Prosecution Insights
Last updated: October 02, 2026
Application No. 19/029,028

PERMISSION-BASED CONTROL OF INTERFACING COMPONENTS WITH A MEDICAL DEVICE

Final Rejection §DP
Filed
Jan 17, 2025
Priority
Apr 26, 2018 — provisional 62/663,131 +3 more
Examiner
MCNALLY, MICHAEL S
Art Unit
2432
Tech Center
2400 — Computer Networks
Assignee
West Affum Holdings Dac
OA Round
2 (Final)
90%
Grant Probability
Favorable
3-4
OA Rounds
10m
Est. Remaining
99%
With Interview

Examiner Intelligence

Grants 90% — above average
90%
Career Allowance Rate
975 granted / 1085 resolved
+31.9% vs TC avg
Moderate +9% lift
Without
With
+8.7%
Interview Lift
resolved cases with interview
Typical timeline
2y 6m
Avg Prosecution
14 currently pending
Career history
1101
Total Applications
across all art units

Statute-Specific Performance

§101
11.7%
-28.3% vs TC avg
§103
38.0%
-2.0% vs TC avg
§102
21.7%
-18.3% vs TC avg
§112
13.9%
-26.1% vs TC avg
Black line = Tech Center average estimate • Based on career data from 1085 resolved cases

Office Action

§DP
DETAILED ACTION Notice of Pre-AIA or AIA Status The present application, filed on or after March 16, 2013, is being examined under the first inventor to file provisions of the AIA . Priority Applicant’s claim for the benefit of a prior-filed application under 35 U.S.C. 119(e) or under 35 U.S.C. 120, 121, 365(c), or 386(c) is acknowledged. Status of the Claims Claims 2-23 are presented for examination. Claims 2 and 13 are amended. Claims 10 and 20 are cancelled. Claims 22 and 23 are new. Response to Arguments Applicant’s arguments with respect to the rejections of claims 2-21 under 35 U.S.C.103 have been fully considered and are persuasive in view of Applicant’s amendment to the independent claims. The rejections of claims 2-21 under 35 U.S.C. 103 have been withdrawn. Applicant’s statement with respect to the non-statutory doubling patenting rejections is not persuasive, see rejection below. Double Patenting The nonstatutory double patenting rejection is based on a judicially created doctrine grounded in public policy (a policy reflected in the statute) so as to prevent the unjustified or improper timewise extension of the “right to exclude” granted by a patent and to prevent possible harassment by multiple assignees. A nonstatutory double patenting rejection is appropriate where the conflicting claims are not identical, but at least one examined application claim is not patentably distinct from the reference claim(s) because the examined application claim is either anticipated by, or would have been obvious over, the reference claim(s). See, e.g., In re Berg, 140 F.3d 1428, 46 USPQ2d 1226 (Fed. Cir. 1998); In re Goodman, 11 F.3d 1046, 29 USPQ2d 2010 (Fed. Cir. 1993); In re Longi, 759 F.2d 887, 225 USPQ 645 (Fed. Cir. 1985); In re Van Ornum, 686 F.2d 937, 214 USPQ 761 (CCPA 1982); In re Vogel, 422 F.2d 438, 164 USPQ 619 (CCPA 1970); In re Thorington, 418 F.2d 528, 163 USPQ 644 (CCPA 1969). A timely filed terminal disclaimer in compliance with 37 CFR 1.321(c) or 1.321(d) may be used to overcome an actual or provisional rejection based on nonstatutory double patenting provided the reference application or patent either is shown to be commonly owned with the examined application, or claims an invention made as a result of activities undertaken within the scope of a joint research agreement. See MPEP § 717.02 for applications subject to examination under the first inventor to file provisions of the AIA as explained in MPEP § 2159. See MPEP § 2146 et seq. for applications not subject to examination under the first inventor to file provisions of the AIA . A terminal disclaimer must be signed in compliance with 37 CFR 1.321(b). The filing of a terminal disclaimer by itself is not a complete reply to a nonstatutory double patenting (NSDP) rejection. A complete reply requires that the terminal disclaimer be accompanied by a reply requesting reconsideration of the prior Office action. Even where the NSDP rejection is provisional the reply must be complete. See MPEP § 804, subsection I.B.1. For a reply to a non-final Office action, see 37 CFR 1.111(a). For a reply to final Office action, see 37 CFR 1.113(c). A request for reconsideration while not provided for in 37 CFR 1.113(c) may be filed after final for consideration. See MPEP §§ 706.07(e) and 714.13. The USPTO Internet website contains terminal disclaimer forms which may be used. Please visit www.uspto.gov/patent/patents-forms. The actual filing date of the application in which the form is filed determines what form (e.g., PTO/SB/25, PTO/SB/26, PTO/AIA /25, or PTO/AIA /26) should be used. A web-based eTerminal Disclaimer may be filled out completely online using web-screens. An eTerminal Disclaimer that meets all requirements is auto-processed and approved immediately upon submission. For more information about eTerminal Disclaimers, refer to www.uspto.gov/patents/apply/applying-online/eterminal-disclaimer. Claims 2-21 are rejected on the ground of nonstatutory double patenting as being unpatentable over claims 1-20 of U.S. Patent No. 12,233,273. Although the claims at issue are not identical, they are not patentably distinct from each other because the claims of the instant application are a reorganization of the claims of the ‘273 Patent and on this basis, the claims of the ‘273 Patent anticipate the claims of the instant application. As to claim 2, the ‘273 Patent discloses a wearable cardiac monitoring system, comprising (Claim 1: A wearable cardiac monitoring system, comprising): a wearable medical device (Claim 1; a wearable cardiac monitoring device (WMD)); a processor (Claim 1: a processor); and a memory in communication with the processor (Claim 1: and a memory in communication with the processor), wherein the processor is configured to: receive a security certificate from a non-medical device requesting communication with the wearable medical device (Claim 20: receive a Certificate Signing Request (CSR) from a trusted component requesting to communicate with a wearable cardiac monitoring device (WMD), transmit the CSR to a Certificate Authority, receive a security certificate from the Certificate Authority, wherein the security certificate includes: information that specifically identifies the trusted component; a public key that enables encryption of data intended to be delivered to the trusted component; at least one data field associated with at least one function that the trusted component can perform in connection with the WMD; and a signature that authenticates the security certificate as being attested to by the Certificate Authority, transmit the security certificate to the WMD); verify the security certificate to authenticate the non-medical device, wherein the verification includes checking that the security certificate is signed by a Certificate Authority (Claim 1: the security certificate including: information that identifies a trusted component with which the WMD has secure communication, a public key that enables encryption of data intended to be delivered to the trusted component, at least one data field associated with at least one function that the trusted component can perform in connection with the WMD, and a signature that authenticates the security certificate as being attested to by a Certificate Authority) associated with the wearable cardiac monitoring system for providing therapy (Claim 8: The wearable cardiac monitoring system of claim 1, wherein the Certificate Authority is associated with the wearable cardiac monitoring system for providing therapy); initiate a secure communication between the wearable medical device and the non-medical device based on the verified security certificate, wherein the secure communication comprises encrypting data exchanged between the wearable medical device and the non-medical device using a public key from the security certificate; and deny communication with the non-medical device when the security certificate is not attested to by the Certificate Authority (Claim 1: wherein the processor is programmed to deny communication with the trusted component when the security certificate is not attested to by the Certificate Authority). As to claim 3, the ‘273 Patent discloses the wearable cardiac monitoring system of claim 2, wherein the memory comprises a certificate store to store the security certificate, the security certificate comprising: information that identifies the non-medical device with which the wearable medical device has secure communication ,the public key that enables encryption of data intended to be delivered to the non- medical device, at least one data field associated with at least one function that the non-medical device can perform in connection with the wearable medical device, and a signature that authenticates the security certificate as being attested to by the Certificate Authority (Claim 1: the memory including a certificate store in which is stored a security certificate, the security certificate including: information that identifies a trusted component with which the WMD has secure communication, a public key that enables encryption of data intended to be delivered to the trusted component, at least one data field associated with at least one function that the trusted component can perform in connection with the WMD, and a signature that authenticates the security certificate as being attested to by a Certificate Authority). As to claim 4, the ‘273 Patent discloses the wearable cardiac monitoring system of claim 3, wherein the signature comprises a digital signature created by the Certificate Authority (Claim 7: The wearable cardiac monitoring system of claim 1, wherein the signature comprises a digital signature created by the Certificate Authority.). As to claim 5, the ‘273 Patent discloses the wearable cardiac monitoring system of claim 3, wherein the at least one data field comprises information that identifies a set of permissions that are authorized to the non- medical device (Claim 2: The wearable cardiac monitoring system of claim 1, wherein the at least one data field comprises information that identifies a set of permissions that are authorized to the trusted component.). As to claim 6, the ‘273 Patent discloses the wearable cardiac monitoring system of claim 5, wherein the information that identifies the set of permissions comprises an element type, and the wearable medical device authorizes the permissions to the non-medical device based on the element type (Claim 3: The wearable cardiac monitoring system of claim 2, wherein the information that identifies the set of permissions comprises an element type, and the WMD authorizes permissions to the trusted component based on the element type.). As to claim 7, the ‘273 Patent discloses the wearable cardiac monitoring system of claim 2, wherein the wearable medical device is a wearable cardioverter defibrillator (WCD) (Claim 4: The wearable cardiac monitoring system of claim 1, wherein the WMD is a wearable cardioverter defibrillator (WCD)), and the non-medical device is a mobile device or a fixed computing device (Claim 1: a trusted component with which the WMD has secure communication). As to claim 8, the ‘273 Patent discloses the wearable cardiac monitoring system of claim 2, wherein the processor is further configured to deny communication with the non-medical device when the security certificate has been revoked (Claim 5: The wearable cardiac monitoring system of claim 1, wherein the processor is further programmed to deny communication with the trusted component when the security certificate has been revoked.). As to claim 9, the ‘273 Patent discloses the wearable cardiac monitoring system of claim 2, wherein the processor is further configured to retrieve a certificate revocation list (CRL) to determine whether the security certificate is revoked (Claim 6: The wearable cardiac monitoring system of claim 1, wherein the processor is further configured to retrieve a certificate revocation list (CRL) to determine whether the security certificate is revoked). As to claim 11, the ‘273 Patent discloses the wearable cardiac monitoring system of claim 2, wherein the non-medical device is further configured to communicate data from the wearable medical device to a cloud- based server (Claim 10: The wearable cardiac monitoring system of claim 1, wherein the trusted component is further configured to communicate data from the WMD to a cloud-based server.), the data comprising patient data (Claim 11: The wearable cardiac monitoring system of claim 1, wherein the secure communication includes patient physiological data that can be used in treating a medical condition) and device data associated with the wearable medical device (Claim 14: The medical communication system of claim 13, wherein the security certificate includes: information that specifically identifies the trusted component; a public key that enables encryption of data intended to be delivered to the trusted component; at least one data field associated with at least one function that the trusted component can perform in connection with the WMD; and a signature that authenticates the security certificate as being attested to by the Certificate Authority). As to claim 12, the ‘273 Patent discloses the wearable cardiac monitoring system of claim 2, wherein the secure communication further comprises transfer of patient physiological data that can be used to treat a medical condition (Claim 11: The wearable cardiac monitoring system of claim 1, wherein the secure communication includes patient physiological data that can be used in treating a medical condition). Claims 13-18 and 21 recite a method commensurate in scope to the system of claims 2-3, 5-9 and 11 respectively and are thus rejected under a substantially similar rationale. As to claim 19, the ‘273 Patent discloses the method of claim 13, wherein after successfully establishing the secure communication, the method further comprises configuring the wearable medical device (Claim 16: The medical communication system of claim 14, wherein the at least one data field comprises an element type having an associated set of permissions that authorize a set of tasks that the trusted component can perform in connection with the medical communication system). Claims 22 and 23 are rejected on the ground of nonstatutory double patenting as being unpatentable over claims 1-20 of U.S. Patent No. 12,233,273 in view of U.S. Patent Application Publication No. 2016/0119307 by Zollinger et al. As to claims 22 and 23, the ‘273 Patent discloses all recited elements of claims 2 and 13 from which claims 22 and 23 depend. The ‘273 Patent does not expressly disclose wherein the security certificate includes an expiration field that indicates a date after which the security certificate is no longer valid. Zollinger discloses wherein the security certificate includes an expiration field that indicates a date after which the security certificate is no longer valid (Zollinger: Page 1, Sec 8; “These security certificates typically include an expiration date. After the expiration date, messages encrypted via the expired certificate are no longer accepted by the receiving machine”). The ’273 Patent and Zollinger are analogous art because they are from, the common area of security certificate use. It would have been obvious to one of ordinary skill in the art, at or before the effective filing date of the instant application to use the certificate expiration of Zollinger in the system of the ‘273 Patent. The rationale would have been to only allow actions with a valid certificate (Zollinger: Page 1, Sec 8). Claims 2-8, 10-17 and 20-21 are rejected on the ground of nonstatutory double patenting as being unpatentable over claims 1-20 of U.S. Patent No. 11,324,960 Although the claims at issue are not identical, they are not patentably distinct from each other because the claims of the instant application are a reorganization of the claims of the 960 Patent and on this basis, the claims of the ‘960 Patent anticipate the claims of the instant application. As to claim 2, the ‘960 Patent discloses a wearable cardiac monitoring system, comprising (Claim 1: A patient monitoring medical device system, comprising: a trusted component intended for communication with a patient monitoring medical device, the patient monitoring medical device comprising a wearable cardiac monitoring system): a wearable medical device (Claim 1: the patient monitoring medical device comprising a wearable cardiac monitoring system); a processor (Claim 1: a processor configured to execute instructions); and a memory in communication with the processor (Claim 1: and a memory including a certificate store), wherein the processor is configured to: receive a security certificate from a non-medical device requesting communication with the wearable medical device (Claim 1: wherein the processor is programmed to cause the communication component to transmit the security certificate to the patient monitoring medical device in support of a request for communication with the patient monitoring medical device.); verify the security certificate to authenticate the non-medical device, wherein the verification includes checking that the security certificate is signed by a Certificate Authority (Claim 1: and a signature that authenticates the security certificate as being attested to by a Certificate Authority) associated with the wearable cardiac monitoring system for providing therapy (Claim 2: the patient monitoring medical device system recited in claim 1, wherein the Certificate Authority is a component of the patient monitoring medical device system);; initiate a secure communication between the wearable medical device and the non-medical device based on the verified security certificate (Claim 1: wherein the processor is programmed to cause the communication component to transmit the security certificate to the patient monitoring medical device in support of a request for communication with the patient monitoring medical device.), wherein the secure communication comprises encrypting data exchanged between the wearable medical device and the non-medical device using a public key from the security certificate (Claim 1: the security certificate including: information that specifically identifies the trusted component, a public key that enables encryption of data intended to be delivered to the trusted component); and deny communication with the non-medical device when the security certificate is not attested to by the Certificate Authority (Claim 4: The patient monitoring medical device system recited in claim 3, wherein the wearable cardioverter defibrillator is further configured to deny secure communications with the trusted component if the security certificate is not properly attested to by the Certificate Authority). As to claim 3, the ‘960 Patent discloses the wearable cardiac monitoring system of claim 2, wherein the memory comprises a certificate store to store the security certificate, the security certificate comprising: information that identifies the non-medical device with which the wearable medical device has secure communication, the public key that enables encryption of data intended to be delivered to the non- medical device, at least one data field associated with at least one function that the non-medical device can perform in connection with the wearable medical device, and a signature that authenticates the security certificate as being attested to by the Certificate Authority (Claim 1: and a memory including a certificate store in which is stored: a security certificate, the security certificate including: information that specifically identifies the trusted component, a public key that enables encryption of data intended to be delivered to the trusted component, at least one data field that implies at least one function that the trusted component may perform in connection with the patient monitoring medical device wherein the at least one data field comprises an element type, and further wherein the element type has an associated set of permissions that authorize a set of tasks that the trusted component may perform in connection with the patient monitoring medical device system, and a signature that authenticates the security certificate as being attested to by a Certificate Authority). As to claim 4, the ‘960 Patent discloses the wearable cardiac monitoring system of claim 3, wherein the signature comprises a digital signature created by the Certificate Authority (Claim 1: and a signature that authenticates the security certificate as being attested to by a Certificate Authority). As to claim 5, the ‘960 Patent discloses the wearable cardiac monitoring system of claim 3, wherein the at least one data field comprises information that identifies a set of permissions that are authorized to the non- medical device (Claim 1: and further wherein the element type has an associated set of permissions that authorize a set of tasks that the trusted component may perform in connection with the patient monitoring medical device system). As to claim 6, the ‘960 Patent discloses the wearable cardiac monitoring system of claim 5, wherein the information that identifies the set of permissions comprises an element type, and the wearable medical device authorizes the permissions to the non-medical device based on the element type (Claim 1: wherein the at least one data field comprises an element type, and further wherein the element type has an associated set of permissions that authorize a set of tasks that the trusted component may perform in connection with the patient monitoring medical device system). As to claim 7, the ‘960 Patent discloses the wearable cardiac monitoring system of claim 2, wherein the wearable medical device is a wearable cardioverter defibrillator (WCD) (Claim 3: The patient monitoring medical device system recited in claim 1, wherein the wearable cardiac monitoring system comprises a Wearable Cardioverter Defibrillator), and the non-medical device is a mobile device or a fixed computing device (Claim 8: The patient monitoring medical device system recited in claim 1, wherein the trusted component is further configured to communicate data from the patient monitoring medical device to a cloud-based server.). As to claim 8, the ‘960 Patent discloses the wearable cardiac monitoring system of claim 2, wherein the processor is further configured to deny communication with the non-medical device when the security certificate has been revoked (Claim 7: The patient monitoring medical device system recited in claim 1, wherein the patient monitoring medical device is further configured to deny secure communications with the trusted component if the security certificate is revoked.). As to claim 10, the ‘960 Patent discloses the wearable cardiac monitoring system of claim 2, wherein the Certificate Authority is associated with the wearable cardiac monitoring system for providing therapy (Claim 2: The patient monitoring medical device system recited in claim 1, wherein the Certificate Authority is a component of the patient monitoring medical device system.). As to claim 11, the ‘960 Patent discloses the wearable cardiac monitoring system of claim 2, wherein the non-medical device is further configured to communicate data from the wearable medical device to a cloud- based server (Claim 8: The patient monitoring medical device system recited in claim 1, wherein the trusted component is further configured to communicate data from the patient monitoring medical device to a cloud-based server.), the data comprising patient data and device data associated with the wearable medical device (Claim 9: The patient monitoring medical device system recited in claim 1, wherein the secure communication includes patient physiological data that can be used in treating a medical condition.). As to claim 12, the ‘960 Patent discloses the wearable cardiac monitoring system of claim 2, wherein the secure communication further comprises transfer of patient physiological data that can be used to treat a medical condition (Claim 9: The patient monitoring medical device system recited in claim 1, wherein the secure communication includes patient physiological data that can be used in treating a medical condition.). Claims 13-17 and 20-21 recite a method commensurate in scope to the system of claims 2-3, 5-8 and 10-11 respectively and are thus rejected under a substantially similar rationale. Claims 22 and 23 are rejected on the ground of nonstatutory double patenting as being unpatentable over claims 1-20 of U.S. Patent No. U.S. Patent No. 11,324,960 in view of U.S. Patent Application Publication No. 2016/0119307 by Zollinger et al. As to claims 22 and 23, the ‘960 Patent discloses all recited elements of claims 2 and 13 from which claims 22 and 23 depend. The ‘960 Patent does not expressly disclose wherein the security certificate includes an expiration field that indicates a date after which the security certificate is no longer valid. Zollinger discloses wherein the security certificate includes an expiration field that indicates a date after which the security certificate is no longer valid (Zollinger: Page 1, Sec 8; “These security certificates typically include an expiration date. After the expiration date, messages encrypted via the expired certificate are no longer accepted by the receiving machine”). The ’960 Patent and Zollinger are analogous art because they are from, the common area of security certificate use. It would have been obvious to one of ordinary skill in the art, at or before the effective filing date of the instant application to use the certificate expiration of Zollinger in the system of the ‘591 Patent. The rationale would have been to only allow actions with a valid certificate (Zollinger: Page 1, Sec 8). Conclusion Applicant's amendment necessitated the new ground(s) of rejection presented in this Office action. Accordingly, THIS ACTION IS MADE FINAL. See MPEP § 706.07(a). Applicant is reminded of the extension of time policy as set forth in 37 CFR 1.136(a). A shortened statutory period for reply to this final action is set to expire THREE MONTHS from the mailing date of this action. In the event a first reply is filed within TWO MONTHS of the mailing date of this final action and the advisory action is not mailed until after the end of the THREE-MONTH shortened statutory period, then the shortened statutory period will expire on the date the advisory action is mailed, and any nonprovisional extension fee (37 CFR 1.17(a)) pursuant to 37 CFR 1.136(a) will be calculated from the mailing date of the advisory action. In no event, however, will the statutory period for reply expire later than SIX MONTHS from the mailing date of this final action. Any inquiry concerning this communication or earlier communications from the examiner should be directed to MICHAEL S MCNALLY whose telephone number is (571)270-1599. The examiner can normally be reached Monday-Friday, 8:30 AM - 5:00 PM. Examiner interviews are available via telephone, in-person, and video conferencing using a USPTO supplied web-based collaboration tool. To schedule an interview, applicant is encouraged to use the USPTO Automated Interview Request (AIR) at http://www.uspto.gov/interviewpractice. If attempts to reach the examiner by telephone are unsuccessful, the examiner’s supervisor, Jeffrey L Nickerson can be reached at (469)295-9235. The fax phone number for the organization where this application or proceeding is assigned is 571-273-8300. Information regarding the status of published or unpublished applications may be obtained from Patent Center. Unpublished application information in Patent Center is available to registered users. To file and manage patent submissions in Patent Center, visit: https://patentcenter.uspto.gov. Visit https://www.uspto.gov/patents/apply/patent-center for more information about Patent Center and https://www.uspto.gov/patents/docx for information about filing in DOCX format. For additional questions, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). If you would like assistance from a USPTO Customer Service Representative, call 800-786-9199 (IN USA OR CANADA) or 571-272-1000. MICHAEL S. MCNALLY Primary Examiner Art Unit 2432 /Michael S McNally/Primary Examiner, Art Unit 2432
Read full office action

Prosecution Timeline

Jan 17, 2025
Application Filed
May 13, 2026
Non-Final Rejection mailed — §DP
Aug 13, 2026
Response Filed
Sep 03, 2026
Final Rejection mailed — §DP (current)

Precedent Cases

Applications granted by this same examiner with similar technology

Patent 12750350
AUTOMATIC ENCRYPTION FOR CLOUD-NATIVE WORKLOADS
1y 12m to grant Granted Sep 29, 2026
Patent 12744817
SECURE VERIFICATION OF DETECTION RULES ON TEST SENSORS
2y 9m to grant Granted Sep 22, 2026
Patent 12737472
ELECTRONIC DEVICE, METHOD, AND NON-TRANSITORY COMPUTER-READABLE STORAGE MEDIUM FOR PERFORMING MOUNT OPERATION FOR PART OF PARTITION
1y 11m to grant Granted Sep 15, 2026
Patent 12688292
A COMPUTER-IMPLEMENTED METHOD FOR MITIGATING ANOMALOUS ACTIVITY
1y 11m to grant Granted Jul 21, 2026
Patent 12675563
METHOD FOR UNLOCKING AN ELECTRONIC DEVICE
1y 10m to grant Granted Jul 07, 2026
Study what changed to get past this examiner. Based on 5 most recent grants.

Strategy Recommendation AI-generated — please review before filing

Get a prosecution strategy drawn from examiner precedents, rejection analysis, and claim mapping.
Typically takes 5-10 seconds — AI-generated, attorney review required before filing

Prosecution Projections

3-4
Expected OA Rounds
90%
Grant Probability
99%
With Interview (+8.7%)
2y 6m (~10m remaining)
Median Time to Grant
Moderate
PTA Risk
Based on 1085 resolved cases by this examiner. Grant probability derived from career allowance rate.

Sign in with your work email

Enter your email to receive a magic link. No password needed.

Personal email addresses (Gmail, Yahoo, etc.) are not accepted.

Free tier: 3 strategy analyses per month