Penetration Testing for Health and Care Providers: Meeting UK GDPR Article 32

Penetration Testing for Health and Care Providers: Meeting UK GDPR Article 32

By EJN Labs · 8 Sep 2026 · 7 min read

Penetration testing for health and care providers is one way to satisfy UK GDPR Article 32(1)(d), which requires a process for regularly testing, assessing and evaluating the effectiveness of technical and organisational security measures. The law does not name a specific method. Where personal data includes health records, a CREST-accredited test, typically £4,400 to £8,400 in the UK market, is a widely used route to that evidence.

Why UK GDPR carries extra weight for health and care providers

Health and care records are special category data under Article 9 of the UK GDPR, so a security failure carries higher stakes than for ordinary personal data. In our experience, procurement teams and insurers in this sector scrutinise that protection closely, most often through UK GDPR Article 32.

This applies whatever type of provider you are. A GP practice, a domiciliary care agency, a private clinic and an NHS-adjacent SaaS platform are all controllers or processors under the same law, and none of them gets a smaller version of the duty for not being an NHS trust. What changes is the technology estate to be tested, not whether Article 32 applies.

What Article 32(1)(d) of the UK GDPR actually requires

Article 32(1)(d) requires organisations to run a process for regularly testing, assessing and evaluating how well their security measures work. It sits alongside Article 32(1)(a) to (c), covering encryption, confidentiality and the ability to restore data after an incident, without naming a testing method.

The Information Commissioner’s Office, the UK regulator for data protection, publishes guidance under the security principle, and that guidance names penetration testing and vulnerability scanning among the techniques organisations use to satisfy this duty. Neither is compulsory on its own; what matters is that some form of regular, evidenced testing is happening.

Some health and care organisations that also share data with NHS systems will recognise a related but separate framework, the NHS Data Security and Protection Toolkit. The current toolkit is CAF-aligned and places an annual penetration test under its IT protection standard, but that sits alongside Article 32(1)(d) rather than replacing it. An independent care provider with no NHS data-sharing agreement in place still has the Article 32 duty on its own.

What a penetration test should cover in a health or care setting

A penetration test for a health or care provider typically covers every system storing, processing or transmitting patient or service-user data: patient portals, electronic care records, staff remote access, and cloud infrastructure hosting those systems. Scope follows your estate, not a checklist.

  • Patient or service-user facing systems. Booking portals, referral forms and family or carer access apps are usually the first thing a member of the public reaches, and often the least tested part of the estate.
  • Electronic care and patient record systems. Whatever platform holds the actual clinical or care notes, including how staff authenticate into it and what happens if a session or device is compromised.
  • Staff remote access. VPNs, remote desktop and any route a domiciliary carer, locum or out-of-hours clinician uses to reach systems from outside the building.
  • Cloud configuration. Where care management software or backups sit in a cloud environment, misconfigured storage or access controls are a common source of exposure.

A web application penetration test is the usual starting point for a patient-facing portal, and where the estate includes on-site servers, VPN gateways or a wider network footprint, an external infrastructure penetration test covers the parts a browser-based test never reaches. Many providers commission both together, since the two surfaces are usually reached by the same attacker path.

For the broader question of what penetration testing looks like across the health sector generally, our healthcare penetration testing guide covers that ground; this article stays focused on the Article 32 duty and how it applies specifically to health and social care providers, NHS-adjacent or not. Does UK GDPR require testing at all? Our separate UK GDPR and penetration testing guide answers that question in more detail.

Scheduling a test that will not interrupt clinical or care operations

Care delivery does not stop for a test, so scheduling is the first thing we work through with a health or care client. Rotas, out-of-hours cover and any system a carer or clinician relies on mid-shift all shape which windows are safe to test in, and which need a quieter overnight or weekend slot instead.

We agree in advance which environments can be tested live and which need a staging copy, so testing itself never touches a real patient or service-user record unless the client wants production coverage. A scoping call fixes the systems in play, the day count, and a window that avoids the busiest points in your service’s calendar.

Testers then work to an agreed rules of engagement document naming what is in and out of scope, with a named contact on your side reachable if anything unexpected turns up mid-test. The final report sets out findings, severity and fixes, written to go straight into an Article 32 evidence file.

Typical UK market costs for health and care providers

In the UK market, day rates for CREST-accredited testing typically run £1,100 to £1,400, and the total is driven almost entirely by the scope in front of the testers rather than the sector name on the contract. A single patient portal costs less to test than a multi-site care group running its own infrastructure.

ScopeTypical effortTypical UK cost
Single patient portal or booking system4 to 6 days£4,400 to £8,400
Patient portal plus backend or record-system API6 to 9 days£6,600 to £12,600
Multi-site infrastructure, app and cloud environment8 to 12 days£8,800 to £16,800
Retest after remediation1 to 2 days£1,100 to £2,800

These are typical UK ranges, not a quote for your organisation; our penetration testing cost guide covers how scope, day count and rate combine more generally. A single web application engagement is often the right starting scope for a smaller provider.

How EJN Labs approaches penetration testing for health and care providers

EJN Labs is a UK-based, CREST-accredited penetration testing firm, also certified to ISO 27001 and ISO 9001. All testing is carried out by UK-based testers, working from an agreed scope built around your actual patient and service-user systems rather than a generic template.

Because we work with providers across the health and social care spectrum, from single-site clinics to multi-location care groups, scoping around live service delivery is standard practice, not a special request. Reports are written to stand as Article 32 evidence on their own, with findings a non-technical DPO or registered manager can act on directly. If you are weighing up providers, our guide to choosing a UK penetration testing provider sets out the questions worth putting to any firm, including us.

Frequently Asked Questions

Does UK GDPR require penetration testing for health and care providers?

UK GDPR does not name penetration testing as a requirement. Article 32(1)(d) requires a process for regularly testing, assessing and evaluating the effectiveness of security measures, and the Information Commissioner’s Office lists penetration testing and vulnerability scanning among the accepted ways to do that.

What does Article 32(1)(d) of the UK GDPR require?

Article 32(1)(d) of the UK GDPR requires a process for regularly testing, assessing and evaluating the effectiveness of technical and organisational security measures. It sits alongside Article 32(1)(a) to (c) on encryption, confidentiality and restoring data after an incident, without prescribing a method.

What should a penetration test cover for a health or care provider?

A penetration test for a health or care provider should cover any system storing or transmitting patient or service-user data: patient portals, electronic care records, staff remote access, and cloud infrastructure hosting clinical systems. Scope depends on your stack, so a scoping call confirms coverage.

What does penetration testing typically cost for a health or care provider?

UK penetration testing typically costs £4,400 to £8,400 for a single web application or care management platform, based on 4 to 6 days at £1,100 to £1,400 per day. Additional infrastructure, multiple sites or cloud environments raise the day count. Get a quote for an exact price.

Does the NHS Data Security and Protection Toolkit affect my UK GDPR Article 32 obligations?

The Data Security and Protection Toolkit is separate from Article 32, though many care organisations sharing data with NHS systems complete both. The toolkit is CAF-aligned and puts an annual penetration test under its IT protection standard; Article 32 applies to every UK GDPR controller regardless of NHS involvement.

Get an Article 32 evidence pack scoped for your organisation

If you need a report you can point to as evidence of regularly testing your security measures, we can scope a fixed-price engagement around your patient or service-user systems. Get a CREST pentesting quote and we will come back with a scope and price built around your organisation, not a generic package.

How testing fits the NHS Data Security and Protection Toolkit for organisations that also handle NHS data, our piece on Caldicott principles and care provider testing expectations, and how the same Article 32 duty plays out for defence subcontractors facing prime-contractor security checks.

Leave a Reply

Your email address will not be published. Required fields are marked *