/Dynamic Access Control To Electronic Patient Records
Abstract

Systems and methods herein provide for access control to information in electronic patient records. One method includes receiving a request from an entity for access to one or more of a plurality of electronic patient records, the records having been machine learned to identify patient information in the electronic patient records including personally identifiable information and protected health information. The method also includes determining a level of access of the entity, retrieving, from a database, the one or more electronic patient records requested by the entity, applying a rule to the retrieved one or more electronic patient records based on the determined level of access of the entity to mask, encrypt, show, etc. one or more elements in the one or more electronic patient records. In response to applying the rule to the retrieved one or more electronic patient records, the electronic patient records are transferred to the entity.

Full Text

What is claimed is:

Systems and methods herein provide for access control to information in electronic patient records. One method includes receiving a request from an entity for access to one or more of a plurality of electronic patient records, the records having been machine learned to identify patient information in the electronic patient records including personally identifiable information and protected health information. The method also includes determining a level of access of the entity, retrieving, from a database, the one or more electronic patient records requested by the entity, applying a rule to the retrieved one or more electronic patient records based on the determined level of access of the entity to mask, encrypt, show, etc. one or more elements in the one or more electronic patient records. In response to applying the rule to the retrieved one or more electronic patient records, the electronic patient records are transferred to the entity.
Timeline
Filed
03/24/2026
Published
07/23/2026
Granted
Not Available
IPC Codes(4)
G06F 21/62:Protecting access to data via a platform, e.g. using keys or access control rules
G16H 10/60:for patient-specific data, e.g. for electronic patient records
G16H 50/20:for computer-aided diagnosis, e.g. based on medical expert systems