Tokenized Trial Data Linking via Bridge File
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Conventional methods for de-identifying personal health information in healthcare data sets are inadequate, leading to privacy breaches and limitations in data sharing and analysis, as they rely on single hashing seeds or encryption keys, making it difficult to link anonymized trial data with de-identified patient data across different healthcare entities.
Innovation Solution
A method and system that generates multiple tokens from personal identification information for a subject participating in a trial, creating a bridge file that links the subject identifier with these tokens, allowing for secure linking of trial data to other de-identified data without revealing personal information, using unique encryption keys managed by a central platform.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Object-affected harmful factors
If conventional hashing methods with single encryption keys are used to de-identify personal health information, then data privacy protection is improved, but the ability to link anonymized trial data with de-identified patient data across different healthcare entities deteriorates
Solution Approach 1:
The patent divides the encryption key into multiple separate keys, with each key managed by a different healthcare entity. This segmentation allows each entity to independently encrypt and de-identify their own data using their unique key, while still enabling linkage across entities through a central coordination mechanism that maps subject identifiers across the fragmented key system.
Solution Approach 2:
The patent introduces a central management system as an intermediary that coordinates between multiple healthcare entities. This intermediary maintains the mapping relationships between subject identifiers from different entities and manages the complex inter-key relationships, enabling data linkage without requiring direct key sharing between entities and thus preserving privacy while enabling connectivity.
2Reliability
If proprietary de-identification methods are used by each healthcare entity, then entity-specific data security is improved, but the ability to aggregate and share data for meaningful analysis deteriorates
Solution Approach 1:
Each healthcare entity maintains its own proprietary encryption key, preserving entity-specific security autonomy. The segmentation of the key management system allows each entity to independently secure their data while the central coordination layer provides the infrastructure for aggregation, thus maintaining both security independence and data sharing capability.
Solution Approach 2:
The patent creates a universal interface and standardized mapping mechanism that works across different proprietary encryption systems. The central management system provides universal functionality to aggregate data from multiple entities with different proprietary methods, enabling meaningful analysis without requiring entities to abandon their secure proprietary approaches.
3Object-affected harmful factors
If subject identifiers are used in trial data to maintain anonymity, then subject privacy is improved, but the ability to link trial data with other de-identified data deteriorates
Solution Approach 1:
The patent introduces a central management system as an intermediary that holds the mapping relationships between trial subject identifiers and external de-identified data identifiers. This intermediary enables linkage without exposing the direct connection between subject identifiers and personal information, maintaining anonymity while providing the necessary linkage capability through controlled access to mapping data.
Solution Approach 2:
The patent performs preliminary mapping and tokenization actions before data linkage is needed. Subject identifiers are pre-mapped to unique tokens and the relationships are pre-established in the central management system. This preliminary action enables efficient linkage operations later without requiring real-time decryption or exposure of identifying information, thus preserving anonymity while enabling data connection.
Data Source
AI summary
Systems and methodologies for generating a bridge file linking a subject identifier (Subject ID) (or a tokenized subject identifier), used to anonymize a subject in a trial, to tokenized personal identification information (PII), used to de-identify other data for the subject, without revealing the link between the subject identifier (subject ID) and the personal identifying information (PII) for the subject. The bridge file can then be used to link trial data for the subject anonymized with a subject ID to other data for the subject de-identified with tokenized PII.


