Healthcare Penetration Testing

Penetration testing for health tech, from patient data access to the technology behind it

Manual penetration testing for digital health suppliers and healthcare providers, with reports you can use as evidence for NHS DTAC and DSPT assessments. Fixed pricing, from a CREST member company.

Accreditations and memberships

Why Health Tech Teams Come to Us

What brings health tech teams to a penetration test

For most NHS suppliers, a penetration test is prompted by an NHS assessment or a buyer's security questions rather than a planned test. These are the most common triggers.

A DTAC assessment for an NHS buyer

Commissioners and care providers in England assess digital health products against the Digital Technology Assessment Criteria (DTAC). For internet-facing products, it asks for a summary report of a third-party penetration test from the last 12 months, covering the OWASP Top 10 and showing no vulnerabilities scoring on or above CVSS 7.0.

The Data Security and Protection Toolkit

Organisations with access to NHS patient data and systems must complete the DSPT. NHS England's DSPT guidance on penetration testing says a test should be undertaken at least annually. Which requirements apply depends on your organisation type and the version of the toolkit you complete.

NHS trust or ICB procurement

Supplier security questionnaires from trusts and integrated care boards commonly ask for evidence of recent, independent penetration testing of the product being bought.

Investors or partners want assurance

Security due diligence is increasingly common in health tech funding rounds and partnership agreements, where a breach of patient data carries regulatory as well as commercial consequences.

Scope of Testing

What a healthcare penetration test covers

Health tech products combine sensitive patient data, several user types with very different access rights, and integrations with clinical systems. Testing is built around how your product handles that data.
01

Patient data access control

Whether one patient can reach another's records, whether clinicians and administrator roles are properly segregated, and whether access rules are resilient when object references are changed. See our web application penetration testing service for the full methodology.
02

APIs and interoperability

Authentication, authorisation and data exposure in the APIs behind your product, including FHIR-based interfaces and integrations with clinical systems. See our API penetration testing service.
03

Patient-facing mobile apps

Local storage of health data, certificate validation, session handling and the APIs the app relies on. See our mobile application security testing service.
04

Authentication and identity

Login and password reset flows, MFA (including on privileged and supplier support accounts), session management, and integrations with single sign-on or third-party identity providers.
05

Audit trails and data exposure

Whether access to records is logged, where you can share audit logs with us, and whether patient data leaks through exports, error messages, caches or reporting features.
06

Hosting and external exposure

Admin panels, staging environments, cloud storage and other internet-facing services around the product. This can be scoped as an add-on through external penetration testing.

How It Works

From first contact to final report

You don't need a scope document prepared before reaching out.
01

Tell us what you need

Submit a quote request or book a scoping call with a rough idea of your product, its user types and integrations, and the assessment you're preparing for. We reply within one business day to confirm the scope, usually with a short questionnaire or a call.
02

Receive a written, fixed-price proposal

The proposal confirms the scope, methodology, timing, rules of engagement and a fixed price. You accept when you're ready, and there's no obligation at any stage.
03

Testing in staging, with synthetic data

Your consultant is your direct contact throughout, and critical findings are escalated the same day they're discovered.
04

Report delivery and debrief

Technical and executive reports are delivered within 2 business days of testing completion, followed by a debrief call. Focused retesting of remediated findings is included, so the report you share reflects the fixes you've made.

What You Receive

Included in every engagement

  • Executive and technical reports, and attestation

    A summary for leadership and NHS buyers, every finding with evidence, CVSS scoring and remediation guidance, and an attestation of testing you can share with buyers or submit with DTAC and DSPT evidence.
  • Debrief session

    A video call or presentation to walk through findings and remediation priorities with your technical and security teams.
  • Retesting and platform access

    Focused retesting of remediated web application and API findings, and findings tracked in the Exploitr platform at no extra cost.

Common Questions

Healthcare penetration testing: frequently asked questions

How healthcare penetration testing is scoped, priced and delivered, answered before you request a quote.

Yes. Version 2.0 of DTAC (February 2026) asks for a summary report of an external, third-party penetration test from the previous 12 months that covers the OWASP Top 10. Every engagement includes an executive report, a technical report and an attestation of testing, documenting the scope, testing dates and OWASP Top 10 coverage.

Retesting is included for web application and API engagements, and can be added to the scope for mobile apps.

Exploitr is a CREST member company, and NHS England's DSPT guidance lists CREST among the indicators to look for when choosing a penetration testing supplier.

Signing the Charter means DTAC doesn't ask you for the penetration test summary. NHS England's DSPT guidance still recommends a test at least annually, and buyers' own security questionnaires often ask for one, so check what your buyer and your toolkit submission need before deciding.

NHS England's DSPT guidance on penetration testing says a test should be undertaken at least annually, covering the webservers your organisation uses. Which requirements apply will depend on your organisation type and the version of the toolkit you complete.

DTAC also asks suppliers with access to patient data or NHS systems to confirm Standards Met or Exceeded status on the DSPT.

If you're completing the toolkit, tell us during scoping and we'll make sure the engagement covers what you need to evidence.

It depends on the contract. CHECK is the NCSC's scheme for penetration testing of government and critical national infrastructure systems. NHS England's DSPT guidance lists CREST, The Cyber Scheme and CHECK as indicators, rather than requiring one of them, and DTAC asks for a third-party tester without naming a scheme.

Exploitr is a CREST member company and doesn't hold CHECK. If a contract you're working to specifies CHECK, let us know and we'll tell you upfront.

Yes. Providers completing the DSPT usually need external and internal network penetration testing rather than product testing, covering internet-facing services, remote access and the internal network that clinical systems run on.

Our network penetration testing page explains how to choose.

In most cases, yes. We prefer to test against a staging environment populated with synthetic data. If production has to be in scope, we agree rules of engagement in advance that set out excluded functionality and what happens if real patient data is encountered, and involve your clinical safety officer where testing could affect clinical workflows.

All findings and evidence are handled securely and deleted in line with the engagement terms, and we're happy to sign an NDA before testing begins.

It depends on what's in scope. Web application testing starts from £3,600, API testing from £2,400 and mobile application testing from £3,600, and products that combine them are usually scoped as a single engagement.

Our penetration testing pricing guide compares costs across every service.

At least annually, in line with NHS England's DSPT guidance, and DTAC asks for a test from the previous 12 months. Test again after significant changes such as a new integration, a new user type or a major release.

If you release frequently, our Pentest as a Service (PTaaS) offering provides ongoing testing aligned with your release cadence.

Ready to scope your healthcare penetration test?

Tell us about your product and the assessment you're preparing for, and we'll reply within one business day to confirm the scope, then send a fixed-price proposal. No obligation at any stage.