Systems and methods for secure matching of encrypted data records
A method for secure matching of data records in a data merging and linking computing system including an identified domain and a deidentified domain. The identified domain stores personally identifiable information (PII), where the deidentified domain does not store PII. The method includes generating a plurality of PII data records and a plurality of transaction data records in the identified domain. The method includes generating, in the identified domain, a PII key for each PII data record of the plurality of PII data records, and matching, in the identified domain, at least two PII keys of the plurality of PII keys. The method includes merging at least two PII data records. The method includes modifying a resulting set of PII data records to generate a plurality of deidentified PII data records. Each deidentified PII data record of the plurality of deidentified PII data records includes a token.
1 . A method for secure matching of data records in a data merging and linking computing system, wherein the data merging and linking computing system includes an identified domain and a deidentified domain, wherein the identified domain processes and stores personally identifiable information (PII), wherein the deidentified domain does not process or store the PII, and wherein the method comprises:
receiving, by the data merging and linking computing system, a plurality of data records in the identified domain;
modifying, by the data merging and linking computing system, the plurality of data records to generate a plurality of PII data records and a plurality of transaction data records in the identified domain;
linking, by the data merging and linking computing system, the plurality of PII data records with the plurality of transaction data records by generating a mapping file in the identified domain;
normalizing, by the data merging and linking computing system, the plurality of transaction data records in the identified domain;
normalizing, by the data merging and linking computing system, the plurality of PII data records in the identified domain;
generating, by the data merging and linking computing system and in the identified domain, a PII key for each PII data record of the plurality of PII data records;
matching, by the data merging and linking computing system and in the identified domain, at least two PII keys of the plurality of PII keys;
merging, by the data merging and linking computing system and in the identified domain, at least two PII data records of the plurality of PII data records based on the matched at least two PII keys to generate at least one merged PII data record;
modifying, by the data merging and linking computing system, a resulting set of PII data records to deidentify the resulting set of PII data records and generate a plurality of deidentified PII data records,
wherein the resulting set of PII data records includes one or more PII data records of the plurality of PII data records and the at least one merged PII data record;
outputting, by the data merging and linking computing system and in the identified domain, at least a portion of each deidentified PII data record of the plurality of deidentified PII data records;
received, by the data merging and linking computing system and in the identified domain, a plurality of tokens;
modifying, by the data merging and linking computing system and in the identified domain, each deidentified PII data record of the plurality of deidentified PII data records to include a token of the plurality of tokens; and
storing, by the data merging and linking computing system, the plurality of deidentified PII data records, the plurality of normalized transaction data records, and the mapping file in at least one repository in the deidentified domain.
2 . The method of claim 1 , wherein each PII data record of the resulting set of PII data records includes a plurality of fields, and wherein modifying the resulting set of PII data records comprises:
encrypting, by the data merging and linking computing system, each field of the plurality of fields of the resulting set of PII data records to generate the plurality of deidentified PH data records.
3 . The method of claim 1 , wherein each PII data record of the resulting set of PII data records includes a plurality of fields, and wherein modifying the resulting set of PII data records comprises:
hashing, by the data merging and linking computing system, each field of the plurality of fields of the resulting set of PII data records to generate the plurality of deidentified PII data records.
4 . The method of claim 1 , wherein each transaction data record of the plurality of transaction data records includes a first unique identifier (UID), wherein each PII data record of the plurality of PII data records includes a second UID, and wherein the mapping file links the plurality of PII data records with the plurality of transaction data records by including at least one first UID associated with at least one second UID.
5 . The method of claim 1 , wherein each PII data record of the plurality of PII data records includes a plurality of fields, and wherein generating the PII key for each PII data record of the plurality of PII data records comprises:
selecting, by the data merging and linking computing system and for each PII data record of the plurality of PII data records, a first field and a second field of the plurality of fields; and
combining, by the data merging and linking computing system and for each PII data record of the plurality of PII data records, the first field and the second field to generate the PII key.
6 . The method of claim 1 , wherein the identified domain processes and stores protected health information (PHI) including the PII, and wherein the deidentified domain does not process or store the PHI.
7 . The method of claim 1 , wherein the identified domain includes a first repository, and wherein the method further comprises:
encrypting, by the data merging and linking computing system and in the identified domain, the plurality of data records using a first encryption algorithm;
storing, by the data merging and linking computing system and in the identified domain, the plurality of encrypted data records;
encrypting, by the data merging and link computing system and in the deidentified domain, the plurality of deidentified PII data records, the plurality of normalized transaction data records, and the mapping file using a second encryption algorithm; and
storing, by the data merging and linking computing system, the encrypted plurality of deidentified PII data records, the encrypted plurality of normalized transaction data records, and the encrypted mapping file in the at least one repository in the deidentified domain.
8 . A method for secure matching of data records in a data merging and linking computing system, wherein the data merging and linking computing system includes an identified domain and a deidentified domain, wherein the identified domain processes and stores personally identifiable information (PII), wherein the deidentified domain does not process or store PII, and wherein the method comprises:
receiving, by the data merging and linking computing system, a plurality of data records in the identified domain;
modifying, by the data merging and linking computing system, the plurality of data records to generate a plurality of PII data records and a plurality of transaction data records in the identified domain;
linking, by the data merging and linking computing system, the plurality of PII data records with the plurality of transaction data records by generating a plurality of mapping data records in the identified domain;
normalizing, by the data merging and linking computing system, the plurality of transaction data records in the identified domain;
normalizing, by the data merging and linking computing system, the plurality of PII data records in the identified domain;
generating, by the data merging and linking computing system and in the identified domain, a PII key for each PII data record of the plurality of PII data records;
matching, by the data merging and linking computing system and in the identified domain, at least two PII keys of the plurality of PII keys;
merging, by the data merging and linking computing system and in the identified domain, at least two PII data records of the plurality of PII data records based on the matched at least two PII keys to generate at least one merged PII data record;
modifying, by the data merging and linking computing system, a resulting set of PII data records to deidentify the resulting set of PII data records and generate a plurality of deidentified PII data records,
wherein the resulting set of PII data records includes one or more PII data records of the plurality of PII data records and the at least one merged PII data record;
generating, by the data merging and linking computing system and in the identified domain, a token for each deidentified PII data record of the plurality of deidentified PII data records; and
modifying, by the data merging and linking computing system and in the identified domain, each deidentified PII data record of the plurality of deidentified PII data records to include the token; and
storing, by the data merging and linking computing system, the plurality deidentified PII data records, the plurality of normalized transaction data records, and the plurality of mapping data records in at least one repository in the deidentified domain.
9 . The method of claim 8 , wherein each PII data record of the resulting set of PII data records includes a plurality of fields, and wherein modifying the resulting set of PII data records comprises:
encrypting, by the data merging and linking computing system, each field of the plurality of fields of the resulting set of PII data records to generate the plurality of deidentified PII data records.
10 . The method of claim 8 , wherein each PII data record of the resulting set of PII data records includes a plurality of fields, and wherein modifying the resulting set of PII data records comprises:
hashing, by the data merging and linking computing system, each field of the plurality of fields of the resulting set of PII data records to generate the plurality of deidentified PII data records.
11 . The method of claim 8 , wherein each transaction data record of the plurality of transaction data records includes a first unique identifier (UID), wherein each PII data record of the plurality of PII data records includes a second UID, and wherein each mapping data record of the plurality of mapping data records includes at least one first UID associated with at least one second UID.
12 . The method of claim 8 , wherein each PII data record of the plurality of PII data records includes a plurality of fields, and wherein generating the PII key for each PII data record of the plurality of PII data records comprises:
selecting, by the data merging and linking computing system and for each PII data record of the plurality of PII data records, a first field and a second field of the plurality of fields; and
combining, by the data merging and linking computing system and for each PII data record of the plurality of PII data records, the first field and the second field to generate the PII key.
13 . The method of claim 8 , wherein the identified domain processes and stores protected health information (PHI) including the PII, and wherein the deidentified domain does not process or store the PHI.
14 . The method of claim 8 , wherein the identified domain includes a first repository, and wherein the method further comprises:
encrypting, by the data merging and linking computing system and in the identified domain, the plurality of data records using a first encryption algorithm;
storing, by the data merging and linking computing system and in the identified domain, the plurality of encrypted data records;
encrypting, by the data merging and link computing system and in the deidentified domain, the plurality deidentified PII data records, the plurality of normalized transaction data records, and the plurality of mapping data records using a second encryption algorithm; and
storing, by the data merging and linking computing system, the encrypted plurality of deidentified PII data records, the encrypted plurality of normalized transaction data records, and the encrypted the plurality of mapping data records in the at least one repository in the deidentified domain.
15 . A non-transitory computer readable medium having computer executable instructions embodied therein that, when executed by at least one processor of a computing system, cause the computing system to perform operations to perform secure matching of data records, the operations comprising:
receiving a plurality of data records in an identified domain of the computing system, wherein the identified domain stores personally identifiable information (PII);
modifying the plurality of data records to generate a plurality of PH data records and a plurality of transaction data records in the identified domain;
linking the plurality of PII data records with the plurality of transaction data records by generating a mapping file in the identified domain;
normalizing the plurality of transaction data records in the identified domain;
normalizing the plurality of PII data records in the identified domain;
generating, in the identified domain, a PII key for each PII data record of the plurality of PII data records;
matching, in the identified domain, at least two PII keys of the plurality of PII keys;
merging, in the identified domain, at least two PII data records of the plurality of PII data records based on the matched at least two PII keys to generate at least one merged PII data record;
modifying a resulting set of PII data records to deidentify the resulting set of PII data records and generate a plurality of deidentified PII data records,
wherein the resulting set of PII data records includes one or more PII data records of the plurality of PII data records and the at least one merged PH data record, and wherein each deidentified PH data record of the plurality of deidentified PH data records includes a token; and
storing the plurality deidentified PII data records, the plurality of normalized transaction data records, and the mapping file in at least one repository in the deidentified domain of the computing system,
wherein the deidentified domain does not store PII.
16 . The non-transitory computer readable medium of claim 15 , wherein each PII data record of the resulting set of PII data records includes a plurality of fields, and wherein modifying the resulting set of PII data records comprises:
encrypting each field of the plurality of fields of the resulting set of PII data records to generate the plurality of deidentified PII data records.
17 . The non-transitory computer readable medium of claim 15 , wherein each PII data record of the resulting set of PII data records includes a plurality of fields, and wherein modifying the resulting set of PII data records comprises:
hashing each field of the plurality of fields of the resulting set of PII data records to generate the plurality of deidentified PII data records.
18 . The non-transitory computer readable medium of claim 15 , wherein the operations further comprise:
outputting, in the identified domain, at least a portion of each deidentified PII data record of the plurality of deidentified PII data records; and
receiving, in the identified domain, a plurality of tokens; and
modifying, in the identified domain, each deidentified PII data record of the plurality of deidentified PII data records to include a token of the plurality of tokens.
19 . The non-transitory computer readable medium of claim 15 , wherein the operations further comprises:
generating, in the identified domain, the token for each deidentified PII data record of the plurality of deidentified PH data records; and
modifying, in the identified domain, each deidentified PH data record of the plurality of deidentified PII data records to include the token.
20 . The non-transitory computer readable medium of claim 15 , wherein each transaction data record of the plurality of transaction data records includes a first unique identifier (UID), wherein each PII data record of the plurality of PII data records includes a second UID, and wherein the mapping file links the plurality of PII data records with the plurality of transaction data records by including at least one first UID associated with at least one second UID.