In-depth penetration testing for healthtech companies that handle sensitive data, electronic health records and telemedicine.
Offensive security assessments built for healthtech. Full coverage of sensitive health data (LGPD Art. 11, Brazil's data protection law), HL7/FHIR, electronic health records, e-prescriptions signed with ICP-Brasil, telemedicine (CFM Resolution 2,314) and integration with Brazil's TISS standard and public health system (SUS). Reports formatted for audits by health plan operators and ANS, Brazil's health plan regulator — and useful as technical evidence in HIPAA or similar audits.
- Mutual NDA within 24h
- Retest included
- Direct contact with the researcher
Why healthtech
Health data breaches carry bigger fines — and stricter regulation
Brazil's data protection law (LGPD) classifies health data as sensitive personal data (Art. 11). Processing it requires a specific legal basis, a narrow purpose and reinforced technical measures. In Brazil, a breach triggers mandatory notification to the National Data Protection Authority (ANPD) and reputational damage with health plan operators, the medical councils (CRM/CFM) and the market.
On top of that, healthtech has flows that a generic pentest doesn't cover:
- Electronic health records (EHR) — physician access auditing, cross-patient BOLA, tampering with clinical notes
- E-prescribing — ICP-Brasil signatures, Memed/Receita Digital validation, prescription replay
- Telemedicine — CFM Resolution 2,314 requires explicit consent, recording and strict patient identification
- HL7/FHIR — integration between hospital systems, with its own attack surface
- TISS / SUS — XML/JSON carrying clinical data between health plan operators, providers and public agencies
Without coverage of these flows, a pentest is security theater — it doesn't reduce real risk.
Scope
What our healthtech penetration testing covers
Regulatory coverage (Brazil)
- LGPD Art. 11 (Brazil's data protection law) — processing of sensitive data (health, biometrics), for companies serving Brazilian users
- LGPD Art. 46 — technical protection measures
- CFM Resolution 2,314/2022 — Federal Council of Medicine rules on telemedicine, identification and consent
- ANVISA RDC 657/2022 — software as a medical device (SaMD), from Brazil's health regulatory agency
- CFM Resolutions 1,638/2002 and 1,821/2007 — medical records and electronic health records
- ICP-Brasil — Brazil's public key infrastructure: digital signature validation on prescriptions
Electronic health records (EHR)
- Cross-patient BOLA when viewing health records
- Cross-institution BOLA (physician A sees a patient from clinic B)
- Tampering with clinical notes (retroactive edits)
- Access audit trail bypass
- Leaks via PDF/CSV exports
- Mass assignment on patient updates
- Path traversal in test result downloads
HL7 and FHIR
- FHIR REST — BOLA on resources (Patient, Encounter, Observation, MedicationRequest)
- FHIR Bundle / transaction — batch abuse, race conditions in transactions
- SMART on FHIR — scope bypass, redirect URI fuzzing, auth code replay
- HL7 v2 — manipulation of PID, PV1, OBR and ORC segments
- MLLP (HL7 transport) — forged message injection
- Digital signature validation in integrations
E-prescribing
- ICP-Brasil signature validation (A1 and A3 certificates)
- Replay of already-dispensed prescriptions
- Tampering with controlled-substance prescriptions
- BOLA — physician A accesses physician B's prescriptions
- Memed / Receita Digital validation bypass
- Tampering with prescription validity periods
Telemedicine (CFM Resolution 2,314)
- Identity verification bypass (selfie/document flow)
- BOLA on consultation rooms (access to someone else's video call)
- Recording leaks via public URLs
- Consent form replay
- Tampering with appointment time/duration for billing
- Confused deputy between physician, patient and platform
Scheduling and operations
- BOLA on practitioner calendars
- Race conditions on slot booking (double booking)
- Tampering with the consultation fee after booking
- Health plan coverage / ANS authorization validation bypass
- Reuse of procedure authorization codes (surgeries, diagnostic tests)
TISS, SUS and integrations
- TISS — XSD bypass, XML manipulation
- Replay of approved TISS claim forms
- Procedure / amount manipulation
- BOLA on eligibility checks
- SUS / DATASUS — web service integration, vital signs validation
- SAML/OAuth with health plan operators (cross-IdP confusion)
Pricing
Healthtech penetration testing pricing
| Scenario | Price range | Coverage |
|---|---|---|
| Early-stage healthtech (scheduling + telemedicine) | Sprint (25h): US$ 3,750 to US$ 6,250 | Web + API + auth + telemedicine |
| Healthtech in production (EHR + e-prescribing) | Deep Dive (50h): US$ 7,500 to US$ 12,500 | + HL7/FHIR + ICP-Brasil + integrations |
| Digital health plan operator / TISS / SUS | Full Scope (100h+): from US$ 15,000 | White box + mobile + cloud + regulatory integrations |
| Recurring, sprint-aligned | PTaaS: on request | Continuous pentesting + monitoring |
Every engagement gets a custom quote once the scope is defined. The hourly rate ranges from US$ 150 to US$ 250 depending on stack, testing mode and timeline — larger packages have a lower hourly rate. Invoiced in USD via Wise or international wire transfer: 50% at kickoff, 50% on delivery.
FAQ
Frequently asked questions
Why does healthtech need a dedicated penetration test?
Because health data is classified as sensitive personal data under Brazil's data protection law (LGPD Art. 11), with stricter processing rules and potentially higher fines after a breach. Healthtech also has its own flows — HL7/FHIR for integration, electronic health records, e-prescriptions signed with ICP-Brasil certificates (Brazil's public key infrastructure), telemedicine (CFM Resolution 2,314), TISS/SUS — that a generic pentest doesn't cover.
Are you familiar with HL7/FHIR and electronic health records?
Yes. Coverage includes FHIR R4 (REST + Bundle + transaction), HL7 v2 (PID, PV1, OBR and ORC segments), scope validation bypass in SMART on FHIR, BOLA on FHIR resources (Patient, Encounter, Observation), tampering with ICP-Brasil digital signatures on prescriptions and audit trail bypass in health records.
How much does healthtech penetration testing cost?
Early-stage healthtech (scheduling + telemedicine): Sprint (25h), US$ 3,750 to US$ 6,250. Healthtech in production (EHR + e-prescribing + integrations): Deep Dive (50h), US$ 7,500 to US$ 12,500. Digital health plan operator + TISS integration: Full Scope (100h+), from US$ 15,000. PTaaS (recurring): on request. The hourly rate ranges from US$ 150 to US$ 250 per hour.
Can the report be used in health plan audits?
Yes. Reports are formatted for health plan operator audits, ANS (Brazil's regulator of private health plans), CFM and LGPD Art. 46, with a focus on sensitive data. They're also useful as technical evidence in HIPAA or similar audits. We also include a formal compliance statement after the retest, useful for M&A due diligence in the sector.
Next step
Request a proposal for your healthtech company.
Mutual NDA within 24h. Once it's signed, a technical call to map your EHR, e-prescribing and telemedicine flows. Formal proposal within 3 business days.
Talk to a researcher