Skip to content

HIPAA Security Rule penetration testing requirements

Not required today; explicitly proposedHHS Office for Civil Rights

Not explicitly, as the rule stands. The HIPAA Security Rule requires a periodic technical and non-technical evaluation, and penetration testing is a recognised way to perform it — but the words are not in the regulation. That is set to change: the Notice of Proposed Rulemaking published on 27 December 2024 would require penetration testing at least every 12 months and vulnerability scanning at least every 6 months. The NPRM has not been finalised, and the timeline for final action has slipped; verify current status before relying on it either way.

How often

Today: "periodic", defined by your own risk analysis, with annual being the common interpretation. Under the proposal: at least every 12 months, with scanning every 6 months.

What is in scope

Any system that creates, receives, maintains or transmits electronic protected health information, including the business associates who touch it.

The actual text

Clause by clause.

What the standard says, rather than what a vendor says it says. Quote these references directly when you are asked to justify a testing programme internally.

ReferenceRequirement
§164.308(a)(8)
Evaluation
Perform a periodic technical and non-technical evaluation, based initially upon the standards implemented under this rule and subsequently in response to environmental or operational changes affecting the security of electronic protected health information. This is the standard penetration testing is normally mapped to.
§164.308(a)(1)(ii)(A)
Risk analysis
Conduct an accurate and thorough assessment of the potential risks and vulnerabilities to the confidentiality, integrity and availability of electronic protected health information held by the covered entity or business associate.
§164.308(a)(1)(ii)(B)
Risk management
Implement security measures sufficient to reduce risks and vulnerabilities to a reasonable and appropriate level. Findings that are identified and then left unaddressed are a risk-management failure, not only a testing one.
NPRM, 27 Dec 2024
Proposed explicit testing
The proposed Security Rule update would require penetration testing at least once every 12 months, and automated vulnerability scanning at least once every 6 months, or more frequently where the risk analysis indicates. Proposed only — not in force.
Evidence

What the assessor wants to see.

Work through it here. Progress is kept in your browser, and copy or print drops it straight into an audit folder.

evidence checklist
5 items to evidence

Tick what you already hold. Progress is saved in this browser only — nothing is sent anywhere — and copy or print puts it into your audit folder.

Failure modes

Where people lose the point

  • Treating "periodic" as meaning whenever convenient. If your own risk analysis implies annual testing and you test every three years, the gap is self-inflicted.
  • Scoping to the EHR system only and excluding the infrastructure, remote access and vendor connections around it.
  • Performing the evaluation but not evidencing the risk-management step that follows it.
  • Assuming a business associate is tested. Their obligations exist, but your exposure does not transfer with them.
  • Planning on the assumption the NPRM is already in force, or that it never will be.
Questions

HIPAA and penetration testing

Is annual penetration testing mandatory under HIPAA in 2026?
Not under the rule currently in force. The Security Rule requires a periodic technical and non-technical evaluation under §164.308(a)(8) without specifying a method or an interval. The December 2024 NPRM proposes an explicit annual penetration testing requirement, but it has not been finalised and the timeline has moved. Anyone telling you annual testing is already mandatory under HIPAA is describing the proposal, not the regulation.
What is the difference between a HIPAA risk analysis and a penetration test?
A risk analysis is an assessment of where risk to ePHI exists across administrative, physical and technical safeguards. A penetration test is a technical exercise that establishes whether specific weaknesses can actually be exploited. The risk analysis is mandatory and broader; the penetration test is one of the strongest inputs to it, and one of the ways the periodic evaluation standard is met.
Do business associates need penetration testing?
Business associates are directly subject to the Security Rule, so the same evaluation obligation applies to them. From a covered entity’s point of view, their testing is also part of your due diligence: their weakness is your breach notification.

For the longer narrative treatment — worked examples, cost and timing — read HIPAA penetration testing requirements: the full guide.

Testing that produces evidence, not just findings.

Reports mapped to the control they satisfy, with a replayable record behind every finding — which is what an assessor asks for when they push back.