S.01Hospitals, clinics, laboratories, health-tech

Penetration testing for healthcare, where downtime means degraded care.

Darkmoon tests the IT around the care: patient portals, EHR web front ends, DICOM and HL7 endpoints reachable on the network, on-call VPNs, Active Directory and the cloud tenants where exports land. Medical devices in clinical use stay out of scope; the goal is to show, with evidence, how an attacker would reach them. Run it yourself inside your perimeter or order a managed engagement at a flat rate.

749
incidents declared by French health and medico-social structures in 2024 (ANS)
230
of those incidents forced degraded mode or interrupted care
€799
flat rate per managed engagement
50
specialist AI agents, 142 tools

S.03Healthcare
Why hospitals and clinics are exposed

The French health agency ANS counted 749 incidents declared by health and medico-social structures in 2024, up from 581 the year before; 230 of them forced a switch to degraded mode or interrupted care. The pattern is the same everywhere: a care activity that cannot pause, an estate that mixes a 2024 patient portal with an imaging workstation frozen on an old operating system, and hundreds of suppliers holding remote access.

FindingsCVSS
SQL injection9.8
SSRF to metadata9.1
Broken access control8.7
JWT signature bypass7.5
Path traversal6.9

Care cannot wait for the patch window

Imaging workstations, lab analysers and their controlling PCs often run operating systems the manufacturer froze at certification time. They cannot be patched like office PCs, so the network around them has to hold. A pentest shows whether it does.

$darkmoon run --scope identity
→AS-REP roast · 3 accounts
→Kerberoast · svc_sql cracked
→NTLM relay → DCSync
✓Domain Admin, proven

The patient portal is the front door

Appointment booking, results retrieval, pre-admission forms and tele-consultation links expose patient identifiers and health data to the internet. An authorization flaw there is a bulk record leak, not a bug.

Attack surfaceexposure

Hundreds of suppliers with remote hands

Scanner vendors, lab-system integrators, HVAC and building-management contractors, shared IT providers of the hospital group: each one keeps a VPN account or a remote-maintenance tunnel. ANS observed malicious incidents reaching facilities through shared service providers.

darkmoon-licence.dmeDocker
LicencePro · annual
Machine code7F3A-…-C21E
Seats1 node
Statussealed ✓

One Active Directory for the whole site

Ward workstations with shared logins, on-call VPN accounts without MFA, service accounts for the HIS and the PACS: a single flat domain links the administrative network to the clinical one, and ransomware groups know the way.

S.04Attack surface
The attack surface of a healthcare provider

Six system families that Darkmoon enumerates and attacks, from the internet inwards. Medical devices themselves are excluded; the paths that lead to them are not.

Patient portal
Appointment, results and pre-admission portals

Account enumeration, weak OTP flows, insecure direct object references on results, file upload handling on pre-admission documents, session management across the hospital's sub-domains.

HIS / EHR
Hospital information system web front ends

Clinician web clients, prescription modules, bed-management and billing interfaces published to the intranet or through a reverse proxy. Authentication, role separation, API endpoints behind the UI.

DICOM / PACS
Imaging and interface endpoints reachable on the network

DICOM listeners, PACS web viewers, HL7 and FHIR interface engines. Darkmoon tests their reachability, authentication and the web consoles that manage them, never the modality or the device firmware.

VPN
Remote access for on-call staff and suppliers

SSL-VPN appliances, remote-desktop gateways, vendor maintenance tunnels. Exposed management interfaces, known CVEs on edge devices, accounts without MFA, split tunnelling into clinical ranges.

Active Directory
Identity: domain, Entra ID and shared ward accounts

Kerberoasting, delegation abuse, legacy protocols, shared accounts in wards and theatres, group policy exposure, synchronisation between the on-premises domain and the Microsoft 365 tenant.

Cloud / HDS
Cloud tenants and exports to HDS-certified hosting

Object storage holding exports and backups, IAM roles of the research or health-tech teams, SaaS integrations with the HDS host. Darkmoon tests your configuration; it is not an HDS host itself.

S.05Attack paths

How an attacker reaches patient data.

Darkmoon chains findings into paths and keeps the evidence of each step: the request, the payload, the screenshot. Four paths our agents look for in a healthcare estate.

01
From the results portal to every patient's file

A predictable identifier in the lab-results download route, no authorization check beyond the session: one authenticated patient can enumerate other patients' reports. Qualified EXPLOITED when the agent retrieves a second record it owns on a test account.

How the engine works

S.06What Darkmoon tests
What Darkmoon tests in a healthcare estate

Three engagement shapes, each with an orchestrator and specialist agents behind an MCP gateway: the model proposes, the gateway executes within the allow-list, and every finding is qualified EXPLOITED, CONFIRMED or UNCONFIRMED by an adversarial rubric.

web, API, edge
FindingsCVSS
SQL injection9.8
SSRF to metadata9.1
Broken access control8.7
JWT signature bypass7.5
Path traversal6.9

External surface: portals, APIs, VPN gateways

Patient and staff portals, appointment APIs, tele-consultation links, VPN and remote-desktop gateways, mail gateways. Web and API agents, edge-device CVE checks, authentication and authorization testing with test accounts you provide.

AD, network
$darkmoon run --scope identity
→AS-REP roast · 3 accounts
→Kerberoast · svc_sql cracked
→NTLM relay → DCSync
✓Domain Admin, proven

Internal estate: Active Directory and clinical network reachability

From an assumed-breach position on the administrative network: identity attacks, lateral movement, segmentation between administrative, biomedical and imaging ranges, reachability of DICOM, HL7 and PACS consoles. Read-only on clinical segments, agreed in scoping.

cloud, identity, CI/CD
Attack surfaceexposure

Cloud tenants, HDS exports and health-tech CI/CD

AWS, Azure or GCP tenants of the group or the health-tech vendor, Microsoft 365 and Entra ID configuration, storage policies, pipeline secrets, Kubernetes clusters hosting patient-facing apps, AI endpoints used in triage tools.

S.07How an engagement works

From order to report, in five steps.

A process designed to be simple for the client and rigorous on the security side.

01
Describe your target

A guided form: target type, scope and objectives.

How the engine works

S.08Evidence & reporting
Concrete, actionable deliverables.

Not just an automated scan: a structured, validated and debriefed audit.

ranked
FindingsCVSS
SQL injection9.8
SSRF to metadata9.1
Broken access control8.7
JWT signature bypass7.5
Path traversal6.9

Detailed pentest report

Vulnerabilities ranked by severity, technical evidence, business impact and prioritized remediation guidance.

email + OTP
New engagement
Targetapp.acme.test
Scopeweb · API · cloud
Window5 business days
Flat rate€799

Secure client space

Access by email and OTP code. Contractual documents, report and exchanges centralized, available whenever you need them.

video call
Attack surfaceexposure

Debrief meeting

A video call with an expert to walk through the findings, answer questions and guide you on the fixes.

S.09Where your data goes
Health data stays where your HDS host keeps it.

Darkmoon does not host or copy patient data. The Privacy Gateway tokenizes every sensitive value (IPs, hostnames, URLs, emails, credentials, internal paths) on your machine before anything reaches the model and rehydrates it locally. Hospitals that cannot send anything outside can self-host the engine with a local LLM via Ollama or llama.cpp, or run it in appliance mode (Pro). In the managed engagement, evidence stays in a client space you control, and tests use the accounts you provide, never live patient records.

S.10Regulatory context
NIS2, HDS and the HIPAA evaluation standard

Healthcare is one of the few sectors named by NIS2 itself. In France, hosting personal health data is a separate, certified activity (HDS). In the United States, the HIPAA Security Rule's evaluation standard (45 CFR 164.308(a)(8)) requires periodic technical and non-technical evaluation of safeguards; it does not mandate a penetration test, and neither does NIS2. Darkmoon does not certify compliance; it produces documented, reproducible findings you can present to your management body, auditors or supervisory authority as part of your evidence base.

NIS2 Annex I, point 5: Health

Annex I lists, as a sector of high criticality, “Healthcare providers as defined in Article 3, point (g), of Directive 2011/24/EU”, EU reference laboratories (Reg. 2022/2371 Art. 15), entities carrying out research and development of medicinal products (Dir. 2001/83/EC), manufacturers of basic pharmaceutical products and preparations (NACE Rev. 2 C 21) and manufacturers of medical devices on the public-health-emergency critical list (Reg. 2022/123 Art. 22). Other medical-device manufacturers are Annex II point 5(a).

Who is in scope, and where France stands

An entity of a listed type is in scope when it is at least a medium-sized enterprise: 50 staff or more, or an annual turnover AND balance-sheet total above €10 M; essential entities are the large ones, 250 staff or more, or turnover above €50 M and balance sheet above €43 M; plus the size-independent cases of Article 2(2) and Article 3. Article 2(2)(c) lets a Member State bring in an entity of any size when a disruption of its service “could have a significant impact on public safety, public security or public health”. In France the transposition bill, adopted by the Sénat on 12 March 2025, is scheduled for public session at the Assemblée nationale on 7 October 2026 and is not promulgated; ANSSI offers pre-registration and an eligibility self-test on messervices.cyber.gouv.fr/nis2 and published the ReCyF reference framework on 17 March 2026.

HIPAA Security Rule: the evaluation standard (United States)

For covered entities and business associates, 45 CFR 164.308(a)(8) requires a periodic technical and non-technical evaluation of how security policies and procedures meet the Security Rule, based initially on the implemented standards and then in response to environmental or operational changes. The standard does not name penetration testing; many covered entities use a pentest as the technical part of that evaluation. Darkmoon's report, evidence and CVSS 3.1 scoring fit that use without being a HIPAA attestation.

HDS: a hosting certification, not a pentest outcome

Article L1111-8 of the Code de la santé publique requires anyone hosting personal health data on behalf of a care provider to be HDS-certified (référentiel v2, arrêté of 26 April 2024). Darkmoon is not an HDS host and a penetration test does not make anyone HDS-certified. It tests the configuration you control around that hosting and the copies that leave it.

Darkmoon does not certify compliance. This section is general information, not legal advice, and reflects the texts as of 4 October 2026, before the French transposition law is promulgated.

S.11Use case
A two-site hospital group with a shared PACS and an on-call VPN

The CISO of a regional hospital group wants to know whether the on-call VPN and the shared PACS create a route from the internet to the imaging network. The scoping call fixes the rules: test accounts on the patient portal, an assumed-breach foothold on the administrative VLAN, imaging ranges in read-only, no interaction with any modality, testing windows outside peak hours. Darkmoon's agents enumerate the external surface, attack the identity layer and map which clinical consoles are reachable from where.

Outcome

A report ranked by severity with the evidence of each step, an infrastructure graph showing the administrative-to-clinical path that worked, a debrief with the CISO and the biomedical engineering lead, and a list of fixes the group can hand to its integrators. The findings become one piece of the group's evidence under Article 21(2)(f) of NIS2; the certification of its hosting stays with its HDS host.

Pentest on Demand
€799/ engagement
  • Full penetration test on the defined scope
  • Legal framework and authorizations included
  • Detailed report with evidence and recommendations
  • Secure client space with OTP access
  • Video debrief meeting with an expert
  • Personalized scoping by our team
S.12Pricing

A clear flat rate, shown upfront.

The price is known before payment. No quote, no surprise. Indicative price, adjusted to the final scope. If the scoping call changes the scope and the price, you are told before anything starts.

Legal framework & authorizations included

S.13Frequently asked
What a hospital CISO asks first.

Do you test medical devices?

No. Medical devices in clinical use (modalities, pumps, monitors, analysers) are out of the autonomous testing scope, and Darkmoon never touches device firmware or anything related to MDR certification. It tests the IT around them: the network they sit on, the consoles that manage them, the identity that reaches them and the portals that expose their data.

Can a penetration test disrupt care?

The scoping call exists to prevent that. Clinical and biomedical ranges are set to read-only or excluded, testing windows are agreed, and the tool execution is gatekept by an MCP gateway with a build-enforced allow-list, so the model never gets a shell. In the managed engagement ASC-IT's experts supervise the run end to end.

Does NIS2 require hospitals to run a penetration test?

No test type or frequency is named in the Directive. Article 21(2)(f) requires “policies and procedures to assess the effectiveness of cybersecurity risk-management measures”; a validated penetration test is one way to produce that evidence, not a mandated deliverable. Whether your establishment is an essential or important entity depends on Annex I, size and national identification.

Does HIPAA require penetration testing?

The HIPAA Security Rule requires a periodic technical and non-technical evaluation (45 CFR 164.308(a)(8)); it does not name penetration testing. Many covered entities use a pentest as the technical part of that evaluation. Darkmoon's report, evidence and CVSS 3.1 scoring fit that use without being a HIPAA attestation.

Our patient data is HDS-hosted. Where does the test evidence go?

Darkmoon is not an HDS host and does not need patient data to test. The Privacy Gateway tokenizes IPs, hostnames, URLs, emails and credentials on your machine before anything reaches the model; you can also run the whole engine inside your perimeter with a local model. In the managed engagement the report lives in a client space protected by email and OTP.

How is a multi-site hospital priced?

The managed engagement is shown at a flat €799, indicative and adjusted to the final scope during the scoping call. A group with several sites and tenants will typically be split into several scopes. The legal framework, test authorization and liability terms are signed electronically before anything starts.

We are a health-tech vendor. Can this run in our CI/CD?

Yes. Darkmoon integrates with GitHub Actions, GitLab CI/CD and Jenkins; the Pro edition adds the scheduler for recurring campaigns and the remediation agent that opens sandbox-validated fix pull requests for human review, never auto-merged. Hospital customers increasingly ask their vendors for this kind of evidence.

What do we need to provide?

A written authorization for the targets in scope (the legal framework you sign at order time), the URLs, hostnames or network ranges to test, test accounts where authenticated testing matters, and a contact for the scoping call. Our experts confirm the scope and the constraints with you before the engagement starts.

Can we share the report with our insurer, clients or auditors?

Yes. The report is yours. It documents each finding with its evidence, severity and remediation guidance, so it can be handed to a cyber-insurer, a client's procurement team or an auditor as a dated, factual description of what was found. It is evidence, not a certification.

What happens after the report?

You get a prioritised fix list with the evidence for each finding, a debrief call to walk through it, and the option to retest once the fixes are in. Teams that self-host can schedule recurring campaigns (Pro) so the same checks run after each change; the Pro remediation agent can also open sandbox-validated fix pull requests for your developers to review.

S.14Related
Go deeper

S.15Next
Test the IT around the care, before someone else does.

Describe your portals, VPNs and tenants, sign the framework online and get an evidence-backed report with a debrief. Medical devices stay out of scope; the paths to them do not.