IP Library Granted Patent US 8,185,411
Granted Patent B2
US 8,185,411 · App. 10/780,098 · Granted May 22, 2012

Method, system, and apparatus for patient controlled access of medical records

Assignee: International Business Machines Corporation
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 8,185,411
App. No.
10/780,098
Granted
May 22, 2012
Kind
B2
Abstract

A method of permitting controlled access to medical information can include establishing a storage means for containing medical information and establishing a means for accessing the medical information. The method further can include controlling the means for accessing the medical information according to a type of entity accessing the medical information, wherein access is limited according to the type of entity.

Claims (30)

1. A computer-implemented method of permitting controlled access to medical information of a patient, the method comprising:

supplying medical information of the patient to a central repository by the patient and any medical providers who have treated the patient;

storing and maintaining the medical information of the patient in the central repository;

accessing the medical information by the patient from an access device using a unique patient identifier and a patient PIN;

controlling by the patient an authorization and a scope of access to the medical information by modifying an access control list within the patient's profile when the patient is connected to the central repository, wherein the access control list lists each authorized user and the assigned role of each authorized user, wherein the scope of access includes which items of medical information are available to an assigned role and how that information will be viewed;

assigning each authorized user with a unique authorized user ID and an authorized user PIN; and

tracking and notifying the patient of an identity of a user who accessed the medical information, information that was accessed by the user, and when the user accessed the information.

2. The method of claim 1 , wherein the access device is controlled using a universally unique identifier.

3. The method of claim 1 , wherein said controlling step is overridden by a registered emergency provider.

4. The method of claim 1 , wherein the patient is compensated for permitting some of the medical information to be available and used by a research institution.

5. The method of claim 1 , wherein during a doctor visit the patient provides access to the medical information for a time period long enough to support the visit at which point the access times out.

6. The method of claim 1 , wherein access to the patient's medical information expires when a physician logs into another room/appointment.

7. A machine-readable storage having stored thereon, a computer program having a plurality of code sections, said code sections executable by a machine for causing the machine to perform the steps of:

supplying medical information of the patient to a central repository by the patient and any medical providers who have treated the patient;

storing and maintaining the medical information of the patient in the central repository;

accessing the medical information by the patient from an access device using a unique patient identifier and a patient PIN;

controlling by the patient an authorization and a scope of access to the medical information by modifying an access control list within the patient's profile when the patient is connected to the central repository, wherein the access control list lists each authorized user and the assigned role of each authorized user, wherein the scope of access includes which items of medical information are available to an assigned role and how that information will be viewed;

assigning each authorized user with a unique authorized user ID and an authorized user PIN; and

tracking and notifying the patient of an identity of a user who accessed the medical information, information that was accessed by the user, and when the user accessed the information.

8. The machine-readable storage of claim 7 , wherein the access device is controlled using a universally unique identifier.

9. The machine-readable storage of claim 7 , wherein said controlling step is overridden by a registered emergency provider.

10. A computer-implemented system for permitting controlled access to medical information of a patient, the system comprising:

a central repository for storing and maintaining medical information of the patient, the medical information of the patient being supplied to the central repository by the patient and any medical providers who have treated the patient;

an access device for accessing the medical information by the patient or any other authorized user, the patient accessing the medical information from the access device using a unique patient identifier and a patient PIN, each authorized user accessing the medical information from the access device using a unique authorized user ID and an authorized user PIN; and

at least a processor configured to

control by the patient an authorization and a scope of access to the medical information by modifying an access control list within the patient's profile when the patient is connected to the central repository, wherein the access control list lists each authorized user and the assigned role of each authorized user, wherein the scope of access includes which items of medical information are available to an assigned role and how that information will be viewed;

assign each authorized user with a unique authorized means for user ID and an authorized user PIN, and

track and notify the patient of an identity of a user who accessed the medical information, information that was accessed by the user, and when the user accessed the information.

11. The system of claim 10 , wherein the access device is controlled using a universally unique identifier.

12. The system of claim 10 , wherein the access control is overridden by registered emergency providers.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Mar 15, 2004
From: ALLARD, DAVID J.; SZABO, ROBERT M.
To: INTERNATIONAL BUSINESS MACHINES CORPORATION
Reel/Frame 014426/0552 →
Continuity (1)
Related Publication 20050182661A1 · Aug 18, 2005