Data protection and information security of digital health applications (DiGA)

被引:2
|
作者
Zilch, Andre [1 ]
Tschirsich, Martin [1 ]
机构
[1] ZFT Co GmbH, Burgstr 2, D-65817 Eppstein, Germany
关键词
Protection needs; Requirements; Deficiencies; Recommendations; How-to;
D O I
10.1007/s00103-021-03412-y
中图分类号
R1 [预防医学、卫生学];
学科分类号
1004 ; 120402 ;
摘要
Ensuring data privacy and information security frequently poses a challenge for manufacturers of digital health applications (DiGA). This is often caused by a low level of maturity of the application development organization and a lack of expertise in the intersection between regulatory requirements and applied information security. As a result, critical mistakes are made during implementation, requirement analysis, and process design. These must be avoided. This paper presents the requirements and solutions derived from and in compliance with the General Data Protection Regulation, the state of the art, other regulations that must be taken into account, the Digital Healthcare Act (DVG), and the corresponding ordinance. In order to derive specific requirements according to the state of the art and considering the identified level of protection with regard to the fundamental objectives of information security, such as confidentiality, integrity and availability, reference is made to important standards and norms. In the spirit of a how-to for manufacturers, the authors then directly address the most important deficiencies regarding authentication, consent, and authorization and give appropriate recommendations. The authors see further support for manufacturers from the Federal Institute for Drugs and Medical Devices (BfArM), for example in the form of specific guidelines, as an important pillar in overcoming the gap between requirements and reality in matters of data protection and information security. At the same time, further maturation of the manufacturer's application development organization is required and expected. At the same time, with the replacement of the Medical Device Directive (MDD) with the Medical Device Regulation (MDR), information security gains more importance.
引用
收藏
页码:1254 / 1261
页数:8
相关论文
共 50 条
  • [41] A Study on Information Security Management with Personal Data Protection
    Huang, Chien-Cheng
    Farn, Kwo-Jean
    Lin, Frank Yeong-Sung
    2011 IEEE 17TH INTERNATIONAL CONFERENCE ON PARALLEL AND DISTRIBUTED SYSTEMS (ICPADS), 2011, : 624 - 630
  • [42] Protection of Personal Information Security in the Age of Big Data
    Zou, Hui
    PROCEEDINGS OF 2016 12TH INTERNATIONAL CONFERENCE ON COMPUTATIONAL INTELLIGENCE AND SECURITY (CIS), 2016, : 586 - 589
  • [43] Data mining techniques for information security applications
    Al-Shawi, Amany
    WILEY INTERDISCIPLINARY REVIEWS-COMPUTATIONAL STATISTICS, 2011, 3 (03): : 221 - 229
  • [44] Digital health applications in primary care-Experiences and observations of general practitioners with regard to the use of DiGA
    Wangler, Julian
    Jansky, Michael
    PRAVENTION UND GESUNDHEITSFORDERUNG, 2023, 18 (04): : 483 - 491
  • [45] Blockchain user digital identity big data and information security process protection based on network trust
    Wang, Feng
    Gai, Yongjie
    Zhang, Haitao
    JOURNAL OF KING SAUD UNIVERSITY-COMPUTER AND INFORMATION SCIENCES, 2024, 36 (04)
  • [46] Erratum zu: Digitale Gesundheitsanwendungen und DatenschutzErratum to: Digital health applications and data protection
    N. Kirsten
    M. Augustin
    K. Strömer
    Der Hautarzt, 2022, 73 (6): : 501 - 501
  • [47] On the way to the digital homo vitruvianus? Medical self-tracking and digital health applications (DiGA) between empowerment and loss of control
    Funer, Florian
    ETHIK IN DER MEDIZIN, 2021, 33 (01) : 13 - 30
  • [48] Network Information Security Data Protection Based on Data Encryption Technology
    Ping, Han
    WIRELESS PERSONAL COMMUNICATIONS, 2022, 126 (03) : 2719 - 2729
  • [49] Network Information Security Data Protection Based on Data Encryption Technology
    Han Ping
    Wireless Personal Communications, 2022, 126 : 2719 - 2729
  • [50] Benchmarking of DiGA (Digital Health Applications) in Rheumatology: First Real-World Evidence (RWE) of the DiGAReal Register
    Albrecht, Alexander
    Taubmann, Jule
    Minopoulou, Ioanna
    Hatscher, Lukas
    Kleinert, Stefan
    Muehlensiepen, Felix
    Labinsky, Hannah
    Welcker, Martin
    Leipe, Jan
    Klemm, Philipp
    Hueber, Axel
    Schett, Georg
    Kuhn, Sebastian
    Knitza, Johannes
    INNERE MEDIZIN, 2024, 65 : S158 - S159