Department of Signal Theory and Communications, and Telematics Engineering, University of Valladolid, Paseo de Belén, 15, 47011, Valladolid, Spain.
University of Deusto, Avenida de las Universidades 24, 48007, Bilbao, Spain.
J Med Syst. 2016 Jun;40(6):152. doi: 10.1007/s10916-016-0513-6. Epub 2016 May 4.
Being the third fastest-growing app category behind games and utilities, mHealth apps are changing the healthcare model, as medicine today involves the data they compile and analyse, information known as Big Data. However, the majority of apps are lacking in security when gathering and dealing with the information, which becomes a serious problem. This article presents a guide regarding security solution, intended to be of great use for developers of mHealth apps. In August 2015 current mobile health apps were sought out in virtual stores such as Android Google Play, Apple iTunes App Store etc., in order to classify them in terms of usefulness. After this search, the most widespread weaknesses in the field of security in the development of these mobile apps were examined, based on sources such as the "OWASP Mobile Security Project, the initiative recently launched by the Office of Civil Rights (OCR), and other articles of scientific interest. An informative, elemental guide has been created for the development of mHealth apps. It includes information about elements of security and its implementation on different levels for all types of mobile health apps based on the data that each app manipulates, the associated calculated risk as a result of the likelihood of occurrence and the threat level resulting from its vulnerabilities - high level (apps for monitoring, diagnosis, treatment and care) from 6 ≤ 9, medium level (calculator, localizer and alarm) from 3 ≤ 6 and low level (informative and educational apps) from 0 ≤ 3. The guide aims to guarantee and facilitate security measures in the development of mobile health applications by programmers unconnected to the ITC and professional health areas.
在游戏和实用工具之后,作为第三大增长最快的应用类别,移动医疗应用正在改变医疗模式,因为当今的医学涉及到它们收集和分析的数据,这些信息被称为大数据。然而,大多数应用在收集和处理信息时缺乏安全性,这成为一个严重的问题。本文提供了一个安全解决方案指南,旨在为移动医疗应用的开发者提供极大的帮助。在 2015 年 8 月,在虚拟商店(如 Android Google Play、Apple iTunes App Store 等)中搜索了当前的移动健康应用,以便根据有用性对其进行分类。在进行了这次搜索之后,根据“OWASP 移动安全项目”、民权办公室(OCR)最近发起的倡议以及其他一些科学兴趣文章等来源,检查了这些移动应用程序开发中安全领域最普遍的弱点。为移动医疗应用程序的开发创建了一个信息丰富、基础的指南。它包括关于安全元素及其在不同级别上的实现的信息,适用于基于每个应用程序处理的数据、由于发生的可能性和漏洞导致的威胁级别而产生的相关计算风险的所有类型的移动健康应用程序 - 高水平(用于监测、诊断、治疗和护理的应用程序)从 6 ⁇ 9,中等级(计算器、定位器和警报器)从 3 ⁇ 6,低等级(信息和教育应用程序)从 0 ⁇ 3。该指南旨在为与 ITC 和专业健康领域无关的程序员在移动健康应用程序的开发中提供和促进安全措施。
J Med Syst. 2016-5-4
AMIA Annu Symp Proc. 2014-11-14
JMIR Mhealth Uhealth. 2021-6-21
JMIR Mhealth Uhealth. 2015-1-19
J Med Internet Res. 2019-1-23
JMIR Mhealth Uhealth. 2020-9-16
JMIR Mhealth Uhealth. 2022-5-6
JMIR Mhealth Uhealth. 2019-4-16
Smart Health (Amst). 2022-12
JMIR Public Health Surveill. 2024-6-24
J Med Internet Res. 2023-5-12
Int J Environ Res Public Health. 2021-11-27
Int J Telerehabil. 2020-12-8
J Med Syst. 2015-11-7
Geriatr Nurs. 2013