Security and Privacy of Digital Mental Health: An Analysis of Web Services and Mobile Applications

被引:3
作者
Surani, Aishwarya [1 ]
Bawaked, Amani [1 ]
Wheeler, Matthew [1 ]
Kelsey, Braden [1 ]
Roberts, Nicolette [1 ]
Vincent, David [1 ]
Das, Sanchari [1 ]
机构
[1] Univ Denver, Denver, CO 80208 USA
来源
DATA AND APPLICATIONS SECURITY AND PRIVACY XXXVII, DBSEC 2023 | 2023年 / 13942卷
关键词
Security and Privacy Analysis; Web Services; Mobile Applications; Mental Healthcare; Telehealth; TECHNOLOGY; ISSUES;
D O I
10.1007/978-3-031-37586-6_19
中图分类号
TP18 [人工智能理论];
学科分类号
081104 ; 0812 ; 0835 ; 1405 ;
摘要
In the wake of the COVID-19 pandemic, a rapid digital transformation has taken place in the mental healthcare sector, with a marked shift towards telehealth services on web and mobile platforms. This transition, while advantageous in many ways, raises critical questions regarding data security and user privacy given the sensitive nature of the information exchanged. To evaluate these concerns, we undertook a rigorous security and privacy examination of 48 web services and 39 mobile applications specific to mental healthcare, utilizing tools such as MobSF, RiskInDroid, AndroBugs, SSL Labs, and Privacy Check. We also delved into privacy policies, manually evaluating how user data is acquired, disseminated, and utilized by these services. Our investigation uncovered that although a handful of mental healthcare web services comply with expert security protocols, including SSL certification and solid authentication strategies, they often lack crucial privacy policy provisions. In contrast, mobile applications exhibit deficiencies in security and privacy best practices, including underdeveloped permission modeling, absence of superior encryption algorithms, and exposure to potential attacks such as Janus, Hash Collision, and SSL Security. This research underscores the urgency to bolster security and privacy safeguards in digital mental healthcare services, concluding with pragmatic recommendations to fortify the confidentiality and security of healthcare data for all users.
引用
收藏
页码:319 / 338
页数:20
相关论文
共 62 条
[1]  
Albrecht J.P., 2016, Eur Data Prot L Rev, V2, P287, DOI [DOI 10.21552/EDPL/2016/3/4, 10.21552/edpl/2016/3/4]
[2]  
Androbugs, Androbugs framework
[3]  
Aydin U., 2022, Ph.D. thesis
[4]   Fuzzing vulnerability discovery techniques: Survey, challenges and future directions [J].
Beaman, Craig ;
Redbourne, Michael ;
Mummery, J. Darren ;
Hakak, Saqib .
COMPUTERS & SECURITY, 2022, 120
[5]  
Camenisch J, 1997, LECT NOTES COMPUT SC, V1294, P410
[6]   Let the Cat out of the Bag: Popular Android IoT Apps under Security Scrutiny [J].
Chatzoglou, Efstratios ;
Kambourakis, Georgios ;
Smiliotopoulos, Christos .
SENSORS, 2022, 22 (02)
[7]   Bifocals: Analyzing WebView Vulnerabilities in Android Applications [J].
Chin, Erika ;
Wagner, David .
INFORMATION SECURITY APPLICATIONS, WISA 2013, 2014, 8267 :138-159
[8]   Veterans' Attitudes Toward Smartphone App Use for Mental Health Care: Qualitative Study of Rurality and Age Differences [J].
Connolly, Samantha L. ;
Miller, Christopher J. ;
Koenig, Christopher J. ;
Zamora, Kara A. ;
Wright, Patricia B. ;
Stanley, Regina L. ;
Pyne, Jeffrey M. .
JMIR MHEALTH AND UHEALTH, 2018, 6 (08)
[9]  
Crussell Jonathan C. H., 2013, Computer Security-ESORICS 2013, P182
[10]  
Das S., 2019, P 13 INT S HUM ASP I