Cargando…

Privacy and Usability in COVID Enrollment Apps

Enrollment apps for COVID-19 vaccinations are meant to be privacy-enhancing, but poor design puts privacy at risk. We report on a qualitative exploration of the experiences of older adults attempting to register for vaccination. We engaged in a think-aloud protocol with six participants over age 65...

Descripción completa

Detalles Bibliográficos
Autores principales: Calloway, Laura, Huber, Lesa, Camp, L Jean
Formato: Online Artículo Texto
Lenguaje:English
Publicado: Oxford University Press 2021
Materias:
Acceso en línea:https://www.ncbi.nlm.nih.gov/pmc/articles/PMC8680517/
http://dx.doi.org/10.1093/geroni/igab046.2488
_version_ 1784616764602056704
author Calloway, Laura
Huber, Lesa
Camp, L Jean
author_facet Calloway, Laura
Huber, Lesa
Camp, L Jean
author_sort Calloway, Laura
collection PubMed
description Enrollment apps for COVID-19 vaccinations are meant to be privacy-enhancing, but poor design puts privacy at risk. We report on a qualitative exploration of the experiences of older adults attempting to register for vaccination. We engaged in a think-aloud protocol with six participants over age 65 over Zoom as they used the New York state vaccination portal. Authentication requirements were: Medicare ID, DOB, address, and phone (optional). For this cohort, Social Security numbers were the default Medicare ID. We found that a privacy-enhanced authentication option exists, but efforts to use privacy-preserving enrollment were confounded by security-enhancing timeouts. Choosing to use the time-consuming privacy-preserving authentication increased the risk that available vaccines were taken. As a result, older adults reliant on volunteers to enroll revealed sensitive information and risked identity theft. A design that was meant to be privacy-enhancing by offering multiple avenues for authentication and ensuring logout via timeouts created a system where the more secure option was not effectively available due to a competing security mechanism. This was exacerbated by a counter counting down the number of vaccine sites available, similar to a well-known stress condition used to create cognitive load in laboratory experiments. All six participants used privacy-sensitive information to enroll; provided adequate information for identity theft; and all six encountered stop points. The countdown of available vaccination sites, the time required for insurance validation as an alternative to Medicare ID, and logging off after inactivity to prevent session theft each are good practices; but fail together.
format Online
Article
Text
id pubmed-8680517
institution National Center for Biotechnology Information
language English
publishDate 2021
publisher Oxford University Press
record_format MEDLINE/PubMed
spelling pubmed-86805172021-12-17 Privacy and Usability in COVID Enrollment Apps Calloway, Laura Huber, Lesa Camp, L Jean Innov Aging Abstracts Enrollment apps for COVID-19 vaccinations are meant to be privacy-enhancing, but poor design puts privacy at risk. We report on a qualitative exploration of the experiences of older adults attempting to register for vaccination. We engaged in a think-aloud protocol with six participants over age 65 over Zoom as they used the New York state vaccination portal. Authentication requirements were: Medicare ID, DOB, address, and phone (optional). For this cohort, Social Security numbers were the default Medicare ID. We found that a privacy-enhanced authentication option exists, but efforts to use privacy-preserving enrollment were confounded by security-enhancing timeouts. Choosing to use the time-consuming privacy-preserving authentication increased the risk that available vaccines were taken. As a result, older adults reliant on volunteers to enroll revealed sensitive information and risked identity theft. A design that was meant to be privacy-enhancing by offering multiple avenues for authentication and ensuring logout via timeouts created a system where the more secure option was not effectively available due to a competing security mechanism. This was exacerbated by a counter counting down the number of vaccine sites available, similar to a well-known stress condition used to create cognitive load in laboratory experiments. All six participants used privacy-sensitive information to enroll; provided adequate information for identity theft; and all six encountered stop points. The countdown of available vaccination sites, the time required for insurance validation as an alternative to Medicare ID, and logging off after inactivity to prevent session theft each are good practices; but fail together. Oxford University Press 2021-12-17 /pmc/articles/PMC8680517/ http://dx.doi.org/10.1093/geroni/igab046.2488 Text en © The Author(s) 2021. Published by Oxford University Press on behalf of The Gerontological Society of America. https://creativecommons.org/licenses/by/4.0/This is an Open Access article distributed under the terms of the Creative Commons Attribution License (http://creativecommons.org/licenses/by/4.0/ (https://creativecommons.org/licenses/by/4.0/) ), which permits unrestricted reuse, distribution, and reproduction in any medium, provided the original work is properly cited.
spellingShingle Abstracts
Calloway, Laura
Huber, Lesa
Camp, L Jean
Privacy and Usability in COVID Enrollment Apps
title Privacy and Usability in COVID Enrollment Apps
title_full Privacy and Usability in COVID Enrollment Apps
title_fullStr Privacy and Usability in COVID Enrollment Apps
title_full_unstemmed Privacy and Usability in COVID Enrollment Apps
title_short Privacy and Usability in COVID Enrollment Apps
title_sort privacy and usability in covid enrollment apps
topic Abstracts
url https://www.ncbi.nlm.nih.gov/pmc/articles/PMC8680517/
http://dx.doi.org/10.1093/geroni/igab046.2488
work_keys_str_mv AT callowaylaura privacyandusabilityincovidenrollmentapps
AT huberlesa privacyandusabilityincovidenrollmentapps
AT campljean privacyandusabilityincovidenrollmentapps