Skip to content
StrikeCyberStrikeCyber
Health

Cloud Security Assessment for a Health Provider

A health provider needed assurance its multi-cloud environment protected patient data and met Privacy Act obligations.

Health sector
Industry
Health
Services
Vulnerability Assessment, Penetration Testing
Engagement
Cloud security assessment across AWS and Azure
Region
National

The Challenge

The client is a health provider that delivers services across multiple sites in Australia and holds a large volume of sensitive patient information. Over several years it had moved core systems into the cloud, running workloads across both AWS and Azure, often configured by different teams and vendors at different times. That organic growth left the security team without a clear, current picture of how the environment was configured or where patient data was exposed.

Health data is among the most sensitive information an organisation can hold, and a breach carries obligations under the Privacy Act and the Notifiable Data Breaches scheme, alongside the direct harm to patients. The provider needed an independent assessment of its cloud posture that reflected how an attacker would actually find and reach patient records, so it could close the gaps before they were exploited and evidence its duty of care.

Our Approach

StrikeCyber scoped a cloud security assessment combining a configuration and vulnerability review with hands-on penetration testing across the AWS and Azure environments, focused on the systems that store and process patient data.

  • Configuration and identity review of both cloud platforms, examining IAM roles and policies, storage permissions, network exposure, logging and multi-factor authentication coverage.
  • Vulnerability assessment of internet-facing services and workloads to identify exposed interfaces and missing patches.
  • Attack-path testing where expert operators chained real misconfigurations together to demonstrate how initial access could lead to patient data, rather than reporting settings in isolation.

Automated discovery mapped the environment quickly, and people then validated and exploited the findings by hand to prove genuine impact. Results were delivered through a live client portal so the internal team could act on the most serious issues immediately. This blended vulnerability assessment and penetration testing gives a true picture of cloud risk.

What We Found

  • Over-permissive IAM. Several roles and access keys carried far broader permissions than their function required, including wildcard policies, so a single compromised credential could reach a large part of the environment.
  • Exposed storage. A cloud storage container holding sensitive files was configured with overly broad access, and legacy storage from an old project remained reachable and unencrypted.
  • Missing multi-factor authentication. MFA was not enforced on some privileged administrative and console accounts, leaving high-value access reliant on passwords alone.
  • Secrets in configuration. Access keys and credentials were found embedded in scripts and configuration, giving an attacker a direct route to escalate privileges across the cloud.

The Outcome

StrikeCyber delivered a prioritised remediation plan mapped to the provider's Privacy Act obligations and written for both its internal team and its cloud vendors. IAM policies were reduced to least privilege and unused keys were removed. The exposed storage was locked down, encryption was enforced, and the abandoned legacy storage was decommissioned. MFA was enforced across all privileged and administrative accounts, and the embedded secrets were rotated and moved into a managed secrets store.

Because the assessment demonstrated a realistic path from an exposed credential to patient data, the provider was able to prioritise the fixes that genuinely reduced breach risk rather than chasing every low-severity setting. It came away with a documented, defensible view of its cloud posture, a hardened multi-cloud environment, and clear assurance to support its regulatory position and its duty of care to patients.

Why It Matters

In healthcare the move to the cloud has been fast, and the risk usually lies not in a single flaw but in ordinary misconfigurations that chain together into a path to patient records. A point-in-time list of settings does not show that path. A healthcare cloud security assessment that validates real attack paths shows exactly how a breach would happen, turning a compliance requirement into genuine protection of patient trust. To scope an assessment of your own cloud environment, get in touch.

Ready to take the offensive?

StrikeCyber specialises in penetration testing and red teaming engagements that deliver actionable findings. Connect with us for a free consultation.

No obligation, no sales pressure. A senior operator replies within one business day.

1300 654 898Free Consultation