Admittedly, HIPAA vulnerability scan requirements are not yet a thing.

Practical guidance for healthcare teams and business associates

HIPAA Vulnerability Scanning Requirements are, admittedly, not yet a thing. That is, as of today’s writing (8/22/2026) at least. Industry rumblings (HHS has already delayed its decision once) are pointing towards mid-July 2027 for a possible final rule that would allegedly require the following going forward: * Annual Penetration Testing * Vulnerability Scans Every Six Months * Enacting Multi-Factor Authentication (MFA) for any device touching electronic protected health information (ePHI)

HIPAA Vulnerability Scanning Every Six Months

Timeline graphic: HIPAA vulnerability scanning every six months under the proposed Security Rule

If the rule is finalized as written, proposed 45 CFR §164.312(h)(2)(i) and (iii) breaks from the past. Until now, timing was left open to a point. The language for ongoing risk assessment says it should be done periodically. Once this rule is final, there is nothing left to read into. The government is telling you point blank: run automated scans at least once every six months (or more often if your risk analysis says so), or you are not compliant with HIPAA.

What Systems Should a Healthcare Organization Test?

Testing should cover the electronic systems that create, receive, store or send ePHI. It also includes systems that could affect the confidentiality, integrity or availability of that data.

For a small healthcare practice, that may include:

  • Public IP addresses, domains, patient portals and VPNs
  • Servers, workstations and laptops
  • Firewalls, routers, switches and wireless networks
  • Electronic health record (EHR) systems and connected apps
  • Microsoft 365 or Google Workspace
  • Cloud storage, backups and remote-access systems
  • Medical, mobile and Internet of Things devices connected to the network
  • Links between the practice and labs, pharmacies, billing companies and other vendors

The scope will differ for every practice. Never test a vendor’s systems without written permission. Test your own settings and connections instead, and ask the vendor for proof of its own security.

The proposed Security Rule uses the term “relevant electronic information systems.” That makes an accurate technology inventory the starting point.

What Reports and Documentation Should the Organization Retain?

There is no single government-issued report format for a pen test. Your records should show what was tested, how it was tested, what was found and what you did about it.

The evidence package should include:

  • Date of each scan or penetration test
  • Names and credentials of the people doing the work
  • Authorized scope and systems tested
  • Testing methods and tools used
  • Original scanner-generated reports
  • The flaws found, with severity ratings
  • CVE (Common Vulnerabilities and Exposures) identifiers and CVSS (Common Vulnerability Scoring System) severity scores when they apply
  • Proof backing the major findings
  • Plain-English explanation of business and patient-data risks
  • Suggested fixes
  • Records showing whether each finding was fixed, accepted or handled some other way
  • Retest results
  • Testing limits and systems left out of scope

Keep the original technical report next to a short summary that management can understand. Keep ePHI out of reports whenever possible. Store them securely, because they reveal a lot about your defenses.

HIPAA generally requires you to keep this kind of record for six years (45 CFR §164.316(b)(2)(i)). These reports can also support risk assessments, insurance forms, customer security reviews and answers to government inquiries.

What Is the Difference Between a Vulnerability Scan and a Penetration Test?

A vulnerability scan is an automated check. It searches systems for known weak points, outdated software, exposed services and unsafe settings. It can cover many systems fast and should be run on a regular basis. But scanners can cry wolf, and they cannot tell how several flaws might be chained in a real attack.

A penetration test goes further. A qualified person uses controlled attack methods to find out whether those weak points can really be exploited, and how far an attacker could get.

In simple terms:

  • A vulnerability scan identifies doors that might be unlocked.
  • A penetration test carefully checks whether those doors can be opened and what can be reached behind them.

One does not replace the other. Scans give broad, repeatable coverage. A pen test adds deeper human review. NIST treats scanning as a way to find possible weak points, and pen testing as a way to prove whether defenses can be beaten. NIST SP 800-115

How Can a Small Practice Prepare Without Wasting Money?

A small practice does not need to buy a costly pen test just because HHS has proposed a future rule. The proposal is not final, and its terms or timeline could still change.

A practical preparation plan is:

  1. Create an inventory of systems, devices, apps and vendors that touch ePHI.
  2. Ask your IT provider whether scanning is already part of its services.
  3. Confirm that software updates and key security patches are being installed.
  4. Turn on MFA and remove unused accounts.
  5. Review public-facing systems, remote access and firewall settings.
  6. Keep all existing security reports, fix logs and IT records.
  7. Use the findings from the Security Risk Assessment to see which systems carry the most risk.
  8. Get a clearly defined scope before paying for any commercial testing.

CISA also gives eligible groups free external scans and web-app scans. These can help find weak points in internet-facing systems, though they do not replace a full internal review or pen test. CISA Cyber Hygiene Services

The goal is not to buy the biggest test. It is to test the right systems, keep solid proof and fix the flaws that could put ePHI at risk.

Frequently Asked Questions

Frequently asked questions about HIPAA vulnerability scanning requirements

Does HIPAA currently require vulnerability scanning?

The current HIPAA Security Rule does not spell out a scan every six months. It does require covered entities and business associates to find and address risks to ePHI. HHS has proposed making automated scans an explicit rule.

How often would vulnerability scans be required under the proposed rule?

The proposed rule would require automated scans at least once every six months. You would need to scan more often if your Security Risk Analysis calls for more testing.

How often would penetration testing be required?

The proposed rule would require a pen test at least once every 12 months, or more often when your Security Risk Analysis requires it.

Who would be allowed to perform the penetration test?

The proposed rule says a qualified person with the right cybersecurity knowledge and experience must perform the pen test. It does not require a specific certification, degree or license.

What is the difference between a vulnerability scan and a penetration test?

A vulnerability scan automatically searches systems for known weak points, outdated software and unsafe settings. A penetration test uses controlled attack methods to prove whether those weak points can really be exploited. The proposed rule would require both because they do different jobs.

HHS delays decision on final rule What is e-PHI? MFA Guidance How to Conduct a HIPAA Risk Assessment OCR Audit Program: Healthcare Survival Guide

Sources

  1. HHS, HIPAA Security Rule NPRM: Cybersecurity of Electronic Protected Health Information (Federal Register, Jan 6, 2025)
  2. HHS, Guidance on Risk Analysis Requirements under the HIPAA Security Rule
  3. 45 CFR §164.316, Policies and procedures and documentation requirements (eCFR)
  4. NIST SP 800-115, Technical Guide to Information Security Testing and Assessment
  5. CISA Cyber Hygiene Services

One Guy Consulting offers affordable HIPAA compliance packages for practices of all sizes.

This content is for educational and informational purposes only and should not be construed as legal advice.