The planned scenario

Hospital Network separates public patient services from internal systems that a healthcare organization would protect differently. Appointments, provider information, and research documents form the public surface. EHR integration metadata, imaging records, pharmacy workflow data, and device inventory form the private context.

This suits an exercise needing several kinds of sensitive business information rather than a generic customer database. A participant can distinguish a provider directory from an appointment record, or research metadata from an internal imaging reference, and explain why those objects need different access rules.

Public surfaces

These reference routes describe possible entry points in the scenario model. They are not live customer services or a guarantee of the routes in a particular product release. Use your configured exercise inventory as the authoritative scope.

Public routes declared in the Hospital Network catalog
RouteSurfaceContext
/patient-portalPatient portal facade for appointments and records workflow.
/appointmentsappointments-apiAppointment and referral API simulation.
/providersprovider-directoryPublic provider directory and department listing.
/researchresearch-docsResearch document and trial metadata facade.

Private systems

These service names and segments describe the internal context of Hospital Network. They help define exercise boundaries and interpret the generated records.

ehr-integration

Private EHR integration and message queue simulation. Catalog segment: private application.

imaging-archive

PACS/imaging metadata store representation. Catalog segment: private data.

pharmacy-workflow

Medication order and pharmacy workflow data. Catalog segment: private application.

device-inventory

Biomedical and bedside device inventory. Catalog segment: private data.

Configure your exercise

Choose a question for the assignment and define the evidence participants should collect.

  • Which information can be public in a provider directory while remaining inappropriate for appointment or patient record views?
  • How should research documents be distinguished from clinical imaging and pharmacy workflow metadata?
  • What evidence shows that a device inventory observation belongs to the represented private context rather than a public patient service?

What to hand in

Create a classification and exposure report separating patient, public directory, research, clinical workflow, and device context. Link observations to actual synthetic records and avoid importing real patient information.

Records and evidence

Synthetic patients, appointments, departments, research documents, imaging metadata, and device inventory make the exercise specific to healthcare. Organize the findings by intended audience: patients, public directory visitors, researchers, and internal clinical or device operations.

  • patients-synthetic
  • appointments
  • departments
  • research-docs
  • imaging-metadata
  • device-inventory

Preserve the scenario and product version, the record or observation, and its source with each finding. Distinguish what a participant observed from what the reviewer inferred. Use synthetic data and your defined evidence-retention rules.

Public self-service at launch

Managed Verse is planned for 1 January 2027. Users will create an account, choose a scenario and configure their own authorized exercise boundaries. Vulnverse will host and operate the platform and cloud; users will not need to provision or maintain an exercise cloud.

Managed Verse is planned to replace all previous services. All new inquiries are paused during the transition. Read Managed Verse →.