Analyzing third-party data leaks on online pharmacy websites

被引:1
|
作者
Rauti, Sampsa [1 ]
Carlsson, Robin [1 ]
Mickelsson, Sini [2 ]
Makila, Tuomas [1 ]
Heino, Timi [1 ]
Pirjatanniemi, Elina [3 ]
Leppanen, Ville [1 ]
机构
[1] Univ Turku, Dept Comp, Turku, Finland
[2] Univ Turku, Fac Law, Turku, Finland
[3] Abo Akad Univ, Inst Human Rights, Turku, Finland
基金
芬兰科学院;
关键词
Online pharmacies; Data leaks; Web privacy; Data concerning health; Sensitive data; COMMUNITY PHARMACY; HEALTH DATA; PRIVACY; WIDESPREAD; ACCESS;
D O I
10.1007/s12553-024-00819-w
中图分类号
R-058 [];
学科分类号
摘要
PurposeWith digitalization, using essential digital services such as online services has become increasingly common. These services process sensitive health related data, such as customers' prescription medicine orders, which makes ensuring stringent data privacy crucial. The current study examines third parties such as analytics services on Finnish pharmacy websites and investigates the nature and contents of data leaks on these websites.MethodsWe perform an extensive network traffic analysis to reveal data leaks among 163 Finnish online pharmacies. We also study a set of privacy policies of these online pharmacies, and provide a legal analysis regarding the interpretation of the concept of data concerning health in the context of online pharmacies.ResultsOur findings reveal serious data leaks among Finnish online pharmacies. We found 145 pharmacies had third-party services on their websites and only 18 did not. Out of all 163 online pharmacies, 57 (35.0 %) leaked a specific prescription medicine name connected with identifying personal data on the customer. We argue that the information concerning purchases on the prescription medicines should be interpreted as data concerning health to ensure efficient protection of customers' right to data protection and privacy.ConclusionsWe hope that these concerning results will serve as a wake-up call for the developers and maintainers of online pharmacies and other web services processing sensitive data. Any third-party services incorporated into websites processing sensitive personal data should be closely inspected in terms of data leaks, or preferably not used at all.
引用
收藏
页码:375 / 392
页数:18
相关论文
共 50 条
  • [1] Analyzing third-party data leaks on online pharmacy websites
    Sampsa Rauti
    Robin Carlsson
    Sini Mickelsson
    Tuomas Mäkilä
    Timi Heino
    Elina Pirjatanniemi
    Ville Leppänen
    Health and Technology, 2024, 14 : 375 - 392
  • [2] Third-Party Data Leaks on Municipal Websites
    Rauti, Sampsa
    Carlsson, Robin
    Puhtila, Panu
    Leppanen, Ville
    PROCEEDINGS OF NINTH INTERNATIONAL CONGRESS ON INFORMATION AND COMMUNICATION TECHNOLOGY, VOL 5, ICICT 2024, 2024, 1000 : 599 - 610
  • [3] Third-Party Data Leaks in the Websites of Finnish Social and Healthcare Districts
    Puhtila, Panu
    Vuorinen, Esko
    Rauti, Sampsa
    GOOD PRACTICES AND NEW PERSPECTIVES IN INFORMATION SYSTEMS AND TECHNOLOGIES, VOL 1, WORLDCIST 2024, 2024, 985 : 139 - 152
  • [4] Analyzing hotel star ratings on third-party distribution websites
    Guillet, Basak Denizci
    Law, Rob
    INTERNATIONAL JOURNAL OF CONTEMPORARY HOSPITALITY MANAGEMENT, 2010, 22 (06) : 797 - 813
  • [5] Prevalence of Third-Party Data Tracking by US Hospital Websites
    Niforatos, Joshua D.
    Zheutlin, Alexander R.
    Sussman, Jeremy B.
    JAMA NETWORK OPEN, 2021, 4 (09)
  • [6] Hotel Overbooking and Cooperation with Third-Party Websites
    Dong, Yufeng
    Ling, Liuyi
    SUSTAINABILITY, 2015, 7 (09): : 11696 - 11712
  • [7] Lessons learned from studying third-party data leaks in web services
    Rauti, Sampsa
    8TH INTERNATIONAL CONFERENCE ON INFORMATION SYSTEMS ENGINEERING, ICISE 2023, 2023, : 125 - 129
  • [8] Prevalence of Third-party Tracking on Medical Journal Websites
    Gupta, Ravi
    Friedman, Ari B.
    McCoy, Matthew S.
    JAMA HEALTH FORUM, 2022, 3 (03): : E220167
  • [9] Risks of third-party data
    Schneier, B
    COMMUNICATIONS OF THE ACM, 2005, 48 (05) : 136 - 136
  • [10] Selling Rooms: Hotels vs. Third-Party Websites
    Toh, Rex S.
    Raven, Peter
    DeKay, Frederick
    CORNELL HOSPITALITY QUARTERLY, 2011, 52 (02) : 181 - 189