Prosecution Insights
Last updated: October 04, 2026
Application No. 19/066,094

TAGGING AND AUDITING SENSITIVE INFORMATION IN A DATABASE ENVIRONMENT

Final Rejection §DP
Filed
Feb 27, 2025
Priority
Mar 15, 2019 — continuation of 10/521,605 +4 more
Examiner
LWIN, MAUNG T
Art Unit
Tech Center
Assignee
Gusto Inc.
OA Round
2 (Final)
89%
Grant Probability
Favorable
3-4
OA Rounds
7m
Est. Remaining
99%
With Interview

Examiner Intelligence

Grants 89% — above average
89%
Career Allowance Rate
554 granted / 623 resolved
+28.9% vs TC avg
Strong +22% interview lift
Without
With
+21.8%
Interview Lift
resolved cases with interview
Typical timeline
2y 2m
Avg Prosecution
17 currently pending
Career history
632
Total Applications
across all art units

Statute-Specific Performance

§101
12.4%
-27.6% vs TC avg
§103
31.5%
-8.5% vs TC avg
§102
13.6%
-26.4% vs TC avg
§112
35.5%
-4.5% vs TC avg
Black line = Tech Center average estimate • Based on career data from 623 resolved cases

Office Action

§DP
DETAILED ACTION The present application, filed on or after March 16, 2013, is being examined under the first inventor to file provisions of the AIA . This office action is in response to the amendment filed on 08/13/2026. Claims 1-8, 10-18 and 20 are currently pending in this application. Claims 1-5, 8, 10-15, 18 and 20 have been amended. Claims 9 and 19 are cancelled. No new IDS has been filed. Response to Arguments The previous 112(b) rejections to the claims 1-8, 10-18 and 20 have been withdrawn in response to the applicants’ amendments/remarks. The previous 102 rejections to the claims 1-8, 10-18 and 20 have been withdrawn in response to the applicants’ amendments/remarks. Regarding the double patenting rejections, the applicants have amended claims (e.g., including the limitations of the previous claim 9 into the claim 1, etc.), and have, in page 8 of the remarks, argued that “… claims, as amended, are believed to overcome these rejections, and the withdrawal of these rejections is requested”. The applicants’ argument is not persuasive. As the applicants noted, the limitations of the previous claim 9 are clearly rejected on page 9 of the previous office action, the updated rejections, according to the current amendments, are stated below. Thus, the applicants’ arguments are not persuasive. Please see amended rejections below for the amended claims. This action is final. Double Patenting The nonstatutory double patenting rejection is based on a judicially created doctrine grounded in public policy (a policy reflected in the statute) so as to prevent the unjustified or improper timewise extension of the “right to exclude” granted by a patent and to prevent possible harassment by multiple assignees. A nonstatutory double patenting rejection is appropriate where the claims at issue are not identical, but at least one examined application claim is not patentably distinct from the reference claim(s) because the examined application claim is either anticipated by, or would have been obvious over, the reference claim(s). See, e.g., In re Berg, 140 F.3d 1428, 46 USPQ2d 1226 (Fed. Cir. 1998); In re Goodman, 11 F.3d 1046, 29 USPQ2d 2010 (Fed. Cir. 1993); In re Longi, 759 F.2d 887, 225 USPQ 645 (Fed. Cir. 1985); In re Van Ornum, 686 F.2d 937, 214 USPQ 761 (CCPA 1982); In re Vogel, 422 F.2d 438, 164 USPQ 619 (CCPA 1970); and In re Thorington, 418 F.2d 528, 163 USPQ 644 (CCPA 1969). A timely filed terminal disclaimer in compliance with 37 CFR 1.321(c) or 1.321(d) may be used to overcome an actual or provisional rejection based on a nonstatutory double patenting ground provided the reference application or patent either is shown to be commonly owned with this application, or claims an invention made as a result of activities undertaken within the scope of a joint research agreement. A terminal disclaimer must be signed in compliance with 37 CFR 1.321(b). The USPTO internet Web site contains terminal disclaimer forms which may be used. Please visit http://www.uspto.gov/forms/. The filing date of the application will determine what form should be used. A web-based eTerminal Disclaimer may be filled out completely online using web-screens. An eTerminal Disclaimer that meets all requirements is auto-processed and approved immediately upon submission. For more information about eTerminal Disclaimers, refer to http://www.uspto.gov/patents/process/file/efs/guidance/eTD-info-I.jsp. Claims 1-20 of the Patent US 12,314,438 B2 contain every element of claims 1-8, 10-18 and 20 of the instant application and as such anticipates claims 1-8, 10-18 and 20 of the instant application. A later patent claim is not patentably distinct from an earlier patent claim if the later claim is obvious over, or anticipated by, the earlier claim. In re Longi, 759 F.2d at 896, 225 USPQ at 651 (affirming a holding of obviousness-type double patenting because the claims at issue were obvious over claims in four prior art patents); In re Berg, 140 F.3d at 1437, 46 USPQ2d at 1233 (Fed. Cir. 1998) (affirming a holding of obviousness-type double patenting where a patent application claim to a genus is anticipated by a patent claim to a species within that genus). “ELI LILLY AND COMPANY v BARR LABORATORIES, INC., United States Court of Appeals for the Federal Circuit, ON PETITION FOR REHEARING EN BANC (DECIDED: May 30, 2001). Current Application No. 19/066094 Reference Patent No.: US 12,314,438 B2 Claim 1: A method of restricting a display of data comprising: after an interface is displayed on a client device that includes a set of fields for including sensitive information and a set of interface elements obscuring the set of fields, receiving, by a security engine, a request from a requesting entity via the client device to view first sensitive information within a first field of the set of fields obscured by a first interface element of the set of interface elements; and in response to determining that the requesting entity is authorized to view the requested first sensitive information, 1) accessing, by the security engine, the requested sensitive information from a database and removing the first interface element and displaying the accessed first sensitive information within the first field without the field being obscured, and 2) accessing, by the security engine, additional sensitive information from the database that the requesting entity is authorized to view and removing additional interface elements and displaying the accessed additional sensitive information within additional fields of the set of fields without the additional fields being obscured; wherein, in response to determining that the requesting entity is not authorized to view the sensitive information, the first sensitive information is not accessed from the database. Claim 1: A method of restricting a display of data comprising: displaying, by a security engine, an interface on a client device of a requesting entity for displaying (or including for display) sensitive information in a set of fields of the interface, the interface including a corresponding interface element that obscures each field (of the set of fields), wherein the client device accesses information for display within the interface from a database that includes sensitive flags indicating columns of sensitive information; after displaying the interface on the client device, receiving, by the security engine, a request from the requesting entity to view the sensitive information within a first field obscured by a corresponding (equivalent to a first) interface element; and in response to determining that the requesting entity is authorized to view the requested sensitive information, 1) accessing, by the security engine, the requested sensitive information from the database and removing the corresponding interface element such that the accessed sensitive information is displayed within the first field without the field being obscured, and 2) accessing, by the security engine, additional sensitive information that the requesting entity is authorized to view and removing corresponding interface elements such that the accessed additional sensitive information is displayed within additional fields of the set of fields without the additional fields being obscured. Claim 9: The method of claim 8, wherein the sensitive information is not accessed from the database in response to determining that the requesting entity is not authorized to view the sensitive information. Claim 2: The method of claim 1, further comprising: accessing, by the security engine, non-sensitive information from the database; and displaying in the interface, by the security engine, the non-sensitive information within a non-sensitive data field of the interface. Claim 2: The method of claim 1, further comprising: accessing, by the security engine, non-sensitive information from the database; and displaying in the interface, by the security engine, the non-sensitive information within a corresponding non-sensitive data field of the interface. Claim 3: The method of claim 1, further comprising modifying, by the security engine, a data access log to identify the request to view the first sensitive information, the modified data access log identifying the requesting entity, the first sensitive information, and a time associated with the request to view the first sensitive information. Claim 3: The method of claim 1, further comprising modifying, by the security engine, a data access log to identify the request to view the sensitive information, the modified data access log identifying the requesting entity, the sensitive information, and a time associated with the request to view the sensitive information. Claim 4: The method of claim 3, further comprising in response to determining that the requesting entity is not authorized to view the first sensitive information, initiating by the security engine, an audit of the modified data access log. Claim 4: The method of claim 3, further comprising in response to determining that the requesting entity is not authorized to view the sensitive information, initiating by the security engine, an audit of the modified data access log. Claim 5: The method of claim 3, wherein the modified data access log further includes information representative of at least one of: a user account associated with the requesting entity, a hardware device used by the requesting entity to access the first sensitive information in the database, a software application used by the requesting entity to access the first sensitive information in the database, and an indication of whether a request to view the first sensitive information was granted. Claim 5: The method of claim 1, wherein the modified data access log further includes information representative of at least one of: a user account associated with the requesting entity, a hardware device used by the requesting entity to access sensitive information in the database, a software application used by the requesting entity to access sensitive information in the database, and an indication of whether a request to view a set of sensitive information was granted. Claim 6: The method of claim 3, wherein the modified data access log includes information identifying the interface. Claim 6: The method of claim 3, wherein the modified data access log includes information identifying the interface. Claim 7: The method of claim 3, wherein the modified data access log further includes information identifying sensitive data fields located within the interface. Claim 7: The method of claim 3, wherein the modified data access log further includes information identifying sensitive data fields located within the interface. Claim 8: The method of claim 1, further comprising: in response to determining that the requesting entity is not authorized to view the first sensitive information, displaying a message in the interface indicating that the requesting entity is not authorized to view the first sensitive information. Claim 8: The method of claim 1, further comprising: in response to determining that the requesting entity is not authorized to view the sensitive information, displaying a message in the interface indicating that the requesting entity is not authorized to view the sensitive information. Claim 10: The method of claim 1, wherein the first interface element comprises an opaque or semi-opaque box obscuring the field. Claim 10: The method of claim 1, wherein the interface element comprises an opaque or semi-opaque box obscuring the field … Claims 11-20 of the Patent US 12,314,438 B2 contain every element of claims 11-18 and 20 of the instant application and as such anticipates claims 11-18 and 20 of the instant application – see the above table for similar matching of the non-transitory computer readable storage medium claims 11-18 and 20. Claims 1 and 6-19 of the Patent US 10,521,605 B1 contain every element of claims 1-8, 10-18 and 20 of the instant application and as such anticipates claims 1-8, 10-18 and 20 of the instant application. Current Application No. 19/066094 Reference Patent No.: US 10,521,605 B1 Claim 1: A method of restricting a display of data comprising: after an interface is displayed on a client device that includes a set of fields for including sensitive information and a set of interface elements obscuring the set of fields, receiving, by a security engine, a request from a requesting entity via the client device to view first sensitive information within a first field of the set of fields obscured by a first interface element of the set of interface elements; and in response to determining that the requesting entity is authorized to view the requested first sensitive information, 1) accessing, by the security engine, the requested sensitive information from a database and removing the first interface element and displaying the accessed first sensitive information within the first field without the field being obscured, and 2) accessing, by the security engine, additional sensitive information from the database that the requesting entity is authorized to view and removing additional interface elements and displaying the accessed additional sensitive information within additional fields of the set of fields without the additional fields being obscured; wherein, in response to determining that the requesting entity is not authorized to view the sensitive information, the first sensitive information is not accessed from the database. Claim 1: A method of restricting a display of data comprising: displaying, by a security engine, an interface on a client device for displaying … one or more sets of sensitive information from a database, each of the one or more sets of non-sensitive information to be displayed in a corresponding non-sensitive data field (equivalent to the interface elements), and each of the one or more sets of sensitive information to be displayed in a corresponding sensitive data field, …; for each of the one or more sets of sensitive information: displaying, by the security engine, a selectable graphical interface element within the interface to at least partially obscure the corresponding sensitive data field; and in response to receiving a request to view the set of sensitive information, the request comprising a selection of the selectable graphical interface element, and in response to determining that a requesting entity is authorized to view the set of sensitive information: accessing, by the security engine, the set of sensitive information from the database and displaying the set of sensitive information within the corresponding sensitive data field, modifying, by the security engine, the interface by removing the selectable graphical interface element from the interface, wherein the corresponding sensitive data field is no longer obscured (equivalent to without the additional fields being obscured, etc.) and … Claim 7: The method of claim 6, wherein for each one of the one or more sets of sensitive information, the set of sensitive information is not accessed from the database in response to determining that the requesting entity is not authorized to view the set of sensitive information. Claim 2: The method of claim 1, further comprising: accessing, by the security engine, non-sensitive information from the database; and displaying in the interface, by the security engine, the non-sensitive information within a non-sensitive data field of the interface. Claim 1: A method of restricting a display of data comprising: … for each of the one or more sets of non-sensitive information, accessing, by the security engine, the set of non-sensitive information from the database and displaying the set of non-sensitive information within the corresponding non-sensitive data field; … Claim 3: The method of claim 1, further comprising modifying, by the security engine, a data access log to identify the request to view the first sensitive information, the modified data access log identifying the requesting entity, the first sensitive information, and a time associated with the request to view the first sensitive information. Claim 1: A method of restricting a display of data comprising: … modifying, by the security engine, a data access log to identify the request to view the set of sensitive information, the modified data access log identifying the requesting entity, the set of sensitive information, and a time associated with the request to view the set of sensitive information. Claim 4: The method of claim 3, further comprising in response to determining that the requesting entity is not authorized to view the first sensitive information, initiating by the security engine, an audit of the modified data access log. Claim 8: The method of claim 1, further comprising: … in response to determining that the requesting entity is not authorized to view the set of sensitive information, initiating, by the security engine, an audit of the modified data access log. Claim 5: The method of claim 3, wherein the modified data access log further includes information representative of at least one of: a user account associated with the requesting entity, a hardware device used by the requesting entity to access the first sensitive information in the database, a software application used by the requesting entity to access the first sensitive information in the database, and an indication of whether a request to view the first sensitive information was granted. Claim 9: The method of claim 1, wherein the modified data access log further includes information representative of at least one of: a user account associated with the requesting entity, a hardware device used by the requesting entity to access sensitive information in the database, a software application used by the requesting entity to access sensitive information in the database, and an indication of whether a request to view a set of sensitive information was granted. Claim 6: The method of claim 3, wherein the modified data access log includes information identifying the interface. Claim 10: The method of claim 1, wherein the modified data access log includes information representative of the interface associated with a request to view the set of sensitive information. Claim 7: The method of claim 3, wherein the modified data access log further includes information identifying sensitive data fields located within the interface. Claim 11: The method of claim 10, wherein the modified data access log further includes information representative of sensitive data fields located within the interface, ... Claim 8: The method of claim 1, further comprising: in response to determining that the requesting entity is not authorized to view the sensitive information, displaying a message in the interface indicating that the requesting entity is not authorized to view the first sensitive information. Claim 6: The method of claim 1, further comprising: … in response to determining that the requesting entity is not authorized to view the set of sensitive information, displaying a message in the interface indicating that the requesting entity is not authorized to view the set of sensitive information. Claim 10: The method of claim 1, wherein the first interface element comprises an opaque or semi-opaque box obscuring the first field. Claim 12: The method of claim 1, wherein the selectable graphical interface element comprises an opaque or semi-opaque box obscuring the data field ... Claims 13-19 of the Patent US 10,521,605 B1 contain every element of claims 11-18 and 20 of the instant application and as such anticipates claims 11-18 and 20 of the instant application – see the above table for similar matching of the non-transitory computer readable storage medium claims 11-18 and 20. Claims 1-7, 12-17 and 20 of the Patent US 10,943,026 B2 contain every element of claims 1-8, 10-13 and 20 of the instant application and as such anticipates claims 1-8, 10-13 and 20 of the instant application. Allowable Subject Matter Claims 1-8, 10-18 and 20 would be allowable if a terminal disclaimer is filed to overcome the double patenting rejections stated above. Conclusion THIS ACTION IS MADE FINAL. Applicant is reminded of the extension of time policy as set forth in 37 CFR 1.136(a). A shortened statutory period for reply to this final action is set to expire THREE MONTHS from the mailing date of this action. In the event a first reply is filed within TWO MONTHS of the mailing date of this final action and the advisory action is not mailed until after the end of the THREE-MONTH shortened statutory period, then the shortened statutory period will expire on the date the advisory action is mailed, and any nonprovisional extension fee (37 CFR 1.17(a)) pursuant to 37 CFR 1.136(a) will be calculated from the mailing date of the advisory action. In no event, however, will the statutory period for reply expire later than SIX MONTHS from the mailing date of this final action. Any inquiry concerning this communication or earlier communications from the examiner should be directed to MAUNG T LWIN whose telephone number is (571)270-7845. The examiner can normally be reached Monday - Friday 10:00 am - 6:00 pm. Examiner interviews are available via telephone, in-person, and video conferencing using a USPTO supplied web-based collaboration tool. To schedule an interview, applicant is encouraged to use the USPTO Automated Interview Request (AIR) at http://www.uspto.gov/interviewpractice. If attempts to reach the examiner by telephone are unsuccessful, the examiner’s supervisor, Farid Homayounmehr can be reached at 571-272-3739. The fax phone number for the organization where this application or proceeding is assigned is 571-273-8300. Information regarding the status of published or unpublished applications may be obtained from Patent Center. Unpublished application information in Patent Center is available to registered users. To file and manage patent submissions in Patent Center, visit: https://patentcenter.uspto.gov. Visit https://www.uspto.gov/patents/apply/patent-center for more information about Patent Center and https://www.uspto.gov/patents/docx for information about filing in DOCX format. For additional questions, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). If you would like assistance from a USPTO Customer Service Representative, call 800-786-9199 (IN USA OR CANADA) or 571-272-1000. /MAUNG T LWIN/Primary Examiner, Art Unit 2495
Read full office action

Prosecution Timeline

Feb 27, 2025
Application Filed
Jun 17, 2026
Non-Final Rejection mailed — §DP
Aug 13, 2026
Response Filed
Sep 10, 2026
Final Rejection mailed — §DP (current)

Precedent Cases

Applications granted by this same examiner with similar technology

Patent 12748881
PRIVACY CHOREOGRAPHER FOR FULLY MANAGED SERVERLESS APPLICATION PLATFORMS
2y 7m to grant Granted Sep 29, 2026
Patent 12745075
SYSTEMS AND METHODS FOR SECURELY PAIRING A TRANSMITTING DEVICE WITH A RECEIVING DEVICE
2y 1m to grant Granted Sep 22, 2026
Patent 12739232
SYSTEMS AND METHODS FOR SECURED NETWORK INFORMATION TRANSMISSION
1y 11m to grant Granted Sep 15, 2026
Patent 12717957
COLUMN HIDING MANAGEMENT SYSTEM
1y 11m to grant Granted Aug 25, 2026
Patent 12711218
COMPUTING DEVICE
3y 4m to grant Granted Aug 18, 2026
Study what changed to get past this examiner. Based on 5 most recent grants.

Strategy Recommendation AI-generated — please review before filing

Get a prosecution strategy drawn from examiner precedents, rejection analysis, and claim mapping.
Typically takes 5-10 seconds — AI-generated, attorney review required before filing

Prosecution Projections

3-4
Expected OA Rounds
89%
Grant Probability
99%
With Interview (+21.8%)
2y 2m (~7m remaining)
Median Time to Grant
Moderate
PTA Risk
Based on 623 resolved cases by this examiner. Grant probability derived from career allowance rate.

Sign in with your work email

Enter your email to receive a magic link. No password needed.

Personal email addresses (Gmail, Yahoo, etc.) are not accepted.

Free tier: 3 strategy analyses per month