Unaddressed privacy risks in accredited health and wellness apps: a cross-sectional systematic assessment

被引:242
作者
Huckvale, Kit [1 ]
Prieto, Jose Tomas [2 ]
Tilney, Myra [1 ]
Benghozi, Pierre-Jean [2 ]
Car, Josip [1 ,3 ]
机构
[1] Univ London Imperial Coll Sci Technol & Med, Global eHlth Unit, London W6 8RP, England
[2] Ecole Polytech, CRG, CNRS, F-91762 Palaiseau, France
[3] Nanyang Technol Univ, Hlth Serv & Outcomes Res Programme, LKC Med, Imperial Coll, Singapore 639798, Singapore
关键词
Smartphone; Mobile; Apps; Accreditation; NHS; Privacy; Confidentiality; Cross-sectional study; Systematic assessment; SECURITY; INFORMATION;
D O I
10.1186/s12916-015-0444-y
中图分类号
R5 [内科学];
学科分类号
1002 ; 100201 ;
摘要
Background: Poor information privacy practices have been identified in health apps. Medical app accreditation programs offer a mechanism for assuring the quality of apps; however, little is known about their ability to control information privacy risks. We aimed to assess the extent to which already-certified apps complied with data protection principles mandated by the largest national accreditation program. Methods: Cross-sectional, systematic, 6-month assessment of 79 apps certified as clinically safe and trustworthy by the UK NHS Health Apps Library. Protocol-based testing was used to characterize personal information collection, local-device storage and information transmission. Observed information handling practices were compared against privacy policy commitments. Results: The study revealed that 89 % (n = 70/79) of apps transmitted information to online services. No app encrypted personal information stored locally. Furthermore, 66 % (23/35) of apps sending identifying information over the Internet did not use encryption and 20 % (7/35) did not have a privacy policy. Overall, 67 % (53/79) of apps had some form of privacy policy. No app collected or transmitted information that a policy explicitly stated it would not; however, 78 % (38/49) of information-transmitting apps with a policy did not describe the nature of personal information included in transmissions. Four apps sent both identifying and health information without encryption. Although the study was not designed to examine data handling after transmission to online services, security problems appeared to place users at risk of data theft in two cases. Conclusions: Systematic gaps in compliance with data protection principles in accredited health apps question whether certification programs relying substantially on developer disclosures can provide a trusted resource for patients and clinicians. Accreditation programs should, as a minimum, provide consistent and reliable warnings about possible threats and, ideally, require publishers to rectify vulnerabilities before apps are released.
引用
收藏
页数:13
相关论文
共 50 条
[1]   A Review on the State-of-the-Art Privacy-Preserving Approaches in the e-Health Clouds [J].
Abbas, Assad ;
Khan, Samee U. .
IEEE JOURNAL OF BIOMEDICAL AND HEALTH INFORMATICS, 2014, 18 (04) :1431-1441
[2]  
Adhikari R., 2014, P 25 AUSTR C INF SYS, P1
[3]   Concern about security and privacy, and perceived control over collection and use of health information are related to withholding of health information from healthcare providers [J].
Agaku, Israel T. ;
Adisa, Akinyele O. ;
Ayo-Yusuf, Olalekan A. ;
Connolly, Gregory N. .
JOURNAL OF THE AMERICAN MEDICAL INFORMATICS ASSOCIATION, 2014, 21 (02) :374-378
[4]  
[Anonymous], ESTR CAL SEG APL MOV
[5]  
[Anonymous], GUID MED DEV STAND A
[6]  
[Anonymous], SQL INJ
[7]  
[Anonymous], HLTH APPS LIB SAF TR
[8]  
Boyles JanLauren., Privacy and data management on mobile devices
[9]  
Bureau of Consumer Protection, MARK YOUR MOB APP GE
[10]   Man-in-the-Middle Attack to the HTTPS Protocol [J].
Callegati, Franco ;
Cerroni, Walter ;
Ramilli, Marco .
IEEE SECURITY & PRIVACY, 2009, 7 (01) :78-81