Voice PHI Access With Out-of-Band User Authentication

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing voice command-controlled devices are unable to authenticate access to confidential information such as private health information (PHI), limiting their ability to provide this information audibly while ensuring confidentiality and privacy.

Innovation Solution

A system and method that uses voice-controlled devices in conjunction with user-controlled devices to authenticate access to PHI through out-of-band authentication methods, including biometric data, vocal recognition, and secondary device verification, allowing secure and audible presentation of PHI.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If voice command-controlled devices present PHI audibly to users, then accessibility and convenience are improved, but confidentiality and privacy cannot be ensured

Engineering Contradiction:
Improveaccessibility of PHIVSAvoidconfidentiality risk
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The patent introduces an intermediary authentication system that mediates between the voice-controlled device and the PHI data. The system uses out-of-band authentication (separate communication channel) to verify user identity before allowing PHI access, thus protecting confidentiality while enabling convenient voice-based access for authenticated users.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent segments the authentication process from the PHI delivery process. Authentication occurs through a separate out-of-band channel (distinct from the voice command channel), creating independent verification layers. This segmentation allows the system to verify identity securely while maintaining the convenience of voice-based PHI retrieval through the original device.

Inventive Principle:
Principle #1Segmentation

2Object-affected harmful factors

If voice command-controlled devices are restricted from accessing PHI, then confidentiality is maintained, but the devices cannot provide useful health information services

Engineering Contradiction:
Improveconfidentiality protectionVSAvoidservice capability
Core Design Contradiction:
Object-affected harmful factorsVSProductivity

Solution Approach 1:

The patent implements preliminary authentication action through out-of-band verification before PHI access is granted. The system pre-verify user identity through a separate authentication channel, then subsequently allows the voice-controlled device to access and present PHI. This preliminary security check enables the device to provide full health information services while maintaining confidentiality through pre-established trust verification.

Inventive Principle:
Principle #10Preliminary action

3Reliability

If out-of-band authentication is implemented, then security is improved, but device complexity increases

Engineering Contradiction:
Improveauthentication securityVSAvoidsystem architecture
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent implements self-service authentication where the user's own devices (mobile phone, wearable) that they already possess and control are used for verification. The out-of-band authentication leverages existing user devices and their built-in security mechanisms, eliminating the need for the voice-controlled device itself to become more complex. The authentication burden is transferred to devices the user already carries and trusts.

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS12493676B2System and method for authenticating access to private health information
Publication Date: 2025.12.09 CIGNA INTPROP
  • US12493676B2 patent drawing
  • US12493676B2 patent drawing
  • US12493676B2 patent drawing

AI summary

A method for authenticating access to private health information (PHI) includes receiving a converted version of a spoken initiation of a retrieval of PHI. The method also includes requesting out-of-band authentication information from a user. The out-of-band authentication information that is requested contains different information than the spoken initiation of the retrieval of the PHI. The method also includes determining whether the out-of-band authentication information received from the user satisfies an authentication criterium associated with the user, obtaining the PHI requested by the user via the spoken initiation provided to the first device responsive to the out-of-band authentication information, and presenting the PHI requested by the user via the first device.