On the privacy of mental health apps

互联网隐私 健康 心理健康 仿形(计算机编程) 计算机科学 数据共享 信息隐私 计算机安全 万维网 医疗保健 心理学 医学 操作系统 病理 经济 替代医学 心理治疗师 经济增长
作者
Leonardo Horn Iwaya,Muhammad Ali Babar,Awais Rashid,Chamila Wijayarathna
出处
期刊:Empirical Software Engineering [Springer Science+Business Media]
卷期号:28 (1) 被引量:41
标识
DOI:10.1007/s10664-022-10236-0
摘要

An increasing number of mental health services are now offered through mobile health (mHealth) systems, such as in mobile applications (apps). Although there is an unprecedented growth in the adoption of mental health services, partly due to the COVID-19 pandemic, concerns about data privacy risks due to security breaches are also increasing. Whilst some studies have analyzed mHealth apps from different angles, including security, there is relatively little evidence for data privacy issues that may exist in mHealth apps used for mental health services, whose recipients can be particularly vulnerable. This paper reports an empirical study aimed at systematically identifying and understanding data privacy incorporated in mental health apps. We analyzed 27 top-ranked mental health apps from Google Play Store. Our methodology enabled us to perform an in-depth privacy analysis of the apps, covering static and dynamic analysis, data sharing behaviour, server-side tests, privacy impact assessment requests, and privacy policy evaluation. Furthermore, we mapped the findings to the LINDDUN threat taxonomy, describing how threats manifest on the studied apps. The findings reveal important data privacy issues such as unnecessary permissions, insecure cryptography implementations, and leaks of personal data and credentials in logs and web requests. There is also a high risk of user profiling as the apps' development do not provide foolproof mechanisms against linkability, detectability and identifiability. Data sharing among 3rd-parties and advertisers in the current apps' ecosystem aggravates this situation. Based on the empirical findings of this study, we provide recommendations to be considered by different stakeholders of mHealth apps in general and apps developers in particular. We conclude that while developers ought to be more knowledgeable in considering and addressing privacy issues, users and health professionals can also play a role by demanding privacy-friendly apps.The online version contains supplementary material available at 10.1007/s10664-022-10236-0.
最长约 10秒,即可获得该文献文件

科研通智能强力驱动
Strongly Powered by AbleSci AI
科研通是完全免费的文献互助平台,具备全网最快的应助速度,最高的求助完成率。 对每一个文献求助,科研通都将尽心尽力,给求助人一个满意的交代。
实时播报
刚刚
dabian8999发布了新的文献求助10
1秒前
uraylong发布了新的文献求助10
1秒前
严明发布了新的文献求助10
1秒前
michal完成签到,获得积分10
3秒前
Akim应助稳重的一曲采纳,获得30
3秒前
爆米花应助清爽问筠采纳,获得10
4秒前
5秒前
5秒前
美丽心情完成签到,获得积分10
6秒前
量子星尘发布了新的文献求助10
6秒前
严尔风发布了新的文献求助20
6秒前
西西完成签到,获得积分20
8秒前
9秒前
10秒前
伊伊发布了新的文献求助10
10秒前
12秒前
jenningseastera应助严明采纳,获得10
13秒前
虞无声发布了新的文献求助10
13秒前
13秒前
14秒前
14秒前
16秒前
外向的易蓉完成签到,获得积分10
16秒前
17秒前
18秒前
猫先生发布了新的文献求助10
19秒前
20秒前
20秒前
巴拉巴拉巴拉拉完成签到,获得积分10
21秒前
22秒前
蘇q完成签到 ,获得积分10
22秒前
量子星尘发布了新的文献求助10
25秒前
26秒前
严尔风完成签到,获得积分10
28秒前
wanci应助lina采纳,获得10
30秒前
31秒前
31秒前
31秒前
Akim应助烂漫碧灵采纳,获得10
32秒前
高分求助中
【提示信息,请勿应助】请使用合适的网盘上传文件 10000
The Oxford Encyclopedia of the History of Modern Psychology 1500
Green Star Japan: Esperanto and the International Language Question, 1880–1945 800
Sentimental Republic: Chinese Intellectuals and the Maoist Past 800
The Martian climate revisited: atmosphere and environment of a desert planet 800
Parametric Random Vibration 800
Building Quantum Computers 500
热门求助领域 (近24小时)
化学 材料科学 医学 生物 工程类 有机化学 物理 生物化学 纳米技术 计算机科学 化学工程 内科学 复合材料 物理化学 电极 遗传学 量子力学 基因 冶金 催化作用
热门帖子
关注 科研通微信公众号,转发送积分 3864457
求助须知:如何正确求助?哪些是违规求助? 3406886
关于积分的说明 10651543
捐赠科研通 3130758
什么是DOI,文献DOI怎么找? 1726577
邀请新用户注册赠送积分活动 831814
科研通“疑难数据库(出版商)”最低求助积分说明 780039