Skip to main content
    HIPAA Compliance

    HIPAA Penetration Testing

    For Covered Entities and Business Associates.

    HIPAA penetration testing from StealthNet validates every system that stores, processes, or transmits ePHI for covered entities and business associates. This is healthcare penetration testing built around the HIPAA Security Rule, so every report maps to technical safeguards (§164.312) and the §164.308(a)(8) technical evaluation requirement, delivered in as little as 48 hours. AI pentests start at $1,500 and hybrid pentests start at $5,000.

    HIPAA pentests from $1,500 · Hybrid engagements from $5,000 · Free remediation retest

    48-Hour Reports HIPAA-Mapped Deliverables US-Based Senior Testers AI + Human Hybrid

    Get Scoped in 24 Hours

    Sample report

    Share a few details and pick a time to chat right after.

    Fixed-fee quote in 24 hours. No credit card. No sales pitch.

    Your details stay private. NDA available on request.

    No commitment. We'll follow up within 1 business day.

    Trusted by Companies Where Security Isn't Optional

    TopLeft logo
    Derma Monitor logo
    Avara Software logo
    Phish Firewall logo
    TopLeft logo
    Derma Monitor logo
    Avara Software logo
    Phish Firewall logo

    What customers say

    Highly recommend StealthNet AI

    "StealthNet AI performed a thorough and comprehensive pen test, fast turnaround on conducting the test, they were very responsive, and it was great value."
    RB

    Richard B.

    Founder · Avara Software · Health, Wellness & Fitness

    The best choice for penetration testing

    "The testing was thorough and the reports were structured precisely for the regulatory requirements. Explanation of issues along with steps to reproduce and remediation advice were detailed and clear, making corrections a breeze."
    JM

    Jeremy M.

    Director · IKO Corp · Medical Devices

    A HIPAA penetration test is a controlled attack simulation against the applications, networks, cloud services, and integrations that create, receive, maintain, or transmit electronic Protected Health Information (ePHI). HHS OCR treats penetration testing as the practical way to satisfy the HIPAA Security Rule §164.308(a)(8) technical evaluation requirement and to validate the §164.312 technical safeguards (access controls, audit controls, integrity, and transmission security).

    Both covered entities and business associates are expected to perform a HIPAA-compliant pentest at least annually and after any material change to ePHI-handling systems. The 2025 HHS NPRM to strengthen the HIPAA Security Rule proposes making annual penetration testing and semi-annual vulnerability scanning explicit requirements. StealthNet's HIPAA-mapped reports are built to satisfy either the current best-practice expectation or the proposed 2026 mandate once finalized.

    How a HIPAA Pentest Runs

    From PHI scope to OCR-ready report in days

    Define your PHI-handling systems, AI agents probe HIPAA-relevant controls, a senior tester validates impact, and you receive evidence formatted for HIPAA Security Rule audits.

    From kickoff to auditor-ready report, delivered in 48 hours.

    The Problem

    Healthcare Breaches Are at an All-Time High.

    Healthcare has recorded the highest average data breach cost of any industry for more than a decade running in IBM's Cost of a Data Breach report, and every breach of 500 or more individuals is published permanently on the HHS OCR breach portal.

    HHS OCR flags your risk analysis

    Auditors expect penetration testing evidence mapped to Security Rule safeguards. Generic vulnerability scans won't pass.

    You're testing reactively

    Post-breach testing costs 10x more. Annual proactive assessments prevent costly remediation and OCR scrutiny.

    You're overpaying for compliance

    Legacy firms charge $20K to $60K for the same coverage StealthNet delivers with AI pentests starting at $1,500 and hybrid pentests starting at $5,000.

    Pricing

    How Much Does a HIPAA Penetration Test Cost?

    Pentest reports built for HIPAA, not retrofitted for it. Transparent pricing for covered entities and business associates.

    StealthStrike

    $1,500

    • 48-hour delivery
    • Exploit-validated findings
    • Mapped to HIPAA §164.312 safeguards

    Best for: Annual risk analysis, business associate validation, proactive assessment

    Most Popular

    Hybrid (AI + Human) Pentest

    Starting at $5,000

    Typical engagements range from $5,000 to $10,000 depending on scope

    • AI attack simulation + senior US-based pentester validation
    • 48-hour first report
    • Dedicated project manager + private Slack channel
    • Compliance-ready report + free retest included

    Best for: Post-breach remediation, covered entities with ePHI systems, OCR-facing evidence

    HIPAA penetration testing cost, side by side

    Legacy healthcare pentests are priced for a six-week manual engagement. Ours are priced for the evidence you actually need. See the full penetration testing cost breakdown.

    EngagementTypical costTime to reportBest fit
    Traditional consultancy pentest$20,000 to $60,0003 to 6 weeksLarge health systems with existing retainers
    StealthNet AI pentestFrom $1,50048 hoursAnnual risk analysis evidence, business associate validation
    StealthNet hybrid AI plus human pentestFrom $5,000, typically $5,000 to $10,00048 hours to first reportCovered entities, OCR-facing evidence, post-breach validation

    Swipe the table sideways to see every column.

    Every engagement includes a free remediation retest. Want proof first? Review a sample pentest report before you scope.

    Deliverables

    Mapped to HIPAA Security Rule Safeguards.

    Access Controls §164.312(a)

    Testing of authentication, authorization, and access policies protecting ePHI

    Audit Controls §164.312(b)

    Validation that systems properly log activity in ePHI-containing systems

    Integrity §164.312(c)

    Testing mechanisms protecting ePHI from improper alteration or destruction

    Transmission §164.312(e)

    Assessment of encryption protecting ePHI during electronic transmission

    Safeguards Mapping

    How the Pentest Maps to §164.308 and §164.312

    Each row is a Security Rule safeguard, what our HIPAA penetration testing does against it, and the evidence that lands in your report.

    HIPAA penetration testing safeguards mapping.
    Each HIPAA §164.312 technical safeguard and the penetration testing activity that produces evidence for it.
    §164.308(a)(1)(ii)(A) Risk analysis
    What we test
    Exploitable paths to ePHI that your paper risk analysis rated theoretically
    Evidence you get
    Validated risks written in risk-register format for your analysis update
    §164.308(a)(8) Technical evaluation
    What we test
    Periodic technical evaluation of ePHI systems after changes
    Evidence you get
    Dated technical evaluation report satisfying the evaluation standard
    §164.308(a)(5) Security awareness
    What we test
    Optional phishing and vishing simulation against workforce members
    Evidence you get
    Campaign results with click, credential, and reporting rates
    §164.312(a) Access control
    What we test
    Unique user IDs, least privilege, cross-patient and cross-tenant access, emergency access
    Evidence you get
    Proven access-control failures with reproduction steps
    §164.312(b) Audit controls
    What we test
    Whether ePHI access is logged, complete, and resistant to tampering
    Evidence you get
    Gap list showing which attacker actions produced no usable log
    §164.312(c) Integrity
    What we test
    Whether ePHI can be improperly altered or destroyed without detection
    Evidence you get
    Integrity findings tied to the affected records and workflows
    §164.312(d) Authentication
    What we test
    MFA coverage, session handling, password reset abuse, API and machine identity
    Evidence you get
    Authentication bypass and takeover findings with impact on ePHI
    §164.312(e) Transmission security
    What we test
    TLS configuration, encryption in transit, and interface-level exposure
    Evidence you get
    Encryption and transmission findings with configuration remediation

    Testing more than one framework this year? The same engagement can produce SOC 2 and PCI DSS evidence alongside HIPAA. See how the overlap works on our compliance penetration testing page.

    Scope

    ePHI Systems We Test

    HIPAA scope is wider than most teams assume. Anything that creates, receives, maintains, or transmits ePHI belongs in the engagement.

    EHR and EMR platforms

    Clinical record systems, vendor-hosted modules, and the admin consoles behind them, including role separation between clinicians, staff, and admins.

    Patient portals and mobile apps

    Registration, messaging, scheduling, billing, and document access flows where cross-patient exposure is the most common critical finding.

    HL7 and FHIR endpoints

    Interface engines, FHIR APIs, OAuth-connected third-party apps, and partner integrations that move ePHI between organizations.

    Connected medical devices

    Device interfaces, companion apps, and management servers. Premarket device work is covered on our FDA track.

    Cloud environments

    AWS, Azure, and GCP accounts holding ePHI: identity, storage buckets, databases, backups, and misconfigured public exposure.

    Internal networks

    Segmentation between clinical and corporate networks, lateral movement to ePHI repositories, and domain privilege escalation paths.

    For the wider clinical and digital health picture, see our healthcare penetration testing page. Building a regulated device? Read how FDA scope and threat modeling change a medical device pentest.

    Scope & Evidence

    What Gets Tested, What the Auditor Receives, and How Long It Takes

    A practical view of a HIPAA penetration test engagement from scoping to evidence delivery.

    EHR / EMR platform and admin console
    Evidence produced
    Access-control and audit-control findings mapped to §164.312(a)-(b)
    Typical timeline
    48 hours to 5 days
    Patient portal and mobile app
    Evidence produced
    Cross-patient exposure, authentication bypass, and transmission security findings
    Typical timeline
    48 hours to 4 days
    HL7 / FHIR endpoints and integrations
    Evidence produced
    Interface abuse, OAuth flaws, and partner-boundary findings
    Typical timeline
    2 to 5 days
    Connected medical devices and companion apps
    Evidence produced
    Device, companion app, and management plane vulnerabilities
    Typical timeline
    3 to 7 days
    Cloud and hosting environment (AWS/Azure/GCP)
    Evidence produced
    Storage exposure, identity misconfigurations, and encryption gaps
    Typical timeline
    2 to 5 days
    Internal network and segmentation
    Evidence produced
    Lateral movement paths and domain privilege escalation to ePHI
    Typical timeline
    4 to 10 days
    Free remediation retest
    Evidence produced
    Retest evidence showing closure of critical and high findings
    Typical timeline
    2 to 4 days after fix verification

    Need the same evidence for SOC 2, PCI DSS, or ISO 27001? See how one engagement covers multiple frameworks on our compliance penetration testing page.

    Coming in 2026

    The proposed HIPAA Security Rule update would make testing mandatory

    HHS OCR has proposed an update to the HIPAA Security Rule that would require automated vulnerability scanning at least every 6 months and penetration testing at least every 12 months, or more often when a risk analysis calls for it. The current Security Rule remains in effect while rulemaking continues, so treat this as a strong signal rather than final legal text.

    • Annual HIPAA penetration testing already satisfies the proposed pentest cadence.
    • Continuous AI testing covers the semi-annual scanning floor without another vendor.
    • Business associates will be held to the same expectations through their BAAs.

    Business associates and BAAs

    Any vendor that creates, receives, maintains, or transmits ePHI on behalf of a covered entity is bound by its business associate agreement to implement the HIPAA Security Rule. In practice that means covered entities now ask their business associates for current penetration testing evidence during vendor reviews and renewals.

    We deliver a shareable summary and letter of attestation alongside the technical report, so you can answer diligence questionnaires without exposing raw findings. Preview the format in our sample report.

    HITRUST crossover

    Payers and enterprise health customers increasingly ask for HITRUST CSF certification on top of HIPAA. A HIPAA-mapped pentest and a HITRUST-mapped pentest overlap heavily in scope, so most teams cover both with one engagement rather than paying for two.

    Read our HITRUST penetration testing guide for how the two programs line up, then tell us both targets during scoping so the report carries both mappings.

    Free Resource

    HIPAA Penetration Testing Checklist

    A six-part checklist covering ePHI scope, Security Rule safeguards, testing execution, evidence, and cadence. Built from the HIPAA pentests we run for covered entities and business associates.

    Most HIPAA penetration testing gaps are scoping gaps. This checklist walks through every ePHI system that belongs in scope, the §164.308 and §164.312 safeguards your report has to speak to, and the evidence HHS OCR expects to see attached to your risk analysis.

    • Inventory every system that creates, receives, maintains, or transmits ePHI
    • Map testing to §164.308 administrative and §164.312 technical safeguards
    • Cover EHR, patient portals, HL7 and FHIR endpoints, devices, cloud, and internal networks
    • Package auditor-ready evidence, remediation owners, and retest validation
    • Set a cadence that meets the proposed 2026 scanning and pentest frequencies
    48-hour reports AI + human validation Security Rule mapping
    StealthNet AI
    Full checklist inside
    Gated Resource

    Get the Checklist

    Downloads instantly. No sales call required to read it.

    By submitting, you agree to receive the checklist and occasional related emails. Unsubscribe anytime.

    Compare

    HIPAA Pentest vs. Vulnerability Scan vs. Risk Analysis

    Three different HIPAA evidence artifacts, three different jobs. Here's how they map to HHS OCR expectations.

    What it tests
    HIPAA Penetration Test
    Exploitable paths to ePHI, proven by a tester
    Vulnerability Scan
    Known CVEs and misconfigurations, no exploitation
    Risk Analysis
    Threats, likelihoods, and impacts on paper
    Combined (Recommended)
    Documented risks validated by real exploitation evidence
    Frequency HHS expects
    HIPAA Penetration Test
    Annually and after material ePHI system changes
    Vulnerability Scan
    Semi-annually (proposed 2026 minimum)
    Risk Analysis
    Continuously; formally updated at least annually
    Combined (Recommended)
    Annual pentest + semi-annual scans + rolling risk analysis
    Evidence produced
    HIPAA Penetration Test
    Executive + technical report, exploited findings, §164.312 mapping
    Vulnerability Scan
    Scanner output with CVSS scores
    Risk Analysis
    Risk register aligned to §164.308(a)(1)(ii)(A)
    Combined (Recommended)
    Audit-ready binder covering §164.308(a)(8) evaluation
    Satisfies §164.308(a)(8) alone
    HIPAA Penetration Test
    Yes, as the technical evaluation component
    Vulnerability Scan
    No, depth insufficient for OCR expectations
    Risk Analysis
    No, needs a technical evaluation to back it
    Combined (Recommended)
    Yes, this is what HHS OCR expects to see
    Why StealthNet

    AI Handles Speed. Humans Validate Everything.

    A named, US-based senior tester validates every finding before your report is delivered.

    Reports are mapped to HIPAA Security Rule safeguards, so there is no manual reformatting for auditors.

    Most clients receive their first report within 48 hours of scoping call completion.

    Cost
    Traditional
    $20K to $60K
    StealthNet
    AI: $1,500 / Hybrid: from $5,000
    Delivery
    Traditional
    3 to 6 weeks
    StealthNet
    48 hours
    HIPAA Mapping
    Traditional
    Manual / extra cost
    StealthNet
    Included
    Retest
    Traditional
    Extra charge
    StealthNet
    Free
    Healthcare Expertise
    Traditional
    Varies
    StealthNet
    Specialized
    FAQ

    HIPAA Pentesting Questions

    While HIPAA doesn't explicitly mandate penetration testing, the Security Rule requires covered entities to conduct regular security risk assessments. Penetration testing is widely recognized as a best practice for meeting these requirements and is recommended by HHS OCR. Many healthcare organizations include pentesting as part of their required annual security risk analysis.

    HIPAA penetration testing evaluates the security of systems that store, process, or transmit Protected Health Information (PHI). It tests technical safeguards required by the HIPAA Security Rule, including access controls, encryption, audit controls, and integrity controls to identify vulnerabilities that could lead to PHI breaches.

    Best practice is to conduct penetration testing annually and after significant changes to systems handling PHI. The HIPAA Security Rule requires ongoing risk analysis, making continuous or frequent testing increasingly important as healthcare cyber threats evolve.

    Testing should cover all systems that create, receive, maintain, or transmit electronic PHI (ePHI). This includes EHR systems, patient portals, medical devices, cloud services, internal networks, and any business associate systems with PHI access.

    Yes, penetration testing is crucial for post-breach remediation and can demonstrate to HHS OCR that you've taken corrective action. It helps identify how the breach occurred, validates remediation efforts, and shows ongoing commitment to protecting PHI.

    Traditional HIPAA-mapped penetration tests range from $20,000 to $60,000. StealthNet AI pentests start at $1,500 and hybrid AI plus human engagements start at $5,000. Most healthcare scopes (EHR, patient portal, and supporting infrastructure) land between $5,000 and $10,000 with free retest included.

    HIPAA does not name a frequency explicitly, but HHS OCR enforcement and the Security Rule §164.308(a)(1)(ii)(A) risk analysis requirement effectively make annual penetration testing the floor. Most covered entities and business associates test at least annually and after any material change to ePHI systems.

    A risk assessment is a documentation exercise that identifies threats and vulnerabilities to ePHI. A penetration test actively exploits those vulnerabilities to prove which ones lead to real ePHI exposure. HHS OCR expects both, and pentest results feed directly into your risk assessment evidence.

    Yes. Any vendor that creates, receives, maintains, or transmits ePHI on behalf of a covered entity is contractually obligated under their BAA to implement the HIPAA Security Rule, which makes regular technical evaluations including penetration testing a defensible expectation during covered entity audits.

    HHS OCR has proposed an update to the HIPAA Security Rule that would require automated vulnerability scanning at least every 6 months and penetration testing at least every 12 months, or more often when a risk analysis calls for it. The current Security Rule remains in effect while the rulemaking process continues, so this is a strong signal to prepare now rather than final legal text. StealthNet's annual and continuous AI options are built to satisfy either the existing best-practice expectation or the proposed mandate once it is finalized.

    Some healthcare organizations pursue HITRUST CSF certification alongside HIPAA compliance, especially when customers or payers require it contractually. A HIPAA-mapped pentest and a HITRUST-mapped pentest overlap heavily in scope, so most teams cover both with one engagement rather than two. See our HITRUST penetration testing guide.

    A HIPAA penetration testing checklist covers six areas: the ePHI system inventory (EHR, patient portals, HL7 and FHIR endpoints, medical devices, cloud, internal networks), the §164.308 administrative safeguards your risk analysis and technical evaluation must show, the §164.312 technical safeguards to test (access control, audit controls, integrity, authentication, transmission security), rules of engagement and data handling for testing, the evidence and safeguard-mapped reporting an auditor expects, and the annual pentest plus semi-annual scanning cadence. You can download StealthNet's HIPAA Penetration Testing Checklist from this page.

    StealthNet delivers most HIPAA penetration test reports within 48 hours of the scoping call. The actual testing window depends on the size of the ePHI environment: a single patient portal or business associate SaaS can often be tested and reported in two business days, while a multi-system covered entity with EHR, patient portal, integrations, and internal networks typically spans one to two weeks. Annual retests and continuous AI monitoring run on shorter cycles.

    An audit-ready HIPAA penetration test report includes an executive summary, the scope and rules of engagement, a findings list mapped to HIPAA Security Rule safeguards (§164.312), proof-of-concept exploitation evidence, CVSS severity ratings, remediation guidance, and a letter of attestation suitable for business associate agreements. StealthNet reports also include a free remediation retest section.

    Yes. Most HIPAA penetration tests are performed remotely against internet-facing patient portals, APIs, cloud environments, and business associate platforms. Internal network and medical device segments can be tested remotely through a VPN or with a shipped appliance when the environment is not publicly reachable. All remote testing follows scoped rules of engagement and avoids impact on clinical operations.

    HIPAA penetration testing is scoped specifically to satisfy the HIPAA Security Rule: it maps findings to §164.312 technical safeguards and §164.308(a)(8) technical evaluation requirements. Healthcare penetration testing is a broader industry term that may include FDA device testing, clinical workflow review, or general hospital network testing without the explicit HIPAA mapping. Many engagements are both, but if your auditor or customer asks for HIPAA evidence, make sure the report explicitly references the Security Rule controls.

    No. A penetration test is designed to find issues, so findings are expected. Remediation comes after the report is delivered. StealthNet includes a free retest after you apply fixes, and the final report can be shared with auditors or customers once retest confirms the critical and high findings are closed or accepted with compensating controls.
    What Auditors Expect

    What a HIPAA Auditor Wants to See in Your Pentest Report

    Reports built to satisfy Big Four assessors, QSAs, 3PAOs, and customer security reviews on the first pass.

    Mapping to §164.312 safeguards

    Every finding tagged to Access Controls (a), Audit Controls (b), Integrity (c), Authentication (d), or Transmission Security (e) so it slots directly into your Security Rule evidence binder.

    ePHI exposure proof

    Demonstrated paths to ePHI (not just CVE listings) so HHS OCR sees real risk reduction between annual risk analyses.

    Risk analysis integration

    Findings written in the format §164.308(a)(1)(ii)(A) expects so they drop straight into your Security Risk Analysis update.

    Business associate coverage

    Clear scope statement covering EHR, patient portal, cloud services, and any third-party systems with ePHI access.

    Related Services

    Pentest Services Included in Every Compliance Engagement

    Every compliance pentest pulls from these test-type services as needed. Scope is sized to your environment, not padded with hours.

    Before You Start

    HIPAA Pentest Cost & Compliance Questions

    Traditional HIPAA-mapped penetration tests range from $20,000 to $60,000. StealthNet AI pentests start at $1,500 and hybrid AI plus human engagements start at $5,000. Most healthcare scopes (EHR, patient portal, and supporting infrastructure) land between $5,000 and $10,000 with free retest included.

    Yes. Any vendor that creates, receives, maintains, or transmits ePHI on behalf of a covered entity is contractually obligated under their BAA to implement the HIPAA Security Rule, which makes regular technical evaluations including penetration testing a defensible expectation during covered entity audits.

    HHS OCR has proposed an update to the HIPAA Security Rule that would require automated vulnerability scanning at least every 6 months and penetration testing at least every 12 months, or more often when a risk analysis calls for it. The current Security Rule remains in effect while the rulemaking process continues, so this is a strong signal to prepare now rather than final legal text. StealthNet's annual and continuous AI options are built to satisfy either the existing best-practice expectation or the proposed mandate once it is finalized.
    Get Scoped

    Get Your HIPAA Pentest Scoped in 24 Hours

    Share a few details and we'll follow up within one business day.

    Fixed-fee quote in 24 hours. No credit card. No sales pitch.

    Your details stay private. NDA available on request.

    No commitment. We'll follow up within 1 business day.