Managing secure sharing of private information across security domains using multiple caseloads

Inventors

Robbins, Richard Allen • Gifford, Warren Stanton • Hassnat, Mojahedul Hoque Abul • Turock, Bradley Drew • Brockie, Justin Mark • Kelly, James Michael • Rahman, Ziaur

Assignees

Therap Services LLC

Interested in licensing this patent?

MTEC can help explore whether this patent might be available for licensing for your application.

Publication Number

US-8615790-B2

Patent

Publication Date

2013-12-24

Expiration Date


Abstract

In a method of granting a user in a first organization access to private information stored within an authorization profile of a second organization, an access agreement between the two organizations is formed. Authorization is requested for the user, the authorization profile is retrieved, and authorization to private information is granted if authorized by the access agreement.In a method of authorizing access by users to private information stored by an organization as associated with a program, three types of caseloads are defined. The first authorizes access to information of a first individual of a first program, the second authorizes access to information of a second individual of all programs, and the third authorizes access to information of all individuals of a second program.Authorization is requested for the user to access one or more of the caseloads, and access to one or more caseloads is granted to the user.

Core Innovation

The invention provides a method of authorizing access by users to information stored by an organization that is associated with at least one program and at least one security domain. It defines access-privilege caseloads tied to security domains for an individual and a medical services program, and also caseloads associated with combinations of security domains and programs. The method requests authorization from the organization for the user to access one or more of the caseloads using the access privilege information associated with those caseloads and the personal health information of the individuals.

The invention further includes logging by one or more physical nodes of the authorization request in an activity log associated with at least one of the medical services programs. The physical nodes determine whether the user is authorized to access the privilege information associated with the one or more caseloads, wherein the determination is based on at least the caseloads and the personal health information of the individuals. Access is granted to the user to one or more of the caseloads when the determination indicates authorization.

In parallel, the invention covers authorizing access to at least one database of information stored by an organization that is associated with at least one program and at least one security domain. It defines caseloads containing access privilege information associated with respective security domains for databases of a first program and a second program, and also defines caseloads associated with combinations of security domains and programs. After requesting authorization and logging the authorization request in an activity log, the physical nodes determine authorization based on the caseloads and the personal health information, and then grant access to the user for the one or more caseloads.

Claims Coverage

The partial content includes two independent claims centered on user access authorization using access-privilege caseloads associated with security domains and their combination, with authorization requests logged and authorization determined based on caseloads and personal health information.

Caseload definitions tied to security domains and programs

Defining caseloads as including access privilege information associated with security domains for individuals or medical services programs, and defining caseloads associated with combinations of security domains and programs.

Authorization request and activity log recording

Requesting authorization from the organization for the user to access one or more caseloads, and logging by one or more physical nodes, in an activity log associated with at least one medical services program or database of information, the request for authorization.

Authorization determination based on caseloads and personal health information

Determining by the one or more physical nodes whether the user is authorized to access the privilege information associated with one or more caseloads, wherein the determination is based on at least the one or more caseloads and the personal health information of the one or more individuals in the organization, and granting access to the user.

Database access authorization with logged requests

Defining caseloads as including access privilege information associated with security domains for databases of a first program and a second program, requesting authorization to access one or more of the caseloads, logging the request, determining whether the user is authorized to access one or more databases of information associated with the caseloads, and granting access to the user.

Across both independent claims, the claim coverage emphasizes caseload-based authorization where privilege information is structured by security domains and by programs, authorization requests are logged by physical nodes, authorization is determined using caseloads and personal health information, and access is then granted to the user.

Stated Advantages

Not explicitly described in patent.

Documented Applications

Not explicitly described in patent.

JOIN OUR MAILING LIST

Stay Connected with MTEC

Keep up with active and upcoming solicitations, MTEC news and other valuable information.