EHR System Granular Access Control via File Segmentation
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Conventional electronic health record (EHR) systems are not well-suited for granular digital rights management, leading to scattered patient data and loss of access restrictions when patients change healthcare providers, resulting in 'silos' of health information and inadequate control over who can access specific portions of a patient's records.
Innovation Solution
A server-based EHR system that uses a computer-readable file structure with access permissions, allowing granular control over who can access different parts of a patient's health records across multiple healthcare enterprises, by matching healthcare worker attributes with access permissions and timestamps to ensure secure and restricted access.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If conventional EHR systems are used to store patient records, then data can be maintained by individual healthcare organizations, but patient records become scattered across multiple EHR systems creating silos that are difficult to access
Solution Approach 1:
The patent introduces a centralized EHR system as an intermediary that receives, stores, and manages patient records from multiple healthcare organizations. This central repository acts as a mediator that allows authorized healthcare workers to access patient records from any participating organization while maintaining a single source of truth for access control restrictions.
Solution Approach 2:
The EHR system is designed to serve multiple healthcare organizations simultaneously, providing a universal platform that can store and manage patient records across different facilities. The system maintains granular access control rules that apply universally across all participating organizations, allowing the same patient record to be accessed by different healthcare workers from different organizations according to their specific authorization levels.
2Reliability
If granular DRM restrictions are applied to patient records, then access control is improved, but conventional EHR data structures cannot maintain these restrictions when records are transferred across healthcare enterprises
Solution Approach 1:
The patent segments patient records into distinct data elements or fields, each with its own access control rules. Instead of applying a single access restriction to an entire patient record, the system divides the record into manageable segments (such as different medical conditions, treatments, or time periods) and applies granular DRM restrictions to each segment. This allows different healthcare workers to access different portions of the same patient record based on their specific authorization.
Solution Approach 2:
The EHR system implements local quality by applying different access control properties to different portions of patient records. Each data element can have its own access restrictions, permissions, and security attributes. This allows the system to maintain highly specific access control rules that are tailored to the sensitivity and nature of each particular data element, rather than applying a blanket restriction to the entire record.
3Reliability
If patient records are centralized in a single EHR system, then access control and security are improved, but the system complexity increases
Solution Approach 1:
The centralized EHR system serves as an intermediary layer between multiple healthcare organizations and their respective local systems. Rather than requiring complex point-to-point integration between every organization, the central EHR acts as a mediator that standardizes data exchange and access control. This intermediary architecture simplifies the overall system complexity by providing a single integration point while maintaining consistent access control policies.
Data Source
AI summary
Described herein are various technologies pertaining to facilitating digital rights management of patient healthcare records. A computing system executing an electronic health records application (EHR) receives an attribute of a healthcare worker and a patient identifier from a client computing device. The computing system retrieves a computer-readable file for the patient, the computer-readable file comprising a plurality of file records and a file access portion. A file record in the plurality of file records comprises a data portion and an access portion. The computing system transmits data in the data portion to the client computing device only when both the file access portion of the computer-readable file and the access portion of the file record include the attribute of the healthcare worker.


