Cloud Storage for De-Identified Medical Data and Encrypted Re-Identification
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
The challenge of securely storing medical data while maintaining data privacy and enabling data re-identification within a hospital network is hindered by current legal regulations and the need for secure backups, which are often costly and vulnerable to local incidents.
Innovation Solution
A method involving de-identification of patient data using non-patient-identifying coded identifiers, generating a re-identifying database, and encrypting it with symmetric and asymmetric encryption methods, allowing secure storage on cloud storage while preserving patient privacy, and enabling re-identification within a trusted environment.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If medical data is encrypted or pseudonymized to maintain data privacy, then patient privacy is protected, but data cannot be re-identified and workflows cannot be associated with specific patients
Solution Approach 1:
The system segments patient data into two distinct parts: de-identified medical data stored in cloud storage and encrypted re-identifying database stored in secure environment. This segmentation allows the medical data to be used for research while keeping re-identification capability separate and secure.
Solution Approach 2:
The patent introduces a coded identifier system as an intermediary between patient identity and medical data. The coded identifiers serve as a mediator that allows data access without direct patient identification, and the encrypted re-identifying database acts as a mediator that can restore the connection when needed.
2Reliability
If local backups are made to ensure data safety, then data can be recovered from local incidents, but hardware costs and maintenance costs increase significantly
Solution Approach 1:
The system creates a copy of the medical data in de-identified form and stores it in cloud storage. This copy can be used for research and backup purposes without requiring expensive local hardware infrastructure, while the original data remains accessible in the secure environment.
3Reliability
If cloud storage is used for backups to avoid local incidents, then data safety is improved, but data privacy must be maintained which complicates the storage solution
Solution Approach 1:
The system segments the storage solution into two parts: de-identified medical data stored in cloud storage and encrypted re-identifying database stored locally in secure environment. This segmentation allows cloud storage to be used for safety while maintaining data privacy through the separation of identifiable information.
4Adaptability or versatility
If de-identified medical data is stored in cloud storage, then data can be used for research and diagnostics, but the system complexity increases due to encryption and re-identifying database requirements
Solution Approach 1:
The system performs preliminary de-identification of medical data before storing it in cloud storage. This preliminary action enables the data to be used for research and diagnostics without requiring complex real-time processing, while the re-identifying database is prepared in advance and encrypted for secure access.
Data Source
AI summary
A gateway and a method are provided for securely storing (and/or securely retrieving) medical data the method for storing comprising at least steps of:obtaining, in a secure environment, medical data which include patient property data as well as patient identifier data wherein the patient identifier data indicate at least one patient to which the patient property data correspond;generating, in the secure environment de identified medical data by replacing the patient identifier data in the medical data with non-patient-identifying coded identifiers;generating, in the secure environment, a re-identifying database indicating correspondences between the non-patient-identifying coded identifiers and the patient identifier data;generating an encrypted re-identifying database by applying, in the secure environment, at least one symmetric and/or asymmetric encryption method to the re-identifying database;storing the encrypted re-identifying database and the de-identified medical data on a cloud storage outside of the secure environment.


