Maintenance Notice

Due to necessary scheduled maintenance, the JMIR Publications website will be unavailable from Wednesday, July 01, 2020 at 8:00 PM to 10:00 PM EST. We apologize in advance for any inconvenience this may cause you.

Who will be affected?

Accepted for/Published in: JMIR mHealth and uHealth

Date Submitted: Apr 27, 2022
Date Accepted: Sep 21, 2022

The final, peer-reviewed published version of this preprint can be found here:

Critical Criteria and Countermeasures for Mobile Health Developers to Ensure Mobile Health Privacy and Security: Mixed Methods Study

Rezaee R, Khashayar M, Saeedinezhad S, Nasiri M, Zare S

Critical Criteria and Countermeasures for Mobile Health Developers to Ensure Mobile Health Privacy and Security: Mixed Methods Study

JMIR Mhealth Uhealth 2023;11:e39055

DOI: 10.2196/39055

PMID: 36862494

PMCID: 10020905

Mobile Health Privacy and Security: Critical Criteria and Countermeasures for Mobile Health Developers: A Mixed Method Study

  • Rita Rezaee; 
  • Mahboobeh Khashayar; 
  • Saeed Saeedinezhad; 
  • Mehdi Nasiri; 
  • Sahar Zare

ABSTRACT

Background:

Despite the importance of patients’ privacy and confidentiality of information, Mobile Health (mhealth) applications can raise the risk of violating users’ privacy and confidentiality. It is shown that many apps provide an insecure infrastructure and security has not been a priority for the developers.

Objective:

This study aimed to develop and validate a comprehensive tool for assessing the security and privacy of mHealth apps to be considered by developers.

Methods:

A literature search was performed to identify papers on app development and assessment or those papers reporting criteria for security and privacy of mHealth. The criteria were extracted using content analysis and presented to experts. Expert panels were held for determining the categories and subcategories of criteria according to meaning, repetition, and overlap; impact scores were also measured. Quantitative and qualitative methods were used for validating the criteria. The validity and reliability of the instrument were calculated to present an assessment instrument.

Results:

The search strategy identified 8190 articles of which 33 were deemed eligible. A total of 218 criteria were extracted based on the literature search; 119 were removed as duplicates and 10 were deemed irrelevant to security or privacy of mhealth apps. The remaining 89 criteria were presented to the expert panels. After calculating impact scores, Content Validity Ratio (CVR) and Content Validity Index (CVI) 63 criteria were confirmed. The mean CVR and CVI of the instrument was 0.72 and 0.86 respectively. The criteria were grouped into “authentication & authorization”, “access management”, “security”, “data storage”, “integrity”, “encryption & decryption”, “privacy”, and “privacy policy content”.

Conclusions:

The proposed comprehensive criteria can be used as a guide for app designers, developers, and even researchers. The criteria and the countermeasures presented in this study can be considered to improve the privacy and security of mHealth apps before releasing them into the market. Regulators are recommended to consider an established standard using such criteria for accreditation process since the available self-certification of developers are not reliable enough. Clinical Trial: not applicable


 Citation

Please cite as:

Rezaee R, Khashayar M, Saeedinezhad S, Nasiri M, Zare S

Critical Criteria and Countermeasures for Mobile Health Developers to Ensure Mobile Health Privacy and Security: Mixed Methods Study

JMIR Mhealth Uhealth 2023;11:e39055

DOI: 10.2196/39055

PMID: 36862494

PMCID: 10020905

Download PDF


Request queued. Please wait while the file is being generated. It may take some time.

© The authors. All rights reserved. This is a privileged document currently under peer-review/community review (or an accepted/rejected manuscript). Authors have provided JMIR Publications with an exclusive license to publish this preprint on it's website for review and ahead-of-print citation purposes only. While the final peer-reviewed paper may be licensed under a cc-by license on publication, at this stage authors and publisher expressively prohibit redistribution of this draft paper other than for review purposes.