Security for video consultation, EHR, digital prescription, pharmacy integration and wearables.
Why now
Telemedicine scaled in 5 years; security did not. Recorded video consultations leaked, manipulated prescriptions, laterally-accessed records, compromised pharmacy integration. CFM, ANS and LGPD don't forgive — fines, license loss and criminal liability for the technical medical director.
Applicable regulation
/attack-surface
Every engagement is designed for your environment. The points below are part of our standard playbook for this sector — final scope is adapted to your stack and contract.
WebRTC, end-to-end encryption, recording, unauthorized third-party access.
IDOR between patients, segregation by specialty, integrity of clinical records.
Prescription manipulation, digital signature, ICP-Brasil and counter validation.
Prescription handoff, exam return, result privacy and chain of trust.
Mobile, exam photo, OCR, professional conversation and consent security.
Data integrity, transit encryption, device authentication and clinical alarm.
/methodology
Automated scanners find what's documented. Real attackers find what isn't. 90% of the work is manual — performed by specialists holding OSCP, CISSP, CRTO and GPEN.
Target mapping, OSINT, footprint, sector-specific threat modeling.
Deep enumeration, complementary scanning, manual exposure identification.
Manual validation with controlled PoC, finding chaining, escalation.
Executive + technical, step-by-step replication, mapped to applicable regulation.
/why-trust
Post-COVID expansion with acknowledged security deficit and growing regulatory pressure.
Technical assessment recognized in highly regulated, mission-critical environments — the pentest that finds what nobody had found before.
Douglas Lopes
Founder · CEO · intrus.io
/crivo · integrity program
of pentester candidates fail our Crivo screening
NDAs work in court. They don't work day-to-day. Before first access, every pentester on our team passes background, psychometric profile and integrity testing.
/faq
Yes. We audit the signature flow, prescription integrity and pharmacist validation.
Yes. When data is used clinically (oximetry, ECG, glycemia), we audit device integrity and channel.
/contact
Schedule a confidential meeting. Within 48h we'll send a proposal with scope, timeline and pricing.