Longitudinal Patient Data Encryption via Dual-Key Standardization
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Integrating de-identified patient data from multiple sources into a longitudinal database while ensuring patient privacy and compliance with regulations such as HIPAA is challenging due to varying encryption techniques and the need for data to be linkable patient by patient.
Innovation Solution
A system that encrypts patient data using multiple encryption keys, standardizes data at the source, and further processes it at a central facility to create a common encrypted format, allowing for longitudinal linking without revealing original patient-identifying attributes, using a token-based key for additional security and statistical matching algorithms to assign pseudo identifiers.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If patient records are completely anonymized by removing all patient identification information, then patient privacy is maximally protected, but the ability to link records longitudinally patient by patient is lost
Solution Approach 1:
The patent extracts patient identification information from the data records before transmission to the longitudinal database facility. This extracted information is stored separately in a secure repository, allowing the main database to contain only de-identified records while preserving the ability to link records through the separate identifier repository when needed.
Solution Approach 2:
The patent introduces an intermediary mechanism - a secure identifier repository that stores extracted patient identification information separately. This intermediary allows longitudinal linking without exposing identifiers in the main database, resolving the contradiction between privacy protection and linking capability.
2Adaptability or versatility
If data from multiple sources are integrated into a longitudinal database, then comprehensive multi-sourced data analysis is enabled, but varying encryption techniques from different sources hinder accurate longitudinal linking
Solution Approach 1:
The patent standardizes encryption techniques across multiple data sources by requiring all sources to use the same encryption algorithm and key management procedures. This homogenization of encryption methods enables accurate longitudinal linking while preserving the ability to integrate diverse multi-sourced data.
3Loss of information
If patient identification information is retained in encrypted form, then longitudinal linking is maintained, but the risk of breach of patient privacy increases
Solution Approach 1:
The patent extracts patient identification information from the main data flow and stores it in a separate secure repository with restricted access. This separation removes identifiers from the primary database, reducing the risk of privacy breaches while preserving longitudinal linking capability through the separate repository.
Solution Approach 2:
The patent segments the database into two distinct components: a main longitudinal database containing de-identified records and a separate secure repository containing encrypted identifiers. This segmentation isolates sensitive information, reducing overall privacy breach risk while maintaining linking functionality.
Data Source
AI summary
Systems and processes for assembling de-identified patient healthcare data records in a longitudinal database are provided. The systems and processes may be implemented over multiple data suppliers and common database facilities while ensuring patient privacy. At the data supplier locations, patient-identifying attributes in the data records are placed in standard format and then doubly encrypted using a pair of encryption keys before transmission to a common database facility. The pair of encryption keys includes a key specific to the data supplier and a key specific to the common database facility. At the common database facility, the encryption specific to the data supplier is removed, so that multi-sourced data records have only the common database encryption. Without direct access to patient identifying-information, the encrypted data records are assigned dummy labels or tags by which the data records can be longitudinally linked in the database. The tags are assigned based on statistical matching of the values of a select set of encrypted data attributes with a reference database of tags and associated encrypted data attribute values.


