IP Library Granted Patent US 12,328,295
Granted Patent B1
US 12,328,295 · App. 18/241,065 · Granted Jun 10, 2025

System for securely monitoring and extracting data through a private network

Inventor: Marc Tobias (Philadelphia, PA)
Assignee: Phrase Health, Inc.
H04L63/02G06F9/451G06F16/245G16H10/60H04L63/0272
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,328,295
App. No.
18/241,065
Granted
Jun 10, 2025
Kind
B1
Abstract

Systems and methods are described for secure data extraction through a private network. A data extraction application may operate behind a firewall on a client system. Application state information may be automatically gathered and sent by the data extraction application upon the data extraction application being awakened at a predetermined time. A remote system outside of a firewall may determine commands to return to the data extraction application that include one or more query parameters, and then send the commands to the data extraction application. The remote system may then obtain, from the client system behind the firewall or from a data store outside of the firewall, results of the data extraction application executing a query with the provided query parameters injected therein, where the query was executed by the data extraction application with respect to one or more files located behind the firewall.

Claims (34)

1. A computer system comprising:

memory; and

a processor in communication with the memory and configured with processor-executable instructions to perform operations comprising:

providing configuration information for a data extraction application operating behind a firewall on a client system;

receiving application state information from the data extraction application, wherein the application state information is automatically gathered and sent by the data extraction application upon the data extraction application being awakened at a predetermined time;

in response to receipt of the application state information, determining commands to return to the data extraction application that include one or more query parameters;

sending the commands to the data extraction application, wherein the commands include the one or more query parameters to be injected by the data extraction application into at least one query; and

obtaining results of the data extraction application executing the query with the parameters injected.

2. The computer system of claim 1 , wherein the client system comprises or is in communication with one of (a) an electronic health record system or (b) a computer system of a medical practice, wherein the query is executed by the data extraction application with respect to one or more files located behind the firewall that are stored in association with at least one of the electronic health record system or the medical practice.

3. The computer system of claim 2 , wherein the at least one query has been previously stored by the data extraction application and is configured, when executed with the one or more query parameters, to access electronic health data behind the firewall.

4. The computer system of claim 1 , wherein the operations further comprise monitoring, by the computer system, a plurality of systems or subsystems of the client system based on the obtained results of the data extraction application, wherein the computer system is not permitted to directly access data of the plurality of systems or subsystems of the client system.

5. The computer system of claim 1 , wherein the computer system is further configured to invoke self-healing functionality of the data extraction application, wherein invoking the self-healing functionality comprises:

identifying that data relating to a first time period was not extracted by the data extraction application as specified by one of (a) a predetermined schedule or (b) a request from the computer system; and

sending a set of commands to the data extraction application related to a second time period that causes the data extraction application to extract both (c) data related to the first time period and (d) data related to the second time period.

6. The computer system of claim 1 , wherein the operations further comprise:

generating a user interface that includes a plurality of metrics derived from the obtained results of the data extraction application that operates behind the firewall on the client system; and

causing presentation of the user interface to an administrator computing device that is not configured to directly access files behind the firewall on the client system.

7. The computer system of claim 6 , wherein the user interface further includes at least one metric or portion of information derived from data retrieved by the computer system from a second computer system that is not located behind the firewall.

8. A computer-implemented method comprising, as implemented by one or more processors configured with specific executable instructions:

providing configuration information for a data extraction application operating behind a firewall on a client system;

receiving application state information from the data extraction application, wherein the application state information is automatically gathered and sent by the data extraction application upon the data extraction application being awakened at a predetermined time;

in response to receipt of the application state information, determining commands to return to the data extraction application that include one or more query parameters;

sending the commands to the data extraction application, wherein the commands include the one or more query parameters to be injected by the data extraction application into at least one query; and

obtaining results of the data extraction application executing the query with the parameters injected.

9. The computer-implemented method of claim 8 , wherein the client system comprises or is in communication with one of (a) an electronic health record system or (b) a computer system of a medical practice, wherein the query is executed by the data extraction application with respect to one or more files located behind the firewall that are stored in association with at least one of the electronic health record system or the medical practice.

10. The computer-implemented method of claim 8 , wherein the at least one query has been previously stored by the data extraction application and is configured, when executed with the one or more query parameters, to access electronic health data behind the firewall.

11. The computer-implemented method of claim 8 , further comprising monitoring, by the computer system, a plurality of systems or subsystems of the client system based on the obtained results of the data extraction application, wherein a computer system implementing the computer-implemented method is not permitted to directly access data of the plurality of systems or subsystems of the client system.

12. The computer-implemented method of claim 8 , further comprising:

identifying that data relating to a first time period was not extracted by the data extraction application as specified by one of (a) a predetermined schedule or (b) a request remotely sent to the data extraction application; and

sending a set of commands to the data extraction application related to a second time period that causes the data extraction application to extract both (c) data related to the first time period and (d) data related to the second time period.

13. The computer-implemented method of claim 8 , further comprising:

generating a user interface that includes a plurality of metrics derived from the obtained results of the data extraction application that operates behind the firewall on the client system; and

causing presentation of the user interface to an administrator computing device that is not configured to directly access files behind the firewall on the client system.

14. The computer-implemented method of claim 13 , wherein the user interface further includes at least one metric or portion of information derived from data retrieved from a second computer system that is not located behind the firewall.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Nov 20, 2024
From: TOBIAS, MARC
To: PHRASE HEALTH, INC.
Reel/Frame 069347/0490 →
Continuity (2)
Continuation 17207494 · Mar 19, 2021
Provisional Application 62992780 · Mar 20, 2020
References Cited (23)
US 8515989B2 · Fernandez · 2013 [imported from a related ]
US 8751252B2 · Chamberlain · 2014 [imported from a related ]
US 9584523B2 · Santhiveeran · 2017 [cited by examiner]
US 9589105B2 · Allen · 2017 [imported from a related ]
US 10050938B2 · Moskow · 2018 [imported from a related ]
US 10257165B2 · Obaidi · 2019 [cited by examiner]
US 10257226B2 · Drummond et al. · 2019 [imported from a related ]
US 10270744B2 · Smith · 2019 [imported from a related ]
US 10826925B2 · Mesic et al. · 2020 [imported from a related ]
US 10908970B1 · Arivazhagan · 2021 [imported from a related ]
US 10951645B2 · Mathew · 2021 [imported from a related ]
US 11017102B2 · Teal · 2021 [cited by examiner]
US 11057430B2 · Bhargava · 2021 [cited by examiner]
US 11243972B1 · Erlandson · 2022 [imported from a related ]
US 11258821B2 · Thomas · 2022 [cited by examiner]
US 11783922B1 · Tong · 2023 [cited by examiner]
US 20160191549A1 · Ernst · 2016 [imported from a related ]
US 20180060496A1 · Bulleit · 2018 [cited by examiner]
US 20190190702A1 · Isshiki · 2019 [cited by examiner]
US 20200007500A1 · Glazemakers · 2020 [cited by examiner]
US 20200067837A1 · Yang · 2020 [cited by examiner]
US 20200192862A1 · Hartfield · 2020 [imported from a related ]
US 20210034767A1 · Free et al. · 2021 [imported from a related ]