Securing Patient Data: VAPT & DPDP Compliance for a Multi-City Hospital Chain

Case Study | Healthcare

Securing 4.5 Lakh Patient Records Across a 5-Hospital Chain — VAPT, DPDP & Ransomware Resilience

Industry: Healthcare
Size: 1,200+ staff
Location: NCR, Pune, Hyderabad
Timeline: 4 months

Client Background

A multi-city private hospital chain operating 5 hospitals across NCR, Pune, and Hyderabad with 1,200+ clinical and administrative staff. The client's Hospital Information System (HIS) and Electronic Medical Records (EMR) platform stored over 4.5 lakh patient records including diagnostic data, prescriptions, and financial information.

The Challenge

A ransomware staging attempt on the PACS server triggered this engagement. Attackers had been in the network for 11 days before detection. The near-miss exposed critical gaps:

  • Unpatched medical devices running Windows 7/XP with no endpoint protection
  • Flat network architecture — PACS, EMR, and billing on the same VLAN
  • No incident response plan — breach discovered by an external researcher, not internal monitoring
  • DPDP Act exposure — patient health data is sensitive personal data with mandatory breach notification

MDIT's Approach

Immediate Response (Week 1)

  • Emergency threat hunt across all endpoints to confirm attacker eviction
  • Forensic analysis of compromised PACS server — initial access via exposed RDP (port 3389)
  • Network isolation of PACS VLAN while maintaining clinical operations

Comprehensive VAPT (Weeks 2–6)

  • Internal & external network pentest — 180 IPs, 12 critical systems
  • HIS/EMR web application VAPT — SQL injection in patient search module (CVSS 9.8)
  • Medical IoT/device security review — 67 networked devices assessed
  • Wi-Fi security audit across all hospital floors

Architecture Hardening (Weeks 7–12)

  • Network segmentation: 6 VLANs (clinical, admin, PACS, IoT, guest, management)
  • Zero-trust access controls for HIS using MFA + conditional access
  • EDR deployment across 340 Windows endpoints
  • 3-2-1 backup architecture with air-gapped offline copy

DPDP Compliance (Weeks 10–16)

  • Patient data inventory and classification across all 5 hospitals
  • Privacy notice and consent mechanism review
  • Data breach notification procedure (72-hour CERT-In reporting workflow)
  • Staff training on DPDP Act 2023 obligations

Results

0
Data breaches since engagement
4.5L
Patient records protected
DPDP ✓
Act readiness achieved
11→0
Days attacker dwell time with new SOC

“After the near-miss, we needed a partner who understood both the clinical environment and cyber threats. MDIT's team spent time learning our workflows before recommending any changes — that made all the difference.”

— Head of IT, Client Hospital Chain (name withheld)

Is Your Patient Data Protected?

Healthcare is the #1 ransomware target in India. MDIT offers a healthcare-specific VAPT + DPDP compliance package from ₹75,000.

Get Healthcare VAPT Quote →

Related MDIT Services

Discuss a Similar Healthcare Security Engagement →

Free Consult