WO2025003708A1 - A server for extending a point-to-point connection between a healthcare information system and at least one medical device - Google Patents
A server for extending a point-to-point connection between a healthcare information system and at least one medical device Download PDFInfo
- Publication number
- WO2025003708A1 WO2025003708A1 PCT/GB2024/051694 GB2024051694W WO2025003708A1 WO 2025003708 A1 WO2025003708 A1 WO 2025003708A1 GB 2024051694 W GB2024051694 W GB 2024051694W WO 2025003708 A1 WO2025003708 A1 WO 2025003708A1
- Authority
- WO
- WIPO (PCT)
- Prior art keywords
- data
- server
- module
- medical device
- information system
- Prior art date
- Legal status (The legal status is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the status listed.)
- Ceased
Links
Classifications
-
- G—PHYSICS
- G16—INFORMATION AND COMMUNICATION TECHNOLOGY [ICT] SPECIALLY ADAPTED FOR SPECIFIC APPLICATION FIELDS
- G16H—HEALTHCARE INFORMATICS, i.e. INFORMATION AND COMMUNICATION TECHNOLOGY [ICT] SPECIALLY ADAPTED FOR THE HANDLING OR PROCESSING OF MEDICAL OR HEALTHCARE DATA
- G16H40/00—ICT specially adapted for the management or administration of healthcare resources or facilities; ICT specially adapted for the management or operation of medical equipment or devices
- G16H40/60—ICT specially adapted for the management or administration of healthcare resources or facilities; ICT specially adapted for the management or operation of medical equipment or devices for the operation of medical equipment or devices
- G16H40/67—ICT specially adapted for the management or administration of healthcare resources or facilities; ICT specially adapted for the management or operation of medical equipment or devices for the operation of medical equipment or devices for remote operation
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L67/00—Network arrangements or protocols for supporting network services or applications
- H04L67/01—Protocols
- H04L67/12—Protocols specially adapted for proprietary or special-purpose networking environments, e.g. medical networks, sensor networks, networks in vehicles or remote metering networks
-
- G—PHYSICS
- G06—COMPUTING OR CALCULATING; COUNTING
- G06F—ELECTRIC DIGITAL DATA PROCESSING
- G06F21/00—Security arrangements for protecting computers, components thereof, programs or data against unauthorised activity
- G06F21/60—Protecting data
- G06F21/62—Protecting access to data via a platform, e.g. using keys or access control rules
- G06F21/6218—Protecting access to data via a platform, e.g. using keys or access control rules to a system of files or objects, e.g. local or distributed file system or database
- G06F21/6245—Protecting personal data, e.g. for financial or medical purposes
-
- G—PHYSICS
- G16—INFORMATION AND COMMUNICATION TECHNOLOGY [ICT] SPECIALLY ADAPTED FOR SPECIFIC APPLICATION FIELDS
- G16H—HEALTHCARE INFORMATICS, i.e. INFORMATION AND COMMUNICATION TECHNOLOGY [ICT] SPECIALLY ADAPTED FOR THE HANDLING OR PROCESSING OF MEDICAL OR HEALTHCARE DATA
- G16H40/00—ICT specially adapted for the management or administration of healthcare resources or facilities; ICT specially adapted for the management or operation of medical equipment or devices
- G16H40/40—ICT specially adapted for the management or administration of healthcare resources or facilities; ICT specially adapted for the management or operation of medical equipment or devices for the management of medical equipment or devices, e.g. scheduling maintenance or upgrades
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L63/00—Network architectures or network communication protocols for network security
- H04L63/02—Network architectures or network communication protocols for network security for separating internal from external traffic, e.g. firewalls
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L9/00—Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols
- H04L9/40—Network security protocols
Definitions
- the present invention relates to hardware and methods for extending a point-to- point connection from inside a trusted local network to outside that network. Specifically, the invention relates to hardware and methods for extending a point- to-point connection from inside a trusted local network to a remote device, for example a field device.
- Integrated care systems including hospital at home, emergency care services and virtual wards are able to alleviate some of these pressures by facilitating care and an effective triage of patients out in the community.
- one critical need is to shift diagnostic testing, currently happening within hospitals, into community settings to ensure high-quality clinical care without conveying patients into hospitals.
- medical grade Point of Care (POC) testing and patient monitoring devices can be placed into communities.
- POC Point of Care
- hospital grade POC devices often automate their recording of data into hospital information systems, this is only possible within hospital IT settings. Once POCs are taken out of hospitals into communities, they lose their ability to automatically communicate with hospital systems.
- 'real-time' access to POC data is critical to enable clinical experts to make time-critical clinical decisions for emergency care. Summary
- a server for extending a point-to-point connection between a healthcare information system and at least one medical device, the server configured: to connect to a local module via a first private network, the local module configured to connect to the healthcare information system, and to connect to a field module via a second private network, the field module configured to connect to the at least one medical device; in response to receiving data from the at least one medical device via a field module, to verify that the data is from the at least one medical device and to send the verified data using the first private network to the local module; and/or in response to receiving data from the local module to send the data to the medical device using the second private network via the field module.
- the medical device may be a device which is remote or outside of a hospital or other care-giving centre.
- the medical device may be a point of care (POC) device, or a point of care testing (POCT) device used on a patient in community or community care setting.
- POC point of care
- POCT point of care testing
- the local module may be a clinical-based device, for example, a hospital-based device, such as a hospital-based computer or server.
- a remote medical device which is in the community outside of a hospital or other caregiving or care-providing centre can automatically connect to any POC device and provide secure connections reaching into hospital information systems.
- Paramedics are therefore able to deliver mobile, laboratory-standard test results in the community with the data being communicated in 'real-time' to clinical experts in hospital pathology labs for appropriate decision-making.
- This enhanced communication may reduce unnecessary hospital admissions, help guide clinical pathway decisions, accelerates time to treatment and reduces inconvenience to patients.
- the server may be configured to connect wirelessly, for example, using broadband or narrowband radio waves, cellular connections, for example, 3G, 4G, 5G, GSM and the like.
- Data may be in the form of a data packet.
- the local module may be configured to connect to the same local area network as the healthcare information system.
- the server may be configured to connect to the local module via a single port.
- the healthcare information system can communicate with a medical device which may be in a location outside the hospital which houses the healthcare information system.
- the diagnostic results can be sent from the healthcare information system back to field module via the local module and the server in a readable format.
- the server may be configured to send the data via a single port, and/or; to receive data via the single port from the local module.
- the number of ports required to cross the hospital IT boundary may be minimised by mapping and remapping the message crossing the between the Server 9 and the local module.
- many POC devices can be connected to hospital information systems with opening a single port or more.
- the server can direct messages to one or more local modules, for example, paramedic who servers more than one hospital in an ambulance the data will be delivered to appropriate hospital local module.
- the data may be verified by checking the data size and/or frequency.
- the verification of the data may be performed by the local module or by the server.
- the verification or check may comprise checking the maximum data size.
- the verification or check may comprise software on the local module or the server which performs the verification or check.
- the data may be verified by confirming that the data conforms to a medical device data type corresponding to the medical device networked to the field module.
- the data may be verified by confirming the medical device fixed internet protocol address or media access control address.
- Data may be verified by waiting for confirmation before proceeding, checking one or more data packets from the medical device and/or the healthcare information system, checking the external service details (e.g., a software driver will check on the data may comprise a data size check, or packet size check, dates fields, message format for example, maximum packet size check, the check on the data fields and data structure may include a device type to confirm that the data or data packet comes from the correct device.
- the external service details e.g., a software driver will check on the data may comprise a data size check, or packet size check, dates fields, message format for example, maximum packet size check, the check on the data fields and data structure may include a device type to confirm that the data or data packet comes from the correct device.
- the server may be configured to communicate with the local module or field module using the transmission protocol expected by the medical device.
- the transmission protocol may be Transmission Control Protocol (TCP) or may be User Datagram Protocol (UDP).
- TCP Transmission Control Protocol
- UDP User Datagram Protocol
- the medical device may be a point of care medical device.
- the medical device may be a medical device remote from a hospital or other care-providing institution, for example, in someone's home, in a vehicle, etc.
- the point of care (POC) medical device may be a point of care testing (POCT) medical device, or a point of care (POC) monitoring device.
- POCT point of care testing
- POC point of care monitoring
- the POCT may be a blood gas analyser, a glucose monitor, bodily fluid antigen analyser.
- the POC monitoring device may be a blood pressure analyser, heart rate recorder, a pulse oximetry device.
- the field module may be configured to connect to a plurality of medical devices.
- connection between the field module and the plurality of medical devices may be a secure connection.
- the server may be configured to verify and send data from a plurality of medical devices simultaneously.
- the server may be configured to receive, verify and/or send data from multiple medical devices (e.g., 10, 20, 50, 100, 1000, 10,000 or more than 10,000 medical devices) at the same time.
- the data received may be encrypted data, and the server is configured to decrypt the data.
- the data received may be protected using a password, and the server is configured to access the data using the password.
- the field module or server may be configured to identify a test type based on the at least one medical device type, and based on the test type, send data from a test performed on the at least one medical device to an associated local module and/or hospital information system.
- the at least one medical device may be a blood sample analyser, or a saliva sample analyser, if the medical device is a blood sample analyser, the test type is given a "blood sample” ID or flag, if the medical device is a saliva sample analyser, the test type is given a "saliva sample” ID or flag.
- the field module or server can identify the type of test and then send it to the appropriate system (local module and/or hospital information system) for record keeping or further analysis.
- a local module for extending a point-to-point connection between a healthcare information system and at least one medical device, the local module configured: to connect to the healthcare information system; to connect to a sever via a private network; in response to receiving data from the server using the private network, to identify an inbound port on the healthcare information system to send the data to the healthcare information system; and/or in response to receiving data from the healthcare information system, to send data from the healthcare information system to the server.
- the local module may connect to the same local area network as the healthcare information system.
- the local module may be configured to receive data from the healthcare information system via a single port.
- the local module may be configured to send data from the healthcare information system to the server via a single port on the healthcare information system.
- the local module may be configured with the single port on the healthcare information system.
- a field module for extending a point-to-point connection between a healthcare information system and at least one medical device, the local module configured : to connect to a server via a private network; to connect to the at least one medical device; and to relay data between the at least one medical device and the server.
- the field module may comprise a location module configured to identify the location of the filed module.
- the location module may be a satellite positioning system module (e.g., a global positioning system, GPS module, or other suitable satellite positioning system), which can identify the location of the field module.
- the field module may be configured to forward the location of the field module on to the local module and/or hospital information system via the server.
- the location module may also record the time as well as the location, and may also forward this to the local module and/or the hospital information system.
- the location module may also be used to identify where and when the field module was used to communicate with a nearby medical device, thus providing the location and time of use of a medical device.
- the module may comprise an interface configured to allow data input, wherein on receiving an input of data, may send the data to the hospital information system via the server.
- the hospital information system on receiving the input data from the file module, may generate a patient record based on the received data.
- the input data system also allows for manual input of novel patient record or patient medical information additional to that which can be supplied from the test.
- the field module may be configured to: send medical device data to the healthcare information system; and receive diagnostic information from the healthcare information system based on the medical device data.
- the field module may be configured to: send medical device data to the healthcare information system; and receive instruction information from the healthcare information system based on the medical device data.
- the instruction information may be for initial or further patient care, for example, a video on how best to treat a patient from whom the medical device data has been collected.
- the instruction information may also cover information on device usage.
- a system for extending a point-to-point connection between a healthcare information system and at least one medical device comprising: a local module connected to the healthcare information system; a server connected to the local module via a first private network; and a field module connected to the server via a second private network.
- the field module is configured: to connect to the at least one medical device; and to relay data between the at least one medical device and the server.
- the server is configured: in response to receiving data from the field module, to verify that the data is from the at least one medical device and to send the verified data to the local module or receive data from the local module.
- the local module is configured : in response to receiving data from the server to forward the data to the healthcare information system; and/or in response to receiving data from the healthcare information system, to send data from the healthcare information system to the server.
- the system may be configured to monitor one or more of: field module location; field module data usage; field module activity; or field module data sent to the server.
- the first or second private networks may be virtual private networks (VPN)
- the private network may be a dual redundant private network.
- the server may be configured to send the verified data via a single port to the local module or receive data via the single port from the local module.
- the data of the local module, the field module or the server may be encrypted data and either the server, the field module, or the local module is configured to decrypt the data.
- the data of the local module, the field module, or the system may be protected using a password, and either the server, the filed module, or the local module is configured to access the data using the password.
- a server for extending a point-to-point connection between a healthcare information system and at least one field module, the server configured: to connect to a local module via a first private network, the local module configured to connect to the healthcare information system, and to connect to a field module via a second private network; in response to receiving data from the local module to send the data to the field module using the second private network via the field module; and/or in response to receiving data from the at least one field module, to verify that the data is from the at least one field module, and to send the verified data using the first private network to the local module.
- the server of the fourth or fifth aspects may be the server of the first aspect.
- the local moule of the fourth or fifth aspects may be the local module of the second aspect.
- the field module of the fourth or fifth aspects may be the field module of the third aspect.
- Figure 1 is a system block diagram of a remote medical device communication system
- Figure 2 is a system block diagram of a remote medical device communication system field device
- Figure 3 is a system block diagram of a remote medical device communication system local area network connected device.
- Figure 4 is a system block diagram of a remote medical device communication system server.
- the inventors have developed an innovative hardware and software system, that eases the mounting pressures on emergency departments, and emergency services by remotely bringing clinical hospital level expertise into communities. With this system, diagnostic testing, which patients typically attend the hospital for, can now be conducted in community settings. Medical Point of Care (POC) devices such as point of care testing, physiological monitoring, respiration and infusion devices can be operated by paramedics or other community healthcare providers or care staff, while test data is reviewed by clinical experts remotely, for example, in a hospital setting.
- the system automatically collects and securely relays data from POC devices into hospital or healthcare information systems in real time. Examples of hospital or healthcare information systems include clinical information system (CIS), electronic patient record system (EPR), laboratory information management system (LIMS), hospital middleware (or Medical Device Data Systems) or a hospital interface engine. Hospital clinical experts can use this information, for example in real-time, to make informed clinical decisions while patients and paramedics are still in the community.
- CIS clinical information system
- EPR electronic patient record system
- LIMS laboratory information management system
- the system enables paramedics to deliver mobile, laboratory-standard test results in communities, combined with remote expert clinical decisions from hospital clinical experts, for example, those working in pathology labs.
- This integrated urgent care service looks after more patients using remote clinical assessment and helps the conveyance of only those patients who require hospital care.
- the system can facilitate device connectivity and communication, which may reduce unnecessary hospital admissions, help guide clinical pathway decisions, and accelerate time to treatment.
- the system can reduce inconvenience and risks to patients who attend hospitals, for example, hospital- acquired infections. It enables patients to receive care close to their homes, supporting their continued independent living. Overall, the system provides a sustainable solution that automates the mobile use of medical devices, complementing other community care services.
- the system presented here bridges the gap between point of care testing (POCT) and hospital communication systems, enabling expert clinical diagnostics to be delivered into the community.
- POCT point of care testing
- the system automatically reads the data collected by POCT devices used in the community. The data are instantly and automatically transmitted to a hospital where they are recorded in a Hospital Information System.
- the system may allow clinical experts to use the information from POCT devices in 'real-time' to make informed, clinical decisions in hospitals while patients and paramedics are still out in the community. Further, the system will support non advanced paramedics who may not have medical device diagnostics training, in clinical decision making.
- the system may facilitate, for example:
- the system 1 is a hardware and software solution, which comprises of two modules (also referred to as devices) : a Field Module 2 (also referred to as "FiM", a “portable module”, or a “remote module”) and a local module 3 (also referred to as a hospital module, or HoM).
- the FiM 2 is a small, mobile router which can be, for example, carried in a paramedics' bag, their uniform or vehicle 4.
- the field module 2 can also be situated in a pharmacy or GP office or surgery and can be used where there is no network connection in remote locations, e.g., by using a cellular connection.
- the FiM 2 establishes a secure connection to any POC device 5, to read the device data and automatically send them securely to a hospital information system such as a hospital patient record, laboratory management or middleware system.
- the system 1 may work over a multicellular network 6, and the FiM 2 and has a power source, for example, a battery (not shown). POC device 5 results are never lost and can be resent in the event of temporary signal drop-out.
- the system 1 hospital module (HoM) 3 (also referred to as a "local module” 3) is as software solution located on or connected to (e.g., via the local area network, which may be the hospital or other care-providing service's network 8) a hospital information system 7 (which may also be referred to as a hospital server).
- the hospital module 3 is configured to remap POC devices' 5 messages to the correct entry in the hospital information system 7.
- the HoM 3 can support many makes, models, and manufacturers of medical devices 5 out in the community and is securely monitored using intelligent message protection, which will be explained in more detail later, ensuring messages are delivered under a protected closed private system.
- the system 1 can automatically connect to any POC 5 device and provide secure connections reaching into Hospital IT systems, in line with NHS regulatory requirements.
- the System 1 can direct messages to one or more HoM 3, for example, paramedic who servers more than one hospital in an ambulance the data will be delivered to appropriate hospital HoM 3.
- HoM for example, paramedic who servers more than one hospital in an ambulance the data will be delivered to appropriate hospital HoM 3.
- the system 1 allows a user to:
- the system 1 is compatible with an entity's (e.g. a hospital) security and their private network, for example, NHS security, including firewalls and the Health and Social Care Network (HSCN), or other suitable private network.
- entity's e.g. a hospital
- NHS security including firewalls and the Health and Social Care Network (HSCN), or other suitable private network.
- HSCN Health and Social Care Network
- the system 1 may contain a dual redundant private network (e.g., a VPN) in case of system failure.
- the system 1 includes intelligent security to allow specified medical device data to be communicated, with other data blocked.
- the system can prevent network attacks such as malware, denial of service, message interception and ransomware.
- the system 1 runs on a private dedicated network, using its own dedicated internet, which may allow the system 1 to require only one secured port into the hospital to connect a plurality, (for example, tens, hundreds, or thousands) of devices 5.
- the system 1 has standardisation, which assures hospital information systems 7 can connect with any medical device 5 rapidly and confidently, now and at any time in the future.
- the system 1 further comprises a server 9 hosted on a managed dedicated internet 10.
- the server 9 is connected to the file module(s) 2 via a private network 11, for example, a virtual private network (VPN).
- VPN virtual private network
- the server 9 is also connected to one or more hospital (or local) modules 3 via a private network 13 or a dedicated network which may be a Health and Social Care Network (HSCN), or another private network, e.g., a VPN.
- HSCN Health and Social Care Network
- the present system 1 has a significant impact on the health economics of the healthcare systems.
- the system 1 enables paramedics to deliver mobile, laboratory-standard test results in the community with the data being communicated in 'real-time' to remote clinical experts in a hospital department for appropriate decision-making. This enhanced communication, can reduce unnecessary hospital admissions, help guide clinical pathway decisions, accelerate time to treatment and reduce inconvenience to patients.
- the system 1 can also reduce labour costs and increases productivity of the healthcare services with significant cost savings.
- the system 1 provides an affordable and sustainable solution which can automate the mobile use of medical devices 5 including point of care devices. This enables clinical decisions and care to be brought to patients' home, which facilitates continued independent living and complements other community support. For example, the system 1 facilitates community clinical professionals and response teams in their clinical decision making from within hospitals, which will support the appropriate use of ambulances and conveyances of patients into hospital.
- POC testing by paramedics a patient was directly admitted to a hospice, negating a visit to the Emergency Department for blood tests; another patient was fast-tracked directly to the intensive care unit. Streamlined patient journeys provide inherent savings to the service and benefits to patient care. Patients report high levels of satisfaction, and paramedics confirm it adds value where it was used to support decisionmaking.
- the system 1 is capable of extending a device medical data system, which may be housed on a local module 3 within a health information system 7, or connected to the same local area network (LAN) as the health information system 7.
- a device medical data system which may be housed on a local module 3 within a health information system 7, or connected to the same local area network (LAN) as the health information system 7.
- LAN local area network
- Medical devices are networked, and the local module 3 communication interfaces collect standardised medical data from bedside and point-of-care medical devices.
- the local module 3 is a middleware solution, that can manage messages or data from a medical device, the medical device message or data may be measurements and waveforms such as heart rate, blood pressure, body temperature, and ECG, point of care results and/or diagnostic results. This includes alarms such as types, triggers, limits, thresholds, settings, and acknowledgements, to a common standard.
- the local module 3 contains medical device drivers making the system device agnostic and, therefore, can be used with many makes or manufacturers of medical devices. Including hospital legacy and newly purchased devices.
- All medical device readings can be passed to the hospital information system 7 or Clinical Information System (CIS) or Electronic Patient Record System (EPR) or Laboratory Information Management System (LIMS) or Hospital Middleware or Hospital Interface Engine.
- CIS Clinical Information System
- EPR Electronic Patient Record System
- LIMS Laboratory Information Management System
- the system 1 ensures that the local module 3 is not just limited to hospital medical devices but can reach out into the community.
- This invention relates to transferring data from a remote medical device to a hospital or healthcare information system.
- Portable medical devices 5 often provide a means to transfer test results or measurements or medical parameters to a computer, but when the device is outside of the hospital environment this can prove challenging.
- the hospital computer network will have extensive network security to prevent unauthorised access restricting data entering or leaving the hospital, and the point-to-point connectivity of mobile devices lacks the sophistication required to accommodate security protocols.
- the mobility of the devices also means they may be operated in point of care vehicles 4 (for example, ambulances) and may require a wireless method to access a network.
- the means to transfer the data may also be scalable, with medical devices installed in multiple vehicles.
- the present invention proposes the means to wirelessly connect the medical device to an hospital information system, while allowing the connectivity to be managed within the security mechanisms of the hospital.
- the system 1 has three main components:
- a portable computing device 2 which can provide a local Wi-Fi hotspot, or other wireless connection or wired connections, to a cellular data network, and a virtual portable network (VPN) client.
- VPN virtual portable network
- a cloud-based application server which also hosts a VPN server.
- the portable computing device (or field module) 2 provides network connectivity to the portable medical device 5.
- the cloud-based application server 9 provides a bridge between the portable computing device 2 and the hospital-based application server (also referred to as the hospital module, or the local module) 3.
- the hospital-based server 3 redirects, relays, or replicates data from the portable medical device 5 to the hospital information system.
- Figure 1 shows the deployment diagram giving the relationship between the components.
- Portable medical devices 5 connect to the Wi-Fi hotspot provided by the portable computing device 2.
- the portable computing devices 2 access the Internet through a cellular network 6 (which may include a cellular tower (not shown)), or multicellular network, which provides connectivity via a private network 11 (e.g., a VPN) to cloud services.
- a cloud-based application server 9 hosts a private network server (e.g., a VPN server) that is accessed through the hospital network 8 (or hospital trust network) by the local module 3, which can act as a local application server.
- the local module 3 can transfer data acquired from the medical devices 5 to the hospital information system 7.
- the portable computing device 2, cloud application server 9, and VPNs 11, 13 between the cloud application server 9 and the hospital-based hospital information system 7 allow the portable medical device 5 to directly connect to the hospitalbased server 7.
- Software on the hospital-based server 7, for example a lookup table, can replicate the server network port(s) of the hospital information system 7 and provide one endpoint of the point to point connect from the portable medical device 2. This can then manage inbound and outbound connections from multiple portable medical devices 5 and route all traffic to the hospital information system 7.
- the field module software runs on a portable device 2, which can be issued to each paramedic or community care staff.
- the system 1 can communicate with any medical device 5 regardless of make or manufacturer, such as Abbott iSTAT, Roche Cardiac Reader, Siemens ePOC, Philips ECG/Patient monitor, LumiraDx, Drager ventilators etc.
- any medical device 5 regardless of make or manufacturer, such as Abbott iSTAT, Roche Cardiac Reader, Siemens ePOC, Philips ECG/Patient monitor, LumiraDx, Drager ventilators etc.
- the field module 2 may be carried by paramedics or their vehicle 4 and establishes a secure connection to the paramedics' medical devices 5.
- a field module 2 located near a community medical device 5 will automatically connect to it wirelessly.
- the field module 2 may have an Ethernet socket or Wi-Fi or wireless dongles (not shown) which attach to community medical devices 5 that lack inbuilt wireless connectivity.
- the field module 2 communicates with the VPN 11 across a multi-network internet connection (which could be any cellular network, such as 3G, 4G, 5G, etc.). If out of signal range, the field module 2 may wait for a signal before automatically broadcasting the communication.
- a multi-network internet connection which could be any cellular network, such as 3G, 4G, 5G, etc.
- the field module 2 has an interface 16 and/or a display 17, which indicates battery usage and shows that the connection to the local module 3 is maintained.
- the field module 2 may also comprise a controller 18, which may comprise a processor 19, volatile memory 20, non-volatile memory 21, an input output interface 22, and a bus 23 connecting these components together.
- Local module 3 may comprise a processor 19, volatile memory 20, non-volatile memory 21, an input output interface 22, and a bus 23 connecting these components together.
- the local module 3 (also referred to as the Hospital Module (HoM) sits on the local area network (LAN) with the hospital information systems 7, such as the hospital's middleware, laboratory information systems or hospitals EPR.
- the software installed on the module may instead be installed on a hospital server. Only one local module 3 is required for each hospital information system 7, regardless of the number of remote sites or community medical devices 5 that need to be monitored.
- the local module 3 may be a dedicated hardware device, and may comprise a controller 28, which may comprise a processor 29, volatile memory 30, non-volatile memory 31, an input output interface 32, and a bus 33 connecting these components together.
- the local module 3 may also have an interface 34 and, optionally, a display 35.
- Software that enables the system 1 to run may be run as a service, for example, the MicrosoftTM Windows ServiceTM, or other functionality can then manage the automatic starting of the application (for instance on server boot up). Since instantiation of the application is an automated process, the use of a GUI is not necessary, and the configuration of the application would be done through a text file.
- the local module 3 connects devices to the required hospital information system 7 within the hospital network 8.
- the server 7, is configured to provide a fixed IP address accessible by the hospital network 8.
- the field module 2 and the local module 3 map medical devices to the hospital system as described below.
- Each medical devices driver will be programmed to communicate to medical device. Each driver will conform to a standardisation (e.g., Cain Medical Standardisation).
- Logging and notifications For each connection the following information is logged, connection status, movement of inbound and outbound packets and error messages. If required, the connection monitoring can push a notification.
- the following configuration defines the criteria: connect events, disconnect, bad packet events, notification destination IP address/ port.
- the server 9 is configured to pass medical device messages, for example, across a dual redundant private dedicated connection hosted privately away from the public internet.
- the server 9 is configured to reduce the communication to a single secured hospital network port.
- the server 9 may be configured to communicate out to the hospital using a peer- to-peer IPSec tunnel or private network or dedicated network on, for example, the VPN or NHS Health and Social Care Network (HSCN).
- a peer- to-peer IPSec tunnel or private network or dedicated network on, for example, the VPN or NHS Health and Social Care Network (HSCN).
- HSCN NHS Health and Social Care Network
- the server 9 may have similar components to that of the field module 2 and the local module 3.
- the server 9 may have a controller 40, which may comprise a processor 41, volatile memory 42, non-volatile memory 43, an input output interface 44, and a bus 45 connecting these components together.
- the local module 3 may also have an interface 46.
- the server 9 may receive data from the medical device 5 via the field module 2 and the private network 11 though a respective port 50i, 502, 503, ..., 50N which may be determined by the medical device. Once the server 9 has verified the data and confirmed that the data is from an expected medical device 5, it can send the data on to the local module 3 through a single dedicated port 51 and the private network 13 or dedicated network (e.g., the Health and Social Care Network (HSCN)).
- HSCN Health and Social Care Network
- the medical devices 5 communicate in two separate ways and the system 1 manages these differences as follows:
- Hospital information systems 7 which initiates connections with community medical devices 5: medical devices 5 to which the hospital information system 7 established connections are processed differently. All medical devices 5 are configured to a single IP address (the IP address of the local module 3 but using different TCP ports to communicate with the hospital information system 7).
- the local module 3 manages the multiple UDP/TCP ports that distinguish communication for each of the medical devices, and requires the correct mapping to hospital system.
- the system 1 allows hospital information systems to communicate with either a medical device interface (e.g., a Cain Medical's medical device interface), drivers or the existing hospital medical device interface drivers (i.e. , when medical device driver is already in place to communicate with internal hospital medical devices).
- a medical device interface e.g., a Cain Medical's medical device interface
- drivers i.e., when medical device driver is already in place to communicate with internal hospital medical devices.
- the system 1 The system 1 :
- the field module 2 can operate without mains supply, e.g., by the use of a battery, or local generator such as a solar panel, and can go beyond that when intermittently charged, e.g., in a paramedic vehicle - the system remains fully operational while on charge.
- the system 1 securely relays data without any loss of information even in the event of power or connectivity loss in the field.
- System 1 Security model Reduces the number of ports required to cross the hospital IT boundary by mapping and remapping the message crossing the between the server 9 and the local module 3 for example, many POC devices can be connected to hospital information systems with opening a single port or more. That is, the server may be configured to send the data via a single port, and/or to receive data via the same single port from the local module.
- the system 1 operates a zero-trust network model, which only lets medical devices 5 communicate with the system 1 and blocks any other users.
- SPI Stateful packet inspection
- Message head and field attributes are intelligently monitored to ensure only legitimate medical device 5 messages are sent and received.
- Drivers on the local module 3 or on the server 9 can verify the make and model of the device, reducing the risk of hacking, or other cyber security event, and ensuring that the correct device is in use.
- the server 9 an VPNs 11, 13 ensure medical device 5 messages are not altered or destroyed.
- the system 1 uses a dedicated internet service, away from any public internet.
- the system has the functionality to encrypt messages which are sent from the field module 2 and decrypt those messages when received by the local module 3. This creates a virtual tunnel so data cannot be intercepted by snoopers, hackers or third parties.
- the server 9 an VPNs 11, 13 offer network visibility by identifying and reporting risks and vulnerabilities. Activity reports provide details on which devices are communicating.
- Remote loT Gateway Management Remote gateway management, using SHH can be deployed to manage the field module 2 and local module 3 devices which include updating device O/S and firmware.
- the unique configuration of the field module 2 will automatically form a connection to the local module 3 via its own virtual private network 11, 13 (VPN).
- VPN virtual private network
- Two key encryption protects this peer-to-peer virtual private network 11, 13 at each end of the system. Therefore, data messages communicated over the Internet will be encrypted and only routed through the VPN 11, 13, i.e., the messages never have an unencrypted format outside the hospital.
- a hospital firewall 14 can be used in addition to the system 1 security. The firewall 14 may be on the local module 3, or between the server 9 and the local module 3.
- a wireless network with encryption is used to prevent local snooping in the vicinity of the medical device. Additionally, the field module 2 and local module 3 will be connected to private networks dedicated to this solution to ensure encryption of patient data between the field module 2 and the local module 3.
- Each paramedic or vehicle 4 will contain a field module 2.
- Each field module 2 operates with a network (SSID) and password to communicate with any of the medical devices 5.
- WPA2 / AE256 protects the wirelessly communicated data when possible (WPA2, which can be encrypted with TKIP or AES256.
- the system 1 may use the same level of encryption of the medical device 5, for example, whether TKIP or AES is used may be determined by the capability of the medical device 5.
- the field module 2 is configured to hold a SIM card with mobile data for communication to the local module 3.
- the field module 2 wireless connection e.g., Wi-Fi
- Wi-Fi wireless connection
- the field module 2 connects automatically to the private network (e.g., VPN) 11, 13 only devices which are members of the private network (VPN) are visible to the field module 2.
- WEP2 / AE256 protects the wireless communication data.
- Private network 11, 13 e.g., VPN
- the Internet component of the solution supports the private network 11, 13 and is accessible from all field modules 2 and the local module 3.
- the purpose of this component is to act as an encrypted network (switch) between components.
- a Site-to-Site private network (e.g., VPN) is a fully managed dedicated service with high availability by using two tunnels stream primary traffic through the first tunnel and use the second tunnel for redundancy — if one tunnel goes down, traffic continues to flow.
- the system can be connected using either IPsec or on the HSCN private (or dedicated) network.
- the local module 3 sits on the same local area network (LAN) as the hospital information systems 7.
- the local module 3 can use a standard operating system, for example, WindowsTM 11 Pro, and can be updated automatically.
- This traffic will only be from devices in the private network 11, 13 (VPN) on a dedicated internet service 11, 13.
- the port will be the same port as used by the medical device 5. All other ports can be firewalled, and therefore may not be accessible by third parties.
- the local module 3 has port on the hospital local area network to connect to the hospital information system 7 via a range of TCP and UDP ports.
- the local module 3 can be monitored, will show the status (number of results forwarded, any security issues), this includes blocked messages based on incorrect size and frequency of message and/or incorrect medical device message structure.
- a medical device 5 may be acting as a client or a server (although client is the typical case).
- the system 1 may be configured with the following information to forward network communication:
- Client devices o Inbound port o Outbound port o Protocol (TCP/UDP)
- Server devices o Server IP Address o Server Port o Protocol (TCP/UDP)
- the server 9 may be configured to perform checks on the inbound packet size, for example, the maximum packet size. Additional monitoring may be performed, for example, the system 1 may query a separate service to determine whether a packet matches the expected type. This would require the following configuration:
- the necessary logic may be incorporated into the driver during driver development.
- the extender supports multiple devices. To provide this, the extender will consist of a component that handles a single connection, and a management component that can instantiate multiple connection components. The individual connection components can also be instantiated manually to assist debugging issues.
- the server 9 may be used for extending a point-to-point connection between the healthcare information system and at least one field module 2. Such a configuration may allow messages, for example results, dosages, or other information to be sent from a clinical expert based in the hospital to the field module 2 to be read and acted on by the community care provider (e.g., paramedic, community nurse and the like).
- the server 9 acts in a similar way as described earlier, but without the communication with the medical device 5.
- the server 9 is connected to a local module 3 via a first private network 13.
- the local module 3 is connected to the healthcare information system 7 based in the hospital.
- the server 9 is also connected to the field module 2 via a second private network 11.
- the server 9 In response to receiving data from the local module 3 the server 9 sends the data to the field module 2 using the second private network 11 to the field module 2. In response to the server 9 receiving data from the field module 2, the server 9 verifies that the data is from the field module 2, and sends the verified data using the first private network 13 to the local module 3. The server 9 may also verify that the data form the local module 3 is from the local module 3 before sending it on to the field module 2. This may help prevent hacks or other cyber security breaches, and also ensures that the data received originates from the correct local module 3, and therefore the correct clinical expert.
- the system can also track the number of results sent and received from the medical device via the field module 2, how much data has been used by the Subscriber Identity Module card (SIM card) of the field module 2, and how often the field module 2 has been used.
- SIM card Subscriber Identity Module card
- This can increase security of the field module, server 9, local module 3, and hospital information system 7 because statistical analysis of these data will allow users to track any change in the pattern of usage of one or more of these components.
- These usage data may also be used to monitor outages of the system and calculate user charges or billing.
Landscapes
- Engineering & Computer Science (AREA)
- Health & Medical Sciences (AREA)
- General Health & Medical Sciences (AREA)
- Computer Security & Cryptography (AREA)
- Biomedical Technology (AREA)
- Medical Informatics (AREA)
- General Business, Economics & Management (AREA)
- Business, Economics & Management (AREA)
- Signal Processing (AREA)
- Computer Networks & Wireless Communication (AREA)
- Epidemiology (AREA)
- Primary Health Care (AREA)
- Public Health (AREA)
- Bioethics (AREA)
- Computer Hardware Design (AREA)
- Theoretical Computer Science (AREA)
- General Engineering & Computer Science (AREA)
- Computing Systems (AREA)
- General Physics & Mathematics (AREA)
- Physics & Mathematics (AREA)
- Databases & Information Systems (AREA)
- Software Systems (AREA)
- Measuring And Recording Apparatus For Diagnosis (AREA)
- Medical Treatment And Welfare Office Work (AREA)
Abstract
Description
Claims
Priority Applications (1)
| Application Number | Priority Date | Filing Date | Title |
|---|---|---|---|
| EP24740523.6A EP4736181A1 (en) | 2023-06-29 | 2024-06-28 | A server for extending a point-to-point connection between a healthcare information system and at least one medical device |
Applications Claiming Priority (2)
| Application Number | Priority Date | Filing Date | Title |
|---|---|---|---|
| GB2309847.8A GB2631415A (en) | 2023-06-29 | 2023-06-29 | A server for extending a point-to-point connection between a healthcare information system and at least one medical device |
| GB2309847.8 | 2023-06-29 |
Publications (1)
| Publication Number | Publication Date |
|---|---|
| WO2025003708A1 true WO2025003708A1 (en) | 2025-01-02 |
Family
ID=87556712
Family Applications (1)
| Application Number | Title | Priority Date | Filing Date |
|---|---|---|---|
| PCT/GB2024/051694 Ceased WO2025003708A1 (en) | 2023-06-29 | 2024-06-28 | A server for extending a point-to-point connection between a healthcare information system and at least one medical device |
Country Status (3)
| Country | Link |
|---|---|
| EP (1) | EP4736181A1 (en) |
| GB (1) | GB2631415A (en) |
| WO (1) | WO2025003708A1 (en) |
Citations (1)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| US20220059216A1 (en) * | 2020-08-20 | 2022-02-24 | Centurylink Intellectual Property Llc | Home Health Monitoring of Patients via Extension of Healthcare System Network Into Customer Premises |
Family Cites Families (2)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| AU7780600A (en) * | 1999-10-01 | 2001-05-10 | Glaxo Group Limited | Patient data monitoring system |
| DE602005011928D1 (en) * | 2004-01-20 | 2009-02-05 | Allergan Inc | COMPOSITIONS FOR LOCALIZED THERAPY OF THE EYE, PREFERABLY CONTAINING TRIAMCINOLONE ACETONIDE AND HYALURONIC ACID |
-
2023
- 2023-06-29 GB GB2309847.8A patent/GB2631415A/en active Pending
-
2024
- 2024-06-28 EP EP24740523.6A patent/EP4736181A1/en active Pending
- 2024-06-28 WO PCT/GB2024/051694 patent/WO2025003708A1/en not_active Ceased
Patent Citations (1)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| US20220059216A1 (en) * | 2020-08-20 | 2022-02-24 | Centurylink Intellectual Property Llc | Home Health Monitoring of Patients via Extension of Healthcare System Network Into Customer Premises |
Also Published As
| Publication number | Publication date |
|---|---|
| GB2631415A (en) | 2025-01-08 |
| GB202309847D0 (en) | 2023-08-16 |
| EP4736181A1 (en) | 2026-05-06 |
Similar Documents
| Publication | Publication Date | Title |
|---|---|---|
| US11729143B2 (en) | Methods for internet communication security | |
| US11930007B2 (en) | Methods for internet communication security | |
| US10397186B2 (en) | Methods for internet communication security | |
| US11245529B2 (en) | Methods for internet communication security | |
| US8694600B2 (en) | Remote monitoring systems for monitoring medical devices via wireless communication networks | |
| US8437854B2 (en) | Regulatory compliant transmission of medical data employing a patient implantable medical device and a generic network access device | |
| US20180254093A1 (en) | Cryptographically secure medical test data distribution system using smart testing/diagnostic devices | |
| KR20140105011A (en) | Remote monitoring systems and methods for medical devices | |
| EP2946323A2 (en) | Secure real-time health record exchange | |
| US20120226771A1 (en) | Remote Monitoring Systems And Methods For Medical Devices | |
| US20130304489A1 (en) | Remote Monitoring And Diagnostics Of Medical Devices | |
| WO2019071131A1 (en) | Methods for internet communication security | |
| WO2005114524A2 (en) | Personalized remote patient monitoring systems and methods | |
| US20150039327A1 (en) | Systems and methods for managing patient research data | |
| WO2008042610A2 (en) | Universal usb-based telemetry rf head | |
| Liu et al. | eHealth interconnection infrastructure challenges and solutions overview | |
| EP4736181A1 (en) | A server for extending a point-to-point connection between a healthcare information system and at least one medical device | |
| US11451567B2 (en) | Systems and methods for providing secure remote data transfer for medical devices | |
| CN112491946A (en) | Method, apparatus, system and program product for data communication in a network | |
| JP2011077691A (en) | Device, method and program for relaying radio communication | |
| CN116707942A (en) | A medical device networking system and method | |
| Gerdes et al. | End-to-end security and privacy protection for co-operative access to health and care data in a telehealth trial system for remote supervision of COPD-Patients | |
| US20240179132A1 (en) | Systems and methods for remote control monitoring of an electronic device | |
| Sundar et al. | Towards a European Health Data Slice | |
| CN120164600A (en) | Systems and methods for transmitting health data in a healthcare environment |
Legal Events
| Date | Code | Title | Description |
|---|---|---|---|
| 121 | Ep: the epo has been informed by wipo that ep was designated in this application |
Ref document number: 24740523 Country of ref document: EP Kind code of ref document: A1 |
|
| WWE | Wipo information: entry into national phase |
Ref document number: 2024740523 Country of ref document: EP |
|
| NENP | Non-entry into the national phase |
Ref country code: DE |
|
| ENP | Entry into the national phase |
Ref document number: 2024740523 Country of ref document: EP Effective date: 20260129 |
|
| ENP | Entry into the national phase |
Ref document number: 2024740523 Country of ref document: EP Effective date: 20260129 |