Penetration testing in Newcastle and the Hunter has to cover more than the corporate network. Most...
Penetration Testing for Central Coast Health and Aged Care Providers: What to Test First

First Published:
Content Written For:
Small & Medium Businesses
Large Organisations & Infrastructure
Government
Read Similar Articles
OWASP Top 10 for LLM Applications 2025: An Australian Guide
All ten OWASP LLM risks (LLM01 to LLM10) for 2025, a mitigation for each, and how to map them to ISO/IEC 42001 and the NIST AI RMF.
Shadow AI in Australian Organisations: How to Secure Staff Use of AI Without Banning It
Shadow AI is already inside most Australian organisations. Here is how to secure staff use of AI without banning it, and govern it to ISO/IEC 42001.
Network Detection and Response (NDR): A Buyer’s Guide for Australian Security Leaders
What NDR does, how it compares to EDR, XDR and SIEM, how it supports Australian compliance, and how to choose a provider.
Australia’s Cyber Security Skills Shortage: The Cost, the Risk, and How to Resource Around It
Australia is short of cyber security specialists. Here is what a vacant role really costs, and how hiring managers and CFOs can resource around the gap.
Penetration testing for Central Coast health and aged care providers has to start in the right place. Clinical risk is not the same as data risk. This guide sets out what to test first, and why the order matters.
The Central Coast runs on health and aged care. Hospitals, medical practices, allied health and aged care homes employ a large share of the local workforce. Those providers hold the most sensitive data there is. Most of them also run small internal IT teams.
Why health and aged care needs a different test
Four things set this sector apart.
The data is the worst kind to lose. The Privacy Act treats health information as sensitive information. That raises the bar for how you handle it. A serious breach of clinical records also triggers the Notifiable Data Breaches scheme. In a community this size, damage to your name lands fast.
Downtime becomes a clinical problem. Lose a practice management system and care suffers the same day. So patching and recovery planning matter more here than in most sectors. That puts backup and recovery in the same conversation as testing.
The environment connects to more than you think. One provider might run a practice system and a clinical system. Add pathology and imaging links, a My Health Record feed, family portals, rostering and payroll. Add medical and assistive devices on the same network. Every connection opens a path. Nobody mapped the whole thing, because each part arrived separately.
Shared access is normal here. Staff share workstations. Nurses share a login at the station. People move between providers. These are facts of the job, not failures. Testing has to reflect how staff actually work.
What penetration testing for Central Coast providers should cover
Work through these in order. The order matters more than the volume.
1. Identity and remote access
Most break-ins start with a stolen login. Check whether MFA really applies everywhere, not just where someone switched it on. Find the shared clinical accounts and see what they reach. Confirm that leavers actually lost access. If you run Microsoft 365, its setup is the single biggest win on this list.
2. Clinical and resident applications
Practice management, clinical systems and resident portals hold the crown jewels. Test the logins. Check whether one user can reach another patient’s records. Probe the links between systems. Treat any family or patient portal as open to the internet, because it is. This is ordinary application security work, applied to clinical software.
3. The internal network
Assume an attacker already has a foothold. That is the real starting point. Then ask what they reach from a staff PC. Do clinical systems sit behind their own walls? Do medical devices have their own segment? Can someone hop from a reception PC to the records server?
4. Email
Phishing still leads the way in. Health providers also get real files all day from pathology, imaging and referrers, so staff cannot easily spot a fake. Test your email security controls. Pair them with awareness training rather than choosing between the two.
5. External attack surface
Find what of yours faces the internet. Typical results include after-hours staff access, telehealth tools, and a portal someone stood up during a busy week.
Which framework should you work to?
No single standard governs a private health or aged care provider. People often read that as nothing applying. Three things do apply.
The Privacy Act and the Australian Privacy Principles set the rules for handling health information. They expect reasonable steps to protect it. The Essential Eight gives you the most useful baseline you can pick, and it maps well to how these sites fail. For aged care, the Aged Care Quality Standards require sound governance, including risk management. Information security sits inside that.
Some providers then chase formal certification. Usually a funder or a large partner asked for it. Those providers end up looking at ISO 27001. That is a far bigger job than a test, so do not start there.
What a first engagement looks like
For a mid-sized Coast provider, start with three things. Test Microsoft 365 and identity setup. Test the external attack surface. Then test the internal network from a hacked staff PC.
That gives you a short, ranked list of what an attacker would really use. It also gives you evidence for a board or a quality committee.
Leave the clinical applications and the device network for a second phase. Those need more planning with the vendors involved.
Why local access helps
Some of this works far better in person. Checking network splits across a multi-building site takes a walk around. So does checking wireless coverage and guest network splits. Watching how staff really use a shared PC tells you more than any call.
CyberPulse was co-founded on the Central Coast, and one of our founders is based here. Meeting in person across Gosford, Erina, Tuggerah, Wyong and Terrigal is straightforward as a result. For scope and delivery detail, see our penetration testing on the Central Coast page. Our national penetration testing service lists the full range of test types.
Five questions to ask a tester
- Have you tested a clinical or aged care site before?
- What did you deliberately avoid touching, and why?
- How will you keep testing from disrupting care?
- Can a board or quality committee read your report, or only IT?
- Will you retest afterwards to confirm the fixes worked?
A provider who answers the second and third questions vaguely has probably never worked on a clinical site.
Next step. A scoping call settles what belongs in a first test and what can wait.
Browse to Read Our Most Recent Articles & Blogs
Subscribe for Early Access to Our Latest Articles & Resources
Connect with us on Social Media
