Privacy-Preserving Health Record Sharing via Universal Anonymization
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing methods for sharing health records between healthcare providers often compromise patient privacy, as individual anonymization by each provider may not be sufficient to prevent identification when data is combined, and reliance on third-party services for data governance is costly and vulnerable to breaches.
Innovation Solution
A system and method that use criteria-based checks, including likelihood functions, to determine if patients are common across data sets and assess the risk of identification, ensuring privacy by denying access or removing identifiable data before sharing, without the need for a third-party service.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If individual anonymization is performed by each healthcare provider, then data sharing is enabled within individual ecosystems, but patient privacy is compromised when data from multiple providers is combined
Solution Approach 1:
The system performs preliminary actions by having all healthcare providers anonymize their data using the same anonymization key before sharing. This preliminary anonymization ensures that when data from multiple providers is combined, patients cannot be re-identified through cross-provider data matching, thus enabling versatile data sharing while protecting privacy.
Solution Approach 2:
The patent implements a universal anonymization key that is shared across all healthcare providers in the network. This single key serves multiple functions: it anonymizes data at each provider individually, enables safe data combination across providers, and prevents re-identification. This universal approach allows the system to handle diverse data sharing needs while maintaining consistent privacy protection.
2Object-affected harmful factors
If data sharing is prevented to protect privacy, then patient privacy is preserved, but patients cannot receive proper care and clinical investigations cannot be carried out
Solution Approach 1:
The system changes the parameter of data representation by transforming identifiable patient data into anonymized form using cryptographic techniques. This parameter change allows the same data to serve both purposes: protecting patient privacy by removing identifiers while maintaining the clinical information needed for care coordination and research activities.
Solution Approach 2:
The patent introduces an intermediary mechanism in the form of a distributed ledger that mediates between privacy protection and data sharing needs. The ledger records anonymization events and data sharing transactions without storing identifiable patient information, enabling verification of privacy compliance while facilitating necessary data exchange for healthcare delivery and research.
3Reliability
If a third-party service provider is used for data governance and verification, then data privacy can be ensured through trusted verification, but costs increase and vulnerability to breaches occurs
Solution Approach 1:
The system implements self-service by enabling healthcare providers to autonomously anonymize their own data using shared anonymization keys and verify anonymization compliance through the distributed ledger. This eliminates the need for expensive third-party verification services while maintaining reliability, as each provider independently ensures their data meets privacy standards before sharing.
Solution Approach 2:
The patent replaces the mechanical system of third-party human verification with an automated cryptographic system. The distributed ledger and anonymization keys provide machine-verifiable privacy compliance without requiring human intermediaries, reducing costs and eliminating the vulnerability associated with third-party data breaches while maintaining or enhancing verification reliability.
Data Source
AI summary
A computer-implemented method that receives at an apparatus a request from a first computing device for access to information related to a first user data set; determines, or receives an indication of a determination, whether the first computing device can access the information based on criteria for sharing information, the criteria based on one or more characteristics of the first user data set and a second user data set accessible by the first computing device; and provide a response based on the determination, the response preserving privacy of a user corresponding to the first user data set.


