Dynamic Role-Based Access Control for Patient Record Anonymity
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Conventional methods for regulating access to patient records are complex, overly inclusive, underinclusive, and inflexible, failing to balance patient privacy with the need for access for treatment and research while ensuring anonymity.
Innovation Solution
A computer database system that uses unique user IDs and role codes to define access to patient records, with the ability to redefine access based on changing user roles and provide anonymity by obscuring data, and modifying results to meet a threshold level of anonymity, while adhering to federal, state, and local regulations.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If conventional methods are used to regulate access to patient records, then patient privacy protection is maintained, but access flexibility and usability deteriorate
Solution Approach 1:
The patent implements dynamic access control where users can assume multiple roles (e.g., researcher, treating physician) and the system automatically adjusts access permissions based on the currently assumed role. This allows the same user to have different levels of access to patient records depending on their current functional need, making the access control system flexible and adaptive rather than static and rigid.
Solution Approach 2:
The patent segments access permissions by dividing them into role-based categories. Each role (researcher, treating physician, administrator) has a specific set of permitted access levels to patient records. This segmentation allows the system to grant appropriate access rights without requiring complex individual permissions for each user, thereby maintaining privacy while improving access flexibility.
2Reliability
If access to patient records is restricted to protect privacy, then anonymity is improved, but access for treatment and research deteriorates
Solution Approach 1:
The system dynamically adjusts the level of anonymity applied to patient records based on the user's current role. When a user assumes the role of a treating physician, the system provides full access to patient records without anonymity restrictions. When the user switches to a researcher role, the system applies anonymity protections such as masking or aggregation. This dynamic adjustment ensures that anonymity is maintained only when necessary for research purposes while allowing full access when needed for treatment.
Solution Approach 2:
The patent applies different levels of data masking or aggregation to different portions of patient records based on the user's role and the specific information being accessed. Rather than applying uniform anonymity to all records, the system selectively applies anonymity measures only to the extent necessary to protect privacy while preserving access to clinically relevant information needed for treatment and research.
3Adaptability or versatility
If role-based access control is implemented, then access management flexibility is improved, but system complexity increases
Solution Approach 1:
The patent implements a universal role-based access control framework where a single set of role definitions can serve multiple users across different contexts. Rather than creating individual permission sets for each user, the system defines roles (researcher, treating physician, administrator) that can be assumed by any user. This multi-functional approach simplifies the system architecture by replacing numerous individual permission configurations with a smaller set of reusable role templates, thereby reducing overall system complexity while maintaining access flexibility.
Solution Approach 2:
The system allows users to self-manage their role assumptions without requiring administrative intervention. Users can independently switch between roles based on their current needs, and the system automatically applies the appropriate access controls. This self-service capability reduces the burden on system administrators and simplifies the management of complex role-based access permissions.
4Reliability
If data masking or aggregation is applied to ensure anonymity, then privacy protection is improved, but data utility for research deteriorates
Solution Approach 1:
The system dynamically adjusts the level of data masking or aggregation applied to patient records based on the user's current role and the specific research context. Rather than applying fixed, heavy anonymity measures to all data, the system applies the minimum necessary level of anonymization to protect privacy while preserving data utility. For example, when a researcher needs to access records for a study on a common condition, the system may apply lighter masking than would be applied for research on rare conditions where anonymity is more difficult to maintain.
Solution Approach 2:
The patent changes the parameters of data anonymization based on contextual factors such as the type of research, the rarity of the condition being studied, and the user's credentials. The system can adjust parameters like the level of masking, the degree of aggregation, and the granularity of data access to optimize the balance between privacy protection and data utility for different research scenarios.
Data Source
AI summary
Methods, systems and computer program products are provided for providing a level of anonymity to patient records/information. A unique user identification (ID) associated with a current user is received at an interface of a computer database environment. A first role code associated with a first role of the current user is received at the interface of the computer database environment. The current user is allowed access to a defined set of patient records/information in the computer database environment. The defined set of patient records/information being defined based on the user ID and the first role code of the current user.


