Overview
An ECG, pulse oximetry, and stethoscope were just some of the health tracking features that had to be built into a remote patient monitoring device for cardiac care and general wellness. It also had to work perfectly with a mobile app and cloud service for real-time monitoring. But the client had a big problem: they couldn’t see the source code, but they had to get FDA approval, make sure they were compliant with HIPAA and GDPR, and make sure the system was safe. Testvox was hired to do “black box” testing to check the device’s security and compliance and make sure it met strict medical and privacy standards.
Our Solution
Testvox dealt with security and legal compliance in a structured and thorough way:
- Penetration Testing
We performed penetration tests on both the application and mobile versions of the product to assess for any security weaknesses/exploitable vulnerabilities that would compromise the integrity of patient data and/or the overall safety of the product.
- Regulatory Compliance Testing
Each respective testing result was assessed according to applicable regulations and standards set forth by the Federal Drug Administration (FDA), the Health Insurance Portability and Accountability Act (HIPAA) and the General Data Protection Regulation (GDPR) in verifying that the overall product complies with Store Data Security and Cybersecurity regulations.
- Vulnerability Testing
Both static testing and dynamic testing were utilised for identifying exploitable security vulnerabilities on the product using industry-standard tools and an internal methodology to perform the test.
Final Thoughts
Testvox helped the client find their way through the complicated web of security and legal rules, making sure the device was ready for FDA approval and fully in line with HIPAA and GDPR. Even though we didn't have direct access to the source code, our "black box" testing method helped us find security holes and get the device ready for approval. As a result? A safer device, fewer risks, and a strong base for growth and future checks.