exposing privacy concerns in mhealth data sharing...institute for security, technology, and society...

12
Institute for Security, Technology, and Society (ISTS) at Dartmouth College Trustworthy Information Systems for Healthcare Exposing Privacy Concerns in mHealth Data Sharing Aarathi Prasad , Jacob Sorber, Timothy Stablein, Denise Anthony and David Kotz HealthSec 2011

Upload: others

Post on 12-Jul-2020

1 views

Category:

Documents


0 download

TRANSCRIPT

Page 1: Exposing Privacy Concerns in mHealth Data Sharing...Institute for Security, Technology, and Society (ISTS) at Dartmouth College Benefits vs privacy ! Consumers & personal information:

Institute for Security, Technology, and Society (ISTS) at Dartmouth College

Trustworthy Information Systems for Healthcare

Exposing Privacy Concerns in mHealth Data Sharing

Aarathi Prasad, Jacob Sorber, Timothy Stablein, Denise Anthony and David Kotz

HealthSec 2011

Page 2: Exposing Privacy Concerns in mHealth Data Sharing...Institute for Security, Technology, and Society (ISTS) at Dartmouth College Benefits vs privacy ! Consumers & personal information:

Institute for Security, Technology, and Society (ISTS) at Dartmouth College

mHealth Architecture

Courtesy: http://benchmark.bpcsite.com

Courtesy: http://ironmantriathlontips.com

Courtesy: http://medicallink.com

Courtesy: http://hhs.state.ne.us

Electronic/Personal Health Record (Server)

Consumer (Client)

Patient

Page 3: Exposing Privacy Concerns in mHealth Data Sharing...Institute for Security, Technology, and Society (ISTS) at Dartmouth College Benefits vs privacy ! Consumers & personal information:

Institute for Security, Technology, and Society (ISTS) at Dartmouth College

Benefits vs privacy

§  Consumers & personal information: 86% of American shoppers use store cards, “and

most say the benefits are worth giving up some privacy” [2004 poll]

§  Health information: 60% think benefits of electronic health records

outweigh privacy concerns [2007 survey]

Is there a third option?

Page 4: Exposing Privacy Concerns in mHealth Data Sharing...Institute for Security, Technology, and Society (ISTS) at Dartmouth College Benefits vs privacy ! Consumers & personal information:

Institute for Security, Technology, and Society (ISTS) at Dartmouth College

Goal

Expressive privacy controls §  enjoy health benefits

§  limit exposure

Courtesy: bannerhealth.com

Page 5: Exposing Privacy Concerns in mHealth Data Sharing...Institute for Security, Technology, and Society (ISTS) at Dartmouth College Benefits vs privacy ! Consumers & personal information:

Institute for Security, Technology, and Society (ISTS) at Dartmouth College

Focus Groups

§  Students, hospital outpatients and residents of retirement home

§  Scenarios

Medication Exercise Location Interactions

Page 6: Exposing Privacy Concerns in mHealth Data Sharing...Institute for Security, Technology, and Society (ISTS) at Dartmouth College Benefits vs privacy ! Consumers & personal information:

Institute for Security, Technology, and Society (ISTS) at Dartmouth College

Focus Group - Questions

§  Benefits/disadvantages

§  Privacy concerns

§  information type

§ time and location

§  Sharing with doctor, family and friends

§  Controls to limit transmission

Page 7: Exposing Privacy Concerns in mHealth Data Sharing...Institute for Security, Technology, and Society (ISTS) at Dartmouth College Benefits vs privacy ! Consumers & personal information:

Institute for Security, Technology, and Society (ISTS) at Dartmouth College

Focus Groups - Results §  Sharing of personal health information

§  Medium of transmission

§  What is being shared

§  Sensitivity level

Social interactions

Location

Medication

Diet and exercise

§  Benefits outweigh privacy in case of serious illness

Courtesy: networkworld.com

Page 8: Exposing Privacy Concerns in mHealth Data Sharing...Institute for Security, Technology, and Society (ISTS) at Dartmouth College Benefits vs privacy ! Consumers & personal information:

Institute for Security, Technology, and Society (ISTS) at Dartmouth College

Focus Groups - Results §  Who information is being shared with

§  Insurance companies and employers

Doctors Family and friends Outpatients Share all information Share only with caregivers

Residents Share some information

Share with trained caregivers

Students Mixed responses Share with trained caregivers Share only if incapable of making decisions on their own

Page 9: Exposing Privacy Concerns in mHealth Data Sharing...Institute for Security, Technology, and Society (ISTS) at Dartmouth College Benefits vs privacy ! Consumers & personal information:

Institute for Security, Technology, and Society (ISTS) at Dartmouth College

Focus Groups - Results

§  Control § To turn device on or off § To choose what to share and with whom

Courtesy: http://comapleteorganizingsolutions.com

Page 10: Exposing Privacy Concerns in mHealth Data Sharing...Institute for Security, Technology, and Society (ISTS) at Dartmouth College Benefits vs privacy ! Consumers & personal information:

Institute for Security, Technology, and Society (ISTS) at Dartmouth College

Privacy controls •  Annotations •  Access logs •  Sensible default settings •  Hierarchical controls

Activity

Courtesy: http://static.imt.ie

Steps Calories Type x Heart rate x Location

x

Page 11: Exposing Privacy Concerns in mHealth Data Sharing...Institute for Security, Technology, and Society (ISTS) at Dartmouth College Benefits vs privacy ! Consumers & personal information:

Institute for Security, Technology, and Society (ISTS) at Dartmouth College

Fitbit study §  Students carry Fitbits for 5 days §  Share information with family, friends

and third parties § Goal : understand how people share their

activity and sleep data

Courtesy: http://fitbit.com

Page 12: Exposing Privacy Concerns in mHealth Data Sharing...Institute for Security, Technology, and Society (ISTS) at Dartmouth College Benefits vs privacy ! Consumers & personal information:

Institute for Security, Technology, and Society (ISTS) at Dartmouth College

Trustworthy Information Systems for Healthcare

Exposing Privacy Concerns in mHealth Data Sharing

Aarathi Prasad, Jacob Sorber, Timothy Stablein, Denise Anthony and David Kotz

HealthSec 2011