A controlled process.
Evidence at every step.
01Agree the boundary
Define systems, identities, objectives, permissions and operating constraints.
02Model the path
Connect relevant attack scenarios to the services and data you need to protect.
03Test under control
Use synthetic patient identities and agreed data cohorts. Name a clinical escalation contact, set request limits and exclude treatment-affecting actions unless separately authorised. Stop immediately if testing encounters unexpected live clinical data or threatens a care workflow.
04Document the result
Record actions, responses, effective controls and the limits of access gained.
05Verify the repair
Prioritise findings, assign ownership and retest agreed acceptance criteria.