Basilisk
BASILISK
[setor_saude]HEALTHCARE & HEALTHTECH

Offensive security for healthcare and healthtech.

Records, results and clinical history form one of the most sensitive data sets that exists — and one of the most targeted. We test hospitals, payers, laboratories and healthtech with that weight in mind.

Why healthcare became a priority target

Health data does not expire. Unlike a card number, cancelled within minutes, a leaked clinical history stays exploitable for decades — for extortion, insurance fraud or discrimination. Add the sector's intolerance for downtime: halting a hospital system has immediate clinical consequences, which makes the environment attractive for extortion.

  • Clinical data is permanent and cannot be reissued after a breach.
  • Pressure for continuous availability shrinks the window for patching and updates.
  • Connected medical equipment often runs legacy systems without vendor support.
  • Integrations between payers, laboratories and providers create implicit trust across separate networks.

What we test in a healthcare environment

We map where clinical data is created, how it travels and who can reach it — including paths nobody designed on purpose.

// electronic records

Role-based access control, segregation between units and object-level authorisation: if a user can read a record that is not theirs, it surfaces here.

// patient portal

Registration, password recovery, scheduling and access to results — the points where account takeover usually happens.

// telehealth

Consultation rooms, recordings, digital prescriptions and signatures: we check whether a third party can join, retrieve content or forge a document.

// integrations and APIs

Data exchange with payers, laboratories and public systems, including clinical interoperability interfaces and service-to-service authentication.

// network and devices

Segmentation between administrative networks, clinical networks and connected equipment, and what an initial foothold reaches from each.

// third parties

Partner clinics, billing companies and vendors with remote access — a recurring entry path in incidents across this sector.

Evidence aligned with sector obligations

The report is written to serve the data protection officer, compliance and audit, without requiring further technical translation.

GDPR — special category data
Health data is a special category with restricted lawful bases. We document which data subjects and which bases would be affected in each exploited scenario.
HIPAA where applicable
For organisations handling US protected health information, we map findings to the safeguards that an assessment will examine.
NIS2 and essential entities
Healthcare providers fall within scope as essential entities, with obligations on risk management and incident handling. The report evidences periodic testing.
Breach notification
Where there is material risk to individuals, notification duties apply. Our evidence helps size the real exposure, which changes the decision to notify.

How we run in a clinical environment

01

Scope without clinical risk

We separate clinical from administrative environments. Nothing that could affect patient care undergoes active testing without a replica and written authorisation.

02

Minimum necessary data

We demonstrate impact with the smallest possible volume of real data, and mask patient identifiers in evidence whenever they are not essential to the proof.

03

Exploitation and chaining

We look for the full path: from initial access to the clinical record. An isolated flaw says little; the chain that reaches the record says everything.

04

Remediation and retest

We prioritise by data subject exposure, follow the remediation and retest. The final report documents the closed cycle.

What you receive

  • Executive report on risk to data subjects
  • Reproducible technical report
  • Sensitive data exposure map
  • Justified CVSS scoring
  • Evidence with masked identifiers
  • Priority by clinical impact
  • Retest of remediated findings
  • Attestation letter for audit

Sector FAQ

Can testing take down a system used in patient care?

+

No, and this is settled before we start. Clinical environments only undergo active testing with a replica available or under specific written authorisation. For everything else we work within an agreed window, with volume limits and an open channel throughout, so any activity can be stopped within seconds.

Will you access real patient records during testing?

+

Only when it is the sole way to prove impact, and always at minimum volume. We prefer to demonstrate with test records. Where real data is unavoidable, evidence is issued with masked identifiers and the material is destroyed at the end of the cycle upon formal confirmation.

Is connected medical equipment in scope?

+

It is, with distinct handling. Much of it runs unsupported legacy software where active testing is risky. In those cases we assess exposure, segmentation and what an attacker would reach from the device, without interacting aggressively with it.

Does the report help respond to a supervisory authority?

+

It helps size the exposure. The document describes which data categories were reachable, by which route and with how much effort. That supports the risk assessment for individuals, which is the central criterion when notification duties apply.

Services applied to this sector

// contact

Ready to uncover your flaws?

First scoping call is free and covered by NDA. Within 48 hours you receive technical proposal, scope and timeline. No bureaucratic forms.