Privacy compliant consent and data access management system and methods
Abstract
An information management system for restricting access to personal data in compliance with law or regulation includes a database having restricted records stored therein, at least one of the records including an identification of a client or group of clients about whom said record concerns. A computer system under the control of a trusted information broker is configured to receive via a communication medium a request initiated by a requestor for access to at least one of the restricted records in the database, the request including an identification of the requestor. The computer system is further configured to transmit a request for consent to the client and receive an indication from the client that the client consents or does not consent to access to the restricted record by the requestor. The computer system grants or denies access to the restricted records based upon the indication from the client.
Claims
exact text as granted — not AI-modifiedThe embodiments of the invention in which an exclusive property or privilege is claimed are defined as follows:
1 . In a computer system comprising at least one database storing a plurality of restricted records, a method for securely storing data, the method comprising:
receiving, over a network, data captured in an electronic form at a client computer system, the data being associated with a first user; storing the received data in one or more restricted records of the plurality of restricted records, the one or more restricted records being associated with the first user; receiving, over a network, sensor data from a body monitoring sensor device associated with the first user; storing the received sensor data in the one or more of the restricted records associated with the first user; and storing a cryptographically-enforced association between the data stored in the one or more restricted records associated with the first user and the first user, the cryptographically-enforced association controlling access to the data stored in the one or more restricted records.
2 . The method of claim 1 , further comprising:
transmitting a request to permit access to the data for receipt by the first user, the request to permit access including identifications of categories of data in the one or more restricted records; receiving, from a computer system associated with the first user in response to the request to permit access, an indication of which of the categories of data to which access is permitted.
3 . The method of claim 2 , wherein the request to permit access to the data is transmitted in response to receiving a service request from a computer system associated with a second user for access to the data stored in the one or more restricted records associated with the first user.
4 . The method of claim 3 , wherein the second user is a service provider.
5 . The method of claim 2 , further comprising:
subsequently receiving a request from a computer system associated with a second user for access to the data stored in the one or more restricted records associated with the first user; and providing access to the data in accordance with the indication of the categories of data to which access is permitted.
6 . The method of claim 5 , wherein the second user is a service provider.
7 . The method of claim 1 , wherein storing the cryptographically-enforced association comprises encrypting the data stored in the one or more restricted records with a first encryption key with a second encryption key, and storing the encrypted first encryption key at the computer system with an identifier for the data.
8 . The method of claim 1 , wherein the body monitoring sensor device comprises a cardiovascular monitor.
9 . The method of claim 1 , wherein the body monitoring sensor device comprises a glucometer.
10 . The method of claim 1 , wherein the electronic form comprises a plurality of fields for capturing data, at least one field of the plurality of fields being identified as comprising private information.
11 . A non-transitory computer-readable medium storing code which, when executed by a computer system, causes the computer system to implement the method of:
receiving, over a network, data captured in an electronic form at a client computer system, the data being associated with a first user; storing the received data in one or more restricted records of the plurality of restricted records, the one or more restricted records being associated with the first user; receiving, over a network, sensor data from a body monitoring sensor device associated with the first user; storing the received sensor data in the one or more of the restricted records associated with the first user; and storing a cryptographically-enforced association between the data stored in the one or more restricted records associated with the first user and the first user, the cryptographically-enforced association controlling access to the data stored in the one or more restricted records.
12 . The non-transitory computer-readable medium of claim 11 , the method further comprising:
transmitting a request to permit access to the data for receipt by the first user, the request to permit access including identifications of categories of data in the one or more restricted records; receiving, from a computer system associated with the first user in response to the request to permit access, an indication of which of the categories of data to which access is permitted.
13 . The non-transitory computer-readable medium of claim 12 , wherein the request to permit access to the data is transmitted in response to receiving a service request from a computer system associated with a second user for access to the data stored in the one or more restricted records associated with the first user.
14 . The non-transitory computer-readable medium of claim 13 , wherein the second user is a service provider.
15 . The non-transitory computer-readable medium of claim 12 , the method further comprising:
subsequently receiving a request from a computer system associated with a second user for access to the data stored in the one or more restricted records associated with the first user; and providing access to the data in accordance with the indication of the categories of data to which access is permitted.
16 . The non-transitory computer-readable medium of claim 15 , wherein the second user is a service provider.
17 . The non-transitory computer-readable medium of claim 11 , wherein storing the cryptographically-enforced association comprises encrypting the data stored in the one or more restricted records with a first encryption key with a second encryption key, and storing the encrypted first encryption key at the computer system with an identifier for the data.
18 . The non-transitory computer-readable medium of claim 11 , wherein the body monitoring sensor device comprises a cardiovascular monitor.
19 . The non-transitory computer-readable medium of claim 11 , wherein the body monitoring sensor device comprises a glucometer.
20 . The non-transitory computer-readable medium of claim 11 , wherein the electronic form comprises a plurality of fields for capturing data, at least one field of the plurality of fields being identified as comprising private information.Join the waitlist — get patent alerts
Track US2016188805A1 — get alerts on status changes and closely related new filings.
We store only your email — no account needed. See our privacy policy.