HIPAA Penetration Testing: A Complete Compliance Guide

Running HIPAA-aligned penetration tests is a vital way to verify that your Electronic Protected Health Information (ePHI) safeguards hold up in practice—and to surface dangerous vulnerabilities before attackers or auditors do. Therefore, it’s wise to find a reputable and experienced vendor to carry out HIPAA penetration testing on your behalf.
In this guide, we explore why penetration testing is so important within HIPAA, how you can prepare, and what you need to prioritize when looking for a partner.
Why pen testing sits at the center of healthcare cybersecurity.
HIPAA penetration testing assesses ePHI safeguards under controlled, realistic attack simulations. While you may have robust processes and policies on paper, pen testing realistically evaluates how your safeguards hold up under a real attack.
Instead of simply documenting safeguards and what they do, penetration testing attempts to exploit weaknesses in them using the methods and tools a real attacker would. HIPAA organizes safeguards into three categories:
- Administrative, which largely covers policies, training, and procedures.
- Physical, which refers to physical access to workstations, facilities, and devices.
- Technical, which includes audit controls and data encryption standards.
A standard penetration test primarily validates technical safeguards. Physical and administrative controls only come into scope when the engagement explicitly includes social engineering or physical intrusion testing, something worth clarifying with any vendor upfront.
Penetration testing has become a core element of healthcare cybersecurity in part due to healthcare companies' increasingly large and complex attack surfaces.
For example, a typical healthcare firm might have a complex infrastructure combining medical devices, application programming interfaces (APIs), web-facing patient portals, Electronic Health Record (EHR) platforms, Customer Relationship Management (CRM) systems, and cloud services. All systems and touchpoints that use ePHI must be thoroughly documented and stress-tested to meet HIPAA requirements.
Evolving threats to ePHI, too, make penetration testing a vital factor in preparing for HIPAA. For instance, recurring threat vectors affecting healthcare include insecure APIs, third-party weaknesses and access, and ransomware.
Ransomware, in particular, can have devastating effects on operations and patient health, and not just in terms of ePHI theft. This malware effectively locks down systems until a ransom fee is paid. And, even then, attackers may extort for more.
“Since 2015, there has been a staggering increase in ransomware attacks on healthcare facilities. And the impacts are severe: Diverted emergency services, delayed critical treatments and even fatalities. Meanwhile, the pledge some ransomware groups made during the COVID-19 pandemic to avoid attacking healthcare providers has been abandoned. It’s clear that hospitals are now fair game.”
Following HIPAA doesn’t just tick compliance boxes and secure patient data; keeping compliant ensures your infrastructure is as secure as possible against threats such as ransomware.
What HIPAA requires today and what the proposed update adds.
Presently, the HIPAA Security Rule does not explicitly state that penetration testing is required. However, it does require periodic technical and nontechnical evaluations of security safeguards—without specifying how often, or how. Moreover, regular pen testing helps to keep healthcare companies and associates robust against evolving threats.
Proposed updates to the HIPAA Security Rule—published in January 2025 and still under review with federal regulatory agendas now targeting July 2027 for final action—would change that. The updates would require all covered entities and business associates to run penetration tests at least once a year, with vulnerability scanning at least every six months.
The aim is to make attack prevention and ePHI safeguarding more proactive and to ensure companies view compliance as a rolling expectation, not a one-off check.
Until a final rule is issued, penetration testing remains recommended rather than mandatory. Covered entities and business associates should still track the rulemaking closely. If finalized as proposed, both annual penetration testing and the new HIPAA vulnerability scan requirements would become binding, with a compliance window measured in months, not years.
How pen testing differs from vulnerability scanning.
Penetration testing is a manual process involving adversarial, controlled vulnerability exploitation. Vulnerability scanning is automated and runs in the background, finding weaknesses without human intervention.
Crucially, pen testing accounts for depth, and scanning accounts for breadth. While vulnerability scanning hunts out threats, penetration testing actively exploits them, recording the effects.
Therefore, scanning is a reconnaissance mission, surfacing threats, while pen testing actually confirms if the threats are exploitable (in line with where ePHI is handled, stored, and processed).
What systems and data fall within scope.
HIPAA penetration testing scope should cover all systems, endpoints, workflows, and platforms that “touch” ePHI. Whether ePHI is transferred, edited, or simply downloaded via a given workflow, it must form part of the pen testing scope. Wherever there is a threat of unauthorized access exposing ePHI, you should run a penetration test.
Systems and data that fall within scope include:
- Patient portals and public-facing online forms and pages.
- Mobile applications and environments.
- Telehealth software, platforms, and connectivity.
- Integrations between EHR and Electronic Medical Records (EMR).
- Billing and claims systems.
- API (including integrations for HL7, pharmacy, lab, and Fast Healthcare Interoperability Resources (FHIR)).
What’s more, testing should account for any additional cloud infrastructure in place, medical device networks, ID providers, and vendor access paths. Third parties shouldn’t be ignored—especially considering that, in 2024, 41% of third-party breaches specifically affected healthcare companies.
Frequency and triggers for HIPAA pen tests.
HIPAA penetration tests should take place depending on a company’s risk profile, size, complexity, and evolving needs. There's no current HIPAA mandate on frequency, but annual testing is the widely accepted baseline—and it's the cadence the proposed Security Rule update would make mandatory. Tests should also run whenever risks alter or new risks emerge.
For example, testing should always follow major changes to applications, infrastructure, policies, procedures, and partnerships. A penetration test should follow vendor changes that affect ePHI, and after any mergers or acquisitions directly impacting an organization. It is especially important to run penetration tests after security incidents, once threats are remediated.
A HIPAA risk assessment may also dictate that pen testing should occur more frequently than these suggested timescales. Should a system be determined to be a high exposure risk, for instance, it is prudent to stress-test it more frequently than the routine baseline.
How to prepare for a HIPAA pen test.
Preparing well for a HIPAA penetration test will ensure that its results stand up to auditing scrutiny. Poor scoping and planning weaken your audit trail. If the Office for Civil Rights (OCR) reviews how your organization evaluates its safeguards, thin or inconsistent documentation is difficult to defend.
Before engaging a third-party pen testing vendor, always ensure there are legal foundations in place. This will help to protect ePHI and show OCR that adequate compliance steps are being taken.
For instance, consider requiring a non-disclosure agreement, and at least a Business Associate Agreement (BAA), which establishes the vendor’s ePHI handling obligations.
Before testing, establish:
- The objectives of the exercise (i.e., what’s being tested, and why?)
- Testing scope (will it cover the whole infrastructure or a section?)
- Target systems (which specific endpoints, stations, and facilities will be exploited?)
- Success criteria (what does a pen test pass look like in this scenario?)
Being technically ready for a penetration test is just as important. Always have recent data backups accessible, for example, and establish a change freeze (where no modifications to infrastructure should be made during tests).
Set clear communication protocols with testers and teams and confirm whom to escalate concerns to during the test.
The right penetration test vendor will communicate openly with you about these factors and what you can expect from the process.
How a HIPAA pen test runs from planning to reporting.
HIPAA penetration tests run across four key stages: planning, discovery, exploitation, and reporting. Following these stages helps to build defensible reports for OCR auditors.
- The Planning stage maps out the scope, foundation, and engagement rules to be expected from the penetration test. It’s here where objectives are set and are clearly linked to HIPAA-mandated safeguards and systems that handle ePHI.
- The Discovery stage is where testers map out their attack environments, gather data on their targets, and uncover vulnerabilities to attack.
- The Attack stage is where exploitation takes place. Here, testers attempt to “attack” the environment established under controlled and authorized conditions. Testers record what happens during the attack, whether ePHI is exposed, and to what extent.
- The Report stage delivers the final analysis, advising of vulnerability severity ratings and evidence that exploitation was successful. The report also advises where ePHI, if any, was exposed, the impact of exposure, and specific guidance on how to remedy the weakness(es). At this point, testers also insist on re-testing to verify closure.
How pen testing strengthens incident response planning.
Without penetration testing, incident response plans are only ever tested when real attacks occur. It is one of the very few exercises that validates how effective a response plan is under realistic conditions and scenarios.
Penetration testing doesn’t purely assess weaknesses but also reviews how effectively incident response controls surface attacker behavior. For example, pen testing assesses how effective response is at logging, monitoring, and detecting suspicious behavior it intends to catch.
What’s more, pen testing reports are highly influential for incident response planning. They uncover gaps in workflows covering detection, escalation timing, and containment, and make suggestions for improvement.
With this, findings translate well into technical cybersecurity exercises. They frequently inform IR drills and tabletop sessions and influence permanent changes to security runbooks.
What to look for in a qualified pen testing vendor.
The penetration testing vendor you choose dictates how the whole process will run. Therefore, it’s crucial to find a qualified, experienced partner who can offer you specialized expertise, skills, and a reliable track record.
Prioritize working with vendors who:
- Offer years of specialized healthcare experience—such as familiarity with HIPAA, telehealth, medical devices, EHR, and APIs (FHIR and HL7).
- Hold and can offer proof of recognized industry certifications—these are excellent indicators that you are working with a team that has thoroughly validated its knowledge and technical skills.
- Follow transparent scoping methodologies.
- Name and document their lead testers and prioritize open communication.
- Provide sample reporting.
- Clearly define the retesting scope and offer specific remediation advice.
- Price testing based on scope, rather than employee headcount.
It is these factors that set genuinely qualified vendors apart from generic testing providers. Be prepared to compare several options, and don’t be afraid to ask questions about how a vendor can fit your specific needs.
BAAs and vendor oversight obligations.
Making vendor and associate relationships defensible to auditors requires an ironclad BAA. As far as HIPAA is concerned, it is a crucial contractual layer that clearly defines responsibilities and expectations regarding how ePHI will be handled and secured by third parties.
It’s vital to set out and agree on a BAA with any potential vendors before they access ePHI (even simply reading or being exposed to this information). A covered entity must use a BAA to define exactly how ePHI is to be used between parties and what is not considered permissible usage.
A BAA should also define exactly what HIPAA safeguards a vendor will apply while in partnership with the covered entity. What’s more, it should clearly detail breach reporting timelines and any responsibilities regarding contract termination.
BAAs and vendor oversight should last far beyond the initial HIPAA penetration test. To protect their own ePHI and prevent enforcement action, covered entities must regularly:
- Review vendor reporting quality.
- Validate retest results.
- Confirm vendors maintain relevant certifications and clean engagement records.
Conclusion
HIPAA penetration testing may not be mandated at present, but it is still a vital control validation exercise for continuous compliance. Therefore, it pays to select a vendor with legitimate expertise in controlled threat exploitation and with measurable experience in the healthcare industry.
Choosing the right HIPAA pen testing vendor is a decision that shapes long-term security posture for the better. Learn more about VikingCloud’s HIPAA compliance services and how our penetration testing team can keep your ePHI safely protected for years to come.
FAQs
Q1. Does HIPAA require penetration testing?
HIPAA does not currently mandate penetration testing for compliance. However, its Security Rule states that covered entities and business associates must conduct regular risk analyses and control reviews. It is good practice to ensure that ePHI is as protected as possible against real-world attack vectors.
Q2. How often should a HIPAA penetration test be conducted?
Current HIPAA Security Rule does not specify exact timeframes for conducting penetration tests. Organizations have flexibility in determining how often to perform these assessments.
It is important to run pen tests after every major change to infrastructure, vendor partnerships, policies, and regulations, and after a security breach and remediation.
The proposal to update HIPAA’s Security Rule would require that penetration tests take place at least once a year.
Q3. Does a penetration testing vendor need to sign a BAA?
Yes, penetration testing vendors must sign BAAs if they are to access, handle, store, edit, or otherwise transmit ePHI. HIPAA mandates that all business associates that intend to “touch” or “view” ePHI must sign these agreements.
Q4. What systems should be included in the scope of a HIPAA pen test?
A HIPAA pen test must cover all systems that handle, access, create, maintain, or transmit ePHI. If a system “contacts” or is exposed to ePHI in any way, it must be tested. This can include EHRs, EMR platforms, APIs, internal networks, cloud environments, patient portals, and telehealth platforms.
Q5. How much does a HIPAA penetration test typically cost?
A HIPAA penetration test typically costs $10,000 – $50,000, though small practices with simple environments may pay as little as $5,000, while large health systems can exceed that range. Scope, infrastructure complexity, and compliance reporting requirements drive the price, so it's wise to compare quotes from multiple vendors before signing.
Related Blogs
Stay up-to-date on the latest happenings in Cybersecurity and PCI Compliance.
Supersized Confidence, Underprepared Frontlines: Closing the Restaurant Cybersecurity Gap



.png)