Remote EHR Access via Patient-Derived Consent Protocols

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Access to electronic health records (EHRs/EMRs) is fragmented and difficult, leading to duplicative examinations, inefficient updates, and challenges in obtaining a comprehensive patient medical history, especially in emergency situations where prior authorization and authentication are not feasible.

Innovation Solution

A method allowing remote access to a patient's EHR/EMR through a system that uses patient-derived information and consent protocols, enabling healthcare providers to access PHI without prior authorization, utilizing a consent management and validation service to ensure secure and authorized access.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If prior authorization and authentication are required for accessing EHR/EMR, then security and privacy of patient information is improved, but immediate remote access in emergency situations deteriorates

Engineering Contradiction:
ImprovesecurityVSAvoidaccess speed
Core Design Contradiction:
ReliabilityVSSpeed

Solution Approach 1:

The system performs preliminary actions by pre-establishing authorization frameworks and consent management protocols before emergencies occur. Patients can pre-designate emergency contacts and set access preferences in advance, so that when an emergency occurs, the system can quickly validate the situation against pre-configured rules without requiring time-consuming real-time authorization.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent introduces an intermediary consent management service that acts as a mediator between security requirements and emergency access needs. This intermediary layer validates emergency situations and facilitates access without compromising overall security, by standing between the requesting provider and the protected EHR system.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Ease of operation

If decentralized EHR storage at multiple clinics is maintained, then patient data availability at individual locations is improved, but comprehensive patient medical history access deteriorates

Engineering Contradiction:
Improvedata availabilityVSAvoidcomprehensive medical history
Core Design Contradiction:
Ease of operationVSLoss of information

Solution Approach 1:

The patent implements a universal access framework that enables a single authorization mechanism to work across multiple decentralized EHR systems. The consent management service provides multi-functional capabilities, serving as an authorization gateway for various types of providers (emergency physicians, specialists, researchers) across different healthcare organizations, allowing comprehensive access without requiring separate systems at each location.

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Measurement precision

If multiple EHR systems are updated independently, then local data accuracy is improved, but synchronization and completeness across systems deteriorates

Engineering Contradiction:
Improvelocal data accuracyVSAvoiddata synchronization
Core Design Contradiction:
Measurement precisionVSStability of the object's composition

Solution Approach 1:

The system implements feedback mechanisms where the consent management service continuously monitors and tracks access requests, authorization decisions, and data sharing across multiple EHR systems. This feedback loop ensures that all systems remain synchronized with the current authorization state, maintaining data consistency without requiring centralized control over the actual medical record content.

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS10902382B2Methods for remotely accessing electronic medical records without having prior authorization
Publication Date: 2021.01.26 HIPAAT
  • US10902382B2 patent drawing
  • US10902382B2 patent drawing
  • US10902382B2 patent drawing

AI summary

Methods are provided for allowing patients, health care practitioners and other service providers to have remote access to electronic medical records of a patient stored on a first computer network by the remote user requesting access to the electronic medical record from a second computer network and providing a first and second piece of patient derived information to the second computer network; the second computer network transferring the first and second piece of patient derived information to a third computer network; the third computer network authorizing the remote user through the first and second piece of patient derived information and dependent on a patient specific authorization protocol; the third computer network confirming a patient specific consent protocol; and the third computer network disclosing the electronic medical record to the remote user dependent upon an authorization and a confirmation received from the third computer network.