IP Library Granted Patent US 12,555,656
Granted Patent B2
US 12,555,656 · App. 19/014,848 · Granted Feb 17, 2026

Methods and systems for analyzing accessing of medical data

Inventors: Nicholas T. Culbertson (Baltimore, MD); Robert K. Lord (Baltimore, MD)
Assignee: BLUESIGHT, INC.
G16H10/60G06Q10/105H04L63/10H04L63/1433H04L63/20
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,555,656
App. No.
19/014,848
Granted
Feb 17, 2026
Kind
B2
Abstract

Various aspects described herein relate to presenting electronic patient data accessing information. Data related to a plurality of access events, by one or more employees, of electronic patient data can be received. A set of access events of the plurality of access events can be determined as constituting, by the one or more employees, possible breach of the electronic patient data. An alert related to the set of access events can be provided based on determining that the set of access events constitute possible breach of the electronic patient data.

Claims (53)

1 . A computer-implemented method for detecting a non-compliant access of electronic patient data, the computer-implemented method comprising:

receiving, by one or more processors, access data comprising a plurality of electronic patient data access events by a plurality of entities;

constructing, by the one or more processors, a plurality of fingerprint data for the plurality of entities based on the plurality of electronic patient data access events, wherein first fingerprint data of the plurality of fingerprint data for a first entity of the plurality of entities comprises patternable electronic patient data access behavior by the first entity;

determining, by the one or more processors, at least one electronic patient data access event of the plurality of electronic patient data access events constitutes a possible non-compliant access of the electronic patient data based on the plurality of fingerprint data, wherein determining the at least one electronic patient data access event constitutes the possible non-compliant access of the electronic patient data comprises:

applying one or more tags defined for anomaly identification to the first fingerprint data for the first entity, and

determining the at least one electronic patient data access event constitutes the possible non-compliant access of the electronic patient data based on a number of tags applied to the at least one electronic patient data access event; and

in response to determining the at least one electronic patient data access event of the plurality of electronic patient data access events constitutes the possible non-compliant access of the electronic patient data, causing, by the one or more processors, display of an indicator of the at least one electronic patient data access event on a user interface.

2 . The computer-implemented method of claim 1 , wherein the one or more tags comprise at least one of:

a negative tag indicative of an electronic patient data access event that comprises a non-compliant access;

a positive tag indicative of an electronic patient data access event that comprises a legitimate access; and

a neutral tag indicative of an electronic patient data access event that does not alone comprise a non-compliant access.

3 . The computer-implemented method of claim 1 , wherein constructing the plurality of fingerprint data for the plurality of entities includes:

filtering the access data by excluding one or more of the plurality of electronic patient data access events that correspond to one or more positive tags indicative of an electronic patient data access event that comprises a legitimate access.

4 . The computer-implemented method of claim 1 , wherein determining that the at least one electronic patient data access event constitutes the possible non-compliant access of the electronic patient data further comprises:

detecting one or more patterns of accessing the electronic patient data by the plurality of entities from the plurality of fingerprint data; and

determining whether the at least one electronic patient data access event is inconsistent with the one or more patterns.

5 . The computer-implemented method of claim 1 , wherein determining that the at least one electronic patient data access event constitutes the possible non-compliant access of the electronic patient data further comprises:

determining whether the at least one electronic patient data access event falls outside of a normal distribution or standard deviation of one or more patterns based on the plurality of fingerprint data.

6 . The computer-implemented method of claim 1 , further comprising:

generating, by the one or more processors, an alert associated with the at least one electronic patient data access event that constitutes the possible non-compliant access of the electronic patient data.

7 . The computer-implemented method of claim 6 , wherein interacting with the indicator causes a display of additional information corresponding to the at least one electronic patient data access event facilitating further investigation of the at least one electronic patient data access event.

8 . The computer-implemented method of claim 6 , wherein the alert is displayed based on one or more user queries.

9 . A system for detecting a non-compliant access of electronic patient data, the system comprising:

one or more processors; and

one or more computer readable storage media storing instructions which, when executed by the one or more processors, cause the one or more processors to perform operations comprising:

receiving access data comprising a plurality of electronic patient data access events by a plurality of entities;

constructing a plurality of fingerprint data for the plurality of entities based on the plurality of electronic patient data access events, wherein first fingerprint data of the plurality of fingerprint data for a first entity of the plurality of entities comprises patternable electronic patient data access behavior by the first entity;

determining at least one electronic patient data access event of the plurality of electronic patient data access events constitutes a possible non-compliant access of the electronic patient data based on the plurality of fingerprint data wherein determining the at least one electronic patient data access event constitutes the possible non-compliant access of the electronic patient data comprises:

applying one or more tags defined for anomaly identification to the first fingerprint data for the first entity, and

determining the at least one electronic patient data access event constitutes the possible non-compliant access of the electronic patient data based on a number of tags applied to the at least one electronic patient data access event; and

in response to determining the at least one electronic patient data access event of the plurality of electronic patient data access events constitutes the possible non-compliant access of the electronic patient data, causing display of an indicator of the at least one electronic patient data access event on a user interface.

10 . The system of claim 9 , wherein the one or more tags comprise at least one of:

a negative tag indicative of an electronic patient data access event that comprises a non-compliant access;

a positive tag indicative of an electronic patient data access event that comprises a legitimate access; and

a neutral tag indicative of an electronic patient data access event that does not alone comprise a non-compliant access.

11 . The system of claim 9 , wherein constructing the plurality of fingerprint data for the plurality of entities includes:

filtering the access data by excluding one or more of the plurality of electronic patient data access events that correspond to one or more positive tags indicative of an electronic patient data access event that comprises a legitimate access.

12 . The system of claim 9 , wherein determining the at least one electronic patient data access event that constitutes the possible non-compliant access of the electronic patient data further comprises:

detecting one or more patterns of accessing the electronic patient data by the plurality of entities from the plurality of fingerprint data; and

determining whether the at least one electronic patient data access event is inconsistent with the one or more patterns.

13 . The system of claim 9 , wherein determining that the at least one electronic patient data access event constitutes the possible non-compliant access of the electronic patient data further comprises:

determining whether the at least one electronic patient data access event falls outside of a normal distribution or standard deviation of one or more patterns based on the plurality of fingerprint data.

14 . The system of claim 9 , further comprising:

generating an alert associated with the at least one electronic patient data access event that constitutes the possible non-compliant access of the electronic patient data.

15 . The system of claim 14 , wherein interacting with the indicator causes a display of additional information corresponding to the at least one electronic patient data access event facilitating further investigation of the at least one electronic patient data access event.

16 . The system of claim 14 , wherein the alert is displayed based on one or more user queries.

17 . One or more non-transitory computer readable media storing instructions which, when executed by one or more processors, cause the one or more processors to perform operations for detecting a non-compliant access of electronic patient data, the operations comprising:

receiving access data comprising a plurality of electronic patient data access events by a plurality of entities;

constructing a plurality of fingerprint data for the plurality of entities based on the plurality of electronic patient data access events, wherein first fingerprint data of the plurality of fingerprint data for a first entity of the plurality of entities comprises patternable electronic patient data access behavior by the first entity;

determining at least one electronic patient data access event of the plurality of electronic patient data access events constitutes a possible non-compliant access of the electronic patient data based on the plurality of fingerprint data wherein determining the at least one electronic patient data access event constitutes the possible non-compliant access of the electronic patient data comprises:

applying one or more tags defined for anomaly identification to the first fingerprint data for the first entity, and

determining the at least one electronic patient data access event constitutes the possible non-compliant access of the electronic patient data based on a number of tags applied to the at least one electronic patient data access event; and

in response to determining the at least one electronic patient data access event of the plurality of electronic patient data access events constitutes the possible non-compliant access of the electronic patient data, causing display of an indicator of the at least one electronic patient data access event on a user interface.

Assignments (4)
CORRECTIVE ASSIGNMENT TO CORRECT THE THE NAME OF THE CONVEYING PARTY PREVIOUSLY RECORDED AT REEL: 70225 FRAME: 709. ASSIGNOR(S) HEREBY CONFIRMS THE ASSIGNMENT. Recorded Feb 24, 2025
From: PROTENUS, INC.
To: BLUESIGHT, INC.
Reel/Frame 070314/0107 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Feb 20, 2025
From: CULBERTSON, NICHOLAS T.; LORD, ROBERT K.
To: PROTENUS, INC.
Reel/Frame 070275/0789 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Feb 14, 2025
From: PROTENUS, INC.,
To: BLUESIGHT, INC.
Reel/Frame 070225/0709 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jan 10, 2025
From: CULBERTSON, NICHOLAS T.; LORD, ROBERT K.
To: PROTENUS, INC.
Reel/Frame 069814/0526 →
Continuity (7)
Continuation 18344430 · Jun 29, 2023
Continuation 17815666 · Jul 28, 2022
Continuation 17505808 · Oct 20, 2021
Continuation 16857716 · Apr 24, 2020
Continuation 15078736 · Mar 23, 2016
Provisional Application 62139494 · Mar 27, 2015
Related Publication 20250149137A1 · May 8, 2025
References Cited (102)
US 6842736B1 · Brzozowski · 2005 [cited by applicant]
US 7587368B2 · Felsher · 2009 [cited by applicant]
US 8578500B2 · Long · 2013 [cited by applicant]
US 8793790B2 · Khurana et al. · 2014 [cited by applicant]
US 8838215B2 · John et al. · 2014 [cited by applicant]
US 8868616B1 · Otto et al. · 2014 [cited by applicant]
US 9032531B1 · Scorvo et al. · 2015 [cited by applicant]
US 9112850B1 · Eisen · 2015 [cited by applicant]
US 9202189B2 · Long · 2015 [cited by applicant]
US 9330134B2 · Long et al. · 2016 [cited by applicant]
US 9727919B2 · Gregg · 2017 [cited by applicant]
US 10679737B1 · Culbertson et al. · 2020 [cited by applicant]
US 10853380B1 · Agnew et al. · 2020 [cited by applicant]
US 10964416B1 · Stack · 2021 [cited by applicant]
US 11037342B1 · Agnew et al. · 2021 [cited by applicant]
US 11037666B1 · Benoit et al. · 2021 [cited by applicant]
US 11183281B2 · Culbertson et al. · 2021 [cited by applicant]
US 11282597B2 · Culbertson et al. · 2022 [cited by applicant]
US 11295844B2 · Culbertson et al. · 2022 [cited by applicant]
US 11437126B2 · Culbertson et al. · 2022 [cited by applicant]
US 11437128B2 · Culbertson et al. · 2022 [cited by applicant]
US 11437131B2 · Culbertson et al. · 2022 [cited by applicant]
US 11482220B1 · Kosowski et al. · 2022 [cited by applicant]
US 11621065B2 · Culbertson et al. · 2023 [cited by applicant]
US 11664105B2 · Yanowitz et al. · 2023 [cited by applicant]
US 11735297B2 · Culbertson et al. · 2023 [cited by applicant]
US 11791029B2 · Culbertson et al. · 2023 [cited by applicant]
US 11862308B2 · Culbertson et al. · 2024 [cited by applicant]
US 11923062B2 · Culbertson et al. · 2024 [cited by applicant]
US 12033736B2 · Culbertson et al. · 2024 [cited by applicant]
US 12050572B1 · Ambrose et al. · 2024 [cited by applicant]
US 12087422B2 · Yanowitz et al. · 2024 [cited by applicant]
US 12191016B2 · Culbertson et al. · 2025 [cited by applicant]
US 12198793B2 · Culbertson et al. · 2025 [cited by applicant]
US 12230375B2 · Culbertson et al. · 2025 [cited by applicant]
US 12230377B2 · Culbertson et al. · 2025 [cited by applicant]
US 12277099B2 · Ambrose et al. · 2025 [cited by applicant]
US 20040162740A1 · Ericsson et al. · 2004 [cited by applicant]
US 20060218626A1 · Goehler · 2006 [cited by applicant]
US 20080060051A1 · Lim · 2008 [cited by applicant]
US 20090018882A1 · Burton et al. · 2009 [cited by applicant]
US 20090177675A1 · Trumbull et al. · 2009 [cited by applicant]
US 20100262688A1 · Hussain · 2010 [cited by examiner]
US 20100268157A1 · Wehba · 2010 [cited by applicant]
US 20110264459A1 · Tyler et al. · 2011 [cited by applicant]
US 20110288886A1 · Whiddon · 2011 [cited by applicant]
US 20120101828A1 · Leibon · 2012 [cited by applicant]
US 20120203571A1 · Crapo · 2012 [cited by applicant]
US 20120229657A1 · Calman et al. · 2012 [cited by applicant]
US 20120289787A1 · Kurgan et al. · 2012 [cited by applicant]
US 20130091539A1 · Khurana et al. · 2013 [cited by applicant]
US 20130173309A1 · Dworkin · 2013 [cited by applicant]
US 20130197927A1 · Vanderveen et al. · 2013 [cited by applicant]
US 20130197931A1 · Gupta et al. · 2013 [cited by applicant]
US 20130218329A1 · Henderson et al. · 2013 [cited by applicant]
US 20130297330A1 · Kamen · 2013 [cited by applicant]
US 20130304506A1 · Gallivan et al. · 2013 [cited by applicant]
US 20130325882A1 · Deshpande · 2013 [cited by applicant]
US 20140188512A1 · Parker et al. · 2014 [cited by applicant]
US 20140214199A1 · Utech et al. · 2014 [cited by applicant]
US 20150205954A1 · Jou et al. · 2015 [cited by applicant]
US 20150235334A1 · Wang · 2015 [cited by applicant]
US 20150242856A1 · Dhurandhar · 2015 [cited by examiner]
US 20150269824A1 · Zhang · 2015 [cited by applicant]
US 20150319185A1 · Kirti et al. · 2015 [cited by applicant]
US 20150381631A1 · Salem et al. · 2015 [cited by applicant]
US 20160005044A1 · Moss · 2016 [cited by applicant]
US 20160085986A1 · Long · 2016 [cited by applicant]
US 20160088000A1 · Siva Kumar et al. · 2016 [cited by applicant]
US 20160180022A1 · Paixao · 2016 [cited by examiner]
US 20160196728A1 · Suman et al. · 2016 [cited by applicant]
US 20160267224A1 · Natarajan · 2016 [cited by applicant]
US 20170017760A1 · Freese · 2017 [cited by applicant]
US 20170109497A1 · Tribble et al. · 2017 [cited by applicant]
US 20170272336A1 · Johnstone et al. · 2017 [cited by applicant]
US 20180039736A1 · Williams · 2018 [cited by applicant]
US 20180174673A1 · Defran et al. · 2018 [cited by applicant]
US 20180191693A1 · Juels · 2018 [cited by applicant]
US 20180247703A1 · D'Amato · 2018 [cited by applicant]
US 20190088354A1 · Yanowitz et al. · 2019 [cited by applicant]
US 20190139638A1 · Keefe et al. · 2019 [cited by applicant]
US 20190220545A1 · Tripodi · 2019 [cited by applicant]
US 20190258731A1 · Mikhailov · 2019 [cited by applicant]
US 20190304583A1 · Henderson et al. · 2019 [cited by applicant]
US 20200042519A1 · Tomlin · 2020 [cited by applicant]
US 20210067542A1 · Linder · 2021 [cited by applicant]
US 20210294797A1 · Gupta · 2021 [cited by applicant]
US 20210319872A1 · Valentine · 2021 [cited by applicant]
US 20220282199A1 · Vann · 2022 [cited by applicant]
US 20230245651A1 · Wang · 2023 [cited by applicant]
US 20240312589A1 · Culbertson et al. · 2024 [cited by applicant]
US 20250054587A1 · Ambrose et al. · 2025 [cited by applicant]
US 20250087328A1 · Culbertson et al. · 2025 [cited by applicant]
CA 3014319 · 2017 [cited by applicant]
WO WO2019055545 · 2019 [cited by applicant]
WO WO2019102433 · 2019 [cited by applicant]
WO WO2020251962 · 2020 [cited by applicant]
WO WO2024249618 · 2024 [cited by applicant]
Bryant, Blake, “Hacking SIEMs to Catch Hackers: Decreasing the Mean Time to Respond to Network Security Events with a Novel Threat Ontology in SIEM Software”, Master's Thesis, University of Kansas, 2016, pp. 257. [cited by applicant]
[cited by applicant]
Epstein et al., “Development of a Scheduled Drug Diversion Surveillance System Based on an Analysis of Atypical Drug Transactions”, Anesthesia and Analgesia, Oct. 2007, vol. 105, No. 4, pp. 1053-1060. [cited by applicant]
Pace et al., “Distributed Ambulatory Research in Therapeutics Network (DARTNet): Summary Report”, Effective Health Care Research Reports, No. 14, Agency for Healthcare Research and Quality, Jul. 2009, pp. 41. [cited by applicant]