IP Library Granted Patent US 12,230,375
Granted Patent B2
US 12,230,375 · App. 18/344,430 · Granted Feb 18, 2025

Methods and systems for analyzing accessing of medical data

Inventors: Nicholas T. Culbertson (Baltimore, MD); Robert K. Lord (Baltimore, MD)
Assignee: Protenus, Inc.
G16H10/60G06Q10/105H04L63/10H04L63/1433H04L63/20
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,230,375
App. No.
18/344,430
Granted
Feb 18, 2025
Kind
B2
Abstract

Various aspects described herein relate to presenting electronic patient data accessing information. Data related to a plurality of access events, by one or more employees, of electronic patient data can be received. A set of access events of the plurality of access events can be determined as constituting, by the one or more employees, possible breach of the electronic patient data. An alert related to the set of access events can be provided based on determining that the set of access events constitute possible breach of the electronic patient data.

Claims (47)

1. A computer-implemented method for detecting a non-compliant access of electronic patient data, the computer-implemented method comprising:

receiving, by one or more processors of a patient privacy monitoring server, access data from a plurality of electronic patient data access devices situated at various locations, the access data comprising a plurality of electronic patient data access events by one or more employees;

determining, by the one or more processors and based on the access data, that at least one electronic patient data access event of the plurality of electronic patient data access events constitutes a possible non-compliant access of electronic patient data, the determining including:

detecting, by a data patterning component and based on the access data, at least one data pattern of electronic patient data access events by a clinical care group; and

determining, by the data patterning component, the at least one electronic patient data access event by a subset of the clinical care group that is inconsistent to the at least one data pattern of electronic patient data access events;

in response to the determining that at least one electronic patient data access event of the plurality of access events constitutes a possible non-compliant access of electronic patient data, causing to present on a display of a user interface, by the one or more processors, an alert indicating the at least one electronic patient data access event, and a feedback indicator configured to allow a user to provide feedback indicating whether the at least one electronic patient data access event associated with the alert presented on the display of the user interface is a valid non-compliant access of electronic patient data or a false positive non-compliant access of electronic patient data;

receiving, by the one or more processors, feedback via the feedback indicator, the feedback indicating whether the at least one electronic patient data access event is a valid non-compliant access of electronic patient data or a false positive non-compliant access of electronic patient data; and

in response to receiving the feedback, modifying or maintaining, by the one or more processors, at least one of the plurality of rules for detecting possible subsequent non-compliant access of electronic patient data.

2. The computer-implemented method of claim 1 , wherein, when the feedback indicates that the at least one electronic patient data access event is a false positive non-compliance access of electronic patient data, modifying or maintaining the at least one of the plurality of rules comprises:

deactivating, by the one or more processors, at least one of the plurality of rules.

3. The computer-implemented method of claim 1 , wherein, when the feedback indicates that the at least one electronic patient data access event is a valid non-compliance access of electronic patient data, modifying or maintaining the at least one of the plurality of rules comprises:

activating, by the one or more processors, at least one of the plurality of rules.

4. The computer implemented method of claim 1 , wherein the access data is distributed across one or more networks.

5. The computer-implemented method of claim 1 , wherein the access data identifies at least one employee of the one or more employees requesting access to electronic patient data, and patient information.

6. The computer-implemented method of claim 1 , wherein the at least one of the plurality of rules relates to determining that the at least one electronic patient data access event is for a duration of time that is greater than a threshold duration of time.

7. The computer-implemented method of claim 1 , wherein modifying or maintaining the at least one of the plurality of rules comprises:

increasing a number of standard deviations for determining the at least one electronic patient data access event of the plurality of electronic patient data access events constitutes at least one possible non-compliant access of electronic patient data.

8. The computer-implemented method of claim 1 , further comprising:

generating, by the one or more processors, an alert associated with the at least one electronic patient data access event, wherein the alert comprises a description of the at least one electronic patient data access event.

9. The computer-implemented method of claim 1 , wherein the feedback is provided via one or more interfaces.

10. A system for detecting a non-compliant access of electronic patient data, the system comprising:

at least one processor; and

at least one storage device comprising instructions which, when executed by the at least one processor, cause the at least one processor to perform operations comprising:

receiving access data from a plurality of electronic patient data access devices situated at various locations, the access data comprising a plurality of electronic patient data access events by one or more employees;

determining, based on the access data, that at least one electronic patient data access event of the plurality of electronic patient data access events constitutes a possible non-compliant access of electronic patient data, the determining including:

detecting, by a data patterning component and based on the access data, at least one data pattern of electronic patient data access events by a clinical care group; and

determining, by the data patterning component, the at least one access event by a subset of the clinical care group that is inconsistent to the at least one data pattern of access events;

in response to the determining that at least one electronic patient data access event of the plurality of access events constitutes a possible non-compliant access of electronic patient data, causing to present, on a display of a user interface, an alert indicating the at least one electronic patient data access event, and a feedback indicator configured to allow a user to provide feedback indicating whether the at least one electronic patient data access event associated with the alert presented on the display of the user interface is a valid non-compliant access of electronic patient data or a false positive non-compliant access of electronic patient data;

receiving feedback via the feedback indicator, the feedback indicating whether the at least one electronic patient data access event is a valid non-compliant access of electronic patient data or a false positive non-compliant access of electronic patient data; and

in response to receiving the feedback, modifying or maintaining at least one of the plurality of rules for detecting possible subsequent non-compliant access of electronic patient data.

11. The system of claim 10 , wherein modifying or maintaining the at least one of the plurality of rules comprises deactivating at least one of the plurality of rules.

12. The system of claim 10 , wherein modifying or maintaining the at least one of the plurality of rules comprises activating at least one of the plurality of rules.

13. The system of claim 10 , wherein modifying or maintaining the at least one of the plurality of rules comprises increasing a number of standard deviations for determining the at least one electronic patient data access event of the plurality of electronic patient data access events constitutes at least one possible non-compliant access of electronic patient data.

14. The system of claim 10 , wherein at least one of the plurality of rules relates to determining that the at least one electronic patient data access event is for a duration of time that is greater than a threshold duration of time.

15. The system of claim 10 , wherein the feedback is provided via one or more interfaces.

16. A non-transitory computer readable medium storing instructions which, when executed by at least one processor, cause the at least one processor to perform operations for processing access data to determine a non-compliant access of electronic patient data, the operations comprising:

receiving access data from a plurality of electronic patient data access devices situated at various locations, the access data comprising a plurality of electronic patient data access events by one or more employees;

determining, based on the access data, that at least one electronic patient data access event of the plurality of electronic patient data access events constitutes a possible non-compliant access of electronic patient data, the determining including:

detecting, by a data patterning component and based on the access data at least one data pattern of electronic patient data access events by a clinical care group; and

determining, by the data patterning component, the at least one access event by a subset of the clinical care group that is inconsistent to the at least one data pattern of access events;

in response to the determining that at least one electronic patient data access event of the plurality of access events constitutes a possible non-compliant access of electronic patient data, causing to present, on a display of a user interface, an alert indicating the at least one electronic patient data access event, and a feedback indicator configured to allow a user to provide feedback indicating whether the at least one electronic patient data access event associated with the alert presented on the display of the user interface is a valid non-compliant access of electronic patient data or a false positive non-compliant access of electronic patient data;

receiving feedback via the feedback indicator, the feedback indicating whether the at least one electronic patient data access event is a valid non-compliant access of electronic patient data or a false positive non-compliant access of electronic patient data; and

in response to receiving the feedback, modifying or maintaining at least one of the plurality of rules for detecting possible subsequent non-compliant access of electronic patient data.

17. The non-transitory computer readable medium of claim 16 , wherein modifying or maintaining the at least one of the plurality of rules comprises deactivating at least one of the plurality of rules.

18. The non-transitory computer readable medium of claim 16 , wherein modifying or maintaining the at least one of the plurality of rules comprises deactivating at least one of the plurality of rules.

19. The non-transitory computer readable medium of claim 16 , wherein modifying or maintaining the at least one of the plurality of rules comprises increasing a number of standard deviations for determining the at least one electronic patient data access event of the plurality of electronic patient data access events constitutes at least one possible non-compliant access of electronic patient data.

20. The non-transitory computer readable medium of claim 16 , wherein at least one of the plurality of rules relates to determining that the at least one electronic patient data access event is for a duration of time that is greater than a threshold duration of time.

Assignments (4)
GRANT OF SECURITY INTEREST IN PATENT RIGHTS Recorded Mar 3, 2025
From: PROTENUS, INC.; BLUESIGHT, INC.
To: MONROE CAPITAL MANAGEMENT ADVISORS, LLC, AS COLLATERAL AGENT
Reel/Frame 070377/0626 →
CORRECTIVE ASSIGNMENT TO CORRECT THE THE NAME OF THE CONVEYING PARTY PREVIOUSLY RECORDED AT REEL: 70225 FRAME: 709. ASSIGNOR(S) HEREBY CONFIRMS THE ASSIGNMENT. Recorded Feb 24, 2025
From: PROTENUS, INC.
To: BLUESIGHT, INC.
Reel/Frame 070314/0107 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Feb 14, 2025
From: PROTENUS, INC.,
To: BLUESIGHT, INC.
Reel/Frame 070225/0709 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jul 27, 2023
From: LORD, ROBERT K; CULBERTSON, NICHOLAS T
To: PROTENUS INC.
Reel/Frame 064398/0491 →
Continuity (6)
Continuation 17815666 · Jul 28, 2022
Continuation 17505808 · Oct 20, 2021
Continuation 16857716 · Apr 24, 2020
Continuation 15078736 · Mar 23, 2016
Provisional Application 62139494 · Mar 27, 2015
Related Publication 20230343423A1 · Oct 26, 2023
References Cited (19)
US 8578500B2 · Long · 2013 [cited by applicant]
US 8793790B2 · Khurana et al. · 2014 [cited by applicant]
US 9032531B1 · Scorvo et al. · 2015 [cited by applicant]
US 9202189B2 · Long · 2015 [cited by applicant]
US 9330134B2 · Long et al. · 2016 [cited by applicant]
US 20080060051A1 · Lim · 2008 [cited by applicant]
US 20090018882A1 · Burton et al. · 2009 [cited by applicant]
US 20100262688A1 · Hussain et al. · 2010 [cited by applicant]
US 20120289787A1 · Kurgan et al. · 2012 [cited by applicant]
US 20130091539A1 · Khurana et al. · 2013 [cited by applicant]
US 20130173309A1 · Dworkin · 2013 [cited by applicant]
US 20150205954A1 · Jou · 2015 [cited by examiner]
US 20150242856A1 · Dhurandhar · 2015 [cited by examiner]
US 20150381631A1 · Salem et al. · 2015 [cited by applicant]
US 20160005044A1 · Moss · 2016 [cited by applicant]
US 20160085986A1 · Long · 2016 [cited by applicant]
US 20160180022A1 · Paixao · 2016 [cited by examiner]
US 20170017760A1 · Freese · 2017 [cited by applicant]
US 20170272336A1 · Johnstone et al. · 2017 [cited by applicant]
Cited By (2)
US 12,555,656 US 12,626,817