Centralised Patient Data Access With Role-Based Privacy Controls

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing systems lack a secure and efficient method for accessing centralized patient data captured from medical devices across an open network by authorized third parties, such as patients, healthcare professionals, dealers, and insurance providers, while ensuring patient privacy and compliance monitoring.

Innovation Solution

A system and method for accessing centralized patient data using irreversible hashes of patient identification information, with different access levels and security roles, allowing authorized parties to access data via a computer system that verifies request access information against stored access information, and optionally requiring physical keys for authentication.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If centralized patient data is made accessible across an open network to multiple third parties, then data accessibility and utility for healthcare management is improved, but patient privacy and security risks worsen

Engineering Contradiction:
Improvedata accessibilityVSAvoidprivacy risks
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The patent segments patient data access by implementing role-based access control where different third parties (healthcare professionals, dealers, insurance providers) receive access to only the specific data subsets relevant to their function. The centralized database is divided into multiple data sets with different access permissions, allowing broad accessibility while maintaining privacy through selective disclosure.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces a centralized database server as an intermediary between patients and third parties. This mediator manages all access requests, authenticates users, and controls data distribution according to pre-defined access rules. The intermediary enables multiple third parties to access data across an open network while the server enforces security policies to protect patient privacy.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If access control mechanisms are implemented to protect patient privacy, then security is improved, but system complexity worsens

Engineering Contradiction:
ImprovesecurityVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent implements preliminary action by pre-configuring access control rules and patient consent preferences before any data access requests occur. The system establishes default access permissions, data set classifications, and third-party role definitions in advance. When access requests are made, the system simply evaluates requests against these pre-established rules rather than making complex real-time security decisions, reducing operational complexity.

Inventive Principle:
Principle #10Preliminary action

3Adaptability or versatility

If multiple access levels are provided for different third parties, then data utility for different stakeholders is improved, but access control complexity worsens

Engineering Contradiction:
Improveaccess flexibilityVSAvoidaccess control complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent applies universality by creating a unified access control framework that handles multiple third-party roles (healthcare professionals, dealers, insurance providers) through a single system architecture. The same database server and access control logic serve all user types, with roles and permissions configured through standardized procedures. This universal approach enables flexible multi-level access without requiring separate systems for each stakeholder group.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS20250299790A1Method and system for accessing centralised patient data
Publication Date: 2025.09.25 FISHER & PAYKEL HEALTHCARE LTD
  • US20250299790A1 patent drawing
  • US20250299790A1 patent drawing
  • US20250299790A1 patent drawing

AI summary

A system and method is provided to allow access to centralised patient data captured from a medical device across an open network to a third party. The system and method receives the request based upon patient-specific information, checks the request and allows access if the request matches stored information.