Penetration testing for Australian healthcare
Patient data is not an American HIPAA slide. It is the Privacy Act, APP 11, state health records law, and a portal that still has test accounts from go-live. We test that world.
Australian health services, private hospital groups, digital-health startups and insurers run patient portals, booking engines, clinical integrations and a growing pile of FHIR/HL7 interfaces. The data is sensitive under the Privacy Act 1988. Some of it is also My Health Record related. Almost none of it is well served by a generic "HIPAA pentest" bought from an overseas vendor who has never read APP 11.
We test the applications and APIs patients and clinicians actually use. We treat production data as radioactive: staging preferred, production only under tight rules, no bulk export as a party trick. Findings that expose health information are phoned through immediately.
If you operate in Queensland, NSW or Victoria, say so. State health records obligations change what "notify" means. We will not give legal advice. We will make sure the technical evidence is good enough for the people who do.
Patient portals
Access to another patient's record is the finding. We hunt it on purpose.
Clinician apps
Role confusion between nurse, GP, specialist and admin.
Integrations
PMS, pathology, imaging, the SFTP box in the plant room.
Onshore handling
Evidence and screenshots stay in Australia. That is not a slogan, it is the job.
Talk to a tester, not a form-letter
Send the framework, the target and the date of the next audit. We will quote a test that produces evidence for that date.