Data sharing practices of medicines related apps and the mobile ecosystem: traffic, content, and network analysis

Data sharing practices of medicines related apps and the mobile ecosystem: traffic, content, and network analysis
复制标题

DOI:
10.1136/bmj.l920
复制
发表时间:
2019-03-20
影响因子:
105.7
通讯作者:
Holz, Ralph
Holz, Ralph
中科院分区:
医学1区
文献类型:
--
作者:
Grundy, Quinn;Chiu, Kellia;Holz, Ralph

文献摘要

被引文献

相似文献

调查用户数据是否以及如何被高评价的药品相关移动的应用程序(app)共享,并消除app用户(包括临床医生和消费者)的隐私风险。分析流量、内容和网络分析。设置在英国、美国、加拿大的Google Play医疗商店类别中提供的Android移动的平台上的高评价药品相关app,和澳大利亚。参与者通过应用程序商店爬行程序识别的821个应用程序中的24个。包括与药物信息、配药、管理、处方或使用有关的应用程序,并且是交互式的。干预对下载到智能手机上的每个应用程序进行基于实验室的流量分析,用四个虚拟脚本模拟真实的世界使用。该应用程序的基线流量与28种不同类型的用户数据有关。为了识别隐私泄露,修改了用户数据的一个来源,并观察了由此产生的流量偏差。主要结果测量直接从抽样应用程序接收用户数据的实体的身份和特征。对公司网站和隐私政策的二级内容分析确定了数据接收者的主要活动;网络分析描述了他们的数据共享关系。46家母公司拥有的55个独特实体接收或处理了应用程序用户数据,包括开发商和母公司(第一方)以及服务提供商(第三方)。18家(33%)提供基础设施相关服务,如云服务。37家公司(67%)提供与收集和分析用户数据相关的服务,包括分析或广告,这表明隐私风险增加。网络分析显示,第一方和第三方收到的用户数据的唯一传输的中位数为3(四分位数范围1-6,范围1-24)。第三方宣传与216个“第四方”共享用户数据的能力;在这个网络中(n= 237),实体可以访问中位数为3(四分位数范围1-11,范围1-140)的用户数据唯一传输。有几家公司占据了网络内的中心位置,有能力聚集和重新识别用户数据。临床医生应该意识到自己使用应用程序的隐私风险,并在推荐应用程序时,解释作为知情同意的一部分的隐私损失的可能性。隐私监管应强调控制和处理用户数据的人的责任。开发人员应披露所有数据共享实践,并允许用户准确选择共享哪些数据以及与谁共享。
OBJECTIVESTo investigate whether and how user data are shared by top rated medicines related mobile applications (apps) and to characterise privacy risks to app users, both clinicians and consumers.DESIGNTraffic, content, and network analysis.SETTINGTop rated medicines related apps for the Android mobile platform available in the Medical store category of Google Play in the United Kingdom, United States, Canada, and Australia.PARTICIPANTS24 of 821 apps identified by an app store crawling program. Included apps pertained to medicines information, dispensing, administration, prescribing, or use, and were interactive.INTERVENTIONSLaboratory based traffic analysis of each app downloaded onto a smartphone, simulating real world use with four dummy scripts. The app's baseline traffic related to 28 different types of user data was observed. To identify privacy leaks, one source of user data was modified and deviations in the resulting traffic observed.MAIN OUTCOME MEASURESIdentities and characterisation of entities directly receiving user data from sampled apps. Secondary content analysis of company websites and privacy policies identified data recipients' main activities; network analysis characterised their data sharing relations.RESULTS19/24 (79%) of sampled apps shared user data. 55 unique entities, owned by 46 parent companies, received or processed app user data, including developers and parent companies (first parties) and service providers (third parties). 18 (33%) provided infrastructure related services such as cloud services. 37 (67%) provided services related to the collection and analysis of user data, including analytics or advertising, suggesting heightened privacy risks. Network analysis revealed that first and third parties received a median of 3 (interquartile range 1-6, range 1-24) unique transmissions of user data. Third parties advertised the ability to share user data with 216 "fourth parties"; within this network (n= 237), entities had access to a median of 3 (interquartile range 1-11, range 1-140) unique transmissions of user data. Several companies occupied central positions within the network with the ability to aggregate and reidentify user data.CONCLUSIONSSharing of user data is routine, yet far from transparent. Clinicians should be conscious of privacy risks in their own use of apps and, when recommending apps, explain the potential for loss of privacy as part of informed consent. Privacy regulation should emphasise the accountabilities of those who control and process user data. Developers should disclose all data sharing practices and allow users to choose precisely what data are shared and with whom.