Medibank tackles mobile app security

 

Builds native iOS, Android apps based on business demand.

Medibank Private has adopted a defence-in-depth strategy to secure customers’ healthcare data in the face of its recently launched self-service mobile applications.

The private health insurer introduced its three mobile apps in December, as part of a 2011 project to integrate its insurance and healthcare businesses.

Enterprise architect Mark White and his team was given six months to develop and deploy the apps, which allow customers to submit claims, search for nearby healthcare providers, look up symptoms, and keep track of food intake and exercise.

Speaking at the IBM Pulse conference in Las Vegas this week, White described the challenge of balancing technologists’ security concerns with the business’ demand for user-friendly features.

The Medibank Mobile App in particular was intended to access Medibank’s customer relationship management (CRM) system and claims engine to allow users to submit claims and view their policy details.

Because it involved personal information, the app and data needed to be secure. But customers were unlikely to want to remember yet another password just to use the app.

"Customer experience desires a streamlined customer interaction model within the mobile application environment," White said, describing the ideal experience as one that required the minimum number of touches, or actions, by the user.

"This desire sometimes conflicts with the need to maintain security and customer privacy."

Medibank's customer experience and IT professionals initially disagreed over the business' desire to store passwords on the device and to simplify the password to a shortened PIN.

The insurer decided to reuse customers’ web login details – already stored in Medibank’s CRM – for its mobile offerings.

It integrated the mobile apps with IBM’s WebSEAL access management product, leaning heavily on the vendor and its out-of-the-box APIs to ensure the implementation was secure.

Apps were designed to store no health information; instead, they were synchronised in real time with back-end systems on Medibank’s private cloud.

Customers were advised in the applications’ terms and conditions that although Medibank would secure data, the users were responsible for their devices and any information stored outside of the apps – such as contact details.

The apps also featured in-built certificates to allow Medibank systems to tell them apart from malicious counterfeits.

“It’s easy to look at a mobile app and say, okay we just need to enable some APIs within our network to transmit data in and out, but you really need to think about security in depth,” White told the conference.

“We put in a lot of architectural layers to ensure that we’re protected from attacks … we had to enable load balancing, we had to build a special app to do API integration into the backend systems, and we had to enable our WebSEAL environment.”

Looking forward, White said Medibank would likely develop hybrid mobile applications, blending native and web elements so they to facilitate updates and more efficient access to backend data.

The insurer was also “putting [its] toe into the water” of social networks by allowing users to link their Facebook accounts with its Energy Balancer app and post exercise goals on their profiles.

Future work will be informed by user behaviour tracking data from its Energy Balancer, Medibank Mobile and Symptom Checker apps. For privacy purposes, such data is de-identified and no health information is used.

Liz Tay attended IBM Pulse in Las Vegas as a guest of IBM

Copyright © iTnews.com.au . All rights reserved.


Medibank tackles mobile app security
 
 
 
 
Top Stories
ATO commits to complexity
Greater demand, fewer apps.
 
Photos: AusCERT 2013 day two
The second day of the Queensland security conference.
 
The illusion of cognitive computing
Opinion: IBM's Watson is a marketing success.
 
 
Sign up to receive iTnews email bulletins
   FOLLOW US...

Latest VideosSee all videos »

Bankwest builds continuous delivery capability
Bankwest builds continuous delivery capability
To automatically deploy test/dev sandboxes by mid-year.
Veterans' Affairs sets sights on modernisation
Veterans' Affairs sets sights on modernisation
Data safe with Human Services, CIO says.
Citi Australia drops platform customisations
Citi Australia drops platform customisations
Technology chief shifts focus from building to leveraging systems.
VicRoads restructures IT team
VicRoads restructures IT team
Department moves to align with industry benchmarks.
Zurich Australia extends IT team offshore
Zurich Australia extends IT team offshore
Malaysian staff served from Australian data centres.
Leigh Berrell - Utilities CIO of the Year
Leigh Berrell - Utilities CIO of the Year
Yarra Valley Water CIO Leigh Berrell accepts his Benchmark Award for Utilities CIO of the Year.
Wayne McMahon - Retail CIO of the Year
Wayne McMahon - Retail CIO of the Year
Domino's Pizza CIO Wayne McMahon accepts his Benchmark Award for Retail CIO of the Year.
Inside Perpetual's ongoing IT transformation
Inside Perpetual's ongoing IT transformation
CIO Jenny Levy discusses how outsourcing will help the firm "simplify, refocus and grow".
Managing Complexity - Defence's Daniel McCabe
Managing Complexity - Defence's Daniel McCabe
Daniel McCabe, Assistant Secretary of Australia's Department of Defence, provides the audience at the iTnews Data Centre Strategy Summit with a deep dive into the organisation's data centre consolidation program.
How Facebook designed the data centre from scratch - Marco Magarelli
How Facebook designed the data centre from scratch - Marco Magarelli
The full keynote by Facebook data centre architect Marco Magarelli at the Australian Data Centre Strategy Summit. Magarelli details the design considerations behind the social network's Prineville, Oregon; North Carolina and Luleå, Sweden data centres.
Modernising Legacy Data Centres - Telstra's Jon Curry
Modernising Legacy Data Centres - Telstra's Jon Curry
Telstra general manager of managed data centres Jon Curry guides the audience at the iTnews Australian Data Centre Summit through the build of the telco's Clayton, Victoria data centre.
NSW Government launches NABERS data centre rating tools
NSW Government launches NABERS data centre rating tools
Matthew Clark from the NSW Department of Environment guides facilties managers through the details of the new NABERS data centre energy rating tool at the Australian Data Centre Strategy Summit.
NABERS launch panel: Australian Data Centre Strategy Summit
NABERS launch panel: Australian Data Centre Strategy Summit
Matthew Clark (NSW Dept of Environment), Greg Boorer (Canberra Data Centres), Glenn Allan (National Australia Bank), Mike Andrea (Strategic Directions) and Bob Sharon (Green Global Consulting) discuss the impact of the NABERS data centre rating.
Judges notes: Fortescue Metals [The Benchmark Awards]
Judges notes: Fortescue Metals [The Benchmark Awards]
iTnews' panel of judges discuss Fortescue Metals 'New World of Work" project, one of three shortlisted finalists for the Industrials category of the CIO Benchmark Awards.
Judges notes: Retail [The Benchmark Awards]
Judges notes: Retail [The Benchmark Awards]
iTnews' panel of judges discuss the shortlisted finalists for the Retail category of the CIO Benchmark Awards.
Judges notes: Pacific Aluminium [The Benchmark Awards]
Judges notes: Pacific Aluminium [The Benchmark Awards]
iTnews' panel of judges discuss Pacific Aluminium's lightning fast service desk refresh, one of three shortlisted finalists for the Industrials category of the CIO Benchmark Awards.
Judges notes: Domino's Pizza [The Benchmark Awards]
Judges notes: Domino's Pizza [The Benchmark Awards]
iTnews' panel of judges discuss Domino's Pizza's shift to hosted services, one of three shortlisted finalists for the Retail category of the CIO Benchmark Awards.
Judges notes: McDonald's Australia [The Benchmark Awards]
Judges notes: McDonald's Australia [The Benchmark Awards]
iTnews' panel of judges discuss McDonald's Australia's new self-service portal for employees, one of three shortlisted finalists for the Retail category of the CIO Benchmark Awards.
Judges notes: ING Direct [The Benchmark Awards]
Judges notes: ING Direct [The Benchmark Awards]
iTnews' panel of judges discuss ING Direct's 'Bank in a Box', one of three shortlisted finalists for the banking and finance category of the CIO Benchmark Awards.
Judges notes: Yarra Valley Water [The Benchmark Awards]
Judges notes: Yarra Valley Water [The Benchmark Awards]
iTnews' panel of judges discuss Yarra Valley Water's insourcing project, one of three shortlisted finalists for the Utilities category of the CIO Benchmark Awards.
Latest articles on BIT Latest Articles from BIT
Work in a restaurant, café, shop? This familiar to you?
May 24, 2013
If you work in cafe, restaurant or a shop, you might relate to this video. Take a look.
Can your tablet do this? The Dell Latitude 10's removable battery
May 24, 2013
Press a small button on the back of the Dell Latitude 10 and it does something not all tablets ...
HP's ElitePad 900: how it's different to the Surface Pro
May 23, 2013
Buying a tablet to use at work? These photos show why the HP ElitePad 900 G1 is an interesting ...
eftpos to trial "mobile wallet"
May 17, 2013
eftpos, the operator of Australia's most widely used debit card system will soon start a mobile ...
New iiNet 4G phone plans include free calls between phones on same account
May 16, 2013
iiNet's new 4G mobile business plans provide free calls between handsets on the same account as ...
Latest Comments
Polls
Do you prefer the Coalition's NBN policy?

   |   View results
Yes
  19%
 
No
  81%
TOTAL VOTES: 1738

Vote