Penetration Testing for Healthcare: What HIPAA Requires, What a Test Finds, and How Often to Run One
HIPAA doesn't name penetration testing today—the proposed Security Rule does. What a test finds in a healthcare environment, and how often to run one.
Ask ten practice administrators whether HIPAA requires a penetration test and you will get ten different answers, most of them copied from a vendor blog. The accurate answer has two parts: what the Security Rule requires today, and what the proposed update would require if it is finalized as written. This post gives you both, then covers what a penetration test actually finds inside a clinic, health center, or specialty practice, and how to set a cadence you can defend to an auditor, an insurer, or a board.
Does HIPAA Require Penetration Testing?
Under the rule in force today: not by name. The HIPAA Security Rule requires every covered entity and business associate to conduct an accurate and thorough risk analysis (45 CFR 164.308(a)(1)(ii)(A)), to manage the risks that analysis identifies, and to perform periodic technical and non-technical evaluations of its safeguards (45 CFR 164.308(a)(8)). The Office for Civil Rights (OCR) does not prescribe a method or a schedule. In practice, a penetration test is the most direct evidence that your evaluation was technical, that it tested real exposure rather than a policy binder, and that you acted on the results. OCR’s enforcement actions after ransomware incidents consistently come back to the same finding: the organization never performed a credible risk analysis.
Under the proposed rule: yes, annually. In January 2025, the Department of Health and Human Services (HHS) published a Notice of Proposed Rulemaking to modernize the Security Rule. Among the proposed changes are penetration testing at least once every 12 months, vulnerability scanning at least every six months, mandatory multi-factor authentication, mandatory encryption of electronic protected health information (ePHI) at rest and in transit, and the removal of most “addressable” flexibility. As of September 2026 the rule remains a proposal; check the HHS Security Rule page for its current status before you rely on either version. Our recommendation does not change either way: build the testing program now. If the rule is finalized, you are ahead of it. If it is delayed, you still have the evidence your risk analysis was supposed to produce.
Outside HIPAA, the requirement is already here. Cyber-insurance applications now ask directly whether you perform penetration testing and how recently. Payer contracts, hospital affiliation agreements, and Federally Qualified Health Center (FQHC) funding reviews increasingly ask the same question. For many practices the insurer, not the regulator, is the first party to demand a test report.
Penetration Test vs. Vulnerability Scan: Why a Clinic Needs Both
The two are often confused, and the confusion is expensive, because a scan report is frequently presented to auditors as if it were a test.
| Vulnerability Scan | Penetration Test | |
|---|---|---|
| What it does | Inventories known weaknesses: missing patches, outdated software, weak configurations | Actively exploits weaknesses to prove which ones lead to ePHI, domain control, or ransomware deployment |
| Output | A long list, often thousands of findings, ranked by severity score | A short list of exploitable attack paths, ranked by real impact, with evidence |
| Answers the question | “What is wrong?” | “What can an attacker actually do with it?” |
| Cadence | Continuous or monthly | At least annually, plus after material change |
| Proposed HIPAA rule | Every 6 months | Every 12 months |
A scan tells you a server is missing a patch. A test tells you that the missing patch, combined with a shared local administrator password and a flat network, gets an attacker from the front-desk workstation to your electronic health record (EHR) database in under an hour. Only the second finding tells you what to fix first.
What a Penetration Test Finds in a Typical Healthcare Environment
Healthcare networks fail in predictable ways. These are the findings that surface most often in practices, community health centers, and multi-site groups, and each one maps directly to a Security Rule safeguard.
- Flat networks. Front-desk PCs, clinical workstations, imaging equipment, the EHR server, and guest Wi-Fi all on one segment. One phished workstation reaches everything.
- Shared and reused credentials. A single local administrator password across every workstation, or a service account with domain-admin rights used by a lab interface.
- Exposed remote access. Remote Desktop Protocol (RDP) or a VPN reachable from the internet without multi-factor authentication, often left over from a pandemic-era remote-work setup.
- Unpatched clinical and imaging systems. Ultrasound carts, digital radiography, lab analyzers, and dictation systems running operating systems the manufacturer stopped supporting years ago.
- Vendor remote-access tools. EHR, practice-management, and device vendors with standing remote access, sometimes through tools nobody on staff can name.
- Legacy protocols. Name-resolution and authentication protocols that allow an attacker on the network to capture and relay credentials without ever cracking a password.
- Weak email and identity hygiene. Missing email authentication records, no conditional access, and mailboxes with legacy authentication still enabled.
None of these is exotic. All of them are exactly what ransomware operators look for, and all of them are what an accurate risk analysis is supposed to surface.
External vs. Internal Testing: What Each One Covers
An external penetration test starts from the internet with no credentials. It answers the question every board asks first: can someone outside get in? It covers your public-facing firewall, VPN, remote-access portals, patient portal, email security, exposed services, and the open-source intelligence an attacker would gather about your organization before touching anything.
An internal penetration test assumes the attacker is already inside, through a phished employee, a compromised vendor, or a rogue device on a guest network. It answers the question that determines whether a phishing click becomes a reportable breach: once in, how far can they go? This is where flat networks, shared credentials, and legacy protocols get exploited, and where the path to ePHI is mapped.
A phishing and social-engineering simulation sits alongside both. It measures the control the other two tests assume has already failed, and it produces the training evidence the Security Rule’s workforce-security standard expects.
For most healthcare organizations the right program is external testing plus a phishing simulation first, then internal testing as part of an ongoing managed security engagement, where the findings feed straight into remediation and 24/7/365 Security Operations Center (SOC) monitoring rather than sitting in a PDF.
How Often Should a Healthcare Organization Run a Penetration Test?
The honest answer is: more often than once a year, and always after a material change. A single annual test is a snapshot. Your network on the day of the test is not your network six months later, after a new EHR module, a new imaging vendor, an office move, or a merger.
- Baseline: a full external and internal test at least annually. This is the floor the proposed HIPAA rule would set and the figure most insurers now expect.
- After material change: a new site, a new EHR or practice-management platform, a significant infrastructure change, or an acquisition.
- Ongoing: monthly or quarterly automated testing against your external perimeter and internal network, so that a change made in March does not wait until next year’s test to be discovered.
Automated, repeatable testing is what makes the third bullet realistic. Traditional consultant-led engagements are point-in-time by design and priced accordingly. A platform-driven approach, run and validated by security engineers, lets you test on a schedule instead of on a budget cycle, with each run producing a comparable report so you can show an auditor a trend rather than a single data point.
What the Report Should Give You
A penetration test report is a compliance artifact and a work order at the same time. Before you accept one, make sure it includes:
- An executive summary a practice administrator or board member can read without a glossary: what was tested, what was found, and how bad it is in plain language.
- Attack-path narratives, not just a findings table: how the tester got from the starting point to ePHI, step by step, with evidence.
- Risk-ranked findings based on real exploitability and business impact, not a raw severity score.
- Specific remediation steps for each finding, written for the people who will actually fix them.
- Compliance mapping so each finding can be tied to the Security Rule safeguard it affects, which is what turns the report into risk-analysis evidence.
- Activity logs from the test window, so your monitoring team can confirm whether the simulated attack was detected. If the SOC saw nothing, that is a finding too.
Then treat the 30 days after delivery as the real engagement. Fix the critical and high findings, document each fix, retest to confirm, and file the before-and-after with your risk analysis. That file is what an OCR investigator, a cyber insurer, or an affiliation reviewer will ask for.
Boom Logic Penetration Testing for Healthcare Organizations
Boom Logic Penetration Testing is performed by our own security engineers using an automated internal and external network testing platform built by OSCP-, CEH-, and CISSP-certified testers. Tests run monthly or on demand rather than once a year, replicate real attacker behavior from reconnaissance through exploitation and privilege escalation, and deliver reports within 48 hours with an executive summary, technical findings, and prioritized remediation steps. Because we operate the stack the test runs against, findings go directly to the engineers who fix them and to the 24/7/365 SOC that watches for the next attempt.
Healthcare organizations with 25 or more staff or endpoints qualify for a complimentary external penetration test and phishing simulation as part of a free security assessment. Every test requires a signed rules-of-engagement agreement before any testing begins; we never test a system we have not been authorized to test.
If you run a medical practice, a community health center, or a multi-site group in Los Angeles, start with our healthcare IT and security services or the dedicated FQHC and community health center page, then request your assessment. Ongoing testing, remediation, and monitoring are delivered through our SOC as a Service and Managed Detection and Response programs.
Frequently Asked Questions
Is a penetration test the same as a HIPAA risk analysis?
No. The risk analysis is the broader process of identifying where ePHI lives and what threatens it. A penetration test is the technical evidence that feeds it. The strongest programs pair the two: the analysis defines scope, the test validates exposure, and the remediation record closes the loop.
Will a penetration test disrupt patient care?
A properly scoped test should not. The rules-of-engagement agreement defines testing windows, systems that are in and out of scope, and escalation contacts. Clinical and imaging systems are typically tested with non-disruptive methods or scheduled outside clinic hours.
Does a small practice need this, or only hospitals?
The Security Rule applies to every covered entity and business associate regardless of size, and the proposed rule does not exempt small organizations. Attackers target practices precisely because they assume smaller organizations have not tested. The right scope scales with the environment; the obligation does not disappear.
Can our EHR vendor’s security certification cover this?
Your vendor’s certification covers their platform, not your network, your workstations, your credentials, or your staff. Most healthcare breaches begin on the covered entity’s side of that line.
More from the blog. Security, infrastructure, and the business of IT.
Cybersecurity for Law Firms: The 2026 Incident-Response Checklist
What cybersecurity for law firms requires in 2026: the ethics duties, the controls that matter, and a step-by-step incident-response checklist for partners.
Read article →MSP vs. MSSP vs. MDR: Which One Does Your Organization Actually Need?
MSP, MSSP, and MDR are not interchangeable. Here is what each one covers, what each one won't do, and how to tell which your…
Read article →Send Us Your Lowest AWS or Azure Quote—We’ll Beat It by 10%
Bring us your lowest AWS, Azure, or Google Cloud quote and we'll beat it by 10%—with fully managed hosting included at no extra cost.
Read article →Have a question this article didn’t answer?
Talk to the engineers directly. Get a free security assessment and a clear, flat-rate plan from one accountable team.