A security assessment of a popular at-home fertility tracking device uncovered 20 vulnerabilities that could have allowed attackers to interfere with the device, manipulate hormone readings, access sensitive health information, and reverse engineer its firmware.

 

What happened

According to Gov Info Security, researchers identified 20 vulnerabilities in the Mira fertility tracking system, an at-home device designed to measure reproductive hormones and provide fertility predictions through a connected smartphone application.

The device measures hormone concentrations from urine samples and wirelessly transfers readings to a smartphone. The associated application then presents hormone trends and fertility information to users. Mira's system uses Bluetooth Low Energy to connect the physical monitor with a smartphone.

According to the researchers, the vulnerabilities could have enabled attackers to impersonate a legitimate device, manipulate hormone readings, obtain sensitive health information, and reverse engineer production firmware. The potential consequences go beyond exposing personal information. If an attacker could alter readings before they reached the application, users could potentially receive inaccurate information about their fertility status.

 

Going deeper

The Northeastern University researchers examined the Mira device, its mobile app, and the systems that support it. They found 20 vulnerabilities across these areas. One flaw involved the Bluetooth connection between the fertility monitor and the mobile app. Researchers found that an attacker could potentially impersonate the device and send fake hormone readings to the app. Researchers also found weaknesses in how the app handled user data. They said exposed API keys could potentially allow access to health profile information. Based on their analysis, the researchers estimated that up to about 659,000 accounts could have been accessible. The researchers also found vulnerabilities that allowed them to examine the device's firmware and how the device communicated with the app and cloud services.

The findings were reported to Mira's manufacturer, Quanovate Tech, as well as the FDA and the Cybersecurity and Infrastructure Security Agency (CISA). According to the researchers, the company acknowledged the findings and carried out two rounds of fixes.

 

What was said

According to Gov Info Security, Kevin Fu, director of the Archimedes Center and professor of the cybersecurity course during which the discoveries were made, said, “The students' findings show real, exploitable gaps sitting in a product on the market today. This case study offers a broader lens on the current state of security review for connected consumer health devices.” In a presentation made by the students, they noted that “This case study offers a broader lens on the current state of security review for connected consumer health devices.”

In response to the study, Zhen Yang, Mira co-founder, in a statement provided to ISMG said “Since receiving the researchers' report, our engineering, security, quality, privacy, legal and regulatory teams investigated the findings, identified the root cause and implemented corrective actions - validated in coordination with the researchers… We strengthened authentication and authorization for device connections and account binding, added server-side verification of measurement data, hardened communication between the app and our servers, added protections against automated login attempts and restricted firmware access through authenticated, time-limited delivery.” He also added that “These updates are now available through the released Mira App and Mira Analyzer firmware upgrade, and the company is continuing post-release verification.”

 

In the know

Fertility information is considered protected health information (PHI) under HIPAA when it is handled by covered entities and their business associates. This includes information about fertility, pregnancy, contraception, and other reproductive health matters. HIPAA requires covered entities to protect electronic PHI with safeguards such as access controls, encryption, and regular risk assessments.

These requirements also apply to connected medical devices when they collect, store, or transmit electronic PHI. For devices that send health information to an app or other system, security measures must be used to protect that information from unauthorized access. Third-party applications that process PHI from medical devices may also have HIPAA obligations.

For fertility trackers, this means that when a device and its connected systems are used in a HIPAA-covered setting and handle PHI, the information must be protected throughout its collection, storage, and transmission.

Go deeper:

 

Why it matters

The vulnerabilities raise concerns about both the privacy and accuracy of reproductive health information. During testing, researchers were able to access health profile information and inject false hormone readings. They also found reproductive health information, including cycle data and medical conditions, being sent to third-party analytics and advertising software. The researchers said they found no evidence that the flaws had been exploited against real users.

These findings are particularly important to HIPAA when fertility devices are used by healthcare providers or other HIPAA-covered organizations. HIPAA requires covered entities and business associates handling electronic protected health information (ePHI) to put safeguards in place to prevent unauthorized access and disclosure. This can include access controls, encryption and risk assessments. Third-party applications that handle PHI from medical devices may also have HIPAA obligations.

For fertility devices, those protections need to extend beyond the physical device. The apps, APIs, and other systems that collect, transmit, and store the resulting health information also form part of the data chain. A weakness at any of these points can expose or alter reproductive health information.

See also: HIPAA Compliant Email: The Definitive Guide (2026 Update)

 

FAQS

What does it mean to impersonate a fertility device?

It means an attacker could potentially make the app believe it was communicating with a legitimate Mira analyzer when it was actually communicating with another device.

 

Are all fertility apps automatically covered by HIPAA?

HIPAA does not automatically apply to every health or fertility app. Whether HIPAA applies depends on who operates the service and how the health information is collected, stored, or shared.