Trusted Information Broker for Patient Data Access Control
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current systems lack comprehensive solutions for managing access to personal data in compliance with privacy regulations, such as HIPAA and PIPEDA, which are essential for protecting sensitive information like health records, leading to inefficiencies and potential breaches.
Innovation Solution
A data access management system that employs a trusted information broker to receive requests for access to restricted records, obtain client consent, and grant or deny access based on client preferences, while providing a centralized repository for healthcare information and enabling patients to control their data.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Productivity
If a centralized data repository is implemented to improve healthcare provider efficiency, then access to patient information is improved, but patient privacy and data security are compromised
Solution Approach 1:
The patent introduces a trusted information broker as an intermediary system that sits between healthcare providers and patient data. This broker manages access requests, enforces consent preferences, and controls data disclosure without requiring providers to directly access or store sensitive patient information. The broker thus enables efficient information retrieval while maintaining security through centralized access control and audit capabilities.
2Reliability
If comprehensive access control policies are implemented to protect patient privacy, then data security is improved, but system complexity and operational difficulty increase
Solution Approach 1:
The system enables patients to self-manage their own data access preferences through the trusted information broker. Patients can directly specify which entities may access their information and under what conditions, eliminating the need for complex manual authorization processes. This self-service approach simplifies the overall system by shifting control to the data owner while maintaining robust security through automated preference enforcement.
Solution Approach 2:
The patent implements preliminary action by requiring patients to establish their consent preferences in advance, before any data access requests occur. The trusted information broker stores these pre-defined preferences and automatically applies them to evaluate and process access requests. This preliminary setup eliminates the need for complex real-time authorization negotiations and simplifies the access control mechanism to a straightforward preference-matching process.
3Ease of operation
If manual consent management processes are used to comply with privacy regulations, then patient control over data is improved, but processing time and operational efficiency deteriorate
Solution Approach 1:
The patent replaces manual, mechanical consent management processes with an automated electronic system. The trusted information broker electronically stores patient consent preferences and automatically evaluates access requests against these preferences using algorithmic logic. This substitution of mechanical manual processes with electronic automation maintains full patient control over their data while dramatically reducing processing time and enabling instant access decisions.
Data Source
AI summary
An information management system for restricting access to personal data in compliance with law or regulation includes a database having restricted records stored therein, at least one of the records including an identification of a client or group of clients about whom said record concerns. A computer system under the control of a trusted information broker is configured to receive via a communication medium a request initiated by a requester for access to at least one of the restricted records in the database, the request including an identification of the requester. The computer system is further configured to transmit a request for consent to the client and receive an indication from the client that the client consents or does not consent to access to the restricted record by the requestor. The computer system grants or denies access to the restricted records based upon the indication from the client.


