Does HIPAA Require Penetration Testing?

HIPAA does not currently name penetration testing as an explicit requirement. The HIPAA Security Rule requires covered entities and business associates to conduct regular technical and non-technical evaluations, but leaves the specific method to the organization's discretion based on risk. However, penetration testing has become the de facto standard for satisfying the technical evaluation requirement, and HHS guidance strongly implies that organizations should conduct it.

Proposed HIPAA Security Rule amendments under HHS notice from 2024 would change this significantly. The proposed rule would make penetration testing an explicit and mandatory requirement for covered entities and business associates, specifically requiring annual testing of all electronic systems containing electronic protected health information (ePHI). While not yet final law, healthcare organizations should treat this as the direction of travel and begin building testing programs now.

Current HIPAA Requirements Relevant to Security Testing

  • Risk Analysis (§164.308(a)(1)): Requires a thorough assessment of the potential risks and vulnerabilities to ePHI. Penetration testing is the most defensible way to identify and document technical vulnerabilities.
  • Evaluation (§164.308(a)(8)): Requires periodic technical and non-technical evaluations in response to environmental or operational changes affecting security. This is where penetration testing most directly applies.
  • Audit Controls (§164.312(b)): Requires hardware, software, and procedural mechanisms to record and examine activity on systems containing ePHI.

Why Healthcare Organizations Are High-Value Targets

Healthcare organizations are among the most targeted industries for ransomware and data theft. Patient records command high prices on criminal markets, and healthcare systems frequently run legacy technology with long patch cycles. According to BreachLock's 2025 Penetration Testing Intelligence Report, 70% of vulnerabilities detected in healthcare systems were medium and high severity, largely due to widespread legacy systems and inadequate security controls. This makes independent testing especially important.

Business Associates Are Also on the Hook

HIPAA's security requirements extend to business associates, any organization that handles ePHI on behalf of a covered entity. This includes EHR vendors, billing companies, IT managed service providers, and cloud hosting providers serving healthcare clients. Business associates face the same breach notification requirements and OCR enforcement risk as covered entities.

HIPAA Security Rule Provisions Relevant to Testing

ProvisionSectionWhat it drives
Risk Analysis164.308(a)(1)Identify and document technical vulnerabilities to ePHI
Evaluation164.308(a)(8)Periodic technical evaluation, where pentesting applies
Access Controls164.312(a)(1)Verify least privilege and authentication for ePHI
Audit Controls164.312(b)Record and examine activity on systems with ePHI

What the Proposed 2024 Amendments Would Change

The HHS notice of proposed rulemaking issued in late 2024 would move penetration testing from an implied practice to an explicit, mandatory one. As drafted, it would require covered entities and business associates to perform penetration testing at least annually and vulnerability scanning more frequently, alongside stronger requirements for encryption, multi-factor authentication, asset inventories, and network segmentation. The rule is not final, but the direction is clear, and organizations that build an annual testing program now will not be scrambling when it takes effect.

Scoping a HIPAA Penetration Test

A HIPAA-focused engagement follows the ePHI. Scope typically includes internet-facing systems and patient portals, the internal network paths to electronic health record systems and databases, and the segmentation that isolates hard-to-patch medical devices from the rest of the environment. Grid32 documents findings in a form that supports your risk analysis and the Section 164.308(a)(8) evaluation requirement.

Frequently Asked Questions

Does HIPAA require penetration testing?

HIPAA does not name penetration testing explicitly, but the Security Rule requires a risk analysis and evaluation of technical safeguards protecting electronic protected health information. Penetration testing is the recognized way to evaluate those safeguards, and auditors and cyber insurers increasingly expect it for covered entities and business associates.

Are business associates subject to HIPAA security testing?

Yes. Business associates that create, receive, maintain, or transmit protected health information are directly liable under the HIPAA Security Rule. They face the same evaluation expectations as covered entities and are often asked to prove testing before a covered entity will sign a business associate agreement.

Why are healthcare organizations high-value targets?

Healthcare holds dense protected health information, runs legacy and medical devices that are hard to patch, and cannot tolerate downtime, which makes it a favored ransomware target. Penetration testing finds the exposed and unpatched systems attackers use before they are exploited.

Serving healthcare clients or handling ePHI?

Grid32 conducts HIPAA-aligned penetration tests for covered entities and business associates. Our reports document the technical evaluation required under the Security Rule.

Get a Quote →