Trusted Information Broker for Patient Data Access Control

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current systems lack comprehensive solutions for managing access to personal data in compliance with privacy regulations, such as HIPAA and PIPEDA, which are essential for protecting sensitive information like health records, leading to inefficiencies and potential breaches.

Innovation Solution

A data access management system that employs a trusted information broker to receive requests for access to restricted records, obtain client consent, and grant or deny access based on client preferences, while providing a centralized repository for healthcare information and enabling patients to control their data.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Productivity

If a centralized data repository is implemented to improve healthcare provider efficiency, then access to patient information is improved, but patient privacy and data security are compromised

Engineering Contradiction:
Improvehealthcare provider efficiencyVSAvoiddata security
Core Design Contradiction:
ProductivityVSReliability

Solution Approach 1:

The patent introduces a trusted information broker as an intermediary system that sits between healthcare providers and patient data. This broker manages access requests, enforces consent preferences, and controls data disclosure without requiring providers to directly access or store sensitive patient information. The broker thus enables efficient information retrieval while maintaining security through centralized access control and audit capabilities.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If comprehensive access control policies are implemented to protect patient privacy, then data security is improved, but system complexity and operational difficulty increase

Engineering Contradiction:
Improvedata securityVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system enables patients to self-manage their own data access preferences through the trusted information broker. Patients can directly specify which entities may access their information and under what conditions, eliminating the need for complex manual authorization processes. This self-service approach simplifies the overall system by shifting control to the data owner while maintaining robust security through automated preference enforcement.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The patent implements preliminary action by requiring patients to establish their consent preferences in advance, before any data access requests occur. The trusted information broker stores these pre-defined preferences and automatically applies them to evaluate and process access requests. This preliminary setup eliminates the need for complex real-time authorization negotiations and simplifies the access control mechanism to a straightforward preference-matching process.

Inventive Principle:
Principle #10Preliminary action

3Ease of operation

If manual consent management processes are used to comply with privacy regulations, then patient control over data is improved, but processing time and operational efficiency deteriorate

Engineering Contradiction:
Improvepatient controlVSAvoidprocessing time
Core Design Contradiction:
Ease of operationVSLoss of time

Solution Approach 1:

The patent replaces manual, mechanical consent management processes with an automated electronic system. The trusted information broker electronically stores patient consent preferences and automatically evaluates access requests against these preferences using algorithmic logic. This substitution of mechanical manual processes with electronic automation maintains full patient control over their data while dramatically reducing processing time and enabling instant access decisions.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Data Source

PatentUS8275632B2Privacy compliant consent and data access management system and methods
Publication Date: 2012.09.25 PRIVIT
  • US8275632B2 patent drawing
  • US8275632B2 patent drawing
  • US8275632B2 patent drawing

AI summary

An information management system for restricting access to personal data in compliance with law or regulation includes a database having restricted records stored therein, at least one of the records including an identification of a client or group of clients about whom said record concerns. A computer system under the control of a trusted information broker is configured to receive via a communication medium a request initiated by a requester for access to at least one of the restricted records in the database, the request including an identification of the requester. The computer system is further configured to transmit a request for consent to the client and receive an indication from the client that the client consents or does not consent to access to the restricted record by the requestor. The computer system grants or denies access to the restricted records based upon the indication from the client.