Skip to content

Industry

Healthcare

Healthcare telephony often runs on older, mixed estates that carry sensitive calls and cannot easily be taken offline. That combination makes careful, authorised assessment especially important.

Why it matters here

The telephony risk in this sector

Healthcare organisations frequently operate legacy PBX systems alongside newer VoIP, with limited windows for change and a low tolerance for disruption. Calls can carry sensitive personal information, so interception and exposure carry both safety and data-protection consequences alongside the fraud risk every organisation faces.

  • Legacy and mixed estates

    Older systems accumulate configuration debt and unpatched software that rarely gets reviewed.

  • Sensitive call content

    Exposure and interception carry data-protection implications, not just cost.

  • Limited change windows

    Assessment and remediation must be planned around continuous operation.

  • Supplier-managed systems

    Third-party-managed telephony needs clear authorisation and coordination before testing.

Context

What makes healthcare different

Healthcare telephony is rarely a single, uniform estate. A hospital trust may run a modern SIP-based PBX in one building, a much older TDM system in another, and outsource its 24-hour on-call answering to a third party. A GP practice may run cloud VoIP for daytime calls and a legacy on-premises PBX for after-hours diverts. All of it sits inside the same wider network, and all of it eventually connects to the same public phone network.

That mix has two consequences. First, configuration drift is the norm rather than the exception: older systems accumulate unpatched software, obsolete SIP handlers and default credentials that no one still on staff put there. Second, change windows are extremely tight. A trust cannot take its main switchboard offline during clinic hours, so remediation has to be planned around continuous operation rather than assumed as available.

Calls in healthcare also carry a category of content the average business call does not. Appointment bookings, results discussions, mental-health lines and safeguarding calls all pass through the same telephony layer as the main switchboard number, and unencrypted media on a shared internal network is a live data-protection exposure — regardless of whether anyone ever intended to listen.

Attack scenarios

How this typically goes wrong

Sector-specific scenarios GoldAgent has scoped assessments against. Defensive framing only — nothing here is a how-to.

  • Extension enumeration into voicemail brute-force

    Attackers who reach an exposed SIP interface can often enumerate valid extensions and then attack voicemail PINs, which are almost always shorter and weaker than user passwords. In a healthcare context that can expose messages left on patient-facing lines — appointment confirmations, results callbacks, safeguarding follow-ups — with obvious data-protection consequences.

  • Toll fraud on out-of-hours and on-call routing

    Out-of-hours diverts, GP on-call answering and after-hours message services are prime targets. They handle small numbers of calls, so a spike in usage stands out less quickly, and they are often the least-monitored corner of the estate. Once compromised they are used to place chargeable calls for the attacker, sometimes for weeks before the pattern is noticed.

  • Interception of unencrypted internal calls

    Where internal calls between clinical staff still travel as unencrypted RTP over a shared network, an attacker who has any position on that network — a compromised workstation, a rogue device on a poorly segmented VLAN — can capture media that contains identifiable patient information. The exposure is the same regardless of intent; the presence of the recording is itself a breach.

Compliance driver

DSPT and data protection

NHS-affiliated organisations must complete the Data Security & Protection Toolkit (DSPT) every year. That process expects the organisation to know its estate, patch it, and have evidence that security testing has been carried out. Excluding the phone system is not a defensible answer. Alongside DSPT, the UK GDPR and Data Protection Act 2018 apply to any call content that identifies a patient, so exposure or interception of clinical telephony has both a regulatory and a safety dimension. GoldAgent's authorised assessments produce scoped, dated and attributable evidence of telephony testing. Whether a given DSPT or insurance submission accepts that evidence is for the organisation and its assessor to decide.

Related services

Explore related assessments

  • PBX Security Assessment

    An authorised, end-to-end assessment of the PBX systems your business runs on.

    Read more
  • VoIP Security Assessment

    An attack-surface review of your VoIP platform, endpoints and remote users.

    Read more
  • Continuous Assurance

    Scheduled, automated reassessment with historical change tracking that keeps your exposure picture current between assessments.

    Read more

Find out exactly how exposed your phone system is

Request an authorised PBX, VoIP or SIP security assessment. We confirm scope and authorisation first, then show you what is exposed and what to fix.

Testing is only performed against systems you own or are explicitly authorised to test.