Patient-Controlled PHR Wallet Access Management

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Patients lack control over their personal health records (PHRs) and have difficulty managing access to their sensitive health data, which can lead to issues with data privacy and security.

Innovation Solution

A secure user-controlled PHR system is introduced, where a patient device can launch a PHR wallet application to connect to a PHR server, define access levels, and control the transfer of PHRs to healthcare providers, ensuring patient-centric management of their health data.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If patient health data is shared with multiple health care providers, then comprehensive health care access is improved, but patient control over data privacy and security deteriorates

Engineering Contradiction:
Improvehealth care accessVSAvoidpatient control
Core Design Contradiction:
Adaptability or versatilityVSEase of operation

Solution Approach 1:

The system enables patients to autonomously manage their own health data through a patient-controlled interface. Patients can independently grant, revoke, and modify access permissions for different healthcare providers without requiring provider intervention or system administrator approval, thus maintaining both comprehensive access and full patient control.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The access control system is dynamically adjustable by patients in real-time. Permission levels can be changed from fully accessible to restricted or completely blocked based on patient preferences, allowing the system to adapt to changing patient needs while maintaining comprehensive healthcare access when desired.

Inventive Principle:
Principle #15Dynamics

2Object-affected harmful factors

If patient health data is anonymized for security, then data privacy is improved, but emergency response capability deteriorates

Engineering Contradiction:
Improvedata privacy protectionVSAvoidemergency response
Core Design Contradiction:
Object-affected harmful factorsVSReliability

Solution Approach 1:

Different portions of the health data system have different security characteristics. Personally identifiable information is protected with high security and anonymization, while health record data can be selectively disclosed to authorized providers and emergency responders through patient-controlled access mechanisms, ensuring both privacy and emergency responsiveness.

Inventive Principle:
Principle #3Local quality

Solution Approach 2:

Patients pre-configure access permissions and emergency protocols before emergencies occur. The system is pre-set to allow rapid access to health data by authorized providers and emergency responders when needed, while maintaining privacy protection through selective disclosure mechanisms that are already in place before emergencies arise.

Inventive Principle:
Principle #10Preliminary action

3Reliability

If walled gardens are used to control access, then data security is improved, but patient portability and flexibility deteriorate

Engineering Contradiction:
Improvedata securityVSAvoidpatient portability
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The system provides universal access control that works across multiple healthcare providers, insurance companies, and facilities. Patients can carry their health data across different organizations and systems while maintaining consistent security controls and access management, eliminating the need for provider-specific walled gardens.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The patient-controlled access system acts as an intermediary layer between health data and various healthcare providers. This mediator enables secure data sharing across multiple organizations without requiring each provider to implement their own separate security infrastructure, thus improving both security and patient portability.

Inventive Principle:
Principle #24Intermediary (Mediator)

4Device complexity

If access control is centralized at provider facilities, then security management is improved, but patient autonomy and ease of data management deteriorate

Engineering Contradiction:
Improvesecurity managementVSAvoidpatient autonomy
Core Design Contradiction:
Device complexityVSEase of operation

Solution Approach 1:

Instead of providers controlling access to patient data, the system inverts the control model so that patients directly control who accesses their data and under what conditions. This inversion simplifies security management by placing control in the hands of data owners while maximizing patient autonomy.

Inventive Principle:
Principle #13The other way round (Inversion)

Solution Approach 2:

Patients independently manage their own access control settings without requiring provider facility intervention. The system empowers patients to self-service their data management needs, granting or revoking access as needed, which maximizes autonomy while reducing the complexity of centralized security management.

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS12237059B2Secure user-controlled personal health records
Publication Date: 2025.02.25 AT&T INTELLECTUAL PROPERTY I L P
  • US12237059B2 patent drawing
  • US12237059B2 patent drawing
  • US12237059B2 patent drawing

AI summary

The concepts and technologies disclosed herein are directed to secure user-controlled personal health records (“PHRs”). According to one aspect disclosed herein, a patient device can launch a PHR wallet device application. The patient device can connect, via the PHR wallet device application, to a PHR server that stores PHRs associated with a user. The patient device can define, via the PHR wallet device application, an access level to be applied to the PHR. The patient device can initiate, via the PHR wallet device application, a transfer of the PHR from the PHR server to a health care provider. The health care provider can be permitted to access the portion of the PHR in accordance with the access level.