QuickBlox’s video and chat features are commonly used in mainstream telemedicine applications and platforms. The researchers analyzed a mobile telemedicine application from an undisclosed organization that uses QuickBlox’s framework to provide chat and video services for patients to connect with physicians. The research revealed existing vulnerabilities that worsened when combined with QuickBlox’s framework.
Here are some of the flaws researchers discovered:
- The app leaked all aspects of the user database, such as medical records, medical history and stored chat history.
- The vulnerabilities allow any hacker to obtain usernames and passwords and impersonate a patient or physician.
- The ability to impersonate a physician grants the power to alter patient information and speak with patients live or in the name of their physician.
The research teams disclosed their findings to QuickBlox, which corrected these flaws and prompted users to update their framework to the latest version, according to the report.
At the Becker's 11th Annual IT + Revenue Cycle Conference: The Future of AI & Digital Health, taking place September 14–17 in Chicago, healthcare executives and digital leaders from across the country will come together to explore how AI, interoperability, cybersecurity, and revenue cycle innovation are transforming care delivery, strengthening financial performance, and driving the next era of digital health. Apply for complimentary registration now.