Cloud Storage for De-Identified Medical Data and Encrypted Re-Identification

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The challenge of securely storing medical data while maintaining data privacy and enabling data re-identification within a hospital network is hindered by current legal regulations and the need for secure backups, which are often costly and vulnerable to local incidents.

Innovation Solution

A method involving de-identification of patient data using non-patient-identifying coded identifiers, generating a re-identifying database, and encrypting it with symmetric and asymmetric encryption methods, allowing secure storage on cloud storage while preserving patient privacy, and enabling re-identification within a trusted environment.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If medical data is encrypted or pseudonymized to maintain data privacy, then patient privacy is protected, but data cannot be re-identified and workflows cannot be associated with specific patients

Engineering Contradiction:
Improvedata privacyVSAvoiddata re-identification
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The system segments patient data into two distinct parts: de-identified medical data stored in cloud storage and encrypted re-identifying database stored in secure environment. This segmentation allows the medical data to be used for research while keeping re-identification capability separate and secure.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces a coded identifier system as an intermediary between patient identity and medical data. The coded identifiers serve as a mediator that allows data access without direct patient identification, and the encrypted re-identifying database acts as a mediator that can restore the connection when needed.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If local backups are made to ensure data safety, then data can be recovered from local incidents, but hardware costs and maintenance costs increase significantly

Engineering Contradiction:
Improvedata safetyVSAvoidhardware cost
Core Design Contradiction:
ReliabilityVSQuantity of substance

Solution Approach 1:

The system creates a copy of the medical data in de-identified form and stores it in cloud storage. This copy can be used for research and backup purposes without requiring expensive local hardware infrastructure, while the original data remains accessible in the secure environment.

Inventive Principle:
Principle #26Copying

3Reliability

If cloud storage is used for backups to avoid local incidents, then data safety is improved, but data privacy must be maintained which complicates the storage solution

Engineering Contradiction:
Improvedata safetyVSAvoidstorage system complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system segments the storage solution into two parts: de-identified medical data stored in cloud storage and encrypted re-identifying database stored locally in secure environment. This segmentation allows cloud storage to be used for safety while maintaining data privacy through the separation of identifiable information.

Inventive Principle:
Principle #1Segmentation

4Adaptability or versatility

If de-identified medical data is stored in cloud storage, then data can be used for research and diagnostics, but the system complexity increases due to encryption and re-identifying database requirements

Engineering Contradiction:
Improvedata usage flexibilityVSAvoidsystem complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The system performs preliminary de-identification of medical data before storing it in cloud storage. This preliminary action enables the data to be used for research and diagnostics without requiring complex real-time processing, while the re-identifying database is prepared in advance and encrypted for secure access.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS12406099B2Method for securely storing and retrieving medical data
Publication Date: 2025.09.02 SIEMENS HEALTHINEERS AG
  • US12406099B2 patent drawing
  • US12406099B2 patent drawing
  • US12406099B2 patent drawing

AI summary

A gateway and a method are provided for securely storing (and/or securely retrieving) medical data the method for storing comprising at least steps of:obtaining, in a secure environment, medical data which include patient property data as well as patient identifier data wherein the patient identifier data indicate at least one patient to which the patient property data correspond;generating, in the secure environment de identified medical data by replacing the patient identifier data in the medical data with non-patient-identifying coded identifiers;generating, in the secure environment, a re-identifying database indicating correspondences between the non-patient-identifying coded identifiers and the patient identifier data;generating an encrypted re-identifying database by applying, in the secure environment, at least one symmetric and/or asymmetric encryption method to the re-identifying database;storing the encrypted re-identifying database and the de-identified medical data on a cloud storage outside of the secure environment.