THE CLIENT
OUR APPROACH
ASSESSMENT CHECKLIST
✓ External Network
✓ Internal Network
✓ Active Directory
✓ Web Applications
✓ Microsoft 365
✓ Wireless Networks
✓ Medical Devices
✓ Physical Security
FINDINGS
OUR FINDINGS
CRITICAL
Domain Compromise via Kerberoasting Attack Chain
A chain of Active Directory misconfigurations allowed escalation from a standard user account to Domain Administrator in under four hours. Every system on the network was accessible from this position.
CRITICAL
Patient Portal Authentication Bypass
A broken access control vulnerability allowed unauthenticated access to patient records by manipulating a predictable URL parameter. Approximately 350,000 patient records were accessible without valid credentials.
CRITICAL
Unpatched CVEs on Internet-Facing Systems
Three internet-facing systems ran software with publicly known critical vulnerabilities, two with published exploit code available. The oldest CVE had been documented for six years. None appeared in previous vendor reports.
HIGH
No Segmentation Between Clinical and Administrative Networks
Network segmentation between clinical and administrative environments was non-existent. Any compromise of an administrative workstation provided direct access to systems connected to medical devices.
HIGH
34 Stale Domain Admin Accounts
34 Domain Administrator accounts belonging to former employees and contractors remained active and privileged. Twelve had not had passwords changed in over three years.
HIGH
Microsoft 365: Legacy Auth Enabled, MFA Not Enforced
Legacy authentication protocols bypassed conditional access policies entirely. MFA was not enforced for any account including administrative roles. Credential spray attacks would succeed without triggering any access controls.
3 · CRITICAL
3 · HIGH
Every finding carries a proof of concept, a full attack narrative, and prioritized remediation guidance. Raw scanner output is never delivered as a finding.
REMEDIATION SUPPORT
Immediate Triage
Within 24 hours of critical findings, Thorium briefed the IT Director and HIPAA Security Officer to ensure interim mitigations were in place while permanent fixes were developed.
Prioritized Remediation Roadmap
All 47 findings organized by severity, complexity, and dependency.. so the IT team could work through fixes in a logical sequence.
Technical Advisory Support
On-demand technical guidance throughout the 94-day remediation window: answering questions, validating approaches, and helping the team understand root causes.
Full Retest and Validation
A complete retest confirmed 43 of 47 findings fully remediated. The remaining four had accepted risk documentation and a defined remediation timeline.
Compliance Outcomes
Following remediation, Thorium conducted a comprehensive HIPAA Security Rule compliance audit. The engagement produced a formal risk analysis reflecting the organization’s actual security posture, gap remediation documentation, and updated security policies aligned to current framework requirements.
An independent HIPAA auditor confirmed Thorium’s documentation package met the requirements of a compliant risk analysis. The organization’s HIPAA Security Officer described it as the first time she felt genuinely confident in the organization’s compliance posture.
Annual Penetration Testing
Routine Vulnerability Scanning
Scheduled internal vulnerability scans conducted monthly from Thorium’s on-site assessment appliance, with prioritized findings delivered as a monthly summary.
Advisory Consulting
Ad-Hoc Testing
-HIPAA Security Officer, Regional Healthcare Network
