Who we serve

For health platforms holding the most sensitive data there is.

Patient portals, booking systems and virtual-care apps carry health information on behalf of people who will never read a security policy. We test the parts that touch patient data first, and help you document a risk analysis you can stand behind.

What we usually find

Where patient data leaks.

01 Mobile APIs that trust the app Back ends that assume only the official app will ever call them, so any filtering happens on the phone.
02 Booking and intake plugins Third-party scheduling components that expose appointment books or intake forms to anyone who guesses a URL.
03 Documents and file storage Uploaded records in cloud storage with predictable names or long-lived public links.
04 Shared clinic accounts Front-desk logins shared across staff, without MFA, with access to every patient record.
Frameworks this sector answers to

The HIPAA Security Rule for US clients, Canadian provincial health-privacy law, and the OWASP API Security Top 10.

Representative engagement. Client names, figures and identifying details are changed or combined; no client findings are published in identifiable form.

Want to know what your patient portal is exposing?

Tell us what you ship and who is asking for proof. We will come back with a scope and a range.