Automated Clinical Data Anonymization and Identifier Conversion

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current systems for sharing clinical data among healthcare facilities face challenges in data collection and anonymization, leading to increased labor, human errors, and inefficiencies, which hinder the creation of a secure and accessible database for multiple facilities.

Innovation Solution

A medical information processing system that includes clinical databases, identifier conversion processors, anonymization processors, and anonymized databases within each facility, along with a research data management system that converts internal patient identifiers to external ones and anonymizes data, enabling secure sharing and management of clinical data across facilities.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If data collection and anonymization are done manually, then data security can be maintained, but labor and efforts increase significantly

Engineering Contradiction:
Improvedata securityVSAvoidlabor efficiency
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent replaces manual mechanical processes with automated computer-based systems. Specifically, it uses automated data collection interfaces that connect to clinical databases, algorithmic anonymization processors that automatically remove personal identifiers, and electronic data transmission systems that securely transfer anonymized data between facilities without human intervention

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Solution Approach 2:

The system enables facilities to automatically perform data collection, anonymization, and sharing without requiring manual intervention. The automated pipelines allow facilities to independently manage their own data contribution to the shared database, with systems that self-regulate data quality, security compliance, and transmission protocols

Inventive Principle:
Principle #25Self-service

2Reliability

If manual anonymization is performed, then data security is maintained, but time and expense are lost

Engineering Contradiction:
Improvedata securityVSAvoidprocessing time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The system performs anonymization processing in advance before data sharing occurs. Automated pipelines continuously pre-process clinical data by removing personal identifiers and encrypting sensitive information, so that when data is needed for sharing, it is already prepared and secured, eliminating last-minute manual processing delays

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

Manual anonymization tasks are replaced with automated computer-based anonymization processors that use algorithms to identify and remove personal identifiers, apply encryption, and validate data security compliance automatically, dramatically reducing processing time while maintaining or improving security consistency

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

3Measurement precision

If manual data collection is used, then data accuracy can be monitored, but human errors occur frequently

Engineering Contradiction:
Improvedata accuracyVSAvoiderror rate
Core Design Contradiction:
Measurement precisionVSReliability

Solution Approach 1:

Manual data collection and verification processes are replaced with automated computer-based systems that use standardized electronic interfaces, validation algorithms, and error-detection protocols to collect and verify data accuracy, eliminating human transcription errors and inconsistencies while maintaining monitoring capabilities through automated quality checks

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Solution Approach 2:

The system implements automated feedback loops where data quality metrics are continuously monitored, validation rules automatically check for errors and inconsistencies, and alerts are generated when anomalies are detected, enabling real-time correction of data quality issues without human intervention

Inventive Principle:
Principle #23Feedback

4Adaptability or versatility

If clinical data is shared among multiple facilities, then research capabilities are enhanced, but information security risks increase

Engineering Contradiction:
Improveresearch accessibilityVSAvoidsecurity risks
Core Design Contradiction:
Adaptability or versatilityVSObject-affected harmful factors

Solution Approach 1:

The patent introduces automated anonymization processors and secure data transmission intermediaries that stand between the clinical databases and the shared research database. These intermediaries automatically remove personal identifiers, apply encryption, and validate data security, allowing facilities to share data for research while maintaining security through automated mediation rather than direct exposure

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

Manual security review and data preparation processes are replaced with automated computer-based security protocols that systematically apply encryption, validate anonymization completeness, and control data access through electronic authentication systems, enhancing security consistency and reducing human error while enabling broader research access

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Data Source

PatentUS11469001B2Medical information processing system and medical information processing method
Publication Date: 2022.10.11 TOPCON CORPORATION
  • US11469001B2 patent drawing
  • US11469001B2 patent drawing
  • US11469001B2 patent drawing

AI summary

A system that includes a clinical database that stores clinical data in association with an internal identifier of a patient. An identifier conversion processor converts internal identifier associated with clinical data to an external identifier. An anonymization processor anonymizes confidential data in clinical data. An anonymized database stores anonymized data including anonymized clinical data and an external identifier associated with the anonymized clinical data. A research database stores anonymized data provided from the anonymized database for individual research projects. A research data provision processor receives a request from a user, reads out from the research database at least part of anonymized data associated with a research project to which the user belongs, and provides it to the user.