Between 2018 and 2023, the number of breaches of unsecured protected health information reported to the U.S. Department of Health and Human Services rose 100 percent, and the number of individuals affected by those breaches rose 950 percent. Reported hacking rose 260 percent and ransomware 264 percent over the same window, and in 2023 more than 160 million individuals were affected by breaches involving the PHI of 500 or more people, a record at the time the Department wrote it down. Those figures are the Department's own, published inside the HIPAA Security Rule proposed rule at 90 FR 898. They are also the reason a healthcare penetration test is now a board conversation rather than a line item.
What that test has to satisfy is more specific, and more misunderstood, than the vendor marketing suggests. HIPAA does not require penetration testing today. HITRUST publishes no cadence. The FDA does name penetration testing, and names exactly what the report must contain. The ranking below is built around those three realities, and every vendor entry links to the page on the vendor's own site that supports the claim, last verified on 5 September 2026.
Quick answer: who are the best healthcare penetration testing companies in 2026?
The best healthcare penetration testing companies in 2026 are Stingrai, Coalfire, NetSPI, Clearwater, Praetorian, Meditology Services, BreachLock, Fortified Health Security, TrustedSec and Schellman. Stingrai ranks first because the bug classes that put one patient's chart on another patient's screen are broken authorization, insecure direct object reference and business logic flaws, and Snipe, Stingrai's autonomous AI agent for web application penetration testing, is purpose-built to hunt exactly those classes while certified penetration testers work concurrently on the same engagement. Coalfire, NetSPI and Clearwater follow for assessor-adjacent healthcare programmes, medical device and connected hardware depth, and healthcare-exclusive coverage respectively.

What healthcare buyers are actually required to test
Three regimes get cited in healthcare procurement, and they say three very different things. Getting this wrong is expensive in both directions: buying a test that no rule required, or presenting a report that the rule that does apply will not accept.
Does HIPAA require penetration testing?
No. The HIPAA Security Rule at 45 CFR Part 164 Subpart C does not use the phrase. What it requires is a risk analysis at 45 CFR 164.308(a)(1)(ii)(A), a periodic technical and nontechnical evaluation at 45 CFR 164.308(a)(8), and maintenance of security measures at 45 CFR 164.306(e). The federal implementation guide, NIST SP 800-66r2, places penetration testing inside those standards as an activity to conduct if reasonable and appropriate.
The rule that would change this is a proposal, not law. The Office for Civil Rights published the HIPAA Security Rule proposed rule at 90 FR 898 on 6 January 2025 under RIN 0945-AA22, with comments closing 7 March 2025. Proposed 45 CFR 164.312(h)(2)(iii) would require a regulated entity to "Perform penetration testing of the covered entity's or business associate's relevant electronic information systems by a qualified person," and states that "Penetration testing must be performed at least once every 12 months or in accordance with the covered entity's or business associate's risk analysis required by Sec. 164.308(a)(2), whichever is more frequent." A qualified person is defined in the proposal as a person with appropriate knowledge of and experience with generally accepted cybersecurity principles and methods.
As of 5 September 2026 there is no final rule. The Federal Register lists exactly one document under RIN 0945-AA22: the proposal itself. A deeper clause-by-clause treatment is in the HIPAA penetration testing requirements guide.
Does HITRUST require penetration testing every 12 months?
HITRUST publishes no penetration testing frequency. The CSF requirement statements are licensed content inside MyCSF, so no public HITRUST page states a cadence, and an article that quotes one without linking a HITRUST document is quoting itself. What HITRUST does publish is the machinery around the test. The HITRUST Assessment Handbook version 1.2 sets a 90-day control incubation period before a control can be tested as implemented, a maximum 90-day fieldwork window, and independence rules that expressly permit assessor personnel to perform penetration testing for an assessed entity so long as they do not also remediate.
That independence carve-out is a real procurement lever. It means an external assessor firm can legitimately sell you both the assessment and the test, which is why several assessor-first firms appear in this ranking. It also means you should ask what the firm does when its own test finds something its own assessment signed off on. The full treatment is in the HITRUST penetration testing requirements guide.
What does the FDA require for medical device penetration testing?
This is the healthcare regime that names penetration testing outright. Under section 524B of the Federal Food, Drug, and Cosmetic Act, a person submitting a 510(k), PMA, PDP, De Novo or HDE for a device meeting the statutory definition of a cyber device must submit information to ensure the device meets the cybersecurity requirements of section 524B(b). Section 524B(c) defines a cyber device as one that includes software validated, installed or authorized by the sponsor, has the ability to connect to the internet, and contains technological characteristics that could be vulnerable to cybersecurity threats.
FDA's operative guidance is Cybersecurity in Medical Devices: Quality Management System Considerations and Content of Premarket Submissions, issued 3 February 2026, which supersedes the guidance issued 27 June 2025 (docket FDA-2021-D-1158). It lists penetration testing alongside vulnerability testing as security testing that should be documented, and it specifies what the report must contain:
Penetration test reports should be provided and include the following elements: Independence and technical expertise of testers; Scope of testing; Duration of testing; Testing methods employed; and Test results, findings, and observations.
The guidance also asks manufacturers to state by whom the testing was performed, for example independent internal testers or external testers, and what level of independence those testers have from the developers who designed the device, noting that in some cases third parties may be necessary to achieve that independence. That single paragraph is why a device manufacturer's penetration testing vendor choice is a regulatory decision, not just a security one.
Regime | Is penetration testing required? | Named cadence | What the evidence has to look like |
|---|---|---|---|
HIPAA Security Rule (current) | Not by name. Risk analysis, periodic evaluation and maintenance are the operative standards | None published | A risk analysis that is evidenced, and an evaluation that was actually performed |
HIPAA proposed rule, 90 FR 898 | Would be, at proposed 45 CFR 164.312(h)(2)(iii). Not final as of 5 September 2026 | At least once every 12 months, or per the risk analysis, whichever is more frequent | Testing by a qualified person as defined in the proposal |
HITRUST | Requirement statements are licensed and not public. No public cadence | None published | Control tested as implemented after a 90-day incubation period, inside a 90-day fieldwork window |
FDA section 524B and February 2026 guidance | Yes, as premarket documentation for cyber devices | Tied to the submission, not to a calendar | A penetration test report carrying tester independence, expertise, scope, duration, methods and results |
How we ranked them
Ten vendors were scored against six healthcare-specific criteria. Every claim below traces to a page the vendor publishes itself.
Published healthcare or medical device practice. A page on the vendor's own site that describes healthcare, HIPAA, HITRUST or medical device testing. Firms that merely list healthcare as a logo were scored down.
Authorization and business logic depth. Multi-tenant isolation, role separation between clinician, patient and administrator, and object-level authorization on record-scoped endpoints. In a health record system these are the classes that leak charts.
Regulatory evidence quality. Whether the report is shaped like something an OCR investigator, a HITRUST assessor or an FDA reviewer will accept, including tester independence and reproduction steps.
Medical device and connected estate capability. Firmware, wireless, companion mobile applications and the cloud backend, tested together rather than separately.
Manual depth relative to automation. Manual verification of findings, not scanner output rewritten as narrative.
Delivery model fit. Whether the vendor supports both a one-time annual test and a continuous programme, and whether findings reach engineers through their tracker rather than a static PDF.
Vendors whose product is regulatory documentation, attack surface discovery or compliance attestation without offensive testing were not ranked as healthcare penetration testing providers, even where they are strong in their own category. Two examples are noted after the ranking.
Quick comparison: best healthcare penetration testing companies
Company | Healthcare positioning | Best for | Source page, verified 5 September 2026 |
|---|---|---|---|
1. Stingrai | AI-augmented penetration testing whose agent hunts broken authorization, IDOR and business logic flaws, with certified penetration testers working concurrently | Health record systems, patient portals, payer and provider APIs and healthtech SaaS, as a one-time annual test or a continuous programme | |
2. Coalfire | Healthcare industry practice combining HIPAA-oriented testing with HITRUST advisory services | Health systems running an assessment-led programme where the assessor relationship drives procurement | |
3. NetSPI | Dedicated medical device penetration testing covering firmware, hardware, wireless, thick client and mobile, mapped to FDA premarket expectations | Device manufacturers assembling section 524B premarket evidence | |
4. Clearwater | Healthcare-exclusive firm offering penetration testing alongside HIPAA risk analysis and HITRUST services | Providers and payers that want the risk analysis and the test from one healthcare-only firm | |
5. Praetorian | Healthcare attack surface management with continuous penetration testing and red teaming, explicitly citing HIPAA, HITRUST and FDA regulation and IoMT exposure | Large connected estates where discovery of unknown assets is the first problem | |
6. Meditology Services | Healthcare-exclusive consultancy with technical testing, HITRUST certification services and a medical device and IoT security practice | Providers, payers and suppliers buying HITRUST certification and testing together | |
7. BreachLock | Dedicated HIPAA penetration testing page citing the evaluation standard at 164.308(a)(8) and NIST SP 800-66 | Healthtech teams that want a fast, framework-mapped, audit-ready report | |
8. Fortified Health Security | Healthcare-exclusive managed security provider whose advisory line includes penetration testing and red team, with managed connected medical device security | Hospitals and health systems that want testing inside a managed security relationship | |
9. TrustedSec | Manual penetration testing practice that names HIPAA among the compliance drivers it supports | Buyers who want deep manual and adversarial testing and are willing to scope the healthcare context themselves | |
10. Schellman | Broad penetration testing portfolio, including hardware and IoT, alongside a separate HITRUST certification practice | Organisations already using the firm for certification work who want testing under one contract |
1. Stingrai (top rated for healthcare)
Stingrai is a Toronto-headquartered offensive security firm founded in 2021, with a London office covering EMEA. Stingrai Inc holds a firm-level CREST accreditation as a Penetration Testing service provider, distinct from the individual CREST CRT certifications its testers hold. The team carries OSCE3, OSCP, OSWE, OSED, OSEP, CREST CRT, CISSP, CRTO, GCPN, CRTE and eWPTX, has published 18 CVEs (Ivan Spiridonov 10, Moaaz Taha 5, Victor Villar 3), presents original research at DEFCON and BSIDES, and holds 5.0/5.0 across 19 [Clutch](https://clutch.co/profile/stingrai) reviews.
At a glance
Signal | Detail |
|---|---|
Headquarters | Toronto, Canada, plus a London, UK office |
Founded | 2021 |
Accreditation | CREST-accredited Penetration Testing service provider at the firm level |
Certifications | OSCE3, OSCP, OSWE, OSED, OSEP, CREST CRT, CISSP, CRTO, GCPN, CRTE, eWPTX |
Research output | 18 published CVEs, DEFCON and BSIDES talks |
Reputation | 5.0/5.0 across 19 Clutch reviews |
Methodology | Manual-first, with the Snipe AI agent running concurrently. Annual one-time penetration tests and continuous PTaaS |
Integrations | Jira, GitHub, Slack |
Compliance support | Penetration testing evidence supporting HIPAA, HITRUST, SOC 2, ISO 27001, PCI DSS 4.0, NIST SP 800-53 and 800-171, DORA and NIS2 programmes |
Why Stingrai ranks first for healthcare
The agent hunts the classes that leak charts. Snipe is Stingrai's autonomous AI agent for web application penetration testing, built for IDOR, broken authorization and access control, and business logic flaws rather than known-class bugs alone. It is custom-trained on more than 6,000 HackerOne Hacktivity disclosure reports plus skills distilled from years of Stingrai's penetration testing methodology. In a patient portal, a payer member portal or an electronic health record integration, the difference between reading your own record and reading everyone's is an object-level authorization check, not a scanner signature.
Certified penetration testers work concurrently, not afterwards. Stingrai's certified penetration testers are fully part of the engagement, testing at the same time as Snipe and directing it where the clinical or administrative workflow makes a chain plausible. Both contribute findings across all severities.
White-box source review and pipeline gating. Snipe performs black-box dynamic testing and white-box review of application source, opens AutoFix pull requests, and can run as a PR-gating check on every pull request. For a healthtech team shipping weekly against an annual assessment cycle, that closes the window between a broken access-control change and the next scheduled test.
Report shape that survives scrutiny. Findings are manually verified with reproduction steps before they reach a report, and remediation retests are included. That is the shape the FDA guidance asks for in a premarket penetration test report, and the shape an OCR investigator or HITRUST assessor expects to see behind a control claim.
Compliance-supporting evidence. Stingrai's penetration testing supports your HIPAA, HITRUST, SOC 2, ISO 27001 and PCI DSS programmes by producing the offensive-testing evidence those programmes consume.
Published pricing. Package pricing is listed openly on the pricing page rather than sitting behind a sales gate.
Pros
Manual validation on every finding, so reports do not ship unverified scanner output.
Remediation retests included in engagements.
Transparent published package pricing, with a No High or Critical Finding, Don't Pay guarantee on the Autonomous tier.
Findings push into Jira, GitHub and Slack rather than arriving only as a static PDF.
Both delivery models supported: a one-time annual test for the assessment cycle, and continuous testing for teams shipping weekly.
Cons
Web application, API and network scope rather than firmware bench work, so a device manufacturer testing an implantable or a bedside monitor at the hardware layer should scope that component with a hardware specialist.
A newer brand than the assessor-first firms, so it suits buyers who weigh technical depth over an existing audit relationship.
Best for: health record systems, patient and member portals, payer and provider APIs and healthtech SaaS, in both one-time annual and continuous testing models, where broken authorization and business logic are the risks that matter.
Start your healthcare penetration test: Get a Quote | Book a Free Scoping Call | See PTaaS
2. Coalfire
Coalfire publishes a healthcare industry page that pairs penetration testing framed around HIPAA with HITRUST advisory services, alongside cyber risk assessment and cloud system evaluation. The same page describes CMMC advisory and assessment work delivered as an experienced C3PAO, which signals the firm's centre of gravity: assessment-led programmes where technical testing sits inside a larger compliance engagement.
Pros
One firm for the HITRUST advisory track and the technical testing, which the HITRUST Assessment Handbook's independence rules permit so long as the same personnel do not also remediate.
Healthcare framing is explicit on the vendor's own page rather than inferred from a logo wall.
Breadth across cloud, application and network testing for multi-entity health systems.
Cons
Assessment-led procurement can mean the technical test is scoped to the framework rather than to the application's real attack surface.
The published healthcare page is service-level rather than methodology-level, so ask for the testing methodology in writing during scoping.
Best for: health systems and payers whose penetration testing budget already sits inside an assessment or advisory relationship.
3. NetSPI
NetSPI publishes a dedicated medical device penetration testing page describing threat modelling combined with penetration testing across firmware analysis, hardware survey, wireless configuration, network analysis, thick client and mobile applications, sensor data, privacy and tracking concerns and potential patient safety issues. The page states the goal as identifying whether medical devices meet the current standards and recommendations of the FDA premarket cybersecurity guidelines.
Pros
One of the few vendors with a published, device-specific service page rather than a generic IoT line, which matters when the deliverable has to travel with a 510(k) or PMA submission.
Coverage spans the whole device system: firmware, wireless, companion application and backend, tested as one estate.
Patient safety is named as a testing consideration, which is the framing FDA reviewers use.
Cons
No comparable published healthcare provider or payer page, so a hospital buying a network and application test is buying the general practice rather than a healthcare practice.
Enterprise platform delivery suits larger programmes more than a single application test.
Best for: medical device manufacturers assembling the penetration test report that section 524B premarket submissions expect.
4. Clearwater
Clearwater is healthcare-exclusive, and says so: it describes working with over 500 customers across the healthcare ecosystem, and its published service set spans penetration testing and technical assessments, HIPAA risk analysis, HITRUST certification services, managed security services and a compliance software suite. For a covered entity, that combination is unusual, because the HIPAA obligation that actually bites today is the risk analysis, and Clearwater sells the analysis and the test from the same healthcare-only bench.
Pros
Healthcare-exclusive, so the scoping conversation starts from clinical and administrative workflows rather than from a generic web application template.
Risk analysis and penetration testing from one firm, which maps cleanly onto how OCR's published settlements describe failures: an inadequate organisation-wide risk analysis, not a missing specific test.
Recognised by KLAS Research and Black Book, and listed among MSSP Alert's top managed security providers.
Cons
Breadth across managed services, software and consulting means the technical testing bench is one line among several, so ask for named tester credentials.
Its Redspin division has repositioned to CMMC work for the defense industrial base rather than healthcare testing, so confirm which team is delivering.
Best for: providers and payers that want the HIPAA risk analysis and the penetration test from a single healthcare-only firm.
5. Praetorian
Praetorian's healthcare page is built around attack surface management and continuous threat exposure management, with continuous penetration testing, red teaming and breach and attack simulation layered on top. It names HIPAA, HITRUST and FDA regulation as the compliance drivers, and frames the connected medical device estate as a primary threat vector, citing IoMT device density per hospital room and the prevalence of known critical vulnerabilities in devices still in use.
Pros
Discovery-first framing is the right one for a health system that genuinely does not know its full asset inventory, which is the honest starting position for most multi-site estates.
Continuous testing and red teaming rather than a single annual snapshot.
The healthcare page cites the regulatory triad explicitly rather than leaving compliance implied.
Cons
Attack surface management is the lead product, so a buyer who wants a deep single-application authorization test should confirm the manual testing depth inside the platform relationship.
Platform-led pricing suits programme budgets more than a one-off scoped test.
Best for: large connected healthcare estates where discovering unknown internet-facing assets is the first problem and testing them is the second.
6. Meditology Services
Meditology is healthcare-exclusive, serving providers, payers and suppliers, and describes itself as purpose-built for healthcare complexity. Its published service set covers technical testing including penetration testing and AI penetration testing, HITRUST certification services, and a medical device and IoT security practice. That last combination is rare: most firms do provider-side testing or device-side testing, not both.
Pros
Covers both the health system side and the device and IoT side under one healthcare-only practice.
HITRUST certification services alongside testing, which the Assessment Handbook's independence carve-out permits.
Explicit AI penetration testing line, relevant as clinical decision support and patient-facing assistants reach production.
Cons
Consultancy-led delivery, so tester continuity across a multi-year programme is worth pinning down in the statement of work.
Less published methodology detail than the device-specialist firms, so ask for a sample redacted report.
Best for: providers, payers and suppliers buying HITRUST certification and technical testing from the same healthcare-only firm.
7. BreachLock
BreachLock publishes a HIPAA penetration testing page that does something most vendor compliance pages do not: it cites the actual regulatory hook. The page references the HIPAA evaluation standard at 45 CFR 164.308(a)(8) requiring a periodic technical and nontechnical evaluation, and NIST SP 800-66 guidance that organisations conduct penetration testing if reasonable and appropriate. It recommends a quarterly programme with security control validation while noting that the framework position is annual. BreachLock lists offices in New York and Amsterdam.
Pros
The compliance page cites the regulation rather than asserting a requirement that does not exist, which is a useful signal about how the report will be written.
Audit-ready reporting mapped to HIPAA alongside PCI DSS, SOC 2 and ISO 27001, useful for healthtech carrying several frameworks at once.
Fast scoping and scheduling, with retesting included.
Cons
Platform-led delivery with a strong automation component, so confirm the manual-testing proportion for authorization and business logic work.
General-purpose compliance practice rather than a healthcare-only bench, so clinical workflow context comes from your side of the table.
Best for: healthtech and digital health teams that need a framework-mapped, audit-ready HIPAA report quickly.
8. Fortified Health Security
Fortified Health Security is healthcare-exclusive, serving hospitals and health systems, provider groups, health plans and healthcare technology and medical device companies from Brentwood, Tennessee. Its advisory line includes advanced penetration testing and red team services alongside virtual CISO, risk assessments and training, and its threat defence line includes managed connected medical device security.
Pros
Testing sits inside an ongoing managed security relationship, so findings land with a team that will actually operate the remediation.
Managed connected medical device security is a published service, not an add-on, which matters for a hospital with thousands of unmanaged IoMT endpoints.
Healthcare-exclusive scoping across providers, plans and device manufacturers.
Cons
Managed services are the centre of gravity, so a buyer wanting a standalone deep application test should confirm the offensive bench separately.
Primarily a United States practice, so multinational health groups should confirm coverage.
Best for: hospitals and health systems that want penetration testing delivered inside a managed security programme rather than as an isolated project.
9. TrustedSec
TrustedSec, headquartered in Fairlawn, Ohio, runs a manual penetration testing practice built around discovery and scoping, reconnaissance, vulnerability identification, exploitation, reporting and validation testing to confirm fixes. Its penetration testing page names HIPAA among the compliance requirements the work supports, alongside PCI DSS and SOC 2, and lists healthcare among the industries served.
Pros
Strong manual and adversarial reputation, with validation testing to confirm fixes built into the described methodology.
Research-led practice with a well-known open-source and tooling contribution record.
Compliance framing is honest: the test supports HIPAA rather than claiming HIPAA mandates it.
Cons
No dedicated healthcare or medical device service page, so the healthcare context has to come from your scoping brief.
Consultancy delivery model rather than a platform, so integration into an engineering tracker is something to specify in the statement of work.
Best for: buyers who want deep manual and adversarial testing and are comfortable supplying the healthcare scoping context themselves.
10. Schellman
Schellman, headquartered in Tampa, Florida, publishes a broad penetration testing portfolio spanning application, network, mobile, social engineering, cloud, physical, hardware and IoT, advanced services including red and purple teaming and Active Directory, and AI red teaming for generative systems. It runs a separate HITRUST certification practice, which is the reason it appears in a healthcare list at all: it is one of the firms where the HITRUST independence carve-out becomes a practical procurement option.
Pros
Hardware and IoT testing is a published line, relevant to connected device estates.
HITRUST certification work and penetration testing available from the same firm.
AI red teaming line is relevant as healthcare organisations put generative systems in front of clinical and patient data.
Cons
The penetration testing page does not reference healthcare, HIPAA or HITRUST, so healthcare specificity is not published at the service level.
Certification-first firm, so verify which team performs the test and how independence is documented if both engagements run together.
Best for: organisations already using the firm for certification work who want penetration testing under one contract.
Two firms worth knowing that are not penetration testing vendors
Category fit matters more in healthcare than in most verticals, because a report that is not a penetration test report will not satisfy an FDA reviewer asking for one.
Medcrypt is a leading name in medical device cybersecurity, and its platform supports FDA readiness, vulnerability management, SBOM analysis, threat modelling and regulatory submission support for FDA, EU MDR and Health Canada. It publishes an article titled "Why Pen Testing Isn't Enough" and positions around regulatory readiness rather than offensive testing services. If you need premarket documentation strategy, that is the right call. If you need the penetration test report itself, that is a separate purchase.
Redspin, historically a healthcare security testing name, now positions exclusively around CMMC and the defense industrial base as a division of Clearwater. Buyers reaching for Redspin on the strength of its healthcare heritage should confirm which practice they are actually engaging.
Neither point is a criticism. Both firms are clear about what they do. The mistake is on the buyer's side when a compliance-readiness engagement is booked expecting a penetration test report.
What a healthcare penetration test should actually cover
The scope that matters is not the network perimeter. It is the authorization boundary between records.
Object-level authorization on every record-scoped endpoint. Patient identifiers, encounter identifiers, claim identifiers and document identifiers are the parameters that leak charts when the server trusts them. The OWASP API Security Project ranks broken object level authorization as the leading API risk.
Role separation across the clinical hierarchy. Clinician, nurse, front desk, billing, patient, caregiver proxy and administrator are distinct trust levels, and the test has to prove a lower role cannot reach a higher role's data or functions.
Multi-tenant isolation for platform vendors. A healthtech SaaS serving many practices must prove practice A cannot reach practice B, including through shared reporting, exports and integration endpoints.
Integration and interface surfaces. HL7, FHIR and flat-file interfaces frequently sit behind weaker authentication than the main application because they were built for a trusted network that is no longer trusted.
Business logic in eligibility, claims and prescribing flows. Limit evasion, state manipulation and replay in workflows that carry clinical or financial consequence.
The connected estate, where it applies. Firmware, wireless, companion applications and backends, tested together, because the exploitable path usually crosses the boundary between them.
Evidence shaped for the regime you answer to. Tester independence and expertise, scope, duration, methods and results, which is precisely the five-element list the FDA's February 2026 guidance asks for and a sensible floor for a HIPAA or HITRUST file too.
The paperwork for all of this lives in two documents. The penetration testing statement of work template covers scope, rules of engagement, deliverables and acceptance criteria, and the penetration testing RFP template covers the vendor-facing questions.
How much does healthcare penetration testing cost in 2026?
Healthcare engagements price above a generic web application test because scope includes authenticated multi-role testing across a clinical hierarchy, integration interfaces, and reporting shaped for a regulator or assessor. Device work prices higher again because it spans firmware, wireless and backend.
Stingrai publishes package pricing openly. A one-time Autonomous Pentest with Snipe starts at US$3,000 and a one-time Hybrid Pentest with certified penetration testers is US$6,800, both covering exactly one web application and its APIs. The same two tiers run as subscriptions from US$450 per month and US$1,275 per month on a 12-month engagement. The Autonomous tier carries a No High or Critical Finding, Don't Pay guarantee, and retesting is included. Hospital estates, multi-application platforms and device programmes are quoted individually. Current figures are on the pricing page.
For an independent view of what testing costs across scopes, the penetration testing cost guide and the penetration testing cost calculator are the two starting points.
What this means for healthcare security buyers in 2026
Three practical conclusions follow from the regulatory picture.
Buy the test for the risk, cite it for the rule. HIPAA does not require a penetration test today, so a vendor telling you otherwise is either selling from a proposal or selling from a competitor's blog post. Buy the test because broken authorization in a patient portal is a reportable breach, and then present it as evidence behind the risk analysis and the periodic evaluation the rule does require.
Write the report requirements into the contract, not the kickoff call. The FDA has published the five elements a penetration test report should carry. Tester independence, expertise, scope, duration, methods and results is a good specification whether or not you file with the FDA, because it is the specification that makes a report auditable by anyone.
Test the authorization boundary, not the perimeter. Across the engagements analysed in the 2026 state of penetration testing report, 1,206 verified findings across 55 tests carried a 0.74% false-positive rate, 92.7% of tests surfaced at least one High or Critical issue, and the median time to fix a Critical was 10.5 days. Those numbers exist because findings are manually verified before they reach a report, which is the same standard the FDA guidance and any competent assessor expect.
Frequently Asked Questions
Who are the best healthcare penetration testing companies in 2026?
The best healthcare penetration testing companies in 2026 are Stingrai, Coalfire, NetSPI, Clearwater, Praetorian, Meditology Services, BreachLock, Fortified Health Security, TrustedSec and Schellman. Stingrai ranks first because Snipe, its autonomous AI agent for web application penetration testing, is purpose-built to hunt the broken authorization, IDOR and business logic flaws that expose patient records, and certified penetration testers work concurrently on the same engagement. Coalfire, NetSPI and Clearwater follow for assessment-led healthcare programmes, medical device depth and healthcare-exclusive coverage respectively. Every entry in this ranking links to the vendor's own published page and was last verified on 5 September 2026.
Does HIPAA require penetration testing?
No. The HIPAA Security Rule at 45 CFR Part 164 Subpart C never uses the phrase. It requires a risk analysis at 45 CFR 164.308(a)(1)(ii)(A), a periodic technical and nontechnical evaluation at 45 CFR 164.308(a)(8), and maintenance of security measures at 45 CFR 164.306(e). NIST SP 800-66r2, the federal implementation guide, places penetration testing inside those standards as an activity to conduct if reasonable and appropriate. A proposed rule published at 90 FR 898 on 6 January 2025 under RIN 0945-AA22 would add an express requirement at proposed 45 CFR 164.312(h)(2)(iii), but as of 5 September 2026 that proposal is not final.
Does HITRUST require penetration testing every 12 months?
HITRUST publishes no penetration testing frequency. The CSF requirement statements are licensed content inside MyCSF, so no public HITRUST page states a cadence. What HITRUST does publish, in the Assessment Handbook version 1.2, is a 90-day control incubation period before a control can be tested as implemented, a maximum 90-day fieldwork window, and independence rules that expressly permit assessor personnel to perform penetration testing for an assessed entity so long as they do not also remediate.
What does the FDA require for medical device penetration testing?
Section 524B of the Federal Food, Drug, and Cosmetic Act requires anyone submitting a 510(k), PMA, PDP, De Novo or HDE for a cyber device to submit information showing the device meets the cybersecurity requirements of section 524B(b). FDA's guidance, Cybersecurity in Medical Devices: Quality Management System Considerations and Content of Premarket Submissions, issued 3 February 2026, asks that penetration test reports include tester independence and technical expertise, scope of testing, duration of testing, testing methods employed, and test results, findings and observations. It also asks manufacturers to state who performed the testing and how independent they are from the device's developers.
Which company is best for medical device penetration testing?
NetSPI publishes the most detailed medical device penetration testing service page among the vendors reviewed here, covering firmware analysis, hardware survey, wireless configuration, network analysis, thick client and mobile applications, sensor data, privacy concerns and potential patient safety issues, and framing the outcome against FDA premarket cybersecurity guidelines. Meditology Services and Fortified Health Security also publish medical device and connected device security practices. For the web application, API and cloud backend layers that accompany almost every connected device, Stingrai's authorization and business logic focus applies directly.
What should a healthcare penetration test cover?
Object-level authorization on every record-scoped endpoint, role separation across the clinical hierarchy from patient through clinician to administrator, multi-tenant isolation for platform vendors, integration surfaces such as HL7 and FHIR interfaces, business logic in eligibility, claims and prescribing flows, and where applicable the connected device estate of firmware, wireless, companion application and backend tested together. The evidence should carry tester independence and expertise, scope, duration, methods and results, which is the five-element specification the FDA's February 2026 guidance sets out and a sensible floor for any healthcare file.
How often should a healthcare organisation run a penetration test?
There is no currently binding federal cadence for HIPAA-regulated entities. The proposed rule at 90 FR 898 would set at least once every 12 months, or in accordance with the entity's risk analysis, whichever is more frequent, but it is not final as of 5 September 2026. In practice, an annual test plus testing after any significant change to an in-scope system is the common commercial position, and organisations shipping application changes weekly increasingly run continuous testing so the gap between a change and its first test is measured in days rather than months.
How much does healthcare penetration testing cost in 2026?
Cost tracks scope: the number of applications and roles, whether integration interfaces are in scope, and whether a connected device estate is included. Stingrai publishes package pricing openly, with a one-time Autonomous Pentest from US$3,000 and a one-time Hybrid Pentest with certified penetration testers at US$6,800, each covering exactly one web application and its APIs, and the same tiers as subscriptions from US$450 and US$1,275 per month on a 12-month engagement. Hospital estates, multi-application platforms and device programmes are quoted individually. Current figures are on the pricing page.
Can a HITRUST assessor also perform our penetration test?
Yes, within limits. The HITRUST Assessment Handbook version 1.2 independence rules expressly permit assessor personnel to perform penetration testing for an assessed entity, provided the same personnel do not also remediate what they find. That is why several assessor-first firms appear in this ranking. The question worth asking during procurement is what the firm does when its own test finds a weakness in a control its own assessment accepted, and how that is documented.
What is the difference between a HIPAA penetration test and a HITRUST penetration test?
They are the same technical activity presented into different files. A HIPAA-oriented test is evidence behind the risk analysis and the periodic evaluation the Security Rule requires, and the audience is an OCR investigator reading a breach response. A HITRUST-oriented test is evidence that a control was implemented, tested inside the Assessment Handbook's 90-day fieldwork window after the 90-day incubation period, and the audience is an external assessor. Scope the test once against the real attack surface, then present the same report into both files.
Related reading
References
U.S. Department of Health and Human Services, Office for Civil Rights. _HIPAA Security Rule To Strengthen the Cybersecurity of Electronic Protected Health Information._ Proposed rule, 90 FR 898, 6 January 2025, RIN 0945-AA22, comments closed 7 March 2025. https://www.federalregister.gov/documents/2025/01/06/2024-30983/hipaa-security-rule-to-strengthen-the-cybersecurity-of-electronic-protected-health-information. Source of the 2018 to 2023 breach growth figures and of the proposed penetration testing implementation specification at 45 CFR 164.312(h)(2)(iii).
U.S. Government Publishing Office. _Federal Register, 6 January 2025, document 2024-30983, authenticated full text._ https://www.govinfo.gov/content/pkg/FR-2025-01-06/html/2024-30983.htm. The text used to verify the proposed regulatory language quoted on this page.
Office of the Federal Register. _45 CFR 164.306, 164.308 and 164.312._ https://www.ecfr.gov/current/title-45/section-164.308. The current Security Rule standards for general rules, administrative safeguards including risk analysis and evaluation, and technical safeguards.
U.S. Food and Drug Administration. _Cybersecurity in Medical Devices: Quality Management System Considerations and Content of Premarket Submissions._ Guidance for industry and FDA staff, issued 3 February 2026, docket FDA-2021-D-1158, superseding the guidance issued 27 June 2025. https://www.fda.gov/regulatory-information/search-fda-guidance-documents/cybersecurity-medical-devices-quality-management-system-considerations-and-content-premarket. Source of the section 524B framing and of the five penetration test report elements quoted on this page.
HITRUST. _The HITRUST Assessment Handbook, Version 1.2._ https://hitrustalliance.net/hubfs/Website/PDF%20Downloads/Final%20-%20HITRUST%20Assessment%20Handbook%20v1.2.pdf. Source of the 90-day incubation period, the 90-day fieldwork window and the independence rules permitting assessor personnel to perform penetration testing.
National Institute of Standards and Technology. _SP 800-66r2, Implementing the HIPAA Security Rule: A Cybersecurity Resource Guide._ February 2024. https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-66r2.pdf. Places penetration testing inside the risk analysis and evaluation standards as an activity to conduct if reasonable and appropriate.
OWASP Foundation. _API Security Project._ https://owasp.org/www-project-api-security/. Ranks broken object level authorization as the leading API security risk.
Coalfire. _Healthcare._ https://coalfire.com/industries/healthcare. Published healthcare practice covering HIPAA-oriented testing, HITRUST advisory services and cyber risk assessment. Verified 5 September 2026.
NetSPI. _Medical Device Penetration Testing._ https://www.netspi.com/netspi-ptaas/hardware-systems/medical-device/. Published medical device testing scope and the FDA premarket cybersecurity guidelines framing. Verified 5 September 2026.
Clearwater. _Company site._ https://clearwatersecurity.com/. Healthcare-exclusive positioning, over 500 healthcare customers, penetration testing, HIPAA risk analysis and HITRUST services. Verified 5 September 2026.
Praetorian. _Attack Surface Management for Healthcare._ https://www.praetorian.com/industries/healthcare/. Healthcare attack surface management, continuous penetration testing and red teaming, with HIPAA, HITRUST and FDA cited. Verified 5 September 2026.
Meditology Services. _Company site._ https://www.meditologyservices.com/. Healthcare-exclusive technical testing, HITRUST certification services and medical device and IoT security practice. Verified 5 September 2026.
BreachLock. _HIPAA Penetration Testing._ https://www.breachlock.com/compliance/hipaa-penetration-testing/. Cites the HIPAA evaluation standard at 164.308(a)(8) and NIST SP 800-66 guidance. Verified 5 September 2026.
Fortified Health Security. _Company site._ https://fortifiedhealthsecurity.com/. Healthcare-exclusive advisory and threat defence lines including penetration testing, red team and managed connected medical device security. Verified 5 September 2026.
TrustedSec. _Penetration Testing._ https://trustedsec.com/services/penetration-testing. Manual penetration testing methodology naming HIPAA among supported compliance requirements. Verified 5 September 2026.
Schellman. _Penetration Testing._ https://www.schellman.com/penetration-testing. Published testing portfolio spanning application, network, mobile, cloud, physical, hardware and IoT, plus red, purple and AI red teaming. Verified 5 September 2026.
Medcrypt. _Company site._ https://www.medcrypt.com/. Medical device cybersecurity platform for FDA readiness, vulnerability management, SBOM analysis and regulatory submission support. Verified 5 September 2026.
Redspin. _Company site._ https://www.redspin.com/. CMMC certification and readiness services for the defense industrial base, operating as a division of Clearwater. Verified 5 September 2026.
Stingrai. _The State of Penetration Testing 2026._ https://www.stingrai.io/blog/state-of-penetration-testing-2026. 1,206 verified findings across 55 penetration tests, severity mix, remediation timing and false positive rate.
Stingrai. _Pricing._ https://www.stingrai.io/pricing. Published one-time and continuous package prices for one web application and its APIs.
Ready to scope a healthcare penetration test?
The finding that turns into a reportable breach is almost never a missing patch. It is an authorization check that trusts a patient identifier it should have validated. Stingrai is a CREST-accredited penetration testing service provider whose penetration testing supports HIPAA, HITRUST, SOC 2 and ISO 27001 programmes by producing the scope statement, technical report, remediation record and retest evidence those programmes consume. Certified penetration testers work concurrently with Snipe, our autonomous AI agent for web application penetration testing, hunting the broken authorization, IDOR and business logic flaws that put one patient's record on another patient's screen. Book a free scoping call, get a quote for a hospital estate or multi-application scope, or read the published package prices on the pricing page.



