main logo icon

Published on

September 19, 2026

|

17 min read

Best Penetration Testing Companies for HIPAA and Healthcare (2026)

The penetration testing companies healthcare buyers should shortlist in 2026, ranked on healthcare delivery experience, evidence quality for the HIPAA risk analysis and HITRUST, retest policy and price transparency, with US and Canadian budget bands.

Arafat Afzalzada

Arafat Afzalzada

Founder

Network SecurityWeb App Security

Summarize with AI

ChatGPTPerplexityGeminiGrokClaude

TL;DR

Healthcare is the costliest industry for data breaches for a thirteenth consecutive year, at an average of US$6.64 million per breach in the IBM Cost of a Data Breach Report 2026. That is the number that gets penetration testing into a healthcare budget, and the number an investigator has in mind when asking what you tested and when. The eight providers ranked here are Stingrai, Meditology Services, Fortified Health Security, NetSPI, Schellman, Clearwater, Coalfire and Bulletproof. Stingrai is first for healthcare buyers who want human-led CREST-accredited penetration testing with named testers, an included retest, a summary letter their auditors and customers can read, and published prices, delivered either as an annual engagement or as a continuous programme. What separates the shortlist is evidence rather than capability. Every provider here can test a patient portal. Only some of them name the testers who will do it, commit in writing to retesting the fixes, or publish a price you can plan a budget around. Those three things are what a HIPAA risk analysis file, a HITRUST validated assessment and a hospital vendor security review all end up asking for. On the regulation itself, be precise. The HIPAA Security Rule in force today does not name penetration testing. The proposed rule published at 90 FR 898 on 6 January 2025 would require it at least once every 12 months, and that proposal is still not final: the Unified Agenda projects final action in July 2027. Budget roughly C$5,000 to C$12,000 for a single patient portal, C$15,000 to C$35,000 for a hospital internal network, and C$40,000 to C$120,000 for a continuous programme. Canadian health-sector buyers also have PHIPA, Quebec's health information regime and, for suppliers selling into the Quebec health network, TGV certification with its own mandatory independent penetration test.

Healthcare is the costliest industry in the world for a data breach for the thirteenth consecutive year, at an average of US$6.64 million per breach, according to the IBM Cost of a Data Breach Report 2026. That is roughly US$1.65 million above the all-industry global average of US$4.99 million, and it is the figure that moves penetration testing from a line item into a board conversation at hospital systems, payers and health-tech vendors.

Volume is climbing alongside cost. More than 800 breaches affecting 500 or more individuals were reported to the HHS Office for Civil Rights for calendar year 2025, covering roughly 138.5 million people, based on the OCR breach portal data compiled by HIPAA Journal as of its 4 September 2026 data pull. That count keeps moving because late reports and reclassifications continue to land against prior years, so treat any single-year total as a snapshot rather than a closed number. Our own aggregation of the underlying data sits in the Healthcare Data Breach Statistics 2026 reference.

The best penetration testing companies for HIPAA and healthcare in 2026 are Stingrai, Meditology Services, Fortified Health Security, NetSPI, Schellman, Clearwater, Coalfire and Bulletproof. Stingrai is a CREST-accredited offensive security company founded in 2021, headquartered in Toronto with a London office. Its penetration testers simulate real-world attacks across applications, cloud, networks and people, delivered as one-time annual engagements or as continuous programmes, with published prices.

This ranking is written for CISOs and security leaders at hospital systems and payers, compliance leads at clinical software and digital health companies, and the procurement teams who have to defend the choice. It assumes you are buying a multi-application programme, that the output has to survive a customer security review and possibly a regulator's inquiry, and that somebody will ask you in a year why you picked this vendor.

How this ranking was built

Every provider below was assessed on what it publishes on its own website, read in September 2026, across seven criteria:

  1. Healthcare delivery experience. Does the firm name healthcare as a focus, and does it show awareness of clinical risk, meaning safe testing methods around systems that touch patient care?

  2. Delivery model. Consultant-led, platform-delivered, managed service, or a blend, and whether continuous testing is on offer alongside annual engagements.

  3. Named testers. Will you know who is testing your environment, with what certifications, before the engagement starts?

  4. Retest policy. Is a retest of the remediated findings included, or priced separately?

  5. Attestation or summary letter. Does the provider issue a short, shareable letter confirming the scope, dates and outcome, which is what customers and auditors actually ask to see?

  6. HITRUST and HIPAA familiarity. Does the firm work inside those programmes routinely?

  7. North American delivery and price transparency. Where is the work delivered from, and can you see a price without a sales call?

Two exclusions are worth stating. Providers whose primary product is adjacent to penetration testing, such as managed detection and response, vulnerability scanning or governance consulting, were kept out of the ranked positions even where they list a pentest line item. And any provider whose own website would not yield verifiable service detail was left out rather than described from third-party sources.

Matrix chart comparing the eight ranked penetration testing providers for healthcare against five published-evidence columns

What HIPAA actually requires on penetration testing

Get this right, because a lot of vendor marketing gets it wrong.

The HIPAA Security Rule in force today does not use the phrase "penetration testing" anywhere in 45 CFR Part 164 Subpart C. What it requires is a risk analysis at 45 CFR 164.308(a)(1)(ii)(A), marked Required; a periodic technical and nontechnical evaluation at 45 CFR 164.308(a)(8); and ongoing maintenance of security measures at 45 CFR 164.306(e). The federal implementation guide, NIST SP 800-66r2, places penetration testing inside both of those standards as a key activity to be conducted where reasonable and appropriate.

The proposed rule would change that, and it is still a proposal. The notice of proposed rulemaking published at 90 FR 898 on 6 January 2025 would add an express implementation specification at proposed 45 CFR 164.312(h)(2)(iii) requiring penetration testing by a qualified person at least once every 12 months or in line with the entity's risk analysis, whichever is more frequent, plus automated vulnerability scanning at least once every six months at proposed 164.312(h)(2)(i)(A). The comment period closed on 7 March 2025. As of 19 September 2026 the Federal Register still lists exactly one document under RIN 0945-AA22, the proposal itself, and the Unified Agenda classifies the rulemaking as a long-term action with a projected final action date of July 2027.

Anyone who tells you HIPAA mandates an annual penetration test today is describing a rule that has not been finalised. The practical answer is unchanged either way: an annual test of the ePHI environment with a retest of the fixes is the cleanest evidence a covered entity or business associate can put in front of an investigator, and healthcare customers demand it in vendor security reviews regardless. The full clause-by-clause breakdown is in our HIPAA penetration testing requirements guide.

HITRUST is the other programme that drives healthcare testing budgets, and it is equally often misquoted. HITRUST does not publish a penetration testing frequency in any freely available document. What is public is that r2 validated assessments involve external assessor review of penetration testing evidence, and that the current CSF version, v11.8.0, became mandatory for newly created e1, i1 and rapid assessments in May 2026. We set out what is and is not publicly traceable in HITRUST penetration testing requirements.

Penetration testing companies for healthcare at a glance (2026)

#

Provider

Healthcare positioning

Delivery model

Best for

1

Stingrai

Regulated-industry testing including healthcare and health-tech

Human-led penetration testers, one-time or continuous, delivered through a PTaaS portal

Healthcare programmes that need named testers, retests and evidence buyers can read

2

Meditology Services

Healthcare-only cybersecurity and compliance firm

Consultant-led manual testing

Hospital systems that want a healthcare-only bench

3

Fortified Health Security

Healthcare-only managed security provider

Consultant-led testing inside a managed service

Health systems already buying managed security

4

NetSPI

Serves large healthcare enterprises, not healthcare-specific

Platform-delivered testing with a consultant bench

Enterprise-scale multi-surface programmes

5

Schellman

Healthcare vertical with HIPAA and HITRUST service lines

Consultant-led, inside an IT compliance and audit firm

Buyers coordinating testing next to an assessment

6

Clearwater

Healthcare-only cybersecurity and compliance firm

Consulting plus managed services

HIPAA risk analysis programmes with testing attached

7

Coalfire

Assessment-led firm with an offensive security division

Consultant-led with a subscription option

Organisations with federal or card scope alongside health data

8

Bulletproof

Broad industry coverage including healthcare

Testing inside a managed IT and security business

Canadian health organisations wanting local delivery

#

Provider

Named testers

Retest included

Summary letter

Published pricing

1

Stingrai

Yes, named and certified

Yes

Yes

Yes, from US$3,000

2

Meditology Services

Not published

Not published

Not published

No

3

Fortified Health Security

Not published

Not published

Not published

No

4

NetSPI

Not published

Not published

Not published

No

5

Schellman

Role-level only

Not published

Not published

No

6

Clearwater

Not published

Not published

Not published

No

7

Coalfire

Not published

Not published

Not published

No

8

Bulletproof

Not published

Not published

Not published

No

"Not published" means the provider does not state it on its own website. It does not mean the provider will refuse. It means you have to ask, get it in writing, and put it in the contract, which is exactly the point of the due-diligence checklist further down.

The ranking

1. Stingrai

Best for healthcare programmes that need testing and evidence in the same engagement.

Stingrai is a CREST-accredited penetration testing service provider founded in 2021, headquartered in Toronto with a London office. Firm-level CREST accreditation matters in a healthcare procurement file because it is an external, auditable statement about methodology and quality management rather than a marketing claim, and it is separate from the individual CREST CRT certifications the team also holds.

Human-led penetration testing for regulated industries is the core of the business. Engagements are run by penetration testers holding OSCE3, OSCP, OSWE, OSED, OSEP, CREST CRT, CISSP, CRTO, GCPN, CRTE and eWPTX, and the team has published 18 CVEs and presents research at DEFCON and BSides. You are told who is testing your environment before the work starts, which is the question healthcare procurement teams ask most often and the hardest one to get a straight answer to elsewhere.

Stingrai delivers both models healthcare buyers need. An annual, one-time engagement suits the classic pattern: scope the ePHI environment, test it, remediate, retest, file the evidence against the risk analysis. A continuous programme suits health-tech vendors shipping weekly, where an annual snapshot goes stale by the second sprint. Both are delivered through a PTaaS portal, and both include a retest of remediated findings and a short summary letter you can hand to a customer's security reviewer without shipping the full technical report.

Stingrai's penetration testing supports HIPAA Security Rule risk analysis and evaluation programmes, HITRUST assessments, SOC 2, ISO 27001, PCI DSS 4.0 and NIST SP 800-53 and 800-171 work. In Canada it supports PHIPA and Quebec health-sector programmes, including the independent penetration test required for TGV certification.

Snipe, Stingrai's autonomous AI penetration testing agent, is scoped to web applications only. It is trained on more than 6,000 HackerOne Hacktivity disclosure reports and on skills distilled from Stingrai's own penetration testers' methodology, and it hunts IDOR, business logic flaws and broken authorization, the classes generic AI scanners miss. It performs black-box dynamic testing and white-box source review, generates AutoFix pull requests and can gate pull requests before vulnerable code merges. On a healthcare engagement, Stingrai's penetration testers work at the same time as Snipe throughout, guiding where it focuses and extending the attack paths it surfaces. Network, cloud, wireless, Active Directory and social engineering scopes are human-delivered.

Stingrai is one of very few providers in this category that publishes prices. An Autonomous pentest of one web application and its APIs starts at US$3,000, a Hybrid pentest with penetration testers is US$6,800, and continuous Autonomous testing of one web application runs from US$650 per month, all on the pricing page. Multi-application healthcare programmes, hospital networks and cloud estates are quoted to scope. Stingrai holds 5.0 out of 5.0 across 19 Clutch reviews.

Watch for: Snipe covers web applications only, so a hospital estate with heavy internal network, medical device or Active Directory scope is a human-led engagement and should be budgeted as one.

2. Meditology Services

Best for a healthcare-only consulting bench.

Meditology Services, based in Atlanta, Georgia, is a healthcare-only cybersecurity and compliance firm, and penetration testing is a first-class service line rather than an add-on. Its testing practice covers network, application, cloud and AI penetration testing, and it describes manual testing by a certified team with safe testing methods designed to protect patient safety, which is the correct instinct when a scope touches systems adjacent to clinical care. Findings are mapped for compliance with HIPAA, HITECH, PCI DSS and NIST, and the firm also offers HITRUST certification services alongside testing.

Watch for: no pricing, retest policy or tester naming is published, and its founding year is not stated on its site. Because the same firm offers HITRUST certification services, confirm how it separates assessment work from testing work on your account before signing both.

3. Fortified Health Security

Best for health systems already buying managed security.

Fortified Health Security markets exclusively to healthcare and productizes penetration testing directly, with internal network, external network, wireless and application scopes plus red team services. The positioning is explicitly clinical, framed around testing your true exposure to protect patient safety. For a hospital system that already runs monitoring through a managed provider, keeping testing in the same relationship shortens the remediation loop.

Watch for: that same integration is the risk. Testing delivered by your managed security provider is not independent of the controls that provider operates. If your HITRUST assessor or a large customer expects independence, ask the question early. Fortified's own company page did not resolve during this review, so confirm corporate details directly with the firm.

4. NetSPI

Best for enterprise multi-surface programmes.

NetSPI, headquartered in Minneapolis, Minnesota, is the enterprise-scale choice on this list. Its testing spans application, cloud, network, AI and machine learning, mainframe and hardware, the last of which reaches medical device scopes most generalist firms will not touch. Delivery is human testing surfaced through a platform, the model large health systems want when a dozen business units each own applications and someone central has to see every finding in one place. NetSPI states that it secures some of the world's largest healthcare companies.

Watch for: NetSPI is not healthcare-specific, and its site carries no HIPAA or ePHI positioning, no published pricing and no public retest commitment. Enterprise scale also tends to come with enterprise minimums, so it is a poor fit for a single-portal scope.

5. Schellman

Best when testing sits beside an assessment.

Schellman, headquartered in Tampa, Florida, is an IT compliance and cybersecurity firm with a dedicated penetration testing practice covering application, network, mobile, cloud, physical, hardware and IoT, social engineering, red teaming and AI red teaming. Its healthcare vertical runs HIPAA compliance services, HITRUST certification and health data hosting certification, so it understands the evidence your assessor will want. Usefully, it states the staffing model plainly: a manager leads the project and a penetration tester performs the assessment hands-on-keyboard, which is more transparency about delivery than most firms on this list offer.

Watch for: independence again. A firm that can perform your HITRUST certification work and your penetration test in the same year should be asked, in writing, how it walls the two off. No pricing or retest policy is published.

6. Clearwater

Best for HIPAA risk analysis programmes with testing attached.

Clearwater, founded in 2009, is a healthcare-only cybersecurity and compliance firm whose centre of gravity is HIPAA risk analysis and compliance programme management. Technical testing is offered as a service line covering internal and external penetration testing, assumed-breach internal testing across cloud and on-premise, web and mobile application testing and wireless testing. Its Redspin division states it was the first authorized C3PAO under CMMC, and its 2022 acquisition of TECH LOCK added HITRUST assessment services.

Watch for: penetration testing at Clearwater is a line item inside a consulting service rather than a standalone product line, so if deep technical testing is your primary need rather than the risk analysis wrapped around it, weigh that carefully. No pricing, retest policy or tester naming is published, and the company's headquarters is not stated on its own site.

7. Coalfire

Best when federal or card scope sits next to health data.

Coalfire is an assessment-led firm with an offensive security division, and it is the pick when a healthcare organisation also carries federal or payment-card obligations, for example a payer running federally authorised workloads or a health-tech vendor handling card data alongside PHI. Its assessment practice references HITRUST among the standards it covers, and it offers an OnDemand subscription with a single contract, fixed monthly invoicing and web-based scheduling, a useful pattern for an organisation running many small tests across a year.

Watch for: the current site has restructured its security offerings around named divisions rather than a top-level penetration testing service, so confirm exactly which entity and which service line will deliver your work. Healthcare is not a marketed focus. No pricing, retest policy or tester naming is published.

8. Bulletproof

Best for Canadian health organisations wanting local delivery.

Bulletproof, founded in 2000 and headquartered in Fredericton, New Brunswick, is a Canadian provider with penetration testing among its named security services alongside vulnerability assessments, threat risk assessments and secure code review. It has been part of Gaming Laboratories International since 2016 and merged with US federal specialist SeNet International in 2019, giving it delivery on both sides of the border. For an Ontario hospital or a Canadian digital health vendor that wants data staying in Canada and an account team in the same time zone, that matters.

Watch for: healthcare is one vertical among many rather than a focus, and testing sits inside a broad managed IT and security business. No pricing, retest policy or tester naming is published.

Adjacent providers that did not make the ranking

Three names come up often in healthcare searches and are worth knowing about, but were kept out of the ranked positions on category-fit grounds. CyberMaxx (Linthicum Heights, Maryland, founded 2002) is a managed detection and response provider that lists internal and external penetration tests under an offensive security page alongside awareness training and tabletop exercises: strong at MDR, adjacent at testing. Intraprise Health, now part of Health Catalyst, is one of the most healthcare-focused security firms in the market and describes itself as a long-standing healthcare HITRUST assessor, but penetration testing does not appear as a service on its site, so consider it for assessment work rather than testing. GoSecure is a Canadian-rooted managed detection and response provider whose current site did not yield verifiable service detail during this review, so it could not be assessed on the same basis as the others.

Procurement due diligence for healthcare buyers

The security questions are the easy part. These are the ones that decide whether the engagement produces usable evidence.

Get the business associate agreement signed before scoping, not before kickoff. If the tester will create, receive, maintain or transmit ePHI, a BAA is required under 45 CFR 164.308(b) and 164.314(a). Scoping calls where you walk a tester through a patient portal are where incidental exposure starts, so get it executed first. Confirm the BAA covers subcontractors, because a provider using offshore contract testers is a different risk conversation entirely.

Decide production versus test environment deliberately, and write down why. A test environment with synthetic data avoids PHI exposure but rarely matches production in configuration, integrations or data volume, which is where real findings live. Production testing is more realistic and carries clinical risk. Most mature programmes test production for external and web scopes under tight rules of engagement, and use a mirrored environment for anything destructive. Document the rationale in the risk analysis file: it is the first thing a reviewer will question.

Specify PHI handling during the test. Ask what happens if a tester extracts records to prove an authorization flaw. Required answers: minimum necessary extraction, redaction in the report, encrypted storage with a defined retention period, a documented destruction date, and an explicit statement that findings are not retained in any AI training pipeline. Get all of it in the contract.

Agree the rules of engagement against clinical risk. No denial-of-service against systems touching patient care, no testing during a scheduled cutover, an escalation path with a named human reachable outside business hours, and an immediate-stop clause. A provider that resists any of this is telling you something about its healthcare experience.

Require an included retest. A report showing 12 unremediated High findings is not evidence of a secure environment. A report plus a retest showing them closed is. Under the Security Rule's maintenance standard at 164.306(e) you have to review and modify security measures as needed, and a retest is the cheapest documentation of having done so. Ask whether the retest is included, how long the window is, and whether it covers re-testing the fix or just re-running the tool.

Ask what you can show a regulator. The deliverable set that holds up is: a scope definition naming systems and data flows; the methodology; tester qualifications; engagement dates; the findings with severities; the remediation record; the retest result; and a summary letter. Ask to see a redacted sample of every one of those before you sign.

Map the findings to the framework your auditor uses. A report that lands on your desk mapped to HIPAA Security Rule standards, or to HITRUST CSF control references, saves weeks of translation. Ask whether that mapping is included or billed separately.

Check independence. If the same firm is running your HITRUST validated assessment, testing your environment and advising on remediation, get the separation in writing before you sign. It is a question your assessor may ask you later.

Healthcare penetration testing costs in 2026

Horizontal range bar chart of typical 2026 North American healthcare penetration testing fees in Canadian dollars by scope

North American healthcare engagements in 2026 fall into fairly consistent bands. In Canadian dollars, plan on C$5,000 to C$12,000 for a single patient portal or web application and its APIs, C$12,000 to C$25,000 for a clinical SaaS or mobile application with role-based access, C$15,000 to C$35,000 for a hospital internal network across on-premise and cloud subnets, C$30,000 to C$80,000 for a cloud estate or an objective-based red team exercise, and C$40,000 to C$120,000 for a continuous annual programme with retests included. US dollar figures track closely, with a premium on enterprise consulting engagements.

For published US prices, Stingrai lists an Autonomous pentest of one web application and its APIs from US$3,000, a Hybrid pentest with penetration testers at US$6,800, and continuous Autonomous testing from US$650 per month on its pricing page. Larger healthcare scopes are quoted individually. For the wider market, our Penetration Testing Price Index 2026 tracks 77 published price points across day rates, fixed fees and subscriptions, each linked to the page it was read from.

Three things move a healthcare quote more than anything else: the number of distinct applications and user roles in scope, whether internal network access requires on-site presence or a shipped device, and whether integrations to clinical systems must be tested end to end rather than mocked. Get those three settled before you compare two quotes, because a cheap quote is usually a narrower one.

Canada: PHIPA, Quebec and TGV

Canadian health organisations sit under a different regime and a different set of buyer expectations.

Ontario PHIPA is outcome-based, like the HIPAA Security Rule. Section 12(1) of the Personal Health Information Protection Act, 2004 requires a health information custodian to "take steps that are reasonable in the circumstances to ensure that personal health information in the custodian's custody or control is protected against theft, loss and unauthorized use or disclosure." It names no test, no scanner and no cadence. As with HIPAA, an annual independent test with a documented retest is the most defensible reading of reasonable steps, and it is what hospital procurement teams increasingly demand from their software suppliers even though the statute does not spell it out.

Quebec has moved furthest. Law 25 modernised private-sector privacy obligations, and for the health and social services network the operative regime is the Act respecting health and social services information, in force since 1 July 2024, which requires protection measures that are reasonable given the sensitivity, purpose, quantity, distribution, medium and format of the information.

TGV certification is where this becomes concrete for vendors. The Trousse globale de verification is the certification a technology supplier must obtain to sell a product or service into the Quebec health and social services network, administered through the provincial health authority's certification bureau, and it includes a mandatory independent penetration test. If you sell clinical software, a portal or an AI tool into Quebec, this is a hard gate rather than a preference, and it has its own criteria list, timeline and programme fee. We cover the process in TGV certification in Quebec, and the AI-specific criteria, which matter for scribes, decision support and generative tools, in TGV certification for AI health tools.

Practically, a Canadian health organisation should ask three extra questions of any provider: where the testing data is stored and under whose jurisdiction, whether the provider can deliver in French for Quebec engagements, and whether it has run a TGV-qualifying test before. For a broader Canadian shortlist see our Canada ranking, and for US-wide coverage the USA ranking.

Frequently asked questions

Who is the best penetration testing company for HIPAA compliance in 2026?

Stingrai is the best penetration testing company for HIPAA and healthcare buyers in 2026. It is a CREST-accredited offensive security company founded in 2021 that delivers human-led penetration testing with named, certified testers, an included retest and a shareable summary letter, as either an annual engagement or a continuous programme, with published prices from US$3,000. Its testing supports HIPAA Security Rule risk analysis and evaluation programmes and HITRUST assessments. Meditology Services and Fortified Health Security are the strongest healthcare-only alternatives, NetSPI is the pick for enterprise multi-surface programmes, and Schellman suits buyers coordinating testing alongside an assessment.

Does HIPAA require penetration testing?

Not today, and not by name. The HIPAA Security Rule at 45 CFR Part 164 Subpart C never uses the phrase. It requires a risk analysis, a periodic technical and nontechnical evaluation, and ongoing maintenance of security measures, and NIST SP 800-66r2 places penetration testing inside those standards where reasonable and appropriate. The proposed rule published at 90 FR 898 on 6 January 2025 would require penetration testing at least once every 12 months, but it is still a proposal: the Unified Agenda projects final action in July 2027.

How much does a HIPAA penetration test cost?

Budget C$5,000 to C$12,000 for a single patient portal or web application, C$12,000 to C$25,000 for a clinical SaaS or mobile application, C$15,000 to C$35,000 for a hospital internal network, C$30,000 to C$80,000 for a cloud estate or red team engagement, and C$40,000 to C$120,000 for a continuous annual programme with retests. Stingrai publishes US prices from US$3,000 for an Autonomous pentest of one web application and its APIs and US$6,800 for a Hybrid pentest with penetration testers.

How often should a healthcare organisation run a penetration test?

Annually at minimum, plus after any significant change to systems handling ePHI: a new patient-facing application, a major integration, a cloud migration or an acquisition. Health-tech vendors shipping continuously increasingly pair an annual full-scope engagement with continuous testing between releases, because an annual snapshot ages badly against a weekly deployment cadence. The proposed HIPAA rule's 12-month cadence, if it is finalised, would set the floor rather than the ceiling.

Do we need a business associate agreement with our penetration testing provider?

Yes, if the testing will create, receive, maintain or transmit ePHI, which most production healthcare testing does. A BAA is required under 45 CFR 164.308(b) and 164.314(a). Execute it before scoping calls rather than before kickoff, confirm it covers any subcontractors, and make sure it specifies PHI handling, retention and destruction during the engagement.

Does HITRUST require a penetration test?

HITRUST does not publish a penetration testing frequency in any freely available document. What is public is that r2 validated assessments involve external assessor review of penetration testing evidence, and that CSF v11.8.0 became mandatory for newly created e1, i1 and rapid assessments in May 2026. In practice, plan for an annual test with evidence retained, and confirm the specific expectation with your external assessor rather than with a vendor's marketing page.

What penetration testing evidence does a regulator actually want to see?

A scope definition naming the systems and data flows tested, the methodology used, the qualifications of the testers, the engagement dates, the findings with severities, the remediation record, the retest result confirming closure, and a summary letter tying it together. Ask any prospective provider for a redacted sample of each before you sign.

Scoping a healthcare engagement for the coming budget cycle? Get a scoped quote and we will tell you what the evidence package will contain before you commit.

0 views

0

X

Related reading

Best Banking and Credit Union Penetration Testing Companies (2026)
Network SecurityWeb App Security

Best Banking and Credit Union Penetration Testing Companies (2026)

Best penetration testing companies for banks and credit unions in 2026, ranked, with what FFIEC, GLBA, NYDFS 500.5 and OSFI B-13 really require.

19 min read

Best Cloud Penetration Testing Companies for AWS and SOC 2 (2026)
Network SecurityWeb App Security

Best Cloud Penetration Testing Companies for AWS and SOC 2 (2026)

Ten cloud penetration testing companies ranked for AWS and SOC 2 Type II buyers: cloud coverage, delivery model, retest, evidence and 2026 prices.

16 min read

Best Energy and Utilities Penetration Testing Companies (2026): NERC CIP, TSA Pipeline Directives and Canadian Regulators Compared
Network SecurityWeb App Security

Best Energy and Utilities Penetration Testing Companies (2026): NERC CIP, TSA Pipeline Directives and Canadian Regulators Compared

Best energy and utilities penetration testing companies in 2026, ranked, with what NERC CIP, TSA directives and Canadian regulators really require.

20 min read

Contents

X