Patient Data De-Identification With Tokenized Record Linking

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional de-identification techniques for health data remove too much information, limiting utility, and are not suited for handling data from different health systems with varying formats, while HIPAA regulations require robust privacy protections.

Innovation Solution

A method involving tokenization and transformation of patient data to generate unique 'fingerprints' for tracking patients across records, removing and modifying identifiers, and maintaining data utility and privacy, with mechanisms to assess and manage re-identification risk.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If conventional de-identification techniques are used, then patient privacy is protected, but data utility is significantly reduced due to excessive information removal

Engineering Contradiction:
Improveprivacy protectionVSAvoiddata utility
Core Design Contradiction:
ReliabilityVSLoss of information

Solution Approach 1:

The patent applies parameter changes by transforming patient identifiers into tokens through cryptographic hash functions, changing the state of the data from identifiable to de-identified while preserving utility. The tokenization process modifies the parameters of patient records by replacing sensitive fields (names, SSNs, dates) with hashed tokens that maintain consistency across records without revealing original values

Inventive Principle:
Principle #35Parameter changes

Solution Approach 2:

The patent creates token copies of patient identifiers that serve as functional replacements. Instead of removing all identifying information, the system creates cryptographic hash copies that preserve the ability to link records while preventing direct identification. These token copies maintain the relational structure needed for data utility without exposing sensitive information

Inventive Principle:
Principle #26Copying

2Reliability

If conventional de-identification techniques are used, then privacy is maintained, but the system cannot handle data from different health systems with varying formats

Engineering Contradiction:
Improveprivacy protectionVSAvoidcross-system data handling
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent implements universality by creating a standardized tokenization framework that works across multiple health systems with different data formats. The system defines universal token types (patient tokens, encounter tokens, provider tokens) that can represent various identifier formats from different sources, enabling consistent de-identification and data aggregation across heterogeneous systems while maintaining privacy protections

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Reliability

If patient identifiers are removed to protect privacy, then re-identification risk is reduced, but the ability to track patients across records is lost

Engineering Contradiction:
Improveprivacy protectionVSAvoidpatient tracking capability
Core Design Contradiction:
ReliabilityVSLoss of information

Solution Approach 1:

The patent introduces tokens as intermediary elements that mediate between patient identifiers and privacy protection. These tokens serve as intermediate representations that preserve the ability to link and track patient records across different encounters and systems while preventing direct access to identifying information. The tokens act as a middle layer that maintains relational integrity without exposing sensitive data

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS20260044629A1Systems and methods for de-identifying patient data
Publication Date: 2026.02.12 TRUVETA INC
  • US20260044629A1 patent drawing
  • US20260044629A1 patent drawing
  • US20260044629A1 patent drawing

AI summary

Systems and methods for de-identifying patient data are disclosed herein. In some embodiments, a method for de-identifying patient data includes receiving a patient record including one or more identifiers. The method can include generating a first de-identified record from the patient record using a first de-identification process. The first de-identification process can be configured to produce a first re-identification risk score. The method can further include receiving a request from a data recipient to access the first de-identified record. The method can also include generating a second de-identified record from the first de-identified record by using a second de-identification process. The second de-identification process can be configured to produce a second re-identification risk score lower than the first re-identification risk score.