Skip to content
September 15, 2026

HIPAA Security Rule Penetration Testing

Does HIPAA require penetration testing? Not yet, but the proposed HIPAA Security Rule update would mandate annual pen tests. Here’s what to know.

Brackish Security8 min read

HIPAA

If you handle electronic protected health information (ePHI), you have probably heard that HIPAA is about to require penetration testing. That’s close, but not quite right yet. The HIPAA Security Rule in force today does not name penetration testing as a requirement. The proposed update to the Security Rule would change that, requiring covered entities and business associates to run a penetration test at least once every 12 months.

This post breaks down what the current rule actually requires, what the proposed rule would add, where things stand today, and what you should be doing now so the first pen test you run isn’t the one an auditor asks about.

What Is the HIPAA Security Rule?

The HIPAA Security Rule (45 CFR Part 164, Subpart C) sets national standards for protecting ePHI. It applies to covered entities (health plans, healthcare clearinghouses, and most healthcare providers) and to their business associates, including IT providers, billing companies, SaaS vendors, and anyone else who creates, receives, maintains, or transmits ePHI on their behalf.

The rule is organized into three categories of safeguards:

The rule was written to be flexible and technology neutral. That flexibility is a big part of why it is now being rewritten.

Does HIPAA Currently Require Penetration Testing?

No, not explicitly. The current Security Rule does not use the words “penetration testing,” and it does not set a testing schedule.

What it does require is:

Here’s the practical reality: it is hard to claim a “thorough” risk analysis or a meaningful technical evaluation without ever testing your defenses the way an attacker would. A penetration test is one of the most defensible ways to show you’ve identified real, exploitable vulnerabilities rather than theoretical ones. When OCR investigates a breach, an inadequate risk analysis is one of the most frequently cited failures.

So while pen testing isn’t mandated by name today, it already supports the requirements you are on the hook for.

What the Proposed HIPAA Security Rule Update Would Change

In December 2024, HHS announced a Notice of Proposed Rulemaking (NPRM) to overhaul the Security Rule, the first major update in over a decade. It was published in the Federal Register on January 6, 2025, and the public comment period closed on March 7, 2025.

The proposal is aimed squarely at the “addressable” loophole. Under the current rule, many specifications are “addressable,” which in practice let organizations document why they skipped a control. The proposed rule would remove the distinction between “required” and “addressable” and make nearly all specifications required, with limited exceptions.

Key proposed changes include:

For many small and mid-sized practices, the pen testing and vulnerability scanning requirements would be brand new territory.

Where Does the Proposed Rule Stand Right Now?

As of this writing, the updated Security Rule is still a proposal. It is not law, and no new compliance deadline is in effect. The finalization target has slipped more than once and is currently pointing toward 2027. Industry groups, including many hospital systems, have pushed back on cost and implementation burden, so the final version may look different from the NPRM.

If the rule is finalized largely as proposed, it would take effect 60 days after publication, with a 180-day compliance period after that. That’s roughly eight months from publication to enforcement. For organizations that have never scoped a penetration test, remediated the findings, and built the documentation around it, eight months goes fast.

Why You Shouldn’t Wait for the Final Rule

Waiting for the final rule is a bet that carries real downside:

  1. The current rule already expects it in spirit. Your risk analysis and evaluation obligations exist today. A pen test strengthens both.
  2. Your first test will find things. Most first-time tests uncover issues that take weeks or months to fix. Better to find them on your own schedule.
  3. Vendor capacity will tighten. When the rule finalizes, a large number of covered entities and business associates will be shopping for testers at the same time.
  4. Business associates will get asked first. Covered entities are already sending security questionnaires that ask about recent pen test results. If you’re a vendor, that question is coming.
  5. Attackers aren’t waiting. Healthcare remains one of the most targeted sectors for ransomware and data theft.

What a HIPAA-Focused Penetration Test Should Cover

A pen test that supports HIPAA compliance should focus on the systems that store, process, or transmit ePHI, and the paths an attacker could use to reach them. Depending on your environment, that typically includes:

What Good Documentation Looks Like

For HIPAA purposes, the report matters as much as the testing. Look for a deliverable that includes:

Then feed those results into your risk analysis and risk management plan. That connection is what turns a pen test from a one-off exercise into compliance evidence.

How to Prepare Now: A Quick Checklist

Frequently Asked Questions

Does HIPAA require penetration testing? Not explicitly under the current Security Rule. However, the rule requires a thorough risk analysis and periodic technical evaluations, and penetration testing is one of the strongest ways to meet those obligations. The proposed Security Rule update would require a penetration test at least every 12 months.

How often would HIPAA require penetration testing under the proposed rule? At least once every 12 months, plus vulnerability scanning at least every six months.

Do business associates need penetration testing? The proposed rule applies to business associates as well as covered entities. Many covered entities already ask their vendors for recent pen test results as part of vendor risk reviews.

Is the new HIPAA Security Rule final? Not yet. It remains a proposed rule, and the finalization date has been pushed back more than once. Check HHS for the latest status.

Are small practices exempt? The proposed rule does not include a blanket exemption for small practices. Scope can be scaled to the size and complexity of your environment, but the testing requirement would still apply.

Is a vulnerability scan the same as a penetration test? No. A vulnerability scan is an automated check for known weaknesses. A penetration test is performed by a skilled tester who actively attempts to exploit weaknesses, chain them together, and show real-world impact. The proposed rule treats them as separate requirements.

Get Ahead of the HIPAA Penetration Testing Requirement

Brackish Security helps healthcare organizations and their business associates test the systems that protect patient data, from external and internal networks to web apps, cloud environments, phishing simulations, and AI applications. Our reports are built to plug directly into your HIPAA risk analysis, with clear findings, practical remediation guidance, and retesting included.

Whether the final rule lands next year or later, the smartest move is to know where you stand today. Contact Brackish Security to scope your HIPAA penetration test.


This article is for informational purposes and is not legal advice. HIPAA requirements and the status of the proposed Security Rule may change; consult HHS guidance and your legal counsel for your specific situation.

Want this tested against your environment?

Reading about an attack path is not the same as knowing whether yours holds. We can tell you which it is.

Scope an engagement