Time-Limited Health Content Access Tokens Across Firewalled Networks
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing electronic health record systems face challenges in securely and efficiently sharing and accessing patient health records across diverse stakeholders due to stringent privacy regulations and the complexity of transferring data between siloed, firewalled networks, often resorting to unethical workarounds that compromise security and privacy.
Innovation Solution
A Health Content Distribution Platform (HCDP) that generates time-limited access tokens based on predefined associations between users, patients, and content creators, enabling secure, transient access to digital health content across distributed devices while maintaining privacy and compliance with regulations.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If traditional EHR systems are used to share patient health records, then data can be accessed by authorized users, but security and privacy are compromised due to firewalled networks and unethical workarounds
Solution Approach 1:
The patent introduces a centralized authentication server as an intermediary between diverse health care systems. This server issues time-limited access tokens that mediate data access requests, eliminating the need for direct firewalled network connections while maintaining security. The intermediary handles authentication and authorization, allowing secure data sharing across network boundaries without compromising privacy.
Solution Approach 2:
Instead of transferring actual patient health record data between systems, the patent creates and transmits only access tokens that copy the authorization information. These tokens contain references to the actual data but not the data itself, reducing network traffic and eliminating the need to copy sensitive information across firewalled networks while maintaining secure access.
2Reliability
If time-limited access tokens are generated based on multiple predetermined associations, then access security is improved, but the complexity of determining access rights increases
Solution Approach 1:
The access control system is segmented into independent predetermined associations stored in a database. Each association represents a specific relationship (e.g., provider-patient, organization-patient) that can be independently evaluated. The authentication server queries these pre-defined associations rather than evaluating complex access rules in real-time, reducing computational complexity while maintaining multi-factor security.
Solution Approach 2:
Access rights are determined by pre-establishing and storing associations between users, organizations, and patients before actual data access occurs. The system uses these pre-computed associations to quickly generate access tokens without needing to perform complex access control calculations at the moment of data retrieval, thereby reducing operational complexity.
3Reliability
If complete medical records are maintained and shared, then healthcare quality is improved through comprehensive data availability, but data transfer costs and duplication increase
Solution Approach 1:
The patent extracts only the necessary access authorization information from complete medical records and places it in time-limited access tokens. The actual patient health data remains in its original complete form in secure storage, while the tokens contain only the minimal information needed for access control. This extraction eliminates the need to transfer and duplicate complete medical records across networks while maintaining data completeness for authorized users.
Data Source
AI summary
Apparatus and associated methods relate to provide transient access rights to entities for creating, accessing, and/or sharing digital health content (DHC). In an illustrative example, a health content distribution system (HCDS) may generate a time-limited access token (TLAT) for authenticated users to access DHC. The TLAT, for example, may be generated based on a predetermined association of a corresponding DHC with a patient, a predetermined association of a requestor with the patient, a predetermined role of the requestor with relation to the patient, and a predetermined association between the requestor and a creator of the content. The TLAT may be further generated based on a predetermined association between the requestor and an organization associated with the patient. The HCDS may, for example, upon receiving the TLAT, transmit the corresponding DHC to be displayed at the requestor's device. Various embodiments may advantageously provide a secure on-demand health content access system.


