CommonSpirit - AR/GA/KY/TN/TX Security & Privacy Scorecard

by CommonSpirit Health · iOS

76
Overall trust score
Acceptable
71
Security
87
Privacy

Health data stays within the app with no third-party services receiving user information. Network connections have some weaker protections, which means data sent over public Wi-Fi travels with less protection than expected. Overall, personal and medical information is handled with reasonable care.

Best for

Patients managing care with CommonSpirit Health

Findings

  • 0 critical
  • 6 high
  • 4 medium
  • 5 low
  • 9 info

5 issues identified across security and privacy analysis.

Top security issues

  • Global ATS disable removes OS-level TLS enforcement for all PHI transmissions in a HIPAA-covered app
  • Custom server URL override in Settings.app silently redirects all PHI and credentials to attacker-controlled endpoint
  • Pre-login SSO WebView accepts HTTP content from broad domain wildcard, enabling credential phishing via network interception

Top privacy issues

  • Misleading HealthKit consent string implies no upload occurs while health readings are automatically sent to Epic/CommonSpirit servers in background
  • Background HealthKit delivery entitlement enables silent PHI upload to clinical servers without per-event user awareness
  • UserDefaults used for functional state that may include clinically meaningful health data type consent choices and proxy patient indicators

Full analysis

Overall Score: 71/100 | Version 11.5.2 | Scanned 2026-04-06

What This Means for You

Health data stays within the app with no third-party services receiving user information. Network connections have some weaker protections, which means data sent over public Wi-Fi travels with less protection than expected. Overall, personal and medical information is handled with reasonable care.

Recommendation: Acceptable

Best For: Patients managing care with CommonSpirit Health

Key Findings

Data Security - 4 findings (1 medium, 2 low, 1 info)

Network Security - 6 findings (2 high, 1 medium, 1 low, 2 info)

Code Safety - 0 findings

Privacy - 3 findings (1 medium, 1 low, 1 info)

Privacy Concerns

What Data is Collected

The app collects personal and health information needed for patient portal use, including name, contact details, and medical record access for appointment scheduling and care management.

Third-Party Data Sharing

No third-party services were identified as receiving user data. Health information remains within the app and CommonSpirit Health's own systems.

Understanding the Scores

Category Score
Security 71/100
Privacy 87/100
Data Security 77/100
Network Security 58/100
Code Safety 92/100
Data Collection 90/100
Data Sharing 100/100
User Control 92/100

Positive Security Features

  • Health information is not shared with advertising networks or analytics companies
  • Strong user controls give patients meaningful authority over their own data
  • The app's code is built with solid safety practices, reducing the risk of common software errors affecting the device

Areas for Improvement

  • Some network connections use older or weaker protection methods, meaning data sent over public Wi-Fi or untrusted networks travels with less protection than expected.
  • Data stored locally on the device could benefit from stronger protections in case the phone is lost or accessed without permission.
  • Improving how the app verifies the identity of the servers it communicates with would provide better protection on public networks.

About This Analysis

This scorecard is based on automated static analysis of the application's code and configuration. Scores reflect security and privacy practices at the time of the scan.

App Details

  • App: org.commonspirit.CommonSpiritSouth
  • Version: 11.5.2 (Build 11.5.2.1)
  • Scan Date: 2026-04-06

Versions & scan history

ScanDateOverall score
#1 (current) 76/100