Multi-source longitudinal patient-level data encryption process
First Claim
1. A process for assembling a longitudinally-linked database from individual patient healthcare transaction data records, the process comprising the steps of:
- at a data supplier location, (a) acquiring data records having patient-identifying attributes and non-identifying attributes;
(b) encrypting the patient-identifying attributes in the data records using a first encryption key specific to a central facility (LDF);
(c) encrypting the patient-identifying attributes in the data records encrypted at step b with a second encryption key specific to the data supplier location;
at the LDF, (d) receiving the data records that have been encrypted at steps (b) and (c) (e) partially decrypting the received data records so that the patient-identifying attributes retain only the step (b) encryption by the first encryption key specific to the LDF;
(f) using an attribute-matching algorithm to assign an LDF identifier (ID) to the encrypted data records. (g) linking the encrypted data records ID by ID, whereby the longitudinally-linked data base is formed.
7 Assignments
0 Petitions
Accused Products
Abstract
Systems and processes for assembling de-identified patient healthcare data records in a longitudinal database are provided. The systems and processes may be implemented over multiple data suppliers and common database facilities while ensuring patient privacy. At the data supplier locations, patient-identifying attributes in the data records are placed in standard format and then doubly encrypted using a pair of encryption keys before transmission to a common database facility. The pair of encryption keys includes a key specific to the data supplier and a key specific to the common database facility. At the common database facility, the encryption specific to the data supplier is removed, so that multi-sourced data records have only the common database encryption. Without direct access to patient identifying-information, the encrypted data records are assigned dummy labels or tags by which the data records can be longitudinally linked in the database. The tags are assigned based on statistical matching of the values of a select set of encrypted data attributes with a reference database of tags and associated encrypted data attribute values.
-
Citations
24 Claims
-
1. A process for assembling a longitudinally-linked database from individual patient healthcare transaction data records, the process comprising the steps of:
-
at a data supplier location, (a) acquiring data records having patient-identifying attributes and non-identifying attributes;
(b) encrypting the patient-identifying attributes in the data records using a first encryption key specific to a central facility (LDF);
(c) encrypting the patient-identifying attributes in the data records encrypted at step b with a second encryption key specific to the data supplier location;
at the LDF, (d) receiving the data records that have been encrypted at steps (b) and (c) (e) partially decrypting the received data records so that the patient-identifying attributes retain only the step (b) encryption by the first encryption key specific to the LDF;
(f) using an attribute-matching algorithm to assign an LDF identifier (ID) to the encrypted data records. (g) linking the encrypted data records ID by ID, whereby the longitudinally-linked data base is formed. - View Dependent Claims (2, 3, 4, 5, 6, 7, 8, 9, 10, 11)
-
-
12. A system for longitudinally-linking individual patient healthcare transaction data records obtained from multiple data suppliers, the system comprising:
-
at a data supplier location, a first component configured to;
acquire data records having patient-identifying attributes and non-identifying attributes; and
doubly encrypt the patient-identifying attributes in the data records with a first encryption key specific to a central facility (LDF) and a second encryption key specific to the data supplier;
at the LDF, a second component configured to;
receive doubly-encrypted data records from the multiple data suppliers;
partially decrypt the received data records so that the patient-identifying attributes retain the encryption by the first encryption key specific to the LDF; and
perform an additional layer of encryption; and
a third component configured to;
assign an LDF identifier (ID) to the encrypted data records by matching attributes in the encrypted data records; and
link the encrypted data records ID by ID, whereby a longitudinal database is formed. - View Dependent Claims (13, 14, 15, 16, 17, 18, 19, 20, 21, 22)
-
-
23. A longitudinally-linked database assembled from individual patient healthcare transaction data records, the database comprising:
multi-sourced data records in which patient identifying attributes are encrypted to preserve patient privacy, wherein each encrypted data record is assigned an identifier based on a statistical match of a select set of data attributes with a reference set of values, and wherein the data records are linked by the assigned identifiers.
-
24. The longitudinally-linked database wherein the select set of data attributes comprises at least one of a patient'"'"'s date of birth, cardholder identification, record number, zip code, first name, last name, street address, and an industry standard patient identifier.
Specification