Analyzing third-party data leaks on online pharmacy websites

dc.contributor.authorRauti Sampsa
dc.contributor.authorCarlsson Robin
dc.contributor.authorMickelsson Sini
dc.contributor.authorMäkilä Tuomas
dc.contributor.authorHeino Timi
dc.contributor.authorPirjatanniemi Elina
dc.contributor.authorLeppänen Ville
dc.contributor.organizationfi=ohjelmistotekniikka|en=Software Engineering|
dc.contributor.organizationfi=oikeustiede|en=Laws|
dc.contributor.organization-code1.2.246.10.2458963.20.53046050752
dc.contributor.organization-code1.2.246.10.2458963.20.71310837563
dc.contributor.organization-code2610302
dc.converis.publication-id386995639
dc.converis.urlhttps://research.utu.fi/converis/portal/Publication/386995639
dc.date.accessioned2025-08-27T21:37:50Z
dc.date.available2025-08-27T21:37:50Z
dc.description.abstract<p><strong>Purpose </strong>With digitalization, using essential digital services such as online services has become increasingly common. These services process sensitive health related data, such as customers' prescription medicine orders, which makes ensuring stringent data privacy crucial. The current study examines third parties such as analytics services on Finnish pharmacy websites and investigates the nature and contents of data leaks on these websites.</p><p><strong>Methods</strong> We perform an extensive network traffic analysis to reveal data leaks among 163 Finnish online pharmacies. We also study a set of privacy policies of these online pharmacies, and provide a legal analysis regarding the interpretation of the concept of data concerning health in the context of online pharmacies.</p><p><strong>Results</strong> Our findings reveal serious data leaks among Finnish online pharmacies. We found 145 pharmacies had third-party services on their websites and only 18 did not. Out of all 163 online pharmacies, 57 (35.0 %) leaked a specific prescription medicine name connected with identifying personal data on the customer. We argue that the information concerning purchases on the prescription medicines should be interpreted as data concerning health to ensure efficient protection of customers' right to data protection and privacy.</p><p><strong>Conclusions</strong> We hope that these concerning results will serve as a wake-up call for the developers and maintainers of online pharmacies and other web services processing sensitive data. Any third-party services incorporated into websites processing sensitive personal data should be closely inspected in terms of data leaks, or preferably not used at all.</p>
dc.format.pagerange375
dc.format.pagerange392
dc.identifier.eissn2190-7196
dc.identifier.jour-issn2190-7188
dc.identifier.olddbid200766
dc.identifier.oldhandle10024/183793
dc.identifier.urihttps://www.utupub.fi/handle/11111/47132
dc.identifier.urlhttps://link.springer.com/article/10.1007/s12553-024-00819-w
dc.identifier.urnURN:NBN:fi-fe2025082789229
dc.language.isoen
dc.okm.affiliatedauthorRauti, Sampsa
dc.okm.affiliatedauthorCarlsson, Robin
dc.okm.affiliatedauthorMickelsson, Sini
dc.okm.affiliatedauthorMäkilä, Tuomas
dc.okm.affiliatedauthorHeino, Timi
dc.okm.affiliatedauthorLeppänen, Ville
dc.okm.discipline113 Computer and information sciencesen_GB
dc.okm.discipline513 Lawen_GB
dc.okm.discipline113 Tietojenkäsittely ja informaatiotieteetfi_FI
dc.okm.discipline513 Oikeustiedefi_FI
dc.okm.internationalcopublicationnot an international co-publication
dc.okm.internationalityInternational publication
dc.okm.typeA1 ScientificArticle
dc.publisherSPRINGER HEIDELBERG
dc.publisher.countryGermanyen_GB
dc.publisher.countrySaksafi_FI
dc.publisher.country-codeDE
dc.publisher.placeHEIDELBERG
dc.relation.doi10.1007/s12553-024-00819-w
dc.relation.ispartofjournalHealth and technology
dc.relation.volume14
dc.source.identifierhttps://www.utupub.fi/handle/10024/183793
dc.titleAnalyzing third-party data leaks on online pharmacy websites
dc.year.issued2024

Tiedostot

Näytetään 1 - 1 / 1
Ladataan...
Name:
s12553-024-00819-w.pdf
Size:
1.47 MB
Format:
Adobe Portable Document Format