{"title":"Security, privacy, and healthcare-related conversational agents: a scoping review.","authors":"Richard May, Kerstin Denecke","doi":"10.1080/17538157.2021.1983578","DOIUrl":null,"url":null,"abstract":"<p><p>Health chatbots interview patients and collect health data. This process makes demands on data security and data privacy. To identify how and to what extent security and privacy are considered in current health chatbots. We conducted a scoping review by searching three bibliographic databases (PubMed, ACM Digital Library, IEEExplore) for papers reporting on chatbots in healthcare. We extracted which, how, and where data is stored by health chatbots and identified which external services have access to the data. Out of 1026 retrieved papers, we included 70 studies in the qualitative synthesis. Most papers report on chatbots that collect and process personal health data, usually in the context of mental health coaching applications. The majority did not provide any information regarding security or privacy aspects. We were able to determine limitations in literature and identified concrete challenges, including data access and usage of (third-party) services, data storage, data security methods, use case peculiarities and data privacy, as well as legal requirements. Data privacy and security in health chatbots are still underresearched and related information is underrepresented in scientific literature. By addressing the five key challenges in future, the transfer of theoretical solutions into practice can be facilitated.</p>","PeriodicalId":54984,"journal":{"name":"Informatics for Health & Social Care","volume":null,"pages":null},"PeriodicalIF":2.5000,"publicationDate":"2022-04-03","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":"17","resultStr":null,"platform":"Semanticscholar","paperid":null,"PeriodicalName":"Informatics for Health & Social Care","FirstCategoryId":"3","ListUrlMain":"https://doi.org/10.1080/17538157.2021.1983578","RegionNum":4,"RegionCategory":"医学","ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"2021/10/7 0:00:00","PubModel":"Epub","JCR":"Q2","JCRName":"HEALTH CARE SCIENCES & SERVICES","Score":null,"Total":0}
引用次数: 17
Abstract
Health chatbots interview patients and collect health data. This process makes demands on data security and data privacy. To identify how and to what extent security and privacy are considered in current health chatbots. We conducted a scoping review by searching three bibliographic databases (PubMed, ACM Digital Library, IEEExplore) for papers reporting on chatbots in healthcare. We extracted which, how, and where data is stored by health chatbots and identified which external services have access to the data. Out of 1026 retrieved papers, we included 70 studies in the qualitative synthesis. Most papers report on chatbots that collect and process personal health data, usually in the context of mental health coaching applications. The majority did not provide any information regarding security or privacy aspects. We were able to determine limitations in literature and identified concrete challenges, including data access and usage of (third-party) services, data storage, data security methods, use case peculiarities and data privacy, as well as legal requirements. Data privacy and security in health chatbots are still underresearched and related information is underrepresented in scientific literature. By addressing the five key challenges in future, the transfer of theoretical solutions into practice can be facilitated.
期刊介绍:
Informatics for Health & Social Care promotes evidence-based informatics as applied to the domain of health and social care. It showcases informatics research and practice within the many and diverse contexts of care; it takes personal information, both its direct and indirect use, as its central focus.
The scope of the Journal is broad, encompassing both the properties of care information and the life-cycle of associated information systems.
Consideration of the properties of care information will necessarily include the data itself, its representation, structure, and associated processes, as well as the context of its use, highlighting the related communication, computational, cognitive, social and ethical aspects.
Consideration of the life-cycle of care information systems includes full range from requirements, specifications, theoretical models and conceptual design through to sustainable implementations, and the valuation of impacts. Empirical evidence experiences related to implementation are particularly welcome.
Informatics in Health & Social Care seeks to consolidate and add to the core knowledge within the disciplines of Health and Social Care Informatics. The Journal therefore welcomes scientific papers, case studies and literature reviews. Examples of novel approaches are particularly welcome. Articles might, for example, show how care data is collected and transformed into useful and usable information, how informatics research is translated into practice, how specific results can be generalised, or perhaps provide case studies that facilitate learning from experience.