U.S. Department of Health and Human Services · HIPAA Security Rule (45 CFR Part 164, Subpart C)
Does HIPAA require a penetration test?
The HIPAA Security Rule sets safeguards for electronic protected health information. It applies to covered entities and to business associates, which is how most health technology startups are caught by it.
The short answer
The HIPAA Security Rule as currently in force does not name penetration testing. It requires an accurate and thorough risk analysis under 164.308(a)(1)(ii)(A) and a periodic technical and nontechnical evaluation under 164.308(a)(8). A proposed rule published in January 2025 would add explicit penetration testing and vulnerability scanning requirements, but it is a proposal and has not taken effect.
Who it applies to
Health plans, providers and clearinghouses, and any vendor that creates, receives, maintains or transmits electronic protected health information on their behalf.
In detail
The Security Rule is deliberately technology-neutral and scales with the size and complexity of the organization. It is built from required and addressable implementation specifications, and addressable does not mean optional: it means implement it, or document why an alternative is reasonable and appropriate.
Two provisions create the testing expectation. The risk analysis requirement at 164.308(a)(1)(ii)(A) asks for an accurate and thorough assessment of risks to electronic protected health information, and OCR enforcement actions have repeatedly turned on risk analyses that were narrow or stale. The evaluation requirement at 164.308(a)(8) asks for periodic technical and nontechnical evaluation of how well the safeguards meet the rule.
In January 2025 HHS published a notice of proposed rulemaking that would significantly tighten the Security Rule, including explicit requirements for penetration testing at least annually and vulnerability scanning at least every six months, and would remove the addressable category. That is a proposal. Until a final rule is published and takes effect, the obligation remains the risk analysis and evaluation language above, and anyone telling a health technology buyer that HIPAA requires an annual pen test today is ahead of the regulation.
What to have in scope
- Systems that create, receive, maintain or transmit electronic protected health information
- Access controls and audit logging, which are where OCR enforcement concentrates
- Findings fed back into the risk analysis rather than kept as a separate artifact
- Evidence a business associate can hand its covered entity during diligence
Questions people ask
Does HIPAA require a penetration test?
Not in the Security Rule as it currently stands. HIPAA requires a risk analysis under 45 CFR 164.308(a)(1)(ii)(A) and a periodic evaluation under 164.308(a)(8). A penetration test is a common way to support both. A proposed rule published by HHS in January 2025 would add an explicit annual penetration testing requirement, but it has not taken effect.
Does a HIPAA risk analysis count as a penetration test?
No. A risk analysis is an assessment of risks to electronic protected health information across the organization. A penetration test is technical testing of specific systems. The test informs the analysis; it does not replace it.
Do business associates need their own testing?
Yes. The Security Rule applies directly to business associates, and covered entities increasingly ask for testing evidence during vendor diligence regardless of what the rule compels.
Related frameworks
This page describes published standards and regulations and is not legal advice. Where a rule is proposed rather than in force, it is labelled as such. Confirm obligations with your auditor or counsel.
Get a scoped price without a discovery call
Tell us what is in scope and what your audit needs. You get a fixed price and a date, not a quote after two meetings.