For healthcare software vendors
What your customer's security team sees before they ask you.
A fixed-scope assessment of everything your company exposes to the public internet, written up as evidence you can hand to a hospital customer, an auditor, or your own board.
The deliverable
A report written to be forwarded.
Your customers ask for evidence, not reassurance. Every section is structured so you can send it on without editing it first.
Executive summary
One page, plain language. This is the page your customer's procurement team actually reads.
Scope and methodology
What was assessed, how, when, and what the assessment cannot tell you.
External asset inventory
Every host, service and domain reachable from the internet, in a form you can import.
Findings
Each one with evidence you can reproduce, business impact, and a specific fix.
HIPAA Security Rule mapping
Findings tied to the administrative and technical safeguards they touch.
Remediation roadmap
Sequenced by risk reduction per unit of effort, with suggested owners and dates.
Scope
The boundaries, stated up front.
A narrow service done properly is worth more than a broad one done vaguely. Here is the line.
Included
- +Attack surface discovery across your domains and address ranges
- +Exposed services, ports and administrative interfaces
- +TLS and certificate configuration
- +HTTP security headers and publicly reachable files
- +Email authentication: SPF, DKIM and DMARC
- +Company credentials appearing in public breach data
- +Findings mapped to HIPAA Security Rule safeguards
Not included
- −Internal networks, endpoints and anything behind your perimeter
- −Exploitation of any finding — nothing is attacked, only observed
- −Social engineering, phishing and physical security
- −Access to any system containing patient data
- −A certification or attestation of HIPAA compliance
- −Remediation work, retesting or ongoing monitoring
Method
Two phases, and the second one needs your signature.
Observed from public sources
DNS records, certificate transparency logs, public registries, search engine indexes and service banners. Nothing touches your infrastructure. This is the phase behind the free sample, and it needs nothing from you.
Validated against your assets
Non-intrusive service discovery and configuration review, run only after you sign an authorization letter naming the exact domains, addresses and time window. No exploitation, no denial of service, no persistence — stated in writing and bounded by the letter.
Your patient data stays where it is. This assessment never requires credentials, system access, or any connection to environments holding electronic protected health information.
Because no ePHI is created, received, maintained or transmitted, there is no business associate relationship to establish and no BAA to negotiate before work can start.
If the assessment inadvertently surfaces anything resembling patient data, work stops and you are notified the same day. That commitment is in the engagement contract, not just on this page.
Engagement
One price, one scope, no call required.
- ›Report and findings register delivered within 7 business days
- ›Entirely asynchronous — everything happens over email
- ›One round of written follow-up questions included
- ›50% on start, 50% on delivery for a first engagement
- ›The report is yours: share it with customers, auditors and regulators
Start here
Ask for the sample first.
Send your domain and you'll get a two-page summary of what is visible from outside it, at no cost and with nothing to sign. Decide about the full assessment after you've read it.
Or write directly to hello@vendorposture.com.