Privacy Firewall for Selective Medical Data Access

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Access to medical data is hindered by regulatory and privacy requirements, making it challenging for medical research to utilize large datasets effectively.

Innovation Solution

The development of systems and methods that enable graphical illustration of private medical information, facilitate privacy-preserving joint medical research, control access to private medical information, and determine ownership and permissions, using non-transitory computer-readable media to manage and analyze medical data securely.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If access to medical data is restricted to protect patient privacy and comply with regulatory requirements, then patient privacy is protected and regulatory compliance is maintained, but medical research access to large datasets is hindered

Engineering Contradiction:
Improvepatient privacy protectionVSAvoidmedical research access
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent implements a privacy firewall system that acts as an intermediary between medical data storage and research access requests. The firewall includes multiple layers of access control mechanisms that filter and evaluate research requests against privacy rules, allowing legitimate research access while blocking requests that would compromise patient privacy. This mediator approach enables both privacy protection and research productivity to coexist by selectively permitting access based on predefined criteria.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The access control system is divided into multiple segmented layers including authentication modules, authorization modules, and data filtering modules. Each layer performs a specific function in the access control chain, allowing fine-grained control over what data can be accessed and by whom. This segmentation enables the system to provide different levels of access to different research entities while maintaining overall privacy protection.

Inventive Principle:
Principle #1Segmentation

2Reliability

If strict access control measures are implemented to maintain patient privacy, then privacy security is enhanced, but the complexity of data access management increases

Engineering Contradiction:
Improveprivacy securityVSAvoiddata access management complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The privacy firewall system is designed as a universal platform that handles multiple types of access control requirements through a single integrated architecture. It supports various authentication methods, multiple authorization models (RBAC, ABAC), and different data types within one system. This multi-functionality reduces the need for separate access control systems for different scenarios, thereby managing complexity while maintaining strong security.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The system incorporates feedback mechanisms that monitor access patterns, detect potential privacy violations, and dynamically adjust access control policies. The firewall logs and analyzes access requests, providing feedback to system administrators for policy refinement and to researchers about their access status. This continuous feedback loop helps maintain security while adapting to changing research needs and privacy concerns.

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS20240406142A1Privacy Firewalls for Access Control
Publication Date: 2024.12.05 LYNX MD LTD
  • US20240406142A1 patent drawing
  • US20240406142A1 patent drawing
  • US20240406142A1 patent drawing

AI summary

Systems, methods and non-transitory computer readable media for controlling access in privacy firewalls are provided. A request to access a content of an element may be received. The content of the element may include a first portion and a second portion. The first portion may include identifiable information and the second portion may include no identifiable information. A permission record corresponding to the element may be accessed. Based on a value in the permission record, full, partial or no access to the content of the element may be provided. Full access may include access to the first portion and the second portion of the content of the element. Partial access may include access to the second portion of the content of the element and excludes access to the first portion of the content of the element.