Pen testing · Clinical care providers
Penetration Testing for Home & Community Care Agencies
Penetration testing for a home and community care agency answers a question that comes up whenever the core platform is SaaS: what, if anything, is actually ours to test. A caregiver mobile app, its APIs, the electronic visit verification tool, and remote access used by schedulers all sit within reach even when the care-management system itself is hosted by a vendor. Testing usually gets scheduled ahead of a contract renewal, before a new app version ships, or after a vendor incident raises the question of what an attacker could actually reach.
Reviewed by the Privacy Horizon team · Last reviewed
What you're protecting
What testing has to reach when the core system is SaaS
A hosted care-management platform narrows the surface, but it does not remove it, and testing has to find what is genuinely left.
The caregiver mobile app and its APIs
The client-side app on PSW and nurse phones, and the backend APIs it calls to pull schedules, care plans and client addresses, a realistic target regardless of who hosts the underlying database.
Remote access used by schedulers and coordinators
The VPN, remote desktop or web portal office-based staff use to manage visits, often the highest-privilege access point an attacker outside the field workforce could reach.
Electronic visit verification integrations
The EVV tool's own login, mobile check-in flow and any interface it exposes to confirm a visit occurred, tested for authentication and data-exposure weaknesses independent of the core platform.
Single sign-on and identity boundaries
Where staff accounts bridge the care-management platform, email and any secondary tools, testing whether a compromised credential in one system opens a path into another.
Public-facing intake and referral forms
Any web form used to receive referrals or client inquiries, checked for the kind of exposure that could leak new-client information before a case is even opened.
Regulatory map
Why testing matters even on a vendor-hosted core
The custodian obligation to safeguard PHI does not shrink because the software is hosted elsewhere.
PHIPA's safeguard expectations attach to the custodian
An agency delivering care under Connecting Care Act funding remains the custodian responsible for reasonable safeguards, whether the technology touching that data is self-hosted or a vendor platform.
The audit-log standard Ontario Health atHome applies to itself
Ontario Health atHome reports investing in access-control and audit-analytics work for the CHRIS system, a benchmark that shapes what a security schedule expects an SPO's own systems to demonstrate.
Alberta HIA's safeguard duty for continuing-care operators
Custodians under Alberta's HIA carry a parallel obligation to protect health information against unauthorized access, a duty testing helps evidence for any agency operating there.
BC PIPA's reasonable-safeguards requirement
A private or non-profit agency operating in BC needs documented safeguards proportionate to the sensitivity of client data, and a penetration test is standard evidence of that work.
What goes wrong
What testing looks for in this environment
The findings that matter here are the ones an attacker could realistically use against a mobile, contract-dependent workforce.
Broken authentication on the caregiver app
Weak session handling or missing account-lockout controls that would let an attacker who obtains one worker's credentials pivot into schedules and addresses for many clients at once.
API endpoints returning more data than the screen shows
Backend calls that hand back full client records when the app only displays a subset, a common gap between what a mobile interface shows and what its API actually exposes.
Unprotected scheduler remote access
Remote-access points without multi-factor authentication or IP restriction, the kind of exposure that turns a guessed password into full visibility of the client roster.
EVV check-in spoofing or data leakage
Weaknesses in how a visit-verification tool confirms location or identity, which can affect both the accuracy of missed-visit reporting and the confidentiality of the underlying data.
Our pen testing for home & community care agencies
What our penetration testing covers for an agency
Testing is scoped to what your organization actually operates and controls, not a generic network sweep unrelated to your real attack surface.

Vulnerability exploration across app, API and remote access
Testing focused on the caregiver mobile app, its backend APIs, scheduler remote access and any EVV integration your agency configures or controls.
Response capability observation
Insight into how your team detects and reacts during simulated attempts, useful groundwork for the incident response plan this sector's contracts increasingly expect.
Defensive improvement guidance
Directional findings on where controls need strengthening, prioritized for a team that has to fix things around ongoing visit delivery, not a maintenance window.
Standards and expectation awareness
Context connecting findings to what an SPO contract's security schedule or a cyber-insurance renewal is likely to ask for as evidence.
How the engagement runs
How a test runs against a home-care agency's environment
The process is built to respect that scheduling and field operations cannot pause for testing.
Step 1
Scope what's actually testable
We confirm which parts of the environment, the caregiver app, its APIs, remote access, EVV tool, are within the agency's control versus purely the vendor's infrastructure.
Step 2
Test outside live visit windows
Testing is scheduled to avoid disrupting active scheduling and field communication, since a caregiver app going down mid-shift is not an acceptable side effect.
Step 3
Document findings with practical severity
Results are written up in terms your team and, where relevant, your platform vendor's own security contact can act on.
Step 4
Debrief and prioritize fixes
We walk through findings with whoever owns the fix, IT, the vendor relationship, or the vCISO if one is engaged, and help sequence remediation.
What it costs
What determines penetration testing cost for a home-care agency
Scope drivers include how many distinct components need testing, the mobile app and its APIs, remote access, EVV integration, and how much of the environment is agency-controlled versus purely vendor-hosted. An agency with a custom-built caregiver app faces a larger scope than one entirely inside a vendor's standard platform.
Retest cycles, how often a contract or insurer expects testing repeated, also shape ongoing cost. Tell us what you operate directly versus what your platform vendor hosts, and we will scope a tailored quote.
Home & Community Care Agencies: Pen testing questions, answered
That is exactly what the engagement determines, rather than something to assume either way. Testing checks authentication strength, session handling and whether the backend APIs return more client data than the interface displays, the combination that matters most for an app carrying schedules and addresses on personal devices.
Often yes in agencies that set remote access up years ago and never revisited it. Testing checks for missing multi-factor authentication, weak password policy and whether the access point is reachable from anywhere on the internet rather than restricted, since this path typically carries higher privilege than any single field device.
The mobile app and its APIs, any remote access your staff use, EVV integrations, and public-facing intake forms are all fair game even when the underlying database sits with a vendor. We scope the engagement to what your agency actually controls and configures, and note where a finding needs to be raised with the vendor directly instead.
Annually at minimum, and again after any material change, a new app version, a new EVV vendor, or a platform migration. Contracts and cyber-insurance renewals increasingly expect current test evidence rather than a report from several years ago.
We schedule testing to avoid live visit windows and coordinate timing with whoever manages the platform, so scheduling and field communication keep running normally. Any test likely to cause disruption is flagged and scheduled with the agency's explicit sign-off first.
Usually yes for the pieces the vendor's own testing does not cover, your specific app configuration, your remote-access setup, and any integration you added on top of the base platform. A vendor's report covers their infrastructure, not the parts of the environment your agency built or configured.
More for home & community care agencies
Other services for this niche
About this service
What's Protecting Your Business from the Next Threat?
Don't wait for a breach to expose your vulnerabilities. Let Privacy Horizon secure your data, ensure compliance, and build lasting trust.