Skip to content
Cybersecurity

Medical Systems Penetration Testing

Medical systems were designed for networks cut off from the internet — DICOM without authentication, HL7 without encryption, PACS servers unpatched for years. Today they are online. We find the vulnerabilities with controlled methods, without stopping the facility. You get a report with priorities and a remediation roadmap.

Sales Representative
Grzegorz Gnych

Grzegorz Gnych

Sales Representative

What is Medical Systems Penetration Testing?

Medical Systems Penetration Testing is the controlled, patient-safety-aware security testing of a healthcare facility's core systems — HIS, PACS, LIS — and medical protocols DICOM, HL7 and FHIR, conducted with methods adapted to 24/7 operation, without risking a disruption of patient care. nFlo follows a tiered approach: from passive reconnaissance, through controlled active testing, to exploitation verification outside production systems, delivering a report with a prioritized remediation roadmap and an optional retest.

Certified Pentesters
OSCP, OSWE, eCPPT
Patient-Safe
24/7 facility operation
Practical Reports
Priorities and remediation steps

Medical systems were designed for offline networks - today they are on the internet

Penetration testing adapted to healthcare specifics

Passive Reconnaissance

We map systems without interfering with operations

Safe Testing

Methods adapted to 24/7 operation

Remediation Roadmap

Vulnerability prioritization and action plan

What Is Medical Systems Penetration Testing?

Medical Systems Penetration Testing is the controlled penetration testing of a healthcare facility’s core systems — HIS, PACS, LIS — and medical protocols (DICOM, HL7, FHIR), carried out with regard for continuity of patient care and the safety of diagnostic equipment.

AttributeValue
ScopeHIS, PACS, LIS, IoMT, integrations (DICOM, HL7, FHIR)
For whomHospitals, clinics, laboratories, medical networks
ApproachNon-invasive, patient-safety-aware
StandardsOWASP Top 10, OWASP API Security, PTES, OSSTMM
Duration10-20 working days
Pricefrom EUR 7,000 (as of 2026)

A Patient’s Medical Image Accessible From a Browser — Without a Password

The DICOM protocol, on which hospital imaging systems rely, was designed at a time when the radiology network was physically cut off from the world. Authentication and encryption were not foreseen — because “everyone on the network was trusted”. Digitalization, teleradiology and the cloud changed that for good: today patient examinations can be publicly accessible online through misconfigured PACS servers. A browser and an IP address are enough.

Without medical systems penetration testing:

  • Critical vulnerabilities remain unknown until a data breach or a ransomware attack
  • A standard IT pentest skips medical protocols, IoMT and the specifics of 24/7 operation
  • You do not know whether HIS, PACS and LIS are genuinely isolated from the internet
  • There is no prioritization — you do not know which vulnerability to patch first
  • You do not meet the NIS2 and KSC act requirement for regular security testing

Pentests Without Risk to Patient Care

We use a methodology adapted to the realities of healthcare. We know which tests are safe for a HIS while a ward is running, and which require a maintenance window or a test environment. We do not stop the facility.

What you get:

  • An inventory of medical systems and integration protocols (DICOM, HL7v2, FHIR)
  • Security testing of the HIS — authentication, access control, application logic
  • Verification of PACS server exposure and DICOM protocol security
  • Testing of laboratory systems (LIS) and data exchange interfaces
  • Analysis of FHIR API security and HL7 integrations
  • Verification of medical network segmentation and IoMT device isolation
  • A report with risk assessment, prioritization and mapping to NIS2 requirements
  • Support during the implementation of fixes
  • An optional retest after remediation

Who Is It For?

This service is for you if you are:

  • A public or private hospital (district, regional, multi-specialty)
  • A clinic or medical center with a HIS
  • A diagnostic laboratory or radiology department
  • A network of medical facilities or a healthcare entity covered by NIS2
  • A medical software vendor who wants to verify the product before deployment

What We Test in a Medical Environment

HIS — Hospital Information System

The facility’s central system — the “brain” of the entire operation. We test:

  • Authentication and role-based access control (RBAC)
  • Business logic and web application vulnerabilities (OWASP Top 10)
  • Session security and login mechanisms
  • Privilege escalation between roles (physician, nurse, administration)
  • Database security and access to medical records (EHR)

PACS and the DICOM Protocol

Imaging systems are most often the part of medical infrastructure exposed to the internet. We test:

  • Exposure of PACS servers and DICOM nodes (ports 104, 11112)
  • Missing authentication and cleartext data transmission
  • Vulnerabilities in known implementations (DCMTK, Orthanc, Sante PACS)
  • The ability to download examinations and PII from DICOM tags
  • The risk of dual-personality files (DICOM + executable file)

LIS and the HL7 / FHIR Protocols

Laboratory systems and medical data exchange interfaces. We test:

  • Security of HL7v2 transmission over MLLP (no authentication or encryption)
  • Integrity of test results and resistance to manipulation
  • FHIR API — access control, object-level authorization (BOLA/IDOR)
  • OAuth 2.0 implementation and token scope
  • Data segregation between patient records

Medical Devices (IoMT)

Infusion pumps, cardiac monitors, diagnostic equipment. We test non-invasively:

  • The real exposure and network isolation (VLAN, segmentation)
  • Default passwords and unsecured services
  • Unencrypted communication and the risk of eavesdropping
  • The effectiveness of compensating controls (NAC, anomaly monitoring)

Integrations and Segmentation

  • Routing and firewalls between the administrative, medical and IoMT networks
  • Integration buses and HL7 interface engines
  • Remote access and teleradiology (VPN, RDP)
  • The attack surface on the vendor side (vendor access)

Our Methodology

Patient Safety Is the Priority

Medical systems penetration testing differs from IT testing — the facility runs without interruption, and diagnostic equipment is sensitive to unusual network traffic. We use a tiered approach:

1. Pre-engagement

  • Detailed discussion of scope and limitations
  • Defining “red lines” — systems and devices we do NOT test actively
  • A communication plan with the IT team and facility management
  • A maintenance window and alarm procedures

2. Passive Reconnaissance (Tier 1)

  • Inventory of systems, protocols and the attack surface
  • Network traffic analysis without sending packets
  • Documentation and configuration review
  • Safe for facility operation: YES

3. Controlled Active Testing (Tier 2)

  • Scanning and vulnerability verification (CVE)
  • Testing of authentication, authorization and application logic
  • Analysis of the DICOM, HL7 and FHIR API protocols
  • Requires: coordination with the IT team, a maintenance window

4. Exploitation Verification (Tier 3)

  • Controlled confirmation of selected vulnerabilities
  • Performed on a test environment or a copy of the system
  • Requires: isolation or a non-production environment

5. Reporting and Remediation

  • A detailed report with risk assessment and prioritization
  • Mapping of the results to NIS2 and KSC act requirements
  • A workshop with the facility’s team
  • An optional retest after fixes are implemented

Learn more about key concepts related to this service:

Contact your account manager

Discuss Medical Systems Penetration Testing with your dedicated account manager.

Sales Representative
Grzegorz Gnych

Grzegorz Gnych

Sales Representative

Response within 24 hours
Free consultation
Custom quote

Providing your phone number will speed up contact.

How we work

Our proven service delivery process.

01

Kick-off

We define scope, critical systems and safety rules

02

Passive Reconnaissance

Inventory of medical systems and protocols without interference

03

Controlled Testing

Safe verification of HIS, PACS, LIS vulnerabilities

04

Report

Detailed report with risk assessment and priorities

05

Retest

Verification of implemented fixes

Benefits for your business

What you gain by choosing this service.

Find Vulnerabilities First

Before an attacker or ransomware does

NIS2 and KSC Compliance

Meet the requirement for annual security testing

Patient Protection

Protect medical data and continuity of care

Lower Risk of Fines

Avoid GDPR penalties for medical data breaches

Frequently Asked Questions

Common questions about Medical Systems Penetration Testing.

How much does medical systems penetration testing cost?

Small clinic (HIS and basic infrastructure): EUR 7,000-12,000. District hospital (HIS, PACS, LIS, integrations): EUR 14,000-26,000. Large multi-specialty hospital or facility network: EUR 33,000+. The price includes testing, the report and a presentation of results.

Can the tests disrupt hospital operations?

No. Reconnaissance and passive analysis do not interfere with systems. Active tests are coordinated with the facility's IT team - in a maintenance window or on a test environment. Exploitation that confirms a vulnerability is carried out outside production systems. You have full control over the scope.

How does medical systems penetration testing differ from a regular application pentest?

A standard web application pentest does not cover medical protocols (DICOM, HL7, FHIR), IoMT devices or the specifics of 24/7 operation. We test them with patient-safety-aware methods - we do not generate traffic that could disturb the operation of diagnostic equipment.

What about medical devices that cannot be updated?

We test them non-invasively and verify the real exposure - whether they are isolated in a separate VLAN, what services they expose, whether they have default passwords. Where a vulnerability cannot be patched, we recommend compensating controls: segmentation, NAC access control and anomaly monitoring.

How often should medical systems penetration tests be repeated?

We recommend every 12 months and after significant changes (a new HIS, an integration, a data migration). NIS2 and the amended KSC act require hospitals to run regular security tests - at least once a year.

Want to Reduce IT Risk and Costs?

Book a free consultation - we respond within 24h

Response in 24h Free quote No obligations

Or download free guide:

Download NIS2 Checklist