HIPAA Penetration Testing
Find out what an attacker could actually reach in your environment — before somebody else does. Scope and rules of engagement agreed in writing, findings reported with the steps to fix them.
What We Test
Tell us what matters and we scope the engagement around it. These are the areas requests usually cover.
Web Applications
Patient portals, booking systems, intake forms and internal tools — authentication, authorisation, session handling, and the logic that decides who can see whose record.
WordPress & CMS
Themes, plugins and the admin surface — the places a content management system most often gives away more access than anybody intended.
Server & Cloud Infrastructure
Hosts, containers and cloud accounts — exposed services, over-broad roles and permissions, and storage that is readable by more people than the architecture diagram suggests.
Network Perimeter
What is reachable from outside, what answers when it is contacted, and how far somebody gets once they are through the first layer.
APIs & Integrations
The endpoints your applications and vendors talk to. Broken object-level authorisation is the flaw that most often exposes one patient's record to another patient's session.
Access & Authentication
Password and MFA handling, session lifetimes, password reset flows, and whether a former employee's access really ended when their account was disabled.
How It Works
Three stages, with the boundaries agreed before anything is touched.
Scope the Engagement
We agree targets, timing and rules of engagement in writing, and confirm who has authorised the testing. Anything fragile or out of bounds is settled here, not discovered mid-test.
Test
Manual testing supported by tooling, against the agreed scope and nothing outside it. Findings are verified rather than reported from a scanner, so what you receive is what is genuinely exploitable.
Report & Retest
Findings ranked by risk, each with reproduction steps and what to change. Once you have made the fixes, a retest confirms they hold — and gives you something to show whoever asked for the test.
Request a Quote
Eight short questions. We use them to scope the engagement and come back with a quote — usually within one business day.
Frequently Asked Questions
A penetration test is a controlled, authorised attempt to find and exploit weaknesses in your systems the way an attacker would. The goal is to learn what is actually reachable and what it would let somebody do, so you find out before somebody else does.
A scan lists what a tool can detect. A penetration test verifies which of those findings can actually be exploited, chains them together to show real impact, and discards the false positives a scan otherwise leaves you to triage yourself.
Scope, timing and rules of engagement are agreed in writing before anything starts, and testing stays inside them. Where a target is fragile or business-critical we agree in advance what is out of bounds and when testing may run.
Yes. Testing only begins once somebody able to authorise it has signed off in writing, covering every system in scope. That is why the request form asks whether you are the person who can approve it.
Related Reading
Where testing fits alongside the rest of a HIPAA security programme.
Find Out What Is Actually Reachable
Tell us what is in scope and who can authorise the testing. We will come back with a quote.