1 / 8100%
First Article: Laws Regulating Mobile Health Apps: Professional software e
Mobile health apps are growing in importance, requiring effective regulation. mHealth affects
practitioners, patients, researchers, and the medical sector. Four laws govern the FDA's digital
health regulations.
HIPAA protects the privacy of medical records. Under the Federal Food, Drug, and Cosmetic
Act, the FDA oversees medical device safety and efficacy. The FTC Act prohibits making
deceptive claims about app use. FTC's Health Breach Notification Rule requires some
companies to notify patients when health data is breached.
The app's nature determines which rules apply. HIPPA restricts applications using PHI. This
category includes health care provider, plan, and HIPAA business associate apps. Kony,
Humana, and myCigna allow users to manage their health plans online, including calling the
insurer and tracking benefits and drugs.
If the app detects, prevents, or cures certain conditions, the FD&C Act applies. Dermatology
helps doctors rapidly and effectively diagnose skin cancers. Asthma tracks symptoms and
trigger patterns to prevent attacks.
Second Article: The state of research on cyberattacks against hospitals and available best
practice recommendations: A scoping review.
Cybercriminals are targeting the healthcare industry. Hospitals are sensitive to cyberattacks
because any disruption in operations or disclosure of patient information can have far-reaching
implications. Hospitals rely more on computer systems for administrative, financial, and
medical activities. Increased use of connected medical equipment, cloud storage, and network
technologies. Technological advances continue despite the need to balance innovation with
privacy and security. Healthcare lags behind other industries in preserving data and
developing employee training programs, despite the latter being the most effective against
breaches.
Because of how easily they're interrupted, health care organizations are vulnerable to attacks.
Delaying or stopping hospital operations might be disastrous. Hollywood Presbyterian
Medical Center's ransomware outbreak lasted 10 days. Another attack on the British NHS had
comparable repercussions on hospitals, as well as radiography and blood-product
refrigeration. Physicians lose access to virtual diagnostic, allergy, and prescription
information, raising patient safety issues. Breach and publishing of sensitive health
information can disrupt health care, social and professional life, and blackmail.
Cybercriminals can steal patients' PHI and commit medical fraud. Direct costs from patient
compensation and fines, plus long-term financial consequences from a damaged reputation.
Care interruptions could affect hospital networks (i.e., spreading into ambulance, pharmacy,
and health insurance company operations).
Mobile health (mHealth) has many definitions. One of them is the National Institutes of
Health Fogarty International Center that states mHealth uses “mobile technologies as tools and
platforms for health research and healthcare delivery.” In addition, the Fogarty International
Center sponsors a particular program that studies innovative research tools for mHealth
applications that are utilized for chronic health conditions. This particular article chooses to
focus “on the use of mobile apps for health-related research, concentrating in particular on
mobile-app-mediated research conducted or participated in by independent scientists, citizen
scientists, and patient researchers.” (Tovino, 2019) One of the applications cited in the article,
MyFitnessPal (owned by Under Armour), discovered a data breach in March 2018. e Over 150
million MyFitnessPal accounts were hacked, and information like passwords, user IDs, and
email addresses was obtained. Under Armour did notify those account holders by email. At
the same time, “MyFitnessPal clearly followed some type of breach notification policy, it is
unclear whether MyFitnessPal had implemented privacy standards and security safeguards
that could have prevented the breach in the first place.” (Tovino, 2019). With that in mind,
MyFitnessPal is not owned or conducted by a healthcare provider (or covered entity), nor does
it function as one, so it does not have to adhere to HIPAA regulations.
e e e e e e e e e The second article discusses how new IT technologies and methods are needed to avert
data breaches. For example, data modeling phase is considered a high-risk phase due to the
“focus of data miners in this phase is to use powerful data mining algorithms that can extract
sensitive data” so “the network components in general, must be configured and protected
against data mining-based attacks and any security breach that may happen, as well as make
sure that only authorized staff work in this phase.” (Abouelmehdi et al., 2017) In addition,
technologies like the authentication of users, encryption of healthcare data, data masking of
patient identifiers, and access control. Another technology mentioned in the article is
monitoring and auditing. Monitoring is searching network activity for malicious invasions,
and auditing is documenting the facility’s user activities, which logs every access to and
alteration of data. This security measure is not only a proactive measure but part of
compliance with the HIPAA security Rule technical standards.
The first article I chose was about mobile health technologies for management of depression.
The article summarized that mobile health technology can help providers diagnose, monitor,
prevent, and treat symptoms of depression (Gramigna,2020). The problem is when it comes to
privacy, regulation, and ethics of others. The second article I read was based on Texas
Department of Insurance data breach that happened this past March. A massive security
breach leaked the personal information of almost 2 million Texans for nearly three years. The
personal information of 1.8 million workers were available online to the public from March
2019 to January 2022 (). The breach came from a programming code in the department's web
application that manages workers compensation data
The first article I chose is Failed to encrypt mobile devices leads to 3 million HIPAA
settlement on the HHS website. This article examines a data breach at the University of
Rochester Medical Center (URMC) that resulted in a violation of HIPAA privacy and security
rules. The data breach occurred because of the uninvited loss of a flash drive and the theft of
an all fan encrypted laptop. Because of the loss of the flash drive and the theft of the laptop,
Phi off patients were released without permission. OCR's investigation revealed that you, as
MC, failed to conduct and encrypt a comprehensive risk assessment. Encrypted and decrypted
electronically protected health information E Phi using device and media controls and a
machine. When doing so was reasonable and appropriate. This was not the first time ORC had
looked into URMC. URMC had lost another in an unscripted flash drive in 2010. Despite the
previous investigation and identification of unencrypted devices, URMC continues to use
unencrypted devices. Using unencrypted devices increases the risk of Phi being compromised.
Your RMC was aware of the problem within their organization but failed to address it,
resulting in the current PHI breach. They were held fully responsible for the breach of PHI due
to their failure to fix the problem. You RMC agreed to pay the OCR $3 million in exchange for
two years of monitoring their HIPAA compliance.
The second article I discovered on the AAP news website is Health care providers are
vulnerable to cyberattacks during the COVID-19 pandemic. With the current state of the
world with the COVID-19, health care providers have become even more reliant on
technology and digital tools. As a result, the likelihood of data breaches increasing. There
have been reports of cybercriminals planting malware on computers that access non-secure
websites using certain types of documents, such as corona virus coverage maps. There have
also been reports of targeted email scams promising personal protective equipment and the
pandemic of COVID-19. The article then discusses some best practices that can be used to
assist in the security of systems. They discuss general security, email security, and web
conferencing security.
Mobile Health Information has become an increasingly popular portal for patient healthcare.
With the ease of schedule making, messages to providers, to even paying your bill from the
ease of an app on your phone. This also leaves patients' information susceptible to malicious
intent. The article, Ethical and Legal Issues Addressing the Use of Mobile Health (mHealth) as
an Adjunct to Psychotherapy the is supporting information on how the use of disclosing
certain information even within the guidelines of HIPAA can still possibly breach a patient’s
private information. For example, the article wrote, that the ease of use of text messaging may
be tempting for psychologists to consult with other professionals about confidential matters
over text messages. However, psychologists should be mindful that this is not a secure
medium and to discuss information only pertinent to the consultation and only for professional
purposes. This is a specific example that shows how easily well-intended information
transpires can create an improper discourse of health information quickly.
Once we understand how fragile health information can be while in a mobile data realm, we
also need to prepare to protect it. Technology brings convenience, but not at the cost of
possible compromise. Article two, Protecting Patient Information in the Age of Breaches
wrote, “A breach can happen in a variety of different ways. However, one of the most common
causes of breaches within the health care field is simply human error. Health care workers who
use unauthorized cloud-based apps can leave a patient’s information vulnerable to an attack.”
Audit trails are a great tool to use to combat this weak area in the protection of patient health
information. By identifying areas of human error policies and procedures can be used to
thwart these attacks on patients’ privacy while allowing the freedoms and accessibility of
mobile apps for healthcare usage. e
Mobile Health Information has become an increasingly popular portal for patient healthcare.
With the ease of schedule making, messages to providers, to even paying your bill from the
ease of an app on your phone. This also leaves patients' information susceptible to malicious
intent. The article, Ethical and Legal Issues Addressing the Use of Mobile Health (mHealth) as
an Adjunct to Psychotherapy the is supporting information on how the use of disclosing
certain information even within the guidelines of HIPAA can still possibly breach a patient’s
private information. For example, the article wrote, that the ease of use of text messaging may
be tempting for psychologists to consult with other professionals about confidential matters
over text messages. However, psychologists should be mindful that this is not a secure
medium and to discuss information only pertinent to the consultation and only for professional
purposes. This is a specific example that shows how easily well-intended information
transpires can create an improper discourse of health information quickly.
Once we understand how fragile health information can be while in a mobile data realm, we
also need to prepare to protect it. Technology brings convenience, but not at the cost of
possible compromise. Article two, Protecting Patient Information in the Age of Breaches
wrote, “A breach can happen in a variety of different ways. However, one of the most common
causes of breaches within the health care field is simply human error. Health care workers who
use unauthorized cloud-based apps can leave a patient’s information vulnerable to an attack.”
Audit trails are a great tool to use to combat this weak area in the protection of patient health
information. By identifying areas of human error policies and procedures can be used to
thwart these attacks on patients’ privacy while allowing the freedoms and accessibility of
mobile apps for healthcare usage. e
References
Karcher, N. R., & Presser, N. R. (2018). Ethical and legal issues addressing the use of mobile
health (mHealth) as an adjunct to psychotherapy. Ethics & Behaviour, 28(1), 1–22.
https://doi.org/10.1080/10508422.2016.1229187
Turteltaub, A. (2017, March 16). Protecting Patient Information in the Age of breaches. The
Compliance and Ethics Blog. https://www.complianceandethics.org/protecting-patient-
information-age-breaches/
Karcher, N. R., & Presser, N. R. (2018). Ethical and legal issues addressing the use of mobile
health (mHealth) as an adjunct to psychotherapy. Ethics & Behaviour, 28(1), 1–22.
https://doi.org/10.1080/10508422.2016.1229187
Turteltaub, A. (2017, March 16). Protecting Patient Information in the Age of breaches. The
Compliance and Ethics Blog. https://www.complianceandethics.org/protecting-patient-
information-age-breaches/
Failure to encrypt mobile devices leads to $3 million hipaa settlement: Guidance portal.
Failure to Encrypt Mobile Devices Leads to $3 Million HIPAA Settlement | Guidance Portal.
(n.d.). Retrieved June 2, 2022, from https://www.hhs.gov/guidance/document/failure-encrypt-
mobile-devices-leads-3-million-hipaa-
settlement#:~:text=The%20University%20of%20Rochester%20Medical,and%20Accountabil
ity%20Act%20(HIPAA)%20Privacy.
Publications.aap.org. (n.d.). Retrieved June 2, 2022, from
https://publications.aap.org/aapnews/news/10884?autologincheck=redirected.
Mobile health technologies for depression present ethical, legal, regulatory challenges. (2020).
Healio. https://www.healio.com/news/psychiatry/20200601/mobile-health-technologies-for-
depression-present-ethical-legal-regulatory-challenges
Abouelmehdi, K., Beni-Hssane, A., Khaloufi, H., & Saadi, M. (2017). Big data security and
privacy in healthcare: A Review. Procedia Computer Science, 113, 73–80. https://doi-
org.ezproxy.snhu.edu/10.1016/j.procs.2017.08.292
Tovino, S. A. (2019). GOING ROGUE: MOBILE RESEARCH APPLICATIONS AND THE
RIGHT TO PRIVACY. Notre Dame Law Review, 95(1), 155+.
https://link.gale.com/apps/doc/A611932802/AONE?u=nhc_main&sid=bookmark-
AONE&xid=00828b4b
Laws Regulating Mobile Health Apps: Regdesk: Professional software. RegDesk. (2019,
March 21). Retrieved May 31, 2022, from https://www.regdesk.co/laws-regulating-mobile-
health-apps/
Argaw, S. T., Bempong, N.-E., Eshaya-Chauvin, B., & Flahault, A. (2019, January 11).
The state of research on cyberattacks against hospitals and available best practice
recommendations: A scoping review. BMC medical informatics and decision making.
Retrieved May 31, 2022, from https://www.ncbi.nlm.nih.gov/pmc/articles/PMC6330387/
Students also viewed