# GSoC 2026: Security Audit and Hardening of the OpenELIS Laboratory Information System

**URL:** <https://talk.openelis-global.org/t/gsoc-2026-security-audit-and-hardening-of-the-openelis-laboratory-information-system/2125>\
**Category:** Community\
**Created:** [March 16, 2026, 6:18pm UTC](https://talk.openelis-global.org/t/gsoc-2026-security-audit-and-hardening-of-the-openelis-laboratory-information-system/2125 "2026-03-16T18:18:14Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![tasksolver](https://yyz2.discourse-cdn.com/flex030/user_avatar/talk.openelis-global.org/tasksolver/32/1067_2.png) [@tasksolver](https://talk.openelis-global.org/u/tasksolver)\
**Post date:** [March 16, 2026, 6:18pm UTC](https://talk.openelis-global.org/t/gsoc-2026-security-audit-and-hardening-of-the-openelis-laboratory-information-system/2125/1 "2026-03-16T18:18:14Z")

</div>

**Name:** Brian Patrick Bahati

**Email:** [bahatibrianp@gmail.com](mailto:bahatibrianp@gmail.com)

**GitHub/Portfolio:** [Bahati308 (Brian308) · GitHub](https://github.com/Bahati308)

**LinkedIn** [https://www.linkedin.com/in/brian-patrick-bahati/](https://www.linkedin.com/in/brian-patrick-bahati/)

## **Synopsis / Abstract**

As a system handling sensitive health information, ensuring the security and integrity of OpenELIS is critical. This project aims to perform a **comprehensive security audit** , identifying vulnerabilities, risks, and potential attack surfaces, and recommending fixes or implementing safeguards where feasible.

The goal is to provide OpenELIS with a **robust security baseline** , enhancing trust, compliance with data protection standards, and long-term maintainability.

## **Benefits to the Community**

1. **Stronger Security Posture:** Identify and mitigate vulnerabilities to protect patient and laboratory data.

2. **Community Awareness:** Provide the OpenELIS community with a detailed security report and best practices for secure deployment.

3. **Compliance:** Align OpenELIS with global healthcare security standards (e.g., HIPAA, GDPR compliance considerations).

4. **Open-Source Security Contribution:** Set an example of secure software practices in open-source healthcare projects.

## **Deliverables / Expected Results**

By the end of this project, the following will be delivered:

1. **Security Audit Report**

2. **Test Cases & Automation Scripts**

3. **Optional Fixes**

4. **Documentation**

## **Technical Details / Implementation Plan**

**Phase 1 – Initial Assessment (Weeks 1–2)**

- Understand OpenELIS Global architecture and components

- Map out potential threat vectors

- Review existing security documentation

**Phase 2 – Vulnerability Scanning (Weeks 3–4)**

- Perform static and dynamic code analysis

- Analyze dependencies for known vulnerabilities

- Test for common security risks (SQL injection, XSS, CSRF, insecure file handling)

**Phase 3 – Risk Analysis & Prioritization (Weeks 5–6)**

- Categorize vulnerabilities by severity

- Identify immediate, medium-term, and long-term security actions

**Phase 4 – Mitigation and Patching (Weeks 7–10)**

- Implement fixes or suggest remediations

- Develop automated CI/CD checks for security issues

**Phase 5 – Reporting and Documentation (Weeks 11–12)**

- Compile final security report with findings, mitigations, and recommendations

- Provide documentation for contributors to maintain secure practices

## **Requirements / Skills Needed**

- Strong understanding of web application security and secure coding practices

- Familiarity with OWASP Top 10 and security best practices for web-based software

- Experience with Python, Java, or related languages used in OpenELIS

- Knowledge of CI/CD, automated testing, and static analysis tools

- Basic understanding of healthcare compliance and data privacy standards

## **Why I Am a Good Fit**

- Certified in Ethical Hacking, Cybersecurity, and Networking

- Experienced in auditing and securing open-source codebases

- Strong background in web applications, DevOps practices, and automated testing

- Passionate about contributing to healthcare IT projects and improving open-source software

- Participated in GSoC 2025 where I improved the E2E QA Tests with OpenELIS

## **References / Resources**

- OpenELIS Global repository: [OpenELIS · GitHub](https://github.com/OpenELIS)

- OWASP Top Ten: [https://owasp.org/www-project-top-ten/](https://owasp.org/www-project-top-ten/)

- Security testing tools: OWASP ZAP, Bandit (Python), SonarQube, Snyk

- Relevant papers and guides on secure lab information systems

## **Future Work**

- Continuous security monitoring integration into OpenELIS CI/CD pipeline

- Regular security audits and automated patching of dependencies

- Education for community contributors on secure coding practices

**Any idea on this project is very welcome and will be glad to hear it.**

cc: @caseyi , @Moses_Mutesasira

---

<div class="post-metadata">

**Author:** ![anujmishra](https://yyz2.discourse-cdn.com/flex030/user_avatar/talk.openelis-global.org/anujmishra/32/1151_2.png) [@anujmishra](https://talk.openelis-global.org/u/anujmishra)\
**Post date:** [March 17, 2026, 8:04am UTC](https://talk.openelis-global.org/t/gsoc-2026-security-audit-and-hardening-of-the-openelis-laboratory-information-system/2125/2 "2026-03-17T08:04:04Z")

</div>

Hi, I’m Anuj Mishra, a beginner contributor interested in GSoC 2026.  
This proposal is really insightful.  
I wanted to ask if there are smaller security-related tasks or beginner-friendly issues where I can start contributing and gradually learn about security auditing in OpenELIS.
