Currently dealing with a breach or active incident?Call 406-924-3731×
≡
CASE STUDY

The clinic thought one public IP meant low risk. Vendors had left them exposed.

A rural Montana clinic believed one public IP meant low risk. Our manual pentest found two vendors had left equipment exposed, putting grant funding at risk.

The clinic thought one public IP meant low risk. Vendors had left them exposed.
February 27, 2026
·
5 min read
·
Montana
CLIENT

A rural healthcare clinic in Montana with a small environment and a single public IP. Camera systems and network equipment were installed and managed by outside vendors.

INDUSTRY

Healthcare

SERVICES

External Penetration Testing, 90-Day Retest, Monthly Vulnerability Assessments

1 public IP
The clinic's entire internet-facing footprint
2 vendors
Left equipment and management interfaces exposed
90 days
To a retest confirming every fix held

A rural healthcare clinic in Montana had a single public IP address and a small network, and the people running it reasonably assumed that meant their exposure was small too. Outside vendors had installed and managed the clinic's camera systems and parts of its network, and nobody had checked what those vendors left reachable from the internet.

The clinic's state and federal grants required ongoing vulnerability assessments and security auditing, not a one-time scan. They brought us in to find out what was actually exposed, get it fixed, and build a record they could hand to grant reviewers.

Before

The Challenge

Nobody at the clinic had a validated view of what was reachable from the internet, or how that exposure could affect patient data, day-to-day operations, or funding. Multiple third-party vendors had worked in the environment, and their work had never been independently checked.

The funding requirements raised the stakes. State and federal grants called for vulnerability management and security auditing as an ongoing activity, and the clinic needed to show that work, not just claim it. They also wanted to meet broader compliance and cyber insurance expectations without making a small environment harder to run.

That meant three things: a fully manual test of the external footprint instead of an automated scan, recurring assessments that proved the work was continuous, and reporting in plain business language that both staff and leadership could reuse with reviewers.

After

The Results

The clinic removed its any/any firewall rules and hardened its public IP, restricting it to required services only, tightening access controls, and improving configuration security.

Vendor-managed systems were locked down, and expectations with vendors were reset: third-party equipment can no longer be placed openly on the internet and left unprotected.

The Hikvision cameras were flagged as a regulatory and funding concern, since federal grant rules restrict equipment from that manufacturer.

Together, the 90-day retest and the monthly assessments gave the clinic a clear evidence package showing ongoing vulnerability assessment and security auditing, which helped it preserve critical state and federal funding.

The Solution

We scoped the engagement as a manual external penetration test, a focused retest at 90 days, and monthly vulnerability assessments with CVE-based reports. The structure was built to produce repeatable evidence that mapped directly to HIPAA requirements and to the grant language on vulnerability management and security auditing.

The penetration test came first. We validated every finding by hand and focused on what was genuinely exploitable from the internet. Legacy systems were still running any/any firewall rules, which opened the attack surface far wider than a single public IP would suggest.

We also found that two vendors, a camera provider and a network support vendor, had left their equipment directly exposed to the internet, management interfaces included. The camera deployment used Hikvision hardware.

After the initial test, we moved the clinic onto monthly vulnerability assessments with CVE-mapped reports. At the 90-day mark, we retested every remediated item to confirm the fixes actually held.

One public IP, and two vendors had still left their equipment sitting directly on the internet.

TALK TO US

Something here raise a question about your own setup?

Thirty minutes, no slide deck. If you're in decent shape we'll tell you that.

Schedule a call