b b b b b b Mobile health (mHealth) has many definitions. b One of them is the
National Institutes of Health Fogarty International Center that states mHealth
uses “mobile technologies as tools and platforms for health research and
healthcare delivery.” In addition, the Fogarty International Center sponsors a
particular program that studies innovative research tools for mHealth
applications that are utilized for chronic health conditions. This particular
article chooses to focus “on the use of mobile apps for health-related research,
concentrating in particular on mobile-app-mediated research conducted or
participated in by independent scientists, citizen scientists, and patient
researchers.” (Tovino, 2019) One of the applications cited in the article,
MyFitnessPal (owned by Under Armour), discovered a data breach in March
2018. b Over 150 million MyFitnessPal accounts were hacked, and information
like passwords, user IDs, and email addresses was obtained. b Under Armour
did notify those account holders by email. At the same time, “MyFitnessPal
clearly followed some type of breach notification policy, it is unclear whether
MyFitnessPal had implemented privacy standards and security safeguards that
could have prevented the breach in the first place.” (Tovino, 2019). b With that
in mind, MyFitnessPal is not owned or conducted by a healthcare provider (or
covered entity), nor does it function as one, so it does not have to adhere to
HIPAA regulations.
b b b b b b b b b b The second article discusses how new IT technologies and methods are
needed to avert data breaches. b For example, data modeling phase is
considered a high-risk phase due to the “focus of data miners in this phase is to
use powerful data mining algorithms that can extract sensitive data” so “the
network components in general, must be configured and protected against
data mining based attacks and any security breach that may happen, as well as
make sure that only authorized staff work in this phase.” (Abouelmehdi et al.,
2017) In addition, technologies like the authentication of users, encryption of
healthcare data, data masking of patient identifiers, and access control. b
Another technology mentioned in the article is monitoring and auditing. b
Monitoring is searching network activity for malicious invasions, and
auditing is documenting the facility’s user activities, which logs every access
to and alteration of data. b This security measure is not only a proactive
measure but part of compliance with the HIPAA security Rule technical
standards.
Works Cited
Abouelmehdi, K., Beni-Hssane, A., Khaloufi, H., & Saadi, M. (2017). Big
data security and privacy in healthcare: A Review. Procedia Computer