Risk
2/9/2012
10:09 AM
50%
50%

TigerText Investment To Tighten Up Messaging Security

As text messaging among healthcare providers increases, TigerText secures $8.2 million to improve security.

Health Data Security: Tips And Tools
Health Data Security: Tips And Tools
(click image for larger view and for slideshow)
TigerText Inc., a provider of security software for text messaging used by physicians on their mobile devices, recently announced that it received $8.2 million in venture capital investments, bringing the company's total backing to more than $10 million.

While the investment reflects the growing momentum on the part of venture capital investors to subsidize money into burgeoning health IT companies, it also signals an expected rise in the use of text messaging among healthcare providers and underscores the need for security as digitized patient information is increasingly accessed and exchanged via text messages.

The Santa Monica, Calif.-based company received the investment from Easton Capital and New Science Ventures, and it will use the money to accelerate development of the TigerText Pro for Business messaging platform. The technology provides a Software as a Service (SAAS)-based messaging model that allows doctor-to-doctor, nurse-to-doctor, and hospital-to-doctor communications as care teams coordinate patient care.

Furthermore, as physicians, nurses, and other hospital employees bring their mobile devices to work, the TigerText platform gives health organizations greater control over messages that are encrypted throughout the transmission process and at rest. For added security, clinicians can also use the product's self-deleting messages (both on sender and receiver handsets).

[For more background on e-prescribing tools, see 6 E-Prescribing Vendors To Watch.]

"All messages and content in the application have a lifespan on the device, so after a set period of time (the clients control the lifespan of messages in their network, but typically lifespan is set from one to five days), the content is pulled from the device," Jeffrey Evans, TigerText's cofounder, said in an interview with InformationWeek Healthcare. "If a device is lost or stolen, the account passwords are changed and the content can be remotely wiped from the device."

According to John Friedman, managing partner of Easton Capital, as more patient data moves from paper-based systems to electronic health records, the need for greater security around text messaging in healthcare will grow, and TigerText's software is poised to address the growing security requirements that come with transmitting patient data using text messaging.

"That is the investment attraction. As more information is moving digitally, the need for a secure messaging system for Healthcare is paramount," Friedman told InformationWeek Healthcare. "It is a very exciting, fast-paced, high-growth area. Healthcare communication has seen very little progress from the era of phones and pagers. The next 10 years will change the way the entire industry communicates."

According to officials at TigerText, more than 20 healthcare organizations are using the TigerText private mobile messaging network. The software works on Apple, Android, and BlackBerry mobile platforms and on computers. The tool also allows for communication from a web-based console to a mobile device.

Companies offering secure text messaging will benefit from the increasing use of mobile devices, as well as from programs that expand text messaging in healthcare, such as Text4Baby, a free mobile information service that uses text messages to inform pregnant women and new moms on ways to improve their health, or the National Coordinator for Health Information Technology (ONC) Beacon Community Program txt4health, which delivers personalized text messages to help people understand their risk for Type 2 diabetes. Programs like these help drive the use of text messaging in healthcare as well as the corresponding need to secure these messages.

"Secure texting has the potential to greatly improve physician communications," Irene Berlinsky, IDC's senior research analyst covering Multiplay Services, said in an interview with InformationWeek Healthcare. "Companies that provide easy-to-use, secure texting solutions will be well positioned to take advantage of doctors' move to texting. However, the technology must be absolutely rock-solid to keep the industry's trust."

Healthcare providers must collect all sorts of performance data to meet emerging standards. The new Pay For Performance issue of InformationWeek Healthcare delves into the huge task ahead. Also in this issue: Why personal health records have flopped. (Free registration required.)

Comment  | 
Print  | 
More Insights
Register for Dark Reading Newsletters
White Papers
Cartoon
Current Issue
Dark Reading Tech Digest, Dec. 19, 2014
Software-defined networking can be a net plus for security. The key: Work with the network team to implement gradually, test as you go, and take the opportunity to overhaul your security strategy.
Flash Poll
Video
Slideshows
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2014-2208
Published: 2014-12-28
CRLF injection vulnerability in the LightProcess protocol implementation in hphp/util/light-process.cpp in Facebook HipHop Virtual Machine (HHVM) before 2.4.2 allows remote attackers to execute arbitrary commands by entering a \n (newline) character before the end of a string.

CVE-2014-2209
Published: 2014-12-28
Facebook HipHop Virtual Machine (HHVM) before 3.1.0 does not drop supplemental group memberships within hphp/util/capability.cpp and hphp/util/light-process.cpp, which allows remote attackers to bypass intended access restrictions by leveraging group permissions for a file or directory.

CVE-2014-5386
Published: 2014-12-28
The mcrypt_create_iv function in hphp/runtime/ext/mcrypt/ext_mcrypt.cpp in Facebook HipHop Virtual Machine (HHVM) before 3.3.0 does not seed the random number generator, which makes it easier for remote attackers to defeat cryptographic protection mechanisms by leveraging the use of a single initial...

CVE-2014-6228
Published: 2014-12-28
Integer overflow in the string_chunk_split function in hphp/runtime/base/zend-string.cpp in Facebook HipHop Virtual Machine (HHVM) before 3.3.0 allows remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact via crafted arguments to the chunk_split ...

CVE-2014-6229
Published: 2014-12-28
The HashContext class in hphp/runtime/ext/ext_hash.cpp in Facebook HipHop Virtual Machine (HHVM) before 3.3.0 incorrectly expects that a certain key string uses '\0' for termination, which allows remote attackers to obtain sensitive information by leveraging read access beyond the end of the string,...

Best of the Web
Dark Reading Radio
Archived Dark Reading Radio
Join us Wednesday, Dec. 17 at 1 p.m. Eastern Time to hear what employers are really looking for in a chief information security officer -- it may not be what you think.