Patient Portal Penetration Testing
CREST-accredited penetration testing for patient portals, medical records portals, telehealth and remote consultation platforms, and care management systems. We test whether a patient, a linked proxy account or clinical staff can reach another patient’s identity, results, appointments or care record through the portal, its API, a telehealth session or a mobile app. Fixed quote in 24 hours.
- Unlimited retesting
- Unlimited pre-retesting
- No hidden fees
“I would highly recommend EJN Labs to any organisation seeking reliable, detailed, and well-managed penetration testing services, particularly for government or enterprise-level projects.”
“There wasn’t another company we could find that could deliver what we needed in the timeframe we needed. The client loved it, and we got instant ROI from the engagement.”
patient accounts, one with a linked carer or parent proxy login, is the minimum test setup we ask for. Without a linked proxy account, proxy access cannot be tested at all.
Patient Identity and Proxy Access Are the Test That Matters
Patient identity and clinical roles. A patient portal has to know who is asking, not just that someone is logged in. We test clinical role separation between a patient’s own account, a clinician’s account and portal administrators, and any proxy account with delegated access, across the interface, the API, exports and any mobile app, because a single path that skips the patient-ID check is enough to expose another patient’s record.
Proxy, family and care-worker access. Carer, parent and family accounts, and the care-worker logins used in care management and home-care apps, add a second identity behind every patient record. We test whether a proxy link can be created or changed without the patient’s consent, whether it stays scoped to the one patient it was granted for, and record integrity where shared devices and more than one care worker can edit the same historical record.
Confidential results, appointments and consent. Health data is special category data under UK GDPR, and Article 32(1)(d) requires a process for regularly testing the effectiveness of your security measures; it does not name penetration testing as the method, but a test is the most direct evidence that your controls work. We test confidential results and appointment data for patient-to-patient access, and agree safe testing windows around clinical service hours so live care is never disrupted.
Who we test for. Digital health and healthtech vendors building patient-facing portals, NHS suppliers, private healthcare and mental health providers, and care management platforms serving home care and family accounts. Our healthcare penetration testing page covers the wider sector, and our Techpharma case study covers a web application and API test for a health technology software company. If your organisation also runs a separate clinician, admin or partner portal on the same backend, see our customer portal penetration testing page.
SCOPE
What We Test in a Patient Portal
Patient Identity & Proxy Access
Patient-to-patient access (IDOR), proxy accounts for carers and parents, and clinical role separation between patient, clinician and admin accounts, tested across the portal, the API and any mobile app.
Medical Records & Confidential Results
Record integrity, audit-log scrutiny and confidential results such as test outcomes and diagnoses, tested for access that should be scoped to one patient and one clinician.
Appointment & Booking Data
Appointment data, scheduling and booking flows, including whether one patient can view, change or cancel another patient’s appointment, and how booking modules shared with telehealth or care management are scoped.
Telehealth & Clinical Messaging
Consultation identity, session and meeting-link access, secure messaging between patient and clinician, and whether attachments shared during a consultation stay scoped to the right patient.
Care Management & Shared Devices
Care planning and home-care apps, care worker access, family accounts and historical records, including shared devices used by more than one care worker or family member.
BOLA & IDOR Testing
Which patient, appointment, result and message IDs are checked, and which objects, relationships and actions a role can reach by changing one, across the portal and its API.
Mobile App to API Testing
Whether the patient-ID checks, proxy scoping and rate limits that protect the portal in the browser also exist on the API a native mobile app calls, not just inside the app itself.
OUR PROCESS
From Scope to Attestation in 4-6 Weeks
Scoping Call
30-minute call to map patient, clinician, admin and proxy roles across your portal, plus any telehealth or care management modules in scope, and agree safe testing windows around clinical service hours. Fixed-price quote within 24 hours.
Test Accounts
You provide at least two patient accounts, one with a linked carer or parent proxy login, in a staging environment with synthetic or pseudonymised patient data.
Active Testing
3-15 days of hands-on testing by CREST-certified UK-based pen testers, crossing every patient, proxy, clinician and admin boundary. Live findings in your client portal.
Report & Retest
CVSS-scored report with a role and access matrix, walkthrough call, free retest and a letter of attestation for DTAC, DSPT or buyer due diligence.
CREDENTIALS
Verified Accreditations Auditors Accept
Every credential below is independently verifiable. UK procurement teams, FCA supervisors, ISO 27001 / SOC 2 auditors, and cyber insurance underwriters all recognise these standards.
GET YOUR QUOTE
Get a CREST patient portal pen test quote in 24 hours
A fixed-price quote back in one business day, from a named CREST assessor. No sales pipeline, no chasing.
- CREST and IASME accredited. Testing your auditors and clients already recognise.
- Fast-track testing within 24 hours where required. Free retest of every fix included.
- Live findings via your client portal, not a four-week PDF.
- Fixed price from £3,500 for a single-role, single-app scope, agreed up front. Most engagements run £5,000 and up. No day-rate surprises.
Under NDA Further named references available on a scoping call.
- We reply within one business day with a fixed-price quote from a named CREST assessor.
- You approve the scope and we book a start date, usually within 24 hours.
- Live findings land in your client portal as we test, with a free retest of every fix.
Get your fixed pen test quote in 24 hours
Quote request received
We will reply within one business day with your fixed-price quote from a named CREST assessor.
Your data stays with us. No newsletter signup.
or book a 20-min scoping call first
We reply within one business day. Your data stays with us. No newsletter signup.
COMPLIANCE READY
Reports Aligned to Every Framework
Findings map to specific control references in each framework, so your audit team submits the report directly without translation work.
NHS DTAC
Technical security evidence: an independent test, a report from the last 12 months and an action plan for findings.
NHS DSPT
Evidence for Guide 9 (IT protection) of the CAF-aligned toolkit, which keeps an annual test.
UK GDPR
Article 32(1)(d) evidence that you regularly test the effectiveness of your security measures.
ISO 27001
Annex A 8.8 technical vulnerability management, once you declare that control applicable.
OWASP API Top 10
Broken object-level authorisation findings across patient, proxy and clinical APIs mapped by category.
Cyber Essentials Plus
Often asked for by NHS buyers alongside DTAC. Certified directly by us as an IASME certification body.
PRICING
Transparent Patient Portal Penetration Testing Pricing
Pricing depends on the number of roles, proxy accounts and care-system integrations in scope, from a single patient portal to a patient portal tested alongside a telehealth or care management platform. The day count flexes; the included deliverables stay the same across all engagements.
Depends on app complexity
Single user role, basic CRUD application, marketing website with auth. Around 5 working days from kickoff to report.
Get a fixed quoteDepends on app complexity
Multi-role SaaS, business application with payment integration. Around 8 to 12 working days from kickoff to report.
Get a fixed quoteDepends on app complexity
Multi-tenant platform, complex authorisation matrix, integration-heavy applications. Around 15 to 20 working days from kickoff to report.
Get a fixed quoteWHY EJN LABS
What You Get From Patient Portal Penetration Testing
Six concrete differentiators competitors don’t all match.
CREST-Certified Testers, Verifiable
Every test by a CREST-certified pen tester (CRT, CCT APP, CCT INF where applicable). Verify our company status at crest-approved.org.
24-Hour Startup, Where Required
From signed scope to active testing in a single business day for incident response, audit deadlines, or regulator-driven timelines.
Live Findings, Not 4-Week PDFs
Critical issues reported during testing through your client portal. Your team remediates while testing continues.
Audit-Ready Reports
Executive summary plus full technical report with CVSS scores and explicit framework mappings (ISO 27001, SOC 2, PCI DSS, FCA SYSC).
Free Retests, Standard
Verify remediation of every finding before close-out. Letter of attestation for audit submission included. Most competitors charge £1,500-£3,000 per retest.
UK-Based CREST Testers
Every engagement performed by vetted, UK-based CREST-certified testers, matched to your needs, security clearance, and compliance scope.
FAQ
Frequently Asked
What is patient portal penetration testing?
Testing whether a patient, a proxy account or someone with no account at all can reach another patient’s records, results or appointments. We cross every patient, proxy, clinician and admin boundary through the portal, its API, attachments and any linked telehealth or care management module, and report each path that leaks.
How do you test proxy accounts for carers and parents?
We test whether a linked proxy account, such as a parent or carer, can only see the specific patient it is linked to, whether that link can be created or changed without the patient’s consent, and whether a proxy account can be escalated into full patient access or another patient’s record.
Can you test our NHS-supplier patient portal’s proxy access ahead of a DTAC submission?
Yes. We test patient identity, proxy access and record integrity in the portal itself, then map findings to DTAC’s technical security section: an independent test, a report from the last 12 months and an action plan for the findings. See our NHS DTAC penetration testing page.
Do you test telehealth and video consultation features?
Yes, as part of a patient portal engagement or as its own scope. We test consultation identity, session and meeting-link access, whether attachments shared in a consultation stay scoped to the right patient, and clinical messaging between patient and clinician.
We have a native mobile app alongside the web portal, do you test that too?
Yes. We test whether the access controls, patient-ID checks and rate limits that protect the web portal also exist on the API the mobile app calls, not just inside the app itself. A protection built into the app’s interface alone does nothing against a direct API request.
How do you test for one patient being able to see another patient’s results?
This is the core of a patient portal test. We change patient, appointment and result IDs across every role, including proxy accounts, to check whether the portal enforces ownership on the server side rather than just hiding a link in the interface. We also test consent scope, where a patient has limited what a linked proxy or a third party can see.
Can you support our DSPT submission for the portal?
Yes. We test the patient portal itself and can include an appendix mapping findings to the relevant DSPT Guide 9 outcomes for your submission. See our DSPT penetration testing page.
What’s in the report?
Executive summary (board-ready), technical report with CVSS 3.1 scores, reproduction steps, screenshots, specific remediation guidance, and a 60-minute walkthrough call. Letter of attestation issued after free retest.
Do you sign NDAs?
Yes. We sign client-supplied NDAs as standard. Engagement data is protected under our ISO 27001 (BSI-audited) information security management system.
How quickly can you start?
From signed scope to active testing in 24 hours where required. Standard pipeline is 3-5 business days from initial scoping call to test start.
Are your testers UK-based and what certifications do they hold?
Every engagement is performed by vetted UK-based CREST-certified testers matched to your engagement based on security clearance, compliance scope, and sector specialism. Testers hold CREST certifications relevant to their discipline (CRT, CCT APP, CCT INF, CCSAM).
20+ CREST-accredited testing services in one place
Web, mobile, API, cloud, AI, infrastructure, red team. Pick the test that fits your environment.
Get my patient portal pen test scope
Tell us how many roles, proxy accounts and modules you run, whether that’s a patient portal on its own or alongside telehealth or care management. A CREST-certified pen tester will contact you within one business day with a fixed price.



