Medical Systems Penetration Testing
Medical systems were designed for networks cut off from the internet — DICOM without authentication, HL7 without encryption, PACS servers unpatched for years. Today they are online. We find the vulnerabilities with controlled methods, without stopping the facility. You get a report with priorities and a remediation roadmap.

What is Medical Systems Penetration Testing?
Medical Systems Penetration Testing is the controlled, patient-safety-aware security testing of a healthcare facility's core systems — HIS, PACS, LIS — and medical protocols DICOM, HL7 and FHIR, conducted with methods adapted to 24/7 operation, without risking a disruption of patient care. nFlo follows a tiered approach: from passive reconnaissance, through controlled active testing, to exploitation verification outside production systems, delivering a report with a prioritized remediation roadmap and an optional retest.
Medical systems were designed for offline networks - today they are on the internet
Penetration testing adapted to healthcare specifics
Passive Reconnaissance
We map systems without interfering with operations
Safe Testing
Methods adapted to 24/7 operation
Remediation Roadmap
Vulnerability prioritization and action plan
What Is Medical Systems Penetration Testing?
Medical Systems Penetration Testing is the controlled penetration testing of a healthcare facility’s core systems — HIS, PACS, LIS — and medical protocols (DICOM, HL7, FHIR), carried out with regard for continuity of patient care and the safety of diagnostic equipment.
| Attribute | Value |
|---|---|
| Scope | HIS, PACS, LIS, IoMT, integrations (DICOM, HL7, FHIR) |
| For whom | Hospitals, clinics, laboratories, medical networks |
| Approach | Non-invasive, patient-safety-aware |
| Standards | OWASP Top 10, OWASP API Security, PTES, OSSTMM |
| Duration | 10-20 working days |
| Price | from EUR 7,000 (as of 2026) |
A Patient’s Medical Image Accessible From a Browser — Without a Password
The DICOM protocol, on which hospital imaging systems rely, was designed at a time when the radiology network was physically cut off from the world. Authentication and encryption were not foreseen — because “everyone on the network was trusted”. Digitalization, teleradiology and the cloud changed that for good: today patient examinations can be publicly accessible online through misconfigured PACS servers. A browser and an IP address are enough.
Without medical systems penetration testing:
- Critical vulnerabilities remain unknown until a data breach or a ransomware attack
- A standard IT pentest skips medical protocols, IoMT and the specifics of 24/7 operation
- You do not know whether HIS, PACS and LIS are genuinely isolated from the internet
- There is no prioritization — you do not know which vulnerability to patch first
- You do not meet the NIS2 and KSC act requirement for regular security testing
Pentests Without Risk to Patient Care
We use a methodology adapted to the realities of healthcare. We know which tests are safe for a HIS while a ward is running, and which require a maintenance window or a test environment. We do not stop the facility.
What you get:
- An inventory of medical systems and integration protocols (DICOM, HL7v2, FHIR)
- Security testing of the HIS — authentication, access control, application logic
- Verification of PACS server exposure and DICOM protocol security
- Testing of laboratory systems (LIS) and data exchange interfaces
- Analysis of FHIR API security and HL7 integrations
- Verification of medical network segmentation and IoMT device isolation
- A report with risk assessment, prioritization and mapping to NIS2 requirements
- Support during the implementation of fixes
- An optional retest after remediation
Who Is It For?
This service is for you if you are:
- A public or private hospital (district, regional, multi-specialty)
- A clinic or medical center with a HIS
- A diagnostic laboratory or radiology department
- A network of medical facilities or a healthcare entity covered by NIS2
- A medical software vendor who wants to verify the product before deployment
What We Test in a Medical Environment
HIS — Hospital Information System
The facility’s central system — the “brain” of the entire operation. We test:
- Authentication and role-based access control (RBAC)
- Business logic and web application vulnerabilities (OWASP Top 10)
- Session security and login mechanisms
- Privilege escalation between roles (physician, nurse, administration)
- Database security and access to medical records (EHR)
PACS and the DICOM Protocol
Imaging systems are most often the part of medical infrastructure exposed to the internet. We test:
- Exposure of PACS servers and DICOM nodes (ports 104, 11112)
- Missing authentication and cleartext data transmission
- Vulnerabilities in known implementations (DCMTK, Orthanc, Sante PACS)
- The ability to download examinations and PII from DICOM tags
- The risk of dual-personality files (DICOM + executable file)
LIS and the HL7 / FHIR Protocols
Laboratory systems and medical data exchange interfaces. We test:
- Security of HL7v2 transmission over MLLP (no authentication or encryption)
- Integrity of test results and resistance to manipulation
- FHIR API — access control, object-level authorization (BOLA/IDOR)
- OAuth 2.0 implementation and token scope
- Data segregation between patient records
Medical Devices (IoMT)
Infusion pumps, cardiac monitors, diagnostic equipment. We test non-invasively:
- The real exposure and network isolation (VLAN, segmentation)
- Default passwords and unsecured services
- Unencrypted communication and the risk of eavesdropping
- The effectiveness of compensating controls (NAC, anomaly monitoring)
Integrations and Segmentation
- Routing and firewalls between the administrative, medical and IoMT networks
- Integration buses and HL7 interface engines
- Remote access and teleradiology (VPN, RDP)
- The attack surface on the vendor side (vendor access)
Our Methodology
Patient Safety Is the Priority
Medical systems penetration testing differs from IT testing — the facility runs without interruption, and diagnostic equipment is sensitive to unusual network traffic. We use a tiered approach:
1. Pre-engagement
- Detailed discussion of scope and limitations
- Defining “red lines” — systems and devices we do NOT test actively
- A communication plan with the IT team and facility management
- A maintenance window and alarm procedures
2. Passive Reconnaissance (Tier 1)
- Inventory of systems, protocols and the attack surface
- Network traffic analysis without sending packets
- Documentation and configuration review
- Safe for facility operation: YES
3. Controlled Active Testing (Tier 2)
- Scanning and vulnerability verification (CVE)
- Testing of authentication, authorization and application logic
- Analysis of the DICOM, HL7 and FHIR API protocols
- Requires: coordination with the IT team, a maintenance window
4. Exploitation Verification (Tier 3)
- Controlled confirmation of selected vulnerabilities
- Performed on a test environment or a copy of the system
- Requires: isolation or a non-production environment
5. Reporting and Remediation
- A detailed report with risk assessment and prioritization
- Mapping of the results to NIS2 and KSC act requirements
- A workshop with the facility’s team
- An optional retest after fixes are implemented
Related Glossary Terms
Learn more about key concepts related to this service:
Contact your account manager
Discuss Medical Systems Penetration Testing with your dedicated account manager.

How we work
Our proven service delivery process.
Kick-off
We define scope, critical systems and safety rules
Passive Reconnaissance
Inventory of medical systems and protocols without interference
Controlled Testing
Safe verification of HIS, PACS, LIS vulnerabilities
Report
Detailed report with risk assessment and priorities
Retest
Verification of implemented fixes
Benefits for your business
What you gain by choosing this service.
Find Vulnerabilities First
Before an attacker or ransomware does
NIS2 and KSC Compliance
Meet the requirement for annual security testing
Patient Protection
Protect medical data and continuity of care
Lower Risk of Fines
Avoid GDPR penalties for medical data breaches
Related Articles
Expand your knowledge with our resources.
IT services outsourcing — how to choose a provider and where to draw the line of responsibility
Outsourcing IT services is not a decision about whether to outsource, but a decision about where the line of responsibility runs. This article compares three delivery models, shows what stays on your side despite the contract, and lists the questions worth asking a provider before you sign.
Read more →Penetration test vs vulnerability scan: what really differs
A company that buys a scan instead of a pentest is not buying the same thing for less — it is buying different information. Here is exactly where the boundary runs and how to arrange both into one process.
Read more →Web application penetration testing cost and what creates it
Three quotes for testing the same application can differ several times over — and rarely because someone applies a different margin. Each one prices different work. Here is what that difference is made of, and how to write a request that makes quotes comparable.
Read more →Frequently Asked Questions
Common questions about Medical Systems Penetration Testing.
How much does medical systems penetration testing cost?
Small clinic (HIS and basic infrastructure): EUR 7,000-12,000. District hospital (HIS, PACS, LIS, integrations): EUR 14,000-26,000. Large multi-specialty hospital or facility network: EUR 33,000+. The price includes testing, the report and a presentation of results.
Can the tests disrupt hospital operations?
No. Reconnaissance and passive analysis do not interfere with systems. Active tests are coordinated with the facility's IT team - in a maintenance window or on a test environment. Exploitation that confirms a vulnerability is carried out outside production systems. You have full control over the scope.
How does medical systems penetration testing differ from a regular application pentest?
A standard web application pentest does not cover medical protocols (DICOM, HL7, FHIR), IoMT devices or the specifics of 24/7 operation. We test them with patient-safety-aware methods - we do not generate traffic that could disturb the operation of diagnostic equipment.
What about medical devices that cannot be updated?
We test them non-invasively and verify the real exposure - whether they are isolated in a separate VLAN, what services they expose, whether they have default passwords. Where a vulnerability cannot be patched, we recommend compensating controls: segmentation, NAC access control and anomaly monitoring.
How often should medical systems penetration tests be repeated?
We recommend every 12 months and after significant changes (a new HIS, an integration, a data migration). NIS2 and the amended KSC act require hospitals to run regular security tests - at least once a year.