Maybe it's too obvious or maybe I'm completely missing something, but seems a "fatal flaw" in this scheme is the fact that not everyone owns a smartphone, or even uses web services enough to develop much of an identifiable "profile". Smartphones are fragile, easily lost, not always available or reliable, making their use for the purpose seem far less than optimum. Furthermore, how high a level of security is needed d…
I would trust Google's security team over most EHRs. I base this on finding a few sql injection flaws and single DES usage in one I worked on but I don't have broad experience in many EHRs.