Alex Lotsu’s Post

View profile for Alex Lotsu, graphic

iOS Developer | Writing about Secure Mobile Development

Developers, don't be like healthcare.gov In 2015 Healthcare.gov, revealed they had been sending Personal health data to at least 14 3rd party domains even if the user selected ‘Do Not Track’. This included zip code, income level, smoking status, pregnancy status and more. Not only was this damaging to the organisation’s reputation and user trust, but it also likely broke HIPAA laws. If this happened in today's age in Europe it would be breaking GDPR compliance. Lessons from Healthcare.gov 🔒 • 3rd party vetting - Map data flows to 3rd parties. This is something you should now be doing as an iOS developer to complete Apple’s Privacy Manifest requirement. • Data minimisation - Only collect and share data that is necessary. • User consent & transparency in the data you collect. In future posts, I will break down essential tips for mobile developers to avoid this being you 💥. https://lnkd.in/edqZbbH6

To view or add a comment, sign in

Explore topics