Patient-Controlled Key Encryption for Secure Medical Record Access
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current systems for managing patient health records are insecure, prone to unauthorized access, and inefficient, as they often require patients to remember multiple usernames and passwords, leading to increased risks of data breaches and misuse, especially in the healthcare industry where complete and accurate medical information is critical for patient care.
Innovation Solution
A cloud-based system that uses private key encryption and public and private key infrastructure to allow patients to control access to their medical records, enabling secure, real-time, and limited access to healthcare providers through a mobile device, eliminating the need for multiple usernames and passwords, and providing an audit trail for authorization.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If patients use traditional username and password systems for accessing medical records, then access is granted to healthcare providers, but security risks increase due to multiple credentials and potential unauthorized access
Solution Approach 1:
The patent extracts the authentication mechanism from traditional username/password systems and replaces it with cryptographic key pairs. Patients hold private keys securely, while public keys enable authentication without exposing sensitive credentials. This eliminates the need for patients to manage multiple passwords while maintaining strong security through cryptographic principles.
Solution Approach 2:
The system introduces cryptographic protocols and key management infrastructure as intermediaries between patients and healthcare providers. Instead of direct password-based authentication, the patent uses public key infrastructure, digital signatures, and secure key exchange mechanisms to mediate access, thereby enhancing security while simplifying patient involvement.
2Productivity
If medical records are stored in centralized databases accessible by multiple providers, then access efficiency improves, but the risk of data breaches and unauthorized access increases
Solution Approach 1:
The patent implements fine-grained access control where different portions of medical records have different access permissions assigned to different healthcare providers. Instead of granting blanket access to entire databases, the system enables selective access to specific records or data elements based on treatment needs, thereby maintaining efficiency while reducing exposure to breaches.
Solution Approach 2:
The system preemptively protects medical records by encrypting them with patient-controlled keys before storage or transmission. Access is granted only through cryptographic verification of authorized providers, preventing unauthorized access at the source. This preliminary security measure counteracts potential data breaches before they can occur.
3Reliability
If patients control access to their medical records through encryption keys, then security is enhanced, but the complexity of key management and distribution increases
Solution Approach 1:
The patent enables patients to self-manage their cryptographic keys through user-friendly interfaces that handle key generation, storage, and rotation automatically. Patients can control which providers access their records without needing to understand cryptographic complexities, as the system abstracts key management behind simple authorization actions.
Solution Approach 2:
The system creates a universal key management framework that works across different healthcare providers, platforms, and record types. A single patient-controlled key infrastructure enables consistent access control throughout the healthcare ecosystem, eliminating the need for provider-specific authentication systems and simplifying overall key management.
4Reliability
If multiple healthcare providers need access to complete patient records, then care quality improves, but the number of authentication credentials patients must manage increases
Solution Approach 1:
The patent merges multiple authentication credentials into a single patient-controlled cryptographic key pair. Instead of requiring separate usernames and passwords for each healthcare provider, the system uses one patient private key to authenticate with multiple providers through their respective public keys, dramatically simplifying credential management while maintaining access to complete medical records.
Data Source
AI summary
A computerized system and method to allow a safe, secure and efficient real-time access to the patient's private health records (PHR) stored in the encrypted format in a remote Private Health Vault (PHV) database. The system uses patient's private encryption key for encrypting and decrypting PHR stored in the PHV, and the patient controls access to the PHR and authorizes by electronic communications with the PHV server to allow doctors to have limited in duration access to the patient PHR. The patient's private keys may be stored in a remote Key Bank database, separately form the PHV database, and the location of the patient's PHV data may also require transmission of the location id from a separate Mapping server. Additional security is also provided by determining digital proximity of the doctor's and patient's mobile devices to the node device in the doctor's office, and terminating access when patient leaves the facilities. It also utilizes 2-way digital token exchange and confirmation of the exchange between the patent and doctor, as well as digital fingerprinting for the confirmation of identity.


