Why Healthcare Needs More Than a Vulnerability Scan
Protected health information is one of the most valuable targets on the black market: a complete medical record sells for far more than a stolen credit card, because it cannot be reissued. Hospitals, clinics, and healthtech platforms run a sprawling attack surface: legacy EHR systems, patient portals, telehealth apps, connected medical devices, third-party billing integrations, and flat clinical networks that were never designed with segmentation in mind.
The HIPAA Security Rule requires covered entities and business associates to conduct an accurate and thorough assessment of the potential risks to electronic PHI. An automated scan lists missing patches; it does not tell you whether an attacker can pivot from a compromised nurse workstation into your EHR database. Thorium bridges that gap. Our team spent their careers running offensive operations at the Department of Defense level, and we bring that adversarial rigor to healthcare environments where a missed finding puts patients, not just data, at risk.
Every engagement produces evidence-backed proof of exposure mapped directly to HIPAA safeguards, along with a prioritized remediation roadmap and OCR-ready documentation that stands up to an audit.
BEYOND DATA
That is why we test the way a real adversary operates, not to hand you a checklist, but to show exactly how an intrusion turns into a disruption to care.
Average cost of a U.S. healthcare data breach, the highest of any industry
Large PHI breaches reported to HHS OCR in a single year, exposing 130M+ records
Mean time to identify a breach in healthcare, the longest dwell time of any sector
The HIPAA Security Rule provision that mandates a thorough risk analysis of ePHI
MAPPED TO THE HIPAA SECURITY RULE
How Testing Satisfies 45 CFR Part 164
Each engagement is scoped to produce evidence that maps directly to the administrative and technical safeguards your organization is required to implement and evaluate.
§164.308(a)(1)(ii)(A)
Risk Analysis
A penetration test delivers the accurate, thorough assessment of vulnerabilities to ePHI the rule requires, with demonstrated exploitability, not theoretical risk.
§164.308(a)(8)
Evaluation
Periodic technical evaluation of your safeguards. Annual and post-change engagements re-verify that controls still hold after environmental or operational change.
§164.312(a)(1)
Access Control
We test whether unique user identification, automatic logoff, and role-based access actually prevent unauthorized reach into ePHI across EHR and clinical systems.
§164.312(e)(1)
Transmission Security
We validate encryption of ePHI in transit across patient portals, APIs, HL7/FHIR interfaces, and VPNs, attempting interception, downgrade, and man-in-the-middle attacks.
§164.308(a)(5)
Security Awareness & Training
Phishing and social-engineering simulations measure how clinical and administrative staff respond to realistic attacks aimed at harvesting credentials and PHI.
§164.308(a)(6)
Security Incident Procedures
The engagement stress-tests detection and response, revealing whether your team notices an active intrusion before an attacker reaches patient data.
ENGAGEMENT METHODOLOGY
A Repeatable, Evidence-Driven Process
01
Scope & RoE
02
Reconnaissance
03
Exploitation
04
PHI Impact
05
Reporting
06
Re-Test
THE DEFINING HEALTHCARE RISK
Connected Medical Devices
Infusion pumps, imaging systems, and bedside monitors were built for uptime and longevity, not security. They run unpatched legacy operating systems, cannot be taken offline for maintenance, and share networks with the very records they endanger. IoMT is where healthcare’s attack surface is most exposed and least understood.
Infusion & Smart Pumps
Dose-critical, network-connected, rarely patched
Imaging: PACS, MRI, CT
Large legacy fleets on flat DICOM networks
Patient & Vital Monitors
Bedside telemetry on shared clinical VLANs
Lab & Diagnostic Systems
Middleware bridging LIS and analyzers
Facility & Building Systems
Nurse call, HVAC, and access control (OT)
ASSESSMENT COVERAGE
What We Test in a Healthcare Environment
Engagements are scoped to your environment. Below are the domains we most commonly assess for hospitals, clinics, and healthtech platforms handling protected health information.
EXTERNAL / PERIMETER
EHR & EMR System Testing
We assess Epic, Cerner, Meditech, and custom EHR deployments for authentication bypass, broken access control, and insecure interfaces that could expose complete patient records to an attacker.
EPIC
CERNER
AUTH BYPASS
RECORD EXPORT
PATIENT-FACING / TELEHEALTH
Patient Portals & Telehealth Apps
Patient portals, scheduling systems, and video-visit platforms are tested for account takeover, insecure direct object references that expose other patients’ records, and weak session handling.
IDOR
ACCOUNT TAKEOVER
SESSION
OWASP TOP 10
IoMT / CONNECTED DEVICES
Connected Medical Device Security
Infusion pumps, imaging systems, patient monitors, and other IoMT endpoints are evaluated for default credentials, unencrypted protocols, and network exposure that can endanger patient safety.
IoMT
DEFAULT CREDS
FDA PREMARKET
LEGACY OS
CLOUD / PHI STORAGE
Cloud & PHI Storage Audits
AWS, Azure, and GCP environments holding ePHI are reviewed for exposed storage buckets, misconfigured IAM roles, and unencrypted backups, mapped to HITRUST CSF and HIPAA safeguard requirements.
HITRUST
IAM MISCONFIG
BUCKET EXPOSURE
ENCRYPTION
INTERNAL / NETWORK
Internal Network & Segmentation
We simulate a breached clinical workstation to test lateral movement, flat-network exposure, and whether a single foothold can reach EHR databases, domain controllers, and backup systems.
LATERAL MOVEMENT
ACTIVE DIRECTORY
SEGMENTATION
PRIVILEGE ESC
WEB / API
Web Apps & HL7 / FHIR Interfaces
Billing portals, provider dashboards, and HL7 / FHIR APIs are tested for injection, broken object-level authorization, and insecure data exchange between clinical and third-party systems.
FHIR
HL7
INJECTION
BROKEN AUTHZ
WIRELESS / PHYSICAL
Wireless & Physical Access
Clinical Wi-Fi, guest networks, and physical access to workstations and server rooms are tested, including tailgating into restricted care areas and unlocked, unattended EHR sessions.
WPA2 / WPA3
ROGUE AP
TAILGATING
WORKSTATION
HUMAN / SOCIAL
Social Engineering & Phishing
Targeted phishing, vishing, and pretexting against clinical and administrative staff measure real-world susceptibility to credential theft and unauthorized PHI access, the leading cause of healthcare breaches.
PHISHING
VISHING
PRETEXTING
MFA FATIGUE
WHO WE SERVE
Built for the Full Care Continuum
Hospitals & Health Systems
Multi-site networks with the EHR at the core
Ambulatory & Clinics
Lean IT teams carrying high patient volume
Healthtech & Digital Health
Apps, APIs, and cloud-native PHI
Payers & TPAs
Claims data and member-facing portals
STANDARDS & FRAMEWORKS
Aligned to the Regulations That Govern You
HIPAA
Security Rule
HITECH
Breach Notif.
HITRUST
CSF
NIST
SP 800-66
HHS OCR
Enforcement
FDA
Premarket
WHAT YOU RECEIVE
Audit-Ready Documentation, Not Just a Tool Dump
OCR-Ready Findings Report
A findings report structured to support your HIPAA risk analysis and evaluation obligations, with reproducible evidence and severity ratings for every issue.
Executive Attestation Letter
A signed engagement summary suitable for boards, auditors, cyber-insurance carriers, and business-associate due-diligence requests.
Prioritized Remediation Roadmap
Every finding mapped to a concrete fix and sequenced by risk to patient data, so your IT team can close the most dangerous gaps first.
Complimentary Re-Test
After you remediate, we re-test the confirmed findings and update your documentation to verify closure, at no additional cost.
We scope every healthcare engagement individually. Tell us about your environment (EHR, portals, devices, cloud) and we’ll respond within one business day.
Request a Scoping Call
