Patient-Controlled Key Encryption for Secure Medical Record Access

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current systems for managing patient health records are insecure, prone to unauthorized access, and inefficient, as they often require patients to remember multiple usernames and passwords, leading to increased risks of data breaches and misuse, especially in the healthcare industry where complete and accurate medical information is critical for patient care.

Innovation Solution

A cloud-based system that uses private key encryption and public and private key infrastructure to allow patients to control access to their medical records, enabling secure, real-time, and limited access to healthcare providers through a mobile device, eliminating the need for multiple usernames and passwords, and providing an audit trail for authorization.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If patients use traditional username and password systems for accessing medical records, then access is granted to healthcare providers, but security risks increase due to multiple credentials and potential unauthorized access

Engineering Contradiction:
ImprovesecurityVSAvoidaccess management complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent extracts the authentication mechanism from traditional username/password systems and replaces it with cryptographic key pairs. Patients hold private keys securely, while public keys enable authentication without exposing sensitive credentials. This eliminates the need for patients to manage multiple passwords while maintaining strong security through cryptographic principles.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The system introduces cryptographic protocols and key management infrastructure as intermediaries between patients and healthcare providers. Instead of direct password-based authentication, the patent uses public key infrastructure, digital signatures, and secure key exchange mechanisms to mediate access, thereby enhancing security while simplifying patient involvement.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Productivity

If medical records are stored in centralized databases accessible by multiple providers, then access efficiency improves, but the risk of data breaches and unauthorized access increases

Engineering Contradiction:
Improveaccess efficiencyVSAvoiddata breach risk
Core Design Contradiction:
ProductivityVSObject-affected harmful factors

Solution Approach 1:

The patent implements fine-grained access control where different portions of medical records have different access permissions assigned to different healthcare providers. Instead of granting blanket access to entire databases, the system enables selective access to specific records or data elements based on treatment needs, thereby maintaining efficiency while reducing exposure to breaches.

Inventive Principle:
Principle #3Local quality

Solution Approach 2:

The system preemptively protects medical records by encrypting them with patient-controlled keys before storage or transmission. Access is granted only through cryptographic verification of authorized providers, preventing unauthorized access at the source. This preliminary security measure counteracts potential data breaches before they can occur.

Inventive Principle:
Principle #9Preliminary anti-action

3Reliability

If patients control access to their medical records through encryption keys, then security is enhanced, but the complexity of key management and distribution increases

Engineering Contradiction:
Improvesecurity controlVSAvoidkey management ease
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent enables patients to self-manage their cryptographic keys through user-friendly interfaces that handle key generation, storage, and rotation automatically. Patients can control which providers access their records without needing to understand cryptographic complexities, as the system abstracts key management behind simple authorization actions.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The system creates a universal key management framework that works across different healthcare providers, platforms, and record types. A single patient-controlled key infrastructure enables consistent access control throughout the healthcare ecosystem, eliminating the need for provider-specific authentication systems and simplifying overall key management.

Inventive Principle:
Principle #6Universality (Multi-functionality)

4Reliability

If multiple healthcare providers need access to complete patient records, then care quality improves, but the number of authentication credentials patients must manage increases

Engineering Contradiction:
Improvecare qualityVSAvoidcredential management
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent merges multiple authentication credentials into a single patient-controlled cryptographic key pair. Instead of requiring separate usernames and passwords for each healthcare provider, the system uses one patient private key to authenticate with multiple providers through their respective public keys, dramatically simplifying credential management while maintaining access to complete medical records.

Inventive Principle:
Principle #5Merging (Combining)

Data Source

PatentUS12183441B2Apparatus, system and method for patient-authorized secure and time-limited access to patient medical records utilizing key encryption
Publication Date: 2024.12.31 DAVIDOVICS BERNARD
  • US12183441B2 patent drawing
  • US12183441B2 patent drawing
  • US12183441B2 patent drawing

AI summary

A computerized system and method to allow a safe, secure and efficient real-time access to the patient's private health records (PHR) stored in the encrypted format in a remote Private Health Vault (PHV) database. The system uses patient's private encryption key for encrypting and decrypting PHR stored in the PHV, and the patient controls access to the PHR and authorizes by electronic communications with the PHV server to allow doctors to have limited in duration access to the patient PHR. The patient's private keys may be stored in a remote Key Bank database, separately form the PHV database, and the location of the patient's PHV data may also require transmission of the location id from a separate Mapping server. Additional security is also provided by determining digital proximity of the doctor's and patient's mobile devices to the node device in the doctor's office, and terminating access when patient leaves the facilities. It also utilizes 2-way digital token exchange and confirmation of the exchange between the patent and doctor, as well as digital fingerprinting for the confirmation of identity.