“That’s Kind of Sus(picious)”: The Comprehensiveness of Mental Health Application Users’ Privacy and Security Concerns
Authors
Title of the Paper
“That’s Kind of Sus(picious)”: The Comprehensiveness of Mental Health Application Users’ Privacy and Security Concerns
Paper Information
- Field of Study: Mental health technology, user privacy, and data security
- Keywords: Mental health, applications, privacy, data security, user concerns, HIPAA, data tracking, third-party data sharing, privacy policies, data encryption
Research Background and Problem Statement
- Problem or Challenge: With the increasing use of mental health applications, issues and risks related to their privacy and data security have garnered widespread attention. These applications often require users to share highly sensitive mental health data, which may face significant protection deficiencies.
- Significance: Data privacy breaches can lead to violations of privacy, exposure of users' mental health conditions, and negative consequences associated with the stigmatization of mental health data, including social isolation, employment risks, and reduced treatment efficacy.
- Research Motivation and Related Work: There is limited focus on how users perceive data privacy and security issues in mental health applications, despite existing studies exploring the ethical concerns of sharing mental health data and the influence of expert opinions on application evaluations. This study aims to bridge the understanding gap between user experiences and expert perspectives and provide a basis for designing safer mental health technologies.
Proposed Solution
- Proposed Solution: By analyzing 437 user reviews of 83 mental health applications, the study identifies users' primary concerns regarding data privacy and security. These concerns are then compared with expert standards from two major application evaluation platforms (Privacy Not Included and One Mind PsyberGuide) to identify gaps between user and expert priorities.
- Innovative Aspects:
- Focuses on analyzing real user experiences and feedback on privacy and security issues rather than solely relying on expert evaluation standards.
- Directly compares user feedback with expert standards, revealing gaps and potential areas for improvement.
- Implementation Steps:
- Phase 1: Collect and analyze user reviews to summarize users' privacy and security concerns.
- Phase 2: Compare the standards of two expert evaluation platforms with user concerns to identify differences in understanding.
- Provide recommendations for optimizing privacy and security design, including enhancing transparency, complying with HIPAA regulations, and protecting user data.
Research Findings
- Specific Findings:
- Identified users’ primary concerns regarding privacy and security in mental health applications, including types of data collected, third-party data sharing, lack of security measures, control over personal data, and data manipulation practices.
- Found that users were highly concerned about certain issues (e.g., collection of personal health information and risks of HIPAA violations) that were not addressed in expert evaluations.
- User reviews covered a broader range of privacy and security issues than expert evaluation platforms but also revealed users’ limited understanding of certain key technical and security standards.
- Strengths:
- Revealed the diversity of privacy and security issues encountered during actual usage through user feedback, providing a more direct perspective on user experiences compared to expert evaluations.
- Proposed improvements to expert evaluation standards, helping users make more informed decisions when selecting mental health applications.
- Experimental or Evaluation Results:
- The comparison between user and expert standards showed that users were strongly concerned about data ownership and manipulation, while expert standards focused on basic security measures (e.g., password strength and encryption).
- User reviews frequently mentioned the inability to control data sharing and deletion, which was inadequately addressed in expert evaluations.
- Limitations and Future Directions:
- Limitations: The authenticity of review data cannot be verified, and it is unclear whether the reviews were posted by actual users; reviews may not fully reveal the reasons behind user behavior.
- Future Directions:
- Conduct more comprehensive research to explore users’ understanding of privacy policies and their behavioral patterns.
- Develop more user-friendly privacy education materials to help users better protect their data.
- Investigate how mental health professionals can provide privacy and security recommendations when endorsing applications.
The analysis demonstrates that this study provides a rich data foundation and specific recommendations for improving the privacy and security of mental health applications. It also highlights significant differences between user and expert perspectives, offering valuable academic and practical insights.
Research Questions / Practical Problems
Question signals indexed for this paper.
Research Questions
3- What are mental health app users' main concerns regarding privacy and security?Category: Sensitive Health, Identity, and Biometric Data GovernanceSimilar questionsarrow_forward
- How do users' privacy and security concerns differ from expert evaluation criteria?Category: Sensitive Health, Identity, and Biometric Data GovernanceSimilar questionsarrow_forward
- How can mental health app privacy and security design be improved to meet user needs?Category: Sensitive Health, Identity, and Biometric Data GovernanceSimilar questionsarrow_forward
Practical Problems
1- Users worry that mental health apps leak privacy and lack trust in data protection.Category: Sensitive Health, Identity, and Biometric Data GovernanceSimilar questionsarrow_forward
- 67%
Being (In)Visible: Privacy, Transparency, and Disclosure in the Self-Management of Bipolar Disorder
CHI '20· Mental Health Apps & Online Support Communities +2
- 67%
Not Only for Contact Tracing: Use of Belgium’s Contact Tracing App among Young Adults
UbiComp '23· Mental Health Apps & Online Support Communities +2
- 60%
SIGCHI Social Impact Award Talk – Making Privacy and Security More Usable
CHI '18· Privacy by Design & User Control +1
- 60%
You 'Might' Be Affected: An Empirical Analysis of Readability and Usability Issues in Data Breach Notifications
CHI '19· Privacy by Design & User Control +1
- 60%
Human-GDPR Interaction: Practical Experiences of Accessing Personal Data
CHI '22· Privacy by Design & User Control +1
- 60%
Obfuscation Remedies Harms Arising from Content Flagging of Photos
CHI '22· Privacy by Design & User Control +1
- 60%
Understanding Privacy Switching Behaviour on Twitter
CHI '22· Privacy by Design & User Control +1
- 60%
User Perspectives and Ethical Experiences of Apps for Depression: A Qualitative Analysis of User Reviews
CHI '22· Mental Health Apps & Online Support Communities +1
- 60%
How Language Formality in Security and Privacy Interfaces Impacts Intended Compliance
CHI '23· Privacy by Design & User Control +1
- 60%
The Impact of Risk Appeal Approaches on Users’ Sharing Confidential Information
CHI '24· Privacy by Design & User Control +1
Based on Jaccard similarity of research subtopics & professions (≥60%)