Vendor Posture External security assessments · Healthcare software

For healthcare software vendors

What your customer's security team sees before they ask you.

A fixed-scope assessment of everything your company exposes to the public internet, written up as evidence you can hand to a hospital customer, an auditor, or your own board.

Observation record Public sources only
app.example.comTLS 1.0 enabledHigh
example.comDMARC policy: noneHigh
legacy.example.comAdmin panel reachableHigh
api.example.comServer version disclosedMedium
staging.example.comIndexed by search enginesMedium
example.com17 subdomains resolvedInventory
Derived from DNS, certificate transparency and public service data. No interaction with your systems. Illustrative example.

The deliverable

A report written to be forwarded.

Your customers ask for evidence, not reassurance. Every section is structured so you can send it on without editing it first.

  1. Executive summary

    One page, plain language. This is the page your customer's procurement team actually reads.

  2. Scope and methodology

    What was assessed, how, when, and what the assessment cannot tell you.

  3. External asset inventory

    Every host, service and domain reachable from the internet, in a form you can import.

  4. Findings

    Each one with evidence you can reproduce, business impact, and a specific fix.

  5. HIPAA Security Rule mapping

    Findings tied to the administrative and technical safeguards they touch.

  6. Remediation roadmap

    Sequenced by risk reduction per unit of effort, with suggested owners and dates.

Scope

The boundaries, stated up front.

A narrow service done properly is worth more than a broad one done vaguely. Here is the line.

Included

  • +Attack surface discovery across your domains and address ranges
  • +Exposed services, ports and administrative interfaces
  • +TLS and certificate configuration
  • +HTTP security headers and publicly reachable files
  • +Email authentication: SPF, DKIM and DMARC
  • +Company credentials appearing in public breach data
  • +Findings mapped to HIPAA Security Rule safeguards

Not included

  • Internal networks, endpoints and anything behind your perimeter
  • Exploitation of any finding — nothing is attacked, only observed
  • Social engineering, phishing and physical security
  • Access to any system containing patient data
  • A certification or attestation of HIPAA compliance
  • Remediation work, retesting or ongoing monitoring

Method

Two phases, and the second one needs your signature.

Phase one · Passive

Observed from public sources

DNS records, certificate transparency logs, public registries, search engine indexes and service banners. Nothing touches your infrastructure. This is the phase behind the free sample, and it needs nothing from you.

Phase two · Authorized

Validated against your assets

Non-intrusive service discovery and configuration review, run only after you sign an authorization letter naming the exact domains, addresses and time window. No exploitation, no denial of service, no persistence — stated in writing and bounded by the letter.

Your patient data stays where it is. This assessment never requires credentials, system access, or any connection to environments holding electronic protected health information.

Because no ePHI is created, received, maintained or transmitted, there is no business associate relationship to establish and no BAA to negotiate before work can start.

If the assessment inadvertently surfaces anything resembling patient data, work stops and you are notified the same day. That commitment is in the engagement contract, not just on this page.

Engagement

One price, one scope, no call required.

$1,500Fixed · per assessment
  • Report and findings register delivered within 7 business days
  • Entirely asynchronous — everything happens over email
  • One round of written follow-up questions included
  • 50% on start, 50% on delivery for a first engagement
  • The report is yours: share it with customers, auditors and regulators

Start here

Ask for the sample first.

Send your domain and you'll get a two-page summary of what is visible from outside it, at no cost and with nothing to sign. Decide about the full assessment after you've read it.

Or write directly to hello@vendorposture.com.