Unaddressed privacy risks in accredited health and wellness apps: a cross-sectional systematic assessment
نویسندگان
چکیده
BACKGROUND Poor information privacy practices have been identified in health apps. Medical app accreditation programs offer a mechanism for assuring the quality of apps; however, little is known about their ability to control information privacy risks. We aimed to assess the extent to which already-certified apps complied with data protection principles mandated by the largest national accreditation program. METHODS Cross-sectional, systematic, 6-month assessment of 79 apps certified as clinically safe and trustworthy by the UK NHS Health Apps Library. Protocol-based testing was used to characterize personal information collection, local-device storage and information transmission. Observed information handling practices were compared against privacy policy commitments. RESULTS The study revealed that 89% (n = 70/79) of apps transmitted information to online services. No app encrypted personal information stored locally. Furthermore, 66% (23/35) of apps sending identifying information over the Internet did not use encryption and 20% (7/35) did not have a privacy policy. Overall, 67% (53/79) of apps had some form of privacy policy. No app collected or transmitted information that a policy explicitly stated it would not; however, 78% (38/49) of information-transmitting apps with a policy did not describe the nature of personal information included in transmissions. Four apps sent both identifying and health information without encryption. Although the study was not designed to examine data handling after transmission to online services, security problems appeared to place users at risk of data theft in two cases. CONCLUSIONS Systematic gaps in compliance with data protection principles in accredited health apps question whether certification programs relying substantially on developer disclosures can provide a trusted resource for patients and clinicians. Accreditation programs should, as a minimum, provide consistent and reliable warnings about possible threats and, ideally, require publishers to rectify vulnerabilities before apps are released.
منابع مشابه
‘Trust but verify’ – five approaches to ensure safe medical apps
Mobile health apps are health and wellness programs available on mobile devices such as smartphones or tablets. In three systematic assessments published in BMC Medicine, Huckvale and colleagues demonstrate that widely available health apps meant to help patients calculate their appropriate insulin dosage, educate themselves about asthma, or perform other important functions are methodologicall...
متن کاملApps for Hearing Healthcare
The hearing healthcare scenario is rapidly evolving due to the pervasive use of m-Health solutions, in particular mobile apps. This brings along significant advantages and opportunities (e.g., accessibility, affordability, personalized healthcare, patient empowerment) as well as significant potential risks and threats (e.g., safety, misuse, quality issues, privacy). Our research aims at the ide...
متن کاملIdentifying Educational Contents and Technical Features of a Self-Management Smartphone Application for Women with Breast Cancer
Background and Objective: Breast cancer patients need a variety of skills and abilities to deal with the consequences of the illness. Self-management is one of the operational strategies that leads to disease acceptance, treatment adherence, and improving the quality of life. The use of smartphone applications (apps) can play a pivotal role in the support and self-management of breast cancer pa...
متن کاملA Longitudinal Study of PII Leaks Across Android App Versions
Is mobile privacy getting better or worse over time? In this paper, we address this question by studying privacy leaks from historical and current versions of 512 popular Android apps, covering 7,665 app releases over 8 years of app version history. Through automated and scripted interaction with apps and analysis of the network traffic they generate on real mobile devices, we identify how priv...
متن کاملMobile Apps for Bipolar Disorder: A Systematic Review of Features and Content Quality
BACKGROUND With continued increases in smartphone ownership, researchers and clinicians are investigating the use of this technology to enhance the management of chronic illnesses such as bipolar disorder (BD). Smartphones can be used to deliver interventions and psychoeducation, supplement treatment, and enhance therapeutic reach in BD, as apps are cost-effective, accessible, anonymous, and co...
متن کامل