De-Identified Health Data Access Using Tokenized PHI Control
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current approaches to accessing patient health data for analytics are expensive, time-consuming, and elevate the risk of breaches due to the need for technical experts to handle protected health information (PHI), making it difficult to create efficient and affordable digital data products.
Innovation Solution
A system that encrypts PHI data, associates it with unique subject tokens and use right authorizations, and uses access tokens to control access, allowing authorized users to access de-identified data while ensuring compliance with patient consent.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If technical experts manually create ad-hoc data models and reports to access patient health data, then access to PHI is achieved, but costs increase and breach risk elevates
Solution Approach 1:
The patent introduces an automated access control system that acts as an intermediary between data requesters and PHI databases. This system uses cryptographic keys and automated verification to mediate access requests, eliminating the need for technical experts to manually handle PHI while maintaining security. The automated system verifies access rights through cryptographic proofs without exposing sensitive data to potential breaches.
Solution Approach 2:
The patent replaces the manual mechanical process of technical experts creating data models and accessing PHI with an automated cryptographic system. The system uses automated key verification, cryptographic proofs, and algorithmic access control to substitute human intervention, thereby reducing breach risk from human error while maintaining systematic control over PHI access.
2Productivity
If technical experts manually access and process PHI for analytics, then data insights are generated, but time consumption increases
Solution Approach 1:
The patent implements preliminary action by pre-establishing cryptographic access keys and authorization frameworks before any data access occurs. Access rights, cryptographic keys, and verification mechanisms are set up in advance, allowing rapid automated processing of data requests without manual intervention. This preliminary setup enables efficient insight generation while minimizing time loss for solution development.
Solution Approach 2:
The system enables self-service by allowing authorized entities to automatically obtain access to PHI through cryptographic verification without requiring manual assistance from technical experts. The automated system verifies access rights and grants data access independently, eliminating the time-consuming manual process of solution development and accelerating insight generation.
3Adaptability or versatility
If PHI is stored in accessible format for analytics, then data utility is improved, but security risk increases
Solution Approach 1:
The patent applies local quality by implementing different security characteristics for different data access scenarios. PHI is stored in encrypted form with localized decryption capabilities granted only to authorized entities with valid cryptographic keys. Each access request receives localized security treatment based on verified authorization, allowing data usability for analytics while maintaining security through context-specific access control.
Solution Approach 2:
The system changes the state parameter of PHI from plaintext to encrypted form, allowing the data to maintain its structural utility for analytics while being secured against breaches. Cryptographic transformations change the data representation to an insecure-to-unauthorized-eye format, enabling the same data to serve both usability and security requirements through parameter transformation.
Data Source
AI summary
A method for storing and controlling access to protected health information (PHI) data, comprising: obtaining health data, wherein the health data comprises, for at least some of a plurality of subjects, use right authorization received from the subject; removing identifying information from the health data to generate de-identified health data and PHI data; encrypting the PHI data; storing the encrypted PHI data in a patient data database, wherein the stored encrypted PHI data for each subject is associated with: (i) a unique subject token for that subject; (ii) a use right authorization received from that subject; and (iii) a corresponding access token for that subject; receiving, from a requester, a request for access to health data; determining which stored encrypted PHI data can be accessed by the requester; and providing access to only the health data for which the requester is determined to be authorized to access.


