Sample Penetration Test Report: Healthcare

Contributors

Shantanoo Govilkar
Shantanoo Govilkar
SVP Strategic Solutions Risk & Cybersecurity Solutions

Introduction

Curious what a pen test report should actually hand you? Here's a full sample, built for a regional health system with hospitals, clinics, telehealth, and connected medical devices.

See Every Section Your Team Receives After a DivIHN Pen Test

Risk Impact Brief: A plain-language summary written for leadership and the board

Attack Path Narrative: How one phished email chains into patient-care systems and ePHI

Detailed Findings: Evidence, CVSS scoring, and step-by-step fixes for each finding

Remediation Roadmap: Prioritized work grouped into three time-boxed windows

Compliance Map: Every finding tied to the HIPAA Security Rule, NIST SP 800-53, and HITRUST CSF

Attestation Letter: Proof of remediation after retest

Sample-Penetration-Test-Report-Healthcare
Back
to Top