Hybrid Cloud Configuration Capsules for HIPAA Data Segmentation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Healthcare providers face challenges in managing proprietary and sensitive data due to disruptions caused by locally maintained computing platforms, which violate customer privacy and HIPAA standards, and limit technical support and testing capabilities in cloud environments.

Innovation Solution

A split/hybrid-cloud system that processes and retains proprietary data locally while managing configuration and content centrally in the cloud, allowing healthcare providers to create and deliver configuration capsules tailored to their needs, ensuring compliance with security standards and facilitating easy version management.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If healthcare providers use locally maintained computing platforms to manage customer records, then customer privacy and HIPAA compliance are improved, but system updates become disruptive and technical support is limited

Engineering Contradiction:
ImproveHIPAA compliance and customer privacyVSAvoidsystem updates and technical support
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The system is segmented into two distinct environments: a cloud-based platform for configuration management and updates, and a local execution environment for processing sensitive healthcare data. This segmentation allows each environment to fulfill its specific function - the cloud platform provides ease of updates and technical support while the local environment ensures HIPAA compliance and data security.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

Configuration capsules serve as an intermediary mechanism between the cloud platform and local execution environment. These capsules package configuration data, rules, and logic that can be securely transmitted to the local environment without exposing sensitive data, enabling centralized management while maintaining local data security.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Productivity

If healthcare providers use cloud platforms to overcome local platform disruptions, then system availability is improved, but customer privacy concerns and HIPAA compliance are worsened

Engineering Contradiction:
Improvesystem availabilityVSAvoidcustomer privacy and HIPAA compliance
Core Design Contradiction:
ProductivityVSReliability

Solution Approach 1:

The architecture segments the system into cloud-based configuration management and local data processing. The cloud platform handles non-sensitive configuration tasks providing high availability, while the local execution environment processes sensitive healthcare data ensuring HIPAA compliance. This segmentation resolves the contradiction by assigning different functions to different environments based on their security and availability characteristics.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

Sensitive healthcare data is extracted from the cloud environment and retained exclusively in the local execution environment. Only non-sensitive configuration data, rules, and logic are transmitted to the cloud for management. This extraction ensures that proprietary and sensitive information never resides in the cloud, maintaining privacy and compliance while still leveraging cloud advantages for configuration management.

Inventive Principle:
Principle #2Taking out (Extraction)

3Reliability

If healthcare providers keep proprietary data away from cloud environments, then data security is improved, but configuration management and deployment complexity increase

Engineering Contradiction:
Improvedata securityVSAvoidconfiguration management and deployment
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

Configuration capsules act as an intermediary that simplifies configuration management in the hybrid environment. The cloud platform generates and manages these capsules containing configuration data, rules, and logic, which are then deployed to the local execution environment. This intermediary mechanism abstracts the complexity of hybrid configuration management, making it as simple as managing cloud-based configurations while maintaining local data security.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

Instead of managing configurations directly in the complex hybrid environment, the system creates simplified copies of configuration data packaged in configuration capsules. These capsules can be easily generated, transmitted, and deployed from the cloud platform to the local environment, reducing the perceived complexity of configuration management while maintaining the security benefits of keeping data local.

Inventive Principle:
Principle #26Copying

4Ease of operation

If healthcare providers use cloud-based platforms for processing, then technical support and testing capabilities are improved, but data security and customer trust are worsened

Engineering Contradiction:
Improvetechnical support and testingVSAvoiddata security and customer trust
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The system segments functions by location: cloud-based environment provides technical support and testing capabilities for non-sensitive operations, while the local execution environment handles sensitive data processing. This segmentation allows healthcare providers to leverage cloud advantages for support and testing without compromising data security or customer trust.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

Sensitive data is extracted from the cloud environment entirely, preventing any risk to data security and customer trust. The cloud platform is used only for managing configuration data, rules, and logic - never for processing sensitive healthcare information. This extraction enables full utilization of cloud-based technical support and testing capabilities while maintaining the highest data security standards.

Inventive Principle:
Principle #2Taking out (Extraction)

Data Source

PatentUS10446268B2Systems and methods for maintaining and processing proprietary or sensitive data in a cloud-hybrid application environment
Publication Date: 2019.10.15 OPTUM INC
  • US10446268B2 patent drawing
  • US10446268B2 patent drawing
  • US10446268B2 patent drawing

AI summary

Systems, methods, and apparatuses for maintaining and processing proprietary or sensitive data using an application implemented in a split/hybrid-cloud system are described. The split/hybrid system utilizes cloud and local platforms, while complying with customer security concerns and HIPAA security standards. Configuration of the application occurs in a cloud platform whereas processing of proprietary or sensitive data occurs within a customer's local computing environment. The customer may create their own unique application configuration that is stored in the cloud platform and that is delivered back to the customer as a package that includes both the unique application configuration as well as general application configuration requirements. The customer may implement the package within one or more local computing environments while managing the application from a single site that is separated from proprietary or sensitive data.