Pentest HIPAA Security Rule (Administrative, Physical, Technical Safeguards) + Breach Notification. Para Business Associate (BA) servindo US healthcare.
Why now
Healthtech brasileira vendendo para US healthcare é Business Associate (BA) sob HIPAA. BAA assinada, OCR audit ativo, multa de até US$ 1.9M/violação. Pentest HIPAA é parte essencial do BAA — sem ele, cliente cancela contrato.
Standard and reference
/attack-surface
Every engagement is designed for your environment. The points below are part of our standard playbook for this sector — final scope is adapted to your stack and contract.
Access control, audit controls, integrity, transmission security.
Risk analysis, workforce training, contingency, incident procedures.
Facility access, workstation security, device controls.
Criptografia em repouso e trânsito, segregação de PHI, minimização.
Runbook de detecção, análise de breach, notificação OCR + indivíduos.
Validação técnica das obrigações do BAA, due diligence de sub-BA.
/methodology
Automated scanners find what's documented. Real attackers find what isn't. 90% of the work is manual — performed by specialists holding OSCP, CISSP, CRTO and GPEN.
Target mapping, OSINT, footprint, sector-specific threat modeling.
Deep enumeration, complementary scanning, manual exposure identification.
Manual validation with controlled PoC, finding chaining, escalation.
Executive + technical, step-by-step replication, mapped to applicable regulation.
/why-trust
Healthtech brasileira com clientes US, sob BAA com hospitais/payers/PBM americanos.
Technical assessment recognized in highly regulated, mission-critical environments — the pentest that finds what nobody had found before.
Douglas Lopes
Founder · CEO · intrus.io
/crivo · integrity program
of pentester candidates fail our Crivo screening
NDAs work in court. They don't work day-to-day. Before first access, every pentester on our team passes background, psychometric profile and integrity testing.
/faq
Sim. Conhecemos os 169 control areas e mapeamos pentest para os controles avaliados em audit.
Healthtech pequena com ePHI: R$ 40-80k. Plataforma multi-tenant servindo payers: R$ 80-200k.
/contact
Schedule a confidential meeting. Within 48h we'll send a proposal with scope, timeline and pricing.