IP Library Granted Patent US 11,837,345
Granted Patent B2
US 11,837,345 · App. 17/357,716 · Granted Dec 5, 2023

Systems and methods for secure prescription status updates using a mobile device

Inventors: Lindsey Whitaker (Chicago, IL); Kevin David Meyer (Deerfield, IL)
Assignee: WALGREEN CO.
G16H10/60G06F21/6245G16H20/10H04L63/08H04L63/10
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,837,345
App. No.
17/357,716
Granted
Dec 5, 2023
Kind
B2
Abstract

A method of providing secure access to prescription information includes transmitting a text message including a short URL with a secure token to a device, receiving the secure token, transmitting to the device when the token matches, receiving a refill request; and transmitting a confirmation. A non-transitory computer readable storage medium includes computer-executable instructions that, when executed by a processor, cause a computer to determine a user of a device, provide a status including a short URL with a secure token, receive a short URL access request, validate the request; and provide authorized PHI access. A system includes a processor and a memory storing computer-executable instructions that, when executed by the processor, cause the system to determine a user corresponding to a device, provide a status including a short URL with a secure token, receive a short URL access request, validate the request; and provide authorized PHI access.

Claims (63)

1. A computer-implemented method of providing secure electronic access to prescription status information of a user, the method comprising:

transmitting, via one or more processors, a text message including a short uniform resource locator (URL) to a mobile computing device associated with the user, wherein the short URL includes a secure authentication token;

receiving, in response to a selection of the user, the secure authentication token in a pharmacy system;

transmitting, when the secure authentication token matches stored authentication data, a prescription refill webpage to the mobile computing device;

receiving, in response to a selection of the user, a prescription refill order request in the pharmacy system; and

transmitting, in response to receiving the prescription refill order request, a refill order confirmation to the mobile device of the user.

2. The computer-implemented method of claim 1 ,

wherein the stored authentication data includes a hash value associated with the secure authentication token and an expiration date associated with the secure authentication token.

3. The computer-implemented method of claim 1 , further comprising:

validating the prescription order refill request by comparing authentication information included in the request to the stored authentication data.

4. The computer-implemented method of claim 1 , further comprising:

obtaining authorization to electronically access protected health information (PHI) of the user by validating, via the one or more processors, a web cookie.

5. The computer-implemented method of claim 1 , further comprising:

providing, over a communication network, a PHI access webpage to the mobile device;

verifying, via the one or more processors, user identity data received via the PHI access prompt based on stored user profile data; and

authorizing electronic access to PHI of the user by assigning, by the one or more processors, an opt-in status to the user in the stored user profile data.

6. The computer-implemented method of claim 5 , further comprising:

providing, over the communication network, the web cookie to the mobile device for storage thereon, the web cookie indicating the opt-in status of the user.

7. The computer-implemented method of claim 1 , wherein determining the user corresponding the mobile device associated with the status request message includes:

comparing, via the one or more processors, an identifier associated with the mobile device to user profile data to identify potential users;

in response to identifying more than one potential user in the user profile data, providing, over the communication network, a clarification message comprising temporary identifiers associated with each of the potential users corresponding to the mobile device; and

in response to receiving a clarification response from the mobile device, selecting the one of the potential users as the user based on the temporary identifier in the clarification response.

8. A non-transitory computer readable storage medium including computer-executable instructions that, when executed by one or more processors, cause a computer to:

determine, in response to receiving a status request message, a user corresponding to a mobile device associated with the status request message;

provide, over a communication network, a refill status message comprising a short uniform resource locator (URL) to the mobile device associated with the status request message, wherein the short URL includes a secure authentication token;

receive a request to access the short URL;

validate the request based on stored authentication data; and

provide, over the communication network, access to the prescription status webpage on the mobile device upon obtaining authorization to electronically access protected health information (PHI) of the user.

9. The non-transitory computer readable storage medium of claim 8 ,

wherein the stored authentication data includes a hash value associated with the authentication token and an expiration date associated with the token, and

wherein validating the request includes comparing, via the one or more processors, authentication information included in the request to stored authentication data.

10. The non-transitory computer readable storage medium of claim 8 , wherein obtaining authorization to electronically access PHI of the user includes validating a web cookie received with the request to access the short URL.

11. The non-transitory computer readable storage medium of claim 8 , wherein obtaining authorization to electronically access PHI of the user includes:

providing, over the communication network, a PHI access webpage to the mobile device;

verifying user identity data received via the PHI access webpage based on user profile data stored in the data storage device; and

assigning an opt-in status to the user in the stored user profile data.

12. The non-transitory computer readable storage medium of claim 8 , wherein the instructions further cause the computer to provide, over the communication network, a web cookie to the mobile device for storage thereon, the web cookie indicating the opt-in status of the user.

13. The non-transitory computer readable storage medium of claim 8 , wherein to determine the user corresponding to the mobile device associated with the status request message, the instructions further cause the computer:

compare an identifier associated with the mobile device to user profile data to identify potential users;

in response to identifying more than one potential user in the user profile data, provide, over the communication network, a clarification message comprising temporary identifiers associated with each of the potential users corresponding to the mobile device; and

in response to receiving a clarification response from the mobile device, select the one of the potential users as the user based on the temporary identifier in the clarification response.

14. A system in network communication with a mobile device of a user, the system comprising:

one or more processors;

one or more memories storing computer-executable instructions that, when executed by the one or more processors, cause the system to:

determine, in response to receiving a status request message, an identity of the user corresponding the mobile device associated with the status request message;

provide, over a communication network, a refill status message comprising a short uniform resource locator (URL) to the mobile device associated with the status request message, the short URL including a secure authentication token;

upon receiving a request to access the short URL, validate the request based on stored authentication data; and

provide, over the communication network, access to the prescription status webpage on the mobile device upon obtaining authorization to electronically access protected health information (PHI) of the user.

15. The system of claim 14 ,

wherein the stored authentication data comprises a hash value associated with the authentication token and an expiration data associated with the token.

16. The system of claim 14 ,

wherein validating the request includes comparing authentication information included in the request to the stored authentication data.

17. The system of claim 14 , wherein obtaining authorization to electronically access PHI of the user includes validating a web cookie received with the request to access the short URL.

18. The system of claim 14 , wherein obtaining authorization to electronically access PHI of the user includes:

providing a PHI access webpage to the mobile device;

verifying user identity data received via the PHI access prompt based on user profile data stored in the memory; and

assigning an opt-in status to the user in the stored user profile data.

19. The system of claim 18 , the memories including further computer-executable instructions that, when executed by the one or more processors, cause the system to:

provide a web cookie to the mobile device for storage thereon, the web cookie indicating the opt-in status of the user.

20. The system of claim 14 , the memories including further computer-executable instructions that, when executed by the one or more processors, cause the system to:

compare an identifier associated with the mobile device to user profile data to identify potential users;

in response to identifying more than one potential user in the user profile data, provide, over the communication network, a clarification message comprising temporary identifiers associated with each of the potential users corresponding to the mobile device; and

in response to receiving a clarification response from the mobile device, select the one of the potential users as the user based on the temporary identifier in the clarification response.

Assignments (3)
INTELLECTUAL PROPERTY SECURITY AGREEMENT Recorded Aug 28, 2025
From: WALGREEN CO.
To: SIXTH STREET LENDING PARTNERS, AS COLLATERAL AGENT
Reel/Frame 072606/0878 →
SECURITY INTEREST Recorded Aug 28, 2025
From: WALGREEN CO.; DUANE READE; WALGREENS SPECIALTY PHARMACY LLC; WALGREENS BOOTS ALLIANCE, INC.
To: WELLS FARGO BANK, NATIONAL ASSOCIATION, AS COLLATERAL AGENT
Reel/Frame 072679/0926 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jun 28, 2021
From: WHITAKER, LINDSEY; MEYER, KEVIN
To: WALGREEN CO.
Reel/Frame 056691/0402 →
Continuity (2)
Continuation 15172960 · Jun 3, 2016
Related Publication 20210319868A1 · Oct 14, 2021
Cited By (1)
US 12,573,478