Overview
Engagements cover patient-facing portals, telehealth and appointment platforms, clinical and practice-management systems, health data APIs including HL7 and FHIR interfaces, and the mobile applications patients use to reach all of it.
The central question in this sector is never whether data is encrypted. It almost always is. It is whether one patient, one provider or one partner organisation can reach another’s records through a path nobody modelled: a document identifier in a notification email, a report that runs outside the request scope, or an API response that returns the full record where the interface shows a name.
What drives testing in this sector
Buying triggers
- HIPAA Security Rule
- The risk analysis and evaluation requirements are met in practice through regular technical testing, and regulators expect to see it evidenced.
- Vendor assessments
- Hospitals and insurers assess their business associates, and a current independent test report is a standard request.
- Ransomware exposure
- Healthcare remains among the most targeted sectors because downtime is clinically unacceptable, which makes payment more likely.
Where the engagement concentrates
PHI access control
Record identifiers replayed across patients, providers and organisations: including documents, images, lab results, messages and audit trails.
Patient portals and telehealth
Registration and identity binding, proxy and dependant access, appointment and consultation flows, and session handling on shared devices.
Clinical interfaces
HL7 and FHIR endpoints tested for authorisation at the resource level, scope enforcement on SMART on FHIR tokens, and bulk-export exposure.
Vendor and device integrations
Practice management, billing, imaging and device gateways, the integrations that hold broad credentials and are rarely in anyone’s test scope.
Audit and accountability
Whether access to records is logged in a way that would reconstruct an incident, and whether those logs can be suppressed by the account being audited.
Data minimisation in responses
API responses that return the full patient object when the interface displays a name, which is the most common quiet PHI exposure.
Track record
Healthcare and health-adjacent engagements have covered patient-facing web platforms, mobile applications and the APIs behind them, with findings written against both the technical control and the corresponding HIPAA safeguard.
200+ projects delivered for 80+ organisations. Internal engagement log
Questions
Do you sign a Business Associate Agreement?
Yes, where the engagement could involve access to protected health information. The strong preference is to test against synthetic or de-identified data, which removes the exposure entirely while testing exactly the same code paths.
Does HIPAA require a penetration test?
The Security Rule requires a risk analysis and periodic technical evaluation rather than naming a penetration test specifically. In practice, technical testing is how organisations evidence that evaluation, and it is what assessors and enterprise partners ask to see.
Can you test with real patient data?
It is strongly discouraged. A staging environment with synthetic records that mirror production volume and shape exercises the same logic without putting real PHI in scope. Where production testing is unavoidable, access is confined to records created for the engagement.
How much does a penetration test cost for a healthcare organisation?
Cost follows scope, and healthcare estates are usually wider than they first appear: patient portal, clinical systems, billing, imaging and device gateways. A fixed quote follows scoping, and the integrations are frequently better value to test than the portal.
What do you find most often in healthcare systems?
Access to records that the interface never exposes. An identifier in an export, an API returning the whole patient object when the screen shows a name, and audit logging that would not reconstruct who saw what. None of it is dramatic, which is why it survives.
Do you test medical devices and their gateways?
Device gateways and the integrations around them, yes. Devices themselves are tested only in a lab or controlled environment, never in clinical use, because availability in a care setting is a patient safety matter rather than a scoping preference.
Can you test HL7 and FHIR interfaces?
Yes. Clinical integration interfaces frequently carry broad credentials, sit inside an assumed-trusted network, and are rarely in anyone's test scope. Authorisation on FHIR resource access is one of the more productive places to look.
How do you handle PHI during testing?
By keeping it out of scope wherever possible. Testing prefers seeded records and synthetic patients, and exposure is proven against data created for the engagement. One record proves an authorisation flaw as well as a million, and extracting more would be the wrong call in this sector particularly.