Hospitals combine classic IT with medical technology and constant foot traffic, a combination few other industries share in quite this form.
Open entrances and a steady stream of visitors and outside contractors create an environment where physical access control is structurally hard to enforce. Add staff under constant strain: shift work, staff turnover, and high workloads reliably lower vigilance against phishing and pretexting.
At the bedside sit networked medical devices: infusion pumps, monitors, imaging systems. They are often maintained by the manufacturer and rarely covered by classic IT security concepts.
A white coat, a clipboard, and the line "I'm here from technical services for the maintenance" open more doors in a hospital than in almost any other industry. Reception desks sit unattended at times, real outside contractors (cleaning, medical equipment servicing, catering) already move through the building unannounced, and night-shift staff rarely have time to scrutinize an ID badge. Our physical and social engineering assessments simulate exactly these scenarios, in a controlled way and with agreement in advance on who gets notified if things go wrong.
The hospital information system is the central system for patient records, billing, and ward workflows: often grown over many years, with many interfaces to third-party systems. Each of those interfaces is a way in, and usually nobody has the complete picture of them anymore.
The medical devices from the ward show up again here, as network connectivity, remote maintenance access, and a segmentation question. That's where we usually test them, rather than actively attacking the devices themselves, because medical devices must not be put at risk during live operation.
Whether a single compromised machine stays a local problem is decided by the segmentation between the HIS, IoMT, and administration, together with access rights and Active Directory hardening. That's why both belong in every hospital pentest.
According to media reports, the Wertachklinik hospital group in Bobingen and Schwabmünchen was hit by a ransomware attack in early September 2024. IT systems were disconnected from the external network as a precaution to prevent further spread, and the Bamberg General Public Prosecutor's Office (Central Cybercrime Unit) opened an investigation. The incident is not an isolated case: the BSI-funded "SiKIS" research project (Fraunhofer SIT) systematically documented vulnerabilities in German hospital information systems in 2024.
Based on public reporting. accessgranted was not involved in this incident.
The B3S is organized into topic areas. Here's exactly which pentest module covers which area, so your evidence has no gaps.
The main entrance closed hours ago; the emergency department didn't. Someone in work clothes, toolbox in hand, badge on a lanyard, follows a nurse through the door onto the ward and mumbles something about a fault in the utility room. Nobody asks, because three call bells are going at once and because outside technicians at this hour are nothing unusual. A little later, that person is alone in the ward office in front of a logged-in workstation, or at the door to the server room.
That's exactly how we test, but never without agreement. Before we start, it's settled who in the building knows, which areas are off-limits (for example the ICU, operating theaters, and anything with direct patient impact), how our people identify themselves immediately when challenged, and who is reachable as the emergency contact. If the attempt gets spotted and stopped, that's a good result, not an embarrassing one. And the moment patient care could be affected anywhere, we stop before it comes to that.
Patient safety always comes first. That's why our approach at hospitals is coordinated more closely than in other industries.
Together, we define which systems get actively tested and which are only analyzed passively, especially anything with direct patient impact.
Information gathering, network scans, and manual testing within the agreed scope, with a defined emergency contact and an immediate stop if anything unexpected affects production systems.
Every finding is rated by severity, exploitability, and impact on hospital operations, and documented with recommendations, a management summary, and mapping to the B3S "Medical Care" standard.
Section 75c and the B3S ask for evidence on several levels at once. These three modules are how we cover them together.
Simulated access attempts at reception, wards, and server rooms. Covers the physical attack surface that hospitals face especially often.
Phishing and pretexting simulations tailored to shift work and the high workload of daily hospital operations.
Network segmentation between the HIS, IoMT, and administration, access rights, and AD hardening.
From 30,000 fully inpatient cases per year, your facility is also considered a KRITIS operator, with its own evidence obligations under the BSI Act and NIS2. Our compliance pages break down exactly what that means.