| Literature DB >> 34152277 |
Bakheet Aljedaani1,2, M Ali Babar1,3.
Abstract
BACKGROUND: Mobile health (mHealth) apps have gained significant popularity over the last few years due to their tremendous benefits, such as lowering health care costs and increasing patient awareness. However, the sensitivity of health care data makes the security of mHealth apps a serious concern. Poor security practices and lack of security knowledge on the developers' side can cause several vulnerabilities in mHealth apps.Entities:
Keywords: developers; mHealth apps; secure apps; security knowledge; systematic literature review
Mesh:
Year: 2021 PMID: 34152277 PMCID: PMC8277314 DOI: 10.2196/15654
Source DB: PubMed Journal: JMIR Mhealth Uhealth ISSN: 2291-5222 Impact factor: 4.773
Figure 1Flow diagram for the selection of articles. IoT: Internet of Things; mHealth: mobile health; WSN: wireless sensor network.
Figure 2Example of the steps of applying the thematic analysis to the qualitative data. mHealth: mobile health.
The number of selected studies published per year and their distribution by outlet.
| Year | Journals, n | Conferences, n | Workshops, n |
| 2012 | 1 | 1 | 0 |
| 2013 | 0 | 0 | 0 |
| 2014 | 5 | 1 | 0 |
| 2015 | 4 | 2 | 0 |
| 2016 | 2 | 0 | 0 |
| 2017 | 3 | 0 | 1 |
| 2018 | 4 | 0 | 0 |
| 2019 | 4 | 1 | 1 |
| 2020 | 0 | 2 | 0 |
Challenges with developing secure mobile health (mHealth) apps (identified from 32 studies).
| Challenge number and description | Key points from reviewed studies | Frequency, n (%) |
| C1. Lack of security guidelines and regulations for developing secure mHealth apps | Lack of security guidelines, regulations, direct laws about the security requirements, secure designing, security testing, security features that need to be employed in mHealth apps (S4 [ | 20 (63) |
| C2. Developers’ lack of knowledge of and expertise with secure mHealth app development | Insufficient knowledge of software developers about the security risks of mHealth apps (S12 [ | 18 (56) |
| C3. Lack of stakeholders’ involvement during mHealth app development | Lack of stakeholders’ participation during the development lifecycle of mHealth apps (S5 [ | 6 (19) |
| C4. No or little attention by developers towards the security of mHealth apps | Developer' assumption that users are not concerned about security (S32 [ | 5 (16) |
| C5. Lack of financial resources for developing secure mHealth apps | No/low budget assigned for employing security measures (S32 [ | 4 (13) |
| C6. Time constraints during mHealth app development process | Rushing to market, which leaves vulnerabilities in mHealth apps (S18 [ | 4 (13%) |
| C7. Lack of security testing during mHealth app development | Lack of security testing (S32 [ | 4 (13) |
| C8. Developers lack motivation and ethical considerations | Lack of motivations for developers during the development process of mHealth apps (S27 [ | 3 (9) |
| C9. Lack of security experts’ engagement during mHealth app development | Lack of collaboration and discussion with security experts from the beginning of the development lifecycle of mHealth apps (S18 [ | 2 (6) |
aAPIs: application programming interfaces.
bTLS: transport security layer.
Figure 3A conceptual framework for correlating the challenges in developing secure mHealth apps.