IP Library Granted Patent US 12,547,769
Granted Patent B2
US 12,547,769 · App. 18/026,641 · Granted Feb 10, 2026

Systems and methods for configuring and operating de-identification systems

Inventors: Amar S. Chaudhry (Toronto, CA); Frank Rudzicz (Toronto, CA); Tianbao Li (Toronto, CA); Shuja Khalid (Toronto, CA); Kevin Yang (Toronto, CA); Teodor Pantchev Grantcharov (Toronto, CA)
Assignee: SURGICAL SAFETY TECHNOLOGIES INC.
G06F21/6254G06F3/0482G16H10/60
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,547,769
App. No.
18/026,641
Granted
Feb 10, 2026
Kind
B2
Abstract

Systems, devices, and methods of configuring and operating a de-identification system are provided. At least one electronic data model is maintained, which includes a plurality of de-identification requirements for removing personal information from clinical data obtained in a clinical environment, the plurality of de-identification requirements including requirements applicable to at least one jurisdiction of a plurality of jurisdictions. An identifier identifying one of the jurisdictions is received. The data model is traversed to determine a subset of the de-identification requirements applicable to the identified jurisdiction. Data defining a user selection of operating parameters of the de-identification system are received. The user selection is analyzed for conformity with the subset of de-identification requirements. In response to determining the user selection conforms with the subset of de-identification requirements, a signal is generated indicating the conformity. A configuration data structure is generated including data reflective of the user selection of operating parameters.

Claims (63)

1 . A computer-implemented method for configuring a de-identification system, the method comprising:

maintaining at least one electronic data model including a plurality of de-identification requirements for removing personal information from clinical video data obtained in a clinical environment, the plurality of de-identification requirements including requirements applicable to at least one jurisdiction of a plurality of jurisdictions, the plurality of de-identification requirements including at least a first set of de-identification requirements to remove visual or audio identifying elements and a second set of de-identification requirements to preserve visual or audio elements;

receiving an identifier identifying one of the jurisdictions;

traversing the electronic data model to determine a subset of the plurality de-identification requirements applicable to the identified jurisdiction, the electronic data model populated using a set of nested de-identification requirements, the nested de-identification requirements including at least both an umbrella jurisdiction and a sub-jurisdiction;

receiving data defining a user selection of operating parameters of the de-identification system;

analyzing the user selection for conformity with the subset of the de-identification requirements;

in response to determining the user selection conforms with the subset of the de-identification requirements, generating a signal indicating the conformity;

generating a configuration data structure including data reflective of the user selection of operating parameters; and

transforming the clinical video data using a trained machine learning model that receives as an input data set the configuration data structure representing the subset of the plurality of the de-identification requirements applicable to the identified jurisdiction and the clinical video data to generate de-identified clinical video data.

2 . The method of claim 1 , wherein the transforming of the clinical video data further includes modifying a compression rate of the generated de-identified clinical video data.

3 . The method of claim 1 , wherein the maintaining the at least one electronic data model includes:

retrieving one or more of the de-identification requirements from an electronic database, each of the one or more de-identification requirements for removing personal information being associated with a respective jurisdiction;

populating the electronic data model by associating the retrieved one or more de-identification requirements with the respective jurisdiction.

4 . The method of claim 1 , wherein:

the plurality of de-identification requirements include requirements applicable to at least one compliance regime of a plurality of compliance regimes;

the identifier identifies one of the compliance regimes; and

traversing the electronic data model to determine the subset of the de-identification requirements includes determining the subset of the de-identification requirements applicable to the identified jurisdiction and the identified compliance regime.

5 . The method of claim 1 , further comprising:

presenting an interactive user interface having a plurality of user interface elements for defining the user selection of operating parameters of the de-identification system.

6 . The method of claim 5 , wherein the user interface elements include one or more default de-identification requirements.

7 . The method of claim 5 , further comprising:

in response to determining the user selection conforms with the subset of the de-identification requirements, modifying the interactive user interface to provide a visual indicator of the conformity.

8 . The method of claim 5 , further comprising:

in response to determining the user selection does not conform with the subset of the de-identification requirements, modifying the interactive user interface to provide a warning visual indicator.

9 . The method of claim 5 , further comprising:

modifying the interactive user interface to include user interface elements for user input of additional identifiers of the de-identification system;

updating the subset of the de-identification requirements by traversing the at least one electronic data model to determine de-identification requirements applicable to the input additional identifiers.

10 . The method of claim 5 , further comprising:

in response to detecting hovering near the user interface elements, modifying the interactive user interface to include an information visual indicator associated with the hovered near user interface element.

11 . The method of claim 5 , further comprising:

populating the interactive user interface with an input interface for receiving new de-identification requirements;

updating the at least one electronic data model with the received new de-identification requirements.

12 . The method of claim 5 , wherein the presenting the interactive user interface comprises:

determining one or more operating parameters in response to the determining the subset of the de-identification requirements; and

populating the interactive user interface with the determined one or more operating parameters.

13 . The method of claim 1 , wherein the de-identification requirements include contractual obligations, and the determined one or more operating parameters include one or more face de-identification algorithms.

14 . The method of claim 1 , wherein the user selection of operating parameters of the de-identification system includes a user selection of a quality assurance process.

15 . A non-transitory computer readable tangible storage medium, when executed by a processor, cause the processor to perform a computer-implemented method for configuring a de-identification system, the method comprising:

maintaining at least one electronic data model including a plurality of de-identification requirements for removing personal information from clinical video data obtained in a clinical environment, the plurality of de-identification requirements including requirements applicable to at least one jurisdiction of a plurality of jurisdictions, the plurality of de-identification requirements including at least a first set of de-identification requirements to remove visual or audio identifying elements and a second set of de-identification requirements to preserve visual or audio elements;

receiving an identifier identifying one of the jurisdictions;

traversing the electronic data model to determine a subset of the plurality of de-identification requirements applicable to the identified jurisdiction, the electronic data model populated using a set of nested de-identification requirements, the nested de-identification requirements including at least both an umbrella jurisdiction and a sub-jurisdiction;

receiving data defining a user selection of operating parameters of the de-identification system;

analyzing the user selection for conformity with the subset of the de-identification requirements;

in response to determining the user selection conforms with the subset of the de-identification requirements, generating a signal indicating the conformity;

generating a configuration data structure including data reflective of the user selection of operating parameters; and

transforming the clinical video data using a trained machine learning model that receives as an input data set the configuration data structure representative of the subset of the plurality of the de-identification requirements applicable to the identified jurisdiction and the clinical video data to generate de-identified clinical video data.

16 . A computer-implemented system for configuring a de-identification system, the computer-implemented system comprising:

a processor connected to a non-transitory computer readable storage medium with executable instructions for causing the processor to:

maintain at least one electronic data model including a plurality of de-identification requirements for removing personal information from clinical video data obtained in a clinical environment, the plurality of de-identification requirements including requirements applicable to at least one jurisdiction of a plurality of jurisdictions, the plurality of de-identification requirements including at least a first set of de-identification requirements to remove visual or audio identifying elements and a second set of de-identification requirements to preserve visual or audio elements;

receive an identifier identifying one of the jurisdictions;

traverse the electronic data model to determine a subset of the de-identification requirements applicable to the identified jurisdiction, the electronic data model populated using a set of nested de-identification requirements, the nested de-identification requirements including at least both an umbrella jurisdiction and a sub-jurisdiction;

receive data defining a user selection of operating parameters of the de-identification system;

analyze the user selection for conformity with the subset of the de-identification requirements;

in response to determining the user selection conforms with the subset of the de-identification requirements, generate a signal indicating the conformity; and

generate a configuration data structure including data reflective of the user selection of operating parameters; and

transform the clinical video data using a trained machine learning model that receives as an input data set the configuration data structure representative of the subset of the plurality of the de-identification requirements applicable to the identified jurisdiction and the clinical video data to generate de-identified clinical video data.

17 . The system of claim 16 , wherein the clinical video data includes at least one of audio data, video data, audio-video data, device data, or text data.

18 . The system of claim 16 , wherein:

the plurality of de-identification requirements include requirements applicable to at least one compliance regime of a plurality of compliance regimes; and

the identifier identifies one of the compliance regimes.

19 . The system of claim 16 , wherein the executable instructions further cause the processor to:

present an interactive user interface having a plurality of user interface elements for defining the user selection of operating parameters of the de-identification system.

20 . The system of claim 19 , wherein the user interface elements include one or more default de-identification requirements.

Assignments (5)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jan 27, 2026
From: SST SURGICAL SAFETY TECHNOLOGIES CANADA ULC
To: SURGICAL SAFETY TECHNOLOGIES INC.
Reel/Frame 073603/0806 →
CHANGE OF NAME Recorded Jan 5, 2026
From: SST CANADA INC.
To: SST SURGICAL SAFETY TECHNOLOGIES CANADA ULC
Reel/Frame 073359/0765 →
CHANGE OF NAME Recorded Nov 19, 2025
From: SURGICAL SAFETY TECHNOLOGIES INC.
To: SST CANADA INC.
Reel/Frame 073287/0191 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jul 18, 2023
From: CHAUDHRY, AMAR S.; RUDZICZ, FRANK; LI, TIANBAO; KHALID, SHUJA; YANG, KEVIN
To: SURGICAL SAFETY TECHNOLOGIES INC.
Reel/Frame 064302/0054 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jul 18, 2023
From: GRANTCHAROV, TEODOR PANTCHEV
To: SURGICAL SAFETY TECHNOLOGIES INC.
Reel/Frame 064302/0169 →
Continuity (2)
Provisional Application 63079072 · Sep 16, 2020
Related Publication 20240028762A1 · Jan 25, 2024
References Cited (10)
US 11138337B2 · Yousfi · 2021 [cited by examiner]
US 11436191B2 · Kuo · 2022 [cited by examiner]
US 20060123341A1 · Smirnov · 2006 [cited by examiner]
US 20110087651A1 · Westin · 2011 [cited by examiner]
US 20120266254A1 · Gupta et al. · 2012 [cited by applicant]
US 20190272387A1 · Gkoulalas-Divanis · 2019 [cited by examiner]
EP 3188058A1 · 2017 [cited by examiner]
WO 2016002086A1 · 2016 [cited by applicant]
European Patent Office (EPO), Extended European Search Report issued to EP 21867982.7 dated Sep. 26, 2024. [cited by applicant]
Canadian Intellectual Property Office (CIPO), International Search Report and Written Opinion to PCT/ CA2021/051285, Nov. 30, 2021. [cited by applicant]