Patient portal IDOR discovered
Tester accesses another patient's appointments via parameter tampering. Finding enters CA-5; API authorization fix and retest close the item before public disclosure risk grows.
CA-8 requires conducting penetration testing on the system at a defined frequency and using defined rules of engagement. Pen tests go beyond vulnerability scanning (RA-5) by attempting exploitation paths that could expose ePHI — phishing to EHR, lateral movement from clinic Wi-Fi, or API abuse on patient portals. Results feed CA-5 remediation and improve detection (AU/IR).
Periodically and safely exercise real-world attack paths against ePHI environments, then remediate and retest significant findings under authorized rules of engagement.
How this control shows up in healthcare and HIPAA-covered environments.
Tester accesses another patient's appointments via parameter tampering. Finding enters CA-5; API authorization fix and retest close the item before public disclosure risk grows.
From a compromised workstation, tester reaches imaging shares. Results drive microsegmentation and EDR hardening — not only patch tickets.
New attack surface (SSO, APIs) is explicitly scoped; prior on-prem-only testing is recognized as insufficient.
Auditors distinguish scanning from exploitation testing. Show RoE, authorization, and closed-loop remediation — not only a glossy PDF.
How this NIST control supports HIPAA Security Rule expectations.
RA-5 finds vulnerabilities; CA-8 attempts to exploit and chain them under controlled conditions to validate real risk.
Yes if skilled and independent enough of the builders; many orgs still use external testers periodically for objectivity.
Follow emergency stop in RoE, treat as an incident if patient care is affected, and improve scoping next cycle.
Related controls that commonly accompany CA-8.
Our auditors map NIST SP 800-53 controls to your HIPAA Security Rule program — policies, technical evidence, and audit readiness.