Find where PHI lives
Inventory every database, bucket, and warehouse that holds patient records across your clouds — then see the identities that can reach each one.
Trident maps the cloud data stores that hold PHI and the identities that can reach them, then correlates exposure, reachability, and pentest findings into the ranked paths that chain all the way to a patient record — with evidence that supports the HIPAA safeguards you attest to.
Capabilities
Map where PHI lives and every path that could reach it — ranked by real risk, each one tied to a fix.
Inventory every database, bucket, and warehouse that holds patient records across your clouds — then see the identities that can reach each one.
Correlate public exposure, IAM reachability, and findings into ranked paths from an internet-facing asset all the way to a PHI store.
Broken access control and tenant isolation are exercised across portals and APIs, so one patient can never load another patient record.
Reproducible evidence maps to the Security Rule safeguards you attest to — Trident supports your program; it does not certify compliance.
Findings are ordered by proximity to PHI, so the short list at the top is the work that actually lowers patient-data risk.
Each path ships its choke-point fix as a draft PR or runbook — human-reviewed, never auto-applied to a clinical system.
How it works
Attach read-only roles. Trident inventories assets, identities, and the stores that hold PHI — nothing is changed.
PHI data stores and the identities that can reach them resolve into one queryable reachability graph.
Exposure, identity edges, and pentest findings collapse into ranked paths that reach a patient record.
Each path ships its single choke-point fix to the team that owns the data store.
Outcomes
Stop chasing standalone alerts. Focus on the few paths that actually reach patient data.
Cloud + app
Connected context
Read-only
No install on clinical systems
PHI-aware
Data-path review
Retested
After remediation
Scope
The copies are usually the problem. The primary store is normally the best-defended thing in the estate.
Healthcare systems leak protected health information through access control far more often than through exotic exploitation. Trident tests the paths that reach PHI: whether a clinician account can retrieve records outside its care relationship, whether patient-facing portals isolate one patient from another, and which cloud identities can reach the databases, backups, and analytics copies where PHI accumulates.
Frequently asked
No. Testing uses synthetic or de-identified test accounts. Demonstrating that a cross-patient authorization flaw exists requires two test identities, not real records — and the proof is equally valid without touching actual PHI.
The Security Rule requires a risk analysis and evaluation of safeguards; it does not name penetration testing as a specific control. In practice, testing is a common and well-regarded way to evidence the technical safeguards and the evaluation requirement.
A BAA is required where a vendor creates, receives, maintains, or transmits PHI on your behalf. Raise it during scoping — the answer depends on the engagement design, and engagements can often be scoped to avoid PHI access entirely.
Scope focuses on cloud infrastructure, web applications, and APIs. Connected medical devices and clinical systems carry patient-safety considerations and regulatory constraints that require specialist testing arrangements beyond this scope.
Connect a read-only role and see the ranked paths to your PHI in a read-only connection without disrupting clinical systems.