Dynamic Health Data Protection via Participant-Specific Policies

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current data protection mechanisms in the healthcare sector lack flexibility to balance data protection levels with the benefits derived from sharing health data, often resulting in either inadequate protection or reduced data utility, and are difficult to update in response to changing regulations and user preferences.

Innovation Solution

Implementing dynamic data protection schemes that determine participant-specific policy-based protection levels through the use of hashing algorithms and differential privacy techniques, allowing for real-time adjustment of data protection based on user preferences and regulatory requirements, enabling secure and useful data sharing across the healthcare ecosystem.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If strict data protection measures are applied to all health data, then data security and privacy are improved, but data utility and sharing benefits are reduced

Engineering Contradiction:
Improvedata securityVSAvoiddata sharing benefit
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent implements participant-specific data protection policies that apply different protection levels to different participants based on their individual risk tolerances and regulatory requirements. Instead of a uniform protection approach, each participant receives customized protection measures tailored to their specific needs, allowing high-risk participants to receive stricter protection while low-risk participants can access more detailed data for greater utility.

Inventive Principle:
Principle #3Local quality

Solution Approach 2:

The system dynamically adjusts data protection parameters such as obfuscation levels, aggregation thresholds, and access restrictions based on participant characteristics, regulatory changes, and risk assessments. These parameters can be modified in real-time to balance security requirements with data utility, allowing the system to adapt protection intensity without completely restricting data access.

Inventive Principle:
Principle #35Parameter changes

2Device complexity

If uniform data protection policies are applied to all participants, then implementation simplicity is improved, but flexibility to meet individual participant needs and changing regulations is reduced

Engineering Contradiction:
Improvepolicy implementation complexityVSAvoidparticipant-specific flexibility
Core Design Contradiction:
Device complexityVSAdaptability or versatility

Solution Approach 1:

The patent establishes a dynamic policy management system that automatically updates and adjusts data protection policies in response to changing regulatory requirements, participant risk profiles, and organizational priorities. The system can modify protection levels, access rules, and compliance parameters without requiring complete policy rewrites, enabling continuous adaptation while maintaining manageable complexity through automated policy generation and enforcement.

Inventive Principle:
Principle #15Dynamics

3Productivity

If detailed health data is shared with multiple participants, then data utility and collaborative benefits are improved, but risk of data breaches and privacy violations increases

Engineering Contradiction:
Improvecollaborative benefitVSAvoiddata breach risk
Core Design Contradiction:
ProductivityVSObject-affected harmful factors

Solution Approach 1:

The patent introduces an intermediary data protection layer that sits between the raw health data and participating organizations. This intermediary system applies transformations such as obfuscation, aggregation, and pseudonymization to data before sharing it with participants. The intermediary maintains security controls and monitoring capabilities while still enabling collaborative analytics and insights, effectively decoupling data utility from direct exposure risks.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS11461499B2Dynamic data protection
Publication Date: 2022.10.04 ENYA INC
  • US11461499B2 patent drawing
  • US11461499B2 patent drawing
  • US11461499B2 patent drawing

AI summary

Methods, systems and computer program products for health data protection. Embodiments commence upon receiving a data access request message from a participant in a health ecosystem. The data access request message comprises an indication of one or more health data sets that are held by or at least potentially of interest to the participant. System components are configured to receive the message and to identify the participant. Based on parameter values corresponding to a data protection policy of the participant, a data protection scheme is generated. The scheme includes parameter values derived from the data protection policy. The parameter values of the scheme are used to generate a variation of the health data set that is formed by applying one or more data anonymization, data obfuscation or other data protection techniques to the health data set. A balance among the parameters is calculated so as to achieve a desired outcome.