Related Experiment Video
Updated: Jan 16, 2026

Hydra, a Computer-Based Platform for Aiding Clinicians in Cardiovascular Analysis and Diagnosis
Published on: September 26, 2018
Web Application Security in Digital Health: A Dual Analysis and a Context-Aware OWASP-Based Tool Proposal
Ylenia Murgia1, Jaime Delgado2, Mauro Giacomini1
1Department of Informatics, Bioengineering, Robotics and System Engineering (DIBRIS), University of Genoa, Genoa, Italy.
Digital Health (DH) cybersecurity risks are rising. This study found a gap in applying Open Web Application Security Project (OWASP) guidelines in healthcare, proposing a tool to bridge this gap for better security.
Area of Science:
- Cybersecurity in healthcare
- Digital Health (DH) technologies
- Application security standards
Background:
- Rapid adoption of digital technologies in healthcare increases cybersecurity risks.
- Web applications in healthcare handle sensitive data, necessitating robust security measures.
- Regulatory compliance and data breach prevention are critical concerns.
Purpose of the Study:
- To investigate the applicability of Open Web Application Security Project (OWASP) guidelines in the healthcare domain.
- To identify common security requirements in Digital Health (DH) technologies and their alignment with OWASP Application Security Verification Standard (ASVS).
- To address the gap between security standards availability and their practical implementation in healthcare IT.
Main Methods:
- Literature review to identify DH security requirements and assess alignment with OWASP ASVS.
- Questionnaire survey distributed to Italian healthcare facilities and IT companies.
- Analysis of survey responses to identify knowledge and usage gaps of security standards.
Main Results:
- Common security requirements in DH technologies were identified and mapped against OWASP ASVS.
- A significant gap was observed between the availability of security standards and their practical application in the healthcare sector.
- Healthcare IT professionals and developers show limited awareness and utilization of existing security guidelines.
Conclusions:
- OWASP guidelines are relevant but underutilized in the healthcare sector.
- A context-aware tool is proposed to guide developers and testers in applying OWASP standards effectively.
- The tool aims to facilitate practical adoption of security best practices in clinical environments through tailored recommendations and checklists.
Related Concept Videos
Healthcare Associated Infections II: Preventive Measures
The best practices for preventing healthcare-associated infections include hand hygiene, patient risk...
Guidelines and Strategies for Safe Computer Charting
Maintain Confidentiality and Security:
Health Information Technology and Healthcare Information System
Health Information Technology, commonly called HIT, integrates advanced information systems and technology in healthcare settings. Its primary functions include:
Defense Mechanism Against Infection
In addition, many body organ systems have unique defenses against infection. The skin is an intact, multilayered surface preventing invasion by microorganisms unless impaired. Mucous membranes lining the mouth, nose, and eyelids are barriers...
Issues And Trends In Healthcare Delivery System
Cost Containment
Payment for healthcare services has historically promoted adoption of costly and often unnecessary or inefficient...
Ethical Standards I
The Code of Ethics provisions outline the nurse's duty to the patient, the healthcare team, the profession, and society. The Code's fundamental principles include advocacy,...

