Data protection and information security of digital health applications (DiGA)

被引:2
|
作者
Zilch, Andre [1 ]
Tschirsich, Martin [1 ]
机构
[1] ZFT Co GmbH, Burgstr 2, D-65817 Eppstein, Germany
关键词
Protection needs; Requirements; Deficiencies; Recommendations; How-to;
D O I
10.1007/s00103-021-03412-y
中图分类号
R1 [预防医学、卫生学];
学科分类号
1004 ; 120402 ;
摘要
Ensuring data privacy and information security frequently poses a challenge for manufacturers of digital health applications (DiGA). This is often caused by a low level of maturity of the application development organization and a lack of expertise in the intersection between regulatory requirements and applied information security. As a result, critical mistakes are made during implementation, requirement analysis, and process design. These must be avoided. This paper presents the requirements and solutions derived from and in compliance with the General Data Protection Regulation, the state of the art, other regulations that must be taken into account, the Digital Healthcare Act (DVG), and the corresponding ordinance. In order to derive specific requirements according to the state of the art and considering the identified level of protection with regard to the fundamental objectives of information security, such as confidentiality, integrity and availability, reference is made to important standards and norms. In the spirit of a how-to for manufacturers, the authors then directly address the most important deficiencies regarding authentication, consent, and authorization and give appropriate recommendations. The authors see further support for manufacturers from the Federal Institute for Drugs and Medical Devices (BfArM), for example in the form of specific guidelines, as an important pillar in overcoming the gap between requirements and reality in matters of data protection and information security. At the same time, further maturation of the manufacturer's application development organization is required and expected. At the same time, with the replacement of the Medical Device Directive (MDD) with the Medical Device Regulation (MDR), information security gains more importance.
引用
收藏
页码:1254 / 1261
页数:8
相关论文
共 50 条
  • [21] The protection of personal data and the security of information
    Ribagorda Garnacho, Arturo
    REVISTA JURIDICA DE CASTILLA Y LEON, 2008, (16): : 373 - 399
  • [22] Information security and protection of personal data
    Siskin, Dilan Serife
    TURKISH LIBRARIANSHIP, 2018, 32 (04) : 342 - 345
  • [23] Information security and data protection in medicine
    Darms, M.
    Hassfeld, S.
    Fedtke, S.
    MKG-CHIRURG, 2020, 13 (04): : 240 - 247
  • [24] Support for innovation at the BfArM-experiences from the consultations on digital health applications (DiGA)
    Loebker, Wiebke
    Boehmer, Anne Christin
    Hoefgen, Barbara
    BUNDESGESUNDHEITSBLATT-GESUNDHEITSFORSCHUNG-GESUNDHEITSSCHUTZ, 2021, 64 (10) : 1241 - 1248
  • [25] How robust are studies of currently permanently included digital health applications (DiGA)? Methodological quality of studies demonstrating positive health care effects of DiGA
    Kolominsky-Rabas, Peter L.
    Tauscher, Martin
    Gerlach, Roman
    Perleth, Matthias
    Dietzel, Nikolas
    ZEITSCHRIFT FUR EVIDENZ FORTBILDUNG UND QUALITAET IM GESUNDHEITSWESEN, 2022, 175 : 1 - 16
  • [26] Digital health applications (DiGA): assessment of reimbursability by means of the "DiGA Fast Track" procedure at the Federal Institute for Drugs and Medical Devices (BfArM)
    Lauer, Wolfgang
    Loebker, Wiebke
    Hoefgen, Barbara
    BUNDESGESUNDHEITSBLATT-GESUNDHEITSFORSCHUNG-GESUNDHEITSSCHUTZ, 2021, 64 (10) : 1232 - 1240
  • [27] Datenschutz und Datensicherheit in Digital Public HealthDigital public health: data protection and data security
    Thomas Kunz
    Benjamin Lange
    Annika Selzer
    Bundesgesundheitsblatt - Gesundheitsforschung - Gesundheitsschutz, 2020, 63 (2) : 206 - 214
  • [28] Digital health applications and date protection
    Kirsten, N.
    Augustin, M.
    Stroemer, K.
    HAUTARZT, 2022, 73 (05): : 391 - 395
  • [29] Implementation of a digital nurse to improve the use of digital health applications (DiGA) for older people with depressive disorders (DiGA4Aged): a randomized proof of concept study
    Anna Mai
    Magdalena Pape
    Theresa Sophie Busse
    Katharina Kunde
    Jennifer Bosompem
    Chantal Giehl
    Ina Carola Otte
    Stephan Herpertz
    Georg Juckel
    Ida Haussleiter
    Rainer Wirth
    Horst Christian Vollmar
    Nina Timmesfeld
    Jan Dieris-Hirche
    Trials, 26 (1)
  • [30] Integration of digital health applications into the German healthcare system: development of "The DiGA-Care Path"
    Giebel, G. D.
    Abels, C.
    Boerchers, K.
    Kampka, B.
    Neusser, S.
    Cissarek, H. R.
    Plescher, F.
    Wasem, J.
    Blase, N.
    FRONTIERS IN HEALTH SERVICES, 2024, 4