Skip to main content
U.S. flag

An official website of the United States government

Official websites use .gov
A .gov website belongs to an official government organization in the United States.

Secure .gov websites use HTTPS
A lock ( ) or https:// means you’ve safely connected to the .gov website. Share sensitive information only on official, secure websites.

Beta This is a new resource

Series: Cybersecurity Testing of HHS and Consumer Mobile Applications

Announced on  | Last Modified on  | Series Number: W-00-24-42040

OBJECTIVE

Various HHS OpDivs use mobile applications as alternative ways to reach mobile device users. Cybersecurity researchers have indicated that a large majority of Android and iOS apps across every industry lack the most basic security protections.HHS-OIG will perform a series of penetration test audits of certain mobile applications to determine whether security controls protecting HHS and its OpDivs' mobile applications are effective in preventing certain cyberattacks. Also, as part of this work, we will determine whether HHS and its OpDivs are following required security standards and policies for the development and vetting of mobile apps.HHS-OIG will perform this work because of the steady increase in the use of mobile apps by HHS and its OpDivs to provide access to health services.

There are 3 projects in this series.

ACTIVE PROJECTS IN THIS SERIES (2)

COMPLETED PROJECTS IN THIS SERIES (1)

Penetration Test of AHRQ Consumer Mobile Applications

TIMELINE

  • October 11, 2021
    Series Number W-00-24-42040 Assigned
  • October 11, 2021
    Project Announced

    Project A-18-22-09006

  • February 15, 2022
    Project Announced

    Project A-18-22-09007

  • March 14, 2022
    Project Announced

    Penetration Test of AHRQ Consumer Mobile Applications - A-18-22-09008

  • December 17, 2024
    Project Complete - A-18-22-09008

    Penetration Test of AHRQ Consumer Mobile Applications has been marked as complete. This audit resulted in 3 recommendations.

  • Today
    2 Audits In-Progress
  • Est FY2026
    Estimated Fiscal Year for Series Completion

1 REPORT PUBLISHED

25-A-18-027.01 to AHRQ - Open Unimplemented
Update expected on 06/16/2025
We recommend that the Agency for Healthcare Research and Quality reassess the Question Builder app to determine if the unnecessary functionality and privileges built into the app can and should be removed or formally assess, document, and accept the risk of not removing them.

25-A-18-027.02 to AHRQ - Open Unimplemented
Update expected on 06/16/2025
We recommend that the Agency for Healthcare Research and Quality update the AHRQ Mobile Application Development Policy to require project officers and app developers to assess AHRQ mobile apps for unnecessary or unused functionality and remove or disable such functionality where feasible before submitting it to an app store and establish a procedure to ensure adherence to these requirements.

25-A-18-027.03 to AHRQ - Open Unimplemented
Update expected on 06/16/2025
We recommend that the Agency for Healthcare Research and Quality update the AHRQ Mobile Application Development Policy to require vetting the security of all AHRQ mobile apps for compliance with the HHS secure coding policy requirements and correcting any security vulnerabilities identified before releasing a mobile app to app stores for public use and establish a procedure to ensure adherence to these requirements

View in Recommendation Tracker

-
-