DETAILED ACTION
Notice of Pre-AIA or AIA Status
The present application, filed on or after March 16, 2013, is being examined under the first inventor to file provisions of the AIA .
Status of Claims
The following is a final office action.
Claims 1-20 are currently pending and have been examined on their merits.
Claims 1, 11, and 18 are currently amended see REMARKS April 27, 2026.
Claim Rejections - 35 USC § 103
In the event the determination of the status of the application as subject to AIA 35 U.S.C. 102 and 103 (or as subject to pre-AIA 35 U.S.C. 102 and 103) is incorrect, any correction of the statutory basis for the rejection will not be considered a new ground of rejection if the prior art relied upon, and the rationale supporting the rejection, would be the same under either status.
The following is a quotation of 35 U.S.C. 103 which forms the basis for all obviousness rejections set forth in this Office action:
(a) A patent may not be obtained though the invention is not identically disclosed or described as set forth in section 102, if the differences between the subject matter sought to be patented and the prior art are such that the subject matter as a whole would have been obvious before the effective filing date of the invention was made to a person having ordinary skill in the art to which said subject matter pertains. Patentability shall not be negatived by the manner in which the invention was made.
The factual inquiries set forth in Graham v. John Deere Co., 383 U.S. 1, 148 USPQ 459 (1966), that are applied for establishing a background for determining obviousness under 35 U.S.C. 103 are summarized as follows:
1. Determining the scope and contents of the prior art.
2. Ascertaining the differences between the prior art and the claims at issue.
3. Resolving the level of ordinary skill in the pertinent art.
4. Considering objective evidence present in the application indicating obviousness or non-obviousness.
Claims 1-10 is/are rejected under 35 U.S.C. 103 as being unpatentable over Kho (US 2017/0208041) in view of Ardhanari (US 2021/0248268) further in view of Rudden (US 2023/0096158).
Claim 1: Kho discloses a distributed computing system comprising: a client agent that resides on a network and is communicably coupled to a central server that resides outside of the network, the client agent comprising instructions which, when executed by one or more processors, cause the client agent to perform a process operable to: receive, from a workstation on the network, a dataset associated with a project maintained by the central server (Paragraph [0003]; [0011-0012]; [0014-0015]; Fig. 1, aspects of the present disclosure include methods, systems, and computer readable mediums for dynamically de-identifying data from a data source. The methods include a remote device deployed in a first security domain of a communication network, the remote device for generating a key value corresponding to a project requiring de-identification of data. The methods further involve a first server located in a second security domain of a communication network. The first server is configured to: securely receive the key value from the remote device and in response to receiving the key value: access a dataset maintained at the first server, the dataset including at least one individual record that uniquely identifies an individual. The first server is further configured to de-identify the dataset so that the at least one individual record in the dataset no longer uniquely identifies the individual. One or more client devices may securely transmit confidential patient health data (e.g. PHI and/or PII) to the de-identification and anonymous linkage management system (DALMS). For example, if a user were interested in de-identifying data for a particular project a user may interact with the one or more client devices to provide data including a seed value and/or key value that identifies the relevant project, and which may be processed by the de-identification module);
if the dataset comprises at least one of protected health information (PHI) or personal identifiable information (PII), pseudonymize or deidentify the dataset to generate a cohort (Paragraph [0003]; [0011-0012]; [0014-0015]; [0032]; Fig. 1, aspects of the present disclosure include methods, systems, and computer readable mediums for dynamically de-identifying data from a data source. The methods include a remote device deployed in a first security domain of a communication network, the remote device for generating a key value corresponding to a project requiring de-identification of data. The methods further involve a first server located in a second security domain of a communication network. The first server is configured to: securely receive the key value from the remote device and in response to receiving the key value: access a dataset maintained at the first server, the dataset including at least one individual record that uniquely identifies an individual. The first server is further configured to de-identify the dataset so that the at least one individual record in the dataset no longer uniquely identifies the individual. One or more client devices may securely transmit confidential patient health data (e.g. PHI and/or PII) to the de-identification and anonymous linkage management system (DALMS). For example, if a user were interested in de-identifying data for a particular project a user may interact with the one or more client devices to provide data including a seed value and/or key value that identifies the relevant project, and which may be processed by the de-identification module. All combined dataset are provided with an associated “universal” identifier that uniquely identifies the hashed data sets as a single set of identifiable health patient data that corresponds to one individual, without actually identifying a unique individual healthcare patient);
Kho discloses a system of de-identifying personal data for a project such as PHI and PII information found in a dataset when generating a cohort. However, Kho does not specifically disclose the following claim limitations: if the dataset does not comprise any of PHI and PII, generate the cohort as a direct copy of the dataset; access a container registry; read a container image comprising code from the container registry; store the cohort in a local directory such that the cohort is accessible to the container; and execute the code on the generated cohort, where the container code is prevented from performing any communication with external systems by executing the code on the first site and wherein the cohort is not exported from the network;
In the same field of endeavor of protecting private data during a project Ardhanari teaches if the dataset does not comprise any of PHI and PII, generate the cohort as a direct copy of the dataset (Paragraph [0125]; [0129]; [0174]; Fig. 3, a policy manager may be configured to manage one or more policy agents. A policy may dictate that a data scientist may receive an outputted dataset enclosed in a secure enclave. This means the data in the dataset is non-transparent to the data scientist. The latter is free to run additional output requests on the outputted dataset in the enclave by injecting new requests into the enclave. In those cases, when the outputted dataset does not have any PII data or does not violate the privacy parameters constraint, the dataset may become unconstrained and may be made available to the data scientist. One way of dealing with healthcare data is to anonymize or mask the private data attributes, e.g., mask social security numbers. In some embodiments methods may be employed for masking and de-identifying personal information from healthcare records. Using these methods, a dataset containing healthcare records may have various portions of its data attributes masked or de-identified).
Before the effective filing date of the invention it would have been obvious to one of ordinary skill in the art to modify the system of de-identifying personal data in a data set to be used in a project as disclosed by Kho (Kho [0011]) with the system of if the dataset does not comprise any of PHI and PII, generate the cohort as a direct copy of the dataset as taught by Ardhanari (Ardhanari Fig. 3). With the motivation of being obvious to try as Kho discloses a system of generating a cohort of data for a project by determining if the data contains PHI or PII information and performing deidentification processes on the information determined to be private while non-private information would not need to be processes through the deidentification processes. Additionally, it would help to improve analyzing biomedical data while maintaining privacy of individual patients (Ardhanari [0005]).
In the same field of endeavor of protecting data security Rudden teaches access a container registry (Paragraph [0003-0006]; [0026]; [0028]; [0037] the method automatically generates a container image based on an identified profile level for a dataset and data residency restrictions that restrict transfer of the dataset across a boundary. In some embodiments the method also includes making available the container image for selection and instantiation on the container host. The method can check whether an appropriate container for processing the dataset into the formatted dataset already exists as a container image in the registry. Containers are virtual environments providing portability to a set of encapsulated applications. Typically a control system accesses a generated container and instantiates the generated container for execution. Data residency restrictions of a target location may restrict the types of data that are imported across a boundary form a source location);
read a container image comprising code from the container registry (Paragraph [0003-0006]; [0026]; [0028]; [0037] the method automatically generates a container image based on an identified profile level for a dataset and data residency restrictions that restrict transfer of the dataset across a boundary. In some embodiments the method also includes making available the container image for selection and instantiation on the container host. The method can check whether an appropriate container for processing the dataset into the formatted dataset already exists as a container image in the registry. Containers are virtual environments providing portability to a set of encapsulated applications. Typically a control system accesses a generated container and instantiates the generated container for execution. Data residency restrictions of a target location may restrict the types of data that are imported across a boundary form a source location);
store the cohort in a local directory such that the cohort is accessible to the container (Paragraph [0003-0006]; [0026]; [0028]; [0037] the method automatically generates a container image based on an identified profile level for a dataset and data residency restrictions that restrict transfer of the dataset across a boundary. In some embodiments the method also includes making available the container image for selection and instantiation on the container host. The method can check whether an appropriate container for processing the dataset into the formatted dataset already exists as a container image in the registry. Containers are virtual environments providing portability to a set of encapsulated applications. Typically a control system accesses a generated container and instantiates the generated container for execution. Data residency restrictions of a target location may restrict the types of data that are imported across a boundary form a source location);
and execute the code on the generated cohort, where the container code is prevented from performing any communication with external systems by executing the code on the first site and wherein the cohort is not exported from the network (Paragraph [0003-0006]; [0026]; [0028]; [0037] the method automatically generates a container image based on an identified profile level for a dataset and data residency restrictions that restrict transfer of the dataset across a boundary. In some embodiments the method also includes making available the container image for selection and instantiation on the container host. The method can check whether an appropriate container for processing the dataset into the formatted dataset already exists as a container image in the registry. Containers are virtual environments providing portability to a set of encapsulated applications. Typically a control system accesses a generated container and instantiates the generated container for execution. Data residency restrictions of a target location may restrict the types of data that are imported across a boundary form a source location).
Before the effective filing date of the invention it would have been obvious to one of ordinary skill in the art to modify the method of protecting sensitive data being used for a project in a client device as disclosed by Kho with the method of access a container registry; read a container image comprising code from the container registry; store the cohort in a local directory such that the cohort is accessible to the container; and execute the code on the generated cohort, where the container code is prevented from performing any communication with external systems by executing the code on the first site and wherein the cohort is not exported from the network as taught by Rudden (Rudden [0006]). With the motivation of helping to secure datasets being used by an application to help protect sensitive data (Rudden [0002]).
Claim 2: Modified Kho discloses the distributed computing system as per claim 1. Kho further discloses wherein the process is further operable to validate a format of the dataset according to a schema associated with the project (Paragraph [0003]; [0011-0012]; [0014-0016]; [0020]; Fig. 1, aspects of the present disclosure include methods, systems, and computer readable mediums for dynamically de-identifying data from a data source. The methods include a remote device deployed in a first security domain of a communication network, the remote device for generating a key value corresponding to a project requiring de-identification of data. The methods further involve a first server located in a second security domain of a communication network. The first server is configured to: securely receive the key value from the remote device and in response to receiving the key value: access a dataset maintained at the first server, the dataset including at least one individual record that uniquely identifies an individual. The first server is further configured to de-identify the dataset so that the at least one individual record in the dataset no longer uniquely identifies the individual. Maintained in the database of the anonymous linker is patient health data that has already been de-identified. When new data is de-identified by the DALMS the newly de-identified data is combined and/or otherwise matched with the already existing de-identified data to ensure there is no duplicate data. A unique “universal” identifier is then provided for the matched de-identified data, thereby uniquely identifying the data without actually identifying a specific health care patient. A user may select or otherwise identify a project and generate a seed. Each seed or key is unique to each project and each user needs to be approved and assigned to a project before using the de-identification application. A user may provide project details to the command line application for requesting the relevant seed/key).
Claim 3: Modified Kho discloses the distributed computing system as per claim 2. Kho further discloses wherein the schema is a pre-defined schema (Paragraph [0003]; [0011-0012]; [0014-0015]; [0019-0020]; Fig. 1, aspects of the present disclosure include methods, systems, and computer readable mediums for dynamically de-identifying data from a data source. The methods include a remote device deployed in a first security domain of a communication network, the remote device for generating a key value corresponding to a project requiring de-identification of data. The methods further involve a first server located in a second security domain of a communication network. The first server is configured to: securely receive the key value from the remote device and in response to receiving the key value: access a dataset maintained at the first server, the dataset including at least one individual record that uniquely identifies an individual. The first server is further configured to de-identify the dataset so that the at least one individual record in the dataset no longer uniquely identifies the individual. One or more client devices may securely transmit confidential patient health data (e.g. PHI and/or PII) to the de-identification and anonymous linkage management system (DALMS). For example, if a user were interested in de-identifying data for a particular project a user may interact with the one or more client devices to provide data including a seed value and/or key value that identifies the relevant project, and which may be processed by the de-identification module. In some embodiments, a graphical user interface may be generated and/or initialized at the one or more client devices that may be employed to deliver an encrypted, project-based, seed/key value to DALMS. For example, a graphical user interface or command line application may be initialized at the client devices that allows a user to request the seed/key value assigned to a particular project. In response, the graphical user interface web portal may encrypt the seed/key value and transmit the seed/key value over a secured protocol to de-identification application at source client end device).
Claim 4: Modified Kho discloses the distributed computing system as per claim 2. Kho further discloses wherein the schema comprises a schema definition received from a user device, generated by a project lead, or derived from the dataset (Paragraph [0003]; [0011-0012]; [0014-0015]; [0019-0020]; Fig. 1, aspects of the present disclosure include methods, systems, and computer readable mediums for dynamically de-identifying data from a data source. The methods include a remote device deployed in a first security domain of a communication network, the remote device for generating a key value corresponding to a project requiring de-identification of data. The methods further involve a first server located in a second security domain of a communication network. The first server is configured to: securely receive the key value from the remote device and in response to receiving the key value: access a dataset maintained at the first server, the dataset including at least one individual record that uniquely identifies an individual. The first server is further configured to de-identify the dataset so that the at least one individual record in the dataset no longer uniquely identifies the individual. One or more client devices may securely transmit confidential patient health data (e.g. PHI and/or PII) to the de-identification and anonymous linkage management system (DALMS). For example, if a user were interested in de-identifying data for a particular project a user may interact with the one or more client devices to provide data including a seed value and/or key value that identifies the relevant project, and which may be processed by the de-identification module. In some embodiments, a graphical user interface may be generated and/or initialized at the one or more client devices that may be employed to deliver an encrypted, project-based, seed/key value to DALMS. For example, a graphical user interface or command line application may be initialized at the client devices that allows a user to request the seed/key value assigned to a particular project. In response, the graphical user interface web portal may encrypt the seed/key value and transmit the seed/key value over a secured protocol to de-identification application at source client end device).
Claim 5: Modified Kho discloses the distributed computing system as per claim 1. Kho further discloses wherein the client agent comprises at least one of a cloud-based server in a virtual private cloud, an on-site provisioned virtual machine, or an on-site server with access to data in a network and compute processing devices including one or more of CPUs or GPUs (Paragraph [0033]; [0039]; Fig. 5, an example of a suitable computing and networking environment that may be used to implement various aspects of the present disclosure. The computing and networking environment includes a general-purpose computing device, the networking environment may include one or more other computing systems, such as personal computers, server computers, hand-help or laptop devices, and the like. The computer may operate in a networked or cloud-computing environment using logical connections of a network interface or adapter to one or more remote devices. The remote computer may be a personal computer, a server, a router, a network PC, and typically includes many or all of the elements relative described relative to the computer).
Claim 6: Modified Kho discloses the distributed computing system as per claim 1. Kho further discloses wherein receiving the dataset comprises receiving at least one of a tabular dataset, imaging data, file data, video data, HER data, graph data, or streamed data (Paragraph [0014]; [0037] the DALMS represents the various computing systems, services, applications, and/or processes that may be deployed at a healthcare enterprise, and thus may include large data sets of confidential and/or sensitive patient health data (e.g. PHI and/or PII). For example, the DALMS may include MHI and/or PII information for a plurality of medical patients, or other confidential patient health care data, which includes any information in the medical record or designated record set that can be used to identify an individual).
Claim 7: Modified Kho discloses the distributed computing system as per claim 1. Kho further discloses wherein the process is further operable to: receive encrypted code and a code key from the central server; decrypt the encrypted code with the received code key; and execute the decrypted code (Paragraph [0017]; [0021-0022]; Fig. 2, in some embodiments the security domain represents separate sets and/or networks of computing components and cannot be accessed without proper authentication and/or encryption/decryption. In response the graphical user interface web portal may encrypt the seed/key value and transmit the seed/key value over a secured protocol to de-identification application as source/client end device. For example and in one embodiment, the seed value and/or key value may be encrypted using secure hash algorithms. The encrypted seed value and/or key value is securely transmitted to the DALMS. The seed/key value is decrypted and used to process patient health data. The DALMS processes the seed value in combination with other PHI/PII elements to generate hashes via cryptographic algorithms).
Claim 8: Modified Kho discloses the distributed computing system as per claim 7. Kho further discloses wherein receiving the encrypted code comprises receiving at least one of encrypted model code or an encrypted container (Paragraph [0017]; [0021-0022]; Fig. 2, in some embodiments the security domain represents separate sets and/or networks of computing components and cannot be accessed without proper authentication and/or encryption/decryption. In response the graphical user interface web portal may encrypt the seed/key value and transmit the seed/key value over a secured protocol to de-identification application as source/client end device. For example and in one embodiment, the seed value and/or key value may be encrypted using secure hash algorithms. The encrypted seed value and/or key value is securely transmitted to the DALMS. The seed/key value is decrypted and used to process patient health data. The DALMS processes the seed value in combination with other PHI/PII elements to generate hashes via cryptographic algorithms).
Claim 9: Modified Kho discloses the distributed computing system as per claim 7. Kho further discloses wherein executing the decrypted code comprises executing the decrypted code on at least one of a central processing unit (CPU) or a graphics processing unit (GPU) or in a Trusted Execution Environment (Paragraph [0017]; [0019]; [0021-0022]; Fig. 2, in some embodiments the security domain represents separate sets and/or networks of computing components and cannot be accessed without proper authentication and/or encryption/decryption. In response the graphical user interface web portal may encrypt the seed/key value and transmit the seed/key value over a secured protocol to de-identification application as source/client end device. For example and in one embodiment, the seed value and/or key value may be encrypted using secure hash algorithms. The encrypted seed value and/or key value is securely transmitted to the DALMS. The seed/key value is decrypted and used to process patient health data. The DALMS processes the seed value in combination with other PHI/PII elements to generate hashes via cryptographic algorithms).
Claim 10: Modified Kho discloses the distributed computing system as per claim 7. Kho further discloses wherein the process is further operable to transmit aggregate output statistics or execution results to the central server (Paragraph [0003]; [0011-0012]; [0014-0015]; [0019-0020]; Fig. 1, aspects of the present disclosure include methods, systems, and computer readable mediums for dynamically de-identifying data from a data source. The methods include a remote device deployed in a first security domain of a communication network, the remote device for generating a key value corresponding to a project requiring de-identification of data. The methods further involve a first server located in a second security domain of a communication network. The first server is configured to: securely receive the key value from the remote device and in response to receiving the key value: access a dataset maintained at the first server, the dataset including at least one individual record that uniquely identifies an individual. The first server is further configured to de-identify the dataset so that the at least one individual record in the dataset no longer uniquely identifies the individual. One or more client devices may securely transmit confidential patient health data (e.g. PHI and/or PII) to the de-identification and anonymous linkage management system (DALMS). For example, if a user were interested in de-identifying data for a particular project a user may interact with the one or more client devices to provide data including a seed value and/or key value that identifies the relevant project, and which may be processed by the de-identification module. In some embodiments, a graphical user interface may be generated and/or initialized at the one or more client devices that may be employed to deliver an encrypted, project-based, seed/key value to DALMS. For example, a graphical user interface or command line application may be initialized at the client devices that allows a user to request the seed/key value assigned to a particular project. In response, the graphical user interface web portal may encrypt the seed/key value and transmit the seed/key value over a secured protocol to de-identification application at source client end device).
Claims 11-20 is/are rejected under 35 U.S.C. 103 as being unpatentable over Kho (US 2017/0208041) in view of Rudden (US 2023/0096158).
Claim 11: Kho discloses a system for providing flexible distributed computation comprising: a server accessible by at least one client agent, the at least one client agent residing on a respective network associated with at least one site (Paragraph [0003]; [0011-0012]; [0014-0015]; Fig. 1, aspects of the present disclosure include methods, systems, and computer readable mediums for dynamically de-identifying data from a data source. The methods include a remote device deployed in a first security domain of a communication network, the remote device for generating a key value corresponding to a project requiring de-identification of data. The methods further involve a first server located in a second security domain of a communication network. The first server is configured to: securely receive the key value from the remote device and in response to receiving the key value: access a dataset maintained at the first server, the dataset including at least one individual record that uniquely identifies an individual. The first server is further configured to de-identify the dataset so that the at least one individual record in the dataset no longer uniquely identifies the individual. One or more client devices may securely transmit confidential patient health data (e.g. PHI and/or PII) to the de-identification and anonymous linkage management system (DALMS). For example, if a user were interested in de-identifying data for a particular project a user may interact with the one or more client devices to provide data including a seed value and/or key value that identifies the relevant project, and which may be processed by the de-identification module);
wherein the server comprises instructions which, when executed by one or more processors, cause the server to perform a process operable to: receive a schema definition from a user device (Paragraph [0003]; [0011-0012]; [0014-0015]; Fig. 1, aspects of the present disclosure include methods, systems, and computer readable mediums for dynamically de-identifying data from a data source. One or more client devices may securely transmit confidential patient health data (e.g. PHI and/or PII) to the de-identification and anonymous linkage management system (DALMS). For example, if a user were interested in de-identifying data for a particular project a user may interact with the one or more client devices to provide data including a seed value and/or key value that identifies the relevant project, and which may be processed by the de-identification module);
receive a container from the user device, the container comprising code to be executed (Paragraph [0003]; [0015]; [0018-0020]; Fig. 2, the methods, systems, and computer readable mediums further involve a first server located in a domain of the communication network. The first server is configured to: securely receive the kay value from the remote device and in response to the receiving the key value: access a dataset maintained at the first server. In some embodiments, a graphical user interface may be generated and/or initialized at the one or more client devices that may be employed to deliver an encrypted, project based, seed/key value to the DALMS. For example, a graphical user interface or command line application may be initialized at the client devices that allows a user to request the seed/key value assigned to particular project, and for which a user is approved to access);
receive, from the user device, a selection of a cohort of a plurality of cohorts associated with the at least one client agent, wherein each cohort was generated by the at least one client agent accessing a respective dataset within a respective network and pseudonymizing or deidentifying the dataset if the dataset comprises at least one of protected health information (PHI) or personal identifiable information (PII) (Paragraph [0003]; [0011-0012]; [0014-0015]; Fig. 1, aspects of the present disclosure include methods, systems, and computer readable mediums for dynamically de-identifying data from a data source. The methods include a remote device deployed in a first security domain of a communication network, the remote device for generating a key value corresponding to a project requiring de-identification of data. The methods further involve a first server located in a second security domain of a communication network. The first server is configured to: securely receive the key value from the remote device and in response to receiving the key value: access a dataset maintained at the first server, the dataset including at least one individual record that uniquely identifies an individual. The first server is further configured to de-identify the dataset so that the at least one individual record in the dataset no longer uniquely identifies the individual. One or more client devices may securely transmit confidential patient health data (e.g. PHI and/or PII) to the de-identification and anonymous linkage management system (DALMS). For example, if a user were interested in de-identifying data for a particular project a user may interact with the one or more client devices to provide data including a seed value and/or key value that identifies the relevant project, and which may be processed by the de-identification module);
and cause at least one summary statistic to be displayed on the user device based on execution of the code (Paragraph [0003]; [0011-0012]; [0014-0015]; Fig. 1, aspects of the present disclosure include methods, systems, and computer readable mediums for dynamically de-identifying data from a data source. The methods include a remote device deployed in a first security domain of a communication network, the remote device for generating a key value corresponding to a project requiring de-identification of data. The methods further involve a first server located in a second security domain of a communication network. The first server is configured to: securely receive the key value from the remote device and in response to receiving the key value: access a dataset maintained at the first server, the dataset including at least one individual record that uniquely identifies an individual. The first server is further configured to de-identify the dataset so that the at least one individual record in the dataset no longer uniquely identifies the individual. One or more client devices may securely transmit confidential patient health data (e.g. PHI and/or PII) to the de-identification and anonymous linkage management system (DALMS). For example, if a user were interested in de-identifying data for a particular project a user may interact with the one or more client devices to provide data including a seed value and/or key value that identifies the relevant project, and which may be processed by the de-identification module).
Kho discloses a system of de-identifying personal data for a project such as PHI and PII information found in a dataset when generating a cohort. However, Kho does not specifically disclose the following claim limitations: wherein the dataset is not accessible by the central server; push the container to a container registry; generate a model object linked to the container; send a request to a client agent associated with the selected cohort; wherein the client agent associated with the selected cohort pulls an image of the container and executes the code on the selected cohort; wherein the code is prevented from performing communication with any other service within the client agent or any external system by executing the code on the first site and wherein the cohort is not exported from the network.
In the same field of endeavor of protecting data security Rudden teaches wherein the dataset is not accessible by the central server; push the container to a container registry (Paragraph [0003-0006]; [0026]; [0028]; [0037] the method automatically generates a container image based on an identified profile level for a dataset and data residency restrictions that restrict transfer of the dataset across a boundary. In some embodiments the method also includes making available the container image for selection and instantiation on the container host. The method can check whether an appropriate container for processing the dataset into the formatted dataset already exists as a container image in the registry. Containers are virtual environments providing portability to a set of encapsulated applications. Typically a control system accesses a generated container and instantiates the generated container for execution. Data residency restrictions of a target location may restrict the types of data that are imported across a boundary form a source location);
generate a model object linked to the container; send a request to a client agent associated with the selected cohort; wherein the client agent associated with the selected cohort pulls an image of the container and executes the code on the selected cohort; wherein the code is prevented from performing communication with any other service within the client agent or any external system by executing the code on the first site and wherein the cohort is not exported from the network; (Paragraph [0003-0006]; [0026]; [0028]; [0037] the method automatically generates a container image based on an identified profile level for a dataset and data residency restrictions that restrict transfer of the dataset across a boundary. In some embodiments the method also includes making available the container image for selection and instantiation on the container host. The method can check whether an appropriate container for processing the dataset into the formatted dataset already exists as a container image in the registry. Containers are virtual environments providing portability to a set of encapsulated applications. Typically a control system accesses a generated container and instantiates the generated container for execution. Data residency restrictions of a target location may restrict the types of data that are imported across a boundary form a source location);
Before the effective filing date of the invention it would have been obvious to one of ordinary skill in the art to modify the method of protecting sensitive data being used for a project in a client device as disclosed by Kho with the method of wherein the dataset is not accessible by the central server; push the container to a container registry; generate a model object linked to the container; send a request to a client agent associated with the selected cohort; wherein the client agent associated with the selected cohort pulls an image of the container and executes the code on the selected cohort; wherein the code is prevented from performing communication with any other service within the client agent or any external system by executing the code on the first site and wherein the cohort is not exported from the network as taught by Rudden (Rudden [0006]). With the motivation of helping to secure datasets being used by an application to help protect sensitive data (Rudden [0002]).
Claim 12: Modified Kho discloses the system as per claim 11. Kho further discloses wherein an output of the executed code comprises a new cohort for each input cohort, a set of new cohorts, or a set of data points or statistics that result from the code execution on each input cohort (Paragraph [0003]; [0011-0012]; [0014-0015]; [0019-0020]; Fig. 1, aspects of the present disclosure include methods, systems, and computer readable mediums for dynamically de-identifying data from a data source. The methods include a remote device deployed in a first security domain of a communication network, the remote device for generating a key value corresponding to a project requiring de-identification of data. The methods further involve a first server located in a second security domain of a communication network. The first server is configured to: securely receive the key value from the remote device and in response to receiving the key value: access a dataset maintained at the first server, the dataset including at least one individual record that uniquely identifies an individual. The first server is further configured to de-identify the dataset so that the at least one individual record in the dataset no longer uniquely identifies the individual. One or more client devices may securely transmit confidential patient health data (e.g. PHI and/or PII) to the de-identification and anonymous linkage management system (DALMS). For example, if a user were interested in de-identifying data for a particular project a user may interact with the one or more client devices to provide data including a seed value and/or key value that identifies the relevant project, and which may be processed by the de-identification module. In some embodiments, a graphical user interface may be generated and/or initialized at the one or more client devices that may be employed to deliver an encrypted, project-based, seed/key value to DALMS. For example, a graphical user interface or command line application may be initialized at the client devices that allows a user to request the seed/key value assigned to a particular project. In response, the graphical user interface web portal may encrypt the seed/key value and transmit the seed/key value over a secured protocol to de-identification application at source client end device).
Claim 13: Modified Kho discloses the system as per claim 11. Kho further discloses wherein receiving the container from the user device comprises receiving an encrypted container, wherein the client agent decrypts the container with a code key (Paragraph [0017]; [0021-0022]; Fig. 2, in some embodiments the security domain represents separate sets and/or networks of computing components and cannot be accessed without proper authentication and/or encryption/decryption. In response the graphical user interface web portal may encrypt the seed/key value and transmit the seed/key value over a secured protocol to de-identification application as source/client end device. For example and in one embodiment, the seed value and/or key value may be encrypted using secure hash algorithms. The encrypted seed value and/or key value is securely transmitted to the DALMS. The seed/key value is decrypted and used to process patient health data. The DALMS processes the seed value in combination with other PHI/PII elements to generate hashes via cryptographic algorithms).
Claim 14: Modified Kho discloses the system as per claim 13. Kho further discloses wherein the code key is provided to the client agent via an external key management system (Paragraph [0017]; [0021-0022]; Fig. 2, in some embodiments the security domain represents separate sets and/or networks of computing components and cannot be accessed without proper authentication and/or encryption/decryption. In response the graphical user interface web portal may encrypt the seed/key value and transmit the seed/key value over a secured protocol to de-identification application as source/client end device. For example and in one embodiment, the seed value and/or key value may be encrypted using secure hash algorithms. The encrypted seed value and/or key value is securely transmitted to the DALMS. The seed/key value is decrypted and used to process patient health data. The DALMS processes the seed value in combination with other PHI/PII elements to generate hashes via cryptographic algorithms).
Claim 15: Modified Kho discloses the system as per claim 11. Kho further discloses wherein the process is further operable to: receive a schema definition from the user device; and provide the schema definition to the at least one client agent to validate the dataset (Paragraph [0003]; [0011-0012]; [0014-0015]; [0019-0020]; Fig. 1, aspects of the present disclosure include methods, systems, and computer readable mediums for dynamically de-identifying data from a data source. The methods include a remote device deployed in a first security domain of a communication network, the remote device for generating a key value corresponding to a project requiring de-identification of data. The methods further involve a first server located in a second security domain of a communication network. The first server is configured to: securely receive the key value from the remote device and in response to receiving the key value: access a dataset maintained at the first server, the dataset including at least one individual record that uniquely identifies an individual. The first server is further configured to de-identify the dataset so that the at least one individual record in the dataset no longer uniquely identifies the individual. One or more client devices may securely transmit confidential patient health data (e.g. PHI and/or PII) to the de-identification and anonymous linkage management system (DALMS). For example, if a user were interested in de-identifying data for a particular project a user may interact with the one or more client devices to provide data including a seed value and/or key value that identifies the relevant project, and which may be processed by the de-identification module. In some embodiments, a graphical user interface may be generated and/or initialized at the one or more client devices that may be employed to deliver an encrypted, project-based, seed/key value to DALMS. For example, a graphical user interface or command line application may be initialized at the client devices that allows a user to request the seed/key value assigned to a particular project. In response, the graphical user interface web portal may encrypt the seed/key value and transmit the seed/key value over a secured protocol to de-identification application at source client end device).
Claim 16: Modified Kho discloses the system as per claim 11. Kho further discloses wherein the process is further operable to: receive a project permission configuration from the user device, the configuration comprising one or more data permissions for one or more collaborators; and enforce the permission configuration (Paragraph [0125]; [0129]; [0174]; Fig. 3, a policy manager may be configured to manage one or more policy agents. A policy may dictate that a data scientist may receive an outputted dataset enclosed in a secure enclave. This means the data in the dataset is non-transparent to the data scientist. The latter is free to run additional output requests on the outputted dataset in the enclave by injecting new requests into the enclave. In those cases, when the outputted dataset does not have any PII data or does not violate the privacy parameters constraint, the dataset may become unconstrained and may be made available to the data scientist. One way of dealing with healthcare data is to anonymize or mask the private data attributes, e.g., mask social security numbers. In some embodiments methods may be employed for masking and de-identifying personal information from healthcare records. Using these methods, a dataset containing healthcare records may have various portions of its data attributes masked or de-identified).
Claim 17: Modified Kho discloses the system as per claim 15. Kho further discloses wherein the process is further operable to receive an updated schema definition from the user device (Paragraph [0003]; [0011-0012]; [0014-0015]; [0019-0020]; Fig. 1, aspects of the present disclosure include methods, systems, and computer readable mediums for dynamically de-identifying data from a data source. The methods include a remote device deployed in a first security domain of a communication network, the remote device for generating a key value corresponding to a project requiring de-identification of data. The methods further involve a first server located in a second security domain of a communication network. The first server is configured to: securely receive the key value from the remote device and in response to receiving the key value: access a dataset maintained at the first server, the dataset including at least one individual record that uniquely identifies an individual. The first server is further configured to de-identify the dataset so that the at least one individual record in the dataset no longer uniquely identifies the individual. One or more client devices may securely transmit confidential patient health data (e.g. PHI and/or PII) to the de-identification and anonymous linkage management system (DALMS). For example, if a user were interested in de-identifying data for a particular project a user may interact with the one or more client devices to provide data including a seed value and/or key value that identifies the relevant project, and which may be processed by the de-identification module. In some embodiments, a graphical user interface may be generated and/or initialized at the one or more client devices that may be employed to deliver an encrypted, project-based, seed/key value to DALMS. For example, a graphical user interface or command line application may be initialized at the client devices that allows a user to request the seed/key value assigned to a particular project. In response, the graphical user interface web portal may encrypt the seed/key value and transmit the seed/key value over a secured protocol to de-identification application at source client end device).
Claim 18: Kho discloses a system for providing flexible distributed computation comprising: a plurality of client agents, each client agent residing on a respective network associated with a respective site and being configured to access an associated dataset, wherein each associated dataset is not accessible by other client agents (Paragraph [0003]; [0011-0012]; [0014-0015]; Fig. 1, aspects of the present disclosure include methods, systems, and computer readable mediums for dynamically de-identifying data from a data source. The methods include a remote device deployed in a first security domain of a communication network, the remote device for generating a key value corresponding to a project requiring de-identification of data. The methods further involve a first server located in a second security domain of a communication network. The first server is configured to: securely receive the key value from the remote device and in response to receiving the key value: access a dataset maintained at the first server, the dataset including at least one individual record that uniquely identifies an individual. The first server is further configured to de-identify the dataset so that the at least one individual record in the dataset no longer uniquely identifies the individual. One or more client devices may securely transmit confidential patient health data (e.g. PHI and/or PII) to the de-identification and anonymous linkage management system (DALMS). For example, if a user were interested in de-identifying data for a particular project a user may interact with the one or more client devices to provide data including a seed value and/or key value that identifies the relevant project, and which may be processed by the de-identification module);
and one or more servers communicably coupled to the plurality of client agents, wherein each associated dataset is not accessible by the one or more servers, wherein each of the one or more servers comprises instructions which, when executed by one or more processors, cause the one or more servers to perform a process operable to: receive processing instructions from a user device (Paragraph [0033]; [0039]; Fig. 5, an example of a suitable computing and networking environment that may be used to implement various aspects of the present disclosure. The computing and networking environment includes a general-purpose computing device, the networking environment may include one or more other computing systems, such as personal computers, server computers, hand-help or laptop devices, and the like. The computer may operate in a networked or cloud-computing environment using logical connections of a network interface or adapter to one or more remote devices. The remote computer may be a personal computer, a server, a router, a network PC, and typically includes many or all of the elements relative described relative to the computer);
instruct one or more of the plurality of client agents to perform the processing instructions on the associated datasets (Paragraph [0015]; [0018-0020]; Fig. 2, in some embodiments, a graphical user interface may be generated and/or initialized at the one or more client devices that may be employed to deliver an encrypted, project based, seed/key value to the DALMS. For example, a graphical user interface or command line application may be initialized at the client devices that allows a user to request the seed/key value assigned to particular project, and for which a user is approved to access);
and receive an output from each of the client agents that performed the processing instructions (Paragraph [0003]; [0011-0012]; [0014-0015]; [0032]; Fig. 1, aspects of the present disclosure include methods, systems, and computer readable mediums for dynamically de-identifying data from a data source. The methods include a remote device deployed in a first security domain of a communication network, the remote device for generating a key value corresponding to a project requiring de-identification of data. The methods further involve a first server located in a second security domain of a communication network. The first server is configured to: securely receive the key value from the remote device and in response to receiving the key value: access a dataset maintained at the first server, the dataset including at least one individual record that uniquely identifies an individual. The first server is further configured to de-identify the dataset so that the at least one individual record in the dataset no longer uniquely identifies the individual. One or more client devices may securely transmit confidential patient health data (e.g. PHI and/or PII) to the de-identification and anonymous linkage management system (DALMS). For example, if a user were interested in de-identifying data for a particular project a user may interact with the one or more client devices to provide data including a seed value and/or key value that identifies the relevant project, and which may be processed by the de-identification module. All combined dataset are provided with an associated “universal” identifier that uniquely identifies the hashed data sets as a single set of identifiable health patient data that corresponds to one individual, without actually identifying a unique individual healthcare patient).
Kho discloses a system of de-identifying personal data for a project such as PHI and PII information found in a dataset when generating a cohort. However, Kho does not specifically disclose the following claim limitations: wherein performing the processing comprises: accessing a container registry; reading a container image comprising code from the container registry; store the cohort in a local directory such that the cohort is accessible to the container; and executing the code on the generated cohort, where the container code is prevented from performing any communication with external systems by executing the code on the respective site and wherein the cohort is not exported from the respective network.
In the same field of endeavor of protecting data security Rudden teaches wherein performing the processing comprises: accessing a container registry; reading a container image comprising code from the container registry; store the cohort in a local directory such that the cohort is accessible to the container; (Paragraph [0003-0006]; [0026]; [0028]; [0037] the method automatically generates a container image based on an identified profile level for a dataset and data residency restrictions that restrict transfer of the dataset across a boundary. In some embodiments the method also includes making available the container image for selection and instantiation on the container host. The method can check whether an appropriate container for processing the dataset into the formatted dataset already exists as a container image in the registry. Containers are virtual environments providing portability to a set of encapsulated applications. Typically a control system accesses a generated container and instantiates the generated container for execution. Data residency restrictions of a target location may restrict the types of data that are imported across a boundary form a source location);
and executing the code on the generated cohort, where the container code is prevented from performing any communication with external systems by executing the code on the respective site and wherein the cohort is not exported from the respective network (Paragraph [0003-0006]; [0026]; [0028]; [0037] the method automatically generates a container image based on an identified profile level for a dataset and data residency restrictions that restrict transfer of the dataset across a boundary. In some embodiments the method also includes making available the container image for selection and instantiation on the container host. The method can check whether an appropriate container for processing the dataset into the formatted dataset already exists as a container image in the registry. Containers are virtual environments providing portability to a set of encapsulated applications. Typically a control system accesses a generated container and instantiates the generated container for execution. Data residency restrictions of a target location may restrict the types of data that are imported across a boundary form a source location).
Before the effective filing date of the invention it would have been obvious to one of ordinary skill in the art to modify the method of protecting sensitive data being used for a project in a client device as disclosed by Kho with the method of wherein performing the processing comprises: accessing a container registry; reading a container image comprising code from the container registry; store the cohort in a local directory such that the cohort is accessible to the container; and executing the code on the generated cohort, where the container code is prevented from performing any communication with external systems by executing the code on the respective site and wherein the cohort is not exported from the respective network as taught by Rudden (Rudden [0006]). With the motivation of helping to secure datasets being used by an application to help protect sensitive data (Rudden [0002]).
Claim 19: Modified Kho discloses the system as per claim 18. Kho further discloses wherein the process is further operable to encrypt the output from each of the client agents that performed the processing instructions (Paragraph [0017]; [0021-0022]; Fig. 2, in some embodiments the security domain represents separate sets and/or networks of computing components and cannot be accessed without proper authentication and/or encryption/decryption. In response the graphical user interface web portal may encrypt the seed/key value and transmit the seed/key value over a secured protocol to de-identification application as source/client end device. For example and in one embodiment, the seed value and/or key value may be encrypted using secure hash algorithms. The encrypted seed value and/or key value is securely transmitted to the DALMS. The seed/key value is decrypted and used to process patient health data. The DALMS processes the seed value in combination with other PHI/PII elements to generate hashes via cryptographic algorithms).
Claim 20: Modified Kho discloses the system as per claim 19. Kho further discloses wherein encrypting the output from each of the client agents comprises performing a homomorphic encryption process (Paragraph [0017]; [0021-0022]; Fig. 2, in some embodiments the security domain represents separate sets and/or networks of computing components and cannot be accessed without proper authentication and/or encryption/decryption. In response the graphical user interface web portal may encrypt the seed/key value and transmit the seed/key value over a secured protocol to de-identification application as source/client end device. For example and in one embodiment, the seed value and/or key value may be encrypted using secure hash algorithms. The encrypted seed value and/or key value is securely transmitted to the DALMS. The seed/key value is decrypted and used to process patient health data. The DALMS processes the seed value in combination with other PHI/PII elements to generate hashes via cryptographic algorithms).
Therefore, claims 1-20 are rejected under U.S.C. 103.
Response to arguments
Applicant’s arguments, see REMARKS, filed April 27, 2026, with respect to the rejections of claims 1-20 under U.S.C. 101 have been fully considered and are persuasive.
Representative argues that the newly amended claims do not recite an abstract idea as they recite a system that is comprises a client agent that is communicably coupled to a central server that is operable to receive a dataset associated with a project, pseudonymize or deidentify the dataset to generate a cohort; access a container registry; read a container image comprising code; store the cohort in a local directory; and execute the code using the generated cohort. The examiner agrees as the independent claims do not recite an abstract idea. As executing a container code or a software application on a cohort of information is not a mental process, a certain method of organizing human activity, nor a mathematical calculation.
Therefore, the examiner maintains the current 101 rejection.
Claims 2-10, 12-17, and 19-20 are dependent on claims 1, 11, and 18 and therefore are rejected under the same rejection.
Applicant’s arguments, see REMARKS, filed April 27, 2026, with respect to the rejections of 1-10 is/are rejected under 35 U.S.C. 103 as being unpatentable over Kho (US 2017/0208041) in view of Ardhanari (US 2021/0248268) further in view of Rudden (US 2023/0096158) and Claims 11-20 is/are rejected under 35 U.S.C. 103 as being unpatentable over Kho (US 2017/0208041) in view of Rudden (US 2023/0096158) are not persuasive as claims were amended which required further search and consideration and new art was applied.
Claims 1, 11, and 18: The applicant argues that the current combination of prior art does not disclose the currently amended claim limitation. However, upon further search and consideration the examiner finds that Rudden can be used in combination with the current prior art to disclose the newly amended claim limitations. Kho discloses a system of de-identification of dataset by determining if project information contains sensitive or private information and performing a series of steps to encrypt the identified private information. Kho can be used in combination with Rudden which teaches a system of determining a limit to how data can be shared. Rudden further teaches allowing a system to select a container from a registry and executing the container using a dataset based on the privacy restrictions of a dataset to help process the dataset. Therefore, the examiner finds that the new combination of prior art teaches the newly amended claim limitations.
Therefore, claims 1, 11, and 18 are rejected under U.S.C. 103
Claims 2-10, 12-17, and 19-20 are argued as being allowable as being dependent on claims 1, 11, and 18. Therefore, they are also rejected under the same rejection as above.
Conclusion
The prior art made of record and not relied upon is considered pertinent to applicant’s disclosure:
Rodriguez (US 2022/0198034) System and method for controlling data using containers.
Patodia (US 2022/0164477) Detecting leakage of personal information in computing code configurations.
Wyatt (US 2020/0285752) Quarantine of software based on analysis of updated device data.
Achyuth (US 2020/0314167) File containerization and management.
Applicant's amendment necessitated the new ground(s) of rejection presented in this Office action. Accordingly, THIS ACTION IS MADE FINAL. See MPEP § 706.07(a). Applicant is reminded of the extension of time policy as set forth in 37 CFR 1.136(a).
A shortened statutory period for reply to this final action is set to expire THREE MONTHS from the mailing date of this action. In the event a first reply is filed within TWO MONTHS of the mailing date of this final action and the advisory action is not mailed until after the end of the THREE-MONTH shortened statutory period, then the shortened statutory period will expire on the date the advisory action is mailed, and any nonprovisional extension fee (37 CFR 1.17(a)) pursuant to 37 CFR 1.136(a) will be calculated from the mailing date of the advisory action. In no event, however, will the statutory period for reply expire later than SIX MONTHS from the mailing date of this final action.
Any inquiry concerning this communication or earlier communications from the examiner should be directed to COREY RUSS whose telephone number is (571)270-5902. The examiner can normally be reached on M-F 7:30-4:30.
Examiner interviews are available via telephone, in-person, and video conferencing using a USPTO supplied web-based collaboration tool. To schedule an interview, applicant is encouraged to use the USPTO Automated Interview Request (AIR) at http://www.uspto.gov/interviewpractice.
If attempts to reach the examiner by telephone are unsuccessful, the examiner’s supervisor, Lynda Jasmin can be reached on 5712726782. The fax phone number for the organization where this application or proceeding is assigned is 571-273-8300.
Information regarding the status of an application may be obtained from the Patent Application Information Retrieval (PAIR) system. Status information for published applications may be obtained from either Private PAIR or Public PAIR. Status information for unpublished applications is available through Private PAIR only. For more information about the PAIR system, see https://ppair-my.uspto.gov/pair/PrivatePair. Should you have questions on access to the Private PAIR system, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). If you would like assistance from a USPTO Customer Service Representative or access to the automated information system, call 800-786-9199 (IN USA OR CANADA) or 571-272-1000.
/COREY RUSS/Primary Examiner, Art Unit 3629