论文标题
移动健康应用最终用户的安全意识:一项实证研究
Security Awareness of End-Users of Mobile Health Applications: An Empirical Study
论文作者
论文摘要
移动系统提供便携式和交互式计算,赋予用户能力,以利用包括移动医疗保健在内的多种上下文敏感服务。移动健康应用程序(即MHealth应用程序)正在通过使利益相关者能够生产和消费医疗服务来彻底改变医疗保健领域。对MHealth技术的广泛采用和MHealth应用程序的快速增长需要面临关键挑战,即最终用户对健康关键数据的安全意识的缺乏。本文提出了一项实证研究,旨在探讨MHealth应用程序最终用户的安全意识。我们与沙特阿拉伯的两个MHealth提供商合作,收集101名最终用户的数据。结果表明,尽管有必要的知识,但最终用户缺乏适当的行为,即不愿或缺乏理解来采用安全实践,损害与社会,法律和财务后果的健康关键数据。结果强调,MHealth提供者应确保对最终用户的安全培训(例如威胁分析研讨会),促进最佳实践来执行安全性(例如,多步验证),并采用合适的MHealth应用程序(例如,用于安全性和可用性的权衡取舍)。该研究提供了有关MHealth应用程序安全意识的经验证据和一系列准则。
Mobile systems offer portable and interactive computing, empowering users, to exploit a multitude of context-sensitive services, including mobile healthcare. Mobile health applications (i.e., mHealth apps) are revolutionizing the healthcare sector by enabling stakeholders to produce and consume healthcare services. A widespread adoption of mHealth technologies and rapid increase in mHealth apps entail a critical challenge, i.e., lack of security awareness by end-users regarding health-critical data. This paper presents an empirical study aimed at exploring the security awareness of end-users of mHealth apps. We collaborated with two mHealth providers in Saudi Arabia to gather data from 101 end-users. The results reveal that despite having the required knowledge, end-users lack appropriate behaviour , i.e., reluctance or lack of understanding to adopt security practices, compromising health-critical data with social, legal, and financial consequences. The results emphasize that mHealth providers should ensure security training of end-users (e.g., threat analysis workshops), promote best practices to enforce security (e.g., multi-step authentication), and adopt suitable mHealth apps (e.g., trade-offs for security vs usability). The study provides empirical evidence and a set of guidelines about security awareness of mHealth apps.