SERVICES / HEALTHCARE PENETRATION TESTING

SERVICES / HEALTHCARE PENETRATION TESTING

HIPAA Compliance & PHI Protection

HIPAA Compliance & PHI Protection

Why Healthcare Needs More Than a Vulnerability Scan

Protected health information is one of the most valuable targets on the black market: a complete medical record sells for far more than a stolen credit card, because it cannot be reissued. Hospitals, clinics, and healthtech platforms run a sprawling attack surface: legacy EHR systems, patient portals, telehealth apps, connected medical devices, third-party billing integrations, and flat clinical networks that were never designed with segmentation in mind.

The HIPAA Security Rule requires covered entities and business associates to conduct an accurate and thorough assessment of the potential risks to electronic PHI. An automated scan lists missing patches; it does not tell you whether an attacker can pivot from a compromised nurse workstation into your EHR database. Thorium bridges that gap. Our team spent their careers running offensive operations at the Department of Defense level, and we bring that adversarial rigor to healthcare environments where a missed finding puts patients, not just data, at risk.

Every engagement produces evidence-backed proof of exposure mapped directly to HIPAA safeguards, along with a prioritized remediation roadmap and OCR-ready documentation that stands up to an audit.

BEYOND DATA

In healthcare, a breach is never just a data problem; it becomes a patient-safety event. Ransomware that locks an EHR delays surgeries, diverts ambulances, and forces clinicians back to paper.

In healthcare, a breach is never just a data problem; it becomes a patient-safety event. Ransomware that locks an EHR delays surgeries, diverts ambulances, and forces clinicians back to paper.

That is why we test the way a real adversary operates, not to hand you a checklist, but to show exactly how an intrusion turns into a disruption to care.

$10.93M

$10.93M

$10.93M

Average cost of a U.S. healthcare data breach, the highest of any industry

725+

725+

725+

Large PHI breaches reported to HHS OCR in a single year, exposing 130M+ records

168 days

168 days

168 days

Mean time to identify a breach in healthcare, the longest dwell time of any sector

§164.308

§164.308

§164.308

The HIPAA Security Rule provision that mandates a thorough risk analysis of ePHI

MAPPED TO THE HIPAA SECURITY RULE

How Testing Satisfies 45 CFR Part 164

Each engagement is scoped to produce evidence that maps directly to the administrative and technical safeguards your organization is required to implement and evaluate.

§164.308(a)(1)(ii)(A)

Risk Analysis

A penetration test delivers the accurate, thorough assessment of vulnerabilities to ePHI the rule requires, with demonstrated exploitability, not theoretical risk.

§164.308(a)(8)

Evaluation

Periodic technical evaluation of your safeguards. Annual and post-change engagements re-verify that controls still hold after environmental or operational change.

§164.312(a)(1)

Access Control

We test whether unique user identification, automatic logoff, and role-based access actually prevent unauthorized reach into ePHI across EHR and clinical systems.

§164.312(e)(1)

Transmission Security

We validate encryption of ePHI in transit across patient portals, APIs, HL7/FHIR interfaces, and VPNs, attempting interception, downgrade, and man-in-the-middle attacks.

§164.308(a)(5)

Security Awareness & Training

Phishing and social-engineering simulations measure how clinical and administrative staff respond to realistic attacks aimed at harvesting credentials and PHI.

§164.308(a)(6)

Security Incident Procedures

The engagement stress-tests detection and response, revealing whether your team notices an active intrusion before an attacker reaches patient data.

ENGAGEMENT METHODOLOGY

A Repeatable, Evidence-Driven Process

01

Scope & RoE

02

Reconnaissance

03

Exploitation

04

PHI Impact

05

Reporting

06

Re-Test

THE DEFINING HEALTHCARE RISK

Connected Medical Devices

Infusion pumps, imaging systems, and bedside monitors were built for uptime and longevity, not security. They run unpatched legacy operating systems, cannot be taken offline for maintenance, and share networks with the very records they endanger. IoMT is where healthcare’s attack surface is most exposed and least understood.

Infusion & Smart Pumps

Dose-critical, network-connected, rarely patched

Imaging: PACS, MRI, CT

Large legacy fleets on flat DICOM networks

Patient & Vital Monitors

Bedside telemetry on shared clinical VLANs

Lab & Diagnostic Systems

Middleware bridging LIS and analyzers

Facility & Building Systems

Nurse call, HVAC, and access control (OT)

ASSESSMENT COVERAGE

What We Test in a Healthcare Environment

Engagements are scoped to your environment. Below are the domains we most commonly assess for hospitals, clinics, and healthtech platforms handling protected health information.

EXTERNAL / PERIMETER

EHR & EMR System Testing

We assess Epic, Cerner, Meditech, and custom EHR deployments for authentication bypass, broken access control, and insecure interfaces that could expose complete patient records to an attacker.

EPIC

CERNER

AUTH BYPASS

RECORD EXPORT

PATIENT-FACING / TELEHEALTH

Patient Portals & Telehealth Apps

Patient portals, scheduling systems, and video-visit platforms are tested for account takeover, insecure direct object references that expose other patients’ records, and weak session handling.

IDOR

ACCOUNT TAKEOVER

SESSION

OWASP TOP 10

IoMT / CONNECTED DEVICES

Connected Medical Device Security

Infusion pumps, imaging systems, patient monitors, and other IoMT endpoints are evaluated for default credentials, unencrypted protocols, and network exposure that can endanger patient safety.

IoMT

DEFAULT CREDS

FDA PREMARKET

LEGACY OS

CLOUD / PHI STORAGE

Cloud & PHI Storage Audits

AWS, Azure, and GCP environments holding ePHI are reviewed for exposed storage buckets, misconfigured IAM roles, and unencrypted backups, mapped to HITRUST CSF and HIPAA safeguard requirements.

HITRUST

IAM MISCONFIG

BUCKET EXPOSURE

ENCRYPTION

INTERNAL / NETWORK

Internal Network & Segmentation

We simulate a breached clinical workstation to test lateral movement, flat-network exposure, and whether a single foothold can reach EHR databases, domain controllers, and backup systems.

LATERAL MOVEMENT

ACTIVE DIRECTORY

SEGMENTATION

PRIVILEGE ESC

WEB / API

Web Apps & HL7 / FHIR Interfaces

Billing portals, provider dashboards, and HL7 / FHIR APIs are tested for injection, broken object-level authorization, and insecure data exchange between clinical and third-party systems.

FHIR

HL7

INJECTION

BROKEN AUTHZ

WIRELESS / PHYSICAL

Wireless & Physical Access

Clinical Wi-Fi, guest networks, and physical access to workstations and server rooms are tested, including tailgating into restricted care areas and unlocked, unattended EHR sessions.

WPA2 / WPA3

ROGUE AP

TAILGATING

WORKSTATION

HUMAN / SOCIAL

Social Engineering & Phishing

Targeted phishing, vishing, and pretexting against clinical and administrative staff measure real-world susceptibility to credential theft and unauthorized PHI access, the leading cause of healthcare breaches.

PHISHING

VISHING

PRETEXTING

MFA FATIGUE

WHO WE SERVE

Built for the Full Care Continuum

Hospitals & Health Systems

Multi-site networks with the EHR at the core

Ambulatory & Clinics

Lean IT teams carrying high patient volume

Healthtech & Digital Health

Apps, APIs, and cloud-native PHI

Payers & TPAs

Claims data and member-facing portals

STANDARDS & FRAMEWORKS

Aligned to the Regulations That Govern You

HIPAA

Security Rule

HITECH

Breach Notif.

HITRUST

CSF

NIST

SP 800-66

HHS OCR

Enforcement

FDA

Premarket

WHAT YOU RECEIVE

Audit-Ready Documentation, Not Just a Tool Dump

OCR-Ready Findings Report

A findings report structured to support your HIPAA risk analysis and evaluation obligations, with reproducible evidence and severity ratings for every issue.

Executive Attestation Letter

A signed engagement summary suitable for boards, auditors, cyber-insurance carriers, and business-associate due-diligence requests.

Prioritized Remediation Roadmap

Every finding mapped to a concrete fix and sequenced by risk to patient data, so your IT team can close the most dangerous gaps first.

Complimentary Re-Test

After you remediate, we re-test the confirmed findings and update your documentation to verify closure, at no additional cost.

Find out what an attacker could reach before an auditor does.

Find out what an attacker could reach before an auditor does.

We scope every healthcare engagement individually. Tell us about your environment (EHR, portals, devices, cloud) and we’ll respond within one business day.

Request a Scoping Call

Thorium Information Security, LLC.

Hayden, Idaho, USA

Hayden, Idaho, USA

(208) 352-2877

(208) 352-2877

Sales@ThoriumInfosec.com

Sales@ThoriumInfosec.com

Copyright © 2026 Thorium Information Security LLC. All rights reserved.

Copyright © 2026 Thorium Information Security LLC. All rights reserved.