Home / Purple Team Services / Healthcare Sector
Healthcare Sector
Three Real-World Purple Team Engagements | Fully Anonymised | ISO 17025 Accredited Methodology
ISO 17025 Accredited · MITRE ATT&CK v15 · All engagements conducted under explicit written authorisation
Sector
Healthcare
Engagement
Purple Team Exercise
ATT&CK Tactics
MITRE ATT&CK v15
Location
About These Case Studies
The following case studies describe real purple team engagements conducted by GLI Secure across healthcare sector organisations. All identifying details — organisation names, locations, system names, and personnel — have been fully anonymised. Statistical outcomes, detection improvements, and regulatory findings are accurate as documented during and after each engagement.
All purple team exercises described in this document were conducted under explicit written authorisation from the client organisation, using GLI Secure’s ISO 17025-accredited testing methodology. MITRE ATT&CK technique IDs are referenced as documented in ATT&CK Enterprise Framework v15.
State & Local Government
Confidentiality Notice: These case studies anonymised; any resemblance to specific organisations is coincidental.
Case Study HC-CS-01
EHR Ransomware Simulation — Regional Hospital Network
Testing whether a 12-hospital system could detect and contain a ransomware attack before clinical operations were disrupted
Organisation
A 12-hospital regional health system operating across three US states (anonymised)
Sector
Healthcare — Acute care, outpatient, and specialist services
Location
Southeastern United States
Engagement
Purple Team Exercise — EHR Ransomware Emulation
Duration
6 weeks (3-week planning, 2-day exercise, 1-week remediation validation)
Frameworks
HIPAA Security Rule §164.308 | HITRUST CSF v11 | MITRE ATT&CK Enterprise v15 | NHS DSPT Objective D (UK-aligned subsidiary)
The Situation
The health system had experienced a near-miss ransomware event 18 months prior. A Conti affiliate had gained access through a compromised vendor VPN account and remained inside the network for 23 days before a routine audit flagged unusual activity. The CISO was honest with the board: they had been lucky, not good.
Following the incident, the organisation invested significantly in EDR tooling, a new SIEM, and a dedicated SOC team. Eighteen months later, the board wanted independent evidence that the investment had actually improved detection capability — not just documentation that the tools were in place.
The organisation had never conducted a purple team exercise. Annual penetration tests and quarterly vulnerability scans told them whether attackers could get in — not whether the SOC could catch them when they did.
Core Challenge
Determine whether 18 months of security investment had produced measurable improvement in the ability to detect ransomware precursor activity — specifically the lateral movement and backup targeting techniques that preceded the prior near-miss.
What GLI Secure Did
We began with a threat intelligence review identifying the specific MITRE ATT&CK techniques used by Conti and BlackCat affiliates against hospital networks of similar size, producing a scenario grounded in the actual threat the organisation faced.
Phase 1 tested detection of initial access and lateral movement across the administrative network. Phase 2 tested ransomware precursor activity: credential harvesting, backup enumeration, and simulated encryption of isolated test file shares.
Our red team operated in full transparency: every technique was announced before execution, the detection hypothesis documented in advance. This allowed the blue team to test detections, identify specifically why missed ones failed, and begin tuning during the exercise.
The Purple Team Approach
Threat Intelligence Scoping
Mapped the 12 MITRE ATT&CK techniques most used by Conti and BlackCat affiliates against US hospital networks based on FBI IC3 2025 healthcare threat data. Selected 8 techniques for the exercise based on the Epic Hyperspace EHR environment and network architecture.
Detection Hypothesis Documentation
Before any technique was executed, the blue team documented the expected detection: which tool, which alert, within what timeframe. This exposed 3 techniques for which no detection rule existed — before the exercise began.
Phase 1 — Initial Access and Lateral Movement
Executed 4 techniques across initial access and lateral movement stages. Red team used a simulated compromised vendor credential, then moved laterally using SMB and RDP techniques consistent with the prior near-miss incident.
Phase 2 — Ransomware Precursor Activity
Executed 4 techniques simulating ransomware staging: credential dumping from LSASS, shadow copy enumeration, backup server access, and simulated encryption of isolated test shares. Each technique was executed, detection measured, and SOC response time recorded.
Real-Time Detection Tuning
For the 3 techniques that failed to generate alerts, detection engineers wrote new SIEM rules during the exercise. Two new rules were validated and confirmed functional before the exercise concluded.
Re-Test Validation
5 days after remediation, we re-executed all 8 techniques. Results were compared against the initial exercise to produce a measurable before/after improvement metric.
MITRE ATT&CK Techniques Tested
| ATT&CK ID | Technique | Detection Result |
|---|---|---|
| T1566.001 | Spear Phishing Attachment |
Detected
Alert fired in 4 minutes. Within target. |
| T1078 | Valid Accounts (Vendor VPN) |
PARTIAL
Alert fired at 47 minutes. Exceeded 15-minute target. |
| T1021.002 | SMB/Windows Admin Shares |
NOT DETECTED
No rule existed for this lateral movement technique. |
| T1003.001 | LSASS Memory Credential Dump |
DETECTED
EDR alert in 2 minutes. Excellent result. |
| T1490 | Inhibit System Recovery (Shadow Copies) |
Not Detected
Logging not enabled on backup servers. |
| T1486 | Data Encrypted for Impact (Test Share) |
Detected
Ransomware behavioural detection in 3 minutes. |
| T1083 | File and Directory Discovery |
Not Detected
No UEBA baseline for file enumeration volume. |
| T1021.001 | Remote Desktop Protocol |
PARTIAL
Alert fired but required manual correlation. MTTD 38 minutes. |
Key Findings
Medium
Detection Coverage:
5 of 8 techniques detected (62.5%) before tuning — improved to 87.5% after same-day tuning and remediation.
Critical
Critical Gap: Backup Server Logging:
Backup servers had no log forwarding to the SIEM. An attacker targeting backup infrastructure would have been completely invisible — the most critical ransomware precursor activity.
High
Vendor Account Monitoring:
Vendor VPN credential alert fired at 47 minutes — far too slow. Alert threshold was set too conservatively for the exact technique used in the prior near-miss incident.
Critical
SMB Lateral Movement Gap:
No detection rule existed for SMB-based lateral movement — the primary technique used in 73% of healthcare ransomware attacks per FBI IC3 2025.
Medium
EDR Strength:
EDR performed excellently on endpoint-level techniques. LSASS dump and ransomware behavioural detection were both sub-5-minute. The gap was network-level detection, not endpoint.
Measurable Outcomes
| Detection Coverage Before | 62.5% — 5 of 8 techniques detected |
| Detection Coverage After | 87.5% — 7 of 8 techniques detected |
| Mean MTTD Before | 24.4 minutes average |
| Mean MTTD After | 8.1 minutes — 67% improvement |
| Critical Gaps Closed | 3: backup logging, SMB detection, vendor MTTD |
| New SIEM Rules Written | 6 rules validated during and after exercise |
| HITRUST CSF Evidence | §09.ab control evidence accepted by assessor |
Regulatory Impact
The exercise produced direct evidence for three HIPAA Security Rule requirements frequently cited in OCR audit findings: §164.308(a)(5) Security Awareness and Training, §164.308(a)(6) Security Incident Procedures, and §164.308(a)(7) Contingency Plan.
The discovery that backup server logging was not configured — despite being documented as complete in the HITRUST CSF assessment — highlighted the gap between self-attestation and operational reality. Addressing it proactively provides a demonstrably stronger HIPAA compliance position than the prior documentation-only approach.
The exercise report was accepted by the organisation’s HITRUST assessor as supporting evidence for Control Category 09.ab (Monitoring System Use), reducing the evidence burden for the next annual HITRUST cycle.
“
We spent 18 months and significant budget building what we thought was a mature detection programme. The purple team exercise showed us that we had excellent tools pointed in slightly the wrong direction. The backup server logging gap — invisible to every prior audit — would have given an attacker complete freedom to destroy our recovery capability. Finding that in a controlled exercise rather than during an actual ransomware attack was worth every dollar we spent.
— CISO, Regional Health System (anonymised)
Key Takeaways
- Penetration testing and purple team exercises answer different questions. Annual pen tests had been passed for years. The purple team exercise found gaps that pen testing was not designed to surface.
- Backup server monitoring is the highest-priority detection gap in healthcare ransomware defence. If an attacker can enumerate and target backups without generating an alert, recovery capability is at risk.
- HITRUST self-attestation and operational reality diverge more often than organisations expect. Purple team testing validates the operational truth behind documented controls.
- Same-day detection tuning is one of the highest-value outcomes of purple team methodology. Three detection rules were written and validated during the exercise itself.
Ready to test your Healthcare security defences?
Case Study HC-CS-02
IoMT Lateral Movement — Academic Medical Centre
Testing whether clinical network segmentation prevented pivot from IT to Internet of Medical Things infrastructure
Organisation
A 900-bed academic medical centre with 14,000 connected devices (anonymised)
Sector
Healthcare — Academic medical centre, Level 1 trauma, research hospital
Location
Midwest United States
Engagement
Purple Team Exercise — IoMT Lateral Movement and Clinical Network Segmentation
Duration
8 weeks (4-week planning including device inventory, 3-day exercise, 1-week remediation)
Frameworks
HIPAA Security Rule §164.312 | FDA Pre-Market Cybersecurity Guidance 2023 | IEC 62443-4-2 | MITRE ATT&CK Enterprise v15 | DTAC (UK subsidiary)
The Situation
The medical centre’s biomedical engineering team had found that of 14,000 connected devices operating across the hospital network, only 3,200 appeared in the IT security team’s asset register. The remaining 10,800 devices — infusion pumps, patient monitors, imaging systems, nurse call systems — were connected to the network but invisible to the security operations centre.
The CISO had invested in network segmentation between administrative and clinical VLANs following a prior security assessment, but nobody had ever tested whether that segmentation actually held under a realistic attack scenario. The specific concern was a Lazarus Group attack pattern documented by CISA in 2024: IT workstation compromise, lateral movement to clinical network via misconfigured firewall rules, then access to medical device control interfaces.
The medical centre wanted to know whether their environment was vulnerable to this specific attack chain.
Core Challenge
Verify whether an attacker who compromised the administrative IT network could reach and interact with clinical IoMT devices, and whether any such movement would be detected by existing security monitoring.
What GLI Secure Did
We began with a three-week device discovery phase, working with biomedical engineering to enumerate all connected devices. This produced the first complete device inventory: 14,200 devices across 47 VLANs, with 62 running end-of-life operating systems.
The exercise tested the segmentation boundary between IT and clinical networks, simulating an attacker who had compromised an IT workstation attempting to pivot to clinical infrastructure — using Lazarus Group healthcare attack techniques.
An isolated test PLC was used for all demonstrations of device interaction impact. No production medical devices were ever interacted with — patient safety was the absolute constraint around which every testing decision was made.
The Purple Team Approach
Device Inventory and Risk Classification
Catalogued all 14,200 devices by risk tier: 62 end-of-life devices with critical CVEs in Tier 1, 847 unmonitored devices with no logging in Tier 2. First complete IoMT asset register the organisation had ever possessed.
Segmentation Architecture Review
Reviewed all firewall rules between administrative and clinical VLANs. Identified 7 legacy rules creating unintended connectivity — created years earlier for operational convenience and never reviewed.
Lateral Movement Simulation
From a simulated compromised IT workstation, tested whether the 7 legacy firewall rules permitted lateral movement to clinical VLANs. Four of seven permitted connectivity; three were exploitable for lateral movement.
Clinical Network Enumeration
Once across the segmentation boundary, tested whether the clinical network could be enumerated. Result: 10,800 previously unknown devices became visible to the simulated attacker.
Test Device Interaction (Isolated Environment)
Using an isolated test infusion pump outside the production network, demonstrated access level achievable. Interaction was limited to reading device configuration — no parameters were modified.
Detection Validation
Tested whether lateral movement, enumeration, or clinical network access activities generated any alerts. Result: zero alerts for any activity after the initial IT workstation compromise.
MITRE ATT&CK Techniques Tested
| ATT&CK ID | Technique | Detection Result |
|---|---|---|
| T1046 | Network Service Scanning |
Not Detected
No anomaly detection for internal scanning traffic. |
| T1021.001 | Remote Desktop Protocol |
Detected
EDR alert on IT workstation. MTTD 6 minutes. |
| T0812 | Default Credentials (ICS) |
Not Detected
No credential monitoring on clinical devices. |
| T1190 | Exploit Public-Facing Application |
PARTIAL
WAF detected but did not block. Alert not actioned. |
| T1135 | Network Share Discovery |
Not Detected
No alerting on clinical VLAN enumeration. |
| T0866 | Exploitation of Remote Services (ICS) |
Not Detected
Clinical network has no security monitoring. |
Key Findings
Critical
Zero Clinical Network Monitoring:
The clinical network — 14,200 connected devices — had no security monitoring infrastructure. An attacker who reached the clinical network could operate indefinitely without generating any alert.
Critical
4 Exploitable Firewall Misconfigurations:
Four legacy firewall rules permitted lateral movement from the administrative network to clinical VLANs. These rules had never been reviewed and were not visible in current network documentation.
High
10,800 Unregistered Devices:
62% of connected clinical devices were absent from the security team’s asset register. You cannot monitor or protect assets you do not know exist.
High
62 End-of-Life Devices with Critical CVEs:
Cannot be patched due to FDA clearance constraints — requiring compensating controls aligned to IEC 62443-4-2.
medium
WAF Alert Not Actioned:
A WAF alert generated during the exercise was not reviewed by the SOC for over 4 hours — an alert management process gap, not a detection tool gap.
Measurable Outcomes
| Firewall Rules Remediated | 4 exploitable rules removed; 3 reviewed and scoped |
| Clinical Network Monitoring | OT security monitoring deployed within 60 days |
| Asset Register | Complete clinical device inventory: 14,200 devices documented |
| End-of-Life Devices | Compensating controls applied to all 62 EOL devices within 30 days |
| Detection Coverage After | Clinical network monitoring now covers 78% of device categories |
| FDA Evidence Package | IoMT security assessment accepted as pre-market cybersecurity evidence |
Regulatory Impact
The HIPAA §164.312 implication is direct: technical security measures must guard against unauthorised access to ePHI transmitted over electronic communications networks. An unmonitored clinical network containing patient monitoring data does not satisfy this requirement.
The IoMT security documentation was structured to align with the FDA’s 2023 Pre-Market Cybersecurity Guidance — supporting both the organisation’s internal security programme and engagement with device manufacturers on patch management.
The exercise highlighted the emerging IEC 62443-4-2 gap in healthcare IoMT: clinical devices that cannot be patched due to FDA clearance constraints require compensating controls — a compliance pathway the organisation’s prior documentation had not addressed.
“
We had passed HIPAA assessments for years and genuinely believed our clinical network segmentation was secure. The purple team exercise found four firewall rules — created years ago by people who no longer work here — that gave an attacker a clear path from our administrative network to 14,200 clinical devices, none of which generated a single alert. That finding alone justified everything we spent on this engagement.
— Vice President of Information Security, Academic Medical Centre (anonymised)
Key Takeaways
- Clinical network segmentation is only as effective as its last validated test. Legacy firewall rules created for operational convenience and never reviewed are one of the most common IoMT security vulnerabilities.
- Asset inventory is the prerequisite for all IoMT security. You cannot monitor, patch, or protect devices you do not know exist.
- Zero clinical network monitoring is more common than the healthcare sector acknowledges. Most SIEM and EDR tools are deployed on the administrative network — the clinical network is frequently unmonitored.
- End-of-life clinical devices require compensating controls, not just documentation that patching is impossible. Network isolation and enhanced monitoring are the primary compensating controls.
Ready to test your Healthcare security defences?
Case Study HC-CS-03
Third-Party Supplier Compromise — NHS Trust Supply Chain
Simulating the Advanced Computer Software Group attack pattern against a regional NHS Trust’s IT supplier ecosystem
Organisation
A mid-sized NHS acute trust serving a population of approximately 500,000 (anonymised)
Sector
Healthcare — NHS acute trust, United Kingdom
Location
England, United Kingdom
Engagement
Purple Team Exercise — Third-Party Supplier Access and Supply Chain Attack Simulation
Duration
5 weeks (2-week scoping, 1.5-day exercise, 1.5-week remediation and reporting)
Frameworks
UK GDPR / DPA 2018 | NHS DSPT Version 8 (Category 1) | ICO Advanced Enforcement Decision March 2025 | NHS England Supplier Security Charter May 2025 | NCSC CAF Objective C | MITRE ATT&CK Enterprise v15
The Situation
In March 2025, the ICO fined Advanced Computer Software Group £3.07 million for the 2022 ransomware attack that disrupted NHS 111 services — the first-ever fine against a data processor under UK GDPR. The Trust’s CISO recognised their own supplier landscape looked uncomfortably similar to Advanced’s pre-attack configuration.
The Trust had 47 third-party suppliers with active access to NHS systems or patient data. Of these, 31 had not been security-assessed in over 18 months. MFA was not enforced for all supplier remote access sessions. And the Trust had no real-time monitoring of supplier connection behaviour.
Following the ICO enforcement action and publication of the NHS England Supplier Security Charter in May 2025, the board commissioned an independent assessment: could a compromised supplier account reach patient data — and would anyone notice?
Core Challenge
Determine whether a compromised NHS IT supplier credential would allow an attacker to access patient data, escalate privileges, and operate undetected — mirroring the exact attack vector responsible for the Advanced incident.
What GLI Secure Did
We conducted a full supplier access audit — reviewing all 47 third-party supplier accounts, their access permissions, the systems they could reach, and monitoring in place on their sessions. This produced the Trust’s first complete supplier access register, a direct DSPT Version 8 requirement.
The exercise simulated a compromised Advanced-style supplier account: an IT support company with legitimate remote access to clinical administration systems. We used the supplier’s actual access pathway and tested whether that access could be extended to reach patient data repositories.
We also tested the Trust’s ability to detect and respond to the specific techniques used in the Advanced attack — credential abuse, lateral movement via legitimate RMM tools, and data staging.
The Purple Team Approach
Supplier Access Audit
Reviewed all 47 supplier accounts. Found: 23 without MFA, 8 with access broader than contracted scope, 5 accounts for suppliers whose contracts had expired.
High-Risk Supplier Identification
Identified 3 suppliers with access profiles most similar to the Advanced attack vector: remote IT support companies with broad administrative access, limited session monitoring, no just-in-time access controls.
Simulated Supplier Credential Compromise
Using a test supplier account mirroring a real high-risk supplier's access level, simulated an attacker operating from a compromised credential. Tested whether access could reach clinical administration systems.
Lateral Movement via Legitimate Tools
Tested the Advanced-documented technique: abusing legitimate remote monitoring and management tools for lateral movement. Found the Trust's environment had two RMM platforms both accessible from supplier accounts.
Patient Data Access Attempt
Tested whether the compromised supplier account could reach patient data repositories. Direct database access was blocked, but indirect access via a shared reporting system was possible.
Detection and Response Timing
Recorded time from initial simulated compromise to first alert. Tested the Trust's ability to revoke supplier access — measuring time from detection to complete access termination.
MITRE ATT&CK Techniques Tested
| ATT&CK ID | Technique | Detection Result |
|---|---|---|
| T1199 | Trusted Relationship (Supplier Access) |
Not Detected
No behavioural monitoring on supplier VPN sessions. |
| T1078 | Valid Accounts (Supplier Credential) |
Not Detected
No anomaly detection on supplier account activity. |
| T1021.001 | Remote Desktop Protocol (via RMM Tool) |
PARTIAL
Tool usage logged but not monitored. No alert generated. |
| T1543 | Create or Modify System Process (Persistence) |
Not Detected
No monitoring on system process creation from supplier context. |
| T1530 | Data from Cloud Storage (Reporting System) |
PARTIAL
Access logged but volume threshold not configured. No alert. |
| T1048 | Exfiltration over Alternative Protocol |
DETECTED
DLP alert on data staging after 34 minutes. |
Key Findings
Critical
Zero Supplier Session Monitoring:
No behavioural monitoring existed on any of the 47 supplier VPN sessions. An attacker using a legitimate supplier credential could operate indefinitely — the exact scenario of the Advanced attack.
Critical
5 Active Accounts for Expired Contracts:
Five supplier accounts remained active after contracts had expired — uncontrolled access pathways with no business justification.
High
Indirect Patient Data Access via Reporting System:
A shared reporting system accessible from supplier accounts contained patient-identifiable data in aggregate form. This access pathway was undocumented in the Trust’s data flow mapping or DPIA.
High
Access Revocation Speed:
From detection to complete supplier access revocation took 3 hours 47 minutes — a documented liability under NHS Supplier Security Charter Principle 6.
medium
23 Supplier Accounts Without MFA:
NHS Supplier Security Charter Principle 1 and the ICO Advanced enforcement decision both specifically address MFA as a minimum requirement. 23 of 47 accounts did not enforce MFA.
Measurable Outcomes
| Supplier Accounts Without MFA | 23 reduced to 0 within 21 days |
| Expired Contract Accounts | 5 accounts terminated within 48 hours |
| Supplier Access Register | First complete register created — DSPT v8 assertion evidence |
| Session Monitoring | Supplier session behavioural monitoring deployed within 30 days |
| Access Revocation Time | 3h 47m reduced to 23 minutes after process improvement |
| ICO Compliance Position | Advanced-pattern controls documented per ICO enforcement requirements |
Regulatory Impact
The exercise produced direct evidence relevant to the ICO’s March 2025 enforcement action. The ICO found that Advanced’s failure to enforce MFA and monitor privileged access was the proximate cause of the breach. The Trust’s identical risk profile — 23 accounts without MFA, zero supplier session monitoring — represented exposure that would be extremely difficult to defend before the ICO in the event of a breach.
The undocumented patient-identifiable data in the reporting system created a UK GDPR Article 35 DPIA gap. UK GDPR requires DPIAs for processing likely to result in high risk to individuals. Patient data accessible through a supplier-accessible, unmonitored system is precisely this category.
For DSPT Version 8, the exercise produced evidence for three supply chain security assertions the Trust had previously marked as ‘Standards Met’ on the basis of policy documentation. The exercise demonstrated operational reality did not match documentation.
“
The ICO fined Advanced £3.07 million because an NHS supplier failed to secure its access to NHS systems. When we looked at our own supplier landscape after reading that enforcement decision, we recognised we had the same problems. The purple team exercise confirmed it. More importantly, it gave us a documented remediation programme we could take to the board, to NHS England, and — if we ever needed to — to the ICO.
— Head of Information Governance, NHS Trust (anonymised)
Key Takeaways
- The ICO Advanced enforcement decision created direct liability precedent for NHS IT suppliers — and indirect pressure on NHS Trusts to verify their suppliers meet the same standards. Purple team exercises validate operational supplier security, not just contractual commitments.
- Supplier access registers are a DSPT Version 8 mandatory requirement that most Trusts have not implemented operationally. Building it as part of the exercise scope addressed a compliance gap and a security gap simultaneously.
- The combination of no MFA and no session monitoring on supplier accounts is the exact risk profile the ICO cited in the Advanced enforcement action. Both are addressable within weeks.
- Access revocation speed is a measurable, improvable metric. A 3-hour 47-minute revocation time is a documented liability. A 23-minute time is a defensible security control.
Book a Free Healthcare Purple Team Discovery Call
GLI Secure | ISO 17025 Accredited
Strengthen your cybersecurity posture today.
Strengthen your cybersecurity posture and protect your organization from evolving threats. Discover how GLI Secure reduces risk, simplifies compliance, and protects customer trust.