| CPC G06F 21/6245 (2013.01) | 20 Claims |

|
1. A method for managing access to privately held health information, the method comprising:
obtaining a request for medical data for a patient, the medical data being part of the privately held health information;
in response to obtaining the request:
identifying a patient device that is designated by the patient;
performing a first consent resolution action with the patient device to attempt to gain a first authorization to disclose the medical data;
in a first instance of the first consent resolution action where the first authorization to disclose the medical data was not obtained:
identifying a verified designee device that is designated by the patient;
performing a second consent resolution action with the verified designee device to attempt to gain a second authorization to disclose the medical data;
in a first instance of the second consent resolution action where the second authorization to disclose the medical data was not obtained:
identifying a verified provider designee device that is designated by the patient;
performing a third consent resolution action with the verified provider designee device to attempt to gain a third authorization to disclose the medical data; and
in a first instance of the third consent resolution action where the third authorization to disclose the medical data was not obtained:
denying access to the medical data to service the request; and
in a second instance of the third consent resolution action where the third authorization to disclose the medical data was obtained:
providing the medical data to service the request.
|