IMPLEMENTAÇÃO DE UM BACKEND SEGURO E OTIMIZADO PARA SISTEMAS DE TELEMEDICINA

Área temática: Tecnologia e Saúde

Authors

  • Arthur Magalhães Ribeiro
  • Osmarindo Ferreira de Borba Neto
  • Felipe Ramos Ribeiro
  • Walter Rodrigues de Andrade

DOI:

https://doi.org/10.47224/revistamaster.v10i20.789

Keywords:

Telemedicina; Backend; Segurança da Informação; API REST; JWT.

Abstract

The advancement of digital technologies has enabled the consolidation of
telemedicine as an essential tool to expand access to healthcare, especially in underserved
areas. However, the success of such systems depends directly on the robustness and security
of the backend infrastructure that supports these applications. This study presents the
development and implementation of a secure and optimized backend for a telemedicine
application, focusing on data protection and system performance. The backend was built
using Node.js with the Express framework, and the database used was MongoDB. The
architecture followed a modular design pattern, with user and patient data schemas, secure
route definitions, and token-based authentication using JWT. Passwords were hashed using
bcrypt. A literature review highlighted key security challenges such as data protection in
transit and at rest, and compliance with LGPD and HIPAA. Best practices such as ABAC,
OAuth 2.0, and end-to-end encryption were also discussed. Functional tests using Postman
confirmed the successful implementation of all core features, including user registration,
login, patient creation, and restricted access to sensitive data. The results show the feasibility
of building a secure backend using open-source technologies and suggest future
improvements such as RBAC, encrypted data storage, audit trails, and the adoption of
blockchain for immutable medical records. The solution contributes to the growing need for
trustworthy and efficient digital health systems.

Downloads

Download data is not yet available.

References

MOTTA, G. H.; FURUIE, S. S.; NARDON, F. B.; GUTIERREZ, M. A.; YAMAGUTI, M.

Autorização e Controle de Acesso para o Prontuário Eletrônico do Paciente em Ambientes

Abertos e Distribuídos: Uma Proposta de Modelo e Arquitetura. Anais do I Workshop em

Segurança de Sistemas Computacionais (WSeg 2001), Florianópolis, p. 92-97, 2001.

Disponível em: <https://sol.sbc.org.br/index.php/sbseg/article/view/21291>. Acesso em: 11

maio 2025.

QUEIROZ, Carlos Felipe; CONCEIÇÃO, Lucas Maués Calandrine; BARRETO, Marcos

Vinicius Casais. Estudo dos aspectos para a disponibilização de dados locais na nuvem:

estudo de caso NetDoctor. RECIMA21 - Revista Científica Multidisciplinar, [S. l.], v. 2, n. 3,

p. 45-50, 2021. Disponível em:

<https://recima21.com.br/index.php/recima21/article/view/474>. Acesso em: 11 maio 2025.

SANTOS, Yago de R. dos; REIS, L. H. A.; BARBOSA, G. N. N.; OLIVEIRA, N.;

MENDES, A. C.; VALLE, R.; MEDEIROS, D. S. V.; MATTOS, D. M. F. SmartMed: uma

ferramenta de controle de acesso a dados de saúde baseado em contratos inteligentes. In:

SIMPÓSIO BRASILEIRO DE SEGURANÇA DA INFORMAÇÃO E DE SISTEMAS

COMPUTACIONAIS – SBSEG ESTENDIDO, 23., 2023, Porto Alegre. Anais Estendidos do

XXIII Simpósio Brasileiro de Segurança da Informação e de Sistemas Computacionais –

SBSeg Estendido 2023. Porto Alegre: SBC, 2023. p. 65–72. Disponível em:

https://sol.sbc.org.br/index.php/sbseg_estendido/article/view/27274. Acesso em: 11 maio

2025.

Published

2026-08-26

How to Cite

MAGALHÃES RIBEIRO, Arthur; FERREIRA DE BORBA NETO, Osmarindo; RAMOS RIBEIRO, Felipe; RODRIGUES DE ANDRADE, Walter. IMPLEMENTAÇÃO DE UM BACKEND SEGURO E OTIMIZADO PARA SISTEMAS DE TELEMEDICINA: Área temática: Tecnologia e Saúde. Revista Master - Ensino, Pesquisa e Extensão, [S. l.], v. 11, n. 21, 2026. DOI: 10.47224/revistamaster.v10i20.789. Disponível em: https://revistamaster.imepac.edu.br/RM/article/view/789. Acesso em: 4 sep. 2026.