All posts
Compliance·May 22, 2026·6 min

HIPAA and penetration testing: required, recommended, or neither?

HIPAA and penetration testing: required, recommended, or neither?

If you handle electronic protected health information, you have probably been told both that HIPAA requires a penetration test and that it does not. Both camps are half right, and the nuance matters because the wrong reading either leaves you exposed or has you buying the wrong thing. Here is the accurate version.

What HIPAA literally says

The HIPAA Security Rule never uses the phrase penetration testing. Two of its requirements, however, point straight at it. The risk analysis requirement (45 CFR 164.308(a)(1)(ii)(A)) obliges you to assess the risks and vulnerabilities to all ePHI you create, receive, maintain, or transmit. And the evaluation standard (164.308(a)(8)) requires periodic technical and nontechnical evaluation of how well your safeguards actually work. Neither names a method. Both describe what a penetration test does.

So is it required?

Strictly, no method is mandated, so a pentest is not a literal HIPAA requirement. Practically, it is the most direct evidence you can produce that you have done the technical evaluation the rule demands. You can attempt to satisfy the evaluation standard with lighter measures, but if a breach occurs and the Office for Civil Rights asks how you verified your safeguards held, "we ran a real test and fixed what it found" is a far stronger answer than "we reviewed our configurations."

HIPAA does not tell you to run a pentest. It tells you to prove your safeguards work, which is a question a pentest is built to answer.

The scope detail people miss

The risk analysis must cover all ePHI, everywhere it lives: production, but also development and test systems if they use real data, mobile and remote environments, and data held by business associates. A test scoped only to your main production app leaves exactly the gaps that turn into reportable breaches. Scope to where the data actually is, not where it is convenient to look.

The direction of travel

Proposed updates to the Security Rule lean toward making technical testing more explicit, not less. Treating a real penetration test as part of your HIPAA program now is both defensible today and ahead of where the rule is heading. The downside of doing it is a cost; the downside of skipping it is discovering your safeguards did not hold from a breach notification instead of a report.

Uvy gives healthcare teams exactly that evidence: a real test that proves which weaknesses in your ePHI-handling systems are actually exploitable, with a retest to confirm the serious ones are closed. See how it works.

Find every way in, before an attacker does

Uvy runs continuous offense and defense across your applications, agents, and embodied AI, at machine speed, and hands your team proof and the exact fix. Start with an application pentest, or talk to sales to cover the rest.

Free to test. No card to start.

Or write to [email protected]