On the Privacy of Mental Health Apps: An Empirical Investigation and its Implications for Apps Development

01/22/2022
by   Leonardo Horn Iwaya, et al.
0

An increasing number of mental health services are offered through mobile systems, a paradigm called mHealth. Although there is an unprecedented growth in the adoption of mHealth systems, partly due to the COVID-19 pandemic, concerns about data privacy risks due to security breaches are also increasing. Whilst some studies have analyzed mHealth apps from different angles, including security, there is relatively little evidence for data privacy issues that may exist in mHealth apps used for mental health services, whose recipients can be particularly vulnerable. This paper reports an empirical study aimed at systematically identifying and understanding data privacy incorporated in mental health apps. We analyzed 27 top-ranked mental health apps from Google Play Store. Our methodology enabled us to perform an in-depth privacy analysis of the apps, covering static and dynamic analysis, data sharing behaviour, server-side tests, privacy impact assessment requests, and privacy policy evaluation. Furthermore, we mapped the findings to the LINDDUN threat taxonomy, describing how threats manifest on the studied apps. The findings reveal important data privacy issues such as unnecessary permissions, insecure cryptography implementations, and leaks of personal data and credentials in logs and web requests. There is also a high risk of user profiling as the apps' development do not provide foolproof mechanisms against linkability, detectability and identifiability. Data sharing among third parties and advertisers in the current apps' ecosystem aggravates this situation. Based on the empirical findings of this study, we provide recommendations to be considered by different stakeholders of mHealth apps in general and apps developers in particular. [...]

READ FULL TEXT

page 5

page 9

page 15

research
06/21/2022

Mobile Mental Health Apps: Alternative Intervention or Intrusion?

Mental health is an extremely important subject, especially in these unp...
research
10/10/2022

Systematic Evaluation and User Study of Privacy of Default Apps in Apple's Mobile Ecosystem

Users need to configure default apps when they first start using their d...
research
08/07/2020

An Empirical Study on Developing Secure Mobile Health Apps: The Developers Perspective

Mobile apps exploit embedded sensors and wireless connectivity of a devi...
research
08/29/2020

Security Awareness of End-Users of Mobile Health Applications: An Empirical Study

Mobile systems offer portable and interactive computing, empowering user...
research
03/01/2021

COVID-19 vs Social Media Apps: Does Privacy Really Matter?

Many people around the world are worried about using or even downloading...
research
05/28/2021

Saudi Parents' Security and Privacy Concerns about their Children's Smart Device Applications

In this paper, we investigate Saudi parents' security and privacy concer...
research
01/21/2021

Personalised Recommendations in Mental Health Apps: The Impact of Autonomy and Data Sharing

The recent growth of digital interventions for mental well-being prompts...

Please sign up or login with your details

Forgot password? Click here to reset