Network Pentesting of 2,000 IPs for a HIPAA-Compliant Healthcare IT Company
Summary
A leading US healthcare IT company that provides cloud-based EHR and telehealth solutions runs quarterly security testing to guard against HIPAA breaches and cyberattack-driven downtime. INNERLUXES carried out black-box network penetration testing across roughly 2,000 IPs and rated the network's security as medium — no severe vulnerabilities, thanks to the Client's strong vulnerability management — while flagging a few issues to fix and delivering a clear remediation plan, all in 24 days.
About the Client
The Client is one of the leading US healthcare IT companies, providing cloud-based EHR and telehealth solutions to medical professionals across the globe.
Quarterly Network Penetration Testing to Protect HIPAA Compliance
The Client works hard to prevent HIPAA compliance breaches and the service downtime that cyberattacks can cause, and runs quarterly network security testing as a key part of its security management plan. Satisfied with INNERLUXES's earlier security testing, the Client returned to INNERLUXES to perform network penetration testing.
Black-Box Pentesting Across ~2,000 IPs
To simulate real-world attacks, INNERLUXES chose black-box penetration testing, with the assigned engineers having no prior knowledge of the Client's network. The team ran pentests targeting around 2,000 IPs and rated the overall network security as medium: thanks to consistent, efficient vulnerability management, the network had no severe vulnerabilities, but the testers still found a few issues worth fixing for top-level protection — a load balancer disclosing IP information, insecure SSL encryption, and outdated TLS in use. INNERLUXES provided detailed remediation guidance, with corrective measures including:
- Encrypting cookies that disclosed confidential information about the internal infrastructure.
- Disabling the weak hashing algorithms of an SSL certificate.
- Moving to the latest TLS version.
- Disabling unused public ports to reduce the network's attack surface.
The team followed the NIST 800-115 methodology and classified the detected vulnerabilities using the NIST CVSS. The whole engagement — from planning and execution to analysis and reporting — took 24 days.
A Strong Network With Targeted Fixes
The Client received a comprehensive report on the penetration testing activities and their results, including a remediation plan for the issues found. Its security team fixed the vulnerabilities in time and achieved a high level of network security.
Technologies and Tools
Nessus, Burp Suite, Nmap, SSLScan, sqlmap, cURL, dirb, Wireshark, and custom scripts (Python, PHP, JavaScript, and Perl for exploiting vulnerabilities).