IP Library Granted Patent US 10,956,867
Granted Patent B2
US 10,956,867 · App. 13/075,903 · Granted Mar 23, 2021

Multi-factor authentication for remote access of patient data

Inventors: William Cameron Powell (San Antonio, TX); Stephen Trey Moore (San Antonio, TX)
Assignee: AirStrip IP Holdings, LLC
G06Q10/10G06F21/31G06F21/44G16H10/60H04L9/3226H04L63/0876H04W12/0602H04W12/0608H04L67/12H04L2209/80H04L2209/88
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,956,867
App. No.
13/075,903
Granted
Mar 23, 2021
Kind
B2
Abstract

The present disclosure is directed to authenticating a mobile device and a user of the mobile device to receive patient data from a clinical information system of a medical facility. In some implementations, methods include receiving a logon request, the logon request comprising credentials and at least one technical factor, accessing a validation database based on the at least one technical factor, determining that the mobile device is an authorized mobile device based on information provided by the validation database and the at least one technical factor, validating the credentials to ensure that the user is authorized to access patient data provided by the clinical information system, and then, upon determining that the user is authorized to access patient data: establishing a session to communicate patient data between the mobile device and the clinical information system, the data managements system processing the patient data communicated during the session.

Claims (53)

1. A computer-implemented method for authenticating a mobile device and a user of the mobile device to receive patient data, the computer-implemented method comprising:

receiving, by a data management system comprising one or more processors, a logon request, the logon request comprising credentials associated with the user and at least one technical factor associated with the mobile device, wherein the credentials comprise a username and a password;

accessing, by the data management system, a validation database based on one of the at least one technical factor and the credentials;

authenticating, by the data management system, the mobile device by determining that the mobile device is an authorized mobile device based on information provided by the validation database and the at least one technical factor and the credentials;

authenticating the user by comparing the credentials received at the data management system with authentication information stored at a first clinical information system of a first medical facility and a second clinical information system of a second medical facility by using the username as an index to retrieve a corresponding stored password that is matched to the password to validate the credentials to ensure that the user is authorized to access the patient data provided by the first clinical information system and the second clinical information system, from which the mobile device is configured to receive the patient data, wherein the first clinical information system is separate from the second clinical information system; and

in response to authenticating the mobile device and authenticating the user:

establishing a session to communicate the patient data between the mobile device and the first clinical information system and the second clinical information system through the data management system,

integrating, by the data management system, the patient data from a plurality of clinical information systems to generate integrated patient data, by synchronizing a portion of the patient data, the portion of the patient data being less than all of an available patient data within the plurality of clinical information systems, such that none of the available patient data is synchronized prior to establishing the session and the portion of the patient data is synchronized based on one or more configuration settings used by the plurality of clinical information systems and a custom rule defining data elements corresponding to the patient data that are to be synchronized, the configuration settings defining a first arrangement of a first set of patients within the first medical facility, each of the first set of patients corresponding to a respective first unit of a first set of units of the first medical facility and a second arrangement of a second set of patients within the second medical facility, each of the second set of patients corresponding to a respective second unit of a second set of units of the second medical facility and being automatically provided by a configuration module to the data management system,

processing, by the data management system, the integrated patient data communicated to the mobile device during the session to generate processed patient data, and

transmitting, by the data management system, the processed patient data to the mobile device for display independent of an operating system operating on the mobile device by using a connectivity mechanism matching the operating system of the mobile device.

2. The computer-implemented method of claim 1 , wherein the credentials comprise a username and a password.

3. The computer-implemented method of claim 1 , wherein the at least one technical factor comprises a device identification associated with the mobile device.

4. The computer-implemented method of claim 3 , wherein the mobile device comprises a mobile phone, and the at least one technical factor further comprises a telephone number associated with the mobile device.

5. The computer-implemented method of claim 1 , wherein the data management system comprises a web server and an application server.

6. The computer-implemented method of claim 5 , wherein the web server operates in a perimeter network and provides services to the application server and an external network, the perimeter network limiting access from the external network to the application server.

7. The computer-implemented method of claim 5 , wherein the web server and the application server are provided on a common physical device and are logically separated from one another.

8. The computer-implemented method of claim 5 , wherein the web server and the application server are provided on respective physical devices to be physically separate from one another.

9. The computer-implemented method of claim 5 , wherein authenticating the mobile device comprises authenticating the mobile device at the web server, and authenticating the user comprises:

in response to determining that the mobile device is the authorized mobile device, transmitting the credentials or the logon request from the web server to the application server.

10. The computer-implemented method of claim 9 , wherein authenticating the user comprises one of transmitting the credentials from the application server to the clinical information system, the clinical information system performing the validating, and retrieving authentication information from the clinical information system, the application server performing the validating based on the authentication information.

11. The computer-implemented method of claim 1 , further comprising transmitting the credentials from the data management system to the clinical information systems when it is determined that the mobile device is the authorized mobile device, each of the clinical information systems authenticating the user.

12. The computer-implemented method of claim 1 , further comprising retrieving authentication information from the clinical information systems, the data management system authenticating the user based on the authentication information.

13. The computer-implemented method of claim 1 , further comprising:

generating at least one of a digital patient data and a patient information at least one of the first medical facility and the second medical facility;

storing at least one of the patient data and the patient information in memory of an information system associated with the at least one of the first medical facility and the second medical facility; and

copying at least one of the patient data and the patient information to the data management system, the data management system being remotely located from the at least one of the first medical facility and the second medical facility.

14. The computer-implemented method of claim 13 , wherein the first medical facility and the second medical facility are included in a facility system, and wherein the data management system is located at the second medical facility of the facility system.

15. The computer-implemented method of claim 13 , wherein the first medical facility and the second medical facility are members of a facility system, and wherein the data management system is resident at a third party location, which is outside of the facility system.

16. The computer-implemented method of claim 13 , wherein the first medical facility and the second medical facility are members of a facility system, and wherein the data management system communicates with the first facility system and a second facility system.

17. The computer-implemented method of claim 13 , further comprising generating the digital patient data using a patient monitoring device that is in communication with the information system.

18. The computer-implemented method of claim 13 , further comprising generating the patient information based on a user input into the information system.

19. A non-transitory computer-readable storage device encoded with a computer program comprising instructions that, when executed, operate to cause one or more processors to perform operations for authenticating a mobile device and a user of the mobile device to receive patient data, the operations comprising:

receiving a logon request, the logon request comprising credentials associated with the user and at least one technical factor associated with the mobile device, wherein the credentials comprise a username and a password;

accessing a validation database based on one of the at least one technical factor and the credentials;

authenticating the mobile device by determining that a mobile device sending the logon request is an authorized mobile device based on information provided by the validation database and the at least one technical factor and the credentials;

authenticating the user by comparing the credentials received at a data management system with authentication information stored at a first clinical information system of a first medical facility and a second clinical information system of a second medical facility by using the username as an index to retrieve a corresponding stored password that is matched to the password to validate the credentials to ensure that the user is authorized to access the patient data provided by the first clinical information system and the second clinical information system, from which the mobile device is configured to receive the patient data, wherein the first clinical information system is separate from the second clinical information system; and

in response to authenticating the mobile device and in response to authenticating the user:

establishing a session to communicate the patient data between the mobile device and the first clinical information system and the second clinical information system through the data management system,

integrating the patient data from a plurality of clinical information systems to generate integrated patient data, by synchronizing a portion of the patient data, the portion of the patient data being less than all of an available patient data within the plurality of clinical information systems, such that none of the available patient data is synchronized prior to establishing the session and the portion of the patient data is synchronized based on one or more configuration settings used by the plurality of clinical information systems and a custom rule defining data elements corresponding to the patient data that are to be synchronized, the configuration settings defining a first arrangement of a first set of patients within the first medical facility, each of the first set of patients corresponding to a respective first unit of a first set of units of the first medical facility and a second arrangement of a second set of patients within the second medical facility, each of the second set of patients corresponding to a respective second unit of a second set of units of the second medical facility and being automatically provided by a configuration module to the data management system,

processing the integrated patient data communicated to the mobile device during the session to generate processed patient data, and

transmitting the processed patient data to the mobile device for display independent of an operating system operating on the mobile device by using a connectivity mechanism matching the operating system of the mobile device.

20. A system comprising:

one or more processors; and

a non-transitory computer-readable medium coupled to the one or more processors having instructions stored thereon which, when executed by the one or more processors, causes the one or more processors to perform operations for authenticating a mobile device and a user of the mobile device to receive patient data, the operations comprising:

receiving a logon request, the logon request comprising credentials associated with the user and at least one technical factor associated with the mobile device, wherein the credentials comprise a username and a password;

accessing a validation database based on one of the at least one technical factor and the credentials;

authenticating the mobile device by determining that a mobile device sending the logon request is an authorized mobile device based on information provided by the validation database and the at least one technical factor and the credentials;

authenticating the user by comparing the credentials received at a data management system with authentication information stored at a first clinical information system of a first medical facility and a second clinical information system of a second medical facility by using the username as an index to retrieve a corresponding stored password that is matched to the password to validate the credentials to ensure that the user is authorized to access the patient data provided by the first clinical information system and the second clinical information system, from which the mobile device is configured to receive the patient data, wherein the first clinical information system is separate from the second clinical information system; and

in response to authenticating the mobile device and in response to authenticating the user:

establishing a session to communicate the patient data between the mobile device and the first clinical information system and the second clinical information system through the data management system,

integrating the patient data from a plurality of clinical information systems to generate integrated patient data, by synchronizing a portion of the patient data, the portion of the patient data being less than all of an available patient data within the plurality of clinical information systems, such that none of the available patient data is synchronized prior to establishing the session and the portion of the patient data is synchronized based on one or more configuration settings used by the plurality of clinical information systems and a custom rule defining data elements corresponding to the patient data that are to be synchronized, the configuration settings defining a first arrangement of a first set of patients within the first medical facility, each of the first set of patients corresponding to a respective first unit of a first set of units of the first medical facility and a second arrangement of a second set of patients within the second medical facility, each of the second set of patients corresponding to a respective second unit of a second set of units of the second medical facility and being automatically provided by a configuration module to the data management system,

processing the integrated patient data communicated to the mobile device during the session to generate processed patient data, and

transmitting the processed patient data to the mobile device for display independent of an operating system operating on the mobile device by using a connectivity mechanism matching the operating system of the mobile device.

Assignments (13)
SECURITY INTEREST Recorded Oct 6, 2025
From: AIRSTRIP IP HOLDINGS, LLC; AIRSTRIP OPERATIONS, LLC; DECISIO HEALTH, LLC
To: ORBIMED ROYALTY & CREDIT OPPORTUNITIES IV, LP, AS ADMINISTRATIVE AGENT
Reel/Frame 072480/0096 →
RELEASE OF SECURITY INTEREST Recorded Sep 30, 2025
From: NANTWORKS, LLC, AS AGENT
To: AIRSTRIP IP HOLDINGS, LLC
Reel/Frame 072425/0545 →
AMENDED AND RESTATED PATENT COLLATERAL ASSIGNMENT AND SECURITY AGREEMENT Recorded Oct 3, 2019
From: AIRSTRIP IP HOLDINGS, LLC
To: NANTWORKS, LLC, AS AGENT
Reel/Frame 050630/0138 →
SECURITY INTEREST Recorded Apr 28, 2017
From: AIRSTRIP IP HOLDINGS, LLC
To: NANTWORKS, LLC
Reel/Frame 042177/0371 →
RELEASE OF SECURITY INTEREST Recorded Apr 28, 2017
From: FIFTH STREET FINANCE CORP.
To: AIRSTRIP IP HOLDINGS, LLC
Reel/Frame 042366/0843 →
RELEASE OF SECURITY INTEREST Recorded Apr 21, 2017
From: TRIPLEPOINT CAPITAL LLC
To: AIRSTRIP TECHNOLOGIES, INC.; AIRSTRIP HOLDINGS, LLC; AIRSTRIP OPERATIONS, LLC; AIRSTRIP IP HOLDINGS, LLC; AIRSTRIP OB, LLC; AIRSTRIP RPM, LLC; AIRSTRIP CARDIO, LLC
Reel/Frame 042313/0811 →
SECURITY INTEREST Recorded May 18, 2015
From: AIRSTRIP IP HOLDINGS, LLC
To: FIFTH STREET FINANCE CORP.
Reel/Frame 035660/0065 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Nov 9, 2011
From: POWELL, WILLIAM CAMERON; MOORE, STEPHEN TREY
To: AIRSTRIP DEVELOPMENT, L.P.
Reel/Frame 027197/0347 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Nov 9, 2011
From: AIRSTRIP DEVELOPMENT, L.P.
To: AIRSTRIP IP HOLDINGS, LLC
Reel/Frame 027197/0416 →
CHANGE OF NAME Recorded Nov 9, 2011
From: MP4 SOLUTIONS, L.P.
To: AIRSTRIP OB, L.P.
Reel/Frame 027197/0436 →
CHANGE OF NAME Recorded Nov 9, 2011
From: AIRSTRIP OB, L.P.
To: AIRSTRIP DEVELOPMENT, L.P.
Reel/Frame 027197/0450 →
CERTIFICATE OF CONVERSION - NV TO TX Recorded Nov 9, 2011
From: AIRSTRIP DEVELOPMENT, L.P.
To: AIRSTRIP DEVELOPMENT, L.P.
Reel/Frame 027197/0453 →
SECURITY AGREEMENT Recorded Sep 27, 2011
From: AIRSTRIP TECHNOLOGIES, INC.; AIRSTRIP HOLDINGS, LLC; AIRSTRIP OPERATIONS, LLC; AIRSTRIP IP HOLDINGS, LLC; AIRSTRIP OB, LLC; AIRSTRIP RPM, LLC; AIRSTRIP CARDIO, LLC
To: TRIPLEPOINT CAPITAL LLC
Reel/Frame 026978/0328 →