Healthcare penetration testing is usually sold with two words attached: HIPAA in the United States, NIS2 in Europe. Both frameworks matter, but neither tells you what to test. This article sets out what a penetration test of a hospital or clinic estate should cover, what it must leave alone, what the HIPAA Security Rule actually requires under its evaluation standard, how that compares with NIS2 Article 21(2)(f) for European healthcare providers, and the French hosting context (HDS) that shapes where the test and its data may run.
Not legal advice
This is a security engineer's reading of the texts cited, not legal advice. Whether your organisation is a HIPAA covered entity or business associate, or an essential or important entity under NIS2, depends on your activity, size and national identification. Confirm with counsel and your competent authority. Darkmoon does not certify compliance.
Why hospitals are tested differently
A hospital is an information system that cannot stop. The ANS observatory counted 749 security incidents declared by French health and medico-social structures in 2024, of which 230 forced a degraded mode or an interruption of care (observatoire 2024). In April 2024 the Hôpital Simone Veil in Cannes was hit by ransomware that the LockBit group claimed, according to press reports. The consequence for testing is a scope that must be precise about what is in, what is reachable but observed only, and what is out.
What a healthcare estate test covers
- Internet-exposed services. Patient and staff portals, appointment booking, results delivery, telehealth gateways, recruitment sites, the public website and its CMS, mail gateways. These are tested as any web application and API would be: authentication, authorisation between patients, injection, upload handling, exposed administration paths.
- Remote access. VPN concentrators, remote-desktop gateways and the remote-maintenance channels used by biomedical and IT vendors. Edge devices remain a heavily targeted vector, and a vendor maintenance tunnel is often the least supervised door.
- Active Directory and identity. The domain that clinicians, administrative staff and service accounts share. A test should show how far a single compromised workstation gets toward domain administration, and whether shared ward accounts or badge-based logins widen that path.
- The hospital information system. The electronic patient record (DPI in France), laboratory and pharmacy systems, scheduling, billing. Tested for authentication, authorisation and exposed interfaces, with test data only.
- Imaging and integration reachability. PACS servers, DICOM listeners and HL7 interfaces are enumerated and checked for unauthenticated reachability, default credentials and network segmentation. The question is "who can reach this from where", not "can we break the modality".
- Legacy imaging workstations and servers. Unsupported operating systems attached to equipment that outlives its software. The test documents their exposure and the compensating controls around them rather than exploiting them.
- Cloud and shared providers. Tenants in Microsoft 365 or a cloud platform, and the interfaces of shared service providers (GHT structures in France, group IT in private chains).
What is excluded, and why
Medical devices in clinical use are out of scope for active testing: infusion pumps, monitors, ventilators, imaging modalities and anything connected to a patient. The risk of disrupting care outweighs any finding. What a test does on the IT side is map the network reachability of those devices, test the systems around them (the VLANs, the jump hosts, the vendor tunnels, the PACS) and report where segmentation fails. Darkmoon tests the IT side and what is reachable over the network; it does not certify medical-device firmware and it makes no claim about device safety.
| Component | Active testing | Reachability and configuration only | Excluded |
|---|---|---|---|
| Patient and staff portals, public web, APIs | Yes | ||
| VPN, remote desktop, vendor maintenance tunnels | Yes | ||
| Active Directory, Entra ID, shared accounts | Yes | ||
| HIS, DPI, lab and pharmacy systems | Yes, with test data and agreed windows | ||
| PACS servers, DICOM listeners, HL7 interfaces | Yes: enumeration, default credentials, segmentation | ||
| Legacy imaging workstations | Yes: exposure and compensating controls | ||
| Medical devices in clinical use | Network reachability map only | Yes |
HIPAA: the evaluation standard, not a pentest mandate
In the United States, the HIPAA Security Rule requires covered entities and business associates to perform a periodic technical and nontechnical evaluation (45 CFR 164.308(a)(8)), based initially on the standards implemented under the rule and subsequently in response to environmental or operational changes affecting the security of electronic protected health information, that establishes the extent to which the entity's security policies and procedures meet the requirements of the rule. The text does not name a penetration test. A test with reproducible evidence is one of the most direct ways to perform the technical part of that evaluation, and to repeat it after an operational change such as a new portal or a migration. The scope above maps to the systems that create, receive, maintain or transmit ePHI.
NIS2: healthcare providers are an Annex I sector
In the European Union, Directive (EU) 2022/2555 lists in Annex I, sector 5 "Health", "Healthcare providers as defined in Article 3, point (g), of Directive 2011/24/EU", together with EU reference laboratories, entities carrying out research and development of medicinal products, manufacturers of basic pharmaceutical products and preparations, and manufacturers of medical devices considered critical during a public health emergency. An entity of a listed type is in scope when it is at least a medium-sized enterprise: 50 staff or more, or an annual turnover and balance-sheet total above €10 M. Essential entities are the large ones, 250 staff or more, or turnover above €50 M and balance sheet above €43 M; medium-sized Annex I entities are important entities. Article 2(2)(c) adds a size-independent case where a disruption could have a significant impact on public health, which is why a smaller clinic may still be identified.
Article 21(2)(f) requires essential and important entities to adopt "policies and procedures to assess the effectiveness of cybersecurity risk-management measures". The Directive never names a penetration test; a validated test is one way to produce that evidence. Points (d) and (e) cover supply-chain security and vulnerability handling, both of which the vendor-tunnel and legacy findings above feed directly.
| HIPAA Security Rule (US) | NIS2 (EU) | |
|---|---|---|
| Who | Covered entities and business associates handling ePHI | Healthcare providers and other Annex I health entities, at least medium-sized, plus identified entities |
| Testing text | 45 CFR 164.308(a)(8): periodic technical and nontechnical evaluation | Art. 21(2)(f): policies and procedures to assess effectiveness of measures |
| Names a pentest? | No | No |
| Trigger | Initially, then on environmental or operational change | Appropriate and proportionate measures, reviewed; corrective action without undue delay (Art. 21(4)) |
| Incident reporting | Breach Notification Rule (separate) | Art. 23: 24 h early warning, 72 h notification, final report within one month |
The French context: HDS hosting, PGSSI-S and a transposition still pending
In France, hosting personal health data on behalf of others requires HDS certification under article L1111-8 of the Code de la santé publique, with the référentiel HDS v2 (arrêté of 26 April 2024). The PGSSI-S published by the Agence du Numérique en Santé sets the security policy framework for health information systems, and incidents are reported to CERT Santé. Two consequences for a penetration test: the test data and evidence must stay within a hosting arrangement the hospital controls, and the tooling must not export patient-identifying values to a third party. Darkmoon runs self-hosted by default, including in appliance mode, and its Privacy Gateway tokenizes IPs, hostnames, URLs, emails, credentials and internal paths on the client's machine before anything reaches the model; the mechanism is described in Inside the Privacy Gateway. A penetration test does not make a hospital HDS-certified; HDS is a hosting certification.
As of 4 October 2026, the French law transposing NIS2 is not in force: the bill is scheduled for public session at the Assemblée nationale on 7 October 2026, and ANSSI offers pre-registration and a self-test on messervices.cyber.gouv.fr/nis2 together with the Référentiel Cyber France (ReCyF) published on 17 March 2026 (ANSSI). Our NIS2 guide tracks the status.
What the report should give a hospital CISO
- Findings qualified by what was demonstrated (EXPLOITED, CONFIRMED, UNCONFIRMED), with the request, payload or screenshot kept, so the biomedical team and the IT team argue about facts rather than scores.
- A reachability map of imaging and integration systems, so segmentation gaps are visible as paths.
- Severity in CVSS 3.1 and a MITRE ATT&CK mapping (Pro reports), which translate directly into the risk analysis an evaluation or an Article 21 file expects.
- A dated record that can be repeated after the next migration, not a one-off PDF.
Where to start
The healthcare page details the exposures, surfaces and tests for hospitals, clinics and laboratories, including the appliance deployment for estates that cannot send anything outside. For an establishment that wants the engagement run for it, with the legal framework, scoping call, report and debrief handled by ASC-IT's experts, Pentest on Demand is a flat €799 per engagement, indicative and adjusted to the final scope.
See the proof, not just the write-up: the Pro remediation benchmark (fixes retested against the exploit) · how Darkmoon compares to other AI pentest tools.
← All articles