Logo image
HIPAA Technical Compliance Evaluation of Laravel-based mHealth Apps
 

HIPAA Technical Compliance Evaluation of Laravel-based mHealth Apps

Mst Shapna Akter, Md Abdul Barek, Md Mostafizur Rahman, Abm Kamrul Islam Riad, Md Abdur Rahman, Md Raihan Mia, Hossain Shahriar, William Chu Sheikh Iqbal Ahamed
2024 IEEE International Conference on Digital Health (ICDH), pp.58-67
IEEE International Conference on Digital Health (ICDH) (Shenzhen, China, 07/07/2024–07/13/2024)
07/07/2024
: WOS:001308534900008
1
HIPAA Compliance Laravel Framework mHealth Applications Mobile Health Security Source Code Analysis Cybersecurity Health Information Technology
The advent of mobile health applications (mHealth apps) has significantly altered the landscape of personal health management. Particularly, mHealth apps developed with the Laravel framework have gained popularity due to their robustness and scalability. However, this convenience comes with the increased responsibility of safeguarding Protected Health Identifier (PHI). The Health Insurance Portability and Accountability Act (HIPAA) sets forth standards for entities handling PHI to ensure privacy and security. Despite these critical regulations, many Laravel developers lack in-depth knowledge of HIPAA compliance, leading to potential vulnerabilities. This work introduces a comprehensive evaluation framework for assessing Laravel-based mHealth apps' HIPAA Technical compliance. Our framework provides developers with analytical tools to review their source code for compliance issues and guide them in implementing robust security features. Through static code analysis, the framework examines access control, audit controls, integrity, authentication, encryption, transmission security, user inactivity monitoring, and data lifecycle management. To validate our framework's effectiveness, we developed a specialized web-based tool and conducted an empirical analysis of 200 Medical and Health Fitness category Laravel applications from Github. The analysis revealed significant compliance gaps, particularly in user authorization, data protection, audit controls, and transmission security. In response, we offer detailed recommendations for developers to address common pitfalls and adhere to HIPAA standards. Additionally, the framework has been used to develop a secured web-based portal to assist consumers in evaluating the privacy and security of mHealth apps.
Logo image