Skip to main content
Advertisement
Home

Main navigation

  • Digital Issue Archive
  • Service Directory
  • Awards
  • Advertise
  • Subscribe now

Secondary

  • Travel Insurance
  • Policies & Partnerships
  • Travel Risk Management
  • Travel Trends
  • Hospitals & Healthcare
  • Industry Moves
  • Reviews
International Hospitals & Healthcare Part of the IH&H family
Part of the
IH&H family
International Hospitals & Healthcare
Hospitals & Healthcare

New report calls for increased security across digital health apps

Hospitals & Healthcare
26 Feb 2021 | Robyn Bainbridge
Share
cybersecurity digital health

A report published by cybersecurity firms highlights that digital health apps are vulnerable to API attacks, as well as EHR breaches

Cybersecurity firm Knight Inc and mobile security company Approov have joined forces to highlight the inadequacies of digital security that most health apps currently have in place. The companies ‘ethically hacked’ 30 mobile health apps to highlight the threats they face through application program interfaces (APIs) - which Approov Founder and CEO David Stewart explained are the communication channels between a mobile app and a cloud service, physical server or hospital infrastructure. APIs allow mobile phones to access X-rays, pathology reports and allergy data.

The problem is systemic

In a report titled All That We Let In, the firms noted that all 30 of the apps involved in the study were vulnerable to API attacks. The study also revealed that some of the apps even allowed access to electronic health records (EHRs). Collectively, the 30 apps expose 23 million mobile health users to attacks, Knight reported.

Commenting on her findings, Alissa Knight, researcher and author of the report, said: “Look, let’s point the pink elephant out in the room. There will always be vulnerabilities in code so long as humans are writing it. Humans are fallible. But I didn’t expect to find every app I tested to have hard-coded keys and tokens and all of the APIs to be vulnerable to broken object level authorization (BOLA) vulnerabilities allowing me to access patient reports, X-rays, pathology reports, and full PHI records in their database. The problem is clearly systemic.”

Protecting patient data from API attacks

Approov’s Stewart added: “These findings are disappointing but not at all surprising. The fact is that leading developers and their corporate and organisational customers consistently fail to recognise that APIs servicing remote clients such as mobile apps need a new and dedicated security paradigm.

“Because so few organisations deploy protections for APIs that ensure only genuine mobile app instances can connect to backend servers, these APIs are an open door for threat actors and present a real nightmare for vulnerable organisations and their patients.”

With the surge in mHealth usage – including telehealth platforms being implemented by international insurers and assistance providers – there needs to be comprehensive protection in place to ensure that individuals’ (patients, employees, etc.) health data is not at the risk of being breached – as Knight points out, personal health data is the most valuable form of data on the dark web.

As such, organisations that have implemented digital health apps and similar platforms into their operations are advised to address both app security and API security through myriad ways identified in the published report.

In February, French health insurance company Mutuelle Nationale des Hospitalier was hit by a ransomware attack that disrupted the company's healthcare operations.

Robyn Bainbridge

Robyn Bainbridge edits the International Hospitals & Healthcare Review and is a writer and copy-editor for both ITIJ and AirMed&Rescue. Six years a freelance writer, she enjoys injecting a fresh take on a tired topic and is a keen advocate of sustainable tourism. She also has over 15 species of plants in her living room.

Ebola vaccine

CEPI approves funds for Ebola vaccine development

3 Jun 2026
Oliver Cuenca
APRIL International retains top IPMI service rating for fifth consecutive year

APRIL International retains top IPMI service rating for fifth consecutive year

1 Jun 2026
Siân Yates
telemedicine laptop

South Korea to expand telemedicine services for foreign patients

1 Jun 2026
Oliver Cuenca
orient-insurance-and-allianz-partners-launch-sphera-international-healthcare-plans

Orient Insurance and Allianz Partners launch Sphera international healthcare plans

29 May 2026
Oliver Cuenca
Hospitals & Healthcare Headlines
Medanta hospital expansion

Medanta Group outlines hospital network expansion plans

The healthcare provider is planning a major expansion of its facilities in the coming years, with five new hospitals planned in four Indian cities
28 May 2026
|
Oliver Cuenca
Italy investigates two suspected Ebola cases in Milan linked to Uganda aid workers

Two suspected Ebola cases in Italy linked to Uganda aid workers test negative

The suspected Ebola cases in Milan involving aid workers returning from Uganda underscore escalating cross-border transmission risks linked to the ongoing outbreak
26 May 2026
|
Chloe Fox
Anthropic and Gates Foundation launch $200m AI partnership focused on global health and education

Anthropic and Gates Foundation launch $200m AI partnership focused on global health and education

The new four-year partnership aims to expand access to AI tools and infrastructure across healthcare and education systems
26 May 2026
|
Siân Yates
Dubai UAE skyline night

UAE to build universal healthcare system

The system, which will be underpinned by a national health insurance scheme, aims to provide international-standard healthcare provision to all citizens
25 May 2026
|
Oliver Cuenca
test

The Red Cross has expressed condolences for three volunteers who died after contracting Ebola while handling bodies in the Democratic Republic of Congo

The Bundibugyo strain of Ebola – for which there is no approved vaccine or treatment – has been declared an international public health emergency by the World Health Organization
25 May 2026
|
Michelle Royle
Berlin partnership accelerates AI-driven shift in cardiovascular care

Berlin partnership accelerates AI-driven shift in cardiovascular care

A Berlin partnership aims to advance AI-driven cardiology, highlighting the growing role of predictive, connected care in cardiac disease management, and remote monitoring
25 May 2026
|
Siân Yates
Osaka big crab

Osaka reports high rates of unpaid medical bills from foreign visitors

The issue reported by the government of Osaka Prefecture reflects a broader issue for Japanese healthcare providers
23 May 2026
|
Oliver Cuenca
New CEO Netcare

Netcare appoints new CEO

Melanie Da Costa will take the reins of the South African private healthcare provider following a six-month handover process
22 May 2026
|
Oliver Cuenca
Read More Hospitals & Healthcare News
H&H February 2025

February 2025
 Issue

Offering readers a deep dive into the issues facing providers and payers of healthcare services around the world. Cost containment, international patient department development, the role of AI in healthcare delivery and more.

Read full issue

Hospitals & Healthcare Long Reads

Suitcase with sandals

Patients without borders

Global travel has rebounded from its pandemic slump – and medical tourism is no exception. IH&H explores the top destinations for cross-border care, and the treatments patients are seeking
1 May 2026
|
Editorial Team
Woman in airport

Canadian patients look abroad for healthcare relief

Milan Korcock shares details about Canadians bypassing domestic waiting lists and heading abroad for care, exploring why the trend is accelerating, which treatments are most affected, and how insurers are...
1 May 2026
|
Milan Korcok
Image of south korea landscape

South Korea’s medical tourism surge

Chloe Fox speaks to industry experts about South Korea’s rise as a medical tourism hub, the global demand for K-beauty and advanced treatments, and the patient-focused services shaping the sector’s...
1 May 2026
|
Chloe Fox
Singapre city skyline

Singapore’s IPMI shift: a blueprint for Southeast Asia’s healthcare future

Singapore’s regulatory adjustments, provider-payer collaboration, and emphasis on transparency offer practical lessons for healthcare systems in Thailand, Malaysia, Indonesia, and Vietnam as they navigate rapid private healthcare growth, medical inflation, and...
1 May 2026
|
Lauren Haigh
Landscape of India

A passage to India

For the citizens of India, and many expats, public healthcare provision can vary wildly depending on where they are. But what does the private healthcare landscape look like – particularly...
1 May 2026
|
Stefan Mohamed
Illustration of doctors

Safe and responsible adoption of AI in healthcare

David Qu explores how AI is transforming global healthcare, from patient care to drug discovery, while addressing data, bias, privacy, and ethical challenges
1 May 2026
|
Editorial Team
Doctors with graphs behind them

From cash pay to covered benefit: the rise of stem cell therapy in insurance

Jonathan Edelheit, CEO of Healthcare Revolution and Co-Founder and CEO of the Medical Tourism Association, shares how regenerative medicine is now sufficiently mainstream that insurers are changing their benefits structure...
1 May 2026
|
Jonathan Edelheit
Graphs and charts

UK wealth moves signal global shift in premium healthcare demand

Karim Idilby, Chief Growth Officer, AXA Global Healthcare, discusses shifting global wealth migration, the policy forces driving talent mobility, and evolving expectations for international healthcare
1 May 2026
|
Karim Idilby
Read More Hospitals & Healthcare Long Reads

Why subscribe to ITIJ?

In-depth analysis

In-depth analysis

Unique insights and expert opinions on the latest industry developments

A wider perspective

A wider perspective

Get the global view on the topics that are trending in your region

Breaking news

Breaking news

ITIJ.com has all the latest news relevant to travel insurance and IPMI professionals

Subscribe now
ITIJ IH&H

Footer menu

  • About Us
  • Subscribe
  • Advertise
  • Contact
  • Privacy Policy
  • Terms
  • Voyageur
International Travel & Health Insurance Conferences

Social

  • LinkedIn link
  • Twitter link

© Voyageur Publishing & Events 2026

Close