Javascript must be enabled to continue!
Privacy and Security for Digital Health: Assessing Risks and Harms to Users
View through CrossRef
Electronic Health (e-Health), such as mobile health (mHealth) and Health Information Systems (HIS), benefits healthcare consumers and professionals. However, it also poses potential privacy risks, as security, privacy, and human factors remain challenges in the rapid digitization of healthcare. Considering an impact assessment of the planned processing helps identify and prevent privacy risks early in the development of digital health technologies. When such risks are exploited, they can result in various privacy harms to individuals, including physical, psychological, financial, reputational, and societal harms. This thesis deals with the overarching objective of analyzing security and privacy risks in health-related systems. Specifically, it focuses on four main topics: (i.) the analysis of a selected category of mHealth apps, specifically, COVID-19 contact tracing apps; (ii.) the exploration of the potential impact on the privacy of patients in the context of cyberwar; (iii.) identification and modeling of privacy harms after a healthcare data breach; and, (iv.) an assessment of whether privacy harms enhance privacy risk assessments. It incorporates empirical methods, including in-depth document analysis through narrative reviews and a systematic literature review. A qualitative approach is also applied, using semi-structured interviews and a privacy risk assessment (PRA) exercise. Our results show that rapidly developed digital health apps present security and privacy risks that could impact healthcare consumers' privacy. While integrating Information and Communications Technology (ICT) in healthcare is advantageous, it also introduces new risks. State-sponsored attackers may exploit these risks, potentially causing privacy harm to healthcare service users. We identify actual privacy impacts and use this to model privacy harms by modifying a PRA methodology. In addition to identifying methods for evaluating Privacy Impact Assessments (PIAs) and PRAs, we assess the coverage of privacy harms within these existing methodologies. Furthermore, we gain insight into the operationalization of privacy harms from practitioners and how this improves PRAs. Among the main contributions, the research creates an awareness of the risks associated with a lack of data protection mechanisms, and data breaches as well as their impact on patient privacy. In addition, a comprehensive systematic literature review on PIAs and PRAs was conducted, which led us to focus on operationalizing privacy harms that can be integrated into PRAs to assess the impact on the privacy of healthcare consumers. As a result, privacy experts and IT practitioners in healthcare will be better informed and guided in understanding privacy harms during privacy risk assessments. This ensures that appropriate safeguards are in place to prevent the materialization of actual privacy harms
Title: Privacy and Security for Digital Health: Assessing Risks and Harms to Users
Description:
Electronic Health (e-Health), such as mobile health (mHealth) and Health Information Systems (HIS), benefits healthcare consumers and professionals.
However, it also poses potential privacy risks, as security, privacy, and human factors remain challenges in the rapid digitization of healthcare.
Considering an impact assessment of the planned processing helps identify and prevent privacy risks early in the development of digital health technologies.
When such risks are exploited, they can result in various privacy harms to individuals, including physical, psychological, financial, reputational, and societal harms.
This thesis deals with the overarching objective of analyzing security and privacy risks in health-related systems.
Specifically, it focuses on four main topics: (i.
) the analysis of a selected category of mHealth apps, specifically, COVID-19 contact tracing apps; (ii.
) the exploration of the potential impact on the privacy of patients in the context of cyberwar; (iii.
) identification and modeling of privacy harms after a healthcare data breach; and, (iv.
) an assessment of whether privacy harms enhance privacy risk assessments.
It incorporates empirical methods, including in-depth document analysis through narrative reviews and a systematic literature review.
A qualitative approach is also applied, using semi-structured interviews and a privacy risk assessment (PRA) exercise.
Our results show that rapidly developed digital health apps present security and privacy risks that could impact healthcare consumers' privacy.
While integrating Information and Communications Technology (ICT) in healthcare is advantageous, it also introduces new risks.
State-sponsored attackers may exploit these risks, potentially causing privacy harm to healthcare service users.
We identify actual privacy impacts and use this to model privacy harms by modifying a PRA methodology.
In addition to identifying methods for evaluating Privacy Impact Assessments (PIAs) and PRAs, we assess the coverage of privacy harms within these existing methodologies.
Furthermore, we gain insight into the operationalization of privacy harms from practitioners and how this improves PRAs.
Among the main contributions, the research creates an awareness of the risks associated with a lack of data protection mechanisms, and data breaches as well as their impact on patient privacy.
In addition, a comprehensive systematic literature review on PIAs and PRAs was conducted, which led us to focus on operationalizing privacy harms that can be integrated into PRAs to assess the impact on the privacy of healthcare consumers.
As a result, privacy experts and IT practitioners in healthcare will be better informed and guided in understanding privacy harms during privacy risk assessments.
This ensures that appropriate safeguards are in place to prevent the materialization of actual privacy harms.
Related Results
Estimating the Likely Harms from Global Warming: A Fresh Look at Accounting for Adaptation and Resilience, and Recommendations for a Bottom-Up Approach
Estimating the Likely Harms from Global Warming: A Fresh Look at Accounting for Adaptation and Resilience, and Recommendations for a Bottom-Up Approach
We urgently need to determine a reasonable ballpark estimate for the likely harms from global warming before we commit to a set of mitigation policies, because aggressive mitigatio...
THE SECURITY AND PRIVACY MEASURING SYSTEM FOR THE INTERNET OF THINGS DEVICES
THE SECURITY AND PRIVACY MEASURING SYSTEM FOR THE INTERNET OF THINGS DEVICES
The purpose of the article: elimination of the gap in existing need in the set of clear and objective security and privacy metrics for the IoT devices users and manufacturers and a...
The Right to Data Privacy: Revisiting Warren & Brandeis
The Right to Data Privacy: Revisiting Warren & Brandeis
Warren and Brandeis in their famous 1890 article The Right to Privacy found privacy as an implicit right within existing law. Regarded as perhaps the most influential legal essay ...
Access Denied
Access Denied
Introduction
As social-distancing mandates in response to COVID-19 restricted in-person data collection methods such as participant observation and interviews, researchers turned t...
Information Security in Artificial Intelligence: A Study of the possible intersection
Information Security in Artificial Intelligence: A Study of the possible intersection
1. IntroductionArtificial Intelligence or A.I attempts to understand intelligent entities, and strives to build ones. And it is obvious that computers with human-level intelligence...
Effects of Webtechnologies on Privacy
Effects of Webtechnologies on Privacy
The rapid development of web technologies has brought many benefits to society, including increased access to information and services.However, these technologies have also raised ...
Multimodal Emotion Recognition and Human Computer Interaction for AI-Driven Mental Health Support (Preprint)
Multimodal Emotion Recognition and Human Computer Interaction for AI-Driven Mental Health Support (Preprint)
BACKGROUND
Mental health has become one of the most urgent global health issues of the twenty-first century. The World Health Organization (WHO) reports tha...
Privacy Risk in Recommender Systems
Privacy Risk in Recommender Systems
Nowadays, recommender systems are mostly used in many online applications to filter information and help users in selecting their relevant requirements. It avoids users to become o...

