HIPAA Security Rule penetration testing requirements
Not explicitly, as the rule stands. The HIPAA Security Rule requires a periodic technical and non-technical evaluation, and penetration testing is a recognised way to perform it — but the words are not in the regulation. That is set to change: the Notice of Proposed Rulemaking published on 27 December 2024 would require penetration testing at least every 12 months and vulnerability scanning at least every 6 months. The NPRM has not been finalised, and the timeline for final action has slipped; verify current status before relying on it either way.
Today: "periodic", defined by your own risk analysis, with annual being the common interpretation. Under the proposal: at least every 12 months, with scanning every 6 months.
Any system that creates, receives, maintains or transmits electronic protected health information, including the business associates who touch it.
Clause by clause.
What the standard says, rather than what a vendor says it says. Quote these references directly when you are asked to justify a testing programme internally.
| Reference | Requirement |
|---|---|
| §164.308(a)(8) Evaluation | Perform a periodic technical and non-technical evaluation, based initially upon the standards implemented under this rule and subsequently in response to environmental or operational changes affecting the security of electronic protected health information. This is the standard penetration testing is normally mapped to. |
| §164.308(a)(1)(ii)(A) Risk analysis | Conduct an accurate and thorough assessment of the potential risks and vulnerabilities to the confidentiality, integrity and availability of electronic protected health information held by the covered entity or business associate. |
| §164.308(a)(1)(ii)(B) Risk management | Implement security measures sufficient to reduce risks and vulnerabilities to a reasonable and appropriate level. Findings that are identified and then left unaddressed are a risk-management failure, not only a testing one. |
| NPRM, 27 Dec 2024 Proposed explicit testing | The proposed Security Rule update would require penetration testing at least once every 12 months, and automated vulnerability scanning at least once every 6 months, or more frequently where the risk analysis indicates. Proposed only — not in force. |
What the assessor wants to see.
Work through it here. Progress is kept in your browser, and copy or print drops it straight into an audit folder.
Tick what you already hold. Progress is saved in this browser only — nothing is sent anywhere — and copy or print puts it into your audit folder.
Where people lose the point
- Treating "periodic" as meaning whenever convenient. If your own risk analysis implies annual testing and you test every three years, the gap is self-inflicted.
- Scoping to the EHR system only and excluding the infrastructure, remote access and vendor connections around it.
- Performing the evaluation but not evidencing the risk-management step that follows it.
- Assuming a business associate is tested. Their obligations exist, but your exposure does not transfer with them.
- Planning on the assumption the NPRM is already in force, or that it never will be.
HIPAA and penetration testing
Is annual penetration testing mandatory under HIPAA in 2026?
What is the difference between a HIPAA risk analysis and a penetration test?
Do business associates need penetration testing?
For the longer narrative treatment — worked examples, cost and timing — read HIPAA penetration testing requirements: the full guide.
The other frameworks
PCI DSS v4.0
Yes. PCI DSS is the one framework on this page that names penetration testing outright and tells you how oft…
SOC 2
No — and this surprises people. The Trust Services Criteria never use the words "penetration test". SOC 2 is…
Cyber insurance
There is no standard to comply with, which makes this the most misunderstood item on the list. Whether a pen…
Or compare all four side by side in the penetration testing compliance requirements guide.
Testing that produces evidence, not just findings.
Reports mapped to the control they satisfy, with a replayable record behind every finding — which is what an assessor asks for when they push back.
