HIPAA penetration testing
HIPAA (Health Insurance Portability and Accountability Act)
Technical evaluation of your safeguards for systems handling PHI, the evidence the Security Rule evaluation standard expects.
Engagement at a glance
Drives testing
§164.308(a)(8) and §164.308(a)(1)(ii)(A): Evaluation and risk analysis
Cadence
Periodically, read in practice as annually and on significant change
Typical duration
2 to 3 weeks of testing, plus retest
Region
United States
Issued by
Enforced by HHS Office for Civil Rights. No certification exists.
(a)(8)
Evaluation standard evidenced
6 yr
Documentation retention
Annual
Practical cadence
2025
Proposed rule would mandate testing
The requirement
What HIPAA asks for
§164.308(a)(8) and §164.308(a)(1)(ii)(A) · Evaluation and risk analysis
The Security Rule requires a periodic technical and nontechnical evaluation establishing the extent to which security policies and procedures meet the requirements (§164.308(a)(8)), built on an accurate and thorough risk analysis of vulnerabilities to electronic protected health information (§164.308(a)(1)(ii)(A)).
The HIPAA Security Rule requires a periodic technical evaluation of whether your safeguards actually meet the rule, and a risk analysis that identifies vulnerabilities to electronic protected health information. Neither is satisfied by a questionnaire.
Enforcement makes this concrete. OCR investigations consistently find that organisations had a risk analysis on paper but no technical testing behind it. Independent penetration testing of the systems that store and transmit PHI is how you evidence the evaluation standard and feed real findings into the risk analysis.
The direction of travel is clearer still. The Security Rule update proposed in January 2025 would require annual penetration testing and regular vulnerability scanning explicitly. It has not been finalised, but building to it now means the work is already done when it lands.
XHack delivers that testing. We scope to the systems handling PHI, test, report, support remediation, retest to closure and sign an attestation letter. Your risk analysis, policies, training and Business Associate Agreements remain your programme.
What your auditor checks
The report has to clear every one of these
These are the questions a HIPAA auditor asks of a penetration test before accepting it as evidence. Every engagement we run is built to answer all of them.
Independent of the team that built the PHI systems
Scope covering systems that create, receive, maintain or transmit ePHI
Recognised methodology documented in the report
Findings rated consistently with CVSS v4.0
Findings usable as input to the risk analysis
Evidence of remediation with dates
Independent retest confirming safeguards now hold
No live PHI exfiltrated during testing
Documentation retained for the six year requirement
Signed attestation letter from the testing firm
What we test
Where the testing effort concentrates
The surfaces this engagement covers, weighted by how much of the work they typically represent. Scope is confirmed with you before anything starts.
Systems storing or transmitting ePHI
Applications, databases, integrations
95%
Access control and audit controls
Unique identification, authorization, logging
90%
Transmission security
Encryption of ePHI in transit
85%
External perimeter
Internet-facing exposure of PHI systems
75%
Integrity controls
Protection of ePHI from improper alteration
60%
Weights are indicative of typical effort. Your exact scope is agreed and signed before testing begins.
How the engagement runs
Scope, test, close, attest
Typically 2 to 3 weeks of testing, plus retest. The retest is included, because a report full of open findings is not evidence of anything.
Scope to PHI systems
We identify which systems create, receive, maintain or transmit ePHI and scope the test to them, so the evidence maps onto your risk analysis.
Test under a BAA and rules of engagement
Where required we sign a Business Associate Agreement. No live PHI is exfiltrated, and anything captured to prove a finding is redacted in the report.
Report against the safeguards
Findings are mapped to the technical safeguards they affect, so they slot directly into your risk analysis and evaluation documentation.
Remediation support
Your team fixes. Anything that could expose ePHI is escalated the day we find it rather than held for the report.
Retest and attestation
Each finding retested and closed, with a dated attestation letter for your six year documentation file.
Where the effort goes
Share of a typical engagement, by phase
Scoping & rules of engagement
15%
Testing & exploitation
45%
Reporting & mapping
20%
Retest & attestation
20%
What we bring
Built for the HIPAA auditor specifically
The parts of this engagement that are shaped by the framework rather than copied from a generic testing template.
Evaluation with teeth
A real technical evaluation of whether the safeguards hold, which is what §164.308(a)(8) asks for and what OCR looks for.
Feeds the risk analysis
Findings are written so they drop straight into your risk analysis as identified vulnerabilities with likelihood and impact.
Tested under a BAA
We sign a Business Associate Agreement where required, and no live PHI leaves your environment.
Ready for the proposed rule
The proposed Security Rule update would require annual penetration testing outright. An annual cadence now means no scramble later.
The deliverable
What lands on your auditor's desk
A report structured so the evidence sits where the auditor is already looking, with every finding mapped to the control it touches.
In the report
Signed letter of attestation with testing dates
Scope covering systems that handle ePHI
Methodology, qualifications and independence statement
Findings with CVSS v4.0, evidence and reproduction steps
Confirmation that no live PHI was exfiltrated
Remediation implemented and independent retest result
Mapping to the technical safeguards for your risk analysis
Control mapping
How the report evidences each control
§164.308(a)(8)
The periodic technical evaluation of whether safeguards meet the rule.
§164.308(a)(1)(ii)(A)
Identified vulnerabilities feeding the required risk analysis.
§164.312(a)
Access control weaknesses tested and closed.
§164.312(b)
Audit controls verified by whether test activity was captured.
§164.312(e)
Transmission security, including encryption of ePHI in transit.
Where our work stops, and who takes it from there
XHack provides the penetration testing evidence for §164.308(a)(8) and §164.308(a)(1)(ii)(A). We do not issue certificates, attestation opinions or regulatory approvals, and we do not run your wider compliance programme. For HIPAA, that sits with: Enforced by HHS Office for Civil Rights. No certification exists.. Staying independent of them is exactly what makes our evidence worth something when they review it.
Questions
HIPAA testing, answered
The Security Rule requires a periodic technical evaluation and a risk analysis, without naming penetration testing. Independent testing is the accepted way to satisfy the evaluation standard. The Security Rule update proposed in January 2025 would require annual penetration testing explicitly, so treating it as a baseline is sensible.
No. We deliver the technical testing evidence that feeds the risk analysis. The risk analysis itself, along with policies, workforce training and Business Associate Agreements, is your programme.
Yes, where the engagement means we could encounter PHI. In practice we design testing to avoid live PHI entirely, and anything captured to prove a finding is redacted in the report.
No. HHS does not certify anyone, and any vendor selling a HIPAA certificate is selling something that does not exist. What you can hold is a documented risk analysis, implemented safeguards and independent testing evidence.
Other frameworks we test for
Get the HIPAA evidence sorted
Tell us who is auditing you and when your review period closes. We will scope the test, tell you what it costs, and make sure there is room to remediate and retest before the deadline.