USRE50117EActiveUtility

System and method for providing multi-layered access control

Assignee: IQVIA INCPriority: Aug 19, 2015Filed: Jul 28, 2022Granted: Sep 10, 2024
Est. expiryAug 19, 2035(~9.1 yrs left)· nominal 20-yr term from priority
G06F 2221/032H04L 63/105G06F 2221/2141H04L 63/102G16H 10/60G06F 21/6245G06F 21/6227
57
PatentIndex Score
0
Cited by
49
References
20
Claims

Abstract

A method and system to provide multi-layered access control for healthcare datasets are disclosed. The method comprises defining an information policy for each of healthcare datasets, wherein the information policy comprises information access permissions. Further, an organization policy is defined for each of the healthcare datasets, wherein the organization policy comprises license permissions for organizations accessing the healthcare datasets. Thereafter, a user account master policy is defined for each of the healthcare datasets, wherein the user account master policy comprises account permissions assigned to users of the organizations. Subsequently, a master user policy is generated for each of the users based on the information policy, the organization policy, the user account master policy, or a combination thereof, wherein the master user policy comprises access control permissions to provide each of the users access to the healthcare datasets.

Claims

exact text as granted — not AI-modified
What is claimed is: 
     
       1. A computer-implemented method to provide permissions for users from different organizations to access health information of cohort members while assuring privacy and security of the cohort members' health information deposited in a plurality of datasets having different commercial owners who control the access to the datasets they own, wherein the access is achieved via computing devices having a hardware processor communicatively connected to the plurality of datasets via a network, the method comprising the steps of:
 defining, by the processor,
 an information policy including permissions set by the different commercial owners of each of the plurality of datasets for access to the health information and granularity of the health information in each of the plurality of the datasets, 
 an organization policy including permissions derived from a plurality of licenses subscribed to by the respective organizations for accessing each of the plurality of datasets, and 
 a user policy including account permissions selectively assigned to the users from each of the different organizations; 
 
 generating a master policy having access control permissions for access to each of the plurality of datasets for each of the users from each of the different organizations, wherein the master policy comprises for one or more users of an organization based on the information policy, an organization policy, and the a user policy; and 
 in response to a request from the computing device of the users: 
 controlling, by the processor, access to the health information of the cohort members in the plurality of datasets based on the access control permissions of the master policy. 
 
     
     
       2. The method of  claim 1 , further comprising a step of: defining, by the processor, an administrator policy including permissions to control at least one of the information policy, the user policy, and the organization policy. 
     
     
       3. The method of claim  2   1 , wherein the administrator policy, the information policy, access permissions defined in the information policy are restricted by a license and/or subscription defined in the organization policy, and the user policy have a hierarchical architecture. 
     
     
       4. The method of claim  3   1 , wherein each of the plurality of licenses is restricted by the information policy, and the user policy is restricted by the information policy and the license permits access to a subset of the datasets. 
     
     
       5. The method of  claim 1 , further comprising a step of: blocking, by the processor, the users from querying, via their respective computing device, the plurality of datasets based on the generated access control permissions defining one or more license permissions for the organization to access the plurality of datasets. 
     
     
       6. The method of  claim 1 , wherein the organization policy inherits permission to access one or more of the datasets from the information policy further comprises at least one of a permission to explore meta-data, a permission to query data for aggregated results, a permission to query sensitive attributes, a permission to set protocol-based permissions, a permission to extract patient level data, and a permission to extract sensitive attributes. 
     
     
       7. The method of  claim 1 , wherein each of the plurality of licenses comprises at least one of a permission to set a user account, a permission to set access restrictions, a permission to set access period, a permission to define refresh periods, a permission to define user limits, and a permission to define access tools further comprising:
 permitting only a subset of the datasets to be accessed based on the master policy. 
 
     
     
       8. A system computer program product to provide permissions for users from different organizations to access health information of cohort members while assuring privacy and security of the cohort members' health information deposited in a plurality of datasets having different commercial owners who control the access to the datasets they own, wherein the access is achieved via computing devices having a hardware processor communicatively connected to the plurality of datasets via a network, the system comprising the computer program product comprising a tangible storage medium encoded with processor-readable instructions that, when executed by one or more processors, enable the computer program product to:
 the processor configured to: 
 define
 an information policy including permissions set by the different commercial owners of each of the plurality of datasets for access to the health information and granularity limits of the health information in each of the plurality of the datasets, 
 an organization policy including permissions derived from a plurality of licenses subscribed to by the respective organizations for accessing each of the plurality of datasets, and 
 a user policy including account permissions selectively assigned to the users from each of the different organizations; 
 
 generate a master policy having access control permissions for access to each of the plurality of datasets for each of the users from each of the different organizations, wherein the master policy comprises for one or more users of an organization based on the information policy, an organization policy, and the a user policy; and 
 in response to a request from the computing device of the users: 
 control access to the health information of the cohort members in the plurality of datasets based on the access control permissions of the master policy of the master policy. 
 
     
     
       9. The system computer program product of  claim 8 , wherein the processor is further configured to define an administrator policy including permissions to control the information policy, and the organization policy information policy includes one or more access permissions for one or more of the plurality of datasets. 
     
     
       10. The system computer program product of claim  9   8 , wherein the administrator policy, the information policy, the organization policy, and the user policy have a hierarchical architecture permits access to only a subset of the datasets. 
     
     
       11. The system computer program product of claim  10   8 , wherein each of the plurality of licenses is restricted by the information policy, and the user policy is restricted by the information policy and the license license controllers define one or more license permissions for the organization to access one or more of the datasets. 
     
     
       12. The system computer program product of  claim 8 , wherein the processor is further configured to block the users from querying, via their respective computing device, the plurality of datasets based on the generated access control permissions user policy provides restricted access for the one or more users of the organization to one or more of the datasets. 
     
     
       13. The system computer program product of  claim 8 , wherein the information policy further comprises at least one of a permission to explore meta-data, a permission to query data for aggregated results, a permission to query sensitive attributes, a permission to set protocol-based permissions, a permission to extract patient level data, and a permission to extract sensitive attributes user policy prevents the one or more users of the organization from access to one or more analytical tools to use on the datasets. 
     
     
       14. The system computer program product of  claim 8 , wherein each of the plurality of licenses comprises at least one of a permission to set a user account, a permission to set access restrictions, a permission to set access period, a permission to define refresh periods, a permission to define user limits, and a permission to define access tools the master policy defines access for one or more administrators to the datasets. 
     
     
       15. A method computer system connected to a network to provide permissions for users from different organizations to access health information of cohort members while assuring privacy and security of the cohort members' health information is deposited in a plurality of datasets having different commercial owners who control the access to the datasets they own, wherein the access is achieved via computing devices having a hardware processor communicatively connected to the plurality of datasets via a network, the method comprising the steps of the system comprising:
 one or more processors configured to:  
 defining, by the processor,define  an information policy including permissions set by the different commercial owners of each of the plurality of datasets for access to the health information and granularity of the health information in each of the plurality of the datasets;   an organization policy including permissions derived from a plurality of licenses subscribed to by the respective organizations for accessing each of the plurality of datasets;   a user policy including account permissions selectively assigned to the users from each of the different organizations;   
 generating generate a master policy having access control permissions for access to the plurality of datasets for each of the users from each of the different organizations, wherein the master policy comprises for one or more users of an organization based on the information policy, an organization policy, and the a user policy; 
 defining, by the processor, an administrator policy including permissions for control of the information policy, and the organization policy; and 
 in response to a request from the computing device of the users: 
 controlling, by the processor, control access to the health information of the cohort members in the plurality of datasets based on the access control permissions of the master policy. 
 
     
     
       16. The method system of  claim 15 , further comprising a step of blocking, by the processor, the users from querying, via their respective computing device, the plurality of datasets based on the generated access control permissions wherein the information policy includes access permissions to the datasets requested by one or more dataset owners. 
     
     
       17. The method system of  claim 15 , wherein the administrator policy, organization policy inherits permissions from the information policy, and the user policy have a hierarchical architecture. 
     
     
       18. The system of  claim 15 , wherein the user policy includes one or more account permissions for each of the one or more users of the organization to access the datasets.  
     
     
       19. The system of  claim 15 , wherein the information policy and the organization policy have a hierarchical architecture.  
     
     
       20. The system of  claim 15 , wherein the master policy includes one or more access control permissions for the datasets.

Join the waitlist — get patent alerts

Track USRE50117E — get alerts on status changes and closely related new filings.

We store only your email — no account needed. See our privacy policy.