Role-Based Access Control for Medical Data Privacy
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current web platforms for medical services lack effective protection of patient privacy, as medical practitioners from different institutions can access patient information from other institutions.
Innovation Solution
An information interaction method and platform that acquires patient description information from registered institutions, determines role data for medical practitioners, and transmits the information based on this data, ensuring that patient information is only accessible to corresponding medical practitioners within the same institution.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If web platforms provide medical services from multiple institutions to patients, then service accessibility and versatility are improved, but patient privacy protection deteriorates as medical practitioners from different institutions can access patient information
Solution Approach 1:
The patent segments patient information access by institution through the role data structure, which includes institution_id and role_id fields. This allows the system to maintain multi-institutional service accessibility while preventing practitioners from accessing patient information from institutions other than their own, thus resolving the privacy leakage issue
Solution Approach 2:
The patent implements local quality by assigning specific access permissions to different roles within each institution. The role data structure enables fine-grained control where each practitioner can only access patient information relevant to their assigned role and institution, maintaining versatility while protecting privacy through localized access control
2Loss of information
If the system transmits patient information to multiple medical practitioners, then information availability is improved, but data security deteriorates due to potential unauthorized access
Solution Approach 1:
The patent performs preliminary action by pre-establishing role data structures that define access permissions before information transmission occurs. The system checks whether a practitioner's role data allows access to specific patient information before transmitting it, preventing unauthorized access while ensuring legitimate practitioners receive necessary information
Solution Approach 2:
The patent uses role data as an intermediary mechanism between the information source and the practitioner. This intermediary layer filters and controls information flow based on predefined roles and permissions, enabling reliable information availability while maintaining data security through authorized access control
Data Source
AI summary
Provided is an information interaction method, applicable to an information interaction platform. The method includes: acquiring patient description information provided by a terminal corresponding to a first institution, wherein the first institution is an institution registered on the information interaction platform, and the terminal corresponding to the first institution is configured to acquire the patient description information provided by a target patient of the first institution; determining role data of a plurality of medical practitioners corresponding to the first institution on the information interaction platform, wherein the role data is configured to identify information of the medical practitioners in the first institution; and transmitting, based on the role data, the patient description information to a terminal of at least one medical practitioner of the plurality of medical practitioners corresponding to the first institution.


