Managing secure sharing of private information pertaining to abuse or neglect across security domains

Inventors

Robbins, Richard Allen • Gifford, Warren Stanton • Hassanat, Mojahedul Hoque Abul • Turock, Bradley Drew • Brockie, Justin Mark • Kelly, James Michael • Rahman, Zaiur

Assignees

Therap Services LLC

Interested in licensing this patent?

MTEC can help explore whether this patent might be available for licensing for your application.

Publication Number

US-8739253-B2

Patent

Publication Date

2014-05-27

Expiration Date


Abstract

A method of granting a user in a first organization access to private information stored within an authorization profile of a second organization, an access agreement between the two organizations is formed. Authorization is requested for the user, the authorization profile is retrieved, and authorization to private information pertaining to abuse or neglect is granted if authorized by the access agreement.In a method of authorizing access by users to private information pertaining to abuse or neglect stored by an organization as associated with a program, three types of caseloads are defined. The first authorizes access to information of a first individual of a first program, the second authorizes access to information of a second individual of all programs, and the third authorizes access to information of all individuals of a second program.

Core Innovation

The invention is directed to secure sharing of information pertaining to abuse or neglect among at least a first organization and a second organization associated with different security domains. The approach receives a first request for authorization for a user in the first organization to access one or more individuals’ information pertaining to abuse or neglect in the second organization, and the request includes an access profile, roles, caseloads, and types of the abuse-or-neglect-related information.

To control and audit access, the system logs the user’s first request for authorization in an activity log associated with at least the first organization or the second organization. It determines whether the user is authorized based on the access profile, the one or more caseloads, the one or more roles associated with the user, and the type of the one or more individuals’ information pertaining to abuse or neglect in the second organization. When authorization is determined, the system transfers the one or more individuals’ information pertaining to abuse or neglect from the second organization to the user in the first organization, and logs the transferring in the activity log.

The authorization request can include identifying information for the one or more individuals, including one or more of the individual’s name, social security number, state identification number, birth date, home address, and Medicaid number. In the broader described healthcare-oriented system, common individuals across domains are identified using multiple identifiers with tolerance for data errors, and regulated emergency access is provided via an emergency data form or role, with access tracked and audited via activity logs across domains.

Claims Coverage

Independent claim coverage is provided for a method, a non-transitory computer-readable storage media, and systems for secure sharing, with authorization and access control based on access profiles, roles, caseloads, and types of abuse-or-neglect-related information. Across the independent claims, the inventive features include receiving authorization requests, logging activity, determining accessibility and/or authorization using access profile and associated data, transferring authorized information, and logging transfers; certain variants additionally include a notification transmitted to the user.

Authorization request among security domains with access profile

Receiving by one or more physical nodes a first request for authorization for a user in a first organization to access one or more individual's information pertaining to abuse or neglect in a second organization, wherein the first organization is associated with a first security domain, the second organization is associated with a second security domain, the second organization has an access profile associated with the first security domain, the user is associated with one or more roles and one or more caseloads, and the first request for authorization includes one or more of the one or more individual's name, social security number, state identification number, birth date, home address, and Medicaid number.

Activity logging of authorization requests

Logging by the one or more physical nodes, in an activity log associated with at least the first organization or the second organization, the user's first request for authorization for the user in the first organization to access the individual's information pertaining to abuse or neglect in the second organization.

Authorization determination based on access profile, caseloads, roles, and information type

Determining by the one or more physical nodes whether the user in the first organization is authorized to access the one or more individual's information pertaining to abuse or neglect in the second organization, wherein the determination is based on at least the access profile, the one or more caseloads, the one or more roles associated with the user, and the type of the one or more individual's information pertaining to abuse or neglect in the second organization.

Transferring authorized abuse-or-neglect information with activity logging

Responsive to determining that the user in the first organization is authorized to access the one or more individual's information pertaining to abuse or neglect in the second organization: transferring by the one or more physical nodes the one or more individual's information pertaining to abuse or neglect in the second organization to the user in the first organization; and logging by the one or more physical nodes, in the activity log, the transferring.

Accessibility determination based on individual identifiers

Determining by the one or more physical nodes whether the one or more individual's information pertaining to abuse or neglect in the second organization is accessible based on one or more of the individual's name, social security number, state identification number, birth date, and Medicaid number.

Notification transmitted to user as part of transfer

Responsive to determining that the user in the first organization is authorized to access the one or more individual's information pertaining to abuse or neglect in the second organization: transferring the one or more individual's information to the user; and transmitting a notification to the user.

Notification endpoint constrained to pager

Transmitting a notification to the user, wherein the notification is transmitted to a pager.

Notification endpoint constrained to cell phone

Transmitting a notification to the user, wherein the notification is transmitted to a cell phone.

Across the independent claims, the core coverage centers on controlled secure sharing of abuse-or-neglect-related individual information between organizations in different security domains by receiving authorization requests, logging activity, determining accessibility and/or authorization using access profile, roles, caseloads, and information type, transferring authorized information, and logging the transfer. Some variants include a notification transmitted to the user during the transfer, with the notification destination constrained to a pager or a cell phone in dependent refinements.

Stated Advantages

Secure sharing of information pertaining to abuse or neglect between organizations associated with different security domains.

Logging of authorization requests and transferring of information in an activity log associated with the organizations.

Determination of whether a user is authorized to access the information based on an access profile, roles, caseloads, and the type of the information.

Providing controlled transfer only when authorized, with transfer activity logged.

Documented Applications

Healthcare-oriented secure inter- and intra-domain sharing of private information, including abuse-or-neglect-related individual information across organizations/security domains under regulations (HIPAA).

Regulated emergency access using an emergency data form or role for abuse-or-neglect-related information.

JOIN OUR MAILING LIST

Stay Connected with MTEC

Keep up with active and upcoming solicitations, MTEC news and other valuable information.