Clinical continuity. Technical evidence.Atlant Security
Hospital/PentestBY ATLANT SECURITY

Delivery

Testing remote vendor access to hospital systems

Assess hospital remote maintenance access across identity, gateways, destination permissions and session termination without disrupting care.

Discuss your requirements
Illustrative hospital architecture and operating environment

For the engagement owner. Validate the approved maintenance route end to end, including the handoff between IT, medical engineering and the supplier.

Inventory the real maintenance routes

Hospital remote support may use several gateways, supplier portals and locally managed tools. Start with an owner-confirmed inventory rather than assuming that the corporate VPN represents all external access. Identify the supported service, approving team, supplier organisation, identity source and destination. Record whether a route can reach medical equipment, an application server or infrastructure management. Those destinations have different operating constraints.

Ask medical engineering and clinical application teams to review the inventory alongside IT. A support route that is essential to a device supplier can be poorly represented in an ordinary network assessment brief. Missing ownership should become a scoping issue before testing begins.

A hospital maintenance access path. Supplier identity: Named person and approved task; Entry point: Gateway and access period; Target boundary: Agreed system and permitted action
Working model 01A hospital maintenance access pathIllustrative planning diagram. Adapt the decisions to your authorised scope.
Read diagram text
Supplier identity
Named person and approved task
Entry point
Gateway and access period
Target boundary
Agreed system and permitted action

Agree a representative, bounded session

Use a dedicated vendor test identity and a maintenance task that does not alter clinical function. Decide which destination will provide the evidence and which prohibited destination will be used for comparison. A canary host or synthetic application object may be appropriate, but explain what it represents and what remains untested. Do not infer permission to test a connected device from permission to access the gateway.

Confirm the supplier's participation and the hospital's stop authority. If the environment is shared across customers, establish the provider's written boundary before any attempt to explore reach beyond the designated test target.

An illustrative hospital operations room beside a clinical corridor
Operational perspectiveTesting starts with the operating context behind the technology.Generated illustrative setting; not a client location.

Inspect what happens after authentication

Successful multifactor authentication is one control. The next question is whether the resulting session has only the approved reach and privileges. Check destination selection, role assignment and the relationship between the support ticket and the permitted access period. Use a small set of agreed comparisons. If a gateway permits an unexpected route, stop at the agreed proof point rather than continuing toward a sensitive target without new authority.

The healthcare supplier access lifecycle guide provides a complementary model for approval, use and revocation. Together, the two views help avoid treating a secure login screen as proof of a secure maintenance path.

Maintenance access comparisons. Approved task: Allow the intended support activity; Other destination: Deny the prohibited route; Revoked permission: Apply the agreed session policy
Working model 02Maintenance access comparisonsIllustrative planning diagram. Adapt the decisions to your authorised scope.
Read diagram text
Approved task
Allow the intended support activity
Other destination
Deny the prohibited route
Revoked permission
Apply the agreed session policy

Test the ability to end access

Agree a revocation scenario with the owners: revoke an approval or disable the test identity while a harmless session is established. Observe whether the existing session and any separately issued application access behave according to the documented policy. Record the relevant interval and component. If a session remains active, determine whether the cause is a deliberate product behaviour, a configuration gap or an unresolved policy requirement.

Make sure the test can be reversed without affecting real supplier users. Record cleanup and verify that no temporary access remains. Session termination should not rely on disconnecting an entire clinical service unless that action is separately authorised.

Reconstruct the test session. Approval: Ticket, owner and authorised period; Access: Gateway session and destination; Closure: Termination and account cleanup
Working model 03Reconstruct the test sessionIllustrative planning diagram. Adapt the decisions to your authorised scope.
Read diagram text
Approval
Ticket, owner and authorised period
Access
Gateway session and destination
Closure
Termination and account cleanup

Check whether the hospital can explain the session

Ask the responsible teams to correlate the approval, person, gateway session, destination and activity time. Shared accounts or disconnected logs can make that reconstruction difficult. Evidence should be sufficient to attribute the controlled test without collecting unnecessary clinical content. Capture which team owns each record and how long it remains available under the organisation's actual retention rules.

In financial testing, the DORA TLPT third-party coordination guide addresses a related governance problem: the entity and provider must understand their responsibilities and boundaries. A hospital does not inherit that regulatory process, but clear permission and escalation arrangements are equally practical here.

Validate the fix without breaking maintenance

Retest both the prohibited comparison and the legitimate support task. Narrowing a route is incomplete if the supplier then needs an uncontrolled workaround to perform essential maintenance. Record the deployed gateway or policy version, the test identity and the resulting access decisions. Assign an owner and expiry to temporary exceptions, and schedule review when the support arrangement changes.

The final report should separate gateway controls, downstream privileges and operating-process observations. This gives each responsible team a concrete action and prevents a broad recommendation such as “improve vendor security” from remaining unresolved indefinitely.

Improve the route without a workaround. Identify the weak boundary: Separate gateway and target permissions; Apply the treatment: Coordinate supplier and hospital owners; Retest normal support: Verify required maintenance still works
Working model 04Improve the route without a workaroundIllustrative planning diagram. Adapt the decisions to your authorised scope.
Read diagram text
Identify the weak boundary
Separate gateway and target permissions
Apply the treatment
Coordinate supplier and hospital owners
Retest normal support
Verify required maintenance still works

Primary sources

General information, not a compliance opinion. Confirm legal applicability and testing requirements for your entity and jurisdiction.

This guide and the related sector publications linked above are published by Atlant Security. Technical examples are planning examples, not claims about completed client tests.

LET’S START A CONVERSATION

Define the scope.
Take the next step.

Your systems, operating constraints and security objectives. A clear starting point for the test.

Discuss your pentest