• 文献检索
  • 文档翻译
  • 深度研究
  • 学术资讯
  • Suppr Zotero 插件Zotero 插件
  • 邀请有礼
  • 套餐&价格
  • 历史记录
应用&插件
Suppr Zotero 插件Zotero 插件浏览器插件Mac 客户端Windows 客户端微信小程序
定价
高级版会员购买积分包购买API积分包
服务
文献检索文档翻译深度研究API 文档MCP 服务
关于我们
关于 Suppr公司介绍联系我们用户协议隐私条款
关注我们

Suppr 超能文献

核心技术专利:CN118964589B侵权必究
粤ICP备2023148730 号-1Suppr @ 2026

文献检索

告别复杂PubMed语法,用中文像聊天一样搜索,搜遍4000万医学文献。AI智能推荐,让科研检索更轻松。

立即免费搜索

文件翻译

保留排版,准确专业,支持PDF/Word/PPT等文件格式,支持 12+语言互译。

免费翻译文档

深度研究

AI帮你快速写综述,25分钟生成高质量综述,智能提取关键信息,辅助科研写作。

立即免费体验

相似文献

1
A comparative study on HIPAA technical safeguards assessment of android mHealth applications.安卓移动健康应用程序的《健康保险流通与责任法案》技术保障评估的比较研究
Smart Health (Amst). 2022 Dec;26. doi: 10.1016/j.smhl.2022.100349. Epub 2022 Oct 8.
2
User Control of Personal mHealth Data Using a Mobile Blockchain App: Design Science Perspective.用户使用移动区块链应用程序控制个人健康数据:设计科学视角。
JMIR Mhealth Uhealth. 2022 Jan 20;10(1):e32104. doi: 10.2196/32104.
3
Security Concerns in Android mHealth Apps.安卓移动医疗应用中的安全问题。
AMIA Annu Symp Proc. 2014 Nov 14;2014:645-54. eCollection 2014.
4
Challenges With Developing Secure Mobile Health Applications: Systematic Review.开发安全移动医疗应用程序的挑战:系统综述。
JMIR Mhealth Uhealth. 2021 Jun 21;9(6):e15654. doi: 10.2196/15654.
5
Doctors Routinely Share Health Data Electronically Under HIPAA, and Sharing With Patients and Patients' Third-Party Health Apps is Consistent: Interoperability and Privacy Analysis.根据 HIPAA 规定,医生通常会以电子方式共享健康数据,与患者及其患者第三方健康应用程序共享数据也是符合规定的:互操作性和隐私分析。
J Med Internet Res. 2020 Sep 2;22(9):e19818. doi: 10.2196/19818.
6
mHealth Solutions for Perinatal Mental Health: Scoping Review and Appraisal Following the mHealth Index and Navigation Database Framework.移动医疗在围产期心理健康中的应用:基于移动医疗索引和导航数据库框架的系统评价和评估。
JMIR Mhealth Uhealth. 2022 Jan 17;10(1):e30724. doi: 10.2196/30724.
7
Pulse Oximeter App Privacy Policies During COVID-19: Scoping Assessment.脉搏血氧仪应用隐私政策在 COVID-19 期间:范围评估。
JMIR Mhealth Uhealth. 2022 Jan 27;10(1):e30361. doi: 10.2196/30361.
8
Analyzing security issues of android mobile health and medical applications.分析安卓移动健康和医疗应用的安全问题。
J Am Med Inform Assoc. 2021 Sep 18;28(10):2074-2084. doi: 10.1093/jamia/ocab131.
9
Privacy, Data Sharing, and Data Security Policies of Women's mHealth Apps: Scoping Review and Content Analysis.女性移动健康应用程序的隐私、数据共享和数据安全政策:范围综述和内容分析。
JMIR Mhealth Uhealth. 2022 May 6;10(5):e33735. doi: 10.2196/33735.
10
Critical Criteria and Countermeasures for Mobile Health Developers to Ensure Mobile Health Privacy and Security: Mixed Methods Study.移动健康开发者确保移动健康隐私和安全的关键标准和对策:混合方法研究。
JMIR Mhealth Uhealth. 2023 Mar 2;11:e39055. doi: 10.2196/39055.

本文引用的文献

1
HIPAA and the Leak of "Deidentified" EHR Data.《健康保险流通与责任法案》与“去标识化”电子健康记录数据泄露
N Engl J Med. 2021 Jun 10;384(23):2171-2173. doi: 10.1056/NEJMp2102616. Epub 2021 Jun 5.
2
Digital advantage in the COVID-19 response: perspective from Canada's largest integrated digitalized healthcare system.新冠疫情应对中的数字优势:来自加拿大最大的综合数字化医疗系统的视角
NPJ Digit Med. 2020 Aug 31;3:114. doi: 10.1038/s41746-020-00326-y. eCollection 2020.
3
Delivering healthcare remotely to cardiovascular patients during COVID-19 : A rapid review of the evidence.在 COVID-19 期间远程为心血管病患者提供医疗保健:对证据的快速综述。
Eur J Cardiovasc Nurs. 2020 Aug;19(6):486-494. doi: 10.1177/1474515120924530. Epub 2020 May 7.
4
Security Recommendations for mHealth Apps: Elaboration of a Developer's Guide.移动医疗应用安全建议:开发者指南详述。
J Med Syst. 2016 Jun;40(6):152. doi: 10.1007/s10916-016-0513-6. Epub 2016 May 4.
5
Health App Use Among US Mobile Phone Owners: A National Survey.美国手机用户使用健康类 APP 情况的全国性调查
JMIR Mhealth Uhealth. 2015 Nov 4;3(4):e101. doi: 10.2196/mhealth.4924.
6
A new dimension of health care: systematic review of the uses, benefits, and limitations of social media for health communication.医疗保健的一个新维度:社交媒体用于健康传播的用途、益处及局限性的系统综述
J Med Internet Res. 2013 Apr 23;15(4):e85. doi: 10.2196/jmir.1933.
7
Mobile personal health records: an evaluation of features and functionality.移动个人健康记录:功能和特点评估。
Int J Med Inform. 2012 Sep;81(9):579-93. doi: 10.1016/j.ijmedinf.2012.04.007. Epub 2012 Jul 17.
8
Health Insurance Portability and Accountability Act of 1996. Public Law 104-191.1996年《健康保险流通与责任法案》。公法第104 - 191号。
US Statut Large. 1996 Aug 21;110:1936-2103.
9
An overview of the HIPAA Security Rule, Part II: Standards and specifications.《健康保险流通与责任法案》安全规则概述,第二部分:标准与规范
Optometry. 2004 Nov;75(11):728-30.
10
Protection of human subjects.保护人类受试者。
Code Fed Regul Public Welfare. 1995 Oct 1;Title 45(Sections 46-101 to 46-409).

安卓移动健康应用程序的《健康保险流通与责任法案》技术保障评估的比较研究

A comparative study on HIPAA technical safeguards assessment of android mHealth applications.

作者信息

Mia Md Raihan, Shahriar Hossain, Valero Maria, Sakib Nazmus, Saha Bilash, Barek Md Abdul, Faruk Md Jobair Hossain, Goodman Ben, Khan Rumi Ahmed, Ahamed Sheikh Iqbal

机构信息

Department of Computer Science at Marquette University, WI, USA.

Department of Information Technology at Kennesaw State University, GA, USA.

出版信息

Smart Health (Amst). 2022 Dec;26. doi: 10.1016/j.smhl.2022.100349. Epub 2022 Oct 8.

DOI:10.1016/j.smhl.2022.100349
PMID:39086849
原文链接:https://pmc.ncbi.nlm.nih.gov/articles/PMC11290549/
Abstract

Protecting personal health records is becoming increasingly important as more people use Mobile Health applications (mHealth apps) to improve their health outcomes. These mHealth apps enable consumers to monitor their health-related problems, store, manage, and share health records, medical conditions, treatment, and medication. With the increase of mHealth apps accessibility and usability, it is crucial to create, receive, maintain or transmit protected health information (PHI) on behalf of a covered entity or another business associate. The Health Insurance Portability and Accountability Act (HIPAA) provides guidelines to the app developers so that the apps must be compliant with required and addressable Technical Safeguards. However, most mobile app developers, including mHealth apps are not aware of HIPAA security and privacy regulations. Therefore, a research opportunity has emerged to develop an analytical framework to assist the developer to maintain a secure and HIPAA-compliant source code and raise awareness among consumers about the privacy and security of sensitive and personal health information. We proposed an Android source code analysis framework that evaluates twelve HIPAA Technical Safeguards to check whether a mHealth application is HIPAA compliant or not. The implemented meta-analysis and data-flow analysis algorithms efficiently identify the risk and safety features of mHealth apps that violate HIPAA regulations. Furthermore, we addressed API level checking for secure data communication mandated by recent CMS guidelines between third-party mobile health apps and EHR systems. Experimentally, a web-based tool has been developed for evaluating the efficacy of analysis techniques and algorithms. We have investigated 200 top popular Medical and Health & Fitness category Android apps collected from Google Play Store. We identified from the comparative analysis of the HIPAA rules assessment results that authorization to access sensitive resources, data encryption-decryption, and data transmission security is the most vulnerable features of the investigated apps. We provided recommendations to app developers about the most common mistake made at the time of app development and how to avoid these mistakes to implement secure and HIPAA-compliant apps. The proposed framework enables us to develop an IDE plugin for mHealth app developers and a web-based interface for mHealth app consumers.

摘要

随着越来越多的人使用移动健康应用程序(mHealth应用)来改善健康状况,保护个人健康记录变得愈发重要。这些mHealth应用使消费者能够监测与健康相关的问题、存储、管理和共享健康记录、医疗状况、治疗情况及用药信息。随着mHealth应用的可访问性和可用性不断提高,代表涵盖实体或其他业务伙伴创建、接收、维护或传输受保护健康信息(PHI)至关重要。《健康保险流通与责任法案》(HIPAA)为应用开发者提供了指导方针,以使应用必须符合规定的和可解决的技术保障措施。然而,包括mHealth应用在内的大多数移动应用开发者并不了解HIPAA的安全和隐私法规。因此,出现了一个研究机会,即开发一个分析框架,以协助开发者维护安全且符合HIPAA的源代码,并提高消费者对敏感和个人健康信息的隐私及安全的认识。我们提出了一个安卓源代码分析框架,该框架评估十二项HIPAA技术保障措施,以检查mHealth应用是否符合HIPAA规定。所实施的元分析和数据流分析算法能有效识别违反HIPAA法规的mHealth应用的风险和安全特征。此外,我们还针对第三方移动健康应用与电子健康记录(EHR)系统之间近期CMS指南所要求的安全数据通信进行了API级别检查。通过实验,开发了一个基于网络的工具来评估分析技术和算法的有效性。我们调查了从谷歌应用商店收集的200款最受欢迎的医疗及健康与健身类安卓应用。从对HIPAA规则评估结果的比较分析中我们发现,访问敏感资源的授权、数据加密解密以及数据传输安全是被调查应用中最易受攻击的特征。我们向应用开发者提供了关于应用开发时最常见错误的建议,以及如何避免这些错误以实现安全且符合HIPAA的应用。所提出的框架使我们能够为mHealth应用开发者开发一个集成开发环境(IDE)插件,并为mHealth应用消费者开发一个基于网络的界面。