Cyber Security and Privacy Issues in Extended Reality Healthcare Applications: Scoping Review (Preprint)

Author:

Lake KaitlynORCID,Mc Kittrick AndreaORCID,Desselle MathildeORCID,Padilha Lanari Bo AntonioORCID,Abayasiri Rammuni Achintha MihiranORCID,Fleming Jennifer MichelleORCID,Baghaei NilufarORCID,Kim Dan DongseongORCID

Abstract

BACKGROUND

Virtual reality (VR) is a type of extended reality (XR) technology increasingly used by rehabilitation practitioners to support rehabilitation following illness or injury that affect the upper limbs. There is robust evidence articulating how consumer-grade VR presents significant cyber security implications, such as security and privacy risks with software and hardware interfaces and use of cameras. However, little is known about how these risks translate in the use of VR systems in healthcare settings. The objective of this review is to identify cyber security risks associated with clinical VR systems, and to develop guidance for health informatics and rehabilitation practitioners to support the safe use of VR in healthcare.

OBJECTIVE

This scoping review aims to identify cyber security and privacy risks to XR technologies and components, including threats, attacks and attackers, with a focus on VR. Furthermore, we aim to understand how these risks can be mitigated in a clinical XR environment, in particular VR environment, by understanding the unique concerns for a healthcare setting and identifying relevant technologies, frameworks and strategies to mitigate these risks.

METHODS

A scoping review of the literature performed in one database (Google Scholar) identified 482 articles from the years 2017 to 2024. After abstract screening, 53 studies were extracted for a full text review, of which 29 were included in the analysis. The review followed the PRISMA extension for Scoping Reviews, and publications were reviewed using the Covidence software. Data on technology, cyber threats and risk mitigation were extracted.

RESULTS

Of the included studies, 79% were published between 2020 and 2023, and 55% focused on VR. The majority identified a privacy threat or mitigation strategy or both (26 papers, 90%). 90% of the XR components investigated were head-mounted display (HMD) devices and the greatest cyber threat identified to these components was information disclosure (76%). Risk mitigation strategies were mapped against the National Institute of Standards and Technology (NIST) Cybersecurity Framework, where 62% of studies identified a preventative mitigation strategy (18/29). The least established cyber security function for XR systems was recovery after a cyber security incident, with only one potential strategy.

CONCLUSIONS

Findings were mapped against an enterprise risk management (ERM) model to contextualise cyber security risks for healthcare organisations. The most significant threat posited for a healthcare VR system was privacy threats, which can disclose personal data from which medical related data may be inferred, and immersive manipulation threats, which can impact user safety. Many potential mitigation strategies were identified for all types of threats, but none have been implemented beyond a proof-of-concept. None of the threats or mitigations have been studied in a healthcare context, which requires further research.

Publisher

JMIR Publications Inc.

同舟云学术

1.学者识别学者识别

2.学术分析学术分析

3.人才评估人才评估

"同舟云学术"是以全球学者为主线,采集、加工和组织学术论文而形成的新型学术文献查询和分析系统,可以对全球学者进行文献检索和人才价值评估。用户可以通过关注某些学科领域的顶尖人物而持续追踪该领域的学科进展和研究前沿。经过近期的数据扩容,当前同舟云学术共收录了国内外主流学术期刊6万余种,收集的期刊论文及会议论文总量共计约1.5亿篇,并以每天添加12000余篇中外论文的速度递增。我们也可以为用户提供个性化、定制化的学者数据。欢迎来电咨询!咨询电话:010-8811{复制后删除}0370

www.globalauthorid.com

TOP

Copyright © 2019-2024 北京同舟云网络信息技术有限公司
京公网安备11010802033243号  京ICP备18003416号-3