A Framework for mHealth App Security and Privacy Analysis
移动医疗应用程序安全和隐私分析框架
基本信息
- 批准号:10325277
- 负责人:
- 金额:$ 25.61万
- 依托单位:
- 依托单位国家:美国
- 项目类别:
- 财政年份:2021
- 资助国家:美国
- 起止时间:2021-09-15 至 2023-08-31
- 项目状态:已结题
- 来源:
- 关键词:AddressAdoptionAndroidAppleAreaAwarenessBehaviorBusinessesCar PhoneCodeCommunicationCommunitiesDataData SecurityDevelopmentDevicesEarly DiagnosisEffectivenessEnsureEnvironmentFDA approvedFutureGoalsGuidelinesHealthHealth Insurance Portability and Accountability ActHealth PersonnelHealthcareKnowledgeMedicalMedical HistoryMobile Health ApplicationMonitorOutcomePatientsPhasePoliciesPrivacyPrivatizationProviderRegulationReportingResearchResearch PersonnelRiskSecureSecuritySource CodeSystemTechniquesTestingVendorbasecomputerized data processingcost effectivenessdata exchangedata privacydata sharingdesignflexibilityhandheld mobile devicehealth dataimprovedmHealthmobile applicationphase 1 studyprototyperemote health caresensorsupport toolstooltransmission processweb based interface
项目摘要
Abstract: With the increased use of mobile health apps to improve health outcomes, protecting
private health data is becoming increasingly important. Researchers estimate there are over
300,000 mHealth apps in existence, and some relate to HIPAA covered entities or their business
associates. With patients’ increasing desire for data accessibility and app data sharing, it is critical
to ensure that patients transmit their Protected Health Information (PHI) to apps that are compliant
with HIPAA privacy and security rules. About 25% of healthcare providers suffer from data
breaches violating HIPAA policies, caused by using mobile devices that come preloaded with
mHealth apps. This results in lawsuits, and loss of confidence among health providers and
patients. Earlier research has focused on security of mobile devices, but not checking further how
apps store or transfer data securely before being used by remote health care providers or users.
Most mobile app developers including mHealth apps are not aware of HIPAA security and privacy
regulations. This creates the market opportunity to develop static and dynamic code analysis tools
for mHealth app developers, so their developed products meet HIPAA security and privacy
guidelines. Currently, there is a lack of an analysis framework to check mHealth apps’ security
and privacy risks following the applicable HIPAA technical security and privacy guidelines. We
propose to develop a framework to analyze mHealth apps for HIPAA security and privacy
compliance. The framework will allow users who have no knowledge of HIPAA or app security to
receive an assessment of security and privacy risks per HIPAA guidelines. Initially based on
Android Studio, the tool will test the source code of mHealth applications for potential data security
breaches related to HIPAA before posting for the marketplace. The tool will further address API
level checking for secure data communication mandated by recent CMS guidelines between third
party mobile health apps and EHR systems. The analysis framework will also address
heterogeneous health data and enable providers to remain compliant with HIPAA administrative
and operational guidelines. We propose to perform two acceptance tests on the prototype based
on partnering with HIPAA experts and medical doctors and for-profit EHR vendors along with the
effectiveness of tools for detecting health data security breaches. The proposed tool will further
enable the development of data breach checking for iOS mHealth apps and adoption and
integration by large scale EHR vendors in the future.
摘要:随着越来越多地使用移动的健康应用程序来改善健康结果,
私人健康数据正变得越来越重要。研究人员估计,
现有300,000个mHealth应用程序,其中一些与HIPAA覆盖的实体或其业务相关
合伙人随着患者对数据可访问性和应用程序数据共享的需求日益增加,
确保患者将其受保护的健康信息(PHI)传输到合规的应用程序
遵守HIPAA隐私和安全规则。约25%的医疗保健提供商遭受数据
因使用预装的移动的设备而导致违反HIPAA政策的违规行为
移动健康应用。这导致诉讼,以及医疗服务提供者之间的信心丧失,
患者早期的研究集中在移动的设备的安全性上,但没有进一步检查如何安全
应用程序在被远程医疗保健提供者或用户使用之前安全地存储或传输数据。
大多数移动的应用程序开发人员,包括mHealth应用程序,都不了解HIPAA安全和隐私
规定这为开发静态和动态代码分析工具创造了市场机会
为mHealth应用程序开发人员,使他们开发的产品符合HIPAA安全和隐私
指南目前,缺乏一个分析框架来检查mHealth应用程序的安全性
遵守适用的HIPAA技术安全和隐私准则。我们
建议开发一个框架,分析移动健康应用程序的HIPAA安全和隐私
合规该框架将允许不了解HIPAA或应用程序安全性的用户
根据HIPAA指南接受安全和隐私风险评估。最初基于
Android Studio,该工具将测试mHealth应用程序的源代码,以确保潜在的数据安全性
在发布到市场上之前,与HIPAA相关的违规行为。该工具将进一步解决API
对第三方之间最近CMS指南规定的安全数据通信进行级别检查
党的移动的健康应用程序和EHR系统。分析框架还将解决
异构健康数据,并使提供商能够保持符合HIPAA管理
和业务准则。我们建议对原型进行两次验收测试,
与HIPAA专家、医生和营利性EHR供应商合作,沿着
检测健康数据安全漏洞的工具的有效性。拟议的工具将进一步
为iOS移动健康应用程序开发数据泄露检查并采用,
在未来的大规模EHR供应商的集成。
项目成果
期刊论文数量(0)
专著数量(0)
科研奖励数量(0)
会议论文数量(0)
专利数量(0)
数据更新时间:{{ journalArticles.updateTime }}
{{
item.title }}
{{ item.translation_title }}
- DOI:
{{ item.doi }} - 发表时间:
{{ item.publish_year }} - 期刊:
- 影响因子:{{ item.factor }}
- 作者:
{{ item.authors }} - 通讯作者:
{{ item.author }}
数据更新时间:{{ journalArticles.updateTime }}
{{ item.title }}
- 作者:
{{ item.author }}
数据更新时间:{{ monograph.updateTime }}
{{ item.title }}
- 作者:
{{ item.author }}
数据更新时间:{{ sciAawards.updateTime }}
{{ item.title }}
- 作者:
{{ item.author }}
数据更新时间:{{ conferencePapers.updateTime }}
{{ item.title }}
- 作者:
{{ item.author }}
数据更新时间:{{ patent.updateTime }}
Sheikh Iqbal Ahamed其他文献
iPeer: A Sociotechnical Systems Approach for Helping Veterans with Civilian Reintegration
iPeer:帮助退伍军人重返平民社会的社会技术系统方法
- DOI:
- 发表时间:
2015 - 期刊:
- 影响因子:0
- 作者:
Rizwana Rizia;Zeno Franco;Katinka Hooyer;Nadiyah Johnson;A. Patwary;G. Ahsan;Bob Curry;M. Flower;Sheikh Iqbal Ahamed - 通讯作者:
Sheikh Iqbal Ahamed
Mobile Application-Based Solution for Building Accessibility Assessment for Comprehensive and Personalized Assessment
基于移动应用程序的解决方案,用于构建全面和个性化评估的无障碍评估
- DOI:
10.1109/compsac57700.2023.00260 - 发表时间:
2023 - 期刊:
- 影响因子:0
- 作者:
Sayeda Farzana Aktar;M. Drake;Kazi Shafiul Alami;Laryn Michele O'Donnell;Shiyu Tian;Rosalind Smith;Sheikh Iqbal Ahamed - 通讯作者:
Sheikh Iqbal Ahamed
ETS (Efficient, Transparent, and Secured) Self-healing Service for Pervasive Computing Applications
适用于普适计算应用的 ETS(高效、透明、安全)自我修复服务
- DOI:
10.6633/ijns.200705.4(3).05 - 发表时间:
2007 - 期刊:
- 影响因子:0
- 作者:
Shameem Ahmed;Moushumi Sharmin;Sheikh Iqbal Ahamed - 通讯作者:
Sheikh Iqbal Ahamed
Collaborative Design with Veterans: Identifying challenges of designing mhealth solution for veterans
与退伍军人协作设计:确定为退伍军人设计移动医疗解决方案的挑战
- DOI:
10.1109/healthcom.2015.7454526 - 发表时间:
2015 - 期刊:
- 影响因子:0
- 作者:
Rizwana Rizia;Zeno Franco;Nadiyah Johnson;Katinka Hooyer;A. Patwary;G. Ahsan;M. Flower;Bob Curry;Sheikh Iqbal Ahamed - 通讯作者:
Sheikh Iqbal Ahamed
CKH: Causal Knowledge Hierarchy for Estimating Structural Causal Models from Data and Priors
CKH:根据数据和先验估计结构因果模型的因果知识层次结构
- DOI:
- 发表时间:
2022 - 期刊:
- 影响因子:0
- 作者:
Riddhiman Adib;M. Naved;Chih;Md. Osman Gani;A. Grama;Paul M. Griffin;Sheikh Iqbal Ahamed;Mohammad Adibuzzaman - 通讯作者:
Mohammad Adibuzzaman
Sheikh Iqbal Ahamed的其他文献
{{
item.title }}
{{ item.translation_title }}
- DOI:
{{ item.doi }} - 发表时间:
{{ item.publish_year }} - 期刊:
- 影响因子:{{ item.factor }}
- 作者:
{{ item.authors }} - 通讯作者:
{{ item.author }}
{{ truncateString('Sheikh Iqbal Ahamed', 18)}}的其他基金
A Framework for mHealth App Security and Privacy Analysis
移动医疗应用程序安全和隐私分析框架
- 批准号:
10760047 - 财政年份:2021
- 资助金额:
$ 25.61万 - 项目类别:
相似海外基金
WELL-CALF: optimising accuracy for commercial adoption
WELL-CALF:优化商业采用的准确性
- 批准号:
10093543 - 财政年份:2024
- 资助金额:
$ 25.61万 - 项目类别:
Collaborative R&D
Investigating the Adoption, Actual Usage, and Outcomes of Enterprise Collaboration Systems in Remote Work Settings.
调查远程工作环境中企业协作系统的采用、实际使用和结果。
- 批准号:
24K16436 - 财政年份:2024
- 资助金额:
$ 25.61万 - 项目类别:
Grant-in-Aid for Early-Career Scientists
Unraveling the Dynamics of International Accounting: Exploring the Impact of IFRS Adoption on Firms' Financial Reporting and Business Strategies
揭示国际会计的动态:探索采用 IFRS 对公司财务报告和业务战略的影响
- 批准号:
24K16488 - 财政年份:2024
- 资助金额:
$ 25.61万 - 项目类别:
Grant-in-Aid for Early-Career Scientists
ERAMET - Ecosystem for rapid adoption of modelling and simulation METhods to address regulatory needs in the development of orphan and paediatric medicines
ERAMET - 快速采用建模和模拟方法的生态系统,以满足孤儿药和儿科药物开发中的监管需求
- 批准号:
10107647 - 财政年份:2024
- 资助金额:
$ 25.61万 - 项目类别:
EU-Funded
Assessing the Coordination of Electric Vehicle Adoption on Urban Energy Transition: A Geospatial Machine Learning Framework
评估电动汽车采用对城市能源转型的协调:地理空间机器学习框架
- 批准号:
24K20973 - 财政年份:2024
- 资助金额:
$ 25.61万 - 项目类别:
Grant-in-Aid for Early-Career Scientists
Ecosystem for rapid adoption of modelling and simulation METhods to address regulatory needs in the development of orphan and paediatric medicines
快速采用建模和模拟方法的生态系统,以满足孤儿药和儿科药物开发中的监管需求
- 批准号:
10106221 - 财政年份:2024
- 资助金额:
$ 25.61万 - 项目类别:
EU-Funded
Our focus for this project is accelerating the development and adoption of resource efficient solutions like fashion rental through technological advancement, addressing longer in use and reuse
我们该项目的重点是通过技术进步加快时装租赁等资源高效解决方案的开发和采用,解决更长的使用和重复使用问题
- 批准号:
10075502 - 财政年份:2023
- 资助金额:
$ 25.61万 - 项目类别:
Grant for R&D
Engage2innovate – Enhancing security solution design, adoption and impact through effective engagement and social innovation (E2i)
Engage2innovate — 通过有效参与和社会创新增强安全解决方案的设计、采用和影响 (E2i)
- 批准号:
10089082 - 财政年份:2023
- 资助金额:
$ 25.61万 - 项目类别:
EU-Funded
De-Adoption Beta-Blockers in patients with stable ischemic heart disease without REduced LV ejection fraction, ongoing Ischemia, or Arrhythmias: a randomized Trial with blinded Endpoints (ABbreviate)
在没有左心室射血分数降低、持续性缺血或心律失常的稳定型缺血性心脏病患者中停用β受体阻滞剂:一项盲法终点随机试验(ABbreviate)
- 批准号:
481560 - 财政年份:2023
- 资助金额:
$ 25.61万 - 项目类别:
Operating Grants
Collaborative Research: SCIPE: CyberInfrastructure Professionals InnoVating and brOadening the adoption of advanced Technologies (CI PIVOT)
合作研究:SCIPE:网络基础设施专业人员创新和扩大先进技术的采用 (CI PIVOT)
- 批准号:
2321091 - 财政年份:2023
- 资助金额:
$ 25.61万 - 项目类别:
Standard Grant