Privacy
Testing expected by auditors

HIPAA penetration testing

HIPAA (Health Insurance Portability and Accountability Act)

Technical evaluation of your safeguards for systems handling PHI, the evidence the Security Rule evaluation standard expects.

Sample report

Engagement at a glance

Drives testing

§164.308(a)(8) and §164.308(a)(1)(ii)(A): Evaluation and risk analysis

Cadence

Periodically, read in practice as annually and on significant change

Typical duration

2 to 3 weeks of testing, plus retest

Region

United States

Issued by

Enforced by HHS Office for Civil Rights. No certification exists.

(a)(8)

Evaluation standard evidenced

6 yr

Documentation retention

Annual

Practical cadence

2025

Proposed rule would mandate testing

The requirement

What HIPAA asks for

§164.308(a)(8) and §164.308(a)(1)(ii)(A) · Evaluation and risk analysis

The Security Rule requires a periodic technical and nontechnical evaluation establishing the extent to which security policies and procedures meet the requirements (§164.308(a)(8)), built on an accurate and thorough risk analysis of vulnerabilities to electronic protected health information (§164.308(a)(1)(ii)(A)).

The HIPAA Security Rule requires a periodic technical evaluation of whether your safeguards actually meet the rule, and a risk analysis that identifies vulnerabilities to electronic protected health information. Neither is satisfied by a questionnaire.

Enforcement makes this concrete. OCR investigations consistently find that organisations had a risk analysis on paper but no technical testing behind it. Independent penetration testing of the systems that store and transmit PHI is how you evidence the evaluation standard and feed real findings into the risk analysis.

The direction of travel is clearer still. The Security Rule update proposed in January 2025 would require annual penetration testing and regular vulnerability scanning explicitly. It has not been finalised, but building to it now means the work is already done when it lands.

XHack delivers that testing. We scope to the systems handling PHI, test, report, support remediation, retest to closure and sign an attestation letter. Your risk analysis, policies, training and Business Associate Agreements remain your programme.

What your auditor checks

The report has to clear every one of these

These are the questions a HIPAA auditor asks of a penetration test before accepting it as evidence. Every engagement we run is built to answer all of them.

Independent of the team that built the PHI systems

Scope covering systems that create, receive, maintain or transmit ePHI

Recognised methodology documented in the report

Findings rated consistently with CVSS v4.0

Findings usable as input to the risk analysis

Evidence of remediation with dates

Independent retest confirming safeguards now hold

No live PHI exfiltrated during testing

Documentation retained for the six year requirement

Signed attestation letter from the testing firm

What we test

Where the testing effort concentrates

The surfaces this engagement covers, weighted by how much of the work they typically represent. Scope is confirmed with you before anything starts.

Systems storing or transmitting ePHI

Applications, databases, integrations

95%

Access control and audit controls

Unique identification, authorization, logging

90%

Transmission security

Encryption of ePHI in transit

85%

External perimeter

Internet-facing exposure of PHI systems

75%

Integrity controls

Protection of ePHI from improper alteration

60%

Weights are indicative of typical effort. Your exact scope is agreed and signed before testing begins.

How the engagement runs

Scope, test, close, attest

Typically 2 to 3 weeks of testing, plus retest. The retest is included, because a report full of open findings is not evidence of anything.

01

Scope to PHI systems

Week 1

We identify which systems create, receive, maintain or transmit ePHI and scope the test to them, so the evidence maps onto your risk analysis.

02

Test under a BAA and rules of engagement

Weeks 1 to 3

Where required we sign a Business Associate Agreement. No live PHI is exfiltrated, and anything captured to prove a finding is redacted in the report.

03

Report against the safeguards

Week 3

Findings are mapped to the technical safeguards they affect, so they slot directly into your risk analysis and evaluation documentation.

04

Remediation support

Weeks 3 to 6

Your team fixes. Anything that could expose ePHI is escalated the day we find it rather than held for the report.

05

Retest and attestation

Week 6 onward

Each finding retested and closed, with a dated attestation letter for your six year documentation file.

Where the effort goes

Share of a typical engagement, by phase

100%EFFORT

Scoping & rules of engagement

15%

Testing & exploitation

45%

Reporting & mapping

20%

Retest & attestation

20%

What we bring

Built for the HIPAA auditor specifically

The parts of this engagement that are shaped by the framework rather than copied from a generic testing template.

Evaluation with teeth

A real technical evaluation of whether the safeguards hold, which is what §164.308(a)(8) asks for and what OCR looks for.

Feeds the risk analysis

Findings are written so they drop straight into your risk analysis as identified vulnerabilities with likelihood and impact.

Tested under a BAA

We sign a Business Associate Agreement where required, and no live PHI leaves your environment.

Ready for the proposed rule

The proposed Security Rule update would require annual penetration testing outright. An annual cadence now means no scramble later.

The deliverable

What lands on your auditor's desk

A report structured so the evidence sits where the auditor is already looking, with every finding mapped to the control it touches.

In the report

  • Signed letter of attestation with testing dates

  • Scope covering systems that handle ePHI

  • Methodology, qualifications and independence statement

  • Findings with CVSS v4.0, evidence and reproduction steps

  • Confirmation that no live PHI was exfiltrated

  • Remediation implemented and independent retest result

  • Mapping to the technical safeguards for your risk analysis

Control mapping

How the report evidences each control

§164.308(a)(8)

The periodic technical evaluation of whether safeguards meet the rule.

§164.308(a)(1)(ii)(A)

Identified vulnerabilities feeding the required risk analysis.

§164.312(a)

Access control weaknesses tested and closed.

§164.312(b)

Audit controls verified by whether test activity was captured.

§164.312(e)

Transmission security, including encryption of ePHI in transit.

Where our work stops, and who takes it from there

XHack provides the penetration testing evidence for §164.308(a)(8) and §164.308(a)(1)(ii)(A). We do not issue certificates, attestation opinions or regulatory approvals, and we do not run your wider compliance programme. For HIPAA, that sits with: Enforced by HHS Office for Civil Rights. No certification exists.. Staying independent of them is exactly what makes our evidence worth something when they review it.

Questions

HIPAA testing, answered

The Security Rule requires a periodic technical evaluation and a risk analysis, without naming penetration testing. Independent testing is the accepted way to satisfy the evaluation standard. The Security Rule update proposed in January 2025 would require annual penetration testing explicitly, so treating it as a baseline is sensible.

No. We deliver the technical testing evidence that feeds the risk analysis. The risk analysis itself, along with policies, workforce training and Business Associate Agreements, is your programme.

Yes, where the engagement means we could encounter PHI. In practice we design testing to avoid live PHI entirely, and anything captured to prove a finding is redacted in the report.

No. HHS does not certify anyone, and any vendor selling a HIPAA certificate is selling something that does not exist. What you can hold is a documented risk analysis, implemented safeguards and independent testing evidence.

Get the HIPAA evidence sorted

Tell us who is auditing you and when your review period closes. We will scope the test, tell you what it costs, and make sure there is room to remediate and retest before the deadline.

All frameworks