Patient Record De-Identification Using Risk-Scored Tokenization
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Conventional de-identification techniques for health data remove too much information, limiting utility, and are not well-suited for handling patient data from different health systems due to non-uniform formats, while HIPAA regulations require robust privacy protections.
Innovation Solution
A method involving tokenization and transformation of patient data to generate unique 'fingerprints' for tracking patients across records, removing and modifying identifiers to create de-identified records, and aggregating them in a common data repository, ensuring compliance with HIPAA standards and maintaining data utility.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If conventional de-identification techniques are used, then privacy protection is improved, but data utility deteriorates due to excessive information removal
Solution Approach 1:
The patent applies parameter changes by transforming identifiers into tokens through cryptographic hash functions, changing the state of the data from identifiable to de-identified while preserving the ability to link records. This resolves the contradiction by maintaining privacy (parameter change to tokenized form) while preserving data utility (through deterministic token generation that allows matching)
Solution Approach 2:
The patent creates token copies of identifiers that serve as surrogate representations. These tokens are deterministic copies that preserve the linking function of original identifiers while removing direct identifiability, thus maintaining data utility without compromising privacy protection
2Reliability
If conventional de-identification techniques are used, then privacy protection is improved, but adaptability deteriorates due to inability to handle non-uniform formats from different health systems
Solution Approach 1:
The patent implements universality by designing a tokenization system that works across multiple health systems with different data formats. The cryptographic hash function approach is format-agnostic and can process identifiers from any health system, making the de-identification process universally applicable while maintaining consistent privacy protection standards
3Object-affected harmful factors
If identifiers are removed to protect privacy, then re-identification risk is reduced, but the ability to track patients across records deteriorates
Solution Approach 1:
The patent introduces tokens as intermediary elements that mediate between the need for privacy protection and the need for patient tracking. Tokens serve as surrogate identifiers that eliminate direct identifiability while preserving the functional capability to link and track patient records across different health systems through deterministic generation
Data Source
AI summary
Systems and methods for de-identifying patient data are disclosed herein. In some embodiments, a method for de-identifying patient data includes receiving a patient record including one or more identifiers. The method can include generating a first de-identified record from the patient record using a first de-identification process. The first de-identification process can be configured to produce a first re-identification risk score. The method can further include receiving a request from a data recipient to access the first de-identified record. The method can also include generating a second de-identified record from the first de-identified record by using a second de-identification process. The second de-identification process can be configured to produce a second re-identification risk score lower than the first re-identification risk score.


