17,796
Internet-facing assets discovered
Across 5 scanned organisations
1,083
Supplier connections mapped
script · cert · ASN · DNS · header
75
Fix Now priorities
Requiring immediate action
3/3
Hospitals with D-rated software risk
Known-vulnerable components detected
Why healthcare attack surfaces demand urgent attention
Healthcare organisations face a unique convergence of risk: they hold the most sensitive personal data in any sector — patient health records, medication histories, diagnostic imaging — and they operate critical infrastructure where disruption directly threatens patient safety. Ransomware groups know this. Healthcare has been the most targeted sector for ransomware globally for five consecutive years, precisely because the operational consequences of downtime create maximum leverage.
Yet most healthcare security programmes focus inward — on clinical systems, network segmentation, and endpoint protection. The external attack surface — the patient portals, supplier integrations, clinical web applications, and third-party scripts that are visible to any attacker with an internet connection — is rarely mapped with the same rigour. ThingsRecon changes that. This report draws on agentless scans of five healthcare organisations across the Netherlands, Belgium, and the United Kingdom. Everything was discovered from public data only: DNS, TLS certificates, cloud metadata, internet-wide scanning, and API ecosystem mapping. No agents. No internal access. No questionnaires.
All organisations in this report are anonymised. Technology suppliers and infrastructure providers are named as they appear on the external attack surface.
Sector Benchmark
How do healthcare organisations compare?
ThingsRecon scanned five healthcare organisations — hospitals, NHS trusts, and health technology vendors — simultaneously. The most striking finding is not the overall scores: it is that every hospital scanned received a D rating for software risk, indicating actively exploitable vulnerable components across their patient-facing digital estates.
Organisation
Assets
Suppliers
Fix Now
Fix Soon
Score
Weak indicators
Company AGeneral hospital · NL
4,118
99
20
30
C
Headers D · Software D · Cert C
Company BGeneral hospital · BE
2,770
72
17
11
C
Headers C · Software D · Cert C · SSL C
Company CNHS trust · UK
2,704
81
12
6
C
Headers C · Software D · DNS C
Company DHealth software vendor · BE
8,083
127
26
78
C
Headers D · Software C · SSL C
Company EHealth tech vendor · NL
121
6
0
6
B
Headers D · Cert C · App C
Sector-wide Risk Patterns
Structural vulnerabilities across the healthcare digital estate
The patterns below appear consistently across all scanned healthcare organisations — regardless of size, country, or whether they are a provider or a vendor. These are not random security gaps: they reflect how healthcare technology has been built, procured, and maintained over decades.
Software Supply Chain
Critical
All three hospitals scanned received a D rating for software risk — the worst finding in this report. Outdated JavaScript libraries, unpatched server-side frameworks, and legacy clinical application components with known CVEs are present across every hospital estate. This is the primary ransomware entry vector in healthcare: a public-facing vulnerable component is exploited to gain initial foothold before lateral movement to clinical systems.
HTTP Security Headers
High
4 of 5 organisations scored C or D on header hygiene. Missing Content-Security-Policy and HSTS on patient portal and clinical web applications leaves these services open to clickjacking, script injection, and protocol downgrade attacks — directly relevant to the protection of patient authentication flows and sensitive health data.
Certificate & TLS Hygiene
High
3 organisations show C-rated certificate risk. Misconfigured TLS on healthcare services — particularly patient portals and appointment systems — creates man-in-the-middle exposure on sessions carrying special-category health data. Under GDPR Article 32, this constitutes a failure to implement appropriate technical security measures.
Supplier Concentration
High
Microsoft and Amazon are present in all 5 scanned organisations. Google, Cloudflare, and GitHub each appear in 4 of 5 organisations. A compromise or supply chain attack on any of these providers has simultaneous impact across the entire sector — exactly the scenario NIS2 Article 21(2)(d) mandates healthcare organisations to assess.
Cookie & Session Security
Medium
Session cookies on patient portals and clinical web applications lack Secure and HttpOnly flags across multiple organisations. This exposes patient authentication tokens to theft — enabling account takeover on systems that hold medication records, appointment history, and diagnostic results.
DNS Misconfiguration
Medium
The NHS trust in this benchmark scored C on DNS risk — a sector-wide concern given that healthcare organisations typically manage large, complex DNS estates spanning clinical systems, patient portals, and supplier integrations. DNS misconfigurations can be exploited for subdomain takeover or traffic interception.
Sector verdict: Healthcare's digital attack surface is shaped by decades of technology procurement decisions, legacy clinical systems, and a supplier ecosystem that most TPRM programmes do not fully map. The D-rated software risk across all three hospitals is not a surprise to anyone who has worked in healthcare IT — but it is the precise entry point that ransomware groups exploit. The question is not whether this risk exists, but whether it is being monitored and prioritised against a backdrop of NIS2 obligations and GDPR enforcement.
NIS2 Directive — Healthcare Obligations
Hospitals and healthcare providers are classified as essential entities under NIS2 Annex I. This triggers mandatory obligations under Article 21: risk analysis, security of network and information systems, supply chain security (Article 21.2.d), vulnerability handling, and incident reporting within 24 hours (Article 23). Health technology vendors supplying to essential entities may also fall within scope as important entities. ThingsRecon provides the continuous outside-in visibility that Article 21 compliance requires.
Why Healthcare Needs This
Discovery. Prioritisation. Monitoring.
Healthcare IT teams manage estates shaped by decades of procurement, mergers, and system integrations — with patient safety as the overriding operational priority. Security visibility cannot compete with clinical operations for resources. ThingsRecon provides the continuous, agentless outside-in view that fills the gap.
01
Continuous Discovery
Hospital digital estates include patient portals, appointment booking systems, clinical information portals, PACS viewer interfaces, supplier VPN endpoints, and legacy web applications — many unknown to the central security team. ThingsRecon discovers the full external surface continuously from a single seed domain, including assets from historical mergers and acquisitions.
02
Clinical Risk Prioritisation
With 75 Fix Now items across five organisations, healthcare security teams cannot act on everything at once. ThingsRecon scores every finding by exploitability and proximity to sensitive assets — enabling teams to prioritise vulnerabilities that directly threaten patient data or clinical operations over lower-risk infrastructure findings.
03
Supply Chain Monitoring
EHR vendors, medical device suppliers, clinical SaaS platforms, and NHS shared services create a complex and constantly changing supplier ecosystem. ThingsRecon detects changes to third-party connections — new certificate authorities, changes in CDN routing, new script suppliers — the moment they appear on the external surface, before they become incidents.
Supply Chain Intelligence
The suppliers inside every healthcare digital estate
Healthcare supply chain risk is not just about medical device vendors and EHR suppliers. ThingsRecon maps the technical supply chain — every third-party component detected on the external attack surface via scripts, certificates, DNS, ASN routing, and HTTP headers. These are the suppliers that standard TPRM questionnaires never reach, because they were never deliberately onboarded: they arrived embedded in platforms, website themes, and inherited integrations.
Sector-wide supplier connections1,083 connections mapped
Across 5 scanned healthcare organisations — detected via script, cert, ASN, DNS, and header vectors. The majority undeclared in TPRM registers.
Universal suppliers (all scanned orgs)2 in every estate
Microsoft and Amazon appear in all 5 scanned organisations — creating a universal, sector-wide dependency that falls squarely within NIS2 Article 21 supply chain risk obligations.
Software Fix Now (sector total)44 across organisations
Fix Now software findings across the sector — with 36 concentrated in hospitals, indicating actively exploitable CVEs in patient-facing web applications and clinical portals.
Highest supplier proximity70% Microsoft & Cloudflare
Both Microsoft and Cloudflare achieve 70% digital proximity in the largest hospital — meaning their infrastructure sits deeply embedded within the critical external estate.
Supplier
Avg proximity
Connection vector
In
Found in
Microsoft Corporationmicrosoft.com · azure.com
54%
script · header · ASN
5 / 5
Company A, B, C, D, E
Amazon Technologies, Inc.amazon.com · aws.com
46%
ASN · cert · dns
5 / 5
Company A, B, C, D, E
Cloudflare, Inc.cloudflare.com
54%
cert · dns · ASN
4 / 5
Company A, B, C, D
Google LLCgoogle.com
57%
script · header · dns
4 / 5
Company A, B, C, D
GitHub Inc.github.com
35%
script · header
4 / 5
Company A, B, C, D
Critical Supplier Spotlight
Microsoft Corporation
microsoft.com · azure.com · office365.com | Avg proximity 50% · Max 70%
Found in
All 5 scanned healthcare organisations
Digital proximity
70% max Highest proximity in Company A
Connection vectors
JavaScript scripts · response headers · ASN routing · DNS
Healthcare risk profile
Identity dependency Data residency
Microsoft is the single most embedded technology supplier in the healthcare sector. In practice, this means Azure Active Directory is the identity provider for every clinical application, Microsoft 365 handles all staff communications (including patient-related correspondence), Teams is used for clinical consultation and handover, and Azure hosts EHR data and clinical workloads. A digital proximity of 70% means Microsoft infrastructure is deeply woven into the most sensitive external-facing estate. The risk is not that Microsoft will be breached — it is that misconfigured Azure AD application registrations, overpermissive OAuth scopes, or undeclared Azure-hosted services create invisible attack paths that no perimeter tool maps. Under NIS2 Article 21(2)(d), healthcare essential entities must specifically assess supply chain security covering ICT service providers — Microsoft, as the dominant ICT supplier, is the first priority. ThingsRecon identifies every Microsoft-connected asset on your external surface, scores its proximity to sensitive clinical data, and monitors for changes continuously.
Attack vector: Misconfigured Azure AD app registration → overpermissive OAuth token → lateral access to M365 clinical data → exfiltration of patient health records (GDPR special category breach)
Healthcare attack path — software vulnerability to clinical disruption
1
Entry point
Known CVE in outdated software component on patient portal (Software risk D — all hospitals)
Entry
Public exploit available — no authentication required
2
Pivot
Foothold in web application server → lateral movement toward clinical network segment
Pivot
Credential harvesting from cached sessions & shared service accounts
3
Impact
Ransomware deployed across clinical systems — patient records encrypted, operations disrupted
Impact
Sector Findings
Aggregated risk signals across all scanned organisations
The following findings reflect patterns observed across all scanned healthcare organisations. Individual organisation-level findings with full asset detail are available through a full ThingsRecon engagement.
- Fix Now
D-rated software risk across all three hospitals — the sector's most critical finding. Known-vulnerable JavaScript libraries and server-side framework components with public CVEs are present on external patient portals and clinical web applications in every hospital scanned. This is the primary initial access vector used in healthcare ransomware campaigns globally. 44 of the 75 Fix Now items sector-wide are software-related.
- Fix Now
SSL/TLS service misconfigurations generating Fix Now findings in two hospitals. Weak cipher configurations and certificate issues on externally accessible clinical services expose patient authentication sessions to interception — directly triggering GDPR Article 32 obligations around appropriate technical security measures for special-category health data.
- Fix Now
Application-level security failures on patient-facing web applications. Fix Now application findings across multiple organisations indicate authentication gaps and insecure configurations on services that handle patient login, appointment data, and health record access.
- Fix Soon
HTTP security headers absent on clinical web applications. All four scanned organisations have C or D-rated header hygiene. Missing Content-Security-Policy on patient portals that load third-party scripts creates a direct cross-site scripting vector — particularly acute where clinical portals integrate with Google Analytics, Microsoft Clarity, or other tracking tools.
- Fix Soon
Certificate hygiene gaps across healthcare estates. Three organisations show C-rated certificate risk with Fix Soon items on externally accessible services. Certificate mismanagement in healthcare is particularly significant given the volume of sensitive data transmitted — and the GDPR obligation to protect special-category health data with appropriate encryption.
- Monitor
Supply chain changes in third-party clinical platform suppliers not tracked. Across 684 mapped supplier connections, certificate rotations, DNS record migrations, and new script introductions occur continuously. Without external monitoring, a supply chain compromise in a clinical SaaS provider, EHR integration, or shared NHS service goes undetected — until it becomes a reportable incident under NIS2 Article 23.
Get the full picture
Your organisation's exposure — mapped in 48 hours
This sector report shows the patterns. A ThingsRecon scan of your organisation shows exactly which assets, suppliers, and attack paths apply to you — with the NIS2 and GDPR mapping your compliance team needs.
✦ Full external asset inventory
✦ Every supplier scored
✦ Software CVE identification
✦ Fix Now / Fix Soon list
✦ NIS2 Art. 21 evidence
✦ GDPR Art. 32 mapping
✦ Continuous monitoring
Request a PoC scan