Why Are HIPAA Security Rule Updates Strengthening Healthcare Cybersecurity?
In January 2025, the U.S. Department of Health and Human Services (HHS) published a Notice of Proposed Rulemaking (NPRM) to update the Health Insurance Portability and Accountability Act (HIPAA) Security Rule, aiming to strengthen cybersecurity protections for healthcare organizations and safeguard patient data. The comment period closed in March 2025, and the rule remains under review, not yet finalized.
The proposed updates emphasize stronger technical safeguards for electronic protected health information. These changes reflect the evolving threat landscape and the growing need for healthcare organizations to strengthen security programs that protect sensitive patient information, regardless of whether or when the rule is ultimately finalized.
Healthcare remains one of the most targeted sectors for cyberattacks. According to the Ponemon Institute’s 2024 Study on Cyber Insecurity in Healthcare: The Cost and Impact on Patient Safety and Care, more than 90 percent of healthcare organizations report experiencing at least one cyberattack within 12 months.
Healthcare organizations are frequent targets because they store multiple categories of high-value data that attackers can monetize or exploit, including:
- Personal identification information
- Medical records and treatment history
- Insurance and billing data
- Payment and financial information
Because of this concentration of valuable data, healthcare organizations require security programs that continuously validate defenses against real-world attack techniques, whether or not a specific testing cadence is yet a regulatory mandate.
How Would the Proposed HIPAA Security Rule Updates Incorporate Penetration Testing?
As proposed, the HIPAA Security Rule update would introduce penetration testing as a required security validation activity, with organizations expected to test at least once every 12 months, alongside vulnerability scanning at least once every six months. Penetration testing simulates real-world attacks on systems, applications, and infrastructure to identify exploitable weaknesses before adversaries can exploit them.
This remains a proposed requirement rather than a current one. HHS had preliminarily targeted a final rule around May 2026; that date has passed without a final rule, and a January 2025 executive order freezing pending federal agency rulemaking, combined with industry concern over compliance costs, has left the timeline uncertain. No updated HIPAA Security Rule is currently in force.
If finalized as proposed, regular penetration testing would help healthcare organizations:
- Identify vulnerabilities affecting systems that store or process ePHI
- Validate that security controls function correctly under adversarial conditions
- Confirm the effectiveness of access control and encryption safeguards
- Reduce the likelihood of breaches involving patient data
While an annual cadence would establish only a baseline expectation under the proposed rule, many healthcare organizations are already adopting more continuous testing models voluntarily, to keep pace with modern technology environments ahead of any formal requirement.
Why Do Traditional Penetration Testing Models Struggle with Modern Healthcare Environments?
Traditional penetration testing engagements often involve a limited testing window performed by a small team of testers. While these engagements can uncover vulnerabilities, they frequently struggle to keep pace with healthcare organizations’ attack surfaces.
Healthcare technology environments now include:
- Cloud infrastructure and hybrid networks
- SaaS applications and web services
- APIs and digital health platforms
- Connected medical devices and IoT systems
Periodic testing engagements provide only a snapshot of security exposure. Vulnerabilities introduced after testing concludes may remain undetected until the next assessment cycle.
Traditional penetration testing approaches also have several limitations, including:
- Limited testing scope that focuses on selected systems rather than the entire attack surface
- Time-bound assessments that may miss vulnerabilities introduced by new deployments
- Small testing teams that limit the diversity of attack techniques
- Manual testing processes, which can overlook complex vulnerabilities
Because of these limitations, organizations are increasingly evaluating testing models that provide broader visibility and faster feedback.
What Advantages Does Penetration Testing as a Service Provide to Healthcare Organizations?
Penetration testing as a service (PTaaS) offers a more flexible, scalable approach to security testing. PTaaS improves healthcare security validation by combining automated detection with human-led adversarial testing to identify exploitable vulnerabilities.
Unlike traditional testing engagements, PTaaS allows organizations to test environments continuously or on demand. This enables security teams to validate changes to infrastructure, applications, and configurations as they occur.
PTaaS platforms can provide several advantages, including:
- Continuous visibility into changing attack surfaces
- Access to a global pool of specialized security researchers
- Faster identification and remediation of vulnerabilities
- Scalable testing across cloud, hybrid, and distributed environments
For healthcare organizations managing complex digital ecosystems, PTaaS supports more consistent validation of security controls and faster response to emerging risks, whether or not a specific testing cadence is ultimately mandated by regulation.
How Does Penetration Testing Help Healthcare Organizations Meet HIPAA Compliance Requirements?
Penetration testing helps healthcare organizations meet HIPAA requirements by validating that security controls protecting electronic protected health information operate effectively, a role penetration testing plays across compliance frameworks generally, covered in whether penetration testing is required for compliance.
HIPAA’s current Security Rule already requires organizations to perform ongoing risk analysis and evaluation of security safeguards, without specifying a testing frequency. Penetration testing provides objective validation that those safeguards function under real attack conditions, a distinction covered in more depth in the difference between vulnerability scanning and penetration testing for compliance.
Security testing programs support HIPAA compliance by:
- Confirming that access controls prevent unauthorized system access
- Validating network segmentation and boundary protections
- Identifying vulnerabilities that could expose ePHI
- Demonstrating due diligence during regulatory audits
By proactively identifying weaknesses and validating remediation, organizations reduce the likelihood of breaches that could result in regulatory penalties, operational disruption, or loss of patient trust, independent of whether the proposed testing mandate is ultimately finalized.
Why Is Continuous Security Validation Becoming Important for Healthcare Cybersecurity?
Continuous security validation is becoming important because healthcare technology environments change rapidly, introducing vulnerabilities that periodic testing may miss. Synack’s guide on how often penetration testing should be performed for compliance covers how testing cadence decisions apply across compliance frameworks more broadly.
Healthcare organizations are increasingly adopting cloud services, digital health platforms, APIs, and connected medical devices. As infrastructure and applications evolve, new security exposures can emerge between traditional testing cycles.
Continuous security validation helps healthcare organizations:
- Detect vulnerabilities introduced by configuration or infrastructure changes
- Validate that security controls remain effective as systems evolve
- Reduce the time between vulnerability discovery and remediation
- Maintain visibility across expanding attack surfaces
By validating defenses on an ongoing basis, healthcare organizations gain greater assurance that systems protecting electronic protected health information remain secure as technology environments evolve, and as the regulatory landscape around required testing frequency continues to develop.
How Should Healthcare Organizations Choose a Penetration Testing Partner?
The proposed HIPAA Security Rule update highlights the potential need for regular penetration testing to identify vulnerabilities, validate security safeguards, and reduce the risk of ePHI breaches, even while the rule itself remains under review.
The Synack PTaaS platform helps healthcare organizations continuously test systems, identify exploitable vulnerabilities, and validate security controls. Request a demo to see how Synack supports healthcare security testing.


