Penetration Testing for a Medical Speech Recognition Provider to Improve ePHI Security

Penetration Testing for a Medical Speech Recognition Provider to Improve ePHI Security

Industry
Healthcare, Software products

Summary

INNERLUXES verified the IT infrastructure of a medical speech recognition software provider against vulnerabilities and conducted black-box penetration testing of its solution — used across hundreds of healthcare organizations — to help ensure that electronic protected health information (ePHI) remained uncompromised.

About the Client

The Client is a provider of medical speech recognition software. Its products allow physicians, surgeons, and nurses to create reports by dictating data, optimizing medical professionals' work time, and are used across hundreds of hospitals and diagnostic centers.

The Client wanted to verify the security of its speech recognition application and check its IT infrastructure against potential vulnerabilities, and was looking for a vendor experienced in both security testing and healthcare.

Speech Recognition Application Security Testing

INNERLUXES devised a tailored plan and conducted black-box penetration testing of the Client's speech recognition application. Having limited information about the application, the cybersecurity team imitated a real-life hacking attack to reveal potential security issues. As a result, the Client received a list of vulnerabilities and a thorough mitigation plan to improve the application's security and protect the ePHI created by its clients from theft, inappropriate use, deletion, and more.

IT Infrastructure Security Testing

To check the Client's IT infrastructure against cyber threats, INNERLUXES's cybersecurity experts carried out black-box penetration testing without any information on the Client's current security policies and network protection. As a result, the team provided the Client with tangible steps toward risk elimination.

As employees may be a prominent cybersecurity risk factor, INNERLUXES also imitated a phishing attack against the Client's staff. The campaign helped the Client identify gaps in its employees' cybersecurity awareness — in particular, their ability to recognize and withstand social engineering techniques.

Key Outcomes

  • Created a vulnerability elimination strategy and a security enhancement plan.
  • Increased client trust and satisfaction through proactive security improvement.
  • Improved cybersecurity awareness among the Client's staff.