Mobile health apps leak sensitive data through APIs, report finds
Recovering hacker” Alissa Knight calls personal health information
the most valuable data on the dark web. The Knight Ink cybersecurity
researcher says, “It's 10 times more the price of a credit card for a
single PHI record.”
Knight partnered with mobile security company Approov to hack 30
mobile health apps to highlight the threats they face through
application program interfaces (APIs).
All of the apps were found to be vulnerable to API attacks, and some
allowed access to electronic health records (EHRs). The 30 apps
collectively expose 23 million mobile health users to attacks.
APIs are the communication channels between a mobile app and a
cloud service, physical server or hospital infrastructure.
It is predicted that by 2022 API attacks will no longer be infrequent
but will become the most frequent attack vector for application
breaches. APIs allow mobile phones to access X-rays, pathology
reports and allergy data.
During her research, Knight hacked into the system of one hospital,
changing the values of an EHR by one digit and then was able to
access the health records of the patient’s family members and other
information that a hospital’s registration desk had captured for a
patient. Knight used a hacking tool that looks like it is generating data
from a mobile health app (Horowitz, 2021).
Phishing Attack Prevention: How to Identify & Avoid Phishing Scams in 2022
Phishing attacks are one of the most common security challenges that
both individuals and companies face in keeping their information
secure. Whether it's getting access to passwords, credit cards, or
other sensitive information, hackers are using email, social media,
phone calls, and any form of communication they can to steal
valuable data.
Phishing attacks are done via email. Phishing attacks use an email
address that resembles a legitimate email address, person or
company. The email will include a request to click a link, change a
password, send a payment, respond with sensitive information, or
open a file attachment.
There are multiple steps a company can take to protect against
phishing.
• Educate your employees and conduct training sessions with
mock phishing scenarios.
• Deploy a SPAM filter that detects viruses, blank senders, etc.
• Keep all systems current with the latest security patches and
updates.
• Install an antivirus solution, schedule signature updates, and
monitor the antivirus status on all equipment.
• Develop a security policy that includes but isn't limited to
password expiration and complexity.
• Deploy a web filter to block malicious websites.
• Encrypt all sensitive company information.
• Convert HTML email into text only email messages or disable
HTML email messages.
• Require encryption for employees that are telecommuting.
(Phishing attack prevention: How to identify & avoid phishing scams in
2022 2022)
References:
Horowitz, B. (2021, February 24). Mobile health apps leak sensitive
data through apis, report finds. Fierce Healthcare. Retrieved June 2,
2022, from https://www.fiercehealthcare.com/tech/mobile-health-
apps-leak-sensitive-data-through-apis-report-finds
Phishing attack prevention: How to identify & avoid phishing scams in
2022. Digital Guardian. (2022, March 14). Retrieved June 2, 2022,
from https://digitalguardian.com/blog/phishing-attack-prevention-
how-identify-avoid-phishing-scams