In-depth penetration testing for healthtech companies that handle sensitive data, electronic health records and telemedicine.

Offensive security assessments built for healthtech. Full coverage of sensitive health data (LGPD Art. 11, Brazil's data protection law), HL7/FHIR, electronic health records, e-prescriptions signed with ICP-Brasil, telemedicine (CFM Resolution 2,314) and integration with Brazil's TISS standard and public health system (SUS). Reports formatted for audits by health plan operators and ANS, Brazil's health plan regulator — and useful as technical evidence in HIPAA or similar audits.

  • Mutual NDA within 24h
  • Retest included
  • Direct contact with the researcher

Why healthtech

Health data breaches carry bigger fines — and stricter regulation

Brazil's data protection law (LGPD) classifies health data as sensitive personal data (Art. 11). Processing it requires a specific legal basis, a narrow purpose and reinforced technical measures. In Brazil, a breach triggers mandatory notification to the National Data Protection Authority (ANPD) and reputational damage with health plan operators, the medical councils (CRM/CFM) and the market.

On top of that, healthtech has flows that a generic pentest doesn't cover:

  • Electronic health records (EHR) — physician access auditing, cross-patient BOLA, tampering with clinical notes
  • E-prescribing — ICP-Brasil signatures, Memed/Receita Digital validation, prescription replay
  • Telemedicine — CFM Resolution 2,314 requires explicit consent, recording and strict patient identification
  • HL7/FHIR — integration between hospital systems, with its own attack surface
  • TISS / SUS — XML/JSON carrying clinical data between health plan operators, providers and public agencies

Without coverage of these flows, a pentest is security theater — it doesn't reduce real risk.

Scope

What our healthtech penetration testing covers

Regulatory coverage (Brazil)

  • LGPD Art. 11 (Brazil's data protection law) — processing of sensitive data (health, biometrics), for companies serving Brazilian users
  • LGPD Art. 46 — technical protection measures
  • CFM Resolution 2,314/2022 — Federal Council of Medicine rules on telemedicine, identification and consent
  • ANVISA RDC 657/2022 — software as a medical device (SaMD), from Brazil's health regulatory agency
  • CFM Resolutions 1,638/2002 and 1,821/2007 — medical records and electronic health records
  • ICP-Brasil — Brazil's public key infrastructure: digital signature validation on prescriptions

Electronic health records (EHR)

  • Cross-patient BOLA when viewing health records
  • Cross-institution BOLA (physician A sees a patient from clinic B)
  • Tampering with clinical notes (retroactive edits)
  • Access audit trail bypass
  • Leaks via PDF/CSV exports
  • Mass assignment on patient updates
  • Path traversal in test result downloads

HL7 and FHIR

  • FHIR REST — BOLA on resources (Patient, Encounter, Observation, MedicationRequest)
  • FHIR Bundle / transaction — batch abuse, race conditions in transactions
  • SMART on FHIR — scope bypass, redirect URI fuzzing, auth code replay
  • HL7 v2 — manipulation of PID, PV1, OBR and ORC segments
  • MLLP (HL7 transport) — forged message injection
  • Digital signature validation in integrations

E-prescribing

  • ICP-Brasil signature validation (A1 and A3 certificates)
  • Replay of already-dispensed prescriptions
  • Tampering with controlled-substance prescriptions
  • BOLA — physician A accesses physician B's prescriptions
  • Memed / Receita Digital validation bypass
  • Tampering with prescription validity periods

Telemedicine (CFM Resolution 2,314)

  • Identity verification bypass (selfie/document flow)
  • BOLA on consultation rooms (access to someone else's video call)
  • Recording leaks via public URLs
  • Consent form replay
  • Tampering with appointment time/duration for billing
  • Confused deputy between physician, patient and platform

Scheduling and operations

  • BOLA on practitioner calendars
  • Race conditions on slot booking (double booking)
  • Tampering with the consultation fee after booking
  • Health plan coverage / ANS authorization validation bypass
  • Reuse of procedure authorization codes (surgeries, diagnostic tests)

TISS, SUS and integrations

  • TISS — XSD bypass, XML manipulation
  • Replay of approved TISS claim forms
  • Procedure / amount manipulation
  • BOLA on eligibility checks
  • SUS / DATASUS — web service integration, vital signs validation
  • SAML/OAuth with health plan operators (cross-IdP confusion)

Pricing

Healthtech penetration testing pricing

ScenarioPrice rangeCoverage
Early-stage healthtech (scheduling + telemedicine)Sprint (25h): US$ 3,750 to US$ 6,250Web + API + auth + telemedicine
Healthtech in production (EHR + e-prescribing)Deep Dive (50h): US$ 7,500 to US$ 12,500+ HL7/FHIR + ICP-Brasil + integrations
Digital health plan operator / TISS / SUSFull Scope (100h+): from US$ 15,000White box + mobile + cloud + regulatory integrations
Recurring, sprint-alignedPTaaS: on requestContinuous pentesting + monitoring

Every engagement gets a custom quote once the scope is defined. The hourly rate ranges from US$ 150 to US$ 250 depending on stack, testing mode and timeline — larger packages have a lower hourly rate. Invoiced in USD via Wise or international wire transfer: 50% at kickoff, 50% on delivery.

FAQ

Frequently asked questions

  • Why does healthtech need a dedicated penetration test?

    Because health data is classified as sensitive personal data under Brazil's data protection law (LGPD Art. 11), with stricter processing rules and potentially higher fines after a breach. Healthtech also has its own flows — HL7/FHIR for integration, electronic health records, e-prescriptions signed with ICP-Brasil certificates (Brazil's public key infrastructure), telemedicine (CFM Resolution 2,314), TISS/SUS — that a generic pentest doesn't cover.

  • Are you familiar with HL7/FHIR and electronic health records?

    Yes. Coverage includes FHIR R4 (REST + Bundle + transaction), HL7 v2 (PID, PV1, OBR and ORC segments), scope validation bypass in SMART on FHIR, BOLA on FHIR resources (Patient, Encounter, Observation), tampering with ICP-Brasil digital signatures on prescriptions and audit trail bypass in health records.

  • How much does healthtech penetration testing cost?

    Early-stage healthtech (scheduling + telemedicine): Sprint (25h), US$ 3,750 to US$ 6,250. Healthtech in production (EHR + e-prescribing + integrations): Deep Dive (50h), US$ 7,500 to US$ 12,500. Digital health plan operator + TISS integration: Full Scope (100h+), from US$ 15,000. PTaaS (recurring): on request. The hourly rate ranges from US$ 150 to US$ 250 per hour.

  • Can the report be used in health plan audits?

    Yes. Reports are formatted for health plan operator audits, ANS (Brazil's regulator of private health plans), CFM and LGPD Art. 46, with a focus on sensitive data. They're also useful as technical evidence in HIPAA or similar audits. We also include a formal compliance statement after the retest, useful for M&A due diligence in the sector.

Next step

Request a proposal for your healthtech company.

Mutual NDA within 24h. Once it's signed, a technical call to map your EHR, e-prescribing and telemedicine flows. Formal proposal within 3 business days.

Talk to a researcher