Volume 198 - Issue 10

Clinical software on personal mobile devices needs regulation

Authors:  Sulakshan Rasiah and Jonathan K Kam

Med J Aust 2013; 198 (10): 530-531. || doi: 10.5694/mja12.11657
Published online: 3 June 2013
To the Editor: Fernando makes a valid statement on the need for regulation of clinical software on personal mobile devices (PMDs).1 Her timely comment regarding acting now before the “courts decide” is fair, given that many doctors, including a high percentage of specialist trainees, are now using PMDs.2 However, it is important for doctors to remember that the security risks highlighted by Fernando are not ...

To the Editor: Fernando makes a valid statement on the need for regulation of clinical software on personal mobile devices (PMDs).1 Her timely comment regarding acting now before the “courts decide” is fair, given that many doctors, including a high percentage of specialist trainees, are now using PMDs.2 However, it is important for doctors to remember that the security risks highlighted by Fernando are not just limited to clinical software. Other intrinsic functions of PMDs — such as text messaging, and video and image capture and transfer — need careful consideration too. These tools are commonly used by doctors to convey information to one another and their use may involve storing potentially sensitive information.3

We acknowledge that text messaging and image capture provide valuable means of improving clinical handover and optimising the provision of medical advice, but warn that any transfer of information has the potential to breach patient–clinician confidentiality. This is especially true if the information is not de-identified. We are concerned about the ease with which this information can be accessed if a clinician misplaces their PMD.

Perhaps the best way to avoid any loss of sensitive information would be to regulate all use of PMDs in the workplace. Introducing policies that mirror business practice, by which professionals often have workplace mobile devices in addition to their PMDs for added security, may be effective. The functions, applications and content of these workplace mobile devices would be regulated, and would include security or locking software to avoid breach of information if the devices were misplaced.

In any case, regulated or not, we must ensure that our patients’ private information is protected. Security measures vary from being as simple as a four-digit passcode for unlocking the phone, to data encryption or remote storage of sensitive information.4 It is also possible to remotely wipe sensitive information from a PMD if it is lost, as long as it has been previously set up to allow this. As the use of PMDs becomes routine in the medical workplace, clinicians should be aware of how they can (and should) protect their patients’ information.4


Authors


Competing interests


References