Mobile Device Pentesting for a Healthcare Technology and Research Company

Mobile Device Pentesting for a Healthcare Technology and Research Company

Industry
Healthcare

Summary

A multinational healthcare technology, research, and consulting company stored, processed, and transferred personal health information (PHI) for commercial clinical trials. As part of its routine security testing after significant changes to corporate software and IT infrastructure, the Client needed to check the Android and iOS mobile devices used by employees for vulnerabilities that could endanger PHI. INNERLUXES's ethical hackers performed multi-level penetration testing, uncovered critical vulnerabilities missed by a previous vendor, and delivered severity-ranked reports with actionable remediation guidance.

About the Client

The Client is a multinational company providing technology solutions, research, and consulting services for the healthcare industry, operating across many countries worldwide.

The Challenge

To conduct commercial clinical trials, the Client stored, processed, and transferred personal health information. To ensure PHI protection and comply with HIPAA regulations, the Client resorted to security testing after any significant changes in corporate software and IT infrastructure. At this stage, the Client needed to check the Android and iOS mobile devices used by its employees for working purposes for security vulnerabilities that could endanger PHI.

The Solution

INNERLUXES's ethical hackers explored the Client's corporate Android and iOS mobile devices at the hardware, middleware, and software levels. They performed black-box and gray-box penetration testing, including:

  • Assessment of wireless transmission of data.
  • Assessment of encryption protocols.
  • Assessment of mobile Bluetooth settings.
  • Exploration of OS security permissions.
  • Analysis of commonly known vulnerabilities of the specific versions of mobile devices and mobile applications under test.
  • Attempted SMS-based attacks (DoS, malware dissemination).
  • Input data manipulation (SQL injections, buffer overflow, network protocol violations).

INNERLUXES's pentesters revealed several critical vulnerabilities that had been missed during previous checks by another vendor. These included outdated user applications and mobile OS versions, unrestricted access to certain user applications, and poorly secured Wi-Fi.

INNERLUXES's security experts documented all the security gaps found and provided recommendations on preventing their exploitation. They advised implementing a reliable network authentication protocol, monitoring Wi-Fi access points on the mobile devices, updating security patches and mobile OS versions, deleting unnecessary user applications, and restricting user access to the Suggested Apps feature and emergency apps, among others.

INNERLUXES also delivered consultations for the Client's IT team to help them better understand the existing security gaps and the best ways to address them.

The Results

  • The Client received detailed reports on the detected vulnerabilities, classified by severity and likelihood, along with actionable guidance on remediation.
  • Satisfied with INNERLUXES's professional approach, the Client decided to rely on INNERLUXES's security experts for another penetration testing project.

Technologies and Tools

Nmap, Wireshark, Metasploit, custom scripts (Python, C, and Perl scripts for the exploitation of vulnerabilities).