A network of medical practicesA medical booking system, taken over and made safe
A booking system other developers built years earlier, still running a network of practices every day. I took it over, found and fixed its security problems, and got its source building again, without breaking anything people relied on.
The problem
A network of medical practices ran its patient bookings on a system other developers had built years earlier. Patients ask for an appointment, staff assign a doctor, a clinic and a time, and the system sends confirmations, reminders and follow-up questionnaires. It held thousands of patients’ details and was in use every day.
The original developers had moved on. There was no documentation, part of the source code was missing, and nobody had ever reviewed it for security. The organisation needed someone to take it over and tell them, plainly, how safe it was.
It also ran on the same server as the organisation’s websites, which had just been cleaned up after a run of compromises, so it was the next thing to check.
What I did
I took the system over, reviewed it line by line, then fixed what was unsafe in small, careful steps.
- Rewrote about 37 database queries that could be manipulated from outside, so anything a visitor sends is always treated as data and never as part of a command.
- Moved stored passwords to proper one-way hashing, upgrading each one quietly the next time its owner logged in, so nobody had to reset anything.
- Made login sessions unguessable, limited repeated login attempts, closed parts of the system that anyone could reach, and stopped the scheduled email jobs being triggered from the web.
- Moved passwords and keys out of the code, and limited the system’s own database account to the tables it actually needs.
- Recovered the missing front-end source code from an old supplier archive, matched it to what was running, and documented how to build and release it.
- Separated a second system that had been copied from the first and still carried a way into patient records.
- Tested every change against a set of normal and attack scenarios before it went live, and wrote a plain report for the owners.
What changed
- The booking system kept running throughout, with nothing broken for patients or staff.
- The known ways in are closed, and what’s left to do is written down, in order.
- The organisation has working, documented source code again, and knows exactly what it has.
Under the bonnet
- PHP 8.3 API and a MySQL database shared with a WordPress site
- Angular and Ionic web app, rebuilt from recovered source
- Prepared statements throughout, bcrypt password hashing, rate-limited logins
- Scheduled email jobs restricted to the command line
- A least-privilege database account; secrets moved into configuration
- Normal and attack scenarios run before each release
Services this touched
Got something like this?
A free chat about the problem, then a written quote before any work starts.