
If you handle electronic protected health information (ePHI), you have probably heard that HIPAA is about to require penetration testing. That’s close, but not quite right yet. The HIPAA Security Rule in force today does not name penetration testing as a requirement. The proposed update to the Security Rule would change that, requiring covered entities and business associates to run a penetration test at least once every 12 months.
This post breaks down what the current rule actually requires, what the proposed rule would add, where things stand today, and what you should be doing now so the first pen test you run isn’t the one an auditor asks about.
What Is the HIPAA Security Rule?
The HIPAA Security Rule (45 CFR Part 164, Subpart C) sets national standards for protecting ePHI. It applies to covered entities (health plans, healthcare clearinghouses, and most healthcare providers) and to their business associates, including IT providers, billing companies, SaaS vendors, and anyone else who creates, receives, maintains, or transmits ePHI on their behalf.
The rule is organized into three categories of safeguards:
- Administrative safeguards: risk analysis, risk management, workforce training, security evaluations, and contingency planning.
- Physical safeguards: facility access, workstation security, and device and media controls.
- Technical safeguards: access control, audit controls, integrity controls, authentication, and transmission security.
The rule was written to be flexible and technology neutral. That flexibility is a big part of why it is now being rewritten.
Does HIPAA Currently Require Penetration Testing?
No, not explicitly. The current Security Rule does not use the words “penetration testing,” and it does not set a testing schedule.
What it does require is:
- A risk analysis (45 CFR 164.308(a)(1)(ii)(A)): an accurate and thorough assessment of the risks and vulnerabilities to the confidentiality, integrity, and availability of ePHI.
- Risk management (45 CFR 164.308(a)(1)(ii)(B)): security measures sufficient to reduce those risks to a reasonable and appropriate level.
- Periodic evaluation (45 CFR 164.308(a)(8)): technical and nontechnical evaluations to confirm your safeguards actually meet the rule’s requirements.
Here’s the practical reality: it is hard to claim a “thorough” risk analysis or a meaningful technical evaluation without ever testing your defenses the way an attacker would. A penetration test is one of the most defensible ways to show you’ve identified real, exploitable vulnerabilities rather than theoretical ones. When OCR investigates a breach, an inadequate risk analysis is one of the most frequently cited failures.
So while pen testing isn’t mandated by name today, it already supports the requirements you are on the hook for.
What the Proposed HIPAA Security Rule Update Would Change
In December 2024, HHS announced a Notice of Proposed Rulemaking (NPRM) to overhaul the Security Rule, the first major update in over a decade. It was published in the Federal Register on January 6, 2025, and the public comment period closed on March 7, 2025.
The proposal is aimed squarely at the “addressable” loophole. Under the current rule, many specifications are “addressable,” which in practice let organizations document why they skipped a control. The proposed rule would remove the distinction between “required” and “addressable” and make nearly all specifications required, with limited exceptions.
Key proposed changes include:
- Penetration testing at least every 12 months, performed by qualified personnel.
- Vulnerability scanning at least every 6 months.
- Mandatory encryption of ePHI at rest and in transit, with limited exceptions.
- Multi-factor authentication for access to relevant information systems.
- A written technology asset inventory and network map, reviewed at least annually.
- Network segmentation.
- More detailed risk analysis requirements, including documented threats and vulnerabilities.
- Defined patching timelines based on risk.
- Restoration of critical systems and data within 72 hours following an incident.
- An annual compliance audit against the Security Rule.
- Stronger business associate oversight, including written verification that business associates have deployed required technical safeguards.
For many small and mid-sized practices, the pen testing and vulnerability scanning requirements would be brand new territory.
Where Does the Proposed Rule Stand Right Now?
As of this writing, the updated Security Rule is still a proposal. It is not law, and no new compliance deadline is in effect. The finalization target has slipped more than once and is currently pointing toward 2027. Industry groups, including many hospital systems, have pushed back on cost and implementation burden, so the final version may look different from the NPRM.
If the rule is finalized largely as proposed, it would take effect 60 days after publication, with a 180-day compliance period after that. That’s roughly eight months from publication to enforcement. For organizations that have never scoped a penetration test, remediated the findings, and built the documentation around it, eight months goes fast.
Why You Shouldn’t Wait for the Final Rule
Waiting for the final rule is a bet that carries real downside:
- The current rule already expects it in spirit. Your risk analysis and evaluation obligations exist today. A pen test strengthens both.
- Your first test will find things. Most first-time tests uncover issues that take weeks or months to fix. Better to find them on your own schedule.
- Vendor capacity will tighten. When the rule finalizes, a large number of covered entities and business associates will be shopping for testers at the same time.
- Business associates will get asked first. Covered entities are already sending security questionnaires that ask about recent pen test results. If you’re a vendor, that question is coming.
- Attackers aren’t waiting. Healthcare remains one of the most targeted sectors for ransomware and data theft.
What a HIPAA-Focused Penetration Test Should Cover
A pen test that supports HIPAA compliance should focus on the systems that store, process, or transmit ePHI, and the paths an attacker could use to reach them. Depending on your environment, that typically includes:
- External network testing: internet-facing systems, VPNs, remote access portals, and exposed services.
- Internal network testing: what an attacker could reach after a phishing click or a compromised workstation, including lateral movement toward EHR, PACS, and database servers.
- Web application and API testing: patient portals, scheduling tools, telehealth platforms, and integrations that handle ePHI.
- Cloud configuration review: storage, identity, and access settings in AWS, Azure, Google Cloud, or Microsoft 365.
- Social engineering and phishing simulation: testing the human layer that most breaches start with.
- AI and LLM applications: if you use AI tools that touch patient data (chatbots, clinical documentation assistants, RAG pipelines), they need to be in scope too.
What Good Documentation Looks Like
For HIPAA purposes, the report matters as much as the testing. Look for a deliverable that includes:
- A clear scope, methodology, and testing dates.
- Findings ranked by risk, with evidence and reproduction steps.
- Remediation guidance your team can act on.
- An executive summary suitable for leadership and auditors.
- A retest to confirm fixes, so you can show the risk was actually reduced.
Then feed those results into your risk analysis and risk management plan. That connection is what turns a pen test from a one-off exercise into compliance evidence.
How to Prepare Now: A Quick Checklist
- Update your Security Risk Analysis and make sure it reflects your current environment.
- Build or refresh your technology asset inventory and network map.
- Start vulnerability scanning on a regular cadence (at least every six months).
- Schedule a baseline penetration test of systems that handle ePHI.
- Roll out MFA on remote and privileged access.
- Confirm encryption of ePHI at rest and in transit.
- Review business associate agreements and ask vendors for evidence of their own testing.
- Budget for annual testing going forward.
Frequently Asked Questions
Does HIPAA require penetration testing? Not explicitly under the current Security Rule. However, the rule requires a thorough risk analysis and periodic technical evaluations, and penetration testing is one of the strongest ways to meet those obligations. The proposed Security Rule update would require a penetration test at least every 12 months.
How often would HIPAA require penetration testing under the proposed rule? At least once every 12 months, plus vulnerability scanning at least every six months.
Do business associates need penetration testing? The proposed rule applies to business associates as well as covered entities. Many covered entities already ask their vendors for recent pen test results as part of vendor risk reviews.
Is the new HIPAA Security Rule final? Not yet. It remains a proposed rule, and the finalization date has been pushed back more than once. Check HHS for the latest status.
Are small practices exempt? The proposed rule does not include a blanket exemption for small practices. Scope can be scaled to the size and complexity of your environment, but the testing requirement would still apply.
Is a vulnerability scan the same as a penetration test? No. A vulnerability scan is an automated check for known weaknesses. A penetration test is performed by a skilled tester who actively attempts to exploit weaknesses, chain them together, and show real-world impact. The proposed rule treats them as separate requirements.
Get Ahead of the HIPAA Penetration Testing Requirement
Brackish Security helps healthcare organizations and their business associates test the systems that protect patient data, from external and internal networks to web apps, cloud environments, phishing simulations, and AI applications. Our reports are built to plug directly into your HIPAA risk analysis, with clear findings, practical remediation guidance, and retesting included.
Whether the final rule lands next year or later, the smartest move is to know where you stand today. Contact Brackish Security to scope your HIPAA penetration test.
This article is for informational purposes and is not legal advice. HIPAA requirements and the status of the proposed Security Rule may change; consult HHS guidance and your legal counsel for your specific situation.