Pentesting for a Remote Patient Monitoring Vendor to Ensure HITRUST CSF and HIPAA Compliance
Summary
A remote patient monitoring vendor whose software collects, stores, and processes personal health information needed annual penetration testing of its web portal and iOS/Android apps to uphold HITRUST CSF and HIPAA requirements. INNERLUXES performed gray-box pentesting per the OWASP Web Security Testing Guide and NIST SP 800-115 in 19 days — combining automated scanning with manual validation and exploitation — uncovered several misconfigurations, and confirmed an improved security level on retest after the vendor applied the fixes.
About the Client
The Client is the provider of an all-in-one solution for managing chronic diseases. They deliver remote patient monitoring and care management to increase patient satisfaction and enhance treatment outcomes.
The Challenge
As the Client's software collects, stores, and processes personal health information, they need to ensure that this sensitive data is protected as required by HITRUST CSF and HIPAA. To perform annual pentesting of their web portal and corresponding iOS and Android apps, the Client was looking for a penetration testing provider with deep expertise in the healthcare industry.
The Solution
To keep a good balance of testing coverage and speed, INNERLUXES suggested conducting penetration tests according to the gray-box model. The Client provided INNERLUXES's team of 3 security testers with credentials for testing under different user roles (a patient, a healthcare provider, and a system administrator).
To conduct pentesting of the Client's web platform and mobile apps, INNERLUXES's security experts relied on the OWASP Web Security Testing Guide and the NIST SP 800-115 methodology. Testing began with automated scanning of the targets to detect the maximum number of vulnerabilities, followed by manual validation and exploitation of vulnerabilities to analyze their potential impact.
INNERLUXES's testers evaluated the overall security level of the platform and mobile apps as medium. Our team identified security issues that could potentially enable unauthorized access to sensitive information or to the IT infrastructure of the healthcare providers that use the platform. Among the misconfigurations we discovered were insecure access control functionality, insecure app-to-server communication in the Android app, and a missing HTTP Strict Transport Security (HSTS) policy.
INNERLUXES's security team described the necessary corrective measures for the discovered vulnerabilities — for example, limiting the number of registration attempts from a single IP address and tailoring access to software functionality by user role.
The pentesting project took 19 days from planning and preparation to execution and reporting.
The Results
- The Client received a detailed report describing the pentesting process, its findings, and recommended corrective measures for the detected security issues — actionable guidance for fixing the revealed vulnerabilities.
- As tangible proof of the Client's proactive approach to PHI protection, the report became a valuable contribution to the company's compliance documentation.
- After the Client fixed the detected security issues, retesting by INNERLUXES confirmed an increased security level of the platform and mobile apps.
Technologies and Tools
Metasploit, Wireshark, Nessus, Burp Suite, Acunetix, Nmap, dirb, custom scripts (Python, C, and Perl scripts to exploit vulnerabilities).