Method for multi-tiered, rule-based data sharing and ontology mapping
A computer-based method for creating enforced, context-specific sharing of ontologically mapped, aggregated medical data includes storing at least one data field in a database as an entity type ontology, receiving context-specific rule configurations corresponding to the entity type ontology, and identifying any conflict between the received context-specific rule and any applicable rule. The context-specific rule configurations include at least one context, one data source, and one entity type ontology data field. If a conflict is identified, the method receives resolution of the conflict and stores the context-specific rule configurations in the database.
1. A computer-based method for generating a data-sharing database based on multi-tier permissioning, comprising:
storing in the database at least one rule regarding sharing of clinical trial data, wherein the rule is based on three rule tiers, a law tier, an informed consent agreement tier, and a user preference tier, wherein a rules engine is configured to calculate the precedence of rules across the three rule tiers;
generating an informed consent agreement regarding sharing of clinical trial data, wherein the informed consent agreement is obtained by a sponsor, signed by a patient, stored in the database, and converted into structured hierarchical rules that govern the sharing of the patient data obtained in the clinical trial, and supersedes user preferences;
receiving a context-specific rule configuration comprising a context, a data source, and an entity type, wherein said context-specific rule configuration comprises at least one term of said informed consent agreement;
identifying any conflict between the context-specific rule configuration by identifying any overlapping rules within the informed consent agreement tier and resolving the overlapping rules;
determining whether the identified conflict is between a term of said informed consent agreement and a user preference and, based on the determination, resolving the conflict in favor of the term of said informed consent agreement;
determining whether the identified conflict is between terms of informed consent agreements or is between user preferences and, based on the determination, receiving resolution of the conflict;
storing said context-specific rule configuration in the database;
generating a query interface comprising a plurality of filters comprising at least the context, the data source, and the entity type;
displaying on the query interface a summary of records, satisfying the filters, that are automatically accessible to a database user, accessible by request by the database user, and outside the query context; and
providing, based on the summary of records, for the database user to view the records that are automatically accessible, to submit a request for access to the records accessible by request, to view rules that govern the database user's query, and to edit or delete the rules.
2. The method of claim 1 , further comprising:
receiving a data access query from a user;
determining the context to query based on said data access query receipt; and
providing said user access to entity data based on said context-specific rule configuration.
3. The method of claim 1 , wherein receiving resolution of the conflict comprises (i) editing said context-specific rule configuration or (ii) contacting a creator of the conflicting rule.
4. The method of claim 1 , further comprising determining whether any queried data fields require access permission.
5. The method of claim 4 , wherein said determining whether any queried data fields require access permission includes issuing requests for data access.
6. The method of claim 1 , further comprising receiving at least one conditional rule selection.
7. The method of claim 1 , further comprising storing transactions in a database.
8. The method of claim 1 , wherein said context-specific rule configuration comprises a law.
9. The method of claim 1 , wherein the different levels of access comprise accessibility without an access permission request and accessibility with an access permission request.
10. The method of claim 9 , further comprising displaying the records satisfying the filters and that are accessible without an access permission request.
11. A computer-based method for generating a data-sharing database based on multi-tier permissioning, comprising:
storing in the database at least one rule regarding sharing of clinical trial data, wherein the rule is based on three rule tiers, a law tier, an informed consent agreement tier, and a user preference tier, wherein a rules engine is configured to calculate the precedence of rules across the three rule tiers;
generating an informed consent agreement regarding sharing of clinical trial data, wherein the informed consent agreement is obtained by a sponsor, signed by a patient, stored in the database, and converted into structured hierarchical rules that govern the sharing of the patient data obtained in the clinical trial, and supersedes user preferences;
receiving a context-specific rule configuration comprising a context, a data source, and an entity type, wherein said context-specific rule configuration comprises at least one term of said informed consent agreement;
identifying any conflict between the context-specific rule configuration by identifying any overlapping rules within the informed consent agreement tier and resolving the overlapping rules;
determining whether the identified conflict is between a term of said informed consent agreement and a user preference and, based on the determination, resolving the conflict in favor of the term of said informed consent agreement;
determining whether the identified conflict is between terms of informed consent agreements or is between user preferences and, based on the determination, receiving resolution of the conflict;
storing said context-specific rule configuration in the database;
generating a query interface comprising a plurality of filters comprising at least the context, the data source, and the entity type;
displaying on the query interface a summary of records, satisfying the filters, that are automatically accessible to a database user, accessible by request by the database user, and outside the query context; and
showing, based on the summary of records, the database user the records that are automatically accessible.