Skip to content

Compliance

New York Hospital
Cybersecurity Regulations

10 NYCRR 405.46, Hospital Cybersecurity Requirements

Component tests from $4,200, free retest. See all pricing →

Last reviewed

Get a fixed quote

Reply in one business day

Senior certified testers, manual-first185+ years combined experienceOnboarding within 24 hoursFree retest includedOur methodology

When you need it

When 405.46 testing comes due

The situations that bring teams to this engagement, and where it fits alongside the rest of your program.

  • Twelve months have nearly passed since your last penetration test, or none has run since the rule became enforceable on October 2, 2025.
  • The CISO’s annual written report to the governing body needs testing results and remediation status behind it.
  • The annual risk assessment turned up systems nobody has tested: remote access, a new EHR module, or building controls.
  • A cybersecurity event at your hospital or a peer raised the question of what an attacker could actually reach.
  • The Department asked for documentation, and the testing records need to hold up for the six years the rule requires.

The rule

New York hospital cybersecurity regulations: what 405.46 requires

New York hospital cybersecurity regulations sit in one section, 10 NYCRR 405.46, which the Department of Health adopted effective October 2, 2024 and made fully enforceable on October 2, 2025. It applies to every general hospital licensed under article 28 of the Public Health Law, and unlike the HIPAA Security Rule it names the penetration test outright. The requirements that bear on testing:

Requirement

(f)(2)(i)
Penetration testing of the hospital’s information systems by a qualified internal or external party
(f)(2)(ii)
Automated scans, or manual or automated reviews, designed to identify publicly known vulnerabilities
(f)(2)(iii)
Timely remediation of vulnerabilities, based on the risk they pose to the hospital
(h)
An accurate and thorough risk assessment; one done for HIPAA counts if it meets the section
(k)(2) and (k)(8)
MFA for anyone reaching internal networks from an external network, and remote-control protocols disabled or securely configured
(l)(2)
Regular cybersecurity awareness training, which may include annual phishing exercises
(n)
Notice to the Department within 72 hours of determining a cybersecurity incident, and supporting records kept for six years

Cadence

(f)(2)(i)
At least annually, based on the risk assessment
(f)(2)(ii)
Set by the risk assessment
(f)(2)(iii)
After each test and scan
(h)
At least annually
(k)(2) and (k)(8)
Ongoing
(l)(2)
Regular
(n)
Per incident

What Invadel delivers

(f)(2)(i)
External and internal penetration tests, reported against 405.46
(f)(2)(ii)
Vulnerability scanning with analyst validation
(f)(2)(iii)
Findings ranked by risk to the hospital, and a free retest
(h)
Test findings written to feed the assessment
(k)(2) and (k)(8)
Remote access and MFA tested from outside
(l)(2)
Phishing simulations with results by department
(n)
Reports and retest evidence formatted for examination

Scope

What counts as an information system

The rule’s definition is wider than many hospital asset lists. It covers any discrete set of electronic information resources, names industrial and process control systems, telephone switching and PBX systems, and environmental control systems, and gives the electronic health record as its example. A test scoped to the corporate network alone leaves most of that out.

Clinical systems

The EHR, PACS, laboratory, and pharmacy systems, and the HL7 and FHIR interfaces between them. Tested in a staging or mirrored environment wherever one exists.

Patient-facing systems

Portals, scheduling, telehealth, and billing: internet-facing and full of nonpublic information. Tested as web application and API engagements.

Network and identity

Active Directory, remote access, and the segmentation between clinical, corporate, biomedical, and guest networks, the paths ransomware uses to spread.

Facilities and telephony

Building management, HVAC and environmental controls, and telephone switching and PBX systems, tested with plant-safe OT methods.

Vendors and devices

Vendor remote-support paths, which subdivision (j) makes the hospital govern, and medical devices, tested as a separate engagement; our guide to medical device penetration testing explains how.

What we assess

What your 405.46 penetration test covers

The rule defines penetration testing as an attempt to circumvent or defeat the security features of an information system from outside or inside the hospital’s systems. We run both, scoped to the systems that hold nonpublic information and keep care running.

External & Remote Access

The internet-facing edge, VPN and remote access, and the MFA 405.46(k)(2) requires for anyone reaching the internal network from an external one.

We test for

  • Internet-facing host and service discovery
  • MFA on remote access, and its exceptions
  • Exposed remote-control protocols
  • Patient portal and email exposure

Internal Network & Identity

How far one phished workstation reaches toward the EHR, and whether privileged accounts are separated and limited as 405.46(k) requires.

We test for

  • Active Directory attack paths
  • Separation of privileged and non-privileged accounts
  • Segmentation between clinical, corporate, and guest networks
  • Access to stores of nonpublic information

Clinical & Business Applications

The EHR, portals, and applications the hospital must assess, whether developed in-house or bought.

We test for

  • Patient record access by ID
  • Authorization between roles
  • HL7 and FHIR interface authentication
  • Encryption over external networks

Facilities & Connected Systems

The rule’s definition of an information system includes industrial and process controls, telephone switching and PBX systems, and environmental control systems.

We test for

  • Building management and HVAC controllers
  • Telephony and PBX administration
  • Medical device network exposure
  • Vendor remote-support paths

Patient safety

Testing a hospital without disrupting care

A test that degrades a clinical system puts patients at risk, so these rules are agreed in writing with IT and clinical engineering before any testing starts.

  • No denial-of-service testing, no fuzzing of clinical devices, and no active scanning of biomedical networks during clinical hours.
  • Production EHR functions are tested in a staging or mirrored environment wherever one exists.
  • A named clinical engineering contact and a stop condition, so any sign of instability halts work immediately.
  • Internal testing scheduled around clinical operations and planned downtime, agreed with IT and nursing leadership.
  • Critical findings reported on discovery, so the CISO can decide the same day whether anything needs action under the rule.

Compare

405.46 and HIPAA: what each asks of testing

New York hospitals carry both. The state rule covers fewer organizations and says more about what they must do.

HIPAA Security Rule

Who
Covered entities and business associates nationwide
Penetration testing
Not named in the current rule; a proposed update would require it every twelve months
Vulnerability scanning
Not named in the current rule; the proposed update would require it every six months
Risk assessment
Required, with no fixed frequency
Security leadership
A designated security official
Incident notice
Breach notification to individuals and HHS under the Breach Notification Rule

10 NYCRR 405.46

Who
General hospitals licensed under article 28 of the Public Health Law
Penetration testing
Required at least annually, by a qualified internal or external party
Vulnerability scanning
Required, at a cadence set by the risk assessment
Risk assessment
At least annually; a HIPAA assessment counts if it meets the section
Security leadership
A CISO from senior or executive staff, reporting in writing to the governing body at least annually
Incident notice
Notice to the Department within 72 hours of determining a cybersecurity incident, on top of any other notice

For the federal safeguards in detail, read our guide to HIPAA technical safeguards.

Governing body

Evidence for the CISO and the Department

Section 405.46(e)(3) requires the CISO to report in writing, at least annually, to the governing body on the cybersecurity program, material risks, and the program’s overall effectiveness. Subdivision (n) requires the hospital to keep supporting records for six years and produce them for examination. The test deliverables are written for both readers.

  • An executive summary in plain language for the governing body: what was tested, what was found, and what was fixed.
  • The dated penetration test report, with a scope statement listing the information systems covered.
  • Scan reports on the cadence the risk assessment set, with remediation ranked by risk.
  • Retest results showing remediated findings closed, and a documented plan for anything needing material improvement, as (n)(3) expects.

Hospitals anywhere in New York State are served from our Manhattan office: external and application testing run remotely, internal testing runs through a small device we ship, and we come on site when the scope needs it; see penetration testing in New York City.

Methodology

How we test

Full methodology →

Every engagement follows the Penetration Testing Execution Standard and the relevant OWASP guides.

These are the phases your compliance test runs through.

  1. 01

    Scope the boundary

    The systems your framework actually covers, and nothing you would pay to test twice.

  2. 02

    Test

    The component penetration tests run to PTES and OWASP standards by senior testers.

  3. 03

    Map to controls

    Every finding tied to the requirement or control it evidences.

  4. 04

    Report for the auditor

    Evidence formatted the way your assessor, examiner, or QSA expects to read it.

  5. 05

    Fix & retest

    A free retest so the audit shows closed findings, not open ones.

How it works

How your engagement runs

From scope through the final retest, your team stays in the loop at every step, with findings tracked live in our platform.

  1. 01

    Scope with clinical teams

    We map the information systems in scope and agree exclusions, testing windows, and stop conditions with IT and clinical engineering.

  2. 02

    Annual test

    External and internal penetration testing, with scans and application testing where the risk assessment calls for them.

  3. 03

    Report for the CISO

    Findings ranked by risk to the hospital, written for the CISO’s report to the governing body.

  4. 04

    Fix & retest

    Close the findings, then a free retest so remediation is documented for the Department.

Fixed prices

What 405.46 penetration testing costs

Published starting prices, fixed in writing before work begins. The annual test is the first two.

What it covers

External penetration test
The internet-facing edge, remote access, portals, and email
Internal penetration test
The hospital network from one compromised workstation, including segmentation
Web application penetration test
Patient portals and in-house applications
Vulnerability scanning
The scans (f)(2)(ii) requires, validated by an analyst
Phishing simulation
The phishing exercises (l)(2) suggests

Price

External penetration test
From $4,200, free retest
Internal penetration test
From $6,000, free retest
Web application penetration test
From $5,200, free retest
Vulnerability scanning
$1,500 up to 250 devices, $2,500 up to 1,000, larger estates quoted

Every starting price is on our pricing page. Health systems with several campuses are quoted from the network layout, as one fixed price.

Proof

Proof in the field

Every engagement is confidential, so the work below is anonymized to sector and engagement type.

All case studies →

Free

Retest on every penetration test

185+

Years combined experience

14

Senior in-house specialists

24h

Onboarding after signing

Healthcare · Imaging

Organization-Wide Phishing Simulation

High risk

Over half the workforce took the bait: roughly a third clicked the link and a quarter entered their credentials on the simulated capture page.

Outcome. Quantified credential-compromise risk across the whole organization and delivered a prioritized program of role-targeted awareness training, recurring simulations, and a faster, simpler reporting workflow.

11,800+

Employees targeted

53%

Phish-prone

24%

Entered credentials

Read the case study

HR & Payroll SaaS

Web Application Penetration Test

High risk

Critical: a file-inclusion flaw that let an attacker read sensitive files from the server through the application itself. High: stored cross-site scripting capable of session theft, insecure direct object references, and an authorization bypass that let an administrator create or delete organization owners.

Outcome. Delivered a remediation plan sequenced by real business impact, critical and high findings first, with a complimentary retest to verify every fix.

28

Findings

1

Critical

5

High

Read the case study

FAQ

Frequently asked questions

What teams most often ask before NY Hospital 405.46 testing.

Still have questions? 
01Does 10 NYCRR 405.46 require penetration testing?

Yes. Section 405.46(f)(2)(i) requires penetration testing of the hospital’s information systems by a qualified internal or external party at least annually, based on the hospital’s risk assessment. Paragraph (f)(2)(ii) adds automated scans, or manual or automated reviews, designed to identify publicly known cybersecurity vulnerabilities, and (f)(2)(iii) requires timely remediation based on the risk each vulnerability poses to the hospital.

02Which hospitals does the regulation apply to?

All general hospitals licensed under article 28 of the New York Public Health Law. In a health system, every licensed general hospital is covered, so testing is usually scoped across the shared network and EHR in a way that reaches each hospital’s systems.

03When did the rule take effect?

Section 405.46 was adopted and took effect on October 2, 2024. Hospitals had one year to comply, so the full rule has been enforceable since October 2, 2025. The 72-hour incident reporting requirement in subdivision (n) applied immediately on adoption.

04Can our own IT team perform the annual test?

The rule allows a qualified internal or external party. An internal team can qualify, but it would be testing systems it built and runs, and the CISO’s annual report to the governing body carries more weight when the test is independent. Many hospitals use an outside firm for the annual test and keep internal staff on scanning and remediation.

05Does our HIPAA risk analysis satisfy the 405.46 risk assessment?

It can. Subdivision (h) accepts a risk assessment performed for another regulatory purpose, such as HIPAA, provided it meets the subdivision’s own requirements, including that it is accurate, thorough, and repeated every year. The annual penetration test is a separate obligation that feeds both. Our HIPAA penetration testing page covers the federal side.

06What must be reported to the Department within 72 hours?

A cybersecurity incident: a cybersecurity event that has a material adverse impact on the hospital’s normal operations, has a reasonable likelihood of materially harming them, or results in ransomware deployed within a material part of its information systems. The hospital must notify the Department as promptly as possible and no later than 72 hours after determining an incident occurred. That notice does not replace any other notification required under State or Federal law.

07Do you test building systems, telephony, and medical devices?

Yes, with plant-safe methods. The rule counts industrial and process controls, telephone switching and PBX systems, and environmental control systems as information systems, so they belong in scope. We start passively and touch live controllers only with written agreement and a facilities or clinical engineering contact on hand; see OT and ICS penetration testing. Medical devices are tested as a separate hardware engagement, never while attached to a patient.

08We sell to New York hospitals. What does 405.46 mean for vendors?

Subdivision (j) requires each hospital to have written policies for the security of systems and information that third-party service providers can reach or hold: identifying and assessing those providers, setting the minimum cybersecurity practices they must meet, and setting guidelines on their access controls, encryption, notice to the hospital of a cybersecurity incident, and representations and warranties about their security. Expect security questionnaires and requests for a recent independent penetration test. A dated test of the product and the systems that hold hospital data answers most of them; our page on healthcare penetration testing covers vendor scopes.

09How much does 405.46 penetration testing cost?

The annual test is built from our published fixed prices: external network testing from $4,200 and internal network testing from $6,000, each with a free retest, plus web application testing from $5,200 for portals and in-house applications, and vulnerability scanning from $1,500 for up to 250 devices, with larger estates quoted. A health system with several campuses gets one fixed price from its network layout. Every starting price is on our pricing page.

Ready to test your defenses?

Talk to our team about what your NY Hospital 405.46 compliance requires.

Prefer the full scoping questionnaire? 

Get a Fixed-Scope Quote

Tell us what you need tested. We reply within one business day.