HIPAA Penetration Testing: Is It Required?
The current HIPAA Security Rule doesn't name "penetration test" as a requirement — but a December 2024 proposed rule would change that outright, and OCR has already asked for penetration test evidence in breach investigations under the existing language. Here's where things actually stand, and what's about to become official.
What the current Security Rule actually says
45 CFR §164.308(a)(8), the Evaluation standard, requires covered entities and business associates to "perform a periodic technical and non-technical evaluation" of how well their security policies and procedures meet the Security Rule's requirements — initially based on the standards implemented, and subsequently in response to environmental or operational changes affecting ePHI security. The regulation names the outcome, not the method. It doesn't say "penetration test," the same structural pattern as SOC 2's CC4.1/CC7.1 and ISO 27001's Annex A 8.8.
In practice, penetration testing has become the accepted technical evaluation method for organizations handling electronic protected health information (ePHI), because it's the most direct way to demonstrate that safeguards actually hold up rather than simply exist on paper. HHS guidance and industry practice both point toward it, even without the word appearing in the regulatory text itself — today.
That's about to change: the December 2024 NPRM
HHS published a Notice of Proposed Rulemaking (NPRM) in December 2024 proposing updates to the HIPAA Security Rule that would make penetration testing an explicit, named requirement — proposed at least once every 12 months — alongside vulnerability scanning at least every six months. If finalized as proposed, this closes the interpretive gap entirely: no more inferring the requirement from "periodic technical evaluation" language, just a stated cadence.
As of this writing, the rule is proposed, not final — it's gone through public comment and remains subject to the federal rulemaking timeline before taking effect. Organizations should track its status directly rather than assume the new explicit requirement is already binding, but should also recognize the direction of travel is clear: build the testing cadence now rather than scrambling once the rule finalizes.
"HIPAA doesn't say 'penetration test' yet. The proposed rule says it plainly — and OCR has been asking for it either way."
What OCR actually asks for after a breach
The gap between "not explicitly required" and "expected in practice" becomes very real once the HHS Office for Civil Rights opens an investigation. In numerous published resolution agreements following reported breaches, OCR has requested evidence of regular technical evaluation — including penetration testing — as part of assessing whether the organization satisfied its 164.308(a)(8) obligations before the incident. Its absence has been a contributing factor in several settlements. Waiting for the NPRM to finalize before treating this seriously is a bet against how OCR already enforces the current rule.
Risk analysis vs. penetration test — both, not either
| HIPAA Risk Analysis (164.308(a)(1)) | Penetration Test | |
|---|---|---|
| Scope | Broad — policies, processes, likely threats to ePHI | Narrow — active exploitation of technical systems |
| Method | Assessment, documentation review, interviews | Hands-on adversarial testing |
| Required by name | Yes, explicitly | Not yet (proposed rule pending) |
| Relationship | Should reference and incorporate pentest findings | Provides technical evidence the risk analysis draws on |
A thorough HIPAA risk analysis doesn't stand on its own without technical validation — it should reference and incorporate recent penetration test findings as part of establishing the actual likelihood and impact of threats to ePHI, not just the theoretical ones. Treating the two as separate, unrelated exercises is a common gap OCR investigations surface.
Scoping for ePHI systems
Scope should cover every system that creates, receives, maintains or transmits ePHI — which, for most healthcare-adjacent SaaS products, extends well beyond the obvious patient portal into APIs, integration endpoints with EHR systems, mobile apps, and increasingly, AI features processing clinical data. A scope that only covers the patient-facing web app while excluding the API layer that actually moves ePHI between systems is a common and consequential gap.
How ComplyArmor supports HIPAA evidence
ComplyArmor's Smart PTaaS covers the full stack ePHI typically touches — web applications, mobile apps, APIs, networks, and increasingly AI features — with every finding verified by a human tester before it reaches your report. See our attack surface breakdown and compliance mapping for how findings translate into evidence. Given the direction of the 2025 NPRM toward a named annual-plus-six-month cadence, continuous testing through Smart PTaaS is a reasonable way to get ahead of that requirement rather than scrambling once it's finalized.
Frequently asked questions
Does HIPAA require penetration testing?
Not explicitly under the current Security Rule — 45 CFR 164.308(a)(8) requires periodic technical and non-technical evaluation of security safeguards, without naming penetration testing as the specific method. In practice, it's the accepted way to demonstrate that evaluation for systems handling electronic protected health information (ePHI). A December 2024 proposed rule (NPRM) would make penetration testing an explicit, named requirement if finalized.
What does 45 CFR 164.308(a)(8) actually require?
It requires covered entities and business associates to perform a periodic technical and non-technical evaluation, based initially on the standards implemented under the Security Rule and subsequently in response to environmental or operational changes affecting the security of ePHI, establishing the extent to which an entity's security policies and procedures meet Security Rule requirements.
What's the difference between a HIPAA risk analysis and a HIPAA penetration test?
A HIPAA risk analysis (required under 164.308(a)(1)) is a broader assessment of potential risks and vulnerabilities to ePHI confidentiality, integrity and availability, often policy and process-focused. A penetration test is a narrower, technical exercise that actively attempts to exploit weaknesses in the systems storing or transmitting ePHI. A thorough risk analysis typically references penetration testing results as supporting evidence, but the two aren't interchangeable.
Does OCR ask for a penetration test report after a breach?
In many HHS Office for Civil Rights investigations and resolution agreements following a reported breach, evidence of regular technical evaluation — including penetration testing — is requested as part of assessing whether the organization met its 164.308(a)(8) obligations. Its absence has featured in several published OCR settlements as a contributing factor.
What's changing in HIPAA's 2025 proposed penetration testing requirement?
HHS published a Notice of Proposed Rulemaking (NPRM) in December 2024 that would update the HIPAA Security Rule to explicitly require penetration testing at least once every 12 months, alongside vulnerability scanning at least every six months. As of this writing the rule is proposed, not final — organizations should track its status rather than assume it's already in effect.
Whether or not the proposed rule has finalized by the time you're reading this, the practical bar is the same: if you handle ePHI and can't produce a recent penetration test, that's the gap an OCR investigator — or the finalized rule — will ask about first.