In July 2025, the U.S. Department of Health and Human Services’ Office of Inspector General (HHS-OIG) released a cybersecurity audit of a large Northeastern hospital.
The findings revealed a sobering truth: even hospitals with robust defenses, like firewalls, disaster recovery, and security training, remain vulnerable if basic configuration and authentication controls are not consistently enforced.
To provide the technical testing for this audit, OIG engaged BreakPoint Labs (BPL) to conduct penetration testing, web application reviews, and vulnerability scanning under a signed Rules of Engagement. Our work demonstrated how minor weaknesses in internet-facing systems can escalate into significant risks to patient safety and data integrity.
Why This Matters for Healthcare
Healthcare providers remain at the center of the cyber threat landscape.
48+ breaches a month → In July 2025, HHS’s breach portal logged 48 reportable incidents; August saw 55. Combined, these affected 8M+ patients, with more than 80% tied to hacking or IT intrusions
Ransomware dominates → Incidents fell from 222 in 2021 to 61 in 2024, yet ransomware still drives 39% of all breached healthcare records. The Change Healthcare breach alone (~190M records) disrupted the entire sector.
High costs and lasting impact → Healthcare remains the most expensive industry to breach, at $7.42M per incident, with an average lifecycle of 279 days (IBM, 2025). In the Change Healthcare case, 74% of hospitals reported experiencing delayed care, and 94% suffered financial harm, with a third losing half of their revenue.
Together, these numbers reinforce the OIG’s audit findings: healthcare is too often playing defense against adversaries who only need to find one overlooked gap.
Key Findings from the Audit’s Technical Testing
The OIG audit validated that many of the hospital’s defenses were effective. Employees successfully resisted phishing attempts, and the web application firewall blocked most malicious traffic. However, BPL’s technical assessment identified exploitable weaknesses that highlight where hospitals remain at risk:
Authentication exposure: 2 of 26 systems had weak identification and authentication controls, enabling unauthorized access.
Account discovery: 16 of 255 systems leaked username information through error messages, aiding password attacks.
Web application misconfigurations: All 13 apps tested had integrity or configuration flaws, including unnecessary connections to external systems and insufficient input validation.
Pivot risk: Although no patient data was directly compromised, the weaknesses could have been used as launch points for deeper intrusions.
OIG’s Recommendations — and the Hospital’s Response
OIG issued five recommendations, all accepted by the hospital:
Enforce stronger configuration and change management.
Enforce a developer secure coding policy aligned with OWASP.
How BreakPoint Labs Can Help
As OIG’s trusted technical partner in this hospital audit, BreakPoint Labs brings proven expertise in offensive security testing tailored for healthcare environments. Our services help you proactively identify and fix the same types of vulnerabilities found in this engagement.
Web Application Security Tune-Ups – remediate coding, configuration, and logic flaws.
External Attack Surface Reviews – monitor and validate internet-accessible systems.
Purple-Team Exercises – simulate attacker tactics to validate defenses.
Cybersecurity is patient safety. Don’t wait for an audit to find your blind spots.
Request a consultation with BreakPoint Labs today, and let’s build a perimeter-hardening plan that works.
Note: This post summarizes lessons learned from an OIG audit without naming the hospital or exposing sensitive details. Recommendations are sector-wide best practices suitable for public use.