- Hospitals fail assessments for structural reasons: flat networks, unsupported clinical systems, and open vendor remote access, not just missing patches.
- A scanner like Nessus finds the easy misconfigurations. Manual testing finds the chained path that actually reaches an EMR database.
- DHA, DoH and MOHAP reviews increasingly expect evidence of testing and remediation, not a policy document alone.
- Remediation and retesting are where the risk actually goes down. A report nobody acts on changes nothing.
What a VAPT Engagement Actually Covers in a Hospital
Vulnerability assessment and penetration testing are two different disciplines run together. The assessment side is broad and largely automated: scan every reachable host, map open services, flag known CVEs, and score them. The testing side is narrow and manual: pick a subset of findings and prove, by actually exploiting them, whether they lead somewhere that matters.
In a healthcare environment the scope usually spans five areas: the external perimeter (patient portals, telehealth endpoints, remote access gateways), the internal corporate network, the web applications and APIs that sit in front of the hospital information system (HIS) and electronic medical records (EMR), wireless networks across clinical floors, and segmentation testing between the corporate network and the VLANs carrying biomedical and imaging equipment. A structured VAPT programme defines which of these are in scope, whether testing is black box, grey box or white box, and what a passing result actually means before the engagement starts, not after the report lands.
Why Hospitals Fail These Assessments More Than Other Sectors
The pattern in UAE healthcare is structural, not a matter of one careless administrator. Imaging and diagnostic equipment often runs an operating system the manufacturer stopped patching years ago, because the device's regulatory approval is tied to that specific software build and an OS update can void it. Infusion pumps, PACS workstations and lab analysers frequently sit on the same flat network as reception PCs and finance systems, because segmentation was never designed in and retrofitting it means downtime nobody wants to schedule. OEM support contracts for clinical devices often come with a standing remote access account, and those accounts outlive the support contract far more often than they should.
None of this is unique to any one hospital. It is what you find, in some combination, in most healthcare networks that have grown over a decade of vendor procurement without a unifying security architecture. That is exactly why segmentation testing, not just a vulnerability scan of the corporate LAN, has to be part of the scope.
Automated Scanning and Manual Testing Answer Different Questions
Where a Scanner Stops and a Human Starts
A vulnerability scanner tells you what is exposed and how it is rated. Nessus-based scanning is a reasonable baseline for that: broad coverage, CVSS scores, and a defensible audit trail showing the organisation looked. What it will not tell you is whether a low-severity misconfiguration on a print server, combined with a shared local administrator password and a database connection string left in a config file, gets an attacker from the guest network into the record system holding patient diagnoses. That chain only shows up when someone tries to build it by hand. This is the actual argument for manual testing over scan-and-report: not that automation is unreliable, but that automation cannot chain.
What DHA, DoH, MOHAP and PDPL Reviews Actually Ask For
Regulatory expectations for healthcare providers in the UAE are less about naming a specific control and more about evidence that a testing and remediation cycle exists and runs on a schedule. Assessors reviewing a Dubai Health Authority or Department of Health Abu Dhabi licensed facility typically want to see a current VAPT report, a remediation tracker showing findings closed against a timeline, and proof of retest for anything rated high or critical. The UAE's federal data protection law adds a separate but related obligation: personal data, and patient data is about as sensitive as personal data gets, has to be protected by measures appropriate to the risk, and a documented testing programme is the standard way an organisation demonstrates that it took the risk seriously rather than asserting it did. None of this substitutes for a compliance review with counsel or the relevant authority; it is a description of what assessors tend to ask for, not a legal requirement checklist.
Findings That Recur Across Healthcare Assessments
A few findings show up often enough in this sector to be worth naming directly, without pretending any single one is unique to a specific hospital: default or vendor-set credentials still active on biomedical devices and network infrastructure; unpatched Windows builds on imaging workstations and building management systems that IT does not consider "theirs" to patch; RDP or a VPN gateway reachable from the internet with no multi-factor authentication in front of it; third-party vendor remote access that was never revoked after a contract ended; and service accounts inside the EMR environment with far more privilege than the task they perform requires. Individually most of these are low or medium severity. Chained together, they are usually how a ransomware operator gets from initial access to encrypting a record system.
Ransomware Against a Hospital Is Usually a Segmentation Failure
Ransomware groups that have hit healthcare targets have not generally needed a novel exploit to do it. One exposed remote access point, one unpatched edge device, and a flat network that lets that foothold reach imaging systems and the EMR is enough. The question a VAPT engagement is actually answering is whether that path exists today, before an attacker finds it rather than after. This is also why a growing share of engagements in this sector are failing to catch what matters: scope gets narrowed to the easy parts of the network and the segmentation test between corporate IT and clinical VLANs gets dropped to save time or budget, which removes the one test most likely to find the path a ransomware operator would actually use.
Remediation and Retesting Decide Whether the Exercise Was Worth Running
Prioritisation should follow exploitability and asset criticality together, not CVSS score alone. A medium-rated finding on a system holding patient records deserves faster attention than a critical-rated finding on an isolated test server nobody depends on. A workable remediation SLA ties severity to a deadline, for example critical findings closed within a defined short window and high findings within a longer one, with the timeline agreed before the engagement starts so remediation does not stall on debate about urgency. Retesting is not optional: a finding marked "fixed" without verification is a claim, not a fact, and it is exactly the gap an auditor or an attacker will test first. Organisations that treat VAPT as an annual paperwork exercise, run it once, file the PDF, and never confirm the fixes, get very little of the actual risk reduction the exercise is capable of producing.
Choosing a VAPT Provider for Healthcare in the UAE
A few things separate a provider that will find what matters from one that will hand back a scan printout with a cover page:
- Manual exploitation capability behind the scan, evidenced by OSCP-level or equivalent certification on the team, not just a licence for a scanning tool.
- Familiarity with healthcare-specific systems: HIS/EMR platforms, PACS, HL7 interfaces, and the operational reality of biomedical devices that cannot simply be patched or rebooted on demand.
- Segmentation testing between corporate IT and clinical or biomedical VLANs included in scope by default, not offered as a costly add-on.
- A fixed retest built into the engagement, so remediation is verified rather than assumed.
- Findings mapped to what DHA, DoH, MOHAP or an ISO 27001 auditor will actually ask to see, so the report doubles as evidence rather than needing to be translated after the fact.