
{"id":2803,"date":"2014-02-23T00:00:00","date_gmt":"2014-02-23T00:00:00","guid":{"rendered":"http:\/\/otava.test\/security-alert-flaw-in-ios-could-impact-hipaa-and-other-privacy-security-compliance-obligations\/"},"modified":"2014-02-23T00:00:00","modified_gmt":"2014-02-23T00:00:00","slug":"security-alert-flaw-in-ios-could-impact-hipaa-and-other-privacy-security-compliance-obligations","status":"publish","type":"post","link":"https:\/\/www.otava.com\/blog\/security-alert-flaw-in-ios-could-impact-hipaa-and-other-privacy-security-compliance-obligations\/","title":{"rendered":"Security alert: Flaw in iOS could impact HIPAA and other privacy security compliance obligations"},"content":{"rendered":"<p>A hat tip to <a href=\"https:\/\/melniklegal.com\/\" target=\"_blank\" rel=\"noopener noreferrer\">Tatiana Melnik <\/a>\u2013 an attorney concentrating her practice on IT, data privacy and security, and regulatory compliance \u2013 for passing on this security alert, which could impact\u00a0<a href=\"https:\/\/onlinetech.com\/compliant-hosting\/hipaa-compliant-hosting\/overview\" target=\"_blank\" rel=\"noopener noreferrer\">HIPAA <\/a>and other privacy security compliance obligations for those using iPhones, iPads and Mac computers, and any company with a Bring Your Own Device (BYOD) policy in the workplace:<\/p>\n<p><a href=\"https:\/\/arstechnica.com\/security\/2014\/02\/extremely-critical-crypto-flaw-in-ios-may-also-affect-fully-patched-macs\/\" target=\"_blank\" rel=\"noopener noreferrer\">ArsTechnica has reported<\/a> today an extremely critical cryptography flaw discovered in iOS versions 6.1.5, 7.0.4, and 7.0.5, and OS X 10.9.0 and 10.9.1 that has exposed sensitive communications.<\/p>\n<blockquote><p>A critical iOS vulnerability that Apple patched on Friday <strong>gives attackers an easy way to surreptitiously circumvent the most widely used technology for preventing eavesdropping on the Interne<\/strong>t. That made the security bug about as dire as one can be. Now, there&#8217;s <strong>strong evidence that the same flaw also exposes sensitive e-mail and Web communications<\/strong> on fully patched versions of OS X, with no indication that there is a patch currently available for the millions of people who use the Mac operating system.<\/p>\n<p>The flaw, \u201caccording to researchers, causes most iOS and Mac applications to skip a crucial verification check that&#8217;s supposed to happen when many transport layer security (TLS) and secure sockets layer (SSL) connections are being negotiated. \u2026 independent security researcher Ashkan Soltani \u2026 and other researchers say virtually all applications that rely on the SecureTransport TLS layer are susceptible to the attack, regardless of whether they use a technique known as certificate pinning designed to block counterfeit encryption certificates.\u201d<\/p><\/blockquote>\n<p>ArsTechnica suggests these next steps:<\/p>\n<ul>\n<li>Immediately update iPhones and iPads to versions 7.0.6 or 6.1.6, preferably using a non-public network; and<\/li>\n<li>For the time being, people using Macs should avoid using public networks.<\/li>\n<\/ul>\n<p>If you are operating in a BYOD environment, you may want to disable network access to iPhones and iPads until staff members update the operating system on their devices and disable network access to Macs until Apple announces that a patch is available.<\/p>\n<p><strong>Resource:<br \/>\nArsTechnia:<\/strong> <a href=\"https:\/\/arstechnica.com\/security\/2014\/02\/extremely-critical-crypto-flaw-in-ios-may-also-affect-fully-patched-macs\/\" target=\"_blank\" rel=\"noopener noreferrer\">Extremely critical crypto flaw in iOS may also affect fully patched Macs<\/a><strong><br \/>\n<\/strong><\/p>\n<hr \/>\n<p><strong>Related Content<\/strong><br \/>\n<em>For more <a href=\"https:\/\/otavawebsite.wpengine.com\/blog\/tag\/byod\/\">BYOD <\/a>security information, check out a <a href=\"https:\/\/otavawebsite.wpengine.com\/blog\/to-be-byod-or-not-to-be-byod-is-a-bring-your-own-device-policy-right-for-your-organization\/\" target=\"_blank\" rel=\"noopener noreferrer\">replay of a past Online Tech webinar<\/a> co-hosted by Melnik, &#8220;To be BYOD or not to be BYOD: Is a Bring Your Own Device Policy Right for Your Organization?&#8221;<\/em><\/p>\n","protected":false},"excerpt":{"rendered":"<p>A hat tip to Tatiana Melnik \u2013 an attorney concentrating her practice on IT, data privacy and security, and regulatory compliance \u2013 for passing on this security alert, which could impact\u00a0HIPAA and other privacy security compliance obligations for those using iPhones, iPads and Mac computers, and any company with a Bring Your Own Device (BYOD) policy in the workplace: ArsTechnica has reported today an extremely critical cryptography flaw discovered in iOS versions 6.1.5, 7.0.4, and 7.0.5, and OS X 10.9.0 and 10.9.1 that has exposed sensitive communications. A critical iOS vulnerability that Apple patched on Friday gives attackers an easy way to surreptitiously circumvent the most widely used technology for preventing eavesdropping on the Internet. That made the security bug about as dire as one can be. Now, there&#8217;s strong evidence that the same flaw also exposes sensitive e-mail and Web communications on fully patched versions of OS X, with no indication that there is a patch currently available for the millions of people who use the Mac operating system. The flaw, \u201caccording to researchers, causes most iOS and Mac applications to skip a crucial verification check that&#8217;s supposed to happen when many transport layer security (TLS) and secure sockets&#8230;<\/p>\n","protected":false},"author":3,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"footnotes":""},"categories":[1],"tags":[],"other_category":[],"class_list":["post-2803","post","type-post","status-publish","format-standard","hentry","category-uncategorized"],"acf":[],"yoast_head":"<!-- This site is optimized with the Yoast SEO Premium plugin v27.2 (Yoast SEO v27.2) - https:\/\/yoast.com\/product\/yoast-seo-premium-wordpress\/ -->\n<title>Security alert: Flaw in iOS could impact HIPAA and other privacy security compliance obligations | OTAVA<\/title>\n<meta name=\"description\" content=\"Apple&#039;s iOS recently confirmed a critical vulnerability that gives attackers an easy way to eavesdrop on the internet. The vulnerability has been patched.\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/www.otava.com\/blog\/security-alert-flaw-in-ios-could-impact-hipaa-and-other-privacy-security-compliance-obligations\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"Security alert: Flaw in iOS could impact HIPAA and other privacy security compliance obligations\" \/>\n<meta property=\"og:description\" content=\"Apple&#039;s iOS recently confirmed a critical vulnerability that gives attackers an easy way to eavesdrop on the internet. The vulnerability has been patched.\" \/>\n<meta property=\"og:url\" content=\"https:\/\/www.otava.com\/blog\/security-alert-flaw-in-ios-could-impact-hipaa-and-other-privacy-security-compliance-obligations\/\" \/>\n<meta property=\"og:site_name\" content=\"OTAVA\" \/>\n<meta property=\"article:published_time\" content=\"2014-02-23T00:00:00+00:00\" \/>\n<meta name=\"author\" content=\"Irma Brillantes\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"Irma Brillantes\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"2 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\/\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\/\/www.otava.com\/blog\/security-alert-flaw-in-ios-could-impact-hipaa-and-other-privacy-security-compliance-obligations\/#article\",\"isPartOf\":{\"@id\":\"https:\/\/www.otava.com\/blog\/security-alert-flaw-in-ios-could-impact-hipaa-and-other-privacy-security-compliance-obligations\/\"},\"author\":{\"name\":\"Irma Brillantes\",\"@id\":\"https:\/\/www.otava.com\/#\/schema\/person\/35774075f8f4fcdd4eae80cb72034263\"},\"headline\":\"Security alert: Flaw in iOS could impact HIPAA and other privacy security compliance obligations\",\"datePublished\":\"2014-02-23T00:00:00+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\/\/www.otava.com\/blog\/security-alert-flaw-in-ios-could-impact-hipaa-and-other-privacy-security-compliance-obligations\/\"},\"wordCount\":384,\"commentCount\":0,\"publisher\":{\"@id\":\"https:\/\/www.otava.com\/#organization\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"CommentAction\",\"name\":\"Comment\",\"target\":[\"https:\/\/www.otava.com\/blog\/security-alert-flaw-in-ios-could-impact-hipaa-and-other-privacy-security-compliance-obligations\/#respond\"]}]},{\"@type\":\"WebPage\",\"@id\":\"https:\/\/www.otava.com\/blog\/security-alert-flaw-in-ios-could-impact-hipaa-and-other-privacy-security-compliance-obligations\/\",\"url\":\"https:\/\/www.otava.com\/blog\/security-alert-flaw-in-ios-could-impact-hipaa-and-other-privacy-security-compliance-obligations\/\",\"name\":\"Security alert: Flaw in iOS could impact HIPAA and other privacy security compliance obligations | OTAVA\",\"isPartOf\":{\"@id\":\"https:\/\/www.otava.com\/#website\"},\"datePublished\":\"2014-02-23T00:00:00+00:00\",\"description\":\"Apple's iOS recently confirmed a critical vulnerability that gives attackers an easy way to eavesdrop on the internet. The vulnerability has been patched.\",\"breadcrumb\":{\"@id\":\"https:\/\/www.otava.com\/blog\/security-alert-flaw-in-ios-could-impact-hipaa-and-other-privacy-security-compliance-obligations\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\/\/www.otava.com\/blog\/security-alert-flaw-in-ios-could-impact-hipaa-and-other-privacy-security-compliance-obligations\/\"]}]},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\/\/www.otava.com\/blog\/security-alert-flaw-in-ios-could-impact-hipaa-and-other-privacy-security-compliance-obligations\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\/\/www.otava.com\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"Security alert: Flaw in iOS could impact HIPAA and other privacy security compliance obligations\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\/\/www.otava.com\/#website\",\"url\":\"https:\/\/www.otava.com\/\",\"name\":\"OTAVA\u00ae\",\"description\":\"\",\"publisher\":{\"@id\":\"https:\/\/www.otava.com\/#organization\"},\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\/\/www.otava.com\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Organization\",\"@id\":\"https:\/\/www.otava.com\/#organization\",\"name\":\"OTAVA\u00ae\",\"url\":\"https:\/\/www.otava.com\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\/\/www.otava.com\/#\/schema\/logo\/image\/\",\"url\":\"https:\/\/www.otava.com\/wp-content\/uploads\/2025\/03\/otava-logo.svg\",\"contentUrl\":\"https:\/\/www.otava.com\/wp-content\/uploads\/2025\/03\/otava-logo.svg\",\"caption\":\"OTAVA\u00ae\"},\"image\":{\"@id\":\"https:\/\/www.otava.com\/#\/schema\/logo\/image\/\"}},{\"@type\":\"Person\",\"@id\":\"https:\/\/www.otava.com\/#\/schema\/person\/35774075f8f4fcdd4eae80cb72034263\",\"name\":\"Irma Brillantes\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\/\/secure.gravatar.com\/avatar\/d5251bebc1699793a698d1a6158603cb3cdc50a095a12357e42d415b3e5546c2?s=96&d=mm&r=g\",\"url\":\"https:\/\/secure.gravatar.com\/avatar\/d5251bebc1699793a698d1a6158603cb3cdc50a095a12357e42d415b3e5546c2?s=96&d=mm&r=g\",\"contentUrl\":\"https:\/\/secure.gravatar.com\/avatar\/d5251bebc1699793a698d1a6158603cb3cdc50a095a12357e42d415b3e5546c2?s=96&d=mm&r=g\",\"caption\":\"Irma Brillantes\"},\"url\":\"https:\/\/www.otava.com\/blog\/author\/ibrillantesotava-com\/\"}]}<\/script>\n<!-- \/ Yoast SEO Premium plugin. -->","yoast_head_json":{"title":"Security alert: Flaw in iOS could impact HIPAA and other privacy security compliance obligations | OTAVA","description":"Apple's iOS recently confirmed a critical vulnerability that gives attackers an easy way to eavesdrop on the internet. The vulnerability has been patched.","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/www.otava.com\/blog\/security-alert-flaw-in-ios-could-impact-hipaa-and-other-privacy-security-compliance-obligations\/","og_locale":"en_US","og_type":"article","og_title":"Security alert: Flaw in iOS could impact HIPAA and other privacy security compliance obligations","og_description":"Apple's iOS recently confirmed a critical vulnerability that gives attackers an easy way to eavesdrop on the internet. The vulnerability has been patched.","og_url":"https:\/\/www.otava.com\/blog\/security-alert-flaw-in-ios-could-impact-hipaa-and-other-privacy-security-compliance-obligations\/","og_site_name":"OTAVA","article_published_time":"2014-02-23T00:00:00+00:00","author":"Irma Brillantes","twitter_card":"summary_large_image","twitter_misc":{"Written by":"Irma Brillantes","Est. reading time":"2 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/www.otava.com\/blog\/security-alert-flaw-in-ios-could-impact-hipaa-and-other-privacy-security-compliance-obligations\/#article","isPartOf":{"@id":"https:\/\/www.otava.com\/blog\/security-alert-flaw-in-ios-could-impact-hipaa-and-other-privacy-security-compliance-obligations\/"},"author":{"name":"Irma Brillantes","@id":"https:\/\/www.otava.com\/#\/schema\/person\/35774075f8f4fcdd4eae80cb72034263"},"headline":"Security alert: Flaw in iOS could impact HIPAA and other privacy security compliance obligations","datePublished":"2014-02-23T00:00:00+00:00","mainEntityOfPage":{"@id":"https:\/\/www.otava.com\/blog\/security-alert-flaw-in-ios-could-impact-hipaa-and-other-privacy-security-compliance-obligations\/"},"wordCount":384,"commentCount":0,"publisher":{"@id":"https:\/\/www.otava.com\/#organization"},"inLanguage":"en-US","potentialAction":[{"@type":"CommentAction","name":"Comment","target":["https:\/\/www.otava.com\/blog\/security-alert-flaw-in-ios-could-impact-hipaa-and-other-privacy-security-compliance-obligations\/#respond"]}]},{"@type":"WebPage","@id":"https:\/\/www.otava.com\/blog\/security-alert-flaw-in-ios-could-impact-hipaa-and-other-privacy-security-compliance-obligations\/","url":"https:\/\/www.otava.com\/blog\/security-alert-flaw-in-ios-could-impact-hipaa-and-other-privacy-security-compliance-obligations\/","name":"Security alert: Flaw in iOS could impact HIPAA and other privacy security compliance obligations | OTAVA","isPartOf":{"@id":"https:\/\/www.otava.com\/#website"},"datePublished":"2014-02-23T00:00:00+00:00","description":"Apple's iOS recently confirmed a critical vulnerability that gives attackers an easy way to eavesdrop on the internet. The vulnerability has been patched.","breadcrumb":{"@id":"https:\/\/www.otava.com\/blog\/security-alert-flaw-in-ios-could-impact-hipaa-and-other-privacy-security-compliance-obligations\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/www.otava.com\/blog\/security-alert-flaw-in-ios-could-impact-hipaa-and-other-privacy-security-compliance-obligations\/"]}]},{"@type":"BreadcrumbList","@id":"https:\/\/www.otava.com\/blog\/security-alert-flaw-in-ios-could-impact-hipaa-and-other-privacy-security-compliance-obligations\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/www.otava.com\/"},{"@type":"ListItem","position":2,"name":"Security alert: Flaw in iOS could impact HIPAA and other privacy security compliance obligations"}]},{"@type":"WebSite","@id":"https:\/\/www.otava.com\/#website","url":"https:\/\/www.otava.com\/","name":"OTAVA\u00ae","description":"","publisher":{"@id":"https:\/\/www.otava.com\/#organization"},"potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/www.otava.com\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Organization","@id":"https:\/\/www.otava.com\/#organization","name":"OTAVA\u00ae","url":"https:\/\/www.otava.com\/","logo":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.otava.com\/#\/schema\/logo\/image\/","url":"https:\/\/www.otava.com\/wp-content\/uploads\/2025\/03\/otava-logo.svg","contentUrl":"https:\/\/www.otava.com\/wp-content\/uploads\/2025\/03\/otava-logo.svg","caption":"OTAVA\u00ae"},"image":{"@id":"https:\/\/www.otava.com\/#\/schema\/logo\/image\/"}},{"@type":"Person","@id":"https:\/\/www.otava.com\/#\/schema\/person\/35774075f8f4fcdd4eae80cb72034263","name":"Irma Brillantes","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/secure.gravatar.com\/avatar\/d5251bebc1699793a698d1a6158603cb3cdc50a095a12357e42d415b3e5546c2?s=96&d=mm&r=g","url":"https:\/\/secure.gravatar.com\/avatar\/d5251bebc1699793a698d1a6158603cb3cdc50a095a12357e42d415b3e5546c2?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/d5251bebc1699793a698d1a6158603cb3cdc50a095a12357e42d415b3e5546c2?s=96&d=mm&r=g","caption":"Irma Brillantes"},"url":"https:\/\/www.otava.com\/blog\/author\/ibrillantesotava-com\/"}]}},"_links":{"self":[{"href":"https:\/\/www.otava.com\/wp-json\/wp\/v2\/posts\/2803","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.otava.com\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.otava.com\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.otava.com\/wp-json\/wp\/v2\/users\/3"}],"replies":[{"embeddable":true,"href":"https:\/\/www.otava.com\/wp-json\/wp\/v2\/comments?post=2803"}],"version-history":[{"count":0,"href":"https:\/\/www.otava.com\/wp-json\/wp\/v2\/posts\/2803\/revisions"}],"wp:attachment":[{"href":"https:\/\/www.otava.com\/wp-json\/wp\/v2\/media?parent=2803"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.otava.com\/wp-json\/wp\/v2\/categories?post=2803"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.otava.com\/wp-json\/wp\/v2\/tags?post=2803"},{"taxonomy":"other_category","embeddable":true,"href":"https:\/\/www.otava.com\/wp-json\/wp\/v2\/other_category?post=2803"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}