Engagements  /  PSY-API-0451

The mobile API that trusted the app too much

A virtual-care app filtered patient records on the phone. The server sent everything and let the app decide what to show.

Representative engagement. Client names, figures and identifying details are changed or combined; no client findings are published in identifiable form.

Sector
Healthcare and health tech
Engagement
API security test
Frameworks
OWASP API Security Top 10 (2023), OWASP MASVS, HIPAA Security Rule
Duration
9 test days

A virtual-care platform.

The platform connected patients with clinicians by video, and stored visit notes, prescriptions and uploaded documents. Its web portal had been tested the year before. Its mobile API had not, on the assumption that it shared the same back end.

It shared the data, but not the controls.

What we did

Test the API as if the app did not exist.

Intercept and enumerate

We proxied the iOS and Android apps to map every call, then compared the result with the documented API. Eleven endpoints existed only for mobile.

Ask for more than the screen shows

Several endpoints returned whole patient objects — including fields the app never displayed — and one accepted writes to fields the app never sent.

Tie it to a risk analysis

Findings were written into the client’s HIPAA Security Rule risk analysis, so the remediation became documented risk treatment, not just a ticket queue.

What we found

Excessive data, and one dangerous write.

SeverityFindingMaps toStatus at retest
CriticalClinician-assignment endpoint let a patient account set its own record to any clinician and read their schedule.API3:2023 BOPLA · API5:2023Closed
HighVisit-history responses included other household members’ notes on shared family accounts.API3:2023 · CWE-213Closed
HighDocument download links were pre-signed for 7 days and not bound to a session.API1:2023 · ASVS V14Closed
MediumDeprecated v1 endpoints still live, without the newer rate limits.API9:2023Closed
MediumCertificate pinning absent on Android build.MASVS-NETWORKAccepted risk

What changed.

The API now returns only the fields each screen needs, enforced by a response schema on the server rather than by the app. The legacy endpoints were retired.

The risk analysis, previously a template, now reflects the platform’s real data flows and was reused for the client’s first hospital partnership review.

Next engagement

Want this for your application?

Tell us what you ship and who is asking for proof. We will come back with a scope and a range.