Abstract-In this paper, we present the results of a security assessment performed on a home care system based on SOA, realised as web services. The security design concepts of this platform were specifically tailored to meet new security challenges and to be compliant with legal frameworks applicable to the healthcare domain. This security design was fed as input to the development team, which implemented the system. However, our assessment revealed a software platform with severe security weaknesses and vulnerabilities, demonstrating dangers that are, or should be, well known.Our experience illustrates that security must be built as an intrinsic software property and emphasises the need for security awareness throughout the whole software development lifecycle.