All Episodes

February 19, 2025 12 mins
Zero Trust for Mobile Healthcare: Protecting ePHI on Personal Devices

The proposed updates to the HIPAA Security Rule aim to address specific cybersecurity threats related to mobile devices and applications that access electronic protected health information (ePHI)1....

These threats include:
• Cloned/modified apps: Addressing the risk of fake apps that can download malware, viruses, or steal credentials to access backend systems3.... App attestation is suggested as a way to verify that apps accessing ePHI are genuine and unmodified5....
• Device manipulation: Providing run time protection against device manipulation, where hackers can jailbreak or root devices and use tools to steal data or modify app operations7.... The proposal suggests continuous scanning for problematic software and real-time reporting of device environment states, with the ability to block requests from compromised devices8....
• Man-in-the-middle attacks: Protecting against the interception and manipulation of mobile device communications to steal sensitive information7.... The proposal suggests the implementation of dynamic pinning on all communication channels used by healthcare apps, including to third-party APIs, as well as blocking tools that enable trust store manipulation or MitM attacks11....
• API secret protection: Preventing hackers from using weaponized mobile apps to scale up attacks on critical APIs by stealing API keys7.... The proposal suggests that API keys for accessing ePHI APIs should never be stored in mobile app code, but delivered only as needed to verified apps via attestation15....
• Identity exploits: Protecting against identity theft and credential stuffing attacks by using app and device attestation at run time for zero-trust protection7.... The proposal suggests tracking signs of identity abuse as a requirement for run time security monitoring17....

Breach readiness and service continuity: Encouraging organisations to prepare for potential security incidents with protocols for addressing breaches, such as revoking access, quarantining affected systems and conducting investigations7.... It suggests that Incident Response plans should extend to third-party breaches and highlight the management of API Keys and certificates.

Relevant links for the podcast:
• Approov Limited: 
◦Website: www.approov.io
• OWASP MASVS (Mobile Application Security Verification Standard): Provides guidelines for mobile app security
•NIST (National Institute of Standards and Technology): Cited in the context of incident response plans
•HHS 405(d) Program: Offers health industry cybersecurity practices8....
•Federal Trade Commission (FTC): Provides a guide for business security8....
•Department of Health and Human Services (HHS): Offers Cybersecurity Performance Goals (CPGs)8....
•ONC Health IT Certification Program: Maintained by the Assistant Secretary for Technology Policy and Office of the National Coordinator for Health Information Technology (ASTP/ONC)10.
• Regulations.gov: For the plain-language summary of the proposed rule and posted comments11:
◦ Go to https://www.regulations.gov and search for Docket ID number HHS-OCR-0945-AA22.
Mark as Played

Advertise With Us

Popular Podcasts

On Purpose with Jay Shetty

On Purpose with Jay Shetty

I’m Jay Shetty host of On Purpose the worlds #1 Mental Health podcast and I’m so grateful you found us. I started this podcast 5 years ago to invite you into conversations and workshops that are designed to help make you happier, healthier and more healed. I believe that when you (yes you) feel seen, heard and understood you’re able to deal with relationship struggles, work challenges and life’s ups and downs with more ease and grace. I interview experts, celebrities, thought leaders and athletes so that we can grow our mindset, build better habits and uncover a side of them we’ve never seen before. New episodes every Monday and Friday. Your support means the world to me and I don’t take it for granted — click the follow button and leave a review to help us spread the love with On Purpose. I can’t wait for you to listen to your first or 500th episode!

Stuff You Should Know

Stuff You Should Know

If you've ever wanted to know about champagne, satanism, the Stonewall Uprising, chaos theory, LSD, El Nino, true crime and Rosa Parks, then look no further. Josh and Chuck have you covered.

Dateline NBC

Dateline NBC

Current and classic episodes, featuring compelling true-crime mysteries, powerful documentaries and in-depth investigations. Follow now to get the latest episodes of Dateline NBC completely free, or subscribe to Dateline Premium for ad-free listening and exclusive bonus content: DatelinePremium.com

Music, radio and podcasts, all free. Listen online or download the iHeart App.

Connect

© 2025 iHeartMedia, Inc.