IP Library Granted Patent US 8,532,764
Granted Patent B2
US 8,532,764 · App. 12/574,380 · Granted Sep 10, 2013

Post-download patient data protection in a medical device

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 8,532,764
App. No.
12/574,380
Granted
Sep 10, 2013
Kind
B2
Abstract

The disclosure describes techniques for protecting patient data stored in a medical device, such as an external defibrillator. The patient data may be transferred, or downloaded, from the medical device to another device, such as to a computing device for storage or analysis. In response to the download, the medical device may protect the patient data so that at least subset of users can no longer access the patient data. Patient data may be protected by modifying the data form, encrypting the data, moving the data to another memory module, password protecting the patient data, or modifying an access control list associated with the patient data. While the patient data may also be deleted as a technique for protecting the data, not deleting the data may allow the data to be recovered at a later time by an authorized user, i.e., a user not part of the subset.

Claims (38)

1. A method comprising:

storing patient data collected by an external defibrillator during treatment of a patient within a medical device;

allowing users to access the patient data stored in the medical device;

downloading the patient data from the medical device to another device; and

in response to downloading the patient data, protecting the patient data in the medical device such that the protected patient data is inaccessible to at least a first subset of authorized users while the protected patient data in the medical device is accessible to a second subset of authorized users, wherein the patient data was accessible to the first subset of authorized users before the patient data was protected.

2. The method of claim 1 , wherein protecting the patient data comprises modifying a form of the patient data in the medical device.

3. The method of claim 1 , wherein protecting the patient data comprises encrypting the patient data in the medical device.

4. The method of claim 1 , wherein protecting the patient data comprises moving the patient data from a first memory location in the medical device to a second memory location in the medical device.

5. The method of claim 1 , wherein protecting the patient data comprises requiring a password to access the patient data.

6. The method of claim 1 , wherein protecting the patient data comprises modifying an access control list associated with the patient data.

7. The method of claim 1 , further comprising determining whether the download of patient data from the medical device to the other device is complete, wherein protecting the patient data comprises protecting the patient data in response to the determination.

8. The method of claim 7 , wherein determining whether the download is complete comprises receiving an acknowledgment from the other device at the medical device.

9. The method of claim 1 , further comprising determining whether one of the users has configured the medical device to protect patient data in response to downloading the patient data, wherein protecting the patient data comprises protecting the patient data based on the determination.

10. The method of claim 1 , wherein the medical device is the external defibrillator.

11. A medical device comprising:

a memory configured to store patient data collected by an external defibrillator during treatment of a patient;

a communications circuit configured to communicate with another device; and

a processor that allows users to access the patient data stored in the memory, controls the communications circuit to download the patient data to the other device and, in response to the download, protects the patient data in the memory such that the patient data is inaccessible to at least a subset of the users, wherein, to protect the patient data, the processor makes the data inaccessible to a first subset of authorized users while leaving the patient data accessible to a second subset of authorized users, wherein the patient data was accessible to the first subset of authorized users before the patient data was protected.

12. The device of claim 11 , wherein the processor modifies a form of the patient data in the memory to protect the patient data.

13. The device of claim 11 , wherein the processor encrypts the patient data in the memory to protect the patient data.

14. The device of claim 11 , wherein the processor moves the patient data from a first location in the memory to a second location in the memory to protect the patient data.

15. The device of claim 11 , wherein the processor protects the patient data by requiring a password to access the patient data in the memory.

16. The device of claim 11 , wherein the processor modifies an access control list associated with the patient data to protect the patient data in the memory.

17. The device of claim 11 , wherein the processor determines whether the download of patient data from the medical device to the other device is complete, and protects the patient data in response to the determination.

18. The device of claim 17 , wherein the processor determines whether the download is complete by receiving an acknowledgement from the other device via the communication circuitry.

19. The device of claim 11 , further comprising a user interface, wherein the processor receives configuration instructions from one of the users via the user interface, and determines whether to protect the patient data in response to the download based on the configuration instructions.

20. The device of claim 11 , wherein the device comprises the external defibrillator.

21. A non-transitory computer readable medium comprising instructions that cause a processor to:

store patient data collected by an external defibrillator during treatment of a patient within a medical device;

allow users to access the patient data stored in the medical device;

download the patient data to another device; and

in response to the download, protect the patient data in the first device such that the protected patient data is inaccessible to at least a first subset of authorized users while the protected patient data is accessible to a second subset of authorized users, wherein the patient data was accessible to the first subset of authorized users before the patient data was protected.

22. The non-transitory computer-readable medium of claim 21 , further comprising instructions that cause a processor to determine whether the download of patient data from the medical device to the other device is complete, wherein the instructions that cause a processor to protect the patient data comprise instructions that cause a processor to protect the patient data in response to the determination.

23. The non-transitory computer-readable medium of claim 21 , wherein the instructions that cause a processor to store patient data in a medical device comprise instructions that cause a processor to store the patient data in the external defibrillator.

24. A medical device comprising:

a memory configured to store patient data collected by an external defibrillator during treatment of a patient;

a communications circuit configured to communicate with another device; and

a processor that allows users to access the patient data stored in the memory, controls the communications circuit to download the patient data to the other device and, in response to the download, deletes the patient data from the memory.

Assignments (10)
RELEASE OF SECURITY INTEREST Recorded Apr 7, 2016
From: CITIBANK, N.A.
To: PHYSIO-CONTROL, INC.; PHYSIO-CONTROL INTERNATIONAL, INC.
Reel/Frame 038379/0001 →
RELEASE OF SECURITY INTEREST Recorded Apr 7, 2016
From: CITIBANK, N.A.
To: PHYSIO-CONTROL, INC.
Reel/Frame 038376/0806 →
RELEASE OF SECURITY INTEREST Recorded Apr 7, 2016
From: CITIBANK, N.A.
To: PHYSIO-CONTROL, INC.; PHYSIO-CONTROL INTERNATIONAL, INC.
Reel/Frame 038378/0028 →
SECOND LIEN SECURITY AGREEMENT Recorded Jan 19, 2016
From: PHYSIO-CONTROL, INC.; PHYSIO-CONTROL INTERNATIONAL, INC.
To: CITIBANK, N.A., AS COLLATERAL AGENT
Reel/Frame 037559/0601 →
FIRST LIEN SECURITY AGREEMENT Recorded Jan 15, 2016
From: PHYSIO-CONTROL, INC.; PHYSIO-CONTROL INTERNATIONAL, INC.
To: CITIBANK, N.A., AS COLLATERAL AGENT
Reel/Frame 037532/0828 →
RELEASE OF SECURITY INTEREST Recorded Jan 14, 2016
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A.
To: PHYSIO-CONTROL, INC.
Reel/Frame 037519/0240 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Mar 12, 2012
From: DUKE, STEVEN B.
To: MEDTRONIC EMERGENCY RESPONSE SYSTEMS, INC.
Reel/Frame 027843/0462 →
SECURITY AGREEMENT Recorded Feb 10, 2012
From: PHYSIO-CONTROL, INC.
To: CITIBANK, N.A., AS COLLATERAL AGENT
Reel/Frame 027763/0881 →
SECURITY AGREEMENT Recorded Feb 9, 2012
From: PHYSIO-CONTROL, INC.
To: BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS *COLLATERAL TRUSTEE, THE
Reel/Frame 027765/0861 →
CHANGE OF NAME Recorded Oct 3, 2011
From: MEDTRONIC EMERGENCY RESPONSE SYSTEMS, INC.
To: PHYSIO-CONTROL, INC.
Reel/Frame 027008/0918 →