Industry
Healthcare
Healthcare telephony often runs on older, mixed estates that carry sensitive calls and cannot easily be taken offline. That combination makes careful, authorised assessment especially important.
Why it matters here
The telephony risk in this sector
Healthcare organisations frequently operate legacy PBX systems alongside newer VoIP, with limited windows for change and a low tolerance for disruption. Calls can carry sensitive personal information, so interception and exposure carry both safety and data-protection consequences alongside the fraud risk every organisation faces.
Legacy and mixed estates
Older systems accumulate configuration debt and unpatched software that rarely gets reviewed.
Sensitive call content
Exposure and interception carry data-protection implications, not just cost.
Limited change windows
Assessment and remediation must be planned around continuous operation.
Supplier-managed systems
Third-party-managed telephony needs clear authorisation and coordination before testing.
Context
What makes healthcare different
Healthcare telephony is rarely a single, uniform estate. A hospital trust may run a modern SIP-based PBX in one building, a much older TDM system in another, and outsource its 24-hour on-call answering to a third party. A GP practice may run cloud VoIP for daytime calls and a legacy on-premises PBX for after-hours diverts. All of it sits inside the same wider network, and all of it eventually connects to the same public phone network.
That mix has two consequences. First, configuration drift is the norm rather than the exception: older systems accumulate unpatched software, obsolete SIP handlers and default credentials that no one still on staff put there. Second, change windows are extremely tight. A trust cannot take its main switchboard offline during clinic hours, so remediation has to be planned around continuous operation rather than assumed as available.
Calls in healthcare also carry a category of content the average business call does not. Appointment bookings, results discussions, mental-health lines and safeguarding calls all pass through the same telephony layer as the main switchboard number, and unencrypted media on a shared internal network is a live data-protection exposure — regardless of whether anyone ever intended to listen.
Attack scenarios
How this typically goes wrong
Sector-specific scenarios GoldAgent has scoped assessments against. Defensive framing only — nothing here is a how-to.
Extension enumeration into voicemail brute-force
Attackers who reach an exposed SIP interface can often enumerate valid extensions and then attack voicemail PINs, which are almost always shorter and weaker than user passwords. In a healthcare context that can expose messages left on patient-facing lines — appointment confirmations, results callbacks, safeguarding follow-ups — with obvious data-protection consequences.
Toll fraud on out-of-hours and on-call routing
Out-of-hours diverts, GP on-call answering and after-hours message services are prime targets. They handle small numbers of calls, so a spike in usage stands out less quickly, and they are often the least-monitored corner of the estate. Once compromised they are used to place chargeable calls for the attacker, sometimes for weeks before the pattern is noticed.
Interception of unencrypted internal calls
Where internal calls between clinical staff still travel as unencrypted RTP over a shared network, an attacker who has any position on that network — a compromised workstation, a rogue device on a poorly segmented VLAN — can capture media that contains identifiable patient information. The exposure is the same regardless of intent; the presence of the recording is itself a breach.
Compliance driver
DSPT and data protection
NHS-affiliated organisations must complete the Data Security & Protection Toolkit (DSPT) every year. That process expects the organisation to know its estate, patch it, and have evidence that security testing has been carried out. Excluding the phone system is not a defensible answer. Alongside DSPT, the UK GDPR and Data Protection Act 2018 apply to any call content that identifies a patient, so exposure or interception of clinical telephony has both a regulatory and a safety dimension. GoldAgent's authorised assessments produce scoped, dated and attributable evidence of telephony testing. Whether a given DSPT or insurance submission accepts that evidence is for the organisation and its assessor to decide.
Related services
Explore related assessments
PBX Security Assessment
An authorised, end-to-end assessment of the PBX systems your business runs on.
Read moreVoIP Security Assessment
An attack-surface review of your VoIP platform, endpoints and remote users.
Read moreContinuous Assurance
Scheduled, automated reassessment with historical change tracking that keeps your exposure picture current between assessments.
Read more
Find out exactly how exposed your phone system is
Request an authorised PBX, VoIP or SIP security assessment. We confirm scope and authorisation first, then show you what is exposed and what to fix.
Testing is only performed against systems you own or are explicitly authorised to test.