Roles and tenant boundaries
Patient, practitioner, support and administrative access are compared. The target is any path that reads or changes records across accounts and customer organisations.
Healthtech
The pentest covers how patients, practitioners, support teams and customer organisations interact across the product, with evidence your engineers can reproduce and fix.
Assessment focus
A healthtech product may give patients, practitioners, support staff, administrators and customer organisations different views of the same underlying records.
Each role is mapped to the actions it can perform. The transitions between them are then tested, both as direct requests to web and API endpoints and as complete workflows: invitations, account recovery, exports, file access, and changes in care or organisation membership.
Patient, practitioner, support and administrative access are compared. The target is any path that reads or changes records across accounts and customer organisations.
Invitations, referrals, consent changes, exports and account lifecycle actions are exercised to find unsafe state transitions and missing checks.
The pentest covers authentication, object-level authorisation and exposed data. It also covers the trust assumptions around mobile clients, identity providers and connected services.
Reports, attachments and structured records are traced through storage, retrieval and sharing, including predictable references and long-lived links.
“I've worked with Perspican to identify the security gaps in three different applications storing medical data. Giuseppe was able to identify hard to exploit security issues that went undiscovered in the previous 3 pentests performed by 2 different providers.
He understands deeply secure software engineering best practices, and I was really impressed by his ability to identify the issue in the codebase and precisely suggest the solutions to the problem.
I'd recommend his services to any business that handles sensitive data”
Sample deliverable
Each finding names the affected role and data, reproduces the behaviour and states the product impact. Perspican walks the team through the report and records the outcome of agreed retests.
Affected endpoint or workflow, required account state, numbered reproduction steps and relevant request and response excerpts.
The records or actions exposed, the roles and tenants involved, realistic abuse conditions and a severity rationale tied to the observed behaviour.
A practical correction path, related patterns worth checking elsewhere in the product and a clear retest status after the fix is available.
Other services
Validate scanner, AI and previous assessment findings against the real code, then make the fix practical.
Review a sensitive change, work through a remediation or verify a fix without repeating a full pentest.
When a verified fix requires production code, remediation engineering is available as a scoped add-on.
A useful first note includes the product, user roles, main integrations and desired test date.
Prefer to write directly? [email protected]