IP Library Granted Patent US 11,784,969
Granted Patent B2
US 11,784,969 · App. 17/207,494 · Granted Oct 10, 2023

System for securely monitoring and extracting data through a private network

Inventor: Marc Tobias (Philadelphia, PA)
Assignee: Phrase Health, Inc.
H04L63/02G06F9/451G06F16/245G16H10/60H04L63/0272
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,784,969
App. No.
17/207,494
Granted
Oct 10, 2023
Kind
B2
Abstract

Systems and methods are described for secure data extraction through a private network. A data extraction application may operate behind a firewall on a client system. Application state information may be automatically gathered and sent by the data extraction application upon the data extraction application being awakened at a predetermined time. A remote system outside of a firewall may determine commands to return to the data extraction application that include one or more query parameters, and then send the commands to the data extraction application. The remote system may then obtain, from the client system behind the firewall or from a data store outside of the firewall, results of the data extraction application executing a query with the provided query parameters injected therein, where the query was executed by the data extraction application with respect to one or more files located behind the firewall.

Claims (32)

1. A computer system comprising:

memory; and

a processor in communication with the memory and configured with processor-executable instructions to perform operations comprising:

providing configuration information for a data extraction application operating behind a firewall on a client system;

receiving application state information from the data extraction application, wherein the application state information is automatically gathered and sent by the data extraction application upon the data extraction application being awakened at a predetermined time;

in response to receipt of the application state information, determining commands to return to the data extraction application that include one or more query parameters;

sending the commands to the data extraction application, wherein the commands include the one or more query parameters as parameters to be injected by the data extraction application into at least one query previously stored by the data extraction application;

obtaining, from the client system or a data store outside of the firewall, results of the data extraction application executing the query with the parameters injected, wherein the query was executed by the data extraction application with respect to one or more files located behind the firewall;

identifying that data relating to a first time period was not extracted by the data extraction application as specified by one of (a) a predetermined schedule or (b) a request from the computer system; and

sending a set of commands to the data extraction application related to a second time period that causes the data extraction application to extract both (c) data related to the first time period and (d) data related to the second time period.

2. The computer system of claim 1 , wherein the client system comprises or is in communication with one of (a) an electronic health record system or (b) a computer system of a medical practice, wherein the one or more files located behind the firewall are stored in association with at least one of the electronic health record system or the medical practice.

3. The computer system of claim 2 , wherein the at least one query previously stored by the data extraction application is configured, when executed with the one or more query parameters, to access electronic health data behind the firewall.

4. The computer system of claim 1 , wherein the operations further comprise monitoring, by the computer system, a plurality of systems or subsystems of the client system based on the obtained results of the data extraction application, wherein the computer system is not permitted to directly access data of the plurality of systems or subsystems of the client system.

5. The computer system of claim 1 , wherein the operations further comprise:

generating a user interface that includes a plurality of metrics derived from the obtained results of the data extraction application that operates behind the firewall on the client system; and

causing presentation of the user interface to an administrator computing device that is not configured to directly access files behind the firewall on the client system.

6. The computer system of claim 5 , wherein the user interface further includes at least one metric or portion of information derived from data retrieved by the computer system from a second computer system that is not located behind the firewall.

7. A computer-implemented method comprising, as implemented by one or more processors configured with specific executable instructions:

providing configuration information for a data extraction application operating behind a firewall on a client system;

receiving application state information from the data extraction application, wherein the application state information is automatically gathered and sent by the data extraction application upon the data extraction application being awakened at a predetermined time;

in response to receipt of the application state information, determining commands to return to the data extraction application that include one or more query parameters;

sending the commands to the data extraction application, wherein the commands include the one or more query parameters as parameters to be injected by the data extraction application into at least one query previously stored by the data extraction application;

obtaining, from the client system or a data store outside of the firewall, results of the data extraction application executing the query with the parameters injected, wherein the query was executed by the data extraction application with respect to one or more files located behind the firewall;

identifying that data relating to a first time period was not extracted by the data extraction application as specified by one of (a) a predetermined schedule or (b) a request remotely sent to the data extraction application; and

sending a set of commands to the data extraction application related to a second time period that causes the data extraction application to extract both (c) data related to the first time period and (d) data related to the second time period.

8. The computer-implemented method of claim 7 , wherein the client system comprises or is in communication with one of (a) an electronic health record system or (b) a computer system of a medical practice, wherein the one or more files located behind the firewall are stored in association with at least one of the electronic health record system or the medical practice.

9. The computer-implemented method of claim 7 , wherein the at least one query previously stored by the data extraction application is configured, when executed with the one or more query parameters, to access electronic health data behind the firewall.

10. The computer-implemented method of claim 7 , further comprising monitoring, by the computer system, a plurality of systems or subsystems of the client system based on the obtained results of the data extraction application, wherein a computer system implementing the computer-implemented method is not permitted to directly access data of the plurality of systems or subsystems of the client system.

11. The computer-implemented method of claim 7 , further comprising:

generating a user interface that includes a plurality of metrics derived from the obtained results of the data extraction application that operates behind the firewall on the client system; and

causing presentation of the user interface to an administrator computing device that is not configured to directly access files behind the firewall on the client system.

12. The computer-implemented method of claim 11 , wherein the user interface further includes at least one metric or portion of information derived from data retrieved from a second computer system that is not located behind the firewall.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 30, 2023
From: TOBIAS, MARC
To: PHRASE HEALTH, INC.
Reel/Frame 065079/0834 →
Continuity (2)
Provisional Application 62992780 · Mar 20, 2020
Related Publication 20210297387A1 · Sep 23, 2021