Methods for remotely accessing electronic medical records without having prior authorization
Abstract
Methods are provided for allowing patients, health care practitioners and other service providers to have remote access to electronic medical records of a patient stored on a first computer network by the remote user requesting access to the electronic medical record from a second computer network and providing a first and second piece of patient derived information to the second computer network; the second computer network transferring the first and second piece of patient derived information to a third computer network; the third computer network authorizing the remote user through the first and second piece of patient derived information and dependent on a patient specific authorization protocol; the third computer network confirming a patient specific consent protocol; and the third computer network disclosing the electronic medical record to the remote user dependent upon an authorization and a confirmation received from the third computer network.
Claims
exact text as granted — not AI-modified1 - 19 . (canceled)
20 . A method for allowing a user to have access to an electronic medical record information of a patient stored on a first computer linked to a network wherein the user is not authenticated or authorized to receive the electronic medical record information from the first computer, the method comprising;
(a) the user requests disclosure of the electronic medical record information from a second computer linked to the network, the second computer enabled to control disclosure of the electronic medical record information from the first computer, wherein the user provides a set of patient information to the second computer, and the user provides a set of user information to the second computer; (b) the second computer authenticates the set of patient information and where the set of patient information is authenticated, the second computer transfers at least one piece of patient information selected from the set of patient information and the set of user information to a third computer connected to the network; (c) the third computer accepting the at least one piece of patient information selected from the set of patient information and the set of user information and based on a patient-specific consent policy known to the third computer, and where the at least one piece of patient information is validated, the third computer transfers an authorization signal to the second computer; (d) upon receipt of the authorization signal from the third computer, the second computer exchanges credentials with the first computer and requests the first computer to disclose the electronic medical record information to the second computer: (e) the first computer discloses the electronic medical record information to the second computer; and (f) the second computer discloses the electronic medical record information to the user.
21 . The method of claim 20 wherein the set of patient information comprises at least a first and second piece of patient information, the first and second piece of patient information selected from the group consisting of a patient specific identification number and a patient specific passphrase.
22 . The method of claim 21 wherein the patient-specific consent policy is based on predetermined patient consent criteria expressed through patient specific consent policy rules.
23 . The method of claim 22 wherein the patient specific consent policy rules are determined by the patient prior to step (a) in claim 1 .
24 . A method for allowing a user to have access to an electronic medical record information of a patient stored on a first computer linked to a network wherein the user is not authenticated or authorized to receive the electronic medical record information from the first computer, the method comprising;
(a) the user requests disclosure of the electronic medical record information from a second computer linked to the network, the second computer enabled to control disclosure of the electronic medical record information from the first computer, wherein the user provides a set of patient information to the second computer, and the user provides a set of user information to the second computer; (b) the second computer authenticates the set of patient information and where the set of patient information is authenticated, the second computer transfers at least one piece of patient information selected from the set of patient information and the set of user information to a third computer connected to the network; (c) the third computer accepting the at least one piece of patient information selected from the set of patient information and the set of user information and based on a patient-specific consent policy known to the third computer, and where the at least one piece of patient information is validated, the third computer transfers an authorization signal to the second computer; (d) upon receipt of the authorization signal from the third computer, the second computer exchanges credentials with the first computer and requests the first computer to disclose the electronic medical record information to the user; and (e) the first computer discloses the electronic medical record information to the user.
25 . The method of claim 24 wherein the set of patient information comprises at least a first and second piece of patient information, the first and second piece of patient information selected from the group consisting of a patient specific identification number and a patient specific passphrase.
26 . The method of claim 25 wherein the patient-specific consent policy is based on predetermined patient consent criteria expressed through patient specific consent policy rules.
27 . The method of claim 26 wherein the patient specific consent policy rules are determined by the patient prior to step (a) in claim 10 .
28 . A method for allowing a user to have access to an electronic medical record information of a patient stored on a first computer linked to a network wherein the user is not authenticated or authorized to receive the electronic medical record information from the first computer, the method comprising;
(a) the user requests disclosure of the electronic medical record information from a second computer linked to the network, the second computer enabled to control disclosure of the electronic medical record information from the first computer, wherein the user provides at least one piece of patient information to the second computer and the user provides a set of user information to the second computer; (b) the second computer transfers at least one piece of user information selected from the set of user information to a third computer connected to the network; (c) the third computer accepts and identifies the at least one piece of user information, and dependant on a user authentication protocol known to the third computer, and where the at least one piece of user information is authenticated, transfers a user authentication signal to the second computer, the second computer accepting the authentication signal transfers the at least one piece of patient information and at least one piece of user information selected from the set of user information to a fourth computer connected to the network (d) the fourth computer accepting the at least one piece of patient information and at least one piece of user information and based on a patient-specific consent policy known to the fourth computer, and where the at least one piece of patient information and the at least one piece of user information is validated, the fourth computer transfers an authorization signal to the second computer; (e) upon receipt of the authorization signal from the fourth computer the second computer exchanges credentials with the first computer and requests the first computer to disclose the electronic medical record information to the second computer; (f) the first computer discloses the electronic medical record information to the second computer; and (g) the second computer discloses the electronic medical record information to the user.
29 . The method of claim 28 wherein the at least one piece of patient information is a patient specific identification number.
30 . The method of claim 29 wherein the at least one piece of user information is selected from the group consisting of a user identification number, a user name, department, Purpose of Use and a user location.
31 . The method of claim 30 wherein the patient-specific consent policy is based on predetermined patient consent criteria expressed through patient specific consent policy rules.
32 . The method of claim 31 wherein the predetermined patient consent criteria rules are determined by the patient prior to step (a) in claim 9 .
33 . The method of claim 32 wherein the third computer is a user authentication service.
34 . An electronic medical record access system for allowing a user to have access to an electronic medical record information of a patient wherein the user has not been previously authenticated or authorized by the electronic medical record access system, the system comprising;
(a) a first, second and third computer connected to a network; (b) the first computer storing the electronic medical record information; (c) the second computer connected to the first and third computer and accessible by the user to allow the user to request disclosure of the electronic medical record information by providing a set of patient information, and by providing a set of user information, wherein the second computer authenticating the set of patient information and where the set of patient information is authenticated, the second computer transferring at least one piece of patient information to the third computer, (d) the third computer accepting and validating the at least one piece of patient information from the set of patient information and set of user information and based on a patient-specific consent policy known to the third computer and where the at least one piece of patient information is validated, the third computer transfers an authorization signal to the second computer.
and upon receiving an authorization signal from the third computer, exchanging credentials with the first computer, the second computer requesting said electronic medical record information from the first computer and the second computer disclosing the requested electronic medical record information to the user;
35 . A method for allowing a user to have access to an electronic medical record information of a patient stored on a first computer linked to a network wherein the user is not authenticated or authorized to receive the electronic medical record information from the first computer, the method comprising;
(a) the user requests disclosure of the electronic medical record information from a second computer linked to the network, the second computer enabled to control disclosure of the electronic medical record information from the first computer, wherein the user provides a set of patient information to the second computer, and the user provides a set of user information to the second computer; (b) the second computer transfers the at least one piece of user information from the set of user information to a fourth computer connected to the network; (c) the fourth computer accepts the at least one piece of user information and dependant on a user authentication protocol known to the fourth computer, and where the at least one piece of user information is authenticated, transfers a user authentication signal to the second computer, the second computer accepting the authentication signal transfers the at least one piece of patient information from the set of patient information and the set of user information to a third computer connected to the network (d) the third computer accepting and validating the at least one piece of patient information from the set of patient information and the set of user information and based on a patient-specific consent policy known to the third computer, and where the at least one piece of patient information is validated, the third computer transfers an authorization signal to the second computer; (e) upon receipt of the authorization signal from the third computer the second computer exchanges credentials with the first computer and requests the first computer to disclose the electronic medical record information to the user; and (f) the first computer discloses the electronic medical record information to the user.
36 . A method for allowing a user to have access to an electronic medical record information of a patient stored on a first computer linked to a network wherein the first user is not authenticated or authorized to receive the electronic medical record information from the first computer, the method comprising;
(a) the user requests disclosure of the electronic medical record information from a second computer linked to the network, the second computer enabled to control disclosure of the electronic medical record information from the first computer, wherein the user provides one piece of patient information to the second computer and the user provides a set of user information to the second computer; (b) the second computer requests user authentication through an authentication service, the user then provides at least one piece of user information selected from the set of user information and the one piece of patient information to the authentication service; (c) the authentication service accepts the at least one piece of user information, and dependant on an interactive user authentication protocol known to the authentication service, and where the at least one piece of user information is authenticated, provides a user authentication token to the user, the user inputting the user authentication token into the second computer, the second computer accepting the user authentication token transfers the one piece of patient information and at least one piece of user information selected from the set of user information to a third computer connected to the network; (d) the third computer accepting the one piece of patient information and the at least one piece of user information from the set of user information and based on a patient-specific consent policy known to the third computer, and where the one piece of patient information and the at least one piece of user information are validated, the third computer transfers an authorization signal to the second computer; (e) upon receipt of the authorization signal from the third computer the second computer exchanges credentials with the first computer and requests the first computer to disclose the electronic medical record information to the second computer; (f) the first computer discloses the electronic medical record information to the second computer; and (g) the second computer discloses the electronic medical record information to the user.
37 . A method for allowing a first user to have access to an electronic medical record information of a patient stored on a first computer linked to a network wherein the first user is not authenticated or authorized to receive the electronic medical record information from the first computer, the method comprising;
(a) the user requests disclosure of the electronic medical record information from a second computer linked to the network, the second computer enabled to control disclosure of the electronic medical record information from the first computer, wherein the user provides at least one piece of patient information to the second computer and the user provides a set of user information to the second computer; (b) the second computer requests user authentication through an authentication service, the user then provides at least one piece of user information selected from the set of user information and the one piece of patient information to the authentication service; (c) the authentication service accepts the at least one piece of user information, and dependant on an interactive user authentication protocol known to the authentication service, and where the at least one piece of user information is authenticated, provides a user authentication token to the user, the user inputting the user authentication token into the second computer, the second computer accepting the user authentication token transfers the at least one piece of patient information and at least one piece of user information selected from the set of user information to a third computer connected to the network (d) the third computer accepting the one piece of patient information and the at least one piece of user information from the set of user information and based on a patient-specific consent policy known to the third computer, and where the one piece of patient information and the at least one piece of user information are validated, the third computer transfers an authorization signal to the second computer; (e) upon receipt of the authorization signal from the third computer the second computer exchanges credentials with the first computer and requests the first computer to disclose the electronic medical record information to the user; and (f) the first computer discloses the electronic medical record information to the user.Join the waitlist — get patent alerts
Track US2015161328A1 — get alerts on status changes and closely related new filings.
We store only your email — no account needed. See our privacy policy.