Analyzing Third-Party Data Leaks on EU Healthcare Websites

dc.contributor.authorRajapaksha, Sammani
dc.contributor.authorHeino, Timi
dc.contributor.authorPuhtila, Panu
dc.contributor.authorRauti, Sampsa
dc.contributor.organizationfi=ohjelmistotekniikka|en=Software Engineering|
dc.contributor.organization-code1.2.246.10.2458963.20.71310837563
dc.converis.publication-id515825408
dc.converis.urlhttps://research.utu.fi/converis/portal/Publication/515825408
dc.date.accessioned2026-04-24T17:43:43Z
dc.description.abstract<p>In the present-day web-based health services, users often reveal sensitive data concerning their health status. Specifically, this is often the case when using the search function in various online services. Users trust that their data stays confidential and private when using websites. However, at the same time, many online health services use third-party web analytics and other third-party services and libraries, which may put users’ sensitive data in jeopardy. In this study, we analyze 480 web-based health services in the EU area. We conduct a network traffic analysis of the data sent out to third-party services when using the studied health websites and provide an analysis of data leaks. We found that 60.2% of the studied websites leaked URLs without consent from the user. Moreover, 58.9% of the websites that had search functionality leaked search terms to third parties. Our study also highlights some regional disparities in website privacy. Our findings are a stark reminder of the current challenges in protecting users’ personal data in online health services. They highlight the urgent need for web developers and health website maintainers to reassess the used third-party services and fix the privacy issues.<br></p>
dc.identifier.urihttps://www.utupub.fi/handle/11111/59065
dc.identifier.urlhttps://ceur-ws.org/Vol-4181/paper10.pdf
dc.identifier.urnURN:NBN:fi-fe2026042333021
dc.language.isoen
dc.okm.affiliatedauthorRajapaksha, Sammani
dc.okm.affiliatedauthorHeino, Timi
dc.okm.affiliatedauthorPuhtila, Panu
dc.okm.affiliatedauthorRauti, Sampsa
dc.okm.discipline113 Computer and information sciencesen_GB
dc.okm.discipline113 Tietojenkäsittely ja informaatiotieteetfi_FI
dc.okm.internationalcopublicationnot an international co-publication
dc.okm.internationalityInternational publication
dc.okm.typeA4 Conference Article
dc.publisher.countryGermanyen_GB
dc.publisher.countrySaksafi_FI
dc.publisher.country-codeDE
dc.relation.conferenceAnnual Doctoral Symposium of Computer Science
dc.relation.ispartofjournalCEUR Workshop Proceedings
dc.relation.volume4181
dc.titleAnalyzing Third-Party Data Leaks on EU Healthcare Websites
dc.title.bookProceedings of the Annual Doctoral Symposium of Computer Science 2025 (TKTP 2025), Helsinki, Finland, June, 2025
dc.year.issued2026

Tiedostot

Näytetään 1 - 1 / 1
Ladataan...
Name:
paper10.pdf
Size:
1.02 MB
Format:
Adobe Portable Document Format