IP Library Granted Patent US 12,223,093
Granted Patent B2
US 12,223,093 · App. 18/585,295 · Granted Feb 11, 2025

Systems and methods for processing electronic images across regions

Inventors: Razik Yousfi (Brooklyn, NY); Leo Grady (Darien, CT); Nathalie D'Amours (Redwood City, CA)
Assignee: HeartFlow, Inc.
G06F21/6254G16H10/60
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,223,093
App. No.
18/585,295
Granted
Feb 11, 2025
Kind
B2
Abstract

Systems and methods are disclosed for preserving patient privacy while transmitting health data from one geographic region to another geographic region for data analysis. One method includes receiving patient-specific health data including patient privacy information at a first region; removing the patient privacy information from the patient-specific health data to generate anonymous health data; storing the patient privacy information at the first region; and transmitting the anonymous health data to a second region for analysis.

Claims (65)

1. A computer-implemented method of processing electronic images while transferring data across regions, the method comprising:

removing, using a processor physically located in a first region, first patient-identifiable information from patient-specific data to generate a first set of de-identified data, based on a first geographic region specific privacy standard;

storing, using the processor physically located in the first region, the first patient-identifiable information within the first region;

transmitting, using the processor physically located in the first region, the first set of de-identified data to a remote data analysis server physically located in a second region for a patient-specific computation based on the first set of de-identified data;

generating, using the remote data analysis server physically located within the second region, a model of a patient based on the first set of de-identified data and conducting the patient-specific computation through the generated model;

determining, using the remote data analysis server physically located within the second region, a patient-specific blood flow computation in the patient based on the generated model and a mass or a volume of a myocardial tissue of the patient;

receiving, by the processor physically located in the first region, analyzed de-identified data from the remote data analysis server physically located in the second region; and

identifying a patient associated with the generated model by determining, using the processor physically located in the first region, first patient-identifiable information associated with the analyzed de-identified data based on the first patient-identifiable information stored within the first region and the patient-specific blood flow computation stored in a permanent storage at the second geographic region, wherein the first patient privacy information is inaccessible within the second geographic region.

2. The computer-implemented method of claim 1 , wherein the second region is distinct from and outside the first region, and

wherein the first region and the second region are governed by different data anonymization regulations.

3. The computer-implemented method of claim 1 , further comprising:

generating, using the processor physically located in the first region, an identifier associated with the first set of de-identified data, wherein the first patient-identifiable information is absent from the identifier.

4. The computer-implemented method of claim 1 , wherein the analyzed de-identified data includes results of a patient-specific blood flow computation calculated at an earlier date and stored in the permanent storage.

5. The computer-implemented method of claim 1 , further comprising:

generating, using the processor physically located in the first region, an irreversible hash of the first patient-identifiable information.

6. The computer-implemented method of claim 1 , further comprising:

prompting refining of modeling techniques available at the second region, based on the analyzed de-identified data.

7. The computer-implemented method of claim 1 , further comprising:

determining, using the processor physically located in the first region, an identifier associated with the analyzed de-identified data from the second region;

determining, using the processor physically located in the first region, an association between the identifier and the first patient-identifiable information stored within the first region; and

determining, using the processor physically located in the first region, the first patient-identifiable information corresponding to the analyzed de-identified data based on the association between the identifier and the first patient-identifiable information stored within the first region.

8. The computer-implemented method of claim 1 , further comprising:

determining, using the processor physically located in the first region, a hash associated with the analyzed de-identified data or the first set of de-identified data; and

determining, using the processor physically located in the second region, previously analyzed data associated with either the analyzed de-identified data or the first set of de-identified data, based on a comparison of the hash to one or more stored hashes.

9. A system for processing electronic images while transferring data across regions, the system comprising:

at least one data storage device physically located within a first region and storing instructions for providing cross-border data transfer while preserving first data anonymization; and

at least one processor physically located within the first region and configured to execute the instructions to perform operations comprising:

removing, using a processor physically located in a first region, first patient-identifiable information from patient-specific data to generate a first set of de-identified data, based on a first geographic region specific privacy standard;

storing, using the processor physically located in the first region, the first patient-identifiable information within the first region;

transmitting, using the processor physically located in the first region, the first set of de-identified data to a remote data analysis server physically located in a second region for a patient-specific computation based on the first set of de-identified data;

generating, using the remote data analysis server physically located within the second region, a model of a patient based on the first set of de-identified data and conducting the patient-specific computation through the generated model;

determining, using the remote data analysis server physically located within the second region, a patient-specific blood flow computation in the patient based on the generated model and a mass or a volume of a myocardial tissue of the patient;

receiving, by the processor physically located in the first region, analyzed de-identified data from the remote data analysis server physically located in the second region; and

identifying a patient associated with the generated model by determining, using the processor physically located in the first region, first patient-identifiable information associated with the analyzed de-identified data based on the first patient-identifiable information stored within the first region and the patient-specific blood flow computation stored in a permanent storage at the second geographic region, wherein the first patient privacy information is inaccessible within the second geographic region.

10. The system of claim 9 , wherein the second region is distinct from and outside the first region, and

wherein the first region and the second region are governed by different data anonymization regulations.

11. The system of claim 9 , wherein the operations at the remote data analysis server physically located within the first region further comprise:

generating an identifier associated with the first set of de-identified data, wherein the first patient-identifiable information is absent from the identifier.

12. The system of claim 9 , further comprising:

transmitting the first set of de-identified data to the second region with the generated identifier.

13. The system of claim 9 , wherein the operations at the remote data analysis server physically located within the first region further comprise:

generating an irreversible hash of the first patient-identifiable information.

14. The system of claim 9 , the operations further comprising:

prompting refining of blood flow modeling techniques available at the second region, based on the analyzed de-identified data.

15. The system of claim 14 , wherein the operations at the remote data analysis server physically located within the first region further comprise:

determining an identifier associated with the de-identified analyzed data from the second region;

determining an association between the identifier and the first patient-identifiable information stored within the first region; and

determining the first patient-identifiable information corresponding to the de-identified analyzed data based on the association between the identifier and the first patient-identifiable information stored within the first region.

16. The system of claim 14 , the operations further comprising:

determining, at the remote data analysis server physically located within the first region, a hash associated with the de-identified analyzed data or the de-identified data; and

determining, at the remote data analysis server physically located within the second region, previously analyzed data associated with either the de-identified analyzed data or the de-identified data, based on a comparison of the hash to one or more stored hashes.

17. A non-transitory computer readable medium for use on a computer system containing computer-executable programming instructions that execute operations for processing electronic images while transferring data across regions, the operations comprising:

removing, using a processor physically located in a first region, first patient-identifiable information from patient-specific data to generate a first set of de-identified data, based on a first geographic region specific privacy standard;

storing, using the processor physically located in the first region, the first patient-identifiable information within the first region;

transmitting, using the processor physically located in the first region, the first set of de-identified data to a remote data analysis server physically located in a second region for a patient-specific computation based on the first set of de-identified data;

generating, using the remote data analysis server physically located within the second region, a model of a patient based on the first set of de-identified data and conducting the patient-specific computation through the generated model;

determining, using the remote data analysis server physically located within the second region, a patient-specific blood flow computation in the patient based on the generated model and a mass or a volume of a myocardial tissue of the patient;

receiving, by the processor physically located in the first region, analyzed de-identified data from the remote data analysis server physically located in the second region; and

identifying a patient associated with the generated model by determining, using the processor physically located in the first region, first patient-identifiable information associated with the analyzed de-identified data based on the first patient-identifiable information stored within the first region and the patient-specific blood flow computation stored in a permanent storage at the second geographic region, wherein the first patient privacy information is inaccessible within the second geographic region.

18. The non-transitory computer readable medium of claim 17 , wherein the second region is distinct from and outside the first region, and

wherein the first region and the second region are governed by different data anonymization regulations.

19. The non-transitory computer readable medium of claim 17 , the operations further comprising:

generating, using a processor physically located in the first region, an identifier associated with the first set of de-identified data, wherein the first patient-identifiable information is absent from the identifier.

20. The non-transitory computer readable medium of claim 17 , the operations further comprising:

generating, using a processor physically located in the first region, an irreversible hash of the first patient-identifiable information.

Assignments (3)
RELEASE OF SECURITY INTEREST Recorded Sep 11, 2025
From: HAYFIN SERVICES LLP
To: HEARTFLOW, INC.
Reel/Frame 072876/0775 →
SECURITY INTEREST Recorded Jun 18, 2024
From: HEARTFLOW, INC.
To: HAYFIN SERVICES LLP
Reel/Frame 067775/0966 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Feb 29, 2024
From: YOUSFI, RAZIK; GRADY, LEO; D'AMOURS, NATHALIE
To: HEARTFLOW, INC.
Reel/Frame 066598/0106 →
Continuity (4)
Continuation 17466312 · Sep 3, 2021
Continuation 15635127 · Jun 27, 2017
Provisional Application 62355742 · Jun 28, 2016
Related Publication 20240232433A1 · Jul 11, 2024
References Cited (32)
US 20050236474A1 · Onuma et al. · 2005 [cited by applicant]
US 20060026040A1 · Reeves et al. · 2006 [cited by applicant]
US 20060179073A1 · Kimura · 2006 [cited by applicant]
US 20070294110A1 · Settimi · 2007 [cited by applicant]
US 20080147554A1 · Stevens et al. · 2008 [cited by applicant]
US 20100034376A1 · Okuizumi et al. · 2010 [cited by applicant]
US 20110153351A1 · Vesper et al. · 2011 [cited by applicant]
US 20120041739A1 · Taylor · 2012 [cited by applicant]
US 20120053918A1 · Taylor · 2012 [cited by examiner]
US 20130208966A1 · Zhao et al. · 2013 [cited by applicant]
US 20150128284A1 · LaFever et al. · 2015 [cited by applicant]
US 20150149208A1 · Lynch et al. · 2015 [cited by applicant]
US 20150342537A1 · Taylor et al. · 2015 [cited by applicant]
US 20160014817A1 · Cave et al. · 2016 [cited by applicant]
US 20160147945A1 · MacCarthy et al. · 2016 [cited by applicant]
US 20160148017A1 · Gossler et al. · 2016 [cited by applicant]
US 20160154977A1 · Jagadish et al. · 2016 [cited by applicant]
US 20160224805A1 · Patti · 2016 [cited by applicant]
US 20190272898A1 · Dormer · 2019 [cited by examiner]
CN 103270513A · 2013 [cited by applicant]
CN 104680076A · 2015 [cited by applicant]
JP 2004008304A · 2004 [cited by applicant]
JP 2007241589A · 2007 [cited by applicant]
JP 2007531124A · 2007 [cited by applicant]
JP 2008117365A · 2008 [cited by applicant]
JP 2015219371A · 2015 [cited by applicant]
KR 1020100001730A · 2010 [cited by applicant]
WO 2008069011A1 · 2008 [cited by applicant]
WO 2016042356A1 · 2016 [cited by applicant]
Garfinkel, Simson. “De-identification of Personal Information.” US Department of Commerce, National Institute of Standards and Technology, Oct. 2015, pp. 1-54. [cited by applicant]
Oshima, Mari, “Vessel Shape Modeling and Blood Flow Analysis From Medical Images of Cerebral Aneurysm”, BME, Japanese Society for Medical and Biological Engineering. [cited by applicant]
Rita Noumeir et al: “Pseudonymization of Radiology Data for Research Purposes”, Journal of Digital Imaging; The Journal of the Society for Computer Applications in Radiology, vol. 20, No. 3, Dec. 28, 2006, pp. 284-295. [cited by applicant]
Cited By (8)
US 12,396,695 US 12,440,180 US 12,499,539 US 12,555,228 US 12,558,048 US 12,589,032 US 12,599,352 US 12,670,587