Prosecution Insights
Last updated: October 02, 2026
Application No. 18/481,581

DATA PRIVACY USING QUICK RESPONSE CODE

Final Rejection §102§103
Filed
Oct 05, 2023
Examiner
PARSONS, THEODORE C
Art Unit
2400
Tech Center
2400 — Computer Networks
Assignee
Truist Bank
OA Round
2 (Final)
78%
Grant Probability
Favorable
3-4
OA Rounds
1m
Est. Remaining
99%
With Interview

Examiner Intelligence

Grants 78% — above average
78%
Career Allowance Rate
369 granted / 470 resolved
+20.5% vs TC avg
Strong +21% interview lift
Without
With
+21.3%
Interview Lift
resolved cases with interview
Typical timeline
3y 1m
Avg Prosecution
14 currently pending
Career history
485
Total Applications
across all art units

Statute-Specific Performance

§101
6.7%
-33.3% vs TC avg
§103
39.7%
-0.3% vs TC avg
§102
30.2%
-9.8% vs TC avg
§112
17.5%
-22.5% vs TC avg
Black line = Tech Center average estimate • Based on career data from 470 resolved cases

Office Action

§102 §103
DETAILED ACTION Response to Amendment The present application, filed on or after March 16, 2013, is being examined under the first inventor to file provisions of the AIA . This is in reply to papers filed on 2025-11-20. Claims 1-3, 7-20 are pending, following Applicant's cancellation of claims 4-6. Claims 1, 20 is/are independent. The rejection(s) of claims on double patenting grounds are withdrawn in view of Applicant’s terminal disclaimer. Applicant's amendment necessitated the new ground(s) of rejection presented in this Office action. Accordingly, THIS ACTION IS MADE FINAL. See MPEP § 706.07(a). Response to Arguments Applicant’s arguments have been fully considered but are moot in view of the new ground(s) of rejection. With respect to claim(s) 1 (see page(s) 3-4 of Applicant’s Remarks), Applicant argues that the prior art of record (in particular, U.S. Publication 20210125297 to Doran et al. (hereinafter "Doran '297") in view of U.S. Publication 20220139510 to Romanychev et al. (hereinafter "Romanychev '510")) does not disclose usage data embedded in a QR code for transmission along with the corresponding user data to a recipient. However, both Doran '297 [Doran '297 ¶ 0041-0052, 0032, 0037] and Romanychev '510 [Romanychev '510 ¶ 0072, 0045, 0072-0076, 0085] explicitly disclose collecting usage data (e.g., user preferences or user consents to sharing, access, and usage of a user's data (e.g., personal health information). Romanychev '510 then goes on to disclose that these consent and access data established by the user are embedded into the QR code [Romanychev '510 ¶ 0072, 0045, 0072-0076, 0085] that conveys the user data. Accordingly, Applicants arguments are unpersuasive. Further, Examiner has reviewed the record and the references. As detailed in the rejections below, Doran '297 in view of Romanychev '510 sufficiently discloses claims 13, 16, 19. Thus, it is unnecessary at this time to rely upon U.S. Publication 20210243185 to Thasale (hereinafter "Thasale '185") or U.S. Publication 20240232560 to Durham (hereinafter "Durham '560"). However, these references remain pertinent to the claims and may be reapplied as prosecution continues, should circumstances warrant. Applicant’s arguments with respect to the remaining claim(s) is/are based on Applicant’s arguments with respect to claim(s) 1 and have been considered as detailed above. Information Disclosure Statement PTO-1449 The Information Disclosure Statement(s) submitted by applicant on 2025-11-20, 2026-07-20, 2025-08-18 has/have been considered. The submission is in compliance with the provisions of 37 CFR § 1.97. Form PTO-1449 signed and attached hereto. Summary of Claim Rejections under 35 U.S.C. § 103 The following table summarizes the rejections set forth in detail below of the claims over the prior art. Claim No. Doran '297 in view of Romanychev '510 1 [Wingdings font/0xFC] 2 [Wingdings font/0xFC] 3 [Wingdings font/0xFC] 7 [Wingdings font/0xFC] 8 [Wingdings font/0xFC] 9 [Wingdings font/0xFC] 10 [Wingdings font/0xFC] 11 [Wingdings font/0xFC] 12 [Wingdings font/0xFC] 13 [Wingdings font/0xFC] 14 [Wingdings font/0xFC] 15 [Wingdings font/0xFC] 16 [Wingdings font/0xFC] 17 [Wingdings font/0xFC] 18 [Wingdings font/0xFC] 19 [Wingdings font/0xFC] 20 [Wingdings font/0xFC] Claim Rejections - 35 U.S.C. § 103 The following is a quotation of the appropriate paragraphs of AIA 35 U.S.C. 102 that form the basis for the rejections under this section made in this Office action: A person shall be entitled to a patent unless – (a)(1) the claimed invention was patented, described in a printed publication, or in public use, on sale or otherwise available to the public before the effective filing date of the claimed invention. (a)(2) the claimed invention was described in a patent issued under section 151, or in an application for patent published or deemed published under section 122(b), in which the patent or application, as the case may be, names another inventor and was effectively filed before the effective filing date of the claimed invention. In the event the determination of the status of the application as subject to AIA 35 U.S.C. 102 and 103 (or as subject to pre-AIA 35 U.S.C. 102 and 103) is incorrect, any correction of the statutory basis for the rejection will not be considered a new ground of rejection if the prior art relied upon, and the rationale supporting the rejection, would be the same under either status. The following is a quotation of AIA 35 U.S.C. 103 that forms the basis for all obviousness rejections set forth in this Office action: A patent for a claimed invention may not be obtained, notwithstanding that the claimed invention is not identically disclosed as set forth in section 102 of this title, if the differences between the claimed invention and the prior art are such that the claimed invention as a whole would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to which the claimed invention pertains. Patentability shall not be negated by the manner in which the invention was made. The factual inquiries set forth in Graham v. John Deere Co., 383 U.S. 1, 148 USPQ 459 (1966), that are applied for establishing a background for determining obviousness under 35 U.S.C. § 103(a) are summarized as follows: 1. Determining the scope and contents of the prior art. 2. Ascertaining the differences between the prior art and the claims at issue. 3. Resolving the level of ordinary skill in the pertinent art. 4. Considering objective evidence present in the application indicating obviousness or nonobviousness. This application currently names joint inventors. In considering patentability of the claims the examiner presumes that the subject matter of the various claims was commonly owned as of the effective filing date of the claimed invention(s) absent any evidence to the contrary. Applicant is advised of the obligation under 37 CFR 1.56 to point out the inventor and effective filing dates of each claim that was not commonly owned as of the effective filing date of the later invention in order for the examiner to consider the applicability of 35 U.S.C. 102(b)(2)(C) for any potential 35 U.S.C. 102(a)(2) prior art against the later invention. Claim(s) 1-3, 7-20 is/are rejected under 35 U.S.C. § 103 as being unpatentable over U.S. Publication 20210125297 to Doran et al. (hereinafter "Doran '297") in view of U.S. Publication 20220139510 to Romanychev et al. (hereinafter "Romanychev '510"). Doran '297 is prior art to the claims under 35 U.S.C. § 102(a)(1) and 35 U.S.C. § 102(a)(2). Romanychev '510 is prior art to the claims under 35 U.S.C. § 102(a)(1) and 35 U.S.C. § 102(a)(2). Per claim 1 (independent): Doran '297 discloses a method for network data privacy (limits sharable user data according to user consent/preference information [Doran '297 ¶ 0041-0052, 0032, 0037]) Doran '297 discloses providing a computing system including at least one processor, at least one memory device including computer-readable instructions, wherein the at least one processor is in communication with at least one user device via a network connection (Doran '297: Fig 5; Input processing system 400 may represent, for example, a network operator that provides communication and input processing services to customers/users [¶ 0050] and input processing system 400 may detect, or otherwise be informed of, devices (E.g., customer devices, user devices, network appliance devices, etc.) that have connected to input processing system 400 or a network thereof [¶ 0052].) Doran '297 discloses providing, by the at least one processor to the at least one user device, a user software application to a user for installation on the at least one user device, wherein the at least one user device is configured to wirelessly communicate with the computing system via the user software application (Doran '297: In other example aspects, the systems and methods described herein may be a standalone executable software that is downloaded to a client device. In aspects, a client device, such as client devices 102, 104, and 106, may receive input from a user, such as user information that is collected during a sign-up process or login. The user information may be encrypted upon input. The encryption may occur locally on the client device, or the encryption may occur remotely at servers 116, 118, and/or 120, where the user information may be transmitted over network 108 [¶ 0028]. See also ¶ 0078-0079) Doran '297 discloses receiving, by the at least one processor from the user software application installed on the at least one user device, user data comprising personal information data of the user; storing the user data in at least one database (Doran '297: In aspects, a client device, such as client devices 102, 104, and 106, may receive input from a user, such as user information that is collected during a sign-up process or login. The user information may be encrypted upon input. The encryption may occur locally on the client device, or the encryption may occur remotely at servers 116, 118, and/or 120, where the user information may be transmitted over network 108 [¶ 0028]. Data collection engine 415 may be configured to collect user input (e.g., user login information, privacy and security preferences, PII, user selections to legal contracts, etc.) and/or business input (e.g., customer data, contracts, contract provisions, ERP system information, etc.). Other data that may be collected by data collection engine 415 may include social media data (from the user, business, or both), GPS data related to electronic devices (e.g., mobile phone, smart vehicle, computer, etc.), healthcare data, and nutritional data [¶ 0052].) Doran '297 discloses receiving, by the at least one processor from a user-specific dashboard of the user software application, at least one communication request related to usage of the user data transmitted from the at least one user device (collects user consent/preference information related to the user's PHI, PII, and personal data [Doran '297 ¶ 0041-0052, 0032, 0037]; dashboard [Doran '297 ¶ 0041]) Doran '297 discloses filtering, by the at least one processor, the user data to allow for certain variables in the user data to be determined private (limits sharable user data according to user consent/preference information [Doran '297 ¶ 0041-0052, 0032, 0037]) Doran '297 discloses collecting, by the at least one processor, usage data related to the filtered user data, wherein the usage data comprises data indicative of use of the user data by the computing system (collects user consent/preference information related to the user's PHI, PII, and personal data [Doran '297 ¶ 0041-0052, 0032, 0037]) Doran '297 does not disclose generating at least one quick response code embedded with at least one of the usage data related to the filtered user data and a link to the usage data related to the filtered user data Doran '297 does not disclose transmitting the quick response code embedded with the at least one of the usage data and the link to the usage data to the at least one user device Further: Romanychev '510 discloses generating at least one quick response code embedded with at least one of the usage data related to the filtered user data and a link to the usage data related to the filtered user data (Romanychev '510: The medical data and their level of sharing, defined by the patient may be embedded in a medical identifier 206. In another embodiment of the present invention, the identification data may be embedded in an identification code 206. In an embodiment of the present invention, the medical identifier 206 may be, but not limited to, a Quick Response (QR) code, a Bar code, a unique identifier, such as a biometric, and so forth [¶ 0073]; QR code includes multiple levels of sharing determine which recipients can access which user data according to user consents/preferences [Romanychev '510 ¶ 0072, 0045, 0072-0076, 0085]) Romanychev '510 discloses transmitting the quick response code embedded with the at least one of the usage data and the link to the usage data to the at least one user device (Romanychev '510: QR code includes multiple levels of sharing determine which recipients can access which user data according to user consents/preferences [Romanychev '510 ¶ 0072, 0045, 0072-0076, 0085]; Alternatively, or additionally, a medical identifier(QR code)is provided in a dynamic form (e.g., electronic/computer storable/readable form). A dynamic medical identifier may be downloaded(transmitted) to a smart user device (e.g., a mobile telephone and/or a wearable device), such as user device 104 in FIGS. 1 and 4A-4G. [¶ 0099].) It would have been obvious to a person having ordinary skill in the art (1) before the effective filing date of the claimed invention and (2) before the invention was made to have modified Doran '297 with the QR code embedding consent data imposing multiple layers of authentication for differential access to levels of the user data of Romanychev '510 to arrive at an apparatus, method, and product including: generating at least one quick response code embedded with at least one of the usage data related to the filtered user data and a link to the usage data related to the filtered user data transmitting the quick response code embedded with the at least one of the usage data and the link to the usage data to the at least one user device A person having ordinary skill in the art would have been motivated to combine them at least because a QR code embedding consent data imposing multiple layers of authentication for differential access to levels of the user data would conveniently and locally convey not only the user data of Doran '297, but also robust and flexible consent data to the recipients. A person having ordinary skill in the art would have been further motivated to combine them at least because such a modification would be to enhance the portability and accessibility of securely sharing a user’s private data and data sharing preferences by allowing the embed information to also be shared offline or with third party systems. A person having ordinary skill in the art would have been further motivated to combine them at least because Romanychev '510 teaches [Romanychev '510 ¶ 0072-0073, 0045, 0072-0076, 0085] modifying a network data privacy scheme [Doran '297 ¶ 0041-0052, 0032, 0037] such as that of Doran '297 to arrive at the claimed invention; because Doran '297 and Romanychev '510 are in the same field of endeavor; because doing so constitutes use of a known technique (QR code embedding multi-level access scheme [Romanychev '510 ¶ 0072-0073, 0045, 0072-0076, 0085]) to improve similar devices and/or methods (network data privacy scheme [Doran '297 ¶ 0041-0052, 0032, 0037]) in the same way; because doing so constitutes applying a known technique (QR code embedding multi-level access scheme [Romanychev '510 ¶ 0072-0073, 0045, 0072-0076, 0085]) to known devices and/or methods (network data privacy scheme [Doran '297 ¶ 0041-0052, 0032, 0037]) ready for improvement to yield predictable results; and because the modification amounts to combining prior art elements according to known methods to yield predictable results. Here, (1) the prior art included each element (as detailed above); (2) one of ordinary skill in the art could have combined the elements as claimed by known methods, and in this combination, each element merely performs the same function as it does separately (network data privacy scheme [Doran '297 ¶ 0041-0052, 0032, 0037] shares user data with recipients while QR code embedding multi-level access scheme [Romanychev '510 ¶ 0072-0073, 0045, 0072-0076, 0085] conveys user consent rules); (3) one of ordinary skill in the art would have recognized that the results of the combination were predictable; and (4) other considerations do not overcome this conclusion. Per claim 2 (dependent on claim 1): Doran '297 in view of Romanychev '510 discloses the elements detailed in the rejection of claim 1 above, incorporated herein by reference Doran '297 discloses the step of receiving identification of the user via the user software application accessible by the at least one user device (Doran '297: In aspects, a client device, such as client devices 102, 104, and 106, may receive input from a user, such as user information that is collected during a sign-up process or login [¶ 0028].). Per claim 3 (dependent on claim 1): Doran '297 in view of Romanychev '510 discloses the elements detailed in the rejection of claim 1 above, incorporated herein by reference Doran '297 does not disclose the step of verifying identification of the user of the user software application accessible by the at least one user device Further: Romanychev '510 discloses the step of verifying identification of the user of the user software application accessible by the at least one user device (Romanychev '510: The user may log-in the medical application 106 by using the log-in credentials, such as, but not limited to, a sign-in ID and a password, and/or a unique identifier, for example, a fingerprint, a face recognition, retina, etc. [¶ 0078].) For the reasons detailed above with respect to claim 1, it would have been obvious to a person having ordinary skill in the art (1) before the effective filing date of the claimed invention and (2) before the invention was made to have modified Doran '297 with the QR code embedding consent data imposing multiple layers of authentication for differential access to levels of the user data of Romanychev '510 to arrive at an apparatus, method, and product including: the step of verifying identification of the user of the user software application accessible by the at least one user device Per claim 7 (dependent on claim 1): Doran '297 in view of Romanychev '510 discloses the elements detailed in the rejection of claim 1 above, incorporated herein by reference Doran '297 discloses the step of displaying the at least one communication request on a graphical user interface of the at least one user device (Doran '297: Further, a user may dynamically give and revoke consent to particular provisions from this screen may include any variations of buttons, switches, etc.[¶ 0072].) Per claim 8 (dependent on claim 1): Doran '297 in view of Romanychev '510 discloses the elements detailed in the rejection of claim 1 above, incorporated herein by reference Doran '297 does not disclose the step of hosting the at least one quick response code embedded with the usage data on the user software application accessible by the at least one user device Further: Romanychev '510 discloses the step of hosting the at least one quick response code embedded with the usage data on the user software application accessible by the at least one user device (Romanychev '510: In another embodiment of the present invention, the protected medical data, such as, but not limited to, the protected PII data, the basic PHI data, or a combination thereof may be embedded in the first medical identifier in an encrypted format, which may be decoded by using the medical application 106 of an authorized user device 104 [¶ 0095]; QR code includes multiple levels of sharing determine which recipients can access which user data according to user consents/preferences [Romanychev '510 ¶ 0072, 0045, 0072-0076, 0085]) For the reasons detailed above with respect to claim 1, it would have been obvious to a person having ordinary skill in the art (1) before the effective filing date of the claimed invention and (2) before the invention was made to have modified Doran '297 with the QR code embedding consent data imposing multiple layers of authentication for differential access to levels of the user data of Romanychev '510 to arrive at an apparatus, method, and product including: the step of hosting the at least one quick response code embedded with the usage data on the user software application accessible by the at least one user device Per claim 9 (dependent on claim 1): Doran '297 in view of Romanychev '510 discloses the elements detailed in the rejection of claim 1 above, incorporated herein by reference Doran '297 does not disclose the step of displaying the at least one quick response code on a graphical user interface of the at least one user device Further: Romanychev '510 discloses the step of displaying the at least one quick response code on a graphical user interface of the at least one user device (Romanychev '510: Fig 4C shows the QR code 406 being displayed on the graphical user interface of a user device ) For the reasons detailed above with respect to claim 1, it would have been obvious to a person having ordinary skill in the art (1) before the effective filing date of the claimed invention and (2) before the invention was made to have modified Doran '297 with the QR code embedding consent data imposing multiple layers of authentication for differential access to levels of the user data of Romanychev '510 to arrive at an apparatus, method, and product including: the step of displaying the at least one quick response code on a graphical user interface of the at least one user device Per claim 10 (dependent on claim 1): Doran '297 in view of Romanychev '510 discloses the elements detailed in the rejection of claim 1 above, incorporated herein by reference Doran '297 does not disclose the step of translating the at least one quick response code into human-readable data upon tactile engagement of the at least one quick response code displayed on a graphical user interface of the at least one user device Further: Romanychev '510 discloses the step of translating the at least one quick response code into human-readable data upon tactile engagement of the at least one quick response code displayed on a graphical user interface of the at least one user device (Romanychev '510: Once the QR code 406 is scanned, an unprotected PII data, a protected PII data, a basic PHI data, or a combination thereof, associated with the patient is displayed on the user device 104, which may include, a first name, a last name, an emergency contact, a date of birth, a gender, and so forth [¶ 0112]; app receives commands via touchscreen [Romanychev '510 ¶ 0112]) For the reasons detailed above with respect to claim 1, it would have been obvious to a person having ordinary skill in the art (1) before the effective filing date of the claimed invention and (2) before the invention was made to have modified Doran '297 with the QR code embedding consent data imposing multiple layers of authentication for differential access to levels of the user data of Romanychev '510 to arrive at an apparatus, method, and product including: the step of translating the at least one quick response code into human-readable data upon tactile engagement of the at least one quick response code displayed on a graphical user interface of the at least one user device Per claim 11 (dependent on claim 10): Doran '297 in view of Romanychev '510 discloses the elements detailed in the rejection of claim 10 above, incorporated herein by reference Doran '297 does not disclose the step of displaying the human-readable data on the graphical user interface of the at least one user device Further: Romanychev '510 discloses the step of displaying the human-readable data on the graphical user interface of the at least one user device (Romanychev '510: Once the QR code 406 is scanned, an unprotected PII data, a protected PII data, a basic PHI data, or a combination thereof, associated with the patient is displayed on the user device 104, which may include, a first name, a last name, an emergency contact, a date of birth, a gender, and so forth. Therefore, the user may then be able to access a set of medical data in a readable format as per the level of authorization. [¶ 0112].) For the reasons detailed above with respect to claim 1, it would have been obvious to a person having ordinary skill in the art (1) before the effective filing date of the claimed invention and (2) before the invention was made to have modified Doran '297 with the QR code embedding consent data imposing multiple layers of authentication for differential access to levels of the user data of Romanychev '510 to arrive at an apparatus, method, and product including: the step of displaying the human-readable data on the graphical user interface of the at least one user device Per claim 12 (dependent on claim 1): Doran '297 in view of Romanychev '510 discloses the elements detailed in the rejection of claim 1 above, incorporated herein by reference Doran '297 does not disclose the step of requiring authentication to access and/or view the embedded data Further: Romanychev '510 discloses the step of requiring authentication to access and/or view the embedded data (Romanychev '510: FIG. 4D; In an embodiment of the present invention, the “log in” button 408 may be used to authorize a user who desires to access the protected medical data in order to provide medical treatment to the patient in an emergency condition [¶ 0113]; multiple levels of sharing determine which recipients can access which user data according to user consents/preferences [Romanychev '510 ¶ 0072, 0045, 0072-0076, 0085]) For the reasons detailed above with respect to claim 1, it would have been obvious to a person having ordinary skill in the art (1) before the effective filing date of the claimed invention and (2) before the invention was made to have modified Doran '297 with the QR code embedding consent data imposing multiple layers of authentication for differential access to levels of the user data of Romanychev '510 to arrive at an apparatus, method, and product including: the step of requiring authentication to access and/or view the embedded data Per claim 13 (dependent on claim 12): Doran '297 in view of Romanychev '510 discloses the elements detailed in the rejection of claim 12 above, incorporated herein by reference Doran '297 does not disclose the authentication has multiple levels of authentication Further: Romanychev '510 discloses the authentication has multiple levels of authentication (Romanychev '510: FIG. 4D; In an embodiment of the present invention, the “log in” button 408 may be used to authorize a user who desires to access the protected medical data in order to provide medical treatment to the patient in an emergency condition [¶ 0113]; multiple levels of sharing determine which recipients can access which user data according to user consents/preferences [Romanychev '510 ¶ 0072, 0045, 0072-0076, 0085]) For the reasons detailed above with respect to claim 1, it would have been obvious to a person having ordinary skill in the art (1) before the effective filing date of the claimed invention and (2) before the invention was made to have modified Doran '297 with the QR code embedding consent data imposing multiple layers of authentication for differential access to levels of the user data of Romanychev '510 to arrive at an apparatus, method, and product including: the authentication has multiple levels of authentication Per claim 14 (dependent on claim 12): Doran '297 in view of Romanychev '510 discloses the elements detailed in the rejection of claim 12 above, incorporated herein by reference Doran '297 does not disclose discloses the authentication includes at least one of a username, a password, a pin, biometric information, and a security token Further: Romanychev '510 discloses the authentication includes at least one of a username, a password, a pin, biometric information, and a security token (Romanychev '510: FIG. 4D; In an embodiment of the present invention, the user log-in into the medical application 106 by providing log-in credentials such as, a username 412, and a password 414 [¶ 0113]; multiple levels of sharing determine which recipients can access which user data according to user consents/preferences [Romanychev '510 ¶ 0072, 0045, 0072-0076, 0085]) For the reasons detailed above with respect to claim 1, it would have been obvious to a person having ordinary skill in the art (1) before the effective filing date of the claimed invention and (2) before the invention was made to have modified Doran '297 with the QR code embedding consent data imposing multiple layers of authentication for differential access to levels of the user data of Romanychev '510 to arrive at an apparatus, method, and product including: the authentication includes at least one of a username, a password, a pin, biometric information, and a security token Per claim 15 (dependent on claim 12): Doran '297 in view of Romanychev '510 discloses the elements detailed in the rejection of claim 12 above, incorporated herein by reference Doran '297 does not disclose the authentication is inputted into a graphical user interface of the at least one user device Further: Romanychev '510 discloses the authentication is inputted into a graphical user interface of the at least one user device (Romanychev '510: FIG. 4D; After entering the log-in credentials, a “Log-in” button 416 is pressed [¶ 0113]; interacts with app via touchscreen, GUI [Romanychev '510 ¶ 0174, 0112-0113]) For the reasons detailed above with respect to claim 1, it would have been obvious to a person having ordinary skill in the art (1) before the effective filing date of the claimed invention and (2) before the invention was made to have modified Doran '297 with the QR code embedding consent data imposing multiple layers of authentication for differential access to levels of the user data of Romanychev '510 to arrive at an apparatus, method, and product including: the authentication is inputted into a graphical user interface of the at least one user device Per claim 16 (dependent on claim 1): Doran '297 in view of Romanychev '510 discloses the elements detailed in the rejection of claim 1 above, incorporated herein by reference Doran '297 does not disclose the at least one quick response code includes at least one an identifier of the enterprise system Further: Romanychev '510 discloses the at least one quick response code includes at least one an identifier of the enterprise system (Romanychev '510: The medical data and their level of sharing, defined by the patient may be embedded in a medical identifier 206. In another embodiment of the present invention, the identification data may be embedded in an identification code 206. In an embodiment of the present invention, the medical identifier 206 may be, but not limited to, a Quick Response (QR) code, a Bar code, a unique identifier, such as a biometric, and so forth [¶ 0073]; PHI includes link to database, web link to extended medical record, which necessarily identifies the enterprise system [Romanychev '510 ¶ 0069, 0070, 0073, 0092, 0119, 0121]) For the reasons detailed above with respect to claim 1, it would have been obvious to a person having ordinary skill in the art (1) before the effective filing date of the claimed invention and (2) before the invention was made to have modified Doran '297 with the QR code embedding consent data imposing multiple layers of authentication for differential access to levels of the user data of Romanychev '510 to arrive at an apparatus, method, and product including: the at least one quick response code includes at least one an identifier of the enterprise system Per claim 17 (dependent on claim 1): Doran '297 in view of Romanychev '510 discloses the elements detailed in the rejection of claim 1 above, incorporated herein by reference Doran '297 discloses a source of the usage data is the enterprise system (Doran '297: Data that may have been previously collected in the ERP system may be shared with the intelligent contract analysis and data organization system [¶ 0025]; collects user consent/preference information related to the user's PHI, PII, and personal data [Doran '297 ¶ 0041-0052, 0032, 0037]; dashboard [Doran '297 ¶ 0041]) Per claim 18 (dependent on claim 1): Doran '297 in view of Romanychev '510 discloses the elements detailed in the rejection of claim 1 above, incorporated herein by reference Doran '297 discloses a source of the usage data is a third-party entity (Doran '297: For instance, a user may have consented that various health data may be collected by multiple third-parties [¶ 0041]; collects user consent/preference information related to the user's PHI, PII, and personal data [Doran '297 ¶ 0041-0052, 0032, 0037]; dashboard [Doran '297 ¶ 0041]; user consent given to first third party to re-share data to second third party is stored in the system [Doran '297 ¶ 0071]; system acquires user data and consent data from outside systems [Doran '297 ¶ 0052, 0074]) Per claim 19 (dependent on claim 1): Doran '297 in view of Romanychev '510 discloses the elements detailed in the rejection of claim 1 above, incorporated herein by reference Doran '297 discloses the at least one quick response code is embedded with information related to product and/or service offerings (all user data and consent data is "related to product and/or service offerings" when it is shared with an advertiser [Doran '297 ¶ 0045; see also ¶ 0041-0052, 0032, 0037, 0071, 0074]) Per claim 20 (independent): Doran '297 discloses a method for network data privacy (limits sharable user data according to user consent/preference information [Doran '297 ¶ 0041-0052, 0032, 0037]) The remaining limitations of the claim(s) correspond(s) to features of claim(s) 1 and the claim(s) is/are rejected for the reasons detailed with respect to those claims. Doran '297 discloses generating a predictive model during training of a machine learning program including a neural network of the machine learning program, wherein a training data set utilized during the training of the machine learning program comprises a personal data set of at least one user, and wherein the personal data set of the at least one user includes at least one data entry related to at least one data portability measure with respect to the at least one user (Doran '297: Specifically, if a user has preferences/values that make privacy of personal information a high priority, then certain contract provisions (e.g., allowing a business to use personal data with third-party advertisers) are going to repeatedly be rejected. The pattern that may be established by the user in rejecting certain contract provisions combined with a user's overall privacy profile (indicating a user's preferences as to how his/her PII is shared or distributed among third parties) may be used to train at least one machine-learning model [¶ 0045]. ) Doran '297 discloses predicting, by the predictive model, at least one predicted data portability measure of the at least one user associated with the at least one user device based upon the personal data set of the at least one user (Doran '297: In other examples, the machine learning models described herein may also be trained on aggregations of population data. For instance, multiple users who may display similar preferences regarding the handling of PII and patterns of accepting and rejecting certain contract provisions may be used to train a machine learning model that may be able to identify a similarly situated user and make intelligent recommendations to that user. Data from aggregated populations may be extrapolated to make suggestions to similarly-situated individuals. For instance, a Democrat voter in her 30's living in Colorado may repeatedly consent to sharing PII related to educational data, demographic/location data, and political data. However, a Republican voter in her 50's may display different data and privacy preferences. The machine learning model may use the data from the Democrat voter in her 30's living in Colorado to make similar consent/no consent recommendations to a user who demonstrates similar political preferences, age, and location. In some example aspects, individual historical data may be coupled with broader population-based data to train the machine-learning model(s) described herein [¶ 0046]. ) Doran '297 does not disclose generating a quick response code embedded with at least one of the usage data related to the filtered user data and a link to the usage data related to the filtered user data based upon the at least one predicted data portability measure However, Doran '297 discloses generating a message embedded with at least one of the usage data related to the filtered user data and a link to the usage data related to the filtered user data based upon the at least one predicted data portability measure (Doran '297: In other examples, the machine learning models described herein may also be trained on aggregations of population data. For instance, multiple users who may display similar preferences regarding the handling of PII and patterns of accepting and rejecting certain contract provisions may be used to train a machine learning model that may be able to identify a similarly situated user and make intelligent recommendations to that user. Data from aggregated populations may be extrapolated to make suggestions to similarly-situated individuals. For instance, a Democrat voter in her 30's living in Colorado may repeatedly consent to sharing PII related to educational data, demographic/location data, and political data. However, a Republican voter in her 50's may display different data and privacy preferences. The machine learning model may use the data from the Democrat voter in her 30's living in Colorado to make similar consent/no consent recommendations to a user who demonstrates similar political preferences, age, and location. In some example aspects, individual historical data may be coupled with broader population-based data to train the machine-learning model(s) described herein [¶ 0046]. ) Doran '297 does not disclose transmitting the quick response code embedded with at least one of the usage data and the link to the usage data based upon the at least one predicted data portability measure to the at least one user device However, Doran '297 discloses transmitting the message embedded with at least one of the usage data and the link to the usage data based upon the at least one predicted data portability measure to the at least one user device (Doran '297: In other examples, the machine learning models described herein may also be trained on aggregations of population data. For instance, multiple users who may display similar preferences regarding the handling of PII and patterns of accepting and rejecting certain contract provisions may be used to train a machine learning model that may be able to identify a similarly situated user and make intelligent recommendations to that user. Data from aggregated populations may be extrapolated to make suggestions to similarly-situated individuals. For instance, a Democrat voter in her 30's living in Colorado may repeatedly consent to sharing PII related to educational data, demographic/location data, and political data. However, a Republican voter in her 50's may display different data and privacy preferences. The machine learning model may use the data from the Democrat voter in her 30's living in Colorado to make similar consent/no consent recommendations to a user who demonstrates similar political preferences, age, and location. In some example aspects, individual historical data may be coupled with broader population-based data to train the machine-learning model(s) described herein [¶ 0046]. ) Further: Romanychev '510 discloses generating a quick response code embedded with at least one of the usage data related to the filtered user data and a link to the usage data related to the filtered user data (Romanychev '510: The medical data and their level of sharing, defined by the patient may be embedded in a medical identifier 206. In another embodiment of the present invention, the identification data may be embedded in an identification code 206. In an embodiment of the present invention, the medical identifier 206 may be, but not limited to, a Quick Response (QR) code, a Bar code, a unique identifier, such as a biometric, and so forth [¶ 0073]; QR code includes multiple levels of sharing determine which recipients can access which user data according to user consents/preferences [Romanychev '510 ¶ 0072, 0045, 0072-0076, 0085]) Romanychev '510 discloses transmitting the quick response code embedded with at least one of the usage data and the link to the usage data to the at least one user device (Romanychev '510: QR code includes multiple levels of sharing determine which recipients can access which user data according to user consents/preferences [Romanychev '510 ¶ 0072, 0045, 0072-0076, 0085]; Alternatively, or additionally, a medical identifier(QR code)is provided in a dynamic form (e.g., electronic/computer storable/readable form). A dynamic medical identifier may be downloaded(transmitted) to a smart user device (e.g., a mobile telephone and/or a wearable device), such as user device 104 in FIGS. 1 and 4A-4G. [¶ 0099].) For the reasons detailed above with respect to claim 1, it would have been obvious to a person having ordinary skill in the art (1) before the effective filing date of the claimed invention and (2) before the invention was made to have modified Doran '297 with the QR code embedding consent data imposing multiple layers of authentication for differential access to levels of the user data of Romanychev '510 to arrive at an apparatus, method, and product including: generating a quick response code embedded with at least one of the usage data related to the filtered user data and a link to the usage data related to the filtered user data based upon the at least one predicted data portability measure transmitting the quick response code embedded with at least one of the usage data and the link to the usage data based upon the at least one predicted data portability measure to the at least one user device Conclusion THIS ACTION IS MADE FINAL. Applicant is reminded of the extension of time policy as set forth in 37 CFR 1.136(a). A shortened statutory period for reply to this final action is set to expire THREE MONTHS from the mailing date of this action. In the event a first reply is filed within TWO MONTHS of the mailing date of this final action and the advisory action is not mailed until after the end of the THREE-MONTH shortened statutory period, then the shortened statutory period will expire on the date the advisory action is mailed, and any extension fee pursuant to 37 CFR 1.136(a) will be calculated from the mailing date of the advisory action. In no event, however, will the statutory period for reply expire later than SIX MONTHS from the mailing date of this final action. The prior art made of record and not relied upon is considered pertinent to applicant's disclosure. Any inquiry concerning this communication or earlier communications from the examiner should be directed to THEODORE C PARSONS whose telephone number is (571)270-1475. The examiner can normally be reached on MTWRF 7:30-4:30. If attempts to reach the examiner by telephone are unsuccessful, the examiner’s supervisor, Jung Kim can be reached on (571) 272-3804. The fax phone number for the organization where this application or proceeding is assigned is 571-273-8300. Information regarding the status of an application may be obtained from Patent Center. Status information for published applications may be obtained from Patent Center. Status information for unpublished applications is available through Patent Center for authorized users only. Should you have questions about access to Patent Center, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). Examiner interviews are available via telephone, in-person, and video conferencing using a USPTO supplied web-based collaboration tool. To schedule an interview, applicant is encouraged to use the USPTO Automated Interview Request (AIR) Form at https://www.uspto.gov/patents/apply/forms. /THEODORE C PARSONS/Primary Examiner, Art Unit 2494
Read full office action

Prosecution Timeline

Oct 05, 2023
Application Filed
Aug 08, 2025
Non-Final Rejection mailed — §102, §103
Nov 06, 2025
Examiner Interview Summary
Nov 06, 2025
Applicant Interview (Telephonic)
Nov 07, 2025
Response Filed
Sep 14, 2026
Final Rejection mailed — §102, §103 (current)

Precedent Cases

Applications granted by this same examiner with similar technology

Patent 12726501
Vector-Based Anomaly Detection
1y 8m to grant Granted Sep 01, 2026
Patent 12717977
PROXIMITY-BASED CONTENT VISIBILITY CONTROL
3y 5m to grant Granted Aug 25, 2026
Patent 12705402
STORAGE DEVICE, OPERATING METHOD THEREOF, AND SYSTEM FOR PROVIDING SAFE STORAGE SPACE BETWEEN APPLICATION AND STORAGE DEVICE ON APPLICATION-BY-APPLICATION BASIS
3y 0m to grant Granted Aug 11, 2026
Patent 12705316
GEO-FENCING OF AN APPLICATION FOR A SECURE CRYPTOGRAPHIC ENVIRONMENT
1y 12m to grant Granted Aug 11, 2026
Patent 12705351
APPARATUS AND METHODS TO CLASSIFY MALWARE WITH EXPLAINABILITY WITH ARTIFICIAL INTELLIGENCE MODELS
1y 10m to grant Granted Aug 11, 2026
Study what changed to get past this examiner. Based on 5 most recent grants.

Strategy Recommendation AI-generated — please review before filing

Get a prosecution strategy drawn from examiner precedents, rejection analysis, and claim mapping.
Typically takes 5-10 seconds — AI-generated, attorney review required before filing

Prosecution Projections

3-4
Expected OA Rounds
78%
Grant Probability
99%
With Interview (+21.3%)
3y 1m (~1m remaining)
Median Time to Grant
Moderate
PTA Risk
Based on 470 resolved cases by this examiner. Grant probability derived from career allowance rate.

Sign in with your work email

Enter your email to receive a magic link. No password needed.

Personal email addresses (Gmail, Yahoo, etc.) are not accepted.

Free tier: 3 strategy analyses per month