Medical Data Gateway Pseudonymization for Privacy and Re-identification

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current medical data management systems face challenges in efficiently managing and accessing medical data within hospital networks while ensuring compliance with privacy regulations, as existing solutions primarily focus on pseudonymization and encryption, making it difficult to re-identify data sets associated with specific patients and requiring separate development for on-premise and cloud environments.

Innovation Solution

A medical data management system that pseudonymizes patient identifiers before storage, allowing re-identification only for authorized users or devices, enabling consistent data management across various devices and networks while maintaining privacy compliance.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If data is pseudonymized or encrypted for privacy compliance, then privacy protection is improved, but data re-identification capability deteriorates

Engineering Contradiction:
Improveprivacy protectionVSAvoiddata re-identification capability
Core Design Contradiction:
ReliabilityVSLoss of information

Solution Approach 1:

The system segments data access by creating separate data views: pseudonymized data for cloud/external access and non-pseudonymized data for local hospital access. This segmentation allows different privacy protection levels for different use cases without compromising either privacy or re-identification capability entirely.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces an intermediary mechanism (data view management system) that mediates between the need for privacy protection and the need for data re-identification. This intermediary controls which form of data (pseudonymized or non-pseudonymized) is presented to which user or system, resolving the contradiction.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If separate development is performed for on-premise and cloud environments, then environment-specific requirements are met, but development time and cost increase

Engineering Contradiction:
Improveenvironment-specific complianceVSAvoiddevelopment time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent creates a universal data management platform that can operate in multiple environments (on-premise and cloud) with a single codebase. The system automatically adapts to different environments through configurable data views, eliminating the need for separate development while maintaining environment-specific compliance.

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Adaptability or versatility

If data is made accessible outside hospital network, then data usability is improved, but privacy security risk increases

Engineering Contradiction:
Improvedata accessibilityVSAvoidprivacy security risk
Core Design Contradiction:
Adaptability or versatilityVSObject-affected harmful factors

Solution Approach 1:

The system applies different quality levels of data protection to different access scenarios: full pseudonymization for external/cloud access, and non-pseudonymized access for internal hospital use. This local quality approach ensures appropriate security levels are applied where needed while maintaining data usability elsewhere.

Inventive Principle:
Principle #3Local quality

Data Source

PatentUS20220101964A1Medical data management system
Publication Date: 2022.03.31 SIEMENS HEALTHINEERS AG
  • US20220101964A1 patent drawing
  • US20220101964A1 patent drawing
  • US20220101964A1 patent drawing

AI summary

A medical data management system is for managing medical data. In an embodiment, the system includes a medical data gateway, including a processor connectable to a plurality of input devices, the medical data gateway being connected to a local network. Further, the processor is configured to carry out: collecting medical data, associated to a non-pseudonymized patient identifier and a data source identifier, from an input device; pseudonymizing at least the non-pseudonymized patient identifier of the medical data; exporting the pseudonymized medical data to a remote storage, the remote storage being part of a remote network external to the local network; allowing access to the non-pseudonymized patient identifier to a local application, running in the local network, and/or refusing access to the non-pseudonymized patient identifier to a remote application, running outside of the local network. A corresponding medical data management method is for managing medical data.