See every path that could reach a patient record

Trident maps the cloud data stores that hold PHI and the identities that can reach them, then correlates exposure, reachability, and pentest findings into the ranked paths that chain all the way to a patient record — with evidence that supports the HIPAA safeguards you attest to.

Capabilities

One graph from exposure to a record

Map where PHI lives and every path that could reach it — ranked by real risk, each one tied to a fix.

Find where PHI lives

Inventory every database, bucket, and warehouse that holds patient records across your clouds — then see the identities that can reach each one.

Trace the path to a record

Correlate public exposure, IAM reachability, and findings into ranked paths from an internet-facing asset all the way to a PHI store.

Test the patient-facing flows

Broken access control and tenant isolation are exercised across portals and APIs, so one patient can never load another patient record.

Supports your HIPAA safeguards

Reproducible evidence maps to the Security Rule safeguards you attest to — Trident supports your program; it does not certify compliance.

Ranked by reach to records

Findings are ordered by proximity to PHI, so the short list at the top is the work that actually lowers patient-data risk.

Fixes for the owning team

Each path ships its choke-point fix as a draft PR or runbook — human-reviewed, never auto-applied to a clinical system.

How it works

From a read-only role to a closed path

01

Connect read-only

Attach read-only roles. Trident inventories assets, identities, and the stores that hold PHI — nothing is changed.

02

Locate the records

PHI data stores and the identities that can reach them resolve into one queryable reachability graph.

03

Correlate the paths

Exposure, identity edges, and pentest findings collapse into ranked paths that reach a patient record.

04

Close the chain

Each path ships its single choke-point fix to the team that owns the data store.

Outcomes

Protect the record, support the safeguard

Stop chasing standalone alerts. Focus on the few paths that actually reach patient data.

Cloud + app

Connected context

Read-only

No install on clinical systems

PHI-aware

Data-path review

Retested

After remediation

Scope

Where PHI actually becomes reachable

The copies are usually the problem. The primary store is normally the best-defended thing in the estate.

What healthcare testing focuses on

Healthcare systems leak protected health information through access control far more often than through exotic exploitation. Trident tests the paths that reach PHI: whether a clinician account can retrieve records outside its care relationship, whether patient-facing portals isolate one patient from another, and which cloud identities can reach the databases, backups, and analytics copies where PHI accumulates.

Record-level authorization
Whether an authenticated clinical or administrative user can reach records outside their assigned care relationship, department, or facility by manipulating identifiers directly.
Patient portal isolation
Cross-patient access in patient-facing applications, including dependants, proxy access, and the account-recovery flows that most often collapse the boundary between two patients.
Integration surfaces
HL7, FHIR, and partner API endpoints, which frequently carry weaker authorization than the primary application because they were built for a trusted network that no longer exists.
Derived PHI stores
Analytics warehouses, backups, exports, and test environments seeded with production data — copies that inherit sensitivity without inheriting the controls of the source system.
Cloud paths to PHI
Which identities, workloads, and networks can reach PHI stores, and which single policy change removes the largest number of those routes.

Frequently asked

Questions teams ask before they start

Do you access real patient data during testing?

No. Testing uses synthetic or de-identified test accounts. Demonstrating that a cross-patient authorization flaw exists requires two test identities, not real records — and the proof is equally valid without touching actual PHI.

Does HIPAA require penetration testing?

The Security Rule requires a risk analysis and evaluation of safeguards; it does not name penetration testing as a specific control. In practice, testing is a common and well-regarded way to evidence the technical safeguards and the evaluation requirement.

Will you sign a business associate agreement?

A BAA is required where a vendor creates, receives, maintains, or transmits PHI on your behalf. Raise it during scoping — the answer depends on the engagement design, and engagements can often be scoped to avoid PHI access entirely.

Can you test medical devices or clinical systems?

Scope focuses on cloud infrastructure, web applications, and APIs. Connected medical devices and clinical systems carry patient-safety considerations and regulatory constraints that require specialist testing arrangements beyond this scope.

Know what can reach a patient record.

Connect a read-only role and see the ranked paths to your PHI in a read-only connection without disrupting clinical systems.