Skip to content

Compliance

HITRUST Penetration
Testing Requirements

Component tests from $4,200, free retest. See all pricing →

Last reviewed

Get a fixed quote

Reply in one business day

Senior certified testers, manual-first185+ years combined experienceOnboarding within 24 hoursFree retest includedOur methodology

When you need it

When you need HITRUST penetration testing

The situations that bring teams to this engagement, and where it fits alongside the rest of your program.

  • A hospital, health system, or payer customer asked for HITRUST certification before it will sign or renew.
  • Your HITRUST scope is set and the assessor’s evidence list includes a recent penetration test.
  • You already have a SOC 2 report or a HIPAA risk analysis, and large healthcare buyers now want HITRUST on top.
  • You are moving from an e1 or i1 to an r2 and the scope, and the testing behind it, is getting bigger.
  • The product changed materially since the last test: a new application, a major release, or a cloud migration.

Why HITRUST

Who asks for HITRUST, and why a HIPAA claim is not enough

Hospitals, health systems, and payers ask their vendors for HITRUST because HIPAA has no official certification. A vendor can say it is HIPAA compliant, but nobody independent has checked. HITRUST offers a certification with a defined control set, testing by an External Assessor, and central quality assurance by HITRUST.

For a health-tech vendor, that often makes HITRUST the price of selling to large healthcare buyers. The penetration test is one of the pieces of evidence behind it, and it is the one that shows your controls hold against an attacker. For HIPAA itself, see our HIPAA penetration testing page.

e1, i1, r2

e1, i1, and r2: where the penetration test fits

HITRUST offers three validated assessments. Each builds on the one before, and the test we usually scope grows with it.

What it is

e1 (essentials)
A foundational set of core controls for lower-risk entities
i1 (implemented)
A fixed set of leading-practice controls; HITRUST lists 182 control requirements
r2 (risk-based)
A control set tailored to your risk factors; HITRUST’s most thorough assessment

Valid for

e1 (essentials)
1 year
i1 (implemented)
1 year
r2 (risk-based)
2 years

What we usually scope

e1 (essentials)
The product and its internet-facing edge: a web application test and an external test
i1 (implemented)
The web application and APIs, the external edge, and the cloud account that hosts them
r2 (risk-based)
The full scope: applications, cloud, external and internal networks, and segmentation

Your requirement statements in MyCSF, not this table, decide what the assessor tests. We confirm scope against them before we quote.

What we assess

What your HITRUST test covers

Most HITRUST scopes are a health-tech product and the cloud it runs in. We test those systems the way an attacker would and hand your assessor evidence, not a raw scan.

Web Applications & APIs

The product your hospital and payer customers log into, and the APIs and integrations behind it.

We test for

  • Authorization between users, roles, and tenants
  • Patient and member record access by ID
  • FHIR, HL7, and partner API authentication
  • Session handling and account takeover

Cloud & Infrastructure

The AWS, Azure, or GCP account and the network edge that host the in-scope systems.

We test for

  • Identity and access management paths
  • Storage and backup exposure
  • Internet-facing services and remote access
  • Logging of our activity

Access & Segmentation

Whether the assessment boundary you drew is the boundary an attacker meets.

We test for

  • Segmentation around in-scope systems
  • Multi-factor authentication on admin and remote access
  • Privileged account exposure
  • Paths from corporate IT into the product environment

Assessment Evidence

The documents your External Assessor asks for when a requirement calls for testing.

We test for

  • Dated report and scope statement
  • Remediation tracking and retest results
  • Tester qualifications and independence
  • Executive summary for leadership

Compare

HITRUST vs HIPAA vs SOC 2

Health-tech buyers often ask for more than one. They are different kinds of thing, and one penetration test can serve all three.

HIPAA

What it is
A federal law: the Security Rule for ePHI
Who checks you
No one certifies; HHS OCR enforces through investigations and compliance reviews
Controls
Required and addressable safeguards, method not prescribed
Penetration testing
Not named in the current rule; a proposed update would require it annually

SOC 2

What it is
An attestation report by a CPA firm against the Trust Services Criteria
Who checks you
Your audit firm
Controls
Criteria you map your own controls to
Penetration testing
Not named; auditors expect it

HITRUST

What it is
A certification against the HITRUST CSF
Who checks you
A HITRUST Authorized External Assessor, then HITRUST quality assurance
Controls
A defined set of requirement statements
Penetration testing
Where your requirement statements call for it

One test, reported against every framework you carry, avoids paying for the same work twice. See SOC 2 penetration testing for the SOC 2 side, and our guide to HITRUST vs SOC 2 for what each expects from testing.

The report

What your External Assessor will want to see

  • A report dated inside the period the assessor reviews, with a scope statement that matches your HITRUST scope.
  • The method stated plainly, which for us is PTES and the OWASP testing guides.
  • Tester qualifications and independence from the systems tested.
  • Findings rated by severity, with evidence of remediation and a retest, not just an initial list.
  • An attestation letter summarizing scope, dates, and outcome, for customers who ask.

Methodology

How we test

Full methodology →

Every engagement follows the Penetration Testing Execution Standard and the relevant OWASP guides.

These are the phases your compliance test runs through.

  1. 01

    Scope the boundary

    The systems your framework actually covers, and nothing you would pay to test twice.

  2. 02

    Test

    The component penetration tests run to PTES and OWASP standards by senior testers.

  3. 03

    Map to controls

    Every finding tied to the requirement or control it evidences.

  4. 04

    Report for the auditor

    Evidence formatted the way your assessor, examiner, or QSA expects to read it.

  5. 05

    Fix & retest

    A free retest so the audit shows closed findings, not open ones.

How it works

How your engagement runs

From scope through the final retest, your team stays in the loop at every step, with findings tracked live in our platform.

  1. 01

    Scope the boundary

    We match the test to the systems in your HITRUST assessment scope and the requirement statements your assessor will test.

  2. 02

    Test

    Application, API, network, and cloud testing by senior testers, manual-first.

  3. 03

    Assessor-ready report

    A dated report with scope, method, findings, and tester independence stated plainly.

  4. 04

    Fix & retest

    Close the findings, then a free retest before the validated assessment.

Proof

Proof in the field

Every engagement is confidential, so the work below is anonymized to sector and engagement type.

All case studies →

Free

Retest on every penetration test

185+

Years combined experience

14

Senior in-house specialists

24h

Onboarding after signing

HR & Payroll SaaS

Web Application Penetration Test

High risk

Critical: a file-inclusion flaw that let an attacker read sensitive files from the server through the application itself. High: stored cross-site scripting capable of session theft, insecure direct object references, and an authorization bypass that let an administrator create or delete organization owners.

Outcome. Delivered a remediation plan sequenced by real business impact, critical and high findings first, with a complimentary retest to verify every fix.

28

Findings

1

Critical

5

High

Read the case study

Healthcare · Imaging

Organization-Wide Phishing Simulation

High risk

Over half the workforce took the bait: roughly a third clicked the link and a quarter entered their credentials on the simulated capture page.

Outcome. Quantified credential-compromise risk across the whole organization and delivered a prioritized program of role-targeted awareness training, recurring simulations, and a faster, simpler reporting workflow.

11,800+

Employees targeted

53%

Phish-prone

24%

Entered credentials

Read the case study

FAQ

Frequently asked questions

What teams most often ask before HITRUST testing.

Still have questions? 
01Does HITRUST require a penetration test?

It depends on the requirement statements in your assessment. The HITRUST CSF is licensed, and the statements that apply to you come out of your scoping in MyCSF, so we do not quote them here. Where a statement calls for penetration testing or technical vulnerability testing, your External Assessor will ask for a dated report covering the systems in scope. We scope the test to those statements.

02Does Invadel issue HITRUST certification?

No. HITRUST certifies, on the basis of a validated assessment run by a HITRUST Authorized External Assessor and HITRUST’s own quality assurance. We are neither. We run the penetration test your assessment relies on, independently of both, and say so in the report.

03How often should we test for HITRUST?

Use the frequency in your requirement statements. Where it is not fixed, test at least once a year and time it three to six months before the validated assessment, so the report, the fixes, and the retest are all dated before the assessor looks.

04We are cloud-only. Do we need an internal network test?

Often not. With no office network inside the scope, the test is usually the web application, its APIs, and the cloud account that hosts them. Your scope decides it, and we confirm it before we quote.

05How much does HITRUST penetration testing cost?

It is built from our published fixed prices: web application testing from $5,200, external network from $4,200, internal network from $6,000, and cloud from $6,800, each with a free retest. You get one fixed quote in writing from your scope details. Starting prices for every service are on our pricing page.

06Can the results go into MyCSF or our GRC platform?

Yes. The report, the executive summary, and the attestation letter come as separate files, so you can attach the right one to each requirement as evidence without exposing more detail than it needs.

Ready to test your defenses?

Talk to our team about what your HITRUST compliance requires.

Prefer the full scoping questionnaire? 

Get a Fixed-Scope Quote

Tell us what you need tested. We reply within one business day.