"Your Doctor is Spying on You": An Analysis of Data Practices in Mobile Healthcare Applications
By: Luke Stevenson, Sanchari Das
Potential Business Impact:
Finds health apps secretly spying on you.
Mobile healthcare (mHealth) applications promise convenient, continuous patient-provider interaction but also introduce severe and often underexamined security and privacy risks. We present an end-to-end audit of 272 Android mHealth apps from Google Play, combining permission forensics, static vulnerability analysis, and user review mining. Our multi-tool assessment with MobSF, RiskInDroid, and OWASP Mobile Audit revealed systemic weaknesses: 26.1% request fine-grained location without disclosure, 18.3% initiate calls silently, and 73 send SMS without notice. Nearly half (49.3%) still use deprecated SHA-1 encryption, 42 transmit unencrypted data, and 6 remain vulnerable to StrandHogg 2.0. Analysis of 2.56 million user reviews found 28.5% negative or neutral sentiment, with over 553,000 explicitly citing privacy intrusions, data misuse, or operational instability. These findings demonstrate the urgent need for enforceable permission transparency, automated pre-market security vetting, and systematic adoption of secure-by-design practices to protect Protected Health Information (PHI).
Similar Papers
Security Evaluation of Android apps in budget African Mobile Devices
Cryptography and Security
Finds hidden dangers in cheap phones.
Security and Privacy Assessment of U.S. and Non-U.S. Android E-Commerce Applications
Cryptography and Security
Finds security flaws in shopping apps.
On the Security and Privacy of AI-based Mobile Health Chatbots
Cryptography and Security
Makes health apps safer and more private.