Trust-Based Health Record Access via Encrypted Protocol

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current systems for managing electronic health records face challenges in providing secure, accessible, and traceable access to patient information across disparate proprietary systems, leading to inconsistent access and privacy concerns, with patients often unaware of where their medical information is stored or who has access to it.

Innovation Solution

A system that allows patients to control access to their health records by authorizing specific entities through a secure, anonymized identifier-based protocol, enabling encrypted communications and restricting access based on user devices, times, and permissions, ensuring privacy and security.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Quantity of substance

If medical information is stored in disparate proprietary systems across different locations, then the quantity of stored medical information increases, but the ease of accessing and compiling medical information deteriorates

Engineering Contradiction:
Improvequantity of stored medical informationVSAvoidease of accessing and compiling medical information
Core Design Contradiction:
Quantity of substanceVSEase of operation

Solution Approach 1:

The patent introduces a centralized access system that acts as an intermediary between medical professionals and disparate proprietary storage systems. This access system provides a unified interface for querying and retrieving medical information across multiple proprietary systems, eliminating the need for professionals to manually access each system separately. The intermediary translates standardized queries into proprietary system-specific protocols, thereby maintaining the benefits of distributed storage while enabling centralized access.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The access system is designed with universal functionality to interface with multiple different proprietary systems simultaneously. It provides a single unified access point that can retrieve information from various storage locations using different protocols, making the system adaptable to diverse medical information infrastructure while maintaining consistent access methods for users.

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Reliability

If access to medical information is restricted to specific computer systems in specific wards, then the security and privacy of medical information is improved, but the ease of operation and accessibility deteriorates

Engineering Contradiction:
Improvesecurity and privacy of medical informationVSAvoidaccessibility of medical information
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent implements location-aware access control where the system determines whether a medical professional is physically present at the appropriate facility or ward before granting access to medical information. This local quality control maintains security by restricting access to geographically appropriate locations while still providing broad accessibility within those locations. The system verifies the professional's location and only permits access to information relevant to that specific facility, thereby maintaining both security and operational ease.

Inventive Principle:
Principle #3Local quality

3Reliability

If patients are given full control over access to their medical information, then the privacy protection is improved, but the complexity of managing access permissions deteriorates

Engineering Contradiction:
Improveprivacy protectionVSAvoidcomplexity of managing access permissions
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent enables patients to directly control access to their own medical information through the system interface. Patients can view who has accessed their information, grant or revoke access permissions, and receive notifications about access events. This self-service capability empowers patients to manage their own privacy without requiring complex intermediary authorization processes, thereby maintaining strong privacy protection while simplifying the management interface.

Inventive Principle:
Principle #25Self-service

4Reliability

If medical information is accessed manually by pulling hard copies one at a time, then the security control is improved, but the productivity and time efficiency deteriorates

Engineering Contradiction:
Improvesecurity controlVSAvoidproductivity and time efficiency
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent enables continuous electronic access to medical information where multiple professionals can simultaneously retrieve information from the centralized access system. Unlike manual hard copy retrieval where each access is discrete and sequential, the electronic system allows concurrent access by multiple users, continuous querying, and rapid information compilation. This maintains security control through authenticated access while dramatically improving productivity through parallel information retrieval and elimination of physical handling delays.

Inventive Principle:
Principle #20Continuity of useful action

Data Source

PatentUS11328088B2Trust based access to records via encrypted protocol communications with authentication system
Publication Date: 2022.05.10 AKIRI INC
  • US11328088B2 patent drawing
  • US11328088B2 patent drawing
  • US11328088B2 patent drawing

AI summary

Systems and techniques are disclosed for trust based access to records via encrypted protocol communications with an authentication system. An example system is configured to authorize and provide selective and secured access to sensitive medical information according to one or more trusted relationships. The system is configured to receive a request for access to a patient's health record from an outside entity. Authentication information associated with the outside entity is determined. Whether the outside entity is authorized to access the requested data is determined. The determination is based on existence of a trust relationship being established between the outside entity and the patient, the trust relationship established by an action of the patient or a patient's representative. Access to the patient's health record is enabled based on a positive determination.