For health platforms holding the most sensitive data there is.
Patient portals, booking systems and virtual-care apps carry health information on behalf of people who will never read a security policy. We test the parts that touch patient data first, and help you document a risk analysis you can stand behind.
Where patient data leaks.
01
Mobile APIs that trust the app
Back ends that assume only the official app will ever call them, so any filtering happens on the phone.
02
Booking and intake plugins
Third-party scheduling components that expose appointment books or intake forms to anyone who guesses a URL.
03
Documents and file storage
Uploaded records in cloud storage with predictable names or long-lived public links.
04
Shared clinic accounts
Front-desk logins shared across staff, without MFA, with access to every patient record.
The HIPAA Security Rule for US clients, Canadian provincial health-privacy law, and the OWASP API Security Top 10.
Representative engagement. Client names, figures and identifying details are changed or combined; no client findings are published in identifiable form.
Want to know what your patient portal is exposing?
Tell us what you ship and who is asking for proof. We will come back with a scope and a range.
Let’s Connect
or email hello@penspycyber.com