Pentesting to Safeguard PHI for a SaaS Provider Serving 9K Pharmacies
Summary
A US SaaS provider of HIPAA-compliant pharmacy management software needed to verify the security of its cloud-based pharmacy–patient engagement platform. In just five business days, INNERLUXES ran a PTES/OWASP/NIST 800-115 black-box penetration test across 106 IP addresses, 23 ELB domain names, and 8 API endpoints, found 13 CVSS-classified vulnerabilities, and delivered remediation guidance that protected PHI — confirmed by a follow-up retest.
About the Client
The Client is a US-based provider of HIPAA-compliant software for pharmacy management, serving more than 9,000 organizations globally.
Need for a Pentesting Vendor with Expertise in Healthcare Software
Committed to ensuring the protection of its clients' data, the Client was looking for a reliable vendor to verify the security of its cloud-based digital platform for pharmacy–patient engagement, and turned to INNERLUXES for security testing.
Pentesting Revealed Risks to Patient Record Security
INNERLUXES conducted security testing of the Client's patient engagement solution following the PTES, the OWASP Web Security Testing Guide, and the NIST 800-115 methodology. The team started with open-source intelligence (OSINT) techniques: acting as a hacker with no prior knowledge of the target, the pentesters investigated publicly available services, applications, and ports serving the solution, gathered information such as domain names and IP ranges, identified potential threats, and prioritized possible attack vectors and scenarios.
The team followed up with a vulnerability assessment: using automated tools and manual analysis, they checked 106 IP addresses, 23 ELB domain names, and 8 API endpoints.
In the subsequent black-box pentest, INNERLUXES explored the likelihood and potential impact of exploiting the security gaps found. As a result, the team discovered 13 vulnerabilities, of which four were high-severity and two were medium-severity. The weaknesses included unauthorized access to sensitive information, security misconfigurations, cryptographic flaws, and outdated, vulnerable software versions. To seal these and other gaps, INNERLUXES suggested corrective measures, such as:
- Classifying sensitive, personally identifiable (PII), and protected health information (PHI) stored and processed by the servers, enforcing strong access control mechanisms, and disabling directory listing to prevent data breaches.
- Restricting access to resources intended for internal use via VPN, proxy, or jump host.
- Enforcing TLS 1.2 and TLS 1.3 and disabling outdated, insecure cryptographic protocols (SSLv3, TLS 1.0, and TLS 1.1).
- Updating outdated and vulnerable software to the latest version to mitigate the risk of confidential information disclosure and command injection, cross-site scripting (XSS), man-in-the-middle (MITM), denial of service (DoS), and other attacks.
Prompt Detection and Remediation of Severe Security Issues
- INNERLUXES performed black-box pentesting of 106 IP addresses, 23 ELB domain names, and 8 API endpoints of the digital patient engagement platform in just five business days.
- The Client received a comprehensive report detailing the testing activities, remediation advice, and vulnerabilities assessed and classified according to the OWASP Top 10, OWASP API Top 10, and NIST CVSS.
- Guided by the remediation recommendations, the Client fortified the security of its IT assets and sensitive data, which INNERLUXES confirmed during a quick retest round.
Technologies and Tools
Nessus, Burp Suite, Acunetix, Postman, Nikto, SSLScan, DirB, KiteRunner, Nmap, Netcat, Ffuf, PuTTY, Python, C, Perl.