IP Library › Granted Patent US 12,626,014
Granted Patent B2
US 12,626,014 · App. 18/762,260 · Granted May 12, 2026

Dynamic access control to electronic patient records

Inventors: Sharad Santhanam (Sunnyvale, CA); Anna Swigart (Seattle, WA); Geraint Levan (San Marcos, CA)
Assignee: Helix, Inc.
G06F21/6245G16H10/60G16H50/20H04L9/3236G06F2221/2141
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,626,014
App. No.
18/762,260
Granted
May 12, 2026
Kind
B2
Abstract

Systems and methods herein provide for access control to information in electronic patient records. One method includes receiving a request from an entity for access to one or more of a plurality of electronic patient records, the records having been machine learned to identify patient information in the electronic patient records including personally identifiable information and protected health information. The method also includes determining a level of access of the entity, retrieving, from a database, the one or more electronic patient records requested by the entity, applying a rule to the retrieved one or more electronic patient records based on the determined level of access of the entity to mask, encrypt, show, etc. one or more elements in the one or more electronic patient records. In response to applying the rule to the retrieved one or more electronic patient records, the electronic patient records are transferred to the entity.

Claims (57)

1 . A computer implemented method, comprising:

receiving a request from an entity for access to one or more of a plurality of electronic patient records, the plurality of electronic patient records having been machine learned to identify patient information in the electronic patient records including personally identifiable information (PII) and protected health information (PHI);

determining a level of access of the entity;

retrieving, from a database, the one or more electronic patient records requested by the entity;

applying a rule to the retrieved one or more electronic patient records based on the determined level of access of the entity to at least one of mask, encrypt, or show one or more elements in the one or more electronic patient records;

in response to applying the rule to the retrieved one or more electronic patient records, transferring the one or more electronic patient records to the entity;

receiving a new electronic patient record; and

machine learning the new electronic patient record with a machine learning model that has been trained on the plurality of electronic patient records.

2 . The computer implemented method of claim 1 , wherein:

encrypting the one or more elements in the one or more electronic patient records comprises applying a hash encryption to the one or more elements in the one or more electronic patient records.

3 . The computer implemented method of claim 1 , further comprising:

restricting access to all elements of the new electronic patient record until all elements of the new electronic patient record have been identified.

4 . The computer implemented method of claim 1 , further comprising:

receiving a new element to at least one of the plurality of electronic patient records; and

restricting access to the new element of the at least one electronic patient record until the new element of the at least one electronic patient record has been identified.

5 . The computer implemented method of claim 1 , wherein:

determining a level of access of the entity further comprises retrieving metadata from a repository, the metadata indicating the entity's role to access classifications of data in the elements of the one or more electronic patient records such that the rule may be selected and applied to the retrieved one or more electronic patient records.

6 . The computer implemented method of claim 1 , wherein:

the level of access of the entity includes one of access to public data, access to confidential data, access to data having indirect identifiers for PII and/or PHI, access to data having direct identifiers for PII and/or PHI, access to genetic data, and access to restricted data.

7 . A non-transitory computer readable medium embodying programmed instructions which, when executed by a processor, are operable for performing a method for securing data in a plurality of electronic patient records, the method comprising:

receiving a request from an entity for access to one or more of the plurality of electronic patient records, the plurality of electronic patient records having been machine learned to identify patient information in the electronic patient records including personally identifiable information (PII) and protected health information (PHI);

determining a level of access of the entity;

retrieving, from a database, the one or more electronic patient records requested by the entity;

applying a rule to the retrieved one or more electronic patient records based on the determined level of access of the entity to at least one of mask, encrypt, or show one or more elements in the one or more electronic patient records;

in response to applying the rule to the retrieved one or more electronic patient records, transferring the one or more electronic patient records to the entity;

receiving a new electronic patient record; and

machine learning the new electronic patient record with a machine learning model that has been trained on the plurality of electronic patient records.

8 . The non-transitory computer readable medium of claim 7 , wherein:

encrypting the one or more elements in the one or more electronic patient records comprises applying a hash encryption to the one or more elements in the one or more electronic patient records.

9 . The non-transitory computer readable medium of claim 7 , further comprising instructions which, when executed by the processor, are operable for:

restricting access to all elements of the new electronic patient record until all elements of the new electronic patient record have been identified.

10 . The non-transitory computer readable medium of claim 7 , further comprising instructions which, when executed by the processor, are operable for:

receiving a new element to at least one of the plurality of electronic patient records; and

restricting access to the new element of the at least one electronic patient record until the new element of the at least one electronic patient record has been identified.

11 . The non-transitory computer readable medium of claim 7 , wherein:

determining a level of access of the entity further comprises retrieving metadata from a repository, the metadata indicating the entity's role to access classifications of data in the elements of the one or more electronic patient records such that the rule may be selected and applied to the retrieved one or more electronic patient records.

12 . The non-transitory computer readable medium of claim 7 , wherein:

the level of access of the entity includes one of access to public data, access to confidential data, access to data having indirect identifiers for PII and/or PHI, access to data having direct identifiers for PII and/or PHI, access to genetic data, and access to restricted data.

13 . A system, comprising:

a database operable to store a plurality of electronic patient records that have been machine learned to identify patient information in the electronic patient records including personally identifiable information (PII) and protected health information (PHI), and to store rules to at least one of mask, encrypt, or show one or more elements in the plurality of electronic patient records based on a determined level of access;

an interface operable to receive a request from an entity for access to one or more of the plurality of electronic patient records;

a processor; and

a memory comprising instructions that direct the processor

wherein the database is further operable to determine a level of access of the entity, to retrieve, from the database, the one or more electronic patient records requested by the entity, to apply at least one of the rules to the retrieved one or more electronic patient records based on the determined level of access of the entity,

wherein, in response to applying the at least one rule to the retrieved one or more electronic patient records, the interface is further operable to transfer the one or more electronic patient records to the entity,

wherein the database is further operable to receive a new electronic patient record, and

wherein the system further comprises a machine learning model that has been trained on the plurality of electronic patient records, the machine learning model being operable to machine learn the new electronic patient record.

14 . The system of claim 13 , wherein:

the database is further operable to encrypt the one or more elements in the one or more electronic patient records by applying a hash encryption to the one or more elements in the one or more electronic patient records.

15 . The system of claim 13 , wherein:

the database further operable to restrict access to all elements of the new electronic patient record until all elements of the new electronic patient record have been identified.

16 . The system of claim 13 , wherein:

the database is further operable to receive a new element to at least one of the plurality of electronic patient records, and to restrict access to the new element of the at least one electronic patient record until the new element of the at least one electronic patient record has been identified.

17 . The system of claim 13 , wherein:

the database is further operable to retrieve metadata from a repository, the metadata indicating the entity's role to access classifications of data in the elements of the one or more electronic patient records such that the rule may be selected and applied to the retrieved one or more electronic patient records.

18 . The system of claim 13 , wherein:

the level of access of the entity includes one of access to public data, access to confidential data, access to data having indirect identifiers for PII and/or PHI, access to data having direct identifiers for PII and/or PHI, access to genetic data, and access to restricted data.

Assignments (2)
CERTIFICATE OF CHANGE OF CORPORATE ADDRESS Recorded Feb 28, 2025
From: HELIX, INC.
To: HELIX, INC.
Reel/Frame 070703/0313 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jan 8, 2025
From: SANTHANAM, SHARAD; SWIGART, ANNA; LEVAN, GERAINT
To: HELIX, INC.
Reel/Frame 069789/0715 →
Continuity (1)
Related Publication 20260010648A1 · Jan 8, 2026
References Cited (8)
US 20150223057A1 · Dellarciprete · 2015 [cited by examiner]
US 20170091391A1 · LePendu · 2017 [cited by examiner]
US 20180137247A1 · Bore · 2018 [cited by examiner]
US 20240177843A1 · Alsubai · 2024 [cited by examiner]
Wilnellys Moore et al., Review of HIPAA, Part 1: History, Protected Health Information, and Privacy and Security Rules, The society of Nuclear Medicine and Molecular Imaging (Year: 2019). [cited by examiner]
Cyera Website accessed Jul. 11, 2024 https://www.cyera.io/platform. [cited by applicant]
Immuta Website “De-risk your data” accessed Jul. 11, 2024 www.immuta.com/. [cited by applicant]
NIST Website “Attribute Based Access Control ABAC” accessed Jul. 11, 2024 https://csrc.nist.gov/projects/attribute-based-access-control. [cited by applicant]