Anonymized Healthcare Performance Data Federation
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Healthcare sites are reluctant to share performance data due to fears of being identified as underperforming, leading to delays in operational improvements and the identification of innovative care processes, as existing methods like mapping sites to generic IDs can still reveal facility information.
Innovation Solution
A system and method for anonymizing performance data by creating normalized data with a common schema, de-normalizing it to prevent inference, and transmitting it to a remote computing resource, while controlling access and re-identification through user authentication and authorization tokens, ensuring that protected health information is not sent to the cloud.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If sites are mapped to generic IDs to protect anonymity, then privacy protection is improved, but data fidelity and ability to identify underperforming sites deteriorates
Solution Approach 1:
The patent segments the identification system into multiple layers: site-specific identifiers are separated from performance data, and a federation of identifier mappings is created across multiple sites. This allows individual sites to be identified in their own systems while presenting anonymized identifiers to the central system, thus protecting privacy while maintaining data fidelity.
Solution Approach 2:
The patent implements a nested identifier structure where site-specific identifiers are embedded within a federation of mappings. Each site has its own identifier namespace that is nested within the overall federal identifier system. This nested structure allows sites to maintain their identity locally while appearing anonymized in the centralized performance measurement system.
2Measurement precision
If detailed performance data is collected to improve measurement accuracy, then performance measurement precision is improved, but the risk of identifying specific sites deteriorates
Solution Approach 1:
The patent applies local quality by allowing different identifier types in different contexts. At the local site level, detailed identifiers are used for precise tracking and measurement. At the central federation level, anonymized identifiers are used to protect privacy. This contextual variation in identifier quality enables both precise measurement and privacy protection.
Solution Approach 2:
The patent introduces a federation of identifier mappings as an intermediary layer between the detailed site identifiers and the centralized performance measurement system. This intermediary translates detailed local identifiers into anonymized federal identifiers, enabling precise data collection while eliminating the risk of identifying specific sites through the intermediary translation layer.
3Reliability
If data is de-normalized to prevent site inference, then anonymity is improved, but the complexity of data processing increases
Solution Approach 1:
The patent applies preliminary action by performing de-normalization and identifier translation at the data collection stage rather than at the analysis stage. Site-specific identifiers are replaced with federal anonymized identifiers before data is aggregated centrally. This preliminary processing prevents the need for complex de-identification operations later, reducing overall system complexity.
4Adaptability or versatility
If re-identification capabilities are provided for authorized users, then data utility is improved, but the risk of unauthorized access increases
Solution Approach 1:
The patent implements dynamic access control where re-identification capabilities are not static but change based on user authorization status. The system dynamically adjusts the level of identifier detail presented to users based on their credentials and permissions. Authorized users can request re-identification through a controlled process, while unauthorized users see only anonymized data, thus providing data utility to those who need it while protecting against unauthorized access.
Data Source
AI summary
A system for making data source anonymous including a plurality of data sources, each data source including a data creation engine which creates normalized data in accordance with a common schema and a transformation engine which de-normalizes the normalized data such that the data source cannot be inferred by other data sources and transmits the de-normalized data to a remote computing resource. A remote computing resource receives and stores the de-normalized data from the plurality of data sources.


