical trial, decline to transmit medical and patient data, or assist the operator in answering any common questions the patient may have regarding the process. From this interface, the operator may select an option for responses to common questions should the patient have follow-up questions (e g., by selecting a graphical element labelled “Common questions”), in which case the operator may be directed to the interface shown in Figure 9. For example, Figure 9 depicts an exemplary interface that can be presented to an operator for facilitating response to patient questions, e.g., such as during an inquiry response operation, according to some embodiments. In particular, if a subject asks a question such as “Will I get paid to take part in research” the interface can indicate to the operator key points to explain to the patient in response.

[0108] From the interface of Figure 8A, the operator may also select an option for moving forward in the process. For example, after the explanatory and conversational statements, the operator may select a graphical element labelled “Next” to proceed to the interface shown in Figure 8B. Figure 8B depicts an exemplary interface that can be presented to an operator as part of a process for obtaining patient data, such as patient contact information, according to some embodiments. For example, Figure 8B may display graphical elements such as those labelled “Yes, patient is interested” and “No, patient is not interested” that the operator may select if the patient indicates that they do or do not consent to participation in the clinical trial (e g., for transmitting medical / patient data). As shown in Figure 8B, the interface may also allow the operator to obtain patient data such as contact information (e.g., email address, phone number) if the patient does consent to transmitting medical and / or patient data as part of the clinical trial. For example, the interface may include text input boxes and input methods such as keyboard and mouse, touch screen, voice input, gesture recognition, and / or the like.

[0109] Alternatively, as described herein, an operator may indicate that the patient is not interested. For example, Figure 8C depicts an exemplary interface that can be presented to an operator responsive to a patient’s indication to discontinue obtainingPATENTAtorney Docket No. 124824.8124.WO01patient data, according to some embodiments. In the interface of Figure 8C, the graphical elements such as those labelled “Yes, patient is interested” and “No, patient is not interested” are displayed, and the “No, patient is not interested” option is selected to indicate the patient desires to discontinue the session. Responsive to a selection of this option, the system may display successful discontinuance of the session, e.g., such as through statement “Got it. Thank you for coming in today.” In some examples, such as in the example of Figure 8C, the statement may be an conversational statement which may be repeated by the operator to the patient.

[0110] In some examples, obtaining patient data for the study may include obtaining additional data such as metrics or further imaging. For example, Figure 8D depicts an exemplary interface that can be presented to an operator as part of a process for obtaining such enrollment data, according to some embodiments. For example, on the left side of the graphical interface, the display indicates under “Tasks for today” a task “Optional: Enter enrollment data.” Once the operator selects the “Next” option to move to the next display interface, the system may display an interface such as that illustrated in Figure 8E.

[0111] Figure 8E depicts an exemplary interface that can be presented to an operator to induce obtaining imaging data, according to some embodiments. For example, Figure 8E includes conversational statements such as “As part of the study we need to capture the following data” and includes elements for inputting data such as “Blood pressure readings.” An operator may be walked through (e.g., using explanatory statements) to obtain such data and input the data into the corresponding fields. Alternatively, as described herein, the system may be communicatively connected to other systems that can measure and obtain such data. The other systems may transmit such obtained data to the system and the system may parse, or process the data and, for example, autofill the fields with the obtained metrics.

[0112] In the example of Figure 8E, the display may also enable further capture of imaging data. For example, a conversational statement “We will need to capture additional image data from another device” may be included, as well as an option to initiate the imaging “Initiate capture” that the operator can select. Figure 8F depicts an exemplary interface that can be presented to an operator responsive to completion ofPATENTAtorney Docket No. 124824.8124.WO01obtaining imaging data, such as OCT data, according to some embodiments. For example, the display indicates “Capture complete.”Guidance Regarding Quality of Digital Images Generated by Retinal Cameras

[0113] Gradeability is critical for healthcare professionals when reviewing digital images generated by retinal cameras, especially in the context of diagnostics. However, gradeability often cannot be determined immediately after a digital image has been generated because a healthcare professional is not available (and may not be for the duration of the patient’s visit). The operator who facilitates generation of the digital image may not be able to readily determine gradeability. This is especially true if the operator has little to no training or experience in grading digital images. Accordingly, while a minimally trained operator may be able to utilize a retinal camera, the minimally trained operator may not be well equipped to determine gradeability of a digital image, and therefore whether the digital image is suitable for clinical evaluation. If the digital image isn’t found ungradable until after the patient has left the facility where imaging took place, scheduling another visit can take additional cost and time. And this additional time can be problematic if, for example, diagnosis and treatment need to occur rapidly.

[0114] An auxiliary tool, such as a deep learning model (or simply “model”) that employs one or more neural networks, could be employed by the diagnostic platform to provide gradeability information for a digital image generated by a retinal camera. However, the model should be studied well with large-scale datasets (e.g., as part of a clinical study) to prove effectiveness. In embodiments where the diagnostic platform resides on the retinal camera, employing the model also requires meaningful amounts of computation be performed locally (i.e. , on the retinal camera) in real time.

[0115] Some quality assessment metrics (or simply “metrics”) utilize density of the blood vessels and a pretrained classifier to determine the quality of digital images. These metrics require a large amount of training data to build the classifier, however. Additionally, blood vessel density analysis could be greatly affected by stronger noise or other artifacts and diseases, not to mention variation from patient to patient.PATENTAtorney Docket No. 124824.8124.WO01Processing System

[0116] Figure 10 is a block diagram illustrating an example of a processing system 1000 in which at least some operations described herein can be implemented. For example, some components of the processing system 1000 may be hosted on a computing device that includes a diagnostic platform (e.g., diagnostic platform 302 of Figure 3 or diagnostic platform 410 of Figure 4).

[0117] The processing system 1000 may include one or more central processing units (“processors”) 1002, main memory 1006, non-volatile memory 1010, network adapter 1012 (e.g., network interface), video display 1018, input / output devices 1020, control device 1022 (e.g., keyboard and pointing devices), drive unit 1024 including a storage medium 1026, and signal generation device 1030 that are communicatively connected to a bus 1016. The bus 1016 is illustrated as an abstraction that represents one or more physical buses and / or point-to-point connections that are connected by appropriate bridges, adapters, or controllers. The bus 1016, therefore, can include a system bus, a Peripheral Component Interconnect (PCI) bus or PCI-Express bus, a HyperTransport or industry standard architecture (ISA) bus, a small computer system interface (SCSI) bus, a universal serial bus (USB), IIC (I2C) bus, or an Institute of Electrical and Electronics Engineers (IEEE) standard 1394 bus (also referred to as “Firewire”).

[0118] The processing system 1000 may share a similar computer processor architecture as that of a desktop computer, tablet computer, personal digital assistant (PDA), mobile phone, game console, music player, wearable electronic device (e.g., a watch or fitness tracker), network-connected (“smart”) device (e.g., a television or home assistant device), virtual / augmented reality systems (e.g., a head-mounted display), or another electronic device capable of executing a set of instructions (sequential or otherwise) that specify action(s) to be taken by the processing system 1000.

[0119] While the main memory 1006, non-volatile memory 1010, and storage medium 1026 (also called a “machine-readable medium”) are shown to be a single medium, the term “machine-readable medium” and “storage medium” should be taken to include a single medium or multiple media (e.g., a centralized / distributed database and / or associated caches and servers) that store one or more sets of instructions 1028. The term “machine-readable medium” and “storage medium” shall also be taken toPATENTAtorney Docket No. 124824.8124.WO01include any medium that is capable of storing, encoding, or carrying a set of instructions for execution by the processing system 1000.

[0120] In general, the routines executed to implement the embodiments of the disclosure may be implemented as part of an operating system or a specific application, component, program, object, module, or sequence of instructions (collectively referred to as “computer programs”). The computer programs typically comprise one or more instructions (e.g. , instructions 1004, 1008, 1028) set at various times in various memory and storage devices in a computing device. When read and executed by the one or more processors 1002, the instruction(s) cause the processing system 1000 to perform operations to execute elements involving the various aspects of the disclosure.

[0121] Moreover, while embodiments have been described in the context of fully functioning computing devices, those skilled in the art will appreciate that the various embodiments are capable of being distributed as a program product in a variety of forms. The disclosure applies regardless of the particular type of machine or computer-readable media used to actually effect the distribution.

[0122] Further examples of machine-readable storage media, machine-readable media, or computer-readable media include recordable-type media such as volatile and non-volatile memory devices 1010, floppy and other removable disks, hard disk drives, optical disks (e.g., Compact Disk Read-Only Memory (CD-ROMS), Digital Versatile Disks (DVDs)), and transmission-type media such as digital and analog communication links.

[0123] The network adapter 1012 enables the processing system 1000 to mediate data in a network 1014 with an entity that is external to the processing system 1000 through any communication protocol supported by the processing system 1000 and the external entity. The network adapter 1012 can include a network adaptor card, a wireless network interface card, a router, an access point, a wireless router, a switch, a multilayer switch, a protocol converter, a gateway, a bridge, bridge router, a hub, a digital media receiver, and / or a repeater.

[0124] The network adapter 1012 may include a firewall that governs and / or manages permission to access / proxy data in a computer network and tracks varying levels of trust between different machines and / or applications. The firewall can be any number of modules having any combination of hardware and / or software componentsPATENTAtorney Docket No. 124824.8124.WO01able to enforce a predetermined set of access rights between a particular set of machines and applications, machines and machines, and / or applications and applications (e.g., to regulate the flow of traffic and resource sharing between these entities). The firewall may additionally manage and / or have access to an access control list that details permissions including the access and operation rights of an object by an individual, a machine, and / or an application, and the circumstances under which the permission rights stand.

[0125] The techniques introduced here can be implemented by programmable circuitry (e.g., one or more microprocessors), software and / or firmware, special-purpose hardwired (i.e. , non-programmable) circuitry, or a combination of such forms. Specialpurpose circuitry can be in the form of one or more application-specific integrated circuits (ASICs), programmable logic devices (PLDs), field-programmable gate arrays (FPGAs), or the like.Remarks

[0126] The foregoing description of various embodiments of the claimed subject matter has been provided for the purposes of illustration and description. It is not intended to be exhaustive or to limit the claimed subject matter to the precise forms disclosed. Many modifications and variations will be apparent to one skilled in the art. Embodiments were chosen and described in order to best describe the principles of the invention and its practical applications, thereby enabling those skilled in the relevant art to understand the claimed subject matter, the various embodiments, and the various modifications that are suited to the particular uses contemplated.

[0127] Although the Detailed Description describes certain embodiments and the best mode contemplated, the technology can be practiced in many ways no matter how detailed the Detailed Description appears. Embodiments may vary considerably in their implementation details, while still being encompassed by the specification. Particular terminology used when describing certain features or aspects of various embodiments should not be taken to imply that the terminology is being redefined herein to be restricted to any specific characteristics, features, or aspects of the technology with which that terminology is associated. In general, the terms used in the following claims should not be construed to limit the technology to the specific embodiments disclosed in the specification, unless those terms are explicitly defined herein. Accordingly, thePATENTAtorney Docket No. 124824.8124.WO01actual scope of the technology encompasses not only the disclosed embodiments, but also all equivalent ways of practicing or implementing the embodiments.

[0128] The language used in the specification has been principally selected for readability and instructional purposes. It may not have been selected to delineate or circumscribe the subject matter. It is therefore intended that the scope of the technology be limited not by this Detailed Description, but rather by any claims that issue on an application based hereon. Accordingly, the disclosure of various embodiments is intended to be illustrative, but not limiting, of the scope of the technology as set forth in the following claims.

Claims

PATENTAtorney Docket No. 124824.8124.WO01CLAIMSl / We claim:

1. A method comprising:initiating generation of one or more digital images of a retina of an individual by a retinal camera;in response to a determination that generation of the one or more digital images is complete,displaying, on a first interface, a request for medical data including the one or more digital images of the retina of the individual and other data that is related to the individual;receiving, via the first interface, first input that is indicative of consent, from the individual, to transmit the medical data to a destination;displaying, via a second interface, one or more explanatory statements, wherein each conveys, to an operator of the retinal camera, howto obtain the other data relating to the request;generating an encrypted package that includes the one or more digital images and the other data; andtransmitting the encrypted package to the destination.

2. The method of claim 1 , wherein generating the encrypted package comprises:identifying, from the request, one or more standards for encryption for (1) personal identifiable information (PH) and (2) digital images of retinas; encrypting, based on a data type, each of the one or more digital images and other data separately to generate encrypted data; andaggregating the encrypted data to form the encrypted package.PATENTAtorney Docket No. 124824.8124.WO013. The method of claim 1, wherein the request comprises one or more parameters indicative of user types from which data is needed for a clinical trial and wherein the method further comprises:comparing values of the other data to values for the one or more parameters to determine a similarity score; andresponsive to determining that the similarity score does not exceed a predetermined threshold, displaying a third interface that contains an explanatory statement conveying, to the operator, that the individual is not a good match for the clinical trial.

4. The method of claim 3, wherein the one or more parameters comprises a minimum threshold value for quality and wherein the method further comprises:applying, to the one or more digital images, an algorithm that produces, as output, a metric of the quality as determined through analysis of pixel content; andresponsive to determining that the metric for quality does not exceed the minimum threshold value, displaying a fourth interface that contains a request for recapturing the one or more digital images.

5. The method of claim 1 , further comprising:receiving, from an authorized device, a request to withdraw consent for accessing medical data of the individual; andcausing removal from storage of the encrypted package.

6. The method of claim 1 , wherein generating the encrypted package comprises embedding a device token for a device associated with the individual, and wherein the method further comprises:detecting that a third party has accessed the encrypted package; and responsive to detecting access, using the device token to transmit a notification of access to the device associated with the individual.PATENTAtorney Docket No. 124824.8124.WO017. The method of claim 1 , wherein the first interface further contains one or more conversational statements, each of which is intended to help the operator engage with the individual.

8. The method of claim 7, wherein each explanatory statement is associated with at least one of the one or more conversational statements.

9. One or more non-transitory computer-readable media storing instructions thereon, where the instructions when executed by one or more processors cause the one or more processors to perform operations comprising:in response to a determination that generation of one or more digital images of an individual by a medical imaging device is complete,displaying, on a first interface, a request for medical data including the one or more digital images of the individual and other data that is related to the individual;receiving, via the first interface, first input that is indicative of consent, from the individual, to transmit the medical data to a destination;displaying, via a second interface, one or more explanatory statements, wherein each conveys, to an operator of the medical imaging device, how to obtain the other data relating to the request;based on one or more second inputs indicative of a portion of the other data relating to the request, automatically relocating explanatory statements for obtaining a remaining portion of the other data for which inputs have not yet been received; andin response to determining that all inputs for the other data have been received, generating an encrypted package that includes the one or more digital images and the other data.PATENTAtorney Docket No. 124824.8124.WO0110. The one or more non-transitory computer-readable media of claim 9, wherein the instructions for generating the encrypted package further cause the one or more processors to perform operations comprising:identifying, from the request, one or more standards for encryption for (1) personal identifiable information (PH) and (2) digital images of living bodies;encrypting, based on a data type, each of the one or more digital images and other data separately to generate encrypted data; andaggregating the encrypted data to form the encrypted package.

11. The one or more non-transitory computer-readable media of claim 9, wherein the instructions further cause the one or more processors to perform operations comprising:receiving, from an authorized user device, a request to withdraw consent for accessing medical data of the individual; andcausing removal from storage of the encrypted package.

12. The one or more non-transitory computer-readable media of claim 9, wherein the request comprises one or more parameters indicative of user types from which data is needed for a clinical trial, and wherein the instructions further cause the one or more processors to perform operations comprising:comparing values of the medical data to values for the one or more parameters to determine a similarity score; andresponsive to determining that the similarity score does not exceed a predetermined threshold, displaying a third interface that contains an explanatory statement conveying, to the operator, that the individual is not a good match for the clinical trial.

13. The one or more non-transitory computer-readable media of claim 12, wherein the one or more parameters comprises a minimum threshold value for quality,PATENTAtorney Docket No. 124824.8124.WO01and wherein the instructions further cause the one or more processors to perform operations comprising:applying, to the one or more digital images, an algorithm that produces, as output, a metric of the quality as determined through analysis of pixel content; andresponsive to determining that the metric for quality does not exceed the minimum threshold value, displaying a fourth interface that contains a request for recapturing the one or more digital images.

14. The one or more non-transitory computer-readable media of claim 9, wherein generating the encrypted package comprises embedding a device token for a device associated with the individual and wherein the instructions further cause the one or more processors to perform operations comprising:detecting that a third party has accessed the encrypted package; and responsive to detecting access, using the device token to transmit a notification of access to the device associated with the individual.

15. The one or more non-transitory computer-readable media of claim 9, wherein the first interface further contains one or more conversational statements, each of which is intended to help the operator engage with the individual.

16. The one or more non-transitory computer-readable media of claim 15, wherein each explanatory statement is associated with at least one of the one or more conversational statements.

17. A device for dynamically guiding an operator through an operation in which a digital image of a patient is generated and transmitted, the device comprising:one or more processors; andone or more memories configured to store instructions that when executed by the one or more processors perform operations comprising: displaying, on a first interface, a request for medical data including (1 ) one or more digital images of an individual captured by a medical imaging device and (2) other data that is related to the individual;PATENTAtorney Docket No. 124824.8124.WO01receiving, via the first interface, first input that is indicative of consent, from the individual, to transmit the medical data to a destination; displaying, via a second interface, one or more explanatory statements, wherein each conveys, to an operator of the medical imaging device, how to obtain the other data relating to the request; generating an encrypted package that includes the one or more digital images and the other data; andtransmitting the encrypted package to the destination.

18. The device of claim 17, wherein the instructions for generating the encrypted package further cause the one or more processors to perform operations comprising:identifying, from the request, one or more standards for encryption for (1) personal identifiable information (PH) and (2) digital images of retinas; encrypting, based on a data type, each of the one or more digital images and other data separately to generate encrypted data; andaggregating the encrypted data to form the encrypted package.

19. The device of claim 17, wherein the instructions further cause the one or more processors to perform operations comprising:receiving, from an authorized user device, a request to withdraw consent for accessing medical data of the individual; andcausing removal from storage of the encrypted package.

20. The device of claim 17, wherein the request comprises one or more parameters indicative of user types from which data is needed for a clinical trial, and wherein the instructions further cause the one or more processors to perform operations comprising:comparing values of the medical data to values for the one or more parameters to determine a similarity score; andresponsive to determining that the similarity score does not exceed a predetermined threshold, displaying a third interface that contains anPATENTAtorney Docket No. 124824.8124.WO01explanatory statement conveying, to the operator, that the individual is not a good match for the clinical trial.

21. The device of claim 20, wherein the one or more parameters comprises a minimum threshold value for quality, and wherein the instructions further cause the one or more processors to perform operations comprising:applying, to the one or more digital images, an algorithm that produces, as output, a metric of the quality as determined through analysis of pixel content; andresponsive to determining that the metric for quality does not exceed the minimum threshold value, displaying a fourth interface that contains a request for recapturing the one or more digital images.

22. The device of claim 17, wherein generating the encrypted package comprises embedding a device token for a device associated with the individual and wherein the instructions further cause the one or more processors to perform operations comprising:detecting that a third party has accessed the encrypted package; and responsive to detecting access, using the device token to transmit a notification of access to the device associated with the individual.

23. The device of claim 17, wherein the first interface further contains one or more conversational statements, each of which is intended to help the operator engage with the patient.

24. The device of claim 23, wherein each explanatory statement is associated with at least one of the one or more conversational statements.

25. The device of claim 17, wherein the destination is a computer server accessible through Internet by an entity device that generated the request.