Legacy HL7 on the clinical VLAN

Healthcare

Nov 16, 2025

Legacy HL7 on the clinical VLAN

Healthcare

Nov 16, 2025

Legacy HL7 on the clinical VLAN

Healthcare

Nov 16, 2025

Client

Hospital network

Service

Internal network review

Location

Undisclosed

An HL7 interface from a previous decade was still running. It was supposed to be isolated. From the clinical VLAN, it answered.

The Challenge

HL7 predates the threat model it now lives in. The protocol assumes a trusted network, so it carries patient data without authentication and accepts messages from whatever can reach it. That assumption holds only while the segmentation does.

Here the segmentation had drifted. A device network that clinical staff use every day could route to an interface that nothing outside the integration engine was ever meant to reach.

The Approach

We started from where an attacker would actually stand, a wired port and a device account on the clinical VLAN, and mapped what was reachable from there rather than what the network diagram claimed.

The interface responded. We demonstrated the reachability and the class of message it would accept, and stopped there. Proving the exposure did not require touching patient data, and we did not.

The Outcome

The interface was moved behind the integration segment and the VLAN routing was corrected.

We retested from the same position and confirmed it no longer answered. Reported as HIGH in 2025. Retest included in the engagement.

HIGH

HIGH

Severity

Severity

2025

2025

Disclosed

Disclosed

Included

Included

Retest

Retest