Cargando…
Data sharing practices of medicines related apps and the mobile ecosystem: traffic, content, and network analysis
OBJECTIVES: To investigate whether and how user data are shared by top rated medicines related mobile applications (apps) and to characterise privacy risks to app users, both clinicians and consumers. DESIGN: Traffic, content, and network analysis. SETTING: Top rated medicines related apps for the A...
Autores principales: | , , , , , |
---|---|
Formato: | Online Artículo Texto |
Lenguaje: | English |
Publicado: |
BMJ Publishing Group Ltd.
2019
|
Materias: | |
Acceso en línea: | https://www.ncbi.nlm.nih.gov/pmc/articles/PMC6425456/ https://www.ncbi.nlm.nih.gov/pubmed/30894349 http://dx.doi.org/10.1136/bmj.l920 |
_version_ | 1783404848954212352 |
---|---|
author | Grundy, Quinn Chiu, Kellia Held, Fabian Continella, Andrea Bero, Lisa Holz, Ralph |
author_facet | Grundy, Quinn Chiu, Kellia Held, Fabian Continella, Andrea Bero, Lisa Holz, Ralph |
author_sort | Grundy, Quinn |
collection | PubMed |
description | OBJECTIVES: To investigate whether and how user data are shared by top rated medicines related mobile applications (apps) and to characterise privacy risks to app users, both clinicians and consumers. DESIGN: Traffic, content, and network analysis. SETTING: Top rated medicines related apps for the Android mobile platform available in the Medical store category of Google Play in the United Kingdom, United States, Canada, and Australia. PARTICIPANTS: 24 of 821 apps identified by an app store crawling program. Included apps pertained to medicines information, dispensing, administration, prescribing, or use, and were interactive. INTERVENTIONS: Laboratory based traffic analysis of each app downloaded onto a smartphone, simulating real world use with four dummy scripts. The app’s baseline traffic related to 28 different types of user data was observed. To identify privacy leaks, one source of user data was modified and deviations in the resulting traffic observed. MAIN OUTCOME MEASURES: Identities and characterisation of entities directly receiving user data from sampled apps. Secondary content analysis of company websites and privacy policies identified data recipients’ main activities; network analysis characterised their data sharing relations. RESULTS: 19/24 (79%) of sampled apps shared user data. 55 unique entities, owned by 46 parent companies, received or processed app user data, including developers and parent companies (first parties) and service providers (third parties). 18 (33%) provided infrastructure related services such as cloud services. 37 (67%) provided services related to the collection and analysis of user data, including analytics or advertising, suggesting heightened privacy risks. Network analysis revealed that first and third parties received a median of 3 (interquartile range 1-6, range 1-24) unique transmissions of user data. Third parties advertised the ability to share user data with 216 “fourth parties”; within this network (n=237), entities had access to a median of 3 (interquartile range 1-11, range 1-140) unique transmissions of user data. Several companies occupied central positions within the network with the ability to aggregate and re-identify user data. CONCLUSIONS: Sharing of user data is routine, yet far from transparent. Clinicians should be conscious of privacy risks in their own use of apps and, when recommending apps, explain the potential for loss of privacy as part of informed consent. Privacy regulation should emphasise the accountabilities of those who control and process user data. Developers should disclose all data sharing practices and allow users to choose precisely what data are shared and with whom. |
format | Online Article Text |
id | pubmed-6425456 |
institution | National Center for Biotechnology Information |
language | English |
publishDate | 2019 |
publisher | BMJ Publishing Group Ltd. |
record_format | MEDLINE/PubMed |
spelling | pubmed-64254562019-04-05 Data sharing practices of medicines related apps and the mobile ecosystem: traffic, content, and network analysis Grundy, Quinn Chiu, Kellia Held, Fabian Continella, Andrea Bero, Lisa Holz, Ralph BMJ Research OBJECTIVES: To investigate whether and how user data are shared by top rated medicines related mobile applications (apps) and to characterise privacy risks to app users, both clinicians and consumers. DESIGN: Traffic, content, and network analysis. SETTING: Top rated medicines related apps for the Android mobile platform available in the Medical store category of Google Play in the United Kingdom, United States, Canada, and Australia. PARTICIPANTS: 24 of 821 apps identified by an app store crawling program. Included apps pertained to medicines information, dispensing, administration, prescribing, or use, and were interactive. INTERVENTIONS: Laboratory based traffic analysis of each app downloaded onto a smartphone, simulating real world use with four dummy scripts. The app’s baseline traffic related to 28 different types of user data was observed. To identify privacy leaks, one source of user data was modified and deviations in the resulting traffic observed. MAIN OUTCOME MEASURES: Identities and characterisation of entities directly receiving user data from sampled apps. Secondary content analysis of company websites and privacy policies identified data recipients’ main activities; network analysis characterised their data sharing relations. RESULTS: 19/24 (79%) of sampled apps shared user data. 55 unique entities, owned by 46 parent companies, received or processed app user data, including developers and parent companies (first parties) and service providers (third parties). 18 (33%) provided infrastructure related services such as cloud services. 37 (67%) provided services related to the collection and analysis of user data, including analytics or advertising, suggesting heightened privacy risks. Network analysis revealed that first and third parties received a median of 3 (interquartile range 1-6, range 1-24) unique transmissions of user data. Third parties advertised the ability to share user data with 216 “fourth parties”; within this network (n=237), entities had access to a median of 3 (interquartile range 1-11, range 1-140) unique transmissions of user data. Several companies occupied central positions within the network with the ability to aggregate and re-identify user data. CONCLUSIONS: Sharing of user data is routine, yet far from transparent. Clinicians should be conscious of privacy risks in their own use of apps and, when recommending apps, explain the potential for loss of privacy as part of informed consent. Privacy regulation should emphasise the accountabilities of those who control and process user data. Developers should disclose all data sharing practices and allow users to choose precisely what data are shared and with whom. BMJ Publishing Group Ltd. 2019-03-20 /pmc/articles/PMC6425456/ /pubmed/30894349 http://dx.doi.org/10.1136/bmj.l920 Text en Published by the BMJ Publishing Group Limited. For permission to use (where not already granted under a licence) please go to http://group.bmj.com/group/rights-licensing/permissions This is an Open Access article distributed in accordance with the Creative Commons Attribution Non Commercial (CC BY-NC 4.0) license, which permits others to distribute, remix, adapt, build upon this work non-commercially, and license their derivative works on different terms, provided the original work is properly cited and the use is non-commercial. See: http://creativecommons.org/licenses/by-nc/4.0/. |
spellingShingle | Research Grundy, Quinn Chiu, Kellia Held, Fabian Continella, Andrea Bero, Lisa Holz, Ralph Data sharing practices of medicines related apps and the mobile ecosystem: traffic, content, and network analysis |
title | Data sharing practices of medicines related apps and the mobile ecosystem: traffic, content, and network analysis |
title_full | Data sharing practices of medicines related apps and the mobile ecosystem: traffic, content, and network analysis |
title_fullStr | Data sharing practices of medicines related apps and the mobile ecosystem: traffic, content, and network analysis |
title_full_unstemmed | Data sharing practices of medicines related apps and the mobile ecosystem: traffic, content, and network analysis |
title_short | Data sharing practices of medicines related apps and the mobile ecosystem: traffic, content, and network analysis |
title_sort | data sharing practices of medicines related apps and the mobile ecosystem: traffic, content, and network analysis |
topic | Research |
url | https://www.ncbi.nlm.nih.gov/pmc/articles/PMC6425456/ https://www.ncbi.nlm.nih.gov/pubmed/30894349 http://dx.doi.org/10.1136/bmj.l920 |
work_keys_str_mv | AT grundyquinn datasharingpracticesofmedicinesrelatedappsandthemobileecosystemtrafficcontentandnetworkanalysis AT chiukellia datasharingpracticesofmedicinesrelatedappsandthemobileecosystemtrafficcontentandnetworkanalysis AT heldfabian datasharingpracticesofmedicinesrelatedappsandthemobileecosystemtrafficcontentandnetworkanalysis AT continellaandrea datasharingpracticesofmedicinesrelatedappsandthemobileecosystemtrafficcontentandnetworkanalysis AT berolisa datasharingpracticesofmedicinesrelatedappsandthemobileecosystemtrafficcontentandnetworkanalysis AT holzralph datasharingpracticesofmedicinesrelatedappsandthemobileecosystemtrafficcontentandnetworkanalysis |