HIPAA Security Rule Penetration Testing
Does HIPAA require penetration testing? Not yet, but the proposed HIPAA Security Rule update would mandate annual pen tests. Here’s what to know.
Read the post →The latest security trends, threat analysis, testing methodology, and more — from the people doing the work.
114 posts
Does HIPAA require penetration testing? Not yet, but the proposed HIPAA Security Rule update would mandate annual pen tests. Here’s what to know.
Read the post →A pentest is a project, not a purchase. Learn how dedicated project management gets you more testing time, faster critical alerts, and findings that get fixed.
Read the post →What actually drives the scope and cost of an LLM penetration test: the questions to answer before you buy, a full scoping checklist, and a sample sow.
Read the post →A daily start and stop email from your penetration testing partner isn’t a formality — it’s a safety net, a scope check, and a real paper trail.
Read the post →CSP is a powerful XSS defense that is routinely misconfigured. How it works, a strict 2026 policy, and the bypasses you will actually run into.
Read the post →CaptiveCrunch turns the captive portal itself into the phish, and MFA does not answer it. How the chain works, and what your simulations never covered.
Read the post →The HIPAA Security Rule overhaul slipped again, and the 240-day compliance window is the part nobody reads. Where the rule stands and what it will demand.
Read the post →One phishing simulation a year measures a single day with a single pretext. Why cadence beats the annual checkbox, and which metric is worth reporting.
Read the post →Bad grammar and generic greetings no longer identify a phishing email. The tells that still work: the ask itself, the channel, and unexplained urgency.
Read the post →Researchers documented JadePuffer, the first known ransomware attack run end to end by an AI agent. What it actually demonstrates, and what it does not.
Read the post →