Departments of Neurology and Population Health, NYU Langone Medical Center, New York, NY, USA (Mia T. Minen).
Technology and Privacy Attorney, New York, NY, USA (Eric J. Stieglitz).
Headache. 2018 Jul;58(7):1014-1027. doi: 10.1111/head.13341. Epub 2018 Jul 4.
BACKGROUND: Headache diaries are a mainstay of migraine management. While many commercial smartphone applications (apps) have been developed for people with migraine, little is known about how well these apps protect patient information and whether they are secure to use. OBJECTIVE: We sought to assess whether there are privacy issues surrounding apps so that physicians and patients could better understand what medical information patients are providing to the app companies, and the potential privacy implications of how the app companies (and other third parties) might use that information. METHODS: We conducted a systematic search of the most popular "headache" and "migraine" apps and developed a database of the types of data the apps requested for input by the user and whether the apps had clear privacy policies. We also examined the content of the privacy policies. RESULTS: Twenty-nine apps were examined (14 diary apps, 15 relaxation apps). Of the diary applications, 79% (11/14) had visible privacy policies. Of the diary apps with privacy policies, all (11/11) stated whether or not the app collects and stores information remotely. A total of 55% (6/11) stated that some user data were used to serve targeted advertisements. A total of 11/15 (73%) of the relaxation apps had privacy policies. CONCLUSIONS: Headache apps shared information with third parties, posing privacy risks partly because there are few legal protections against the sale or disclosure of data from medical apps to third parties.
背景:头痛日记是偏头痛管理的主要方法。虽然已经开发出许多针对偏头痛患者的商业智能手机应用程序(app),但对于这些应用程序在保护患者信息方面的效果以及使用这些应用程序是否安全的问题知之甚少。
目的:我们旨在评估是否存在与应用程序相关的隐私问题,以便医生和患者能够更好地了解患者向应用程序公司提供哪些医疗信息,以及应用程序公司(和其他第三方)可能如何使用这些信息所带来的潜在隐私影响。
方法:我们对最受欢迎的“头痛”和“偏头痛”应用程序进行了系统搜索,并建立了一个数据库,其中包含应用程序要求用户输入的各种数据类型,以及应用程序是否具有明确的隐私政策。我们还检查了隐私政策的内容。
结果:共检查了 29 个应用程序(14 个日记应用程序,15 个放松应用程序)。在日记应用程序中,79%(11/14)具有可见的隐私政策。在具有隐私政策的日记应用程序中,全部(11/11)都声明应用程序是否远程收集和存储信息。共有 55%(6/11)的应用程序声明部分用户数据用于提供定向广告。共有 11/15(73%)的放松应用程序具有隐私政策。
结论:头痛应用程序与第三方共享信息,带来了隐私风险,部分原因是针对从医疗应用程序向第三方出售或披露数据的法律保护很少。
J Med Internet Res. 2017-4-7
J Neuropsychiatry Clin Neurosci. 2021
BMJ. 2021-6-16
J Med Internet Res. 2015-8-17
JMIR Mhealth Uhealth. 2021-4-13
JMIR Mhealth Uhealth. 2022-6-21
BMC Med Inform Decis Mak. 2022-3-31
JMIR Mhealth Uhealth. 2022-1-27
Am J Geriatr Psychiatry. 2017-8
Health Aff (Millwood). 2016-12-1
JMIR Mhealth Uhealth. 2016-2-10
Lancet Psychiatry. 2016-3
JMIR Mhealth Uhealth. 2015-11-4