Penetration Testing of a Hospital IT Infrastructure for a US Health System

Penetration Testing of a Hospital IT Infrastructure for a US Health System

Industry
Healthcare

Summary

A large US public health system was concerned about potential vulnerabilities in the internal IT infrastructure of its teaching hospital that could endanger patient health information and critical IT services. In an 18-day gray-box penetration test, INNERLUXES assessed the hospital's complex environment, surfaced HIPAA-relevant security gaps, and delivered actionable remediation guidance that the in-house IT team used to strengthen its security posture.

About the Client

The Client is a large US public health system with more than 20 outpatient clinics and a teaching hospital.

The Challenge

The Client was concerned about potential vulnerabilities in the internal IT infrastructure of its teaching hospital that could endanger patients' personal health information and critical IT services, causing HIPAA compliance breaches and workflow disruption. The size and complexity of the hospital's IT environment required a comprehensive and scrupulous approach, so the Client looked for an experienced provider with a portfolio of healthcare pentesting projects.

The Solution

Having analyzed the Client's testing scope and needs, INNERLUXES suggested gray-box penetration testing to deliver quick and comprehensive results. A team of three penetration testers started with automated vulnerability scanning to detect security gaps in the internal infrastructure, then analyzed the findings to exclude false positives and proceeded with vulnerability exploitation.

Thanks to the Client's proactive approach to cyber defense — regular security testing and continuous vulnerability management of its IT assets, as required by the HIPAA Security Rule — its internal infrastructure had no severe vulnerabilities. However, INNERLUXES's penetration testers revealed a number of less critical security gaps that could be exploited to break through the hospital's security perimeter, for example: an obsolete operating system, outdated software, expired SSL certificates, deprecated SSH cryptographic settings, and weak security configurations of a remote desktop protocol (RDP).

INNERLUXES recommended corrective actions to improve protection against potential attacks — for example, updating the OS and vulnerable software to the latest available versions, enabling Network Level Authentication (NLA) on the remote RDP server and upgrading the RDP encryption level, and installing SSL certificates with valid start and end dates. The entire project, from planning to reporting the results, took 18 days.

The Results

  • The Client received a comprehensive report describing the detected vulnerabilities, classified by severity and likelihood of exploitation, with actionable guidance on remediation.
  • Relying on the guidance, the Client's IT team fixed the potentially dangerous security issues and ensured a high security level for its internal IT infrastructure.

Technologies and Tools

Nessus, OWASP Zed Attack Proxy (ZAP), SSLScan, Metasploit, Burp Suite, Nmap, dirb, DBeaver.