Case Study | Healthcare
Securing 4.5 Lakh Patient Records Across a 5-Hospital Chain — VAPT, DPDP & Ransomware Resilience
Size: 1,200+ staff
Location: NCR, Pune, Hyderabad
Timeline: 4 months
Client Background
A multi-city private hospital chain operating 5 hospitals across NCR, Pune, and Hyderabad with 1,200+ clinical and administrative staff. The client's Hospital Information System (HIS) and Electronic Medical Records (EMR) platform stored over 4.5 lakh patient records including diagnostic data, prescriptions, and financial information.
The Challenge
A ransomware staging attempt on the PACS server triggered this engagement. Attackers had been in the network for 11 days before detection. The near-miss exposed critical gaps:
- Unpatched medical devices running Windows 7/XP with no endpoint protection
- Flat network architecture — PACS, EMR, and billing on the same VLAN
- No incident response plan — breach discovered by an external researcher, not internal monitoring
- DPDP Act exposure — patient health data is sensitive personal data with mandatory breach notification
MDIT's Approach
Immediate Response (Week 1)
- Emergency threat hunt across all endpoints to confirm attacker eviction
- Forensic analysis of compromised PACS server — initial access via exposed RDP (port 3389)
- Network isolation of PACS VLAN while maintaining clinical operations
Comprehensive VAPT (Weeks 2–6)
- Internal & external network pentest — 180 IPs, 12 critical systems
- HIS/EMR web application VAPT — SQL injection in patient search module (CVSS 9.8)
- Medical IoT/device security review — 67 networked devices assessed
- Wi-Fi security audit across all hospital floors
Architecture Hardening (Weeks 7–12)
- Network segmentation: 6 VLANs (clinical, admin, PACS, IoT, guest, management)
- Zero-trust access controls for HIS using MFA + conditional access
- EDR deployment across 340 Windows endpoints
- 3-2-1 backup architecture with air-gapped offline copy
DPDP Compliance (Weeks 10–16)
- Patient data inventory and classification across all 5 hospitals
- Privacy notice and consent mechanism review
- Data breach notification procedure (72-hour CERT-In reporting workflow)
- Staff training on DPDP Act 2023 obligations
Results
“After the near-miss, we needed a partner who understood both the clinical environment and cyber threats. MDIT's team spent time learning our workflows before recommending any changes — that made all the difference.”
— Head of IT, Client Hospital Chain (name withheld)
Is Your Patient Data Protected?
Healthcare is the #1 ransomware target in India. MDIT offers a healthcare-specific VAPT + DPDP compliance package from ₹75,000.
Related MDIT Services
- Vulnerability Assessment & Penetration Testing — Comprehensive security testing for hospitals and healthcare networks
- DPDP Act Compliance Services — End-to-end Digital Personal Data Protection Act compliance for healthcare organisations
- Cybersecurity for Healthcare — Specialised security solutions for hospitals, clinics, and health-tech companies
