Skip to main content

mHealth and Network security


1. What are the major trends you’re noticing in healthcare mobility?

In a country like India where Doctor to patient ratio is 1:900, Doctors are a few and work is like 24/7. Patient demands low cost, timely and quality healthcare coverage. For Healthcare enterprises, Patient Data is critical to collect and manage and hence mhealth is primarily aimed at bridging the economic divide in terms of healthcare. Mobility is the key here- Many Healthcare enterprises which are spread over 10-20 establishments in India are now using VPNs as the enabling technology which allows Doctors to use standard public Internet ISPs and high-speed lines to access closed private networks. A simple use case for this is to access Virtual Patient Health records and there are other wireless technologies designed specifically for use in the provision of healthcare, like:

  1. Standard Mobile enterprise services used by health-care workers, such as remote access to e-mail and health-information systems;
  2. Mobile Applications to meet a specific need of medical workers, such as mobile prescriptions and remote diagnoses;
  3. Applications that play a direct role in the provision of care, such as mobile data collection and wireless transmission of health data; and
  4. Consumer-targeted applications to encourage health and help prevent illness.

2. What are the security concerns around these trends?

Security of patient data is important. Even if you comply with HIPAA, it doesn’t have that depth and breadth of protection which is required as health care is comprised of exceedingly complex information environments that demand comprehensive patient data security approaches especially when the data is shared across networks. For a simple use case of accessing a patient’s Virtual Electronic Patient Records with a wireless device, there are 3 main security issues to address:
1. To Authenticate & authorize from the wireless to the wired network
2. Secure Data share in transit
3. Integrity & Good Resolution in the information that is requested and visualized by the users/doctors.

3. Is there a security risk re: healthcare mobility that is overrated or underrated? What are they?

Not overrated actually. Healthcare mobility is the key. As manpower is scanty in hospitals, therefore in scenarios where large volumes of background traffic needs to be sent from automated programs talking to other automatic programs, IPsec here serves the best. End to end security is however required in several Govt Health missions where there are a lot of private partners in the value chain and secured/encrypted communication is a must. SSL enabled VPN is useful here. With SSL, a secure tunnel is established directly from the client to the resource the client is accessing. With true end-to-end security, no data is sent in the clear, either on the internal network or on the Internet. Everything from the client to the resource is securely authenticated and encrypted.


4. What are the security concerns around sensor technology, portable medical devices and wireless health applications – and how will they be mitigated?

There are several security concerns and hence before we deploy mobility we need to understand that fully automated Remote Access VPN Management is necessary. Solutions should be easy to use and efficient as well. A holistic remote access solution is required to integrate all essential technologies regarding security and communication. Hospitals and Healthcare enterprises are looking to upgrade and hence low switching costs is the major driving force coupled with greater efficiency and ease to use and deploy.

5. What role will IPsec play in mobile health security?

Two parties who wish to create an IPSec tunnel must first negotiate on a standard way to communicate. Since IPSec supports several modes of operation, both sides must first decide on the security policy and mode to use, which encryption algorithms they wish to communicate with and what type of authenticate method to use. IPSec and WPA EAP-TLS solutions are very efficient against MITM, impersonation and session hijacking attacks. Both solutions are not efficient against DoS attacks. It is possible to successfully perform DoS attacks using freely available tools. For systems where availability is essential, it is necessary to complement those solutions with more mechanisms that reduce the risk of such attack. It is thus necessary to use tools like Intrusion Detection Systems (IDS) and vulnerability scanners. Because IPSec sits at the network layer not only is all your network traffic encrypted, but all users gain access to all company resources as if they were physically resident in the office connected to that LAN. Hospitals may or may not want partners or temporary remote employees to be part of their network. The network may only need to have a small portion of its traffic secure. Hospitals may not want to encrypt everything from the remote client to the corporate network. Also scalability is a problem with IPsec. On the other side, SSL proxies enforce much stronger authentication methods than a back-end resource could ever support natively. Many Web servers today do not natively support authentication methods other than SSL.

Inference: Solutions require high degree of integrational ability and interoperability that makes it possible for Healthcare enterprises to deploy these software products in an already available IT infrastructure.

Popular posts from this blog

Artificial Intelligence Policy and Governance in HEALTHCARE

  Artificial Intelligence has become the new frontier for digital transformation. Several  #digitalhealth  businesses of today rely on Machine Learning,  #AI  and other such technologies to make healthcare delivery more efficient and comprehensive. However, the efficient and responsible use of AI tools is an ongoing discussion and would mean culture, data management, technology shifts in the industry, and required up-grading and training professionals for better coordination. Hence, with the growing market potential and interest in AI, it is imperative to develop a thoughtthrough regulatory and legal framework on the adoption and use of AI. I have set forward a hypotheses to design a policy framework for AI technologies in my paper- "𝐀𝐫𝐭𝐢𝐟𝐢𝐜𝐢𝐚𝐥 𝐈𝐧𝐭𝐞𝐥𝐥𝐢𝐠𝐞𝐧𝐜𝐞 𝐢𝐧 𝐇𝐞𝐚𝐥𝐭𝐡 𝐏𝐨𝐥𝐢𝐜𝐲 – 𝐀 𝐆𝐥𝐨𝐛𝐚𝐥 𝐏𝐞𝐫𝐬𝐩𝐞𝐜𝐭𝐢𝐯𝐞" last year https://lnkd.in/emi3XWwa cited further by "𝐓𝐡𝐞 𝐐𝐮𝐚𝐧𝐝𝐚𝐫𝐲 𝐢𝐧 𝐃𝐚𝐭𝐚 𝐏𝐫𝐨𝐭𝐞𝐜𝐭𝐢𝐨𝐧 𝐚𝐧𝐝 𝐑

Artificial intelligence and Technology for Dentistry

Have you heard of this company  ORCA Dental AI ? ORCA combines clinical expertise with machine learning and AI technologies to create diagnostic reports, treatment plan suggestions and smart clinical predictions. Good to learn about these innovations that benefit every stakeholder in the value chain. Recently,  VideaHealth  raised $20M to Expand AI-Based Diagnostics led by Spark Capital including existing investors Zetta Venture Partners. Among its many benefits to dentists and patients are: – A 31% increase in diagnosis rate for cavities and 26% increase in treatment plan value; – An increase in case acceptance by patients due to second opinions; – Automated workflows accelerate treatment planning and charting; Another company touting AI-powered dental care and practice management is  Overjet , which announced a $42.5 million Series B funding round in December months after it had scored $27 million in Series A funding.  Pearl  provides AI for dental images to assist in diagnosis. It l

Big Data Analytics- The Microscope and Telescope for Pharma/CRO

This article is produced in consultation with Industry experts, and KOLs in India and across the world and especially highlights how “Predictive Analytics algorithms” are poised to provide Useful Analytics to the Pharma industry.   In today’s highly competitive market, it is extremely important for contract research and manufacturers to have access to information that allows them to target the specific segments of the pharmaceutical and biotechnology industry that are looking to outsource the particular services they provide.  Understanding shifts in annual outsourcing budgets and spending can help CROs and CMOs to better position themselves for capturing business, particularly at a time when many – if not all – pharma and biotech companies are looking to cut costs and streamline operations.  As per a recent report by NiceInsights, Analytical Services, Clinical Research, and Clinical Monitoring will be the most demanded services over the next 12 to 18 months. For CROs and CMOs looki