Healthcare combines the most valuable data an attacker can steal — electronic protected health information — with zero tolerance for downtime, making it one of the most attacked sectors and one where security failures have patient-safety consequences. In Abu Dhabi, ADHICS control OM 7.1 explicitly mandates yearly penetration testing, vulnerability assessment and web security assessment. Under US HIPAA, testing is expected Security Rule evidence, with a December 2024 proposed rule that would make it mandatory annually. The region's PDPL regimes add data-protection obligations. We test patient portals, EHR systems, hospital networks and connected medical devices, map findings to the applicable frameworks, and handle ePHI with appropriate care.
// 01 Why healthcare needs penetration testing
Healthcare sits at an uncomfortable intersection of high value and high fragility. Patient records are worth more on criminal markets than credit-card data, because they contain everything needed for identity and insurance fraud and cannot be reissued. At the same time, hospitals cannot simply take systems offline — care delivery depends on availability, which is exactly why ransomware operators target the sector so heavily: a provider under pressure to restore patient care is more likely to pay. When an attack disrupts systems, the consequence is not just a data breach but a potential impact on patient safety.
Add large, long-lived technology estates, a growing population of connected medical devices, and strict regulation, and healthcare becomes a sector where penetration testing is both mandated and genuinely consequential. Finding the weaknesses before an attacker does protects patients as much as data.
// 02 The regulatory drivers
Abu Dhabi — explicit yearly mandate
ADHICS control OM 7.1 requires Abu Dhabi healthcare entities to conduct yearly penetration testing, vulnerability assessment and web security assessment. The region's clearest healthcare mandate.
United States
Penetration testing is expected evidence for the HIPAA Security Rule; a December 2024 proposed rule would make annual testing and six-monthly vulnerability scans mandatory.
Data protection
The Bahrain, Saudi and UAE personal-data-protection laws impose security obligations on patient data — including that unmasked patient records should not sit in test environments.
Saudi health entities
Saudi healthcare organisations, especially those classified as critical, also fall under the NCA ECC.
// 03 What we test for a healthcare provider
Patient portals & APIs
Public-facing portals and their APIs — authentication, and whether a patient can only ever access their own records.
EHR & clinical systems
Electronic health record and clinical systems holding ePHI, and the access paths that could reach them.
Internal network
The hospital network and Active Directory — lateral movement, and segmentation between clinical and corporate systems.
Medical devices & IoMT
Connected medical devices and the Internet of Medical Things — a growing, often poorly-segmented attack surface.
// 04 What we commonly find
Broken authorisation in patient portals
A portal that authenticates a patient but fails to verify record ownership, exposing other patients' health data by changing an identifier.
Flat clinical networks
Medical devices and clinical systems on the same flat network as corporate IT, so a phishing foothold reaches life-critical systems.
Unpatched legacy and devices
Medical devices and clinical workstations on end-of-life operating systems that cannot be patched without vendor re-validation.
Patient data in test environments
Unmasked ePHI in non-production — a finding in its own right and a PDPL and HIPAA exposure.
// 05 Reporting for compliance and patient safety
A healthcare report has to serve the regulator, the clinical leadership and often the health insurer at once. We map every finding to the applicable control — ADHICS OM 7.1, the HIPAA Security Rule, PDPL obligations — and express severity in terms of both data risk and, where relevant, care-delivery risk. ePHI is handled with appropriate care throughout the engagement and in the report itself. Because retesting is included, you can evidence closure to your regulator and demonstrate the continuous security-testing posture that ADHICS and the proposed HIPAA rule expect. Where medical devices are in scope, we account for their fragility exactly as we would in an OT environment.
// 06 Frequently asked questions
Is penetration testing required for healthcare?
In Abu Dhabi, yes — ADHICS OM 7.1 mandates yearly testing. Under HIPAA it is expected Security Rule evidence, with a 2024 proposed rule that would make it mandatory annually. PDPL adds data-protection obligations.
What does it cover?
Patient portals and APIs, EHR and clinical systems, the internal network, insurance/claims systems, and connected medical devices.
Why is healthcare a ransomware target?
Valuable patient data plus zero tolerance for downtime makes providers more likely to pay — and the impact reaches patient safety, not just data.
Does ADHICS require yearly testing?
Yes — OM 7.1 requires yearly penetration testing, vulnerability assessment and web security assessment.