Exploring the Far Side of Mobile Health: Information Security and Privacy of Mobile Health Apps on iOS and Android

被引:145
|
作者
Dehling, Tobias [1 ]
Gao, Fangjian [1 ]
Schneider, Stephan [1 ]
Sunyaev, Ali [1 ]
机构
[1] Univ Cologne, Dept Informat Syst, Fac Management Econ & Social Sci, D-50923 Cologne, Germany
来源
JMIR MHEALTH AND UHEALTH | 2015年 / 3卷 / 01期
关键词
mobile health; mobile apps; data security; software and application security; patient privacy; health information technology; OF-THE-LITERATURE; SMARTPHONE APPLICATIONS; CARE; ARCHITECTURE; TECHNOLOGY; MANAGEMENT; AGREEMENT; SERVICES; FEATURES; MHEALTH;
D O I
10.2196/mhealth.3672
中图分类号
R19 [保健组织与事业(卫生事业管理)];
学科分类号
摘要
Background: Mobile health (mHealth) apps aim at providing seamless access to tailored health information technology and have the potential to alleviate global health burdens. Yet, they bear risks to information security and privacy because users need to reveal private, sensitive medical information to redeem certain benefits. Due to the plethora and diversity of available mHealth apps, implications for information security and privacy are unclear and complex. Objective: The objective of this study was to establish an overview of mHealth apps offered on iOS and Android with a special focus on potential damage to users through information security and privacy infringements. Methods: We assessed apps available in English and offered in the categories "Medical" and "Health & Fitness" in the iOS and Android App Stores. Based on the information retrievable from the app stores, we established an overview of available mHealth apps, tagged apps to make offered information machine-readable, and clustered the discovered apps to identify and group similar apps. Subsequently, information security and privacy implications were assessed based on health specificity of information available to apps, potential damage through information leaks, potential damage through information manipulation, potential damage through information loss, and potential value of information to third parties. Results: We discovered 24,405 health-related apps (iOS; 21,953; Android; 2452). Absence or scarceness of ratings for 81.36% (17,860/21,953) of iOS and 76.14% (1867/2452) of Android apps indicates that less than a quarter of mHealth apps are in more or less widespread use. Clustering resulted in 245 distinct clusters, which were consolidated into 12 app archetypes grouping clusters with similar assessments of potential damage through information security and privacy infringements. There were 6426 apps that were excluded during clustering. The majority of apps (95.63%, 17,193/17,979; of apps) pose at least some potential damage through information security and privacy infringements. There were 11.67% (2098/17,979) of apps that scored the highest assessments of potential damages. Conclusions: Various kinds of mHealth apps collect and offer critical, sensitive, private medical information, calling for a special focus on information security and privacy of mHealth apps. In order to foster user acceptance and trust, appropriate security measures and processes need to be devised and employed so that users can benefit from seamlessly accessible, tailored mHealth apps without exposing themselves to the serious repercussions of information security and privacy infringements.
引用
收藏
页数:17
相关论文
共 50 条
  • [31] Developing mental health mobile apps: Exploring adolescents' perspectives
    Kenny, Rachel
    Dooley, Barbara
    Fitzgerald, Amanda
    [J]. HEALTH INFORMATICS JOURNAL, 2016, 22 (02) : 265 - 275
  • [32] Mobile apps and metabolic health
    Burki, Talha Khan
    [J]. LANCET DIABETES & ENDOCRINOLOGY, 2017, 5 (01): : 17 - 17
  • [33] Mobile apps and children's privacy: a traffic analysis of data sharing practices among children's mobile iOS apps
    Pimienta, Jessica
    Brandt, Jacco
    Bethe, Timme
    Holz, Ralph
    Continella, Andrea
    Jibb, Lindsay
    Grundy, Quinn
    [J]. ARCHIVES OF DISEASE IN CHILDHOOD, 2023, 108 (11) : 943 - +
  • [34] Analyzing security issues of android mobile health and medical applications
    Tangari, Gioacchino
    Ikram, Muhammad
    Sentana, I. Wayan Budi
    Ijaz, Kiran
    Kaafar, Mohamed Ali
    Berkovsky, Shlomo
    [J]. JOURNAL OF THE AMERICAN MEDICAL INFORMATICS ASSOCIATION, 2021, 28 (10) : 2074 - 2084
  • [35] Conceptual framework for the security of mobile health applications on Android platform
    Hussain, Muzammil
    Zaidan, A. A.
    Zidan, B. B.
    Iqbal, S.
    Ahmed, M. M.
    Albahri, O. S.
    Albahri, A. S.
    [J]. TELEMATICS AND INFORMATICS, 2018, 35 (05) : 1335 - 1354
  • [36] Post hoc security and privacy concerns in mobile apps: the moderating roles of mobile apps' features and providers
    Nikkhah, Hamid Reza
    Grover, Varun
    Sabherwal, Rajiv
    [J]. INFORMATION AND COMPUTER SECURITY, 2024, 32 (01) : 1 - 37
  • [37] An Automated Virtual Security Testing Platform for Android Mobile Apps
    Wang, Yong
    [J]. 2015 1ST CONFERENCE ON MOBILE AND SECURE SERVICES (MOBISECSERV), 2015, : 27 - 28
  • [38] Mobile admittance of Health Information with privacy and analysis in Telemedicine
    Arun, Vanishree
    Padma, S. K.
    Shyam, V
    [J]. 2015 INTERNATIONAL CONFERENCE ON TRENDS IN AUTOMATION, COMMUNICATIONS AND COMPUTING TECHNOLOGY (I-TACT-15), 2015,
  • [39] Security Deficiencies in the Architecture and Overview of Android and iOS Mobile Operating Systems
    Jasek, Roman
    [J]. PROCEEDINGS OF THE 10TH INTERNATIONAL CONFERENCE ON CYBER WARFARE AND SECURITY (ICCWS-2015), 2015, : 153 - 161
  • [40] Assessment of the Fairness of Privacy Policies of Mobile Health Apps: Scale Development and Evaluation in Cancer Apps
    Benjumea, Jaime
    Ropero, Jorge
    Rivera-Romero, Octavio
    Dorronzoro-Zubiete, Enrique
    Carrasco, Alejandro
    [J]. JMIR MHEALTH AND UHEALTH, 2020, 8 (07):