Secure Data Merging via Pseudonymization and Segmentation
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
The manual allocation of evaluated data to patient information by external service providers is prone to errors and requires significant time and personnel, compromising data protection, especially when personal data is not completely deleted from image data.
Innovation Solution
A method involving a secure connection between networks for merging evaluation data and personal data using pseudonymization, where data are separated into partial data with assignment information, pseudonymized, and transmitted securely for evaluation and re-merging, ensuring data protection and reducing errors.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If manual allocation of evaluated data to patient information is performed by external service providers, then data can be evaluated externally, but error susceptibility increases and data protection is compromised
Solution Approach 1:
The data is segmented into two distinct parts: personal data stored locally in the first network and evaluation data stored in the second network. Each part is assigned a unique identification number that serves as a key. This segmentation allows external evaluation while maintaining local control over personal data, thereby reducing error susceptibility and protecting data privacy.
Solution Approach 2:
An identification number acts as an intermediary between personal data and evaluation data. Instead of directly linking personal data with evaluation results, the identification number mediates the connection. This intermediary mechanism enables accurate data assignment while preventing direct access to personal data by external service providers, thus improving both reliability and data protection.
2Reliability
If personal data is not completely deleted from image data, then data protection is reduced, but manual deletion increases time and personnel outlay
Solution Approach 1:
Personal data is preliminarily processed by replacing it with identification numbers before external evaluation takes place. This preliminary anonymization action is automated and systematic, eliminating the need for manual graphic deletion. The identification numbers are generated and assigned in advance, ensuring data protection is maintained without requiring additional time-consuming manual intervention.
Solution Approach 2:
The manual mechanical process of graphic deletion is replaced with an automated digital substitution system. Instead of manually erasing or obscuring personal data from images, the system automatically replaces personal data with identification numbers using computer-based processes. This substitution dramatically reduces time and personnel requirements while maintaining or improving data protection levels.
3Adaptability or versatility
If data are transmitted between networks for evaluation, then external evaluation is enabled, but secure connection requirements increase system complexity
Solution Approach 1:
Personal data is extracted from the evaluation process and kept entirely within the first network. Only de-identified evaluation data with identification numbers is transmitted to the second network for external evaluation. This extraction approach enables cross-network evaluation functionality while minimizing the security requirements, as the most sensitive personal data never leaves the local network.
Solution Approach 2:
Different networks have different data quality requirements: the first network maintains high-quality personal data with strict local protection, while the second network receives lower-quality de-identified data for evaluation purposes. This local quality differentiation allows external evaluation to proceed with simplified security requirements in the second network, reducing overall system complexity while maintaining data protection in the first network.
Data Source
AI summary
A method for combining different partial data includes providing a secure connection between a connection unit in a first network and an analysis unit a second network, separating original data into at least two items of partial data comprised of analysis data and personal data as first and second partial data that can be assigned to each other by way of assigning information, pseudonymizing the second partial data, transmitting the first partial data and pseudonymized second partial data and the assigning information to the analysis unit, storing the second partial data on the connection unit, providing third partial data on the analysis unit in the form of analyzed first partial data, transmitting the third partial data and the pseudonymized second partial data with the assigning information to the connection unit via the secure connection, and combining the third partial data and the second partial data using the assigning information.

