Penetration Testing for Central Coast Health and Aged Care Providers: What to Test First

by | Blog, Penetration Testing

First Published:

July 30, 2026

Content Written For:

Small & Medium Businesses

Large Organisations & Infrastructure

Government

Read Similar Articles

Penetration testing for Central Coast health and aged care providers has to start in the right place. Clinical risk is not the same as data risk. This guide sets out what to test first, and why the order matters.

The Central Coast runs on health and aged care. Hospitals, medical practices, allied health and aged care homes employ a large share of the local workforce. Those providers hold the most sensitive data there is. Most of them also run small internal IT teams.

Why health and aged care needs a different test

Four things set this sector apart.

The data is the worst kind to lose. The Privacy Act treats health information as sensitive information. That raises the bar for how you handle it. A serious breach of clinical records also triggers the Notifiable Data Breaches scheme. In a community this size, damage to your name lands fast.

Downtime becomes a clinical problem. Lose a practice management system and care suffers the same day. So patching and recovery planning matter more here than in most sectors. That puts backup and recovery in the same conversation as testing.

The environment connects to more than you think. One provider might run a practice system and a clinical system. Add pathology and imaging links, a My Health Record feed, family portals, rostering and payroll. Add medical and assistive devices on the same network. Every connection opens a path. Nobody mapped the whole thing, because each part arrived separately.

Shared access is normal here. Staff share workstations. Nurses share a login at the station. People move between providers. These are facts of the job, not failures. Testing has to reflect how staff actually work.

What penetration testing for Central Coast providers should cover

Work through these in order. The order matters more than the volume.

1. Identity and remote access

Most break-ins start with a stolen login. Check whether MFA really applies everywhere, not just where someone switched it on. Find the shared clinical accounts and see what they reach. Confirm that leavers actually lost access. If you run Microsoft 365, its setup is the single biggest win on this list.

2. Clinical and resident applications

Practice management, clinical systems and resident portals hold the crown jewels. Test the logins. Check whether one user can reach another patient’s records. Probe the links between systems. Treat any family or patient portal as open to the internet, because it is. This is ordinary application security work, applied to clinical software.

3. The internal network

Assume an attacker already has a foothold. That is the real starting point. Then ask what they reach from a staff PC. Do clinical systems sit behind their own walls? Do medical devices have their own segment? Can someone hop from a reception PC to the records server?

4. Email

Phishing still leads the way in. Health providers also get real files all day from pathology, imaging and referrers, so staff cannot easily spot a fake. Test your email security controls. Pair them with awareness training rather than choosing between the two.

5. External attack surface

Find what of yours faces the internet. Typical results include after-hours staff access, telehealth tools, and a portal someone stood up during a busy week.

Which framework should you work to?

No single standard governs a private health or aged care provider. People often read that as nothing applying. Three things do apply.

The Privacy Act and the Australian Privacy Principles set the rules for handling health information. They expect reasonable steps to protect it. The Essential Eight gives you the most useful baseline you can pick, and it maps well to how these sites fail. For aged care, the Aged Care Quality Standards require sound governance, including risk management. Information security sits inside that.

Some providers then chase formal certification. Usually a funder or a large partner asked for it. Those providers end up looking at ISO 27001. That is a far bigger job than a test, so do not start there.

What a first engagement looks like

For a mid-sized Coast provider, start with three things. Test Microsoft 365 and identity setup. Test the external attack surface. Then test the internal network from a hacked staff PC.

That gives you a short, ranked list of what an attacker would really use. It also gives you evidence for a board or a quality committee.

Leave the clinical applications and the device network for a second phase. Those need more planning with the vendors involved.

Why local access helps

Some of this works far better in person. Checking network splits across a multi-building site takes a walk around. So does checking wireless coverage and guest network splits. Watching how staff really use a shared PC tells you more than any call.

CyberPulse was co-founded on the Central Coast, and one of our founders is based here. Meeting in person across Gosford, Erina, Tuggerah, Wyong and Terrigal is straightforward as a result. For scope and delivery detail, see our penetration testing on the Central Coast page. Our national penetration testing service lists the full range of test types.

Five questions to ask a tester

  • Have you tested a clinical or aged care site before?
  • What did you deliberately avoid touching, and why?
  • How will you keep testing from disrupting care?
  • Can a board or quality committee read your report, or only IT?
  • Will you retest afterwards to confirm the fixes worked?

A provider who answers the second and third questions vaguely has probably never worked on a clinical site.

Next step. A scoping call settles what belongs in a first test and what can wait.

Book a 30-minute strategy call.