A Framework for mHealth App Security and Privacy Analysis
移动医疗应用程序安全和隐私分析框架
基本信息
- 批准号:10325277
- 负责人:
- 金额:$ 25.61万
- 依托单位:
- 依托单位国家:美国
- 项目类别:
- 财政年份:2021
- 资助国家:美国
- 起止时间:2021-09-15 至 2023-08-31
- 项目状态:已结题
- 来源:
- 关键词:AddressAdoptionAndroidAppleAreaAwarenessBehaviorBusinessesCar PhoneCodeCommunicationCommunitiesDataData SecurityDevelopmentDevicesEarly DiagnosisEffectivenessEnsureEnvironmentFDA approvedFutureGoalsGuidelinesHealthHealth Insurance Portability and Accountability ActHealth PersonnelHealthcareKnowledgeMedicalMedical HistoryMobile Health ApplicationMonitorOutcomePatientsPhasePoliciesPrivacyPrivatizationProviderRegulationReportingResearchResearch PersonnelRiskSecureSecuritySource CodeSystemTechniquesTestingVendorbasecomputerized data processingcost effectivenessdata exchangedata privacydata sharingdesignflexibilityhandheld mobile devicehealth dataimprovedmHealthmobile applicationphase 1 studyprototyperemote health caresensorsupport toolstooltransmission processweb based interface
项目摘要
Abstract: With the increased use of mobile health apps to improve health outcomes, protecting
private health data is becoming increasingly important. Researchers estimate there are over
300,000 mHealth apps in existence, and some relate to HIPAA covered entities or their business
associates. With patients’ increasing desire for data accessibility and app data sharing, it is critical
to ensure that patients transmit their Protected Health Information (PHI) to apps that are compliant
with HIPAA privacy and security rules. About 25% of healthcare providers suffer from data
breaches violating HIPAA policies, caused by using mobile devices that come preloaded with
mHealth apps. This results in lawsuits, and loss of confidence among health providers and
patients. Earlier research has focused on security of mobile devices, but not checking further how
apps store or transfer data securely before being used by remote health care providers or users.
Most mobile app developers including mHealth apps are not aware of HIPAA security and privacy
regulations. This creates the market opportunity to develop static and dynamic code analysis tools
for mHealth app developers, so their developed products meet HIPAA security and privacy
guidelines. Currently, there is a lack of an analysis framework to check mHealth apps’ security
and privacy risks following the applicable HIPAA technical security and privacy guidelines. We
propose to develop a framework to analyze mHealth apps for HIPAA security and privacy
compliance. The framework will allow users who have no knowledge of HIPAA or app security to
receive an assessment of security and privacy risks per HIPAA guidelines. Initially based on
Android Studio, the tool will test the source code of mHealth applications for potential data security
breaches related to HIPAA before posting for the marketplace. The tool will further address API
level checking for secure data communication mandated by recent CMS guidelines between third
party mobile health apps and EHR systems. The analysis framework will also address
heterogeneous health data and enable providers to remain compliant with HIPAA administrative
and operational guidelines. We propose to perform two acceptance tests on the prototype based
on partnering with HIPAA experts and medical doctors and for-profit EHR vendors along with the
effectiveness of tools for detecting health data security breaches. The proposed tool will further
enable the development of data breach checking for iOS mHealth apps and adoption and
integration by large scale EHR vendors in the future.
摘要:随着移动健康应用程序的使用增加以改善健康结果,保护
私人健康数据变得越来越重要。研究人员估计已经结束了
存在300,000个MHealth应用程序,有些与HIPAA涵盖的实体或其业务有关
同事。随着患者对数据可访问性和应用数据共享的日益渴望,这至关重要
确保患者将其受保护的健康信息(PHI)传输到合规性的应用
使用HIPAA隐私和安全规则。大约25%的医疗保健提供者遭受了数据的困扰
违反违反HIPAA政策的行为,该政策是由于使用预装的移动设备而引起的
MHealth应用程序。这导致诉讼以及卫生提供者和
患者。较早的研究重点是移动设备的安全性,但没有进一步检查
在远程医疗保健提供者或用户使用之前,请牢固地存储或传输数据。
包括MHealth应用在内的大多数移动应用程序开发人员都不知道HIPAA安全性和隐私
法规。这创造了开发静态和动态代码分析工具的市场机会
对于MHealth应用程序开发人员,因此他们的开发产品符合HIPAA安全性和隐私
指南。目前,缺乏检查MHealth应用程序安全性的分析框架
遵循适用的HIPAA技术安全和隐私指南的隐私风险。我们
提出开发一个框架以分析MHealth应用程序的HIPAA安全性和隐私性
遵守。该框架将允许对HIPAA或APP Security不了解的用户来
根据HIPAA准则,获得对安全性和隐私风险的评估。最初基于
Android Studio,该工具将测试MHealth应用程序的源代码,以确保潜在数据安全
在发布市场之前,与HIPAA有关的漏洞。该工具将进一步解决API
级别检查最近CMS指南规定的安全数据通信
政党移动健康应用程序和EHR系统。分析框架也将解决
异构健康数据,并使提供者能够遵守HIPAA管理
和运营指南。我们建议对基于原型的两个接受测试进行两项接受测试
与HIPAA专家和医生以及营利性EHR供应商合作
检测健康数据安全损耗的工具的有效性。提出的工具将进一步
启用iOS MHealth应用程序和采用的数据泄露检查的开发以及
将来大规模EHR供应商集成。
项目成果
期刊论文数量(0)
专著数量(0)
科研奖励数量(0)
会议论文数量(0)
专利数量(0)
数据更新时间:{{ journalArticles.updateTime }}
{{
item.title }}
{{ item.translation_title }}
- DOI:
{{ item.doi }} - 发表时间:
{{ item.publish_year }} - 期刊:
- 影响因子:{{ item.factor }}
- 作者:
{{ item.authors }} - 通讯作者:
{{ item.author }}
数据更新时间:{{ journalArticles.updateTime }}
{{ item.title }}
- 作者:
{{ item.author }}
数据更新时间:{{ monograph.updateTime }}
{{ item.title }}
- 作者:
{{ item.author }}
数据更新时间:{{ sciAawards.updateTime }}
{{ item.title }}
- 作者:
{{ item.author }}
数据更新时间:{{ conferencePapers.updateTime }}
{{ item.title }}
- 作者:
{{ item.author }}
数据更新时间:{{ patent.updateTime }}
Sheikh Iqbal Ahamed其他文献
ETS (Efficient, Transparent, and Secured) Self-healing Service for Pervasive Computing Applications
适用于普适计算应用的 ETS(高效、透明、安全)自我修复服务
- DOI:
10.6633/ijns.200705.4(3).05 - 发表时间:
2007 - 期刊:
- 影响因子:0
- 作者:
Shameem Ahmed;Moushumi Sharmin;Sheikh Iqbal Ahamed - 通讯作者:
Sheikh Iqbal Ahamed
Collaborative Design with Veterans: Identifying challenges of designing mhealth solution for veterans
与退伍军人协作设计:确定为退伍军人设计移动医疗解决方案的挑战
- DOI:
10.1109/healthcom.2015.7454526 - 发表时间:
2015 - 期刊:
- 影响因子:0
- 作者:
Rizwana Rizia;Zeno Franco;Nadiyah Johnson;Katinka Hooyer;A. Patwary;G. Ahsan;M. Flower;Bob Curry;Sheikh Iqbal Ahamed - 通讯作者:
Sheikh Iqbal Ahamed
Reality Versus Grant Application Research “Plans”
现实与拨款申请研究“计划”
- DOI:
10.1177/1524839917700892 - 发表时间:
2018 - 期刊:
- 影响因子:1.9
- 作者:
L. Burhansstipanov;L. Krebs;D. Petereit;M. Dignan;Sheikh Iqbal Ahamed;Michele Sargent;K. Cina;K. Crawford;Doris Thibeault;S. Bordeaux;S. Kanekar;G. Ahsan;Dr. Williams;Ivor D. Addo - 通讯作者:
Ivor D. Addo
iPeer: A Sociotechnical Systems Approach for Helping Veterans with Civilian Reintegration
iPeer:帮助退伍军人重返平民社会的社会技术系统方法
- DOI:
- 发表时间:
2015 - 期刊:
- 影响因子:0
- 作者:
Rizwana Rizia;Zeno Franco;Katinka Hooyer;Nadiyah Johnson;A. Patwary;G. Ahsan;Bob Curry;M. Flower;Sheikh Iqbal Ahamed - 通讯作者:
Sheikh Iqbal Ahamed
Design and implementation of S-MARKS: A secure middleware for pervasive computing applications
S-MARKS的设计与实现:普适计算应用的安全中间件
- DOI:
10.1016/j.jss.2009.03.020 - 发表时间:
2009 - 期刊:
- 影响因子:0
- 作者:
Sheikh Iqbal Ahamed;Haifeng Li;N. Talukder;Mehrab Monjur;C. S. Hasan - 通讯作者:
C. S. Hasan
Sheikh Iqbal Ahamed的其他文献
{{
item.title }}
{{ item.translation_title }}
- DOI:
{{ item.doi }} - 发表时间:
{{ item.publish_year }} - 期刊:
- 影响因子:{{ item.factor }}
- 作者:
{{ item.authors }} - 通讯作者:
{{ item.author }}
{{ truncateString('Sheikh Iqbal Ahamed', 18)}}的其他基金
A Framework for mHealth App Security and Privacy Analysis
移动医疗应用程序安全和隐私分析框架
- 批准号:
10760047 - 财政年份:2021
- 资助金额:
$ 25.61万 - 项目类别:
相似国自然基金
采用新型视觉-电刺激配对范式长期、特异性改变成年期动物视觉系统功能可塑性
- 批准号:32371047
- 批准年份:2023
- 资助金额:50 万元
- 项目类别:面上项目
破解老年人数字鸿沟:老年人采用数字技术的决策过程、客观障碍和应对策略
- 批准号:72303205
- 批准年份:2023
- 资助金额:30.00 万元
- 项目类别:青年科学基金项目
通过抑制流体运动和采用双能谱方法来改进烧蚀速率测量的研究
- 批准号:12305261
- 批准年份:2023
- 资助金额:30.00 万元
- 项目类别:青年科学基金项目
采用多种稀疏自注意力机制的Transformer隧道衬砌裂缝检测方法研究
- 批准号:62301339
- 批准年份:2023
- 资助金额:30.00 万元
- 项目类别:青年科学基金项目
政策激励、信息传递与农户屋顶光伏技术采用提升机制研究
- 批准号:72304103
- 批准年份:2023
- 资助金额:30 万元
- 项目类别:青年科学基金项目
相似海外基金
Remote Kinesiology for Improving Human Health with Auto-locating Compliant Motion Tracking Stickers and Artificial Intelligence
通过自动定位兼容运动跟踪贴纸和人工智能来改善人类健康的远程运动机能学
- 批准号:
10751952 - 财政年份:2023
- 资助金额:
$ 25.61万 - 项目类别:
Digital Technology to Support Adherence to Hypertension Medications for Older Adults with Mild Cognitive Impairment
数字技术支持患有轻度认知障碍的老年人坚持高血压药物治疗
- 批准号:
10363162 - 财政年份:2022
- 资助金额:
$ 25.61万 - 项目类别:
Managing Adolescent Asthma Virtually (MAAV)
虚拟管理青少年哮喘 (MAAV)
- 批准号:
10481220 - 财政年份:2022
- 资助金额:
$ 25.61万 - 项目类别:
Digital Technology to Support Adherence to Hypertension Medications for Older Adults with Mild Cognitive Impairment
数字技术支持患有轻度认知障碍的老年人坚持高血压药物治疗
- 批准号:
10618618 - 财政年份:2022
- 资助金额:
$ 25.61万 - 项目类别:
Design and Testing of a mHealth App for Ambivalent Smokers Living with HIV: A Randomized Pilot Study
为患有艾滋病毒的矛盾吸烟者设计和测试移动医疗应用程序:一项随机试点研究
- 批准号:
10250713 - 财政年份:2021
- 资助金额:
$ 25.61万 - 项目类别: