Date: October 13, 2024
An audit of the top 100 Android and iOS healthcare apps revealed major threats, data leakages, cryptographic shortcomings, and other security breaches of healthcare mobile apps across the globe. These findings highlight the gaps in data security & pinpoint areas where massive improvement is required in the post-COVID 19 remote healthcare boost.
SAN FRANCISCO- September 29, 2020 - Intertrust is a leading company in application security solutions and digital rights management (DRM) technology. They released their 2020 Security Report on Global mHealth Apps. The crucial and invaluable findings showcased the vulnerability of mobile healthcare apps across the world. 71% of medical applications showed one critical shortcoming that could result in the breach of the user's medical data. The report put 100 global healthcare apps under the lens to study threatening mHealth security trends. Investigated apps ranged across various categories- COVID tracking, telehealth, medical device, and health commerce.
The most serious and prevalent issue was of Cryptography. About 91% of apps failed in at least one cryptographic test. Implying that the encryption used in most applications could be easily broken, increasing risk to patient's medical data. Such apps invite malicious hackers to tamper, steal, or use the data for personal use.
The study's conclusive findings revealed that the massive push to revolutionize remote healthcare apps in a COVID 19 world comes at the cost of mobile data security.
Bill Horne, CTO at Intertrust and General Manager of Secure Systems product group commented on this "Unfortunately, there’s been a history of security vulnerabilities in the healthcare and medical space. Things are getting a lot better, but we still have a lot of work to do" He then expressed in a more positive note "The good news is that application protection strategies and technologies can help healthcare organizations bring the security of their apps up to speed."
The Intertrust security report on medical and healthcare mobile applications derived its findings on the basis of a detailed audit of 100 Android & iOS apps from worldwide organizations. All of the audited apps underwent a full host of Dynamic application security testing (DAST) and Static application security testing (SAST) based on the Open web application security project or OWASP mobile security testing.
Some major highlights from the report:
Details on medical application protection can be found here
Intertrust provides services and trusted computing products to consumer electronics, service providers, IoT manufacturers, mobile app industry leaders, and enterprise software platform companies. Products include software tamper resistance, the world's top digital rights management (DRM), and technologies to enable private data exchanges for many verticals including automotive, fintech, energy, entertainment, IoT, and retail/marketing. Founded in 1990 and headquartered in Silicon Valley with offices in London, Tokyo, Bangalore, Mumbai, Seoul, Beijing, Riga, and Tallinn. Intertrust has a renowned legacy of creative innovation and contributions in the area of digital trust and computer security. We hold hundreds of patents that are critical to privacy management components of OS, trust, internet security, trusted mobile code and network operating environments, cloud computing, and web services.
By Aman Gaur
Aman Gaur is a Senior Writer at MobileAppDaily (MAD). He is an IT engineer (as per academics) who turned to writing because of his flair for storytelling. He has an experience of 6+ years and has worked with multiple companies in many niches but primarily ‘Tech’. He has many interests that range from being a tech enthusiast to an admirer of international music and cinema. Currently, he is using his skills to help MAD expand and create valuable content for the platform, thereby, helping in improving overall traffic, leads, and branding of the company.
Sofy.ai Launches ‘Visual Match’ to Enhance User’s Scriptless Testing Abilities, Providing Superior Testing Maintainability and Significantly Decreasing Test Flakiness
Sofy’s platform transforms test maintenance into a seamless part of the software development lifecycle.
Wizz Transforms Safety Into Self-Expression Through Partnerships with Yoti, Sight Engine, Webhelp and Besedo
The 16M+ User Social Discovery App Doubles Down on Moderation Efforts that Improve User Experience, With Four Best-in-Class Tech Partners
From Tutanota to Tuta: Unveiling the New Name
Tutanota unveiled its new name Tuta on 7th November, 2023. The company is all set to work on post-quantum secure encryption.
Tutanota launches into the age of quantum computing by building a secure Drive solution
TutaDrive is the first quantum-resistant tech designed to offer end-to-end encryption for data storage and exchange that Tutanota is building. Check out rest of the report for more details!