Decipher
Book a Call Get Started
Home / Security / Security for Healthcare
Industry: Hospitals, Healthtech & Digital Health

Cyber security for Indian healthcare that keeps the clinic open

HMIS ransomware defence that does not disrupt biomedical devices. ABDM sandbox and production hardening for HIPs and HIUs. HL7 and FHIR API security tested against the abuse patterns healthcare attackers actually use. DPDP alignment for patient data. HIPAA scope for US-facing telehealth. On-prem deployments when data cannot leave the hospital.

60+
VAPT engagements shipped
< 4 hrs
RTO on clinical workloads
99.95%
Uptime target for HMIS
5
Compliance regimes supported
Threat Surface for Healthcare

Attack shapes every hospital IT lead has to plan against

Ransomware on the HMIS. Attackers know a hospital cannot afford to be offline. When surgeries are scheduled and lab results are queued, the pressure to pay is measured in hours, not days. Every ransomware post-mortem in Indian and US healthcare traces back to the same three gaps: flat network between admin and clinical VLANs, backups without an offline copy, and EDR either missing or excluded from key workstations because someone was worried it would slow down imaging software.

Patient data exfiltration through the portal or app. Login enumeration on the patient portal, IDOR on record IDs in the mobile app, unbounded search on FHIR endpoints. These are the boring bugs that leak a hundred thousand records to a scraper working nights. They are also almost always missed by generic web-app scanners because the abuse pattern is functional, not a payload.

Biomedical device exposure. The infusion pump, the ultrasound machine, the imaging workstation running an OS the vendor stopped supporting six years ago. They cannot be patched without voiding the AMC. They sit on the same VLAN as everything else because nobody made the segmentation call. When an attacker gets to them, they become the persistence layer nothing else has visibility into.

Consent artefact abuse in ABDM flows. If you are a HIP or HIU, consent artefacts are the audit trail regulators will trace when a patient complains their data was pulled without authorisation. Weak certificate rotation, missing signature verification on incoming artefacts, or a gateway that accepts stale timestamps all produce the same outcome: a NHA notice you have to respond to inside a compressed timeline.

Why healthcare teams pick us

Clinical downtime tolerance drives every decision

A patch window in a hospital is not the same as a patch window in a fintech. Surgeries are booked. Lab machines have calibration cycles. Nurses need the HMIS running at 6am. Every control we roll out is scoped against clinical downtime, not just against a checklist. Deployment plans go through the ops team before they get near production.

See full security service
What We Do

Six security engagements for hospitals and healthtech

HMIS + Patient Portal VAPT

Named-tester penetration testing on HMIS, patient portal, mobile app, HL7 / FHIR APIs. Tests the healthcare-specific abuse patterns: mass patient enumeration, IDOR on record IDs, unbounded date searches, scope-escalation on FHIR resources.

Healthcare-specific tests

Ransomware Defence for HMIS

Immutable backup architecture (object lock, hardened repo, tape rotation), network segmentation between clinical and admin VLANs, EDR rollout tuned around biomedical device tolerances, offline incident playbook.

Recovery, not ransom

ABDM HIP / HIU Readiness

Sandbox test coverage, consent artefact signature verification, X.509 rotation, mTLS to NHA gateways, PHR encryption at rest, audit log retention. Handoff pack for NHA filings.

Sandbox to production

DPDP + HIPAA Data Protection

Data-flow map from admission to discharge, consent capture at collection, purpose limitation on downstream use, PHI encryption, breach notification playbook for DPB (India) and HHS OCR (US). BAA templates for US buyers.

India + US ready

Backup, DR & BCP for Clinical Systems

3-2-1-1-0 backup pattern with an immutable copy. Documented RTO and RPO per system class. DR runbook tested against clinical shift patterns. Quarterly restore drills the ops team runs on their own after handover.

Tested, not theoretical

Managed SOC + Healthcare IR Retainer

24x7 alerting on Wazuh / Sentinel with rules tuned for clinical downtime tolerance. On-call incident commander. Quarterly ransomware tabletop with the hospital ops team. CERT-In 6-hour reporting workflow.

Clinical-aware alerting

ABDM go-live scheduled? Ransomware post-mortem still open?

15-min call. Tell us the environment (on-prem or cloud), the deadline, the ops constraints. Fixed-price plan back in 48 hours.

Book Free 15-min Call
Tech Stack We Use

Tools that work on-prem, in-cloud, and in the space between

Hospitals often run mixed. Some clinical systems on-prem, some SaaS. We deploy inside the constraint, not against it.

SIEM & Detection

Wazuh (on-prem friendly) Microsoft Sentinel Splunk Falco (runtime)

EDR & Endpoint

CrowdStrike Falcon SentinelOne Microsoft Defender

VAPT Toolchain

Burp Suite Pro Nessus Pro Nuclei MobSF / Frida

Backup & DR

Veeam (hardened repo) AWS S3 Object Lock Rubrik LTO tape rotation

Identity & Access

Okta / Azure AD HashiCorp Vault 1Password Business

Cloud & API Edge

Cloudflare AWS WAF AWS Security Hub Azure Defender for Cloud
Compliance We Prep You For

Regimes healthcare providers answer to

ABDM (NHA)

HIP / HIU sandbox tests, consent artefact flow, X.509 rotation, gateway mTLS.

DPDP Act 2023

Consent capture, purpose limitation on health data, 72-hour breach notification.

HIPAA (US)

Security Rule mapping, BAA templates, PHI encryption, HHS OCR breach workflow.

ISO 27001

SoA scoped for a hospital or healthtech, risk register, internal audit.

SOC 2 Type II

For healthtech platforms selling into US health systems.

CERT-In Directions

6-hour reporting, 180-day log retention, SLA integration.

NABH Digital Health

Where applicable, information security clauses in the NABH DHS.

GDPR (if EU patients)

Special category data handling for telemedicine or trials involving EU patients.

Pricing

Fixed-scope engagements, fixed prices

Engagement
HMIS + App VAPT

Named tester on HMIS, patient portal, mobile app, HL7 / FHIR API. CVSS 3.1, PoC, remediation retest.

Rs. 1.5-5 L
Sprint
Ransomware Defence

Immutable backup, VLAN segmentation, EDR rollout, incident playbook, ops-team tabletop.

Rs. 3-6 L
Sprint
ABDM + DPDP Readiness

Sandbox tests, consent flow, X.509 rotation, DPDP purpose limitation mapping, DPO advisory.

Rs. 4-8 L
Ongoing
Managed SOC + IR

24x7 alerting tuned for clinical constraints, on-call IR commander, quarterly tabletop, CERT-In workflow.

Rs. 90k-2 L/mo
FAQ

Questions healthcare IT leaders ask on every call

Layered work in the order that matters. First, immutable backups (S3 object lock, Veeam hardened repo, or LTO tape rotation) so recovery is possible even if the primary storage is encrypted. Second, network segmentation between clinical VLANs, admin VLANs and biomedical devices so lateral movement is capped. Third, EDR (CrowdStrike or SentinelOne) on every workstation that touches the HMIS, tuned to avoid interfering with imaging and lab devices. Fourth, an incident playbook rehearsed with the ops team so a triage decision at 3am does not depend on one senior engineer being awake.

Yes. Digital patient data is personal data under DPDP, and clinical records are treated as sensitive because of the health category. That means consent capture at collection, purpose limitation on use, 72-hour breach notification to the DPB, and retention limits after the care episode. Paper records fall outside DPDP but once they are scanned into the HMIS they are in scope. We do a data-flow map from admission through discharge and fill only the gaps against your existing controls.

If you are a HIP or HIU, the sandbox tests check API signing, consent artefact handling, X.509 certificate rotation, and audit log retention. Beyond the sandbox, production readiness needs mTLS between your gateway and NHA gateways, encryption of PHR data at rest, and a working process for handling consent revocations. We do a full ABDM security review, run the sandbox tests, and hand over the artefacts your compliance team files with NHA.

Yes. BAA templates, HIPAA Security Rule control mapping, PHI encryption at rest and in transit, access logging, breach notification workflow to HHS OCR. Where the platform serves US patients from India-based infra, we set up region-locked storage in US-East-1 or US-West-2 so PHI does not egress. Annual risk assessment as HIPAA requires. Documentation formatted for the questionnaires US healthcare buyers send during procurement.

Yes. Many hospitals in India cannot use public cloud for clinical data because of internal policy or state directives. We deploy Wazuh, on-prem backup targets, and self-hosted EDR management inside your DC. Only anonymised operational telemetry (uptime, alert counts, patch levels) leaves the hospital for our NOC dashboard. Everything else stays behind your firewall. We also handle the biomedical device network separately since those systems often cannot take modern patches.

Authentication (OAuth 2.0 with SMART on FHIR profiles or mTLS for backend-to-backend), authorisation scopes so a lab-report reader cannot pull psychiatric notes, request signing, replay window enforcement, and PHI-safe error messages. We test against the OWASP API Top 10 plus the healthcare-specific abuse patterns (mass patient enumeration through search endpoints, unbounded date ranges, IDOR on record IDs). Then we harden and re-test.

HMIS + application VAPT: Rs. 1.5 to 5 lakh depending on surface (patient portal + HMIS + mobile + HL7 / FHIR APIs). Ransomware defence + backup hardening: Rs. 3 to 6 lakh depending on site count and biomedical device inventory. ABDM + DPDP readiness sprint: Rs. 4 to 8 lakh. Managed SOC + IR retainer: Rs. 90,000 to 2 lakh per month. Fixed-price scoping within 48 hours of a discovery call.
Explore More

Related services

Keep the clinic open, keep patient data safe

15-min call. Tell us the environment, the compliance target, the ops constraints. Fixed-price plan back in 48 hours.

Decipher Assistant
Typically replies instantly