Does HIPAA Require Penetration Testing?
HIPAA does not currently name penetration testing as an explicit requirement. The HIPAA Security Rule requires covered entities and business associates to conduct regular technical and non-technical evaluations — but leaves the specific method to the organization's discretion based on risk. However, penetration testing has become the de facto standard for satisfying the technical evaluation requirement, and HHS guidance strongly implies that organizations should conduct it.
Proposed HIPAA Security Rule amendments under HHS notice from 2024 would change this significantly. The proposed rule would make penetration testing an explicit and mandatory requirement for covered entities and business associates, specifically requiring annual testing of all electronic systems containing electronic protected health information (ePHI). While not yet final law, healthcare organizations should treat this as the direction of travel and begin building testing programs now.
Current HIPAA Requirements Relevant to Security Testing
- Risk Analysis (§164.308(a)(1)) — Requires a thorough assessment of the potential risks and vulnerabilities to ePHI. Penetration testing is the most defensible way to identify and document technical vulnerabilities.
- Evaluation (§164.308(a)(8)) — Requires periodic technical and non-technical evaluations in response to environmental or operational changes affecting security. This is where penetration testing most directly applies.
- Audit Controls (§164.312(b)) — Requires hardware, software, and procedural mechanisms to record and examine activity on systems containing ePHI.
Why Healthcare Organizations Are High-Value Targets
Healthcare organizations are among the most targeted industries for ransomware and data theft. Patient records command high prices on criminal markets, and healthcare systems frequently run legacy technology with long patch cycles. According to BreachLock's 2025 Penetration Testing Intelligence Report, 70% of vulnerabilities detected in healthcare systems were medium and high severity — largely due to widespread legacy systems and inadequate security controls. This makes independent testing especially important.
Business Associates Are Also on the Hook
HIPAA's security requirements extend to business associates — any organization that handles ePHI on behalf of a covered entity. This includes EHR vendors, billing companies, IT managed service providers, and cloud hosting providers serving healthcare clients. Business associates face the same breach notification requirements and OCR enforcement risk as covered entities.
Serving healthcare clients or handling ePHI?
Grid32 conducts HIPAA-aligned penetration tests for covered entities and business associates. Our reports document the technical evaluation required under the Security Rule.
Get a Quote →