Skip to content
Selva Ops

Compliance

HIPAA Security Rule and Penetration Testing

Published

Selva Ops S.R.L.

The HIPAA Security Rule (45 CFR Parts 160 and 164 Subpart C) requires administrative, physical, and technical safeguards to protect electronic protected health information (ePHI). It is intentionally technology-neutral.

Risk analysis first

Penetration testing is most defensible when it answers risks identified in your Security Rule risk analysis — not when it is purchased as a checkbox detached from that analysis. NIST’s SP 800-66 Rev. 2 remains a primary implementation resource for mapping Security Rule standards to cybersecurity practice.

Evaluation and technical safeguards

Expect HIPAA-minded buyers and assessors to ask how you evaluate technical controls over time. Authenticated testing of patient portals, APIs, and mobile apps that handle ePHI is a common way to produce that evidence — without claiming the Rule “requires an annual pentest” by name.

Business associate agreements

See web application, API, and mobile testing when those systems process ePHI.

Related services

FAQ

Does the HIPAA Security Rule mandate penetration testing?
The Security Rule does not use the words “penetration test” as a required specification. It does require risk analysis and risk management, and technical evaluation activities that organizations commonly evidence with vulnerability assessment and penetration testing.
Who needs this — covered entities or business associates?
Both covered entities and business associates that create, receive, maintain, or transmit ePHI must comply with the Security Rule. BAAs often add contractual testing expectations on top of the regulation.

See what the deliverable looks like

Review a sanitized sample report before you talk to anyone — findings structure, severity model, and remediation detail.

Get the sample report