Cloud Imaging Hub Anonymization for Secure Medical Data
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing systems for secure storage and access of medical image data face challenges in balancing security and accessibility, being complex and vulnerable to attacks, which increases costs and complexity for implementation and usage.
Innovation Solution
A cloud-based system using a cloud imaging hub and security tokens generates anonymous identifiers for medical image data, allowing secure storage and access while minimizing patient information transmission and system footprint, using unique identifiers for anonymization and decryption locally without external data transmission.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If traditional secure storage systems are used for medical image data, then data security is improved, but accessibility and ease of sharing among providers and patients deteriorates
Solution Approach 1:
The patent introduces a cloud-based imaging hub as an intermediary that stores medical image data in encrypted form. This hub acts as a mediator between patients and multiple providers, allowing secure centralized storage while enabling authorized access without requiring direct secure connections between all parties. The hub uses cryptographic keys and tokens to manage access permissions, resolving the contradiction between security and accessibility.
Solution Approach 2:
The system creates and distributes access tokens and cryptographic keys that serve as copies of authorization credentials. These tokens can be shared with patients and providers without exposing the actual medical data or master encryption keys. Multiple valid access copies enable widespread accessibility while the original secured data remains protected in centralized storage.
2Reliability
If comprehensive security measures are implemented for medical data storage, then security confidence is improved, but system complexity and implementation costs increase
Solution Approach 1:
The imaging hub automatically manages cryptographic key generation, storage, and distribution without requiring manual security configuration. The system self-provisions security infrastructure, automatically creates encrypted storage containers, and manages access token lifecycle. This automation reduces the complexity burden on implementers while maintaining high security standards through consistent, error-free security management.
Solution Approach 2:
The cloud-based imaging hub provides multiple functions within a single system: secure storage, encryption/decryption, access token management, and data sharing coordination. By consolidating these security-critical functions into one universal platform, the system avoids the complexity of integrating multiple separate security solutions while maintaining comprehensive security coverage.
3Ease of operation
If patient information is transmitted for access and display, then accessibility and personalization are improved, but security vulnerabilities and privacy risks increase
Solution Approach 1:
The system extracts and separates personally identifiable information (PII) from the actual medical data transmission. Patient identifiers are stored separately in encrypted form, while medical images are transmitted with only necessary access metadata. This extraction minimizes the attack surface by removing sensitive PII from transmission paths while maintaining patient-specific accessibility through separate key-based authorization.
Data Source
AI summary
A medical imaging system is configured to receive and securely store medical image data for patients, while providing sufficient access to view, review, and access image data. A care provider uses a cloud imaging hub and security token to receive medical image data produced by an image data source. The hub associates an arbitrary identifier with the medical image data based on patient information and the security token. The patient information is locally stored on the hub and not transmitted to any other device or server, and is scrubbed from the device after the UID is generated. The UID serves as an anonymous identifier for any medical image data associated with the patient, and may also be used to identify and access anonymous medical image data. The UID may be provided to the patient as a QR code, and is usable by the patient to access their anonymized image data and/or provide such access to another care provider.


