Health Activity Abstraction Layer for Secure PHI Access

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The digital health paradigm faces challenges in maintaining compatibility with evolving customer technologies and managing protected health information (PHI) securely, particularly during caregiver shifts and across different healthcare domains, with existing solutions lacking efficient access control and integration of augmented reality and spatial computing.

Innovation Solution

A system and method that identifies health data associated with activities, processes it based on PHI control, and ensures secure viewing and communication by moving the abstraction layer to the customer interaction layer, utilizing a protected health information control unit (PHICU) for authorization and access management, and integrating blockchain technology for secure data storage and access.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If the abstraction layer is moved to the customer interaction layer, then adaptability to evolving technologies is improved and API modification costs are reduced, but system complexity increases

Engineering Contradiction:
Improveadaptability to evolving technologiesVSAvoidsystem complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The system segments the health information ecosystem into distinct functional layers: customer interaction layer (HAL), domain layers, and infrastructure layer. Each layer operates independently with defined interfaces, allowing technology evolution at the customer interaction layer without requiring modifications to backend domain systems. This segmentation enables organizations to adopt new customer technologies without reworking core APIs and domain logic.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The Health Activity Layer (HAL) acts as an intermediary between customer technologies and domain systems. It provides standardized abstractions for health activities that mediate between diverse customer device interfaces and uniform domain operations, eliminating the need for continuous API modifications when new customer technologies emerge.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If PHI control is implemented across multiple domains and actors, then data security is improved, but access management complexity increases

Engineering Contradiction:
Improvedata securityVSAvoidaccess management complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The PHI control unit implements a universal access control mechanism that functions across all domains and actors in the health information ecosystem. A single PHI control framework manages authorization for diverse users (patients, providers, caregivers) across multiple domains (hospitals, clinics, labs) without requiring domain-specific access control implementations, simplifying cross-domain security management.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The system performs preliminary authorization actions by establishing PHI control rules and access permissions in advance through the PHI control unit. Access rights are predetermined and validated before data requests, allowing seamless secure access across domains without real-time complex authentication negotiations, reducing both security risks and management overhead.

Inventive Principle:
Principle #10Preliminary action

3Productivity

If health data is shared across multiple caregivers and domains, then caregiving efficiency is improved, but information security risks increase

Engineering Contradiction:
Improvecaregiving efficiencyVSAvoidinformation security risks
Core Design Contradiction:
ProductivityVSObject-affected harmful factors

Solution Approach 1:

The system applies local quality by providing customized data access views for different caregiver roles and contexts. Each caregiver receives precisely the health information they need for their specific function, no more and no less. This role-based localized data delivery improves caregiving efficiency by reducing information overload while maintaining security through granular access control that limits exposure to only necessary data elements.

Inventive Principle:
Principle #3Local quality

Data Source

PatentUS12068062B2Customer health activity based system for secure communication and presentation of health information
Publication Date: 2024.08.20 CVS PHARMACY INC
  • US12068062B2 patent drawing
  • US12068062B2 patent drawing
  • US12068062B2 patent drawing

AI summary

A system and method for identifying health data associated with a health activity and processing the health data based on protected health information control for secure viewing and communication are provided. The method includes: detecting, by one or more processors, a health activity from a hardware device accessed by a user; identifying, by the one or more processors, health data associated with the health activity; identifying, by the one or more processors, a task to be performed based on the health activity; determining, by the one or more processors, whether the user is an authorized user based on a protected health information control unit; and responsive to the user being authorized, performing the task using the health data for the authorized user.