Patient Data Isolation with Encrypted Distributed Copies During Outages
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
During a ransomware attack or system outage, healthcare organizations face challenges in maintaining access to critical patient data, leading to potential risks in patient care and safety due to network or system unavailability.
Innovation Solution
A method and system that isolates and encrypts patient data from a vulnerable computer system, transferring it to a secure server for decentralized storage and access through a client application, ensuring continuous availability during disruptions.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If data is stored centrally on a vulnerable computer system, then data security is compromised during a cyberattack, but data availability is maintained during normal operation
Solution Approach 1:
The patent segments the centralized data storage system into multiple distributed copies across different computer systems. Each system stores a portion or duplicate of the data, so that if one system is compromised, other systems remain available. This is achieved through automated distribution of data copies to multiple locations, ensuring both availability and reduced vulnerability to cyberattacks.
Solution Approach 2:
The patent introduces an intermediary automated system that manages data distribution and isolation between the vulnerable primary system and secure backup systems. This intermediary automatically identifies, isolates, and transfers data to protected locations, acting as a mediator that protects against cyberattacks while maintaining data availability through coordinated distribution.
2Reliability
If data is isolated and distributed to multiple locations, then data availability during system failure is improved, but system complexity increases
Solution Approach 1:
The patent implements a self-service automated system that performs data identification, isolation, and distribution without requiring manual intervention. The system automatically monitors for system failures, identifies affected data, and redistributes it to appropriate locations, thereby improving reliability during failures while minimizing the operational complexity burden on users.
Solution Approach 2:
The patent performs preliminary actions by pre-configuring data distribution paths and backup locations before system failures occur. The automated system is pre-programmed with rules for data isolation and distribution, so when a failure occurs, the system can immediately execute the predetermined distribution plan without requiring complex real-time decision-making, thus reducing operational complexity.
3Object-affected harmful factors
If data is encrypted and stored securely, then data security is improved, but data access speed decreases
Solution Approach 1:
The patent applies partial encryption selectively to only the portions of data that require enhanced security protection, rather than encrypting all data uniformly. This allows frequently accessed data that does not require high security to remain accessible at full speed, while only the sensitive portions undergo encryption, thus balancing security improvements with minimal impact on data access speed.
Data Source
AI summary
The disclosure provides systems, methods and machine-readable programs for isolation of data. In some implementations, this is performed on a healthcare information system (HCIS). It will be noted, however, that the disclosed embodiments can be used for different fields of endeavor, and for data other than medical patient data. After capturing data elements, such as patient records, the system automatically reviews and can extract the data elements in an isolated location, generates and stores reports, encrypts the reports, and sends them to multiple designated workstations and devices throughout a network at regular intervals to ensure that the most recent patient data is captured. After a compromising event, such as a system outage or a cyberattack, the updated patent data can be accessed locally by way of a locally installed client program.


