Client
Hospital network
Service
Internal network review
Location
Undisclosed
An HL7 interface from a previous decade was still running. It was supposed to be isolated. From the clinical VLAN, it answered.
The Challenge
HL7 predates the threat model it now lives in. The protocol assumes a trusted network, so it carries patient data without authentication and accepts messages from whatever can reach it. That assumption holds only while the segmentation does.
Here the segmentation had drifted. A device network that clinical staff use every day could route to an interface that nothing outside the integration engine was ever meant to reach.
The Approach
We started from where an attacker would actually stand, a wired port and a device account on the clinical VLAN, and mapped what was reachable from there rather than what the network diagram claimed.
The interface responded. We demonstrated the reachability and the class of message it would accept, and stopped there. Proving the exposure did not require touching patient data, and we did not.

The Outcome
The interface was moved behind the integration segment and the VLAN routing was corrected.
We retested from the same position and confirmed it no longer answered. Reported as HIGH in 2025. Retest included in the engagement.
Case Studies


