Introduction
Curious what a pen test report should actually hand you? Here's a full sample, built for a regional health system with hospitals, clinics, telehealth, and connected medical devices.
See Every Section Your Team Receives After a DivIHN Pen Test
Risk Impact Brief: A plain-language summary written for leadership and the board
Attack Path Narrative: How one phished email chains into patient-care systems and ePHI
Detailed Findings: Evidence, CVSS scoring, and step-by-step fixes for each finding
Remediation Roadmap: Prioritized work grouped into three time-boxed windows
Compliance Map: Every finding tied to the HIPAA Security Rule, NIST SP 800-53, and HITRUST CSF
Attestation Letter: Proof of remediation after retest