CommonSpirit - AR/GA/KY/TN/TX Security & Privacy Scorecard
by CommonSpirit Health · iOS
Health data stays within the app with no third-party services receiving user information. Network connections have some weaker protections, which means data sent over public Wi-Fi travels with less protection than expected. Overall, personal and medical information is handled with reasonable care.
Best for
Patients managing care with CommonSpirit Health
Findings
- 0 critical
- 6 high
- 4 medium
- 5 low
- 9 info
5 issues identified across security and privacy analysis.
Top security issues
- Global ATS disable removes OS-level TLS enforcement for all PHI transmissions in a HIPAA-covered app
- Custom server URL override in Settings.app silently redirects all PHI and credentials to attacker-controlled endpoint
- Pre-login SSO WebView accepts HTTP content from broad domain wildcard, enabling credential phishing via network interception
Top privacy issues
- Misleading HealthKit consent string implies no upload occurs while health readings are automatically sent to Epic/CommonSpirit servers in background
- Background HealthKit delivery entitlement enables silent PHI upload to clinical servers without per-event user awareness
- UserDefaults used for functional state that may include clinically meaningful health data type consent choices and proxy patient indicators
Full analysis
Overall Score: 71/100 | Version 11.5.2 | Scanned 2026-04-06
What This Means for You
Health data stays within the app with no third-party services receiving user information. Network connections have some weaker protections, which means data sent over public Wi-Fi travels with less protection than expected. Overall, personal and medical information is handled with reasonable care.
Recommendation: Acceptable
Best For: Patients managing care with CommonSpirit Health
Key Findings
Data Security - 4 findings (1 medium, 2 low, 1 info)
Network Security - 6 findings (2 high, 1 medium, 1 low, 2 info)
Code Safety - 0 findings
Privacy - 3 findings (1 medium, 1 low, 1 info)
Privacy Concerns
What Data is Collected
The app collects personal and health information needed for patient portal use, including name, contact details, and medical record access for appointment scheduling and care management.
Third-Party Data Sharing
No third-party services were identified as receiving user data. Health information remains within the app and CommonSpirit Health's own systems.
Understanding the Scores
| Category | Score |
|---|---|
| Security | 71/100 |
| Privacy | 87/100 |
| Data Security | 77/100 |
| Network Security | 58/100 |
| Code Safety | 92/100 |
| Data Collection | 90/100 |
| Data Sharing | 100/100 |
| User Control | 92/100 |
Positive Security Features
- Health information is not shared with advertising networks or analytics companies
- Strong user controls give patients meaningful authority over their own data
- The app's code is built with solid safety practices, reducing the risk of common software errors affecting the device
Areas for Improvement
- Some network connections use older or weaker protection methods, meaning data sent over public Wi-Fi or untrusted networks travels with less protection than expected.
- Data stored locally on the device could benefit from stronger protections in case the phone is lost or accessed without permission.
- Improving how the app verifies the identity of the servers it communicates with would provide better protection on public networks.
About This Analysis
This scorecard is based on automated static analysis of the application's code and configuration. Scores reflect security and privacy practices at the time of the scan.
App Details
- App: org.commonspirit.CommonSpiritSouth
- Version: 11.5.2 (Build 11.5.2.1)
- Scan Date: 2026-04-06
Versions & scan history
| Scan | Date | Overall score |
|---|---|---|
| #1 (current) | 76/100 |