Volatile Memory Image Erasure for HIPAA Compliance
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing systems fail to securely acquire and transmit images containing protected health information (PHI) in compliance with HIPAA regulations, risking unauthorized interception and intrusion, which can lead to legal and financial liabilities for healthcare providers.
Innovation Solution
A method and system utilizing a mobile communication device to acquire images, allocate volatile memory space for secure storage, encrypt the images, and transmit them using a secure protocol, with the volatile memory space being de-allocated and the image erased after the session, ensuring non-persistent retention and secure transmission.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Loss of information
If images are stored in persistent memory for later retrieval, then data accessibility is improved, but security against unauthorized access and intrusion is worsened
Solution Approach 1:
The patent uses volatile memory (RAM) as a temporary storage medium that automatically loses data when power is removed or memory is de-allocated. This disposable storage approach ensures that PHI images are accessible during the session but cannot be retrieved afterward, eliminating the security risk of persistent storage while maintaining operational accessibility.
Solution Approach 2:
The patent changes the storage state parameter from persistent (hard drive) to volatile (RAM), and from stored to transmitted. By de-allocating memory after transmission, the data transitions from an accessible state to an erased state, resolving the contradiction between accessibility and security.
2Adaptability or versatility
If images are transmitted over open networks, then communication capability is improved, but protection from unauthorized interception is worsened
Solution Approach 1:
The patent introduces encryption as an intermediary layer between the image data and the transmission channel. The PHI image is encrypted before transmission and decrypted only at the destination, preventing unauthorized interception while maintaining communication capability over open networks.
Solution Approach 2:
The patent uses transient volatile memory for storing images only during the transmission session, eliminating persistent storage that could be compromised. Combined with encryption during transmission, this approach enables secure communication without relying on persistent storage infrastructure.
3Reliability
If volatile memory is de-allocated after session, then security against data theft is improved, but data retention capability is worsened
Solution Approach 1:
The patent deliberately uses volatile memory with automatic data loss on de-allocation as the storage medium. This short-living storage property is the core security mechanism, ensuring that PHI cannot be stolen from persistent storage while still being accessible during the transmission session.
Solution Approach 2:
The patent discards the image data from volatile memory after successful transmission by de-allocating the memory space. The data is recovered at the destination system where it is stored securely, transferring the retention burden from the mobile device to the destination system.
Data Source
AI summary
Methods and systems allow secure acquisition and transmission of images by a mobile communication device. The method includes acquiring an image by the mobile device and allocating volatile memory space in the mobile device for a defined session. The image may be acquired by a digital camera built in the mobile device. The method includes digitally storing the acquired image in the allocated volatile memory space. The method includes encrypting and transmitting the stored image using a secure transmission protocol during the session. The method includes de-allocating the volatile memory space at the termination of the session. The de-allocation of the volatile memory space may cause the digitally stored image to be erased from the volatile memory space. Thus, the stored image is not persistently retained by the mobile device.

