IP Library Granted Patent US 11,735,297
Granted Patent B2
US 11,735,297 · App. 17/815,666 · Granted Aug 22, 2023

Methods and systems for analyzing accessing of medical data

Inventors: Nicholas T. Culbertson (Baltimore, MD); Robert K. Lord (Baltimore, MD)
Assignee: Protenus, Inc.
G16H10/60G06Q10/105H04L63/10H04L63/1433H04L63/20
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,735,297
App. No.
17/815,666
Granted
Aug 22, 2023
Kind
B2
Abstract

Various aspects described herein relate to presenting electronic patient data accessing information. Data related to a plurality of access events, by one or more employees, of electronic patient data can be received. A set of access events of the plurality of access events can be determined as constituting, by the one or more employees, possible breach of the electronic patient data. An alert related to the set of access events can be provided based on determining that the set of access events constitute possible breach of the electronic patient data.

Claims (45)

1. A computer-implemented method for displaying an indication of non-compliant access to an electronic medical record (EMR) on a user interface, the method comprising:

receiving, by one or more processors of a patient privacy monitoring system, access data from at least one EMR access log, at least one EMR, and human resources (HR) data associated with a plurality of employees of a healthcare organization, the at least one EMR access log comprising a plurality of access events;

determining, by the one or more processors and based on the access data, at least one access event of the plurality of access events that constitutes a possible breach, the determining including:

detecting, by a data patterning component and based on the access data, at least one data pattern of access events by a clinical care group, wherein at least two employees of the clinical care group access at least one same EMR; and

determining, by the data patterning component, the at least one access event by a subset of the clinical care group that is inconsistent to the at least one data pattern of access events; and

generating, by the one or more processors, an alert associated with the at least one access event, wherein the alert comprises a description of the at least one access event.

2. The computer-implemented method of claim 1 , wherein the at least one data pattern of access events includes at least one threshold access time.

3. The computer-implemented method of claim 2 , the determining the at least one access event by the subset of the clinical care group further comprising:

determining, by the data patterning component, that the at least one access event surpasses the at least one threshold access time.

4. The computer-implemented method of claim 1 , wherein the at least two employees access the at least one same EMR within a threshold period of time.

5. The computer-implemented method of claim 1 , the method further comprising:

applying, by a rule applying component, one or more rules to the access data to filter the access data for the possible breach.

6. The computer-implemented method of claim 5 , the one or more rules corresponding to detecting common data among the access data and the HR data.

7. The computer-implemented method of claim 1 , the determining the at least one access event by the subset of the clinical care group further comprising:

determining, by the one or more processors, that the access data includes the at least one access event by an employee of the plurality of employees that surpasses an average access duration for the employee.

8. The computer-implemented method of claim 1 , the determining the at least one access event by the subset of the clinical care group further comprising:

determining, by the data patterning component, that the access data includes the at least one access event by an employee of the plurality of employees from a workstation different from a usual workstation.

9. A computer system for displaying an indication of non-compliant access to an electronic medical record (EMR) on a user interface, the system comprising:

one or more processors; and

one or more computer readable storage media storing instructions which, when executed by the one or more processors, cause the one or more processors to perform operations comprising:

receiving access data from at least one EMR access log, at least one EMR, and human resources (HR) data associated with a plurality of employees of a healthcare organization, the at least one EMR access log comprising a plurality of access events;

determining, based on the access data, at least one access event of the plurality of access events that constitutes a possible breach, the determining including:

detecting, based on the access data, at least one data pattern of access events by a clinical care group, wherein at least two employees of the clinical care group access at least one same EMR; and

determining the at least one access event by a subset of the clinical care group that is inconsistent to the at least one data pattern of access events; and

generating an alert associated with the at least one access event, wherein the alert comprises a description of the at least one access event.

10. The computer system of claim 9 , wherein the at least one data pattern of access events includes at least one threshold access time.

11. The computer system of claim 10 , the determining the at least one access event by the subset of the clinical care group further comprising:

determining that the at least one access event surpasses the at least one threshold access time.

12. The computer system of claim 9 , wherein the employee group includes one or more of the plurality of employees that access a same at least one EMR within a threshold period of time.

13. The computer system of claim 9 , the operations further comprising:

applying one or more rules to the access data to filter the access data for the possible breach.

14. The computer system of claim 13 , the one or more rules corresponding to detecting common data among the access data and the HR data.

15. A non-transitory computer readable medium storing instructions which, when executed by one or more processors, cause the one or more processors to perform operations for displaying an indication of non-compliant access to an electronic medical record (EMR) on a user interface, the operations comprising:

receiving access data from at least one EMR access log, at least one EMR, and human resources (HR) data associated with a plurality of employees of a healthcare organization, the at least one EMR access long comprising a plurality of access events;

determining, based on the access data, at least one access event of the plurality of access events that constitutes a possible breach, the determining including:

detecting, based on the access data, at least one data pattern of access events by a clinical care group, wherein at least two employees of the clinical care group access at least one same EMR; and

determining the at least one access event by a subset of the clinical care group that is inconsistent to the at least one data pattern of access events; and

generating an alert associated with the at least one access event, wherein the alert comprises a description of the at least one access event.

16. The non-transitory computer readable medium of claim 15 , wherein the at least one data pattern of access events includes at least one threshold access time.

17. The non-transitory computer readable medium of claim 16 , the determining the at least one access event by the subset of the clinical care group further comprising:

determining that the at least one access event surpasses the at least one threshold access time.

18. The non-transitory computer readable medium of claim 15 , wherein the at least two employees access the at least one same EMR within a threshold period of time.

19. The non-transitory computer readable medium of claim 16 , the operations further comprising:

applying one or more rules to the access data to filter the access data for the possible breach.

20. The non-transitory computer readable medium of claim 19 , the one or more rules corresponding to detecting common data among the access data and the HR data.

Assignments (4)
GRANT OF SECURITY INTEREST IN PATENT RIGHTS Recorded Mar 3, 2025
From: PROTENUS, INC.; BLUESIGHT, INC.
To: MONROE CAPITAL MANAGEMENT ADVISORS, LLC, AS COLLATERAL AGENT
Reel/Frame 070377/0626 →
CORRECTIVE ASSIGNMENT TO CORRECT THE THE NAME OF THE CONVEYING PARTY PREVIOUSLY RECORDED AT REEL: 70225 FRAME: 709. ASSIGNOR(S) HEREBY CONFIRMS THE ASSIGNMENT. Recorded Feb 24, 2025
From: PROTENUS, INC.
To: BLUESIGHT, INC.
Reel/Frame 070314/0107 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Feb 14, 2025
From: PROTENUS, INC.,
To: BLUESIGHT, INC.
Reel/Frame 070225/0709 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 2, 2022
From: LORD, ROBERT K.; CULBERTSON, NICHOLAS T.
To: PROTENUS INC.
Reel/Frame 060702/0574 →
Continuity (5)
Continuation 17505808 · Oct 20, 2021
Continuation 16857716 · Apr 24, 2020
Continuation 15078736 · Mar 23, 2016
Provisional Application 62139494 · Mar 27, 2015
Related Publication 20220367018A1 · Nov 17, 2022
Cited By (2)
US 12,555,656 US 12,626,817