Security across the care journeyAtlant Security
Healthcare/PentestBY ATLANT SECURITY

HEALTHCARE PENETRATION TESTING

Patient portal & healthcare API testing

Test the permissions behind the patient experience, from account recovery to record sharing.

Discuss your requirements

The boundary worth testing

Object-level access checks, patient/proxy relationships, provider tenancy and bulk exports require deliberate testing with different identities. A valid login is only the beginning of the authorisation model.

A patient portal can be well defended at the login screen while a laboratory integration accepts a record identifier without checking the requesting organisation. The valuable test follows those hand-offs, including the support processes that sit outside the main application.

What the scope can include

  • Patient, clinician, proxy and administrator role boundaries
  • Record/document identifiers and cross-organisation access
  • Account recovery, session expiry and consent-sensitive sharing
  • File upload, referral changes and export workflows

The final proposal identifies the specific applications, accounts, environments and interfaces included. It also states which prerequisites your team or a supplier must provide.

What useful proof looks like

Use two synthetic patients and two provider organisations. Record which principal requested which object, the expected decision and the actual response. Verify a write with a separate read-back rather than trusting a success banner.

Preserve UTC time, asset identifier, requesting principal, expected decision and observed response. State-changing tests need confirmation from the resulting object or a trusted audit record. Denied operations and effective controls remain part of the outcome.

Safety and assessment limits

The scope identifies the specific APIs and profiles in use. FHIR is a data-exchange standard, not proof that an endpoint enforces the organisation’s access policy.

Use synthetic patient identities and agreed data cohorts. Name a clinical escalation contact, set request limits and exclude treatment-affecting actions unless separately authorised. Stop immediately if testing encounters unexpected live clinical data or threatens a care workflow.

Close the loop

Connect each weakness to a named owner, immediate safeguard and durable correction. Define positive and negative retest cases so the change restores the intended boundary while preserving legitimate use. Open items retain their dependencies and deadlines.

Preview the sector sample report to see the evidence and treatment-plan format.

LET’S START A CONVERSATION

Define the scope.
Take the next step.

Your systems, operating constraints and security objectives. A clear starting point for the test.

Discuss your pentest