Integrated HIPAA-compliant computer security system for permitting an individual's circle of support to have access to individual budget and service plan data, and to monitor a plan for achieving the individual's goals
Inventors
Brockie, Justin Mark • Ali, Md. Asif • Faruq, A. S. M. Omar • Kelly, James Michael • Rafique, Sazzad • Robbins, Richard Allen
Assignees
Interested in licensing this patent?
MTEC can help explore whether this patent might be available for licensing for your application.
Abstract
Systems and methods are described which permit the state, the individual, the individual's case manager, and the individual's circle of support to have real time access to utilization data to monitor services and progress toward outcomes as part of a plan for achieving the individual's goals and maintain the individual's health and wellbeing, as well as to forecast future needs. Systems and methods for sharing billing information across at least two organizations in an integrated manner are also described. A physical node may receive a request for authorization for a user in an organization to access an individual's information in another organization. The request may be logged. The physical node may determine whether the user is authorized to access the individual's information and, if it is, provide appropriate access.
Core Innovation
The invention provides a HIPAA-compliant computer security method and a HIPAA-compliant computer security system for sharing service, budget, and billing information associated with personal health information of one or more individuals among at least a first organization and a second organization in an integrated manner. The invention includes preventing unauthorized access to the billing information while enabling authorized sharing in compliance with HIPAA.
The method and system receive, by one or more physical nodes, a first request for authorization for a user in the first organization to access service and budget information in the second organization pertaining to the personal health information of one or more individuals. The invention associates the first organization with a first security domain and the second organization with a second security domain, where the second organization has an access profile associated with the first security domain.
The invention logs the user's first request for authorization in an activity log associated with at least the first organization or the second organization and determines whether the user in the first organization is authorized to access the service and budget information in the second organization. If authorized, the invention transfers the service and budget information in compliance with HIPAA and logs the transferring in the activity log in compliance with HIPAA; if not authorized, the invention prevents the requested access in compliance with HIPAA and receives information pertaining to services provided and billing information generated by the first organization to permit monitoring of the service plan and progress toward outcomes and to forecast future needs.
Claims Coverage
The document includes two independent claims: a HIPAA-compliant computer security method for sharing service, budget, and billing information and a HIPAA-compliant computer security system for the same sharing. The independent claims center on authorization request receipt, activity logging, role/caseload/access-profile-based authorization determination, HIPAA-compliant transfer or prevention of unauthorized access, and receiving service and billing information to support monitoring and forecasting.
Integrated HIPAA-compliant sharing with unauthorized access prevention
A HIPAA-compliant computer security method of sharing service, budget, and billing information associated with personal health information of one or more individuals among at least a first organization and a second organization in an integrated manner, and preventing unauthorized access to the billing information.
Authorization request handling using security domains and access profile
Receiving by one or more physical nodes a first request for authorization for a user in the first organization to access service and budget information in the second organization pertaining to personal health information of one or more individuals, wherein the first organization is associated with a first security domain, the second organization is associated with a second security domain, and the second organization has an access profile associated with the first security domain.
HIPAA-compliant activity logging and transfer or prevention based on roles, caseloads, and type
Logging in an activity log the user's first request for authorization and determining whether the user is authorized based on at least the access profile, the one or more caseloads and the one or more roles associated with the user and the type of service and budget information in the second organization; responsive to an authorization determination, transferring the service and budget information in compliance with HIPAA and logging the transferring in compliance with HIPAA, and responsive to a non-authorization determination preventing the requested access in compliance with HIPAA.
Service plan monitoring and forecasting using received services and billing information
Receiving information pertaining to services provided to the one or more individuals by the first organization and billing information generated by the first organization pertaining to the provided services, wherein the information pertaining to services permits the user to monitor the service plan for achieving the individual's goals and the individual's progress toward outcomes and to forecast future needs.
HIPAA-compliant computer security system configured with receiving, logging, determining, transferring, and preventing
A HIPAA-compliant computer security system for sharing service, budget, and billing information associated with personal health information of one or more individuals among at least a first organization and a second organization in an integrated manner, and preventing unauthorized access to the billing information, comprising means for receiving a first request for authorization, means for logging the request in an activity log, means for determining authorization based on access profile, roles, and caseloads, means for responding by transferring in compliance with HIPAA and logging transferring in compliance with HIPAA or preventing requested access in compliance with HIPAA, and means for receiving service and billing information for monitoring and forecasting.
System authorization determination based on access profile, roles, caseloads, and type
Means for determining whether the user in the first organization is authorized to access service and budget information in the second organization, wherein the determination is based on at least the access profile, the one or more caseloads and the one or more roles associated with the user and the type of service and budget information in the second organization pertaining to the one or more individuals and associated with the individual's personal health information.
Across both independent claims, the claim coverage centers on an integrated, HIPAA-compliant sharing framework that uses security domains and an access profile tied to roles and caseloads to authorize transfer of service and budget information with HIPAA-compliant activity logging or to prevent unauthorized access. Both independent claims further include receiving service and billing information from the first organization to support monitoring the service plan and progress toward outcomes and to forecast future needs.
Stated Advantages
Permits the user to monitor the service plan for achieving the individual's goals and the individual's progress toward outcomes.
Permits the user to forecast future needs.
Prevents unauthorized access to the billing information in compliance with HIPAA.
Documented Applications
No documented applications found
Interested in licensing this patent?