Related Experiment Video
Updated: Jun 18, 2025

Setup of Consumer Wearable Devices for Exposure and Health Monitoring in Population Studies
Published on: February 3, 2023
A comparative study on HIPAA technical safeguards assessment of android mHealth applications
Md Raihan Mia1, Hossain Shahriar2, Maria Valero2
1Department of Computer Science at Marquette University, WI, USA.
Mobile Health (mHealth) apps must comply with HIPAA security rules. A new framework analyzes Android apps for HIPAA compliance, finding vulnerabilities in data access, encryption, and transmission, and offers developer recommendations.
Area of Science:
- Health Informatics
- Software Engineering
- Cybersecurity
Background:
- Mobile Health (mHealth) applications are increasingly used for health management, necessitating robust protection of personal health records (PHR).
- The Health Insurance Portability and Accountability Act (HIPAA) mandates specific security and privacy regulations for handling protected health information (PHI).
- Many mHealth app developers lack awareness of HIPAA compliance requirements, posing risks to sensitive user data.
Purpose of the Study:
- To develop an analytical framework for assessing mHealth app source code for HIPAA compliance.
- To identify common security vulnerabilities in mHealth applications related to HIPAA Technical Safeguards.
- To provide actionable recommendations for developers to create secure and HIPAA-compliant mHealth applications.
Main Methods:
- Proposed an Android source code analysis framework evaluating twelve HIPAA Technical Safeguards.
- Implemented meta-analysis and data-flow analysis algorithms to detect HIPAA violations and security risks.
- Developed a web-based tool for evaluating the framework's efficacy on 200 popular mHealth apps from the Google Play Store.
Main Results:
- Identified significant vulnerabilities in authorization for sensitive resource access, data encryption/decryption, and secure data transmission across investigated apps.
- The analysis revealed common mistakes made by developers in implementing security features.
- API-level checks for secure data communication between third-party apps and EHR systems were addressed.
Conclusions:
- The developed framework effectively identifies HIPAA compliance issues in mHealth apps.
- Recommendations are provided to developers to mitigate common security flaws and enhance app security.
- The framework can be extended into an IDE plugin for developers and a web interface for consumers.
Related Concept Videos
Standards of Care II
Ethical Standards I
The Code of Ethics provisions outline the nurse's duty to the patient, the healthcare team, the profession, and society. The Code's fundamental principles include advocacy,...
Legal Guidelines for Documentation
Issues And Trends In Healthcare Delivery System
Cost Containment
Payment for healthcare services has historically promoted adoption of costly and often unnecessary or inefficient...
Health Information Technology and Healthcare Information System
Health Information Technology, commonly called HIT, integrates advanced information systems and technology in healthcare settings. Its primary functions include:
Documentation in Long-Term and Home Healthcare Setting
Long-Term Care Facilities

