SlideShare a Scribd company logo
1 of 11
Protecting Privacy, Security and 
Patient Safety in mHealth 
Oklahoma Telemedicine Conference 
Telehealth Transition: Opportunity to Value Creation 
Patricia D. King, J.D., M.B.A.
HIPAA Privacy 
and Breach Notification 
 Many reported breaches of unsecured PHI involve 
mobile devices 
 Examples: Massachusetts Eye & Ear Infirmary settled 
case for $1.5 million, agreed to adopt safeguards for 
mobile devices 
 OCR has developed compliance resources specifically 
for mobile devices* 
 Portability and ease of use of mobile devices create 
unique risks 
http://www.healthit.gov/providers-professionals/your-mobile-device- 
and-health-information-privacy-and-security
HIPAA Security 
 HIPAA Security Rule requires covered entities to 
periodically review their security procedures when 
technology changes and introduces new risks 
 Access to EPHI on mobile devices is a significant 
operational change requiring providers to revisit their 
security policies and procedures 
 BYOD introduces additional vulnerabilities 
 ENCRYPTION, ENCRYPTION, ENCRYPTION!
NIST Guidelines for Mitigating Risk of 
Mobile Devices* 
 Risk: theft or loss 
 Mitigation: 
 Encryption 
 Permitting access to EPHI 
but not storage 
 Device-based 
authentication 
 Network-based 
authentication 
 Risk: inherent 
vulnerabilities due to lack 
of root of trust features 
 Mitigation: 
 Centralized mobile device 
management technology 
 If BYOD is permitted, 
isolation of organization’s 
data and applications 
Guidelines for Managing the Security of Mobile Devices in the 
Enterprise, NIST Special Publication 800-124, Rev. 1
NIST guidelines (cont’d) 
 Risk: “man in the middle” 
attacks on unsecure 
networks 
 Mitigation: 
 Use of virtual private 
network (VPN) 
 Risk: introduction of 
malware through apps 
 Mitigation: 
 Prohibiting installation of 
third-party apps unless 
“white-listed” 
 Prohibiting browser 
access or forcing through 
secure gateway
Special Considerations for BYOD* 
 Advantages: user satisfaction, potential savings on 
device purchases 
 If BYOD is permitted, the user-owned device will have 
2 information owners: the user for personal data, and 
the organization for EPHI and business processes. 
 If the organization’s data and apps are confined to a 
sandbox/secure container, then a remote wipe can be 
performed if the device is vulnerable without 
disrupting the owner’s data. 
Guidelines on Hardware-Rooted Security in Mobile Devices, NIST Special 
Publication 800-164 (draft)
Other Security Considerations 
 FDA guidance on cybersecurity for medical devices 
and networked hospital systems* 
 2014 Work Plan of the HHS Office of Inspector 
General states that OIG intends to review security 
controls implemented by hospitals for portable 
devices containing PHI and networked medical 
devices 
FDA Safety Communication: Cybersecurity for Medical Devices 
and Hospital Networks, June 13, 2013
Patient Safety 
 2011 Institute of Medicine report focused on how 
health information technology can itself contribute to 
medical errors, through poor usability of electronic 
health records, alert fatigue, and other factors* 
 HHS Office of the National Coordinator for HIT has 
developed numerous resources to help providers 
assess safety features of health information 
technology** 
*Institute of Medicine, Health IT and Patient Safety: Building Safer Systems 
for Better Care, 2011 
**http://www.healthit.gov/sites/default/files/safety_plan_master.pdf
FDASIA 
 2012 Food and Drug Administration Safety and Innovation 
Act required the FDA, ONC and FCC to issue a report on 
development of an “appropriate risk-based regulatory 
framework pertaining to health information technology, 
that promotes innovation, protects patient safety, and 
avoids regulatory duplication” 
 FDASIA Health IT Report* recommends that assessment of 
risk and needed controls should focus on HIT functionality, 
not on the platform (mobile, cloud, etc.) on which the 
functionality resides 
FDASIA Health IT Report: Proposed Strategy and Recommendations for a 
Risk-Based Framework, April 2014
FDA Guidance 
on Mobile Medical Apps 
 FDA guidance states that the FDA intends to regulate 
only those mobile apps that meet the definition of a 
medical device under the Food, Drug and Cosmetic 
Act, or that is intended to be used as an accessory to 
a medical device or to transform a mobile platform 
into a medical device 
 Since apps that are not mobile medical apps will not 
have FDA review, providers considering us of the app 
should conduct their own review of the app’s 
effectiveness
Role of the FCC 
 The Federal Communications Commission has 
expanded access to radio frequency spectrum for 
wireless medical communications 
 Wireless Medical Telemetry Service 
 MedRadio Service 
 Medical Micro-Power Networks 
 Medical Body Area Networks 
 Focus of FCC regulation is avoiding interference 
among users of wireless spectrum

More Related Content

What's hot

2016 PLCT PPT - PRODUCT MALFUNCTION THEORY WHEN “SMART” PRODUCTS ACT DUMB
2016 PLCT PPT - PRODUCT MALFUNCTION THEORY WHEN “SMART” PRODUCTS ACT DUMB2016 PLCT PPT - PRODUCT MALFUNCTION THEORY WHEN “SMART” PRODUCTS ACT DUMB
2016 PLCT PPT - PRODUCT MALFUNCTION THEORY WHEN “SMART” PRODUCTS ACT DUMB
Rob Smith
 
Introducing the mHealth Platform as a Service
Introducing the mHealth Platform as a ServiceIntroducing the mHealth Platform as a Service
Introducing the mHealth Platform as a Service
kidozen
 
Immunization Registry Stakeholders Meeting 2013 02-04 - cothren
Immunization Registry Stakeholders Meeting 2013 02-04 - cothrenImmunization Registry Stakeholders Meeting 2013 02-04 - cothren
Immunization Registry Stakeholders Meeting 2013 02-04 - cothren
CHeQ-IPHI
 

What's hot (20)

2016 PLCT PPT - PRODUCT MALFUNCTION THEORY WHEN “SMART” PRODUCTS ACT DUMB
2016 PLCT PPT - PRODUCT MALFUNCTION THEORY WHEN “SMART” PRODUCTS ACT DUMB2016 PLCT PPT - PRODUCT MALFUNCTION THEORY WHEN “SMART” PRODUCTS ACT DUMB
2016 PLCT PPT - PRODUCT MALFUNCTION THEORY WHEN “SMART” PRODUCTS ACT DUMB
 
Telemedicine software platform for hospitals & healthcare providers an ul...
Telemedicine software platform for hospitals & healthcare providers an ul...Telemedicine software platform for hospitals & healthcare providers an ul...
Telemedicine software platform for hospitals & healthcare providers an ul...
 
Wearable Tech Medical Devices
Wearable Tech Medical DevicesWearable Tech Medical Devices
Wearable Tech Medical Devices
 
Introducing the mHealth Platform as a Service
Introducing the mHealth Platform as a ServiceIntroducing the mHealth Platform as a Service
Introducing the mHealth Platform as a Service
 
Wireless Medical Devices
Wireless Medical DevicesWireless Medical Devices
Wireless Medical Devices
 
Immunization Registry Stakeholders Meeting 2013 02-04 - cothren
Immunization Registry Stakeholders Meeting 2013 02-04 - cothrenImmunization Registry Stakeholders Meeting 2013 02-04 - cothren
Immunization Registry Stakeholders Meeting 2013 02-04 - cothren
 
eHealth and mhealth presentation
eHealth and mhealth presentationeHealth and mhealth presentation
eHealth and mhealth presentation
 
IM2459 Mobile Device Policy
IM2459 Mobile Device Policy IM2459 Mobile Device Policy
IM2459 Mobile Device Policy
 
Federated architecture
Federated architectureFederated architecture
Federated architecture
 
eHealth - Medical Systems Interoperability & Mobile Health
eHealth - Medical Systems Interoperability & Mobile HealtheHealth - Medical Systems Interoperability & Mobile Health
eHealth - Medical Systems Interoperability & Mobile Health
 
Challenges and Opportunities Around Integration of Clinical Trials Data
Challenges and Opportunities Around Integration of Clinical Trials DataChallenges and Opportunities Around Integration of Clinical Trials Data
Challenges and Opportunities Around Integration of Clinical Trials Data
 
Responding To The Opportunity
Responding To The OpportunityResponding To The Opportunity
Responding To The Opportunity
 
Healthcare industry
Healthcare industryHealthcare industry
Healthcare industry
 
Healthcare Assets Management Solution
Healthcare Assets Management SolutionHealthcare Assets Management Solution
Healthcare Assets Management Solution
 
Improving Efficiency and Outcomes in Healthcare using Internet of Things
Improving Efficiency and Outcomes in Healthcare using Internet of ThingsImproving Efficiency and Outcomes in Healthcare using Internet of Things
Improving Efficiency and Outcomes in Healthcare using Internet of Things
 
HIPAA Compliance For Small Practices
HIPAA Compliance For Small PracticesHIPAA Compliance For Small Practices
HIPAA Compliance For Small Practices
 
Io t in healthcare 03.2016
Io t in healthcare 03.2016Io t in healthcare 03.2016
Io t in healthcare 03.2016
 
Cybersecurity for medical devices in the EU
Cybersecurity for medical devices in the EUCybersecurity for medical devices in the EU
Cybersecurity for medical devices in the EU
 
An Effective Security Mechanism for M-Commerce Applications Exploiting Ontolo...
An Effective Security Mechanism for M-Commerce Applications Exploiting Ontolo...An Effective Security Mechanism for M-Commerce Applications Exploiting Ontolo...
An Effective Security Mechanism for M-Commerce Applications Exploiting Ontolo...
 
Byod - IWEEE2013
Byod - IWEEE2013Byod - IWEEE2013
Byod - IWEEE2013
 

Similar to Protecting Privacy, Security and Patient Safety in mHealth

MMHA 6600 WU Technology and The Future in Healthcare Discussion.docx
MMHA 6600 WU Technology and The Future in Healthcare Discussion.docxMMHA 6600 WU Technology and The Future in Healthcare Discussion.docx
MMHA 6600 WU Technology and The Future in Healthcare Discussion.docx
4934bk
 
pillphone: enterprise mobile application for medical compliance and patient e...
pillphone: enterprise mobile application for medical compliance and patient e...pillphone: enterprise mobile application for medical compliance and patient e...
pillphone: enterprise mobile application for medical compliance and patient e...
Violet Le, MBA MIS
 
Safeguarding_Innovations
Safeguarding_InnovationsSafeguarding_Innovations
Safeguarding_Innovations
PJ Fitzpatrick
 
The fda and byod mobile and fixed medical device cybersecurity[1]
The fda and byod mobile and fixed medical device cybersecurity[1]The fda and byod mobile and fixed medical device cybersecurity[1]
The fda and byod mobile and fixed medical device cybersecurity[1]
Pam Gilmore
 
Mobile monday mhealth
Mobile monday mhealthMobile monday mhealth
Mobile monday mhealth
Joe Drumgoole
 
Connecting Patient Monitoring Devices to EHRsAn electronic health .pdf
Connecting Patient Monitoring Devices to EHRsAn electronic health .pdfConnecting Patient Monitoring Devices to EHRsAn electronic health .pdf
Connecting Patient Monitoring Devices to EHRsAn electronic health .pdf
eyebolloptics
 
Assuring regulatory compliance, ePHI protection, and secure healthcare delivery
Assuring regulatory compliance, ePHI protection, and secure healthcare deliveryAssuring regulatory compliance, ePHI protection, and secure healthcare delivery
Assuring regulatory compliance, ePHI protection, and secure healthcare delivery
Trend Micro
 

Similar to Protecting Privacy, Security and Patient Safety in mHealth (20)

Understanding Cybersecurity in Medical Devices and Applications
Understanding Cybersecurity in Medical Devices and ApplicationsUnderstanding Cybersecurity in Medical Devices and Applications
Understanding Cybersecurity in Medical Devices and Applications
 
MMHA 6600 WU Technology and The Future in Healthcare Discussion.docx
MMHA 6600 WU Technology and The Future in Healthcare Discussion.docxMMHA 6600 WU Technology and The Future in Healthcare Discussion.docx
MMHA 6600 WU Technology and The Future in Healthcare Discussion.docx
 
MobileSecurity WhitePaper
MobileSecurity WhitePaperMobileSecurity WhitePaper
MobileSecurity WhitePaper
 
pillphone: enterprise mobile application for medical compliance and patient e...
pillphone: enterprise mobile application for medical compliance and patient e...pillphone: enterprise mobile application for medical compliance and patient e...
pillphone: enterprise mobile application for medical compliance and patient e...
 
Roadmap to Healthcare HIPAA Compliance and Mobile Security for BYOD
Roadmap to Healthcare HIPAA Compliance and Mobile Security for BYODRoadmap to Healthcare HIPAA Compliance and Mobile Security for BYOD
Roadmap to Healthcare HIPAA Compliance and Mobile Security for BYOD
 
Safeguarding_Innovations
Safeguarding_InnovationsSafeguarding_Innovations
Safeguarding_Innovations
 
The FDA and BYOD, Mobile and Fixed Medical Device Cybersecurity
The FDA and BYOD, Mobile and Fixed Medical Device CybersecurityThe FDA and BYOD, Mobile and Fixed Medical Device Cybersecurity
The FDA and BYOD, Mobile and Fixed Medical Device Cybersecurity
 
The fda and byod mobile and fixed medical device cybersecurity[1]
The fda and byod mobile and fixed medical device cybersecurity[1]The fda and byod mobile and fixed medical device cybersecurity[1]
The fda and byod mobile and fixed medical device cybersecurity[1]
 
Breakout Session: Cybersecurity in Medical Devices
Breakout Session: Cybersecurity in Medical DevicesBreakout Session: Cybersecurity in Medical Devices
Breakout Session: Cybersecurity in Medical Devices
 
Dov Greenbaum, "Avoiding Regulation in the Medical Internet of Things"
Dov Greenbaum, "Avoiding Regulation in the Medical Internet of Things"Dov Greenbaum, "Avoiding Regulation in the Medical Internet of Things"
Dov Greenbaum, "Avoiding Regulation in the Medical Internet of Things"
 
Securing Mobile Healthcare Application
Securing Mobile Healthcare ApplicationSecuring Mobile Healthcare Application
Securing Mobile Healthcare Application
 
HP Whitepaper BYOD in Healthcare
 HP Whitepaper BYOD in Healthcare  HP Whitepaper BYOD in Healthcare
HP Whitepaper BYOD in Healthcare
 
Cybersecurity in Medical Devices
Cybersecurity in Medical DevicesCybersecurity in Medical Devices
Cybersecurity in Medical Devices
 
Mobile Privacy & Personal Health Information
Mobile Privacy & Personal Health InformationMobile Privacy & Personal Health Information
Mobile Privacy & Personal Health Information
 
Mobile monday mhealth
Mobile monday mhealthMobile monday mhealth
Mobile monday mhealth
 
Scary acronyms
Scary acronymsScary acronyms
Scary acronyms
 
Connecting Patient Monitoring Devices to EHRsAn electronic health .pdf
Connecting Patient Monitoring Devices to EHRsAn electronic health .pdfConnecting Patient Monitoring Devices to EHRsAn electronic health .pdf
Connecting Patient Monitoring Devices to EHRsAn electronic health .pdf
 
How to Secure Your Medical Devices
How to Secure Your Medical DevicesHow to Secure Your Medical Devices
How to Secure Your Medical Devices
 
Assuring regulatory compliance, ePHI protection, and secure healthcare delivery
Assuring regulatory compliance, ePHI protection, and secure healthcare deliveryAssuring regulatory compliance, ePHI protection, and secure healthcare delivery
Assuring regulatory compliance, ePHI protection, and secure healthcare delivery
 
Medical Device Cybersecurity : A Regulatory Perspective
Medical Device Cybersecurity : A Regulatory PerspectiveMedical Device Cybersecurity : A Regulatory Perspective
Medical Device Cybersecurity : A Regulatory Perspective
 

More from TAOklahoma

More from TAOklahoma (7)

Oklahoma Universal Service Fund for Telehealth
Oklahoma Universal Service Fund for TelehealthOklahoma Universal Service Fund for Telehealth
Oklahoma Universal Service Fund for Telehealth
 
Albert 2 oklahoma telemedicine
Albert 2 oklahoma telemedicineAlbert 2 oklahoma telemedicine
Albert 2 oklahoma telemedicine
 
Telemedicine Reimbursement: Medicaid and Private Payers
Telemedicine Reimbursement: Medicaid and Private PayersTelemedicine Reimbursement: Medicaid and Private Payers
Telemedicine Reimbursement: Medicaid and Private Payers
 
Telemedicine Credentialing and Privileging
Telemedicine Credentialing and PrivilegingTelemedicine Credentialing and Privileging
Telemedicine Credentialing and Privileging
 
Neonatologists and Rural Providers Collaborate to Provide Neonatal Care in a ...
Neonatologists and Rural Providers Collaborate to Provide Neonatal Care in a ...Neonatologists and Rural Providers Collaborate to Provide Neonatal Care in a ...
Neonatologists and Rural Providers Collaborate to Provide Neonatal Care in a ...
 
The Role of Retail Clinics in Today’s Healthcare System
The Role of Retail Clinics in Today’s Healthcare SystemThe Role of Retail Clinics in Today’s Healthcare System
The Role of Retail Clinics in Today’s Healthcare System
 
Accessing Diabetes Education Through Telehealth
Accessing Diabetes Education Through TelehealthAccessing Diabetes Education Through Telehealth
Accessing Diabetes Education Through Telehealth
 

Recently uploaded

VIP Call Girl Sector 10 Noida Call Me: 9711199171
VIP Call Girl Sector 10 Noida Call Me: 9711199171VIP Call Girl Sector 10 Noida Call Me: 9711199171
VIP Call Girl Sector 10 Noida Call Me: 9711199171
Call Girls Service Gurgaon
 
Muzaffarpur Call Girls 👙 6297143586 👙 Genuine WhatsApp Number for Real Meet
Muzaffarpur Call Girls 👙 6297143586 👙 Genuine WhatsApp Number for Real MeetMuzaffarpur Call Girls 👙 6297143586 👙 Genuine WhatsApp Number for Real Meet
Muzaffarpur Call Girls 👙 6297143586 👙 Genuine WhatsApp Number for Real Meet
Call Girls Service
 
Call Girls Service Anantapur 📲 6297143586 Book Now VIP Call Girls in Anantapur
Call Girls Service Anantapur 📲 6297143586 Book Now VIP Call Girls in AnantapurCall Girls Service Anantapur 📲 6297143586 Book Now VIP Call Girls in Anantapur
Call Girls Service Anantapur 📲 6297143586 Book Now VIP Call Girls in Anantapur
gragmanisha42
 
VIP Call Girls Noida Sia 9711199171 High Class Call Girl Near Me
VIP Call Girls Noida Sia 9711199171 High Class Call Girl Near MeVIP Call Girls Noida Sia 9711199171 High Class Call Girl Near Me
VIP Call Girls Noida Sia 9711199171 High Class Call Girl Near Me
mriyagarg453
 
Ernakulam Call Girls 👙 6297143586 👙 Genuine WhatsApp Number for Real Meet
Ernakulam Call Girls 👙 6297143586 👙 Genuine WhatsApp Number for Real MeetErnakulam Call Girls 👙 6297143586 👙 Genuine WhatsApp Number for Real Meet
Ernakulam Call Girls 👙 6297143586 👙 Genuine WhatsApp Number for Real Meet
Call Girls Chandigarh
 
Punjab❤️Call girls in Mohali ☎️7435815124☎️ Call Girl service in Mohali☎️ Moh...
Punjab❤️Call girls in Mohali ☎️7435815124☎️ Call Girl service in Mohali☎️ Moh...Punjab❤️Call girls in Mohali ☎️7435815124☎️ Call Girl service in Mohali☎️ Moh...
Punjab❤️Call girls in Mohali ☎️7435815124☎️ Call Girl service in Mohali☎️ Moh...
Sheetaleventcompany
 
Call Girl In Zirakpur ❤️♀️@ 9988299661 Zirakpur Call Girls Near Me ❤️♀️@ Sexy...
Call Girl In Zirakpur ❤️♀️@ 9988299661 Zirakpur Call Girls Near Me ❤️♀️@ Sexy...Call Girl In Zirakpur ❤️♀️@ 9988299661 Zirakpur Call Girls Near Me ❤️♀️@ Sexy...
Call Girl In Zirakpur ❤️♀️@ 9988299661 Zirakpur Call Girls Near Me ❤️♀️@ Sexy...
Sheetaleventcompany
 
Ozhukarai Call Girls 👙 6297143586 👙 Genuine WhatsApp Number for Real Meet
Ozhukarai Call Girls 👙 6297143586 👙 Genuine WhatsApp Number for Real MeetOzhukarai Call Girls 👙 6297143586 👙 Genuine WhatsApp Number for Real Meet
Ozhukarai Call Girls 👙 6297143586 👙 Genuine WhatsApp Number for Real Meet
Call Girls Service
 
Russian Call Girls in Noida Pallavi 9711199171 High Class Call Girl Near Me
Russian Call Girls in Noida Pallavi 9711199171 High Class Call Girl Near MeRussian Call Girls in Noida Pallavi 9711199171 High Class Call Girl Near Me
Russian Call Girls in Noida Pallavi 9711199171 High Class Call Girl Near Me
mriyagarg453
 
VIP Call Girl Sector 32 Noida Just Book Me 9711199171
VIP Call Girl Sector 32 Noida Just Book Me 9711199171VIP Call Girl Sector 32 Noida Just Book Me 9711199171
VIP Call Girl Sector 32 Noida Just Book Me 9711199171
Call Girls Service Gurgaon
 
VIP Call Girls Noida Jhanvi 9711199171 Best VIP Call Girls Near Me
VIP Call Girls Noida Jhanvi 9711199171 Best VIP Call Girls Near MeVIP Call Girls Noida Jhanvi 9711199171 Best VIP Call Girls Near Me
VIP Call Girls Noida Jhanvi 9711199171 Best VIP Call Girls Near Me
mriyagarg453
 

Recently uploaded (20)

VIP Call Girl Sector 10 Noida Call Me: 9711199171
VIP Call Girl Sector 10 Noida Call Me: 9711199171VIP Call Girl Sector 10 Noida Call Me: 9711199171
VIP Call Girl Sector 10 Noida Call Me: 9711199171
 
Call Girls Hyderabad Just Call 9907093804 Top Class Call Girl Service Available
Call Girls Hyderabad Just Call 9907093804 Top Class Call Girl Service AvailableCall Girls Hyderabad Just Call 9907093804 Top Class Call Girl Service Available
Call Girls Hyderabad Just Call 9907093804 Top Class Call Girl Service Available
 
Muzaffarpur Call Girls 👙 6297143586 👙 Genuine WhatsApp Number for Real Meet
Muzaffarpur Call Girls 👙 6297143586 👙 Genuine WhatsApp Number for Real MeetMuzaffarpur Call Girls 👙 6297143586 👙 Genuine WhatsApp Number for Real Meet
Muzaffarpur Call Girls 👙 6297143586 👙 Genuine WhatsApp Number for Real Meet
 
❤️♀️@ Jaipur Call Girls ❤️♀️@ Jaispreet Call Girl Services in Jaipur QRYPCF ...
❤️♀️@ Jaipur Call Girls ❤️♀️@ Jaispreet Call Girl Services in Jaipur QRYPCF  ...❤️♀️@ Jaipur Call Girls ❤️♀️@ Jaispreet Call Girl Services in Jaipur QRYPCF  ...
❤️♀️@ Jaipur Call Girls ❤️♀️@ Jaispreet Call Girl Services in Jaipur QRYPCF ...
 
Call Girls Service Anantapur 📲 6297143586 Book Now VIP Call Girls in Anantapur
Call Girls Service Anantapur 📲 6297143586 Book Now VIP Call Girls in AnantapurCall Girls Service Anantapur 📲 6297143586 Book Now VIP Call Girls in Anantapur
Call Girls Service Anantapur 📲 6297143586 Book Now VIP Call Girls in Anantapur
 
VIP Call Girls Noida Sia 9711199171 High Class Call Girl Near Me
VIP Call Girls Noida Sia 9711199171 High Class Call Girl Near MeVIP Call Girls Noida Sia 9711199171 High Class Call Girl Near Me
VIP Call Girls Noida Sia 9711199171 High Class Call Girl Near Me
 
Call Girl Raipur 📲 9999965857 ヅ10k NiGhT Call Girls In Raipur
Call Girl Raipur 📲 9999965857 ヅ10k NiGhT Call Girls In RaipurCall Girl Raipur 📲 9999965857 ヅ10k NiGhT Call Girls In Raipur
Call Girl Raipur 📲 9999965857 ヅ10k NiGhT Call Girls In Raipur
 
Ernakulam Call Girls 👙 6297143586 👙 Genuine WhatsApp Number for Real Meet
Ernakulam Call Girls 👙 6297143586 👙 Genuine WhatsApp Number for Real MeetErnakulam Call Girls 👙 6297143586 👙 Genuine WhatsApp Number for Real Meet
Ernakulam Call Girls 👙 6297143586 👙 Genuine WhatsApp Number for Real Meet
 
(Sonam Bajaj) Call Girl in Jaipur- 09257276172 Escorts Service 50% Off with C...
(Sonam Bajaj) Call Girl in Jaipur- 09257276172 Escorts Service 50% Off with C...(Sonam Bajaj) Call Girl in Jaipur- 09257276172 Escorts Service 50% Off with C...
(Sonam Bajaj) Call Girl in Jaipur- 09257276172 Escorts Service 50% Off with C...
 
Punjab❤️Call girls in Mohali ☎️7435815124☎️ Call Girl service in Mohali☎️ Moh...
Punjab❤️Call girls in Mohali ☎️7435815124☎️ Call Girl service in Mohali☎️ Moh...Punjab❤️Call girls in Mohali ☎️7435815124☎️ Call Girl service in Mohali☎️ Moh...
Punjab❤️Call girls in Mohali ☎️7435815124☎️ Call Girl service in Mohali☎️ Moh...
 
Call Girl In Zirakpur ❤️♀️@ 9988299661 Zirakpur Call Girls Near Me ❤️♀️@ Sexy...
Call Girl In Zirakpur ❤️♀️@ 9988299661 Zirakpur Call Girls Near Me ❤️♀️@ Sexy...Call Girl In Zirakpur ❤️♀️@ 9988299661 Zirakpur Call Girls Near Me ❤️♀️@ Sexy...
Call Girl In Zirakpur ❤️♀️@ 9988299661 Zirakpur Call Girls Near Me ❤️♀️@ Sexy...
 
Jaipur Call Girls 9257276172 Call Girl in Jaipur Rajasthan
Jaipur Call Girls 9257276172 Call Girl in Jaipur RajasthanJaipur Call Girls 9257276172 Call Girl in Jaipur Rajasthan
Jaipur Call Girls 9257276172 Call Girl in Jaipur Rajasthan
 
Ozhukarai Call Girls 👙 6297143586 👙 Genuine WhatsApp Number for Real Meet
Ozhukarai Call Girls 👙 6297143586 👙 Genuine WhatsApp Number for Real MeetOzhukarai Call Girls 👙 6297143586 👙 Genuine WhatsApp Number for Real Meet
Ozhukarai Call Girls 👙 6297143586 👙 Genuine WhatsApp Number for Real Meet
 
Krishnagiri call girls Tamil aunty 7877702510
Krishnagiri call girls Tamil aunty 7877702510Krishnagiri call girls Tamil aunty 7877702510
Krishnagiri call girls Tamil aunty 7877702510
 
Russian Call Girls in Noida Pallavi 9711199171 High Class Call Girl Near Me
Russian Call Girls in Noida Pallavi 9711199171 High Class Call Girl Near MeRussian Call Girls in Noida Pallavi 9711199171 High Class Call Girl Near Me
Russian Call Girls in Noida Pallavi 9711199171 High Class Call Girl Near Me
 
VIP Call Girl Sector 32 Noida Just Book Me 9711199171
VIP Call Girl Sector 32 Noida Just Book Me 9711199171VIP Call Girl Sector 32 Noida Just Book Me 9711199171
VIP Call Girl Sector 32 Noida Just Book Me 9711199171
 
VIP Call Girls Noida Jhanvi 9711199171 Best VIP Call Girls Near Me
VIP Call Girls Noida Jhanvi 9711199171 Best VIP Call Girls Near MeVIP Call Girls Noida Jhanvi 9711199171 Best VIP Call Girls Near Me
VIP Call Girls Noida Jhanvi 9711199171 Best VIP Call Girls Near Me
 
❤️Call girls in Jalandhar ☎️9876848877☎️ Call Girl service in Jalandhar☎️ Jal...
❤️Call girls in Jalandhar ☎️9876848877☎️ Call Girl service in Jalandhar☎️ Jal...❤️Call girls in Jalandhar ☎️9876848877☎️ Call Girl service in Jalandhar☎️ Jal...
❤️Call girls in Jalandhar ☎️9876848877☎️ Call Girl service in Jalandhar☎️ Jal...
 
❤️♀️@ Jaipur Call Girls ❤️♀️@ Meghna Jaipur Call Girls Number CRTHNR Call G...
❤️♀️@ Jaipur Call Girls ❤️♀️@ Meghna Jaipur Call Girls Number CRTHNR   Call G...❤️♀️@ Jaipur Call Girls ❤️♀️@ Meghna Jaipur Call Girls Number CRTHNR   Call G...
❤️♀️@ Jaipur Call Girls ❤️♀️@ Meghna Jaipur Call Girls Number CRTHNR Call G...
 
❤️♀️@ Jaipur Call Girl Agency ❤️♀️@ Manjeet Russian Call Girls Service in Jai...
❤️♀️@ Jaipur Call Girl Agency ❤️♀️@ Manjeet Russian Call Girls Service in Jai...❤️♀️@ Jaipur Call Girl Agency ❤️♀️@ Manjeet Russian Call Girls Service in Jai...
❤️♀️@ Jaipur Call Girl Agency ❤️♀️@ Manjeet Russian Call Girls Service in Jai...
 

Protecting Privacy, Security and Patient Safety in mHealth

  • 1. Protecting Privacy, Security and Patient Safety in mHealth Oklahoma Telemedicine Conference Telehealth Transition: Opportunity to Value Creation Patricia D. King, J.D., M.B.A.
  • 2. HIPAA Privacy and Breach Notification  Many reported breaches of unsecured PHI involve mobile devices  Examples: Massachusetts Eye & Ear Infirmary settled case for $1.5 million, agreed to adopt safeguards for mobile devices  OCR has developed compliance resources specifically for mobile devices*  Portability and ease of use of mobile devices create unique risks http://www.healthit.gov/providers-professionals/your-mobile-device- and-health-information-privacy-and-security
  • 3. HIPAA Security  HIPAA Security Rule requires covered entities to periodically review their security procedures when technology changes and introduces new risks  Access to EPHI on mobile devices is a significant operational change requiring providers to revisit their security policies and procedures  BYOD introduces additional vulnerabilities  ENCRYPTION, ENCRYPTION, ENCRYPTION!
  • 4. NIST Guidelines for Mitigating Risk of Mobile Devices*  Risk: theft or loss  Mitigation:  Encryption  Permitting access to EPHI but not storage  Device-based authentication  Network-based authentication  Risk: inherent vulnerabilities due to lack of root of trust features  Mitigation:  Centralized mobile device management technology  If BYOD is permitted, isolation of organization’s data and applications Guidelines for Managing the Security of Mobile Devices in the Enterprise, NIST Special Publication 800-124, Rev. 1
  • 5. NIST guidelines (cont’d)  Risk: “man in the middle” attacks on unsecure networks  Mitigation:  Use of virtual private network (VPN)  Risk: introduction of malware through apps  Mitigation:  Prohibiting installation of third-party apps unless “white-listed”  Prohibiting browser access or forcing through secure gateway
  • 6. Special Considerations for BYOD*  Advantages: user satisfaction, potential savings on device purchases  If BYOD is permitted, the user-owned device will have 2 information owners: the user for personal data, and the organization for EPHI and business processes.  If the organization’s data and apps are confined to a sandbox/secure container, then a remote wipe can be performed if the device is vulnerable without disrupting the owner’s data. Guidelines on Hardware-Rooted Security in Mobile Devices, NIST Special Publication 800-164 (draft)
  • 7. Other Security Considerations  FDA guidance on cybersecurity for medical devices and networked hospital systems*  2014 Work Plan of the HHS Office of Inspector General states that OIG intends to review security controls implemented by hospitals for portable devices containing PHI and networked medical devices FDA Safety Communication: Cybersecurity for Medical Devices and Hospital Networks, June 13, 2013
  • 8. Patient Safety  2011 Institute of Medicine report focused on how health information technology can itself contribute to medical errors, through poor usability of electronic health records, alert fatigue, and other factors*  HHS Office of the National Coordinator for HIT has developed numerous resources to help providers assess safety features of health information technology** *Institute of Medicine, Health IT and Patient Safety: Building Safer Systems for Better Care, 2011 **http://www.healthit.gov/sites/default/files/safety_plan_master.pdf
  • 9. FDASIA  2012 Food and Drug Administration Safety and Innovation Act required the FDA, ONC and FCC to issue a report on development of an “appropriate risk-based regulatory framework pertaining to health information technology, that promotes innovation, protects patient safety, and avoids regulatory duplication”  FDASIA Health IT Report* recommends that assessment of risk and needed controls should focus on HIT functionality, not on the platform (mobile, cloud, etc.) on which the functionality resides FDASIA Health IT Report: Proposed Strategy and Recommendations for a Risk-Based Framework, April 2014
  • 10. FDA Guidance on Mobile Medical Apps  FDA guidance states that the FDA intends to regulate only those mobile apps that meet the definition of a medical device under the Food, Drug and Cosmetic Act, or that is intended to be used as an accessory to a medical device or to transform a mobile platform into a medical device  Since apps that are not mobile medical apps will not have FDA review, providers considering us of the app should conduct their own review of the app’s effectiveness
  • 11. Role of the FCC  The Federal Communications Commission has expanded access to radio frequency spectrum for wireless medical communications  Wireless Medical Telemetry Service  MedRadio Service  Medical Micro-Power Networks  Medical Body Area Networks  Focus of FCC regulation is avoiding interference among users of wireless spectrum