SoK: Analysis of User-Centered Studies Focusing on Healthcare Privacy & Security (2306.06033v3)
Abstract: Sensitive information is intrinsically tied to interactions in healthcare, and its protection is of paramount importance for achieving high-quality patient outcomes. Research in healthcare privacy and security is predominantly focused on understanding the factors that increase the susceptibility of users to privacy and security breaches. To understand further, we systematically review 26 research papers in this domain to explore the existing user studies in healthcare privacy and security. Following the review, we conducted a card-sorting exercise, allowing us to identify 12 themes integral to this subject such as "Data Sharing," "Risk Awareness," and "Privacy." Further to the identification of these themes, we performed an in-depth analysis of the 26 research papers report on the insights into the discourse within the research community about healthcare privacy and security, particularly from the user perspective.
- Investigating mental health service user opinions on clinical data sharing: qualitative focus group study. JMIR mental health, 8(9):e30596, 2021.
- False data injection attacks in healthcare. In Australasian Data Mining Conference, pages 192–202, Singapore, 2017. Springer, Springer Singapore.
- Machine learning–based analysis of encrypted medical data in the cloud: Qualitative study of expert stakeholders’ perspectives. JMIR human factors, 8(3):e21810, 2021.
- Healthcare and security: Understanding and evaluating the risks. In International Conference on Ergonomics and Health Aspects of Work with Computers, pages 99–108. Springer, 2011.
- Privacy concerns can explain unwillingness to download and use contact tracing apps when covid-19 concerns are high. Computers in Human Behavior, 119:106718, 2021.
- Cyber-risk in healthcare: Exploring facilitators and barriers to secure behaviour. In International Conference on Human-Computer Interaction, pages 105–122. Springer, 2020.
- Sanchari Das et al. Sok: a proposal for incorporating accessible gamified cybersecurity awareness training informed by a systematic literature review. In Proceedings of the workshop on usable security and privacy (USEC), 2022.
- All about phishing exploring user research through a systematic literature review. In Proceedings of the Thirteenth International Symposium on Human Aspects of Information Security & Assurance (HAISA 2019), 2019.
- Evaluating user perception of multi-factor authentication: A systematic review. In Proceedings of the Thirteenth International Symposium on Human Aspects of Information Security & Assurance (HAISA 2019), 2019.
- Hopeful and concerned: public input on building a trustworthy medical information commons. Journal of Law, Medicine & Ethics, 47(1):70–87, 2019.
- Sok: A systematic literature review of knowledge-based authentication on augmented reality head-mounted displays. In Proceedings of the 17th International Conference on Availability, Reliability and Security, pages 1–12, 2022.
- A decentralized privacy-preserving healthcare blockchain for IoT. Sensors, 19(2):326, 2019.
- Cybersecurity in Medical Private Practice: Results of a Survey in Audiology. In 2020 IEEE 6th International Conference on Collaboration and Internet Computing (CIC), pages 169–176, 2020.
- Bernice S Elger. Violations of medical confidentiality: opinions of primary care physicians. British Journal of General Practice, 59(567):e344–e352, 2009.
- Improving individual acceptance of health clouds through confidentiality assurance. Applied Clinical Informatics, 7(04):983–993, 2016.
- Excel snafus causes the loss of 16K UK COVID cases. https://cloudsek.com/threatintel/excel-snafus-causes-the-loss-of-16k-uk-covid-cases-un-shipping-agency-forced-offline-after-cyberattack-and-more/, Oct 2020.
- Co-creating social licence for sharing health and care data. International Journal of Medical Informatics, 149:104439, 2021.
- Are participants concerned about privacy and security when using short message service to report product adherence in a rectal microbicide trial? Journal of the American Medical Informatics Association, 25(4):393–400, 2018.
- Individuals’ privacy concerns and adoption of contact tracing mobile applications in a pandemic: A situational privacy calculus perspective. Journal of the American Medical Informatics Association, 28(3):463–471, 2021.
- Why employees (still) click on phishing links: investigation in hospitals. Journal of Medical Internet Research, 22(1):e16775, 2020.
- Physicians’ knowledge, perceptions, and attitudes related to patient confidentiality and data sharing. International Journal of General Medicine, 14:721, 2021.
- Psychological factors shaping public responses to covid-19 digital contact tracing technologies in germany. Scientific Reports, 11(1):1–19, 2021.
- Cybersecurity in healthcare: A systematic review of modern threats and trends. Technology and Health Care, 25(1):1–10, 2017.
- Security practices and regulatory compliance in the healthcare industry. Journal of the American Medical Informatics Association, 20(1):44–51, 2013.
- Structural model of the healthcare information security behavior of nurses applying protection motivation theory. International Journal of Environmental Research and Public Health, 18(4):2084, 2021.
- Sok: An evaluation of quantum authentication through systematic literature review. In Proceedings of the Workshop on Usable Security and Privacy (USEC), 2021.
- Exploring medical identity theft. Perspectives in health information management/AHIMA, American Health Information Management Association, 6(Fall), 2009.
- Privacy management of patient physiological parameters. Telematics and Informatics, 35(4):677–701, 2018.
- Sustaining patient portal continuous use intention and enhancing deep structure usage: Cognitive dissonance effects of health professional encouragement and security concerns. Information Systems Frontiers, pages 1–14, 2021.
- Exploring evolution of augmented and virtual reality education space in 2020 through systematic literature review. Computer Animation and Virtual Worlds, page e2020, 2021.
- Patient perspectives on the linkage of health data for research: insights from an online patient community questionnaire. International Journal of Medical Informatics, 127:9–17, 2019.
- Kalamullah Ramli et al. Hipaa-based analysis on the awareness level of medical personnel in indonesia to secure electronic protected health information (ephi). In 2021 IEEE International Conference on Health, Instrumentation & Measurement, and Natural Sciences (InHeNce), pages 1–6. IEEE, 2021.
- Public Perspectives of Mobile Phones’ Effects on Healthcare Quality and Medical Data Security and Privacy: A 2-Year Nationwide Survey. In AMIA Annual Symposium Proceedings, volume 2015, page 1076. American Medical Informatics Association, 2015.
- Privacy preservation in e-healthcare environments: State of the art and future directions. IEEE Access, 6:464–478, 2017.
- Trust, perceived risk, perceived ease of use and perceived usefulness as factors related to mhealth technology use. Studies in Health Technology and Informatics, 216:467, 2015.
- Sok: a systematic literature review of bluetooth security threats and mitigation measures. In International Symposium on Emerging Information Security and Applications, pages 108–127. Springer, 2022.
- Do data security measures, privacy regulations, and communication standards impact the interoperability of patient health information? a cross-country investigation. International Journal of Medical Informatics, page 104401, 2021.
- Designing and evaluating mhealth interventions for vulnerable populations: A systematic review. In Proceedings of the 2018 CHI Conference on Human Factors in Computing Systems, pages 1–17, 2018.
- Sok: Evaluating privacy and security vulnerabilities of patients’ data in healthcare. In International Workshop on Socio-Technical Aspects in Security, pages 153–181. Springer, 2022.
- Privacy vs usability: a qualitative exploration of patients’ experiences with secure internet communication with their general practitioner. Journal of Medical Internet Research, 7(2):e368, 2005.
- Privacy and data security in e-health: Requirements from the user’s perspective. Health Informatics Journal, 18(3):191–201, 2012.
- Examining how internet users trust and access electronic health record patient portals: Survey study. JMIR Human Factors, 8(3):e28501, 2021.