Project Grant R41GM146313

Award Date 9/15/21
Completion Date 8/31/23
Dollars Obligated $768K
Federal Grant Program
93.859
Assistance Type
Project Grant
Place of Performance
Bayside, WI 53217, USA
Similar Awards
This Project Grant from the National Science Foundation's Computer and Information Science and Engineering program, totaling $125,962, supports research from December 1, 2022 to February 29, 2024 examining privacy expectations and practices regarding mobile health apps. Led by The University of Texas at San Antonio with the University of Texas System as parent organization, the grant combines expertise across social sciences, computer security, natural language processing, and law. The...
This Project Grant award from the National Science Foundation (NSF) Division of Social and Economic Science under the Social, Behavioral, and Economic Sciences program (CFDA 47.075) provides $393,256 to George Mason University to conduct research investigating the broader privacy ecosystems that vulnerable populations experience, beyond just individual mobile applications. The key products and services being delivered under this three-year award include: Qualitative research, including...
This National Science Foundation (NSF) Computer and Information Science and Engineering (CISE) Federal Grant Program (CFDA 47.070) Project Grant award of $166,924 aims to enhance privacy leak detection in mobile applications by identifying and analyzing sources of domain-sensitive user data. The key products and services to be delivered include: Conducting a crowdsourcing study to categorize domain-sensitive data within mobile app user interfaces. Developing a novel approach using static and...
This National Science Foundation award of $150,000 provides funding for a two-year project grant to Arizona State University under the Computer and Information Science and Engineering program (CFDA 47.070). The project aims to develop a software analysis framework to detect and mitigate security and privacy risks in augmented reality mobile applications. Specifically, the university researchers will conduct static and dynamic program analysis focused on unique augmented reality elements like...
This National Science Foundation (NSF) Project Grant award, under the CFDA 47.070 Computer and Information Science and Engineering program, provides $250,000 in funding to Arizona State University to develop intelligent anonymization methods for preserving the privacy of clients' bio-signals while retaining data utility for clinical purposes. The key products and services delivered through this 3-year award (10/1/2024 - 9/30/2027) include: 1) Designing reinforcement learning-guided generative...
This Project Grant from the National Science Foundation (NSF) provides $150,000 to Case Western Reserve University to develop a software analysis framework and conduct a study of security and privacy risks in augmented reality (AR) mobile applications. The award falls under the NSF's Computer and Information Science and Engineering program (CFDA 47.070), which supports foundational research and education in computing disciplines. Specifically, the university will create static and dynamic...
The National Science Foundation awarded a $280,000 Project Grant under the Social, Behavioral, and Economic Sciences program (CFDA 47.075) to the University of Maryland, College Park to conduct research into privacy ecosystems and management strategies for vulnerable populations. The project aims to go beyond an app-centric view of privacy by examining the broader privacy risks faced by vulnerable individuals, particularly in the healthcare context. Through qualitative research including...
This $180,000 Project Grant award from the National Science Foundation (NSF) Computer and Information Science and Engineering (CISE) program aims to develop new methods for privacy-preserving data sharing and collaborative analysis of mobile internet measurement data. The collaborative project involving researchers from the University of Nebraska-Lincoln, Utah State University, and the University of Wisconsin-Madison will focus on: 1) Developing quality-explainable data synthesis and...
This $206,542 federal Project Grant award from the National Science Foundation's (NSF) Computer and Information Science and Engineering (CISE) program to Indiana University will fund research to address privacy accountability challenges in the mobile software supply chain. The key objectives are: 1) understanding privacy accountability risks in third-party mobile code modules, 2) designing a privacy-accountable disclosure framework, and 3) continuously enforcing privacy accountability during...
The National Science Foundation (NSF) awarded a $234,347 Project Grant under the Social, Behavioral, and Economic Sciences program (CFDA 47.075) to the Regents of the University of Michigan, Office of Research and Sponsored Projects (doing business as the University of Michigan) for the project "Collaborative Research: SATC: CORE: MEDIUM: Beyond App-Centric Privacy: Investigating Privacy Ecosystems Among Vulnerable Populations." The project aims to go beyond app-centric approaches to...

A FRAMEWORK FOR MHEALTH APP SECURITY AND PRIVACY ANALYSIS - ABSTRACT: WITH THE INCREASED USE OF MOBILE HEALTH APPS TO IMPROVE HEALTH OUTCOMES, PROTECTING PRIVATE HEALTH DATA IS BECOMING INCREASINGLY IMPORTANT. RESEARCHERS ESTIMATE THERE ARE OVER 300,000 MHEALTH APPS IN EXISTENCE, AND SOME RELATE TO HIPAA COVERED ENTITIES OR THEIR BUSINESS ASSOCIATES. WITH PATIENTS' INCREASING DESIRE FOR DATA ACCESSIBILITY AND APP DATA SHARING, IT IS CRITICAL TO ENSURE THAT PATIENTS TRANSMIT THEIR PROTECTED HEALTH INFORMATION (PHI) TO APPS THAT ARE COMPLIANT WITH HIPAA PRIVACY AND SECURITY RULES. ABOUT 25% OF HEALTHCARE PROVIDERS SUFFER FROM DATA BREACHES VIOLATING HIPAA POLICIES, CAUSED BY USING MOBILE DEVICES THAT COME PRELOADED WITH MHEALTH APPS. THIS RESULTS IN LAWSUITS, AND LOSS OF CONFIDENCE AMONG HEALTH PROVIDERS AND PATIENTS. EARLIER RESEARCH HAS FOCUSED ON SECURITY OF MOBILE DEVICES, BUT NOT CHECKING FURTHER HOW APPS STORE OR TRANSFER DATA SECURELY BEFORE BEING USED BY REMOTE HEALTH CARE PROVIDERS OR USERS. MOST MOBILE APP DEVELOPERS INCLUDING MHEALTH APPS ARE NOT AWARE OF HIPAA SECURITY AND PRIVACY REGULATIONS. THIS CREATES THE MARKET OPPORTUNITY TO DEVELOP STATIC AND DYNAMIC CODE ANALYSIS TOOLS FOR MHEALTH APP DEVELOPERS, SO THEIR DEVELOPED PRODUCTS MEET HIPAA SECURITY AND PRIVACY GUIDELINES. CURRENTLY, THERE IS A LACK OF AN ANALYSIS FRAMEWORK TO CHECK MHEALTH APPS' SECURITY AND PRIVACY RISKS FOLLOWING THE APPLICABLE HIPAA TECHNICAL SECURITY AND PRIVACY GUIDELINES. WE PROPOSE TO DEVELOP A FRAMEWORK TO ANALYZE MHEALTH APPS FOR HIPAA SECURITY AND PRIVACY COMPLIANCE. THE FRAMEWORK WILL ALLOW USERS WHO HAVE NO KNOWLEDGE OF HIPAA OR APP SECURITY TO RECEIVE AN ASSESSMENT OF SECURITY AND PRIVACY RISKS PER HIPAA GUIDELINES. INITIALLY BASED ON ANDROID STUDIO, THE TOOL WILL TEST THE SOURCE CODE OF MHEALTH APPLICATIONS FOR POTENTIAL DATA SECURITY BREACHES RELATED TO HIPAA BEFORE POSTING FOR THE MARKETPLACE. THE TOOL WILL FURTHER ADDRESS API LEVEL CHECKING FOR SECURE DATA COMMUNICATION MANDATED BY RECENT CMS GUIDELINES BETWEEN THIRD PARTY MOBILE HEALTH APPS AND EHR SYSTEMS. THE ANALYSIS FRAMEWORK WILL ALSO ADDRESS HETEROGENEOUS HEALTH DATA AND ENABLE PROVIDERS TO REMAIN COMPLIANT WITH HIPAA ADMINISTRATIVE AND OPERATIONAL GUIDELINES. WE PROPOSE TO PERFORM TWO ACCEPTANCE TESTS ON THE PROTOTYPE BASED ON PARTNERING WITH HIPAA EXPERTS AND MEDICAL DOCTORS AND FOR-PROFIT EHR VENDORS ALONG WITH THE EFFECTIVENESS OF TOOLS FOR DETECTING HEALTH DATA SECURITY BREACHES. THE PROPOSED TOOL WILL FURTHER ENABLE THE DEVELOPMENT OF DATA BREACH CHECKING FOR IOS MHEALTH APPS AND ADOPTION AND INTEGRATION BY LARGE SCALE EHR VENDORS IN THE FUTURE.

Posted 9/15/21, 12:00 AM