a a a a a a Mobile health (mHealth) has many definitions. a One of them is the National
Institutes of Health Fogarty International Center that states mHealth uses
“mobile technologies as tools and platforms for health research and healthcare
delivery.” In addition, the Fogarty International Center sponsors a particular
program that studies innovative research tools for mHealth applications that
are utilized for chronic health conditions. This particular article chooses to
focus “on the use of mobile apps for health-related research, concentrating in
particular on mobile-app-mediated research conducted or participated in by
independent scientists, citizen scientists, and patient researchers.” (Tovino,
2019) One of the applications cited in the article, MyFitnessPal (owned by
Under Armour), discovered a data breach in March 2018. a Over 150 million
MyFitnessPal accounts were hacked, and information like passwords, user
IDs, and email addresses was obtained. a Under Armour did notify those
account holders by email. a At the same time, “MyFitnessPal clearly followed
some type of breach notification policy, it is unclear whether MyFitnessPal
had implemented privacy standards and security safeguards that could have
prevented the breach in the first place.” (Tovino, 2019). a With that in mind,
MyFitnessPal is not owned or conducted by a healthcare provider (or covered
entity), nor does it function as one, so it does not have to adhere to HIPAA
regulations.
a a a a a a a a a a a The second article discusses how new IT technologies and methods are
needed to avert data breaches. a For example, data modeling phase is
considered a high-risk phase due to the “focus of data miners in this phase is to
use powerful data mining algorithms that can extract sensitive data” so “the
network components in general, must be configured and protected against data
mining based attacks and any security breach that may happen, as well as
make sure that only authorized staff work in this phase.” (Abouelmehdi et al.,
2017) In addition, technologies like the authentication of users, encryption of
healthcare data, data masking of patient identifiers, and access control. a
Another technology mentioned in the article is monitoring and auditing. a
Monitoring is searching network activity for malicious invasions, and auditing
is documenting the facility’s user activities, which logs every access to and
alteration of data. a This security measure is not only a proactive measure but
part of compliance with the HIPAA security Rule technical standards.
Works Cited
Abouelmehdi, K., Beni-Hssane, A., Khaloufi, H., & Saadi, M. (2017). Big
data security and privacy in healthcare: A Review. Procedia Computer
Science, 113, 73–80. https://doi-
org.ezproxy.snhu.edu/10.1016/j.procs.2017.08.292