开发者

Should HIPAA complinace not allow offline storage in Mobile Native Applications? [closed]

开发者 https://www.devze.com 2023-03-21 23:03 出处:网络
Closed. This question is off-topic. It is not currently accepting answers. 开发者_C百科 Want to improve this question? Update the question so it's on-topic for Stack Overflow.
Closed. This question is off-topic. It is not currently accepting answers. 开发者_C百科

Want to improve this question? Update the question so it's on-topic for Stack Overflow.

Closed 11 years ago.

Improve this question

Should HIPAA complinace not allow offline storage in Mobile Native Applications??I dont know if already there is this sort of regulation in HIPAA. I assume there is no such thing.

If you feel this question need not be asked in this forum, I request you to completely read this and suggest a programmatic solution for this problem.

Main reason why this came up was that all of the security considerations regarding the Mobile development may be specifically in iOS seems to have been hacked in to once a device is jailbroken or rooted.

I came to know that hardware encryption is hacked.

http://anthonyvance.com/blog/forensics/iphone_encryption/

Then there are questions on iOS 4's encryption techniques.

People claim, Key chain access in iOS can be compromised if the phone is rooted.

Only thing I think which has not met with any skepticism is the sqlCipher.

If you could find any flaws with SqlCipher , please share it.

And I think that, until people find a theft-proof way to manage offline data in Mobile Phones, people can refrain from making offline features for EMR apps where HIPAA compliance is mandatory.

It can be argued that, any system can be hacked when people are desperate to hack it. But I feel Mobile devices can be an easy target. You can lose it as you lose your Handkerchief.

Please share your views.


I agree with bshirley. Your surface of vulnerability is much greater if you are storing many records about many people on the device. But if you are only storing limited info about one person temporarily - as when conducting a query for prescription info or gathering information about a current health problem - then the risk is much lower. Of course you also need to consider whether the hacked phone presents a security risk to the online data, that is, does the app on the phone enable a wrong user to access protected data online?

Here's an application note you may find helpful: "Formotus™ Mobile Solutions and HIPAA Compliance"

0

精彩评论

暂无评论...
验证码 换一张
取 消

关注公众号