
data picture, irrelevant to the text. Photo by Li Muyi, reporter of Beijing News
Recently, after a shopping app deleted user data on its own, it caused heated discussion, and the privacy protection of App users has also attracted attention again. According to the " Workers' Daily " report on November 21, a user downloaded a medical and health mobile app (App) and was asked to fill in his name, mobile phone number and other privacy data. Even after uninstalling this app, he still received a harassed call from the Siwutong. Among them, many medical beauty institutions asked about hair transplantation , etc., and even promoted loans.
and this is just the tip of the iceberg for illegal collection and leakage of user privacy by the Medical and Health App. The report stated that in the past one or two years, the apps reported by the official include the suspected privacy non-compliance of Good Doctor App, the Helian Health App collects personal information that is not related to the provision of services, and the Yiyao.com App privately collects personal information and shares it with third parties. In the context of
Internet + medical , how to standardize the operation of medical and health apps in a targeted manner and plug the security loopholes in personal privacy information is an industry problem that needs to be solved urgently and a public security issue in the digital era. It must be taken with sufficient attention.
Medical Health App Operation has already basic guidelines
Compared with other fields such as e-commerce, consumer finance, audio and video platforms, the user privacy risks involved in medical health App are particularly high.
On the one hand, in the process of seeking medical treatment and self-care, some users who lack Internet experience can easily regard the platform operator as the main body of "hospitals", take off their guards, answer questions and provide them with core privacy data.
On the other hand, once the core privacy data such as mobile phone address book, facial features, property status, etc. are mastered by criminals, they may be used to crack bank accounts, mobile phone systems, facial recognition access control , etc., causing information security threats to users, and even loss of life and property.
In fact, the country attaches great importance to the data security work of medical and health apps, and has clearly curbed excessive collection of personal privacy data at different levels. For example, the "Regulations on the Scope of Necessary Personal Information for Common Types of Mobile Internet Applications of " jointly formulated by National Cyberspace Affairs Office and other departments clearly states that apps shall not refuse users to use their basic functional services just because users do not agree to provide "non-essential" personal information. There are also targeted regulations among
. For example, for women's health, the basic functional services are "female menstrual management, child care, beauty and body care and other health management services", and basic functional services can be used without personal information; for consultation and registration, the basic functional services are "online consultation and appointment", and the necessary personal information is limited to mobile phone numbers, patient's name, ID type and number, hospitals and departments that make appointments; medical conditions must be provided during consultation.
Of course, emphasizing data security does not mean that user data is "lying down and basking in the sun", which wastes the driving role of big data on social governance and the digital economy.
In order to meet the needs of the health industry and public welfare undertakings, the "14th Five-Year Plan" issued by the National Health Commission and others not long ago proposed to adopt methods such as "original data does not leave the domain, and data is not visible" to promote the sharing and application of health and medical big data in an orderly manner.
Against this background, relevant ministries and commissions and provinces are also exploring the use of business scenarios such as authorizing personal resident health records information and basic medical insurance insurance to third parties for commercial health insurance insurance, claims, and application for charitable assistance.
The above explorations all have the following common characteristics: privacy data sharing needs to follow multiple goals such as national security, medical security, industrial security, and personal health and safety; data categories and data volume need to meet the principles of "minimum visibility" and "minimum availability" for completing business needs; data sharing requires traces throughout the process, third-party audits and lifelong accountability.
and other platforms are undoubtedly the basic guidelines for the operation of various platforms, including medical and health apps, and they need to be taken seriously and strictly implemented by all parties. At the same time, application stores should strengthen compliance assessments of relevant apps, and users should also strengthen their awareness of personal information protection and rights protection.

For irregular App platforms, there should be a targeted regulatory mechanism.Photo/Xinhua News Agency
uses list-based supervision to regulate the operation of the App platform
In fact, whether it is artificial intelligence "federal learning", big data "sandbox model" or blockchain anti-tampering and chasing and leaks, protecting user privacy data, there is never a shortage of technical means, what is lacking is data governance rules and multi-party incentive mechanism.
For example, the current threshold for mobile medical care is low. You only need to spend tens of thousands of yuan to use the inherent program module to put on a new "skin". After minor modifications, you can launch the application platform for users to download and use. Therefore, a third-party industrial and commercial information platform shows that at present, there are more than 4,000 medical and health apps, and both the platform itself and related services are of varying quality.
However, mobile medical care has emerged around 2012 and has been around for 10 years. We can no longer simply regard the App and data industry as "high technology". In view of this, for some platforms that do not have core technologies, do not have mature business models, and only want to embezzle and resell user privacy data, they need to come up with a list-based targeted supervision and rectification mechanism.
is different from a single software that violates a small number of individual citizens. The larger user privacy data violations may come from large and medium-sized enterprises that undertake public projects. For example, as epidemic prevention and control measures become normalized, it is necessary to strictly prevent some urban "health code" operators from over-collecting user health data and trajectory data, and even apply them to areas that are not related to public health such as exercise and sleep monitoring.
At the same time, as the customized commercial medical insurance in cities such as Huimin Insurance has been released to thousands of cities across the country, we must strictly prevent some Huimin Insurance members and unit-price commercial insurance companies from over-collecting users' financial data and medical data, and even use them in precise marketing, actuarial analysis, and value-added services of other insurance products without the authorization of the insured.
This requires the health and health commissions and medical insurance bureaus at all levels to list user privacy protection clauses in the bidding rules for public projects. Once illegal and irregular behavior is discovered, the relevant companies will be immediately terminated, and the "Sword of Damocles" will force large and medium-sized enterprises not to cross the line and infringe on the rights.
has long been arguing and gambled endlessly around the implementation path of user privacy protection.
For example, for informed consent right , is the object of consent to be used every time, or is it a whole category of services after "packaging"? Should it be necessary to informed consent in advance, or can you sign the "Informed Consent Form" after the event in special circumstances? Should it adopt the "argument" model of agreeing without shaking your head or the "authorization" model of nodding... The dispute over the right to informed consent is actually the dispute between " economic efficiency " and "social fairness". To this end, it is also necessary to solicit opinions from the whole society, do a good job in popular science with professional knowledge, explain the rights and interests behind it, stimulate the heated discussion of privacy protection among the whole people, and ultimately form technical specifications that lead the consensus of public opinion and take into account industrial demands.
After all, user privacy protection seems to be just a "small matter for people's livelihood", but as an agent of user's health rights and economic rights, medical institutions, insurance institutions, and medical and health App operating institutions, it is unavoidable to manage and protect user medical and health information.
also hopes that under scientific and powerful supervision, the loopholes in the collection, use and commercialization of private data of the Medical and Health App can be blocked in a timely manner, effectively benefiting the people and helping build a healthy China.
Written by / Liang Jialin (Secretary-General of the Expert Committee of Value Medical Consulting)
Editing / He Rui
Proofreading / Liu Yue