Hospital Data Masking System for Secure External Transfer

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current systems for transferring electronic data from hospitals to external servers face challenges in efficiently extracting necessary information while preventing sensitive or regulated data from leaking, and they become cumbersome to extend as the number of service applications increases.

Innovation Solution

A data management system with an in-hospital information processing device that includes an information storage unit, a mask setting mechanism to control data access, and a publishable information generation unit, which allows only permitted data to be transferred outside the hospital, using an external server to read and store this data securely.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Productivity

If service applications directly access the in-hospital server to obtain data, then data access efficiency is improved, but security control becomes difficult and server load increases

Engineering Contradiction:
Improvedata access efficiencyVSAvoidsecurity control
Core Design Contradiction:
ProductivityVSReliability

Solution Approach 1:

The patent introduces a data transfer management system as an intermediary between service applications and the in-hospital server. This system manages data extraction and transfer, allowing service applications to access data efficiently while the management system maintains security control and distributes server load through centralized management.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Adaptability or versatility

If all data is transferred to external servers, then data availability for secondary use is improved, but sensitive information leakage risk increases

Engineering Contradiction:
Improvedata availabilityVSAvoidinformation leakage risk
Core Design Contradiction:
Adaptability or versatilityVSObject-affected harmful factors

Solution Approach 1:

The patent applies local quality by differentiating data types and applying different transfer rules to different data categories. Sensitive data is restricted from external transfer while non-sensitive data can be transferred for secondary use, achieving both data availability and security protection through localized data quality control.

Inventive Principle:
Principle #3Local quality

Solution Approach 2:

The system performs preliminary classification and marking of data before transfer, identifying which data fields are sensitive and should not be transferred. This preliminary action prevents sensitive information leakage while allowing necessary data to be made available for external secondary use.

Inventive Principle:
Principle #10Preliminary action

3Adaptability or versatility

If multiple service applications access the in-hospital server individually, then service flexibility is improved, but system complexity and extension difficulty increase

Engineering Contradiction:
Improveservice flexibilityVSAvoidsystem complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The data transfer management system serves multiple service applications through a universal interface and centralized data extraction mechanism. Instead of each application individually accessing the server, the management system handles all data transfer requests uniformly, reducing system complexity while maintaining service flexibility.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS7957982B2Data management system
Publication Date: 2011.06.07 OLYMPUS CORPORATION(JP)
  • US7957982B2 patent drawing
  • US7957982B2 patent drawing
  • US7957982B2 patent drawing

AI summary

Mask information for instructing the prohibition of information which cannot be serviced to the outside, is set and inputted by a manager so that the information, the permission of service of which is indicated by the mask information is exclusively sucked up from an in-hospital server by an external server outside the hospital. A service application created for each service reads out and exploits the information needed by itself, from the in-hospital information sucked up by the external server.