Unique Access Link for Secure Health Data Entry

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The healthcare system faces a challenge in balancing security and accessibility when collecting sensitive information, as very secure processes can be inconvenient and may be bypassed, potentially negating their security value.

Innovation Solution

An electronic information system generates a unique access link that allows users to enter sensitive information without a username and password, using two-factor authentication such as personal identifiers or biometric verification, ensuring secure data entry while complying with regulations like HIPAA/HITECH.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If traditional username and password login is used, then security is maintained, but accessibility and convenience are reduced

Engineering Contradiction:
ImproveAccessibilityVSAvoidSecurity
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The authentication process is segmented into two distinct pathways: a public-facing unique link system for convenient access, and a separate credential verification system for security. The unique link acts as a segmented authentication token that divides the login process into link-based access rather than requiring traditional username/password entry, thereby improving ease of operation while maintaining security through the segmented authentication architecture.

Inventive Principle:
Principle #1Segmentation

2Reliability

If very secure processes are implemented, then security is improved, but convenience and accessibility deteriorate

Engineering Contradiction:
ImproveSecurityVSAvoidConvenience
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

A unique link serves as an intermediary authentication mechanism between the user and the protected health information system. This intermediary token (the unique link) carries authentication credentials without requiring the user to directly handle sensitive login credentials, thus maintaining high security standards while providing a convenient, simple user experience where users only need to click or enter a link rather than manage complex passwords.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Reliability

If secure authentication requirements are enforced, then security compliance is improved, but user experience and accessibility worsen

Engineering Contradiction:
ImproveSecurity complianceVSAvoidUser experience
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

Security compliance actions are performed preliminarily through the unique link generation and distribution process. The system pre-establishes authentication credentials by generating unique, secure links that embed necessary security tokens and permissions. This preliminary authentication setup eliminates the need for users to perform complex security actions during access, as the security verification has already been completed when the unique link was created and assigned to the user.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS11055434B2Process for collecting electronic protected health information without a login
Publication Date: 2021.07.06 MEND VIP INC
  • US11055434B2 patent drawing
  • US11055434B2 patent drawing
  • US11055434B2 patent drawing

AI summary

An efficient and secure process by which users may enter sensitive information into an electronic information system. When information is required from a user, the electronic information system may be configured to generate a unique access link (uniform resource locator, or URL) for that user. The link may be sent to the user via electronic communication, such as a text message or email. When the user follows the link with a web browser, the system prompts the user to enter an additional piece of personal information that is not known to the general public. Once identity is verified, the user may be required to electronically sign agreements. The user is then prompted to enter the required information. This may allow a user to deposit sensitive information into the system without requiring the user to provide full login credentials.