The HIPAA Security Rule in force today does not contain the words “penetration test.” It requires a risk analysis, a risk management process, and a periodic technical and nontechnical evaluation of your safeguards, and it leaves the method to you. A proposed rule published in January 2025 would change that by requiring penetration testing at least every twelve months and vulnerability scanning at least every six months. This guide explains what is required now, what is proposed, how the Office for Civil Rights enforces the current rule, and how to scope a test that satisfies both the regulation and the auditor who reads the report.
What the Security Rule requires today
Three provisions of 45 CFR Part 164 do the work:
- §164.308(a)(1)(ii)(A), risk analysis. Conduct an accurate and thorough assessment of the potential risks and vulnerabilities to the confidentiality, integrity and availability of electronic protected health information. This is the provision OCR cites most often, and a penetration test is the most direct way to produce evidence of “thorough.”
- §164.308(a)(1)(ii)(B), risk management. Implement security measures sufficient to reduce those risks to a reasonable and appropriate level. The findings from a test, and the retest showing they were fixed, are the evidence.
- §164.308(a)(8), evaluation. Perform a periodic technical and nontechnical evaluation of how well your policies and procedures meet the Security Rule. A technical evaluation of ePHI systems is, in practice, a penetration test or a vulnerability assessment.
HHS’s guidance on the risk analysis requirement makes identifying and documenting vulnerabilities a required element, and NIST SP 800-66, the implementation guide HHS points to, names penetration testing among the methods. Nothing in the current rule sets a frequency; “periodic” and “reasonable and appropriate” are the standards, judged against your risk analysis and the size of your organization. Our HIPAA penetration testing page describes how we map an engagement to these three provisions.
What the proposed rule would require
On January 6, 2025, HHS published a Notice of Proposed Rulemaking to update the Security Rule. Among many changes, it would require covered entities and business associates to:
- perform penetration testing at least once every twelve months, or more often as the risk analysis indicates;
- perform vulnerability scanning at least once every six months, and after significant changes, on all systems that create, receive, maintain or transmit ePHI;
- maintain a technology asset inventory and network map, updated at least annually;
- remove the “addressable” designation so that safeguards such as encryption and multi-factor authentication become required.
As of September 2026 the rule remains proposed, not final. OCR is reviewing comments, a large number of hospital systems have asked for it to be narrowed or withdrawn, and the federal regulatory agenda targets final action in 2027. Plan for it anyway: an annual penetration test and semiannual scanning is already what SOC 2 auditors, cyber insurers and most healthcare customers expect, so meeting the proposed standard now costs nothing extra when it becomes mandatory.
How OCR enforces the current rule
The enforcement record is the clearest statement of what “required” means in practice.
- OCR closed 21 enforcement actions in 2025 and collected $8,330,066 in penalties. 76% of those actions cited a failure to conduct an accurate and thorough risk analysis. (HIPAA Journal, 2025 Healthcare Data Breach Report)
- 804 breaches of 500 or more records were reported for 2025, affecting more than 138.5 million people, with hacking and IT incidents responsible for more than 80% of them, up from 49% in 2019. (HIPAA Journal, Healthcare Data Breach Statistics)
- Network servers were the location of 61.5% of large breaches and compromised email accounts 24.9%. Business associates accounted for 35.8% of breaches and most of the largest ones. (HIPAA Journal)
- The average healthcare data breach cost $6.64 million, the highest of any industry. (IBM Cost of a Data Breach Report 2026)
- State attorneys general enforce alongside OCR: New York fined Orthopedics NY $500,000 in 2025 over a breach affecting 656,086 people. (HIPAA Journal)
The pattern in the resolution agreements is consistent: the entity was breached through a technical weakness, OCR asked for the risk analysis, and the risk analysis either did not exist or did not cover the system that was breached. A penetration test report dated before the breach, covering the system, is the document that changes that conversation. Our data breach statistics page has the full healthcare set.
What to test: scoping for ePHI
The rule is about ePHI, so the scope follows the data:
- The systems that hold it. EHR platforms, practice management, imaging, billing, data warehouses, and the databases and file stores behind them.
- The systems that move it. Patient portals, APIs (including FHIR endpoints), HL7 interfaces, fax-to-email, and the integrations with payers, labs and clearinghouses.
- The identities that reach it. Active Directory, single sign-on, remote access for clinicians and vendors. Email accounts were the breach location in a quarter of large breaches; a phishing test belongs in the scope.
- The network around it. Internal segmentation between clinical, guest and business networks; medical devices that cannot be patched and have to be isolated instead. See medical device penetration testing.
- The cloud it runs in. Most new health IT runs in AWS, Azure or GCP; the account configuration is in scope. See cloud penetration testing.
- The business associates. Vendors who hold your ePHI are your risk under the rule. Ask for their test reports; see third-party penetration testing.
A typical first engagement for a covered entity is an external network test, an internal network test and a web application test of the patient portal, with the report mapped to §164.308 and §164.312.
What the report has to contain
For OCR, an auditor or a customer’s security review, the report should:
- state the scope in terms of ePHI systems, so it can be matched to the risk analysis;
- describe the methodology (we follow PTES and OWASP);
- list findings with severity, the safeguard each one affects (mapped to §164.308 administrative and §164.312 technical safeguards), and remediation;
- include the retest showing which findings were closed;
- carry an attestation letter summarizing the above on one page.
The format is on the sample report page.
Frequently asked questions
Is penetration testing required by HIPAA? Not by name in the current rule. It is the standard way to meet the risk analysis and evaluation requirements, and OCR’s enforcement history shows what happens without it. The proposed rule would make it explicit and annual.
How often should a healthcare organization test? Annually at minimum, and after significant changes to ePHI systems, which is the proposed rule’s cadence and the one auditors already expect. See how often you should do a penetration test.
Does a vulnerability scan satisfy the requirement? It is part of the evidence and the proposed rule requires it every six months. It does not find authorization flaws in a patient portal or show what an attacker reaches from a compromised workstation. See penetration testing vs vulnerability scanning.
Do business associates have to test? The Security Rule applies to business associates directly. Their customers’ risk analyses also depend on it.
Does HITRUST or SOC 2 cover this? Both expect a penetration test in their evidence, and both map to the HIPAA safeguards. One test, reported against all three, is the efficient route.
The short version
Today’s HIPAA rule requires you to find your vulnerabilities and fix them, and OCR penalizes organizations that cannot show they did. Tomorrow’s rule would require a penetration test every year and a scan every six months. Do the annual test now, scope it around the ePHI, and keep the report and the retest. If you want it done at a published price with the HIPAA mapping built in, scope an engagement.
Written by
Invadel Team
Senior penetration testers writing from real engagements, the same team that scopes, tests, and reports for our clients. About Invadel →