Mobile Health Applications Put the Personal Data of Millions of Users at Risk

80% of the most popular health applications available on Android do not comply with standards intended to prevent the misuse and dissemination of their users' data. This is the finding of a European study started in 2016 and involving Agustí Solanas, head of the Smart Health research group at the URV's Department of Computer Engineering and Mathematics, and researchers from the University of Piraeus (Greece) headed by Constantinos Patsakis. The research has brought to light evidence of serious security problems regarding the twenty most popular applications on the internet. The research consisted of analysing the security problems, communicating them to the software developers and then checking them to see if they had been resolved.

The applications chosen by the researchers had been downloaded between 100,000 and 10 million times and had a minimum rating of 3.5 out of 5. To analyse their levels of security, the researchers intercepted, stored and monitored private data relating to users' health problems, illnesses and medical records. The researchers analysed how the applications communicated, how they stored information, which permissions they required to operate, and how they handled the data. The results showed the existence of serious security problems in the way users' data were handled.

Only 20% of the applications stored the data on the user's smartphone, and one in two requested and administered passwords without using a secure connection. The researchers also found that 50% of the applications shared data with third parties, including text, multimedia content or X-ray images.

More than half transferred users' health data via HTTP links, which means that anybody with access can get their hands on the data. 20% of the applications did not inform the user of any privacy policy or the content was not available in English, the language of the application. Others requested access to geolocation, microphones, cameras, contact lists, external storage cards and Bluetooth, even though the application did not need access to these data to operate.

Information for businesses

On completing the analysis, the researchers contacted the software developers to inform them of the security problems. After waiting for a given period, they then analysed the same parameters and found that although some of the security issues had been fixed (e.g. insecure health data transfers or the ability to identify users via insecure data transfers to third parties), other problems such as data leaks regarding the use of the application had not been resolved.

The research has been partially funded by the European OPERANDO project (as part of the H2020 programme) and has also received funding from the COST programme (Cooperation in Science and Technology) through Acció Cryptacus.

A Papageorgiou, M Strigkos, E Politou, E Alepis, A Solanas, C Patsakis.
Security and Privacy Analysis of Mobile Health Applications: The Alarming State of Practice.
IEEE Explore. DOI: 10.1109/ACCESS.2018.2799522.

Most Popular Now

Patient Safety must be Central to the De…

An EPR system brings together different patient information in one place, making it easier to access for healthcare professionals. This information can include patients' own notes, test results, observations by...

ChatGPT Shows Promise in Answering Patie…

The groundbreaking ChatGPT chatbot shows potential as a time-saving tool for responding to patient questions sent to the urologist's office, suggests a study in the September issue of Urology Practice®...

Survey: Most Americans Comfortable with …

Artificial intelligence (AI) is all around us - from smart home devices to entertainment and social media algorithms. But is AI okay in healthcare? A new national survey commissioned by...

AI Spots Cancer and Viral Infections at …

Researchers at the Centre for Genomic Regulation (CRG), the University of the Basque Country (UPV/EHU), Donostia International Physics Center (DIPC) and the Fundación Biofisica Bizkaia (FBB, located in Biofisika Institute)...

Video Gaming Improves Mental Well-Being

A pioneering study titled "Causal effect of video gaming on mental well-being in Japan 2020-2022," published in Nature Human Behaviour, has conducted the most comprehensive investigation to date on the...

Machine learning helps identify rheumato…

A machine-learning tool created by Weill Cornell Medicine and Hospital for Special Surgery (HSS) investigators can help distinguish subtypes of rheumatoid arthritis (RA), which may help scientists find ways to...

New Diabetes Research Links Blood Glucos…

As part of its ongoing exploration of vocal biomarkers and the role they can play in enhancing health outcomes, Klick Labs published a new study in Scientific Reports - confirming...

New AI Software could Make Diagnosing De…

Although Alzheimer's is the most common cause of dementia - a catchall term for cognitive deficits that impact daily living, like the loss of memory or language - it's not...

A New AI Tool for Cancer

Scientists at Harvard Medical School have designed a versatile, ChatGPT-like AI model capable of performing an array of diagnostic tasks across multiple forms of cancers. The new AI system, described Sept...

Vision-Based ChatGPT Shows Deficits Inte…

Researchers evaluating the performance of ChatGPT-4 Vision found that the model performed well on text-based radiology exam questions but struggled to answer image-related questions accurately. The study's results were published...

Bayer Launches New Healthy-Aging Ecosyst…

Combining a scientifically formulated dietary supplement, a leading-edge wellness companion app, and a saliva-based a biological age test by Chronomics, Bayer is taking a big step in the emerging healthy-aging...

New AI-Driven Tool could Revolutionize B…

Researchers at the Icahn School of Medicine at Mount Sinai have developed a noninvasive technique that could dramatically improve the way doctors monitor intracranial hypertension, a condition where increased pressure...