DPDP deadline: May 2027 · 219 days left Get your business ready in 15 days, done for you Learn more →
Home / Security / Security for Healthcare INDUSTRY FILE · SEC-02
SEC-02 / INDUSTRY: HOSPITALS, HEALTHTECH & DIGITAL HEALTH

Cyber security for Indian healthcare that keeps the clinic open

HMIS ransomware defence that does not disrupt biomedical devices. ABDM sandbox and production hardening for HIPs and HIUs. HL7 and FHIR API security tested against the abuse patterns healthcare attackers actually use. DPDP alignment for patient data. HIPAA scope for US-facing telehealth. On-prem deployments when data cannot leave the hospital.

60+VAPT engagements shipped
< 4hrsRTO on clinical workloads
99.95%Uptime target for HMIS
5Compliance regimes supported
FILE 01 / THREAT SURFACE FOR HEALTHCARE

Attack shapes every hospital IT lead has to plan against

THREAT-01

Ransomware on the HMIS

Attackers know a hospital cannot afford to be offline. When surgeries are scheduled and lab results are queued, the pressure to pay is measured in hours, not days. Every ransomware post-mortem in Indian and US healthcare traces back to the same three gaps: flat network between admin and clinical VLANs, backups without an offline copy, and EDR either missing or excluded from key workstations because someone was worried it would slow down imaging software.

THREAT-02

Patient data exfiltration through the portal or app

Login enumeration on the patient portal, IDOR on record IDs in the mobile app, unbounded search on FHIR endpoints. These are the boring bugs that leak a hundred thousand records to a scraper working nights. They are also almost always missed by generic web-app scanners because the abuse pattern is functional, not a payload.

THREAT-03

Biomedical device exposure

The infusion pump, the ultrasound machine, the imaging workstation running an OS the vendor stopped supporting six years ago. They cannot be patched without voiding the AMC. They sit on the same VLAN as everything else because nobody made the segmentation call. When an attacker gets to them, they become the persistence layer nothing else has visibility into.

THREAT-04

Consent artefact abuse in ABDM flows

If you are a HIP or HIU, consent artefacts are the audit trail regulators will trace when a patient complains their data was pulled without authorisation. Weak certificate rotation, missing signature verification on incoming artefacts, or a gateway that accepts stale timestamps all produce the same outcome: a NHA notice you have to respond to inside a compressed timeline.

WHY HEALTHCARE TEAMS PICK US

Clinical downtime tolerance drives every decision

A patch window in a hospital is not the same as a patch window in a fintech. Surgeries are booked. Lab machines have calibration cycles. Nurses need the HMIS running at 6am. Every control we roll out is scoped against clinical downtime, not just against a checklist. Deployment plans go through the ops team before they get near production.

See full security service
FILE 02 / WHAT WE DO

Six security engagements for hospitals and healthtech

ENG-01 · Healthcare-specific tests

HMIS + Patient Portal VAPT

Named-tester penetration testing on HMIS, patient portal, mobile app, HL7 / FHIR APIs. Tests the healthcare-specific abuse patterns: mass patient enumeration, IDOR on record IDs, unbounded date searches, scope-escalation on FHIR resources.

ENG-02 · Recovery, not ransom

Ransomware Defence for HMIS

Immutable backup architecture (object lock, hardened repo, tape rotation), network segmentation between clinical and admin VLANs, EDR rollout tuned around biomedical device tolerances, offline incident playbook.

ENG-03 · Sandbox to production

ABDM HIP / HIU Readiness

Sandbox test coverage, consent artefact signature verification, X.509 rotation, mTLS to NHA gateways, PHR encryption at rest, audit log retention. Handoff pack for NHA filings.

ENG-04 · India + US ready

DPDP + HIPAA Data Protection

Data-flow map from admission to discharge, consent capture at collection, purpose limitation on downstream use, PHI encryption, breach notification playbook for DPB (India) and HHS OCR (US). BAA templates for US buyers.

ENG-05 · Tested, not theoretical

Backup, DR & BCP for Clinical Systems

3-2-1-1-0 backup pattern with an immutable copy. Documented RTO and RPO per system class. DR runbook tested against clinical shift patterns. Quarterly restore drills the ops team runs on their own after handover.

ENG-06 · Clinical-aware alerting

Managed SOC + Healthcare IR Retainer

24x7 alerting on Wazuh / Sentinel with rules tuned for clinical downtime tolerance. On-call incident commander. Quarterly ransomware tabletop with the hospital ops team. CERT-In 6-hour reporting workflow.

ABDM go-live scheduled? Ransomware post-mortem still open?

15-min call. Tell us the environment (on-prem or cloud), the deadline, the ops constraints. Fixed-price plan back in 48 hours.

FILE 03 / TECH STACK WE USE

Tools that work on-prem, in-cloud, and in the space between

Hospitals often run mixed. Some clinical systems on-prem, some SaaS. We deploy inside the constraint, not against it.

STACK-01

SIEM & Detection

Wazuh (on-prem friendly) · Microsoft Sentinel · Splunk · Falco (runtime)

STACK-02

EDR & Endpoint

CrowdStrike Falcon · SentinelOne · Microsoft Defender

STACK-03

VAPT Toolchain

Burp Suite Pro · Nessus Pro · Nuclei · MobSF / Frida

STACK-04

Backup & DR

Veeam (hardened repo) · AWS S3 Object Lock · Rubrik · LTO tape rotation

STACK-05

Identity & Access

Okta / Azure AD · HashiCorp Vault · 1Password Business

STACK-06

Cloud & API Edge

Cloudflare · AWS WAF · AWS Security Hub · Azure Defender for Cloud

FILE 04 / COMPLIANCE WE PREP YOU FOR

Regimes healthcare providers answer to

REG-01

ABDM (NHA)

HIP / HIU sandbox tests, consent artefact flow, X.509 rotation, gateway mTLS.

REG-02

DPDP Act 2023

Consent capture, purpose limitation on health data, 72-hour breach notification.

REG-03

HIPAA (US)

Security Rule mapping, BAA templates, PHI encryption, HHS OCR breach workflow.

REG-04

ISO 27001

SoA scoped for a hospital or healthtech, risk register, internal audit.

REG-05

SOC 2 Type II

For healthtech platforms selling into US health systems.

REG-06

CERT-In Directions

6-hour reporting, 180-day log retention, SLA integration.

REG-07

NABH Digital Health

Where applicable, information security clauses in the NABH DHS.

REG-08

GDPR (if EU patients)

Special category data handling for telemedicine or trials involving EU patients.

FILE 05 / PRICING

Fixed-scope engagements, fixed prices

ENGAGEMENT

HMIS + App VAPT

Named tester on HMIS, patient portal, mobile app, HL7 / FHIR API. CVSS 3.1, PoC, remediation retest.

Rs. 1.5-5 L
SPRINT

Ransomware Defence

Immutable backup, VLAN segmentation, EDR rollout, incident playbook, ops-team tabletop.

Rs. 3-6 L
SPRINT

ABDM + DPDP Readiness

Sandbox tests, consent flow, X.509 rotation, DPDP purpose limitation mapping, DPO advisory.

Rs. 4-8 L
ONGOING

Managed SOC + IR

24x7 alerting tuned for clinical constraints, on-call IR commander, quarterly tabletop, CERT-In workflow.

Rs. 90k-2 L/mo

This page covers healthcare specifics. For the full service catalogue — access control, backup and recovery, monitoring, continuity planning and how engagements run — see Security & Continuity →

FILE 06 / FIELD MANUAL — FAQ

Questions healthcare IT leaders ask on every call

How do you defend an HMIS against ransomware without disrupting clinical workflows?
Layered work in the order that matters. First, immutable backups (S3 object lock, Veeam hardened repo, or LTO tape rotation) so recovery is possible even if the primary storage is encrypted. Second, network segmentation between clinical VLANs, admin VLANs and biomedical devices so lateral movement is capped. Third, EDR (CrowdStrike or SentinelOne) on every workstation that touches the HMIS, tuned to avoid interfering with imaging and lab devices. Fourth, an incident playbook rehearsed with the ops team so a triage decision at 3am does not depend on one senior engineer being awake.
Does DPDP Act 2023 apply to hospital patient records?
Yes. Digital patient data is personal data under DPDP, and clinical records are treated as sensitive because of the health category. That means consent capture at collection, purpose limitation on use, 72-hour breach notification to the DPB, and retention limits after the care episode. Paper records fall outside DPDP but once they are scanned into the HMIS they are in scope. We do a data-flow map from admission through discharge and fill only the gaps against your existing controls.
What does ABDM compliance actually require from a security angle?
If you are a HIP (Health Information Provider) or HIU (Health Information User), the sandbox tests check API signing, consent artefact handling, X.509 certificate rotation, and audit log retention. Beyond the sandbox, production readiness needs mTLS between your gateway and NHA gateways, encryption of PHR data at rest, and a working process for handling consent revocations. We do a full ABDM security review, run the sandbox tests, and hand over the artefacts your compliance team files with NHA.
Can you handle HIPAA scope for US-facing telemedicine or digital health?
Yes. Business Associate Agreement templates, HIPAA Security Rule control mapping, PHI encryption at rest and in transit, access logging, breach notification workflow to HHS OCR. Where the platform serves US patients from India-based infra, we set up region-locked storage in US-East-1 or US-West-2 so PHI does not egress. Annual risk assessment as HIPAA requires. Documentation formatted for the questionnaires US healthcare buyers send during procurement.
Our data cannot leave the hospital. Can you deploy on-prem?
Yes. Many hospitals in India cannot use public cloud for clinical data because of internal policy or state directives. We deploy Wazuh, on-prem backup targets, and self-hosted EDR management inside your DC. Only anonymised operational telemetry (uptime, alert counts, patch levels) leaves the hospital for our NOC dashboard. Everything else stays behind your firewall. We also handle the biomedical device network separately since those systems often cannot take modern patches.
What does HL7 / FHIR API security actually cover?
Authentication (OAuth 2.0 with SMART on FHIR profiles or mTLS for backend-to-backend), authorisation scopes so a lab-report reader cannot pull psychiatric notes, request signing, replay window enforcement, and PHI-safe error messages. We test against the OWASP API Top 10 plus the healthcare-specific abuse patterns (mass patient enumeration through search endpoints, unbounded date ranges, IDOR on record IDs). Then we harden and re-test.
How much does a healthcare security engagement cost?
HMIS + application VAPT: Rs. 1.5 to 5 lakh depending on surface (patient portal + HMIS + mobile + HL7 / FHIR APIs). Ransomware defence + backup hardening: Rs. 3 to 6 lakh depending on site count and biomedical device inventory. ABDM + DPDP readiness sprint: Rs. 4 to 8 lakh. Managed SOC + IR retainer: Rs. 90,000 to 2 lakh per month. Fixed-price scoping within 48 hours of your first message.

Keep the clinic open, keep patient data safe

15-min call. Tell us the environment, the compliance target, the ops constraints. Fixed-price plan back in 48 hours.