Translating GDPR into the mHealth Practice

The interaction between patients and health providers through mobile apps can potentially improve the efficiency and quality of healthcare. But despite the advantages, the majority of mobile apps provide low or no security protection and there is a lack of security standards and guidelines to support its development with an adequate balance between availability and confidentiality. Since May 2018, this lack of security awareness and measures has to change. With the application of the new General Data Protection Regulation (GDPR), the European residents' personal data processing by third parties will be stricter and more controlled. On the way to understanding how GDPR affects the content and interactions of mHealth apps, this article aims to compare how previous legislation is reflected in the interactions between users and those apps and what key changes must take place now that GDPR is in force. GDPR empowers patients to ask and receive in a simple understandable manner, information about the security measures that are applied to protect their personal data and transparently see how their personal data is processed, by whom and to what purposes. Use-case scenarios are presented to discuss the impact of GDPR key changes in the visual interactions between the user/patient and mHealth apps and how the app content can be adapted to a more objective and uncluttered view. This study provides means to easily and quickly integrate the key privacy and legislation requirements from GDPR into app visualization, improving this way availability, transparency and patients' empowerment.

[1]  Samir Chatterjee,et al.  A Taxonomy of mHealth Apps -- Security and Privacy Concerns , 2015, 2015 48th Hawaii International Conference on System Sciences.

[2]  Cornelia M. Ruland,et al.  Secure solution for mobile access to patient's health care record , 2011, 2011 IEEE 13th International Conference on e-Health Networking, Applications and Services.

[3]  C. Pyper,et al.  Access to electronic health records in primary care-a survey of patients' views. , 2004, Medical science monitor : international medical journal of experimental and clinical research.

[4]  C. L. Ventola Mobile devices and apps for health care professionals: uses and benefits. , 2014, P & T : a peer-reviewed journal for formulary management.

[5]  Gabriele Lenzini,et al.  Envisioning secure and usable access control for patients , 2014, 2014 IEEE 3nd International Conference on Serious Games and Applications for Health (SeGAH).

[6]  J. Dumortier Directive 98/48/EC of the European Parliament and of the Council , 2006 .

[7]  Ricardo Jorge Tomé Rodrigues Pires mHealth: o impacto da nova diretiva Europeia de proteção de dados, caso de uso e avaliação , 2016 .

[8]  Russell A. McCann,et al.  mHealth for mental health: Integrating smartphone technology in behavioral healthcare. , 2011 .