Federal grant · project grant (b)
A Framework for Mhealth App Security and Privacy Analysis - Abstract: With the Increased Use of Mobile Health Apps to Improve Health Outcomes, Protecting Private Health Data Is Becoming Increasingly Important. Researchers Estimate There Are Over 300,000 Mhealth Apps in Existence, and Some Relate to Hipaa Covered Entities or Their Business Associates. With Patients’ Increasing Desire for Data Accessibility and App Data Sharing, It Is Critical to Ensure That Patients Transmit Their Protected Health Information (PHI) to Apps That Are Compliant With Hipaa Privacy and Security Rules. About 25% of Healthcare Providers Suffer From Data Breaches Violating Hipaa Policies, Caused by Using Mobile Devices That Come Preloaded With Mhealth Apps. This Results in Lawsuits, and Loss of Confidence Among Health Providers and Patients. Earlier Research Has Focused on Security of Mobile Devices, But Not Checking Further How Apps Store or Transfer Data Securely Before Being Used by Remote Health Care Providers or Users. Most Mobile App Developers Including Mhealth Apps Are Not Aware of Hipaa Security and Privacy Regulations. This Creates the Market Opportunity to Develop Static and Dynamic Code Analysis Tools for Mhealth App Developers, So Their Developed Products Meet Hipaa Security and Privacy Guidelines. Currently, There Is a Lack of an Analysis Framework to Check Mhealth Apps’ Security and Privacy Risks Following the Applicable Hipaa Technical Security and Privacy Guidelines. We Propose to Develop a Framework to Analyze Mhealth Apps for Hipaa Security and Privacy Compliance. the Framework Will Allow Users Who Have No Knowledge of Hipaa or App Security to Receive an Assessment of Security and Privacy Risks Per Hipaa Guidelines. Initially Based on Android Studio, the Tool Will Test the Source Code of Mhealth Applications for Potential Data Security Breaches Related to Hipaa Before Posting for the Marketplace. the Tool Will Further Address Api Level Checking for Secure Data Communication Mandated by Recent CMS Guidelines Between Third Party Mobile Health Apps and Ehr Systems. the Analysis Framework Will Also Address Heterogeneous Health Data and Enable Providers to Remain Compliant With Hipaa Administrative and Operational Guidelines. We Propose to Perform Two Acceptance Tests on the Prototype Based on Partnering With Hipaa Experts and Medical Doctors and For-profit Ehr Vendors Along With the Effectiveness of Tools for Detecting Health Data Security Breaches. the Proposed Tool Will Further Enable the Development of Data Breach Checking for Ios Mhealth Apps and Adoption and Integration by Large Scale Ehr Vendors in the Future.
Committed
$256,079
Paid out
$254.7K
99%
Committed, not yet paid
$1.4K
<1%
Loading…
Everything here is this single award's whole record — signed, amended, paid — not a fiscal-year slice. The by-year charts elsewhere split an award across the years it was committed; this page keeps it whole.
Committed is what the government has legally promised on this award so far. Contracts can also carry a ceiling — the maximum if every option is exercised. Unspent ceiling is headroom, not money owed.
The cash actually disbursed against this award. The gap from committed is the disbursement pipeline: promised, not yet cashed.
Each transaction is a signing event — an action that created or changed the award, dated the day it was signed — not a payment. Negative amounts are real: money de-committed at closeout or renegotiation.
One bar, the award’s whole arithmetic: paid out, then committed, not yet paid, then unspent ceiling.