Opt-In Collector System Using Device Identifiers for HIPAA Compliance
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing systems face challenges in requesting and collecting opt-ins from individuals, particularly in healthcare and other industries, due to privacy and security restrictions on personally identifiable information, limiting access to information about available goods, services, and options, such as prescription drug discounts and therapy information.
Innovation Solution
A system and method for requesting and collecting opt-ins via a communications device connected to a network, using a unique identifier address, a server computer, a data channel, a dispatcher, and a database to communicate opt-in requests and records, enabling secure and compliant communication of opt-in permissions, including HIPAA authorization, through SMS or other messaging services.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If personal identifying information is restricted due to privacy and security requirements, then privacy and security are improved, but the ability to direct opt-in requests to individuals deteriorates
Solution Approach 1:
The patent uses device identifiers (such as mobile device IDs, IP addresses, or other anonymous identifiers) as intermediaries to link individuals to opt-in requests without exposing personal identifying information. This mediator approach allows the system to direct requests to specific devices while maintaining privacy restrictions, resolving the contradiction between privacy protection and the ability to deliver opt-in requests.
Solution Approach 2:
The system creates and uses copies of identifying information in the form of device identifiers that can be used for communication purposes without revealing the actual personal identifying information. These identifier copies enable targeted communication while preserving the original privacy protections, allowing opt-in requests to be directed without exposing sensitive personal data.
2Ease of operation
If device identifiers are used to direct opt-in requests, then the ability to communicate with individuals is improved, but privacy and security restrictions may be violated
Solution Approach 1:
The system changes the parameter used for identification from personal identifying information (PII) to device-level identifiers. This parameter substitution allows communication to occur at the device level without accessing or exposing personal information, thereby maintaining compliance with privacy and security restrictions while enabling effective communication of opt-in requests.
3Loss of information
If personal information is made accessible to direct opt-in requests, then access to information about goods and services is improved, but privacy and security risks increase
Solution Approach 1:
The patent segments the identification process into two distinct layers: device identification (for communication purposes) and personal information (for privacy protection). By separating these functions, the system can provide access to information about goods and services through device identifiers without compromising personal privacy and security, thus reducing information loss while minimizing harmful factors.
Data Source
AI summary
Systems request and collect an opt-in from a network-connected communications device. The communications device has a unique identifier address. A server computer is connected to the network. A detector connects to a data channel over which the unique identifier address passes, and determines the unique identifier address. A dispatcher connected to and controlled by the server computer creates an opt-in request message directed to the communications device at the unique identifier address. A database is connected to the server computer. A record of the database is created for the communications device, which record includes the opt-in request message and unique identifier address. The server computer communicates the opt-in request to the communications device, and any reply message of the opt-in is received from the communications device and the database record updated accordingly. The opt-in reply message is a HIPAA authorization in a prescription drug benefit system.


