Cargando…

Exploring the Far Side of Mobile Health: Information Security and Privacy of Mobile Health Apps on iOS and Android

BACKGROUND: Mobile health (mHealth) apps aim at providing seamless access to tailored health information technology and have the potential to alleviate global health burdens. Yet, they bear risks to information security and privacy because users need to reveal private, sensitive medical information...

Descripción completa

Detalles Bibliográficos
Autores principales: Dehling, Tobias, Gao, Fangjian, Schneider, Stephan, Sunyaev, Ali
Formato: Online Artículo Texto
Lenguaje:English
Publicado: JMIR Publications Inc. 2015
Materias:
Acceso en línea:https://www.ncbi.nlm.nih.gov/pmc/articles/PMC4319144/
https://www.ncbi.nlm.nih.gov/pubmed/25599627
http://dx.doi.org/10.2196/mhealth.3672
_version_ 1782355912887894016
author Dehling, Tobias
Gao, Fangjian
Schneider, Stephan
Sunyaev, Ali
author_facet Dehling, Tobias
Gao, Fangjian
Schneider, Stephan
Sunyaev, Ali
author_sort Dehling, Tobias
collection PubMed
description BACKGROUND: Mobile health (mHealth) apps aim at providing seamless access to tailored health information technology and have the potential to alleviate global health burdens. Yet, they bear risks to information security and privacy because users need to reveal private, sensitive medical information to redeem certain benefits. Due to the plethora and diversity of available mHealth apps, implications for information security and privacy are unclear and complex. OBJECTIVE: The objective of this study was to establish an overview of mHealth apps offered on iOS and Android with a special focus on potential damage to users through information security and privacy infringements. METHODS: We assessed apps available in English and offered in the categories “Medical” and “Health & Fitness” in the iOS and Android App Stores. Based on the information retrievable from the app stores, we established an overview of available mHealth apps, tagged apps to make offered information machine-readable, and clustered the discovered apps to identify and group similar apps. Subsequently, information security and privacy implications were assessed based on health specificity of information available to apps, potential damage through information leaks, potential damage through information manipulation, potential damage through information loss, and potential value of information to third parties. RESULTS: We discovered 24,405 health-related apps (iOS; 21,953; Android; 2452). Absence or scarceness of ratings for 81.36% (17,860/21,953) of iOS and 76.14% (1867/2452) of Android apps indicates that less than a quarter of mHealth apps are in more or less widespread use. Clustering resulted in 245 distinct clusters, which were consolidated into 12 app archetypes grouping clusters with similar assessments of potential damage through information security and privacy infringements. There were 6426 apps that were excluded during clustering. The majority of apps (95.63%, 17,193/17,979; of apps) pose at least some potential damage through information security and privacy infringements. There were 11.67% (2098/17,979) of apps that scored the highest assessments of potential damages. CONCLUSIONS: Various kinds of mHealth apps collect and offer critical, sensitive, private medical information, calling for a special focus on information security and privacy of mHealth apps. In order to foster user acceptance and trust, appropriate security measures and processes need to be devised and employed so that users can benefit from seamlessly accessible, tailored mHealth apps without exposing themselves to the serious repercussions of information security and privacy infringements.
format Online
Article
Text
id pubmed-4319144
institution National Center for Biotechnology Information
language English
publishDate 2015
publisher JMIR Publications Inc.
record_format MEDLINE/PubMed
spelling pubmed-43191442015-02-13 Exploring the Far Side of Mobile Health: Information Security and Privacy of Mobile Health Apps on iOS and Android Dehling, Tobias Gao, Fangjian Schneider, Stephan Sunyaev, Ali JMIR Mhealth Uhealth Original Paper BACKGROUND: Mobile health (mHealth) apps aim at providing seamless access to tailored health information technology and have the potential to alleviate global health burdens. Yet, they bear risks to information security and privacy because users need to reveal private, sensitive medical information to redeem certain benefits. Due to the plethora and diversity of available mHealth apps, implications for information security and privacy are unclear and complex. OBJECTIVE: The objective of this study was to establish an overview of mHealth apps offered on iOS and Android with a special focus on potential damage to users through information security and privacy infringements. METHODS: We assessed apps available in English and offered in the categories “Medical” and “Health & Fitness” in the iOS and Android App Stores. Based on the information retrievable from the app stores, we established an overview of available mHealth apps, tagged apps to make offered information machine-readable, and clustered the discovered apps to identify and group similar apps. Subsequently, information security and privacy implications were assessed based on health specificity of information available to apps, potential damage through information leaks, potential damage through information manipulation, potential damage through information loss, and potential value of information to third parties. RESULTS: We discovered 24,405 health-related apps (iOS; 21,953; Android; 2452). Absence or scarceness of ratings for 81.36% (17,860/21,953) of iOS and 76.14% (1867/2452) of Android apps indicates that less than a quarter of mHealth apps are in more or less widespread use. Clustering resulted in 245 distinct clusters, which were consolidated into 12 app archetypes grouping clusters with similar assessments of potential damage through information security and privacy infringements. There were 6426 apps that were excluded during clustering. The majority of apps (95.63%, 17,193/17,979; of apps) pose at least some potential damage through information security and privacy infringements. There were 11.67% (2098/17,979) of apps that scored the highest assessments of potential damages. CONCLUSIONS: Various kinds of mHealth apps collect and offer critical, sensitive, private medical information, calling for a special focus on information security and privacy of mHealth apps. In order to foster user acceptance and trust, appropriate security measures and processes need to be devised and employed so that users can benefit from seamlessly accessible, tailored mHealth apps without exposing themselves to the serious repercussions of information security and privacy infringements. JMIR Publications Inc. 2015-01-19 /pmc/articles/PMC4319144/ /pubmed/25599627 http://dx.doi.org/10.2196/mhealth.3672 Text en ©Tobias Dehling, Fangjian Gao, Stephan Schneider, Ali Sunyaev. Originally published in JMIR Mhealth and Uhealth (http://mhealth.jmir.org), 19.01.2015. http://creativecommons.org/licenses/by/2.0/ This is an open-access article distributed under the terms of the Creative Commons Attribution License (http://creativecommons.org/licenses/by/2.0/), which permits unrestricted use, distribution, and reproduction in any medium, provided the original work, first published in JMIR mhealth and uhealth, is properly cited. The complete bibliographic information, a link to the original publication on http://mhealth.jmir.org/, as well as this copyright and license information must be included.
spellingShingle Original Paper
Dehling, Tobias
Gao, Fangjian
Schneider, Stephan
Sunyaev, Ali
Exploring the Far Side of Mobile Health: Information Security and Privacy of Mobile Health Apps on iOS and Android
title Exploring the Far Side of Mobile Health: Information Security and Privacy of Mobile Health Apps on iOS and Android
title_full Exploring the Far Side of Mobile Health: Information Security and Privacy of Mobile Health Apps on iOS and Android
title_fullStr Exploring the Far Side of Mobile Health: Information Security and Privacy of Mobile Health Apps on iOS and Android
title_full_unstemmed Exploring the Far Side of Mobile Health: Information Security and Privacy of Mobile Health Apps on iOS and Android
title_short Exploring the Far Side of Mobile Health: Information Security and Privacy of Mobile Health Apps on iOS and Android
title_sort exploring the far side of mobile health: information security and privacy of mobile health apps on ios and android
topic Original Paper
url https://www.ncbi.nlm.nih.gov/pmc/articles/PMC4319144/
https://www.ncbi.nlm.nih.gov/pubmed/25599627
http://dx.doi.org/10.2196/mhealth.3672
work_keys_str_mv AT dehlingtobias exploringthefarsideofmobilehealthinformationsecurityandprivacyofmobilehealthappsoniosandandroid
AT gaofangjian exploringthefarsideofmobilehealthinformationsecurityandprivacyofmobilehealthappsoniosandandroid
AT schneiderstephan exploringthefarsideofmobilehealthinformationsecurityandprivacyofmobilehealthappsoniosandandroid
AT sunyaevali exploringthefarsideofmobilehealthinformationsecurityandprivacyofmobilehealthappsoniosandandroid