Methods, systems, and media for determining application compliance with the health insurance portability and accountability act

Inventors

Longmire, Michelle RaeSmith, Timothy RobertSas, James Marcel

Assignees

Medable Inc

Interested in licensing this patent?

MTEC can help explore whether this patent might be available for licensing for your application.

Publication Number

US-11901050-B2

Patent

Publication Date

2024-02-13

Expiration Date


Abstract

Methods and systems for determining whether a software application that is executable by an electronic device is compliant under the Health Insurance Portability and Accountability Act (HIPAA) are provided. A software application is accessed over a network. A programmed computer processor is used to determine whether said software application, upon execution, is at or above an (i) access control threshold, (ii) audit control threshold, (iii) data integrity threshold, (iv) authentication threshold, and (v) transmission security threshold, which thresholds are minimum thresholds for HIPAA compliance.Additionally, a determination that said software application is HIPAA compliant is made if said software application, upon execution, is at or above (i) said access control threshold, (ii) audit control threshold, (iii) data integrity threshold, (iv) authentication threshold, and (v) transmission security threshold. Further, a determination as to whether said software application is HIPAA compliant is output.

Core Innovation

The invention provides a method for determining whether a software application executing on an electronic device is compliant with the Health Insurance Portability and Accountability Act (HIPAA). A request is received over a computer network to determine compliance, where the software application has access to a data object that includes at least protected health information (PHI) or personally identifiable information (PII). Compliance checking is performed at a computing system including a processor.

The method determines whether the software application implements, for the data object, a threshold number of one or more safeguard techniques for each of a plurality of different types of safeguard techniques. The software application is determined to be compliant with HIPAA in response to implementing the threshold number of safeguard techniques for each safeguard-technique type, and not compliant in response to not implementing the threshold number for each safeguard-technique type.

The invention outputs, on a user interface, an indication indicating whether the software application is compliant with HIPAA or not compliant with HIPAA. The disclosed embodiments further cover a non-transitory computer readable medium carrying machine executable code and a system having a processor configured to receive the request, perform the threshold-based safeguard-technique determination for PHI/PII-containing data objects, and output the compliance indication on the user interface.

Claims Coverage

The provided independent claims are method claim clm-00001, system claim clm-00020, and medium claim clm-00016. Across these claims, the core inventive coverage is the same threshold-based compliance determination across multiple safeguard-technique types for a data object containing PHI and/or PII, with a user-interface indication of compliant versus not compliant.

Receiving a compliance determination request for a PHI/PII data object

receiving, over a computer network, a request to determine whether the software application is compliant with HIPAA, wherein the software application has access to a data object that includes at least protected health information (PHI) or personally identifiable information (PII).

Threshold-based safeguard-technique implementation across safeguard types

determining if the software application implements for the data object a threshold number of one or more safeguard techniques for each of a plurality of different types of safeguard techniques.

Compliant determination in response to threshold satisfaction

determining that the software application is compliant with HIPAA in response to determining that the software application implements for the data object the threshold number of the one or more safeguard techniques for each of the plurality of different types of safeguard techniques.

Not-compliant determination in response to threshold failure

determining that the software application is not compliant with HIPAA in response to determining that the software application does not implement for the data object the threshold number of the one or more safeguard techniques for each of the plurality of different types of safeguard technique.

User-interface output indicating compliant or not compliant

outputting, on a user interface, an indication indicating that the software application is compliant with HIPAA or not compliant with HIPAA.

Non-transitory computer readable medium with machine executable code

a non-transitory computer readable medium comprising machine executable code that, upon execution by one or more computer processors, cause the computing device to perform operations comprising receiving the request, determining threshold satisfaction across safeguard-technique types for a PHI/PII data object, determining compliant or not compliant, and outputting the indication on a user interface.

System configured to perform the threshold-based compliance determination

a system comprising a processor configured to receive the request, determine threshold satisfaction across safeguard-technique types for a PHI/PII data object, determine compliant or not compliant, and output, on a user interface, an indication indicating that the software application is compliant with HIPAA or not compliant with HIPAA.

Remedial measures for transitioning from non-compliance

outputting, on a user interface, one or more remedial measures that indicate modifications to the software application’s operation to transition the software application from non-HIPAA-compliant to HIPAA-compliant.

The independent claims cover receiving a request for HIPAA compliance of a software application that accesses a PHI/PII-containing data object, determining compliance by checking whether the application implements a threshold number of one or more safeguard techniques for each of a plurality of different safeguard-technique types, and outputting a user-interface indication of compliant versus not compliant. The claims also cover the same functionality in a non-transitory computer-readable medium and as a processor-based system, with an additional dependent feature of outputting remedial measures indicating modifications when transitioning from non-compliant to compliant.

Stated Advantages

Not explicitly described in patent.

Documented Applications

Not explicitly described in patent.

JOIN OUR MAILING LIST

Stay Connected with MTEC

Keep up with active and upcoming solicitations, MTEC news and other valuable information.