Healthcare Monitoring Data Exchange With Segmented Access Keys
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing systems fail to securely transfer sensitive patient data over the internet while maintaining patient anonymity, which is essential for compliance with regulations like GDPR and ensuring accurate patient identification.
Innovation Solution
A method and system that uses a unique access key with a first and second part, where the first part is sent to the client application and the second part is stored with patient identity information, enabling secure and anonymous communication of patient data by pairing client and host applications during a meeting with strong authentication.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If patient data is transferred over the internet using existing systems, then data communication is enabled, but patient anonymity and security are compromised
Solution Approach 1:
The access key is segmented into two distinct parts: a first part transmitted to the client application and a second part stored securely with patient identity information. This segmentation allows the system to verify patient identity without transmitting or storing the complete identifying information in one location, thereby maintaining security while enabling accurate identification.
Solution Approach 2:
The first part of the access key acts as an intermediary element that enables communication between the client application and host application without directly exposing patient identifying information. This intermediary mechanism allows data transfer while preserving patient anonymity during transmission.
2Measurement precision
If patient identity information is transmitted with patient data, then accurate patient identification is enabled, but security and privacy protection are weakened
Solution Approach 1:
By dividing the access key into two parts and separating their storage locations, the system achieves both accurate patient identification (through verification of the second part against stored data) and privacy protection (by never transmitting the complete identifying information over the network).
Solution Approach 2:
The critical identifying information (second part of access key) is extracted from the transmission process and stored securely on the server side. Only the non-identifying first part is transmitted, thereby removing the harmful element (exposure of identifying information) while preserving the useful function (patient identification).
Data Source
AI summary
There are provided methods in a healthcare monitoring system for anonymous communication of patient data associated with a patient between at least one electronic user device, using a respective client application implemented in the electronic user device, and a host server, using a host application implemented in the host server, via a wireless network. Embodiments of the method further enables identification of the patient associated with the anonymous patient data in a secure manner. There is further provided corresponding systems, computer programs and non-volatile data carriers containing the computer programs.


