Type-Based Personal Data Deidentification with Reversible Controls

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional methods for managing sensitive patient information, such as those used by healthcare organizations, are inadequate in preserving data usability while maintaining privacy, often being irreversible, computationally expensive, or insufficiently effective in preventing reidentification.

Innovation Solution

A software and hardware facility that employs data type determination, procedural deidentification operations, and NLP inference to efficiently deidentify personal information, allowing for partially reversible transformations and preserving temporal relationships, while reducing computational resources.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If conventional deidentification methods are used, then privacy protection is improved, but data usability deteriorates

Engineering Contradiction:
Improveprivacy protectionVSAvoiddata usability
Core Design Contradiction:
ReliabilityVSLoss of information

Solution Approach 1:

The system changes the parameter of deidentification reversibility from irreversible (conventional) to partially reversible. By implementing reversible deidentification transformations, the system maintains privacy protection while preserving data usability, allowing authorized parties to restore original data when needed.

Inventive Principle:
Principle #35Parameter changes

Solution Approach 2:

The system introduces dynamic control over deidentification through authorization mechanisms. Data can be dynamically switched between deidentified and identifiable states based on authorization, enabling flexible balance between privacy protection and data usability rather than static irreversible deidentification.

Inventive Principle:
Principle #15Dynamics

2Reliability

If conventional deidentification methods are used, then privacy protection is improved, but computational cost increases

Engineering Contradiction:
Improveprivacy protectionVSAvoidcomputational cost
Core Design Contradiction:
ReliabilityVSUse of energy by moving object

Solution Approach 1:

The system changes the computational parameter from expensive conventional deidentification to efficient reversible deidentification. By using reversible transformations instead of complex irreversible deidentification algorithms, the system achieves comparable privacy protection with reduced computational cost and energy consumption.

Inventive Principle:
Principle #35Parameter changes

3Reliability

If conventional deidentification methods are used, then privacy protection is improved, but reidentification resistance deteriorates

Engineering Contradiction:
Improveprivacy protectionVSAvoidreidentification risk
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The system changes the security parameter from vulnerable conventional deidentification to secure reversible deidentification with authorization control. By implementing authorized reversible transformations rather than conventional irreversible deidentification, the system maintains stronger resistance against unauthorized reidentification while enabling legitimate data recovery.

Inventive Principle:
Principle #35Parameter changes

Data Source

PatentUS20250298923A1Advanced deidentification of information, such as information about a person
Publication Date: 2025.09.25 PROVIDENCE ST JOSEPH HEALTH
  • US20250298923A1 patent drawing
  • US20250298923A1 patent drawing
  • US20250298923A1 patent drawing

AI summary

A facility for the identifying contents of a data object is described. The facility identifies in the data object two or more constituent portions. For each of the constituent portions identified in the data object, the facility: identifies a type of data items occurring within the constituent portion; on the basis of the identified data item type, selects a deidentification operation; and causes the selected deidentification operation to be performed on the data items of the constituent portion, such that these data items are modified to make the data items less identifiable with a person, and/or less-harmfully identifiable with a person. After the causing, the facility assembles the constituent portions containing the modified data items into a modified version of the data object.