As revealed in its recent report by Intertrust Technologies, approximately 71% of healthcare and medical apps contain at least one serious vulnerability that could lead to a breach of medical data, while 5% of COVID-19 leak data. The research tested 100 healthcare apps (Android and iOS) covering a wide range of services.

A vulnerability is classified as severe when it can be easily exploited and has the potential to cause significant damage or data loss.
Bill Horne , General Manager of the Secure Systems Product Group and Chief Technology Officer at Intertrust, told Toolbox that nearly every healthcare application examined lacks the proper tools to protect itself from attacks .
Data breaches cost healthcare providers an average of $7.13 million per breach. Nevertheless, they do not make a special effort to secure themselves.
According to the Verizon Data Breach Investigations, the healthcare sector was hit by 798 attacks, 521 of which resulted in confirmed data breaches in 2020.

The risk is further amplified if applications lack strong encryption. According to the Intertrust report, 91% of applications lack strong encryption for their data, which increases the chances of information exposure, code manipulation, illegal command execution, and IP theft.
Additionally, 34% of Android apps and 28% of iOS apps were vulnerable to cryptographic issues that present the most widespread and serious threats.
Data in 60% of Android apps is subject to insecure access control protocols and is open to attackers as it is stored in the Shared Preferences API . In terms of mHealth apps , the most issues were found in health e-commerce apps – 90% contained four or more issues per app. Telemedicine/patient engagement apps came in second at 86.4%, followed by COVID trackers (84.6%) and medical device apps (81.2%).
