mHealth: A Privacy Threat Analysis for Public Health Surveillance Systems
Title | mHealth: A Privacy Threat Analysis for Public Health Surveillance Systems |
Publication Type | Conference Paper |
Year of Publication | 2018 |
Authors | Iwaya, L. H., Fischer-Hübner, S., \AAhlfeldt, R., Martucci, L. A. |
Conference Name | 2018 IEEE 31st International Symposium on Computer-Based Medical Systems (CBMS) |
ISBN Number | 978-1-5386-6060-7 |
Keywords | comprehensive privacy threat analysis, Data collection, data privacy, data protection, data quality, data security issues, expert systems, GeoHealth, Health Care, human factors, MDCS, medical computing, mHealth, mHealth data collection system, mobile computing, Mobile Health Data Collection Systems, national-level databases, PIA, primary healthcare, privacy, privacy impact assessment methodology, pubcrawl, Public Health Surveillance Systems, public health surveys, public healthcare, public surveillance, Scalability, security, security of data, surveillance, threat analysis |
Abstract | Community Health Workers (CHWs) have been using Mobile Health Data Collection Systems (MDCSs) for supporting the delivery of primary healthcare and carrying out public health surveys, feeding national-level databases with families' personal data. Such systems are used for public surveillance and to manage sensitive data (i.e., health data), so addressing the privacy issues is crucial for successfully deploying MDCSs. In this paper we present a comprehensive privacy threat analysis for MDCSs, discuss the privacy challenges and provide recommendations that are specially useful to health managers and developers. We ground our analysis on a large-scale MDCS used for primary care (GeoHealth) and a well-known Privacy Impact Assessment (PIA) methodology. The threat analysis is based on a compilation of relevant privacy threats from the literature as well as brain-storming sessions with privacy and security experts. Among the main findings, we observe that existing MDCSs do not employ adequate controls for achieving transparency and interveinability. Thus, threatening fundamental privacy principles regarded as data quality, right to access and right to object. Furthermore, it is noticeable that although there has been significant research to deal with data security issues, the attention with privacy in its multiple dimensions is prominently lacking. |
URL | https://ieeexplore.ieee.org/document/8417210 |
DOI | 10.1109/CBMS.2018.00015 |
Citation Key | iwaya_mhealth:_2018 |
- Mobile Health Data Collection Systems
- threat analysis
- surveillance
- security of data
- security
- Scalability
- public surveillance
- public healthcare
- public health surveys
- Public Health Surveillance Systems
- pubcrawl
- privacy impact assessment methodology
- privacy
- primary healthcare
- PIA
- national-level databases
- comprehensive privacy threat analysis
- mobile computing
- mHealth data collection system
- mhealth
- medical computing
- MDCS
- Human Factors
- health care
- GeoHealth
- expert systems
- data security issues
- data quality
- Data protection
- data privacy
- Data collection