Data Sharing with a Third-Party Within IoMT Environment: Challenges and Opportunities
摘要
This paper is set to understand and analyze the controversy surrounding a mental health application called BetterHelp and what the organization could have done to prevent losing people’s trust and data leakage. A proper understanding of the Internet of Things in healthcare systems was required, along with understanding the concepts of data-sharing and data-leakage as both have different meanings. Data-sharing being the company willingly sharing their users’ data to other companies, and data-leakage being data that is leaked unwillingly by hackers. Both cases were apparent in BetterHelp, hence finding suitable solutions that cater to the two main issues. The first solution is to change the terms, policies and core values within BetterHelp, and determine whether they see users as patients or as products for other companies. The second solution is to be aware of where the key sensitive data resides in which system, for BetterHelp there are several sensitive data like credit card credentials, names, addresses, sessions, and diagnoses. Evaluating and prioritizing the key sensitive data is vital through the use of Data Loss Prevention software. Second is to use the Lepide Data Security Platform to emphasize the importance of auditing, monitoring and alerting critical changes within a system by either training a certain team for such tasks or hiring a third-party organization that specializes in it. Lastly, it is to encrypt the data. BetterHelp is not alone when it comes to controversies and scandals dealing with data-sharing and data-leakage, in the related-work there are fourother organizations that dealt with similar issues but had different approaches that they used, all of which were taken into consideration for the benefit of BetterHelp and how to attain the people’s trust again.