BPL Logo Banner
CareersContact

In July 2025, the U.S. Department of Health and Human Services’ Office of Inspector General (HHS-OIG) released a cybersecurity audit of a large Northeastern hospital.

The findings revealed a sobering truth: even hospitals with robust defenses, like firewalls, disaster recovery, and security training, remain vulnerable if basic configuration and authentication controls are not consistently enforced.

To provide the technical testing for this audit, OIG engaged BreakPoint Labs (BPL) to conduct penetration testing, web application reviews, and vulnerability scanning under a signed Rules of Engagement. Our work demonstrated how minor weaknesses in internet-facing systems can escalate into significant risks to patient safety and data integrity.

Why This Matters for Healthcare

Healthcare providers remain at the center of the cyber threat landscape.

Together, these numbers reinforce the OIG’s audit findings: healthcare is too often playing defense against adversaries who only need to find one overlooked gap.

Key Findings from the Audit’s Technical Testing

The OIG audit validated that many of the hospital’s defenses were effective. Employees successfully resisted phishing attempts, and the web application firewall blocked most malicious traffic. However, BPL’s technical assessment identified exploitable weaknesses that highlight where hospitals remain at risk:

OIG’s Recommendations — and the Hospital’s Response

OIG issued five recommendations, all accepted by the hospital:

Your 30/60/90-Day Action Plan

Hospitals and healthcare organizations can use this roadmap to harden their defenses quickly:

Days 0–30: Close Obvious Gaps

Days 31–60: Prove Controls in Practice

Days 61–90: Make Security Durable

How BreakPoint Labs Can Help

As OIG’s trusted technical partner in this hospital audit, BreakPoint Labs brings proven expertise in offensive security testing tailored for healthcare environments. Our services help you proactively identify and fix the same types of vulnerabilities found in this engagement.

Our healthcare cybersecurity services include:

Cybersecurity is patient safety. Don’t wait for an audit to find your blind spots.

Request a consultation with BreakPoint Labs today, and let’s build a perimeter-hardening plan that works.

Note: This post summarizes lessons learned from an OIG audit without naming the hospital or exposing sensitive details. Recommendations are sector-wide best practices suitable for public use.

https://oig.hhs.gov/documents/audit/10493/A-18-22-08019.pdf

chevron-down