Permission monitoring and data exchange
Abstract
A method may include providing a user with one or more questions regarding permissions for use of personal data related to the user, and compiling the permissions for the use of the personal data. The method may also include receiving a request from a third party for access to the personal data, and providing a response to the third party based on the compiled permissions. The method may also include, based on the response indicating that the third party is permitted access to the personal data, sending a responsive dataset to a data holder, where the responsive dataset is responsive to the request from the third party. The method may also include facilitating the third party accessing the personal data.
Claims
exact text as granted — not AI-modifiedWhat is claimed is:
1 . A method, comprising:
generating a plurality of questions for a user, each of the plurality of questions including multiple facets of permissions regarding use of personal data related to the user; sequentially providing at least two questions of the plurality of questions to the user, the at least two questions covering at least what entities are permitted access to the personal data and for what purposes the personal data can be used; compiling answers provided by the user to the at least two of the plurality of questions to generate compiled permissions by a consent server; receiving a request from a third party for access to the personal data of the user for a given purpose, the personal data being stored by a data holder and not stored by the consent server when the request is received; and providing a response to the third party based on the compiled permissions and the request.
2 . The method of claim 1 , wherein the at least two questions are binary questions such that the user is able to respond with a single affirmative or negative response.
3 . The method of claim 1 , wherein the at least two questions are multi-modal such that each individual questions addresses at least two instances of a combination of what entities are permitted access to the personal data and for what purposes the personal data can be used.
4 . The method of claim 1 , wherein the generating and sequentially providing questions is repeated until a series of entries related to a combination of what entities are permitted access to the personal data and for what purposes the personal data can be used are filled for the user.
5 . The method of claim 1 , wherein the plurality of questions further include separate categories of personal data.
6 . The method of claim 1 , wherein the consent server stores a limited version of demographic information of the user.
7 . The method of claim 6 , wherein the limited version of the demographic information is limited to age, gender, name, address, and telephone number.
8 . The method of claim 1 , wherein the entities of one of the at least two questions includes both a named entity and partners of the named entity.
9 . The method of claim 8 , wherein the named entity includes at least one of a clinic, medical office, or hospital and the partners of the named entity include at least one of a laboratory, a vendor, a service provider, a medical office referring to the named entity, or a medical office referring from the named entity.
10 . One or more non-transitory computer-readable media containing instructions that, when executed by one or more processors, cause a system to perform operations, the operations comprising:
generating a plurality of questions for a user, each of the plurality of questions including multiple facets of permissions regarding use of personal data related to the user; sequentially providing at least two questions of the plurality of questions to the user, the at least two questions covering at least what entities are permitted access to the personal data and for what purposes the personal data can be used; compiling answers provided by the user to the at least two of the plurality of questions to generate compiled permissions by a consent server; receiving a request from a third party for access to the personal data of the user for a given purpose, the personal data being stored by a data holder and not stored by the consent server when the request is received; and providing a response to the third party based on the compiled permissions and the request.
11 . The computer-readable media of claim 10 , wherein the at least two questions are binary questions such that the user is able to respond with a single affirmative or negative response.
12 . The computer-readable media of claim 10 , wherein the at least two questions are multi-modal such that each individual questions addresses at least two instances of a combination of what entities are permitted access to the personal data and for what purposes the personal data can be used.
13 . The computer-readable media of claim 10 , wherein the generating and sequentially providing questions is repeated until a series of entries related to a combination of what entities are permitted access to the personal data and for what purposes the personal data can be used are filled for the user.
14 . The computer-readable media of claim 10 , wherein the plurality of questions further include separate categories of personal data.
15 . The computer-readable media of claim 10 , wherein the consent server stores a limited version of demographic information of the user.
16 . The computer-readable media of claim 15 , wherein the limited version of the demographic information is limited to age, gender, name, address, and telephone number.
17 . The computer-readable media of claim 10 , wherein the entities of one of the at least two questions includes both a named entity and partners of the named entity.
18 . The computer-readable media of claim 17 , wherein the named entity includes at least one of a clinic, medical office, or hospital and the partners of the named entity include at least one of a laboratory, a vendor, a service provider, a medical office referring to the named entity, or a medical office referring from the named entity.
19 . A consent server, comprising:
one or more processors; and one or more non-transitory computer-readable media containing instructions that, when executed by the one or more processors, cause the consent server to perform operations, the operations comprising:
generating a plurality of questions for a user, each of the plurality of questions including multiple facets of permissions regarding use of personal data related to the user;
sequentially providing at least two questions of the plurality of questions to the user, the at least two questions covering at least what entities are permitted access to the personal data and for what purposes the personal data can be used;
compiling answers provided by the user to the at least two of the plurality of questions to generate compiled permissions;
receiving a request from a third party for access to the personal data of the user for a given purpose, the personal data being stored by a data holder and not stored by the consent server when the request is received; and
providing a response to the third party based on the compiled permissions and the request.
20 . The system of claim 19 , wherein the generating and sequentially providing questions is repeated until a series of entries related to a combination of what entities are permitted access to the personal data and for what purposes the personal data can be used are filled for the user.Join the waitlist — get patent alerts
Track US2023359763A1 — get alerts on status changes and closely related new filings.
We store only your email — no account needed. See our privacy policy.