US 11,720,704 B1
System and method for authenticating access to private health information
Jonathan Clark, Tolland, CT (US); and Steven J. Mastrianni, Colchester, CT (US)
Assigned to Cigna Intellectual Property, Inc., Wilmington, DE (US)
Filed by Cigna Intellectual Property, Inc., Wilmington, DE (US)
Filed on Sep. 1, 2020, as Appl. No. 17/9,409.
Int. Cl. H04L 9/08 (2006.01); G06F 21/62 (2013.01); H04L 9/40 (2022.01); G10L 17/22 (2013.01); G16H 10/60 (2018.01)
CPC G06F 21/6245 (2013.01) [G10L 17/22 (2013.01); G16H 10/60 (2018.01); H04L 63/083 (2013.01); H04L 63/0853 (2013.01); H04L 63/0861 (2013.01); H04L 63/102 (2013.01)] 22 Claims
OG exemplary drawing
 
1. A method comprising:
responsive to a first device receiving a spoken initiation of a retrieval of private health information (PHI), receiving a converted version of the spoken initiation at a second device that is different and separate from the first device;
requesting out-of-band authentication information from a user via the second device responsive to receiving the converted version of the spoken initiation, the out-of-band authentication information that is requested containing different information than the spoken initiation of the retrieval of the PHI;
determining whether the out-of-band authentication information received from the user at the second device satisfies an authentication criterium associated with the user;
obtaining the PHI requested by the user via the spoken initiation provided to the first device responsive to the out-of-band authentication information satisfying the authentication criterium;
presenting the PHI requested by the user via the first device; and
further comprising:
receiving user limitations that restrict the PHI that is presented via the first device, the user limitations including one more of a user-configurable time period over which the PHI is permitted to be presented via the first device, a user-defined category of the PHI that is permitted to be presented via the first device, a user-defined date range that restricts the PHI that is presented via the first device to the PHI that was obtained over the user-defined date range, a user-identified provider identification that restricts the PHI that is presented via the first device to the PHI provided by a provider associated with the user-identified provider identification, or a user-identified type of benefit claim that restricts the PHI that is permitted to be presented via the first device to the user-identified type of benefit claim.