Surgical Robotic Data Anonymisation for Patient Privacy

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing surgical robotic systems capture data that includes personally-identifiable information, limiting its wider use due to privacy concerns, which restricts the ability to utilize this data for teaching and training purposes.

Innovation Solution

A method and system for anonymizing data captured by surgical robotic systems by detecting personally-identifiable features and generating an anonymized data stream that omits or obscures this information, using techniques such as removal, blurring, or masking, which can be done in real-time.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If data captured by surgical robotic systems is used for teaching and training purposes, then the educational value and utility of the system is improved, but patient privacy is compromised due to personally-identifiable information in the data

Engineering Contradiction:
Improvedata usability for teaching and trainingVSAvoidpatient privacy violation
Core Design Contradiction:
Adaptability or versatilityVSObject-affected harmful factors

Solution Approach 1:

The patent extracts and removes personally-identifiable information from captured surgical data while retaining the educational content. The system identifies features such as patient names, faces, and unique identifiers, and removes or anonymizes them, allowing the data to be used for teaching purposes without compromising patient privacy.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent introduces an intermediary anonymization process between data capture and data usage. This intermediary system processes the raw captured data, removes personally-identifiable information, and produces anonymized data suitable for teaching and training, thus mediating between the conflicting requirements of data usability and privacy protection.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If real-time anonymization is performed on captured data, then patient privacy is protected, but processing time and computational resources increase

Engineering Contradiction:
Improveprivacy protectionVSAvoiddata processing time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent performs preliminary anonymization during the data capture process itself, rather than as a separate post-processing step. By identifying and removing personally-identifiable information in real-time as data is captured, the system ensures privacy protection without adding significant processing delays, as the anonymization occurs concurrently with data acquisition.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent replaces complex, time-consuming manual anonymization processes with automated computational algorithms. The system uses machine learning models and pattern recognition to automatically identify and remove personally-identifiable information, significantly reducing processing time compared to manual methods while maintaining high privacy protection standards.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Data Source

PatentUS12423473B2Anonymising robotic data
Publication Date: 2025.09.23 CMR SURGICAL LTD
  • US12423473B2 patent drawing
  • US12423473B2 patent drawing
  • US12423473B2 patent drawing

AI summary

A method is provided of anonymising data in a surgical robotic system. The surgical robotic system comprises a robot having a base and an arm extending from the base to an attachment for an instrument, the arm comprising a plurality of joints whereby the configuration of the arm can be altered. The method comprises receiving a data stream captured by the surgical robotic system, the data stream comprising data relating to a surgical procedure and comprising personally-identifiable data; determining one or more personally-identifiable feature in the received data stream; and generating, in dependence on the determined personally-identifiable feature and the received data stream, an anonymised data stream omitting the personally-identifiable data.