This is a different twist - I'm pushing dispatch information to first responders, such as fire, police, and EMS. But they all could, potentially, include medical information and PII together.
My goal is to make it easier for the first responder to obtain critical information, so I want to make it available in the vehicle, or on the smartphone if necessary. This is where I'm not certain what my responsibilities are. I'd like to provide the information via the browser. I'm curious if a) this scenario falls under HIPAA's domain, and b) are there guidelines I need to follow in the application design - the browser component. The back end I am confident is secure. But I don't know what I need to do on the front end side to protect from accidental or even malicious stealing/accessing this data (by taking the phone, or glancing over a shoulder...
Any advice? Thanks!