Preprint submitted to IEEE Access. Date of current version June 22, 2020. Digital Object Identifier 10.1109/ACCESS.2017.DOI Security and Privacy for mHealth and uHealth Systems: a Systematic Mapping Study LEONARDO HORN IWAYA1,2, AAKASH AHMAD3, AND M. ALI BABAR.1,2 1Centre for Research on Engineering Software Technologies, The University of Adelaide, Adelaide, SA, Australia 2Cyber Security Cooperative Research Centre (CSCRC), Australia 3College of Computer Science and Engineering, University of Ha’il, Saudi Arabia Corresponding author: Leonardo Horn Iwaya (e-mail:
[email protected]). The work has been supported by the Cyber Security Cooperative Research Centre (CSCRC) whose activities are partially funded by the Australian Government’s Cooperative Research Centres Programme. ABSTRACT An increased adoption of mobile health (mHealth) and ubiquitous health (uHealth) systems empower users with handheld devices and embedded sensors for a broad range of healthcare services. However, m/uHealth systems face significant challenges related to data security and privacy that must be addressed to increase the pervasiveness of such systems. This study aims to systematically identify, classify, compare, and evaluate state-of-the-art on security and privacy of m/uHealth systems. We conducted a systematic mapping study (SMS) based on 365 qualitatively selected studies to (i) classify the types, frequency, and demography of published research and (ii) synthesize and categorize research themes, (iii) recurring challenges, (iv) prominent solutions (i.e., research outcomes) and their (v) reported evaluations (i.e., practical validations). Results suggest that the existing research on security and privacy of m/uHealth systems primarily focuses on select group of control families (compliant with NIST800-53), protection of systems and information, access control, authentication, individual participation, and privacy authorisation.