Healthcare Penetration Testing
Penetration testing for health tech, from patient data access to the technology behind it
Scope of Testing
What a healthcare penetration test covers
Patient data access control
APIs and interoperability
Patient-facing mobile apps
Authentication and identity
Audit trails and data exposure
Hosting and external exposure
How It Works
From first contact to final report
Tell us what you need
Receive a written, fixed-price proposal
Testing in staging, with synthetic data
Report delivery and debrief
What You Receive
Included in every engagement
Executive and technical reports, and attestation
A summary for leadership and NHS buyers, every finding with evidence, CVSS scoring and remediation guidance, and an attestation of testing you can share with buyers or submit with DTAC and DSPT evidence.Debrief session
A video call or presentation to walk through findings and remediation priorities with your technical and security teams.Retesting and platform access
Focused retesting of remediated web application and API findings, and findings tracked in the Exploitr platform at no extra cost.
Common Questions
Healthcare penetration testing: frequently asked questions
Yes. Version 2.0 of DTAC (February 2026) asks for a summary report of an external, third-party penetration test from the previous 12 months that covers the OWASP Top 10. Every engagement includes an executive report, a technical report and an attestation of testing, documenting the scope, testing dates and OWASP Top 10 coverage.
Retesting is included for web application and API engagements, and can be added to the scope for mobile apps.
Exploitr is a CREST member company, and NHS England's DSPT guidance lists CREST among the indicators to look for when choosing a penetration testing supplier.
Signing the Charter means DTAC doesn't ask you for the penetration test summary. NHS England's DSPT guidance still recommends a test at least annually, and buyers' own security questionnaires often ask for one, so check what your buyer and your toolkit submission need before deciding.
NHS England's DSPT guidance on penetration testing says a test should be undertaken at least annually, covering the webservers your organisation uses. Which requirements apply will depend on your organisation type and the version of the toolkit you complete.
DTAC also asks suppliers with access to patient data or NHS systems to confirm Standards Met or Exceeded status on the DSPT.
If you're completing the toolkit, tell us during scoping and we'll make sure the engagement covers what you need to evidence.
It depends on the contract. CHECK is the NCSC's scheme for penetration testing of government and critical national infrastructure systems. NHS England's DSPT guidance lists CREST, The Cyber Scheme and CHECK as indicators, rather than requiring one of them, and DTAC asks for a third-party tester without naming a scheme.
Exploitr is a CREST member company and doesn't hold CHECK. If a contract you're working to specifies CHECK, let us know and we'll tell you upfront.
Yes. Providers completing the DSPT usually need external and internal network penetration testing rather than product testing, covering internet-facing services, remote access and the internal network that clinical systems run on.
Our network penetration testing page explains how to choose.
In most cases, yes. We prefer to test against a staging environment populated with synthetic data. If production has to be in scope, we agree rules of engagement in advance that set out excluded functionality and what happens if real patient data is encountered, and involve your clinical safety officer where testing could affect clinical workflows.
All findings and evidence are handled securely and deleted in line with the engagement terms, and we're happy to sign an NDA before testing begins.
It depends on what's in scope. Web application testing starts from £3,600, API testing from £2,400 and mobile application testing from £3,600, and products that combine them are usually scoped as a single engagement.
Our penetration testing pricing guide compares costs across every service.
At least annually, in line with NHS England's DSPT guidance, and DTAC asks for a test from the previous 12 months. Test again after significant changes such as a new integration, a new user type or a major release.
If you release frequently, our Pentest as a Service (PTaaS) offering provides ongoing testing aligned with your release cadence.
