Industry · Healthcare · GCC & US

Penetration testing for healthcare — where security is patient safety

Healthcare holds the most sensitive data there is and cannot tolerate downtime, which makes it a prime target. We deliver penetration testing for providers aligned to ADHICS, HIPAA and the region's data-protection laws — protecting patient data, EHR systems and the connected devices that care depends on.

HealthcareADHICSHIPAAEHRMedical DevicesePHI
Healthcare Security: ADHICS OM 7.1 (Yearly) · HIPAA Security Rule · PDPL · EHR · Patient Portals · Medical Devices · ePHI Protection Healthcare Security: ADHICS OM 7.1 (Yearly) · HIPAA Security Rule · PDPL · EHR · Patient Portals · Medical Devices · ePHI Protection
// TL;DR

Healthcare combines the most valuable data an attacker can steal — electronic protected health information — with zero tolerance for downtime, making it one of the most attacked sectors and one where security failures have patient-safety consequences. In Abu Dhabi, ADHICS control OM 7.1 explicitly mandates yearly penetration testing, vulnerability assessment and web security assessment. Under US HIPAA, testing is expected Security Rule evidence, with a December 2024 proposed rule that would make it mandatory annually. The region's PDPL regimes add data-protection obligations. We test patient portals, EHR systems, hospital networks and connected medical devices, map findings to the applicable frameworks, and handle ePHI with appropriate care.

// 01 Why healthcare needs penetration testing

Healthcare sits at an uncomfortable intersection of high value and high fragility. Patient records are worth more on criminal markets than credit-card data, because they contain everything needed for identity and insurance fraud and cannot be reissued. At the same time, hospitals cannot simply take systems offline — care delivery depends on availability, which is exactly why ransomware operators target the sector so heavily: a provider under pressure to restore patient care is more likely to pay. When an attack disrupts systems, the consequence is not just a data breach but a potential impact on patient safety.

Add large, long-lived technology estates, a growing population of connected medical devices, and strict regulation, and healthcare becomes a sector where penetration testing is both mandated and genuinely consequential. Finding the weaknesses before an attacker does protects patients as much as data.

// 02 The regulatory drivers

ADHICS

Abu Dhabi — explicit yearly mandate

ADHICS control OM 7.1 requires Abu Dhabi healthcare entities to conduct yearly penetration testing, vulnerability assessment and web security assessment. The region's clearest healthcare mandate.

HIPAA

United States

Penetration testing is expected evidence for the HIPAA Security Rule; a December 2024 proposed rule would make annual testing and six-monthly vulnerability scans mandatory.

PDPL

Data protection

The Bahrain, Saudi and UAE personal-data-protection laws impose security obligations on patient data — including that unmasked patient records should not sit in test environments.

NCA ECC

Saudi health entities

Saudi healthcare organisations, especially those classified as critical, also fall under the NCA ECC.

// 03 What we test for a healthcare provider

01

Patient portals & APIs

Public-facing portals and their APIs — authentication, and whether a patient can only ever access their own records.

02

EHR & clinical systems

Electronic health record and clinical systems holding ePHI, and the access paths that could reach them.

03

Internal network

The hospital network and Active Directory — lateral movement, and segmentation between clinical and corporate systems.

04

Medical devices & IoMT

Connected medical devices and the Internet of Medical Things — a growing, often poorly-segmented attack surface.

// 04 What we commonly find

CriticalAccess control

Broken authorisation in patient portals

A portal that authenticates a patient but fails to verify record ownership, exposing other patients' health data by changing an identifier.

HighSegmentation

Flat clinical networks

Medical devices and clinical systems on the same flat network as corporate IT, so a phishing foothold reaches life-critical systems.

HighLegacy

Unpatched legacy and devices

Medical devices and clinical workstations on end-of-life operating systems that cannot be patched without vendor re-validation.

MediumData

Patient data in test environments

Unmasked ePHI in non-production — a finding in its own right and a PDPL and HIPAA exposure.

// 05 Reporting for compliance and patient safety

A healthcare report has to serve the regulator, the clinical leadership and often the health insurer at once. We map every finding to the applicable control — ADHICS OM 7.1, the HIPAA Security Rule, PDPL obligations — and express severity in terms of both data risk and, where relevant, care-delivery risk. ePHI is handled with appropriate care throughout the engagement and in the report itself. Because retesting is included, you can evidence closure to your regulator and demonstrate the continuous security-testing posture that ADHICS and the proposed HIPAA rule expect. Where medical devices are in scope, we account for their fragility exactly as we would in an OT environment.

// 06 Frequently asked questions

Is penetration testing required for healthcare?

In Abu Dhabi, yes — ADHICS OM 7.1 mandates yearly testing. Under HIPAA it is expected Security Rule evidence, with a 2024 proposed rule that would make it mandatory annually. PDPL adds data-protection obligations.

What does it cover?

Patient portals and APIs, EHR and clinical systems, the internal network, insurance/claims systems, and connected medical devices.

Why is healthcare a ransomware target?

Valuable patient data plus zero tolerance for downtime makes providers more likely to pay — and the impact reaches patient safety, not just data.

Does ADHICS require yearly testing?

Yes — OM 7.1 requires yearly penetration testing, vulnerability assessment and web security assessment.

AH

Ankur H.

Security & Compliance Specialist, CyberFortify

Leads healthcare engagements mapped to ADHICS, HIPAA and the region's PDPL regimes — protecting patient data and the systems care delivery depends on.

Protecting patient data?

We scope healthcare engagements to your ePHI systems and connected devices, handle patient data with care, and map findings to ADHICS, HIPAA and PDPL — with retest included so you can evidence continuous testing.

Schedule scoping call → ADHICS requirements →