Healthcare & University OSINT Assessment
Sector-specific OSINT assessment focused on healthcare institutions and universities, providing exposure analysis and external threat mapping.
In scope
- Healthcare data exposure review
- University open-source intelligence scan
- Research asset mapping
- Public exposure snapshot
- Sector-specific threat assessment
You receive
- Sector-Specific OSINT Report
- Exposure findings
- Risk mitigation strategies
Tiers
Choose the depth.
Healthcare Assessment
$6.5K
Passive OSINT for one healthcare organization with up to 3 root domains and up to 5 facilities: exposed patient-data indicators, clinical and staff portal exposure, leaked staff credentials, vendor-related exposure, and healthcare threat actor activity.
- domains
- 3
- Sites
- 5
- Healthcare data exposure review
- External asset and portal mapping for up to 3 root domains
- Leaked staff credential search
- Healthcare sector threat assessment
- Sector-specific report with mitigation strategies
- — Active scanning or penetration testing
- — Medical device security testing
- — Compliance assessment of any kind
- — Health systems with more than 5 facilities
University Assessment
$6.5K
Passive OSINT for one academic institution with up to 3 root domains and up to 5 campuses: research asset mapping, exposed student and faculty data, departmental shadow IT on subdomains, leaked credentials, and academic-sector threat activity.
- domains
- 3
- Sites
- 5
- University open-source intelligence scan
- Research asset and lab exposure mapping
- Departmental subdomain and shadow IT discovery
- Leaked student and faculty credential search
- Sector-specific report with mitigation strategies
- — Active scanning or penetration testing
- — Assessment of individual researchers or executives
- — Compliance assessment of any kind
- — University systems with more than 5 campuses
Members: engagement coupons from the CISO Marketplace coupon book apply to services. There is no blanket discount.
What's inside this engagement
Phase by phase.
How a security assessment engagement runs, what happens in each phase and what you see. Exact scope, tier and timeline are fixed in your proposal and SOW.
01Scoping
Systems, sites, stakeholders and the question the assessment must answer.
You see · Your objectives and constraints.
02Discovery & evidence
Documents, configurations and interviews, plus technical testing where the service includes it.
You see · Access and time with key people.
03Analysis
Findings rated by risk to your business, not by a generic score.
You see · A prioritized view of your risk.
04Report & debrief
Executive summary, findings and a remediation roadmap, walked through with your team.
You see · The report and the debrief.
Commercials
From first call to final report.
- 01
Scoping call
A practitioner, not a salesperson, walks through targets, constraints and what a good outcome looks like for you.
- 02
Proposal & rules of engagement
A fixed-scope proposal with tier, price and deliverables. Rules of engagement, contacts and out-of-bounds systems are agreed in writing.
- 03
Sign, then start
MSA and SOW are signed electronically and the deposit is paid. Only then does testing begin.
- 04
Execution
Testing runs to the agreed plan. Critical findings are escalated as they are found; you don't wait for the report.
- 05
Report & debrief
An executive summary plus technical findings with evidence, reproduction steps and fixes, walked through with your team.
- 06
Retest
Where the tier includes it, we verify your fixes and reissue the report, so auditors and customers see the issues closed.
Timelines are set per engagement in the SOW.
Related
Dark Web & Credential Exposure Monitoring
Stolen credentials and infostealer logs are the most common way in. We monitor breach corpuses, infostealer markets, paste sites and criminal forums for your domains, executives and key vendors, validate what we find, and tell you what to reset and why — analyst-reviewed alerts rather than a raw feed.
Domain Profiler (OSINT) External
Domain Profiler (OSINT) - External is a tool that provides a comprehensive footprint analysis of your domain, identifying exposed data and vulnerabilities across multiple public sources.
Mergers & Acquisitions OSINT Pre-Assessment
Provides critical pre-acquisition intelligence by assessing a target organizations public exposure, risks, and external footprint before finalizing M&A deals.
Research
Latest from the blog

ai-security · Apr 25, 2026
Healthcare Wasn't Ready for AI-Powered Attacks — and the Evidence Is Already In
A ransomware attack interrupted chemotherapy infusions at Brockton Hospital in April 2026. Spring Lake Park School shut down. A new generation of AI-accelerated attack tooling — including the capabilities unlocked by Project Glasswing — is compressing attack timelines in ways healthcare security programs weren't designed to handle. The gap is widening.

ai-security · Feb 25, 2026
Black Box in the Control Room: AI in Critical Infrastructure, Explainability Failures, and the Audit Gap CISOs Can't Ignore
AI is making life-or-death decisions in hospitals, power grids, and water treatment plants — and no one can explain how. The explainability crisis isn't academic. It's a compliance violation, a liability exposure, and a safety risk that regulators are about to enforce.
compliance · Jul 3, 2025
Healthcare Security Micro-Tools: Navigating HIPAA, Medical Device Risks, and Digital Twin Security
As healthcare technology rapidly evolves with AI, robotics, and telehealth, specialized micro-tools for HIPAA compliance, medical device security, and digital twin risk management are helping CISOs address unprecedented security challenges.
Start an engagement