More Security for Patient Data: Pentest and Cloud Audit at medavis

23. September 2020

Compliance requirements are often the driving force behind the necessity of a pentest. However, each company and its IT infrastructure has to be looked at individually. Usually the initially requested pentest is not enough. For example, if applications run in the cloud, other attack vectors need to be  considered as well. A good example is the cooperation with medavis GmbH.

The Karlsruhe-based provider of radiology workflow solutions processes highly sensitive patient data, such as diagnostic images and medical findings, and thus places the radiology workflow at the center of its thoughts and actions. Due to the very high protection requirements of the processed data, medavis ordered a check of the IT security level of the entire cloud infrastructure in addition to the pentest. The usd security experts analyzed the configuration of the AWS cloud services and the applications running on it.

usd Experts have developed a special testing procedure, which is based on the specifications of the Payment Card Industry Data Security Standards (PCI DSS), the recommendations of the German Federal Office for Information Security (BSI) and the Open Web Application Security Project (OWASP), among others. Furthermore, benchmarks of the Center for Internet Security (CIS) and best practices of the cloud service providers are taken into account. Combining all those requirements as the basis of the usd approach increases the security of the tested systems in the long term.

Tobias Troesch, Product Owner at medavis GmbH, and his colleagues take information security very seriously: “As a manufacturer of radiology workflow solutions, we provide the information flow of sensitive data for medical diagnoses. The protection of patient data is hence a top priority for us. Only this way, we can guarantee our customers the best possible security level. usd AG has supported us in a highly professional and competent way from the beginning. This was already evident in the initial consultation: In close collaboration, we defined the risk classifications of the various functions and thus received an excellent offer adapted to our needs in order to have the most efficient examination carried out. Taking also the configuration of AWS cloud services into consideration was an excellent approach from the usd specialist sales department at this phase. Overall, we would like to thank usd AG for the always pleasant and goal-oriented cooperation and competent advice – even beyond the actual project.”

Tobias Neitzel, usd Managing Consultant IT Security, about the specifics of the environment they have tested: “The pentest of a cloud infrastructure is different from the traditional on-premise infrastructure test. Cloud provider such as AWS offer many features and a high degree of flexibility. This has many advantages for cloud users, but also entails security-related risks that should not be underestimated. Cloud providers therefore generally follow a model of shared responsibility: For example, the responsibility for configuring the servers and access rights lies with the user.”

“Companies usually focus on testing their application. In doing so, they often disregard the configuration of the cloud services themselves. It is very important for us to address precisely these points of attack in the initial consultation with our customers. medavis GmbH took exactly the right steps to achieve a higher IT security level by conducting a technical security analysis in the form of pentests as well as a configuration audit. We are looking forward to a continued  partnership and cooperation.”, added Dr. Kai SchubertManaging Consultant der usd AG.


About medavis GmbH

medavis AG is an owner-managed medium-sized company that has been a specialist in the market for innovative radiology workflow systems for 23 years.

By now, the future-oriented medavis RIS is one of the most innovative radiology workflow solutions worldwide. That is due to its speed, its well thought-out workflows and its stability, among others.

Using modular and scalable applications, medavis can network radiologists across sites, both among themselves and with referring physicians, and provide a comprehensive, fast and secure flow of information. medavis enables radiologists to increase the speed and efficiency of their patient care.

Beyond conventional radiological workflows, medavis enables an unrestricted flow of information with its web-based communication platform – even across site boundaries, from the referral portal to teleradiology.

More information: https://www.medavis.com/

Also interesting:

Security Advisories on PRTG Network Monitor

Security Advisories on PRTG Network Monitor

The pentest professionals at usd HeroLab examined the PRTG Network Monitor web application as part of web application pentests and identified several vulnerabilities. Two vulnerabilities relate to cross-site scripting (XSS), which allows attackers to inject JavaScript...

PCI Secure Software Standard v2.0: What You Should Know

PCI Secure Software Standard v2.0: What You Should Know

On 15 January 2026, the PCI Security Standards Council (PCI SSC) released version 2.0 of the PCI Secure Software Standard. This is the first comprehensive revision since the introduction of the standard. Insight into the Key Changes The new version streamlines the...

Part-IS and ISO 27001: How to Leverage Synergies for Your Compliance

Part-IS and ISO 27001: How to Leverage Synergies for Your Compliance

On 22 February 2026, the EU Regulation Part-IS for aviation organizations will come into force. They must manage information security risks in a way that best protects civil aviation safety. Many already rely on an ISMS according to ISO 27001 – but is that enough for...

Categories

Categories