Regulation-Compliant Computing System for HIPAA Data Security

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Commercial web browsers fail to provide a secure environment for handling regulated data, such as ePHI, leading to non-compliance with data regulation standards like HIPAA, as they allow features like saving, printing, and viewing of secured content, which can compromise data protection.

Innovation Solution

A computing system with a user interface controller and compliance engine that modifies the user interface to disable regulation-compromising features, assesses compliance, and establishes secured connections between compliant and non-compliant applications, using AI for continuous monitoring and updating, to ensure data regulation standards are met.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If commercial web browsers are used to access applications, then ease of operation is improved, but data security and regulation compliance deteriorate

Engineering Contradiction:
Improveease of operationVSAvoiddata security
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The system segments the web browsing environment into isolated containers (web views) that are sandboxed from the host operating system and other applications. Each web view operates in a restricted environment where only specific, approved functions are accessible, preventing unauthorized access to regulated data while maintaining ease of use through familiar browser interfaces.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces an intermediary layer (the compliant computing system with compliance engine) between the user and the applications/data. This intermediary monitors and controls all interactions, blocking unauthorized actions (right-click, save, print) while allowing legitimate operations, thus maintaining usability without compromising security.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If regulation-compliant features are disabled in web browsers, then data security is improved, but ease of operation deteriorates

Engineering Contradiction:
Improvedata securityVSAvoidease of operation
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The system applies different quality controls to different parts of the interface and functionality. Standard browser features are blocked in regulated contexts, while compliant features are enabled. The compliance engine dynamically adjusts available functions based on the specific application and data context, providing ease of operation for permitted actions while maintaining security restrictions where needed.

Inventive Principle:
Principle #3Local quality

3Productivity

If multiple applications are accessed simultaneously, then productivity is improved, but compliance monitoring complexity increases

Engineering Contradiction:
ImproveproductivityVSAvoidcompliance monitoring complexity
Core Design Contradiction:
ProductivityVSDevice complexity

Solution Approach 1:

Each simultaneously accessed application is isolated in its own sandboxed web view with independent compliance controls. The compliance engine monitors each web view separately through defined APIs, allowing multiple applications to run in parallel without increasing overall system complexity. Each segment is independently controllable and monitorable.

Inventive Principle:
Principle #1Segmentation

4Reliability

If user interface modifications are made to disable non-compliant features, then regulation compliance is improved, but device complexity increases

Engineering Contradiction:
Improveregulation complianceVSAvoiddevice complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The compliance engine automatically modifies the user interface and blocks non-compliant features without requiring manual configuration or complex device architecture. The system self-adjusts based on compliance rules, dynamically enabling or disabling features as needed. This automation reduces the effective complexity burden on the device while maintaining high compliance standards.

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS12073927B2Systems and methods for regulation compliant computing
Publication Date: 2024.08.27 WHITE KNIGHT INVESTMENTS
  • US12073927B2 patent drawing
  • US12073927B2 patent drawing
  • US12073927B2 patent drawing

AI summary

Disclosed are methods and systems for a computing environment that allows an operator to maximize or increase compliance with one or more data and privacy standards. In one embodiment, compliant and non-compliant sources are identified and exchange of data between those sources are blocked, partially allowed or allowed with regulation-compliant encryption of data.