Affiliations
AffiliationsItem in Clipboard
Unaddressed privacy risks in accredited health and wellness apps: a cross-sectional systematic assessmentKit Huckvale et al. BMC Med. 2015.
doi: 10.1186/s12916-015-0444-y. AffiliationsItem in Clipboard
AbstractBackground: Poor information privacy practices have been identified in health apps. Medical app accreditation programs offer a mechanism for assuring the quality of apps; however, little is known about their ability to control information privacy risks. We aimed to assess the extent to which already-certified apps complied with data protection principles mandated by the largest national accreditation program.
Methods: Cross-sectional, systematic, 6-month assessment of 79 apps certified as clinically safe and trustworthy by the UK NHS Health Apps Library. Protocol-based testing was used to characterize personal information collection, local-device storage and information transmission. Observed information handling practices were compared against privacy policy commitments.
Results: The study revealed that 89% (n = 70/79) of apps transmitted information to online services. No app encrypted personal information stored locally. Furthermore, 66% (23/35) of apps sending identifying information over the Internet did not use encryption and 20% (7/35) did not have a privacy policy. Overall, 67% (53/79) of apps had some form of privacy policy. No app collected or transmitted information that a policy explicitly stated it would not; however, 78% (38/49) of information-transmitting apps with a policy did not describe the nature of personal information included in transmissions. Four apps sent both identifying and health information without encryption. Although the study was not designed to examine data handling after transmission to online services, security problems appeared to place users at risk of data theft in two cases.
Conclusions: Systematic gaps in compliance with data protection principles in accredited health apps question whether certification programs relying substantially on developer disclosures can provide a trusted resource for patients and clinicians. Accreditation programs should, as a minimum, provide consistent and reliable warnings about possible threats and, ideally, require publishers to rectify vulnerabilities before apps are released.
FiguresFig. 1
A ‘man-in-the-middle’ attack. A man-in-the-middle…
Fig. 1
A ‘man-in-the-middle’ attack. A man-in-the-middle attack is able to intercept network traffic sent…
Fig. 1A ‘man-in-the-middle’ attack. A man-in-the-middle attack is able to intercept network traffic sent by a mobile app in a way that is invisible to users and services
Similar articlesHuckvale K, Torous J, Larsen ME. Huckvale K, et al. JAMA Netw Open. 2019 Apr 5;2(4):e192542. doi: 10.1001/jamanetworkopen.2019.2542. JAMA Netw Open. 2019. PMID: 31002321 Free PMC article.
Silva BM, Rodrigues JJ, Canelo F, Lopes IC, Zhou L. Silva BM, et al. J Med Internet Res. 2013 Apr 25;15(4):e66. doi: 10.2196/jmir.2498. J Med Internet Res. 2013. PMID: 23624056 Free PMC article.
Tangari G, Ikram M, Ijaz K, Kaafar MA, Berkovsky S. Tangari G, et al. BMJ. 2021 Jun 16;373:n1248. doi: 10.1136/bmj.n1248. BMJ. 2021. PMID: 34135009 Free PMC article.
Jiang J, Zheng Z. Jiang J, et al. JMIR Mhealth Uhealth. 2023 Nov 14;11:e48714. doi: 10.2196/48714. JMIR Mhealth Uhealth. 2023. PMID: 37990813 Free PMC article. Review.
Kolasa K, Mazzi F, Leszczuk-Czubkowska E, Zrubka Z, Péntek M. Kolasa K, et al. JMIR Mhealth Uhealth. 2021 Jun 10;9(6):e23250. doi: 10.2196/23250. JMIR Mhealth Uhealth. 2021. PMID: 34033581 Free PMC article. Review.
Bardus M, Al Daccache M, Maalouf N, Al Sarih R, Elhajj IH. Bardus M, et al. JMIR Mhealth Uhealth. 2022 Jul 12;10(7):e35195. doi: 10.2196/35195. JMIR Mhealth Uhealth. 2022. PMID: 35709334 Free PMC article.
Lukka L, Palva JM. Lukka L, et al. JMIR Serious Games. 2023 Sep 4;11:e42173. doi: 10.2196/42173. JMIR Serious Games. 2023. PMID: 37665624 Free PMC article.
Lupton D. Lupton D. Digit Health. 2019 Apr 29;5:2055207619847017. doi: 10.1177/2055207619847017. eCollection 2019 Jan-Dec. Digit Health. 2019. PMID: 31069106 Free PMC article.
Zhou L, Bao J, Watzlaf V, Parmanto B. Zhou L, et al. JMIR Mhealth Uhealth. 2019 Apr 16;7(4):e11223. doi: 10.2196/11223. JMIR Mhealth Uhealth. 2019. PMID: 30990458 Free PMC article.
Fernandez-Luque L, Al Herbish A, Al Shammari R, Argente J, Bin-Abbas B, Deeb A, Dixon D, Zary N, Koledova E, Savage MO. Fernandez-Luque L, et al. Front Pediatr. 2021 Jul 29;9:715705. doi: 10.3389/fped.2021.715705. eCollection 2021. Front Pediatr. 2021. PMID: 34395347 Free PMC article. Review.
RetroSearch is an open source project built by @garambo | Open a GitHub Issue
Search and Browse the WWW like it's 1997 | Search results from DuckDuckGo
HTML:
3.2
| Encoding:
UTF-8
| Version:
0.7.3