In healthcare, a cyberattack is not an IT problem. It is a patient safety problem.

Healthcare providers, pharmaceutical companies and medical technology firms handle sensitive medical data and critical clinical systems. A security flaw here is not only a technical problem: it can directly affect patient care. We test those systems with the same approach a real attacker would use, and tell you exactly what could be exploited.

Tell us about your healthcare project
30 minutes with a senior consultant. Under NDA.

Protected by reCAPTCHA. The Google Privacy Policy and Terms of Service apply.

Trusted by healthcare and health-tech teams across Europe.

A breach here can cost you care, not just data.

In almost any sector a leak costs data, trust and money. In healthcare it can cost care itself. An attack on a hospital or a clinic does not stay in IT: it locks clinicians out of the medical record, delays diagnoses, cancels scheduled surgery and sends staff back to paper, while some of the most sensitive personal data there is walks out of the door.

Recent incidents
2024 ~$2.9B
Change Healthcare (US)
Ransomware shut down US prescription processing for weeks.
Source · Reuters
2024 Surgeries cancelled
Synnovis (UK NHS)
Pathology services crippled across major London hospitals; surgeries cancelled.
Source · BBC
2024 Days offline
Hospital Universitari de Torrevieja (ES)
Cyberattack disrupted appointments and clinical history for days.
Source · El País
2024 Manual ops
Hospital Verge dels Lliris, Alcoi (ES)
Ransomware forced manual operations across multiple hospital units.
Source · Bleeping Computer
2023 11M records
HCA Healthcare (US)
11 million patient records stolen and posted on a hacker forum.
Source · Reuters
2023 150 surgeries
Hospital Clínic de Barcelona (ES)
Ransomware cancelled 150 surgeries and 3,000 appointments; data leaked.
Source · El País
2023 Millions exposed
MOVEit / multiple healthcare (Global)
Supply-chain breach exposed millions of records via one vendor.
Source · Bleeping Computer
2023 Region-wide
SESCAM, Castilla-La Mancha (ES)
Regional health service hit; administrative systems affected.
Source · El País
2024 ~$2.9B
Change Healthcare (US)
Ransomware shut down US prescription processing for weeks.
Source · Reuters
2024 Surgeries cancelled
Synnovis (UK NHS)
Pathology services crippled across major London hospitals; surgeries cancelled.
Source · BBC
2024 Days offline
Hospital Universitari de Torrevieja (ES)
Cyberattack disrupted appointments and clinical history for days.
Source · El País
2024 Manual ops
Hospital Verge dels Lliris, Alcoi (ES)
Ransomware forced manual operations across multiple hospital units.
Source · Bleeping Computer
2023 11M records
HCA Healthcare (US)
11 million patient records stolen and posted on a hacker forum.
Source · Reuters
2023 150 surgeries
Hospital Clínic de Barcelona (ES)
Ransomware cancelled 150 surgeries and 3,000 appointments; data leaked.
Source · El País
2023 Millions exposed
MOVEit / multiple healthcare (Global)
Supply-chain breach exposed millions of records via one vendor.
Source · Bleeping Computer
2023 Region-wide
SESCAM, Castilla-La Mancha (ES)
Regional health service hit; administrative systems affected.
Source · El País

Why attackers go after healthcare.

A generic security test does not find what actually matters in healthcare. Here the risk is not a leaked spreadsheet: it is a cancelled operation, a stolen medical record that cannot be reissued, or a medical device that fails in the middle of a procedure.

01

The data is worth a lot

Medical records, identity and insurance details are worth more to criminals than card numbers, and unlike a card, a patient’s history cannot be cancelled and reissued.

02

You cannot afford downtime

When systems stop, the pressure is immediate and real: emergencies, operating theatres, diagnostics, admissions. That is exactly what makes extortion work against a hospital.

03

The ecosystem is large and old

Suppliers, integrators, multiple sites, remote access and medical devices that stay in service for a decade or more: every one of them a possible way in, and few of them watched closely.

Why would the healthcare sector call us?

A new patient portal goes live

Before you open access to patients, it is worth proving that no one can reach another patient’s record: the most common serious flaw in these portals.

An ENS or NIS2 audit ahead

Healthcare is an essential sector under NIS2, and Spanish public hospitals fall under the ENS. Your auditor wants technical evidence, not a statement.

A connected medical device joins the network

New kit, or kit that has been in service for a decade, arrives with its own attack surface. We assess it within an agreed scope and conservatively.

The board asks about ransomware

When the question comes from the top it needs an evidenced answer: which path exists to the clinical record, and to care stopping altogether.

Security file for a medical device

A manufacturer preparing product documentation needs testing against the security expectations of the EU medical device rules and IEC 62443.

Hardening after an incident

After a breach of your own or at a supplier, the question is no longer whether there are findings, but whether another path to patient data is still open.

An insurer or client asks for proof

A cyber policy or a client’s security questionnaire calls for an external pentest, with a report, a certificate of execution and retest evidence.

A 30-minute conversation with someone who understands a critical sector.

Whether it is a hospital, an insurer, a clinic group, a medical device manufacturer or a health tech product, we define the scope, the schedule and the consultant who will run your project together. The same person who runs the tests is with you from the first call.

Every finding, its clinical evidence and its closure, in one place.

Live tracking of every vulnerability, with evidence ready for your compliance team and your board, without touching clinical operations.

ASPERIS PLATFORM · DEMO LIVE

What our clients say, in their own words.

We at Etnia highly value our collaboration with Asperis Security. Their professionalism, approachability, quick response and ability to adapt to our needs have been key in every project. The quality of service and continuous support always give us peace of mind. Without a doubt, it is a pleasure to have them as technology partners.

Sergi Leno, Systems Manager
ETNIA Barcelona

At NPAW we have collaborated with Asperis on various security initiatives and the experience has been very positive. We especially value their ability to adapt to our needs and the depth with which they approach each project. Results are clear, structured and useful for decision-making and continuous security improvement. We like working with Asperis for the judgment and value they bring to every collaboration. Their work has helped us strengthen our security level.

Sergi Laencina Verdaguer, CISO
NPAW

ASPERIS has worked alongside us to define and implement our cybersecurity roadmap in Microsoft 365 with a structured approach aligned to business objectives. Thanks to their advice, we took the strategic step of completing our Microsoft ecosystem and reinforcing it with CrowdStrike for advanced mobile device protection, significantly raising our security level.

Jordi Bondia, IT Director
SALVI

With Asperis you don’t hire a service. You hire a partner. They don’t look to bill a project. They look to establish a relationship of trust, caring about the key points that affect your organisation’s security. Professionalism, know-how and diligence.

Juan Valer Tecedor, Software Engineer
GNOSS

Questions we get from healthcare CISOs and IT directors.

Seven questions we hear in every healthcare introductory meeting. If yours isn’t here, ask it.

Because in healthcare the risk is not only confidentiality, it is availability and care continuity. In most sectors a breach is about data being stolen; in a hospital, an attack can also stop clinicians from working, delay diagnosis and cancel treatment. That makes the impact operational and, ultimately, a matter of patient safety, which is why we test with that firmly in mind.

Ransomware aims to interrupt activity: it locks up electronic health records, scheduling, diagnostics and admissions, and often steals data at the same time to add extortion pressure. The result can be cancelled surgery, diverted ambulances and staff forced back to paper. Preventing that starts with finding the way in before an attacker does.

Yes, and that is central to how we work in healthcare. We agree the rules, the windows and the limits before we start, and we treat sensitive and clinical systems conservatively, never using disruptive techniques against them without explicit approval. The aim is a real attacker’s view of your risk with zero impact on care.

Yes. We can assess connected medical devices and the wider Internet of Medical Things, always within a carefully agreed scope and with a conservative approach for anything that touches patient care. Where a device is too sensitive to test live, we agree a safe method in the scoping stage.

The most common serious problem is one patient being able to reach another patient’s records, along with weak access control by role, over-exposed data, and APIs that do not properly check who is asking. These are logic and access problems a scanner cannot judge, which is why we test them by hand.

It supports the main ones healthcare faces: GDPR, where health data is treated as special-category personal data; NIS2, which covers healthcare as an essential sector; and the ENS for Spanish public hospitals. For medical-device makers, it supports the EU device rules and IEC 62443. We provide the technical evidence; your team and your auditor make the formal assessment.

You get an executive and technical report, a prioritised remediation guide, a certificate of execution, and a retest with documented closure evidence, all traceable and exportable from the platform, ready to drop into a GDPR, NIS2 or ENS file.

Ready to prove your healthcare systems are secure?

We work with hospitals, patient portals, health tech platforms and connected devices to test their security without interrupting care. We scope the work carefully, we run the tests against the real environment, and we hand over evidence your auditors and your board can rely on, closed with a retest.

Or email [email protected] directly.