For the engagement owner. Validate the approved maintenance route end to end, including the handoff between IT, medical engineering and the supplier.
Inventory the real maintenance routes
Hospital remote support may use several gateways, supplier portals and locally managed tools. Start with an owner-confirmed inventory rather than assuming that the corporate VPN represents all external access. Identify the supported service, approving team, supplier organisation, identity source and destination. Record whether a route can reach medical equipment, an application server or infrastructure management. Those destinations have different operating constraints.
Ask medical engineering and clinical application teams to review the inventory alongside IT. A support route that is essential to a device supplier can be poorly represented in an ordinary network assessment brief. Missing ownership should become a scoping issue before testing begins.
Read diagram text
- Supplier identity
- Named person and approved task
- Entry point
- Gateway and access period
- Target boundary
- Agreed system and permitted action
Agree a representative, bounded session
Use a dedicated vendor test identity and a maintenance task that does not alter clinical function. Decide which destination will provide the evidence and which prohibited destination will be used for comparison. A canary host or synthetic application object may be appropriate, but explain what it represents and what remains untested. Do not infer permission to test a connected device from permission to access the gateway.
Confirm the supplier's participation and the hospital's stop authority. If the environment is shared across customers, establish the provider's written boundary before any attempt to explore reach beyond the designated test target.

Inspect what happens after authentication
Successful multifactor authentication is one control. The next question is whether the resulting session has only the approved reach and privileges. Check destination selection, role assignment and the relationship between the support ticket and the permitted access period. Use a small set of agreed comparisons. If a gateway permits an unexpected route, stop at the agreed proof point rather than continuing toward a sensitive target without new authority.
The healthcare supplier access lifecycle guide provides a complementary model for approval, use and revocation. Together, the two views help avoid treating a secure login screen as proof of a secure maintenance path.
Read diagram text
- Approved task
- Allow the intended support activity
- Other destination
- Deny the prohibited route
- Revoked permission
- Apply the agreed session policy
Test the ability to end access
Agree a revocation scenario with the owners: revoke an approval or disable the test identity while a harmless session is established. Observe whether the existing session and any separately issued application access behave according to the documented policy. Record the relevant interval and component. If a session remains active, determine whether the cause is a deliberate product behaviour, a configuration gap or an unresolved policy requirement.
Make sure the test can be reversed without affecting real supplier users. Record cleanup and verify that no temporary access remains. Session termination should not rely on disconnecting an entire clinical service unless that action is separately authorised.
Read diagram text
- Approval
- Ticket, owner and authorised period
- Access
- Gateway session and destination
- Closure
- Termination and account cleanup
Check whether the hospital can explain the session
Ask the responsible teams to correlate the approval, person, gateway session, destination and activity time. Shared accounts or disconnected logs can make that reconstruction difficult. Evidence should be sufficient to attribute the controlled test without collecting unnecessary clinical content. Capture which team owns each record and how long it remains available under the organisation's actual retention rules.
In financial testing, the DORA TLPT third-party coordination guide addresses a related governance problem: the entity and provider must understand their responsibilities and boundaries. A hospital does not inherit that regulatory process, but clear permission and escalation arrangements are equally practical here.
Validate the fix without breaking maintenance
Retest both the prohibited comparison and the legitimate support task. Narrowing a route is incomplete if the supplier then needs an uncontrolled workaround to perform essential maintenance. Record the deployed gateway or policy version, the test identity and the resulting access decisions. Assign an owner and expiry to temporary exceptions, and schedule review when the support arrangement changes.
The final report should separate gateway controls, downstream privileges and operating-process observations. This gives each responsible team a concrete action and prevents a broad recommendation such as “improve vendor security” from remaining unresolved indefinitely.
Read diagram text
- Identify the weak boundary
- Separate gateway and target permissions
- Apply the treatment
- Coordinate supplier and hospital owners
- Retest normal support
- Verify required maintenance still works
Primary sources
General information, not a compliance opinion. Confirm legal applicability and testing requirements for your entity and jurisdiction.
This guide and the related sector publications linked above are published by Atlant Security. Technical examples are planning examples, not claims about completed client tests.

