IP Library Patent Application 19014899
Patent Application
App. No. 19/014,899

METHODS AND SYSTEMS FOR ANALYZING ACCESSING OF MEDICAL DATA

Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US None
App. No.
19/014,899
Abstract

Various aspects described herein relate to presenting electronic patient data accessing information. Data related to a plurality of access events, by one or more employees, of electronic patient data can be received. A set of access events of the plurality of access events can be determined as constituting, by the one or more employees, possible breach of the electronic patient data. An alert related to the set of access events can be provided based on determining that the set of access events constitute possible breach of the electronic patient data.

Claims (54)

1 . A computer-implemented method for detecting a non-compliant access of electronic patient data, the computer-implemented method comprising:

receiving, by one or more processors of a patient privacy monitoring server, access data comprising a plurality of electronic patient data access events by one or more entities and entity-specific identification data associated with the one or more entities;

filtering, by the one or more processors, the plurality of electronic patient data access events based on one or more whitelist events by excluding one or more of the plurality of electronic patient data access events that correspond to the one or more whitelist events to generate a filtered set of electronic patient data access events by the one or more entities;

determining, by the one or more processors, that at least one electronic patient data access event of the plurality of electronic patient data access events constitutes a potential non-compliant access of the electronic patient data based on the entity-specific identification data and the filtered set of electronic patient data access events; and

in response to determining that the at least one electronic patient data access event of the plurality of electronic patient data access events constitutes the potential non-compliant access of the electronic patient data, causing to present on a display of a user interface, by the one or more processors, an indicator of the at least one electronic patient data access event.

2 . The computer-implemented method of claim 1 , wherein:

the access data is received from a plurality of electronic patient data access devices situated at a plurality of locations, and the entity-specific identification data is human resources (HR) data associated with the one or more entities from one or more storage devices local or remote to the patient privacy monitoring server.

3 . The computer-implemented method of claim 1 , wherein determining that the at least one electronic patient data access event of the plurality of electronic patient data access events constitutes the potential non-compliant access of the electronic patient data comprises:

applying one or more tags defined for anomaly identification to the filtered set of electronic patient data access events; and

detecting the potential non-compliant access of electronic patient data based on a weighted score of tags, a number of tags, or a combination of the tags satisfied by the at least one electronic patient data access event.

4 . The computer-implemented method of claim 3 , wherein the one or more tags comprise at least one of:

a negative tag indicative of an electronic patient data access event that comprises a non-compliant access;

a positive tag indicative of an electronic patient data access event that comprises a legitimate access; and

a neutral tag indicative of an electronic patient data access event that does not alone comprise a non-compliant access.

5 . The computer-implemented method of claim 4 , wherein the negative tag is one of: a low level negative tag comprising a first weighted score, or a high level negative tag comprising a second weighted score, where the second weighted score is greater than the first weighted score.

6 . The computer-implemented method of claim 4 , wherein the negative tag is indicative of one or more of: accessing data of a patient with a same full name as a person accessing the data; accessing data of a patient with a same address as the person accessing the data or of another patient; accessing data of a patient with a same last name as the person accessing the data; or accessing data from an unusual workstation.

7 . The computer-implemented method of claim 1 , wherein a machine learning model is trained to determine that the at least one electronic patient data access event of the plurality of electronic patient data access events constitutes the potential non-compliant access of the electronic patient data based on the entity-specific identification data and the filtered set of electronic patient data access events.

8 . The computer-implemented method of claim 1 , wherein each of the one or more whitelist events is indicative of one or more of: an appointment entry, a procedure or medication entry related to ordering a procedure or a medication for a patient, an allergy information update, a patient check-in, or a primary care provider modification

9 . The computer-implemented method of claim 1 , further comprising:

determining, by the one or more processors, a priority score for the at least one electronic patient data access event, wherein the priority score is based on a weighted score of tags, a number of tags, or a combination of the tags satisfied by the at least one electronic patient data access event.

10 . The computer-implemented method of claim 9 , further comprising:

sorting, by the one or more processors, an alert associated with the at least one electronic patient data access event based on the priority score for the at least one electronic patient data access event, wherein the sorted alert is displayed on the user interface.

11 . A system for detecting a non-compliant access of electronic patient data, the system comprising:

one or more processors; and

one or more computer readable storage media storing instructions which, when executed by the one or more processors, cause the one or more processors to perform operations comprising:

receiving access data comprising a plurality of electronic patient data access events by one or more entities and entity-specific identification data associated with the one or more entities;

filtering the plurality of electronic patient data access events based on one or more whitelist events by excluding one or more of the plurality of electronic patient data access events that correspond to the one or more whitelist events to generate a filtered set of electronic patient data access events by the one or more entities;

determining that at least one electronic patient data access event of the plurality of electronic patient data access events constitutes a potential non-compliant access of the electronic patient data based on the entity-specific identification data and the filtered set of electronic patient data access events; and

in response to determining that the at least one electronic patient data access event of the plurality of electronic patient data access events constitutes the potential non-compliant access of the electronic patient data, causing to present on a display of a user interface, by the one or more processors, an indicator of the at least one electronic patient data access event.

12 . The system of claim 11 , wherein:

the access data is received from a plurality of electronic patient data access devices situated at various locations, and the entity-specific identification data is human resources (HR) data associated with the one or more entities.

13 . The system of claim 11 , wherein determining that the at least one electronic patient data access event of the plurality of electronic patient data access events constitutes a potential non-compliant access of the electronic patient data comprises:

applying one or more tags defined for anomaly identification to the filtered set of electronic patient data access events; and

detecting the potential non-compliant access of electronic patient data based on a weighted score of tags, a number of tags, or a combination of the tags satisfied by the at least one electronic patient data access event.

14 . The system of claim 13 , wherein the one or more tags comprise at least one of:

a negative tag indicative of an electronic patient data access event that comprises a non-compliant access;

a positive tag indicative of an electronic patient data access event that comprises a legitimate access; and

a neutral tag indicative of an electronic patient data access event that does not alone comprise a non-compliant access.

15 . The system of claim 14 , wherein a machine learning model is trained to determine that the at least one electronic patient data access event of the plurality of electronic patient data access events constitutes the potential non-compliant access of the electronic patient data based on the entity-specific identification data and the filtered set of electronic patient data access events.

16 . One or more non-transitory computer readable media storing instructions which, when executed by one or more processors, cause the one or more processors to perform operations for detecting a non-compliant access of electronic patient data, the operations comprising:

receiving access data comprising a plurality of electronic patient data access events by one or more entities and entity-specific identification data associated with the one or more entities;

filtering the plurality of electronic patient data access events based on one or more whitelist events by excluding one or more of the plurality of electronic patient data access events that correspond to the one or more whitelist events to generate a filtered set of electronic patient data access events by the one or more entities;

determining that at least one electronic patient data access event of the plurality of electronic patient data access events constitutes a potential non-compliant access of the electronic patient data based on the entity-specific identification data and the filtered set of electronic patient data access events; and

in response to determining that the at least one electronic patient data access event of the plurality of electronic patient data access events constitutes the potential non-compliant access of the electronic patient data, causing to present on a display of a user interface, by the one or more processors, an indicator of the at least one electronic patient data access event.

17 . The one or more non-transitory computer readable media of claim 16 , wherein:

the access data is received from a plurality of electronic patient data access devices situated at various locations, and the entity-specific identification data is human resources (HR) data associated with the one or more entities.

18 . The one or more non-transitory computer readable media of claim 16 , wherein determining that the at least one electronic patient data access event of the plurality of electronic patient data access events constitutes a potential non-compliant access of the electronic patient data comprises:

applying one or more tags defined for anomaly identification to the filtered set of electronic patient data access events; and

detecting the potential non-compliant access of electronic patient data based on a weighted score of tags, a number of tags, or a combination of the tags satisfied by the at least one electronic patient data access event.

19 . The one or more non-transitory computer readable media of claim 18 , wherein the one or more tags comprise at least one of:

a negative tag indicative of an electronic patient data access event that comprises a non-compliant access;

a positive tag indicative of an electronic patient data access event that comprises a legitimate access; and

a neutral tag indicative of an electronic patient data access event that does not alone comprise a non-compliant access.

20 . The one or more non-transitory computer readable media of claim 19 , wherein a machine learning model is trained to determine that the at least one electronic patient data access event of the plurality of electronic patient data access events constitutes the potential non-compliant access of the electronic patient data based on the entity-specific identification data and the filtered set of electronic patient data access events.

Assignments (4)
CORRECTIVE ASSIGNMENT TO CORRECT THE THE NAME OF THE CONVEYING PARTY PREVIOUSLY RECORDED AT REEL: 70225 FRAME: 709. ASSIGNOR(S) HEREBY CONFIRMS THE ASSIGNMENT. Recorded Feb 24, 2025
From: PROTENUS, INC.
To: BLUESIGHT, INC.
Reel/Frame 070314/0107 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Feb 20, 2025
From: CULBERTSON, NICHOLAS T.; LORD, ROBERT K.
To: PROTENUS, INC.
Reel/Frame 070275/0789 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Feb 14, 2025
From: PROTENUS, INC.,
To: BLUESIGHT, INC.
Reel/Frame 070225/0709 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jan 10, 2025
From: CULBERTSON, NICHOLAS T.; LORD, ROBERT K.
To: PROTENUS, INC.
Reel/Frame 069814/0560 →