Orchestral

Penetration Test
Scoping Call Prep

A plain-English walk-in kit for the meeting where Orchestral and the security vendor confirm assumptions, agree the rules, and lock the scope of the pen test behind HITRUST r2.

Meeting
Vendor scoping call
Prepared for
IT coordinator
Source RFQ
8 June 2026
Goal
HITRUST r2 evidence
What this is

A job posting for ethical hackers

The original document is a Request for Quote. Orchestral sends it to security companies: here is our system, here is what to try to break, send us your price and approach. Several vendors reply with quotes, and Orchestral picks one.

01

Manual, not a scan

Skilled humans finding real attack paths, not just an automated tool's checklist.

02

Grey-box, authenticated

Testers get architecture docs and real logins at several privilege levels. Faster and deeper than starting blind.

03

Synthetic data only

They attack a clone of the real system loaded with fake patient data. No real patient is ever at risk.

Why Orchestral wants this

HITRUST r2 is a safety inspection for companies that handle health data. It demands proof that an independent expert tried to hack you. This pen test produces that proof.

IndependentAn outside team, not internal review
EvidenceA formal report your auditor accepts
RetestedProof the big findings were fixed
The system being tested

Seven components, in plain language

Keycloak

The bouncer that checks IDs. Fool it, get in as someone else.

Application Client API

The main front door for querying health data. The primary way to pull data out.

Big Data Query Service

The giant search engine over the data lake. Could be tricked into over-returning.

Product Portal & Data Catalogue

Customer site plus a catalogue of where data lives. A treasure map if it leaks.

File Object Service

The mailroom for large files. Unsafe file handling is a classic way in.

JupyterHub Sandbox

A notebook playground that runs code. Running user code is risky to contain.

Inference Service

The AI model API. New surface: prompt abuse, data leakage.

The two scope options

Core, or comprehensive

Option 1

Core Assessment

  • Keycloak
  • Application Client API
  • Big Data Query Service
  • Data Catalogue
  • File Object Service
The five plumbing services.
Option 2

Comprehensive

  • Everything in Option 1, plus:
  • JupyterHub Sandbox
  • Inference Service
Recommended if HITRUST scope or customers touch the AI features. Bolting it on later usually costs more.
Out of scope

If a vendor drifts here, that's a flag

Denial-of-service, stress, or load testing

Phishing, social engineering, physical security

Real patient data or real PHI

Third-party services Orchestral does not control

The underlying AWS managed services themselves

Destructive changes, malware, persistence

Source-code review

Broad cloud-architecture review

What Orchestral gets

Six deliverables, one that the auditor wants

Executive summary

For leadership and HITRUST audit evidence.

Technical findings report

Vulnerabilities, evidence, reproduction, remediation.

CVSS severity ratings

The 0 to 10 industry score per finding.

Early Critical alerts

A call during testing, not only at the end.

Attestation letter

Confirms scope, dates, completion. The artifact your HITRUST assessor wants.

One round of retest

For Critical and High findings after you fix them.

Your one job in the call

Confirm the assumptions are true, agree the rules, and leave with three things. You are de-risking the engagement, not committing budget in the room.

1. ScopeOption 1 or Option 2
2. Start dateWhen the environment is ready
3. InputsThe list Orchestral owes the vendor
Inputs to deliver

Your gather-list

Test accounts at multiple privilege levels, ideally two tenants for isolation.identity / Keycloak
API documentation for the Client API and Big Data Query Service.dev / platform
Synthetic data loaded in the test environment. Confirm zero real PHI.data team
Sample files for the File Object Service.data / platform
Architecture overview material under NDA.you / architect
Hostnames and URLs for every in-scope component.platform / infra
Signed NDA in place before anything is shared.legal / you
Rules-of-engagement doc: window, contact, stop trigger, channel.you
Scoping-call agenda

Run it in this order

1
Confirm the environment. Non-prod clone, synthetic data, AWS.
2
Walk the components. Each reachable. Settle Option 1 vs 2.
3
Confirm exclusions. Read back the no-go list together.
4
Rules of engagement. Windows, contacts, mid-test alerts.
5
Inputs and access. Who delivers what, by when.
6
Timeline and effort. Start date, duration, person-days.
7
Deliverables and retest. Included or itemised?
8
Evidence handling. Storage, retention, secure deletion.
9
Next steps. Who finalises the quote, and what you owe first.
Questions to ask the vendor

Show them you've read the RFQ

Are your testers OSCP or CREST certified, with healthcare, AWS, API and AI experience?

What methodology do you map to: OWASP Web, API Top 10, WSTG?

How fast do you notify us of Critical findings during testing?

Is the retest included in this price or itemised separately?

Can you share a redacted sample report for our HITRUST assessor?

How do you handle evidence: storage, encryption, deletion?

Red flags

If you hear these, slow down

!
They pitch a pure automated scan. The RFQ explicitly wants manual testing.
!
They want to test real PHI or the live production system.
!
They propose touching AWS managed services or third-party services.
!
Vague on certifications, attestation letter, or retest. All HITRUST-critical.
!
No clear evidence-handling or deletion answer. A confidentiality risk.
HITRUST r2: what to protect

Guard the evidence trail

  • The attestation letter is the artifact your auditor cares about. File it with your HITRUST evidence.
  • Critical and High findings must be remediated and retested. Don't let the retest line get dropped from the quote.
  • Keep the pen-test scope consistent with the assessor's scope. AI in HITRUST scope but excluded here creates an evidence gap.
Walk in ready

Confirm. Agree.
Lock the scope.

Leave the call with a chosen scope, a start date, and your list of inputs. Protect the retest and the attestation letter. You'll be the most prepared person in the room.

Orchestral HIP · Internal prep · not for external distribution

01 / 14
Arrow keys, space, or swipe