Dunicot A cybersecurity consultancy and advisory firm.

Framework · HIPAA

HIPAA penetration testing

The HIPAA Security Rule is deliberately technology-neutral. It tells you to evaluate, not how. Penetration testing is how most covered entities and business associates evidence that evaluation with something an investigator would accept.

Overview

Technical evidence for the risk analysis and periodic evaluation the Security Rule requires.

Framework reference

Regulation
HIPAA Security Rule, 45 CFR Part 164 Subpart C
Risk analysis
§164.308(a)(1)(ii)(A), accurate and thorough assessment of risks to ePHI
Evaluation
§164.308(a)(8), periodic technical and non-technical evaluation
Access control
§164.312(a)(1), technical policies limiting ePHI access to authorised persons
Audit controls
§164.312(b), mechanisms that record and examine ePHI system activity
Agreement
Business Associate Agreement signed where the engagement can touch ePHI

What the framework requires

The risk analysis at §164.308(a)(1)(ii)(A) must be accurate and thorough. A documented technical assessment of the systems holding ePHI is the difference between a risk analysis grounded in evidence and one grounded in a questionnaire.

The evaluation requirement at §164.308(a)(8) asks for periodic technical evaluation in response to environmental or operational change. Regular testing satisfies it and gives a defensible cadence.

Access control at §164.312(a)(1) and audit controls at §164.312(b) are both testable directly: whether one patient can reach another’s record, and whether the attempt is recorded in a way that would reconstruct the event.

What the engagement delivers

01

Safeguard mapping

Findings mapped to the specific administrative, physical and technical safeguards affected, with the CFR reference.

02

Risk analysis input

Technical findings expressed with likelihood and impact so they feed the required risk analysis rather than sitting beside it.

03

Access control verification

Cross-patient, cross-provider and cross-organisation access actively attempted against every record type.

04

Audit control verification

Whether access to records is logged usefully, and whether those logs can be suppressed by the account being audited.

05

BAA and synthetic data

A signed Business Associate Agreement where required, with a strong preference for synthetic data that removes ePHI from scope entirely.

06

Vendor assessment answers

Documentation that answers the testing questions on hospital and insurer business-associate assessments directly.

Questions

Does HIPAA require penetration testing?

Not explicitly. It requires an accurate and thorough risk analysis and a periodic technical evaluation. Penetration testing is the most common and most defensible way to evidence both, and it is what enterprise healthcare partners ask about during vendor assessment.

Will you sign a BAA?

Yes, where the engagement could involve access to ePHI. The preferred arrangement is testing against synthetic data, which exercises identical code paths without bringing real ePHI into scope at all.

We are a business associate, not a covered entity. Does this apply?

Yes. Business associates are directly liable for Security Rule compliance, and in practice face more frequent assessment than covered entities because every client assesses them independently.

How does this help with OCR investigations?

Where an incident occurs, documented testing and remediation demonstrate that reasonable and appropriate safeguards were in place and actively verified. That record is materially better than reconstructing intent after the fact.

How much does HIPAA penetration testing cost?

Cost follows scope: patient-facing systems, clinical and billing applications, integrations and internal network. A fixed quote follows scoping, and the integrations holding broad credentials are frequently better value than the portal everyone focuses on.

How often should a covered entity test?

The Security Rule requires periodic evaluation without naming an interval. Annually plus after significant change is what OCR guidance and industry practice converge on, and it is what an investigator compares your record against if something goes wrong.

Does the Security Risk Analysis replace penetration testing?

No, and conflating the two is a common and expensive mistake. The risk analysis is an assessment of risks to ePHI across your organisation. Testing is technical evidence of whether the safeguards that analysis relies on actually hold. Investigators have repeatedly found organisations with a completed analysis and untested controls.

Testing for your HIPAA deadline

Tell us the audit date and the scope. Engagements are scheduled backwards from your deadline so remediation and retest both land inside it.