“I’m calling for my partner.”
Does the caller have current permission to cancel this appointment—or just enough information to sound convincing?
Test the permission ↗PATIENT-ACCESS PENETRATION TESTING
A convincing request. An unchecked permission. A real change to someone’s care arrangements.
We test who can act through your voice agents, chat and portals—and follow the result into your scheduling records, communications and recovery.
Independent assessment. Your workflow. Your rules. Led by Cole Lyons.
THE ACTION BEHIND THE ANSWER
A helpful answer can hide an unauthorized write, an unresolved transaction or a patient left without a workable next step.
Does the caller have current permission to cancel this appointment—or just enough information to sound convincing?
Test the permission ↗If the first change committed before the response timed out, a retry can create another error. What does the record actually show?
Test the recovery ↗Who owns that request? A blocked write still needs a truthful status and an assisted route the patient can use.
Test the handoff ↗Illustrative assessment scenarios. No customer system or patient outcome is represented.
A DOCUMENTED FAILURE CLASS
A June 2026 Easy!Appointments maintainer advisory describes authenticated users obtaining other providers’ appointment identifiers and using them to modify or delete appointments.
This is a specific software advisory, not evidence that most hospitals are vulnerable or that AI caused the flaw.
Read the maintainer’s advisory ↗ONE FLAGSHIP ENGAGEMENT
Start with one consequential workflow and the dependencies that make it work. Get evidence your security, operations and vendor teams can act on.
EXAMPLE SCOPE
One voice agent and scheduling connector, with agreed patient and proxy roles, record access, notifications, handoff and a recovery path.
Explore the engagementApproved rules, dependencies, test authorization and expected outcomes.
Adversarial cases paired with legitimate use, tied to authoritative records.
Prioritized findings, corrective owners and a bounded retest of agreed fixes.
Before an access rollout, connector change or vendor acceptance decision.
Independent evidence for a configured customer workflow and its shared responsibilities.
Separately scoped refill intake, pickup authority and account access, using pharmacy-specific rules.
INSPECT THE WORK PRODUCT
See how a finding separates an attempted action from a committed change—and includes the legitimate request the fix must preserve.
Read the synthetic finding ↗DIRECT ACCOUNTABILITY
Access Red Team is a founder-led practice built around the systems behind patient access.
Cole’s published work connects authorization, operational quality and recovery. He leads scoping, assessment communication and the handoff of evidence to your team.
START WITH ONE WORKFLOW
Tell Cole where a request becomes an action. Start a conversation about scope, evidence and the decision you need to make.
Cole is available around the clock for customer concerns. Live answering and technical response depend on the contact route and your engagement.
For an urgent existing-customer concern, use your agreed escalation route. If Cole is occupied, leave a callback request there and contact your organization’s responsible owner.