Skip to main content

HIPAA Penetration Testing

Find out what an attacker could actually reach in your environment — before somebody else does. Scope and rules of engagement agreed in writing, findings reported with the steps to fix them.

What We Test

Tell us what matters and we scope the engagement around it. These are the areas requests usually cover.

Web Applications

Patient portals, booking systems, intake forms and internal tools — authentication, authorisation, session handling, and the logic that decides who can see whose record.

WordPress & CMS

Themes, plugins and the admin surface — the places a content management system most often gives away more access than anybody intended.

Server & Cloud Infrastructure

Hosts, containers and cloud accounts — exposed services, over-broad roles and permissions, and storage that is readable by more people than the architecture diagram suggests.

Network Perimeter

What is reachable from outside, what answers when it is contacted, and how far somebody gets once they are through the first layer.

APIs & Integrations

The endpoints your applications and vendors talk to. Broken object-level authorisation is the flaw that most often exposes one patient's record to another patient's session.

Access & Authentication

Password and MFA handling, session lifetimes, password reset flows, and whether a former employee's access really ended when their account was disabled.

Server infrastructure with security monitoring

How It Works

Three stages, with the boundaries agreed before anything is touched.

1

Scope the Engagement

We agree targets, timing and rules of engagement in writing, and confirm who has authorised the testing. Anything fragile or out of bounds is settled here, not discovered mid-test.

2

Test

Manual testing supported by tooling, against the agreed scope and nothing outside it. Findings are verified rather than reported from a scanner, so what you receive is what is genuinely exploitable.

3

Report & Retest

Findings ranked by risk, each with reproduction steps and what to change. Once you have made the fixes, a retest confirms they hold — and gives you something to show whoever asked for the test.

Request a Quote

Eight short questions. We use them to scope the engagement and come back with a quote — usually within one business day.

Your details
About the engagement
Are there specific requirements or frameworks involved? (optional)

Testing can only begin once somebody able to authorise it has signed off in writing. “No” or “I need to confirm” is a fine answer — we will work through it with you.

Please do not include patient names, clinical details, or other protected health information in this inquiry. We will arrange an appropriate secure process if your request requires it.

Frequently Asked Questions

A penetration test is a controlled, authorised attempt to find and exploit weaknesses in your systems the way an attacker would. The goal is to learn what is actually reachable and what it would let somebody do, so you find out before somebody else does.

A scan lists what a tool can detect. A penetration test verifies which of those findings can actually be exploited, chains them together to show real impact, and discards the false positives a scan otherwise leaves you to triage yourself.

Scope, timing and rules of engagement are agreed in writing before anything starts, and testing stays inside them. Where a target is fragile or business-critical we agree in advance what is out of bounds and when testing may run.

Yes. Testing only begins once somebody able to authorise it has signed off in writing, covering every system in scope. That is why the request form asks whether you are the person who can approve it.

Modern secure healthcare facility with advanced technology

Related Reading

Where testing fits alongside the rest of a HIPAA security programme.

Find Out What Is Actually Reachable

Tell us what is in scope and who can authorise the testing. We will come back with a quote.