Penetration Testing Requirements Under HIPAA Security Rule
HIPAA's risk-analysis rules implicitly demand penetration testing without saying so.

- Written by
- Compliance Picks EditorsEditorial team
- Published
- October 10, 2026
- Reading time
- 8 min read
- Sources cited
- 3 sources ↓
What this covers
Nowhere does the HIPAA Security Rule say “penetration testing,” but since 2013 it has expected nearly the same thing. The rule requires a risk-analysis result so concrete that paperwork alone cannot get any organization there.
Implied Penetration Testing in the HIPAA Security Rule
Three provisions in 45 CFR Part 164 Subpart C do the work. The first, §164.308(a)(1)(ii)(A), requires an accurate and thorough assessment of the risks and vulnerabilities threatening the confidentiality, integrity, and availability of electronic protected health information. The second, §164.308(a)(8), requires periodic evaluation of the safeguards an organization has put in place. The third pair, §164.308(a)(1)(ii)(B) and §164.316(b)(1), requires that when an assessment turns up a risk, the organization fixes it and writes down what it did.
Read as a whole, the three requirements create a cycle: identify what is missing, address it, and document the result. The text is silent on how those gaps must be found. It points to no tool, no method, and no tester. Since 2013, no change has been made to §164.308, and the term "penetration testing" is absent from the provision. Covered entities decide how and when to assess, by design: the standard can fit both a solo practice and a large hospital network while staying durable without repeated revision.
Such latitude is precisely what creates the vulnerability. No entity may claim its risk assessment is accurate and thorough without stress-testing defenses to confirm an intruder cannot breach them, pivot laterally, or exfiltrate data. Cataloging risks on paper never demonstrates whether network filters function or authentication systems withstand automated password attacks. The regulation frames being accurate and thorough as the intended result, which only hands-on technical testing can deliver. The remainder of this article, covering enforcement actions through the freshly proposed rule, stems from that disconnect between mandated outcomes and unspecified methods.
OCR Enforcement and the Gap in the Rule's Text
Since then, the federal regulator has handled the rule’s broad risk-analysis duty case by case, steadily recasting it as a de facto obligation to test. That was the reason OCR created its Risk Analysis Initiative; as of March 2026, the program had produced 12 announced enforcement actions.
MMG Fusion settled with OCR on March 5, 2026, because it never did an accurate, thorough risk analysis. MMG agreed to a small settlement, a corrective plan, and OCR monitoring for three years. Hundreds of thousands of patients were caught up in that breach. Bryan County Ambulance Authority settled in October 2024 after ransomware encrypted the ePHI of tens of thousands; OCR's finding was blunter: the organization had not done a risk analysis. Ransomware exposed the ePHI of tens of thousands at Elgon Information Systems, a Massachusetts billing and EHR vendor that settled as a business associate on January 7, 2025. Attackers used open firewall ports to get in, and only a ransom note revealed their presence.
Throughout these settlements and the broader initiative, one finding keeps appearing: an inadequate or incomplete risk analysis. Rather than appearing as merely one violation among several, it emerges as the underlying source, the single breakdown enabling all subsequent failures. Elgon is significant for another reason: it demonstrates that this duty extends to business associates as well, not only to the hospitals and insurers executing the agreements.
For 2026, the head of OCR said the initiative would widen again, adding risk management alongside risk analysis. That ends the workaround in which some organizations merely named a documented risk and took no further action. With the program broadened, any organization recording a vulnerability and failing to fix it now faces equal exposure to one that skipped the search for weaknesses. OCR already deems a review inadequate if it lacks technical proof that controls function, even with the final rule still pending.
The Cost of Treating Testing as Optional
The incident at Change Healthcare illustrates the price of omissions permitted under the existing regulation's leniency. An ALPHV/BlackCat-linked ransomware actor breached Change Healthcare via a Citrix portal with stolen credentials on February 12, 2024. Multifactor authentication was never enabled on that access point. For about nine days the intruder remained undetected, siphoning roughly six terabytes of information prior to unleashing the payload on February 21. In the end, the breach impacted a victim pool numbering in the hundreds of millions, making it the worst healthcare data compromise in US history.
That breach stemmed from a narrow technical failure: a single remote access portal was missing MFA, an inexpensive and well understood control. Targeted assessments of external entry points exist to uncover such oversights by simulating the very routes intruders might exploit ahead of any real compromise. Elgon Information Systems illustrates a different manifestation of that identical weakness, where exposed firewall ports substituted for an absent authentication safeguard. The organization learned about them only upon receiving a ransom demand, since internal monitoring had failed to flag anything beforehand.
HHS has cited this pattern to support its new rule. OCR’s records show that since 2018, large data breaches have doubled, while ransomware has accounted for a much larger share of them. The risk reaches beyond networks and portals, too. Claroty’s 2025 findings from its State of CPS Security report, based on a review of internet-linked medical equipment at hundreds of entities, showed that known vulnerabilities affected most devices and that nearly every organization had one or more machines exposed to a flaw attackers were already using. Automated scanning usually falls short of showing how those flaws behave under authenticated, hands-on penetration testing. The takeaway from Change Healthcare and Elgon, along with Claroty’s device findings, is clear: these weaknesses can be pinpointed and repaired only if defenders look for them first.
What the 2025 NPRM would require, in specific terms
The agency overseeing health privacy released a draft regulation on 6 January 2025 that would make penetration testing an explicit obligation rather than an implied one, complete with set intervals, coverage, and staffing criteria. Come October 2026, the rule has yet to be finalized.
Proposed 164.312(h) would require covered systems to undergo automated vulnerability checks no less often than every six months, and sooner if the organization's risk analysis shows the need. The scanning tool would also have to be assessed and tried out once in every 12 months, and again after any major environmental change. In addition to those scans, regulated entities would have to run yearly penetration tests on relevant electronic information systems as a mandatory specification, not an addressable standard, leaving no room to rely on another safeguard instead or justify skipping it in documentation. A qualified person would have to conduct that testing, a role the NPRM describes as one requiring enough expertise to apply established cybersecurity practices to protect ePHI. Although the NPRM names no required credentials, organizations would likely look for proven offensive security work and certifications such as CEH or OSCP.
A handful of other proposed controls would define the scope of that testing. Covered technology assets in applicable electronic information systems must use multifactor authentication, except during emergencies, for pre-March 2023 federally approved medical devices, or legacy setups covered by a written migration plan. Entities must also conduct a yearly compliance audit under the Security Rule. Collectively, these updates reshape HIPAA's foundation, replacing the old model where entities chose safeguards matching their unique threats with a stricter, proof-driven approach that mandates named controls so gaps are easy to spot.
The legitimate objections to the proposed rule
Critics of the NPRM identify real structural concerns, but they do not say technical validation is not needed. The dispute is over how and when to test, not whether it should happen.
The primary complaint about organizational impact relates to scale. The draft would force both a solo practice and a large health system to comply with identical technical safeguards, despite the effort involved growing alongside an organization's IT complexity. The College of Healthcare Information Management Executives led over 100 healthcare organizations in signing a letter that asked HHS to pull back the rule for this reason. Another criticism focuses on the timeline. Scheduled annual testing may fail to detect the very dangers it is designed to identify. The 2023 MOVEit breach compromised numerous healthcare entities via an unpatched flaw that periodic assessments could not have identified promptly, while opponents contend that scheduling evaluations by date rather than risk leaves systems vulnerable during intervals between reviews. A third issue is the expense. HHS's Regulatory Impact Analysis estimated initial industry compliance expenses at billions of dollars, with significant expenses persisting through the fifth year, prompting smaller and rural providers to voice particular worries about bearing these financial burdens given their narrow operating margins.
Yet these concerns do not alter the current mandate under §164.308(a)(1)(ii)(A) for a complete and precise risk assessment right now, irrespective of the NPRM's fate. The agency applies this expectation to smaller entities no less rigorously than to major ones. Though hardly a major health system, Bryan County Ambulance Authority was held to the identical risk assessment standard applied to any hospital network. Financial concerns are legitimate, yet preparing for tests today remains cheaper than funding post-breach remediation alongside a subsequent OCR settlement. Nor has the wait for a final rule tempered the agency's enforcement pace. The agency still resolves matters using existing rules, and by expanding the Risk Analysis Initiative in 2026 to encompass risk management alongside risk analysis, it shows oversight growing stricter while the final rule remains pending.
A compliant penetration testing program under both the current and proposed rule
A testing regime designed to meet the existing rule's risk-analysis and periodic-evaluation requirements will, in the end, cover nearly everything the new proposal spells out, apart from a handful of specified extras. The two frameworks overlap far more than a first glance suggests.
Include all systems involved with ePHI creation, receipt, maintenance, or transmission. In practice, scope extends to EHRs and patient portals, plus mobile apps, FHIR endpoint APIs, hosting in cloud or on-premises environments, identity platforms, backup stores, and external links to vendors, partners, and other business associate relationships. For connected medical devices, partner across clinical engineering to include IoMT assets while patient care continues uninterrupted.
Cadence is treated in distinct ways depending on which version of the rule applies. The rule in place today does not mandate any set testing interval. Rather, each entity must show, within its risk analysis, why its chosen schedule makes sense, taking into account data sensitivity, internet-facing exposure, significant shifts like adding an EHR module, moving to the cloud, or merging, plus prior security incidents. Under the proposal, a baseline would replace that discretion: penetration testing every year at least, vulnerability scans no less than twice a year, and more often after significant shifts or breaches. NIST SP 800-66r2 endorses a flexible rhythm of this sort, tied to shifts in business and technology.
If an organization builds its program on that logic, wide scope, a cadence driven by real risk and change, plus documentation that closes the gap from finding to resolution, it satisfies the current rule's demands now and won't be left flat-footed whichever way the final rule lands.
Methodology & sources
- HIPAA Penetration Testing Requirements
Provided context on Claroty's 2025 State of CPS Security findings about known vulnerabilities in internet-linked medical devices.
- The HIPAA Security Rule Overhaul: Where Things Stand in Mid-2026
Provided background on the status of the HIPAA Security Rule overhaul as of mid-2026, cited multiple times in the article.
- Federal Register :: HIPAA Security Rule To Strengthen the Cybersecurity of Electronic Protected Health Information
Provided the official text of the January 6, 2025 proposed rule, including the specific provisions such as proposed §164.312(h) for vulnerability scanning and annual penetration testing.