For the engagement owner. The rules need to be usable during a live operational decision: who may test, what may change, who can stop the work and how normal service is confirmed.
Put clinical decisions in the control channel
Name a security lead, clinical operations representative and relevant technical owners. Decide who can pause activity without waiting for a weekly meeting. The escalation path must remain usable if the identity or communication service under test is unavailable.
Read diagram text
- Before activity
- Owner confirms the permitted window
- During activity
- Observe agreed service indicators
- Unexpected effect
- Pause and reach the stop authority
Replace broad permission with a working boundary
List approved source hosts, destinations, test accounts and time windows. Record medical devices, treatment workflows and shared vendor systems excluded from active testing. A general hospital authorisation letter does not resolve each supplier’s contractual boundary or every device’s tolerance for active requests.

Define observable stop conditions
Agree thresholds for service degradation, unexpected data access, clinical alerts and uncertainty about scope. Testers should stop at the boundary, retain minimal evidence and request a decision through the control channel. Document the decision before restarting rather than treating silence as approval.
Read diagram text
- Clinical device
- Only separately authorised methods
- Synthetic message
- Confirm no clinical action is triggered
- Unexpected latency
- Apply the agreed pause condition
Plan cleanup and handover
Reconcile canary accounts, files, rules and sessions at the end of each agreed phase. A hospital’s operations team needs an accurate list of what was introduced and what remains. Include a handover route for genuine incidents discovered during testing, separate from the simulated scenario.
Read diagram text
- Permission
- System, method and accountable owner
- Change
- Approved adjustment and rationale
- Cleanup
- Introduced objects and final status
Rehearse one difficult decision before the test
Walk through a concrete situation with the hospital team: a permitted application check produces unexpected latency while a clinical service is busy. Who receives the call, who can stop the activity and who decides whether it can resume? Record the primary and alternate contacts, the communication channel and the acknowledgement expected from the testers. A generic emergency number is insufficient if nobody on the call can identify the test or reach the relevant service owner.
The rehearsal should include a real incident occurring during the same window. Test activity must not cause defenders to dismiss an unrelated alert as part of the assessment. Agree how the restricted coordination team will distinguish and escalate those situations without broadcasting sensitive exercise details unnecessarily.
Write restrictions as operational instructions
Replace “avoid disruption” with instructions a tester can apply. Identify prohibited devices and methods, approved accounts, request limits, maintenance windows, notification side effects and permitted evidence. State whether a database write, a message submission or an account lockout test requires a separate decision. These conditions should follow the service's dependencies, not simply its network address range. Prepare a safe alternative where a control can be evaluated through configuration review or a canary destination.
For supplier entry points, the healthcare supplier session lifecycle guide helps define approval, permitted reach and revocation as separate checks. Each may need a different operational owner present.
Make resumption and cleanup explicit
A paused activity should resume only after the agreed owner confirms the condition is understood and the required safeguards are in place. Preserve the reason for the pause and any resulting scope change in the evidence record. At the end of each window, reconcile temporary accounts, sessions, uploaded files and synthetic objects against an agreed inventory. Ask the service owner to confirm the relevant normal workflow still functions.
Financial institutions use different governance for advanced threat-led tests, but the practical escalation discipline in the DORA TLPT control-team guide is useful when designing restricted coordination. Applying that lesson does not make a hospital pentest a DORA TLPT or create an equivalent regulatory process.
Read diagram text
- Reach the right people
- Name primary and alternate contacts
- Confirm the stop path
- Require an acknowledged pause
- Control resumption
- Obtain the agreed operational decision
Put the guidance to work
Use the readiness checklist to document assumptions, or inspect the fictional Hospital AG report for evidence and treatment-plan examples. Contact Atlant Security with a non-sensitive description of your scope.
Primary sources
General information, not a compliance opinion. Confirm legal applicability and testing requirements for your entity and jurisdiction.
This guide and the related sector publications linked above are published by Atlant Security. Technical examples are planning examples, not claims about completed client tests.

