IP Library Granted Patent US 12,632,595
Granted Patent B1
US 12,632,595 · App. 19/368,459 · Granted May 19, 2026

Systems and methods for secure matching of encrypted data records

Inventors: Asaf Evenhaim (New York, NY); Saar Barhoom (Kiryat Ono, IL); Dikla Dotan (Jerusalem, IL); Keren Elia (Merkaz, IL); Nina Kirshenbaum (Scarsdale, NY)
Assignee: Veeva Systems Inc.
G06F21/6245G06F21/602
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,632,595
App. No.
19/368,459
Granted
May 19, 2026
Kind
B1
Abstract

A method for secure matching of data records in a data merging and linking computing system including an identified domain and a deidentified domain. The identified domain stores personally identifiable information (PII), where the deidentified domain does not store PII. The method includes generating a plurality of PII data records and a plurality of transaction data records in the identified domain. The method includes generating, in the identified domain, a PII key for each PII data record of the plurality of PII data records, and matching, in the identified domain, at least two PII keys of the plurality of PII keys. The method includes merging at least two PII data records. The method includes modifying a resulting set of PII data records to generate a plurality of deidentified PII data records. Each deidentified PII data record of the plurality of deidentified PII data records includes a token.

Claims (82)

1 . A method for secure matching of data records in a data merging and linking computing system, wherein the data merging and linking computing system includes an identified domain and a deidentified domain, wherein the identified domain processes and stores personally identifiable information (PII), wherein the deidentified domain does not process or store the PII, and wherein the method comprises:

receiving, by the data merging and linking computing system, a plurality of data records in the identified domain;

modifying, by the data merging and linking computing system, the plurality of data records to generate a plurality of PII data records and a plurality of transaction data records in the identified domain;

linking, by the data merging and linking computing system, the plurality of PII data records with the plurality of transaction data records by generating a mapping file in the identified domain;

normalizing, by the data merging and linking computing system, the plurality of transaction data records in the identified domain;

normalizing, by the data merging and linking computing system, the plurality of PII data records in the identified domain;

generating, by the data merging and linking computing system and in the identified domain, a PII key for each PII data record of the plurality of PII data records;

matching, by the data merging and linking computing system and in the identified domain, at least two PII keys of the plurality of PII keys;

merging, by the data merging and linking computing system and in the identified domain, at least two PII data records of the plurality of PII data records based on the matched at least two PII keys to generate at least one merged PII data record;

modifying, by the data merging and linking computing system, a resulting set of PII data records to deidentify the resulting set of PII data records and generate a plurality of deidentified PII data records,

wherein the resulting set of PII data records includes one or more PII data records of the plurality of PII data records and the at least one merged PII data record;

outputting, by the data merging and linking computing system and in the identified domain, at least a portion of each deidentified PII data record of the plurality of deidentified PII data records;

received, by the data merging and linking computing system and in the identified domain, a plurality of tokens;

modifying, by the data merging and linking computing system and in the identified domain, each deidentified PII data record of the plurality of deidentified PII data records to include a token of the plurality of tokens; and

storing, by the data merging and linking computing system, the plurality of deidentified PII data records, the plurality of normalized transaction data records, and the mapping file in at least one repository in the deidentified domain.

2 . The method of claim 1 , wherein each PII data record of the resulting set of PII data records includes a plurality of fields, and wherein modifying the resulting set of PII data records comprises:

encrypting, by the data merging and linking computing system, each field of the plurality of fields of the resulting set of PII data records to generate the plurality of deidentified PH data records.

3 . The method of claim 1 , wherein each PII data record of the resulting set of PII data records includes a plurality of fields, and wherein modifying the resulting set of PII data records comprises:

hashing, by the data merging and linking computing system, each field of the plurality of fields of the resulting set of PII data records to generate the plurality of deidentified PII data records.

4 . The method of claim 1 , wherein each transaction data record of the plurality of transaction data records includes a first unique identifier (UID), wherein each PII data record of the plurality of PII data records includes a second UID, and wherein the mapping file links the plurality of PII data records with the plurality of transaction data records by including at least one first UID associated with at least one second UID.

5 . The method of claim 1 , wherein each PII data record of the plurality of PII data records includes a plurality of fields, and wherein generating the PII key for each PII data record of the plurality of PII data records comprises:

selecting, by the data merging and linking computing system and for each PII data record of the plurality of PII data records, a first field and a second field of the plurality of fields; and

combining, by the data merging and linking computing system and for each PII data record of the plurality of PII data records, the first field and the second field to generate the PII key.

6 . The method of claim 1 , wherein the identified domain processes and stores protected health information (PHI) including the PII, and wherein the deidentified domain does not process or store the PHI.

7 . The method of claim 1 , wherein the identified domain includes a first repository, and wherein the method further comprises:

encrypting, by the data merging and linking computing system and in the identified domain, the plurality of data records using a first encryption algorithm;

storing, by the data merging and linking computing system and in the identified domain, the plurality of encrypted data records;

encrypting, by the data merging and link computing system and in the deidentified domain, the plurality of deidentified PII data records, the plurality of normalized transaction data records, and the mapping file using a second encryption algorithm; and

storing, by the data merging and linking computing system, the encrypted plurality of deidentified PII data records, the encrypted plurality of normalized transaction data records, and the encrypted mapping file in the at least one repository in the deidentified domain.

8 . A method for secure matching of data records in a data merging and linking computing system, wherein the data merging and linking computing system includes an identified domain and a deidentified domain, wherein the identified domain processes and stores personally identifiable information (PII), wherein the deidentified domain does not process or store PII, and wherein the method comprises:

receiving, by the data merging and linking computing system, a plurality of data records in the identified domain;

modifying, by the data merging and linking computing system, the plurality of data records to generate a plurality of PII data records and a plurality of transaction data records in the identified domain;

linking, by the data merging and linking computing system, the plurality of PII data records with the plurality of transaction data records by generating a plurality of mapping data records in the identified domain;

normalizing, by the data merging and linking computing system, the plurality of transaction data records in the identified domain;

normalizing, by the data merging and linking computing system, the plurality of PII data records in the identified domain;

generating, by the data merging and linking computing system and in the identified domain, a PII key for each PII data record of the plurality of PII data records;

matching, by the data merging and linking computing system and in the identified domain, at least two PII keys of the plurality of PII keys;

merging, by the data merging and linking computing system and in the identified domain, at least two PII data records of the plurality of PII data records based on the matched at least two PII keys to generate at least one merged PII data record;

modifying, by the data merging and linking computing system, a resulting set of PII data records to deidentify the resulting set of PII data records and generate a plurality of deidentified PII data records,

wherein the resulting set of PII data records includes one or more PII data records of the plurality of PII data records and the at least one merged PII data record;

generating, by the data merging and linking computing system and in the identified domain, a token for each deidentified PII data record of the plurality of deidentified PII data records; and

modifying, by the data merging and linking computing system and in the identified domain, each deidentified PII data record of the plurality of deidentified PII data records to include the token; and

storing, by the data merging and linking computing system, the plurality deidentified PII data records, the plurality of normalized transaction data records, and the plurality of mapping data records in at least one repository in the deidentified domain.

9 . The method of claim 8 , wherein each PII data record of the resulting set of PII data records includes a plurality of fields, and wherein modifying the resulting set of PII data records comprises:

encrypting, by the data merging and linking computing system, each field of the plurality of fields of the resulting set of PII data records to generate the plurality of deidentified PII data records.

10 . The method of claim 8 , wherein each PII data record of the resulting set of PII data records includes a plurality of fields, and wherein modifying the resulting set of PII data records comprises:

hashing, by the data merging and linking computing system, each field of the plurality of fields of the resulting set of PII data records to generate the plurality of deidentified PII data records.

11 . The method of claim 8 , wherein each transaction data record of the plurality of transaction data records includes a first unique identifier (UID), wherein each PII data record of the plurality of PII data records includes a second UID, and wherein each mapping data record of the plurality of mapping data records includes at least one first UID associated with at least one second UID.

12 . The method of claim 8 , wherein each PII data record of the plurality of PII data records includes a plurality of fields, and wherein generating the PII key for each PII data record of the plurality of PII data records comprises:

selecting, by the data merging and linking computing system and for each PII data record of the plurality of PII data records, a first field and a second field of the plurality of fields; and

combining, by the data merging and linking computing system and for each PII data record of the plurality of PII data records, the first field and the second field to generate the PII key.

13 . The method of claim 8 , wherein the identified domain processes and stores protected health information (PHI) including the PII, and wherein the deidentified domain does not process or store the PHI.

14 . The method of claim 8 , wherein the identified domain includes a first repository, and wherein the method further comprises:

encrypting, by the data merging and linking computing system and in the identified domain, the plurality of data records using a first encryption algorithm;

storing, by the data merging and linking computing system and in the identified domain, the plurality of encrypted data records;

encrypting, by the data merging and link computing system and in the deidentified domain, the plurality deidentified PII data records, the plurality of normalized transaction data records, and the plurality of mapping data records using a second encryption algorithm; and

storing, by the data merging and linking computing system, the encrypted plurality of deidentified PII data records, the encrypted plurality of normalized transaction data records, and the encrypted the plurality of mapping data records in the at least one repository in the deidentified domain.

15 . A non-transitory computer readable medium having computer executable instructions embodied therein that, when executed by at least one processor of a computing system, cause the computing system to perform operations to perform secure matching of data records, the operations comprising:

receiving a plurality of data records in an identified domain of the computing system, wherein the identified domain stores personally identifiable information (PII);

modifying the plurality of data records to generate a plurality of PH data records and a plurality of transaction data records in the identified domain;

linking the plurality of PII data records with the plurality of transaction data records by generating a mapping file in the identified domain;

normalizing the plurality of transaction data records in the identified domain;

normalizing the plurality of PII data records in the identified domain;

generating, in the identified domain, a PII key for each PII data record of the plurality of PII data records;

matching, in the identified domain, at least two PII keys of the plurality of PII keys;

merging, in the identified domain, at least two PII data records of the plurality of PII data records based on the matched at least two PII keys to generate at least one merged PII data record;

modifying a resulting set of PII data records to deidentify the resulting set of PII data records and generate a plurality of deidentified PII data records,

wherein the resulting set of PII data records includes one or more PII data records of the plurality of PII data records and the at least one merged PH data record, and wherein each deidentified PH data record of the plurality of deidentified PH data records includes a token; and

storing the plurality deidentified PII data records, the plurality of normalized transaction data records, and the mapping file in at least one repository in the deidentified domain of the computing system,

wherein the deidentified domain does not store PII.

16 . The non-transitory computer readable medium of claim 15 , wherein each PII data record of the resulting set of PII data records includes a plurality of fields, and wherein modifying the resulting set of PII data records comprises:

encrypting each field of the plurality of fields of the resulting set of PII data records to generate the plurality of deidentified PII data records.

17 . The non-transitory computer readable medium of claim 15 , wherein each PII data record of the resulting set of PII data records includes a plurality of fields, and wherein modifying the resulting set of PII data records comprises:

hashing each field of the plurality of fields of the resulting set of PII data records to generate the plurality of deidentified PII data records.

18 . The non-transitory computer readable medium of claim 15 , wherein the operations further comprise:

outputting, in the identified domain, at least a portion of each deidentified PII data record of the plurality of deidentified PII data records; and

receiving, in the identified domain, a plurality of tokens; and

modifying, in the identified domain, each deidentified PII data record of the plurality of deidentified PII data records to include a token of the plurality of tokens.

19 . The non-transitory computer readable medium of claim 15 , wherein the operations further comprises:

generating, in the identified domain, the token for each deidentified PII data record of the plurality of deidentified PH data records; and

modifying, in the identified domain, each deidentified PH data record of the plurality of deidentified PII data records to include the token.

20 . The non-transitory computer readable medium of claim 15 , wherein each transaction data record of the plurality of transaction data records includes a first unique identifier (UID), wherein each PII data record of the plurality of PII data records includes a second UID, and wherein the mapping file links the plurality of PII data records with the plurality of transaction data records by including at least one first UID associated with at least one second UID.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Nov 18, 2025
From: BARHOOM, SAAR; DOTAN, DIKLA; ELIA, KEREN; EVENHAIM, ASAF; KIRSHENBAUM, NINA
To: VEEVA SYSTEMS INC.
Reel/Frame 072937/0677 →
References Cited (66)
US 4965763A · Zamora · 1990 [cited by applicant]
US 5253164A · Holloway et al. · 1993 [cited by applicant]
US 5307262A · Ertel · 1994 [cited by applicant]
US 5420786A · Felthauser et al. · 1995 [cited by applicant]
US 5491473A · Gilbert · 1996 [cited by applicant]
US 5544044A · Leatherman · 1996 [cited by applicant]
US 5557514A · Seare et al. · 1996 [cited by applicant]
US 5628530A · Thornton · 1997 [cited by applicant]
US 5781893A · Felthauser et al. · 1998 [cited by applicant]
US 5794042A · Terada et al. · 1998 [cited by applicant]
US 5835897A · Dang et al. · 1998 [cited by applicant]
US 5845255A · Mayaud · 1998 [cited by applicant]
US H1782H · Wicks et al. · 1999 [cited by applicant]
US 5950630A · Portwood et al. · 1999 [cited by applicant]
US 6014631A · Russel et al. · 2000 [cited by applicant]
US 6067523A · Bair et al. · 2000 [cited by applicant]
US 6223164B1 · Seare et al. · 2001 [cited by applicant]
US 6269404B1 · Hart et al. · 2001 [cited by applicant]
US 6305377B1 · Portwood et al. · 2001 [cited by applicant]
US 6356873B1 · Russel et al. · 2002 [cited by applicant]
US 6370511B1 · Dang · 2002 [cited by applicant]
US 6397224B1 · Zubeldia et al. · 2002 [cited by applicant]
US 6529952B1 · Blumenau · 2003 [cited by applicant]
US 6578003B1 · Camarda et al. · 2003 [cited by applicant]
US 6584472B2 · Classen · 2003 [cited by applicant]
US 6587829B1 · Camarda et al. · 2003 [cited by applicant]
US 6611846B1 · Stoodley · 2003 [cited by applicant]
US 6636875B1 · Bashant et al. · 2003 [cited by applicant]
US 7543149B2 · Ricciardi et al. · 2009 [cited by applicant]
US 7657540B1 · Bayliss · 2010 [cited by examiner]
US 7823207B2 · Evenhaim · 2010 [cited by applicant]
US 8577933B2 · Evenhaim · 2013 [cited by applicant]
US 10885225B2 · Balzer · 2021 [cited by examiner]
US 11550956B1 · Gupta · 2023 [cited by examiner]
US 20020016923A1 · Knaus et al. · 2002 [cited by applicant]
US 20020073138A1 · Gilbert · 2002 [cited by examiner]
US 20020103806A1 · Yamanoue · 2002 [cited by applicant]
US 20020116227A1 · Dick · 2002 [cited by applicant]
US 20020120505A1 · Henkin et al. · 2002 [cited by applicant]
US 20040172287A1 · O'toole et al. · 2004 [cited by applicant]
US 20060026156A1 · Zuleba · 2006 [cited by applicant]
US 20060173716A1 · Wang · 2006 [cited by applicant]
US 20070061393A1 · Moore · 2007 [cited by applicant]
US 20070220611A1 · Socolow et al. · 2007 [cited by applicant]
US 20100070298A1 · Kalies · 2010 [cited by applicant]
US 20110301982A1 · Green, Jr. et al. · 2011 [cited by applicant]
US 20200066386A1 · Katz · 2020 [cited by applicant]
US 20220284331A1 · Aispuro et al. · 2022 [cited by applicant]
US 20220318613A1 · Nambirajan et al. · 2022 [cited by applicant]
US 20240379199A1 · Srinathan · 2024 [cited by examiner]
WO 0237213A2 · 2002 [cited by applicant]
Adherence to Long-Term Therapies Evidence for action by the World Health Organization 2003 Attached file name: Adherance report.pdf. [cited by applicant]
CBI Conference Agenda for Anonymous Patient-Level Data and AnalysisNov. 2003 Attached file name: CBI Conf. on Patient-Level Data.pdf. [cited by applicant]
Data Rights Agreement Between Quintiles and Healtheon/WebMD Attached file name: WEBMD-QUINTILES DATA SHARING AGREEMENT.pdf. [cited by applicant]
Dataset De-Identification—A Technical Overview Attached file name: Dataset De-Identification—A Technical Overview.pdfdate Jan. 2003. [cited by applicant]
International Preliminary Report on Patentability (Report confirms that the inventionis novel, non-obvious, and has utility), date Jun. 29, 2011. [cited by applicant]
International Search Report & Written Opinion of International Searching Authority-Published Jul. 27, 2010. Please note the ISA's positive opinion that the claims are novel, involve an inventive stepand have industrial … [cited by applicant]
K-anonymity-A Model for Protecting Privacy Attached file name:K-anonymity—A Model for Protecting Privacy. pdfMay 2002. [cited by applicant]
Kaushik et al. (“Using LSTMs for Predicting Patient's Expenditure on Medications,” 2017 International Conference on Machine Learning and Data Science (MLDS), Naida, India, 2017, pp. 120-127) (Year: 2017). [cited by applicant]
MTS HealthTrak Inserts Essential 'Why' in Consumer Rx Purchasing Behaviors and Patt Attached filed name: MTS Healthtrak.pdf, Jul. 312006. [cited by applicant]
NDC Health Pharmaceutical website, as of Nov. 112003 Attached filed name: NDCHealth Pharmaceutical website.pdf. [cited by applicant]
Pfizer and RxRemedy—the Impact of DTC Advertising Relative to Patient Compliance Attached file name: Pfizer Inc Impact of DTC Advertising.pdfJun. 2001. [cited by applicant]
Pharmetrics HIPAA Compliance: Statistical Disclosure Limitation Methodology Attached file name: Pharmetrics HIPAA Compliance.pdf, May 142001. [cited by applicant]
Right-Channeling Consumer Drug Marketing by Forrester Research Attached file name: Right Channeling CD Mark.pdfDec. 2002. [cited by applicant]
Tools for Privacy Preserving Distributed Data Mining Attached file name: Tools for Privacy Preserving Distributed Data Mining.pdf. [cited by applicant]
Using De-Identified Information to Simplify Privacy Compliance Attached file name: Legal review of de-identification. pdf. [cited by applicant]