DETAILED ACTION
Notice of Pre-AIA or AIA Status
The present application, filed on or after March 16, 2013, is being examined under the first inventor to file provisions of the AIA .
Respond Applicant Arguments
The Examiner has considered Applicant’s arguments regarding the rejection of Claims 1-16 under 35 U.S.C. § 112, including in the remarks filed on May 8, 2026, pages 9-15, and finds the arguments persuasive for the reasons below.
Applicant argues that Claims 1 and 9 do not invoke 35 U.S.C. § 112(f) because the amended terms “storage unit,” “control unit,” “analysis unit,” “a processor configured to,” and “display” connote structure in view of Fig. 1 and Spec. [0020], [0024], and that Claim 11 is definite because “the personal information of the log” now has clear antecedent basis.
The Examiner agrees that Applicant’s amendments remove the placeholder-function and antecedent-basis issues; therefore, the rejections under 35 U.S.C. § 112(f) and § 112(b) are withdrawn.
The Examiner has considered Applicant’s arguments regarding the rejection of Claims 1-16 under 35 U.S.C. § 101, including the remarks filed on May 8, 2026, pages 15-64, and finds the arguments unpersuasive for the reasons below.
Applicant argues that Claims 1 and 9, and their dependent claims, do not recite an abstract idea because the claimed setting identifiers, deleting related information, outputting a copy database and copy log via a network, and comparing identifiers to perform mutual tracing without using the related information allegedly fall outside the certain methods of organizing human activity grouping, cannot practically be performed in the human mind, do not preempt the field, and improve patient information technology under Spec. [0009]-[0010] and [0058]-[0061].
The Examiner does not rely on the certain methods of organizing human activity grouping for maintaining the rejection; that portion of Applicant’s argument is moot. The rejection is maintained because, under the broadest reasonable interpretation required by MPEP § 2111 and MPEP § 2106, Claims 1 and 9 recite the mental-process abstract idea of using substitute non-identifying identifiers to preserve traceability between patient-linked database records and log records after deleting patient-linked related information. The network-output limitation does not remove the abstract idea from the claims because the rejection does not treat the physical act of network transmission as the mental process. Rather, the mental-process limitations are the record-handling judgments of assigning a neutral identifier, matching the same related information between the database and log, replacing related information with the corresponding identifier, deleting patient-linked information, and comparing identifiers to trace corresponding records. The processor, storage unit, database, log, external device, network, display, and button are additional elements evaluated under Step 2A, Prong Two and Step 2B. Applicant’s preemption argument is also not persuasive because MPEP § 2106.04 explains that preemption is not a standalone eligibility test; the absence of complete preemption does not establish eligibility where the claim remains directed to a judicial exception under the Alice/Mayo framework. Accordingly, Applicant’s Step 2A, Prong One arguments do not overcome the rejection.
Applicant argues that Claims 1 and 9 integrate the alleged abstract idea into a practical application because the claims allegedly recite a particular analyzer/information-output arrangement, improve patient information analysis technology, are not merely insignificant extra-solution activity, and are comparable to Ex parte Desjardins.
The Examiner respectfully disagrees. The claims have been considered as a whole, and all additional elements have been given weight under Step 2A, Prong Two. However, MPEP § 2106.04(d)(1) requires more than using ordinary computer or analyzer components to carry out the exception; the specification must describe the invention such that a person of ordinary skill would recognize an improvement in computer functionality or another technology, and the claim must reflect that improvement. The present specification identifies the problem as loss of traceability after personal and related information are hidden because the database and the log cannot be traced, identifies the object as outputting information by which a database and a log can be traced, and identifies the effect as enabling tracing by identifiers. Spec. [0007]-[0010]. The later stated effects are the same information-governance benefits: it is possible to trace the databases DB1 to DB3 and DB5 and the logs by using the identifiers, personal-information security can be strictly controlled, deleted records can be investigated using an accumulation database, and a screen-output field can obtain the same effect. Spec. [0058]-[0061]. These disclosures improve the usefulness of redacted records for investigation and privacy control, but do not improve sample analysis, analyzer operation, processor architecture, memory arrangement, database structure, network protocol, display technology, or access-control technology. Desjardins is distinguishable because the credited improvement concerned how a machine-learning model itself learned new tasks while protecting prior-task performance; Claims 1 and 9 do not train a model, adjust model parameters, preserve model performance, reduce model storage, or improve a computer component. The amended limitations apply an identifier-redaction-and-tracing rule to records after sample-analysis information exists; they do not change how the analyzer physically analyzes a sample or how the computer technologically stores, searches, compares, copies, transmits, or displays data. Therefore, the claims do not integrate the judicial exception into a practical application.
Applicant argues that Claims 1 and 9 provide significantly more under Step 2B because the ordered combination of setting identifiers, deleting related information, outputting the copy database and copy log via a network, and comparing identifiers to perform mutual tracing without using the related information is not well-understood, routine, or conventional.
The Examiner respectfully disagrees. Under proper BRI, the assigning, matching, deleting, replacing, outputting, and comparing operations are the identifier-redaction-and-tracing rule identified as the judicial exception, not additional elements that supply the inventive concept. The additional elements are the analyzer hardware, processor, storage unit, database, log, external device, network, display, and button. Those elements do not add significantly more because the claims do not require an unconventional analyzer operation, processor architecture, memory arrangement, database structure, log structure, network protocol, display mechanism, button structure, or access-control technology. The specification describes the processor environment as a hardware structure of a general information processing device, with HDD/SSD storage and connection to a network 40, Spec. 0024-0025. The asserted benefit remains informational: it is possible to trace the databases DB1 to DB3 and DB5 and the logs by using the identifiers, Spec.0058.
Applicant argues that Berkheimer requires factual support for any well-understood, routine, conventional finding.
The Examiner respectfully disagrees because the rejection does not treat the entire ordered combination as WURC by unsupported assertion. The WURC finding is limited to the analyzer/computer implementation environment, which is supported by the specification’s general computer disclosure and the cited pre-filing publications showing automatic analyzers with sample disks, reaction disks, reagent disks, and computer/processor/controller sample-analysis functions. The remaining additional elements are recited at a high level and perform ordinary implementation roles: storing records, applying the record-governance rule, displaying or withholding information, and transmitting copied records.
Applicant argues that Ex parte Desjardins supports eligibility because the claims allegedly improve patient information analysis technology.
The Examiner respectfully disagrees. Desjardins involved an improvement to how a machine-learning model itself operated. Claims 1 and 9 do not train a model, adjust model parameters, preserve model performance, reduce model storage through model operation, or improve a computer component. The claims apply an identifier-redaction-and-tracing rule to database and log records after sample-analysis information exists. The specification describes an information-governance benefit, not a technological improvement to the analyzer, processor, database, storage, network, display, or access-control technology.
Applicant argues that the claims are not merely network transmission.
The Examiner respectfully disagrees. The Examiner does not treat the network alone as the whole claim. The network and external device merely deliver the result of the abstract record-processing rule. The claims do not recite improved packet handling, encryption, authentication, bandwidth use, routing, transmission security, or external-device operation.
Applicant argues that the claims are not merely applying an abstract idea using a computer.
The Examiner respectfully disagrees. The processor is recited as the tool that performs the assigning, matching, deleting, replacing, outputting, and comparing functions. The specification describes ordinary processing: copying databases/logs, deleting patient-linked fields, replacing matched sample IDs in the log with identifiers, outputting the resulting files, and deleting temporary files. Spec. 0052-0058. This does not show a specially configured computer that operates differently because of the claimed rule.
Applicant argues that Claims 2-8 and 10-16 are eligible because they depend from Claims 1 and 9 and include additional subject matter.
The Examiner respectfully disagrees. The dependent claims have been considered individually and as part of the ordered combination, but they do not add an inventive concept. Claims 2, 3, 10, and 11 further define replacement and deletion of personal information. Claims 4 and 12 add an accumulation database and record-retention rule, which is ordinary record storage and retention for later investigation, not an improved database structure. Claims 5 and 13 add display/non-display classification, which is record-status display selection. Claims 6 and 14 add sample-type characters or signs to the identifier, which is data-label formatting. Claims 7, 8, 15, and 16 add display modes and button activation/inactivation to control access to personal information; the specification describes this as preventing personal information from leaking to a serviceman, not as improved display, button, authentication, or access-control technology. Spec. 0073-0074.
Therefore, Applicant’s Step 2B arguments are not persuasive. The additional elements, individually and as an ordered combination, do not amount to significantly more than the judicial exception, and the § 101 rejection of Claims 1-16 is maintained.
The Examiner has considered Applicant’s arguments regarding the rejection of Claims 1-16 under 35 U.S.C. § 103, including the remarks filed on May 8, 2026, pages 64-76, and finds the arguments unpersuasive for the reasons below.
Applicant argues that Claims 1 and 9 distinguish because the prior rejection over Karan and Landi allegedly failed to teach deleting related information, adding identifiers that do not contain related information, outputting a copy database and copy log, and mutually tracing the copy database and copy log without using the related information. Applicant further argues that Landi encrypts patient-identifying information rather than deleting it, and that a POSITA would not have combined Karan and Landi without hindsight or a reasonable expectation of success.
The Examiner respectfully finds these arguments moot because the present rejection no longer relies on Karan as the primary reference and no longer relies on Landi. The prior-art basis has changed in view of the amended claims: Carlson is now relied upon for the healthcare de-identification, database/log, identifier, external output, and mutual-tracing limitations; Karan is applied only for the dependent accumulation, display, sample/test-type, and GUI-control limitations; and Tokiwa is applied only for the analyzer hardware recited in Claims 1-8. Thus, Applicant’s arguments that Karan alone does not delete related information and that Landi encrypts rather than deletes patient information do not overcome the current rejection. Attorney argument that the former combination failed to teach the amended limitations is not persuasive against a new rejection based on different teachings.
For Claims 1-8, the apparatus claims mirror the method limitations of Claims 9-16, except that Claim 1 further recites the analyzer hardware: a sample disk, a reaction disk, a reagent disk, and a processor configured to analyze a sample. The findings for Claims 9-16 over Carlson and Karan apply to the corresponding mirror limitations of Claims 1-8, and Tokiwa is additionally applied to teach the missing disk-based analyzer structure and sample-analysis processor. Applicant’s prior arguments against Karan and Landi do not address Tokiwa.
Accordingly, Applicant’s arguments are moot as to Landi and the former Karan/Landi combination, and are not persuasive against the current rejection. The previous § 103 rejection over Karan and Landi is withdrawn, and a new § 103 rejection over Carlson, Karan, and Tokiwa is set forth below in view of the amended claims.
Claim Rejections - 35 USC § 101
35 U.S.C. 101 reads as follows:
Whoever invents or discovers any new and useful process, machine, manufacture, or composition of matter, or any new and useful improvement thereof, may obtain a patent therefor, subject to the conditions and requirements of this title.
Subject Matter Eligibility Rejection 35 U.S.C. § 101
Claims 1–16 are rejected under 35 U.S.C. § 101 because the claimed subject matter is directed to a judicial exception (an abstract idea) without reciting elements that integrate the exception into a practical application or provide an inventive concept amounting to significantly more than the exception itself.
Step 1: Statutory Categories Analysis
The claims are directed to statutory subject matter, encompassing the following statutory categories:
· Process (Claims 9–16): The language reciting "storing, in a storage unit, a database," "setting a unique identifier," and "outputting the database and the log" defines a series of acts or steps, aligning with the definition of a process in MPEP § 2106.03.
· Machine (Claims 1–8): The language reciting an analyzer comprising a sample disk, reaction disk, reagent disk, processor, and storage unit describes a concrete thing consisting of parts, aligning with the machine category in MPEP § 2106.03.
Having confirmed the claims are directed to statutory subject matter, the analysis proceeds to Prong One.
Step 2A, Prong One: Judicial Exception Analysis
Prong One asks whether the claims recite a judicial exception.
Claim 1 and 9, is directed to replacing patient-linked database and log information with matching non-identifying identifiers so the exported database and exported log remain mutually traceable after the related identifying information is deleted. Refer to claim 1 representative claim below that show abstract idea non-bold and additional elements in bold.
Claim 1 recites a judicial exception because limitations 4, 6, 7, 8, and 9, with supporting record-relationship language in limitations 2 and 3, set forth the mental-process abstract idea of assigning corresponding non-identifying identifiers, substituting those identifiers for patient-linked related information, deleting the related information from copied database/log records, and comparing the identifiers to trace corresponding database/log records without using the deleted related information.
The following examples explain why and how the claim 1 recite judicial exception: a human lab clerk could perform with paper records: assign a neutral identifier to a patient-linked database record, place the same identifier on matching log entries, remove the patient-linked information from copied records, ensure the identifier itself does not contain the removed information, and compare the identifiers to trace the copied database and copied log without using the deleted related information.
Claim 1.
An analyzer comprising:1. a sample disk, a reaction disk, a reagent disk, and a processor configured to analyze a sample;
and2. a storage unit that stores a database in which related information linked to personal information of a patient having supplied the sample, and sample information of the sample to be analyzed by the processor,
3. an analysis result of the sample by the processor, or the personal information of the patient are stored in a corresponding manner and a log including the related information4. wherein the processor is further configured to set a unique identifier for each record of the database, set, for the related information of the log, the identifier set for the related information of the database which is the same as the related information of the log the related information of the database and the related information of the log;
5. output the database and the log to an external device via a network;
6. output to the external device via the network a copy database in which the related information of the database is deleted and the identifier is added; and7. output a copy log to the external device via the network in which the related information of the log is deleted and the identifier corresponding to the identified added in the copy database is added,8. wherein the identifier added in the copy database is information that does not contain the related information of the database,wherein the identifier added in the copy log is information that does not contain the related information of the log, and9. wherein the processor is further configured to compare the identifier added in the copy database with the identifier added in the copy log, to perform mutual tracing between the copy database and the copy log without using the related information.
Dependent Claims Analysis (Prong One)
The dependent claims are also directed to an abstract idea by further narrowing the cognitive or administrative steps.
Claims 2 and 10 (Replacing): Specifies replacing as the mechanism of substitution. This is a Mental Process refinement of the substitution judgment. No new additional elements are added.
Claims 3 and 11 (Deleting Personal Info): Extends the redaction judgment to include personal fields such as name. This is a Mental Process: a judgment about which additional fields are sensitive. No new additional elements are added.
Claims 4 and 12 (Accumulation Database): Recites a data retention rule to keep records. This is a Mental Process: a judgment to preserve records in a secondary ledger. No new hardware is added as a database is a functional organization of data.
Claims 5 and 13 (Display Classification): Recites categorizing records for display. This is a Mental Process: an evaluation and classification judgment.
Claims 6 and 14 (Sample Type ID): Specifies encoding sample type in the ID. This is a Mental Process: a judgment on formatting. No new hardware is added.
Claims 7 and 15 (Display Modes): Recites conditional display based on user role. This is a Mental Process: a judgment about what information to show based on context.
Claims 8 and 16 (Button Inactivation): Recites enabling or disabling access. This is a Mental Process: a judgment to permit or deny access based on user role.
Having established that Claims 1–16 recite abstract ideas falling within the Mental Process grouping, the analysis proceeds to Step 2A, Prong Two to determine whether the additional elements (e.g., storage unit, analyzing unit, external device, display unit, button) integrate the abstract idea into a practical application.
Step 2A, Prong Two: Integration into a Practical Application
Under the broadest reasonable interpretation consistent with MPEP 2111, claim 1 recites the mental-process abstract idea of replacing patient-linked database and log information with matching non-identifying identifiers so copied database and log records remain mutually traceable after the related information is deleted. The remaining additional elements are the analyzer, sample disk, reaction disk, reagent disk, processor configured to analyze a sample, storage unit, database, log, external device, and network.
Claim 1 and 9 Analysis:
These additional elements do not integrate the abstract idea into a practical application under MPEP 2106.04(d). The analyzer hardware merely provides the sample-analysis environment from which records are produced. The claim does not use the identifier-substitution and tracing process to improve operation of the sample disk, reaction disk, reagent disk, analyzer measurement, reagent handling, sample handling, or analysis accuracy. The claimed improvement is directed to how information in database and log records is anonymized and traced after the records exist, not to a technological improvement in the analyzer itself.
The processor, storage unit, database, and log also do not integrate the exception into a practical application. The processor is recited at a high level of generality and is used as a tool to perform the abstract acts of assigning identifiers, deleting related information, adding identifiers, and comparing identifiers. The storage unit, database, and log merely hold the information on which those abstract acts operate. Claim 1 does not recite a new database architecture, a new memory structure, a new processor configuration, a new data-security protocol, or a technical improvement in storing, searching, copying, comparing, or transmitting records.
The external device and network do not change the result. The claim only requires outputting the database, log, copy database, and copy log to an external device via a network. That recitation is generic data transmission and output of the result of the abstract information-processing steps. It does not improve network operation, external-device operation, transmission security, or any particular communication protocol.
Considered as an ordered combination, the additional elements still do not impose a meaningful technological limit on the abstract idea. The claim follows an ordinary sequence: the analyzer generates sample-analysis records, the storage unit stores database/log information, the processor performs identifier substitution and comparison, and the network outputs the resulting records. This arrangement applies the abstract privacy-and-tracing rule in the technological environment of an analyzer, but it does not improve the analyzer, computer, database, storage, or network technology. Accordingly, claim 1 and 9 are directed to the judicial exception and does not integrate the exception into a practical application.
Dependent Claims Analysis
The dependent claims add only minor limitations that fail to provide the necessary integration.
Claims 2, 3, 10, and 11: These claims do not recite new additional elements beyond those already analyzed in the independent claims. Instead, they merely narrow the abstract idea of privacy-governance by specifying the method of substitution ("replacing") and the category of data to be redacted ("personal information"). Because these limitations refine the judicial exception itself without adding non-abstract hardware or improving computer functionality beyond off-the-shelf capabilities, they do not integrate the idea into a practical application.
Claims 4 and 12: These claims add a database for accumulation, which is a fails to improve computer functionality (a) limitation. While this specifies a redundant storage rule, it does not recite a new physical component or improve the technical functioning of the storage unit, merely narrowing the administrative record-keeping rule for historical auditability (h).
Claims 5, 13, 7–8, and 15–16: These claims add display modes, a display unit, and inactivating a button, which are generic user-interface limitations that serve as a mere field-of-use limitation (h). They govern the presentation of information to the user through standard interface logic rather than improving the internal functioning of the display or the analyzer hardware.
Claims 6 and 14: These claims add sample-type characters to the identifier, which is a data-formatting instruction (f) that does not overcome the abstract character of the underlying labeling process.
When viewed as a whole, the combination of these elements in the dependent and independent claims does not integrate the abstract idea because they only specify the types of data being handled or the generic interface through which the data is viewed, neither of which results in a technical advancement.
Because the claims are directed to an abstract idea without integrating it into a practical application, the analysis proceeds to Step 2B.
Step 2B: Inventive Concept Analysis
Step 2B considers whether the additional elements, individually or as an ordered combination, amount to significantly more than the judicial exception. The same additional elements remain: the analyzer, sample disk, reaction disk, reagent disk, processor, storage unit, database, log, external device, and network.
Claim 1 and 9 Analysis:
The analyzer hardware does not provide an inventive concept. The claim does not require the sample disk, reaction disk, or reagent disk to operate in any unconventional way, and it does not require the identifier process to alter the physical sample analysis and well-understood refer to US 2013/0294974 A1-par. 0019, fig. 1, EP 3594688 A1, par. 0019-0021, fig. 1 and EP 3101431 A1, abstract, par. 0016-0025. Those components perform their ordinary role as analyzer components that produce or support sample-analysis records.
The processor and storage unit do not provide an inventive concept. The processor performs the abstract record-handling steps, and the storage unit stores the records. The claim recites these elements generically and does not require any non-conventional processor operation, memory arrangement, database structure, or security mechanism. The database and log content likewise do not add significantly more because they are the information being organized, anonymized, copied, and traced by the abstract idea itself.
The external device and network do not provide an inventive concept. The claim merely sends the database/log information and copied records to an external device via a network. Generic data output or transmission of the result of an abstract process is well-understood, routine, and conventional when claimed at this level of generality.
The ordered combination also does not add significantly more. The components operate in their expected roles: analyzer hardware obtains sample-analysis information, storage holds records, the processor applies the abstract identifier-replacement and comparison rule, and the network transmits the resulting records. The claim does not recite a non-generic arrangement of components or a technical solution that improves analyzer, computer, database, storage, network, or external-device functionality. Therefore, claim 1 and 9 does not recite additional elements that amount to significantly more than the judicial exception under MPEP 2106.05.
Dependent Claims Analysis
The dependent claims fail to provide an inventive concept because they either lack new additional elements or merely recite insignificant activities that do not amount to significantly more than the exception.
(Claims 2, 3, 10, and 11): These claims do not recite new additional elements beyond those already evaluated in the independent claims. Instead, as explained in Prong One, they merely narrow the abstract idea of privacy-governance by specifying the method of substitution ("replacing") and the category of data to be redacted ("personal information"). Because these limitations refine the judicial exception itself without introducing non-abstract hardware, they do not contribute to an inventive concept and remain directed to the same abstract idea identified in Step 2A, Prong One.
(Claims 4 and 12): These claims add an accumulation database, which is a fails to improve computer functionality (a) step. The specification confirms this is a standard storage implementation where "the storage unit 15 stores databases DB1 to DB7" and the "control unit 30 does not execute the operation" to change the record, effectively utilizing off-the-shelf "HDD or SSD" storage to satisfy an administrative rule (Spec., para. [0024], [0050]).
(Claims 5, 13, 7–8, and 15–16): These claims add display modes, a display unit, and inactivating a button, which is a mere field-of-use limitation (h). The specification describes this as a way to "prevent personal information from leaking to the serviceman" (Spec., para. [0073]), which the MPEP 2106.05(g) classifies as insignificant pre-solution or post-solution activity that does not transform the abstract rule of access control into a technical achievement.
(Claims 6 and 14): These claims add sample-type characters to the identifier, which is MPEP § 2106.05(f) - Mere Instructions. The specification admits "for control purposes, the identifier has an incrementable configuration" (Spec., para. [0044]), which is a basic data-labeling instruction that narrows the abstract idea without providing a technical improvement to the underlying system.
As a whole, the combination of dependent claims and additional elements is not enough because each element merely implements an administrative rule using the "general information processing device" admitted in the specification.
The claims are directed to an abstract idea and lack an inventive concept as the additional elements provide nothing significantly more than the judicial exception itself. Therefore, Claims 1–16 are rejected under 35 U.S.C. § 101.
Claim Rejections - 35 USC § 102
The following is a quotation of the appropriate paragraphs of 35 U.S.C. 102 that form the basis for the rejections under this section made in this Office action:
A person shall be entitled to a patent unless –
(a)(1) the claimed invention was patented, described in a printed publication, or in public use, on sale, or otherwise available to the public before the effective filing date of the claimed invention.
Claim 9-11 rejected under 35 U.S.C. 102(a)(1) based upon a public use or sale or other public availability of the invention Carlson et al. - US 2021/0240853 A1.
Claim 9.
Carlson teaches,
An information output method comprising:
storing, in a storage unit, a database in which related information linked to personal information of a patient having supplied a sample, and sample information of the sample to be analyzed by a processor configured to analyze the sample, an analysis result of the sample by the processor or the personal information of the patient are stored in a corresponding manner, and a log including the related information; (Carlson, fig. 4 (storage subsystem), par. 009 (schema of an input may be provided along with the data itself), par. 0034 (health information ( “ PHI ” ) is identified), par. 0007 (database row id), par. 0140 (generate a log to track the processing ( block 310 ) of each data point of the plurality of data), par. 0044-0045)
Carlson, recited logs, storage subsystem and scheme read in storing in a database health linked to patient information
setting a unique identifier for each record of the database; (Carlson, par. 0007, 0009)
Carlson identifies a system identifier e.g., a database row id used in a software/database system, and a database row id is the ordinary database mechanism by which each row/record is uniquely identified.
setting, for the related information of the log, the identifier set for the related information of the database which is the same as the related information of the log; (Carlson, par. 0007, 0076-0077, 0009)
Carlson processes protected healthcare data elements using a common lookup-table handler: when the same related identifier appears again, the handler returns the existing lookup value instead of generating a different value. Thus, the same MRN, encounter ID, database row ID, or other patient-linked identifier appearing in database/structured data and in the processing log would receive the same UUID conversion
after deleting the related information of the database and the related information of the log, outputting the database and the log to an external device via a network; (Carlson, par. 0003, 0013, fig. 10, par. 0184, fig. 3, 0142)
Carlson processes healthcare datasets so that identifying features are removed from the resulting de-identified data, and transmits that de-identified data to outside entities over computing networks. Logs 108 and the Fig. 3 tracking log satisfy the log requirement because they record processing of each data point, and the same de-identification pipeline handles protected data elements across the processed data stream. The claimed “outputting … via a network” is met by Carlson’s network interface 416, which transmits de-identified data over one or more computing networks to an outside entity.
outputting to the external device via the network a copy database in which the related information of the database is deleted and the identifier is added; (par. 0009… de-identification processor, although this would result in code duplication…, 0076… a new universally unique identifier (UUID) is generated, added to the lookup table, and returned…, 0182…de-identified data may be transmitted…networks…, 0013, 0077, par. 0134)
Carlson’s structured healthcare datasets are database-like records, Carlson generates de-identified data from those datasets, and Carlson transmits that de-identified data over computing networks to an outside entity. The required related information of the database is deleted and the identifier is added is met because Carlson’s de-identified data lacks at least one of the plurality of identifying features, while the lookup-table handler adds and returns a UUID replacement for the identifying data element.and outputting a copy log to the external device via the network in which the related information of the log is deleted and the identifier corresponding to the identified added in the copy database is added, (Carlson, par. 0003 -0004, 0076-0077, 0171, 0044, 0140)
Carlson’s logging engine creates logs for processing/audit/provenance, Carlson de-identifies protected healthcare data by removing or transforming identifying features, and Carlson transmits de-identified data to outside entities over networked components. The same-identifier relationship is supported by Carlson’s lookup-table handler: when the same protected identifier is encountered again, the existing lookup value is returned, and Carlson’s example confirms that related identifier values can receive the same UUID conversion. Thus, where the same related identifier appears in the structured/copy database and in the processing/audit log, Carlson’s common de-identification service would add the same UUID-type identifier while deleting or replacing the original related information.
wherein the identifier added in the copy database is information that does not contain the related information of the database,(Carlson, par. 0003, 0013, 0077-0079)
Carlson meets the limitation because the original identifying feature is absent or obfuscated in the de-identified output, while the replacement value is a UUID or lookup-table value, not the original MRN, encounter ID, database-row ID, or other related information.
wherein the identifier added in the copy log is information that does not contain the related information of the log,(fig. 1- fig.3, par. 0044, 0003, 0079)
Carlson meets the limitation because its logging/provenance system tracks processed data points, while its de-identification handler replaces protected identifiers with UUID-type output values rather than carrying forward the original PHI value.
and wherein the processor is further configured to compare the identifier added in the copy database with the identifier added in the copy log, (par. 0004, 0006, 0077, 0171)
Carlson reasonably meets the limitation because the same lookup-table identifier is returned for repeated protected identifiers, the outputs are intended to remain linked across de-identified datasets, and the logging engine supports inspection/provenance of transmitted data; a POSITA would understand that linking a de-identified structured dataset with its corresponding log by the same UUID requires matching/comparing the identifiers.
to perform mutual tracing between the copy database and the copy log without using the related information. (Carlson, par. 0003-0004, 0006, 0019, 0076, 0171)
Carlson meets this because its centralized de-identification framework removes or obfuscates PHI, replaces repeated protected identifiers through the same lookup value/UUID mechanism, and expressly preserves linkage and later reassembly of de-identified datasets through non-PHI linking information.Claim 10.
Carlson teaches The information output method according to Claim 9, wherein setting the identifier is replacing the related information of the log with the identifier set for the related information of the database which is the same as the related information of the log. (Carlson, par. 0077, 0140)
Carlson meets this because the same protected data element is processed through a lookup-table replacement handler, and repeated occurrences receive the existing lookup value/UUID; the log tracks processing of each data point and may include the mapping between the original subject identifier and the generated unique identifier.Claim 11.
Carlson teaches The information output method according to Claim 9, wherein outputting the database and the log includes outputting the database and the log to the external device via the network after deleting the related information and the personal information of the database, and the related information and personal information of the log. (Carlson, fig. 1-3, par. 0003, fig.10)
Under BRI, Claim 11 requires external network output after patient-linked related information and personal information have been removed or transformed from the database/log information. Carlson meets the database-side requirement directly through de-identified healthcare data transmitted to outside entities, and meets the log side reasonably because its logging engine/logs are part of the same de-identification framework that tracks processed data points. No material missing element is apparent if Carlson’s logs are read as de-identified processing/provenance logs rather than only secure internal re-identification logs.
Claim Rejections - 35 USC § 103
The following is a quotation of 35 U.S.C. 103 which forms the basis for all obviousness rejections set forth in this Office action:
A patent for a claimed invention may not be obtained, notwithstanding that the claimed invention is not identically disclosed as set forth in section 102, if the differences between the claimed invention and the prior art are such that the claimed invention as a whole would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to which the claimed invention pertains. Patentability shall not be negated by the manner in which the invention was made.
The factual inquiries for establishing a background for determining obviousness under 35 U.S.C. 103 are summarized as follows:
1. Determining the scope and contents of the prior art.
2. Ascertaining the differences between the prior art and the claims at issue.
3. Resolving the level of ordinary skill in the pertinent art.
4. Considering objective evidence present in the application indicating obviousness or nonobviousness.
Claims 12-16 are rejected under 35 U.S.C. § 103 as being unpatentable over Carlson et al. - US 2021/0240853 A1, and further in view of Karan - CN 103619255.
Note: strikethrough means language not clearly describe in primary prior art.
Claim 12.
Carlson teaches The information output method according to Claim 9, further comprising:storing (Carlson,0038, 0045, 0140, 0019)
Carlson supports the storage and healthcare-result because Carlson stores relational/structured healthcare data, including lab results, in a storage subsystem, and also stores logs or reassembly data.
when a record is to be added to the database, adding a record corresponding to the record to (Carlson,0037-0038, fig. 1-3, par. 0140)
Carlson supports adding/importing new datasets into a continuous pipeline and recording processing information in a log/database.
and when the record is to be deleted from the database, keeping the record corresponding to the record in (Carlson, par. 0003-0004, 0019, 0140)
Carlson supports retaining reassembly/audit information after de-identification because it stores lookup/reassembly data and may maintain an auditable log.
Carlson teaches storing healthcare result data, logs, and reassembly information in persistent storage, as shown by structured data files... may contain recorded physiological measurements, lab results, Carlson 0045; the log may include a two-way mapping, Carlson 0140; and storage subsystem 424, Carlson Fig. 4. This reads on the storage/result/audit environment because Carlson stores patient-linked healthcare result records and audit-linking information.
However, Carlson does not teach accumulation-record handling.
Karan teaches the missing accumulation-record handling, as shown by establishing storing... a copy of the test data... on the remote device, Karan 0180; test data... synchronized to the remote data storage device, Karan 0180; the table may be organized into records, Karan 0181; and when the firmware updating device, keeping the current device setting and testing history, Karan 0166. This teaches a copied, synchronized record table that preserves analyte test history apart from the active device state.
A POSITA would have combined Carlson with Karan to preserve traceable healthcare test-result history after de-identification, deletion, or database maintenance, by adding Karan’s synchronized remote test-data record table and testing-history retention to Carlson’s de-identification storage/log system. Carlson already preserves audit/reassembly information for de-identified healthcare data, while Karan teaches copying test data into record tables and keeping testing history; the modification predictably retains corresponding accumulation records for later audit and investigation.
Claim 13.
Carlson teaches The information output method according to Claim 9, further comprising:controlling a plurality of records in the database in a manner to classify the records (Carlson, fig.3-4, par. 0052)
Carlson includes a user-output/display subsystem.
Carlson does not teach records to be displayed on a display and records not to be displayed on the display.
Karan teaches the missing display/non-display control, as shown by the device can display the masking mode screen... the user can obtain a reading sensor, without displaying the obtained reading to the user, Karan 0261; and picture 398 does not provide the obtained reading to the user. obtained readings... are stored in the device, Karan 0302. This teaches stored analyte records controlled by display visibility: ordinary results may be displayed, while masked-mode results are stored but not displayed.
A POSITA would have combined Carlson with Karan to prevent unnecessary disclosure of protected healthcare records, by applying Karan’s masking-mode visibility control to Carlson’s classified healthcare records. Carlson already classifies sensitive data for handler-based processing, and Karan supplies the known display rule that a stored analyte reading can be obtained and retained without being shown. The predictable result is a database control arrangement that classifies records as displayable or non-displayable.
Claim 14.
Carlson teaches The information output method according to Claim 9, wherein the identifier (Carlson, 0051-0053, 0077)
Carlson’s tags indicate data modality/study type and may guide identifier assignment.
Carlson does not teach a character or sign indicating a type of the sample within the identifier.
Karan teaches the missing sample/test-type indication, as shown by test strip may include identifying elements... so that device can identify the type of test strip, Karan 0329, and by distinguishing glucose and ketone testing, Karan 0360–0368. This teaches using a sign or identifying element to determine the type of analyte sample/test before result generation.
A POSITA would have combined Carlson with Karan to make de-identified records easier to sort and investigate by sample/test type, by modifying Carlson’s subtype-aware identifier to include Karan’s known glucose/ketone or test-strip-type indication. Carlson already uses subtype classification to assign identifiers, and Karan teaches identifying the test/sample type at measurement; encoding that known type information into the identifier would have been a predictable record-management variation.
Claim 15.
Carlson teaches The information output method according to Claim 9, further comprising:in a first display mode, displaying information including the related information on a display and in a second display mode, displaying information except the related information on the display (Carlson,fig.7, fig.4, fig.6, par. 0151)
Carlson discloses different levels of de-identified data, a clinical/re-identification path, inspection by data security officers, and user-output devices.Carlson does not teach a first display mode and a second display mode controlling whether related information is shown on the display.
Karan teaches the missing first/second display-mode behavior, as shown by receiving operation according to the masking mode indication... sensor reading is not displayed on the display, Karan 0776; receiving operation according to a masking mode indication... the sensor reading is displayed on the display, Karan 0777; and picture 398 does not provide the obtained reading to the user, Karan 0302. This teaches a normal display mode and a masking display mode for the same analyte-reading information.
A POSITA would have combined Carlson with Karan to implement privacy-tiered display output, by applying Karan’s normal/masking display modes to Carlson’s de-identified healthcare data system. Carlson already separates data by de-identification level and re-identification context, and Karan supplies the concrete GUI mode control for displaying or withholding sensitive result information. The predictable result is a first display mode showing related information for authorized use and a second display mode hiding related information for restricted use.
Claim 16.
Carlson teaches The information output method according to Claim 15, further comprising:in the first display mode, displaying on the display button to show the personal information, and showing the personal information on the display according to selection with the button; (Carlson,)
and in the second display mode, prohibiting reference to the personal information, or inactivating the button. (Carlson,par. 0140-0143)
Carlson teaches touchscreen/display hardware and re-identification capability because it discloses a touchscreen incorporated into the display and a display subsystem, and further teaches that processing can be reversed to re-identify previously de-identified data points.
However, Carlson does not teach displaying a button to show personal information, showing the personal information in response to selection of that button, or inactivating the button in the second mode.
Karan teaches the missing button-based and restricted-mode GUI control, as shown by the user can through trigger element on the device to navigate through branch of each picture, Karan 0201; touch screen display and trigger element is displayed on the icon of the touch screen, Karan 0202; access to professional option image 2502 code or password is needed, Karan 0597; and masking mode interface 2510 includes an activation icon, symbol, a trigger element, Karan 0601. This teaches selectable GUI trigger elements and password/masking-mode access control for restricting sensitive display functions.
A POSITA would have combined Carlson with Karan to control access to re-identifiable personal information, by implementing Karan’s touch-screen trigger/button and masking/password-restricted interface in Carlson’s healthcare de-identification/re-identification system. Carlson already provides re-identification for secure contexts, and Karan supplies the predictable user-interface mechanism for selecting an information screen and restricting access in a masked/professional mode. The predictable result is a first mode in which an authorized user selects a button to show personal information and a second mode in which that access path is blocked or inactive.
Claims 1-3 are rejected under 35 U.S.C. § 103 as being unpatentable over Carlson et al. - US 2021/0240853 A1 in view of Tokiwa - US 2020/0141960 A1.
Claims 1-3 are rejected based on the corresponding rejection of method claims 9-11 because claims 1-3 recite apparatus limitations that mirror the information-output limitations of claims 9-11. The findings and rationale set forth above for claims 9-11 over Carlson therefore apply to the corresponding limitations of claims 1-3. The additional analyzer structure recited in claim 1, namely a sample disk, a reaction disk, a reagent disk, and a processor configured to analyze a sample, is not taught by Carlson alone, but is taught by Tokiwa, as explained below.
Carlson teaches a processor-based healthcare information system, as shown by Processor s 414, Carlson Fig. 4, and healthcare data collected from health care equipment and personnel, Carlson 0002. This teaches processor-based handling of healthcare information from healthcare equipment. However, Carlson does not teach a sample disk, a reaction disk, a reagent disk, and a processor configured to analyze a sample.
Tokiwa teaches the missing analyzer hardware and sample-analysis processor, as shown by a reaction disk 2, a sample disk 3, a first reagent disk 4, a second reagent disk 5... and a photometer 6 are disposed on a casing of the automatic analyzer 1, Tokiwa 0022; The reaction disk 2 is a disk-shaped unit... reaction containers 7 can be arranged, Tokiwa 0023; The sample disk 3 is a disk-shaped unit... analyte sample containers 8 containing samples... can be arranged, Tokiwa 0024; The first reagent disk 4 and the second reagent disk 5 are disk-shaped units... reagent containers containing a reagent can be arranged, Tokiwa 0025; the computer 203 is connected... via an interface 207, Tokiwa 0033; and concentration data is calculated, Tokiwa 0048. Tokiwa therefore supplies the exact disk-based clinical analyzer structure and the computer-controlled sample-analysis function missing from Carlson.
A POSITA would have combined Carlson with Tokiwa to apply Carlson’s healthcare de-identification and information-output framework to a known automated clinical analyzer that generates biological sample-analysis data, by using Tokiwa’s automatic analyzer as the healthcare equipment source of the sample-analysis results handled by Carlson. Carlson expressly addresses protected healthcare data collected from healthcare equipment, Carlson 0002–0003, while Tokiwa supplies the conventional analyzer that physically analyzes blood or urine samples using sample, reaction, and reagent disks, Tokiwa 0001–0002, 0022–0025. Doing so would have predictably produced a disk-based automated analyzer that generates sample-analysis results and then protects and outputs the resulting healthcare information using Carlson’s processor-based data-protection system.
Claims 5-8 are rejected under 35 U.S.C. § 103 as being unpatentable over Carlson et al. - US 2021/0240853 A1 in view of Tokiwa - US 2020/0141960 A1 and further view of Karan - CN 103619255.
Claims 5-8 are rejected based on the corresponding rejection of method claims 12-16 because claims 5-8 recite apparatus limitations that mirror limitations of claims 12-16. The findings and rationale set forth above for claims 12-16 over Carlson and Karan therefore apply to the corresponding limitations of claims 5-8.
Relevant Prior Arts:
US20080147554
Stevens teaches the database, processor, healthcare/laboratory data, non-identifying identifier, deletion of personal information, network output, and identifier-based tracing portions of the limitation. Stevens discloses a data source with database and processor, where healthcare data 112 can include ... laboratory data ... test results, par. 0025, the anonymous linking code is appended to healthcare data, PII is removed par. 0041, and data can be linked ... without using PI par. 0022I. Stevens further teaches a new sanitized output file because a new file is created after removed-PII fields are skipped par. 0066, and the resulting modified file is transmitted by secure FTP. Stevens also teaches comparison for tracing because the linkage module compares the received anonymous linking code with stored anonymous linking codes, and matching codes indicate corresponding files for the same patient. These disclosures read on the claimed copy database with deleted related information and added identifier because Stevens removes PII from healthcare/laboratory data, appends a non-identifying anonymous linking code, creates a new modified file without PII, transmits it, and later links records by comparing the code instead of using identifying information.
US20150104351
Makino teaches the analyzer hardware because Makino discloses that the automatic analyzer includes reaction disk 10, sample disk 20, reagent disks, photometer, and computer, that samples include biological samples such as blood and urine, that the photometer output is applied to an A/D converter, and that memory stores analysis requests, calibration results, and analyses. Refer abstract, par. 0063, fig. 1
US20090282036
Fedtke teaches the log-output feature because Fedtke discloses that dump/log files are created for problem determination and analysis, that a dump file and a log file are interchangeable, that the dump/log anonymizer can modify, remove, and/or anonymize confidential information, and that the anonymized dump/log file is transmitted over a network. Fedtke therefore supplies the log-side sanitization and service/debugging output context missing from Stevens: an original log is anonymized by removing or modifying confidential information while preserving technical usability and then transmitted to a recipient for analysis. Refer to Par. 0023, 0038-0039, abstract
Conclusion
Applicant's amendment necessitated the new ground(s) of rejection presented in this Office action. Accordingly, THIS ACTION IS MADE FINAL. See MPEP § 706.07(a). Applicant is reminded of the extension of time policy as set forth in 37 CFR 1.136(a).
A shortened statutory period for reply to this final action is set to expire THREE MONTHS from the mailing date of this action. In the event a first reply is filed within TWO MONTHS of the mailing date of this final action and the advisory action is not mailed until after the end of the THREE-MONTH shortened statutory period, then the shortened statutory period will expire on the date the advisory action is mailed, and any nonprovisional extension fee (37 CFR 1.17(a)) pursuant to 37 CFR 1.136(a) will be calculated from the mailing date of the advisory action. In no event, however, will the statutory period for reply expire later than SIX MONTHS from the mailing date of this final action.
Any inquiry concerning this communication or earlier communications from the examiner should be directed to JOSHUA DAMIAN RUIZ whose telephone number is (571)272-0409. The examiner can normally be reached 0800-1800.
Examiner interviews are available via telephone, in-person, and video conferencing using a USPTO supplied web-based collaboration tool. To schedule an interview, applicant is encouraged to use the USPTO Automated Interview Request (AIR) at http://www.uspto.gov/interviewpractice.
If attempts to reach the examiner by telephone are unsuccessful, the examiner’s supervisor, Shahid Merchant can be reached at (571) 270-1360. The fax phone number for the organization where this application or proceeding is assigned is 571-273-8300.
Information regarding the status of published or unpublished applications may be obtained from Patent Center. Unpublished application information in Patent Center is available to registered users. To file and manage patent submissions in Patent Center, visit: https://patentcenter.uspto.gov. Visit https://www.uspto.gov/patents/apply/patent-center for more information about Patent Center and https://www.uspto.gov/patents/docx for information about filing in DOCX format. For additional questions, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). If you would like assistance from a USPTO Customer Service Representative, call 800-786-9199 (IN USA OR CANADA) or 571-272-1000.
/JOSHUA DAMIAN RUIZ/Examiner, Art Unit 3684
/Shahid Merchant/Supervisory Patent Examiner, Art Unit 3684