Doximity - Medical Network Security & Privacy Scorecard
Android
User activity is tracked by Segment Analytics and Singular, which share behavioral data with advertising and attribution networks. Bugsnag and Firebase collect diagnostic information about how the app is used. Data is stored with weaker protections than expected for a medical platform.
Best for
Healthcare professionals comfortable with standard analytics
Findings
- 3 critical
- 4 high
- 5 medium
- 1 low
- 0 info
0 issues identified across security and privacy analysis.
Top security issues
- Unencrypted PHI in Room Databases
- OAuth Client Secrets Hardcoded in APK
- Hardcoded Environment API Token
Top privacy issues
- Unencrypted PHI in Room Databases
- Device ID Injection in Login WebView
- Clipboard Data Exposure
Full analysis
Doximity - Medical Network
What This Means for You
User activity is tracked by Segment Analytics and Singular, which share behavioral data with advertising and attribution networks. Bugsnag and Firebase collect diagnostic information about how the app is used. Data is stored with weaker protections than expected for a medical platform.
Recommendation: Use With Caution
Best For: Healthcare professionals comfortable with standard analytics
Key Findings
Data Security - 2 findings (1 critical, 1 medium)
Network Security - 0 findings
Code Safety - 0 findings
Privacy - 4 findings (1 high, 2 medium, 1 low)
Privacy Concerns
What Data is Collected
Doximity collects professional and behavioral data including usage patterns, device identifiers, and in-app activity. Diagnostic data about how users interact with the app is gathered through Bugsnag and Firebase, which monitor crashes and performance. Communication features powered by Twilio, 100ms, and Telnyx WebRTC may process audio and messaging content.
Third-Party Data Sharing
Behavioral and usage data is shared with the following third-party services:
- Segment Analytics - Collects and routes behavioral data to downstream advertising and analytics platforms
- Singular - Attribution service that shares user activity data with advertising networks to measure ad performance
- Firebase - Google's platform for app diagnostics, crash reporting, and usage analytics
- Bugsnag - Crash and error monitoring service that receives diagnostic information about user sessions
- Twilio, 100ms, Telnyx WebRTC - Communication infrastructure providers that handle call and messaging data
- Apollo GraphQL - Data query layer used for app-to-server communication
Understanding the Scores
| Category | Score |
|---|---|
| Security | 58/100 |
| Privacy | 68/100 |
| Data Security | 45/100 |
| Network Security | 95/100 |
| Code Safety | 60/100 |
| Data Collection | 72/100 |
| Data Sharing | 70/100 |
| User Control | 65/100 |
Positive Security Features
- Network communications are well-secured, with strong protections against interception of data in transit.
Areas for Improvement
- Local data storage uses weaker protection settings than expected for a medical platform, increasing risk if a device is lost or accessed without authorization.
- Behavioral data flows to advertising and attribution networks through Segment and Singular. Clearer in-app controls to limit this sharing would better protect user privacy.
- The level of diagnostic and behavioral data collected across multiple third-party services exceeds what is typical for a professional medical networking app.
About This Analysis
This scorecard is based on automated static analysis of the application. Scores reflect observed practices at the time of analysis and may not capture all behaviors.
App Details
- App: Doximity - Medical Network
- Package: com.doximity.doximitydroid
- Version: 11.44.0 (Build 262908)
- Scan Date: 2025-12-21
Versions & scan history
| Scan | Date | Overall score |
|---|---|---|
| #4 (current) | 62/100 | |
| #2 | 78/100 | |
| #1 | 85/100 |