A Framework for mHealth App Security and Privacy Analysis

移动医疗应用程序安全和隐私分析框架

基本信息

  • 批准号:
    10760047
  • 负责人:
  • 金额:
    $ 78.88万
  • 依托单位:
  • 依托单位国家:
    美国
  • 项目类别:
  • 财政年份:
    2021
  • 资助国家:
    美国
  • 起止时间:
    2021-09-15 至 2025-08-31
  • 项目状态:
    未结题

项目摘要

PROJECT SUMMARY/ABSTRACT With the increased use of mobile health (mHealth) apps to improve health outcomes, protecting private health data is becoming increasingly important. These mHealth apps are offered by healthcare providers and used by patients for various reasons such as paying bills, scheduling appointments, sending messages to providers, accessing lab results, and viewing prescriptions and medical records. With patients’ increasing desire for data accessibility and app data sharing, it is critical to ensure that patients transmit their Protected Health Information (PHI) to apps that comply with HIPAA privacy and security regulations. Unfortunately, about 25% of healthcare providers suffer from data breaches violating HIPAA policies caused by using mobile devices that come with mHealth apps. These breaches result in lawsuits and loss of confidence among health providers and patients. Earlier research has focused on mobile device security but has not checked further how apps store or transfer data securely before being used by remote healthcare providers or users. A total of 303,867 complaints have been received in the HHS.gov until July 2022 [95], which indicates that most developers, including mHealth apps developers, are unaware of HIPAA security and privacy regulations. This creates the market opportunity to develop static and dynamic code analysis tools for mHealth app developers, so their developed products meet HIPAA security and privacy guidelines. Currently, there is a lack of an analysis framework to check mHealth apps’ security and privacy risks following the applicable HIPAA technical security and privacy guidelines. We have developed a framework to analyze mHealth apps for HIPAA security and privacy compliance for Android. The tool is available both as a web-based interface for users without knowledge of HIPAA or app security and as a plugin with Android Studio to enable health app developers to test source code for potential data security breaches related to HIPAA before posting to the marketplace. In addition, the tool addresses API level checking for secure data communication mandated by recent Centers for Medicare & Medicaid Services (CMS) guidelines between third-party mobile health apps and EHR systems. The analysis framework also addresses heterogeneous health data and enables providers to comply with HIPAA administrative and operational guidelines. We have performed two acceptance tests on the prototype based on partnering with HIPAA experts, medical doctors, and for-profit EHR vendors along with the effectiveness of tools for detecting health data security breaches. In Phase II, we propose a commercial product mSPAiOS as a mHealth HIPAA checker by extending the framework for iOS mHealth apps security and privacy assessment, plugin support for xCode environment, and performance evaluation of the product by at least 3 for-profit organizations/EHR vendors. The proposed tool has the potential to capture the market of the HIPAA-compliant assessment as a unique product that is not provided by any existing tools.
项目摘要/摘要 随着移动健康(MHealth)应用程序的增加来改善健康结果,保护 私人健康数据变得越来越重要。这些MHealth应用程序由 医疗保健提供者,患者出于各种原因,例如支付账单,安排时间安排 约会,向提供商发送消息,访问实验室结果并查看处方 和病历。随着患者对数据可访问性和应用数据共享的渴望, 至关重要的是要确保患者将其受保护的健康信息(PHI)传递给应用程序 遵守HIPAA隐私和安全法规。不幸的是,约有25%的医疗保健 提供者遭受数据中断违反HIPAA政策的数据中断,原因是使用移动设备引起的 随附MHealth应用程序。这些呼吸导致诉讼和健康之间的信心丧失 提供者和患者。较早的研究重点是移动设备安全,但没有 在远程医疗保健使用之前,进一步检查了应用程序如何安全地存储或传输数据 提供者或用户。直到7月,HHS.GOV总共收到了303,867个投诉 2022 [95],表明大多数开发人员(包括MHealth应用程序开发人员)都不知道 HIPAA安全和隐私法规。这创造了开发静态的市场机会 和MHealth应用程序开发人员的动态代码分析工具,因此他们的开发产品满足 HIPAA安全和隐私指南。目前,缺乏分析框架 遵循适用的HIPAA技术安全检查MHealth应用程序的安全性和隐私风险 和隐私指南。我们已经开发了一个框架来分析HIPAA的MHealth应用程序 Android的安全性和隐私合规性。该工具既可以作为基于网络的接口 对于不了解HIPAA或App Security的用户以及Android Studio的插件 使Health应用程序开发人员能够测试源代码,以了解与 HIPAA发布到市场之前。此外,该工具解决了API级检查 最近由医疗保险和医疗补助服务中心要求的安全数据通信 (CMS)第三方移动健康应用程序和EHR系统之间的指南。分析 框架还解决了异构健康数据,并使提供者能够遵守 HIPAA行政和运营指南。我们已经对 基于与HIPAA专家,医生和营利性EHR合作的原型 供应商以及用于检测健康数据安全休息的工具的有效性。在阶段 ii,我们通过扩展 iOS MHealth应用程序安全和隐私评估的框架,XCode的插件支持 至少3个营利性组织/EHR对产品的环境和性能评估 供应商。提出的工具有可能捕获符合HIPAA的市场 评估是任何现有工具未提供的独特产品。

项目成果

期刊论文数量(0)
专著数量(0)
科研奖励数量(0)
会议论文数量(0)
专利数量(0)

数据更新时间:{{ journalArticles.updateTime }}

{{ item.title }}
{{ item.translation_title }}
  • DOI:
    {{ item.doi }}
  • 发表时间:
    {{ item.publish_year }}
  • 期刊:
  • 影响因子:
    {{ item.factor }}
  • 作者:
    {{ item.authors }}
  • 通讯作者:
    {{ item.author }}

数据更新时间:{{ journalArticles.updateTime }}

{{ item.title }}
  • 作者:
    {{ item.author }}

数据更新时间:{{ monograph.updateTime }}

{{ item.title }}
  • 作者:
    {{ item.author }}

数据更新时间:{{ sciAawards.updateTime }}

{{ item.title }}
  • 作者:
    {{ item.author }}

数据更新时间:{{ conferencePapers.updateTime }}

{{ item.title }}
  • 作者:
    {{ item.author }}

数据更新时间:{{ patent.updateTime }}

Sheikh Iqbal Ahamed其他文献

ETS (Efficient, Transparent, and Secured) Self-healing Service for Pervasive Computing Applications
适用于普适计算应用的 ETS(高效、透明、安全)自我修复服务
  • DOI:
    10.6633/ijns.200705.4(3).05
  • 发表时间:
    2007
  • 期刊:
  • 影响因子:
    0
  • 作者:
    Shameem Ahmed;Moushumi Sharmin;Sheikh Iqbal Ahamed
  • 通讯作者:
    Sheikh Iqbal Ahamed
Collaborative Design with Veterans: Identifying challenges of designing mhealth solution for veterans
与退伍军人协作设计:确定为退伍军人设计移动医疗解决方案的挑战
Reality Versus Grant Application Research “Plans”
现实与拨款申请研究“计划”
  • DOI:
    10.1177/1524839917700892
  • 发表时间:
    2018
  • 期刊:
  • 影响因子:
    1.9
  • 作者:
    L. Burhansstipanov;L. Krebs;D. Petereit;M. Dignan;Sheikh Iqbal Ahamed;Michele Sargent;K. Cina;K. Crawford;Doris Thibeault;S. Bordeaux;S. Kanekar;G. Ahsan;Dr. Williams;Ivor D. Addo
  • 通讯作者:
    Ivor D. Addo
iPeer: A Sociotechnical Systems Approach for Helping Veterans with Civilian Reintegration
iPeer:帮助退伍军人重返平民社会的社会技术系统方法
  • DOI:
  • 发表时间:
    2015
  • 期刊:
  • 影响因子:
    0
  • 作者:
    Rizwana Rizia;Zeno Franco;Katinka Hooyer;Nadiyah Johnson;A. Patwary;G. Ahsan;Bob Curry;M. Flower;Sheikh Iqbal Ahamed
  • 通讯作者:
    Sheikh Iqbal Ahamed
Design and implementation of S-MARKS: A secure middleware for pervasive computing applications
S-MARKS的设计与实现:普适计算应用的安全中间件
  • DOI:
    10.1016/j.jss.2009.03.020
  • 发表时间:
    2009
  • 期刊:
  • 影响因子:
    0
  • 作者:
    Sheikh Iqbal Ahamed;Haifeng Li;N. Talukder;Mehrab Monjur;C. S. Hasan
  • 通讯作者:
    C. S. Hasan

Sheikh Iqbal Ahamed的其他文献

{{ item.title }}
{{ item.translation_title }}
  • DOI:
    {{ item.doi }}
  • 发表时间:
    {{ item.publish_year }}
  • 期刊:
  • 影响因子:
    {{ item.factor }}
  • 作者:
    {{ item.authors }}
  • 通讯作者:
    {{ item.author }}

{{ truncateString('Sheikh Iqbal Ahamed', 18)}}的其他基金

A Framework for mHealth App Security and Privacy Analysis
移动医疗应用程序安全和隐私分析框架
  • 批准号:
    10325277
  • 财政年份:
    2021
  • 资助金额:
    $ 78.88万
  • 项目类别:

相似国自然基金

无线供能边缘网络中基于信息年龄的能量与数据协同调度算法研究
  • 批准号:
    62372118
  • 批准年份:
    2023
  • 资助金额:
    50 万元
  • 项目类别:
    面上项目
NURBS参数化的自交理论与算法研究
  • 批准号:
    12301490
  • 批准年份:
    2023
  • 资助金额:
    30 万元
  • 项目类别:
    青年科学基金项目
基于先进算法和行为分析的江南传统村落微气候的评价方法、影响机理及优化策略研究
  • 批准号:
    52378011
  • 批准年份:
    2023
  • 资助金额:
    50 万元
  • 项目类别:
    面上项目
分组密码算法后门的研究
  • 批准号:
    62302293
  • 批准年份:
    2023
  • 资助金额:
    30 万元
  • 项目类别:
    青年科学基金项目
时序深度可加网络的算法与学习理论研究
  • 批准号:
    62306338
  • 批准年份:
    2023
  • 资助金额:
    30 万元
  • 项目类别:
    青年科学基金项目

相似海外基金

Remote Kinesiology for Improving Human Health with Auto-locating Compliant Motion Tracking Stickers and Artificial Intelligence
通过自动定位兼容运动跟踪贴纸和人工智能来改善人类健康的远程运动机能学
  • 批准号:
    10751952
  • 财政年份:
    2023
  • 资助金额:
    $ 78.88万
  • 项目类别:
A mobile health framework for left ventricular end diastolic pressure diagnostics and monitoring.
用于左心室舒张末压诊断和监测的移动健康框架。
  • 批准号:
    10601929
  • 财政年份:
    2023
  • 资助金额:
    $ 78.88万
  • 项目类别:
PA TH2Caregiving: Data-Driven Digital Engagement to Assess and Address the Needs of Family Caregivers
PA TH2Caregiving:数据驱动的数字参与,评估和满足家庭护理人员的需求
  • 批准号:
    10598028
  • 财政年份:
    2023
  • 资助金额:
    $ 78.88万
  • 项目类别:
HORNET Center for Autonomic Nerve Recording and Stimulation Systems (CARSS)
HORNET 自主神经记录和刺激系统中心 (CARSS)
  • 批准号:
    10557002
  • 财政年份:
    2022
  • 资助金额:
    $ 78.88万
  • 项目类别:
Managing Adolescent Asthma Virtually (MAAV)
虚拟管理青少年哮喘 (MAAV)
  • 批准号:
    10481220
  • 财政年份:
    2022
  • 资助金额:
    $ 78.88万
  • 项目类别:
{{ showInfoDetail.title }}

作者:{{ showInfoDetail.author }}

知道了