Medical Data Relocation for Secondary Use
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current systems for managing medical care data primarily focus on its primary use, lacking structures for secondary use, which is hindered by privacy concerns, and do not effectively facilitate the relocation of confidential data for secondary research purposes without compromising patient privacy.
Innovation Solution
An information management apparatus and method that classifies medical care data into confidential and published data, with a problem event detector monitoring for clinical exacerbations, requesting patient consent, and relocating anonymized data to a separate storage area for secondary use, ensuring privacy protection.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Loss of information
If medical care data is stored with identifiable patient information for primary use, then data value for secondary use is improved, but patient privacy protection deteriorates
Solution Approach 1:
The patent divides medical care data into two separate storage areas: a first storage area for confidential data containing identifiable patient information for primary use, and a second storage area for published data for secondary use. This segmentation allows the system to maintain high data value for research while protecting patient privacy by storing sensitive information in separate, access-controlled locations.
Solution Approach 2:
The patent extracts and removes identifiable patient information from the medical care data before storing it in the second storage area for secondary use. By taking out the privacy-sensitive attributes (name, address, identification numbers), the system enables research utilization while eliminating the harmful factor of patient identification, thus resolving the contradiction between data value and privacy protection.
2Object-affected harmful factors
If all attribute data is deleted from medical care data to protect privacy, then patient privacy protection is improved, but data value for secondary use deteriorates
Solution Approach 1:
The patent applies local quality by differentiating the treatment of different data attributes across different storage areas. In the first storage area, all attribute data is stored as-is for primary use. In the second storage area, identifiable attributes are removed while non-identifiable attributes (age, sex, disease information) are retained. This localized differentiation allows the system to maximize data value for research while maintaining privacy protection where needed.
3Adaptability or versatility
If medical care data is classified into confidential and published data, then data management flexibility is improved, but system complexity increases
Solution Approach 1:
The patent implements segmentation by creating distinct storage areas with different access rights and data characteristics. The first storage area holds confidential data accessible only to authorized personnel for primary use, while the second storage area holds published data accessible for secondary use. This segmentation provides management flexibility through clear data categorization while keeping the system relatively simple through straightforward access control mechanisms.
Data Source
AI summary
An information sharing apparatus (management apparatus) for medical care data of a patient body includes a data uploader for classifying the medical care data into confidential data for a primary use in medical care of the patient body, and published data published for a secondary use different from the primary use, to store the confidential data and the published data in a storage medium. A problem event detector monitors the confidential data being added or updated, to check occurrence of a problem event of clinical exacerbation of the patient body. An activation processor checks occurrence of a flag signal for activating relocation of the confidential data to the published data upon the occurrence of the problem event. A relocation unit filters the confidential data at least partially to produce published data upon occurrence of the flag signal after the occurrence of the problem event.


