CINTESIS-Center for Health Technologies and Services Research, Faculty of Medicine, University of Porto, Porto, Portugal.
Department of Computer Science, Universidade da Beira Interior and Instituto de Telecomunicações, Covilhã, Portugal.
J Healthc Eng. 2020 Jan 17;2020:5601068. doi: 10.1155/2020/5601068. eCollection 2020.
Smartphones can tackle healthcare stakeholders' diverse needs. Nonetheless, the risk of data disclosure/breach can be higher when using such devices, due to the lack of adequate security and the fact that a medical record has a significant higher financial value when compared with other records. Means to assess those risks are required for every mHealth application interaction, dependent and independent of its goals/content.
To present a risk assessment feature integration into the SoTRAACE (Socio-Technical Risk-Adaptable Access Control) model, as well as the operationalization of the related mobile health decision policies.
Since there is still a lack of a definition for health data security categorization, a Delphi study with security experts was performed for this purpose, to reflect the knowledge of security experts and to be closer to real-life situations and their associated risks.
The Delphi study allowed a consensus to be reached on eleven risk factors of information security related to mobile applications that can easily be adapted into the described SoTRAACE prototype. Within those risk factors, the most significant five, as assessed by the experts, and in descending order of risk level, are as follows: (1) security in the communication (e.g., used security protocols), (2) behavioural differences (e.g., different or outlier patterns of behaviour detected for a user), (3) type of wireless connection and respective encryption, (4) resource sensitivity, and (5) device threat level (e.g., known vulnerabilities associated to a device or its operating system).
Building adaptable, risk-aware resilient access control models into the most generalized technology used nowadays (e.g., smartphones) is crucial to fulfil both the goals of users as well as security and privacy requirements for healthcare data.
智能手机可以满足医疗保健利益相关者的多样化需求。然而,由于缺乏足够的安全性,并且与其他记录相比,医疗记录具有更高的财务价值,因此在使用此类设备时,数据泄露/被破坏的风险可能更高。需要为每个移动健康应用程序交互评估这些风险,无论其目标/内容如何。
将风险评估功能集成到 SoTRAACE(社会技术风险自适应访问控制)模型中,并实现相关移动健康决策策略的实施。
由于健康数据安全分类仍然缺乏定义,因此为此目的进行了安全专家的 Delphi 研究,以反映安全专家的知识,并更接近现实生活情况及其相关风险。
Delphi 研究达成了共识,即确定了与移动应用程序相关的十一个信息安全风险因素,这些因素可以轻松地适应所描述的 SoTRAACE 原型。在这些风险因素中,专家评估的五个最重要的风险因素,按风险级别降序排列如下:(1)通信安全(例如,使用的安全协议),(2)行为差异(例如,检测到用户的不同或异常行为模式),(3)无线连接类型及其加密方式,(4)资源敏感性,以及(5)设备威胁级别(例如,与设备或其操作系统相关的已知漏洞)。
将自适应、风险感知的弹性访问控制模型构建到当今使用的最通用的技术(例如智能手机)中,对于满足用户的目标以及医疗保健数据的安全和隐私要求至关重要。