Mobile App Risk is Business Risk.
Regulators are watching Enterprise mobile apps. Users demand transparency. Get instant visibility into privacy risks, AI data exposure, dangerous permissions and suspicious network connections across your entire enterprise app portfolio.
Search 2,000+ Enterprise Apps. Know Your Risk in Minutes.
Spruce: Medical Communication
Spruce: Medical Communication
Spruce is the leading platform for HIPAA-compliant communication and care outside of the exam room. Call, text, fax, secure message, video chat, and more—all from one secure app, with a unified team inbox. Designed for healthcare professionals and their patients, Spruce takes your clinical operations to the next level, with powerful, easy-to-use tools for team collaboration, panel management, telehealth, business phone functionality, and automated custom communications.
Healthcare Professionals: Start your free 14-day trial today—no credit card required.
Patients: Spruce is always free. Download to connect with your care team for secure messaging and telehealth.
SPRUCE FOR HEALTHCARE PROFESSIONALS
• Get new phone and fax numbers, or transfer in your existing lines
• Robust mobile and desktop apps
• Built-in compliance: Automatic HIPAA BAA, two-factor login security, SOC 2 auditing, HITRUST certification, and automatic audit logging for communication read, write, and view
• Advanced phone system: Phone trees, multiple lines, secure voicemail, automated transcription, VoIP, number sharing
• Messaging and fax: Secure individual and group messaging, two-way SMS texting, secure two-way eFax
• Telehealth: Secure video calling, as well as adaptive clinical questionnaires for patient intake and screening
• After-hours: Automated schedules adjust your phone system and messaging to match your business hours
• Automation: Save messages for reuse, schedule messages for future delivery, implement automatic message responses for common needs
• Panel management: Contact and conversation tagging, patient list upload, advanced search, bulk messaging, and custom inbox configuration and communication routing for each team member
• Team collaboration: Secure team chats, shared inboxes, internal notes, and @-paging bring the features of modern team software to the healthcare space
• And more…!
SPRUCE FOR PATIENTS
• Sign in to a free and secure patient app, on mobile or desktop
• Receive video calls from your care team
• Send and receive secure messages, including photos
• Receive alerts for new activity
Ask your healthcare team for an invitation to connect on Spruce. If they're not on Spruce yet, ask them to sign up today!
Please visit our website at www.sprucehealth.com for more information.
Spruce: Medical Communication
Package ID
com.spruce.messenger
Version
34034020
Developer
Spruce Health
Category
Medical
Store Rank
58
App Store Link
View in Google PlayDeveloper Privacy Policy
Privacy PolicyObservations Summary:
Permissions Observations
DETECTEDPermissions defined by Apple and Google as dangerous have been observed.
Observed During Analysis
- Allows applications to access information about networks.
- Allows applications to access information about Wi-Fi networks.
- + 23 more
- Allows applications to connect to paired bluetooth devices.
- Allows an application to initiate a phone call without going through the Dialer user interface for the user to confirm the call.
- Required to be able to access the camera device.
- Allows a regular application to use Service.startForeground.
- Allows a regular application to use Service.startForeground with the type "camera".
- Allows a regular application to use Service.startForeground with the type "dataSync".
- Allows a regular application to use Service.startForeground with the type "microphone".
- Allows a regular application to use Service.startForeground with the type "phoneCall".
- Allows applications to open network sockets.
- Allows a calling application which manages its own calls through the self-managed ConnectionService APIs.
- Allows an application to modify global audio settings.
- Allows an app to post notifications
- Allows an application to read the user's contacts data.
- Allows an application to read from external storage.
- Allows read only access to phone state, including the current cellular network information, the status of any ongoing calls, and a list of any PhoneAccounts registered on the device.
- Allows an application to receive the Intent.ACTION_BOOT_COMPLETED that is broadcast after the system finishes booting.
- Allows an application to record audio.
- Allows an app to create windows using the type WindowManager.LayoutParams.TYPE_APPLICATION_OVERLAY, shown on top of all other apps.
- Allows an app to use device supported biometric modalities.
- This constant was deprecated in API level 28. Applications should request USE_BIOMETRIC instead
- Required for apps targeting Build.VERSION_CODES.Q that want to use notification full screen intents.
- Allows access to the vibrator.
- Allows using PowerManager WakeLocks to keep processor from sleeping or screen from dimming.
- show less
- See Your App’s Risk Profile
Why Permissions Matter
If not managed properly, dangerous permissions can permit malicious access to sensitive data, and device features.
Sensitive Data Collection and Sharing Observations
SENSITIVE INFO FOUNDThis app collects, stores, or shares information that is often designated as sensitive and private.
Observed During Analysis
- WiFi IP Address
- See Your App’s Risk Profile
Why Data Collection and Sharing Matters
If not managed properly private data can expose enterprises, customers, employees and partners to breach and compliance violations.
AI Observations
DETECTEDThis app uses artificial intelligence and may introduce risks including loss of IP, privacy concerns, or other unintended consequences.
Observed During Analysis
- ML Kit
- See Your App’s Risk Profile
Why AI Matters
AI features can process sensitive data in unexpected ways, potentially exposing proprietary information or creating liability.
Network Connections Observations
DETECTEDNetwork analysis has detected communication with external servers and data transfer patterns.
Observed During Analysis
Connected Hostname:
- amazon.com
- google.com
Server Locations:
- Ashburn, Virginia, US
- Kansas City, Missouri, US
- + 3 more
- Mountain View, California, US
- Seattle, Washington, US
- Toronto, Ontario, CA
- show less
- See Your App’s Risk Profile
Why Network Connections Matter
Uncontrolled communication with external servers by an employee-used app could expose sensitive business data to unauthorized third parties. This unauthorized access can lead to data breaches, regulatory non-compliance, and damage to your business's reputation and financial standing.
Privacy Declarations Observations
NOT DETECTEDThis test did not detect a discrepancy, indicating all required declarations are disclosed.
- See Your App’s Risk Profile
Why Privacy Declarations Matter
Declarations matter because they provide transparency on how apps collect and use sensitive data. iOS requires Privacy Manifest declarations, while Android requires Data Safety disclosures and manifest permissions.
NowSecure provides detailed risk assessments for millions of mobile apps. We Can Help Secure Your App.
All trademarks, logos, and brand names are the property of their respective owners. All company, product, and service names used in this website are for identification purposes only. Use of these names, trademarks, and brands does not imply endorsement.
MARC App Directory