PHI sits four hops from your portal

Trident maps portal to database, proves which hop actually reaches patient data, and shows the one fix that severs it.

Patient portal sign-in
Portal service role
Choke point
Peered data network
Patient record replica
Every hop is one the portal already trusts.

Which route actually arrives

highCWE-284

A portal service role reaches a copy of the record store

EntryPortal sessionImpactPatient records

Reach proven, no record read

Patient portal
Appointment service — stops at scheduling
Portal service role — reaches the replica
Billing export — de-identified only
Message inbox — no data-network route
Patient records
Several routes leave the portal. One arrives.

How the engagement runs

01

Recon

Read-only roles inventory services, identities, and record stores.

02

Path mapping

Exposure and identity edges resolve into ranked paths.

03

Exploit validation

Sanitized probes prove reach without touching a record.

04

Draft PR + report

The choke-point fix opens as a draft pull request.

The report is the deliverable

The engagement above, typeset the way a compliance reviewer expects to receive it.

  • Read-only cloud roles with scoped, expiring credentials
  • Probes are sanitized — evidence never contains PHI
  • Every finding carries its reproduction and its fix
  • Retest evidence attached once the patch lands

Trident tests technical safeguards. Trident does not certify HIPAA compliance.

Preparing for a HIPAA evaluation? See the safeguard mapping →

Where PHI actually becomes reachable

The copies are usually the problem. The primary store is normally the best-defended thing in the estate.

PHI exposure

Healthcare systems leak protected health information through access control far more often than through exotic exploitation. Trident tests the paths that actually reach PHI, and shows which single change severs the most of them. The flaw on this page is representative: a portal service role scoped wider than the portal, ending at a replica of the record store.

Record-level authorization
Whether a clinical or administrative user can reach records outside their care relationship, department or facility by manipulating identifiers directly.
Patient portal isolation
Cross-patient access in patient-facing applications, including dependants, proxy access, and the account-recovery flows that most often collapse the boundary between two patients.
Integration surfaces
HL7, FHIR and partner API endpoints, which often carry weaker authorization because they assumed a trusted network that no longer exists.
Derived PHI stores
Analytics warehouses, backups, exports and test environments seeded with production data — copies that inherit sensitivity without the source controls.
Cloud paths to PHI
Which identities, workloads and networks can reach PHI stores, and which single policy change removes the largest number of those routes.

Questions about testing near patient data

Reach is proven, records are not read. Testing uses synthetic or de-identified accounts, and demonstrating a cross-patient authorization flaw needs two test identities rather than a real chart.

Know which paths reach patient records.

See the ranked paths to your PHI, each ending in a fix.

Trident does not certify HIPAA compliance.