Digital Therapeutics (DTx) are transforming modern healthcare by introducing software-based, clinically-validated therapeutic interventions that complement or replace traditional treatments. These solutions can potentially improve accessibility, personalization, and scalability of care, but at the same time, they raise critical concerns for patient safety and privacy, as they rely on the processing of highly sensitive health data and directly influence clinical decision-making. This paper addresses the gap between academic research and current industry practices by introducing a dedicated threat model for DTx applications, focusing on patient safety. Building on this model, we evaluate a selection of commercially available DTx services, systematically identifying common vulnerabilities and analyzing their implications for security and privacy. The findings reveal recurring weaknesses and highlight areas where improvements are most urgently needed. Based on these insights, we formulate a set of actionable recommendations for developers. By doing so, we contribute to the establishment of domain-specific best practices that can strengthen security and safeguard patient outcomes.

Evaluating Threats and Proposing Evidence-Based Recommendations for Mobile Digital Therapeutics Applications

Balossini, Marco;Gervasio, Dario A.;Caiani, Enrico G.;Zanero, Stefano;Carminati, Michele;Longari, Stefano
2026-01-01

Abstract

Digital Therapeutics (DTx) are transforming modern healthcare by introducing software-based, clinically-validated therapeutic interventions that complement or replace traditional treatments. These solutions can potentially improve accessibility, personalization, and scalability of care, but at the same time, they raise critical concerns for patient safety and privacy, as they rely on the processing of highly sensitive health data and directly influence clinical decision-making. This paper addresses the gap between academic research and current industry practices by introducing a dedicated threat model for DTx applications, focusing on patient safety. Building on this model, we evaluate a selection of commercially available DTx services, systematically identifying common vulnerabilities and analyzing their implications for security and privacy. The findings reveal recurring weaknesses and highlight areas where improvements are most urgently needed. Based on these insights, we formulate a set of actionable recommendations for developers. By doing so, we contribute to the establishment of domain-specific best practices that can strengthen security and safeguard patient outcomes.
2026
File in questo prodotto:
File Dimensione Formato  
Evaluating_Threats_and_Proposing_Evidence-Based_Recommendations_for_Mobile_Digital_Therapeutics_Applications.pdf

accesso aperto

: Publisher’s version
Dimensione 1.9 MB
Formato Adobe PDF
1.9 MB Adobe PDF Visualizza/Apri

I documenti in IRIS sono protetti da copyright e tutti i diritti sono riservati, salvo diversa indicazione.

Utilizza questo identificativo per citare o creare un link a questo documento: https://hdl.handle.net/11311/1315925
Citazioni
  • ???jsp.display-item.citation.pmc??? ND
  • Scopus ND
  • ???jsp.display-item.citation.isi??? ND
social impact