What the Security Rule actually says
§164.308(a)(1)(ii)(A) requires an accurate and thorough risk analysis of the risks to electronic protected health information. §164.308(a)(8) requires a "periodic technical and nontechnical evaluation" of how well your safeguards meet the rule. The Office for Civil Rights treats technical testing of your internet-facing and internal systems as part of that evaluation. HIPAA is the least prescriptive framework about frequency and method, which means the burden is on you to show you did something real, documented it, and acted on it.
What a defensible HIPAA test shows
- The systems that store, process, or transmit ePHI were in scope
- Findings rated by severity, with dates
- Remediation and retesting of anything that could expose ePHI
- An annual cadence, or after major changes to systems
Getting it done this week
Automated external penetration testing from Clone Systems covers your internet-facing systems: patient portals, telehealth endpoints, web applications, remote access. From $1,995 for one asset. Internal penetration testing, from $2,995 for 25 hosts, covers the network where ePHI lives. Authenticated web application scanning, from $5,995 a year for 10 applications, tests behind the login where patient data is handled. Managed penetration testing by our engineers is available when a human-led engagement is required.
Why Clone Systems
Clone Systems has served healthcare organizations for over two decades and has been a PCI Approved Scanning Vendor since 2007. Published prices, buy online, results in days.
Buy a pen test and start today · Request managed pen test scoping
Related
- A real penetration test used to cost $10,000
- Penetration testing for SOC 2
- Penetration testing for ISO 27001
- Penetration testing for PCI DSS Requirement 11.4
Clone Systems is a PCI Security Standards Council Approved Scanning Vendor, listed since 2007. This page is general guidance, not legal or audit advice.
