Multi-tiered Rule-based Data Access Permissioning Filters
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing data permissioning systems lack granular control over data access, failing to accommodate context-specific, requester-specific, and time-sensitive permissions, leading to fragmented privacy management and non-compliance with individual preferences and laws across disparate data silos.
Innovation Solution
A computer-based system implementing multi-tiered, rule-based data access permissioning filters that allow users to customize access based on contexts, entity types, date ranges, and data sources, integrating laws, consent agreements, and individual preferences to manage sensitive information securely.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If data are segregated into non-overlapping silos across different organizations, then patient privacy is protected at each source, but applications cannot leverage data across silos to obtain a complete picture of patient health
Solution Approach 1:
A patient-controlled data exchange system acts as an intermediary between data sources (hospitals, clinics, devices) and data consumers (applications, researchers). The system enables cross-silo data sharing while maintaining patient privacy through centralized permission management and audit trails, resolving the contradiction by mediating between privacy protection and information completeness
2Ease of manufacture
If existing binary data permissioning protocols are used, then implementation is simple, but they fail to accommodate context-specific, requester-specific, and time-sensitive permissions
Solution Approach 1:
The permissioning system is segmented into multiple independent rule tiers (laws/regulations, consent agreements, individual preferences) that can be applied hierarchically. Each tier addresses specific aspects of data sharing, allowing the system to accommodate diverse permission requirements without requiring complete redesign of the entire permissioning framework
Solution Approach 2:
The permissioning system transitions from static binary permissions to dynamic, multi-dimensional rules that can change based on context, requester identity, and time. Rules can be added, modified, or removed independently, allowing the system to adapt to evolving privacy requirements while maintaining operational simplicity through automated rule evaluation
3Productivity
If data are shared across multiple organizations, then data utilization is optimized, but manual oversight and paperwork increase significantly
Solution Approach 1:
The system implements automated permission evaluation and enforcement mechanisms that independently assess data sharing requests against defined rules without requiring manual intervention. The automated audit trails and compliance checks perform oversight functions that would otherwise require significant manual administrative effort, enabling efficient data utilization across organizations
4Adaptability or versatility
If different organizations use different ontologies for data storage, then each organization maintains its data structure, but translation into commonly-understood format becomes difficult
Solution Approach 1:
The system implements a universal data exchange framework that can handle multiple ontologies and data formats simultaneously. By defining standardized data schemas and mapping mechanisms at the system level, it enables organizations to maintain their native data structures while facilitating seamless translation and integration when data is exchanged, reducing the complexity of individual organization systems
Data Source
AI summary
A computer-based method for creating enforced, context-specific sharing of ontologically mapped, aggregated medical data includes storing at least one data field in a database as an entity type ontology, receiving context-specific rule configurations corresponding to the entity type ontology, and identifying any conflict between the received context-specific rule and any applicable rule. The context-specific rule configurations include at least one context, one data source, and one entity type ontology data field. If a conflict is identified, the method receives resolution of the conflict and stores the context-specific rule configurations in the database.


