The vulnerability was found in the app’s personal messaging feature that was thought to be secure. Upon investigation, Walgreens determined “an internal application error allowed certain personal messages from Walgreens that are stored in a database to be viewable by other customers using the Walgreens mobile app,” reports ZDNet.
The bug allowed users to view other users’ personal data and drug prescription details between Jan. 9-15. Patient data that may have been exposed included names, prescription details, store numbers and shipping addresses.
Walgreens fixed the flaw on Jan. 15 by disabling the message viewing feature and installing a permanent correction. Although it’s unclear how many patients were affected, Walgreens said that sensitive drug prescription data was only exposed for a small percentage of users.
More articles on cybersecurity:
Texas provider alerts 6,500 patients of phishing attack
Connecticut payer alerts 1,100 members of phishing attack
10 tips for hospitals to mitigate ransomware attacks
At the Becker's 11th Annual IT + Revenue Cycle Conference: The Future of AI & Digital Health, taking place September 14–17 in Chicago, healthcare executives and digital leaders from across the country will come together to explore how AI, interoperability, cybersecurity, and revenue cycle innovation are transforming care delivery, strengthening financial performance, and driving the next era of digital health. Apply for complimentary registration now.