CASE STUDY · HEALTHTECH · WEB APP · API · CUSTOMER ASSURANCE
How Techpharma Solutions had its GP practice platform independently penetration tested.
Techpharma Solutions builds a software platform that helps GP practices monitor high-risk medicines. Its founder wanted an independent test he could point to, to reassure the practices that rely on the platform. EJN Labs priced the work from his written scope, tested the web application and API, and recommended remediation steps.
- Industry
- HealthTech · software for GP practices
- Market
- UK primary care · practices with NHS contracts
- Service
- Web app + API pen test
- Engagement
- Customer assurance
- Scope
- Web application · API
- Retest
- Requested after remediation
The challenge.
Techpharma Solutions makes a software platform that helps general practices monitor high-risk medicines. Its founder says it helps practices save time, improve safety and improve CQC readiness. The practices it serves hold NHS contracts, and he wanted to give them reassurance on data protection.
The founder says there was no legal requirement for a penetration test. He saw it as good practice for his industry, and wanted to be able to tell practices that the platform had been independently tested.
He also raised the Digital Technology Assessment Criteria (DTAC). He describes it as not mandatory for him today, but very good practice. He says a supplier that wants NHS contracts later has to do it every year.
Why Techpharma Solutions chose EJN Labs.
He sent a specific, technical scope by email. EJN Labs replied with a price and a quote there and then, before any scoping call.
The call confirmed the scope and covered the client portal and retests, so he could picture the process going forward.
A shared Slack channel was there for questions during testing. He says it helps keep things on track.
He says the testing and reporting met his expectations, and that the tester also recommended remediation steps.
What EJN tested.
A web application and API penetration test under an agreed statement of work. The founder framed what he needed around the OWASP Top 10. We publish scope, not exploit detail.
- Web applicationThe platform GP practices use to monitor high-risk medicines.
- APIThe interfaces behind the application.
How the engagement worked.
- ENQUIRYEnquire
The founder sent a specific, technical written scope. EJN Labs replied with a price and a quote.
- ONBOARDINGConfirm
A call confirmed the scope and explained how the client platform and retests work.
- TESTINGTest
The application and API were tested, with a shared Slack channel for questions along the way.
- REPORTReport
A report. The tester also recommended remediation steps.
- JULY 2026Fix and request retest
The founder made his changes, noted them in the portal and requested a retest.
Results and business impact.
- The founder describes the penetration test as generally successful, and says the outcome was the biggest benefit of the project.
- The tester recommended remediation steps, which he found really useful.
- On the penetration testing part of DTAC, he said EJN Labs met what he was looking for. He is clear that a penetration test does not cover all of DTAC.
- He would recommend EJN Labs to others for its friendly people and a streamlined, efficient process.
The fact that you could get back to me with a price and a quote there and then, without additional scoping, definitely helped with the process, just because it made it much smoother.
Check our accreditations yourself.
Do not take our badges on trust. These are the public registers where you can check them.
// READY?
Book a 30-minute scoping call.
Tell us your procurement or audit deadline. We’ll size the engagement the same day.



