Metadata Envelope for Patient Data Security

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current systems for collecting, processing, and analyzing patient data are complex and difficult to manage due to varying regulations and security concerns, with limited security measures applied only during data transmission, leaving patient data vulnerable when at rest.

Innovation Solution

The proposed solution involves encapsulating patient data within a metadata envelope with specified security and privacy attributes, using a schema-defined metadata envelope that remains secure even when the data is at rest, and implementing a publisher-subscriber data exchange model with native security and privacy attributes to ensure secure data handling and access.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional IT systems are used to collect, process, and analyze patient data with multiple security layers at network and storage points, then data security during transmission is improved, but system complexity increases and data remains vulnerable when at rest

Engineering Contradiction:
Improvedata securityVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent implements a metadata envelope that encapsulates patient data, creating a nested structure where metadata attributes are embedded within the data container itself. This envelope travels with the data through the system, carrying security and privacy instructions internally rather than requiring external security systems at each processing point.

Inventive Principle:
Principle #7Nested doll (Nesting)

Solution Approach 2:

The metadata envelope enables patient data to carry its own security and privacy instructions autonomously. The envelope contains embedded attributes that automatically guide handling, storage, and transmission requirements without requiring external security systems to interpret or enforce policies at each system boundary.

Inventive Principle:
Principle #25Self-service

2Object-affected harmful factors

If varying types of encryption and security layers are applied at network, firewall, gateway, and storage devices, then data protection during transmission is improved, but security measures are insufficient when data is at rest

Engineering Contradiction:
Improvedata protectionVSAvoiddata security at rest
Core Design Contradiction:
Object-affected harmful factorsVSReliability

Solution Approach 1:

The patent applies security and privacy attributes to patient data before the data enters the system or is stored. The metadata envelope is created in advance with embedded security instructions, ensuring protection is already in place before data reaches storage devices or processing systems, rather than relying on post-hoc security measures.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

By nesting metadata attributes within the data envelope structure, the patent ensures security instructions travel with the data throughout its lifecycle including at-rest storage. The envelope maintains its protective structure regardless of the data's state (in-transit or at-rest), providing continuous security coverage.

Inventive Principle:
Principle #7Nested doll (Nesting)

3Reliability

If complex heterogeneous systems are built to manage patient data exchange with multiple security checkpoints, then data security is improved, but ease of operation and system management deteriorates

Engineering Contradiction:
Improvedata securityVSAvoidsystem management
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The metadata envelope serves multiple functions simultaneously: it contains patient data, carries security attributes, stores privacy instructions, and provides handling guidance. This single universal structure replaces the need for separate security systems, policies, and management layers that would otherwise be required at each processing point.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The envelope's embedded metadata attributes enable automated decision-making about data handling, storage, and transmission requirements. Systems can automatically process the envelope based on its self-contained instructions without requiring complex external security management or interpretation of separate security policies.

Inventive Principle:
Principle #25Self-service

4Productivity

If patient data is accessed and shared across multiple systems and entities, then patient outcomes and research capabilities are improved, but security and privacy compliance becomes more difficult to maintain

Engineering Contradiction:
Improvepatient outcomesVSAvoidregulation compliance
Core Design Contradiction:
ProductivityVSReliability

Solution Approach 1:

The metadata envelope embeds consent information and privacy attributes before data sharing occurs. This preliminary tagging ensures that when data is accessed or shared across systems for patient care or research, the compliance requirements are already established and travel with the data, making regulatory adherence automatic rather than requiring verification at each access point.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS10147502B2Data driven schema for patient data exchange system
Publication Date: 2018.12.04 MEDTRONIC INC
  • US10147502B2 patent drawing
  • US10147502B2 patent drawing
  • US10147502B2 patent drawing

AI summary

A patient data exchange system comprises at least one device. Each of the devices implements an interface. When a device in the patient data exchange system publishes patient data, the device generates a metadata envelope that encapsulates the patient data. The metadata envelope conforms to a schema that defines allowable metadata attributes of the metadata envelope. When a device in the patient data exchange system receives a metadata envelope that conforms to the schema, the device determines, based at least in part on a metadata attribute of the metadata envelope, a particular patient data handling policy to apply to patient data encapsulated by the metadata envelope. In some instances, the metadata attribute indicates that authorization is required from an authorization service to access the patient data encapsulated by the metadata envelope.