CyberPulse has been named Security Partner of the Year at the 2026 techpartner.news Impact Awards, for a programme delivering continuous audit readiness across four compliance frameworks.
Penetration Testing for Central Coast Health and Aged Care Providers: What to Test First

First Published:
Content Written For:
Small & Medium Businesses
Large Organisations & Infrastructure
Government
Read Similar Articles
What Is the AESCSF? A Guide for Australian Energy Organisations (2026)
How the AESCSF works, what Security Profile 2 requires, and what the June 2026 enhanced CIRMP Rules mean for critical energy assets under the SOCI Act.
ISO 42001 Certification Australia: The Complete Guide (2026)
What ISO 42001 certification involves for Australian organisations: the two-stage audit, timeframes, cost drivers, and how it pairs with ISO 27001.
Penetration Testing in Newcastle and the Hunter: What Port, Energy and Industrial Operators Should Test First
Penetration testing in Newcastle and the Hunter has to cover more than the corporate network. Most...
OWASP Top 10 for LLM Applications 2025: An Australian Guide
All ten OWASP LLM risks (LLM01 to LLM10) for 2025, a mitigation for each, and how to map them to ISO/IEC 42001 and the NIST AI RMF.
Penetration testing for Central Coast health and aged care providers has to start in the right place. Clinical risk is not the same as data risk. This guide sets out what to test first, and why the order matters.
The Central Coast runs on health and aged care. Hospitals, medical practices, allied health and aged care homes employ a large share of the local workforce. Those providers hold the most sensitive data there is. Most of them also run small internal IT teams.
Why health and aged care needs a different test
Four things set this sector apart.
The data is the worst kind to lose. The Privacy Act treats health information as sensitive information. That raises the bar for how you handle it. A serious breach of clinical records also triggers the Notifiable Data Breaches scheme. In a community this size, damage to your name lands fast.
Downtime becomes a clinical problem. Lose a practice management system and care suffers the same day. So patching and recovery planning matter more here than in most sectors. That puts backup and recovery in the same conversation as testing.
The environment connects to more than you think. One provider might run a practice system and a clinical system. Add pathology and imaging links, a My Health Record feed, family portals, rostering and payroll. Add medical and assistive devices on the same network. Every connection opens a path. Nobody mapped the whole thing, because each part arrived separately.
Shared access is normal here. Staff share workstations. Nurses share a login at the station. People move between providers. These are facts of the job, not failures. Testing has to reflect how staff actually work.
What penetration testing for Central Coast providers should cover
Work through these in order. The order matters more than the volume.
1. Identity and remote access
Most break-ins start with a stolen login. Check whether MFA really applies everywhere, not just where someone switched it on. Find the shared clinical accounts and see what they reach. Confirm that leavers actually lost access. If you run Microsoft 365, its setup is the single biggest win on this list.
2. Clinical and resident applications
Practice management, clinical systems and resident portals hold the crown jewels. Test the logins. Check whether one user can reach another patient’s records. Probe the links between systems. Treat any family or patient portal as open to the internet, because it is. This is ordinary application security work, applied to clinical software.
3. The internal network
Assume an attacker already has a foothold. That is the real starting point. Then ask what they reach from a staff PC. Do clinical systems sit behind their own walls? Do medical devices have their own segment? Can someone hop from a reception PC to the records server?
4. Email
Phishing still leads the way in. Health providers also get real files all day from pathology, imaging and referrers, so staff cannot easily spot a fake. Test your email security controls. Pair them with awareness training rather than choosing between the two.
5. External attack surface
Find what of yours faces the internet. Typical results include after-hours staff access, telehealth tools, and a portal someone stood up during a busy week.
Which framework should you work to?
No single standard governs a private health or aged care provider. People often read that as nothing applying. Three things do apply.
The Privacy Act and the Australian Privacy Principles set the rules for handling health information. They expect reasonable steps to protect it. The Essential Eight gives you the most useful baseline you can pick, and it maps well to how these sites fail. For aged care, the Aged Care Quality Standards require sound governance, including risk management. Information security sits inside that.
Some providers then chase formal certification. Usually a funder or a large partner asked for it. Those providers end up looking at ISO 27001. That is a far bigger job than a test, so do not start there.
What a first engagement looks like
For a mid-sized Coast provider, start with three things. Test Microsoft 365 and identity setup. Test the external attack surface. Then test the internal network from a hacked staff PC.
That gives you a short, ranked list of what an attacker would really use. It also gives you evidence for a board or a quality committee.
Leave the clinical applications and the device network for a second phase. Those need more planning with the vendors involved.
Why local access helps
Some of this works far better in person. Checking network splits across a multi-building site takes a walk around. So does checking wireless coverage and guest network splits. Watching how staff really use a shared PC tells you more than any call.
CyberPulse was co-founded on the Central Coast, and one of our founders is based here. Meeting in person across Gosford, Erina, Tuggerah, Wyong and Terrigal is straightforward as a result. For scope and delivery detail, see our penetration testing on the Central Coast page. Our national penetration testing service lists the full range of test types.
Five questions to ask a tester
- Have you tested a clinical or aged care site before?
- What did you deliberately avoid touching, and why?
- How will you keep testing from disrupting care?
- Can a board or quality committee read your report, or only IT?
- Will you retest afterwards to confirm the fixes worked?
A provider who answers the second and third questions vaguely has probably never worked on a clinical site.
Next step. A scoping call settles what belongs in a first test and what can wait.
Browse to Read Our Most Recent Articles & Blogs
Subscribe for Early Access to Our Latest Articles & Resources
Connect with us on Social Media
