The Rise of Mobile Health
Mobile health, or mHealth, applications and devices have become widespread tools for patient engagement, chronic disease management, and remote monitoring. Health information management professionals must extend data governance frameworks to address the unique risks and opportunities these technologies introduce.
mHealth Applications
mHealth apps range from consumer wellness tools with no clinical integration to clinically validated applications that transmit data directly into the electronic health record. Governance frameworks should distinguish between these categories, applying more rigorous data quality and security requirements to applications that inform clinical decision-making.
BYOD Policies
Bring your own device, or BYOD, policies govern workforce members' use of personal smartphones and tablets to access organizational systems and data. Effective BYOD policies require minimum security configurations, such as passcodes and encryption, prohibit storage of PHI directly on personal devices outside approved applications, and reserve the organization's right to remotely wipe corporate data if a device is lost or an employee separates.
Mobile Device Management
Mobile device management, or MDM, software allows organizations to enforce security policies, deploy applications, and remotely manage or wipe both organization-owned and personal devices enrolled in the program. MDM solutions are essential for maintaining security control over the growing number of endpoints accessing health data.
Data Security Considerations
Mobile health data introduces risks including device loss or theft, insecure data transmission, and third-party app vendors with inconsistent security practices. Organizations should vet mHealth vendors for appropriate encryption standards, require business associate agreements when apps handle PHI, and conduct security assessments before integrating any mobile solution with clinical systems.
Patient-Generated Health Data
Patient-generated health data, such as home blood pressure readings or fitness tracker information, offers valuable insight into patient status between encounters but raises governance questions about data provenance, accuracy, and how it should be incorporated into the legal health record. Organizations need clear policies defining which patient-generated data becomes part of the official record and how it is validated before informing clinical decisions.