Health Record Access Control via Distinct Encryption Parameters

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current systems for managing patient health records lack secure and efficient access control, leading to challenges in protecting patient privacy and reducing the effort required for users to manage access permissions.

Innovation Solution

An apparatus and method that configure secure access to patient health record data by using distinct access encryption parameters, allowing patients to control access based on consent, with features such as encryption, decryption, and revocation of access permissions for specific users and data fields, and implementing secure access protocols for upload, download, and sharing operations.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If patient health records are encrypted with storage encryption parameters, then patient privacy protection is improved, but access management complexity increases

Engineering Contradiction:
Improvepatient privacy protectionVSAvoidaccess management complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent segments the health record data into multiple data fields and applies different encryption parameters to different segments. Each data field can have its own access control policies, allowing fine-grained management of who can access what information. This segmentation enables the system to protect patient privacy while managing access complexity through modular, field-level control rather than all-or-nothing access management.

Inventive Principle:
Principle #1Segmentation

2Adaptability or versatility

If distinct access encryption parameters are configured for each data field, then selective access control is improved, but system complexity increases

Engineering Contradiction:
Improveselective access controlVSAvoidsystem complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent applies local quality by configuring distinct access encryption parameters for each data field based on its specific access requirements. Each data field can have customized access controls tailored to its sensitivity and usage needs, rather than applying a uniform access policy across all data. This allows the system to achieve high adaptability for selective access control while managing complexity through localized, context-specific configurations.

Inventive Principle:
Principle #3Local quality

3Reliability

If patients manually manage access permissions for each provider, then access control security is improved, but user effort increases

Engineering Contradiction:
Improveaccess control securityVSAvoiduser effort
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent implements self-service by enabling patients to automatically manage their own access permissions through the system. Patients can configure which providers have access to which data fields, and these permissions are automatically enforced through the encryption parameter system. This eliminates the need for manual permission management while maintaining strong access control security, as the system automatically handles the complex permission enforcement that would otherwise require significant user effort.

Inventive Principle:
Principle #25Self-service

4Adaptability or versatility

If access permissions are revoked when consent is withdrawn, then patient ownership control is improved, but access management overhead increases

Engineering Contradiction:
Improvepatient ownership controlVSAvoidaccess management efficiency
Core Design Contradiction:
Adaptability or versatilityVSProductivity

Solution Approach 1:

The patent applies preliminary action by pre-configuring access encryption parameters and permission structures before access requests occur. When patients withdraw consent, the system automatically revokes access by referencing these pre-configured parameters, eliminating the need for manual intervention or complex real-time permission management. This preliminary setup enables efficient automatic permission revocation while maintaining strong patient ownership control, as the system is already prepared to enforce permission changes immediately when needed.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS20240005009A1Apparatus and method for consent controlled health record access
Publication Date: 2024.01.04 MEDINEX CORP
  • US20240005009A1 patent drawing
  • US20240005009A1 patent drawing
  • US20240005009A1 patent drawing

AI summary

Apparatus and associated methods relate to configuring secure access to a patient's stored health record data, in response to receiving the patient's consent to a health record data access request, and providing the secure access to a specific user at a location and time related to the request. The access request may be received from a provider. The provider may be a doctor. Secure access by a specific user to a discrete health record data field may be configured, granted, or revoked based on patient consent status, permitting the patient selective control over access to their personal health record data. Access encryption parameters distinct from the storage encryption parameters securing the stored health record may be configured to permit specific user access to a specific data field. The access encryption parameters may be revoked by the patient withdrawing consent, permitting the patient to assert ownership control of their health records.