healthcaretechoutlook
| | APRIL 20229UTLOOKHealthcare Tech starting to use more mobile applications (applications used on smart devices). With mobile applications, most organizations can place these applications in a minimum of two categories. While clinicians and physicians might not really care how these two categories are managed, they are important from a security perspective. For example, the minimum two categories could be a mobile application that is on a corporate-owned device or a mobile application that is placed on a BYOD device.Mobile applications that are placed on corporate-owned devices have some security advantages. In most organizations, corporate-owned devices are managed through a Mobile Device Management (MDM) software component. The MDM software has many capabilities from building profiles that only allow certain applications to run, such as disabling certain applications such as non-corporate email that could leverage weak security protocols, which could eventually lead to bad outcomes. The ability to profile and publish business-approved applications helps with a reduction in the attack surface. In addition, the MDM software can help assist with asset management and provide capabilities with remote wipe and erase when a smart device has become lost or stolen.Some healthcare delivery organizations have physicians and clinicians who are not employees and have some expectations with continuation of care and patient safety with mobile applications. Some ED departments and modality clinicians use mobile applications that assist with critical timing of patient care that can become a difference between a good or a bad outcome. When business-facing applications must be placed on a BYOD (non-corporate) device, the using MDM software becomes a challenge.When a business-facing application must be placed on a BYOD device, there are a couple of security considerations that should be reviewed. The consideration is, there is a fine line between the privacy of the business application versus the privacy of the BYOD owner. There are solutions that can assist with how mobile applications are used on BYOD devices, such as ensuring that the corporate-owned application/data are isolated from other BYOD applications, such as personal email or browsers. For example, these technologies can assist with the inability to copy and paste data from business-facing applications to personal applications. Also, these technologies can assist with the ability to perform a remote wipe of business-facing applications when the applications are no longer needed or, worse, when a BYOD device is lost or stolen.As technology continues to advance in the healthcare risk domain, these advancements support better-managed care and patient safety. Enhanced capabilities and technologies are inevitable as technology improves in its abilitability to help prolong and save lives. As these advancements continue, security should remain as an integrated process and not a bolted-on approach. HTSecurity that can affect patient safety has become a concern with medical devices' enhanced capabilitiesJohn Wilson
< Page 8 | Page 10 >