A secured app environment on a phone is plenty well secure for medical data. It is preferred strongly over a web based solution. Having a personal device running a company profile of security compliance monitoring and conditional access is as good as a company device provided by the hospital. They would do literally the same thing.
My local hospital apparently requires their employees to use a “secure” app on their personal phone to transmit data on the patients.
Seems like irresponsible handling of PHI (by the administration, not the staff) to me.
Work in IT, alongside info security. Nah.
A secured app environment on a phone is plenty well secure for medical data. It is preferred strongly over a web based solution. Having a personal device running a company profile of security compliance monitoring and conditional access is as good as a company device provided by the hospital. They would do literally the same thing.