
Table of contents
19
By Salman Khan, OSCP+, Founder of XHack, SRT (Synack Red Team member)
Read this in 30 seconds: HIPAA penetration testing is not required by name today. But a rule that would require it is written, and the risk analysis you must already do points straight at it.
- Today, the rule says “evaluate.” 45 CFR 164.308(a)(8) requires a “periodic technical and nontechnical evaluation” of your safeguards. It names no method and no schedule. NIST’s HIPAA guide lists penetration testing as one method “if reasonable and appropriate.”
- The proposal says “test every year.” HHS’s proposed rule (published January 6, 2025) would add scans at least every six months and penetration testing at least every 12 months by a “qualified person.”
- It is still only a proposal. In July 2026, the law firm Clark Hill reported that HHS moved it to a long-term agenda with a July 2027 target, after more than 4,000 comments.
- Enforcement has not waited. OCR had brought 12 enforcement actions under its Risk Analysis Initiative by March 2026, so regulators already ask whether you looked for weaknesses.
- Our advice: test annually and scan every six months now. That fits today’s rule and the proposed one.
Most HIPAA articles get this wrong in one of two directions. Some say a pentest is already the law, and some say it is optional. Neither is true.
Under the current Security Rule, HIPAA penetration testing is one of the best ways to prove your safeguards work, but no sentence in the rule tells you to do it. Under the proposed rule, it would become a hard requirement with a clock.
Here is what each version says, what to do about the gap, and how to scope a test that protects patient data.

HIPAA penetration testing is a security test where skilled testers try to break into the systems that handle electronic protected health information (ePHI). They act like an attacker, but with permission, to find weaknesses before a real attacker does.
The focus is healthcare. Testers look at the systems where patient data lives and moves: the EHR, patient portals, billing systems, the APIs between them, cloud hosting and staff access.
It applies to covered entities (providers, health plans and clearinghouses) and to business associates, which means any vendor, contractor or SaaS company that handles ePHI for a covered entity.
Not by name. The Security Rule is technology-neutral, so it does not list tools or tests. It asks for outcomes, and HIPAA penetration testing helps with two of them.
1. The risk analysis. You must assess the risks and vulnerabilities to your ePHI. A pentest shows which weaknesses an attacker could really use, which a paper review cannot.
2. The evaluation standard. This is 45 CFR 164.308(a)(8), and it is the closest thing to a testing rule:
“Perform a periodic technical and nontechnical evaluation, based initially upon the standards implemented under this rule and, subsequently, in response to environmental or operational changes affecting the security of electronic protected health information, that establishes the extent to which a covered entity’s or business associate’s security policies and procedures meet the requirements of this subpart.”
Read it closely. It says “technical” evaluation, which is where HIPAA penetration testing fits. It says “periodic,” which is undefined. It names no method, no frequency and no tester qualification.
NIST fills in some of the gap. Its HIPAA guide, SP 800-66 Rev. 2, lists this among the steps of an evaluation: “Conduct penetration testing (where testers attempt to compromise system security for the sole purpose of testing the effectiveness of security controls), if reasonable and appropriate.” It also asks whether senior management gave “specifically worded, written approval” before any planned penetration test.
So the honest summary is short. HIPAA penetration testing is not mandatory by name. It is recognized guidance, and skipping it means you need another way to prove your technical safeguards work.
For contrast, PCI DSS names the test outright, as our PCI DSS penetration testing requirements guide shows, while ISO 27001 does not, as our ISO 27001 penetration testing guide explains. HIPAA sits closer to ISO 27001 today.
HHS signed the proposal in December 2024, and it was published in the Federal Register on January 6, 2025. Comments closed on March 7, 2025.
It adds a new section, proposed 45 CFR 164.312(h), on vulnerability management. This is the wording for penetration testing:
“Perform penetration testing of the covered entity’s or business associate’s relevant electronic information systems by a qualified person… Penetration testing must be performed at least once every 12 months or in accordance with the covered entity’s or business associate’s risk analysis… whichever is more frequent.”
The proposal defines a qualified person as someone “with appropriate knowledge of and experience with generally accepted cybersecurity principles and methods.” It names no certification.
The same section would add automated vulnerability scans “at least once every six months,” or more often if your risk analysis says so.
The other changes that matter for testing:

The rule is still proposed. It has not been finalized, and it has not been withdrawn.
In July 2026, Clark Hill reported that HHS moved the proposal to its Long-Term Actions agenda and named July 2027 as its target for final action. Agenda dates are estimates, not deadlines, but the firm notes that the placement “generally indicates that HHS does not anticipate issuing a final rule within the next 12 months.”
The proposal drew more than 4,000 comments. HHS estimated the cost at about $9 billion in the first year and about $6 billion a year after that, so pushback on cost is no surprise.
Treat the proposal as a signal, not as law. It shows where HHS wants HIPAA penetration testing to end up, and it may still change.
Because the current rule already asks for the evidence that HIPAA penetration testing produces, and regulators already ask for it.
OCR announced its 11th and 12th enforcement actions under its Risk Analysis Initiative in March 2026. These actions are about risk analysis, so the question they raise is simple: did you identify the risks and vulnerabilities to your ePHI? A current pentest report is direct evidence that you looked.
There is also a timing problem. If the rule finalizes as proposed, you would have about 240 days from publication to comply. A testing program, with scoping, fixes and a retest, does not start well inside that window.
One more number is worth a look. HHS’s own cost model assumes about three hours of burden per regulated entity for penetration testing. Do not budget from that. A real test takes days, and the fixes take longer.
The simple rule is to follow the ePHI. Wherever patient data is created, stored or sent, the test should reach.

Medical devices need their own plan. Connected devices often cannot be patched easily and can sit on the same networks as ePHI. Test them only under a plan agreed with clinical engineering, because a bad test can affect patient care. Ask any provider whether they test devices at all.
A test that covers the office network and skips the cloud-hosted patient portal misses where the risk is.
NIST’s guide asks whether senior management gave written approval before a planned pentest. That is a good habit even without the rule, and it is the first item in a safe engagement.
Agree these in writing before testing starts:
Our penetration testing checklist walks through an engagement from scoping to report.
Today the answer is risk-based: as often as your risk analysis says, and after major changes such as a new patient portal, an EHR migration or a big infrastructure update.
The proposal would set the floor at once every 12 months, plus scans every six months. You can adopt that schedule now. It fits both versions of the rule, and most mature healthcare security teams already work this way.
The report is your evidence, so it should stand on its own. A good one has:
The last point matters more under the proposal. Its fix clocks (15 days for critical, 30 for high) are tied to the results of penetration tests, so a report with no owner and no due date leaves you with a finding and no plan. Our vulnerability assessment vs penetration testing guide explains why a scan is not a substitute.
For business associates, a recent report also answers the questions covered entities ask. Under the proposal, they would have to get written proof of your safeguards every year.
Scope drives the price of HIPAA penetration testing. The number of ePHI-handling systems, the mix of networks, apps and APIs, and whether internal testing is included all matter.
XHack publishes fixed prices, with the retest included:
Larger or unusual environments are quoted. Judge any offer by what it includes: how much is manual, who the testers are, whether the retest is included, and whether the report would satisfy your risk analysis. Our VAPT services buyer guide shows how to compare quotes.
XHack does not certify, approve or issue HIPAA compliance certificates, and no penetration testing company can decide whether you comply. What we deliver for HIPAA penetration testing is a report built to give you the technical evidence your evaluation and risk analysis need.
Our published sample report maps its findings to HIPAA §164.308(a)(8), which it describes as “Technical evaluation of safeguards,” alongside PCI DSS, SOC 2, ISO 27001 and GDPR. It is a sample with a redacted client. You can read our sample report.
The tier whose card names HIPAA is Assurance, from $5,000. The card says “Evidence mapped to PCI DSS, SOC 2, ISO 27001, HIPAA and GDPR.” One report can serve more than one audit, which our penetration testing for compliance guide covers in full.
Every engagement includes certified human testers. The XHack AI agent runs alongside them only with your explicit permission, at no extra cost, and its pentest chats and session data stay on your own machine, where you can delete them any time.
We also offer compliance consulting for gap analysis, policy work and audit preparation. Want a fixed-price quote scoped to your ePHI systems? Request one and expect a reply within 24 hours.
Not by name. The current Security Rule requires a risk analysis and a “periodic technical and nontechnical evaluation” of your safeguards, and NIST lists penetration testing as one method “if reasonable and appropriate.” A proposed rule would require HIPAA penetration testing at least every 12 months, but it is not final.
Today, as often as your risk analysis says and after major changes. The proposed rule would require penetration testing at least once every 12 months and automated scans at least every six months. Adopting both schedules now fits either version.
It would, but it is not law yet. HHS published the proposal on January 6, 2025. As of July 2026, it sits on HHS’s long-term agenda with a July 2027 target, so the current Security Rule still applies.
Covered entities and business associates alike. That means providers, health plans, clearinghouses, and any vendor or SaaS company that handles ePHI for them. The proposal would require covered entities to get written verification of their business associates’ safeguards every 12 months.
It depends on scope. XHack’s fixed prices start at $2,500 for a single application or up to 50 host IPs, $5,000 for up to 100 host IPs or several apps, and $12,000 for up to 200 host IPs or 20 web apps, each with a retest included.
A risk analysis is a broad review of the risks to ePHI across the whole organization, and the current rule requires it. HIPAA penetration testing is a hands-on test of your technical defenses. They work together: the test shows what an attacker could really do, and the analysis decides what to fix first.
HIPAA penetration testing sits between two facts. Today’s rule asks you to evaluate your safeguards and does not name the method. The proposed rule would name it, with a clock, but it is still a proposal and its target date has slipped to 2027.
The safe move for HIPAA penetration testing does not depend on the outcome: test annually, scan every six months, get written approval, fix findings on a clock, and retest. It satisfies the rule you have now and the one that may come.
If you handle ePHI and want HIPAA penetration testing scoped to your systems, see the fixed-price tiers. We will tell you honestly if a scan is all you need.
Related articles