We're having an appointment and health-tracking mobile app developed in Hamburg for private clinics and patients. We agreed on a 22,000 EUR budget and a 5-month turnaround with a local agency for this hybrid iOS and Android project. We're now in the final month, and the agency wants to hand over and publish the app next week.
Whenever I ask how they protect the data, I just get generic answers like "Don't worry, all traffic is SSL encrypted and the database is kept on a secure cloud server." But the app will store patients' personal info, appointment history, and doctor notes. I know that in Germany, legal and criminal liability for a health data breach falls straight on us. I'm not a technical founder, so I can't just dive into the source code to spot SQL injection flaws or check if authorization is handled properly.
What tangible security deliverables should I demand from the dev before making the final milestone payment and submitting the app to the stores? What's the most sensible way to independently audit an agency's work?