Universal Security Manager for Secure EMR Transfer

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The incompatibility of various electronic medical record (EMR) systems and the lack of secure, user-controlled methods for transferring EMR information to third-party health applications hinder the seamless integration of health services, as users face difficulties in accessing and sharing their medical records securely across different healthcare facilities and applications.

Innovation Solution

A universal security manager is introduced to facilitate the secure transfer of EMR information by validating trusted third-party applications and using secure linking codes, allowing users to control the transfer process and set parameters for data sharing, thereby bridging the compatibility gap between incompatible EMR systems.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Productivity

If EMR systems are adopted to store and manage medical records electronically, then the benefit of digital health record management is improved, but compatibility issues between different EMR systems cause information inaccessibility

Engineering Contradiction:
Improvehealth record management efficiencyVSAvoidEMR system compatibility
Core Design Contradiction:
ProductivityVSAdaptability or versatility

Solution Approach 1:

A universal security manager is introduced as an intermediary system between incompatible EMR systems and third-party applications. The security manager receives secure linking codes from different EMR systems, validates third-party applications against security criteria, and facilitates controlled information transfer, thereby enabling compatibility without requiring direct integration between disparate EMR systems.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If EMR information is protected with increasing security measures and regulations, then data security is improved, but access difficulty for third-party applications increases

Engineering Contradiction:
ImproveEMR information securityVSAvoidaccess process complexity
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

Third-party applications undergo preliminary validation against minimum security criteria before being granted access to EMR information. The universal security manager pre-establishes trust relationships by validating applications in advance, so that when information transfer is needed, the process is streamlined rather than requiring complex real-time security negotiations.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The universal security manager acts as a mediator that handles security validation and authorization, shielding third-party applications from the complexity of direct security negotiations with multiple EMR systems. Users set preferences once, and the security manager manages the security protocols, simplifying the access process while maintaining strong security.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Speed

If direct transfer methods are used between healthcare service facilities and third-party applications, then transfer speed is improved, but user control and authorization management become difficult

Engineering Contradiction:
ImproveEMR transfer speedVSAvoiduser control capability
Core Design Contradiction:
SpeedVSEase of operation

Solution Approach 1:

The universal security manager serves as an intermediary that maintains fast direct transfer capabilities between EMR systems and third-party applications while simultaneously providing a centralized control interface for users. Users can set their preferences and authorization parameters once, and the security manager enforces these controls automatically during transfers, eliminating the need for users to manually authorize each transfer while maintaining user oversight.

Inventive Principle:
Principle #24Intermediary (Mediator)

4Reliability

If multiple user accounts are required at different third-party applications for different healthcare facilities, then application-specific access control is improved, but system complexity and user burden increase

Engineering Contradiction:
Improveaccess control precisionVSAvoidaccount management complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The universal security manager provides a single, unified authorization interface that works across multiple healthcare facilities and third-party applications. Instead of requiring separate accounts at each application, users interact with one security manager that handles authentication and authorization for all connected systems, maintaining precise access control while eliminating the need for multiple accounts.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS10623380B1Secure transfer of medical records to third-party applications
Publication Date: 2020.04.14 CERNER INNOVATION INC
  • US10623380B1 patent drawing
  • US10623380B1 patent drawing
  • US10623380B1 patent drawing

AI summary

Media and methods for securely providing third-party applications, such as health based service applications, with electronic medical records (EMRs), or discrete information therein, of an individual is provided. To facilitate the secure transfer of medical records, a universal security manager is described. The universal security manager may act as an intermediary between a healthcare service facility, such as a hospital, and the third-party application. A secure link for transferring EMRs from the healthcare service facility to the universal security manager may be established using a secure linking code. The third-party application may be validated as a trusted third-party application by the universal security manager based on a set of security criteria. The universal security manager may provide the EMR information from an EMR system associated with the healthcare service facility to the trusted third-party application based on a set of permissions created and/or maintained by a user.