HIPAA penetration testing

Pen testing of the systems that create, receive, store, or transmit ePHI, documented to support your Security Rule evaluation and risk analysis.

Last reviewed October 2026

Does HIPAA require penetration testing?

The current HIPAA Security Rule doesn’t name penetration testing. It requires a periodic technical and nontechnical evaluation of your safeguards (45 CFR 164.308(a)(8)) and an accurate and thorough risk analysis (45 CFR 164.308(a)(1)(ii)(A)). A pen test of the systems that hold ePHI can support both.

What reviewers will want to see

  • Which systems create, receive, store, or transmit ePHI, and whether they were tested
  • Testing dates and methodology
  • Findings ranked by risk, with fixes
  • Evidence that fixes were retested

Reports document the scope, methodology, and dates that assessors typically look for.

Fitting the test into your risk analysis

  1. Map the systems that hold ePHI, and the systems that can reach them, on a free scoping call. You get a fixed-fee proposal and rules of engagement to sign.
  2. Testing can usually start within 5 business days of signing.
  3. Testing, typically 1 to 3 weeks. Critical findings are reported within 24 hours of confirmation, not held for the report.
  4. Final report delivered within 5 business days after testing ends. We walk your team through the findings on a call.
  5. Fix, then retest. One retest of reported findings within 90 days of the final report, included in the price, with an updated report and attestation letter. Then update your risk analysis with what the test found.

Start dates are agreed during scoping, so tell us your deadline when you ask for a quote.

What it costs

  • Web application, including its own APIFrom $5,000 per application
  • External networkFrom $5,000
  • Internal network and Active DirectoryFrom $15,000 per network
  • Cloud environmentFrom $10,000 per environment

Starting prices in US dollars for the smallest scope of each service, reviewed October 2026. Your price is a fixed fee, set in a written proposal after a free scoping call.

All testing is performed by HackNow’s own US-based testers. We never pass your test to another firm.

See starting prices for every service

What you get for your HIPAA records

  • A full report: scope, dates, methodology, and findings ranked by risk, with evidence and fixes
  • An attestation letter with the test dates, scope, method, and results, to share with customers and partners who ask
  • A retest report and an updated letter once you’ve fixed the findings
  • A walkthrough call with your team after the report

See an example report and attestation letter

What a pen test adds to a scan

A risk analysis looks at the potential risks and vulnerabilities to ePHI. A scan lists known issues. A pen test shows which of them an attacker could actually use, and how they combine. NIST SP 800-115 notes most penetration tests seek combinations of vulnerabilities granting more access than any single flaw, and manual analysis can identify new or obscure vulnerabilities scanners may miss.[1]

Questions about HIPAA pen testing

Which systems are in scope?

Any system that creates, receives, stores, or transmits ePHI, plus the systems that can reach them, such as your identity provider and admin tools. We map them with you on the scoping call.

How do you handle ePHI during testing?

We access ePHI only as far as needed to prove impact, and handle evidence under the confidentiality and retention terms in our contract.

How often should we test?

The Security Rule calls for a periodic evaluation, and another when environmental or operational changes affect the security of ePHI. Test on the schedule your risk analysis sets, and after significant changes to the systems that hold ePHI.

Can we share the results with our customers?

Yes. Share the attestation letter with the customers and partners who ask, and keep the full technical report for your team or share it under NDA.

Will you sign a business associate agreement?

Yes. We sign a business associate agreement (BAA) when you need one.

Tell us what you need tested.

We reply to every request within one business day. Every engagement is a fixed fee after a free scoping call.