IP Library Granted Patent US 12701407
Granted Patent B2
US 12701407 · App. 16/558,052 · Granted Aug 4, 2026

Secure data translation using a low-energy wireless communication link

Inventors: Kenneth Hill (Atlanta, GA); Katherine S. Hill (Atlanta, GA)
Assignee: WONDERHEALTH, LLC
H04W12/033H04L9/16H04W12/02H04W12/04H04L2209/805
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12701407
App. No.
16/558,052
Granted
Aug 4, 2026
Kind
B2
Abstract

Disclosed are various embodiments for providing access control to the sensitive data, such as personal medical history. A first client device executes an application that ingests input data entered by a user via a user interface of the first client device, encrypts at least a first portion of the input data using a first cryptographic key, and transmits the encrypted input data over a low-power wireless private area network (WPAN), such as a Bluetooth Low-Energy (BLE) WPAN, for example. A second client device executing a second application receives the encrypted input data transmitted over the low-power WPAN by the first client device and use the first cryptographic key to decrypt the encrypted input data.

Claims (77)

1 . A system for use in a healthcare environment for securely communicating information between a healthcare patient user account and a healthcare provider user account, the system comprising:

a first client device associated with the healthcare patient user account, the first client device comprising at least one hardware processor, at least one memory device, and a display for rendering a user interface;

a second client device associated with the healthcare provider user account, the second client device comprising at least one hardware processor, at least one memory device, and a display for rendering a second user interface, wherein the second client device comprises a reader device;

a first application executable in the first client device, the first application comprising program instructions that, when executed, cause the first client device to:

ingest input data entered by a user via the user interface, the ingested input data comprising healthcare information in association with the healthcare patient user account;

store the ingested input data in the memory device;

access input data from the memory device;

render a first cryptographic key in the display through the user interface, the first cryptographic key being generated locally on the first client device or being received from a remote service over a network;

encrypt at least a first portion of the accessed input data using the first cryptographic key into a first set of encrypted payload data messages, the first set comprising one or more encrypted payload data messages;

generate a machine-readable identifier that provides access to the first set of encrypted payload data messages, the machine-readable identifier being rendered on the user interface of the first client device;

receive an encrypted initiate transfer payload message transmitted over a first low-power WPAN from the second client device executing a second application comprising program instructions, wherein the second application comprises additional program instructions that, when executed, enable the second client device to interpret the machine-readable identifier to access the first set of encrypted payload data messages;

use the first cryptographic key to decrypt the encrypted initiate transfer payload message, the decrypted initiate transfer payload message including information that notifies the first client device that a communication session with the second client device has commenced;

transmit the first set of encrypted payload data messages over the first low-power wireless private area network (WPAN) to the second client device associated with the healthcare provider user account, wherein use of the first low-power WPAN provides an additional layer of security beyond a level of security provided by the encryption.

2 . The system of claim 1 , wherein the first low-power WPAN is a BLE WPAN.

3 . The system of claim 1 , wherein prior to the program instructions causing the first client device to transmit the first set of encrypted payload data messages over the first low-power WPAN and after using the first cryptographic key to decrypt the encrypted initiate transfer payload message, the program instructions of the first application, when executed, cause the first client device to:

encrypt a metadata payload message; and

transmit the encrypted metadata payload message over the first low-power WPAN to the second client device, wherein the encrypted metadata payload message includes information describing a size of a payload that will be subsequently transmitted by the system over the first low-power WPAN during the communication session.

4 . The system of claim 3 , wherein after the program instructions of the first application cause the first client device to transmit the encrypted metadata payload message over the first low-power WPAN, the program instructions of the first application, when executed, cause the first client device to:

receive an encrypted first acknowledgement message transmitted over the first low-power WPAN by the second client device, the encrypted first acknowledgement message including information that notifies the first client device that the second client device has received the encrypted metadata payload message;

use the first cryptographic key to decrypt the encrypted first acknowledgement message; and

analyze contents of the decrypted first acknowledgement message to determine if the decrypted first acknowledgment message contains an acknowledgement before causing the first client device to transmit at least a first encrypted payload data message of the first set of encrypted payload data messages over the first low-power WPAN to the second client device.

5 . The system of claim 1 , wherein the program instructions of the first application, when executed by the first client device, cause the first client device to:

encrypt at least a second portion of the accessed input data using a second cryptographic key into a second set of encrypted payload data messages, the second set comprising one or more encrypted payload data messages; and

transmit at least a first encrypted payload data message of the second set over a second low-power WPAN to the second client device.

6 . The system of claim 5 , wherein prior to the program instructions of the first application causing the first client device to transmit at least the first encrypted payload data message of the second set over the second low-power WPAN, the program instructions of the first application, when executed, cause the first client device to:

receive an encrypted initiate transfer payload message transmitted over the second low-power WPAN from a third client device executing a third application; and

use the second cryptographic key to decrypt the encrypted initiate transfer payload message transmitted from the third client device, the decrypted initiate transfer payload message including information that notifies the first client device that a communication session with the third client device has commenced.

7 . The system of claim 6 , wherein prior to the program instructions of the first application causing the first client device to transmit at least the first encrypted payload data message of the second set over the second low-power WPAN and after using the second cryptographic key to decrypt the encrypted initiate transfer payload message, the program instructions, when executed, cause the first client device to:

use the second cryptographic key to encrypt a metadata payload message; and

transmit the encrypted metadata payload message over the second low-power WPAN, wherein the encrypted metadata payload message transmitted over the second low-power WPAN includes information describing a size of a payload that will be subsequently transmitted by the system over the second WPAN during the communication session.

8 . The system of claim 7 , wherein after the program instructions of the first application cause the first client device to transmit the encrypted metadata payload message over the second low-power WPAN, the program instructions of the first application, when executed, cause the first client device to:

receive an encrypted first acknowledgement message transmitted over the second low-power WPAN, the encrypted first acknowledgement message including information that notifies the first client device that the third client device has received the encrypted metadata payload message transmitted over the second low-power WPAN;

use the second cryptographic key to decrypt the encrypted first acknowledgement message transmitted over the second low-power WPAN; and

analyze contents of the decrypted first acknowledgement message transmitted over the second low-power WPAN to determine if the decrypted first acknowledgment message contains an acknowledgement before causing the first client device to transmit at least a first encrypted payload data message of the second set over the second low-power WPAN.

9 . A system for use in a healthcare environment for securely communicating information between a healthcare patient and a healthcare provider, the system comprising:

a first client device associated with the healthcare patient, the first client device comprising at least one processor, at least one memory device and a user interface;

an application executable in the first client device, the application comprising program instructions that, when executed, cause the first client device to:

receive one or more encrypted payload data messages that have been transmitted over a first low-power wireless private area network (WPAN) by a second client device associated with the healthcare provider, said one or more encrypted payload data messages including input data entered by a user into the second client device via a user interface of the second client device, the input data comprising information relating to the healthcare patient, wherein use of the first low-power WPAN provides an additional layer of security beyond a level of security provided by the encryption;

use a first cryptographic key to decrypt said one or more encrypted payload data messages;

use the first cryptographic key to encrypt a first acknowledgement message; and

transmit the encrypted first acknowledgement message over the first low-power WPAN.

10 . A computer-implemented method for use in a healthcare environment for securely communicating information between a healthcare patient and a healthcare provider, comprising:

ingesting, by a first client device, input data entered into the first client device by a user via a user interface, the ingested input data comprising information relating to the healthcare patient, the first client device being associated with the healthcare patient;

storing, by the first client device, the ingested input data in the memory device;

accessing, by the first client device, the input data from the memory device;

rendering, by the first client device, a first cryptographic key in the display through the user interface, the first cryptographic key being generated locally on the first client device or being received from a remote service over a network;

receiving, by a second client device, an out-of-band transfer of the first cryptographic key, wherein receipt of the first cryptographic key does not utilize a network;

encrypting, by the first client device, at least a first portion of the accessed input data using the first cryptographic key into a first set of one or more encrypted payload data messages;

receiving an encrypted initiate transfer payload message transmitted over a first low-power wireless private area network (WPAN) from the second client device executing a second application comprising program instructions;

using the first cryptographic key to decrypt the encrypted initiate transfer payload message, the decrypted initiate transfer payload message including information that notifies the first client device that a communication session with the second client device has commenced; and

transmitting, by the first client device, the first set of one or more encrypted payload data messages over the first low-power wireless private area network (WPAN) to the second client device associated with the healthcare provider, wherein use of the first low-power WPAN provides an additional layer of security beyond a level of security provided by the encryption.

11 . The method of claim 10 , wherein the first low-power WPAN is a Bluetooth Low Energy (BLE) WPAN.

12 . The method of claim 10 , further comprising:

prior to transmitting the first set of one or more encrypted payload data messages over the first low-power WPAN and after using the first cryptographic key to decrypt the encrypted initiate transfer payload message:

encrypting a metadata payload message; and

transmitting the encrypted metadata payload message over the first low-power WPAN to the second client device, wherein the encrypted metadata payload message includes information describing a size of a payload that will be subsequently transmitted by the first client device over the first low-power WPAN during the communication session.

13 . The method of claim 12 , further comprising:

after transmitting the encrypted metadata payload message over the first low-power WPAN:

receiving an encrypted first acknowledgement message transmitted over the first low-power WPAN, the encrypted first acknowledgement message including information that notifies the first client device that the second client device has received the encrypted metadata payload message;

using the first cryptographic key to decrypt the encrypted first acknowledgement message; and

analyzing contents of the decrypted first acknowledgement message to determine if the decrypted first acknowledgment message contains an acknowledgement before transmitting at least a first encrypted payload data message of the first set of one or more encrypted payload data messages over the first low-power WPAN.

14 . The method of claim 10 , further comprising:

encrypting at least a second portion of the accessed input data using a second cryptographic key into a second set of one or more encrypted payload data messages; and

transmitting the second set of one or more encrypted payload data messages over a second low-power WPAN.

15 . The method of claim 14 , further comprising:

prior to transmitting the second set of one or more encrypted payload data messages over the second low-power WPAN:

receiving an encrypted initiate transfer payload message transmitted over the second low-power WPAN from a third client device executing a third application comprising program instructions; and

using the second cryptographic key to decrypt the encrypted initiate transfer payload message transmitted from the third client device, the decrypted initiate transfer payload message including information that notifies the first client device that a communication session with the third client device has commenced.

16 . The method of claim 15 , further comprising:

prior to transmitting the second set of one or more encrypted payload data messages over the second low-power WPAN and after using the second cryptographic key to decrypt the encrypted initiate transfer payload message:

using the second cryptographic key to encrypt a metadata payload message; and

transmitting the encrypted metadata payload message over the second low-power WPAN, wherein the encrypted metadata payload message includes information describing a size of a payload that will be subsequently transmitted by the first client device over the second WPAN during the communication session.

17 . The method of claim 16 , further comprising:

after transmitting the encrypted metadata payload message over the second low-power WPAN:

receiving an encrypted first acknowledgement message transmitted over the second low-power WPAN, the encrypted first acknowledgement message including information that notifies the first client device that the third client device has received the encrypted metadata payload message;

using the second cryptographic key to decrypt the encrypted first acknowledgement message; and

analyzing contents of the decrypted first acknowledgement message to determine if the decrypted first acknowledgment message contains an acknowledgement before transmitting at least a first encrypted payload data message of the second set of one or more encrypted payload data messages over the second low-power WPAN.