XHack Logo
XHack
Products
Services
Compliance
Pricing
Resources
Company
Sign upLogin
XHack Logo
XHackOffensive Security

Certified offensive security team delivering penetration testing evidence written for your auditor.

OSCP+OSCPC-AI/MLPenCASA
support@xhack.io

24/7 SOC Operations

XHack Status
Under attack? Get help now
Services
  • VAPT Services
  • Red Teaming
  • SOC Services
  • Threat Intelligence
  • Incident Response
  • Managed Testing
Pricing
  • Platform Plans
  • Services Pricing
Compliance
  • SOC 2
  • PCI DSS
  • ISO 27001
  • GDPR
  • HIPAA
  • ISO 42001
  • AI Maturity Assessment
  • TX-RAMP
  • NBFC / SECP
  • All Frameworks
Products
  • Vulnerability Assessment
  • GitGuard
  • AI Probe
  • SOC Dashboard
  • AI Agent
  • Cloud Investigation
Comparison
  • XBOW vs XHack
  • Horizon3 vs XHack
  • Strix vs XHack
  • Pentera vs XHack
Resources
  • Platform Tour
  • All Features
  • Install the Agent
  • XHack AI
  • Documentation
  • Blog
  • Case Studies
  • Documents
  • FAQ
Company
  • About Us
  • Our Team
  • Certifications
  • Security and Trust
  • VAPT Explained
  • Contact

© 2026 XHack. All rights reserved.

Security & TrustVulnerability DisclosurePrivacy PolicyTerms of ServiceRefund Policy
Blog/General

HIPAA Penetration Testing: The Complete 2026 Guide

salman

salman

Author

July 31, 2026

14 min read

HIPAA Penetration Testing: The Complete 2026 Guide

Table of contents

19

What HIPAA Penetration Testing Is

Is HIPAA Penetration Testing Required Today?

What the Proposed Rule Would Change

Where the Proposed Rule Stands in September 2026

Why Not Wait for the Final Rule

What HIPAA Penetration Testing Should Cover

Getting Approval and Scoping HIPAA Penetration Testing Safely

How Often to Run HIPAA Penetration Testing

What a HIPAA Penetration Testing Report Should Contain

What HIPAA Penetration Testing Costs

How XHack Fits

FAQ: HIPAA Penetration Testing Questions Answered

Is HIPAA penetration testing required?

How often should I do HIPAA penetration testing?

Does the new HIPAA rule make penetration testing mandatory?

Who needs HIPAA penetration testing?

How much does HIPAA penetration testing cost?

What is the difference between a HIPAA risk analysis and HIPAA penetration testing?

The Bottom Line

By Salman Khan, OSCP+, Founder of XHack, SRT (Synack Red Team member)

Read this in 30 seconds: HIPAA penetration testing is not required by name today. But a rule that would require it is written, and the risk analysis you must already do points straight at it.

  • Today, the rule says “evaluate.” 45 CFR 164.308(a)(8) requires a “periodic technical and nontechnical evaluation” of your safeguards. It names no method and no schedule. NIST’s HIPAA guide lists penetration testing as one method “if reasonable and appropriate.”
  • The proposal says “test every year.” HHS’s proposed rule (published January 6, 2025) would add scans at least every six months and penetration testing at least every 12 months by a “qualified person.”
  • It is still only a proposal. In July 2026, the law firm Clark Hill reported that HHS moved it to a long-term agenda with a July 2027 target, after more than 4,000 comments.
  • Enforcement has not waited. OCR had brought 12 enforcement actions under its Risk Analysis Initiative by March 2026, so regulators already ask whether you looked for weaknesses.
  • Our advice: test annually and scan every six months now. That fits today’s rule and the proposed one.

Most HIPAA articles get this wrong in one of two directions. Some say a pentest is already the law, and some say it is optional. Neither is true.

Under the current Security Rule, HIPAA penetration testing is one of the best ways to prove your safeguards work, but no sentence in the rule tells you to do it. Under the proposed rule, it would become a hard requirement with a clock.

Here is what each version says, what to do about the gap, and how to scope a test that protects patient data.

HIPAA penetration testing today versus the proposed rule: the current evaluation standard has no method or schedule, the proposal adds six-month scans and 12-month penetration testing by a qualified person
HIPAA penetration testing today and under the proposed Security Rule

What HIPAA Penetration Testing Is

HIPAA penetration testing is a security test where skilled testers try to break into the systems that handle electronic protected health information (ePHI). They act like an attacker, but with permission, to find weaknesses before a real attacker does.

The focus is healthcare. Testers look at the systems where patient data lives and moves: the EHR, patient portals, billing systems, the APIs between them, cloud hosting and staff access.

It applies to covered entities (providers, health plans and clearinghouses) and to business associates, which means any vendor, contractor or SaaS company that handles ePHI for a covered entity.

Is HIPAA Penetration Testing Required Today?

Not by name. The Security Rule is technology-neutral, so it does not list tools or tests. It asks for outcomes, and HIPAA penetration testing helps with two of them.

1. The risk analysis. You must assess the risks and vulnerabilities to your ePHI. A pentest shows which weaknesses an attacker could really use, which a paper review cannot.

2. The evaluation standard. This is 45 CFR 164.308(a)(8), and it is the closest thing to a testing rule:

“Perform a periodic technical and nontechnical evaluation, based initially upon the standards implemented under this rule and, subsequently, in response to environmental or operational changes affecting the security of electronic protected health information, that establishes the extent to which a covered entity’s or business associate’s security policies and procedures meet the requirements of this subpart.”

Read it closely. It says “technical” evaluation, which is where HIPAA penetration testing fits. It says “periodic,” which is undefined. It names no method, no frequency and no tester qualification.

NIST fills in some of the gap. Its HIPAA guide, SP 800-66 Rev. 2, lists this among the steps of an evaluation: “Conduct penetration testing (where testers attempt to compromise system security for the sole purpose of testing the effectiveness of security controls), if reasonable and appropriate.” It also asks whether senior management gave “specifically worded, written approval” before any planned penetration test.

So the honest summary is short. HIPAA penetration testing is not mandatory by name. It is recognized guidance, and skipping it means you need another way to prove your technical safeguards work.

For contrast, PCI DSS names the test outright, as our PCI DSS penetration testing requirements guide shows, while ISO 27001 does not, as our ISO 27001 penetration testing guide explains. HIPAA sits closer to ISO 27001 today.

What the Proposed Rule Would Change

HHS signed the proposal in December 2024, and it was published in the Federal Register on January 6, 2025. Comments closed on March 7, 2025.

It adds a new section, proposed 45 CFR 164.312(h), on vulnerability management. This is the wording for penetration testing:

“Perform penetration testing of the covered entity’s or business associate’s relevant electronic information systems by a qualified person… Penetration testing must be performed at least once every 12 months or in accordance with the covered entity’s or business associate’s risk analysis… whichever is more frequent.”

The proposal defines a qualified person as someone “with appropriate knowledge of and experience with generally accepted cybersecurity principles and methods.” It names no certification.

The same section would add automated vulnerability scans “at least once every six months,” or more often if your risk analysis says so.

The other changes that matter for testing:

  • Fix clocks. The proposal would require patching or updating within 15 calendar days for a critical risk and 30 calendar days for a high risk, where a patch exists.
  • No more “addressable.” HHS proposes to remove the difference between “addressable” and “required” specifications, so all of them become required, with limited exceptions.
  • Business associates. A regulated entity would have to get written verification at least every 12 months that each business associate has deployed the required technical safeguards, with a written analysis of the associate’s systems.
  • Timing. A final rule would take effect 60 days after publication, and compliance would be due 180 days after that.
HIPAA Security Rule proposal timeline: published January 6, 2025, comments closed March 7, 2025, moved to the long-term agenda in July 2026 with a July 2027 target, 60 days to take effect and 180 days to comply
HIPAA penetration testing under the proposed rule: where the timeline stands

Where the Proposed Rule Stands in September 2026

The rule is still proposed. It has not been finalized, and it has not been withdrawn.

In July 2026, Clark Hill reported that HHS moved the proposal to its Long-Term Actions agenda and named July 2027 as its target for final action. Agenda dates are estimates, not deadlines, but the firm notes that the placement “generally indicates that HHS does not anticipate issuing a final rule within the next 12 months.”

The proposal drew more than 4,000 comments. HHS estimated the cost at about $9 billion in the first year and about $6 billion a year after that, so pushback on cost is no surprise.

Treat the proposal as a signal, not as law. It shows where HHS wants HIPAA penetration testing to end up, and it may still change.

Why Not Wait for the Final Rule

Because the current rule already asks for the evidence that HIPAA penetration testing produces, and regulators already ask for it.

OCR announced its 11th and 12th enforcement actions under its Risk Analysis Initiative in March 2026. These actions are about risk analysis, so the question they raise is simple: did you identify the risks and vulnerabilities to your ePHI? A current pentest report is direct evidence that you looked.

There is also a timing problem. If the rule finalizes as proposed, you would have about 240 days from publication to comply. A testing program, with scoping, fixes and a retest, does not start well inside that window.

One more number is worth a look. HHS’s own cost model assumes about three hours of burden per regulated entity for penetration testing. Do not budget from that. A real test takes days, and the fixes take longer.

What HIPAA Penetration Testing Should Cover

The simple rule is to follow the ePHI. Wherever patient data is created, stored or sent, the test should reach.

What HIPAA penetration testing should cover: external and internal networks, web apps and patient portals, APIs, cloud environments, medical devices, access controls and business associate access paths
What HIPAA penetration testing should cover: follow the ePHI
  • External network: internet-facing systems, the first thing an attacker tries.
  • Internal network: what an attacker could reach after getting a foothold.
  • Web applications: patient portals, scheduling and billing apps, and anything else that touches ePHI.
  • APIs: the interfaces between healthcare systems, an attack surface that keeps growing.
  • Access controls: logins, roles and password resets, since improper access to ePHI is the core HIPAA worry.
  • Cloud: the platforms and SaaS tools that host patient data.
  • Vendor access: the paths your business associates and support staff use to reach ePHI.

Medical devices need their own plan. Connected devices often cannot be patched easily and can sit on the same networks as ePHI. Test them only under a plan agreed with clinical engineering, because a bad test can affect patient care. Ask any provider whether they test devices at all.

A test that covers the office network and skips the cloud-hosted patient portal misses where the risk is.

Getting Approval and Scoping HIPAA Penetration Testing Safely

NIST’s guide asks whether senior management gave written approval before a planned pentest. That is a good habit even without the rule, and it is the first item in a safe engagement.

Agree these in writing before testing starts:

  • Scope: which systems and environments are in, and which are off limits.
  • Windows: dates and hours, with quiet hours for anything that could affect care.
  • Contacts: who to call the moment something breaks.
  • Data handling: how the tester treats any ePHI seen during testing, and how long evidence is kept.

Our penetration testing checklist walks through an engagement from scoping to report.

How Often to Run HIPAA Penetration Testing

Today the answer is risk-based: as often as your risk analysis says, and after major changes such as a new patient portal, an EHR migration or a big infrastructure update.

The proposal would set the floor at once every 12 months, plus scans every six months. You can adopt that schedule now. It fits both versions of the rule, and most mature healthcare security teams already work this way.

What a HIPAA Penetration Testing Report Should Contain

The report is your evidence, so it should stand on its own. A good one has:

  • Scope: which ePHI-handling systems were tested, and which were left out.
  • Method: how the testing was done, and by whom.
  • Findings: each with a severity, the proof, and the specific risk to ePHI.
  • Fixes and retest: guidance to fix each finding, and a retest confirming it worked.

The last point matters more under the proposal. Its fix clocks (15 days for critical, 30 for high) are tied to the results of penetration tests, so a report with no owner and no due date leaves you with a finding and no plan. Our vulnerability assessment vs penetration testing guide explains why a scan is not a substitute.

For business associates, a recent report also answers the questions covered entities ask. Under the proposal, they would have to get written proof of your safeguards every year.

What HIPAA Penetration Testing Costs

Scope drives the price of HIPAA penetration testing. The number of ePHI-handling systems, the mix of networks, apps and APIs, and whether internal testing is included all matter.

XHack publishes fixed prices, with the retest included:

  • Essential, from $2,500: one unauthenticated web application or up to 50 host IPs, external.
  • Assurance, from $5,000: up to 3 unauthenticated web apps, 1 low-complexity authenticated web app, or up to 100 host IPs, internal and external, across web, host, API and mobile.
  • Comprehensive, from $12,000: up to 20 unauthenticated web apps, 3 authenticated web apps, or up to 200 host IPs, with a cloud configuration review.

Larger or unusual environments are quoted. Judge any offer by what it includes: how much is manual, who the testers are, whether the retest is included, and whether the report would satisfy your risk analysis. Our VAPT services buyer guide shows how to compare quotes.

How XHack Fits

XHack does not certify, approve or issue HIPAA compliance certificates, and no penetration testing company can decide whether you comply. What we deliver for HIPAA penetration testing is a report built to give you the technical evidence your evaluation and risk analysis need.

Our published sample report maps its findings to HIPAA §164.308(a)(8), which it describes as “Technical evaluation of safeguards,” alongside PCI DSS, SOC 2, ISO 27001 and GDPR. It is a sample with a redacted client. You can read our sample report.

The tier whose card names HIPAA is Assurance, from $5,000. The card says “Evidence mapped to PCI DSS, SOC 2, ISO 27001, HIPAA and GDPR.” One report can serve more than one audit, which our penetration testing for compliance guide covers in full.

Every engagement includes certified human testers. The XHack AI agent runs alongside them only with your explicit permission, at no extra cost, and its pentest chats and session data stay on your own machine, where you can delete them any time.

We also offer compliance consulting for gap analysis, policy work and audit preparation. Want a fixed-price quote scoped to your ePHI systems? Request one and expect a reply within 24 hours.

FAQ: HIPAA Penetration Testing Questions Answered

Is HIPAA penetration testing required?

Not by name. The current Security Rule requires a risk analysis and a “periodic technical and nontechnical evaluation” of your safeguards, and NIST lists penetration testing as one method “if reasonable and appropriate.” A proposed rule would require HIPAA penetration testing at least every 12 months, but it is not final.

How often should I do HIPAA penetration testing?

Today, as often as your risk analysis says and after major changes. The proposed rule would require penetration testing at least once every 12 months and automated scans at least every six months. Adopting both schedules now fits either version.

Does the new HIPAA rule make penetration testing mandatory?

It would, but it is not law yet. HHS published the proposal on January 6, 2025. As of July 2026, it sits on HHS’s long-term agenda with a July 2027 target, so the current Security Rule still applies.

Who needs HIPAA penetration testing?

Covered entities and business associates alike. That means providers, health plans, clearinghouses, and any vendor or SaaS company that handles ePHI for them. The proposal would require covered entities to get written verification of their business associates’ safeguards every 12 months.

How much does HIPAA penetration testing cost?

It depends on scope. XHack’s fixed prices start at $2,500 for a single application or up to 50 host IPs, $5,000 for up to 100 host IPs or several apps, and $12,000 for up to 200 host IPs or 20 web apps, each with a retest included.

What is the difference between a HIPAA risk analysis and HIPAA penetration testing?

A risk analysis is a broad review of the risks to ePHI across the whole organization, and the current rule requires it. HIPAA penetration testing is a hands-on test of your technical defenses. They work together: the test shows what an attacker could really do, and the analysis decides what to fix first.

The Bottom Line

HIPAA penetration testing sits between two facts. Today’s rule asks you to evaluate your safeguards and does not name the method. The proposed rule would name it, with a clock, but it is still a proposal and its target date has slipped to 2027.

The safe move for HIPAA penetration testing does not depend on the outcome: test annually, scan every six months, get written approval, fix findings on a clock, and retest. It satisfies the rule you have now and the one that may come.

If you handle ePHI and want HIPAA penetration testing scoped to your systems, see the fixed-price tiers. We will tell you honestly if a scan is all you need.


Categories

GeneralSecurity

Previous

OWASP Top 10 for LLM: The Complete 2025 Risks Guide

Next

MCP Server Security: The Critical 2026 Risk Guide

On this page

What HIPAA Penetration Testing Is

Is HIPAA Penetration Testing Required Today?

What the Proposed Rule Would Change

Where the Proposed Rule Stands in September 2026

Why Not Wait for the Final Rule

What HIPAA Penetration Testing Should Cover

Getting Approval and Scoping HIPAA Penetration Testing Safely

How Often to Run HIPAA Penetration Testing

What a HIPAA Penetration Testing Report Should Contain

What HIPAA Penetration Testing Costs

How XHack Fits

FAQ: HIPAA Penetration Testing Questions Answered

Is HIPAA penetration testing required?

How often should I do HIPAA penetration testing?

Does the new HIPAA rule make penetration testing mandatory?

Who needs HIPAA penetration testing?

How much does HIPAA penetration testing cost?

What is the difference between a HIPAA risk analysis and HIPAA penetration testing?

The Bottom Line

Related articles

Continue reading

Career Paths After Bug Bounty: 5 Honest Routes From Hunter to Founder

Security

Career Paths After Bug Bounty: 5 Honest Routes From Hunter to Founder

A bug bounty career can lead to pentesting, AppSec, red teaming, the platform side or a company. Five honest routes, wit...

Read article
API Credits: The Complete 2026 XHack AI API Guide

Security

API Credits: The Complete 2026 XHack AI API Guide

API credits for the XHack AI API: how to buy them, create a key, price each request, and connect Codex, Claude Code and ...

Read article
XHack AI Can Make Mistakes: What Goes Wrong, Why, and How to Catch It

Security

XHack AI Can Make Mistakes: What Goes Wrong, Why, and How to Catch It

AI mistakes in pentesting: how XHack AI errs, why they happen, what research shows, and the checks that catch false posi...

Read article