HIPAA penetration testing: what the Security Rule requires, and what is still only proposed

Threat emulation schedule with dates, sources, statuses, and a vulnerabilities list with severity and fix status.

The HIPAA Security Rule does not currently require penetration testing. It requires a periodic technical and nontechnical evaluation of your safeguards. A 12-month penetration testing requirement has been formally proposed, but as of 29 July 2026 it has not been finalised and is not in force. That distinction matters, because a great deal of published guidance states the opposite.

Is it safe to skip penetration testing for HIPAA?

Penetration testing is never named. The Evaluation standard obliges covered entities and business associates to perform a periodic technical and nontechnical evaluation establishing the extent to which their security policies and procedures meet the Rule's requirements. It is technology-neutral by design.

"Periodic" is not defined as annual. No interval appears anywhere in the text of the standard, which is why the widely repeated "HIPAA requires an annual pentest" does not survive contact with the regulation itself.

Change is an explicit trigger. An evaluation is expected in response to environmental or operational changes affecting the security of electronic protected health information, not only on a calendar. That is the clause most often skipped, and the one that most resembles how modern environments actually behave.

User interface with sections titled 'Strikers assigned' showing two profile pictures and their details, and an 'Export' panel with options to include Findings Summary, Assessment Updates, and Compliance Checklist, with a Download button.

Healthcare penetration testing: why regulated teams test anyway

Not named is not the same as not expected. The Evaluation standard is technology-neutral, so an assessor asks how you satisfied it. A penetration test is the most legible evidence that a technical evaluation actually took place, which is why it supports HIPAA programs even though the Rule never names it.

The proposed rule is a signal, not an obligation. An explicit 12-month penetration testing standard was proposed in January 2025 and has not been finalised. Teams building the capability now are not complying early; they are avoiding a compressed deadline later.

The change trigger is the stronger argument. Electronic protected health information moves through systems that ship weekly, and an evaluation is expected in response to operational change. Continuous Threat Emulation fits that clause more closely than a single engagement a year, and Strike supports audit and compliance programs with reporting aligned to HIPAA, ISO 27001, SOC 2 and PCI DSS.

Source: HHS, HIPAA Security Rule notice of proposed rulemaking, Federal Register, 6 January 2025 — accessed 29 July 2026, still at proposed-rule stage.

Our solution architecture

A centralized platform that combines continuous asset monitoring, autonomous threat emulation, and expert remediation support—powered by AI agents, human validation, and a dedicated governance team.

ALWAYS-ON PLATFORM

How Strike produces the evidence a HIPAA evaluation needs

Evaluation is only useful if it is current and evidenced. Strike runs continuous hybrid validation against an authorised scope, with expert human validation before customer delivery, so the record accumulates with dates and assets attached rather than arriving once a year.

In-depth continuous testing

Strikers uncover high-impact vulnerabilities across multi-technology environments (web apps, APIs, mobile, cloud, and more).

AI-led retesting on-demand

Validate fixes without waiting for the next testing cycle. Retesting availability depends on the subscribed scope.

Real-time fixing

coming soon

AI agents guide your team step-by-step through remediation to accelerate resolution.

Step-by-step Threat emulation creation

Easily scope, launch, and track your Threat emulation with full transparency.

Human triaging & peer review

Expert human validation before customer delivery, for accuracy and impact.

Full visibility

Track every finding with complete transparency through security expert work logs and real-time notifications.

Seamless integrations

Connect directly with Slack, Teams and Jira to streamline collaboration with your security and development teams.

Vulnerability Manager

Visualize, manage, and retest vulnerabilities in one platform, with full context on severity, sources, and remediation.

Reporting that supports audit and compliance programs

Generate up-to-date reports with evidence per finding to support your PCI DSS, HIPAA, ISO 27001 and SOC 2 programs. Strike does not issue SOC 2 reports, ISO certificates or PCI DSS attestations.

Ongoing partnership

Weekly check-ins with a dedicated Customer Success Manager, plus personalized onboarding and strategic planning.

An annual test describes a system as it existed on one day. The Rule's own language, evaluation in response to operational change, sits uncomfortably with a once-a-year engagement.

Boost your experience with Hybrid Testing Booster

Continuous Hybrid Testing

Emulated, deep stealth-based attacks executed by creative, unconventional security experts. Find out how real attackers would breach your systems, and stop them before they do.

Human expertise.
AI power.
Superior security.

Whether you’re scaling fast, closing enterprise deals, or just tired of noisy reports, we’ll help you build a security stack that moves faster than your threats.

Book a Demo