System and method for creation of persistent patient identification
Methods, systems, and apparatus, including computer programs encoded on computer storage media, for creating source-specific, persistent patient identifiers for healthcare service providers. One method includes accessing a record of healthcare data, wherein the record includes patient identifying information (PII) associated with one or more persons to whom the healthcare data pertains. The portions of PII included in the accessed record of healthcare data are extracted from the accessed record and encrypted. Based on one or more business rules, one or more hashed tokens are created by applying one or more hashing functions to the extracted portions of PII. A source-specific identifier is received, the source-specific identifier having been encoded in a manner specific to an organization associated with the computer system and having been encoded with reference to the one or more hashed tokens. An association is stored between the source-specific identifier and the accessed record of healthcare data.
1 . A system comprising:
one or more computers and one or more storage devices storing instructions that are operable, when executed by the one or more computers, to cause the one or more computers to perform operations comprising:
generating, by a first server, one or more hashed tokens using an encryption key and personally identifying information (PII) removed from at least one healthcare data record that contains PII for a patient;
transmitting, by the first server, the one or more generated hashed tokens to a second server;
matching, by the second server, the one or more generated hashed tokens to one or more other hashed tokens generated from data removed when de-identifying other healthcare data records; and
determining, by the second server, an encrypted indexing tag according to the at least one match in response to at least one match occurring between the one or more received generated hashed tokens and the one or more other hashed tokens, wherein the encryption of the indexing tag is based on a computing rule specific to the first server, the computing rule based on PII extracted from the at least one healthcare data record.
2 . The system of claim 1 , wherein generating the one or more hashed tokens using the encryption key and the PII removed from the at least one healthcare data record comprises:
extracting, by the first server, the PII in the at least one healthcare data record;
encrypting, by the first server, the extracted PII; and
generating, by the first server, the one or more hashed tokens using the encryption key and the encrypted PII.
3 . The system of claim 2 , further comprising:
appending the one or more hashed tokens to the at least one healthcare data record from which the PII was extracted.
4 . The system of claim 3 , further comprising:
transmitting the at least one healthcare data record with the appended one or more hashed tokens to a data storage location.
5 . The system of claim 4 , wherein the data storage location is a data warehouse accessible by a plurality of healthcare related sources.
6 . The system of claim 4 , wherein the data storage location is maintained by a third-party intermediary.
7 . The system of claim 4 , wherein the at least one healthcare data record stored in the data storage location is accessible through a user interface.
8 . The system of claim 2 , wherein the extracted PII comprises strings, and wherein encrypting the extracted PII into the one or more hashed tokens using one or more hashing functions specific to the first server comprises:
aggregating the strings based on the computing rule specific to the first server, the computing rule indicating a shared encryption format comprising one or more of content for combining and ordering or PII for the one or more hashed tokens.
9 . The system of claim 2 , further comprising:
generating, by the first server, one or more strings from the extracted PII;
generating, by the first server, an order of the one or more strings that increases a likelihood that the one or more generated hashed tokens match with the one or more other hashed tokens generated from data removed when de-identifying other healthcare data records;
organizing, by the first server, the one or more strings according to the generated order;
encrypting, by the first server, the one or more organized strings using the encryption key; and
generating, by the first server, the one or more hashed tokens using the one or more encrypted strings.
10 . The system of claim 1 , wherein the match occurring between the one or more generated hashed tokens and the one or more other hashed tokens represents a link between tokens indicative of a same person.
11 . The system of claim 1 , wherein determining the indexing tag according to the at least one match comprises:
retrieving de-identified healthcare data records corresponding to the one or more other hashed tokens that match to the one or more generated hashed tokens; and
obtaining the indexing tag according to the retrieved de-identified healthcare data records.
12 . The system of claim 1 , the operations further comprising encrypting the obtained indexing tag to a source of the one or more generated hashed tokens, wherein the source of the one or more generated hashed tokens corresponds to a healthcare related source such that the encrypted indexing tag is inaccessible to other healthcare related sources.
13 . The system of claim 1 , the operations further comprising:
determining, by the second server, that the one or more generated hashed tokens do not match to the one or more other hashed tokens in the de-identified healthcare data records;
in response to determining that the one or more generated hashed tokens do not match to the one or more other hashed tokens generated from data removed when de-identifying the other healthcare data records:
generating, by the second server, an indexing tag to anonymously identify the patient that corresponds to the one or more generated hashed tokens;
storing, by the second server, the generated indexing tag and the one or more generated hashed tokens in memory.
14 . The system of claim 4 , wherein obtaining the encrypted indexing tag specific to the first server comprises receiving the encrypted indexing tag from the data storage location, wherein the encrypted indexing tag has been identified through operations comprising:
determining whether the one or more hashed tokens match one or more hashed tokens from other healthcare data in the data storage location sharing an encryption format; and
in response to determining a match, retrieving the encrypted indexing tag specific to the first server from the data storage location.
15 . The system of claim 14 , further comprising, in response to not determining a match, generating the encrypted indexing tag specific to the first server, wherein generating the encrypted index tag comprises:
replacing the one or more hashed tokens with an indexing tag; and
encrypting the indexing tag to generate the encrypted indexing tag specific to the first server using one or more encryption functions specific to the first server.
16 . The system of claim 1 , wherein the indexing tag is used to link deidentified healthcare data of the patient from the first server with deidentified healthcare data at a second server through operations comprising:
receiving the deidentified healthcare data comprising one or more hashed tokens specific to the first server from the first server;
determining a corresponding indexing tag of the patient using the one or more hashed tokens specific to the first server; and
identifying deidentified healthcare data from the second server using the corresponding indexing tag.
17 . The system of claim 1 , further comprising receiving a report comprising an analysis of one or more healthcare data records for a plurality of patients at a plurality of locations, wherein the report has been generated through operations comprising:
aggregating respective deidentification healthcare data records of each of the plurality of patients from one or more locations; and
analyzing the aggregate data.
18 . The system of claim 1 , the operations further comprising:
obtaining a persistent patient identifier for the patient comprising the encrypted indexing tag, wherein only the first server has access to the persistent patient identifier and the healthcare data records of the patient at the first server.
19 . A computer-implemented method, the method comprising:
generating, by a first server, one or more hashed tokens using an encryption key and personally identifying information (PII) removed from at least one healthcare data record that contains PII for a patient;
transmitting, by the first server, the one or more generated hashed tokens to a second server;
matching, by the second server, the one or more generated hashed tokens to one or more other hashed tokens generated from data removed when de-identifying other healthcare data records; and
determining, by the second server, an encrypted indexing tag according to the at least one match in response to at least one match occurring between the one or more received generated hashed tokens and the one or more other hashed tokens, wherein the encryption of the indexing tag is based on a computing rule specific to the first server, the computing rule based on PII extracted from the at least one healthcare data record.
20 . A non-transitory computer-readable medium storing software comprising instructions executable by one or more computers which, upon such execution, cause the one or more computers to perform operations comprising:
generating, by a first server, one or more hashed tokens using an encryption key and personally identifying information (PII) removed from at least one healthcare data record that contains PII for a patient;
transmitting, by the first server, the one or more generated hashed tokens to a second server;
matching, by the second server, the one or more generated hashed tokens to one or more other hashed tokens generated from data removed when de-identifying other healthcare data records; and
determining, by the second server, an encrypted indexing tag according to the at least one match in response to at least one match occurring between the one or more received generated hashed tokens and the one or more other hashed tokens, wherein the encryption of the indexing tag is based on a computing rule specific to the first server, the computing rule based on PII extracted from the at least one healthcare data record.