PHI discovery and classification
We scan object and field metadata, descriptions and a sample of free-text fields to find where health information is stored, including places nobody intended. Files, emails and chat transcripts attached to cases are included. Each location is labeled by sensitivity, with a note on whether it is encrypted, tracked and restricted, so your privacy officer has a factual inventory rather than a set of assumptions.
Access and audit trail testing
We log in as sample users from care coordination, billing, sales, medical affairs and support, then document what each can see and export. Login history, setup audit logs and field tracking are checked to confirm that access to sensitive records can be reconstructed after the fact. Gaps are written up as specific settings to change rather than general advice about tightening access.
Healthcare professional data review
For device, diagnostics and pharmaceutical organizations, we examine how prescribers, facilities and affiliations are stored, how often reference data is refreshed and how many duplicate practitioner records exist. We also check that interaction records capture the details your transparency and spend reporting depends on, and whether sample, event and meal logging follows your internal policies consistently across field teams and regions.
Patient program and portal review
Patient support programs, intake forms and portals often combine Experience Cloud, Service Cloud and marketing tools. We review guest user access, consent capture, identity verification steps and how patient messages route internally. Any path by which an unauthenticated visitor or the wrong patient could reach another person's record is ranked as the highest priority finding in the report. Consent withdrawal handling is checked too.