Data protection and information security of digital health applications (DiGA)

被引:2
|
作者
Zilch, Andre [1 ]
Tschirsich, Martin [1 ]
机构
[1] ZFT Co GmbH, Burgstr 2, D-65817 Eppstein, Germany
关键词
Protection needs; Requirements; Deficiencies; Recommendations; How-to;
D O I
10.1007/s00103-021-03412-y
中图分类号
R1 [预防医学、卫生学];
学科分类号
1004 ; 120402 ;
摘要
Ensuring data privacy and information security frequently poses a challenge for manufacturers of digital health applications (DiGA). This is often caused by a low level of maturity of the application development organization and a lack of expertise in the intersection between regulatory requirements and applied information security. As a result, critical mistakes are made during implementation, requirement analysis, and process design. These must be avoided. This paper presents the requirements and solutions derived from and in compliance with the General Data Protection Regulation, the state of the art, other regulations that must be taken into account, the Digital Healthcare Act (DVG), and the corresponding ordinance. In order to derive specific requirements according to the state of the art and considering the identified level of protection with regard to the fundamental objectives of information security, such as confidentiality, integrity and availability, reference is made to important standards and norms. In the spirit of a how-to for manufacturers, the authors then directly address the most important deficiencies regarding authentication, consent, and authorization and give appropriate recommendations. The authors see further support for manufacturers from the Federal Institute for Drugs and Medical Devices (BfArM), for example in the form of specific guidelines, as an important pillar in overcoming the gap between requirements and reality in matters of data protection and information security. At the same time, further maturation of the manufacturer's application development organization is required and expected. At the same time, with the replacement of the Medical Device Directive (MDD) with the Medical Device Regulation (MDR), information security gains more importance.
引用
收藏
页码:1254 / 1261
页数:8
相关论文
共 50 条
  • [1] Datenschutz und Informationssicherheit bei digitalen Gesundheitsanwendungen (DiGA)Data protection and information security of digital health applications (DiGA)
    André Zilch
    Martin Tschirsich
    Bundesgesundheitsblatt - Gesundheitsforschung - Gesundheitsschutz, 2021, 64 : 1254 - 1261
  • [2] Digital Health Applications (DiGA) as an innovative Component in digital Healthcare in Germany - Information, Experiences and Perspectives
    Lauer, Wolfgang
    Loebker, Wiebke
    Sudhop, Thomas
    Broich, Karl
    BUNDESGESUNDHEITSBLATT-GESUNDHEITSFORSCHUNG-GESUNDHEITSSCHUTZ, 2021, 64 (10) : 1195 - 1197
  • [3] Digital public health: data protection and data security
    Kunz, Thomas
    Lange, Benjamin
    Selzer, Annika
    BUNDESGESUNDHEITSBLATT-GESUNDHEITSFORSCHUNG-GESUNDHEITSSCHUTZ, 2020, 63 (02) : 206 - 214
  • [4] Digital Health Applications (DiGA) - Something for Urology too?
    Miller, Kurt
    AKTUELLE UROLOGIE, 2021, 52 (03) : 197 - 197
  • [5] Trends in Clinical Evidence for Digital Health Applications (DiGa) Reimbursed in the German DiGa Directory
    Costello, J.
    D'Souza, V
    Gildea, L.
    Kinderas, M.
    Ling, C.
    Belisario, Marcano J.
    Warttig, S.
    VALUE IN HEALTH, 2022, 25 (12) : S386 - S386
  • [6] Digital Health Applications and Data Protection (2022)
    Kirsten, N.
    Augustin, M.
    Stroemer, K.
    HAUTARZT, 2022, 73 (06): : 501 - 501
  • [7] Interoperability in healthcare: also prescribed for digital health applications (DiGA)
    Weber, Stefanie
    Heitmann, Kai U.
    BUNDESGESUNDHEITSBLATT-GESUNDHEITSFORSCHUNG-GESUNDHEITSSCHUTZ, 2021, 64 (10) : 1262 - 1268
  • [8] Practical use of digital health applications (DiGA) in internal medicine
    Mittermaier, Mirja
    Sina, Christian
    Richter, Jutta G.
    Raspe, Matthias
    Stais, Patrick
    Vehreschild, Jorg
    Wolfrum, Sebastian
    Anthes, Christina
    Mockel, Martin
    INTERNIST, 2022, 63 (03): : 245 - 254
  • [9] Evidence requirements of permanently listed digital health applications (DiGA) and their implementation in the German DiGA directory: an analysis
    Melanie Mäder
    Patrick Timpel
    Tonio Schönfelder
    Carsta Militzer-Horstmann
    Sandy Scheibe
    Ria Heinrich
    Dennis Häckl
    BMC Health Services Research, 23
  • [10] Evidence requirements of permanently listed digital health applications (DiGA) and their implementation in the German DiGA directory: an analysis
    Maeder, Melanie
    Timpel, Patrick
    Schoenfelder, Tonio
    Militzer-Horstmann, Carsta
    Scheibe, Sandy
    Heinrich, Ria
    Haeckl, Dennis
    BMC HEALTH SERVICES RESEARCH, 2023, 23 (01)