EHR API Gateway Mediator for Secure Third-Party Data Integration

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current electronic health record (EHR) systems face challenges with security and privacy risks, high costs, and usability issues, leading to low adoption rates among healthcare providers despite their potential to improve medical care quality.

Innovation Solution

Integration of practice productivity applications and patient data collection devices with EHR systems through APIs, using persistent security tokens for authentication and authorization, allowing seamless data exchange and customization of user experiences.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If EHR systems are implemented to improve medical care quality and accessibility, then data accessibility and coordination of care are improved, but security and privacy risks increase

Engineering Contradiction:
Improvedata accessibilityVSAvoidsecurity and privacy risks
Core Design Contradiction:
Adaptability or versatilityVSObject-affected harmful factors

Solution Approach 1:

The patent implements an API gateway as an intermediary component that sits between external applications and the EHR system's medical records database. This gateway validates authentication tokens, authorization tokens, and API calls before allowing access to patient data, thereby mediating security concerns while maintaining data accessibility. The gateway acts as a security layer that enables third-party applications to access EHR data without exposing the underlying database to direct access risks.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Adaptability or versatility

If comprehensive EHR systems are deployed to provide extensive functionalities, then medical care quality improves, but implementation costs increase

Engineering Contradiction:
ImprovefunctionalitiesVSAvoidimplementation costs
Core Design Contradiction:
Adaptability or versatilityVSQuantity of substance

Solution Approach 1:

The patent creates a universal API framework that enables multiple third-party applications to access and integrate with the EHR system through standardized interfaces. Rather than building custom integration solutions for each application, the system provides a multi-functional API gateway that serves various purposes (data retrieval, patient portal access, analytics, etc.) through a single unified infrastructure, thereby reducing overall implementation and maintenance costs.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The patent segments the EHR system into modular components, with the API gateway as a separate, independently deployable layer that interfaces with the core medical records database. This segmentation allows healthcare providers to implement EHR functionality incrementally and enables third-party applications to access specific functions without requiring the entire EHR system, thereby reducing implementation costs for both the EHR provider and application developers.

Inventive Principle:
Principle #1Segmentation

3Productivity

If EHR systems are implemented to streamline medical records management, then record accessibility improves, but usability challenges arise

Engineering Contradiction:
Improverecord accessibilityVSAvoidusability
Core Design Contradiction:
ProductivityVSEase of operation

Solution Approach 1:

The API gateway serves as an intermediary that handles complex authentication, authorization, and data retrieval operations, thereby simplifying the user interface for medical professionals. Rather than requiring users to directly interact with complex database queries or authentication protocols, the gateway mediates these operations in the background, presenting simplified interfaces to end users while maintaining robust security and data access capabilities.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS20150379203A1Medical professional application integration into electronic health record system
Publication Date: 2015.12.31 ALLSCRIPTS SOFTWARE LLC
  • US20150379203A1 patent drawing
  • US20150379203A1 patent drawing
  • US20150379203A1 patent drawing

AI summary

Embodiments relate to integrating data collection and productivity applications with an EHR system. To integrate a patient's data collection application with the EHR system, an EHR server provides API calls to (i) retrieve patient information, (ii) post data to the patient's account, and (iii) post data to the medical professional's account. To integrate a medical professional's productivity application with the EHR system, an EHR server provides API calls to (i) retrieve practice information, (ii) retrieve patient information, and (iii) post data to the medical professional's account. Embodiments securely provide these APIs to third party providers.