Healthtech

Pentesting for healthtech web applications and APIs.

The pentest covers how patients, practitioners, support teams and customer organisations interact across the product, with evidence your engineers can reproduce and fix.

Starting point
Web & API pentest
Focused on the product’s actual permissions.
Typical engagement
8–12 consultant days
A fixed fee is provided after scoping.
Who does the work
The named tester
No hand-off after the scoping call.

Assessment focus

Follow the data through roles, workflows and integrations.

A healthtech product may give patients, practitioners, support staff, administrators and customer organisations different views of the same underlying records.

Each role is mapped to the actions it can perform. The transitions between them are then tested, both as direct requests to web and API endpoints and as complete workflows: invitations, account recovery, exports, file access, and changes in care or organisation membership.

Roles and tenant boundaries

Patient, practitioner, support and administrative access are compared. The target is any path that reads or changes records across accounts and customer organisations.

Clinical and operational workflows

Invitations, referrals, consent changes, exports and account lifecycle actions are exercised to find unsafe state transitions and missing checks.

APIs and integrations

The pentest covers authentication, object-level authorisation and exposed data. It also covers the trust assumptions around mobile clients, identity providers and connected services.

Sensitive files and records

Reports, attachments and structured records are traced through storage, retrieval and sharing, including predictable references and long-lived links.

A perspective from three healthtech engagements.

“I've worked with Perspican to identify the security gaps in three different applications storing medical data. Giuseppe was able to identify hard to exploit security issues that went undiscovered in the previous 3 pentests performed by 2 different providers.

He understands deeply secure software engineering best practices, and I was really impressed by his ability to identify the issue in the codebase and precisely suggest the solutions to the problem.

I'd recommend his services to any business that handles sensitive data”

Sample deliverable

A report your engineering team can work from.

Each finding names the affected role and data, reproduces the behaviour and states the product impact. Perspican walks the team through the report and records the outcome of agreed retests.

Reproducible evidence

Affected endpoint or workflow, required account state, numbered reproduction steps and relevant request and response excerpts.

Product impact

The records or actions exposed, the roles and tenants involved, realistic abuse conditions and a severity rationale tied to the observed behaviour.

Remediation and retest

A practical correction path, related patterns worth checking elsewhere in the product and a clear retest status after the fix is available.

Other services

Already have findings, or need what comes after.

When a verified fix requires production code, remediation engineering is available as a scoped add-on.

Show me what needs testing.

A useful first note includes the product, user roles, main integrations and desired test date.