Skip to main content
QUICK REVIEW

[Paper Review] Mobile Technology in Healthcare Environment: Security Vulnerabilities and Countermeasures

Sajedul Talukder, Shalisha Witherspoon|arXiv (Cornell University)|Jul 29, 2018
Electronic Health Records Systems1 references4 citations
TL;DR

This paper evaluates security vulnerabilities in mobile healthcare applications, focusing on Epic Rover, and proposes a comprehensive risk mitigation framework aligned with HIPAA and NIST standards. It demonstrates that with proper technical, administrative, and physical safeguards, mobile adoption in healthcare can be secure and compliant, leading to improved clinical efficiency and reduced errors.

ABSTRACT

Mobile devices and technologies offer a tremendous amount of benefits to users, although it is also understood that it introduces a set of challenges when it comes to security, compliance, and risks. More and more healthcare organizations have been seeking to update their outdated technology, and have considered the adoption of mobile devices to meet these needs. However, introducing mobile devices and technology also introduces new risks and threats to the organization. As a test case, we examine Epic Rover, a mobile application that has been identified as a viable solution to manage the electronic medical system. In this paper, we study the insights that the security team needs to investigate, before the adoption of this mobile technology, as well as provide a thorough examination of the vulnerabilities and threats that the use of mobile devices in the healthcare environment brings, and introduce countermeasures and mitigations to reduce the risk while maintaining regulatory compliance.

Motivation & Objective

  • To assess security vulnerabilities and threats associated with mobile device adoption in healthcare environments.
  • To evaluate the feasibility and security posture of Epic Rover as a mobile solution for electronic patient health information (EPHI) access.
  • To identify and implement risk mitigation strategies aligned with HIPAA and NIST cybersecurity framework.
  • To conduct a qualitative risk assessment to determine whether mobile device adoption is justifiable for healthcare organizations.
  • To provide actionable recommendations for secure deployment, including BYOD and corporate-owned device models.

Proposed method

  • Conducted a threat and vulnerability analysis on Epic Rover, identifying 12 key threats and corresponding vulnerabilities.
  • Mapped administrative, physical, and technical safeguards from the HIPAA Security Rule to functions in the NIST Cybersecurity Framework.
  • Developed a qualitative risk assessment matrix (Table IV) to rate threat probability, impact, inherent risk, and residual risk.
  • Proposed technical controls such as end-to-end encryption, secure wireless access, and secure transmission protocols (e.g., HTTPS, S/MIME).
  • Implemented administrative controls including two-factor authentication, role-based access, and mandatory user training.
  • Recommended device-level protections such as remote wipe, full-disk encryption, and automatic OS/app updates.

Experimental results

Research questions

  • RQ1What are the primary security vulnerabilities and threats associated with using mobile devices like Epic Rover in healthcare settings?
  • RQ2How do existing regulatory standards (HIPAA) and industry frameworks (NIST CSF) align with mobile healthcare security needs?
  • RQ3What technical, administrative, and physical controls effectively reduce the risk of EPHI exposure in mobile environments?
  • RQ4What is the residual risk level after implementing recommended countermeasures, and is mobile adoption still justifiable?
  • RQ5How can organizations balance usability, efficiency, and security when deploying mobile health applications like Epic Rover?

Key findings

  • Epic Rover enables real-time access to patient data, including medical history, lab results, and vitals, improving clinical workflow and reducing documentation errors.
  • The study identified 12 significant threats, including unauthorized access, data leakage, and device loss, with high to medium risk levels.
  • Residual risk was reduced to acceptable levels through implementation of encryption, remote wipe, two-factor authentication, and secure network protocols.
  • The qualitative risk assessment matrix (Table IV) confirmed that with proper controls, the benefits of mobile adoption outweigh the risks.
  • Organizations can achieve HIPAA compliance and reduce attack surface by enforcing device encryption, access controls, and regular patching.
  • User training and awareness programs were identified as critical to mitigating human-related risks such as device loss and phishing.

Better researchstarts right now

From reading papers to final review, dramatically reduce your research time.

No credit card · Free plan available

This review was created by AI and reviewed by human editors.