PROTECT CARE
UNDER PRESSURE.
Ransomware in a hospital is not a data problem, it is a continuity of care problem. We test whether a compromised endpoint can reach PHI, clinical systems, and the networks that keep them running.
THE HEALTHCARE THREAT MODEL
Availability is the safety control
In most sectors an outage is a revenue problem. Here it diverts ambulances and forces paper charting. Ransomware operators understand this, which is why healthcare draws extortion. Testing has to respect clinical operations.
A flat network holding forty years of protocols
HL7 v2 over unauthenticated TCP, DICOM nodes that trust any peer, imaging workstations that cannot be patched without revalidation, and biomedical devices with fixed credentials. The interesting question is not whether these are weak, but whether the network lets a phished workstation reach them.
Identity spans employers you do not control
Affiliated physicians, rotating residents, contracted radiology, billing companies, and payer portals all hold credentials into clinical systems. Third-party and delegated access is routinely the shortest path to PHI, and the hardest to inventory.
WHAT DRIVES THE REQUIREMENT
For a healthcare organization, testing is rarely optional. PHI handling, HIPAA expectations and clinical safety all assume the systems have been adversarially tested.
HIPAA Security Rule
45 CFR §164.308(a)(1)(ii)(A) requires a risk analysis of threats to electronic PHI. Exploitation evidence is what distinguishes an assessed control from a documented one.
HHS OCR breach reporting
Breaches affecting 500 or more individuals are publicly posted. Your detection and forensic evidence becomes part of the public record.
FDA premarket and postmarket cybersecurity guidance
Applies to device manufacturers and shapes what a delivery organisation can reasonably expect from connected devices on its network.
Business associate agreements
Contractual security obligations flow between covered entities and their vendors, and are frequently evidenced with independent testing.
WHAT WE TEST
Clinical systems & PHI access
- EHR role and break-glass boundary testing (Epic, Cerner, MEDITECH)
- HL7 v2 and FHIR interface authorisation and injection testing
- PACS and DICOM node exposure and access control
- Clinical portal authentication and session handling
- Audit logging sufficiency for PHI access events
Network segmentation & device isolation
- Reachability testing from user VLANs to biomedical networks
- Device-to-cloud and device-to-EHR data flow inspection
- Wireless segmentation across clinical, guest, and corporate SSIDs
- Passive analysis of device network behaviour, without touching devices in clinical use
- Vendor remote support paths into clinical segments
Identity, infrastructure & recovery
- Active Directory attack paths to clinical system service accounts
- Federation, delegated access, and affiliated-provider identity review
- VPN and remote access assessment
- Backup integrity and tamper resistance under a ransomware scenario
- Email gateway and phishing resilience
HOW WE WORK
Machine-speed testing, constrained by the fact that these systems are treating patients while we test them. Every finding ships with a human signature on what it means.
PHI flow mapping
Trace every pathway to protected health information before agreeing scope: clinical portals, interfaces, reporting databases, vendor connections, and backups.
Adversary simulation planning
Threat models drawn from what actually happens here: ransomware operators seeking availability impact, insider access abuse, and espionage against research data.
Agentic exploitation, clinically aware
Agent swarms work interfaces, identity systems and segmentation, exploiting what they reach within a tightly drawn boundary. Active techniques are scheduled around clinical operations. Devices in patient use are observed, never probed.
Evidence and control mapping
Findings mapped to the HIPAA Security Rule and any payer or accreditation requirements in scope, with an executive summary and a technical report written for separate audiences.
WHAT YOU RECEIVE
WHEN HEALTHCARE BREAKS
Public disclosures worth reading closely. The entry points are remote access, shared identity infrastructure, and exposed interfaces, not novel exploits.
Change Healthcare (UnitedHealth)
2024Ransomware entered through a Citrix remote access portal without multi-factor authentication and halted a national claims clearinghouse.
Weeks of manual claims processing across the US healthcare system; disclosed costs in the hundreds of millions.
CommonSpirit Health
2022Ransomware spread across a multi-state hospital network through shared Active Directory infrastructure.
Elective procedures delayed and EHR access lost across facilities during weeks of recovery.
Scripps Health
2021Ransomware took the Epic EHR offline, forcing ambulance diversion and paper-based charting.
Approximately a month of EHR downtime, with remediation and lost revenue disclosed at over $100M.
Exposed PACS archives
OngoingResearchers have repeatedly found DICOM and PACS servers reachable from the public internet with no authentication required.
Patient imaging and identifiers retrievable by anyone who scans for the port. Consistently a configuration failure, not an exploit.
FREQUENTLY ASKED
Do you test while clinical systems are in use?+
Yes, with constraints agreed in advance. Non-disruptive techniques run during normal operations; anything with a plausible availability impact is scheduled into maintenance windows and coordinated with IT and biomedical engineering. Patient safety takes precedence over test coverage, and we will say so in the report where it limited scope.
Can this satisfy the HIPAA Security Rule risk analysis requirement?+
Penetration testing evidences the technical safeguard side of the analysis required under 45 CFR §164.308(a)(1)(ii)(A). It is one input to a broader risk analysis, and the one that shows a control was tested.
Do you test medical devices themselves?+
We do not perform active testing against devices in clinical use. We assess the network paths to them, the segmentation intended to isolate them, their communications, and their cloud and EHR integrations. Active device testing is possible against spare or bench units when the organisation can supply them.
How do you handle PHI encountered during testing?+
We do not extract, store, or transmit real PHI. Synthetic records are used wherever they exist. Where proving access requires touching real data, we capture the minimum evidence, mask identifiers, report the exposure immediately under the business associate agreement, and purge it from testing infrastructure.
Find out what a phished workstation can actually reach
Tell us which clinical systems you run and how they are segmented. We will scope the engagement around your PHI pathways and your clinical calendar.
