Analyzing third-party data leaks on online pharmacy websites

被引:1
作者
Rauti, Sampsa [1 ]
Carlsson, Robin [1 ]
Mickelsson, Sini [2 ]
Makila, Tuomas [1 ]
Heino, Timi [1 ]
Pirjatanniemi, Elina [3 ]
Leppanen, Ville [1 ]
机构
[1] Univ Turku, Dept Comp, Turku, Finland
[2] Univ Turku, Fac Law, Turku, Finland
[3] Abo Akad Univ, Inst Human Rights, Turku, Finland
基金
芬兰科学院;
关键词
Online pharmacies; Data leaks; Web privacy; Data concerning health; Sensitive data; COMMUNITY PHARMACY; HEALTH DATA; PRIVACY; WIDESPREAD; ACCESS;
D O I
10.1007/s12553-024-00819-w
中图分类号
R-058 [];
学科分类号
摘要
PurposeWith digitalization, using essential digital services such as online services has become increasingly common. These services process sensitive health related data, such as customers' prescription medicine orders, which makes ensuring stringent data privacy crucial. The current study examines third parties such as analytics services on Finnish pharmacy websites and investigates the nature and contents of data leaks on these websites.MethodsWe perform an extensive network traffic analysis to reveal data leaks among 163 Finnish online pharmacies. We also study a set of privacy policies of these online pharmacies, and provide a legal analysis regarding the interpretation of the concept of data concerning health in the context of online pharmacies.ResultsOur findings reveal serious data leaks among Finnish online pharmacies. We found 145 pharmacies had third-party services on their websites and only 18 did not. Out of all 163 online pharmacies, 57 (35.0 %) leaked a specific prescription medicine name connected with identifying personal data on the customer. We argue that the information concerning purchases on the prescription medicines should be interpreted as data concerning health to ensure efficient protection of customers' right to data protection and privacy.ConclusionsWe hope that these concerning results will serve as a wake-up call for the developers and maintainers of online pharmacies and other web services processing sensitive data. Any third-party services incorporated into websites processing sensitive personal data should be closely inspected in terms of data leaks, or preferably not used at all.
引用
收藏
页码:375 / 392
页数:18
相关论文
共 65 条
  • [1] The Challenges and Opportunities in the Digitalization of Companies in a Post-COVID-19 World
    Almeida F.
    Duarte Santos J.
    Augusto Monteiro J.
    [J]. IEEE Engineering Management Review, 2020, 48 (03): : 97 - 103
  • [2] A detailed analysis of online pharmacy characteristics to inform safe usage by patients
    Alwon, Bassam M.
    Solomon, Gennifer
    Hussain, Faseeha
    Wright, David J.
    [J]. INTERNATIONAL JOURNAL OF CLINICAL PHARMACY, 2015, 37 (01) : 148 - 158
  • [3] Feedback from community pharmacy users on the contribution of community pharmacy to improving the public's health: a systematic review of the peer reviewed and non-peer reviewed titerature 1990-2002
    Anderson, C
    Blenkinsopp, A
    Armstrong, M
    [J]. HEALTH EXPECTATIONS, 2004, 7 (03) : 191 - 202
  • [4] [Anonymous], C 184 20 VYRIAUSIOJI
  • [5] [Anonymous], 2005, CASE T 105 03 TRIANT
  • [6] [Anonymous], 2016, Case C-582/14,Patrick Breyer v. Bundesrepublik Deutschland
  • [7] [Anonymous], 2003, CASE C 101 01 CRIMIN
  • [8] [Anonymous], 2023, C 252 21 METAPLATFOR
  • [9] [Anonymous], 2017, C 434 16 P NOWAK DAT
  • [10] [Anonymous], 2015, T 343 13 CN EUROPEAN