# Medical Device Security Assessment

> From $32K · Offensive Security · https://cisomarketplace.services/services/medical-device-security-assessment

Specialized security testing for medical devices and healthcare technology, focusing on patient safety, data security, and regulatory compliance.

## In scope

- Device firmware analysis
- Wireless protocol testing
- Patient data security review
- Authentication mechanism testing
- Remote access security
- Regulatory compliance check
- Third-party component analysis

## Deliverables

- Medical device security report
- HIPAA compliance analysis
- Patient safety risk assessment
- Data security recommendations
- Regulatory compliance guidance
- Remediation roadmap
- 90-day retest period

## Tiers

### Core Medical Device Assessment: $32K

Security test of 1 device model over 1 communication interface: firmware analysis, authentication testing, patient data security review, remote access check, and HIPAA-oriented compliance review. Includes a retest.

Limits: devices 1

Includes:
- Testing of 1 device model on 1 interface (e.g. Ethernet or USB)
- Firmware analysis
- Authentication mechanism testing
- Patient data security review
- HIPAA compliance analysis
- Report, remediation roadmap, 90-day retest period

Excludes:
- Wireless protocol testing (BLE, Wi-Fi, proprietary RF)
- Third-party component / SBOM analysis
- Companion app and cloud service testing
- Additional device models

### Advanced Medical Device Assessment: $48K

Security test of 1 device model across all its interfaces. Adds wireless protocol testing, remote access and update channel testing, third-party component analysis, patient safety risk assessment, and detailed regulatory compliance guidance. Includes a retest.

Limits: devices 1

Includes:
- Everything in the Core tier, across all device interfaces
- Wireless protocol testing
- Remote access and update channel security testing
- Third-party component analysis
- Patient safety risk assessment
- Regulatory compliance guidance

Excludes:
- Additional device models or variants
- Retest beyond 90 days
- Regulatory submission document authoring

### Enterprise Medical Device Assessment: $65K

Security test of up to 3 device models or variants across all interfaces. Adds firmware reverse engineering and exploit development for confirmed findings, a cross-device platform review, and an extended retest period.

Limits: devices 3

Includes:
- Everything in the Advanced tier, for up to 3 device models
- Firmware reverse engineering and exploit proof-of-concepts
- Shared platform / component review across devices
- Retest period extended to 180 days
- Engineering team readout

Excludes:
- Regulatory submission document authoring
- Hospital network deployment assessment
- More than 3 device models (scoped separately)

## Terms

Starting price shown is the lowest published tier. A written proposal fixes scope, tier and price before anything is signed. Timeline is set in the SOW.

Scope this engagement: https://cisomarketplace.services/scope?service=medical-device-security-assessment
