12款医疗聊天机器人隐私漏洞多,用户数据保护形同虚设。
Can I Trust This Chatbot? Assessing User Privacy in AI-Healthcare Chatbot Applications
- 调研12款主流医疗聊天机器人,从注册到政策全面评估隐私设计。
- 半数应用注册时无隐私政策,仅2款允许关闭数据共享。
- 多数政策未说明数据保护措施,用户几乎无数据控制权。
随着对话式人工智能日益融入日常生活,AI驱动的医疗聊天机器人在移动端被广泛应用。这类应用提供全天候支持,但其对敏感健康数据的收集与处理带来严重隐私风险。现有研究多关注聊天机器人安全,却忽视其在医疗场景下的隐私问题。本研究评估了美国App Store和Google Play上12款下载量高的AI医疗聊天机器人应用,采用三阶段分析:(1)注册时的隐私设置,(2)应用内的隐私控制,(3)隐私政策内容。结果发现,半数应用在注册阶段未展示隐私政策,仅有2款提供关闭数据共享的选项。多数应用的隐私政策未明确数据保护措施,用户对个人数据的控制极为有限。研究为信息科学、开发者与政策制定者改进医疗聊天机器人隐私保护提供了关键洞见。
原文摘要 · Abstract (English)
As Conversational Artificial Intelligence (AI) becomes more integrated into everyday life, AI-powered chatbot mobile applications are increasingly adopted across industries, particularly in the healthcare domain. These chatbots offer accessible and 24/7 support, yet their collection and processing of sensitive health data present critical privacy concerns. While prior research has examined chatbot security, privacy issues specific to AI healthcare chatbots have received limited attention. Our study evaluates the privacy practices of 12 widely downloaded AI healthcare chatbot apps available on the App Store and Google Play in the United States. We conducted a three-step assessment analyzing: (1) privacy settings during sign-up, (2) in-app privacy controls, and (3) the content of privacy policies. The analysis identified significant gaps in user data protection. Our findings reveal that half of the examined apps did not present a privacy policy during sign up, and only two provided an option to disable data sharing at that stage. The majority of apps' privacy policies failed to address data protection measures. Moreover, users had minimal control over their personal data. The study provides key insights for information science researchers, developers, and policymakers to improve privacy protections in AI healthcare chatbot apps.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。