WO2005098736A2

System and method for controlling access and use of patient medical data records

Abstract

A system for processing patient health information(PHI) protects the confidentiality of PHI to achieve regulatory compliance. The PHI contains patient medical data and associated patient identification data. A de-identification agent extracts patient medical data and separates from all identification data to create de-identified patient data. A key is generated that allows subsequent reassociation of the patient medical data and the patient identification data. The de-identified patient data base may be queried for patient screening purposes. Patient queries are processed only if the study or patient screening has been authorized by appropriate authorities, such as an internal review board. Patients whose medical characteristics conform with patient query are selected for possible use in a study. If re-identification of the selected patients is necessary, and authorized, the key may be used to provide the necessary reaassociation. A data log records all access to patient data.

WO2005098736A2, drawing sheet 1
Sheet 1 of 18

Term

No projected expiry on record.

  1. Priority
  2. Filed
  3. Published
  4. Today

79 claims: 5 independent, 74 dependent

  1. 1
    CLAIMS The invention claimed is:1. A system to control access to a protected health information (PHI) storage structure that stores patient identification data and associated patient medical data comprising: a de-identified data storage structure to store patient medical data in a manner that is disassociated from the patient identification data;a key file containing data interrelating the disassociated patient identification data and the patient medical data;an authorization controller to process data access requests, the authorization controller receiving an access request, comparing the received access request with a predetermined data access authorization and, if the received access request complies with the predetermined data access authorization, permitting access to patient medical data.
  2. 18
    A system to control access to a protected health information (PHI) storage structure in each of a plurality of medical institutions that stores patient identification data and associated patient medical data of the respective medica l institutions, the system comprising:a de-identified data storage structure to store patient medical data in a manner that is disassociated from the patient identification data;a key file containing data interrelating the disassociated patient identification data and the patient medical data;an authorization controller to process data access requests, the authorization controller receiving an access request, comparing the received access request with a predetermined data access authorization and, if the received access request complies with the predetermined data access authorization, permitting access to patient medical data.
  3. 38
    A method for controlling access to patient medical data stored in a protected health information (PHI) storage structure to store patient identification data and associated patient medical data, the method comprising:storing patient medical data in a de-identified data structure in a manner that disassociates patient medical data from the patient identification data;storing data interrelating the disassociated patient identification data and the patient medical data;receiving an access request to access patient medical data;comparing the received access request with a predetermined data access authorization;and permitting access to patient medical data if the received access request complies with the predetermined data access authorization.
  4. 50
    A method for controlling access to patient medical data stored in a protected health information (PHI) storage structure in each of a plurality of medical institutions to store patient identification data and associated patient medical data, the method comprising:storing patient medical data in a de-identified data structure in a manner that disassociates patient medical data from the patient identification data;storing data interrelating the disassociated patient identification data and the patient medical data;receiving an access request to access patient medical data;comparing the received access request with a predetermined data access authorization;and permitting access to patient medical data if the received access request complies with the predetermined data access authorization.
  5. 62
    A computer-readable media for controlling access to patient medical data stored in a protected health information (PHI) storage structure configured to store patient identification data and associated patient medical data by causing a computer to:store patient medical data in a de-identified data structure in a manner that disassociates patient medical data from the patient identification data;store data interrelating the disassociated patient identification data and the patient medical data;receive an access request to access patient medical data;compare the received access request with a predetermined data access authorization;and permit access to patient medical data if the received access request complies with the predetermined data access authorization.