HIPAA Penetration Testing
Getting a practice ready for HIPAA, or proving an existing one actually holds up? We test the systems that touch patient data, your records system, patient portal, and Microsoft 365 tenant, and hand you a plain-English report, a prioritized fix list, a retest, and a summary letter for your compliance file.
Manual and automated testing. Transparent pricing from $4,000. Retest included.
Get a fair, fixed quote
HIPAA does not require a penetration test by name, and anyone who tells you it does is selling something. What the Security Rule actually requires is a risk analysis and a periodic evaluation of whether your safeguards work, and a penetration test is the strongest evidence you can put behind that evaluation. We wrote up the full honest answer in our guide to whether HIPAA requires a penetration test. Worth knowing too: a proposed update to the Security Rule would make penetration testing at least once every twelve months an explicit requirement. It is a proposal, not a final rule, and it may change, but it shows where the regulators are headed. This page is our HIPAA penetration testing service for practices: what we test, what it costs, and what you walk away with.
What we test
The systems a practice actually runs
A HIPAA penetration test is scoped to where patient data actually lives in your practice, not sold off a shelf. Here is what typically goes in scope, and what the test checks in each.
Your records system
Electronic medical records, practice management, scheduling. Whether it is a big-name cloud product or software built just for you, this is where patient data lives, so it gets tested first: how you sign in, what each role can see, and whether the systems behind it are patched and configured right.
The patient portal
A portal on the internet is not a security problem, it is the point. The question is what a person on that login page can actually do: guess passwords without limit, reset an account they do not own, or read a chart that belongs to someone else. That last one is the finding that matters.
APIs and integrations
Labs, billing, e-prescribing, telehealth, appointment reminders. Modern practices are stitched together with connections between systems, and each one is a place patient data flows. We test whether those connections check who is asking before they answer.
Your Microsoft 365 tenant
Most practices run on Microsoft 365, and a mailbox full of patient conversations is patient data too. We look at multi-factor authentication coverage, sharing settings, and what an attacker with one stolen password could quietly reach.
Network and remote access
The office network, the VPN, staff working from home. Internal testing answers the uncomfortable question: if one workstation is compromised, how far does it reach? A flat network is not a crisis by itself, but it decides the blast radius.
Staging, before go-live
Building or moving to a new records system? We can test it in staging before it ever holds a live patient record. Findings cost the least to fix when there is no patient data behind them and no downtime to schedule.
One thing worth saying plainly: you do not need the biggest test on the menu to satisfy HIPAA. You need a test scoped to your actual environment. A solo practice with a cloud records system and a handful of laptops is a different engagement than a multi-site group, and it should be priced like one.
How it works
From scoping call to compliance file
Most practice engagements run one to two weeks from scoping to report. If a go-live date, an audit, or a partner request is driving the timeline, we plan the whole arc with you: test, fix, retest, letter, with room to spare. Federal guidance for implementing the Security Rule, NIST SP 800-66, points to penetration testing as a way to evaluate whether your safeguards actually work, and that evaluation is exactly what this engagement documents.
- 01
Scope
A short call to map where patient data actually lives: the records system, the portal, the tenant, the network. We agree what is in scope and put it in writing before anything starts. If you are pre-go-live, we scope around staging and the launch date.
- 02
Test
Automated tooling plus real hands-on manual testing. Scanners find the obvious things. A person finds the chain of small things, a role that sees too much, a forgotten account, that actually exposes a chart.
- 03
Report
A clear report in plain English: what we tested, what we found, how serious each item really is, and proof. An executive summary you can read and a technical section your IT person or your developer can act on.
- 04
Fix list
A prioritized, do-this-first remediation list. Your team, your MSP, or your developer makes the fixes; we are happy to walk them through it in plain language. We are an independent second opinion, not a replacement for anyone.
- 05
Retest and letter
We retest the fixed findings, included in every tier, then issue the summary letter for your compliance file: tested, fixed, retested, dated. That is the evaluation evidence HIPAA expects you to be able to show.
What you walk away with
The report stays with you. The letter goes in the compliance file.
This distinction saves practices real grief. The full report is a map of your weaknesses with proof, and you usually should not hand it to anyone outside the practice. What an auditor, a partner, or an insurance carrier gets is the summary letter. We wrote a plain guide to what a penetration test report looks like, section by section, if you want to see what you are buying before you buy it.
The full technical report
Executive summary in plain English, scope and dates, every finding ranked by how exploitable it really is with proof, and a prioritized fix list. Treat it as sensitive; it describes exactly how your practice could be broken into.
The summary letter
A short letter stating a test was performed, when, what was in scope, and the outcome at a high level, including that findings were fixed and retested. This is what goes in the compliance file and what you hand a partner or auditor who asks for proof.
The retest, included
Once the findings are fixed, we check the work and update the record. HIPAA expects you to keep documentation like this for six years, so the file ends up holding the story you want it to hold: tested, fixed, retested, dated.
Pricing
What a HIPAA penetration test costs
There is no special HIPAA price, and you can be suspicious of anyone who has one. The work is penetration testing scoped to your environment. A practice checking its internet-facing exposure, the portal, remote access, email, starts with the Small External test at $4,000. Most practices with an office network choose the Medium Full test, external plus internal, from $6,500, because patient data deserves the from-the-inside check too. The retest is included in every tier, not billed back as an upsell.
We publish our prices, which most firms will not do, so you can budget before the conversation instead of during it. The final number depends on the size of your environment and what is in scope, and the quote is fixed once we agree it.
Being offered a scan with HIPAA on the cover?
The cheapest "HIPAA penetration test" on the market is often an automated scan with a compliance logo on the report. A scan lists known weaknesses. A person confirms what is actually exploitable and how the pieces chain together. For the evaluation HIPAA expects, that difference matters, and it is worth five minutes to understand.
Penetration test vs vulnerability scanFAQ
HIPAA penetration testing: common questions
- Does HIPAA require a penetration test?
- Not by name. The Security Rule requires a risk analysis and a periodic evaluation of whether your safeguards actually work, and a penetration test is one of the strongest ways to evidence that evaluation. A proposed update to the rule would make annual testing explicit, but it is not final.
- What systems should a medical practice have tested?
- The systems that touch patient data: your records system, the patient portal, the connections to labs and billing, your Microsoft 365 tenant, and the office network with its remote access. The test is scoped to where your data actually lives, so a small cloud-based practice needs less than a multi-site group.
- Can you test a new records system before it goes live?
- Yes, and it is the best time to do it. We test the staging environment before it ever holds a live patient record, so findings get fixed with no patient data behind them and no downtime to schedule. This is common for practices building custom software or migrating systems.
- Is a vulnerability scan enough for HIPAA?
- A scan helps, but it is not the same thing. A scan lists known weaknesses automatically. A penetration test has a person confirm what is actually exploitable and how the pieces chain together. For the evaluation HIPAA expects you to perform, the hands-on test is far more convincing evidence.
- What do I actually put in the compliance file?
- The summary letter, which states what was tested, when, and that findings were fixed and retested. The full technical report stays inside the practice; it is a map of your weaknesses and should be treated as sensitive. Partners and auditors get the letter or the executive summary, not the map.
- What does a HIPAA penetration test cost?
- There is no special HIPAA price; the work is penetration testing scoped to your environment. External testing starts at $4,000, and a full external-plus-internal test starts at $6,500, with a retest of fixed findings included in every tier. The final number depends on the size of your setup.
Know where your practice stands before someone asks for proof
Tell us a little about your practice, what records system you run, and what is prompting the test: a go-live date, a partner or auditor asking, an insurance renewal, or just wanting to know. We will come back with a scope, a timeline, and a fair, fixed quote. No pressure, no scare tactics.