QuestionQ187

Privacy Enhancing Technologies

Ivan is a nurse for a U.S. home healthcare service provider. The company has deployed a mobile application that Ivan uses during home visits to record a patient’s vital statistics and access the patient’s healthcare records.

During one visit, Ivan cannot access the healthcare application to record the patient’s vitals. Instead, he records the information in his mobile phone’s note-taking application so he can enter the data into the healthcare application the next time it is available. What is the best action for the IT department to take to ensure the data is protected on his device?

  • A Provide all healthcare employees with mandatory annual security awareness training with a focus on the health information protection.
  • B Complete a SWOT analysis exercise on the mobile application to identify what caused the application to be inaccessible and remediate any issues.
  • C Adopt mobile platform standards to ensure that only mobile devices that support encryption capabilities are used.
  • D Implement Mobile Device Management (MDM) to enforce company security policies and configuration settings.
Explanation

Mobile device management (MDM) provides centralized enforcement of an organization’s security policies and device configuration settings, such as encryption, authentication, application restrictions, and remote-wipe capabilities. This directly protects electronic protected health information temporarily stored on a clinician’s mobile device. HHS guidance identifies mobile device management and security/configuration settings as topics for mobile-device policies that safeguard health information.

Learn more

Community Discussion

No comments yet. Be the first to start the discussion!