Innovative New Research Exposes Security, Privacy, and Safety Issues in Femtech

▴ Newcastle University
Researchers call for regulatory action after highlighting security and privacy concerns in female-oriented technologies (FemTech).

March 13th, 2024: Experts at Newcastle University, Royal Holloway, University of London University of London and ETH Zurich, have identified significant security, privacy, and safety issues in FemTech.

FemTech is a term applied to the collection of digital technologies focused on women’s health and well-being and includes applications, software and wearable devices, and can range from mobile period apps and fertility-tracking wearables to IVF services and is estimated to reach more than $75b by 2025

The threats identified by the researchers include the apps accessing users’ personal contacts, cameras, microphones, location and other personal data (e.g., medical scans), as well as system settings and other accounts that expose security and privacy risks. These apps and IoT (Internet of Things) devices collect a wide range of data about users, their relatives (children, partners, family), their bodies and environments via embedded sensors. The research showed that such practices can reveal very sensitive and intimate information about users (such as gender, fertility, and medical data) to third parties.

During the research, the team reviewed the existing regulations related to FemTech in the UK, EU, and Switzerland to identify gaps in regulations, compliance practices of the industry and enforcements by running experiments on a range of FemTech smart devices, apps, and websites. Their analysis of FemTech-related regulations shows they are inadequate in addressing the risks associated with these technologies. The EU and UK medical devices regulations don’t currently have any references to FemTech data and user protection. The GDPR and Swiss FADP have references to sensitive and special category data, which overlap with FemTech data. However, the industry practices include many non-complaint practices in data collection and sharing.

The study also focused on industry non-compliance. The team identified a range of inappropriate security and privacy practices in a subset of FemTech systems. The research shows that these systems do not brand as medical devices, do not present valid consent and do not give extra protection to sensitive data, and track users without consent.

The authors show that, not only is such intimate data collected by FemTech systems, but also this data is processed and sold to third parties. The findings have exposed a lack of research and guidelines for developing cyber-secure, privacy-preserving and safe products.

The findings of this research were published in the journal Frontiers in the Internet of Things and Symposium on Usable Privacy and Security Workshop and the authors are calling on policymakers to explicitly acknowledge and accommodate the risks of these technologies in the relevant regulations.

Professor Mike Catt of Newcastle University, one of the study authors, said: “We urge regulatory bodies to update and strengthen guidelines to ensure the development and use of secure, private, and safe FemTech products. Many of the apps surveyed access mobile and device resources too. Some of these permissions are marked as dangerous, according to Google’s protection levels. Such access potentially exposes contacts, camera, microphone, location and other personal data. Some specific permissions, such as access to system Settings and other Accounts on the device, also impose security and privacy risks. Access to sensors on the mobile phone can also be used to break user privacy. Users deserve better protection, especially where this relates to sensitive personal health and gender data.”

Dr Maryam Mehrnezhad, lead author of the research and Senior Lecturer at Royal Holloway added: “We have identified multiple threat-actors interested in FemTech data such as fertility and sex information. We have been conducting security and privacy research on this topic since 2019. Apart from our system studies, our user studies also highlight that end-users are indeed concerned about their intimate and sensitive data being handled by FemTech products. We constantly share our research results with the industry and related regulatory bodies, such as the Information Commissioner's Office. We hope to see better collaborative efforts across the stakeholders to enable the citizens to use FemTech solutions to improve the quality of their lives without any risk and fear.”

This research was supported by the UKRI EPSRC PETRAS CyFer and AGENCY projects. These multi-disciplinary research teams are working with other stakeholders on the complex risks and harms of modern technologies such as FemTech to mitigate these risks and to design privacy-preserving, cyber-secure, and safe products which are inclusive.

 

ABOUT NEWCASTLE UNIVERSITY: Newcastle University, UK, is a thriving international community of more than 28,000 students from over 130 countries worldwide. As a member of the Russell Group of research-intensive universities in the UK, Newcastle has a world-class reputation for research excellence in the fields of medicine, science and engineering, social sciences and the humanities. Its academics are sharply focused on responding to the major challenges facing society today. Our research and teaching are world-leading in areas as diverse as health, culture, technology and the environment. Newcastle University is committed to providing our students with excellent, research-led teaching delivered by dedicated and passionate teachers. Newcastle University is ranked 110th  in the QS World Ranking 2024 and 139th in the Times Higher Education World University Ranking 2023.

Tags : #

About the Author


Team Medicircle

Related Stories

Loading Please wait...

-Advertisements-




Trending Now

Scientists in Moscow Develop Fetal Phantom for Obstetric UltrasoundNovember 19, 2024
International Men’s Day: A Celebration of Strength, Vulnerability, and ChangeNovember 19, 2024
The Bloody Truth: Why Menstruation Is Still a Taboo in Indian SchoolsNovember 19, 2024
Toxic Air, Fragile Hearts: The Hidden Cost of Pollution on Heart Failure PatientsNovember 19, 2024
Government of Telangana Hosts the AI in Healthcare Summit – Road to BioAsia 2025November 18, 2024
In yet another groundbreaking medical milestone, Sarvodaya Hospital successfully performs India’s youngest cochlear implant on a 5- month old babyNovember 18, 2024
Sightsavers India in collaboration with AbbVie Therapeutics India Private Limited Hosted the 4th State-Level Consultation on ‘Prevention of Visual Impairment Caused by Glaucoma’November 16, 2024
Is Your Saree Hurting You? How Tight Waist Petticoats Could Trigger Skin CancerNovember 16, 2024
10 New-born Lives Lost: The Jhansi Hospital Fire That Shook India’s ConscienceNovember 16, 2024
Streax introduces revolutionary Shampoo Hair Colour in South India at accessible price point.November 15, 2024
The Silent Killer in Your Genes: Can Splicing Errors Unlock New Cancer Cures?November 15, 2024
Stress on a Schedule: What Your Gut Bacteria Know That You Don’tNovember 15, 2024
A Preventable Catastrophe: Why Are Children Still Dying from Measles?November 15, 2024
The University of Tasmania invites applications for Master of Marine and Antarctic ScienceNovember 14, 2024
ICMR’s Bold Bet: Can India’s Scientists Deliver World-First Health Breakthroughs?November 14, 2024
The Dark Reality Behind India’s Ayushman Bharat: Profits Before Patients?November 14, 2024
Not a Fan of Exercise? Here’s How Few Steps You Actually Need for Better HealthNovember 14, 2024
Shiprocket launches AI Powered Shiprocket Copilot to empower a Self-Reliant Digital Future for over 1,00,000+ Indian MSMEsNovember 13, 2024
AIIMS Darbhanga and More: Can PM Modi’s 12,000 Crore Investment Turn Bihar into India’s Next Growth Engine?November 13, 2024
Self-Made Survivor: How a Virologist Battled Breast Cancer with Her Own Lab-Grown VirusesNovember 13, 2024