HIPAA Compliant Distributed Data Storage System

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing data storage systems face challenges in maintaining confidentiality of medical information, particularly when data is hacked or compromised, as seen in the storage of medical records and research data.

Innovation Solution

The system involves storing patient medical information on a local processing device, anonymizing a portion of it, and storing it on a second processing device. This anonymized data is then exposed to a third processing device through a network, while ensuring that only HIPAA-compliant medical information is accessed, with alarms in place to detect improper data transfer.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If medical information is stored in a centralized data store, then data accessibility is improved, but data security and confidentiality are worsened

Engineering Contradiction:
Improvedata accessibilityVSAvoiddata security
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent divides the centralized data store into multiple distributed data stores across different locations and institutions. Each data store holds a portion of the medical records, eliminating the single point of failure and reducing the risk of comprehensive data breaches while maintaining accessibility through distributed query capabilities.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces cryptographic intermediaries including public-key infrastructure, digital signatures, and homomorphic encryption schemes that enable secure access to distributed medical records without centralizing the actual data. These cryptographic layers act as intermediaries that verify authenticity and enable computation on encrypted data.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Loss of information

If personal identification information is stored with medical records, then data completeness is improved, but patient privacy is worsened

Engineering Contradiction:
Improvedata completenessVSAvoidpatient privacy
Core Design Contradiction:
Loss of informationVSObject-affected harmful factors

Solution Approach 1:

The patent extracts personally identifiable information (PII) from medical records and stores it in separate, securely protected locations. The medical records themselves are stored with de-identified or pseudonymized data, while the PII is kept in isolated vaults with strict access controls, thereby maintaining data completeness for medical purposes while protecting patient privacy.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent applies different levels of identification and anonymity to different portions of the data based on their purpose. Full PII is retained locally at the patient's choosing for their own records, while shared records use pseudonymization or encryption that provides local anonymity. This allows data completeness where needed while protecting privacy where appropriate.

Inventive Principle:
Principle #3Local quality

3Object-affected harmful factors

If data is anonymized before sharing, then patient privacy is improved, but data utility for research is worsened

Engineering Contradiction:
Improvepatient privacyVSAvoiddata utility
Core Design Contradiction:
Object-affected harmful factorsVSLoss of information

Solution Approach 1:

The patent employs advanced cryptographic transformations including homomorphic encryption and secure multi-party computation that allow mathematical operations to be performed on encrypted data without decryption. This changes the parameter state of the data from plaintext to ciphertext, enabling privacy protection while maintaining computational utility for research analytics, statistical analysis, and pattern recognition.

Inventive Principle:
Principle #35Parameter changes

Solution Approach 2:

The patent performs preliminary cryptographic processing and pseudonymization of data before it is shared across the distributed network. Data is pre-prepared with embedded cryptographic structures that enable future research queries and analytics to be performed on the anonymized data without requiring re-identification, thus maintaining both privacy and long-term research utility.

Inventive Principle:
Principle #10Preliminary action

4Reliability

If multiple data stores are distributed across networks, then data security is improved, but system complexity is worsened

Engineering Contradiction:
Improvedata securityVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent implements a universal cryptographic protocol suite that handles multiple functions across the distributed system including authentication, data encryption, query routing, and access control. This multi-functional approach reduces the number of separate systems and interfaces needed, thereby managing complexity while maintaining the security benefits of distribution.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The patent incorporates feedback mechanisms where the distributed data stores continuously communicate metadata, access patterns, and system state information to a coordinating layer. This feedback enables automatic load balancing, security policy enforcement, and conflict resolution, reducing the manual complexity of managing distributed systems while maintaining their security advantages.

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS12223094B1HIPAA compliant distributed data
Publication Date: 2025.02.11 RUDOLPH VOLKER
  • US12223094B1 patent drawing
  • US12223094B1 patent drawing
  • US12223094B1 patent drawing

AI summary

Disclosed herein are systems and methods for storing patient medical information on a local processing device, anonymizing a portion of that medical information and storing it on a second processing device, exposing that anonymized medical information to a third processing device coupled to the second processing device through a network, and restricting users of the third processing device to only accessing HIPAA compliant medical information. Alarms are included for indicating the improper transfer of HIPAA data.