IP Library Granted Patent US 8,931,044
Granted Patent B1
US 8,931,044 · App. 13/538,047 · Granted Jan 6, 2015

Methods and systems for automated assignment of protection to physical documents that are digitized

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 8,931,044
App. No.
13/538,047
Granted
Jan 6, 2015
Kind
B1
Abstract

Content analysis is performed on documents that have been scanned or converted into a digital format. Based on the content analysis of a document, a security policy is selected and assigned or attached to the document. The security policy prevents the document from being improperly accessed. In a specific implementation, the documents include patient medical records.

Claims (64)

1. A method comprising:

storing at a central server a plurality of scanned documents, and a plurality of security policies, each security policy having a corresponding policy definition;

analyzing a scanned document to identify a visual feature in the scanned document, wherein the analyzing comprises parsing optical character recognition (OCR) data extracted from the scanned document to identify a form field and an handwritten entry of a name of a person for the form field in the scanned document, wherein the visual feature comprises the form field and the handwritten entry for the form field;

selecting, based on the identified visual feature, a security policy of the plurality of security policies;

assigning the selected security policy to the scanned document;

detecting an attempt to access the scanned document having the assigned security policy;

determining whether a user attempting to access the scanned document has a name that matches the name of the person;

evaluating at the central server the policy definition corresponding to the assigned security policy to determine whether the access is granted or denied; and

determining that access should be granted when the user has a name that matches the name of the person and that access should be denied when the user has a name that does not match the name of the person.

2. The method of claim 1 wherein the scanned document comprises a medical image and the visual feature comprises an abnormality.

3. The method of claim 1 wherein the method comprises:

parsing the OCR data to identify an address field and an entry for the address field in the scanned document, wherein the entry for the address field is used to identify a person listed in a directory;

determining whether the user attempting to access the scanned document has an address that matches the entry for the address field; and

determining that access should be granted when the user has an address that matches the entry for the address field and that access should be denied when the user has an address that does not match the entry for the address field.

4. The method of claim 1 wherein the handwritten entry for the form field comprises a name of a person and the method comprises:

determining whether the person belongs to a first group or a second group; and

assigning a first security policy to the scanned document when the person belongs to the first group, the first security policy being the assigned security policy, or a second security policy to the scanned document when the person belongs to the second group, the second security policy being the assigned security policy, wherein one of the first or second security policies is more restrictive than another of the first or second security policies.

5. The method of claim 1 wherein the plurality of scanned documents are medical records, the scanned document thereby being a medical record of a patient, and the method comprises:

determining whether an entry in the medical record comprises information indicating the patient suffers at least one of a sexually transmitted disease (STD), human immunodeficiency virus (HIV), mental illness, alcohol abuse, or drug abuse;

if the medical record comprises the information, assigning a first security policy to the medical record, the first security policy being the assigned security policy; and

if the medical record does not comprise the information, assigning a second security policy to the medical record, the second security policy being the assigned security policy,

wherein the first security policy blocks the medical record from being distributed through electronic mail, and the second security policy permits the medical record to be distributed through electronic mail.

6. The method of claim 1 comprising:

encrypting the scanned document; and

copying the encrypted scanned document to a client, wherein the client is remote from the central server, and the detecting an attempt to access the scanned document comprises receiving a request from the client to open the encrypted document at the client.

7. A computer program product, comprising a non-transitory computer-readable medium having a computer-readable program code embodied therein, the computer-readable program code including instructions to be executed by one or more processors to:

store at a central server a plurality of scanned documents, and a plurality of security policies, each security policy having a corresponding policy definition;

analyze a scanned document to identify a visual feature in the scanned document, wherein the analyzing comprises parsing optical character recognition (OCR) data extracted from the scanned document to identify a form field and an handwritten entry of a name of a person for the form field in the scanned document, wherein the visual feature comprises the form field and the handwritten entry for the form field;

select, based on the identified visual feature, a security policy of the plurality of security policies;

assign the selected security policy to the scanned document;

detect an attempt to access the scanned document having the assigned security policy;

determine whether a user attempting to access the scanned document has a name that matches the name of the person;

evaluate at the central server the policy definition corresponding to the assigned security policy to determine whether the access is granted or denied; and

determine that access should be granted when the user has a name that matches the name of the person and that access should be denied when the user has a name that does not match the name of the person.

8. The computer program product of claim 7 wherein the scanned document comprises a medical image and the visual feature comprises a foreign object.

9. The computer program product of claim 7 wherein further comprising instructions to:

parse the OCR data to identify an address field and an entry for the address field in the scanned document, wherein the name of the person and the entry for the address field are used to identify a person listed in a directory;

determine whether the user attempting to access the scanned document has an address that matches the entry for the address field; and

determine that access should be granted when the user has an address that matches the entry for the address field and that access should be denied when the user has an address that does not match the entry for the address field.

10. The computer program product of claim 7 wherein the handwritten entry for the form field comprises a name of a person, further comprising instructions to:

determine whether the person belongs to a first group or a second group; and

assign a first security policy to the scanned document when the person belongs to the first group, the first security policy being the assigned security policy, or a second security policy to the scanned document when the person belongs to the second group, the second security policy being the assigned security policy, wherein one of the first or second security policies is more restrictive than another of the first or second security policies.

11. The computer program product of claim 7 wherein the plurality of scanned documents are medical records, the scanned document thereby being a medical record of a patient, further comprising:

determining whether an entry in the medical record comprises information indicating the patient suffers at least one of a sexually transmitted disease (STD), human immunodeficiency virus (HIV), mental illness, alcohol abuse, or drug abuse;

if the medical record comprises the information, assigning a first security policy to the medical record, the first security policy being the assigned security policy; and

if the medical record does not comprise the information, assigning a second security policy to the medical record, the second security policy being the assigned security policy,

wherein the first security policy blocks the medical record from being distributed through electronic mail, and the second security policy permits the medical record to be distributed through electronic mail.

12. The computer program product of claim 7 , further comprising:

encrypting the scanned document; and

copying the encrypted scanned document to a client, wherein the client is remote from the central server, and the detecting an attempt to access the scanned document comprises receiving a request from the client to open the encrypted scanned document at the client.

13. A system for automatically assigning a security policy to a document, the system comprising:

a processor-based database management system, which when executed on a computer system, will cause the processor to:

store at a central server a plurality of scanned documents, and a plurality of security policies, each security policy having a corresponding policy definition;

analyze a scanned document to identify a visual feature in the scanned document, wherein the analyzing comprises parsing optical character recognition (OCR) data extracted from the scanned document to identify a form field and an handwritten entry of a name of a person for the form field in the scanned document, wherein the visual feature comprises the form field and the handwritten entry for the form field;

select, based on the identified visual feature, a security policy of the plurality of security policies;

assign the selected security policy to the scanned document;

detect an attempt to access the scanned document having the assigned security policy;

determine whether a user attempting to access the scanned document has a name that matches the name of the person;

evaluate at the central server the policy definition corresponding to the assigned security policy to determine whether the access is granted or denied; and

determine that access should be granted when the user has a name that matches the name of the person and that access should be denied when the user has a name that does not match the name of the person.

14. The system of claim 13 wherein the scanned document comprises a medical image and the visual feature comprises an abnormality.

15. The system of claim 13 wherein the handwritten entry for the form field comprises a name of a person and the processor-based database management system when executed on a computer system, will further cause the processor to:

determine whether the person belongs to a first group or a second group; and

assign a first security policy to the scanned document when the person belongs to the first group, the first security policy being the assigned security policy, or a second security policy to the scanned document when the person belongs to the second group, the second security policy being the assigned security policy, wherein one of the first or second security policies is more restrictive than another of the first or second security policies.

Assignments (7)
RELEASE OF SECURITY INTEREST IN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (045455/0001) Recorded May 20, 2022
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
To: DELL MARKETING CORPORATION (SUCCESSOR-IN-INTEREST TO ASAP SOFTWARE EXPRESS, INC.); DELL MARKETING L.P. (ON BEHALF OF ITSELF AND AS SUCCESSOR-IN-INTEREST TO CREDANT TECHNOLOGIES, INC.); DELL USA L.P.; DELL INTERNATIONAL L.L.C.; DELL PRODUCTS L.P.; DELL MARKETING CORPORATION (SUCCESSOR-IN-INTEREST TO FORCE10 NETWORKS, INC. AND WYSE TECHNOLOGY L.L.C.); EMC CORPORATION (ON BEHALF OF ITSELF AND AS SUCCESSOR-IN-INTEREST TO MAGINATICS LLC); EMC IP HOLDING COMPANY LLC (ON BEHALF OF ITSELF AND AS SUCCESSOR-IN-INTEREST TO MOZY, INC.); SCALEIO LLC
Reel/Frame 061753/0001 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Feb 1, 2017
From: EMC CORPORATION
To: OPEN TEXT CORPORATION
Reel/Frame 041579/0133 →
PATENT RELEASE (REEL:40134/FRAME:0001) Recorded Jan 23, 2017
From: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH, AS COLLATERAL AGENT
To: EMC CORPORATION, AS GRANTOR
Reel/Frame 041073/0136 →
RELEASE OF SECURITY INTEREST Recorded Jan 23, 2017
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
To: EMC CORPORATION
Reel/Frame 041073/0443 →
SECURITY AGREEMENT Recorded Sep 21, 2016
From: ASAP SOFTWARE EXPRESS, INC.; AVENTAIL LLC; CREDANT TECHNOLOGIES, INC.; DELL USA L.P.; DELL INTERNATIONAL L.L.C.; DELL MARKETING L.P.; DELL PRODUCTS L.P.; DELL SOFTWARE INC.; DELL SYSTEMS CORPORATION; EMC CORPORATION; EMC IP HOLDING COMPANY LLC; FORCE10 NETWORKS, INC.; MAGINATICS LLC; MOZY, INC.; SCALEIO LLC; SPANNING CLOUD APPS LLC; WYSE TECHNOLOGY L.L.C.
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
Reel/Frame 040136/0001 →
SECURITY AGREEMENT Recorded Sep 21, 2016
From: ASAP SOFTWARE EXPRESS, INC.; AVENTAIL LLC; CREDANT TECHNOLOGIES, INC.; DELL USA L.P.; DELL INTERNATIONAL L.L.C.; DELL MARKETING L.P.; DELL PRODUCTS L.P.; DELL SOFTWARE INC.; DELL SYSTEMS CORPORATION; EMC CORPORATION; EMC IP HOLDING COMPANY LLC; FORCE10 NETWORKS, INC.; MAGINATICS LLC; MOZY, INC.; SCALEIO LLC; SPANNING CLOUD APPS LLC; WYSE TECHNOLOGY L.L.C.
To: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH, AS COLLATERAL AGENT
Reel/Frame 040134/0001 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 28, 2012
From: SUBRAMANIAN, LALITH G.
To: EMC CORPORATION
Reel/Frame 028860/0633 →