Selected work
OWASP security assessment for a healthcare SaaS product
Engagement at a glance
- Security Assessment
- 2025
- Healthcare SaaS provider
What happened
Challenge
Enterprise healthcare buyers required documented evidence of security testing before signing — and the product had never had an independent security review. The internal team had no way to know whether the absence of known issues meant the product was sound or merely unexamined. The requirement arrived with a deal attached, which meant the assessment had to produce something a procurement reviewer would accept, not just a list of engineering tickets.
Approach
We ran a structured OWASP Top 10 assessment across the application and its APIs: authentication, access control, injection, misconfiguration and dependency review, followed by remediation guidance sessions with the development team. Access control got particular attention, since a product handling patient data spans clinician, administrator and patient roles and the damaging findings live in the combinations nobody enumerated. Every finding was demonstrated with a reproduction rather than inferred from a scanner’s output, and written up with the severity reasoning shown.
Outcome
High-severity findings were remediated and verified in a retest, and the resulting report became part of the security documentation shared in enterprise procurement. The remediation sessions meant the fixes were made by the client’s own developers, so the reasoning stayed in the team rather than leaving with us.
Why this stack
Burp Suite and OWASP ZAP were used together deliberately rather than as redundancy: the automated crawl establishes coverage and the manual proxy work is where the access-control findings actually come from. Dependency scanning was included because a product assembled from packages inherits their vulnerabilities, and that surface is invisible to any amount of testing against the running application.
What we would do differently
The remediation sessions were scheduled after the report, and they should have been interleaved with it. Findings that were explained while the tester still had the reproduction in front of them were fixed correctly first time; the ones handed over cold produced a round of clarification. We would now book a working session per severity tier as findings emerge, rather than one handover at the end.
Stack
- OWASP ZAP
- Burp Suite
- Dependency scanning
Contact
Something similar in flight?
Describe where it currently stands and what worries you about it. You will get a considered reply from an engineer, not an autoresponder.